Control frames carry no NETWORK_ID, so three things can tell two OPENBRIDGE bridges apart: a legacy port of their own, a passphrase of their own, or a source address that matches what one of them is configured with. Any one is enough. Sharing the fan-in port and a passphrase leaves only the address, and a frame from an address none of them knows then goes to whichever bridge was registered first — the misattribution behind #79 and #87. Nothing said so. The validator checks duplicate NETWORK_IDs and duplicate legacy ports, but treats PASSPHRASE as just another string. openbridge_passphrase_collisions() groups the enabled OPENBRIDGE systems that share one, and returns the names only, never the secret. It surfaces as a warn finding in --doctor and as a line at startup next to the fan-in summary. Kept advisory on purpose: a shared passphrase works as long as every peer address is distinct and current, so refusing to start would stop servers that are fine today.pull/89/head
parent
427ae67889
commit
2ed5d74bc6
Loading…
Reference in new issue