Skip to main content

recall_wire/
discovery.rs

1//! What a server says about itself, and what a client says about itself.
2//!
3//! `GET /.well-known/recall` answers with a [`Discovery`] document: which
4//! protocol versions the server speaks, which release it is, the oldest
5//! client it accepts, how clients may authenticate, and what it can do. It
6//! is unauthenticated, like `/health`, and at the path RFC 8615 sets aside
7//! for exactly this kind of document.
8//!
9//! The rules that keep it readable by clients that do not exist yet, taken
10//! from git protocol v2, Matrix's `/versions` and MCP:
11//!
12//! 1. **Two layers.** [`Protocol`] changes only for a breaking change; the
13//!    capabilities only ever grow.
14//! 2. **Unknown keys are ignored**, at any depth. Nothing here denies
15//!    unknown fields, and a client must not either.
16//! 3. **Absent means unsupported.** A capability that is not listed is not
17//!    available.
18//! 4. **A map, not a list.** Each capability is an object, so it can carry
19//!    parameters later without a new key.
20//! 5. **Nothing is removed** within a protocol version.
21//!
22//! In the other direction, every request a client sends carries
23//! [`PROTOCOL_HEADER`] and a `User-Agent` of the form [`user_agent`] builds.
24
25use std::collections::BTreeMap;
26
27use serde::{Deserialize, Serialize};
28
29/// Where the discovery document is served.
30pub const DISCOVERY_PATH: &str = "/.well-known/recall";
31
32/// The protocol version this build speaks.
33pub const PROTOCOL: u32 = 1;
34
35/// The request header a client names its protocol version in. A request
36/// without it is treated as protocol 1, which is what every client before
37/// the header existed spoke.
38pub const PROTOCOL_HEADER: &str = "recall-protocol";
39
40/// The discovery document.
41#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
42pub struct Discovery {
43    /// The protocol versions the server speaks.
44    pub protocol: Protocol,
45    /// Which build of the server this is.
46    pub server: ServerInfo,
47    /// The oldest client version the server accepts, as SemVer.
48    pub min_client: String,
49    /// How clients may authenticate.
50    pub auth: Auth,
51    /// What the server can do, by name. An absent name is unsupported.
52    #[serde(default)]
53    pub capabilities: BTreeMap<String, serde_json::Value>,
54}
55
56impl Discovery {
57    /// Whether the server speaks protocol `version`.
58    pub fn speaks(&self, version: u32) -> bool {
59        self.protocol.supported.contains(&version)
60    }
61
62    /// Whether the server lists the capability `name`.
63    pub fn can(&self, name: &str) -> bool {
64        self.capabilities.contains_key(name)
65    }
66
67    /// Whether the server accepts the authentication method `name`, such
68    /// as [`AUTH_DEVICE_SIG`].
69    pub fn accepts(&self, name: &str) -> bool {
70        self.auth.methods.iter().any(|m| m == name)
71    }
72
73    /// The [`CAPABILITY_DEVICES`] capability, read into its type. [`None`]
74    /// when the server does not list it, and also when it lists one this
75    /// build cannot read, which is the same answer: a client cannot use it.
76    pub fn devices(&self) -> Option<crate::DevicesCapability> {
77        serde_json::from_value(self.capabilities.get(CAPABILITY_DEVICES)?.clone()).ok()
78    }
79
80    /// The [`CAPABILITY_AUDIT`] capability, read into its type: [`None`]
81    /// from a server that keeps no audit log (one older than 0.4.2), or
82    /// lists one this build cannot read.
83    pub fn audit(&self) -> Option<crate::AuditCapability> {
84        serde_json::from_value(self.capabilities.get(CAPABILITY_AUDIT)?.clone()).ok()
85    }
86}
87
88/// The protocol versions a server speaks.
89#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
90pub struct Protocol {
91    /// The newest one, which a server's own client speaks.
92    pub current: u32,
93    /// Every version the server accepts requests in.
94    pub supported: Vec<u32>,
95}
96
97/// Which build of the server answered.
98#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
99pub struct ServerInfo {
100    /// The server's identity, as SemVer: the release version for a release
101    /// build, and a `-dev` pre-release of the next patch for anything else.
102    pub version: String,
103    /// Where the build came from.
104    pub build: Build,
105}
106
107/// Where a build came from. Provenance only: nothing is decided on it.
108#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
109pub struct Build {
110    /// [`CHANNEL_RELEASE`] for a release build, [`CHANNEL_DEV`] otherwise.
111    pub channel: String,
112    /// The commit it was built from, when known.
113    #[serde(default, skip_serializing_if = "Option::is_none")]
114    pub revision: Option<String>,
115    /// When it was built, in RFC 3339, when known.
116    #[serde(default, skip_serializing_if = "Option::is_none")]
117    pub created: Option<String>,
118}
119
120/// How a client may authenticate.
121#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
122pub struct Auth {
123    /// The methods the server accepts, by name, e.g. [`AUTH_BEARER`].
124    pub methods: Vec<String>,
125}
126
127/// The one shared bearer token, `RECALL_TOKEN`.
128pub const AUTH_BEARER: &str = "bearer";
129
130/// Requests signed by an enrolled device's key: see
131/// [`crate::signature`].
132pub const AUTH_DEVICE_SIG: &str = "device-sig-v1";
133
134/// The capability a server lists when it enrols devices; its parameters
135/// are a [`crate::DevicesCapability`].
136pub const CAPABILITY_DEVICES: &str = "devices";
137
138/// The capability a server lists when it can queue a stale push for a
139/// merge worker and has the job routes (see [`crate::jobs`]). A worker
140/// asks for it before enrolling, and works for no server without it.
141pub const CAPABILITY_MERGE_QUEUE: &str = "merge_queue";
142
143/// The capability a server lists when it makes evaluation reports: the
144/// routes in [`crate::evaluations`], and `evaluate` jobs for a worker.
145pub const CAPABILITY_EVALUATION: &str = "evaluation";
146
147/// The capability a server lists when it keeps an audit log (see
148/// [`crate::audit`]); its parameters are a [`crate::AuditCapability`],
149/// which says how large a page of entries may be.
150pub const CAPABILITY_AUDIT: &str = "audit";
151
152/// A build made by the release workflow from a release tag.
153pub const CHANNEL_RELEASE: &str = "release";
154
155/// Any other build: from `main`, from a pull request, or on someone's
156/// machine.
157pub const CHANNEL_DEV: &str = "dev";
158
159/// This build's channel, decided at compile time by `build.rs`:
160/// `RECALL_BUILD_CHANNEL` when set, otherwise `dev` for a git checkout and
161/// `release` for a crate built from crates.io, which is what
162/// `cargo install recall` compiles.
163pub fn channel() -> &'static str {
164    match env!("RECALL_RESOLVED_CHANNEL") {
165        CHANNEL_RELEASE => CHANNEL_RELEASE,
166        _ => CHANNEL_DEV,
167    }
168}
169
170/// The commit this build was compiled from, when the build recorded one.
171pub fn revision() -> Option<&'static str> {
172    option_env!("RECALL_GIT_COMMIT").filter(|r| !r.is_empty())
173}
174
175/// When this build was made, when the build recorded it.
176pub fn created() -> Option<&'static str> {
177    option_env!("RECALL_BUILD_CREATED").filter(|c| !c.is_empty())
178}
179
180/// This build's version, as SemVer: see [`version_for`].
181pub fn version() -> String {
182    version_for(channel(), revision())
183}
184
185/// The version a build of this source reports.
186///
187/// A release build reports its release. Anything else reports a
188/// pre-release of the next patch, with the commit as build metadata, so
189/// `0.3.2` built from a later `main` reads `0.3.3-dev+g1a2b3c4`. SemVer
190/// orders that after `0.3.2` and before `0.3.3`, which is where the code
191/// actually sits, and ignores the metadata when comparing.
192pub fn version_for(channel: &str, revision: Option<&str>) -> String {
193    let base = env!("CARGO_PKG_VERSION");
194    if channel == CHANNEL_RELEASE {
195        return base.to_string();
196    }
197    let next = match Version::parse(base) {
198        Some(v) => format!("{}.{}.{}", v.major, v.minor, v.patch + 1),
199        None => base.to_string(),
200    };
201    match revision {
202        Some(rev) => {
203            let short: String = rev.chars().take(7).collect();
204            format!("{next}-dev+g{short}")
205        }
206        None => format!("{next}-dev"),
207    }
208}
209
210/// The `User-Agent` a client sends: `recall/<version> (<os>-<arch>)`, the
211/// way git sends `agent=git/<version>`.
212pub fn user_agent() -> String {
213    format!(
214        "recall/{} ({}-{})",
215        version(),
216        std::env::consts::OS,
217        std::env::consts::ARCH
218    )
219}
220
221/// A SemVer version, enough of it to compare two.
222///
223/// Build metadata is dropped on parsing: SemVer says it *"MUST be ignored
224/// when determining version precedence"*.
225#[derive(Debug, Clone, PartialEq, Eq)]
226pub struct Version {
227    /// Major.
228    pub major: u64,
229    /// Minor.
230    pub minor: u64,
231    /// Patch.
232    pub patch: u64,
233    /// Pre-release identifiers, empty for a release.
234    pub pre: Vec<String>,
235}
236
237impl Version {
238    /// Parses `1.2.3`, `1.2.3-dev`, `1.2.3-rc.1+build`. [`None`] for
239    /// anything else.
240    pub fn parse(text: &str) -> Option<Self> {
241        let text = text.trim().trim_start_matches('v');
242        let text = text.split('+').next()?;
243        let (core, pre) = match text.split_once('-') {
244            Some((core, pre)) => (core, pre.split('.').map(str::to_string).collect()),
245            None => (text, Vec::new()),
246        };
247        let mut parts = core.split('.');
248        let major = parts.next()?.parse().ok()?;
249        let minor = parts.next()?.parse().ok()?;
250        let patch = parts.next()?.parse().ok()?;
251        if parts.next().is_some() {
252            return None;
253        }
254        Some(Self {
255            major,
256            minor,
257            patch,
258            pre,
259        })
260    }
261}
262
263impl PartialOrd for Version {
264    fn partial_cmp(&self, other: &Self) -> Option<std::cmp::Ordering> {
265        Some(self.cmp(other))
266    }
267}
268
269impl Ord for Version {
270    /// SemVer §11: major, minor and patch numerically; then a version with
271    /// a pre-release before the same version without one; then pre-release
272    /// identifiers left to right, numeric ones numerically and before
273    /// alphanumeric ones, and a shorter list before a longer one it prefixes.
274    fn cmp(&self, other: &Self) -> std::cmp::Ordering {
275        use std::cmp::Ordering;
276        let core =
277            (self.major, self.minor, self.patch).cmp(&(other.major, other.minor, other.patch));
278        if core != Ordering::Equal {
279            return core;
280        }
281        match (self.pre.is_empty(), other.pre.is_empty()) {
282            (true, true) => return Ordering::Equal,
283            (true, false) => return Ordering::Greater,
284            (false, true) => return Ordering::Less,
285            (false, false) => {}
286        }
287        for (a, b) in self.pre.iter().zip(&other.pre) {
288            let order = match (a.parse::<u64>(), b.parse::<u64>()) {
289                (Ok(x), Ok(y)) => x.cmp(&y),
290                (Ok(_), Err(_)) => Ordering::Less,
291                (Err(_), Ok(_)) => Ordering::Greater,
292                (Err(_), Err(_)) => a.cmp(b),
293            };
294            if order != Ordering::Equal {
295                return order;
296            }
297        }
298        self.pre.len().cmp(&other.pre.len())
299    }
300}
301
302#[cfg(test)]
303mod tests {
304    use super::*;
305
306    fn v(text: &str) -> Version {
307        Version::parse(text).unwrap()
308    }
309
310    /// The ordering examples from SemVer §11, in order.
311    #[test]
312    fn versions_order_the_way_semver_says() {
313        let ordered = [
314            "1.0.0-alpha",
315            "1.0.0-alpha.1",
316            "1.0.0-alpha.beta",
317            "1.0.0-beta",
318            "1.0.0-beta.2",
319            "1.0.0-beta.11",
320            "1.0.0-rc.1",
321            "1.0.0",
322            "2.0.0",
323            "2.1.0",
324            "2.1.1",
325        ];
326        for pair in ordered.windows(2) {
327            assert!(v(pair[0]) < v(pair[1]), "{} < {}", pair[0], pair[1]);
328        }
329    }
330
331    #[test]
332    fn build_metadata_does_not_count() {
333        assert_eq!(v("0.3.3-dev+g1a2b3c4"), v("0.3.3-dev+gffffff0"));
334        assert!(v("0.3.2") < v("0.3.3-dev+g1a2b3c4"));
335        assert!(v("0.3.3-dev+g1a2b3c4") < v("0.3.3"));
336    }
337
338    #[test]
339    fn what_is_not_a_version_is_refused() {
340        for bad in ["", "1", "1.2", "1.2.3.4", "a.b.c", "1.2.x"] {
341            assert_eq!(Version::parse(bad), None, "{bad:?}");
342        }
343        assert_eq!(v("v1.2.3"), v("1.2.3"));
344    }
345
346    #[test]
347    fn a_release_build_is_its_release_and_anything_else_the_next_dev() {
348        let base = env!("CARGO_PKG_VERSION");
349        assert_eq!(version_for(CHANNEL_RELEASE, Some("abc")), base);
350        let dev = version_for(CHANNEL_DEV, Some("e100cfdd88e8a0e6659b"));
351        assert!(dev.ends_with("-dev+ge100cfd"), "{dev}");
352        assert!(v(base) < v(&dev), "{base} < {dev}");
353        assert!(version_for(CHANNEL_DEV, None).ends_with("-dev"));
354    }
355
356    /// A document from a newer server, with a key and a capability this
357    /// build has never heard of, still reads, and still answers.
358    #[test]
359    fn unknown_keys_are_ignored_and_absent_capabilities_are_unsupported() {
360        let doc: Discovery = serde_json::from_str(
361            r#"{
362                "protocol": {"current": 2, "supported": [1, 2]},
363                "server": {"version": "0.9.0", "build": {"channel": "release", "signed": true}},
364                "min_client": "0.3.0",
365                "auth": {"methods": ["device-sig-v1", "bearer"]},
366                "capabilities": {"merge_base": {}, "telepathy": {"level": 3}},
367                "operator": {"contact": "someone"}
368            }"#,
369        )
370        .unwrap();
371        assert!(doc.speaks(1) && doc.speaks(2) && !doc.speaks(3));
372        assert!(doc.can("merge_base") && doc.can("telepathy"));
373        assert!(!doc.can("scopes"));
374        assert!(doc.accepts(AUTH_DEVICE_SIG) && doc.accepts(AUTH_BEARER));
375        assert!(!doc.accepts("passkey"));
376        assert_eq!(doc.devices(), None, "not listed, so not supported");
377    }
378
379    /// A devices capability with keys this build has never heard of still
380    /// reads; one missing a key it needs does not, and so is unusable.
381    #[test]
382    fn the_devices_capability_reads_into_its_type() {
383        let mut doc: Discovery = serde_json::from_str(
384            r#"{
385                "protocol": {"current": 1, "supported": [1]},
386                "server": {"version": "0.4.1", "build": {"channel": "release"}},
387                "min_client": "0.1.0",
388                "auth": {"methods": ["bearer", "device-sig-v1"]},
389                "capabilities": {"devices": {
390                    "enroll_path": "/v1/devices/enroll", "code_ttl_seconds": 900,
391                    "poll_interval_seconds": 5, "signature_window_seconds": 60,
392                    "passkeys": {}
393                }}
394            }"#,
395        )
396        .unwrap();
397        let devices = doc.devices().unwrap();
398        assert_eq!(devices.enroll_path, "/v1/devices/enroll");
399        assert_eq!(devices.signature_window_seconds, 60);
400
401        doc.capabilities.insert(
402            CAPABILITY_DEVICES.into(),
403            serde_json::json!({"enroll_path": "/x"}),
404        );
405        assert_eq!(doc.devices(), None);
406    }
407
408    #[test]
409    fn the_user_agent_names_the_version_and_platform() {
410        let ua = user_agent();
411        assert!(ua.starts_with("recall/"), "{ua}");
412        assert!(ua.contains(std::env::consts::OS), "{ua}");
413    }
414}