swactor/crates/iroh-driver
Zachery Aaron Shores-Chmielewski 553347a8f7 feat(myelin): enforce actor-owned control flow
Architecture enforcement:
- Install a repository-owned rustc wrapper for ordinary cargo check,
  build, and test commands. Resolve compiler item identities so renamed
  imports and helper wrappers cannot hide spawning, timing, blocking,
  polling, thread, or runtime-driving capabilities.
- Define the execution-owner crates and reject dependencies from those
  substrates back into Myelin policy. Add compile-pass and compile-fail
  contracts for actor helpers, execution owners, test waits, forbidden
  capabilities, suppression attempts, and owner dependency inversions.

Execution ownership:
- Add engine-owned actor timers with cancellation and generation identity,
  then migrate lifecycle deadlines and protocol ticks off application
  tasks. Keep networking, process output, telemetry, and blocking provider
  calls in their approved I/O substrates.
- Move process spawn, wait, signal, Unix listener, and output-following
  mechanics into swactor-process. Isolate Vast.ai blocking HTTP mechanics
  behind its adapter while actors retain retry, recovery, and provisioning
  decisions.

Myelin control flow:
- Rework manual control, worker lifecycle, provisioning, provider recovery,
  job deployment, distribution, edge orchestration, and shutdown as actor
  state transitions and typed effects. Preserve durable provider adoption
  and command outcomes across graceful and abrupt restarts.
- Replace controller loops and timer-forwarding tasks with actor messages;
  leave substrate tasks as cancellable observation streams with no durable
  policy state.

Properties and resource ownership:
- Add deterministic engine and component properties, a stateful mock-VastAI
  lifecycle model, persisted regression cases, controlled fault injection,
  and a bounded nightly workflow covering restart and teardown behavior.
- Terminate reply observers, cancel telemetry collectors, bound dashboard
  projections, and release child observers, file descriptors, process
  records, and inode-verified Unix sockets on every terminal path.

Verified with the compiler-policy contracts, 105 Myelin library tests, 32
swactor-process tests, telemetry cancellation contracts, randomized
stateful restart cases, cargo check, and formatting checks.
2026-08-20 01:46:11 +04:00
..
src feat(myelin): enforce actor-owned control flow 2026-08-20 01:46:11 +04:00
tests feat(myelin): enforce actor-owned control flow 2026-08-20 01:46:11 +04:00
Cargo.toml Move all edge logic into data-plane; reduce iroh-driver to a byte-transport port 2026-08-16 21:49:45 +04:00
IROH_DRIVER_SPEC.md Move all edge logic into data-plane; reduce iroh-driver to a byte-transport port 2026-08-16 21:49:45 +04:00
README.md refactor: datastream crate is now telemetry 2026-08-15 12:18:56 +04:00

iroh-driver

iroh-driver is the iroh-backed transport bridge for the actorized distribution stack. It owns the concrete iroh endpoint, QUIC connections, relay configuration, peer authorization, and frame shuttling between iroh and swactor actor mailboxes.

Engine ownership

The driver runs on a caller-supplied swactor EngineHandle — the single engine that owns the node's Tokio substrate. All accepts, reads, dials, writes, retries, and teardown are scheduled through that handle; the driver stores no raw Tokio handle and performs no ambient-runtime detection (ENGINE_SPEC.md §7).

let driver = IrohDriver::with_engine(engine.handle(), config)?;

The driver validates that the engine provides the tasks, timers, and io capabilities before binding the endpoint or starting any background work (ENGINE_SPEC.md). Endpoint construction runs as an engine-hosted task; with_engine blocks on a synchronous channel until the endpoint is bound (or fails), so callers need not enter or possess the raw substrate runtime.

Engine-hosted progression

All adapter progression — actor-bridge ingress/egress, telemetry ingress, and edge ingress — is driven by an engine-hosted interval pump installed via install_actor_bridge_pump. Applications do not (and cannot) manually pump these adapters; the single engine owns progression for the node's lifetime (ENGINE_SPEC.md). snapshot is a pure-synchronous read of driver state, callable from any thread. The shutdown method closes the endpoint via an engine-hosted task, blocking on a synchronous channel until completion.