Skip to content

moq-net: anonymous peers each get a random origin, so an anonymous subscriber cannot resolve an anonymous publisher's broadcast (regression in #3042) #3588

Description

@riedlse

Since 4cb5fc2 ("fix(net): assign anonymous server peers an origin", #3042), a relay that
allows anonymous publish and anonymous subscribe can no longer connect the two: a SUBSCRIBE
from one anonymous session for a broadcast announced by a different anonymous session is
rejected with 404 dropped.

Bisected to 4cb5fc2 over the 139 commits in 260a3a47..fd477082, 7 steps, no skips.

Repro

ghcr.io/eyevinn/mlmtest:latest (moqlivemock 0.14.0, draft-18) against moq-relay with
anonymous subscribe on the root path:

MOQ_AUTH_KEY=auth.jwk MOQ_AUTH_PUBLIC_SUBSCRIBE="" \
moq-relay --server-bind 0.0.0.0:4443 --web-http-listen 0.0.0.0:4443 \
          --tls-cert tls.crt --tls-key tls.key
ok 1 - setup-only
ok 2 - announce-only
ok 3 - publish-namespace-done
ok 4 - subscribe-error
not ok 5 - announce-subscribe
  error: SUBSCRIBE: request rejected: unknown request error code: 0x194: dropped
not ok 6 - subscribe-before-announce
  error: subscriber timed out (neither OK nor ERROR received)
rev result
260a3a4 6/6
4cb5fc2^ (356df39) 6/6
4cb5fc2 4/6
fd47708 4/6
7bcee5d 4/6

Tests 1–4 pass because none of them cross two anonymous sessions; 5 and 6 are the two that do.

Mechanism

Before #3042 an anonymous peer carried peer_origin: None. The commit assigns each request a
fresh crate::Origin::random() in rs/moq-net/src/server.rs, and with_peer_origin's own
doc comment gives the contract:

Two sessions given the same origin are treated as one endpoint: routes learned from either
are kept off both, and content arriving on either is interchangeable with the other's.

A random origin per session makes every anonymous connection a distinct endpoint, so the
announce from the publisher session is not resolvable from the subscriber session. The 404
comes out of rs/moq-net/src/ietf/publisher.rs:546, carrying Error::Dropped as the reason.

The intent of #3042 looks right for cluster loop-prevention — the issue is that an
unauthenticated peer has no established identity, and giving it a unique one makes it its own
island. Two anonymous sessions to the same relay probably want the same (or no) origin.

Impact

This is currently costing 8 cells in the nightly interop matrix (imquic, moq-playa,
moqlivemock, moqtopus, xquic-draft-18 against our relay went 6/6 → 4/6 the night we picked up
the bump). Happy to test a patch against the same harness.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    questBeing tracked/planned in a quest. See `quest/`

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions