Skip to content

Link: order the streams of an attachment by bind sequence - #358

Merged
SaladDay merged 2 commits into
feature/agent-outside-sandboxfrom
aos/link-bind-seq
Oct 1, 2026
Merged

SaladDay merged 2 commits into
feature/agent-outside-sandboxfrom
aos/link-bind-seq

Conversation

@SaladDay

@SaladDay SaladDay commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Link protocol change, split out of the File protocol fixes (plan row 6a, L1c) so that it gets its own review.

What changes

  • sandboxlink.ServiceHandler.Serve now also receives a bind sequence: func(ctx, Bind, seq uint64, Stream).
  • The serve peer assigns the sequence under track's lock, before it answers Bound. A stream of an attachment that binds later therefore gets a larger sequence, however late its handler runs.
  • docs/sandbox-link-protocol.md § "Implement a serve peer" states that order. A service may rely on it to fence the succession of an attachment's streams.

Why

The File protocol's stream succession fence admits one stream per attachment at a time. Without this change, its order would come from when each handler reaches the File server, which can differ from bind order. This PR only adds the sequence; the File protocol PR that follows uses it.

Callers

  • netservice and the gateway test take the new parameter.
  • In sandboxio, the File and Process handlers accept and ignore it, so the File protocol is unchanged at this commit.

Checks

  • go build ./...
  • go vet ./internal/sandboxlink/... ./apps/sandboxio/... ./apps/daemon/...
  • go test -race -count=1 ./internal/sandboxlink/... ./apps/sandboxio/... ./apps/daemon/internal/gateway/
  • GOOS=darwin and GOOS=windows builds of ./internal/sandboxlink/... ./apps/daemon/...

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

The serve peer assigns each bound stream a sequence under its tracking lock,
before it answers Bound, and passes it to the service handler. A stream bound
later gets a larger sequence however late its handler runs, so a service can
fence a stream's successor by bind order. Handlers that need no order ignore
it.
@SaladDay
SaladDay merged commit 880532b into feature/agent-outside-sandbox Oct 1, 2026
@SaladDay
SaladDay deleted the aos/link-bind-seq branch October 1, 2026 03:33
TestBindSequence opens two streams of one attachment, lets the later one's
handler report first, reconnects the serve peer and opens a third; the
sequences the handlers saw must increase strictly from above zero. The
ServiceHandler comment and the Link guide define bind order as the order of
assignment under the serve peer's tracking lock, which concurrent Bound and
Opened replies need not follow, and scope the sequence to one Serve call:
it survives reconnects and increases strictly, with gaps.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant