When unsharing a federation node, tunnels created via federationTunnelCreate
were not cleaned up, allowing clients to continue using them. Added
cleanupFederationTunnels() to delete these tunnels and reload the node agent.
Added dual-layer port range enforcement for federation sharing:
Server-side (Provider):
- federationRuntimeApplyRole: validate runtime.Port against share range
- validateFederationCommandPorts: hardened against malformed JSON bypass
- New helpers: validateRemoteNodePort, remoteNodePortRange
Client-side (Consumer):
- prepareTunnelCreateState: pre-check ports for remote nodes
- tunnelCreate type=1: validate targetPort for remote entry
- forwardCreate/Update/BatchChangeTunnel: port range validation
Prevents consumers from using arbitrary ports outside provider's allowed range.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-opencode)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
- Fix Type 1 (port forwarding) tunnels to call applyFederationRuntime
Previously only Type 2 tunnels applied federation runtime, causing
port forwarding tunnels to not be properly configured in federation mode
- Remove incorrect UDP tunnel type override in federationTunnelCreate
UDP tunnels were being incorrectly set to Type 2, which conflicted with
the federation runtime logic that expects Type 1 for port forwarding
These fixes ensure all tunnel types are properly handled in federation mode
with correct runtime configuration applied.
The federationRuntimeCommand handler forwarded AddService/UpdateService
commands from consumers to provider nodes without validating that the
port in the service payload falls within the share's allowed port range.
This allowed consumers to use any port on shared nodes, bypassing the
provider's port_range_start/port_range_end restrictions.
Add port extraction and validation in federationRuntimeCommand for
service commands, rejecting requests with ports outside the allowed
range with a 403 error.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Run Postgres id-sequence repair on every startup migration and add contract coverage plus a GitHub Actions Postgres job to catch schema-drift regressions before release.
- Add transaction support for import operations with rollback on failure
- Add auto-backup before import to allow recovery on failure
- Convert user import to use INSERT ON CONFLICT pattern
- Add Execer interface to support both DB and Tx in import functions
The gcode.hostcentral.cc proxy only supports github.com file downloads,
not api.github.com requests. API calls through the proxy returned 404
HTML pages, causing JSON decode error: invalid character '<'.
Also updates repo name from flux-panel to flvx across upgrade and
install URLs.