Skip to content

Track transport teardown for rejected relay canary allocations #138

Description

@mickvandijke

Context

The relay canary gate now prevents unverified MASQUE relay allocations from entering saorsa-core DHT self-record gossip. The core reachability driver clears unpublished relay state after canary rejection or insufficient witness coverage.

The MASQUE allocation itself has already been established at the transport layer before canaries run. For a fully airtight gate, saorsa-transport should expose APIs that let core either defer outbound relay advertisement until canary verification succeeds or explicitly tear down a rejected allocation.

Follow-up work

  • Add a transport API for tearing down a specific proactive MASQUE relay allocation after canary rejection.
  • Consider deferring outbound ADD_ADDRESS relay advertisement until core marks the relay as canary-verified.
  • Ensure rejected allocations do not remain usable or advertised outside the sequenced DHT self-record path.
  • Add integration coverage for rejected relay cleanup once the transport API exists.

Related PR

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions