Skip to content

conformance: sslmode through the host's TLS (Q-P4-9): the suite's host connector and a TLS front over the live Postgres - #21

Merged
MattJackson merged 16 commits into
devfrom
p4-conf-host
Oct 5, 2026
Merged

MattJackson merged 16 commits into
devfrom
p4-conf-host

Conversation

@MattJackson

Copy link
Copy Markdown
Contributor

ARCHITECT Q-P4-9 / pin-check ruling. Stacks on #20. Pinned to busbar lane-p4-fleet-doors daf4c0275e.

  • declares.json: needs: ["tcp"]; rendered with GetBusbar/busbar-release#162 (+#161 parity-lines): the host adapter, dev-deps, one-contract patch, deny sources; Cargo.lock from busbar's lock at the pin.
  • conformance.json: sslmode=require against the suite's TLS front (localhost:52670); the front answers SSLRequest, the TLS is the HOST's (busbar's connector, upgrade_secure), verified against the CA that signed the front's certificate (tls: conformance_host::anchors()), and it carries the connection to the live Postgres service.
  • RED: with tls: withheld the store does not open.

Do not merge.

ARCHITECT rulings 2026-10-03 on Q-L14-1 and Q-L16-2 (busbar THE DESIGN: every call Ready or
Pending(wake); no plugin opens its own socket). Depends on busbar lane-dg-storebridge@c7cc4f6696.

- The logic crate drops the `postgres` driver. src/pgwire.rs is an async Postgres frontend on the
  sans-IO postgres-protocol (messages, SCRAM-SHA-256, md5) and postgres-types (the same binary
  ToSql/FromSql the 1.5.5 driver used), every byte over the op's one connection (store SDK
  wire::drive / Op::checkout). Parse/Describe/Sync then Bind/Execute/Sync, binary values; an
  uncommitted Transaction is rolled back before the connection's next statement.
- store_door!(.., needs: NEEDS): one outbound `tcp` need, operator-infrastructure, target = the
  DSN's host:port. `open` parses the settings (same refusal texts); StoreSlots::connect connects,
  authenticates and migrates, so an unreachable or refusing server still fails the load at boot in
  the driver's words ("error connecting to server: ...", password scrubbed).
- Every op is one connection: startup + auth, the 1.5.5 SQL body (now on a Session, with .await),
  Terminate. RepeatableRead snapshots, advisory locks, SQLSTATE checks, render_pg_error/scrub and
  the durable op_id dedupe are unchanged. sslmode=require|verify-* -> SSLRequest + upgrade_secure
  through the host; the other modes stay plaintext as 1.5.5's NoTls.
- The plugin crate exports only the door; the cold-lane registration is deleted.
- busbar pinned at c7cc4f6696d53654ba1ac4f8e8c4fad0b9cd9df8 (manifests, .busbar-ref, workflows).

Tests open the store through the real loader with busbar's test connection table (tcp_conns),
raw verification on an independent `postgres` connection (dev-dependency). The metering test moves
to bucket 20_270_611: it raced the purge test on 20_270_601.
…root connector wakes a plugin's pending connection and drives dispatcher-worker sockets on its own I/O thread; the real-binary e2e tests need it)
…ion); TLS test through the host; busbar pin 180d92c205 -> 8faed15ca4

ARCHITECT rulings 2026-10-03 12:10Z (STORE-KEEP, TLS).

- STORE-KEEP: the instance holds the store SDK's kept set (wire::Pool) bounded at KEPT_CONNECTIONS = 1,
  1.5.5's one mutex-guarded connection (the 1.5.5 store has no pool setting). The connect step and
  every op run under wire::drive_kept: a kept connection skips TLS + startup/auth; the connection is
  kept only if the session is idle (last ReadyForQuery status I, nothing unread, no rollback
  pending; pgwire::Client::release), and a client dropped any other way (early return, protocol
  failure, open or failed transaction) discards it, so the next op connects afresh. No retry 1.5.5
  did not have.
- TLS: unchanged mapping (disable/allow/prefer plaintext as 1.5.5 NoTls; require/verify-* SSLRequest,
  'S', upgrade_secure on the DSN host; 'N' fails the load). Docs say the host always verifies.
- Tests: src/tests/tls.rs (live): verify_full_secures_the_connection_through_the_host (in-test TLS
  proxy with a per-run rcgen CA in front of the live server; TcpConns::with_roots),
  an_untrusted_server_certificate_fails_the_load_in_the_drivers_words,
  the_store_keeps_one_connection_across_its_ops (one backend pid across the connect step and ten
  ops). The harness closes each test store's instance on drop. rustls/rustls-pki-types/rcgen are
  dev-dependencies only.
- Pin: busbar 8faed15ca46ec48d5818dc0bd0c22a9c15218de1 (manifests, .busbar-ref, workflows, Cargo.lock).
…dStore closes its instance on drop)

The harness's own close-on-drop workaround is struck: busbar's LoadedStore now closes its instance
when dropped, and its kept connection with it. the_store_keeps_one_connection_across_its_ops again
asserts that dropping the store closes its backend connection. The full live suite runs at the
server's default max_connections (100).
The fleet's bothways gate needs a RED arm in the conformance target as a test of its own. The
foreign-bytes arm and the as-another-kind arm move out of
the_linked_and_the_dropped_in_postgres_store_are_one_store into
foreign_bytes_dropped_in_are_not_the_postgres_store and
the_postgres_store_library_loaded_as_another_kind_is_refused, every assertion kept; neither needs a
database. The loader at the pin dlopens the path it is given (no memfd), and the foreign image sits
under its own directory, so the arm no longer depends on running first.
Seeded from busbar's Cargo.lock at the pin and re-resolved: every crate both locks hold is at
busbar's version (rustls 0.23.43 -> 0.23.45 clears RUSTSEC-2026-0285), except the sha2 0.11 line
postgres-protocol 0.6.12 needs (sha2 0.11.0, digest 0.11.3, block-buffer 0.12.1, crypto-common
0.2.2, const-oid 0.10.2) and wasi 0.14.7 (dev-only: postgres -> tokio-postgres 0.7.18 -> whoami 2).
Older postgres-protocol (<= 0.6.10, sha2 0.10) carries RUSTSEC-2026-0179/0180 and tokio-postgres
< 0.7.18 RUSTSEC-2026-0178.
…d lines); Cargo.lock re-derived from busbar's lock at the pin

Seeded from busbar's Cargo.lock at d85c166728 and re-resolved: every crate both locks hold is at
busbar's version except the lines busbar's .github/fleet/deps.toml [parity-lines] declares for this
repo (sha2 0.11, digest 0.11, block-buffer 0.12, crypto-common 0.2, const-oid 0.10 shipped through
postgres-protocol 0.6.12; wasi 0.14 tests-only through the postgres test client). xtask plugin-gates
parity at the pin: 0 findings.
…-release #161: the [parity-lines] rows open their lines)

The workspace table and deny.toml are the render of busbar-release PR #161 (p4-parity-lines,
f20a4dc) at pin d85c166728: busbar's dependency policy at the pin, and the declared sha2 0.11,
digest 0.11, block-buffer 0.12, crypto-common 0.2, const-oid 0.10 and wasi 0.14 lines allowed. rcgen
now comes from the workspace table (its row carries the features the TLS test asked for).
…store script over the live Postgres)

store-postgres-plugin/tests/conformance.rs runs busbar_plugin_loader::conformance_suite! over the
logic crate's door and the built cdylib, with conformance.json naming the CI service
(postgres://busbar:busbar@localhost:5432/busbar_test) and the store section's inputs. The repo's
own both-ways test and its two RED tests stay beside it. busbar-plugin-loader gains the
`conformance` feature as a dev-dependency.

The suite's both-ways arm and two of its RED arms do not pass against this store at d85c166728:
the store script pins one crossing per op, but every op of a store that talks to its server over the
connector pends on its reads and is resumed (measured 2 to 26 crossings per op); red_ready expects
`open` to answer READY in one call while this store connects in `open`; the script's credentials
are kind "generic", which the store's schema refuses (kind IN ('sigv4')); and both legs (and the
parallel RED fold) share one database under the same ids and op ids.
… (busbar d85c166728 TcpConns::with_tls)

At the pin the loader's test table names no TLS library: TcpConns::with_roots is gone and a test
hands it the TLS it secures with. The TLS test's is rustls trusting the run's CA alone (certificate
and name verified), the handshake the old with_roots ran, moved into the test.
…uires a store: block)

At the pin busbar refuses a config without `store:` (BUSBAR-9007), so the first boot's config now
names `store: {module: memory}`, the RAM store the absent block used to mean.
…-fold namespace and resumes); Cargo.lock re-derived from busbar's lock at the pin; Cargo.toml and deny.toml the busbar-release #161 render at the pin

xtask plugin-gates parity at the pin: 0 findings; cargo deny: clean.
At the pin a Bind's table is a ConnTable: the live tests' binds are ConnTable::Host over the
loader's test table; the as-another-kind RED test binds a Probe (no table, nothing opened), so its
refusal is still the kind's.
…-fold namespace hooks); Cargo.lock re-derived from busbar's lock at the pin; Cargo.toml and deny.toml the busbar-release #161 render at the pin

xtask plugin-gates parity at the pin: 0 findings; cargo deny: clean.
…e hooks, search_path={fold}), credential kind sigv4

conformance.json's url sets search_path to the fold's namespace; the suite's namespace hooks
create that schema before each fold and drop it (CASCADE) after, on an independent connection of
the postgres driver, so the two legs and CI's debug, release and RED runs never share rows. The
store's credential kind input is sigv4, the one its schema holds. Locally (Postgres 17): the suite's
six tests and the repo's three pass in release and debug, the moved count fails on the comparator,
and no fold schema is left behind.
…uite's host connector, a TLS front over the live Postgres, pinned to busbar lane-p4-fleet-doors daf4c0275e

- declares.json states the store's network need (`needs: ["tcp"]`), the data the fleet render reads.
- Rendered by busbar-release #162 (with #161's parity-lines, merged locally) at
  `plugin render busbar-store-postgres --tree . --out . --pin daf4c0275e... 1.6.0`: the pin, the
  host adapter (store-postgres-plugin/tests/support/conformance_host.rs), its dev-dependency rows
  (busbar-core-connector with test-support, busbar-transport-tcp at busbar's rev), the
  one-contract [patch], deny's sources; Cargo.lock re-resolved from busbar's lock at the pin.
- conformance.json's url names the suite's TLS front (localhost:52670) with sslmode=require; the
  store's SSLRequest is answered by the front, the TLS is the HOST's (upgrade_secure through
  busbar's connector), verified against the suite's test CA (`tls: conformance_host::anchors()`,
  the CA that signed the front's certificate), and the front carries the secured connection to the
  live Postgres (BUSBAR_TEST_POSTGRES_URL's authority). The namespace hooks reach the live server
  directly, in the clear, on the test's own client.

Local (postgres 17 on loopback): fmt, clippy -D warnings, cargo deny, pin-check, the conformance
target debug and --release 11/11; RED: with `tls:` withheld the store does not open (both_ways
panics at the open); BUSBAR_CONFORMANCE_RED=count fails with "crossing(s), pinned".
@MattJackson
MattJackson merged commit 8658327 into dev Oct 5, 2026
5 checks passed
@MattJackson
MattJackson deleted the p4-conf-host branch October 5, 2026 16:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant