Skip to content

fix: bootstrap public discovery roots without changing node defaults - #649

Merged
ty-everett merged 1 commit into
mainfrom
codex/staging-root-discovery-bootstrap-20260927
Sep 27, 2026
Merged

ty-everett merged 1 commit into
mainfrom
codex/staging-root-discovery-bootstrap-20260927

Conversation

@ty-everett

@ty-everett ty-everett commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

A public discovery root can answer direct SHIP requests while default SDK clients cannot find ls_ship. Ordinary Overlay defaults suppress its discovery-service advertisements, and its wallet advertiser relies on discovering SHIP before synchronizing advertisements. Add explicit DISCOVERY_ROOT=true so a designated public root registers the default discovery topics/services and bootstraps its advertiser at its own HTTPS origin. Ordinary deployments retain their current defaults and clients retain normal network presets.

Program and scope

  • Tracker: operator-authorized UHRP recovery; NanoStore staging PR fix(sdk): resolve SonarCloud code-smell issues in sdk-core #78 awaits default TTN discovery.
  • Gate advanced: explicit root registration and bootstrap, with negative URL/flag validation.
  • Scope: Overlay Server 2.1.44 runtime/configuration, service contract, generated facts and docs. No public npm package bytes, database schema, wire format or workflow changed.
  • Exact head SHA reviewed: fc20185d92980bb8fc2329d87c1d0b25c4e8244b.

Impact

  • No public package source or manifest changed
  • Infrastructure source, image or deployment configuration changed
  • Security-sensitive boundary changed
  • Documentation changed

Overlay Server 2.1.44 is an unpublished image candidate. DISCOVERY_ROOT defaults to false. Root mode requires a credential-free HTTPS origin, uses the correct mainnet/testnet/TTN preset, and directs only the advertiser's bootstrap lookups to that origin. Existing signature, admission, propagation, CORS and resource controls remain unchanged.

Verification

  • Node 24 standalone service: 10 tests passed, build and warning-free lint passed; audit reported zero vulnerabilities.
  • Root: pnpm build, pnpm typecheck, pnpm lint, pnpm format:check and pnpm health:check passed. Existing maintenance reminders remain visible and were not changed.
  • New tests cover unchanged ordinary-node defaults, all three root network mappings, malformed flags and unsafe hosting origins.
  • Hosted CI 36283922000, runtime contracts 36283921955, CodeQL 36283921980 and conformance 36283921956 passed on that exact head. Sonar reports zero new findings and unreviewed hotspots; the PR CodeQL alert list and review threads are empty.
  • Browser/mobile/packed consumers: no public package or client artifact changed. Live default SDK discovery and a real staged advertisement broadcast remain required after the verified image release.
  • Performance: configuration is read once at startup; request paths are unchanged.
  • I self-reviewed the complete diff for correctness, security, compatibility, artifacts, dependencies, docs and operations.
  • All applicable checks are terminal and successful on the exact head.

Security and dependencies

  • Dependency graph is unchanged; the standalone lock changes only its image version metadata.
  • Runtime/peer compatibility and audit results were reviewed.
  • Negative tests cover the changed URL/flag boundary.
  • Exact-head CodeQL has no new alert.
  • Exact-head Sonar has zero new findings and unreviewed hotspots.
  • No new override, advisory dismissal, suppression, exception or skipped test.
  • Workflow permissions and denied dependency lifecycle scripts remain unchanged.

Release and operations

  • No npm publication was performed from a workstation or this PR.
  • No public npm patch is required; the changed service has its own 2.1.44 image version.
  • Image, migration and operational guidance are current.

Publish only through protected Infra Release after merged-source acceptance. No schema or wire migration is needed. Operator staging must enable the flag, retain two Ready serving nodes, pass direct and default SHIP/SLAP discovery before handoff, and verify a real UHRP broadcast. Root-mode retirement must verify withdrawal after normal advertisement sync; a restart alone is insufficient. The previous 2.1.43 image preserves data and physical readiness but reintroduces the bootstrap limitation, so it is not a functional recovery claim.

Completion evidence

  • Tracker claims are limited to work actually proved.
  • Documentation and migration/operation decisions are current.
  • All review threads are resolved and hosted checks are accepted.
  • Final exact head has qualified maintainer review before merge.

@sonarqubecloud

Copy link
Copy Markdown

@ty-everett
ty-everett marked this pull request as ready for review September 27, 2026 01:01
@ty-everett
ty-everett merged commit daca156 into main Sep 27, 2026
43 checks passed
@ty-everett
ty-everett deleted the codex/staging-root-discovery-bootstrap-20260927 branch September 27, 2026 01:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant