diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-09-13 22:14:47 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-09-13 22:14:47 +0200 |
| commit | 413837a0845240241ed7e9d9ac1f3b1dc45a2f40 (patch) | |
| tree | 842eb464b141be64a0576564b8cfe64e8090761c /docs | |
| parent | 532d762678e0eda7ac08fcc6a361069114f12d79 (diff) | |
| download | meshbay-413837a0845240241ed7e9d9ac1f3b1dc45a2f40.tar.gz | |
fix(hub): federation is closed until two hubs have run it
Every MHP route answers a stated 503. `federation.FEDERATION_ENABLED` is the
only thing that decides it, applied as a dependency on the router so the six
routes that exist and any added later are covered by construction — a gate you
have to remember to write in each handler is the shape C6 is the standing
lesson about.
The protocol is not what is wrong with it. What is wrong is that nothing has
ever run it: two hubs have never completed one authenticated request between
them. AV14 was two defects in the same path — an issuer signing with a key
bound before it was loaded, naming itself after the reference deployment
whatever the instance was called, and a verifier naming no audience for the
`aud` the issuer sets, which PyJWT refuses outright. Both stood for a month
behind a green suite, and both were found by reading rather than by running,
because a second implementation of a peer proves the protocol and nothing about
two machines.
Four of the six routes carry no authentication of their own — the MHP token is
the authentication — and two of those write, a directory push and a revocation.
That is the surface being closed until somebody stands up a second hub.
A constant and not a `hub_settings` row, deliberately: a switch in the admin
panel invites an operator to turn on a feature that has never worked between
two machines, where this takes an edit, a deploy, and reading the comment above
it. `/v1/hub/info` reports the state, because the `mhp_version` beside it would
otherwise be a claim the hub does not honour.
The protocol tests open the gate for their own duration and say why; the one
that runs with the flag as it ships asserts all six routes refuse. §7.6 states
the closure, §15.2 carries federation between two hubs as not built.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UMxEQadpzPkYLFf5CYKhpW
Diffstat (limited to 'docs')
| -rw-r--r-- | docs/MESHBAY_DESIGN.md | 25 |
1 files changed, 24 insertions, 1 deletions
diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md index 32d688b..a511093 100644 --- a/docs/MESHBAY_DESIGN.md +++ b/docs/MESHBAY_DESIGN.md @@ -1687,7 +1687,29 @@ operationally. ### 7.6 Federation (MHP) -Peer hubs exchange directory rows and revocations. The trust rules: +> **Federation is closed in the code, and every MHP route refuses with a stated +> 503.** `federation.FEDERATION_ENABLED` is the only thing that decides it — a +> constant rather than a setting, because a switch in an admin panel invites an +> operator to turn on something that has never worked between two machines. +> `/v1/hub/info` reports it, since the `mhp_version` beside it would otherwise +> be a claim this hub does not honour. +> +> The reason is not the design below. It is that **nothing has ever run it**: +> two hubs have never completed one authenticated request between them +> (**AV14** — the issuer signed with a key bound before it was loaded and named +> itself after the reference deployment whatever it was called, and the verifier +> named no audience for the `aud` the issuer sets). Both were found by reading, +> and both stood for a month behind a green suite, because a second +> implementation of a peer proves the protocol and nothing about two machines — +> the sentence §12 already writes about a second implementation of the client. +> It re-opens when a second hub has been stood up and the exchange run both +> ways. +> +> What the closure does not touch: the public directory still reads whatever +> `federated_groups` holds, which is nothing, because nothing can arrive. + +Peer hubs exchange directory rows and revocations. The trust rules, which hold +when it re-opens: - a pushed row's **source is bound to the signer**, not taken from the payload; - the **token audience is checked**; @@ -2758,6 +2780,7 @@ account recovery, and the Windows port through packaging. | — | Tier 3 roster attestation (§3.3) | | — | Playlists (§9.10) | | — | Android client | +| — | **Federation between two hubs.** The protocol is written and switched off in the code (§7.6); what is not built is one run between two machines | ### 15.3 Open, and why each is where it is |