EnrolReply.TryAgain: while the mesh says it cannot answer (its store restarting), the host asks again with the same request — the same keys — every few seconds for up to two minutes, then says to wait that long and run enrol again, and to issue a new token if it is refused. answered() decides, tested.
EnrolRequest.Proof: the host signs EnrolProof(secret, public, overlay, sealing, serving) with the identity key it just generated. The mesh requires it before letting an enrolment finish on a token that key already spent, so a leaked token plus a public key cannot replay it. The signed bytes have a known answer repeated in mesh-controller's test.
The installer no longer says a token "has now been spent" when it may not have been.
Suite green. Proof: mesh-lab store-window bed green. Reviewed independently three times. Companion MRs on multiple-fixes: mesh-controller, mesh-lab, hq.
- `EnrolReply.TryAgain`: while the mesh says it cannot answer (its store restarting), the host asks again with the same request — the same keys — every few seconds for up to two minutes, then says to wait that long and run enrol again, and to issue a new token if it is refused. `answered()` decides, tested.
- `EnrolRequest.Proof`: the host signs `EnrolProof(secret, public, overlay, sealing, serving)` with the identity key it just generated. The mesh requires it before letting an enrolment finish on a token that key already spent, so a leaked token plus a public key cannot replay it. The signed bytes have a known answer repeated in mesh-controller's test.
- The installer no longer says a token "has now been spent" when it may not have been.
Suite green. Proof: mesh-lab store-window bed green. Reviewed independently three times. Companion MRs on `multiple-fixes`: mesh-controller, mesh-lab, hq.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
EnrolReply.TryAgain: while the mesh says it cannot answer (its store restarting), the host asks again with the same request — the same keys — every few seconds for up to two minutes, then says to wait that long and run enrol again, and to issue a new token if it is refused.answered()decides, tested.EnrolRequest.Proof: the host signsEnrolProof(secret, public, overlay, sealing, serving)with the identity key it just generated. The mesh requires it before letting an enrolment finish on a token that key already spent, so a leaked token plus a public key cannot replay it. The signed bytes have a known answer repeated in mesh-controller's test.Suite green. Proof: mesh-lab store-window bed green. Reviewed independently three times. Companion MRs on
multiple-fixes: mesh-controller, mesh-lab, hq.