Commit Graph
15 Commits
Author SHA1 Message Date
deepseek-v4-pro ae0a0d3985 chore: mark Phase 0 and Phase 1 tasks as completed
All six tasks are done:
- core/connection-credentials: ConnectionCredentials + RemoteIdentity in alknet-core
- tls/crate-init: alknet-tls crate skeleton with deps and feature flags
- tls/server-extract: server-side TLS code extracted into alknet-tls
- tls/client-extract: client-side TLS code extracted into alknet-tls
- tls/tests: 34 TLS tests moved and adapted into alknet-tls
- tls/review-tls: spec conformance review passed, all feature combos green
2026-07-17 10:10:59 +00:00
deepseek-v4-pro ad4d9446d0 chore: update Cargo.lock for alknet-tls crate dependencies 2026-07-17 10:10:03 +00:00
deepseek-v4-pro 95fd2b3596 fix(tls/review-tls): add feature gates to for_quinn tests, run cargo fmt
Phase 1 review checkpoint fixes:
- Added #[cfg(feature = "quinn")] to build_quinn_server_config_from_rustls
  and build_quinn_client_config_* tests (for_quinn is feature-gated)
- Ran cargo fmt for consistent formatting
- All 34 tests pass across all feature combos (default, no-default, all-features)
- Workspace fully green: cargo test --workspace, cargo clippy, cargo fmt
2026-07-17 10:07:39 +00:00
deepseek-v4-pro b749fa8019 feat(tls/tests): move and adapt TLS tests into alknet-tls
Phase 1, Task 4 of crate extraction. Moves 34 tests into alknet-tls:
- server.rs: 16 tests (RawKeyCertResolver, SelfSignedCert, AcmeDirectory,
  TlsServerConfig, build_rustls_server_config, build_quinn_server_config,
  AcceptAnyCertVerifier)
- client.rs: 10 tests (FingerprintPinVerifier, select_server_verifier,
  build_client_auth, TlsClientConfig::new + for_quinn)
- signing.rs: 6 tests (Ed25519SigningKey trait impls)
- pem.rs: 3 tests (load_cert_chain, load_private_key error paths)

build_quinn_client_config tests adapted to use TlsClientConfig::new().for_quinn().
tls_setup_x509 test adapted to use TlsServerConfig::new().
Test helpers (build_ed25519_spki_der, build_x509_cert_der, aws_lc_rs_provider,
verify_pin) moved with their tests.

Old tests stay in endpoint.rs and call_client.rs (duplicated). No breakage.
2026-07-17 10:05:58 +00:00
deepseek-v4-pro effbd4174e feat(tls/client-extract): extract client-side TLS code into alknet-tls
Phase 1, Task 3 of crate extraction. Extracts client-side TLS setup code
from alknet-call/call_client.rs into alknet-tls:
- client.rs: TlsClientConfig, build_client_auth, select_server_verifier,
  load_platform_root_cert_store, FingerprintPinVerifier,
  RawKeyClientCertResolver, NoClientCertResolver
- load_platform_root_cert_store includes webpki-roots fallback (ADR-088 §5)
- Reuses shared Ed25519SigningKey from signing.rs and load_cert_chain/
  load_private_key from pem.rs
- All error returns use TlsError (not String)
- webpki-roots 0.26 with TrustAnchor-based fallback

Old code in call_client.rs stays (duplicated). No breakage.
2026-07-17 10:04:14 +00:00
deepseek-v4-pro 114cd73a21 feat(tls/server-extract): extract server-side TLS code into alknet-tls
Phase 1, Task 2 of crate extraction. Extracts server-side TLS setup code
from alknet-core/endpoint.rs into alknet-tls:
- server.rs: TlsServerConfig, build_rustls_server_config, RawKeyCertResolver,
  AcceptAnyCertVerifier, SelfSignedCert, generate_self_signed_cert
- signing.rs: Ed25519SigningKey (shared, used by both server and client)
- pem.rs: load_cert_chain, load_private_key (shared)
- lib.rs: TlsError enum (Config, Io, Cert variants)
- Cargo.toml: added futures dependency for ACME feature

Old code in endpoint.rs stays (duplicated). No breakage.
2026-07-17 09:59:18 +00:00
deepseek-v4-pro 44f5e32740 feat(tls/crate-init): initialize alknet-tls crate with Cargo.toml, deps, and module skeleton
Phase 1, Task 1 of crate extraction. Creates the alknet-tls crate with:
- Cargo.toml with all dependencies and feature flags (quinn, tcp, acme)
- Module skeleton: server.rs, client.rs, signing.rs, pem.rs
- Workspace membership in root Cargo.toml
- rustls-native-certs and webpki-roots always-present (not feature-gated)
- alknet-core dependency via workspace path
2026-07-17 09:55:52 +00:00
deepseek-v4-pro 9b527a888d feat(core/connection-credentials): add ConnectionCredentials + RemoteIdentity to alknet-core
Phase 0 of crate extraction. Purely additive — adds two small types
(ConnectionCredentials, RemoteIdentity) to a new credentials.rs module
in alknet-core. No other crates touched. All workspace tests pass.
2026-07-17 09:54:56 +00:00
deepseek-v4-pro 4ced71f44a tasks: decompose phases 0-1 of crate extraction into implementation tasks
Phase 0 (core/connection-credentials): purely additive — add
ConnectionCredentials + RemoteIdentity to alknet-core. No call crate
changes. ~40 lines, zero breakage.

Phase 1 (tls/*): greenfield alknet-tls crate in 5 tasks:
- tls/crate-init: Cargo.toml, deps, module skeleton
- tls/server-extract: TlsServerConfig + server TLS code from endpoint.rs
- tls/client-extract: TlsClientConfig + client TLS code from call_client.rs
- tls/tests: 32 TLS tests moved and adapted
- tls/review-tls: phase gate review checkpoint

All old code stays duplicated — purely additive phases. Prunes in 4-5.
2026-07-17 09:29:20 +00:00
deepseek-v4-pro e91d943857 docs: remove CallCredentials — dead field, dead from_call path, auth_token is per-request payload
ADR-091 amended 2026-07-17: CallCredentials removed (not retained in
alknet-call). Trace showed CallCredentials.auth_token had no reader
(connect() read only tls_identity + remote_identity; spawn_dispatch
takes no credentials; from_call's credentials_auth_token was a
different type, always None, never connected). auth_token is a
per-request payload field — browsers send it in the WS payload; the
HTTP gateway resolves bearer → Identity at its boundary.

from_call's credentials_auth_token dead path removed in the same pass
(OpSummary field, handler params, build_forwarded_payload param, and
the two tests asserting the never-exercised Some path).

ADR-089 §5 further amended, ADR-080 noted, all spec READMEs and
overview updated. Migration plan (findings.md) corrected: Phase 5
prune now includes CallCredentials removal + from_call dead-path
removal; test audit corrected (4 unchanged + 2 move to core, not 6
unchanged); integration-test split documented; all 'or' hedges
resolved.
2026-07-17 08:54:04 +00:00
deepseek-v4-pro eb9ea506f6 docs(research): clarify channel 0 is just alknet/call pre-negotiated
Channel 0 is not a special control plane with its own framing. It is
simply the alknet/call ALPN, pre-negotiated so both sides route it to
the CallAdapter without an explicit channel/open exchange. Every channel
works the same way: reassemble chunks into a stream, look up the ALPN
in the HandlerRegistry, hand off to the handler. Channel open is
bidirectional — either side can initiate.
2026-07-11 07:52:55 +00:00
deepseek-v4-pro deea6de38a docs(arch): remove channels from hub spec — channels are research-phase, not specced
The channels concept (docs/research/alknet-channels/phase-0-findings.md)
was developed in a separate session and is research-phase, not
architecture. The hub spec was inadvertently built assuming a channel
model that doesn't exist yet.

Changes:
- Remove all channels references from hub README (subtitle, channel
  model section, channel management bullet, channel proxying section,
  'does NOT do' bullet, references)
- Remove OQ-55 (channel/open operation) — channels research has its
  own question tracking (OQ-CH-01 through OQ-CH-07)
- Hub spec now describes what it actually provides: peer lifecycle,
  aggregated operation env, service discovery. One QUIC connection
  per peer carrying the call protocol. No channels, no future
  multiplexing, no research references.
2026-07-11 07:52:02 +00:00
deepseek-v4-pro 5d56bae1ba docs(arch): fix inbound worker hook — callback inside handle(), not post-hoc
- Replace on_worker_connected() post-hoc call with WorkerConnectedCallback
  that fires inside CallAdapter::handle(). handle() blocks until disconnect
  — there is no 'after handle accepts' point for the assembly layer to
  hook into. The callback carries both on_connected (from_call + attach_peer)
  and on_disconnected (detach_peer + drop channels).

- Add CallAdapter::with_worker_connected_callback(callback) builder method.

- Consolidate duplicate WorkerConnectedCallback struct definitions.

- Fix channel role: 'channel proxying' → 'channel management'. The hub
  tracks channels; it does not proxy streams. What the caller does with
  the resulting channel is the assembly layer's business.

- Resolve OQ-54: callback is the committed design. Update OQ file and
  open-questions.md table.
2026-07-11 07:46:00 +00:00
deepseek-v4-pro b38b1d28a7 docs(arch): channel model — call protocol as control plane, any ALPN as data plane
Replace the 'future strategies' section with the channel model:

- Channel 0 is the call protocol — the universal control plane. Handles
  operation discovery (from_call), operation routing (invoke_peer),
  service discovery, and channel negotiation (channel/open, channel/close,
  channel/list).

- Channels 1..N carry any ALPN as data planes. Opened via channel/open on
  the call protocol. Each channel is a bidirectional QUIC stream, wrapped
  as Connection::from_bidi (ADR-065), and handed to the same
  ProtocolHandler::handle() that handles dedicated connections. The
  handler does not know it's on a multiplexed channel.

- Channel negotiation is symmetric — either side can open a channel.
  Same pattern as from_call: bidirectional, symmetric, negotiated over
  the call protocol.

- The hub's role for channels 1..N is transparent stream proxying. The
  hub does not interpret the protocol; the client and worker speak the
  ALPN directly.

- Hub struct gains channel tracking (PeerId → ChannelId → ChannelInfo).
  HubError gains ChannelAlreadyOpen, ChannelNotFound, ChannelOpenFailed.

- New OQ-55: channel/open operation spec (deferred to call-protocol
  implementation phase).
2026-07-11 07:41:07 +00:00
deepseek-v4-pro 31ca32f796 docs(research): add alknet-channels phase-0 research findings
Generalizes TTY's chunk format into a universal channel multiplexer
(alknet-channels) that serves as a transparent proxy between the call
protocol (control plane) and data-plane protocols (TTY, SSH, tunnels).
Key design: 9-byte chunk header (channel_id + stream_type + length),
ChannelConnection implementing the existing Connection interface, and
ACL inherited from the call protocol's OperationContext.
2026-07-10 14:52:56 +00:00