Files
fips/src/proto/routing/mod.rs
T
Johnathan Corgan 7ccc7adab0 Merge maint into master, carrying the twenty-one security fixes
Not a replay: master had independently reorganized or reimplemented nearly
every area the batch touches, so most of this is re-derivation. Four files
maint modified do not exist on master at all, and git marks those DU with no
conflict markers, so the lazy resolution would have dropped 499 lines while
the tree still built and still passed tests.

Two conflicts turned out to be the same defect already present on master in a
different place, and fixing it there reaches further than the original did.
Master had centralized socket binding into sockbind across three sockets, one
of which maint does not have, with the same create-wide-then-narrow window; and
master's shared PerAddrRateLimiter swept the whole map on every admit with no
entry ceiling, which is the routing-error limiter finding in a primitive the
lookup-forward limiter also uses.

Two others would have added dead code if replayed. Master had already deleted
the pre-refactor restart block the epoch dampener patched, so it went onto
InboundDecision::RestartThenPromote instead; and master already carried the
relocated reactive-MTU floor check, so the copy inside the conflict was the old
post-apply one that had been removed.

The lookup dedup eviction was re-derived into the hoisted lookup core, and its
target-side signing gate re-added to the request path, where the merge had
dropped it entirely and left the limiter inert.

Two regression tests were repaired rather than accepted. The gap-tracker test
adapted into master's ReceiverState style asserted an empty burst after a jump
to the ceiling counter, which is not what that code does; and the epoch
dampener's stamp-on-acceptance ordering was pinned by nothing, so a sustained
replay could have starved a restarting peer with every test still green. Both
now red when the fix they guard is reverted.

Gate: fmt, build, clippy -D warnings, 2273 tests passing, six repo guards on
the committed tree.
2026-08-23 15:49:39 +01:00

38 lines
1.4 KiB
Rust
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
//! Sans-IO routing protocol state.
//!
//! Pure, runtime-agnostic routing state and decision core, migrated out of
//! the async node shell. The async I/O handlers remain in
//! `node::dataplane::forwarding`.
//!
//! - `core.rs` — the `RoutingView` read-seam trait, the `NextHop` /
//! `RouteOutcome` types, `Router::route`, the pure transit-forward
//! decision (local-vs-forward, transit TTL, path-MTU min-fold, ECN CE), and the
//! pure hop-selection / route-classification helpers (`RouteClass`,
//! `select_best_candidate`, `classify_forward`). Selection reads borrowed
//! per-peer data through the `RoutingView` seam; the shell keeps only the seam
//! impl.
//! - `state.rs` — `Router`, the routing-subsystem state owned by `Node`.
//! - `limits.rs` — the routing error-signal rate limiter.
//! - `wire.rs` — the routing error-signal PDUs (`CoordsRequired`,
//! `PathBroken`, `MtuExceeded`) and the `RoutingSignalType` (`0x20`–`0x2F`)
//! message-type registry split off from the FSP `SessionMessageType`.
mod core;
mod limits;
mod state;
mod wire;
#[cfg(test)]
mod tests;
pub(crate) use core::{
DropReason, NextHop, RouteAction, RouteClass, RouteOutcome, RoutingView, classify_forward,
select_best_candidate,
};
pub(crate) use limits::{LimitVerdict, RoutingErrorRateLimiter};
pub(crate) use state::Router;
pub use wire::{
COORDS_REQUIRED_SIZE, CoordsRequired, MTU_EXCEEDED_SIZE, MtuExceeded, PathBroken,
RoutingSignalType,
};