Skip to content

Fix household authentication on resume and VPN tracker advertisement - #180

Merged
JustVugg merged 1 commit into
mainfrom
fix/household-auth-advertise
Sep 14, 2026
Merged

JustVugg merged 1 commit into
mainfrom
fix/household-auth-advertise

Conversation

@JustVugg

Copy link
Copy Markdown
Owner

Fixes #178 and fixes #179.

Restore the saved household key before reopening the donor TUI, so a restarted donor does not depend on shell credentials. Preserve the existing single AUTH exchange; the duplicate AUTH block described in #178 is not present in either main 231f83f or the cited 9434b77 commit. Regression tests now exercise a complete encrypted AUTH/OFFER exchange, reject wrong/missing/duplicate AUTH, and check saved-key activation.

Honor the existing LUMABRI_ADVERTISE IPv4 override when creating/resuming the household tracker. Persist that endpoint, reject malformed overrides without silently switching interfaces, keep exact household admission and peer identity checks, and return an actionable tracker-mismatch rejection. README documents the advanced override and restart requirement.

Validation passed locally: strict-warning TUI build; encrypted monitor/auth/admission tests; network/address validation; real tracker PTY create/attach/restart/discovery/join; complete resident household flow with two executing donors and one donor started without LUMABRI_TOKEN in its environment, followed by a source-offline second chat with no weight mirror writes. Added encrypted admission coverage to native macOS CI. Physical Tailscale reproduction by the reporter remains to be confirmed; no native macOS or Windows claim from the local Linux run.

@JustVugg
JustVugg merged commit bdfa7cc into main Sep 14, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant