Skip to main content

mkit_server/ssh/
mod.rs

1//! The `mkit.rpc.v1.ssh` session over the pipeline (PRD §6.9, D23;
2//! SPEC-TRANSPORT §4.2): the `Hello` handshake, per-verb dispatch, the
3//! streaming upload and download, the per-connection budgets and the CAS
4//! conflict reply of `mkit serve`, moved here from `mkit-cli` so the ssh
5//! stdio path and any enc listener share one implementation.
6//!
7//! [`serve_session`] is transport-agnostic: it reads frames from a
8//! [`FrameSource`] and writes them to a [`FrameSink`], and never spawns or
9//! sleeps, so it runs under a blocking executor (`mkit serve` over stdio)
10//! as well as under tokio (an enc listener). [`ReadFrames`] and
11//! [`WriteFrames`] adapt blocking `std::io` streams. The wire is frozen:
12//! responses and error frames are `mkit serve`'s byte for byte, pinned by
13//! `rust/tests/golden/ssh-serve/`.
14//!
15//! The pipeline runs in `AuthMode::TransportIdentity` with the principal
16//! the transport established (`SshForcedCommand` for stdio,
17//! `TransportPeer` for enc), so no replay record or quota is written.
18
19mod budget;
20mod io;
21mod session;
22#[cfg(test)]
23mod tests;
24mod verbs;
25
26pub use budget::{MAX_BYTES_PER_CONN, MAX_FRAMES_PER_CONN, frame_byte_estimate, upload_limits};
27pub use io::{ReadFrames, WriteFrames};
28pub use session::{
29    FrameIoError, FrameSink, FrameSource, SessionConfig, SessionEnd, handshake, serve_session,
30};
31pub use verbs::{PAYMENT_REQUIRED_FRAME, cas_conflict_body};