Decision
Transport scope T2: retain and harden Cloudflare Quick as one explicit, temporary public-relay fallback when a user cannot use a private network.
Product boundary
- It is temporary Quick Tunnel access only; no account-managed/named Cloudflare surface.
- It must use the existing fragment-keyed app-layer E2E framing. Cloudflare may see traffic metadata but must not receive terminal bytes, typed input, approval payloads, or control contents in plaintext.
- It remains opt-in, never an automatic fallback from private transports.
Required evidence
- Verify pair, PTY, events, controls, and approval decisions are covered by the E2E path with no plaintext bypass.
- Fail closed if relay E2E bootstrap, verifier, or framing is unavailable.
- Keep a documented real-device/reconnect/restart smoke gate and reliable child-process cleanup.
- Give users concise, accurate disclosure of what relay metadata remains visible.
Acceptance criteria
- Public Cloudflare Quick behavior is bounded to this contract; no named-tunnel/account-management behavior leaks back in.
- Security, reconnection, cleanup, and real-device tests pass.
Decision
Transport scope T2: retain and harden Cloudflare Quick as one explicit, temporary public-relay fallback when a user cannot use a private network.
Product boundary
Required evidence
Acceptance criteria