This repository has been archived on 2026-08-30. You can view files and clone it. You cannot open issues or pull requests or push a commit.
Files
varde/README.md
T
bl ad69f7d884 Migrate to iroh 1.0 and iroh-blobs 0.103
The 0.35 pin's rationale ("the post-0.35 rewrite is not yet production
quality") expired when iroh hit 1.0 in June 2026: the rewrite line
(0.103) is now the production line and the only one receiving fixes.

The rewrite replaced wrappable store traits with an irpc-based API, so
the seams moved:

- shaped.rs: the 440-line ShapedStore trait wrapper becomes a provider
  event handler. Trust gating (untrusted peers see only openly-served
  hashes) now intercepts requests before any bytes move; upload rate
  limiting rides the provider's Throttle hook; upload progress events
  come from per-request update streams. The TokenBucket is unchanged.
- store.rs: FsStore's API handle replaces the store traits, and the
  LocalPool machinery for non-Send futures is gone. GC is now the
  store's built-in periodic mark-and-sweep, fed by a pin-roots snapshot
  via the protect callback (new config knob gc_interval_secs, default
  300); the on-demand Gc request answers Unimplemented, and the gc
  conformance test polls the sweep instead.
- transfer.rs: BlobsProtocol + Router replace handle_connection, the
  new multi-provider Downloader replaces the old queue, and mdns
  discovery moved to the iroh-mdns-address-lookup crate (it left iroh
  core in 1.0). Ticket-embedded provider addresses feed a MemoryLookup
  address book. Endpoint presets: Minimal (LAN-only default) or N0
  (wan_upload), preserving the old relay posture.
- Node* became Endpoint* throughout; announcement signatures use iroh's
  own Signature type (ed25519-dalek dep dropped); iroh-io dropped.

Known regression: max_download_bytes_per_sec is currently not enforced
— download shaping rode the old store's batch writer and 0.103's
downloader has no equivalent seam yet.

Announcement wire format note: EndpointAddr serializes differently than
NodeAddr, so pre- and post-migration daemons won't parse each other's
LAN announcements. Announcements are live-only, nothing stored breaks.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-16 14:03:15 +02:00

67 lines
2.4 KiB
Markdown

# varde
A small, boring, distro-packageable Linux daemon that owns a
content-addressed blob store and mirrors content between consenting
peers, built on [iroh](https://iroh.computer) (iroh 1.0, iroh-blobs 0.103).
Applications talk to it over a unix socket: "add this path", "pin this
hash", "materialize hash X at path Y". Think: what Windows Delivery
Optimization is for updates — generalized, open, legible.
*varde* (Norwegian): a stone cairn used as a waypoint.
## Design ethos
- **Infrastructure, not product.** No GUI, no self-updater. A daemon, a
CLI, a JSON-lines socket protocol, man pages, systemd units.
- **Legible to the network.** Identifiable mDNS advertisement, DSCP CS1
marking, conservative rate limits (10 MiB/s up default), LAN-only with
zero WAN upload by default, all transfers stop on metered connections.
- **Consent-tiered.** Discovery is open; replication is explicit.
Content is served only to allowlisted peers, except what you
deliberately publish (`--open-lan` pins, exported tickets). All
fetched data is BLAKE3-verified regardless — trust gates
participation, not integrity.
## Layout
| crate | role |
|---|---|
| `varde-proto` | wire types for the socket API (serde, no I/O) |
| `varde-daemon` | the service: store, endpoint, policy, socket server |
| `varde-ctl` | CLI client and protocol reference implementation |
`dist/` holds systemd units (system + user, socket activation),
scdoc man pages, an example config, and an untested Arch PKGBUILD.
`docs/` has per-milestone decision notes and the redoal integration
sketch.
## Quick start
```console
$ varde-daemon --user &
$ varde-ctl add ~/dataset -r
added 5b1c…e0 (1234567 bytes)
$ varde-ctl pin 5b1c…e0
$ varde-ctl ticket export 5b1c…e0 # hand this to another machine
$ varde-ctl ticket import <ticket> # ...which runs this
$ varde-ctl materialize 5b1c…e0 /srv/dataset # reflinks when possible
```
Trusted peers on the same LAN sync overlapping pins automatically:
```console
$ varde-ctl status # shows this daemon's node id
$ varde-ctl peer trust <node-id-of-the-other-machine> # on both ends
```
## Building and testing
```console
$ cargo build --release
$ cargo test --workspace # spawns real daemons; no mocked iroh
$ cargo clippy --workspace --all-targets -- -D warnings
```
The `metered` feature (default on) needs D-Bus at runtime only; build
with `--no-default-features` for systems without it.