1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
/*
* Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.
* SPDX-License-Identifier: Apache-2.0
*/
//! Connection pooling with explicit runtime and network placement.
//!
//! A [`ConnectionPool`] owns connection policy and a fixed set of partitions.
//! A [`Client`] binds Smithy HTTP operations to one partition. Pools without
//! explicit [`Partition`] values contain one anonymous partition; otherwise a
//! client selects a declared partition by [`PartitionId`].
//!
//! A partition owns connection establishment, protocol drivers, and idle
//! maintenance. [`ConnectionReuseScope`] controls whether another partition may
//! dispatch through those connections. Reuse transfers protocol dispatch
//! authority; it never moves the socket, driver, or capacity accounting.
//! Partitions in the same eligibility group are exactly those whose configured
//! reuse scope permits them to share a connection.
//!
//! Connection establishment and installed connection lifetime are separate
//! ownership phases:
//!
//! ```text
//! establishment task
//! |-- DNS, socket, proxy, TLS, and ALPN
//! `-- negotiated transport
//! `-- PendingOpen
//! |-- Hyper protocol setup
//! `-- Open
//! `-- pool installation
//! `-- discoverable -> draining -> closed
//! ```
//!
//! The establishment task and its permit represent work that may fail before a
//! physical connection exists. `ConnectionState` begins only after the
//! connector returns connected I/O and selects HTTP/1 or HTTP/2. For TLS, that
//! boundary follows TLS and ALPN. Hyper protocol setup moves the state from
//! `PendingOpen` to `Open`; cell installation then makes the connection
//! discoverable. Establishment and connection events can therefore be observed
//! independently without representing failed attempts as installed
//! connections.
//!
//! # State ownership
//!
//! ```text
//! ConnectionPool
//! `-- PoolInner
//! |-- immutable policy and transport factory
//! `-- PartitionRegistry
//! |-- PartitionState per partition
//! | |-- runtime placement and idle maintenance
//! | `-- OriginCell per canonical origin
//! | |-- acquisition queue and supply revisions
//! | |-- H1 connection ownership
//! | `-- H2 flights, generations, routes, and gates
//! `-- OriginAdmission per bounded origin
//! |-- capacity budget
//! |-- demand schedule
//! |-- H1 supply index and retained matches
//! `-- H2 supply index and route/reclaim state
//! ```
//!
//! One `OriginCell` lock owns local acquisition order and protocol state.
//! For a bounded origin, `OriginAdmission` separately owns the origin-wide
//! connection limit and cross-cell matching. An H2 request-claim lock records
//! independent upload and response completion. `ConnectionState` owns logical
//! connection lifetime, and partition maintenance owns its timer state.
//!
//! No two pool locks are held together. Demand snapshots and supply revisions
//! move cell state into admission. Assignments and detached guards carry one
//! selected payload or route back toward a cell. H2 claim completion detaches
//! its dispatch guard before entering connection or cell state.
//! Maintenance detaches cells and wakers before expiration or wake callbacks.
//!
//! # HTTP/1 request lifecycle
//!
//! Hyper represents an HTTP/1 connection with one exclusive
//! `SendRequest<SdkBody>` handle. This module calls that handle the sender. The
//! sender authorizes request dispatch but does not own the socket or protocol
//! driver.
//!
//! ```text
//! Client(partition, request)
//! `-- OriginCell(partition, origin)
//! |-- local idle sender --------------------------> H1Selection
//! `-- acquisition queue
//! |-- returned local or eligible peer sender -> H1Selection
//! |-- capacity permit -> establish HTTP/1 ---> H1Selection
//! `-- reclaimed peer capacity -> establish ---> H1Selection
//!
//! H1Selection -- Hyper accepts request --> H1Exchange
//! H1Exchange
//! |-- complete response + ready --> offer to owning OriginCell
//! `-- failure, cancellation, or upgrade ----------> retire pool record
//! ```
//!
//! A local hit touches only the cell lock. On a miss, one queued acquisition
//! remains authoritative while a returned sender and establishment race to
//! satisfy it. Bounded origins may borrow an eligible peer sender or reclaim a
//! peer connection and transfer its permit; active connections are not
//! reclaimed.
//!
