The datastream is metrics/logging only; control decisions must never branch on a frame. This was a recurring cultural problem with no structural enforcement. This change makes it a compile-time and CI-enforced fact. datastream crate (lib.rs): - Stop re-exporting Frame, DatastreamEvent, FrameDelivery at crate root. is now a compile error (E0425). These types live only in datastream::frame::* and are documented as the observer surface. - Safe identity types (ChannelId, StreamId, Position, Record, etc.) remain re-exported at root for producer-side callers. orchestration/app.rs: - Extracted all frame-touching code (CollectedDatastreamFrame, drain_datastream_connections, update_load_progress_from_frame, drain_frames, archive_collected_frame, pump, OrchDatastream, DashboardSupport) into two new observability modules: frame_collector.rs and orch_datastream.rs. - The orchestrator now interacts through a FrameCollector whose drain/drain_with_progress methods take closures; it never names Frame, DatastreamEvent, or CollectedDatastreamFrame. - StageLoadProgress (the one control-relevant signal previously scraped from frame payloads) is extracted inside FrameCollector and handed to the control loop as plain data. xtask: - New check-telemetry-isolation command scans control-plane modules (orchestration/, distribution/, data-plane/, provisioning/) for forbidden frame-type references and fails the build if any are found. Verified: workspace builds (myelin + dashboard feature), datastream 29 tests pass, myelin 64 lib tests pass, check-telemetry-isolation passes clean. Signed-off-by: Zachery Aaron Shores-Chmielewski <zacheryasc@gmail.com> |
||
|---|---|---|
| .. | ||
| src | ||
| tests | ||
| Cargo.toml | ||
| IROH_DRIVER_SPEC.md | ||
| README.md | ||
iroh-driver
iroh-driver is the iroh-backed transport bridge for the actorized distribution stack. It owns the concrete iroh endpoint, QUIC connections, relay configuration, peer authorization, and frame shuttling between iroh and swactor actor mailboxes.
Engine ownership
The driver runs on a caller-supplied swactor EngineHandle — the
single engine that owns the node's Tokio substrate. All accepts, reads, dials,
writes, retries, and teardown are scheduled through that handle; the driver
stores no raw Tokio handle and performs no ambient-runtime detection
(ENGINE_SPEC.md §7).
let driver = IrohDriver::with_engine(engine.handle(), config)?;
The driver validates that the engine provides the tasks, timers, and io
capabilities before binding the endpoint or starting any background work
(ENGINE_SPEC.md). Endpoint construction runs as an engine-hosted
task; with_engine blocks on a synchronous channel until the endpoint is bound
(or fails), so callers need not enter or possess the raw substrate runtime.
Engine-hosted progression
All adapter progression — actor-bridge ingress/egress, datastream ingress, and
edge ingress — is driven by an engine-hosted interval pump installed via
install_actor_bridge_pump. Applications do not (and cannot) manually pump
these adapters; the single engine owns progression for the node's lifetime
(ENGINE_SPEC.md). snapshot is a pure-synchronous read of driver
state, callable from any thread. The shutdown method closes the endpoint via
an engine-hosted task, blocking on a synchronous channel until completion.