Files
orca/src/shared
Neil 94ba0b9f05 docs(relay): say plainly that the protocol negotiation is not reachable yet
Two claims that read as live and are not.

`relay-protocol-version.ts` documents a negotiation that no live path can reach, and
reads as the fix for #13852. It is not. The deploy path namespaces the relay directory
by the CLIENT'S OWN build hash — `remoteInstallDirName` is `relay-<fullVersion>` — and
the daemon socket lives inside it; the short-socket fallback derives its segment from
the same directory, and every `runConnectHandshake` caller takes its path from that one
deploy result. So a bridge can only ever meet a daemon of its own build,
`msg.version === launchVersion` short-circuits, and `relayProtocolOfferAdmits` never
decides anything. The stranded incumbent the feature exists for sits in
`relay-<otherVersion>/`, which nothing dials. What ships is three log lines;
`MIN_RELAY_PROTOCOL_VERSION` and the `minProtocolVersion` wire field have no live reader.

Keeping it is right — the mechanism is correct and hostile-input-safe (20 malformed and
hostile offers refused against a real daemon, which stayed up and still admitted a valid
cross-build offer afterwards), and it is the part that has to exist first. What was
missing is the statement of what else has to land with it, which is now written where
someone editing this file will see it: route the bridge to the incumbent's socket, and
stop `validateGrant` refusing on `serverBuildId`. That second one matters because its
premise, "client and relay ship in one build", is still TRUE today and becomes false the
instant the first lands — it is a second gate that would refuse what the handshake just
admitted, and shipping only the routing change would look like a regression in the
negotiation rather than a missed dependency.

`lingerMs` on the coordinator contract reads as a policy knob. No production path sets
it: the only `new RelayAuthCoordinator` is in `desktop-relay-service.ts` and passes
neither it nor `random`, so every shipped linger is the hardcoded ten-minute default.
Labelled a test seam so the next person tunes the default, which is the only thing a
user can feel.

No behaviour change. Both found by a dead-code and unread-field sweep over the stack.
2026-09-10 17:54:24 -07:00
..
2026-05-31 05:55:04 -07:00
2026-09-03 17:32:59 -07:00