Show durable connection requests and timestamped node availability
This commit is contained in:
@@ -0,0 +1,73 @@
|
||||
# IndeeHub distribution: current implementation design
|
||||
|
||||
Status: design for the post-1.9 follow-up, not implemented/accepted. Earlier
|
||||
swarm plans describe historical experiments and must not be read as live proof.
|
||||
|
||||
## Standards checked on 2026-10-05
|
||||
|
||||
- Nostr [NIP-71](https://github.com/nostr-protocol/nips/blob/master/71.md)
|
||||
defines video metadata, including addressable normal-video kind34235. Use a
|
||||
stable producer/project identifier for revisions. This does not define paid
|
||||
viewing rights. Hash/media metadata follows
|
||||
[NIP-94](https://github.com/nostr-protocol/nips/blob/master/94.md).
|
||||
- [NIP-98](https://github.com/nostr-protocol/nips/blob/master/98.md) authenticates
|
||||
HTTP requests; it is not proof of payment or permission to another creator's
|
||||
project. Keep the existing verified app session and project ownership checks.
|
||||
- [Cashu NUT-18](https://github.com/cashubtc/nuts/blob/main/18.md) supplies payment
|
||||
request negotiation. [NUT-04](https://github.com/cashubtc/nuts/blob/main/04.md)
|
||||
covers mint quotes/issuance; method-specific current specifications and older
|
||||
deployed mint responses must both be capability-tested. Keep quote identifiers
|
||||
private to the receiving wallet. Payment settlement must be correlated to the
|
||||
purchase, never inferred from a change in wallet balance.
|
||||
- [NUT-19](https://github.com/cashubtc/nuts/blob/main/19.md) provides mint-side
|
||||
cached responses where supported. It supplements a durable local payment
|
||||
journal; it does not replace one or make an arbitrary retry safe.
|
||||
- [LNURL-pay](https://github.com/lnurl/luds/blob/luds/06.md) supports an invoice
|
||||
handoff. A Lightning address by itself is not a signed settlement receipt.
|
||||
|
||||
## Required implementation contract
|
||||
|
||||
1. Backstage publishes only the selected, owned project. Announcements contain
|
||||
public metadata, producer identity, node identity, content hashes, current
|
||||
price/window and accepted-method capabilities. Never publish Cloud paths,
|
||||
mint quotes, tokens, paid media keys or private management addresses.
|
||||
2. Each instance's Archipelago source verifies signatures, identity bindings and
|
||||
monotonic event revisions. Persist discovery so a relay outage does not empty
|
||||
an existing library. Keep other sources and the current default intact.
|
||||
3. A purchase binds buyer identity, publisher, project revision, amount, currency,
|
||||
selected payment method and an unpredictable idempotency identifier. Persist
|
||||
the quote before requesting payment. Snapshot the offer so later edits cannot
|
||||
silently change the purchased terms.
|
||||
4. Reuse file-payment capability negotiation and proven settlement primitives.
|
||||
Existing file Lightning invoices currently require LND; therefore adding
|
||||
first-use Lightning-to-Cashu receiving is real work, not a display label. The
|
||||
receiver must verify a correlated invoice/mint receipt and recover issuance
|
||||
after a lost response before granting access. Its provisioned ecash address
|
||||
must map to the actual receiving wallet. No new real payment is authorized by
|
||||
this design; use isolated fixtures until a bounded payment is approved.
|
||||
5. A paid purchase creates one durable entitlement. Default demo window proposal:
|
||||
start at the first successfully authorized media response; persist start and
|
||||
expiry atomically. Retries, seek and reconnect reuse it without another
|
||||
payment. Check the entitlement for every media/range/key request. Clock
|
||||
rollback must not extend an already-started window.
|
||||
6. Browser/companion playback remains ordinary authenticated local HTTP. Actual
|
||||
inter-node media bytes use FIPS, with a bound node identity and authenticated
|
||||
purchase capability. No silent Tor/LAN/iroh fallback for required FIPS media.
|
||||
Show a recoverable unavailable route without requesting another payment.
|
||||
7. Range/segment serving streams bounded buffers with backpressure and cancel
|
||||
propagation. Do not read an entire paid film into a Vec before serving it.
|
||||
Verify length/hash/revision, reject malformed ranges and path escapes, and
|
||||
keep cache access subject to the same entitlement. Delivered plaintext cannot
|
||||
be made impossible to copy; expiry controls subsequent authorized delivery.
|
||||
|
||||
## Qualification that remains required
|
||||
|
||||
Publisher/receiver integration must cover altered metadata, forged identities,
|
||||
wrong mint, rejected/late/duplicate payment, missing transaction response, restart,
|
||||
clock change, expired window, revocation, missing FIPS route, seek and disconnect.
|
||||
Measure real media-byte transport and memory use. Test the actual Backstage,
|
||||
Archipelago listing, purchase and player on mobile/desktop and companion.
|
||||
|
||||
Use only the operator-designated Yaya Cloud video, preserve the source, and
|
||||
publish the IndeeHub app image/catalog update at the end of qualification.
|
||||
One working fixture is not acceptance of the complete distributed flow.
|
||||
@@ -0,0 +1,64 @@
|
||||
# Peer requests, delivery, and availability follow-up
|
||||
|
||||
Status: implementation under qualification. Not a claim of reciprocal live-node
|
||||
acceptance or completion of the post-1.9 backlog.
|
||||
|
||||
## Confirmed failures
|
||||
|
||||
Yaya retained the dev node's approved inbound request while the dev node retained
|
||||
its outbound Sent request, without reciprocal federation membership. Approval
|
||||
previously had no durable delivery/retry record. Configured managed relays were
|
||||
also omitted from reply publication; that separate repair is in 9a041bed.
|
||||
|
||||
The Connected Nodes card cached untimestamped reachability booleans, with cached
|
||||
results overriding the shared store. A failing RPC was rendered as an offline
|
||||
route. Nostr requests were absent from its Requests tab and badge.
|
||||
|
||||
## Changes
|
||||
|
||||
- Persist the approval decision and a node-key-encrypted reply before delivery.
|
||||
Retry the same invite with bounded exponential backoff, at most four eligible
|
||||
replies per background pass. Relay acknowledgement alone does not remove it;
|
||||
reciprocal membership does. Removed peers and expired requests are excluded.
|
||||
- Recover legacy Approved rows through the same supported delivery path. Do not
|
||||
edit peer files by hand or elevate Observer relationships to Trusted.
|
||||
- Serialize pending-store mutations and replace its private file atomically.
|
||||
Malformed storage is preserved and fails explicitly. Conflicting decisions
|
||||
cannot both win. Approved requests expire after 30 days to permit reconnect.
|
||||
- Validate the invite's DID and key against the requested identity, normalize
|
||||
discovery trust to Observer before acceptance and callback.
|
||||
- Poll in the background every 30 seconds, skipping missed ticks.
|
||||
- Show Nostr requests in Connected Nodes with a direct link to review them.
|
||||
Preserve pending rows on failed refresh, and surface partial failures.
|
||||
- Render independently arriving node lists, limit reachability probes to four,
|
||||
ignore superseded replies and age timestamped reachability after 90 seconds.
|
||||
An RPC failure is unknown; an explicit failed reachability check is unreachable.
|
||||
Report last successful contact without inventing continuous offline duration.
|
||||
- Place online nodes first, then unknown and unreachable, preserving order within
|
||||
each group. Fleet describes stale reports as Not reporting. Map labels include
|
||||
last contact and dashed links indicate no recent contact, not a live route.
|
||||
|
||||
## Evidence so far
|
||||
|
||||
- Original full backend candidate: 1,693 passed, 4 ignored, no failures, through
|
||||
the isolated runner (`/tmp/archy-peering-full-backend.log`).
|
||||
- Additional review added recovery-through-real-relay and retry-backoff checks;
|
||||
all 50 focused federation tests pass, including actual encrypted relay delivery
|
||||
for legacy Approved rows and suppression of duplicate attempts during backoff.
|
||||
Final formatted source also passes all 1,693 backend tests (4 ignored).
|
||||
- Connected Nodes: 9 focused tests pass, including independent rendering,
|
||||
mixed failed/negative/successful probes, Nostr requests, cache age and clock skew.
|
||||
- Fleet/request display: 13 focused tests pass.
|
||||
- Type checking and production UI build pass. Final frontend suite: 1,238 tests
|
||||
in 153 files pass (`/tmp/archy-peering-full-ui-final.log`).
|
||||
- Yaya Chromium at 390 and 1440px passes candidate-asset browser checks with
|
||||
deterministic peer RPC fixtures: availability text/order, approved Nostr requests,
|
||||
connection navigation and no page errors (`/tmp/archy-peering-browser-candidate-7.log`).
|
||||
Fixture checks are not evidence of actual reciprocal membership.
|
||||
- Clean backend artifact at 10d31ae1: SHA256
|
||||
`120bd0f51fbceafeceb5557117a442fffc432a7b4d5115da1a163e472f7160da`.
|
||||
Actual-node deployment and reciprocal membership checks remain required.
|
||||
|
||||
The prior reply-rejection test expected a Pending row. This revision deliberately
|
||||
supersedes that behavior: the decision remains Approved with delivery pending,
|
||||
so a relay outage does not undo an operator decision or require reapproval.
|
||||
@@ -1,8 +1,17 @@
|
||||
# Work requested after 1.9.0-alpha
|
||||
|
||||
Status: queued by the operator on 2026-10-05. Complete the current release first;
|
||||
these requests do not silently expand its artifact scope. No implementation or
|
||||
acceptance is claimed by this backlog.
|
||||
Status: implementation and qualification in progress. 1.9.0-alpha was published
|
||||
separately; these follow-ups are not in its immutable artifacts. The list below
|
||||
remains the complete acceptance scope, not a claim that every item is finished.
|
||||
|
||||
Current evidence is recorded in [Fleet metrics](fleet-metrics-followup.md),
|
||||
[peering reliability](peering-reliability-followup.md), and the
|
||||
[IndeeHub design review](indeehub-distribution-current-design.md). Monitoring and
|
||||
the tested signer/dashboard candidate are deployed to dev and Yaya with rollback
|
||||
backups; actual IndeeHub image publication is deferred until the end as requested.
|
||||
Framework's authenticated Monitoring check awaits an operator dashboard login.
|
||||
Streaming, storage-source integrations, AIUI setup, V4V packaging/player,
|
||||
companion hardware checks and the full Fleet acceptance matrix remain open.
|
||||
|
||||
## 1. Distributed IndeeHub publishing and paid viewing
|
||||
|
||||
|
||||
Reference in New Issue
Block a user