feat(transport): 完成安全架构拆分并收口 stream/bulk 传输优化
- 新增 managed/external/nested 三种传输保护模式 - 新增 peer attach 显式认证、抗重放、channel binding 和可选前向保密协商 - 明确单连接注入与可重拨连接源的语义边界 - 禁止 ConnectByConn 场景下 dedicated bulk 走 sidecar,auto 模式自动回退 shared - 修正 dedicated attach 在 bootstrap/steady profile 切换下的处理逻辑 - 优化 shared bulk super-batch 与批量 framed write 路径 - 降低 stream/bulk fast path 的复制和分发损耗 - 补齐 benchmark、回归测试、运行时快照和 README 文档
This commit is contained in:
@@ -119,6 +119,7 @@ func TestReplyPeerAttachUsesInboundConnWithoutWaitingSignalAck(t *testing.T) {
|
||||
defer serverConn.Close()
|
||||
|
||||
logical := bootstrapPeerAttachLogicalForTest(t, server, serverConn)
|
||||
originalProfile := logical.transportProtectionProfileSnapshot()
|
||||
message := Message{
|
||||
NetType: NET_SERVER,
|
||||
LogicalConn: logical,
|
||||
@@ -131,6 +132,13 @@ func TestReplyPeerAttachUsesInboundConnWithoutWaitingSignalAck(t *testing.T) {
|
||||
Time: time.Now(),
|
||||
inboundConn: serverConn,
|
||||
}
|
||||
message = hydrateServerMessagePeerFields(message)
|
||||
|
||||
alternate, err := deriveModernPSKProtectionProfile([]byte("notify-peer-attach-reply-alternate"), testModernPSKOptions(), ProtectionManaged)
|
||||
if err != nil {
|
||||
t.Fatalf("deriveModernPSKProtectionProfile failed: %v", err)
|
||||
}
|
||||
logical.applyTransportProtectionProfile(alternate)
|
||||
|
||||
done := make(chan error, 1)
|
||||
go func() {
|
||||
@@ -140,7 +148,7 @@ func TestReplyPeerAttachUsesInboundConnWithoutWaitingSignalAck(t *testing.T) {
|
||||
})
|
||||
}()
|
||||
|
||||
env := readServerEnvelopeFromConn(t, server, logical, clientConn, time.Second)
|
||||
env := readServerEnvelopeFromConnWithProfile(t, server, originalProfile, clientConn, time.Second)
|
||||
if env.Kind != EnvelopeSignal {
|
||||
t.Fatalf("reply envelope kind = %v, want %v", env.Kind, EnvelopeSignal)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user