diff --git a/docs/indeehub-distribution-current-design.md b/docs/indeehub-distribution-current-design.md new file mode 100644 index 00000000..39cb6d33 --- /dev/null +++ b/docs/indeehub-distribution-current-design.md @@ -0,0 +1,73 @@ +# IndeeHub distribution: current implementation design + +Status: design for the post-1.9 follow-up, not implemented/accepted. Earlier +swarm plans describe historical experiments and must not be read as live proof. + +## Standards checked on 2026-10-05 + +- Nostr [NIP-71](https://github.com/nostr-protocol/nips/blob/master/71.md) + defines video metadata, including addressable normal-video kind34235. Use a + stable producer/project identifier for revisions. This does not define paid + viewing rights. Hash/media metadata follows + [NIP-94](https://github.com/nostr-protocol/nips/blob/master/94.md). +- [NIP-98](https://github.com/nostr-protocol/nips/blob/master/98.md) authenticates + HTTP requests; it is not proof of payment or permission to another creator's + project. Keep the existing verified app session and project ownership checks. +- [Cashu NUT-18](https://github.com/cashubtc/nuts/blob/main/18.md) supplies payment + request negotiation. [NUT-04](https://github.com/cashubtc/nuts/blob/main/04.md) + covers mint quotes/issuance; method-specific current specifications and older + deployed mint responses must both be capability-tested. Keep quote identifiers + private to the receiving wallet. Payment settlement must be correlated to the + purchase, never inferred from a change in wallet balance. +- [NUT-19](https://github.com/cashubtc/nuts/blob/main/19.md) provides mint-side + cached responses where supported. It supplements a durable local payment + journal; it does not replace one or make an arbitrary retry safe. +- [LNURL-pay](https://github.com/lnurl/luds/blob/luds/06.md) supports an invoice + handoff. A Lightning address by itself is not a signed settlement receipt. + +## Required implementation contract + +1. Backstage publishes only the selected, owned project. Announcements contain + public metadata, producer identity, node identity, content hashes, current + price/window and accepted-method capabilities. Never publish Cloud paths, + mint quotes, tokens, paid media keys or private management addresses. +2. Each instance's Archipelago source verifies signatures, identity bindings and + monotonic event revisions. Persist discovery so a relay outage does not empty + an existing library. Keep other sources and the current default intact. +3. A purchase binds buyer identity, publisher, project revision, amount, currency, + selected payment method and an unpredictable idempotency identifier. Persist + the quote before requesting payment. Snapshot the offer so later edits cannot + silently change the purchased terms. +4. Reuse file-payment capability negotiation and proven settlement primitives. + Existing file Lightning invoices currently require LND; therefore adding + first-use Lightning-to-Cashu receiving is real work, not a display label. The + receiver must verify a correlated invoice/mint receipt and recover issuance + after a lost response before granting access. Its provisioned ecash address + must map to the actual receiving wallet. No new real payment is authorized by + this design; use isolated fixtures until a bounded payment is approved. +5. A paid purchase creates one durable entitlement. Default demo window proposal: + start at the first successfully authorized media response; persist start and + expiry atomically. Retries, seek and reconnect reuse it without another + payment. Check the entitlement for every media/range/key request. Clock + rollback must not extend an already-started window. +6. Browser/companion playback remains ordinary authenticated local HTTP. Actual + inter-node media bytes use FIPS, with a bound node identity and authenticated + purchase capability. No silent Tor/LAN/iroh fallback for required FIPS media. + Show a recoverable unavailable route without requesting another payment. +7. Range/segment serving streams bounded buffers with backpressure and cancel + propagation. Do not read an entire paid film into a Vec before serving it. + Verify length/hash/revision, reject malformed ranges and path escapes, and + keep cache access subject to the same entitlement. Delivered plaintext cannot + be made impossible to copy; expiry controls subsequent authorized delivery. + +## Qualification that remains required + +Publisher/receiver integration must cover altered metadata, forged identities, +wrong mint, rejected/late/duplicate payment, missing transaction response, restart, +clock change, expired window, revocation, missing FIPS route, seek and disconnect. +Measure real media-byte transport and memory use. Test the actual Backstage, +Archipelago listing, purchase and player on mobile/desktop and companion. + +Use only the operator-designated Yaya Cloud video, preserve the source, and +publish the IndeeHub app image/catalog update at the end of qualification. +One working fixture is not acceptance of the complete distributed flow. diff --git a/docs/peering-reliability-followup.md b/docs/peering-reliability-followup.md new file mode 100644 index 00000000..42b8d476 --- /dev/null +++ b/docs/peering-reliability-followup.md @@ -0,0 +1,64 @@ +# Peer requests, delivery, and availability follow-up + +Status: implementation under qualification. Not a claim of reciprocal live-node +acceptance or completion of the post-1.9 backlog. + +## Confirmed failures + +Yaya retained the dev node's approved inbound request while the dev