Repository navigation
Correlate Link handshake replies - #453
Merged
Merged
Conversation
The Hello, Open and Bind exchanges accepted a reply under any request ID and a Failure for any operation. sandboxlink.ReadReply now reads the reply to one request and answers anything else with ProtocolViolation and EffectPossible; control calls check the Failure's operation the same way. Delete the negotiable frame limit: HelloAccepted.MaxStreams and the MaxFrameBytes of HelloAccepted, Opened and Bind had no reader, and every service stream reads against sandboxwire.MaxPayload. relay.Config keeps only the Authority and the stream limit becomes a constant. Delete the uncalled AttachLink.Accepted and sandboxlinktest.Authority.RemoveGrant.
An answer that does not decode, or that carries another request ID or operation, fails its request with a final ProtocolViolation and EffectPossible; only a failed stream stays Uncertain. HelloAccepted carries no fields, ReadMessage enforces MaxMessageBytes itself, and relay.New takes the Authority directly.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This is a Link protocol change from the B4 simplicity audit.
Failure.Opwas not checked. A reply that fails to decode or fails correlation is now a non-retryableProtocolViolationwithEffectPossible, and only a failed stream staysUncertain.Servestops rather than reconnects after a malformed Hello reply.MaxFrameBytesandMaxStreamsleaveHelloAccepted,OpenedandBind, along with their validators and fixtures. No production code set them, and File and Process ignored the frame limit. Every service stream usessandboxwire.MaxPayload, and the relay keeps a 256-stream constant.HelloAccepted.LinkID, soOnConnectedtakes no argument;relay.Config, sorelay.Newtakes the Authority;ReadMessage's limit parameter, so it always enforcesMaxMessageBytes;AttachLink.Accepted;sandboxlinktest.Authority.RemoveGrant.docs/sandbox-link-protocol.mdand its zh translation, with a currentsource_hash.Net: production −48, tests +83, docs −10.
Testing:
TestAnswersMatchTheirRequestsdrives the real callers with a wrong ID, a zero ID and a wrong op. Reverting any single guard fails exactly the matching cases.-race -count=50oninternal/sandboxlink/....FuzzDecode.Blind review (Codex) asked for these fixes; they are all included.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.