Milestone 5: metered awareness, DSCP, systemd, man pages, packaging

Metered detection polls NetworkManager's Metered property over D-Bus
(feature "metered", default on; builds without D-Bus via
no-default-features). While metered the daemon closes incoming blob
connections and defers every fetch; VARDE_FORCE_METERED=true forces the
state as a kill switch and test hook. Endpoint UDP sockets get DSCP CS1
best-effort by matching bound ports to /proc/net/udp inodes (iroh hides
its fds). systemd socket activation adopts LISTEN_FDS fd 3, readiness
is a hand-rolled sd_notify READY=1 (abstract + path sockets), and
standalone binding still works unchanged. dist/ ships hardened system
and user units (DynamicUser, ProtectSystem=strict, StateDirectory,
RestrictAddressFamilies), a commented config example, scdoc man pages
validated with scdoc, and an untested PKGBUILD skeleton.

Tests: activation-socket round trip via a real fd-3 handoff, READY=1
received on a NOTIFY_SOCKET, metered daemons neither serve nor fetch.

Dependencies: zbus (optional, feature-gated D-Bus client for the
NetworkManager metered flag).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Bendik Lynghaug
2026-07-15 08:07:24 +02:00
co-authored by Claude Fable 5
parent 20bdf56668
commit 871280553e
19 changed files with 1031 additions and 5 deletions
+12 -3
View File
@@ -82,16 +82,25 @@ fn main() -> Result<()> {
async fn run(config: Config) -> Result<()> {
let socket_path = config.socket_path.clone();
let daemon = daemon::Daemon::open(config).await?;
let listener = server::bind_socket(&socket_path)?;
// Prefer a systemd activation socket; bind ourselves otherwise so
// non-systemd distros work identically.
let (listener, activated) = match server::activation_listener()? {
Some(listener) => (listener, true),
None => (server::bind_socket(&socket_path)?, false),
};
server::notify_ready();
let result = tokio::select! {
r = server::serve(listener, daemon.clone()) => r,
r = shutdown_signal() => r.map(|signal| info!(signal, "shutting down")),
};
// Close the endpoint, flush the store, remove the socket.
// Close the endpoint and flush the store. The socket file is ours to
// remove only when we bound it (systemd owns activation sockets).
daemon.shutdown().await;
let _ = std::fs::remove_file(&socket_path);
if !activated {
let _ = std::fs::remove_file(&socket_path);
}
result
}