server: self-test — sysctl audit + egress-MTU self-proof ("server proven good")
A measurement server must prove its own host isn't distorting results:
- sysctl audit (/proc/sys): flags accept_ra on a static host, ICMP
redirects, ICMP rate-limiting of the server's own errors, and disabled
TCP options — each a measurement-fidelity hazard, with the "why".
- egress-MTU self-proof: DF PMTUD probe (IP_MTU_DISCOVER + getsockopt
IP_MTU, no root — Linux-only, stub elsewhere) to external anchors. If the
server's own uplink is below 1500, client MTU tests measure THIS server,
so we say so.
Exposed at GET /admin/selftest (full report) and as server_selftest
{mtu_ok, sysctl_ok} in the profile so clients can trust or skip MTU tests.
Recommended deploy/99-echolot-sysctl.conf + README section.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
c9e0d06ea2
commit
4ae744aae5
@@ -53,6 +53,11 @@ type Server struct {
|
||||
CanaryQueries func(sessionPrefix string) any
|
||||
// CanaryZone is surfaced in the profile so the app knows what to query.
|
||||
CanaryZone string
|
||||
// ProvenGood reports the server's self-test signal (may be nil). Surfaced
|
||||
// in the profile so a client can trust — or skip — MTU tests: if the
|
||||
// server's own egress isn't full-MTU, client MTU results measure the
|
||||
// server, not the client.
|
||||
ProvenGood func() (mtuOK, sysctlOK bool)
|
||||
}
|
||||
|
||||
func (s *Server) Handler() http.Handler {
|
||||
@@ -78,6 +83,16 @@ func (s *Server) EchoHandler() http.Handler {
|
||||
return mux
|
||||
}
|
||||
|
||||
// selftestSignal is the compact "server proven good" object for the profile.
|
||||
// mtu_ok=false tells a client its MTU results would measure this server.
|
||||
func selftestSignal(f func() (bool, bool)) map[string]any {
|
||||
if f == nil {
|
||||
return map[string]any{"mtu_ok": nil, "sysctl_ok": nil}
|
||||
}
|
||||
mtuOK, sysctlOK := f()
|
||||
return map[string]any{"mtu_ok": mtuOK, "sysctl_ok": sysctlOK}
|
||||
}
|
||||
|
||||
// sessionAuth resolves {id} and requires the bearer to be the owning device.
|
||||
func (s *Server) sessionAuth(w http.ResponseWriter, r *http.Request) *session.Session {
|
||||
dev := s.Store.DeviceByCredential(bearer(r))
|
||||
@@ -264,10 +279,11 @@ func (s *Server) profile(w http.ResponseWriter, r *http.Request) {
|
||||
"tcp_port": s.TCPPort,
|
||||
"stun_port": s.StunPort,
|
||||
}},
|
||||
"pins": []string{"pin-sha256:" + s.PinB64},
|
||||
"next_pins": []string{},
|
||||
"canary_zone": s.CanaryZone,
|
||||
"limits": map[string]any{"max_kbps": 50000, "max_session_s": 900},
|
||||
"pins": []string{"pin-sha256:" + s.PinB64},
|
||||
"next_pins": []string{},
|
||||
"canary_zone": s.CanaryZone,
|
||||
"server_selftest": selftestSignal(s.ProvenGood),
|
||||
"limits": map[string]any{"max_kbps": 50000, "max_session_s": 900},
|
||||
})
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user