//! Dispatch commits against logical close before Hyper receives the request.
//! Once accepted, the response lifecycle retains the sender until Hyper proves
//! a complete reusable message boundary. Failure retires the connection, and
//! an upgrade closes the pool record before exposing upgraded root I/O.
//!
//! # HTTP/2 request lifecycle
//!
//! One HTTP/2 connection carries many concurrent request streams. The pool
//! calls one installed incarnation of that connection a generation. A
//! replacement connection receives a new generation identity so delayed
//! close, route, and completion work cannot affect it.
//!
//! The connection-owning cell retains the generation's authoritative Hyper
//! request handle and capacity. A requesting cell may retain only a route that
//! names the owning cell and one exact accepting generation. Each use
//! revalidates that route before cloning a transient request handle.
//!
//! ```text
//! Client(partition, request)
//! `-- OriginCell(partition, origin)
//! |-- local accepting generation ----------------> H2Activation
//! `-- acquisition queue
//! |-- local flight result --------------------> H2Activation
//! |-- eligible peer generation route --------> H2Activation
//! `-- capacity permit -> connect + ALPN
//! |-- HTTP/2 -> join or drive one flight -> H2Activation
//! `-- HTTP/1 -> H1Selection or incompatible-version error
//!
//! H2Activation -- Hyper accepts request --> H2RequestClaim
//! H2RequestClaim
//! |-- request body ends or drops -----> upload side complete
//! `-- response body ends or drops ----> response side complete
//! both sides complete --------------------> release generation request count
//! ```
//!
//! `H2Activation` reserves pool accounting for a prospective stream on one
//! exact generation. It is not yet an HTTP/2 stream. Dropping it before Hyper
//! accepts the request returns its generation-gate turn and request count.
//! Acceptance creates two independent completion sides because upload and response
//! can finish in either order. Logical close stops new activations and releases
//! bounded capacity; accepted streams retain the draining generation until
//! both sides end. Hyper remains responsible for stream identifiers,
//! stream credit, and flow control.
//!
//! A peer route moves only generation identity. The socket, protocol driver,
//! request handle, and capacity remain with the connection-owning partition.
//!
//! `ConnectionState` separates logical close, accepted-request accounting, and
//! physical connection ownership. Logical close rejects new dispatch and
//! normally releases bounded capacity while accepted work drains. An HTTP/1
//! upgrade retains capacity until upgraded root I/O leaves the client.
//! `DispatchGuard` follows an accepted request, while
//! `PhysicalConnectionGuard` follows root I/O until the client releases its
//! transport handle. The operating system may continue TCP teardown afterward.
//! All connection-owned work runs through the partition
//! [`DriverSpawner`].
//!
//! # Observation
//!
//! A pool-wide [`ConnectionEventListener`] observes establishment failure,
//! successful installation, logical close, and release of the client's root
//! transport handle. Callbacks run synchronously after pool locks are released.
//! Observation is disabled unless a listener is configured.
//!
//! [`ConnectionPool::origin_stats`] reports the bounded capacity shared by all
//! partitions for one canonical origin. [`ConnectionPool::partition_stats`]
//! reports request acquisition and connection state for one exact
//! partition-origin cell. These snapshots are diagnostic; the pool does not use
//! them for admission, reuse, reclaim, routing, or dispatch.
pub use ;
pub use ;
pub use ;
pub use ;
pub use ;
pub use ;
pub use ;
pub use crateConnectPath;
use crateArc;
use ConnectorError;
use SdkBody;
use TransportFactory;
use ;
use ;
use fmt;
use NonZeroUsize;
use AtomicU64;
use Arc as StdArc;
use Duration;
/// Shared connection topology and pooling policy.
///
/// Construct a pool with [`ConnectionPool::builder`], then create [`Client`]
/// handles for its anonymous or explicit partitions. The pool itself owns no
/// request placement; each client supplies that partition choice. Cloning a
/// pool or client shares all retained connections and admission state.
///
/// A pool built with explicit partitions does not also create an anonymous
/// partition. Dropping the final shared owner logically closes retained
/// connections and stops partition maintenance.
/// Immutable pool policy retained with the partition registry.
/// Shared implementation state behind [`ConnectionPool`].