swactor/crates/iroh-driver
Zachery Aaron Shores-Chmielewski b8aff00dc1 enforce datastream telemetry-only invariant: ban frame types from control code
The datastream is metrics/logging only; control decisions must never branch
on a frame.  This was a recurring cultural problem with no structural
enforcement.  This change makes it a compile-time and CI-enforced fact.

datastream crate (lib.rs):
- Stop re-exporting Frame, DatastreamEvent, FrameDelivery at crate root.
   is now a compile error (E0425).  These types live
  only in datastream::frame::* and are documented as the observer surface.
- Safe identity types (ChannelId, StreamId, Position, Record, etc.) remain
  re-exported at root for producer-side callers.

orchestration/app.rs:
- Extracted all frame-touching code (CollectedDatastreamFrame,
  drain_datastream_connections, update_load_progress_from_frame,
  drain_frames, archive_collected_frame, pump, OrchDatastream,
  DashboardSupport) into two new observability modules:
  frame_collector.rs and orch_datastream.rs.
- The orchestrator now interacts through a FrameCollector whose
  drain/drain_with_progress methods take closures; it never names Frame,
  DatastreamEvent, or CollectedDatastreamFrame.
- StageLoadProgress (the one control-relevant signal previously scraped
  from frame payloads) is extracted inside FrameCollector and handed to
  the control loop as plain data.

xtask:
- New check-telemetry-isolation command scans control-plane modules
  (orchestration/, distribution/, data-plane/, provisioning/) for
  forbidden frame-type references and fails the build if any are found.

Verified: workspace builds (myelin + dashboard feature), datastream 29
tests pass, myelin 64 lib tests pass, check-telemetry-isolation passes
clean.

Signed-off-by: Zachery Aaron Shores-Chmielewski <zacheryasc@gmail.com>
2026-08-12 16:14:57 +04:00
..
src enforce datastream telemetry-only invariant: ban frame types from control code 2026-08-12 16:14:57 +04:00
tests feat(core): add process-local multicore runtime 2026-08-11 16:12:09 +04:00
Cargo.toml feat(engine): substrate-neutral execution engine abstraction 2026-08-11 00:23:03 +04:00
IROH_DRIVER_SPEC.md feat(core): add process-local multicore runtime 2026-08-11 16:12:09 +04:00
README.md feat(engine): substrate-neutral execution engine abstraction 2026-08-11 00:23:03 +04:00

iroh-driver

iroh-driver is the iroh-backed transport bridge for the actorized distribution stack. It owns the concrete iroh endpoint, QUIC connections, relay configuration, peer authorization, and frame shuttling between iroh and swactor actor mailboxes.

Engine ownership

The driver runs on a caller-supplied swactor EngineHandle — the single engine that owns the node's Tokio substrate. All accepts, reads, dials, writes, retries, and teardown are scheduled through that handle; the driver stores no raw Tokio handle and performs no ambient-runtime detection (ENGINE_SPEC.md §7).

let driver = IrohDriver::with_engine(engine.handle(), config)?;

The driver validates that the engine provides the tasks, timers, and io capabilities before binding the endpoint or starting any background work (ENGINE_SPEC.md). Endpoint construction runs as an engine-hosted task; with_engine blocks on a synchronous channel until the endpoint is bound (or fails), so callers need not enter or possess the raw substrate runtime.

Engine-hosted progression

All adapter progression — actor-bridge ingress/egress, datastream ingress, and edge ingress — is driven by an engine-hosted interval pump installed via install_actor_bridge_pump. Applications do not (and cannot) manually pump these adapters; the single engine owns progression for the node's lifetime (ENGINE_SPEC.md). snapshot is a pure-synchronous read of driver state, callable from any thread. The shutdown method closes the endpoint via an engine-hosted task, blocking on a synchronous channel until completion.