Skip to main content

Module ssh

Module ssh 

Source
Expand description

The mkit.rpc.v1.ssh session over the pipeline (PRD §6.9, D23; SPEC-TRANSPORT §4.2): the Hello handshake, per-verb dispatch, the streaming upload and download, the per-connection budgets and the CAS conflict reply of mkit serve, moved here from mkit-cli so the ssh stdio path and any enc listener share one implementation.

serve_session is transport-agnostic: it reads frames from a FrameSource and writes them to a FrameSink, and never spawns or sleeps, so it runs under a blocking executor (mkit serve over stdio) as well as under tokio (an enc listener). ReadFrames and WriteFrames adapt blocking std::io streams. The wire is frozen: responses and error frames are mkit serve’s byte for byte, pinned by rust/tests/golden/ssh-serve/.

The pipeline runs in AuthMode::TransportIdentity with the principal the transport established (SshForcedCommand for stdio, TransportPeer for enc), so no replay record or quota is written.

Structs§

ReadFrames
A FrameSource over a blocking reader.
SessionConfig
A session’s settings.
WriteFrames
A FrameSink over a blocking writer; each frame is flushed.

Enums§

FrameIoError
Why a frame could not be read or written.
SessionEnd
How a session ended. mkit serve maps Self::Clean and Self::IoError to exit::OK and the rest to exit::PROTOCOL_ERROR.

Constants§

MAX_BYTES_PER_CONN
Most estimated request bytes per session (1 GiB); see frame_byte_estimate. It also caps an upload’s declared size.
MAX_FRAMES_PER_CONN
Most top-level frames a session reads after Hello. The chunk frames an upload reads are not counted here; UploadLimits::max_chunks caps them instead.
PAYMENT_REQUIRED_FRAME
The frame message for a write whose admission needs a payment or a reservation: ssh and enc cannot carry either, so the client is told to use HTTPS. Sent as INVALID_REQUEST with empty details, so a client never reads it as a ref conflict; the frozen ErrorCode set is unchanged.

Traits§

FrameSink
Where a session writes its frames.
FrameSource
Where a session reads its frames.

Functions§

cas_conflict_body
The SPEC-TRANSPORT §4.2.1 reply to a failed CAS: Error{INVALID_REQUEST} whose details is the ref’s current id, or empty when the ref is absent, mirroring ReadRefResponse’s empty-means-absent encoding. Strict clients classify a non-empty details as RefConflict and surface the empty case’s message as a remote error, rather than fabricating a current id.
frame_byte_estimate
A frame’s cost against MAX_BYTES_PER_CONN, without re-encoding: a chunk’s data length, the total_bytes a header declares, or 64 for a small control frame. An upload is charged its declared size once, by its header; the chunks it then reads are not charged again.
handshake
The application handshake (SPEC-RPC §4): the first frame must be a protocol-1 Hello, answered by a HelloResponse carrying server_id.
serve_session
Serve one ssh-frame session: the handshake, then one verb per top-level frame until Close, a clean end of stream, a protocol error or a failure. Each verb runs on pipeline as principal.
upload_limits
The upload caps of the ssh wire: a declared size of at most MAX_BYTES_PER_CONN and at most MAX_FRAMES_PER_CONN chunks. A binding builds its pipeline’s PipelineConfig with these.