mirror of
https://github.com/jmcorgan/fips.git
synced 2026-08-09 16:24:45 +00:00
Merge branch 'refactor-node' into refactor-node-next
Forward-merge the dataplane/session concept-home reorganization onto the next line. The moved files carry next's (XX-line) content; the one hand-resolved surface is src/peer/active.rs, where the source-location citation sits in different surrounding text than on the master line — resolved by keeping next's body and applying the same node/session.rs -> node/session/mod.rs citation update.
This commit is contained in:
@@ -2780,12 +2780,12 @@ mod tests {
|
||||
/// Structural confirmation that the rx_loop no longer dispatches `show_*`:
|
||||
/// the rx_loop source carries no `queries::dispatch` call and no
|
||||
/// `starts_with("show_")` routing branch. Reads the committed source of
|
||||
/// `src/node/handlers/rx_loop.rs` and asserts both markers are absent. This
|
||||
/// `src/node/dataplane/rx_loop.rs` and asserts both markers are absent. This
|
||||
/// is the milestone's "remove `show_*` from the data-plane dispatch path"
|
||||
/// invariant, guarded against regression.
|
||||
#[test]
|
||||
fn rx_loop_has_no_show_dispatch() {
|
||||
let src = include_str!("../node/handlers/rx_loop.rs");
|
||||
let src = include_str!("../node/dataplane/rx_loop.rs");
|
||||
assert!(
|
||||
!src.contains("queries::dispatch"),
|
||||
"rx_loop must not call queries::dispatch (show_* served off-loop)"
|
||||
|
||||
@@ -0,0 +1,15 @@
|
||||
//! Data plane: the RX `select!` loop and the per-packet forwarding path.
|
||||
//!
|
||||
//! Holds the whole hot path in one home: the `select!` run loop
|
||||
//! (`rx_loop`), transit/local datagram forwarding (`forwarding`), the
|
||||
//! link-message router (`dispatch`), the RX decrypt path including responder
|
||||
//! K-bit cutover and address-roam writes (`encrypted`), and the per-peer
|
||||
//! connected-UDP fast-path socket activation (`connected_udp`). Each module
|
||||
//! contributes `impl Node` methods driven by the run loop.
|
||||
|
||||
#[cfg(unix)]
|
||||
pub(crate) mod connected_udp;
|
||||
mod dispatch;
|
||||
mod encrypted;
|
||||
mod forwarding;
|
||||
mod rx_loop;
|
||||
@@ -1,14 +1,8 @@
|
||||
//! RX event loop and message handlers.
|
||||
//! Message handlers: per-message-type behavior on `impl Node`.
|
||||
|
||||
#[cfg(unix)]
|
||||
pub(crate) mod connected_udp;
|
||||
mod dispatch;
|
||||
mod encrypted;
|
||||
mod forwarding;
|
||||
mod handshake;
|
||||
pub(crate) mod lookup;
|
||||
mod mmp;
|
||||
mod rekey;
|
||||
mod rx_loop;
|
||||
pub(in crate::node) mod session;
|
||||
mod timeout;
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
pub(crate) mod acl;
|
||||
mod bloom;
|
||||
pub(crate) mod context;
|
||||
mod dataplane;
|
||||
#[cfg(unix)]
|
||||
pub(crate) mod decrypt_worker;
|
||||
#[cfg(unix)]
|
||||
|
||||
+1
-1
@@ -222,7 +222,7 @@ pub enum MmpReject {
|
||||
/// Forwarding-path rejection reasons.
|
||||
///
|
||||
/// Each variant corresponds to a silent-rejection path in
|
||||
/// `src/node/handlers/forwarding.rs::handle_session_datagram`. Matching
|
||||
/// `src/node/dataplane/forwarding.rs::handle_session_datagram`. Matching
|
||||
/// `ForwardingStats` counters already track packets and bytes for each
|
||||
/// outcome; `record_reject` mirrors the packet-count side of the bump
|
||||
/// for parity with the other rejection clusters.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
//! Tests for the consecutive-decrypt-failure threshold force-removal path.
|
||||
//!
|
||||
//! Covers `Node::handle_decrypt_failure` (in `node/handlers/encrypted.rs`),
|
||||
//! Covers `Node::handle_decrypt_failure` (in `node/dataplane/encrypted.rs`),
|
||||
//! which increments `ActivePeer::increment_decrypt_failures` on each AEAD
|
||||
//! verification failure and force-removes the peer once
|
||||
//! `DECRYPT_FAILURE_THRESHOLD` consecutive failures are observed. The
|
||||
@@ -18,7 +18,7 @@ use super::*;
|
||||
/// the full `peers_by_index` cleanup path (not just the bare `peers` table).
|
||||
#[test]
|
||||
fn test_decrypt_failure_threshold_removes_peer() {
|
||||
// Threshold constant in node/handlers/encrypted.rs (kept in sync with
|
||||
// Threshold constant in node/dataplane/encrypted.rs (kept in sync with
|
||||
// production code; see DECRYPT_FAILURE_THRESHOLD).
|
||||
const THRESHOLD: u32 = 20;
|
||||
|
||||
|
||||
@@ -1241,7 +1241,7 @@ async fn test_should_admit_msg1_admits_rekey_when_udp_accept_off() {
|
||||
///
|
||||
/// The carve-out predicate must also consult peer state by source
|
||||
/// address: `current_addr()` is updated from inbound encrypted-frame
|
||||
/// source addrs (`handlers/encrypted.rs`), so an established peer can
|
||||
/// source addrs (`dataplane/encrypted.rs`), so an established peer can
|
||||
/// be matched even when the addr_to_link key is hostname-form and the
|
||||
/// incoming addr is numeric.
|
||||
#[tokio::test]
|
||||
|
||||
+1
-1
@@ -222,7 +222,7 @@ pub struct ActivePeer {
|
||||
// === Rekey msg3 retransmission (initiator liveness) ===
|
||||
/// Retained wire-format rekey msg3, resent until the responder is
|
||||
/// confirmed on the new epoch. Mirrors the FSP
|
||||
/// `rekey_msg3_payload` mechanism (node/session.rs). Liveness only:
|
||||
/// `rekey_msg3_payload` mechanism (node/session/mod.rs). Liveness only:
|
||||
/// overlapping-epoch decrypt covers cutover skew; retransmission
|
||||
/// guarantees the responder eventually derives the new session even
|
||||
/// if the first msg3 datagram is lost.
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
//! Sans-IO routing decision core.
|
||||
//!
|
||||
//! Pure, runtime-agnostic transit-forward decision for SessionDatagrams. The
|
||||
//! async I/O adapter in `node::handlers::forwarding` decodes the wire bytes,
|
||||
//! async I/O adapter in `node::dataplane::forwarding` decodes the wire bytes,
|
||||
//! pre-resolves the next hop, builds a [`RoutingView`] over live node state,
|
||||
//! calls [`Router::route`], and drives the returned [`RouteOutcome`] (the
|
||||
//! actual encrypted sends, metrics, and logging). No I/O, no clock, no
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
//!
|
||||
//! Pure, runtime-agnostic routing state and decision core, migrated out of
|
||||
//! the async node shell. The async I/O handlers remain in
|
||||
//! `node::handlers::forwarding`.
|
||||
//! `node::dataplane::forwarding`.
|
||||
//!
|
||||
//! - `core.rs` — the `RoutingView` read-seam trait, the `NextHop` /
|
||||
//! `RouteOutcome` types, `Router::route`, the pure transit-forward
|
||||
|
||||
Reference in New Issue
Block a user