A connection that cannot point at the machine it is running on

"Nothing runs on the LLeMbas host" is the sentence the absent sandbox and the
absent local MCP rest on, and an SSH profile aimed at 127.0.0.1 walked straight
past it -- through a real login, with every gate in policy.py still applying,
onto the machine holding the database and the Fernet key. From the SSH layer
down it is indistinguishable from a container on the network, so nothing here
could have noticed.

One switch, three positions: never, one named port, anywhere. The middle one is
the one with a real use -- a container that published its SSH port on the
loopback interface is genuinely somewhere else -- and port 22 is refused even
there, because that one is this host's own sshd.

Enforced in five places, because a row can predate a setting: saving a profile,
`session.resolve` (the control every agent tool, the terminal and the canvas go
through), the composer's picker, browsing, and the draft the panels open against
before a chat exists. Check refuses before it opens its socket rather than after.

And the recognition never resolves a name on the request path. `refusal` runs
several times per page render; the first version of this looked names up inline
and the suite went from two minutes to not finishing. Literal forms are decided
from the string, a name is settled where a network call is already expected, and
the answer lives on the row. The gap that leaves is written down rather than
discovered.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Jaroslav Beneš
2026-08-06 10:07:36 +02:00
parent bdd7e09753
commit 09156230b3
13 changed files with 698 additions and 11 deletions
+13
View File
@@ -54,6 +54,19 @@ def fresh_database(tmp_path: Path) -> Iterator[None]:
Base.metadata.create_all(bind=get_engine())
sync_schema(get_engine())
# An SSH connection to loopback is refused by default -- see
# services/agent/hosts.py, and `tests/test_agent_hosts.py` for the guard
# itself. Almost every agent test has to point at 127.0.0.1 anyway, because
# the ones that stand up a real asyncssh server can only listen there, and
# the rest were written beside them. So the suite runs with the switch open
# and the tests that care about it close it explicitly.
from lembas.db.session import session_scope
from lembas.services import settings_store
with session_scope() as db:
settings_store.update(db, {"loopback": "on"}, key=settings_store.AGENTS)
yield
reset_engine()