Expand description
The mkit.rpc.v1.ssh session over the pipeline (PRD §6.9, D23;
SPEC-TRANSPORT §4.2): the Hello handshake, per-verb dispatch, the
streaming upload and download, the per-connection budgets and the CAS
conflict reply of mkit serve, moved here from mkit-cli so the ssh
stdio path and any enc listener share one implementation.
serve_session is transport-agnostic: it reads frames from a
FrameSource and writes them to a FrameSink, and never spawns or
sleeps, so it runs under a blocking executor (mkit serve over stdio)
as well as under tokio (an enc listener). ReadFrames and
WriteFrames adapt blocking std::io streams. The wire is frozen:
responses and error frames are mkit serve’s byte for byte, pinned by
rust/tests/golden/ssh-serve/.
The pipeline runs in AuthMode::TransportIdentity with the principal
the transport established (SshForcedCommand for stdio,
TransportPeer for enc), so no replay record or quota is written.
Structs§
- Read
Frames - A
FrameSourceover a blocking reader. - Session
Config - A session’s settings.
- Write
Frames - A
FrameSinkover a blocking writer; each frame is flushed.
Enums§
- Frame
IoError - Why a frame could not be read or written.
- Session
End - How a session ended.
mkit servemapsSelf::CleanandSelf::IoErrortoexit::OKand the rest toexit::PROTOCOL_ERROR.
Constants§
- MAX_
BYTES_ PER_ CONN - Most estimated request bytes per session (1 GiB); see
frame_byte_estimate. It also caps an upload’s declared size. - MAX_
FRAMES_ PER_ CONN - Most top-level frames a session reads after
Hello. The chunk frames an upload reads are not counted here;UploadLimits::max_chunkscaps them instead. - PAYMENT_
REQUIRED_ FRAME - The frame message for a write whose admission needs a payment or a
reservation: ssh and enc cannot carry either, so the client is told to use
HTTPS. Sent as
INVALID_REQUESTwith emptydetails, so a client never reads it as a ref conflict; the frozenErrorCodeset is unchanged.
Traits§
- Frame
Sink - Where a session writes its frames.
- Frame
Source - Where a session reads its frames.
Functions§
- cas_
conflict_ body - The SPEC-TRANSPORT §4.2.1 reply to a failed CAS:
Error{INVALID_REQUEST}whosedetailsis the ref’s current id, or empty when the ref is absent, mirroringReadRefResponse’s empty-means-absent encoding. Strict clients classify a non-emptydetailsasRefConflictand surface the empty case’s message as a remote error, rather than fabricating a current id. - frame_
byte_ estimate - A frame’s cost against
MAX_BYTES_PER_CONN, without re-encoding: a chunk’s data length, thetotal_bytesa header declares, or 64 for a small control frame. An upload is charged its declared size once, by its header; the chunks it then reads are not charged again. - handshake
- The application handshake (SPEC-RPC §4): the first frame must be a
protocol-1
Hello, answered by aHelloResponsecarryingserver_id. - serve_
session - Serve one ssh-frame session: the handshake, then one verb per top-level
frame until
Close, a clean end of stream, a protocol error or a failure. Each verb runs onpipelineasprincipal. - upload_
limits - The upload caps of the ssh wire: a declared size of at most
MAX_BYTES_PER_CONNand at mostMAX_FRAMES_PER_CONNchunks. A binding builds its pipeline’sPipelineConfigwith these.