Skip to main content

wire/
endpoints.rs

1//! Multi-endpoint routing for v0.5.17 (dual-slot sessions).
2//!
3//! Each wire session can hold up to TWO slots:
4//!   - **Federation** — on a public relay (default `https://wireup.net`),
5//!     listed in the phonebook, reachable across machines.
6//!   - **Local** — on a loopback relay (default `http://127.0.0.1:8771`,
7//!     started with `wire relay-server --local-only`), invisible from
8//!     off-box, sub-millisecond round-trip for same-machine sister-Claude
9//!     traffic.
10//!
11//! Both slots are advertised to paired peers via the `pair_drop` body's
12//! `endpoints[]` array (additive — v0.5.16-and-earlier peers see only
13//! the federation endpoint at the top-level legacy fields, unchanged).
14//!
15//! Routing decision lives in `cmd_push`: walk a peer's pinned endpoints
16//! in priority order (local first if we also have a local slot), POST
17//! the event, fall back to the next endpoint on failure. Pulling: the
18//! daemon reads from BOTH slots, dedupes by `event_id`.
19//!
20//! Storage shape in `relay_state.json` is purely additive:
21//!
22//! ```jsonc
23//! {
24//!   "self": {
25//!     "relay_url": "https://wireup.net",     // legacy federation pointer
26//!     "slot_id":   "abc...",
27//!     "slot_token":"...",
28//!     "endpoints": [                          // v0.5.17 additive
29//!       {"relay_url": "https://wireup.net",     "slot_id": "abc...",  "slot_token": "...", "scope": "federation"},
30//!       {"relay_url": "http://127.0.0.1:8771",  "slot_id": "loop...", "slot_token": "...", "scope": "local"}
31//!     ]
32//!   },
33//!   "peers": {
34//!     "wire-mesh": {
35//!       "relay_url": "https://wireup.net",   // legacy back-compat
36//!       "slot_id":   "...",
37//!       "slot_token":"...",
38//!       "endpoints": [...]                    // v0.5.17 additive
39//!     }
40//!   }
41//! }
42//! ```
43
44use anyhow::Result;
45use serde::{Deserialize, Serialize};
46use serde_json::Value;
47
48/// Where this endpoint sits in the reachability graph.
49#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize)]
50#[serde(rename_all = "lowercase")]
51pub enum EndpointScope {
52    /// Public-facing relay (e.g. `https://wireup.net`). Crosses machines.
53    Federation,
54    /// Loopback-only relay (e.g. `http://127.0.0.1:8771`). Same-machine only.
55    Local,
56    /// LAN-bound relay (e.g. `http://192.168.1.50:8771`). Reachable from
57    /// other machines on the same network without going through federation.
58    /// v0.7.0-alpha.9: third scope for noble-creek-on-paul-mac ↔
59    /// running-light-on-spark style across-the-room pairing without
60    /// wireup.net hop. Visible to anyone who fetches the agent-card —
61    /// opt-in per session (operator passes `--with-lan-relay <url>` at
62    /// `wire session new` time).
63    Lan,
64    /// Unix Domain Socket (e.g. `unix:///path/to/local.sock`). Same-host,
65    /// same-uid only. v0.7.0-alpha.16: framed primarily as a SECURITY
66    /// boundary — no bound TCP port (no firewall surface), SO_PEERCRED
67    /// kernel-attested peer uid (sister-session trust anchor), 0600
68    /// socket permissions. Performance win over loopback HTTP is real
69    /// but tiny (~1.3µs) and not the headline reason. Opt-in via
70    /// `wire session new --with-uds`; Unix-only (Windows falls back to
71    /// Local loopback).
72    Uds,
73}
74
75/// One reachable address for a wire identity. Includes the bearer
76/// `slot_token` because endpoints flow through the pair_drop body,
77/// which is encrypted at protocol level (signed envelope + bilateral
78/// pin gate from v0.5.14). Token is the slot's bearer credential; it
79/// MUST stay private to the pair and is never published in the agent
80/// card or phonebook.
81#[derive(Debug, Clone, Serialize, Deserialize)]
82pub struct Endpoint {
83    pub relay_url: String,
84    pub slot_id: String,
85    pub slot_token: String,
86    pub scope: EndpointScope,
87}
88
89impl Endpoint {
90    pub fn federation(relay_url: String, slot_id: String, slot_token: String) -> Self {
91        Self {
92            relay_url,
93            slot_id,
94            slot_token,
95            scope: EndpointScope::Federation,
96        }
97    }
98
99    pub fn local(relay_url: String, slot_id: String, slot_token: String) -> Self {
100        Self {
101            relay_url,
102            slot_id,
103            slot_token,
104            scope: EndpointScope::Local,
105        }
106    }
107
108    /// v0.7.0-alpha.9: construct a LAN-scope endpoint.
109    pub fn lan(relay_url: String, slot_id: String, slot_token: String) -> Self {
110        Self {
111            relay_url,
112            slot_id,
113            slot_token,
114            scope: EndpointScope::Lan,
115        }
116    }
117
118    /// v0.7.0-alpha.16: construct a UDS-scope endpoint.
119    /// `relay_url` is a `unix:///abs/path/to/local.sock` URL (the
120    /// `unix://` scheme is wire-internal; readers route to a UDS HTTP
121    /// client rather than reqwest).
122    pub fn uds(relay_url: String, slot_id: String, slot_token: String) -> Self {
123        Self {
124            relay_url,
125            slot_id,
126            slot_token,
127            scope: EndpointScope::Uds,
128        }
129    }
130}
131
132/// Read all of a peer's pinned endpoints from `relay_state.json`,
133/// sorted in routing priority order:
134///
135/// 1. Local endpoints first — only when we ALSO have a local slot
136///    (i.e. our `self.endpoints` includes a local one with the same
137///    relay_url). Otherwise local endpoints are skipped because we
138///    can't reach them.
139/// 2. Federation endpoints second.
140///
141/// Back-compat: peers stored by v0.5.16 or earlier have only the
142/// top-level `relay_url`/`slot_id`/`slot_token`; this falls back to
143/// synthesizing a single federation `Endpoint` from those fields.
144pub fn peer_endpoints_in_priority_order(relay_state: &Value, peer_handle: &str) -> Vec<Endpoint> {
145    let our_local_relay_url = relay_state
146        .get("self")
147        .and_then(|s| s.get("endpoints"))
148        .and_then(Value::as_array)
149        .and_then(|arr| {
150            arr.iter()
151                .find(|e| e.get("scope").and_then(Value::as_str) == Some("local"))
152                .and_then(|e| e.get("relay_url"))
153                .and_then(Value::as_str)
154                .map(str::to_string)
155        });
156
157    let peer = match relay_state.get("peers").and_then(|p| p.get(peer_handle)) {
158        Some(p) => p,
159        None => return Vec::new(),
160    };
161
162    let mut all: Vec<Endpoint> = Vec::new();
163
164    if let Some(arr) = peer.get("endpoints").and_then(Value::as_array) {
165        for ep in arr {
166            if let Ok(parsed) = serde_json::from_value::<Endpoint>(ep.clone()) {
167                all.push(parsed);
168            }
169        }
170    }
171
172    // Back-compat: peer was pinned by v0.5.16 or earlier and has no
173    // `endpoints` array, just the top-level legacy fields. Synthesize
174    // one federation Endpoint from them so routing still finds a path.
175    if all.is_empty() {
176        let relay_url = peer.get("relay_url").and_then(Value::as_str).unwrap_or("");
177        let slot_id = peer.get("slot_id").and_then(Value::as_str).unwrap_or("");
178        let slot_token = peer.get("slot_token").and_then(Value::as_str).unwrap_or("");
179        if !relay_url.is_empty() && !slot_id.is_empty() && !slot_token.is_empty() {
180            all.push(Endpoint::federation(
181                relay_url.to_string(),
182                slot_id.to_string(),
183                slot_token.to_string(),
184            ));
185        }
186    }
187
188    // Sort: UDS (same-host trust anchor) first, then local-loopback-
189    // with-matching-self-local, then LAN (cross-machine same-network),
190    // then federation. Drop unreachable scopes via the retain pass.
191    //
192    // v0.7.0-alpha.9: LAN endpoints sit between Local and Federation.
