mirror of
https://github.com/jmcorgan/fips.git
synced 2026-08-10 08:37:02 +00:00
node: establish dataplane/ and session/ concept homes (behavior-neutral)
Reorganize the node module tree by concept rather than by
message-handling verb, as the first step of the node runtime
decomposition. Pure relocation: no wire, config, metric, or log
semantics change; the lib test count is unchanged (1577 passed).
Moves (git mv, 100% rename similarity):
- handlers/{forwarding,rx_loop,connected_udp,dispatch,encrypted}.rs
-> node/dataplane/ — the whole RX hot path (the select! run loop,
transit/local forwarding, the link-message router, the RX decrypt
path with responder K-bit cutover + roam writes, and connected-UDP
fast-path activation) now lives in one home.
- node/session.rs -> node/session/mod.rs — establishes the session
concept home for the data/state types. The message-behavior file
handlers/session.rs stays put for now (folds in with the later FSP
session step).
The IK/XX-divergent establishment files (handlers/{handshake,rekey,
timeout}.rs) and the deferred-home files (handlers/{mmp,lookup}.rs)
deliberately stay in handlers/, to move once rather than twice.
Every module is reached through impl Node methods, so no call site or
re-export shim was needed. Updated in lockstep with the moves: the
module_path!-derived tracing targets in the two mesh-lab compose-trace
overlays, a structural test's include_str! source path, doc-comments
in proto/routing and the mesh-lab docs, and the stale source-location
citations (node/handlers/{forwarding,rx_loop,encrypted}.rs and
node/session.rs) in doc-comments and the discovery design doc.
This commit is contained in:
@@ -2767,12 +2767,12 @@ mod tests {
|
||||
/// Structural confirmation that the rx_loop no longer dispatches `show_*`:
|
||||
/// the rx_loop source carries no `queries::dispatch` call and no
|
||||
/// `starts_with("show_")` routing branch. Reads the committed source of
|
||||
/// `src/node/handlers/rx_loop.rs` and asserts both markers are absent. This
|
||||
/// `src/node/dataplane/rx_loop.rs` and asserts both markers are absent. This
|
||||
/// is the milestone's "remove `show_*` from the data-plane dispatch path"
|
||||
/// invariant, guarded against regression.
|
||||
#[test]
|
||||
fn rx_loop_has_no_show_dispatch() {
|
||||
let src = include_str!("../node/handlers/rx_loop.rs");
|
||||
let src = include_str!("../node/dataplane/rx_loop.rs");
|
||||
assert!(
|
||||
!src.contains("queries::dispatch"),
|
||||
"rx_loop must not call queries::dispatch (show_* served off-loop)"
|
||||
|
||||
@@ -0,0 +1,15 @@
|
||||
//! Data plane: the RX `select!` loop and the per-packet forwarding path.
|
||||
//!
|
||||
//! Holds the whole hot path in one home: the `select!` run loop
|
||||
//! (`rx_loop`), transit/local datagram forwarding (`forwarding`), the
|
||||
//! link-message router (`dispatch`), the RX decrypt path including responder
|
||||
//! K-bit cutover and address-roam writes (`encrypted`), and the per-peer
|
||||
//! connected-UDP fast-path socket activation (`connected_udp`). Each module
|
||||
//! contributes `impl Node` methods driven by the run loop.
|
||||
|
||||
#[cfg(unix)]
|
||||
pub(crate) mod connected_udp;
|
||||
mod dispatch;
|
||||
mod encrypted;
|
||||
mod forwarding;
|
||||
mod rx_loop;
|
||||
@@ -1,14 +1,8 @@
|
||||
//! RX event loop and message handlers.
|
||||
//! Message handlers: per-message-type behavior on `impl Node`.
|
||||
|
||||
#[cfg(unix)]
|
||||
pub(crate) mod connected_udp;
|
||||
mod dispatch;
|
||||
mod encrypted;
|
||||
mod forwarding;
|
||||
mod handshake;
|
||||
pub(crate) mod lookup;
|
||||
mod mmp;
|
||||
mod rekey;
|
||||
mod rx_loop;
|
||||
pub(in crate::node) mod session;
|
||||
mod timeout;
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
pub(crate) mod acl;
|
||||
mod bloom;
|
||||
pub(crate) mod context;
|
||||
mod dataplane;
|
||||
#[cfg(unix)]
|
||||
pub(crate) mod decrypt_worker;
|
||||
#[cfg(unix)]
|
||||
|
||||
+1
-1
@@ -222,7 +222,7 @@ pub enum MmpReject {
|
||||
/// Forwarding-path rejection reasons.
|
||||
///
|
||||
/// Each variant corresponds to a silent-rejection path in
|
||||
/// `src/node/handlers/forwarding.rs::handle_session_datagram`. Matching
|
||||
/// `src/node/dataplane/forwarding.rs::handle_session_datagram`. Matching
|
||||
/// `ForwardingStats` counters already track packets and bytes for each
|
||||
/// outcome; `record_reject` mirrors the packet-count side of the bump
|
||||
/// for parity with the other rejection clusters.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
//! Tests for the consecutive-decrypt-failure threshold force-removal path.
|
||||
//!
|
||||
//! Covers `Node::handle_decrypt_failure` (in `node/handlers/encrypted.rs`),
|
||||
//! Covers `Node::handle_decrypt_failure` (in `node/dataplane/encrypted.rs`),
|
||||
//! which increments `ActivePeer::increment_decrypt_failures` on each AEAD
|
||||
//! verification failure and force-removes the peer once
|
||||
//! `DECRYPT_FAILURE_THRESHOLD` consecutive failures are observed. The
|
||||
@@ -18,7 +18,7 @@ use super::*;
|
||||
/// the full `peers_by_index` cleanup path (not just the bare `peers` table).
|
||||
#[test]
|
||||
fn test_decrypt_failure_threshold_removes_peer() {
|
||||
// Threshold constant in node/handlers/encrypted.rs (kept in sync with
|
||||
// Threshold constant in node/dataplane/encrypted.rs (kept in sync with
|
||||
// production code; see DECRYPT_FAILURE_THRESHOLD).
|
||||
const THRESHOLD: u32 = 20;
|
||||
|
||||
|
||||
@@ -1072,7 +1072,7 @@ async fn test_should_admit_msg1_admits_rekey_when_udp_accept_off() {
|
||||
///
|
||||
/// The carve-out predicate must also consult peer state by source
|
||||
/// address: `current_addr()` is updated from inbound encrypted-frame
|
||||
/// source addrs (`handlers/encrypted.rs`), so an established peer can
|
||||
/// source addrs (`dataplane/encrypted.rs`), so an established peer can
|
||||
/// be matched even when the addr_to_link key is hostname-form and the
|
||||
/// incoming addr is numeric.
|
||||
#[tokio::test]
|
||||
|
||||
+1
-1
@@ -1529,7 +1529,7 @@ mod tests {
|
||||
// === FMP rekey cutover: authenticate-before-promote ===
|
||||
//
|
||||
// IK-adapted analogue of the FSP trial-decrypt tests
|
||||
// (node/session.rs `trial_decrypt_picks_pending_and_promotes` /
|
||||
// (node/session/mod.rs `trial_decrypt_picks_pending_and_promotes` /
|
||||
// `trial_decrypt_failed_slot_leaves_replay_window_intact`). The FMP
|
||||
// cutover is gated on an authenticated decrypt against `pending`, not
|
||||
// the bare header K-bit. These tests exercise that primitive:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
//! Sans-IO routing decision core.
|
||||
//!
|
||||
//! Pure, runtime-agnostic transit-forward decision for SessionDatagrams. The
|
||||
//! async I/O adapter in `node::handlers::forwarding` decodes the wire bytes,
|
||||
//! async I/O adapter in `node::dataplane::forwarding` decodes the wire bytes,
|
||||
//! pre-resolves the next hop, builds a [`RoutingView`] over live node state,
|
||||
//! calls [`Router::route`], and drives the returned [`RouteOutcome`] (the
|
||||
//! actual encrypted sends, metrics, and logging). No I/O, no clock, no
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
//!
|
||||
//! Pure, runtime-agnostic routing state and decision core, migrated out of
|
||||
//! the async node shell. The async I/O handlers remain in
|
||||
//! `node::handlers::forwarding`.
|
||||
//! `node::dataplane::forwarding`.
|
||||
//!
|
||||
//! - `core.rs` — the `RoutingView` read-seam trait, the `NextHop` /
|
||||
//! `RouteOutcome` types, `Router::route`, the pure transit-forward
|
||||
|
||||
Reference in New Issue
Block a user