mirror of
https://github.com/block/buzz.git
synced 2026-08-18 06:50:31 +02:00
fix(mesh): RuntimeId = boot-unique mesh endpoint key, not the relay signing key
Wren's contract-review blocker: the chart shares one BUZZ_RELAY_PRIVATE_KEY Secret across all pods of a release, and that key is secp256k1 while iroh endpoint ids are ed25519 — so 'runtime id = relay signing pubkey' would give every pod the same runtime id (registry/lease collapse) and doesn't even type-check against iroh. RuntimeId is now the ed25519 pubkey of a mesh keypair generated fresh at process start: boot-unique by construction, and identical to the iroh endpoint id so transport auth and ownership identity stay one value. Deployment-identity binding moves out-of-band: the ready registry record carries a relay-key-signed attestation of the runtime pubkey (membership lane); peers accept connections only from attested endpoint ids. Doc-only change; no wire shape or test change. Co-authored-by: Tyler Longwell <tlongwell@block.xyz> Signed-off-by: Tyler Longwell <tlongwell@block.xyz>
This commit is contained in:
co-authored by
Tyler Longwell
parent
f29fd321f0
commit
93bec73809
@@ -1,6 +1,7 @@
|
||||
//! buzz-relay-mesh — the inter-relay QUIC mesh.
|
||||
//!
|
||||
//! One iroh endpoint per relay runtime (identity = the relay's signing key),
|
||||
//! One iroh endpoint per relay runtime (identity = a boot-unique mesh
|
||||
//! keypair, attested by the relay's signing key — see [`wire::RuntimeId`]),
|
||||
//! a warm full mesh of authenticated connections, scuttlebutt membership
|
||||
//! gossip on a control substream, and a fenced wire contract that carries
|
||||
//! tunnel traffic (reliable streams + realtime datagrams) between pods.
|
||||
|
||||
@@ -45,9 +45,19 @@ pub const WIRE_VERSION: u8 = 1;
|
||||
/// larger is a protocol error, not a bigger buffer.
|
||||
pub const MAX_STREAM_FRAME: u32 = 16 * 1024 * 1024;
|
||||
|
||||
/// A relay runtime's mesh identity: the ed25519 public key of its signing
|
||||
/// key, which is also its iroh endpoint id. Mesh authentication IS relay
|
||||
/// identity — there is no separate credential.
|
||||
/// A relay runtime's mesh identity: the ed25519 public key of the **mesh
|
||||
/// endpoint keypair generated fresh at process start**. This is both the
|
||||
/// iroh endpoint id and the boot-unique runtime id used in the ready
|
||||
/// registry and ownership leases — one value, boot-unique by construction.
|
||||
///
|
||||
/// It is deliberately NOT the deployment's Nostr relay key: that key is
|
||||
/// secp256k1, and the helm chart shares one `BUZZ_RELAY_PRIVATE_KEY` Secret
|
||||
/// across all pods of a release — using it here would give every pod the
|
||||
/// same runtime id and collapse the ownership plane (Wren's contract-review
|
||||
/// blocker). Binding to the deployment identity is done out-of-band: the
|
||||
/// ready-registry record carries a relay-key-signed attestation of the
|
||||
/// runtime pubkey (membership lane), and peers accept mesh connections only
|
||||
/// from endpoint ids present in attested registry/gossip records.
|
||||
#[derive(Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize)]
|
||||
pub struct RuntimeId(pub [u8; 32]);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user