• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

archetech / archon / 32876748443
87%

Build:
DEFAULT BRANCH: main
Ran 25 Aug 2026 05:18PM UTC
Jobs 1
Files 92
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

25 Aug 2026 05:14PM UTC coverage: 92.463% (-1.5%) from 93.932%
32876748443

push

github

web-flow
fix(keymaster): Check the target of remote name lookups, on every path (#943)

* fix(keymaster): Check the target of remote name lookups, on every path

Remote name lookup fetches https://<domain>/.well-known/names from a
domain the caller supplies, so the target check is the only thing between
the API and the host's own network. There were two faults, and either one
alone leaves the door open.

The check ran on one path of three. isPrivateHostname was defined once
and called once, in resolveRemoteName, which is private. importAddress
and checkAddress are public, reachable over REST and as `import-address`
and `check-address` on the CLI, and neither consulted it. The guard now
lives in normalizeAddressDomain, which all three already funnel through,
so covering them is one check rather than three that can drift apart.

And the check read the start of the string rather than the address:

    /^(localhost|127\.|10\.|172\.(1[6-9]|2\d|3[01])\.|192\.168\.)/

169.254.169.254 -- the cloud metadata address, the first risk the issue
names -- walked straight past it, as did every IPv6 literal, and the
inet_aton spellings of loopback that the resolver honours but a
dotted-decimal reading does not see: 2130706433, 0177.0.0.1, 0x7f000001,
127.1. Replaced with real address parsing. It is written out by hand
because this package runs in browser wallets, where node:net does not
exist.

Redirects are re-checked rather than followed. fetch follows them by
default, so a public host answering 302 with a Location of
http://169.254.169.254/ reaches the address the check just rejected. Each
hop is now validated for scheme and target, the way the Lightning LUD-16
path already walks hops for the scheme alone.

The Python port had the same two surfaces and no check whatsoever, not
even the weak one, while httpx followed redirects. Fixed alongside, with
the cases kept in step: a hostname either port accepts is one both have
to account for. Only 100.64.0.0/10 needed stating expli... (continued)

3856 of 4438 branches covered (86.89%)

Branch coverage included in aggregate %.

8 of 122 new or added lines in 2 files covered. (6.56%)

8485 of 8909 relevant lines covered (95.24%)

686.61 hits per line

Uncovered Changes

Lines Coverage ∆ File
114
0.0
packages/common/src/net.ts
Jobs
ID Job ID Ran Files Coverage
1 32876748443.1 25 Aug 2026 05:18PM UTC 184
93.55
GitHub Action Run
Source Files on build 32876748443
  • Tree
  • List 92
  • Changed 77
  • Source Changed 1
  • Coverage Changed 77
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #32876748443
  • fba693bb on github
  • Prev Build on main (#32862541985)
  • Next Build on main (#32887966504)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc