Commit Graph
27 Commits
Author SHA1 Message Date
deepseek-v4-pro ddc577cd3e docs: update Phase 6 findings — QuicStream wrapper is necessary, deferred
SendStream implements only AsyncWrite, RecvStream implements only
AsyncRead. The QuicStream wrapper (44 lines) is a necessary adapter
that combines the split pair from accept_bi() into a single
AsyncRead+AsyncWrite type. Phase 6 is deferred — removing it would
require a new BidiStream abstraction or restructuring HttpAdapter::handle.
2026-07-17 14:09:21 +00:00
deepseek-v4-pro 4fc6854846 chore(call): prune connect, TLS helpers, CallCredentials, and dead paths (Phase 5)
- Remove RemoteIdentity, CallCredentials, ClientError, connect() from call_client.rs
- Remove all TLS helpers (build_quinn_client_config, build_client_auth,
  select_server_verifier, FingerprintPinVerifier, RawKeyClientCertResolver,
  NoClientCertResolver, Ed25519SigningKey, cert/key loaders)
- Remove credentials_auth_token dead path from from_call.rs
  (OpSummary field, build_bundles, make_forwarding_handler,
  make_streaming_forwarding_handler, build_forwarded_payload)
- Remove 2 dead-path tests (build_forwarded_payload_sets_auth_token,
  streaming_forwarding_handler_sets_auth_token)
- Update mod.rs re-exports to only CallClient
- Remove quinn feature and TLS deps from Cargo.toml
- Delete tests/two_node_call.rs (used connect() + CallCredentials)
- alknet-call is now a pure protocol crate
2026-07-17 14:01:51 +00:00
deepseek-v4-pro a0dbe4fd3c chore(core): prune endpoint.rs and heavy deps (Phase 4)
- Delete crates/alknet-core/src/endpoint.rs (1606 lines)
- Remove pub mod endpoint from lib.rs, update doc comment
- Remove rcgen, rustls-pemfile, rustls-acme deps from Cargo.toml
- Remove acme feature
- Update fingerprint.rs doc comment references to alknet-endpoint/alknet-tls
2026-07-17 13:21:54 +00:00
deepseek-v4-pro 83a94ec03f chore(client): mark all client tasks as completed
Phase 3 complete: alknet-client crate implemented with:
- AlknetClient struct with builder methods (with_quinn, with_tcp_tls, with_iroh, with_socks5_proxy)
- ClientDialError enum with 5 variants
- dial_quic, dial_tcp_tls, dial_iroh methods
- SOCKS5 proxy support (Socks5ProxyConfig, Socks5Credentials, Socks5UdpSocket)
- Unit tests (18) + integration test (3)
- All feature combos compile and test clean
- Workspace build and tests pass
2026-07-17 12:49:50 +00:00
deepseek-v4-pro 2a75724dde style(client): cargo fmt 2026-07-17 12:49:40 +00:00
deepseek-v4-pro 759c627ca4 test(client): add unit tests and integration test for alknet-client
- AlknetClient construction tests: new(), Default, Send+Sync, Debug
- ClientDialError tests: #[from] conversion, display formatting, Send+Sync
- dial_quic error path tests: NoTransport, TlsConfig on invalid creds
- dial_tcp_tls error path tests: NoTransport
- dial_iroh error path tests: NoTransport, extract_iroh_endpoint_id
- SOCKS5 proxy error display test (feature-gated)
- Integration test: dial_and_takeover.rs

Task: client/tests
2026-07-17 12:47:40 +00:00
deepseek-v4-pro 82ee37e206 feat(client): implement alknet-client crate — AlknetClient, dial methods, error type, SOCKS5 proxy
- Initialize alknet-client crate with Cargo.toml, deps, feature flags
- Implement ClientDialError enum with 5 variants (TlsConfig, Connect, Handshake, NoTransport, Proxy)
- Implement AlknetClient struct with builder methods (with_quinn, with_tcp_tls, with_iroh, with_socks5_proxy)
- Implement dial_quic — QUIC dial via quinn, producing a Connection
- Implement dial_tcp_tls — TCP+TLS dial via tokio-rustls, producing a Connection
- Implement dial_iroh — iroh dial, producing a Connection
- Implement SOCKS5 proxy support — Socks5ProxyConfig, Socks5Credentials, Socks5UdpSocket, proxy integration
- Add into_rustls_config() to TlsClientConfig in alknet-tls
- Add alknet-client to workspace members

Tasks: client/crate-init, client/error-type, client/client-core,
client/dial-quic, client/dial-tcp-tls, client/dial-iroh, client/socks5-proxy
2026-07-17 12:42:47 +00:00
deepseek-v4-pro b476182d64 feat(tasks): decompose Phase 3 alknet-client into 9 atomic tasks
Phase 3 of the crate extraction (per findings.md): create the
alknet-client crate — the native client dial seam, client-side
analogue of AlknetEndpoint. Three dial methods (dial_quic,
dial_tcp_tls, dial_iroh) unified on &ConnectionCredentials (ADR-091),
pre-built transports via builder methods, optional SOCKS5 proxy
support (ADR-090).

9 tasks, 7 generations, no cycles:
- client/crate-init: Cargo.toml, feature flags, module skeleton
- client/error-type: ClientDialError enum (5 variants)
- client/client-core: AlknetClient struct + builder methods
- client/dial-quic: QUIC dial via quinn
- client/dial-tcp-tls: TCP+TLS dial via tokio-rustls
- client/dial-iroh: Iroh dial (key-not-config)
- client/socks5-proxy: Socks5ProxyConfig, Socks5UdpSocket, proxy integration
- client/tests: Unit tests + integration test
- client/review-client: Review checkpoint

Depends on: tls/review-tls, endpoint/review-endpoint (both completed).
Purely additive — old CallClient::connect stays until Phase 5 prune.
2026-07-17 12:07:08 +00:00
deepseek-v4-pro ab56acae69 feat(endpoint): complete review and mark all tasks as completed
- Fix formatting in endpoint.rs
- Mark tests.md and review-endpoint.md as completed
- All 9 endpoint tasks are now complete
- Workspace: all tests pass, clippy clean, fmt clean
2026-07-17 10:54:50 +00:00
deepseek-v4-pro 5467c30892 feat(endpoint): add tests and mark tasks 1-7 as completed
- Add 7 registry tests (handler_registry_*) to registry.rs
- Add 4 dispatch tests (build_auth_context_*, dispatch_decision_logic_*) to dispatch.rs
- Add 6 endpoint tests to endpoint.rs:
  - debug_for_alknet_endpoint_is_implemented_without_panicking
  - endpoint_constructs_with_iroh_raw_key_identity (adapted for new API)
  - iroh_endpoint_runs_accept_loop_and_shutdown (adapted for new API)
  - with_iroh_sets_field (replaces has_iroh_identity_true_for_raw_key)
  - without_iroh_field_is_none (replaces has_iroh_identity_false_for_x509)
  - endpoint_works_without_iroh (replaces has_iroh_identity_false_when_no_identity)
- Add async-trait as dev-dependency
- All 17 tests pass with iroh feature
- All 8 tests pass without features
- Workspace tests all pass (no breakage)
- Mark tasks 1-7 as completed
2026-07-17 10:53:25 +00:00
deepseek-v4-pro 2755b995c6 feat(endpoint): initialize alknet-endpoint crate with all modules
- Create crates/alknet-endpoint/ with Cargo.toml, feature flags (quinn, iroh, tcp, acme)
- Implement HandlerRegistry (registry.rs) — extracted from core/endpoint.rs
- Implement AlknetEndpoint (endpoint.rs) — fresh build against ADR-083 shape
  - new() takes no StaticConfig, no TLS config
  - with_quinn/with_iroh/with_tcp_tls builder methods
  - run() spawns accept loops for each active transport
  - shutdown() is infallible (no Result)
  - No EndpointError type
- Implement dispatch (dispatch.rs) — shared dispatch_connection free function
  - Transport-agnostic: takes pre-extracted alpn, fingerprint, remote_addr
  - ACME guard (acme-tls/1) behind acme feature
  - build_auth_context resolves identity from fingerprint
- Implement accept loops:
  - accept/quinn.rs — quinn accept loop with ALPN + fingerprint extraction
  - accept/iroh.rs — iroh accept loop with ALPN negotiation + fingerprint
  - accept/tcp_tls.rs — TCP+TLS accept loop (new code, not in old endpoint.rs)
- Add alknet-endpoint to workspace members
- All feature combos compile cleanly (no features, quinn, iroh, tcp, all three)
- Workspace cargo check passes
2026-07-17 10:48:39 +00:00
deepseek-v4-pro 67d2f4affb feat(endpoint): decompose Phase 2 into 9 tasks for alknet-endpoint crate extraction
- endpoint/crate-init: initialize crate, Cargo.toml, module skeleton
- endpoint/registry: extract HandlerRegistry (~50 lines)
- endpoint/endpoint-core: AlknetEndpoint fresh build against ADR-083 shape
- endpoint/dispatch: public dispatch, build_auth_context, ACME guard
- endpoint/accept-quinn: quinn accept loop + extractors (extracted)
- endpoint/accept-iroh: iroh accept loop + extractors (extracted)
- endpoint/accept-tcp-tls: TCP+TLS accept loop (new code)
- endpoint/tests: move + adapt 17 tests
- endpoint/review-endpoint: review checkpoint