193    // Faster than federation; not gated by "our_local matches" because
194    // cross-machine peers won't have a matching our-local by definition.
195    //
196    // v0.7.0-alpha.16: UDS endpoints get rank 0 when peer + self share
197    // a UDS socket path (we need to be able to connect to their socket
198    // which means it must be readable by our uid). The "same-uid same-
199    // host" sister-session trust shape this enforces is the whole
200    // point of UDS — see project_wire_transport_substrate_research.
201    let our_local = our_local_relay_url.clone();
202    all.sort_by_key(|ep| match (ep.scope, &our_local) {
203        (EndpointScope::Uds, _) => 0,
204        (EndpointScope::Local, Some(our)) if &ep.relay_url == our => 1,
205        (EndpointScope::Lan, _) => 2,
206        (EndpointScope::Federation, _) => 3,
207        _ => 4,
208    });
209    // Drop unreachable: Local needs matching loopback URL; UDS needs
210    // the socket file to exist on our filesystem (the daemon-side
211    // connect will surface a clearer error than a routing-time drop
212    // would, but we still keep UDS in the routing list — failure
213    // falls through to lower-priority scopes).
214    all.retain(|ep| match (ep.scope, &our_local) {
215        (EndpointScope::Local, None) => false,
216        (EndpointScope::Local, Some(our)) => &ep.relay_url == our,
217        (EndpointScope::Lan, _) => true,
218        (EndpointScope::Uds, _) => true,
219        (EndpointScope::Federation, _) => true,
220    });
221    all
222}
223
224/// All of OUR own endpoints from `relay_state.json`. Used by `cmd_push`
225/// to find the local slot when routing local-first, and by the daemon's
226/// pull loop to iterate every slot we should be reading from.
227pub fn self_endpoints(relay_state: &Value) -> Vec<Endpoint> {
228    let self_state = match relay_state.get("self") {
229        Some(s) if !s.is_null() => s,
230        _ => return Vec::new(),
231    };
232    let mut all: Vec<Endpoint> = Vec::new();
233    if let Some(arr) = self_state.get("endpoints").and_then(Value::as_array) {
234        for ep in arr {
235            if let Ok(parsed) = serde_json::from_value::<Endpoint>(ep.clone()) {
236                all.push(parsed);
237            }
238        }
239    }
240    if all.is_empty() {
241        // Back-compat: synthesize a federation endpoint from legacy
242        // top-level fields. Slot_token may be absent in some old
243        // states; in that case the synthesized endpoint is partial
244        // and downstream code must guard against empty token.
245        let relay_url = self_state
246            .get("relay_url")
247            .and_then(Value::as_str)
248            .unwrap_or("");
249        let slot_id = self_state
250            .get("slot_id")
251            .and_then(Value::as_str)
252            .unwrap_or("");
253        let slot_token = self_state
254            .get("slot_token")
255            .and_then(Value::as_str)
256            .unwrap_or("");
257        if !relay_url.is_empty() && !slot_id.is_empty() {
258            all.push(Endpoint::federation(
259                relay_url.to_string(),
260                slot_id.to_string(),
261                slot_token.to_string(),
262            ));
263        }
264    }
265    all
266}
267
268/// v0.9 canonical single-reader for "my best inbound slot." Returns
269/// the first endpoint from `self_endpoints()` — which is already
270/// priority-ordered (UDS → Local-with-matching-self → LAN →
271/// Federation) AND back-compat-falls-back to legacy top-level fields.
272///
273/// Replaces ad-hoc `self_state["relay_url"].as_str()` reads scattered
274/// through the codebase. Pre-v0.9 those bare reads were the silent-
275/// fail root cause: a session with only `self.endpoints[]` (no legacy
276/// top-level fields) returned empty strings instead of the available
277/// endpoint, and pair_drop_ack / pull / rotate-slot all silently
278/// no-op'd. Always use this from new code.
279pub fn self_primary_endpoint(relay_state: &Value) -> Option<Endpoint> {
280    self_endpoints(relay_state).into_iter().next()
281}
282
283/// Pin a peer's full set of endpoints into `relay_state.json` under
284/// `peers[handle]`. Preserves the v0.5.16-and-earlier `relay_url` /
285/// `slot_id` / `slot_token` top-level fields (pointing at the
286/// federation endpoint) so older code paths and back-compat readers
287/// don't break. The new `endpoints` array is additive.
288pub fn pin_peer_endpoints(
289    relay_state: &mut Value,
290    peer_handle: &str,
291    endpoints: &[Endpoint],
292) -> Result<()> {
293    // Pick the federation endpoint (if any) to fill the legacy fields.
294    // v0.7.0-alpha.9: when no federation present, prefer LAN over Local
295    // for the legacy fields — LAN is cross-machine-reachable.
296    let fed = endpoints
297        .iter()
298        .find(|e| e.scope == EndpointScope::Federation);
299    let peers = relay_state
300        .as_object_mut()
301        .map(|m| {
302            m.entry("peers")
303                .or_insert_with(|| Value::Object(Default::default()))
304        })
305        .ok_or_else(|| anyhow::anyhow!("relay_state.json root is not an object"))?
306        .as_object_mut()
307        .ok_or_else(|| anyhow::anyhow!("relay_state.peers is not an object"))?;
308    let mut entry = serde_json::Map::new();
309    if let Some(f) = fed {
310        entry.insert("relay_url".into(), Value::String(f.relay_url.clone()));
311        entry.insert("slot_id".into(), Value::String(f.slot_id.clone()));
312        entry.insert("slot_token".into(), Value::String(f.slot_token.clone()));
313    } else if let Some(lan_ep) = endpoints.iter().find(|e| e.scope == EndpointScope::Lan) {
314        entry.insert("relay_url".into(), Value::String(lan_ep.relay_url.clone()));
315        entry.insert("slot_id".into(), Value::String(lan_ep.slot_id.clone()));
316        entry.insert(
317            "slot_token".into(),
318            Value::String(lan_ep.slot_token.clone()),
319        );
320    } else if let Some(loc) = endpoints.iter().find(|e| e.scope == EndpointScope::Local) {
321        // No federation, no LAN? Local is the only option. Unusual
322        // (peer would only be reachable from same loopback), but keeps
323        // schema invariant intact.
324        entry.insert("relay_url".into(), Value::String(loc.relay_url.clone()));
325        entry.insert("slot_id".into(), Value::String(loc.slot_id.clone()));
326        entry.insert("slot_token".into(), Value::String(loc.slot_token.clone()));
327    }
328    entry.insert("endpoints".into(), serde_json::to_value(endpoints)?);
329    peers.insert(peer_handle.to_string(), Value::Object(entry));
330    Ok(())
331}
332
333#[cfg(test)]
334mod tests {
335    use super::*;
336    use serde_json::json;
337
338    #[test]
339    fn peer_endpoints_back_compat_falls_back_to_legacy_fields() {
340        let state = json!({
341            "peers": {
342                "alice": {
343                    "relay_url": "https://wireup.net",
344                    "slot_id": "abc",
345                    "slot_token": "tok"
346                }
347            }
348        });
349        let eps = peer_endpoints_in_priority_order(&state, "alice");
350        assert_eq!(eps.len(), 1);
351        assert_eq!(eps[0].relay_url, "https://wireup.net");
352        assert_eq!(eps[0].scope, EndpointScope::Federation);
353    }
354
355    #[test]
356    fn peer_endpoints_lan_beats_federation() {
357        // v0.7.0-alpha.9: when a peer publishes both Lan and Federation
358        // endpoints (and we have a matching local too), priority must be
359        // Local(matched) > Lan > Federation. Lan is cross-machine same-
360        // network, faster than federation but not as fast as loopback.
