fix(fips): P0 uptime fixes — open peer port 5679, allow /blob+/dwn, fix LAN anchor port, un-deaden direct peering, fast-fail budgets
Phase A1 of docs/FIPS-UPTIME-AND-UI-STATE-PLAN.md — the five changes that made FIPS fall back to Tor even when a FIPS path existed: - RC0: the fips.d drop-in now opens PEER_PORT 5679 (was 80+8443 only, so every hardened node firewalled peers' FIPS dials; 28k drops on .198) - RC4: /blob/ and /dwn/ added to the peer-path allowlist — mesh file sharing and DWN sync were 404 → 100% Tor by construction - RC2-G2: lan_fips_anchors dials PUBLISHED_UDP_PORT (2121) instead of the dead 8668, with a drift-guard test against the rendered daemon config - RC2-G1: direct LAN peering actually runs now — mDNS TXT advertises the FIPS npub, discovery calls set_fips_npub, and the anchor tick hydrates npubs from federation storage for peers on older builds - RC3: FIPS attempt budget is a hard cap (retry no longer doubles it) and the 12 hot call sites get explicit fips_timeout fast-fail so Tor keeps its full budget (browse-peer, preview, /blob, DWN, node-message, rotation notifies) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
94b5374f66
commit
eb2fc0f37b
@@ -24,17 +24,27 @@ pub struct LanTransport {
|
||||
our_did: String,
|
||||
our_pubkey_hex: String,
|
||||
our_port: u16,
|
||||
/// This node's FIPS npub, advertised in the mDNS TXT record so
|
||||
/// co-located peers can form a direct FIPS link (`lan_fips_anchors`)
|
||||
/// without waiting for federation storage to sync.
|
||||
our_fips_npub: Option<String>,
|
||||
daemon: Option<ServiceDaemon>,
|
||||
available: AtomicBool,
|
||||
}
|
||||
|
||||
impl LanTransport {
|
||||
/// Create a new LAN transport. Does not start discovery yet.
|
||||
pub fn new(our_did: &str, our_pubkey_hex: &str, port: u16) -> Self {
|
||||
pub fn new(
|
||||
our_did: &str,
|
||||
our_pubkey_hex: &str,
|
||||
port: u16,
|
||||
our_fips_npub: Option<String>,
|
||||
) -> Self {
|
||||
Self {
|
||||
our_did: our_did.to_string(),
|
||||
our_pubkey_hex: our_pubkey_hex.to_string(),
|
||||
our_port: port,
|
||||
our_fips_npub,
|
||||
daemon: None,
|
||||
available: AtomicBool::new(false),
|
||||
}
|
||||
@@ -47,11 +57,14 @@ impl LanTransport {
|
||||
|
||||
// Advertise our service
|
||||
let hostname = format!("archy-{}.local.", &self.our_pubkey_hex[..8]);
|
||||
let properties = vec![
|
||||
let mut properties = vec![
|
||||
("did".to_string(), self.our_did.clone()),
|
||||
("pubkey".to_string(), self.our_pubkey_hex.clone()),
|
||||
("version".to_string(), "0.1.0".to_string()),
|
||||
];
|
||||
if let Some(npub) = &self.our_fips_npub {
|
||||
properties.push(("fips".to_string(), npub.clone()));
|
||||
}
|
||||
|
||||
let service_info = ServiceInfo::new(
|
||||
SERVICE_TYPE,
|
||||
@@ -93,6 +106,11 @@ impl LanTransport {
|
||||
.map(|v| v.val_str().to_string());
|
||||
let addresses = info.get_addresses();
|
||||
|
||||
let fips_npub = info
|
||||
.get_properties()
|
||||
.get("fips")
|
||||
.map(|v| v.val_str().to_string());
|
||||
|
||||
if let (Some(did), Some(pubkey)) = (did, pubkey) {
|
||||
if let Some(scoped_ip) = addresses.iter().next() {
|
||||
let ip: std::net::IpAddr = match scoped_ip.to_string().parse() {
|
||||
@@ -106,6 +124,9 @@ impl LanTransport {
|
||||
.await;
|
||||
registry_clone.set_lan_address(&did, socket_addr).await;
|
||||
registry_clone.set_name(&did, info.get_fullname()).await;
|
||||
if let Some(npub) = fips_npub.as_deref() {
|
||||
registry_clone.set_fips_npub(&did, npub).await;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -106,7 +106,7 @@ pub enum PeerSource {
|
||||
}
|
||||
|
||||
/// Unified peer record with per-transport capabilities.
|
||||
#[derive(Debug, Clone, Serialize, Deserialize)]
|
||||
#[derive(Debug, Clone, Default, Serialize, Deserialize)]
|
||||
pub struct PeerRecord {
|
||||
pub did: String,
|
||||
pub pubkey_hex: String,
|
||||
|
||||
Reference in New Issue
Block a user