7 generations, 3 parallel tasks (accept loops), no cycles.
Depends on tls/review-tls (Phase 1 complete).
2026-07-17 10:33:42 +00:00
deepseek-v4-pro ae0a0d3985 chore: mark Phase 0 and Phase 1 tasks as completed
All six tasks are done:
- core/connection-credentials: ConnectionCredentials + RemoteIdentity in alknet-core
- tls/crate-init: alknet-tls crate skeleton with deps and feature flags
- tls/server-extract: server-side TLS code extracted into alknet-tls
- tls/client-extract: client-side TLS code extracted into alknet-tls
- tls/tests: 34 TLS tests moved and adapted into alknet-tls
- tls/review-tls: spec conformance review passed, all feature combos green
2026-07-17 10:10:59 +00:00
deepseek-v4-pro ad4d9446d0 chore: update Cargo.lock for alknet-tls crate dependencies 2026-07-17 10:10:03 +00:00
deepseek-v4-pro 95fd2b3596 fix(tls/review-tls): add feature gates to for_quinn tests, run cargo fmt
Phase 1 review checkpoint fixes:
- Added #[cfg(feature = "quinn")] to build_quinn_server_config_from_rustls
  and build_quinn_client_config_* tests (for_quinn is feature-gated)
- Ran cargo fmt for consistent formatting
- All 34 tests pass across all feature combos (default, no-default, all-features)
- Workspace fully green: cargo test --workspace, cargo clippy, cargo fmt
2026-07-17 10:07:39 +00:00
deepseek-v4-pro b749fa8019 feat(tls/tests): move and adapt TLS tests into alknet-tls
Phase 1, Task 4 of crate extraction. Moves 34 tests into alknet-tls:
- server.rs: 16 tests (RawKeyCertResolver, SelfSignedCert, AcmeDirectory,
  TlsServerConfig, build_rustls_server_config, build_quinn_server_config,
  AcceptAnyCertVerifier)
- client.rs: 10 tests (FingerprintPinVerifier, select_server_verifier,
  build_client_auth, TlsClientConfig::new + for_quinn)
- signing.rs: 6 tests (Ed25519SigningKey trait impls)
- pem.rs: 3 tests (load_cert_chain, load_private_key error paths)

build_quinn_client_config tests adapted to use TlsClientConfig::new().for_quinn().
tls_setup_x509 test adapted to use TlsServerConfig::new().
Test helpers (build_ed25519_spki_der, build_x509_cert_der, aws_lc_rs_provider,
verify_pin) moved with their tests.

Old tests stay in endpoint.rs and call_client.rs (duplicated). No breakage.
2026-07-17 10:05:58 +00:00
deepseek-v4-pro effbd4174e feat(tls/client-extract): extract client-side TLS code into alknet-tls
Phase 1, Task 3 of crate extraction. Extracts client-side TLS setup code
from alknet-call/call_client.rs into alknet-tls:
- client.rs: TlsClientConfig, build_client_auth, select_server_verifier,
  load_platform_root_cert_store, FingerprintPinVerifier,
  RawKeyClientCertResolver, NoClientCertResolver
- load_platform_root_cert_store includes webpki-roots fallback (ADR-088 §5)
- Reuses shared Ed25519SigningKey from signing.rs and load_cert_chain/
  load_private_key from pem.rs
- All error returns use TlsError (not String)
- webpki-roots 0.26 with TrustAnchor-based fallback

Old code in call_client.rs stays (duplicated). No breakage.
2026-07-17 10:04:14 +00:00
deepseek-v4-pro 114cd73a21 feat(tls/server-extract): extract server-side TLS code into alknet-tls
Phase 1, Task 2 of crate extraction. Extracts server-side TLS setup code
from alknet-core/endpoint.rs into alknet-tls:
- server.rs: TlsServerConfig, build_rustls_server_config, RawKeyCertResolver,
  AcceptAnyCertVerifier, SelfSignedCert, generate_self_signed_cert
- signing.rs: Ed25519SigningKey (shared, used by both server and client)
- pem.rs: load_cert_chain, load_private_key (shared)
- lib.rs: TlsError enum (Config, Io, Cert variants)
- Cargo.toml: added futures dependency for ACME feature

Old code in endpoint.rs stays (duplicated). No breakage.
2026-07-17 09:59:18 +00:00
deepseek-v4-pro 44f5e32740 feat(tls/crate-init): initialize alknet-tls crate with Cargo.toml, deps, and module skeleton
Phase 1, Task 1 of crate extraction. Creates the alknet-tls crate with:
- Cargo.toml with all dependencies and feature flags (quinn, tcp, acme)
- Module skeleton: server.rs, client.rs, signing.rs, pem.rs
- Workspace membership in root Cargo.toml
- rustls-native-certs and webpki-roots always-present (not feature-gated)
- alknet-core dependency via workspace path
2026-07-17 09:55:52 +00:00
deepseek-v4-pro 9b527a888d feat(core/connection-credentials): add ConnectionCredentials + RemoteIdentity to alknet-core
Phase 0 of crate extraction. Purely additive — adds two small types
(ConnectionCredentials, RemoteIdentity) to a new credentials.rs module
in alknet-core. No other crates touched. All workspace tests pass.
2026-07-17 09:54:56 +00:00
deepseek-v4-pro 4ced71f44a tasks: decompose phases 0-1 of crate extraction into implementation tasks
Phase 0 (core/connection-credentials): purely additive — add
ConnectionCredentials + RemoteIdentity to alknet-core. No call crate
changes. ~40 lines, zero breakage.

Phase 1 (tls/*): greenfield alknet-tls crate in 5 tasks:
- tls/crate-init: Cargo.toml, deps, module skeleton
- tls/server-extract: TlsServerConfig + server TLS code from endpoint.rs
- tls/client-extract: TlsClientConfig + client TLS code from call_client.rs
- tls/tests: 32 TLS tests moved and adapted
- tls/review-tls: phase gate review checkpoint

All old code stays duplicated — purely additive phases. Prunes in 4-5.
2026-07-17 09:29:20 +00:00
deepseek-v4-pro e91d943857 docs: remove CallCredentials — dead field, dead from_call path, auth_token is per-request payload
ADR-091 amended 2026-07-17: CallCredentials removed (not retained in
alknet-call). Trace showed CallCredentials.auth_token had no reader
(connect() read only tls_identity + remote_identity; spawn_dispatch
takes no credentials; from_call's credentials_auth_token was a
different type, always None, never connected). auth_token is a
per-request payload field — browsers send it in the WS payload; the
HTTP gateway resolves bearer → Identity at its boundary.

from_call's credentials_auth_token dead path removed in the same pass
(OpSummary field, handler params, build_forwarded_payload param, and
the two tests asserting the never-exercised Some path).

ADR-089 §5 further amended, ADR-080 noted, all spec READMEs and
overview updated. Migration plan (findings.md) corrected: Phase 5
prune now includes CallCredentials removal + from_call dead-path
removal; test audit corrected (4 unchanged + 2 move to core, not 6
unchanged); integration-test split documented; all 'or' hedges
resolved.
2026-07-17 08:54:04 +00:00
deepseek-v4-pro eb9ea506f6 docs(research): clarify channel 0 is just alknet/call pre-negotiated
Channel 0 is not a special control plane with its own framing. It is
simply the alknet/call ALPN, pre-negotiated so both sides route it to
the CallAdapter without an explicit channel/open exchange. Every channel
works the same way: reassemble chunks into a stream, look up the ALPN
in the HandlerRegistry, hand off to the handler. Channel open is
bidirectional — either side can initiate.
2026-07-11 07:52:55 +00:00
deepseek-v4-pro deea6de38a docs(arch): remove channels from hub spec — channels are research-phase, not specced
The channels concept (docs/research/alknet-channels/phase-0-findings.md)
was developed in a separate session and is research-phase, not
architecture. The hub spec was inadvertently built assuming a channel
model that doesn't exist yet.

Changes:
- Remove all channels references from hub README (subtitle, channel
  model section, channel management bullet, channel proxying section,
  'does NOT do' bullet, references)
- Remove OQ-55 (channel/open operation) — channels research has its
  own question tracking (OQ-CH-01 through OQ-CH-07)
- Hub spec now describes what it actually provides: peer lifecycle,
  aggregated operation env, service discovery. One QUIC connection
  per peer carrying the call protocol. No channels, no future
  multiplexing, no research references.
2026-07-11 07:52:02 +00:00
deepseek-v4-pro 5d56bae1ba docs(arch): fix inbound worker hook — callback inside handle(), not post-hoc
- Replace on_worker_connected() post-hoc call with WorkerConnectedCallback
  that fires inside CallAdapter::handle(). handle() blocks until disconnect
  — there is no 'after handle accepts' point for the assembly layer to
  hook into. The callback carries both on_connected (from_call + attach_peer)
  and on_disconnected (detach_peer + drop channels).

- Add CallAdapter::with_worker_connected_callback(callback) builder method.

- Consolidate duplicate WorkerConnectedCallback struct definitions.

- Fix channel role: 'channel proxying' → 'channel management'. The hub
  tracks channels; it does not proxy streams. What the caller does with
  the resulting channel is the assembly layer's business.

- Resolve OQ-54: callback is the committed design. Update OQ file and
  open-questions.md table.
2026-07-11 07:46:00 +00:00
deepseek-v4-pro b38b1d28a7 docs(arch): channel model — call protocol as control plane, any ALPN as data plane
Replace the 'future strategies' section with the channel model:

- Channel 0 is the call protocol — the universal control plane. Handles
  operation discovery (from_call), operation routing (invoke_peer),
  service discovery, and channel negotiation (channel/open, channel/close,
  channel/list).

- Channels 1..N carry any ALPN as data planes. Opened via channel/open on
  the call protocol. Each channel is a bidirectional QUIC stream, wrapped
  as Connection::from_bidi (ADR-065), and handed to the same
  ProtocolHandler::handle() that handles dedicated connections. The
  handler does not know it's on a multiplexed channel.

- Channel negotiation is symmetric — either side can open a channel.
  Same pattern as from_call: bidirectional, symmetric, negotiated over
  the call protocol.

- The hub's role for channels 1..N is transparent stream proxying. The
  hub does not interpret the protocol; the client and worker speak the
  ALPN directly.

- Hub struct gains channel tracking (PeerId → ChannelId → ChannelInfo).
  HubError gains ChannelAlreadyOpen, ChannelNotFound, ChannelOpenFailed.

- New OQ-55: channel/open operation spec (deferred to call-protocol
  implementation phase).
2026-07-11 07:41:07 +00:00
deepseek-v4-pro 31ca32f796 docs(research): add alknet-channels phase-0 research findings
Generalizes TTY's chunk format into a universal channel multiplexer
(alknet-channels) that serves as a transparent proxy between the call
protocol (control plane) and data-plane protocols (TTY, SSH, tunnels).
Key design: 9-byte chunk header (channel_id + stream_type + length),
ChannelConnection implementing the existing Connection interface, and
ACL inherited from the call protocol's OperationContext.
2026-07-10 14:52:56 +00:00