Skip to content

feat: validate peer setup before a demo runs on - #9537

Merged
koenvanderveen merged 5 commits into
devfrom
pjwerneck/validate-peer-setup
Oct 7, 2026
Merged

koenvanderveen merged 5 commits into
devfrom
pjwerneck/validate-peer-setup

Conversation

@pjwerneck

@pjwerneck pjwerneck commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Adds client.validate_peer(email). It catches a wrong peer email right after peering, instead of
halfway through a demo. The enclave demo notebooks now call it.

Changes

  • validate_peer() on SyftboxManager, SyftRDSClient and SyftEnclaveClient. It raises
    PeerSetupError if the email is not a peer, is waiting for this client's approval, or was
    rejected, and PeerNotReadyError if the peer has not approved our request yet.
  • It warns if the peer was already connected, or already waiting, when this client first loaded its
    peers: the connection can be left over from an earlier run. delete_syftbox() clears that record.
  • 14 enclave demo notebooks call validate_peer() after peering. The enclave is left to
    attest_peer().

Testing

  • New tests/unit/test_validate_peer.py (6 tests, mock Drive) and one enclave-client test.
  • Full suites pass: tests/unit 526, syft-rds 105, syft-enclave 280.
  • Tested on real Drive through feat: add wait helpers to run all cells #9545's live run (four test accounts).

Asana task

@review-notebook-app

Copy link
Copy Markdown

Check out this pull request on  ReviewNB

See visual diffs & provide feedback on Jupyter Notebooks.


Powered by ReviewNB

@rasswanth-s rasswanth-s left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@pjwerneck
pjwerneck force-pushed the pjwerneck/validate-peer-setup branch from f60605b to 9d6eb07 Compare October 5, 2026 13:06
A wrong peer email showed up only halfway through a notebook, and a
connection left over from an earlier run looked live. validate_peer()
fails unless the peer is approved and either connected in this session
or logged in within max_age (Drive's modified time of its version file).

With a timeout it waits for a late approval or login, one Drive request
per poll. The demo notebooks call it after peering.
validate_peer() now warns about a peer that was already connected, or
already waiting for our approval, at the first load_peers(). Either can
be left over from an earlier run. The login-time check and its Drive
read are removed. delete_syftbox() clears the record, so a reset client
does not warn. The notebooks leave the enclave to attest_peer().
Waiting for an approval belongs to wait_until_peered, so validate_peer()
loses its timeout, the poll loop and peer_may_be_valid(). The notebooks
call it without a timeout.
@pjwerneck
pjwerneck force-pushed the pjwerneck/validate-peer-setup branch from 9d6eb07 to 4ab778f Compare October 7, 2026 01:51
@koenvanderveen
koenvanderveen merged commit e7f330f into dev Oct 7, 2026
20 checks passed
@koenvanderveen
koenvanderveen deleted the pjwerneck/validate-peer-setup branch October 7, 2026 11:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants