Skip to content

anon: fetch and verify an Anyone consensus - #551

Closed
eKisNonos wants to merge 2 commits into
mainfrom
anon/anyone-consensus
Closed

eKisNonos wants to merge 2 commits into
mainfrom
anon/anyone-consensus

Conversation

@eKisNonos

Copy link
Copy Markdown
Contributor

The directory half of the Anyone transport. Authority certificates, the microdescriptor consensus, quorum verification against the certs held, path selection under the bandwidth weights and the network rule, and the ntor handshake and cell layer the link will carry.

The consensus is hashed inside the capsule. The kernel's crypto_hash refuses anything over a megabyte and a microdescriptor consensus signs about 1.7 MB, so every consensus this client fetched failed its digest with errno 22 and was thrown away as unverifiable, over a transport that was working underneath it.

The capsule is built but not spawned. nonos-capsule-net-anon is declared and deliberately left out of all five feature bundles. The link stage does not complete yet, and a transport that cannot finish a connection should not be started at boot. Turning it on is one line, later.

Draft, because it does not compile against main yet. It needs two things that are in flight:

The two proof crates depend on neither and should run: anon_ntor_proofs pulls the capsule's own source in by #[path] rather than copying it, and takes its expected values from the network's reference implementation and from the cipher and hash standards. The live consensus test reads a document from a path in the environment and passes quietly when there is none, because committed vectors pin field offsets and malformed shapes but only a real document answers whether the parsers survive five thousand relays written by five thousand operators.

I have marked it draft rather than leaving it unpushed: 14,000 lines living on one disk was the larger risk.

The directory half of the Anyone transport: authority certificates, the
microdescriptor consensus, quorum verification against the certs held, path
selection under the bandwidth weights and the network rule, and the ntor
handshake and cell layer the link will carry.

The consensus is hashed inside the capsule. The kernel's crypto_hash refuses
anything over a megabyte and a microdescriptor consensus signs about 1.7 MB,
so every consensus fetched failed its digest with errno 22 and was discarded
as unverifiable over a transport that was working.

The capsule is built but not spawned: nonos-capsule-net-anon is declared and
left out of every feature bundle, because the link stage does not complete
yet and a transport that cannot finish a connection should not be started.
Every module under a #[path] is the file the capsule compiles, not a copy.
Values come from the network's reference implementation and from the cipher
and hash standards.

The live consensus test reads a document from a path in the environment and
passes quietly when there is none: committed vectors pin field offsets and
malformed shapes, but only a real document answers whether the parsers
survive five thousand relays written by five thousand operators.
@senseix21

Copy link
Copy Markdown
Collaborator

Reviewed at 8e8ecdb90 (draft, base main, 2 commits, 347 commits behind main, last pushed 2026-09-21). Measured against this branch's own merge base with main (f816dea78), the change is userland/capsule_net_anon +10537, anon_ntor_proofs +3004, anon_link_proofs +516, src/userspace +195, and four lines of wiring. Purely additive.

Verdict: Close in favour of #589. The work is not abandoned — it is already carried forward, and I checked that rather than assuming it from the titles.

This branch's code is in #589, including the kernel wiring

Both PRs add userland/capsule_net_anon from nothing, which looks at first like two independent implementations of the same Anyone-network subsystem. It is one implementation, continued:

I also checked the eight files that exist here and not on #589, because "superseded" and "silently dropped" look identical from a file count:

only here successor on #589
src/circuit/build/{drive,extend,first,next_cell}.rs src/circuit/build/{answer,ask,error,reply,timing}.rs and a new src/circuit/extend/{build,mod,reply,types}.rs
src/manager/{http,http_exchange,read_body}.rs src/manager/{body_closed,body_step}.rs
src/link/held.rs folded into the restructured link/

Circuit construction and HTTP body handling both survive, split into smaller files. So closing this loses nothing.

The one thing worth carrying across

proof-crates (anon_link_proofs) fails here, on 2026-09-21:

error: couldn't read `src/../vectors/certs_cell.bin`: No such file or directory (os error 2)

and it fails on #589 ten days later with the byte-identical error. So this branch is where that gap starts, and it has been inherited rather than noticed.

The cause is not in either diff. .gitignore:10 is a bare *.bin for the whole repository, with deliberate exceptions at :12 for bootloader firmware and :53 for nonos-data/trust, and none for proof-crate vectors. The file exists wherever these tests were written, include_bytes! resolves there, and git add has been silently declining it ever since. The fix belongs on #589 now:

!userland/**/vectors/*.bin

An exception rather than generating the vector in the build, since a checked-in CERTS cell is evidence of what a real one looked like — not an input the code under test should re-derive.

Worth running git grep -l include_bytes userland/*proofs against a fresh clone before #589 lands, in case certs_cell.bin is not the only fixture in this position.

The rest of the red is stale, not informative

build / build fails on a dead-code lint — TableError never constructed, under -D warnings — and boot-smoke, benchmark and verus fail with it. Against a main that has moved 347 commits, none of those verdicts tell anyone anything about the code today; #589's run of the same crates is the current answer, and there only anon_link_proofs is red.

That is the practical argument for closing rather than rebasing: a 347-commit rebase of a draft whose content already exists on a branch that is 90 behind and otherwise green is work with no product.

Verified correct

What to do

Close this and let #589 carry it, or — if there is something in the eight restructured files that #589's reorganisation lost and I have not spotted — say which, because the blob comparison says the rest is already there.

@eKisNonos

Copy link
Copy Markdown
Contributor Author

Superseded. This work is integrated into the 0.9.2 release and ships in the current tree. Closing as part of the 0.9.2 consolidation.

@eKisNonos eKisNonos closed this Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants