Known Issues¶
Current bugs, limitations, and workarounds. Each entry names its security registry ID where it has one.
Critical Issues¶
No critical issues currently known.
High Priority¶
Standing cannot be granted¶
Issue: standing <user> <tier> does not change anyone's standing. Given a name, it looks the account up in a
table shape the node no longer has, and answers Cannot resolve user '<name>' to a DID. Given a did:key, it records
the tier under that key, but a Hall's gates look people up by their AID, so the record is never read.
Impact: Everyone in a Hall stays at the standing accept or an open threshold gave them, which is Newcomer. No
one can be raised to Familiar, Trusted or Steward, so the common and private zones stay closed to members, and a
members_only Hall cannot gather the two Trusted vouches that admit someone. A Steward can still accept each knock.
Workaround: Use the knock threshold and accept people one by one.
Status: Open. Found 2026-09-30 while reconciling the system walkthrough, and passed to the node team.
Capability validation incomplete¶
Issue: Some Place methods (add, remove and list contents) ignore the capability they are given. Their checks are still TODO stubs in world/location_registry.py. Registry: CAP-04.
Impact: Access control may not be fully enforced in all code paths.
Workaround: Don't rely on capability security for alpha testing. Assume trusted peers.
Status: Open
Medium Priority¶
IPFS does not carry connections between nodes¶
Issue: IPFS peer discovery never subscribes to its topic, so no connection between nodes can start over IPFS. Registry: TPT-44.
Impact: The node reports IPFS as impaired in transport. IPFS still stores the media you upload.
Workaround: None needed. mDNS, Veilid and Tor carry connections.
Status: Open
IPFS P2P requires TCP addresses¶
Issue: IPFS P2P forwarding only works with TCP, not QUIC addresses.
Impact: Some IPFS peers may not be reachable.
Workaround: Ensure IPFS has TCP swarm addresses. Check with @ipfsid, which shows the node's IPFS peer ID and addresses.
Status: IPFS limitation, no fix planned
Only a few settings are configurable¶
Issue: The node's general config loader, Config.load() in core/config.py, is still a stub. The node reads only the installer's config.json and a set of environment variables.
Impact: Most settings are hardcoded.
Workaround: Use the settings that exist, listed in Configuration.
Status: In backlog
Low Priority¶
mDNS peer count includes peers that left¶
Issue: The node never removes a LAN peer from its mDNS registry when the peer goes away.
Impact: The mDNS peer count in transport can be higher than the number of peers still connected.
Workaround: Use ping <name> to check whether one peer is connected now.
Status: Known, not scheduled
A peer can be listed twice in @peers¶
Issue: @peers merges transports by exact name. When the Tor arm reports a name in different letter case from mDNS, the same person appears twice, once tagged [mDNS] and once [Tor].
Impact: Cosmetic. Both lines are the same peer.
Workaround: None needed.
Status: Known, not scheduled
Platform-Specific¶
macOS: Untested¶
Issue: macOS builds compile but are not regularly tested. Veilid is not available for macOS x86_64 (Intel).
Impact: Unknown issues may exist. An Intel Mac has no Veilid transport.
Workaround: Report any macOS-specific issues.
Status: Seeking macOS testers
Windows: Path handling¶
Issue: Some paths may not handle Windows separators correctly. The command parser treats a bare backslash as an escape, so an unquoted path such as C:\Users\you\id.bin becomes a different filename with no error.
Impact: Occasional path-related errors.
Workaround: Put paths in single quotes when you type them, as in export-identity 'C:\Users\you\id.bin' <base64_passphrase>. In the Urchin client, type export-identity bare and the dialog does the quoting for you. Report other path errors with the full path.
Status: Fixed as found
Transport-Specific¶
mDNS: AP isolation blocks discovery¶
Issue: Some routers/access points block mDNS between clients.
Impact: LAN discovery fails.
Workaround: Disable "AP isolation" or "client isolation" in router settings.
Status: Cannot fix (router configuration)
mDNS: Mixed versions connect one way only¶
Issue: A node from the current build can reach an older node over mDNS, but an older node cannot reach a current one.
Impact: Two machines on different releases may not connect on a LAN.
Workaround: Run the same release on both machines. Check with /check-updates.
Status: Expected. The first release after the data wipe reinstalls every node
Veilid: First connection slow¶
Issue: Initial Veilid connection can take 30-60 seconds.
Impact: The first join over Veilid seems to hang.
Workaround: Wait patiently. Subsequent connections are faster. Veilid also needs an accurate system clock.
Status: Veilid behavior, not a bug
Tor: Onion propagation delay¶
Issue: New onion services take time to propagate.
Impact: Immediate connection after creating service may fail.
Workaround: Wait 1-2 minutes after first start.
Status: Tor behavior, not a bug
Reporting New Issues¶
If you encounter an issue not listed here, please report it.
See Reporting Issues for how to submit useful bug reports.
Changelog¶
| Date | Issue | Change |
|---|---|---|
| 2025-01-22 | Tor transport | Marked as IMPLEMENTED |
| 2025-01-22 | Session registry | Marked as IMPLEMENTED |
| 2025-01-22 | Installer system | Marked as IMPLEMENTED |
| 2026-02-17 | CapTP dual-session | Fixed session merging in handle_hello for dual mDNS connections |
| 2026-02-17 | mDNS self-connection | Fixed in both add_service and _handle_incoming_connection |
| 2026-02-17 | mDNS DID mismatch | Added to known issues; workarounds in place; roadmap for SEER DID |
| 2026-02-17 | Client TLS polling | Fixed: added _tcp.poll() before _tls.poll() in Godot client |
| 2026-02-17 | Presence messages | Changed from raw text to Urchin event packets |
| 2026-02-17 | Prompt indicator | Fixed case-sensitive @pjoin/@vjoin matching |
| 2026-09-29 | mDNS DID mismatch | Fixed. The 4242 listener is retired. An mDNS sighting keys nothing and dials the peer, and the signed CapTP hello decides who the peer is. The session and registry are recorded under the proven name (TPT-97, TPT-98, CONSENT-13, merge b6d8384) |
| 2026-09-30 | mDNS: mixed versions, peer count, duplicate @peers line | Added |
| 2026-09-30 | IPFS does not carry connections | Added (TPT-44) |
| 2026-09-30 | CHI PIRO not functioning | Removed. The CHI PIRO code was removed from seer.py, and PIRO v3 replaces it |
| 2026-09-30 | Veilid route signature verification missing | Removed from this list. The TODO is gone, and nothing in the node imports transport/veilid/route_exchange.py, so testers do not meet it. Its security row (NEW-10) stays on the registry until SERVER re-checks it |
| 2026-09-30 | HeartbeatManager is empty stub | Removed. The heartbeat module now runs its timers, and it was never visible to a tester |
| 2026-09-30 | Type hints use Any extensively |
Removed. A development issue, not a tester issue |
| 2026-09-30 | Config file loading not implemented | Reworded to what the node reads today |