summaryrefslogtreecommitdiffstats
path: root/docs/MESHBAY_DESIGN.md
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-13 22:14:47 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-13 22:14:47 +0200
commit413837a0845240241ed7e9d9ac1f3b1dc45a2f40 (patch)
tree842eb464b141be64a0576564b8cfe64e8090761c /docs/MESHBAY_DESIGN.md
parent532d762678e0eda7ac08fcc6a361069114f12d79 (diff)
downloadmeshbay-413837a0845240241ed7e9d9ac1f3b1dc45a2f40.tar.gz
fix(hub): federation is closed until two hubs have run it
Every MHP route answers a stated 503. `federation.FEDERATION_ENABLED` is the only thing that decides it, applied as a dependency on the router so the six routes that exist and any added later are covered by construction — a gate you have to remember to write in each handler is the shape C6 is the standing lesson about. The protocol is not what is wrong with it. What is wrong is that nothing has ever run it: two hubs have never completed one authenticated request between them. AV14 was two defects in the same path — an issuer signing with a key bound before it was loaded, naming itself after the reference deployment whatever the instance was called, and a verifier naming no audience for the `aud` the issuer sets, which PyJWT refuses outright. Both stood for a month behind a green suite, and both were found by reading rather than by running, because a second implementation of a peer proves the protocol and nothing about two machines. Four of the six routes carry no authentication of their own — the MHP token is the authentication — and two of those write, a directory push and a revocation. That is the surface being closed until somebody stands up a second hub. A constant and not a `hub_settings` row, deliberately: a switch in the admin panel invites an operator to turn on a feature that has never worked between two machines, where this takes an edit, a deploy, and reading the comment above it. `/v1/hub/info` reports the state, because the `mhp_version` beside it would otherwise be a claim the hub does not honour. The protocol tests open the gate for their own duration and say why; the one that runs with the flag as it ships asserts all six routes refuse. §7.6 states the closure, §15.2 carries federation between two hubs as not built. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UMxEQadpzPkYLFf5CYKhpW
Diffstat (limited to 'docs/MESHBAY_DESIGN.md')
-rw-r--r--docs/MESHBAY_DESIGN.md25
1 files changed, 24 insertions, 1 deletions
diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md
index 32d688b..a511093 100644
--- a/docs/MESHBAY_DESIGN.md
+++ b/docs/MESHBAY_DESIGN.md
@@ -1687,7 +1687,29 @@ operationally.
### 7.6 Federation (MHP)
-Peer hubs exchange directory rows and revocations. The trust rules:
+> **Federation is closed in the code, and every MHP route refuses with a stated
+> 503.** `federation.FEDERATION_ENABLED` is the only thing that decides it — a
+> constant rather than a setting, because a switch in an admin panel invites an
+> operator to turn on something that has never worked between two machines.
+> `/v1/hub/info` reports it, since the `mhp_version` beside it would otherwise
+> be a claim this hub does not honour.
+>
+> The reason is not the design below. It is that **nothing has ever run it**:
+> two hubs have never completed one authenticated request between them
+> (**AV14** — the issuer signed with a key bound before it was loaded and named
+> itself after the reference deployment whatever it was called, and the verifier
+> named no audience for the `aud` the issuer sets). Both were found by reading,
+> and both stood for a month behind a green suite, because a second
+> implementation of a peer proves the protocol and nothing about two machines —
+> the sentence §12 already writes about a second implementation of the client.
+> It re-opens when a second hub has been stood up and the exchange run both
+> ways.
+>
+> What the closure does not touch: the public directory still reads whatever
+> `federated_groups` holds, which is nothing, because nothing can arrive.
+
+Peer hubs exchange directory rows and revocations. The trust rules, which hold
+when it re-opens:
- a pushed row's **source is bound to the signer**, not taken from the payload;
- the **token audience is checked**;
@@ -2758,6 +2780,7 @@ account recovery, and the Windows port through packaging.
| — | Tier 3 roster attestation (§3.3) |
| — | Playlists (§9.10) |
| — | Android client |
+| — | **Federation between two hubs.** The protocol is written and switched off in the code (§7.6); what is not built is one run between two machines |
### 15.3 Open, and why each is where it is