From d8c7089963647acdf8c9a18f861eacd15970ebb3 Mon Sep 17 00:00:00 2001 From: roboomp Date: Tue, 4 Aug 2026 15:38:37 +0000 Subject: [PATCH] test(stats): probed loopback bind over direct tcp Replaced the 127.0.0.2 fetch, which a configured HTTP proxy could intercept, with a direct Bun.connect TCP probe so the loopback-only bind is asserted against the real listener. Fixes #7633 --- .../stats/test/server-port-conflict.test.ts | 26 ++++++++++++++----- 1 file changed, 20 insertions(+), 6 deletions(-) diff --git a/packages/stats/test/server-port-conflict.test.ts b/packages/stats/test/server-port-conflict.test.ts index fc8447dfa..5db2e4ca9 100644 --- a/packages/stats/test/server-port-conflict.test.ts +++ b/packages/stats/test/server-port-conflict.test.ts @@ -1,8 +1,23 @@ import { afterEach, describe, expect, it } from "bun:test"; -import type { Subprocess } from "bun"; +import { connect, type Subprocess } from "bun"; import { STATS_DASHBOARD_HEADER, STATS_DASHBOARD_HOSTNAME } from "../src/port-conflict"; import { startServer } from "../src/server"; +/** + * Directly probe a TCP endpoint, bypassing any configured HTTP proxy so the + * loopback-only bind is asserted against the real listener rather than a proxy + * response. Resolves true when the connection is accepted, false when refused. + */ +async function tcpConnects(hostname: string, port: number): Promise { + try { + const socket = await connect({ hostname, port, socket: { data() {}, open() {}, close() {}, error() {} } }); + socket.end(); + return true; + } catch { + return false; + } +} + const holderProcesses: Array> = []; async function startBunHolder(responseExpr: string, options?: { statsOwned?: boolean }) { @@ -58,11 +73,10 @@ describe("startServer access", () => { expect(response.headers.get("Access-Control-Allow-Origin")).toBeNull(); await response.body?.cancel(); - await expect( - fetch(`http://127.0.0.2:${server.port}/api/stats/models`, { - signal: AbortSignal.timeout(1_000), - }), - ).rejects.toThrow(); + // 127.0.0.2 also routes to the loopback interface, but the server bound + // only 127.0.0.1, so a direct connection there must be refused. + expect(await tcpConnects(server.hostname, server.port)).toBe(true); + expect(await tcpConnects("127.0.0.2", server.port)).toBe(false); } finally { server.stop(); }