Repository navigation
feat(iroh): publish signed direct UDP ports - #8480
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Greptile SummaryThis PR adds broker-side support for signed direct UDP port advertisements in the Iroh trust broker. When clients include a
Confidence Score: 5/5Safe to merge — the change is purely additive, cryptographically scoped, and correctly isolated to same-account discovery. All three layers of the feature (validation, persistence, publication) are consistent and well-guarded. Ports are validated at the application layer (1–65535, integer, non-empty) and enforced again by DB CHECK constraints. Publication is strictly same-account: publicBinding is only called from register (own binding) and discover (userId-scoped snapshot), so cross-account paths never see the field. Revocation immediately nulls the ports, and the retention sweep now covers them as a backstop. The migration is additive with no breaking changes for legacy clients. No files require special attention. Important Files Changed
Sequence Diagram%%{init: {'theme': 'neutral'}}%%
sequenceDiagram
participant Client
participant TrustBroker
participant Model
participant Repository
participant DB
Client->>TrustBroker: register(userId, signedPayload)
TrustBroker->>Model: parseRegistrationPayload(raw)
Model-->>TrustBroker: IrohRegistrationPayload
TrustBroker->>Repository: consumeChallengeAndRegister(payload)
Repository->>DB: INSERT/UPDATE iroh_endpoint_bindings
DB-->>Repository: IrohBindingRecord
Repository-->>TrustBroker: binding
TrustBroker-->>Client: binding with direct_ports
Client->>TrustBroker: discover(userId)
TrustBroker->>Repository: discoverySnapshot userId-scoped
Repository->>DB: SELECT same-account bindings
DB-->>Repository: bindings
TrustBroker-->>Client: bindings with direct_ports
Client->>TrustBroker: revoke(userId, bindingId)
TrustBroker->>Repository: revokeBinding
Repository->>DB: clear ports and path_hints
%%{init: {'theme': 'base', 'themeVariables': {"darkMode": true, "background": "#0d1117", "primaryColor": "#21262d", "primaryTextColor": "#e6edf3", "primaryBorderColor": "#8b949e", "lineColor": "#8b949e", "textColor": "#e6edf3", "edgeLabelBackground": "#161b22", "actorBkg": "#21262d", "actorBorder": "#8b949e", "actorTextColor": "#e6edf3", "actorLineColor": "#8b949e", "signalColor": "#8b949e", "signalTextColor": "#e6edf3", "noteBkgColor": "#373320", "noteBorderColor": "#d4a72c", "noteTextColor": "#f0e6c0", "labelBoxBkgColor": "#21262d", "labelBoxBorderColor": "#8b949e", "labelTextColor": "#e6edf3", "loopTextColor": "#e6edf3", "activationBkgColor": "#30363d", "activationBorderColor": "#8b949e"}}}%%
sequenceDiagram
participant Client
participant TrustBroker
participant Model
participant Repository
participant DB
Client->>TrustBroker: register(userId, signedPayload)
TrustBroker->>Model: parseRegistrationPayload(raw)
Model-->>TrustBroker: IrohRegistrationPayload
TrustBroker->>Repository: consumeChallengeAndRegister(payload)
Repository->>DB: INSERT/UPDATE iroh_endpoint_bindings
DB-->>Repository: IrohBindingRecord
Repository-->>TrustBroker: binding
TrustBroker-->>Client: binding with direct_ports
Client->>TrustBroker: discover(userId)
TrustBroker->>Repository: discoverySnapshot userId-scoped
Repository->>DB: SELECT same-account bindings
DB-->>Repository: bindings
TrustBroker-->>Client: bindings with direct_ports
Client->>TrustBroker: revoke(userId, bindingId)
TrustBroker->>Repository: revokeBinding
Repository->>DB: clear ports and path_hints
Reviews (2): Last reviewed commit: "fix(iroh): scrub revoked direct ports" | Re-trigger Greptile |
| function udpPort(value: unknown): number { | ||
| if (!Number.isInteger(value) || (value as number) < 1 || (value as number) > 65_535) { | ||
| throw new IrohInvalidInputError({ code: "invalid_direct_ports" }); | ||
| } | ||
| return value as number; | ||
| } |
There was a problem hiding this comment.
Every other numeric validator in this file (
positiveInteger) uses Number.isSafeInteger. While the upper bound > 65_535 makes Number.isInteger functionally equivalent here (no unsafe integer can be ≤ 65535), the inconsistency could mislead future maintainers into using Number.isInteger for a larger bounded range where unsafe integers could slip through.
| function udpPort(value: unknown): number { | |
| if (!Number.isInteger(value) || (value as number) < 1 || (value as number) > 65_535) { | |
| throw new IrohInvalidInputError({ code: "invalid_direct_ports" }); | |
| } | |
| return value as number; | |
| } | |
| function udpPort(value: unknown): number { | |
| if (!Number.isSafeInteger(value) || (value as number) < 1 || (value as number) > 65_535) { | |
| throw new IrohInvalidInputError({ code: "invalid_direct_ports" }); | |
| } | |
| return value as number; | |
| } |
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
Stacked on feat-iroh-final-integration.
Adds the broker half of authenticated direct-path support:
Verification:
Need help on this PR? Tag
/codesmithwith what you need. Autofix is disabled.Summary by cubic
Adds signed direct-path UDP ports to the Iroh broker. Stores per-family ports, publishes them only to authenticated same-account discovery, and scrubs them on revocation and retention.
New Features
directPortswithipv4/ipv6integers (1–65535) in signed registrations; reject empty or invalid shapes.direct_port_v4/direct_port_v6; clear both when a refresh omitsdirectPorts.direct_portsonly to same‑account discovery; never store private addresses.direct_port_v4/direct_port_v6on binding revocation and during retention drain of revoked bindings.Migration
20260719120000_iroh_direct_portsto adddirect_port_v4/direct_port_v6with range checks.Written for commit 89b9dd9. Summary will update on new commits.