feat: implement channels protocol + ADR-047 (openable ALPNs are operations)

ADR-047: the unifying decision that  dissolves into
per-ALPN ops (, ) with a
 marker on . Each openable ALPN registers
its own ops with their own , ,
, and the marker. The  field is replaced
by  (Sub/Pub). The generic ops (channel/close,
channel/control, channel/resources/subscribe) stay, keyed by
channel_id. Resolves Gaps A-G from the research findings (Gap B broker
named out-of-scope for alkcall; Gap C relay wrapper is consumer
concern; Gap D connection-owner allocates; Gap E extension trait;
Gap F boolean marker on wire; Gap G ACL/ownership complementary).

ADR-037 amended:  dissolves;  removed; generic
ops stay;  preview dropped from resources/subscribe.

Spec docs updated: channel-operations.md (unified model, opener ledger,
ACL flow), operation-registry.md (channel_open marker, ChannelOpenSpec),
README.md (ADR-047), open-questions.md (OQ-31..38 resolved).

Source changes:
- spec.rs: ChannelOpenSpec struct, channel_open field on OperationSpec,
  with_channel_open builder, 3 tests
- discovery.rs: spec_to_json emits channel_open boolean,
  operation_spec_schema includes channel_open, 2 tests
- from_call.rs: rebuild_spec_for parses channel_open marker,
  derive_alpn_from_op_name helper, 6 tests

Channels module (src/channels/, 10 files, ~2400 lines):
- wire.rs: 8-byte chunk header (ChunkHeader, parse/write_header,
  read_header/write_chunk/write_eof async helpers), 12 tests
- reassembly.rs: MpscRecvStream (tokio::mpsc::Receiver<Bytes> →
  AsyncRead), MpscSendStream (AsyncWrite → tokio::mpsc::Sender<Bytes>),
  REQ-CH-01 shutdown sentinel, REQ-CH-02 sender-drop EOF, 10 tests
- mux.rs: MuxHandle (clone-able, register(channel_id)),
  MuxRunner (per-channel pump tasks, exits when handles drop),
  OpenerLedger (ADR-047 §7), 4 tests
- manager.rs: ChannelManager (channel map, open_channel,
  install_channel_zero, route_payload, teardown_channel, clear_all),
  11 tests
- source.rs: ChannelBidiStreamSource (yield-once accept_bi),
  channel_source helper, 4 tests
- adapter.rs: ChannelsAdapter (ProtocolHandler for alknet/channels,
  demux loop, install_channel_zero hook), 1 test
- operations.rs: ChannelOperations (registers channel/close,
  channel/control, channel/resources/subscribe), ChannelCore
  (check_open/on_close wrappers), 4 tests
- policy.rs: ChannelLifecyclePolicy trait, NoCap, PerIdentityChannelPolicy
  (default 256, per_identity_caps override), default_policy, 8 tests
- env.rs: ChannelOperationEnv extension trait (ADR-047 §4),
  ChannelsSessionEnv impl, 2 tests
- client.rs: ChannelClient (from_connection, call_open_op,
  take_call_connection), 1 test

Verification: 432 tests pass (66 new channels + 10 marker + 356
existing), clippy clean, fmt clean, cargo doc generates.

Cargo.toml: +bytes dependency.
This commit is contained in:
2026-08-12 12:13:53 +00:00
parent ea66398c88
commit f305f8c0a5
23 changed files with 3753 additions and 204 deletions

View File

@@ -6,7 +6,46 @@ Accepted (amended 2026-07-18 by ADR-035 — `stream_types` field removed
from `channel/open`; `stream_type` field removed from `channel/control`;
`channel:stream_type_unavailable` error code removed; the channels layer
has no `stream_type` concept — see "Amendment (ADR-035, 2026-07-18)"
below)
below; amended 2026-08-12 by ADR-047 — `channel/open` dissolves into
per-ALPN ops `channels/<alpn>/sub` and `channels/<alpn>/pub`; the
`direction` field is removed (replaced by `OperationType`); the generic
ops `channel/close`, `channel/control`, `channel/resources/subscribe`
stay; error codes `channel:unknown_alpn` and `channel:invalid_params`
become ordinary `NOT_FOUND` / schema rejection — see "Amendment
(ADR-047, 2026-08-12)" below)
## Amendment (ADR-047, 2026-08-12)
The generic `channel/open` operation is **removed**. Each openable ALPN
registers its own ops on the call `OperationRegistry`, named
`channels/<alpn>/sub` (`OperationType::Sub` — consumer subscribes to a
binary stream) and/or `channels/<alpn>/pub` (`OperationType::Pub`
producer publishes a binary stream). The `direction` field is **removed**
`OperationType` carries the direction (building on ADR-046). The
`alpn` and `params` fields move into the op's `input_schema` (the
`alpn` is derivable from the op name; `params` is the op's input).
The generic ops `channel/close`, `channel/control`,
`channel/resources/subscribe` **stay** (keyed by `channel_id`). The
`access` preview in `channel/resources/subscribe` is **dropped** — it's
on the op spec, available via `services/schema`. The error codes
`channel:unknown_alpn` and `channel:invalid_params` become ordinary
`NOT_FOUND` (op not registered) and schema rejection (input doesn't
match `input_schema`).
`OperationSpec` gains a `channel_open: Option<ChannelOpenSpec>` marker
(ADR-047 §2) — the dispatch hint that tells the channels layer "this
op's stream is binary, allocate a channel." The op's `access_control` is
the ACL (unchanged); the marker is orthogonal. The marker is
wire-visible (`"channel_open": true` in `services/schema`).
`channel_id` allocation is amended to "the connection owner allocates"
(ADR-047 §5) — the side that holds the `ChannelManager`. In the `Sub`
case that's the responder; in the `Pub` case that's the initiator.
The body below describes the **original** (with generic `channel/open`
and `direction`) shape; the amendments above are the operative decision.
See ADR-047 for the unification rationale and the resolved gaps.
## Amendment (ADR-035, 2026-07-18)