Protocol v2: trusted-peer push, truthful partials, split downloads

Three capabilities the iroh-blobs 0.103 line makes possible:

- Push (new API surface, protocol v2): `Push { hash, node_id }` hands
  fully-present content to a trusted peer, unprompted. Consent is
  mutual — the sender pushes only to peers it trusts, and the receiver
  (which now accepts connections unconditionally and gates per request)
  admits pushes only from peers *it* trusts, deferring with RateLimited
  while metered. An accepted push is pinned by the receiver (default
  policy, format inferred from the request ranges) once its transfer
  completes, and surfaces as a PushReceived event. Because QUIC writes
  are fire-and-forget, the sender confirms delivery by observing the
  receiver's bitfields (root + last hashseq child) before replying —
  Pushed { bytes } means verified received, not merely sent. New
  varde-ctl `push` command.

- Truthful partial presence: Status/List report bytes actually present
  and verified for partial blobs, from the store's bitfields via
  observe, instead of the old "0 until complete".

- Split downloads: multi-provider fetches stripe one request across
  providers (SplitStrategy::Split) instead of trying them serially.

Trusted peers may observe bitfields even when serving is disabled or
metered — bitfields are metadata, and push confirmation rides on them.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Bendik Lynghaug
2026-08-16 14:52:27 +02:00
co-authored by Claude Fable 5
parent ad69f7d884
commit 4033c0ffab
9 changed files with 474 additions and 33 deletions
+7 -3
View File
@@ -330,9 +330,13 @@ impl BlobStore {
pub async fn presence(&self, hash: Hash) -> Result<(u64, Option<u64>, bool), OpError> {
match self.store.blobs().status(hash).await.map_err(internal)? {
BlobStatus::NotFound => Ok((0, None, false)),
// Valid-range accounting for partials arrives with the
// transfer milestone; absence of data is the safe report.
BlobStatus::Partial { size } => Ok((0, size, false)),
BlobStatus::Partial { size } => {
// Chunk-accurate accounting from the store's bitfield:
// report the bytes actually present and verified.
let bitfield = self.store.blobs().observe(hash).await.map_err(internal)?;
let total = bitfield.validated_size().or(size);
Ok((bitfield.total_bytes().min(total.unwrap_or(u64::MAX)), total, false))
}
BlobStatus::Complete { size } => Ok((size, Some(size), true)),
}
}