Add manual signed peer card exchange

This commit is contained in:
Eric Wendland 2026-05-18 04:03:52 +02:00
commit 1ab24631cd
14 changed files with 360 additions and 25 deletions

View file

@ -96,10 +96,12 @@ geth-to-geth connections without granting trust from discovery alone.
- `[ ]` Signed peer-card LAN discovery payloads.
Acceptance criteria:
- The daemon can advertise and discover signed geth peer cards over LAN
- `[x]` Manual `geth peer export/import/list` can exchange signed peer cards
and store them as untrusted candidates.
- `[ ]` The daemon can advertise and discover signed geth peer cards over LAN
discovery.
- LAN-discovered peer cards are stored only as untrusted peer candidates.
- Discovered EndpointIDs do not grant module access without keychain/auth
- `[x]` Imported peer cards are stored only as untrusted peer candidates.
- `[x]` Discovered EndpointIDs do not grant module access without keychain/auth
validation.
- `[x]` Protocol/router scaffold.
@ -112,6 +114,8 @@ geth-to-geth connections without granting trust from discovery alone.
Acceptance criteria:
- A peer card contains node ID, agent ID, endpoint candidates, timestamp, and
signature metadata.
- Peer-card signatures cover deterministic canonical payloads and reject
tampered endpoint candidates.
- Peer cards are stored in `peer_cards`.
- Invalid or unsigned peer cards do not update trust state.