Maintainer ruling (Eric, 2026-09-25, CIRISServer#655): announce is per node. Each node runs the setup wizard, and the person chooses whether to announce that node (POST /v1/federation/announce promotes the owner-binding user→node to federation). The public device roster is exactly "the devices we chose to announce on, that people can contact us via". Unannounced devices are darknet: reachable by the person's own nodes and by whoever they hand a code to, never listed.
At v31.0.0, replication/serve_policy.rs serves IdentityOccurrence and TransportDestination as ("self_own", "public"). A node offers its own occurrence rows and transport route to every peer it replicates with, whatever its announce state. So an unannounced device's row still lands on its consented peers (for agents, the canonical), and a node holding them could list them.
Ask: gate the serve of a node's own IdentityOccurrence (and its TransportDestination) on that node's announce state:
- Announced node (owner-binding at
federation): serve as today.
- Unannounced node: serve only to the owner's own nodes (the
self send set, nodes_of(principals)), never to other peers.
This is the per-node form of CC 5.4.6's split: identity rows are lightnet only for the devices the person announced. CIRISServer's read route (GET /v1/self/occurrences) is being gated the same way in 0.5.218.
Maintainer ruling (Eric, 2026-09-25, CIRISServer#655): announce is per node. Each node runs the setup wizard, and the person chooses whether to announce that node (
POST /v1/federation/announcepromotes the owner-binding user→node tofederation). The public device roster is exactly "the devices we chose to announce on, that people can contact us via". Unannounced devices are darknet: reachable by the person's own nodes and by whoever they hand a code to, never listed.At v31.0.0,
replication/serve_policy.rsservesIdentityOccurrenceandTransportDestinationas("self_own", "public"). A node offers its own occurrence rows and transport route to every peer it replicates with, whatever its announce state. So an unannounced device's row still lands on its consented peers (for agents, the canonical), and a node holding them could list them.Ask: gate the serve of a node's own
IdentityOccurrence(and itsTransportDestination) on that node's announce state:federation): serve as today.selfsend set,nodes_of(principals)), never to other peers.This is the per-node form of CC 5.4.6's split: identity rows are lightnet only for the devices the person announced. CIRISServer's read route (
GET /v1/self/occurrences) is being gated the same way in 0.5.218.