1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
//! The methods that had no JSON-RPC equivalent before #6286.
//!
//! Why: `transport::rpc::dispatch` already routed the whole tool surface —
//! `palace_*`, `memory_*`, `kg_*`, the MCP protocol arms — and mounts whole
//! through [`RpcFallback`]. What it did NOT route was the roughly twenty
//! endpoints that existed only as axum routes: `/api/v1/status`, `/config`,
//! `/health`, the drawer CRUD, seven KG reads, the dream trio, `/activity`,
//! `/logs/tail`, `/admin/stop`, the async remember, chat and the three message
//! endpoints. Retiring the listener without folding those would delete
//! behaviour rather than move it.
//!
//! What: one submodule per former route file, each handler converted from an
//! axum extractor signature to `(&AppState, Params) -> Result<Value, ApiError>`
//! — a plain async function with no framework in it. [`super::uds::build_router`]
//! is what binds them to names.
//!
//! Why a separate module tree rather than more arms in `transport/rpc.rs`: that
//! file is already 574 lines against the 500 SLOC cap, and these handlers have
//! nothing to do with its envelope types.
//!
//! [`RpcFallback`]: trusty_common::uds::server::RpcFallback
//!
//! Test: `super::uds::tests` — `rpc_*` over a real socket.
use ;
use crate;
/// The palace `memory.health`'s round-trip probe writes into (#185).
///
/// Why: earlier revisions probed whichever palace happened to be first on disk,
/// so the check wrote — and, when recall failed, LEAKED — a drawer in a real
/// user-facing palace. The `__` prefix is this project's convention for a
/// system palace, which `MemoryService::list_palaces` filters out, so a leaked
/// drawer is confined somewhere the user never sees.
/// Test: `health_probe_palace_is_invisible`.
pub const HEALTH_PROBE_PALACE: &str = "__health_probe__";
/// The params of a method that takes no arguments.
///
/// Why: `RpcRouter::typed` decodes `params` into the handler's request type
/// before the handler runs, and `params` is absent — `Value::Null` — on a
/// well-formed call to a no-argument method. A plain unit struct refuses
/// `null`, so every `memory.status` call would answer `invalid_params`.
/// What: accepts anything and keeps nothing. A caller that sends a stray field
/// is not refused: these methods have no arguments to get wrong.
/// Test: `rpc_status_answers_with_no_params`.
;
/// The params of a method that names one palace and nothing else.
///
/// The id used to be a path segment; on this wire it is a field, so the eight
/// methods that took only `{id}` share one type.
/// Who is calling, as the caller itself reports.
///
/// Why: attribution used to arrive in `X-Trusty-Client-*` headers, and a
/// JSON-RPC frame has no header channel. The fields move into `params`, keeping
/// the rule the headers encoded (DOC-53 §4.3): the daemon never reads its OWN
/// environment for caller identity, because it is one shared process serving
/// every attached session. What it knows is what the caller sent.
/// What: all three optional, mirroring the headers' optionality; [`creator`]
/// applies the same precedence `CreatorInfo::new_for_caller` always did.
/// Test: `rpc_drawer_create_attributes_the_caller_it_was_given`.
///
/// [`creator`]: CallerParams::creator
/// Parse an optional ISO-8601 timestamp, refusing a value it cannot read.
///
/// Why: `since` / `until` are caller-supplied. Dropping an unparseable one
/// silently would return a correct-looking page filtered by something other
/// than what was asked for.
/// What: `None` and `""` are absent; anything else must be RFC 3339.
/// Test: `rpc_activity_refuses_an_unparseable_since`.
/// Serialise a handler's own response type into the `result` half.
///
/// Why: every folded handler answers `Value` so one registration shape covers
/// all of them, and a handler whose response will not serialise is a programmer
/// error on this side of the wire rather than anything the caller sent.