Add Network::probe_address for non-disruptive reachability + identity probing - #75
Merged
Merged
Conversation
aschran
marked this pull request as ready for review
June 23, 2026 22:14
bmwill
approved these changes
Jun 24, 2026
8 tasks
aschran
added a commit
to MystenLabs/sui
that referenced
this pull request
Jul 14, 2026
…27124) ## Description Validators have no signal today when a peer advertises an unreachable address (e.g. a wrong external address gossiped via discovery), which silently degrades connectivity. This adds a prober that runs on validators and periodically checks whether each trusted peer's advertised P2P and consensus addresses are actually reachable, exposing the results as Prometheus metrics plus an admin endpoint that dumps full per-address detail for operators to act on. Bumps `anemo` to MystenLabs/anemo#75 for the non-disruptive `Network::probe_address` the P2P check uses. ## Test plan New `discovery_tests` sim tests cover the core differential (a validator's real address probes reachable, its bad gossiped address does not), plus no-false-positives and reconfiguration cleanup cases. --- ## Release notes Check each box that your changes affect. If none of the boxes relate to your changes, release notes aren't required. For each box you select, include information after the relevant heading that describes the impact of your changes that a user might notice and any actions they must take to implement updates. - [ ] Protocol: - [ ] Nodes (Validators and Full nodes): - [ ] gRPC: - [ ] JSON-RPC: - [ ] GraphQL: - [ ] CLI: - [ ] Rust SDK: - [ ] Indexing Framework:
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds
Network::probe_address(addr, expected_peer_id) -> ProbeOutcome: a short-lived QUIC+TLS connection that verifies reachability + identity, then closes. It bypasses the connection manager (and its peer-id dedup) entirely.Probes are identified with a dedicated probe server-name (SNI),
anemo-probe.Tests
New unit tests cover identity match, identity mismatch, unreachable address, and — most importantly — that probing a peer with an existing connection does not disrupt it (no
LostPeerevent, peer stays connected, RPC still works).