feat(transport): 完成安全架构拆分并收口 stream/bulk 传输优化
- 新增 managed/external/nested 三种传输保护模式 - 新增 peer attach 显式认证、抗重放、channel binding 和可选前向保密协商 - 明确单连接注入与可重拨连接源的语义边界 - 禁止 ConnectByConn 场景下 dedicated bulk 走 sidecar,auto 模式自动回退 shared - 修正 dedicated attach 在 bootstrap/steady profile 切换下的处理逻辑 - 优化 shared bulk super-batch 与批量 framed write 路径 - 降低 stream/bulk fast path 的复制和分发损耗 - 补齐 benchmark、回归测试、运行时快照和 README 文档
This commit is contained in:
+16
-9
@@ -404,6 +404,7 @@ func (c *LogicalConn) applyAttachmentProfile(maxReadTimeout time.Duration, maxWr
|
||||
c.updateAttachmentState(func(state *clientConnAttachmentState) {
|
||||
state.maxReadTimeout = maxReadTimeout
|
||||
state.maxWriteTimeout = maxWriteTimeout
|
||||
state.protectionMode = ProtectionManaged
|
||||
state.msgEn = msgEn
|
||||
state.msgDe = msgDe
|
||||
state.fastStreamEncode = fastStreamEncode
|
||||
@@ -525,17 +526,23 @@ func (c *LogicalConn) runtimeSnapshot() ClientConnRuntimeSnapshot {
|
||||
return ClientConnRuntimeSnapshot{}
|
||||
}
|
||||
status := c.Status()
|
||||
authenticated, fallback, attachAt := c.peerAttachAuthenticatedSnapshot()
|
||||
now := time.Now()
|
||||
snapshot := ClientConnRuntimeSnapshot{
|
||||
ClientID: c.clientIDSnapshot(),
|
||||
Alive: status.Alive,
|
||||
Reason: status.Reason,
|
||||
IdentityBound: c.clientConnIdentityBoundSnapshot(),
|
||||
UsesStreamTransport: c.usesStreamTransportSnapshot(),
|
||||
TransportGeneration: c.transportGenerationSnapshot(),
|
||||
TransportAttachCount: c.clientConnTransportAttachCountSnapshot(),
|
||||
TransportDetachCount: c.clientConnTransportDetachCountSnapshot(),
|
||||
LastTransportAttachAt: c.clientConnLastTransportAttachedAtSnapshot(),
|
||||
ClientID: c.clientIDSnapshot(),
|
||||
Alive: status.Alive,
|
||||
Reason: status.Reason,
|
||||
IdentityBound: c.clientConnIdentityBoundSnapshot(),
|
||||
UsesStreamTransport: c.usesStreamTransportSnapshot(),
|
||||
TransportGeneration: c.transportGenerationSnapshot(),
|
||||
TransportAttachCount: c.clientConnTransportAttachCountSnapshot(),
|
||||
TransportDetachCount: c.clientConnTransportDetachCountSnapshot(),
|
||||
LastTransportAttachAt: c.clientConnLastTransportAttachedAtSnapshot(),
|
||||
AuthMode: authModeName(c.authModeSnapshot()),
|
||||
ProtectionMode: protectionModeName(c.protectionModeSnapshot()),
|
||||
PeerAttachAuthenticated: authenticated,
|
||||
PeerAttachAuthFallback: fallback,
|
||||
LastPeerAttachAt: attachAt,
|
||||
}
|
||||
if status.Err != nil {
|
||||
snapshot.Error = status.Err.Error()
|
||||
|
||||
Reference in New Issue
Block a user