mirror of
https://github.com/simplex-chat/simplexmq.git
synced 2026-10-01 04:17:59 +00:00
* implement resolving 2LD names by labelhash * tiny test addition * simplify language * report expiry and availability correctly * compare block instead of wall clock * simplify language * simplify language * map resolver 410 to NAME NOT_FOUND (a lapsed name is an answer, not a failure) * split error into a machine-readable code and a human message * resolver: reduce comments * resolver: reduce comments, remove REVIEW.html * extend SMP protocol to support name availability queries with accurate and meaningful replies * review fixes * more review fixes * docs shortening and other review fixes * add catch all for furture variants * adversarial review (against simplex-chat) fix * next iteration fixes * adapt house style * eth_call guard and cache constants * revert NAVL command and wrap it all into RSLV * doc fixes * Update src/Simplex/Messaging/Server/Names.hs Co-authored-by: Evgeny <evgeny@poberezkin.com> * Update src/Simplex/Messaging/Protocol.hs Co-authored-by: Evgeny <evgeny@poberezkin.com> * Update src/Simplex/Messaging/Protocol.hs Co-authored-by: Evgeny <evgeny@poberezkin.com> * Update src/Simplex/Messaging/Protocol.hs Co-authored-by: Evgeny <evgeny@poberezkin.com> * Update src/Simplex/Messaging/Protocol.hs Co-authored-by: Evgeny <evgeny@poberezkin.com> * protocol types refactoring * next iteration on types only * rentPrices map * claude answering ep review. to be continued... * separate labelhash and plaintext names cleanly * align implementation with latest type changes to test against client * fix adversarial review findings * trim diff * align resolver with contract changes for names v2 * fix reverse compatibility with .testing mainnet * fix more robustly * NameQuery simplification * revert drive-by refactoring * implement full type change and introduce resolver endpoint versioning * fix stale docs * derive NameRegistration JSON the same way on every build sumTypeJSON switches to the _owsf form on swift builds, but this JSON is the RNAME payload and the resolver's HTTP contract, so a swift client and a Linux relay would disagree on every field. taggedObjectJSON is what it already resolves to everywhere else. The label modifier keeps the reservedReason_ collision escape out of the API, as AgentWorkersDetails does: both arms now say reservedReason. * fix resolver boundary: status before body, cover /v2, drop dead field httpGet read the response body before checking the status, so an oversized error page surfaced as a transient "response too large" instead of the authoritative status. Reverting it to its previous shape restores that and removes the status test both callers had been re-deriving. registration() had no tests at all, though it is the endpoint SMP v22 consumes. RegistrationV2Tests covers the three answer shapes, the error paths and the exact key set of each, which is the wire contract. auctionUntil was always None with no consumer. The spec claimed a reason word travels unchanged; a resolver can only send a word it has, and SNRC's registry records a number. * fix review findings * resolver errors say what went wrong, not "no such name" /v2/resolve answers 200, 400 or 502, and an unregistered name is NRAvailable, so no status means "not registered". Mapping 400/404/410 to NOT_FOUND made a misconfigured relay deny every name, and hid a relay upgraded ahead of its resolver. All three now surface as RESOLVER. rslvNotFound would have gone dead, so it counts what its name says: an availability answer the encoder downgrades for a session below v22. The wire is unchanged. A hashed query the registrar cannot name is refused with 502 rather than answered with a record named "unknown", which the client rejects anyway. NRRUnknown is capped to 32 printable characters again, as the spec says. A registered name that is also reserved no longer offers a date it will never free up on. rentPrices is registrationPrices throughout, and yearPriceUSD is USDCents rather than a bare Int64. * fix regressions found reviewing the last two commits resolveNameMsg read the version off thParams', which on the PFWD path is the proxy's session, not the client's. It takes the version as an argument now, so each call site passes its own — the forwarded one uses fwdVersion. reservedReasonOf matched the reason words before capping, so "internal review" became NRRUnknown "internal", which encodes back as NRRInternal. Capping precedes the match, so what is kept encodes to what it decoded. Four agent tests still pinned NAME NOT_FOUND from a 404 stub, and two spec statements still described the old mapping. A registrar that does not record labels cannot answer a hashed query, which the resolver README now says. * docs sweep * simplify encoding * drop resolver caching (#1866) * rename * remove trailing_ filter * fix resolver v2 for subnames (#1867) * fix resolver v2 for subnames * simplify doc * resolver should report response truth freshness (#1868) * first shot at reporting freshness * fix review findings * renaming --------- Co-authored-by: sh <github.shum@liber.li> Co-authored-by: Evgeny <evgeny@poberezkin.com>
167 lines
5.6 KiB
YAML
167 lines
5.6 KiB
YAML
services:
|
|
# One-shot setup (runs as root): generates /jwt/jwt.hex and chowns the
|
|
# nimbus-data volume to UID 1000 (the user Nimbus runs as inside its image).
|
|
# Without this chown Nimbus gets "Permission denied" on its data dir
|
|
# because docker creates fresh named volumes owned by root.
|
|
init:
|
|
image: alpine:latest
|
|
volumes:
|
|
- jwt:/jwt
|
|
- nimbus-data:/nimbus-data
|
|
command: >
|
|
sh -c '
|
|
set -e;
|
|
if [ ! -f /jwt/jwt.hex ]; then
|
|
apk add --no-cache openssl >/dev/null;
|
|
openssl rand -hex 32 | tr -d "\n" > /jwt/jwt.hex;
|
|
chmod 644 /jwt/jwt.hex;
|
|
echo "Generated /jwt/jwt.hex";
|
|
else
|
|
echo "jwt.hex already exists";
|
|
fi;
|
|
chown 1000:1000 /nimbus-data;
|
|
echo "Chowned /nimbus-data to 1000:1000";
|
|
'
|
|
restart: "no"
|
|
|
|
# One-shot: fetches a recent finalised checkpoint into the Nimbus data dir
|
|
# using the trustedNodeSync subcommand. Skipped if the data dir is already
|
|
# initialised, so subsequent compose-ups are no-ops.
|
|
nimbus-checkpoint-sync:
|
|
image: statusim/nimbus-eth2:multiarch-latest
|
|
depends_on:
|
|
init:
|
|
condition: service_completed_successfully
|
|
volumes:
|
|
- nimbus-data:/home/user/nimbus-eth2/build/data
|
|
entrypoint:
|
|
- sh
|
|
- -c
|
|
- |
|
|
if [ -d /home/user/nimbus-eth2/build/data/${NETWORK}/db ]; then
|
|
echo "Nimbus data dir already initialised — skipping checkpoint sync";
|
|
exit 0;
|
|
fi;
|
|
/home/user/nimbus-eth2/build/nimbus_beacon_node trustedNodeSync \
|
|
--network=${NETWORK} \
|
|
--data-dir=/home/user/nimbus-eth2/build/data/${NETWORK} \
|
|
--trusted-node-url=${TRUSTED_NODE_URL} \
|
|
--backfill=false
|
|
restart: "no"
|
|
|
|
# One-shot: downloads a pre-synced snapshot from snapshots.reth.rs into the
|
|
# Reth data dir. Turns a multi-day from-scratch sync into a ~hour download.
|
|
# Skipped if the data dir is already initialised — re-runs are no-ops.
|
|
# Privacy note: snapshots.reth.rs sees this download (operator existence).
|
|
# Subsequent eth_call traffic stays local.
|
|
reth-snapshot-init:
|
|
image: ghcr.io/paradigmxyz/reth:latest
|
|
depends_on:
|
|
init:
|
|
condition: service_completed_successfully
|
|
volumes:
|
|
- reth-data:/data
|
|
entrypoint:
|
|
- sh
|
|
- -c
|
|
- |
|
|
if [ -f /data/.snapshot-done ] || [ -d /data/db ]; then
|
|
echo "Reth data already initialised — skipping snapshot download";
|
|
exit 0;
|
|
fi;
|
|
echo "Downloading Reth ${NETWORK} --minimal snapshot...";
|
|
reth download --datadir /data --chain ${NETWORK} --minimal && \
|
|
touch /data/.snapshot-done && \
|
|
echo "Snapshot download complete"
|
|
restart: "no"
|
|
|
|
reth:
|
|
image: ghcr.io/paradigmxyz/reth:latest
|
|
depends_on:
|
|
reth-snapshot-init:
|
|
condition: service_completed_successfully
|
|
volumes:
|
|
- reth-data:/data
|
|
- jwt:/jwt:ro
|
|
ports:
|
|
# JSON-RPC for smp-server. Bound to loopback — put Caddy in front for remote access.
|
|
- "127.0.0.1:8545:8545"
|
|
# p2p (Ethereum network). Open these on your firewall for sync.
|
|
- "30303:30303/tcp"
|
|
- "30303:30303/udp"
|
|
command: >
|
|
node
|
|
--datadir /data
|
|
--chain ${NETWORK}
|
|
--minimal
|
|
--authrpc.jwtsecret /jwt/jwt.hex
|
|
--authrpc.addr 0.0.0.0 --authrpc.port 8551
|
|
--http
|
|
--http.addr 0.0.0.0 --http.port 8545
|
|
--http.api eth,net
|
|
--rpc.gascap 50000000
|
|
--port 30303
|
|
--discovery.port 30303
|
|
restart: unless-stopped
|
|
|
|
nimbus:
|
|
image: statusim/nimbus-eth2:multiarch-latest
|
|
depends_on:
|
|
nimbus-checkpoint-sync:
|
|
condition: service_completed_successfully
|
|
volumes:
|
|
- nimbus-data:/home/user/nimbus-eth2/build/data
|
|
- jwt:/jwt:ro
|
|
ports:
|
|
- "9000:9000/tcp"
|
|
- "9000:9000/udp"
|
|
- "127.0.0.1:5052:5052"
|
|
command: >
|
|
--network=${NETWORK}
|
|
--data-dir=/home/user/nimbus-eth2/build/data/${NETWORK}
|
|
--el=http://reth:8551
|
|
--jwt-secret=/jwt/jwt.hex
|
|
--non-interactive
|
|
--rest --rest-address=0.0.0.0 --rest-port=5052
|
|
--nat=${NAT:-any}
|
|
restart: unless-stopped
|
|
|
|
# SNRC REST resolver. Talks to reth on the compose-internal network,
|
|
# exposes /resolve and /health on 127.0.0.1:8000 by default. The
|
|
# smp-server points its [NAMES] resolver_endpoint at this URL.
|
|
# To change the host port, edit the LEFT side of the port mapping below.
|
|
resolver:
|
|
build:
|
|
context: ./service
|
|
dockerfile: Dockerfile
|
|
depends_on:
|
|
# reth's `service_started` is sufficient — the resolver tolerates
|
|
# eth_call failures gracefully (returns 502 with the error body), so
|
|
# starting before reth has finished snapshot replay just yields a few
|
|
# 502s until the chain is queryable. The upstream reth image doesn't
|
|
# ship a HEALTHCHECK, so we can't gate on healthy.
|
|
reth:
|
|
condition: service_started
|
|
environment:
|
|
SNRC_RPC: http://reth:8545
|
|
SNRC_BIND: 0.0.0.0
|
|
# Registry addresses cascade through the script's own defaults
|
|
# (mainnet `.testing`; `.simplex` unconfigured). Set explicitly here
|
|
# only if you're deploying against a different network or contract.
|
|
# SNRC_REGISTRY_TESTING: 0x...
|
|
# SNRC_REGISTRY_SIMPLEX: 0x...
|
|
# Registrar and controller, same cascade. Without the registrar `status`
|
|
# is "unknown"; without the controller a reserved name is "unregistered".
|
|
# SNRC_REGISTRAR_TESTING: 0x...
|
|
# SNRC_REGISTRAR_SIMPLEX: 0x...
|
|
# SNRC_CONTROLLER_TESTING: 0x...
|
|
# SNRC_CONTROLLER_SIMPLEX: 0x...
|
|
ports:
|
|
- "127.0.0.1:8000:8000"
|
|
restart: unless-stopped
|
|
|
|
volumes:
|
|
reth-data:
|
|
nimbus-data:
|
|
jwt:
|