Repository navigation
Syncthing privacy fix and release pinning
This release fixes a privacy bug in the Syncthing add-on, pins Syncthing to a verified release the same way Bitcoin Core and LND are pinned, and fixes a second bug that weakened the channel backup folder's protection when pairing a device.
If you do not use the Syncthing add-on, just update from System, Self-Update. Nothing else applies to you.
What happened
The Syncthing add-on was supposed to disable global discovery, local discovery, relays, and NAT traversal. It did not. A bug in how the installer edited Syncthing's configuration caused those settings to silently revert to their defaults on every install. Every node with the add-on installed has been announcing its device ID and public IP address to Syncthing's public discovery and relay servers since the add-on shipped.
What this exposed: the fact that your server runs Syncthing, its device ID, and its public IP, published to public directory infrastructure. What this did not expose: your channel backup data (protected by Syncthing's mutual TLS, only devices you approved could ever connect), your keys, or your funds. The README's claim that discovery and relays were disabled was false on every deployment before this release. We are sorry for that.
What changed
Syncthing is now pinned to a specific verified release (v2.1.1), downloaded over Tor and verified against the Syncthing release signing key's known fingerprint, exactly like Bitcoin Core and LND. The apt repository is no longer used, and the binary's self-update is switched off. The version only changes when a release deliberately changes it, after review.
With the version fixed, the installer now writes Syncthing's entire configuration itself before the daemon ever starts, then verifies every privacy setting and refuses to start (and disables) Syncthing if anything does not check out. The privacy settings were verified live on fresh installs: packet capture, socket sampling, daemon logs, and the running daemon's reported configuration all showed zero discovery, relay, or NAT traversal traffic, from the daemon's very first start.
Honest scope: this defends every currently known discovery and announce mechanism, verified before the daemon starts. It cannot anticipate settings a future Syncthing version might add. Pinning is the control for that: the version cannot change without a deliberate review, and the installer hard-fails if it ever finds a version it has not been reviewed against.
Also fixed: pairing a backup device quietly switched the backup folder from "send only" to "send and receive", letting a paired device change or delete the node's copy of the channel backup. LND's own files were never at risk: the node copies the channel backup out of LND's data directory into the synced folder, and nothing copies back. Folder updates now preserve the folder type, and paired devices no longer get permission to auto-share folders to the node. The Syncthing install is also about 30 seconds faster (a readiness probe was checking an endpoint that always refused it).
If you already use the Syncthing add-on: migration
Existing installs have the apt-era Syncthing and the misconfigured settings. Five steps move you to the pinned setup. Your channel backup stays safe throughout: LND's own backup file is never touched, and your local device keeps its copy the whole time.
-
Update to v0.6.3 from the dashboard: System, Self-Update.
-
Press ctrl+c to drop to the shell, then paste this block:
sudo systemctl stop syncthing && sudo systemctl disable syncthing
sudo apt-get purge -y syncthing
sudo rm -f /etc/apt/sources.list.d/syncthing.list /etc/apt/keyrings/syncthing-archive-keyring.gpg /etc/systemd/system/syncthing.service
sudo systemctl daemon-reload
sudo rm -rf /etc/syncthing /var/lib/syncthing
sudo python3 - <<'EOF'
import json
p = "/etc/rlvpn/config.json"
c = json.load(open(p))
c["syncthing_installed"] = False
c.pop("syncthing_password", None)
c["syncthing_devices"] = []
json.dump(c, open(p, "w"), indent=2)
EOFConfirm the reset took (it should print "syncthing_installed": false):
grep -o '"syncthing_installed": [a-z]*' /etc/rlvpn/config.json-
Type
rlvpnto relaunch the dashboard, open Add-On, and install Syncthing. This installs the pinned, verified release. -
On your local device: remove the old node entry in your Syncthing (the node has a new identity), then pair again from the dashboard. Enter the node's address manually as
tcp://YOUR-NODE-IP:22000(discovery is off by design, so automatic address resolution will not find the node). The first connection can take a couple of minutes. -
Accept the backup folder share on your device and set it to Receive Only. Your channel backup syncs over within seconds.
These steps were verified end to end on a production deployment, including the self-update, before this release was published.
Everything in this release
- Syncthing pinned to a verified release binary (v2.1.1), GPG-verified over Tor, apt repository removed, self-update disabled
- Syncthing configuration written in full by the installer and verified before first start; the install fails loudly and leaves the daemon disabled if any privacy setting does not verify
- Discovery (global and local), relays, NAT traversal, usage reporting, and crash reporting confirmed off on the running daemon
- Device pairing no longer reverts the backup folder to two-way sync; paired devices cannot auto-share folders to the node
- Syncthing install completes about 30 seconds faster
- README corrections to match the above
Full Changelog: v0.6.2...v0.6.3