glm-5.3-flash
7f89db1058
fix(adapters): subscriptions escape the 30s total timeout + total SSE byte cap (FWD-15, FWD-14)
...
FWD-15: forward_stream now sends through SharedHttpClient::stream_client
— a client derived from the same config with the total request timeout
removed and connect + read timeouts retained. reqwest 0.13's per-request
override can lengthen a client-level total timeout but never clear it
(request-scoped None falls back to the client default), so the derived
client is the only correct mechanism. Both clients rebuild-and-swap
together atomically (FWD-12). A healthy >30s subscription survives; the
read timeout stays as the staleness guard, matching the gateway's
deadline: None dispatch contract (alkcall ADR-021).
FWD-14: the streaming branch enforces a total streamed-bytes cap per
subscription (HttpClientConfig::stream_total_byte_cap, default 1 GiB),
accumulated across every chunk fed to the SSE parser; exceeding it
terminates with a single terminal HTTP_413 error envelope. The SSE
line-cap check moved before extend_from_slice so the reassembly buffer
can never exceed the cap. Removing the total timeout without this cap
would open an unbounded-memory window, so both land together.
Wire tests: keepalive trickle past a scaled total-timeout deadline keeps
delivering; over-cap stream terminates with exactly one terminal error;
parser boundary tests for pre-extend cap checks.
Verified: cargo test (302+5), --all-features (373+41), clippy
--all-targets -D warnings (default + all-features), fmt --check,
doc --no-deps clean.
2026-08-30 12:01:55 +00:00
glm-5.3-flash
91483a74b4
docs: missing_docs sweep — 0 warnings + deny gate + publish-prep decisions (HY-02, HY-04, HY-11)
...
- document every public-API item across 18 files (openapi_spec model,
HttpAuthScheme/HttpServiceConfig, HttpClientBuildError + SharedHttpClient
accessors, RetryAfterMiddleware, GatewayDispatch, gateway error
mapping, CallRequest/SchemaQuery/SubscribeStream, HttpAdapter +
ALPNs + builders, decoy/healthz/state, WsSessions/WsPumps,
from_openapi/from_jsonschema/from_mcp/from_wss/to_mcp, lib.rs module
docs)
- enforcement: #![deny(missing_docs)] at crate root — stronger than CI
rustdocflags (every build incl. cfg(test), where rustdoc misses the
test-support module docs)
- HY-10 (opportunistic): all 8 docs.rs/alkhttp placeholder ADR links +
the one relative ../docs link converted to plain text; the 10
pre-existing private/redundant intra-doc-link warnings fixed —
RUSTDOCFLAGS="-D warnings" cargo doc is fully clean
- HY-11 decision: docs/ + tasks/ excluded from the published package
(contributor-facing design/process material; ADR references degrade
to plain text uniformly). cargo publish --dry-run: 38 files, ~889 KiB,
zero docs/ or tasks/ entries
- HY-04 decision: keep + document — frame_channel0_chunk's unwrap is
on serializing the acyclic EventEnvelope (unreachable failure);
# Panics on it and the adjacent WsClient senders state the contract
Verified: cargo test (299 + 5 TLS), --all-features (370 + suites),
--no-default-features (299), clippy --all-targets -D warnings
(default + all-features), fmt --check, cargo doc -D warnings clean,
cargo publish --dry-run --allow-dirty clean.
Tasks: review-001-missing-docs-sweep (final pending task; 42/42)
2026-08-30 08:25:18 +00:00
glm-5.3-flash
edbda6605b
refactor(client): owned RetryConfig + TLS/mTLS test coverage (HY-06, COV-02)
...
- HttpClientConfig.retry_policy: ExponentialBackoff (semver anchor to a
reqwest-retry concrete type) replaced by retry: RetryConfig — an
owned struct of plain scalars (max_retries, initial_backoff,
max_retry_interval, defaults matching the previous backoff exactly);
the ExponentialBackoff policy is built internally by the middleware
stack; no reqwest_retry type is public anymore
- ClientCertConfig fields documented (none had docs)
- new tests/client_tls.rs: per-test rcgen private PKI + tokio-rustls
HTTPS server; drives the real SharedHttpClient through
HttpClientConfig file paths — CA-bundle success path, private-roots
rejection (source-chain assertion: invalid peer certificate),
mTLS end-to-end with client identity, mTLS rejection without
identity, and reload-to-CA-bundle interplay
- dev-deps: rcgen 0.14, tokio-rustls 0.26, rustls 0.23 (aws_lc_rs),
rustls-pki-types 1, uuid
Verified: cargo test (288 + 5 TLS), --all-features (359 + suites),
--no-default-features (288; pre-existing warnings only), clippy
--all-targets -D warnings (default + all-features), fmt --check,
cargo doc --no-deps.
Tasks: review-001-client-config-and-cert-coverage
2026-08-30 07:24:34 +00:00
glm-5.3-flash
9bb8487c6d
fix(adapters): upstream response decode fidelity (FWD-07, FWD-08, FWD-10, FWD-12) — core, tests follow
2026-08-29 10:26:03 +00:00
glm-5.3-flash
4a557a0453
fix(client): drop unused import/ctor, needless ? (clippy -D warnings)
2026-08-29 08:23:56 +00:00
glm-5.3-flash
b1529dd195
style(client): cargo fmt
2026-08-29 08:22:10 +00:00
glm-5.3-flash
015b2417b9
fix(client): redirect/retry policy hardening + timeouts (FWD-03..05, 09, 11)
...
- same-host redirect policy (scheme+host+port), cross-host redirects
surface the 302 untouched - API-key/default headers cannot cross hosts
- retries gated to idempotent methods only (GET/HEAD/PUT/DELETE/OPTIONS);
POST/PATCH/CONNECT/TRACE bypass the retry middleware entirely
- retry backoff jittered (Bounded) with tightened bounds [100ms, 2s] and
a wall-clock budget (TotalRetryBudget, default 10s) on top of the count
- default request 30s / connect 10s / read 30s timeouts (gateway 30s
deadline anchor); Retry-After ceiling 300s, configurable
- Retry-After recorded against the effective (post-redirect) URL;
eviction prefers expired entries, then the farthest-future deadline;
wake jittered (25% of remaining, capped 2s) to break the thundering herd
- reload() is async (tokio::fs); new() documented as one-shot blocking
verification: cargo test --lib client:: 36 passed; clippy/fmt applied
2026-08-29 08:21:42 +00:00
glm-5.3-flash
0c1de05f85
feat(client): shared reqwest client host with retry stack and Retry-After
...
- src/client/http_client.rs: SharedHttpClient (ArcSwap rebuild-and-swap
hot-reload), HttpClientConfig/ClientCertConfig, HttpClientBuildError
- src/client/retry_after.rs: inlined RetryAfterMiddleware — 429/503
Retry-After (seconds + HTTP-date), bounded URL->deadline storage with
earliest-deadline eviction, sleep-before-next-request
- middleware stack: RetryTransientMiddleware (exponential backoff) +
RetryAfterMiddleware; credentials stay per-request via
OperationContext.capabilities (no env reads)
- applied poisoned-lock recovery convention (into_inner)
Verified: cargo test (95 lib tests), clippy -D warnings, fmt.
2026-08-28 08:33:26 +00:00
glm-5.3-flash
320ea87b08
docs: port architecture specs and ADRs from alknet-http; write new alkhttp ADRs 067-070
...
Phase 1 (SDD) — architecture documentation:
Ported specs (adapted for alkcall, producer/consumer terms, 6-endpoint
gateway, channels-over-WS, Sub/Pub operation types):
- overview.md, http-server.md, http-adapters.md, http-mcp.md
- README.md index (rewritten for alkhttp)
New ADRs:
- 067: WebSocket carries the channels protocol (8-byte chunk demux,
channel 0 = alk/call, upgrade path /alk/channels)
- 068: gateway /publish endpoint for Pub operations (NDJSON body)
- 069: WebTransport out of scope in alkhttp (alknet concern)
- 070: from_wss consumer adapter (wss feature, tokio-tungstenite)
Ported ADRs (25, same numbers, port notes + amendments where the
extraction changed facts): 001-004, 010, 014, 015, 017, 022, 023, 027,
034, 036, 037, 039, 041, 042, 044, 045, 046, 047, 048, 049, 051, 066.
websocket.md rewritten for the channels session; open-questions.md
seeded (OQ-01 WS byte-stream adapter, OQ-02 /publish framing,
OQ-03 from_wss reconnect, OQ-04 browser client ownership).
Verified: cargo test, clippy -D warnings, fmt, doc --no-deps.
2026-08-27 14:19:24 +00:00
glm-5.3-flash
28c521b2f3
feat: scaffold crate with alkcall 0.1.1 dependency
...
Empty module tree (adapters, client, gateway, server, websocket) matching
the AGENTS.md subsystem map. Features: h2/http1 (default), mcp (rmcp),
wss (tokio-tungstenite, for the from_wss consumer adapter).
Verified: cargo check (default), cargo check --all-features.
2026-08-27 12:50:43 +00:00