Test Details Overview

Add peer blocklist by node id and address (#5200)

* Add peer blocklist container

Node ids and IP addresses this node refuses to connect with, kept in a
thread-safe set. IPv4 addresses are stored in the v4 mapped IPv6 form
peers are seen with, so an entry matches however the address is
spelled. Nothing consults the container yet.

* Refuse blocklisted peers

Addresses are refused by the listener before a connection is made, in
both directions, and by reachout tracking, so no attempt is recorded
for them. Node ids are refused where channels are created, once the
handshake has proven the id, so a blocklisted peer never gets a channel
either way. Rejections are counted under the blocklisted stat and a
refused outbound connect reports peer_blocklisted.

* Drop connected peers once they are blocklisted

An entry added while its peer is connected takes effect at the next
connection cleanup, which closes every channel whose node id or
address is blocklisted, counted under tcp_channels_purge. The peer is
then refused when it reconnects.

* Load the peer blocklist from its own config file

The list lives in peer-blocklist.toml in the data directory, separate
from the node config so it can be maintained and shared on its own. A
single [blocklist] table holds the node_ids and ip_addresses lists,
and the file is read through the common config loader by the daemon
and the wallet. An entry that is not a node id or an IP address, or a
list that is not an array of strings, stops the node from starting
with an error naming the file and the entry. The node reports the
loaded counts at startup and --generate_config blocklist prints a
template.

__________

Type: commit

Hash: f32f120a326ac6eab41c442f81bd7b9b18c2b0da

Created: today

__________

gr0v1ty/nano-node:f32f120a326ac6eab41c442f81bd7b9b18c2b0da

Test Results

Test Case Status Duration Median Deviation Log Graph
5n4pr_conf_10k_bintree PASS 120 s 5.0 s - Show
5n4pr_conf_10k_change PASS 145 s -2.0 s - Show
5n4pr_conf_change_dependant PASS 119 s 4.5 s - -
5n4pr_conf_change_independant PASS 119 s 1.5 s - -
5n4pr_conf_send_dependant PASS 108 s -7.5 s - -
5n4pr_conf_send_independant PASS 109 s -6.0 s - -
5n4pr_rocks_10k_bintree PASS 120 s 2.0 s - -
5n4pr_rocks_10k_change PASS 170 s 3.0 s - -