Everything on, phase 2 completed: SecureMode on in production, checked by the deploy
Owner decision 2026-10-04: SecureMode on once the pasture passes with it.
- Both clean pasture passes were run over all six peers:
- normally: 246 passed, 0 failed;
- with Federation__SecureMode=true: every federation check passed. The only failures were four checks expecting an
unsigned GET to get 404 or 410 where SecureMode answers 401. Those checks now go through `unserved` and
`gone_unsigned` (lib/interop.sh), which expect 401 when SecureMode is on.
- Circle posts now reach their member on GoToSocial and Mastodon, and survive Mastodon's signed refetch, as does a
followers-only post. The GoToSocial expected failure is gone.
- appsettings.Production.json turns SecureMode on.
- The deploy now checks that an unsigned GET of @thepra answers 401 and that a browser is redirected. It reads
@thepra's discoverability through the Mastodon API, since the actor is no longer readable unsigned.
- docs/INTEROP.md (Mastodon, GoToSocial), CLAUDE.md and ROADMAP updated.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ELjqpznMFMNrJoJUj6K5p2
This commit is contained in:
1 parent
8c2eba6cbb
commit
f6dbf71964
8 files changed
+47
-14
No files matched your search
@@ -431,9 +431,11 @@ tools/pasture/run.sh down # removes e
|
||||
delete is checked as a 404 on `/api/v1/statuses/{id}`.
|
||||
- It creates its accounts locked, so the scenario approves alice's request through `/api/v1/follow_requests`, which
|
||||
also checks our pending (`requested`) state and the manual Accept.
|
||||
- 37 checks: discovery and follows both ways; posts and CW; a reply and its notification; likes and boosts both
|
||||
- 55 checks: discovery and follows both ways; posts and CW; a reply and its notification; likes and boosts both
|
||||
ways; DMs both ways and off public timelines; polls both ways; quote policy; link cards; edits and deletes both
|
||||
ways; unfollow; block and unblock; statistics.
|
||||
ways; communities and circles; locked personas; unfollow; block and unblock; statistics.
|
||||
- It files a circle post as a direct message and shows it only to the accounts it mentions, so like a DM it is
|
||||
checked in the member's `/api/v1/conversations`, never by URI.
|
||||
- **Mastodon (4.7.3):** web and sidekiq on the shared Postgres and Redis, `ALLOWED_PRIVATE_ADDRESSES` for the network.
|
||||
Its token comes from `rails runner` (no password grant). Without Elasticsearch its status search finds nothing, so
|
||||
deliveries are checked through `/api/v1/accounts/:id/statuses` of the sender as Mastodon knows them, or
|
||||
@@ -461,6 +463,9 @@ tools/pasture/run.sh down # removes e
|
||||
its own activity and every bare `Announce{object}` 400 by design, and the echo is still needed (see
|
||||
`docs/INTEROP.md`, Lemmy). A new Lemmy never sends what it queued for a server before its send worker for that
|
||||
server started, so the scenario waits for that worker (`lm_worker`) before its first follow. 20 checks; relayed votes and a moderator's removal are expected failures (P7).
|
||||
- **SecureMode:** `PRIVAPUB_ENV="Federation__SecureMode=true" run.sh up …`, as production runs. A check of what an
|
||||
unsigned reader sees uses `unserved` and `gone_unsigned` (`lib/interop.sh`), which expect 401 when SecureMode is on and
|
||||
404 or 410 when it is off.
|
||||
- **Crawler:** `PRIVAPUB_ENV="Statistics__Crawler__Enabled=true Statistics__Crawler__Seeds__0=mastodon.test"
|
||||
run.sh up mastodon`, then `interop.sh crawler`. `PRIVAPUB_ENV` passes any setting to the PrivaPub container.
|
||||
- `run.sh up` replaces every container, Mongo included, so each run starts clean. To keep the data, republish into
|
||||
|
||||
Reference in new issue
Block a user