test(stats): probed loopback bind over direct tcp

Replaced the 127.0.0.2 fetch, which a configured HTTP proxy could intercept, with a direct Bun.connect TCP probe so the loopback-only bind is asserted against the real listener.

Fixes #7633
This commit is contained in:
roboomp
2026-08-04 15:38:37 +00:00
parent 951051086d
commit d8c7089963
@@ -1,8 +1,23 @@
import { afterEach, describe, expect, it } from "bun:test";
import type { Subprocess } from "bun";
import { connect, type Subprocess } from "bun";
import { STATS_DASHBOARD_HEADER, STATS_DASHBOARD_HOSTNAME } from "../src/port-conflict";
import { startServer } from "../src/server";
/**
* Directly probe a TCP endpoint, bypassing any configured HTTP proxy so the
* loopback-only bind is asserted against the real listener rather than a proxy
* response. Resolves true when the connection is accepted, false when refused.
*/
async function tcpConnects(hostname: string, port: number): Promise<boolean> {
try {
const socket = await connect({ hostname, port, socket: { data() {}, open() {}, close() {}, error() {} } });
socket.end();
return true;
} catch {
return false;
}
}
const holderProcesses: Array<Subprocess<"ignore", "pipe", "pipe">> = [];
async function startBunHolder(responseExpr: string, options?: { statsOwned?: boolean }) {
@@ -58,11 +73,10 @@ describe("startServer access", () => {
expect(response.headers.get("Access-Control-Allow-Origin")).toBeNull();
await response.body?.cancel();
await expect(
fetch(`http://127.0.0.2:${server.port}/api/stats/models`, {
signal: AbortSignal.timeout(1_000),
}),
).rejects.toThrow();
// 127.0.0.2 also routes to the loopback interface, but the server bound
// only 127.0.0.1, so a direct connection there must be refused.
expect(await tcpConnects(server.hostname, server.port)).toBe(true);
expect(await tcpConnects("127.0.0.2", server.port)).toBe(false);
} finally {
server.stop();
}