Files
buzz/crates
npub1qyvc0c5kl4gqv2fd97fsk46tu378sqgy35vc83rvgfwne90sel7s0ed67dandTyler Longwell 785653dae1 Fix startup-wiring review blockers; add inbound profile dispatcher
Wren's review of 8b077fdb raised two correctness blockers, both fixed:

1. BUZZ_MESH now defaults OFF. Mesh forms only on explicit
   BUZZ_MESH=on|true|1 — an image upgrade with untouched env binds no
   UDP port and writes no Redis key (strict rollout no-regression).
   Pinned by mesh_defaults_off_when_env_absent.

2. Ready-record acceptance is anchored to the deployment's relay
   identity: MeshMembership::with_expected_relay_pubkey (set from the
   relay signing key in boot_mesh) rejects seeds attested by any other
   key — possession of some relay key is not authorization. Unanchored
   membership is fail-closed (admits nothing). Rejections are counted
   as foreign_relay_rejections in /_mesh.

Plus the single-slot inbound dispatcher (thread-agreed contract):
MeshInboundDispatcher in mesh_boot.rs implements InboundHandler,
installed once by boot_mesh; consumers register per-profile
entrypoints via MeshHandle.dispatcher (register_huddle_control /
register_reliable_stream / register_datagrams, first-registration
wins). HuddleControl/ReliableStream streams fan out by hello profile;
RealtimeMedia as a stream is rejected (datagram-only); traffic before
registration is logged and dropped (bounded boot-window race, fencing
makes retry safe). MeshStream::new and BoxFuture are now public so
consumer crates can stub streams/transports in tests.

cargo test -p buzz-relay-mesh: 32 passed; -p buzz-relay: 494 passed,
2 ignored; clippy both packages clean; fmt clean.

Co-authored-by: Tyler Longwell <tlongwell@block.xyz>
Signed-off-by: Tyler Longwell <tlongwell@block.xyz>
2026-07-08 13:06:49 -04:00
..