fix(mesh): RuntimeId = boot-unique mesh endpoint key, not the relay signing key

Wren's contract-review blocker: the chart shares one BUZZ_RELAY_PRIVATE_KEY
Secret across all pods of a release, and that key is secp256k1 while iroh
endpoint ids are ed25519 — so 'runtime id = relay signing pubkey' would give
every pod the same runtime id (registry/lease collapse) and doesn't even
type-check against iroh. RuntimeId is now the ed25519 pubkey of a mesh
keypair generated fresh at process start: boot-unique by construction, and
identical to the iroh endpoint id so transport auth and ownership identity
stay one value. Deployment-identity binding moves out-of-band: the ready
registry record carries a relay-key-signed attestation of the runtime pubkey
(membership lane); peers accept connections only from attested endpoint ids.

Doc-only change; no wire shape or test change.

Co-authored-by: Tyler Longwell <tlongwell@block.xyz>
Signed-off-by: Tyler Longwell <tlongwell@block.xyz>
This commit is contained in:
npub1qyvc0c5kl4gqv2fd97fsk46tu378sqgy35vc83rvgfwne90sel7s0ed67d
2026-07-08 10:18:14 -04:00
co-authored by Tyler Longwell
parent f29fd321f0
commit 93bec73809
2 changed files with 15 additions and 4 deletions
+2 -1
View File
@@ -1,6 +1,7 @@
//! buzz-relay-mesh — the inter-relay QUIC mesh.
//!
//! One iroh endpoint per relay runtime (identity = the relay's signing key),
//! One iroh endpoint per relay runtime (identity = a boot-unique mesh
//! keypair, attested by the relay's signing key — see [`wire::RuntimeId`]),
//! a warm full mesh of authenticated connections, scuttlebutt membership
//! gossip on a control substream, and a fenced wire contract that carries
//! tunnel traffic (reliable streams + realtime datagrams) between pods.
+13 -3
View File
@@ -45,9 +45,19 @@ pub const WIRE_VERSION: u8 = 1;
/// larger is a protocol error, not a bigger buffer.
pub const MAX_STREAM_FRAME: u32 = 16 * 1024 * 1024;
/// A relay runtime's mesh identity: the ed25519 public key of its signing
/// key, which is also its iroh endpoint id. Mesh authentication IS relay
/// identity — there is no separate credential.
/// A relay runtime's mesh identity: the ed25519 public key of the **mesh
/// endpoint keypair generated fresh at process start**. This is both the
/// iroh endpoint id and the boot-unique runtime id used in the ready
/// registry and ownership leases — one value, boot-unique by construction.
///
/// It is deliberately NOT the deployment's Nostr relay key: that key is
/// secp256k1, and the helm chart shares one `BUZZ_RELAY_PRIVATE_KEY` Secret
/// across all pods of a release — using it here would give every pod the
/// same runtime id and collapse the ownership plane (Wren's contract-review
/// blocker). Binding to the deployment identity is done out-of-band: the
/// ready-registry record carries a relay-key-signed attestation of the
/// runtime pubkey (membership lane), and peers accept mesh connections only
/// from endpoint ids present in attested registry/gossip records.
#[derive(Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize)]
pub struct RuntimeId(pub [u8; 32]);