feat: harden the RNS carrier: idle-link reaper, refusal logging, patched microReticulum fork

This commit is contained in:
randogoth 2026-09-29 10:27:44 +03:00
parent 07f064460f
commit 8ea6865e7e
6 changed files with 110 additions and 16 deletions

6
RNS.md
View file

@ -126,6 +126,7 @@ One process serves both carriers: shared `Store`, shared config, one systemd uni
| `--rns-max-links` | 100 | concurrent links — refused past the cap |
| `--rns-rate-link-requests` | 60 | per link per minute |
| `--rns-rate-link-bytes` | 1048576 | per link per minute, via `ByteRateLimiter` |
| `--rns-link-idle` | 300 | seconds of silence before a link is reaped; 0 disables the reaper |
| `--rns-udp` | `127.0.0.1:4242` | UDP interface to listen on, host[:port] |
| `--rns-udp-forward` | unset | optional forward target; without it the interface replies to the last datagram's source |
@ -144,8 +145,9 @@ The per-link request limiter reuses `RateLimiter` keyed by the link hex. The per
## 9. Remaining open items
1. Cross-transport envelope size: per-transport caps are enforced; a 768 KiB TCP envelope is still delivered whole to an RNS FETCH. Operators should apply the smaller cap mailbox-wide when in doubt (upstream spec 13.7).
2. Interfaces beyond UDP (RNS-compatible TCP hub/client, I2P): microReticulum ships none; the UDP interface is the first supported one.
3. The reference `test_interop/run_request_response.sh` harness was not rerun against the shim; its PlatformIO build step is unavailable here. The equivalent interop was exercised directly against `smolmail_rns.py` (§10.6).
2. Upstream `microReticulum` deadlock: a client dying mid-resource-transfer wedges the single transport loop forever — `Resource::request_next` sends its `RESOURCE_REQ` through `Transport::outbound` from inside the `jobs()` resource tick, and `outbound` busy-waits on `_jobs_running`, a flag `jobs()` itself holds. No announces, no new links, mesh dead until restart. The vendored source is a local fork carrying the fix (same-thread reentrant calls skip the cycle wait); the equivalent report is filed upstream.
3. Interfaces beyond UDP (RNS-compatible TCP hub/client, I2P): microReticulum ships none; the UDP interface is the first supported one.
4. The reference `test_interop/run_request_response.sh` harness was not rerun against the shim; its PlatformIO build step is unavailable here. The equivalent interop was exercised directly against `smolmail_rns.py` (§10.6).
Formerly open items resolved during implementation: raw identity bytes exist (`load_private_key`); the shim ABI and run-loop drive pattern are §7.1/§7.2; `ALLOW_ALL` matches the reference; announcing at startup + every 2 h, unconditional even when invite-only (the invite gates REGISTER, not the link); the interface question is §7.4.