Skip to content

Let loopback-lint see a positional bind whose port is a call - #875

Merged
nedtwigg merged 1 commit into
mainfrom
fix/loopback-lint-call-port
Oct 1, 2026
Merged

nedtwigg merged 1 commit into
mainfrom
fix/loopback-lint-call-port

Conversation

@dormouse-bot

Copy link
Copy Markdown
Collaborator

scripts/loopback-lint.mjs missed the loopback bind in hosted/server/dev.ts:45, server.listen(Number(process.env.PORT || 0), "127.0.0.1"). The node positional form scanned the port argument with [^,)]+, which stops at the inner ) of Number(...), so the file never appeared in the lint's output. That contradicts security-local.md -> "Loopback Listeners", which says the lint prints every bind and fails an unguarded new one. The nightly audit flagged it in #873. The listener itself is guarded (allowedDevRequest from hosted/server/dev-host-guard.ts), so this was lint drift, not exposure.

The port may now contain one level of parenthesised call, (?:[^,()]|\([^()]*\))+, and the header's list of limits says so. A new loopback-lint-selftest.mjs fixture appends exactly that shape. It went red before the regex change and passes after. The lint now lists hosted/server/dev.ts:45 among non-test listeners and stays green because the file imports its guard.

This settles one of the three FAILs in #873; #874 takes the Local networks candidate filter, and the installers' ts ip -4 | head -1 remains.

Refs #873 — automated triage

The node positional form scanned the port with [^,)]+, which stopped at
the inner ) of Number(process.env.PORT || 0), so hosted/server/dev.ts's
loopback bind went unlisted. The port may now wrap one call, and a
selftest fixture pins that shape.

Refs #873
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Deploying mouseterm with  Cloudflare Pages  Cloudflare Pages

Latest commit: feb1300
Status: ✅  Deploy successful!
Preview URL: https://d5bd2948.mouseterm.pages.dev
Branch Preview URL: https://fix-loopback-lint-call-port.mouseterm.pages.dev

View logs

@nedtwigg nedtwigg left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the bounded positional-port matcher and its regression fixture. This closes the missed Number(...) bind without changing listener policy; CI and bot self-review passed.

@nedtwigg
nedtwigg merged commit be3056c into main Oct 1, 2026
11 checks passed

This branch is waiting to be deployed

1 waiting deployment
hosted-preview — feb13001 Waiting Oct 1, 2026 by nedtwigg via cleanup #643
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants