Stop shipping a relay that is not there - #59
Merged
Merged
Conversation
The hosted relay is closed. `DEFAULT_SERVER` is deleted rather than repointed, because a default naming a host that no longer answers is worse than no default at all: it turns "you have not configured a relay" into a TLS failure against somebody else's DNS, at a hostname this project no longer controls. Entry 8 is the reason it cannot simply be corrected in place. It argued for a stable API hostname precisely because the value is compiled in — so every binary already installed keeps reaching for it until its owner installs a new one. What entry 8 wanted, it can no longer have; the honest response is to stop shipping a guess. Recorded as decisions.md entry 16, which supersedes entry 8 rather than rewriting it. What this changes for a person: - `--server` and `DROP_SERVER` have no default. Unset, and empty, both mean no relay. - `--transport relay` without one is an error, raised before the payload is read, because being told the relay is missing is worth nothing after a wait to compress a directory. - `auto` without one is peer-to-peer that says so rather than falling back to nowhere. `may_fall_back` now takes the configured relay so it can tell *no relay configured* from *`--transport p2p` forbids falling back* — they were one branch before, and a person who never asked for `p2p` should not be told their transport forbids a fallback they did not choose. It also costs the one thing the relay was still for: a browser cannot speak QUIC and can only meet a CLI at a relay, so browser transfers now need an operator to run one. Stated in `--help` rather than discovered. The help's OPTIONS block is regrouped while it is being edited. It listed `-h` and `-V`, which work alone, beside `-s` and `-t`, which do not, with no way to tell them apart — so `drop -s` answered "unknown command `-s`" about an option that exists. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The hosted relay is closed.
DEFAULT_SERVERis deleted rather than repointed, because a default naming a host that no longer answers is worse than no default: it turns "you have not configured a relay" into a TLS failure against somebody else's DNS, at a hostname this project no longer controls.Entry 8 is why it cannot simply be corrected in place. It argued for a stable API hostname precisely because the value is compiled in — so every already-installed binary keeps reaching for it until its owner installs a new one. What entry 8 wanted, it can no longer have. Recorded as
decisions.mdentry 16, which supersedes entry 8 rather than rewriting it: the reasoning is still the record of why the API host was named separately, and still the shape for anyone self-hosting.What changes for a person
--serverandDROP_SERVERhave no default. Unset, and empty, both mean no relay.--transport relaywithout one is an error, raised before the payload is read — being told the relay is missing is worth nothing after a wait to compress a directory.autowithout one is peer-to-peer that says so, rather than falling back to nowhere.may_fall_backnow takes the configured relay so it can distinguish no relay configured from--transport p2pforbids falling back. Those were one branch before, and a person who never asked forp2pshould not be told their transport forbids a fallback they did not choose.The cost, stated rather than hidden
A browser cannot speak QUIC and can only meet a CLI at a relay, so browser transfers now need an operator to run one. That is in
--help.The README headline also changes. It claimed a relay fallback "for browsers and uncooperative NATs" — the first half now needs a relay you run, and the second was never the Drop relay's job: iroh carries the connection over n0's relay when two peers cannot punch.
AGENTS.mdforbids a headline claiming what only one path delivers, so the new text says "no Drop server" and names what the direct path still depends on.Help regrouping
The
OPTIONSblock listed-hand-V, which work alone, beside-sand-t, which do not, with no way to tell them apart — sodrop -sansweredunknown command \-s`` about an option that exists. Options are now grouped by the command they belong to.Verification
Full workspace suite,
clippy --all-targets,fmt,check-secrets.sh— all pass. Verified by hand that both relay-missing errors fire, and thatDROP_SERVER=counts as unset.🤖 Generated with Claude Code