feat(cluster): RFC 010 c6b — handshake on the accept/connect path

Drive the c5 machines as straight-line code on the path (D8): dial_handshake
and accept_handshake do the IO on a shared FramedConn, and a connection actor
is spawned only after a successful handshake. Rejects, tie-break losses (D7),
protocol faults and timeouts are all resolved on the path by closing, so no
actor ever exists for a connection that did not establish. The whole
FramedConn travels into spawn_established, carrying any read-ahead past the
handshake frames.

Handshake deadlines land here rather than in c6c: FramedConn::recv_deadline
enforces them between reads via the connection's fd arm, so a peer that
connects and goes silent cannot wedge the acceptor.

Connection lifetime moves to the manager (pulled forward from c7). The path
registers each established connection and hands over its ConnHandle; the
manager owns it, monitors the actor, and tears the connection down on
Disconnect, on peer close, or at manager shutdown. spawn_established returns
a Pid, so a connection neither outlives nor dies with whichever actor
established it — the ownership that made two-node teardown unorderable.

The manager also tracks in-flight dial intents, monitored so a panicking
dial cannot wedge the tie-break, and answers HelloCtx for the accept path.
This commit is contained in:
Claude
2026-08-14 21:09:08 +00:00
parent bbaaa062e3
commit c8ed858e4c
8 changed files with 1037 additions and 46 deletions
+20 -10
View File
@@ -2,11 +2,12 @@
//!
//! The handshake is bypassed here (c6b wires it): each connection is
//! constructed already-established over a real localhost TCP pair, handed a
//! fabricated `Peer`, and spawned. The actor registers with the manager, which
//! monitors it, so the table reflects the connection while it lives and reaps
//! it on any exit path. This proves three things at once: a live connection
//! shows up, a commanded shutdown removes exactly that one, and a peer close
//! (EOF, no command) removes the other.
//! fabricated `Peer`, and spawned. `spawn_established` registers it with the
//! manager, which takes its handle and monitors it, so the table reflects the
//! connection while it lives and reaps it on any exit path. This proves three
//! things at once: a live connection shows up, a commanded `Disconnect`
//! removes exactly that one, and a peer close (EOF, no command) removes the
//! other.
//!
//! TCP parks the calling actor, so everything runs inside `smarm::run`; the
//! single-threaded runtime is fine because every wait is a cooperative fd park.
@@ -80,14 +81,23 @@ fn connection_up_commanded_shutdown_and_eof_all_reflected_in_table() {
// Manage the `a` ends as peers node-b and node-c; keep the `b` far ends
// open so neither socket is closed from the far side yet.
let h1 = spawn_established(FramedConn::new(a1), peer("node-b"));
let _h2 = spawn_established(FramedConn::new(a2), peer("node-c"));
spawn_established(FramedConn::new(a1), peer("node-b")).expect("node-b registers");
spawn_established(FramedConn::new(a2), peer("node-c")).expect("node-c registers");
// Up: both connections register and the table shows them.
wait_peers(&["node-b", "node-c"]);
// A commanded shutdown reaps exactly its own connection.
h1.shutdown();
// A commanded disconnect reaps exactly its own connection: the
// manager drops that entry's handle and the actor stops.
assert!(matches!(
gen_server::call(
MANAGER,
Call::Disconnect {
name: "node-b".to_string()
}
),
Ok(Reply::Disconnected)
));
wait_peers(&["node-c"]);
// A peer close (EOF) reaps the other with no command at all.
@@ -95,7 +105,7 @@ fn connection_up_commanded_shutdown_and_eof_all_reflected_in_table() {
wait_peers(&[]);
// node-b's far end stayed open until here, so its removal above was the
// shutdown command and not an EOF.
// disconnect command and not an EOF.
drop(b1);
// All connection actors have exited; stop the manager so `run` returns.