Files
orca/src
Neil 147792d9e8 fix(relay): apply the host LAN pairing mode to already-paired devices
settings.mobilePairingConnectionMode was only consulted when minting the next
QR. The live question — may this desktop serve mobile over Relay right now —
had no implementation, so a device paired as `automatic` kept the desktop on
Relay forever after the user picked LAN (#18211).

- src/shared/mobile-relay-policy.ts: isMobileRelayAllowed composes the host
  setting with the per-device pair-time mode, restrictive-only.
- RelayDemandLedger consults the policy for standing bindings and for in-flight
  transient refs (now keyed with a device id) so in-flight work cannot outvote
  the policy.
- DesktopRelayService gates every grant path at withTransientDemand, which is
  what finally covers createPairingRelay; the host mode is pulled through an
  optional callback so existing prototype-built tests keep working.
- RelayAuthCoordinator.reconcile({ skipLinger }) closes the broker promptly on
  a deliberate policy change; pairing churn keeps its ten-minute linger.
- desktop-relay-startup.ts wires the settings read and the settings-changed
  wake signal; the launch file shrinks below the line budget.
- The Relay-mint-failure "Use LAN" recovery buttons no longer persist the host
  policy, since revoking Relay from every paired phone is not what they promise.

Closes #18211
2026-09-11 01:08:02 -07:00
..