node retained +its outbound Sent request, without reciprocal federation membership. Approval +previously had no durable delivery/retry record. Configured managed relays were +also omitted from reply publication; that separate repair is in 9a041bed. + +The Connected Nodes card cached untimestamped reachability booleans, with cached +results overriding the shared store. A failing RPC was rendered as an offline +route. Nostr requests were absent from its Requests tab and badge. + +## Changes + +- Persist the approval decision and a node-key-encrypted reply before delivery. + Retry the same invite with bounded exponential backoff, at most four eligible + replies per background pass. Relay acknowledgement alone does not remove it; + reciprocal membership does. Removed peers and expired requests are excluded. +- Recover legacy Approved rows through the same supported delivery path. Do not + edit peer files by hand or elevate Observer relationships to Trusted. +- Serialize pending-store mutations and replace its private file atomically. + Malformed storage is preserved and fails explicitly. Conflicting decisions + cannot both win. Approved requests expire after 30 days to permit reconnect. +- Validate the invite's DID and key against the requested identity, normalize + discovery trust to Observer before acceptance and callback. +- Poll in the background every 30 seconds, skipping missed ticks. +- Show Nostr requests in Connected Nodes with a direct link to review them. + Preserve pending rows on failed refresh, and surface partial failures. +- Render independently arriving node lists, limit reachability probes to four, + ignore superseded replies and age timestamped reachability after 90 seconds. + An RPC failure is unknown; an explicit failed reachability check is unreachable. + Report last successful contact without inventing continuous offline duration. +- Place online nodes first, then unknown and unreachable, preserving order within + each group. Fleet describes stale reports as Not reporting. Map labels include + last contact and dashed links indicate no recent contact, not a live route. + +## Evidence so far + +- Original full backend candidate: 1,693 passed, 4 ignored, no failures, through + the isolated runner (`/tmp/archy-peering-full-backend.log`). +- Additional review added recovery-through-real-relay and retry-backoff checks; + all 50 focused federation tests pass, including actual encrypted relay delivery + for legacy Approved rows and suppression of duplicate attempts during backoff. + Final formatted source also passes all 1,693 backend tests (4 ignored). +- Connected Nodes: 9 focused tests pass, including independent rendering, + mixed failed/negative/successful probes, Nostr requests, cache age and clock skew. +- Fleet/request display: 13 focused tests pass. +- Type checking and production UI build pass. Final frontend suite: 1,238 tests + in 153 files pass (`/tmp/archy-peering-full-ui-final.log`). +- Yaya Chromium at 390 and 1440px passes candidate-asset browser checks with + deterministic peer RPC fixtures: availability text/order, approved Nostr requests, + connection navigation and no page errors (`/tmp/archy-peering-browser-candidate-7.log`). + Fixture checks are not evidence of actual reciprocal membership. +- Clean backend artifact at 10d31ae1: SHA256 + `120bd0f51fbceafeceb5557117a442fffc432a7b4d5115da1a163e472f7160da`. + Actual-node deployment and reciprocal membership checks remain required. + +The prior reply-rejection test expected a Pending row. This revision deliberately +supersedes that behavior: the decision remains Approved with delivery pending, +so a relay outage does not undo an operator decision or require reapproval. diff --git a/docs/post-1.9.0-work-backlog.md b/docs/post-1.9.0-work-backlog.md index 578d5f95..4d71e7f5 100644 --- a/docs/post-1.9.0-work-backlog.md +++ b/docs/post-1.9.0-work-backlog.md @@ -1,8 +1,17 @@ # Work requested after 1.9.0-alpha -Status: queued by the operator on 2026-10-05. Complete the current release first; -these requests do not silently expand its artifact scope. No implementation or -acceptance is claimed by this backlog. +Status: implementation and qualification in progress. 1.9.0-alpha was published +separately; these follow-ups are not in its immutable artifacts. The list below +remains the complete acceptance scope, not a claim that every item is finished. + +Current evidence is recorded in [Fleet metrics](fleet-metrics-followup.md), +[peering reliability](peering-reliability-followup.md), and the +[IndeeHub design review](indeehub-distribution-current-design.md). Monitoring and +the tested signer/dashboard candidate are deployed to dev and Yaya with rollback +backups; actual IndeeHub image publication is deferred until the end as requested. +Framework's authenticated Monitoring check awaits an operator dashboard login. +Streaming, storage-source integrations, AIUI setup, V4V packaging/player, +companion hardware checks and the full Fleet acceptance matrix remain open. ## 1. Distributed IndeeHub publishing and paid viewing diff --git a/neode-ui/src/components/federation/NetworkMap3D.vue b/neode-ui/src/components/federation/NetworkMap3D.vue index 14945465..39961782 100644 --- a/neode-ui/src/components/federation/NetworkMap3D.vue +++ b/neode-ui/src/components/federation/NetworkMap3D.vue @@ -12,6 +12,7 @@ Trusted Observer Untrusted + Dashed: no recent contact Request -
{{ peersError }}
{{ p.name || p.onion || (p.pubkey || '').slice(0, 16) + '...' }}
-{{ p.onion }}
+{{ availabilityText(p) }} · {{ contactText(p) }}