net: build banlist infrastructure (CBanList, banlist.dat, setban/listbanned/clearbanned RPCs) [epic] #17
Labels
No labels
enhancement
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
SubGeniusFinance/Offerings-to-Cthulhu#17
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Epic. Do-not-merge-pre-Codex. Tracked here for design discussion + post-Codex implementation.
Why
OFF has no banlist infrastructure today. No
CBanList, nobanlist.dat, nosetban/listbanned/clearbannedRPCs, no Qt right-click → Ban action. Verified by searching the tree:The misbehavior counter (
CNodeState::nMisbehavior,Misbehaving()) exists and trips at-banscore=100(default), but the consequence is just disconnect — there's no persistent record, and the peer can immediately reconnect via addrman. There's no way to manually ban a known-bad IP.For the post-Restoration era, with the chain having a known >80%-hash attacker and external eyes increasing as the BCT announcement lands, OFF will want this. Not today, but soon.
What's needed (scope)
This is a real backend feature, ~200+ LOC across multiple files. Rough plan, modeled on modern Bitcoin Core's
banman.{cpp,h}:1.
src/banlist.{cpp,h}or equivalent (new files)CBanEntry— single ban record: subnet/CIDR, ban-until timestamp, reason (manual / misbehavior / consensus)CBanList(or BanMan) — in-memory map of CSubNet → CBanEntry, persistence tobanlist.dat, sweep timer to expire timed bans, thread-safe interfaceIsBanned(CNetAddr),Ban(CSubNet, ban_reason, ban_time_offset),Unban(CSubNet),ClearBanned(),GetBanned()2.
src/net.cppintegrationIsBannedcheck on inboundaccept()path (net.cppconnection acceptance)Misbehaving()so a peer crossing the banscore threshold gets an auto-ban (existing OFF behavior is just disconnect — no persistence)3.
src/init.cppbanlist.daton startup4. RPCs
setban <subnet> <add|remove> [bantime] [absolute] [reason]listbannedclearbanned5. Qt integration (much smaller)
Why post-Codex
This touches
net.cppconnection-accept and peer-selection paths. Bugs in those paths surface as network partitions or peer-discovery failures — exactly what cannot happen during the inscription window (blocks 999,991 → 1,050,666). Hard freeze: not merging until block 1,050,667 or later.Open design questions (for future discussion)
Misbehaving()? Modern Bitcoin Core auto-bans on banscore threshold. Should OFF? Pro: shuts up sustained attackers. Con: misbehaving bots are an attack vector for partitioning honest nodes if the threshold is easy to trigger from outside.CSubNet; the persistence format would match.banlist.datbe wire-compatible with Bitcoin Core's, or OFF-specific? Compat means external tooling (some block explorers, monitoring scripts) can read it.What this isn't
References
banman.{cpp,h}— the canonical reference implementationdobbscoin-source/src/banlist.{cpp,h}(if present in (BOB)'s vintage of the codebase — verify)src/main.cpp::Misbehaving()— current OFF misbehavior counter, untriggered consequencesrc/net.cpp::CNode::fDisconnect— current disconnect mechanism (one-shot, no persistence)The Sleeping God's blacklist is long but unread. Iä Iä.