Repository: https://github.com/CoNET-project/CoNET-L0D
Linux userspace daemon that lets CoNET L1 geth and Prysm beacon-chain use Layer Minus (L0) as a static overlay P2P path without patching those clients.
conet-l0d owns the network objects for its own lifetime:
- creates TUN
conet-l0 - adds the overlay address and a route for
100.64.0.0/10 - installs a dedicated iptables chain
CONET_L0D(loopback is returned first) - removes exactly those objects on
stop, SIGINT / SIGTERM, orteardown
Operators do not run iptables by hand.
Maturity: under development. Crate MVP is accepted (CLI, locator, TUN / iptables lifecycle, packet counters). Overlay /post prefers SI l0_listen / l0_connect occupancy plus application duplex (duplex_offer on Chat gossip; accept / reject / AES duplex_frame on the occupied pipe); P1 gossip remains the fallback if the peer app never sends duplex_accept or the pipe is missing. P1 outbound encrypt + mailbox wrap + POST { data }, inbound decrypt + TUN write-back, and listen HTTP+SSE workers exist in-crate and default off. Listen ingest matches SI forWardPGPMessageToClient raw JSON { "data": "<armor>" } (Chat handleInbound), plus duplex JSON frames. In-crate listen matches SI checkSign. An authorized lab may enable [l0]. The 2026-08-18 lab on authorized L0_ONLY .45 advertises overlay vIP 100.64.0.5, completed overlay geth + beacon TCP, and is running CL initial-sync over overlay; after the batching binary the limiter is Prysm (~3.2 blocks/s); EL is still 0x0. Lab overlay UDP echo and :4300 (direct + public-ENR steer) arrived on the peer TUN; live discv5 from L0_ONLY .45 to the .98 DHT server over L0 is accepted (not a production product). Production mailbox delivery is not shipped. Production proposers keep public P2P (geth 8400, beacon 4200 / 4300) for the 6-second slot.
| Other product | Difference |
|---|---|
SilentPass / SaaS_Sock5 |
Device or app egress to a public host:port. Not L1 consensus P2P. |
| Current L0 UDP forward | AES frames over HTTP / SSE — not raw OS UDP, not discv4. |
| Validator client | Talks only to the local beacon. Do not capture its uid or read its keystore. |
Layer Minus stays a PGP / wallet-address forwarding plane. HTTP /post is only { "data": "<OpenPGP armor>" }. This crate is an application composition, not a second IP network.
Overlay duplex is SI l0_listen / l0_connect plus application JSON on Chat gossip / occupied AES. SI does not implement duplex_*. There is no live SI command named p2p_stream_* or listenKind: "l1p2p". Do not send mining + listenKind: "duplex".
The URI is a peer locator, not an ERC-4804 content URL.
web3://0x<40-hex>/p2p/geth
web3://YourExactTag.web3/p2p/beacon
@beamioTag must match exactly (CoNET ≠ CONET). Do not take search-users results[0]. An AA without AddressPGP is not a destination.
Routing EOA ≠ deposit keystore ≠ fee recipient.
Requires a stable Rust toolchain (rust-toolchain.toml).
git clone https://github.com/CoNET-project/CoNET-L0D.git
cd CoNET-L0D
cargo test
cargo build --release
# binary: target/release/conet-l0d
sudo install -m 0755 target/release/conet-l0d /usr/local/sbin/conet-l0dcheck-config, resolve, and status run on any OS. start / stop / teardown need Linux, ip, iptables, and CAP_NET_ADMIN (usually sudo).
conet-l0d check-config --config config/conet-l0d.example.toml
conet-l0d resolve 'web3://0x1111111111111111111111111111111111111111/p2p/geth'
conet-l0d status --config /etc/conet-l0d.toml
sudo conet-l0d start --config /etc/conet-l0d.toml
sudo conet-l0d stop --config /etc/conet-l0d.toml
sudo conet-l0d teardown --config /etc/conet-l0d.tomlCopy config/conet-l0d.example.toml to /etc/conet-l0d.toml and set local_vip, identity.locator, and [[peers]].
Optional systemd unit (systemd/conet-l0d.service):
sudo cp systemd/conet-l0d.service /etc/systemd/system/
sudo systemctl daemon-reload
sudo systemctl enable --now conet-l0dThe unit must call conet-l0d start / stop. Do not put raw iptables in the unit.
Authorized L0_ONLY .45 points geth / beacon advertise flags at the overlay vIP. .98 and production proposers keep the public IP. Do not bind Engine or HTTP to the vIP.
geth --nat extip:100.64.0.5 --bootnodes "enode://<peer-key>@100.64.0.1:8400" \
--http.addr 127.0.0.1 --authrpc.addr 127.0.0.1 --port 8400
beacon-chain --p2p-host-ip=100.64.0.5 --p2p-tcp-port=4200 --p2p-udp-port=4300 \
--rpc-host=127.0.0.1 --grpc-gateway-host=127.0.0.1Advertise-only flags do not stop the clients when the TUN is down. Binding --http.addr, --authrpc.addr, --p2p-local-ip, or --rpc-host to the overlay vIP can fail startup. Details: docs/operator-flags.md.
Phase 1 uses static overlay peers. The crate envelope already carries IPv4 including UDP. A lab may prove overlay UDP / DHT-port comms and live discv5 via L0 (docs/P2.md); that is not a production discv5 product.
- First iptables rules:
RETURN127.0.0.0/8(Engine JWT, beacon gRPC, local RPC). - Optional
validator_uidis never captured. - Never REDIRECT
0.0.0.0/0:8400or the whole public P2P space. - This process does not restart geth, beacon, or validator.
- Do not invent a new public hostname for this product.
| Document | Role |
|---|---|
| Whitepaper (EN) | Design (canonical technical wording) |
| 白皮书(简体中文) | Paired translation |
| MVP · MVP(中文) | Accepted crate MVP |
| P1 · P1(中文) | Overlay /post encrypt + mailbox wrap + POST; inbound decrypt + TUN write-back; EIP-191 listen worker; SI gossip JSON ingest; [l0] default off; authorized lab may enable [l0]; 2026-08-18: .45 advertises overlay vIP; overlay geth + beacon TCP; CL initial-sync in progress |
| P2 · P2(中文) | Lab overlay UDP / DHT-port comms (echo + :4300 + public-ENR steer + live discv5 via L0). Not a closed P2 / production product |
| Lab overlay QoS 2026-08-18 | Both-end log + TUN + TCP quality snapshot (~15 min). Mailbox path lossless; overlay RTT ~500 ms; hub TUN tx_dropped=937. Not a protocol change |
| Operator flags | geth / beacon advertise flags |
| RULES.md | Engineering constraints |
| GitBook Applications | Operator how-to |
| GitBook Developers | CLI, config, wire contract |
| How to use Layer Minus | L0 forwarding plane |
| Run an L1 node | Public P2P (production default) |
A change to the whitepaper, RULES.md, or MVP must update both GitBook pages in the same task.
Does: overlay vIP table, web3:// locator parse, TUN + iptables lifecycle, packet counters, application duplex on Chat gossip (offer / accept / AES duplex_frame) when the peer app accepts, P1 gossip fallback otherwise, dest-aggregated IPv4 batch in ipv4 (POST concurrency 32 / queue 2048; inbound TUN write queue 1024), inbound decrypt + TUN write queue when routing_key_file is set, listen HTTP+SSE workers when enabled plus listen_entries, mailbox_route_pgp_file, routing_eoa, routing_key_file, and routing_eth_key_file. Optional [[l0.channels]] is one routing EOA + SSE per overlay port (8400 / 4200 / 4300). Listen ingest accepts SI gossip JSON { "data": "<armor>" } and duplex frames. An authorized lab may enable [l0].
Does not (yet): finish L0-only follow-the-chain (2026-08-18: overlay TCP proven; after the batching binary the limiter is Prysm initial-sync at ~3.2 blocks/s, ~15 h; .45 EL still 0x0; watch with scripts/watch-l0-follow.sh), production mailbox delivery, production discv4 / discv5 (lab discv5 via L0 is accepted — docs/P2.md; if connected drops, overlay-dht-steer.sh apply first; authorized .45 restart-beacon only after dial backoff; after DNAT, .45 ss may show hub public :4200 — original dest, not a leak), validator proxying. Do not treat SI duplex_* or p2p_stream_* as current SI. The crate never restarts geth/beacon; an authorized operator script may restart only the named lab host.
MIT © 2026 CoNET / Beamio