Remove unresolvable internal references from source comments

Fifteen comments in src/ cited internal identifiers that a reader of the
published source cannot resolve. Each now states the thing the identifier
stood for, or drops the citation where the surrounding text already carries
the meaning.

The MMP report group needed more than a rewording. It claimed the payload
content was undefined and both variants were stubs, and neither is true: the
link dispatcher routes 0x01 and 0x02 to real handlers, and both report types
implement encode and decode. The group comment now names the types, and the
two stale "(stub)" doc comments below it are corrected with it.
This commit is contained in:
Johnathan Corgan
2026-08-16 06:37:21 +00:00
parent 19d8537e97
commit b2ad24363f
11 changed files with 20 additions and 23 deletions
+1 -1
View File
@@ -299,7 +299,7 @@ async fn main() {
}
};
// Install inbound port-forward rules (TASK-2026-0061).
// Install inbound port-forward rules.
if let Err(e) = nat_mgr.set_port_forwards(&gw_config.port_forwards) {
error!(error = %e, "Failed to install port-forward rules");
let _ = nat_mgr.cleanup();
+1 -1
View File
@@ -76,7 +76,7 @@ pub struct GatewayConfig {
#[serde(default)]
pub conntrack: ConntrackConfig,
/// Inbound mesh port forwarding rules. See TASK-2026-0061.
/// Inbound mesh port forwarding rules.
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub port_forwards: Vec<PortForward>,
}
+4 -5
View File
@@ -68,8 +68,7 @@ const PUB_FILENAME: &str = "fips.pub";
/// Recognizes IPv4 `127.x.x.x`, IPv6 `::1` (with or without brackets), and
/// the literal string `localhost`. Hostnames are conservatively assumed to
/// be non-loopback. Used by `Config::validate()` to reject misconfigured
/// loopback UDP binds combined with non-loopback peer addresses (see
/// ISSUE-2026-0005).
/// loopback UDP binds combined with non-loopback peer addresses.
fn is_loopback_addr_str(addr: &str) -> bool {
// Bracketed IPv6: `[::1]:port`
if let Some(rest) = addr.strip_prefix('[')
@@ -896,9 +895,9 @@ impl Config {
// Reject loopback UDP bind combined with non-loopback peer addresses.
// Linux pins the source IP to a loopback-bound socket, so packets
// sent from such a socket to external peers are dropped at the
// routing layer with no clear error in the daemon log. See
// ISSUE-2026-0005. Outbound-only mode is exempt because it
// overrides bind_addr to 0.0.0.0:0 (kernel-picked source).
// routing layer with no clear error in the daemon log.
// Outbound-only mode is exempt because it overrides bind_addr to
// 0.0.0.0:0 (kernel-picked source).
for (name, cfg) in self.transports.udp.iter() {
if cfg.outbound_only() {
continue;
+1 -1
View File
@@ -103,7 +103,7 @@ pub struct UdpConfig {
/// unfamiliar addresses. The Node-level gate at
/// `src/node/handlers/handshake.rs` carves out msg1 from peers
/// already established on this transport (so rekey continues to
/// work) — see ISSUE-2026-0004.
/// work).
#[serde(default, skip_serializing_if = "Option::is_none")]
pub accept_connections: Option<bool>,
}
+1 -2
View File
@@ -128,8 +128,7 @@ fn log_refusals(tally: &PunchTargetTally, peer: &str, session: &str) {
/// `BootstrapEvent::Established` events and `adopt_established_traversal` keeps
/// only the first on a non-deterministic race; when the two nodes' independent
/// races resolve to mismatched sessions, each side's Noise msg1 lands on a peer
/// port the peer already stopped draining and both handshakes stall (root cause
/// of ISSUE-2026-0031).
/// port the peer already stopped draining and both handshakes stall.
///
/// To collapse the four-socket dance to a single, guaranteed-matching socket
/// pair, both nodes deterministically keep the session **initiated by the
+2 -2
View File
@@ -66,7 +66,7 @@ pub struct NatManager {
lan_interface: String,
/// Active mappings keyed by virtual IP.
mappings: HashMap<Ipv6Addr, NatMapping>,
/// Inbound port-forward rules (TASK-2026-0061).
/// Inbound port-forward rules.
port_forwards: Vec<PortForward>,
}
@@ -235,7 +235,7 @@ impl NatManager {
batch.add(&snat_rule, MsgType::Add);
}
// Inbound port-forward rules (TASK-2026-0061). Each forward is
// Inbound port-forward rules. Each forward is
// one DNAT rule in prerouting keyed on (iif fips0, nfproto ipv6,
// l4proto, th dport). When any forwards are configured, emit a
// single LAN-side masquerade in postrouting so the LAN target
-2
View File
@@ -1322,8 +1322,6 @@ impl Node {
/// Returning the smallest (rather than the first-iterated, which used
/// to vary across HashMap iteration order + async-startup race) makes
/// the clamp deterministic across daemon restarts.
///
/// See `ISSUE-2026-0011` for the empirical investigation.
pub fn transport_mtu(&self) -> u16 {
let min_operational = self
.transports
+3 -2
View File
@@ -997,7 +997,7 @@ async fn test_should_admit_msg1_rejects_fresh_when_accept_off() {
assert!(!node.should_admit_msg1(transport_id, &addr));
}
/// ISSUE-2026-0004 regression test: `should_admit_msg1` admits rekey/restart
/// Regression test: `should_admit_msg1` admits rekey/restart
/// msg1 from a peer with an existing link even when the transport has
/// accept_connections=false. Without this, the dual-init tie-breaker
/// deadlocks (the larger-NodeAddr side drops the winner's rekey msg1).
@@ -1069,7 +1069,8 @@ async fn test_should_admit_msg1_admits_rekey_when_udp_accept_off() {
}
/// Regression test for the udp.outbound_only rekey loop observed in
/// production 2026-04-30 (parallel to ISSUE-2026-0004).
/// production 2026-04-30 (parallel to the rekey/restart admission case
/// above).
///
/// Production scenario: nomad runs `udp.outbound_only=true` with peer
/// core-vm configured by hostname (`core-vm.tail65015.ts.net:2121`).
+2 -2
View File
@@ -1404,7 +1404,7 @@ async fn test_initiate_peer_connections_schedules_retry_on_no_transport() {
}
// ============================================================================
// transport_mtu() — ISSUE-2026-0011 regression coverage
// transport_mtu() — minimum-across-transports regression coverage
// ============================================================================
/// Helper: spawn a UdpTransport with the given mtu, started and operational.
@@ -1429,7 +1429,7 @@ async fn make_udp_transport_with_mtu(id: u32, mtu: u16) -> TransportHandle {
async fn test_transport_mtu_returns_min_across_operational() {
// Multiple operational transports with varied MTUs. The picker must
// return the smallest, deterministically, regardless of HashMap
// iteration order. This is the core ISSUE-2026-0011 regression test.
// iteration order. This is the core regression test for that.
let mut node = make_node();
let (packet_tx, packet_rx) = packet_channel(64);
node.packet_tx = Some(packet_tx);
+3 -3
View File
@@ -73,10 +73,10 @@ pub enum LinkMessageType {
/// Payload is opaque to intermediate nodes (end-to-end encrypted).
SessionDatagram = 0x00,
// MMP reports (0x01-0x02) — content defined in TASK-2026-0006
/// Sender-side MMP report (stub).
// MMP reports (0x01-0x02) — payload is an encoded SenderReport or ReceiverReport
/// Sender-side MMP report.
SenderReport = 0x01,
/// Receiver-side MMP report (stub).
/// Receiver-side MMP report.
ReceiverReport = 0x02,
// Tree protocol (0x10-0x1F)
+2 -2
View File
@@ -419,8 +419,8 @@ impl Transport for UdpTransport {
/// Whether the transport accepts inbound handshake initiations.
/// `outbound_only` mode forces this to false; otherwise reflects the
/// `accept_connections` config field (default: true). Note that the
/// hard gate is at the Node level (see ISSUE-2026-0004 fix in
/// `src/node/handlers/handshake.rs`); this method is what that gate
/// hard gate is at the Node level (in `src/node/handlers/handshake.rs`);
/// this method is what that gate
/// consults for transports that lack runtime-state-based filtering.
fn accept_connections(&self) -> bool {
if self.config.outbound_only() {