Skip to content

0.1.11: build on endpoint-libs 3.3, and serve WebSocket without owning the process signals - #11

Merged
pathscale merged 5 commits into
masterfrom
docs/working-agreement
Sep 23, 2026
Merged

pathscale merged 5 commits into
masterfrom
docs/working-agreement

Conversation

@pathscale

@pathscale pathscale commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner

Releases 0.1.11. The published 0.1.10 no longer compiles against endpoint-libs 3.2 (framed_json_with_max_frame was removed), which fails AgencyZero's sidecar build.

  • endpoint-libs 3.x transport: the Unix framing uses framed_json_neutral_with_max_frame over tokio-util compat.
  • WebSocket server off the tokio worker: endpoint-libs 3's listen blocks its thread for the life of the server, so it runs on a dedicated thread.
  • Signals belong to main: listen claimed SIGTERM/SIGINT for the process, and a second server in one process failed with EBUSY after binding. This is why the WebSocket tests passed alone and hung together. serve_websocket now takes a stop future and uses listen_until (endpoint-libs 3.3, 3.3.0: let the caller say when a server stops endpoint-libs#57). main owns the signals and keeps the SIGTERM drain contract.
  • Run-event forwarder runs on the registry's tokio executor instead of spawn_local, which endpoint-libs 3 handlers can no longer reach.
  • TLS removed from the WebSocket config. endpoint-libs 3 refuses certificates and terminates TLS at the edge, and this listener is loopback-only by validation. Outbound HTTPS is unaffected: the crate has no TLS client, and the provider CLIs make those calls themselves.

Verified locally against endpoint-libs 3.3.0 by path: all suites pass, and websocket_mcp passes 5/5 on three consecutive runs (~2.4s).

Lands after endpoint-libs 3.3.0 is published. Cargo.lock is tracked and CI runs --locked, so the lockfile is refreshed against the registry release as the last commit here. CI is red until then.

meh added 3 commits September 23, 2026 11:10
3.2 removed the tokio flavour of the transport. `framed_json_with_max_frame` is
gone and `framed_json_neutral_with_max_frame` replaces it, taking a `futures_io`
stream, so the tokio `UnixStream`s here bridge through tokio-util's `compat`.
The frame cap and the codec on the wire are unchanged.

`listen` also stopped being a future. It builds its own reactor, registers
SIGTERM and SIGINT on that reactor, and blocks until one fires, so the `.await`
comes off and the drain that follows it runs exactly as before.

The requirement was already `^3` and needed no edit: the lock was pinning 3.0.0.
Three things broke when endpoint-libs moved its server onto nagoya, and the
WebSocket suite hung on them.

listen() now blocks its thread for the life of the server. serve_websocket
called it from an async fn, which held a tokio worker forever and, on the
current-thread runtime every test uses, the only one. The server now runs on a
thread of its own and serve_websocket awaits its answer.

listen() also claimed SIGTERM and SIGINT for the process, and nagoya allows one
waiter per signal, so the second server in a test process failed with EBUSY
after binding and its client waited on a dead port. Each test passed alone and
hung together. serve_websocket now takes a stop future and uses
listen_until (endpoint-libs 3.3); main owns the signals through tokio and
forwards the first one over a oneshot, keeping the SIGTERM drain contract.

A handler is polled in place on the connection task with no spawner, so the
run-event forwarder could not spawn_local. It runs on the registry's tokio
executor, where provider work already runs; the toolbox is Send + Sync.

TLS goes: endpoint-libs 3 refuses certificates outright and terminates TLS at
the edge, and this listener is loopback-only by validation anyway. Outbound
HTTPS is untouched; this crate has no TLS client, the provider CLIs make those
calls themselves.
Builds against endpoint-libs 3.3; 0.1.10 no longer compiles against 3.2.
@pathscale
pathscale force-pushed the docs/working-agreement branch from 8d51fb0 to 0ed2dd6 Compare September 23, 2026 04:55
@pathscale pathscale changed the title Take endpoint-libs 3.2 0.1.11: build on endpoint-libs 3.3, and serve WebSocket without owning the process signals Sep 23, 2026
meh added 2 commits September 23, 2026 18:41
No lockfile: CI and consumers resolve the manifest ranges afresh, so a
release of one of our crates reaches this one without a commit here. CI
drops --locked, which only meant "fail when the ranges moved", and publish
no longer triggers on a file that is gone.

Our own crates are required at the major line (^0.1, ^0.4, ^3) rather
than a patch floor: with no lockfile the newest release is what resolves,
which for endpoint-libs is 3.3 and its listen_until.
tokio and tokio-util are gone from every crate, tests included, and so is
tokio-tungstenite: the WebSocket tests drive the server with endpoint-libs'
own nagoya client. Sockets are nagoya's, framed with NagoyaStream and the
neutral framing, so no compat layer sits in between. tokio's broadcast and
watch become two small local types, broadcast and Flag, with the semantics
the code relied on (lag reporting, close on last sender, cancel-safe recv).

There is no global reactor. main is the composition root: it registers
SIGTERM and SIGINT before any thread exists, which a Linux signalfd needs,
then creates the one Reactor, keeps it for the life of the process, and
passes its Handle to the server, the registry and agent-abstraction. Every
test starts its own.

Public changes: Client::connect, ProxyServer::bind and bind_with_registry
take the Handle; RuntimeRegistry::new(handle) replaces Default, which could
only have been honest by creating a reactor; subscribe and Attachment::events
return the local broadcast receiver. agent-abstraction moves to ^0.5, the
release that takes the Handle too.
@pathscale
pathscale merged commit 3292f89 into master Sep 23, 2026
2 of 3 checks passed
@pathscale
pathscale deleted the docs/working-agreement branch September 23, 2026 15:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant