You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Derive the serve peer's identity from its credential (#344)
ServeHello no longer carries a PeerID: the serve side has no source for it
and the credential already identifies the peer. The relay checks only the
Hello's Resource against the Authority's ServePeer, which still returns the
peer's identity. Updates the codec, validation, serve config, relay, tests,
golden frames and the Link protocol document.
Copy file name to clipboardExpand all lines: docs/sandbox-link-protocol.md
+2-3Lines changed: 2 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -18,7 +18,7 @@ A stream ends in one of two ways, and the relay keeps them apart end to end. An
18
18
19
19
The Sandbox I/O service runs `sandboxlink.Serve` with a `ServeConfig`:
20
20
21
-
-`URL`, `Credential` and `Resource` come from the [bootstrap input](sandbox-bootstrap.md). `PeerID`identifies the service. `ServerInstanceID` is a new ID whenever the service starts without its operation and handle registries.
21
+
-`URL`, `Credential` and `Resource` come from the [bootstrap input](sandbox-bootstrap.md). The credential identifies the service, so the Hello carries no peer ID. `ServerInstanceID` is a new ID whenever the service starts without its operation and handle registries.
22
22
-`Services` holds one handler per offered service and version. A handler receives the `Bind`, which carries the authorized binding including a File stream's exports, and the stream. It owns the stream and returns when it is done with it. Its context ends when the attachment closes or `Serve` returns.
23
23
-`Serve` reconnects with jittered exponential backoff, sending the same `ServerInstanceID`, whenever the link drops. It returns when its context ends or when the relay refuses the Hello with any failure other than `ServiceUnavailable` or `LimitExceeded`, for example `AuthenticationFailed` after the credential is withdrawn or `StaleGeneration` after a newer sandbox took over the resource. Before returning it cancels every handler's context and waits for the handlers.
24
24
-`OnAttachmentLost` fires when an attachment's last open stream ends while the attachment is still open, such as when the link drops. `OnAttachmentRestored` fires when a stream binds a lost attachment again. `OnAttachmentClosed` fires with the reason when the relay reports `AttachmentClosed`. Losing a socket is not closing an attachment: the service keeps an attachment's state until it is closed.
@@ -114,7 +114,6 @@ Hello
114
114
Version u16 // 1
115
115
Role enum // RoleServe = 1, RoleAttach = 2
116
116
if RoleServe:
117
-
PeerID ID
118
117
Credential bytes // 1..4096 bytes
119
118
Resource ResourceRef
120
119
ServerInstanceID ID
@@ -204,7 +203,7 @@ Later control requests continue the Hello's request IDs. The relay ends an attac
204
203
205
204
`HelloAccepted.MaxStreams` bounds the link's concurrent service streams. `MaxFrameBytes` bounds the payload of every frame on the link's service streams.
206
205
207
-
For a serve peer, the Authority returns the peer ID and the resource, including generation, that the credential serves. Both must equal the Hello's, otherwise the answer is `PermissionDenied`. The relay then applies the [generation rule](#authority-and-staleness) and makes the link the resource's current serve peer.
206
+
For a serve peer, the Authority returns the peer's identity and the resource, including generation, that the credential serves. The resource must equal the Hello's, otherwise the answer is `PermissionDenied`. The relay then applies the [generation rule](#authority-and-staleness) and makes the link the resource's current serve peer.
208
207
209
208
The relay and the serve peer bound each handshake step, the WebSocket upgrade, the Hello, reading an `Open`, a `Bind` and its answer and each Authority call, by `sandboxlink.HandshakeTimeout` (10 seconds). The attach peer bounds an Open with its context.
0 commit comments