mirror of
https://github.com/jmcorgan/fips.git
synced 2026-07-30 19:46:15 +00:00
Merge branch 'maint'
# Conflicts: # CHANGELOG.md
This commit is contained in:
@@ -99,6 +99,14 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
|
|||||||
Subscribe retries with exponential backoff (2 s base, 60 s cap),
|
Subscribe retries with exponential backoff (2 s base, 60 s cap),
|
||||||
publish attempts time out at 10 s, and the new tasks are aborted
|
publish attempts time out at 10 s, and the new tasks are aborted
|
||||||
cleanly on `Node::stop`.
|
cleanly on `Node::stop`.
|
||||||
|
- `node.bloom.max_inbound_fpr` default raised from `0.05` to `0.10`. The
|
||||||
|
cap rejects inbound `FilterAnnounce` whose FPR (`fill^k`) exceeds it. On
|
||||||
|
the fixed 1 KB / k=5 filter, `0.05` corresponds to fill 0.549 (~1,300
|
||||||
|
reachable entries) and had begun rejecting the busiest nodes' aggregates
|
||||||
|
as the mesh approached that size. `0.10` (fill 0.631, ~1,630 entries)
|
||||||
|
restores headroom toward the fixed-filter capacity limit without
|
||||||
|
materially weakening the antipoison gate: a saturated or poisoned filter
|
||||||
|
is ~100% FPR and still rejected.
|
||||||
- Sidecar example (`examples/sidecar-nostr-relay`): `udp.mtu` is now
|
- Sidecar example (`examples/sidecar-nostr-relay`): `udp.mtu` is now
|
||||||
overridable via the `FIPS_UDP_MTU` environment variable, defaulting to
|
overridable via the `FIPS_UDP_MTU` environment variable, defaulting to
|
||||||
1472 (preserving prior behavior). Plumbed through `docker-compose.yml`
|
1472 (preserving prior behavior). Plumbed through `docker-compose.yml`
|
||||||
|
|||||||
@@ -350,14 +350,14 @@ exposed through the control socket and `fipstop` dashboard.
|
|||||||
|
|
||||||
The estimator refuses to produce a value when any contributing filter
|
The estimator refuses to produce a value when any contributing filter
|
||||||
is above the antipoison FPR cap (`node.bloom.max_inbound_fpr`,
|
is above the antipoison FPR cap (`node.bloom.max_inbound_fpr`,
|
||||||
default `0.05`); a partial aggregate would silently underestimate.
|
default `0.10`); a partial aggregate would silently underestimate.
|
||||||
Consumers handle the resulting `None` by displaying an "unknown"
|
Consumers handle the resulting `None` by displaying an "unknown"
|
||||||
state rather than a misleading number.
|
state rather than a misleading number.
|
||||||
|
|
||||||
## Antipoison: Inbound FPR Cap
|
## Antipoison: Inbound FPR Cap
|
||||||
|
|
||||||
Inbound `FilterAnnounce` payloads are checked against
|
Inbound `FilterAnnounce` payloads are checked against
|
||||||
`node.bloom.max_inbound_fpr` (default `0.05`). Filters whose
|
`node.bloom.max_inbound_fpr` (default `0.10`). Filters whose
|
||||||
estimated false positive rate exceeds the cap are dropped silently
|
estimated false positive rate exceeds the cap are dropped silently
|
||||||
(no NACK on the wire) — they would otherwise inflate downstream
|
(no NACK on the wire) — they would otherwise inflate downstream
|
||||||
candidate evaluation cost without contributing useful discrimination.
|
candidate evaluation cost without contributing useful discrimination.
|
||||||
|
|||||||
@@ -254,7 +254,7 @@ Controls tree construction and parent selection.
|
|||||||
| Parameter | Type | Default | Description |
|
| Parameter | Type | Default | Description |
|
||||||
|-----------|------|---------|-------------|
|
|-----------|------|---------|-------------|
|
||||||
| `node.bloom.update_debounce_ms` | u64 | `500` | Debounce interval for filter update propagation |
|
| `node.bloom.update_debounce_ms` | u64 | `500` | Debounce interval for filter update propagation |
|
||||||
| `node.bloom.max_inbound_fpr` | f64 | `0.05` | Antipoison cap: reject inbound `FilterAnnounce` frames whose advertised false-positive rate exceeds this value. Valid range `(0.0, 1.0)`. The default `0.05` corresponds to fill 0.549 at k=5 (≈3,200 entries on the 1 KB filter) |
|
| `node.bloom.max_inbound_fpr` | f64 | `0.10` | Antipoison cap: reject inbound `FilterAnnounce` frames whose advertised false-positive rate exceeds this value. Valid range `(0.0, 1.0)`. The default `0.10` corresponds to fill 0.631 at k=5 (≈1,630 entries on the 1 KB filter); a saturated/poisoned filter is still ~100% FPR and rejected |
|
||||||
|
|
||||||
Bloom filter size (1 KB), hash count (5), and size classes are protocol
|
Bloom filter size (1 KB), hash count (5), and size classes are protocol
|
||||||
constants and not configurable.
|
constants and not configurable.
|
||||||
@@ -899,7 +899,7 @@ node:
|
|||||||
flap_dampening_secs: 120 # extended hold-down on flap
|
flap_dampening_secs: 120 # extended hold-down on flap
|
||||||
bloom:
|
bloom:
|
||||||
update_debounce_ms: 500
|
update_debounce_ms: 500
|
||||||
max_inbound_fpr: 0.05 # antipoison cap on inbound FilterAnnounce FPR
|
max_inbound_fpr: 0.10 # antipoison cap on inbound FilterAnnounce FPR
|
||||||
session:
|
session:
|
||||||
default_ttl: 64
|
default_ttl: 64
|
||||||
pending_packets_per_dest: 16
|
pending_packets_per_dest: 16
|
||||||
|
|||||||
+8
-5
@@ -635,9 +635,12 @@ pub struct BloomConfig {
|
|||||||
pub update_debounce_ms: u64,
|
pub update_debounce_ms: u64,
|
||||||
/// Antipoison cap: reject inbound FilterAnnounce whose FPR exceeds
|
/// Antipoison cap: reject inbound FilterAnnounce whose FPR exceeds
|
||||||
/// this value (`node.bloom.max_inbound_fpr`). Valid range `(0.0, 1.0)`.
|
/// this value (`node.bloom.max_inbound_fpr`). Valid range `(0.0, 1.0)`.
|
||||||
/// Default `0.05` ≈ fill 0.549 at k=5 ≈ ~3,200 entries on the 1KB
|
/// Default `0.10` ≈ fill 0.631 at k=5 ≈ ~1,630 entries on the 1 KB
|
||||||
/// filter. Conceptually distinct from future autoscaling hysteresis
|
/// filter (Swamidass–Baldi). Raised from 0.05 so aggregates that are
|
||||||
/// setpoints — same unit, different knobs.
|
/// legitimately near their operating ceiling are not rejected before
|
||||||
|
/// the network reaches the fixed-filter capacity limit; conceptually
|
||||||
|
/// distinct from future autoscaling hysteresis setpoints — same unit,
|
||||||
|
/// different knobs.
|
||||||
#[serde(default = "BloomConfig::default_max_inbound_fpr")]
|
#[serde(default = "BloomConfig::default_max_inbound_fpr")]
|
||||||
pub max_inbound_fpr: f64,
|
pub max_inbound_fpr: f64,
|
||||||
}
|
}
|
||||||
@@ -646,7 +649,7 @@ impl Default for BloomConfig {
|
|||||||
fn default() -> Self {
|
fn default() -> Self {
|
||||||
Self {
|
Self {
|
||||||
update_debounce_ms: 500,
|
update_debounce_ms: 500,
|
||||||
max_inbound_fpr: 0.05,
|
max_inbound_fpr: 0.10,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -656,7 +659,7 @@ impl BloomConfig {
|
|||||||
500
|
500
|
||||||
}
|
}
|
||||||
fn default_max_inbound_fpr() -> f64 {
|
fn default_max_inbound_fpr() -> f64 {
|
||||||
0.05
|
0.10
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user