Add NAT traversal: public address discovery, UDP hole punching, and keep-alive#7
Draft
Copilot wants to merge 2 commits into
Draft
Add NAT traversal: public address discovery, UDP hole punching, and keep-alive#7Copilot wants to merge 2 commits into
Copilot wants to merge 2 commits into
Conversation
…y and keep-alive Co-authored-by: jose-blockchain <30682875+jose-blockchain@users.noreply.github.com>
Copilot
AI
changed the title
[WIP] Add NAT Traversal feature
Add NAT traversal: public address discovery, UDP hole punching, and keep-alive
Mar 17, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Nodes behind NAT routers have no mechanism to discover their public address or establish direct peer connections. This adds a NAT traversal subsystem integrated with the existing UDP networking stack.
New:
src/nat_traversal.rsNatType—Open | FullCone | RestrictedCone | PortRestrictedCone | Symmetric | UnknownHolePunchMessage— wire protocol:DiscoverRequest/Response,CoordinateHolePunch,HolePunchProbe/Ack,KeepAliveNatTraversalConfig— discovery/punch timeouts, attempt count, keep-alive interval, enabled flagNatTraversalManager— core engine:discover_public_addr(reflector)— learn externally-observed address via reflector peerprobe_nat_type_with_reflectors(r1, r2)— same external port from two reflectors → cone NAT; different → Symmetricinitiate_hole_punch(socket, remote)— burst probes + wait for ack, records confirmed sessionhandle_message(msg, sender)— serves reflector, coordinator, and responder rolessend_keep_alive(socket)— periodic packets to all traversal peers to maintain NAT mappingssrc/node.rsNodeConfiggainsnat_traversal: NatTraversalConfig(enabled by default)ChaincraftNodegainsnat_traversal: Option<Arc<NatTraversalManager>>start_networking()initialises the manager, routes NAT messages before the general UDP handler, and spawns a background keep-alive task.nat_traversal(bool),.with_nat_traversal_config(config)set_nat_traversal_enabled(),nat_traversal_manager()src/error.rsTwo new
NetworkErrorvariants:NatDiscoveryFailed { reason }andHolePunchFailed { addr, reason }.Usage sketch
Original prompt
🔒 GitHub Advanced Security automatically protects Copilot coding agent pull requests. You can protect all pull requests by enabling Advanced Security for your repositories. Learn more about Advanced Security.