Files
fips/src/upper
Johnathan Corgan d246f84da5 Rebuild alias name resolution and ACL alias entries when the peer list is replaced at runtime
Node::update_peers replaced the configured peer list but left every map
that reads peer aliases as it was at startup. Each hosts map (the display
map, the peer ACL's alias resolution and the .fips DNS responder's map)
kept the startup aliases as a fixed base and only re-merged the hosts file
over it. After an update, a new peer's alias did not resolve as a .fips
name or match an ACL entry naming it, a removed or moved alias kept
resolving to the old npub, and a deny entry written as an alias that moved
to another key kept denying the old key while admitting the new one. A
kept peer whose alias was removed also kept showing the old alias as its
display name.

update_peers now rebuilds the alias base from the new peer list and hands
it to all three maps: the display map directly, the peer ACL through a
forced rebuild that runs before any added peer is dialed, and the running
DNS responder through a watch channel it checks before each answer. Each
map keeps the hosts file as last read, so the file stays merged on top and
still wins, including edits picked up at runtime. The kept peer's display
name falls back to its short npub when its alias is removed.

run_dns_responder keeps its signature. This reaches only embedders that
call Node::update_peers.
2026-09-26 18:59:43 +00:00
..
2026-08-15 07:56:54 +00:00