361        let state = json!({
362            "self": {
363                "endpoints": [
364                    {"relay_url": "http://127.0.0.1:8771", "slot_id": "self-loop", "slot_token": "t1", "scope": "local"},
365                    {"relay_url": "https://wireup.net", "slot_id": "self-fed", "slot_token": "t2", "scope": "federation"}
366                ]
367            },
368            "peers": {
369                "alice": {
370                    "endpoints": [
371                        {"relay_url": "https://wireup.net", "slot_id": "a-fed", "slot_token": "ta-f", "scope": "federation"},
372                        {"relay_url": "http://192.168.1.50:8771", "slot_id": "a-lan", "slot_token": "ta-l", "scope": "lan"},
373                        {"relay_url": "http://127.0.0.1:8771", "slot_id": "a-loop", "slot_token": "ta-loop", "scope": "local"}
374                    ]
375                }
376            }
377        });
378        let eps = peer_endpoints_in_priority_order(&state, "alice");
379        assert_eq!(
380            eps.len(),
381            3,
382            "Local(matched) + Lan + Federation all reachable"
383        );
384        assert_eq!(
385            eps[0].scope,
386            EndpointScope::Local,
387            "loopback wins (same-machine)"
388        );
389        assert_eq!(
390            eps[1].scope,
391            EndpointScope::Lan,
392            "Lan second (same-network)"
393        );
394        assert_eq!(
395            eps[2].scope,
396            EndpointScope::Federation,
397            "Federation last (anywhere)"
398        );
399    }
400
401    #[test]
402    fn peer_endpoints_lan_kept_when_self_has_no_local() {
403        // Cross-machine peer scenario: we have no Local, peer has Lan
404        // and Federation. Lan must still be kept (we connect TO their
405        // LAN address; we don't need a Local of our own to do so).
406        let state = json!({
407            "self": {
408                "endpoints": [
409                    {"relay_url": "https://wireup.net", "slot_id": "self-fed", "slot_token": "t1", "scope": "federation"}
410                ]
411            },
412            "peers": {
413                "alice": {
414                    "endpoints": [
415                        {"relay_url": "https://wireup.net", "slot_id": "a-fed", "slot_token": "ta-f", "scope": "federation"},
416                        {"relay_url": "http://192.168.1.50:8771", "slot_id": "a-lan", "slot_token": "ta-l", "scope": "lan"}
417                    ]
418                }
419            }
420        });
421        let eps = peer_endpoints_in_priority_order(&state, "alice");
422        assert_eq!(eps.len(), 2);
423        assert_eq!(
424            eps[0].scope,
425            EndpointScope::Lan,
426            "Lan preferred over Federation"
427        );
428        assert_eq!(eps[1].scope, EndpointScope::Federation);
429    }
430
431    #[test]
432    fn pin_peer_endpoints_uses_lan_as_legacy_when_no_federation() {
433        // Backward compat: when peer has no federation endpoint but has
434        // a LAN one, the legacy top-level relay_url/slot_id/slot_token
435        // should point at the LAN address (since LAN is cross-machine
436        // reachable; Local loopback wouldn't be).
437        let mut state = json!({});
438        let endpoints = vec![
439            Endpoint::lan(
440                "http://192.168.1.50:8771".to_string(),
441                "lan-slot".to_string(),
442                "lan-tok".to_string(),
443            ),
444            Endpoint::local(
445                "http://127.0.0.1:8771".to_string(),
446                "loop-slot".to_string(),
447                "loop-tok".to_string(),
448            ),
449        ];
450        pin_peer_endpoints(&mut state, "alice", &endpoints).unwrap();
451        let alice = &state["peers"]["alice"];
452        assert_eq!(
453            alice["relay_url"], "http://192.168.1.50:8771",
454            "LAN wins legacy fields"
455        );
456        assert_eq!(alice["slot_id"], "lan-slot");
457    }
458
459    #[test]
460    fn peer_endpoints_orders_local_first_when_self_has_matching_local() {
461        let state = json!({
462            "self": {
463                "endpoints": [
464                    {"relay_url": "https://wireup.net",    "slot_id": "self-fed",  "slot_token": "t1", "scope": "federation"},
465                    {"relay_url": "http://127.0.0.1:8771", "slot_id": "self-loop", "slot_token": "t2", "scope": "local"}
466                ]
467            },
468            "peers": {
469                "alice": {
470                    "endpoints": [
471                        {"relay_url": "https://wireup.net",    "slot_id": "a-fed",  "slot_token": "ta1", "scope": "federation"},
472                        {"relay_url": "http://127.0.0.1:8771", "slot_id": "a-loop", "slot_token": "ta2", "scope": "local"}
473                    ]
474                }
475            }
476        });
477        let eps = peer_endpoints_in_priority_order(&state, "alice");
478        assert_eq!(eps.len(), 2);
479        assert_eq!(eps[0].scope, EndpointScope::Local);
480        assert_eq!(eps[1].scope, EndpointScope::Federation);
481    }
482
483    #[test]
484    fn peer_endpoints_drops_local_when_self_has_no_local() {
485        let state = json!({
486            "self": {
487                "endpoints": [
488                    {"relay_url": "https://wireup.net", "slot_id": "self-fed", "slot_token": "t1", "scope": "federation"}
489                ]
490            },
491            "peers": {
492                "alice": {
493                    "endpoints": [
494                        {"relay_url": "https://wireup.net",    "slot_id": "a-fed",  "slot_token": "ta1", "scope": "federation"},
495                        {"relay_url": "http://127.0.0.1:8771", "slot_id": "a-loop", "slot_token": "ta2", "scope": "local"}
496                    ]
497                }
498            }
499        });
500        let eps = peer_endpoints_in_priority_order(&state, "alice");
501        // Only federation reachable: local was filtered.
502        assert_eq!(eps.len(), 1);
503        assert_eq!(eps[0].scope, EndpointScope::Federation);
504    }
505
506    #[test]
507    fn peer_endpoints_drops_local_when_relay_urls_dont_match() {
508        let state = json!({
509            "self": {
510                "endpoints": [
511                    {"relay_url": "http://127.0.0.1:8771", "slot_id": "self-loop", "slot_token": "t2", "scope": "local"}
512                ]
513            },
514            "peers": {
515                "alice": {
516                    "endpoints": [
517                        {"relay_url": "http://127.0.0.1:9999", "slot_id": "a-loop", "slot_token": "ta2", "scope": "local"}
518                    ]
519                }
520            }
521        });
522        // Our local is :8771, peer's local is :9999 — can't route there.
523        let eps = peer_endpoints_in_priority_order(&state, "alice");
524        assert_eq!(
525            eps.len(),
526            0,
527            "different local relays cannot reach each other"
528        );
529    }
530
531    #[test]
532    fn pin_peer_endpoints_preserves_legacy_top_level_fields() {
533        let mut state = json!({"peers": {}});
534        let endpoints = vec![
535            Endpoint::federation("https://wireup.net".into(), "abc".into(), "tok".into()),
536            Endpoint::local(
537                "http://127.0.0.1:8771".into(),
538                "loop".into(),
539                "loop-tok".into(),
540            ),
541        ];
542        pin_peer_endpoints(&mut state, "alice", &endpoints).unwrap();
543        let alice = &state["peers"]["alice"];
544        // Legacy fields point at the federation endpoint.
545        assert_eq!(alice["relay_url"], "https://wireup.net");
546        assert_eq!(alice["slot_id"], "abc");
547        assert_eq!(alice["slot_token"], "tok");
548        // Endpoints array carries the full set.
549        let eps = alice["endpoints"].as_array().unwrap();
550        assert_eq!(eps.len(), 2);
551    }
552
553    #[test]
554    fn self_endpoints_back_compat_falls_back_to_legacy_fields() {
555        let state = json!({
556            "self": {
557                "relay_url": "https://wireup.net",
558                "slot_id": "self-fed",
559                "slot_token": "t1"
560            }
561        });
562        let eps = self_endpoints(&state);
563        assert_eq!(eps.len(), 1);
564        assert_eq!(eps[0].scope, EndpointScope::Federation);
565        assert_eq!(eps[0].slot_id, "self-fed");
566    }
567
568    #[test]
569    fn self_endpoints_returns_both_when_dual_slot() {
570        let state = json!({
571            "self": {
572                "endpoints": [
573                    {"relay_url": "https://wireup.net",    "slot_id": "self-fed",  "slot_token": "t1", "scope": "federation"},
574                    {"relay_url": "http://127.0.0.1:8771", "slot_id": "self-loop", "slot_token": "t2", "scope": "local"}
575                ]
576            }
577        });
578        let eps = self_endpoints(&state);
579        assert_eq!(eps.len(), 2);
580    }
581}