From 93bec73809881e49cf57b821f7ffbd0f6eeb92cd Mon Sep 17 00:00:00 2001 From: npub1qyvc0c5kl4gqv2fd97fsk46tu378sqgy35vc83rvgfwne90sel7s0ed67d <011987e296fd5006292d2f930b574be47c7801048d1983c46c425d3c95f0cffd@sprout-oss.stage.blox.sqprod.co> Date: Wed, 8 Jul 2026 10:18:14 -0400 Subject: [PATCH] fix(mesh): RuntimeId = boot-unique mesh endpoint key, not the relay signing key MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Wren's contract-review blocker: the chart shares one BUZZ_RELAY_PRIVATE_KEY Secret across all pods of a release, and that key is secp256k1 while iroh endpoint ids are ed25519 — so 'runtime id = relay signing pubkey' would give every pod the same runtime id (registry/lease collapse) and doesn't even type-check against iroh. RuntimeId is now the ed25519 pubkey of a mesh keypair generated fresh at process start: boot-unique by construction, and identical to the iroh endpoint id so transport auth and ownership identity stay one value. Deployment-identity binding moves out-of-band: the ready registry record carries a relay-key-signed attestation of the runtime pubkey (membership lane); peers accept connections only from attested endpoint ids. Doc-only change; no wire shape or test change. Co-authored-by: Tyler Longwell Signed-off-by: Tyler Longwell --- crates/buzz-relay-mesh/src/lib.rs | 3 ++- crates/buzz-relay-mesh/src/wire.rs | 16 +++++++++++++--- 2 files changed, 15 insertions(+), 4 deletions(-) diff --git a/crates/buzz-relay-mesh/src/lib.rs b/crates/buzz-relay-mesh/src/lib.rs index cbe922c32..f1c1beadb 100644 --- a/crates/buzz-relay-mesh/src/lib.rs +++ b/crates/buzz-relay-mesh/src/lib.rs @@ -1,6 +1,7 @@ //! buzz-relay-mesh — the inter-relay QUIC mesh. //! -//! One iroh endpoint per relay runtime (identity = the relay's signing key), +//! One iroh endpoint per relay runtime (identity = a boot-unique mesh +//! keypair, attested by the relay's signing key — see [`wire::RuntimeId`]), //! a warm full mesh of authenticated connections, scuttlebutt membership //! gossip on a control substream, and a fenced wire contract that carries //! tunnel traffic (reliable streams + realtime datagrams) between pods. diff --git a/crates/buzz-relay-mesh/src/wire.rs b/crates/buzz-relay-mesh/src/wire.rs index 1cf0f3af0..73c8b5692 100644 --- a/crates/buzz-relay-mesh/src/wire.rs +++ b/crates/buzz-relay-mesh/src/wire.rs @@ -45,9 +45,19 @@ pub const WIRE_VERSION: u8 = 1; /// larger is a protocol error, not a bigger buffer. pub const MAX_STREAM_FRAME: u32 = 16 * 1024 * 1024; -/// A relay runtime's mesh identity: the ed25519 public key of its signing -/// key, which is also its iroh endpoint id. Mesh authentication IS relay -/// identity — there is no separate credential. +/// A relay runtime's mesh identity: the ed25519 public key of the **mesh +/// endpoint keypair generated fresh at process start**. This is both the +/// iroh endpoint id and the boot-unique runtime id used in the ready +/// registry and ownership leases — one value, boot-unique by construction. +/// +/// It is deliberately NOT the deployment's Nostr relay key: that key is +/// secp256k1, and the helm chart shares one `BUZZ_RELAY_PRIVATE_KEY` Secret +/// across all pods of a release — using it here would give every pod the +/// same runtime id and collapse the ownership plane (Wren's contract-review +/// blocker). Binding to the deployment identity is done out-of-band: the +/// ready-registry record carries a relay-key-signed attestation of the +/// runtime pubkey (membership lane), and peers accept mesh connections only +/// from endpoint ids present in attested registry/gossip records. #[derive(Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize)] pub struct RuntimeId(pub [u8; 32]);