Since 4cb5fc2 ("fix(net): assign anonymous server peers an origin", #3042), a relay that
allows anonymous publish and anonymous subscribe can no longer connect the two: a SUBSCRIBE
from one anonymous session for a broadcast announced by a different anonymous session is
rejected with 404 dropped.
Bisected to 4cb5fc2 over the 139 commits in 260a3a47..fd477082, 7 steps, no skips.
Repro
ghcr.io/eyevinn/mlmtest:latest (moqlivemock 0.14.0, draft-18) against moq-relay with
anonymous subscribe on the root path:
MOQ_AUTH_KEY=auth.jwk MOQ_AUTH_PUBLIC_SUBSCRIBE="" \
moq-relay --server-bind 0.0.0.0:4443 --web-http-listen 0.0.0.0:4443 \
--tls-cert tls.crt --tls-key tls.key
ok 1 - setup-only
ok 2 - announce-only
ok 3 - publish-namespace-done
ok 4 - subscribe-error
not ok 5 - announce-subscribe
error: SUBSCRIBE: request rejected: unknown request error code: 0x194: dropped
not ok 6 - subscribe-before-announce
error: subscriber timed out (neither OK nor ERROR received)
Tests 1–4 pass because none of them cross two anonymous sessions; 5 and 6 are the two that do.
Mechanism
Before #3042 an anonymous peer carried peer_origin: None. The commit assigns each request a
fresh crate::Origin::random() in rs/moq-net/src/server.rs, and with_peer_origin's own
doc comment gives the contract:
Two sessions given the same origin are treated as one endpoint: routes learned from either
are kept off both, and content arriving on either is interchangeable with the other's.
A random origin per session makes every anonymous connection a distinct endpoint, so the
announce from the publisher session is not resolvable from the subscriber session. The 404
comes out of rs/moq-net/src/ietf/publisher.rs:546, carrying Error::Dropped as the reason.
The intent of #3042 looks right for cluster loop-prevention — the issue is that an
unauthenticated peer has no established identity, and giving it a unique one makes it its own
island. Two anonymous sessions to the same relay probably want the same (or no) origin.
Impact
This is currently costing 8 cells in the nightly interop matrix (imquic, moq-playa,
moqlivemock, moqtopus, xquic-draft-18 against our relay went 6/6 → 4/6 the night we picked up
the bump). Happy to test a patch against the same harness.
Since 4cb5fc2 ("fix(net): assign anonymous server peers an origin", #3042), a relay that
allows anonymous publish and anonymous subscribe can no longer connect the two: a SUBSCRIBE
from one anonymous session for a broadcast announced by a different anonymous session is
rejected with 404
dropped.Bisected to 4cb5fc2 over the 139 commits in
260a3a47..fd477082, 7 steps, no skips.Repro
ghcr.io/eyevinn/mlmtest:latest(moqlivemock 0.14.0, draft-18) againstmoq-relaywithanonymous subscribe on the root path:
Tests 1–4 pass because none of them cross two anonymous sessions; 5 and 6 are the two that do.
Mechanism
Before #3042 an anonymous peer carried
peer_origin: None. The commit assigns each request afresh
crate::Origin::random()inrs/moq-net/src/server.rs, andwith_peer_origin's owndoc comment gives the contract:
A random origin per session makes every anonymous connection a distinct endpoint, so the
announce from the publisher session is not resolvable from the subscriber session. The 404
comes out of
rs/moq-net/src/ietf/publisher.rs:546, carryingError::Droppedas the reason.The intent of #3042 looks right for cluster loop-prevention — the issue is that an
unauthenticated peer has no established identity, and giving it a unique one makes it its own
island. Two anonymous sessions to the same relay probably want the same (or no) origin.
Impact
This is currently costing 8 cells in the nightly interop matrix (imquic, moq-playa,
moqlivemock, moqtopus, xquic-draft-18 against our relay went 6/6 → 4/6 the night we picked up
the bump). Happy to test a patch against the same harness.