Skip to content

Gate a node's own IdentityOccurrence/TransportDestination serve on its announce state — an unannounced device's row reaches every peer today #682

Description

@emooreatx

Maintainer ruling (Eric, 2026-09-25, CIRISServer#655): announce is per node. Each node runs the setup wizard, and the person chooses whether to announce that node (POST /v1/federation/announce promotes the owner-binding user→node to federation). The public device roster is exactly "the devices we chose to announce on, that people can contact us via". Unannounced devices are darknet: reachable by the person's own nodes and by whoever they hand a code to, never listed.

At v31.0.0, replication/serve_policy.rs serves IdentityOccurrence and TransportDestination as ("self_own", "public"). A node offers its own occurrence rows and transport route to every peer it replicates with, whatever its announce state. So an unannounced device's row still lands on its consented peers (for agents, the canonical), and a node holding them could list them.

Ask: gate the serve of a node's own IdentityOccurrence (and its TransportDestination) on that node's announce state:

  • Announced node (owner-binding at federation): serve as today.
  • Unannounced node: serve only to the owner's own nodes (the self send set, nodes_of(principals)), never to other peers.

This is the per-node form of CC 5.4.6's split: identity rows are lightnet only for the devices the person announced. CIRISServer's read route (GET /v1/self/occurrences) is being gated the same way in 0.5.218.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions