Repository navigation
[fix] Re-probe reachability while the relay is firewalled - #16
Merged
Merged
Conversation
dht-rpc probes once at bootstrap and skips its periodic re-check while the public host is unchanged, so one lost probe round left a correctly forwarded relay firewalled until restart. Re-run the probe while firewalled, from 1 minute backing off to 15, and keep the firewalled gauge current.
This was referenced Sep 20, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The bug
On a live StartOS box the relay came up
firewalledafter an update and stayed that way, with the port forward, outbound gateway and public address all intact. The same box had been firewalled for 5.5 hours on 0.3.0 three days earlier, and both times a plain restart fixed it.The cause is in
dht-rpc. It probes reachability once at bootstrap (_checkIfFirewalled: up to 5 nodes are asked to ping the server port, and fewer than 3 replies counts as firewalled). Its periodic re-check is then guarded by:so while the public host is unchanged it never probes again. One lost round in the first seconds after a restart is permanent until the next one.
The fix
src/reprobe.jsre-runsdht._updateNetworkState()— the same call dht-rpc's own tick makes, minus the same-host guard — while the node is firewalled: after 1 minute, doubling to a 15-minute ceiling, and stopping for good once a probe passes. It updatesrelay_dht_firewalled, which was previously only set at startup, and logsreachability re-probe passed.It is not started under
MIRALL_RELAY_ASSUME_REACHABLE. The hook is dht-rpc internals, so its absence degrades to a single warning and no self-heal; nothing else depends on it.Testing
test/unit/reprobe.test.js: never probes a reachable node; retries until a probe passes, then schedules nothing; backoff sequence and ceiling; a throwing probe does not end the retries;stop()cancels pending and in-flight work; a missing hook is a no-op with one warning.dht-rpc6.27.0 on a NAT'd machine: the hook exists, each re-probe performs a real ~4 s ping round, and the node correctly stays firewalled where there is no forward.npm run lintclean,npm test408/408.