Skip to content

feat(api): add peer management to admin RPC - #86

Open
317787106 wants to merge 1 commit into
feature/admin_rpcfrom
feature/peer_management
Open

317787106 wants to merge 1 commit into
feature/admin_rpcfrom
feature/peer_management

Conversation

@317787106

@317787106 317787106 commented Aug 20, 2026 •

Copy link
Copy Markdown
Owner

What does this PR do?

Adds runtime peer management to Admin JSON-RPC over HTTP and IPC, so operators can adjust active nodes, inspect connections, and block malicious IPs without restarting FullNode.

The API adds admin_addPeer, admin_removePeer, admin_disconnectPeer, admin_listActivePeers, admin_blockIp, admin_unblockIp, and admin_listBlockedIps. Mutations return a shared PeerOperationResult; active-peer queries reuse the connection, latency, and synchronization statistics used by PeerConnection.log(). The IPC client also supports optional text-table output for admin_listActivePeers.

Why are these changes required?

Operators need to disconnect or block identified malicious peers and add trusted endpoints promptly when investigating degraded connectivity or network isolation. Persistent manual IP blocking keeps those decisions effective across node restarts.

Integration with the built-in p2p module

Upstream PR #6992 has merged libp2p into java-tron as the local :p2p module. This PR targets feature/admin_rpc, which already includes that change from release_v4.8.3, and contains both the framework integration and the required p2p implementation and tests. It has no dependency on a separate libp2p PR, SNAPSHOT artifact, or release.

  • framework owns Admin HTTP/IPC dispatch, operation coordination, peer statistics, and persistence of normalized IPs and blockedAtMillis timestamps in CommonStore["blocked-ips"].
  • p2p provides addActiveNode, removeActiveNode, disconnect, and replaceBlockedIps, plus TCP admission, dialing, candidate filtering, and disconnection enforcement.
  • ConnectionPolicy publishes an immutable IP set through a volatile reference and normalizes IPv4-mapped IPv6 addresses for matching. P2pConfig.blockedIps supplies the initial policy; runtime changes update the policy without writing back to startup configuration.
  • The independently runnable p2p-standalone.jar retains --blocked-ips / -b. Its argument coverage is consolidated in StartAppArgsTest, and the module README documents startup and runtime usage.

Behavior and compatibility

  • admin_addPeer adds an active endpoint without adding it to trustNodes or waiting for a successful connection. Adding a blocked IP is rejected.
  • admin_removePeer removes the active endpoint and closes its connection. admin_disconnectPeer only closes the current connection; an active node can reconnect later.
  • When node.dynamicConfig.enable is enabled, add/remove operations return a structured failure directing operators to update node.active. Other peer-management operations remain available.
  • Persisted blocks are loaded and installed before network initialization. Malformed stored data is deleted on a best-effort basis and the node starts with an empty manual blocklist.
  • A blocklist change first installs the p2p policy and closes matching connections, then persists the snapshot, then publishes the framework query snapshot. A persistence failure returns an internal error and leaves the query snapshot unchanged, although the runtime policy may already have changed; retrying the operation reapplies and persists the intended snapshot.
  • Blocking applies to TCP connections and dialing candidates. UDP discovery traffic remains outside its scope. FullNode gains no new peer-management configuration switch.
  • Connect.proto adds DisconnectReason.REQUESTED = 0x0F for explicit disconnects. The existing disconnect message structure, consensus rules, and chain-data formats remain unchanged.

Testing

  • Coverage includes startup policy installation, persistence and corrupt-data recovery, update ordering and retries, idempotency, concurrent mutations, dynamic-config restrictions, IP normalization, and TCP inbound/outbound rejection.
  • HTTP/IPC dispatch, error codes, peer statistics, IPC text output, network lifecycle, and effective-connection compatibility have regression coverage.
  • Full p2p suite: 383 tests, 3 existing skips, no failures or errors; StartAppArgsTest includes all 11 argument tests.
  • Related framework suites: 197 tests, no failures or errors.
  • All-module checkstyleMain and checkstyleTest passed.
  • :p2p:buildStandaloneJar and a standalone JAR help invocation with --blocked-ips passed.

@317787106 317787106 changed the title support peer management based on ipc feat(net): support runtime peer management Aug 20, 2026
@317787106 317787106 changed the title feat(net): support runtime peer management feat(api): add peer management to admin RPC Aug 20, 2026
Add peer management to Admin HTTP and IPC, including active-peer inspection,
persistent IP blocking, and optional IPC text output.

Implement the management APIs and TCP connection policy in the built-in p2p
module. Retain the standalone blocked-ips option and consolidate its tests
in StartAppArgsTest.

Base the change on feature/admin_rpc with java-tron 4.8.3.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant