hubcio commented on code in PR #4193:
URL: https://github.com/apache/iggy/pull/4193#discussion_r4016268797


##########
core/shard/src/coordinator.rs:
##########
@@ -358,31 +344,78 @@ impl ShardZeroCoordinator {
     /// fails or `dup(2)` fails. Returns [`SendError::RoutingFailed`]
     /// when the target shard's inbox refuses the setup frame.
     pub fn delegate_ws_client(&self, stream: TcpStream) -> Result<u128, 
SendError> {
+        self.ship_client_fd(stream, ClientTransportKind::Ws, |fd, meta| {
+            LifecycleFrame::ClientWsConnectionSetup { fd, meta }
+        })
+    }
+
+    /// Delegate a raw TCP socket and its listener's TLS configuration.
+    /// The destination shard owns the TLS handshake and encrypted I/O.
+    ///
+    /// # Errors
+    ///
+    /// Returns the same lookup, duplication and routing errors as
+    /// [`Self::delegate_client`]. Both socket handles close on failure.
+    pub fn delegate_tcp_tls_client(
+        &self,
+        stream: TcpStream,
+        config: SharedTlsServerConfig,
+    ) -> Result<u128, SendError> {
+        self.ship_client_fd(stream, ClientTransportKind::TcpTls, |fd, meta| {
+            LifecycleFrame::ClientTcpTlsConnectionSetup { fd, meta, config }
+        })
+    }
+
+    /// Delegate WSS before TLS or WebSocket state is created. Both
+    /// handshakes and all subsequent I/O run on the destination shard.
+    ///
+    /// # Errors
+    ///
+    /// Returns the same lookup, duplication and routing errors as
+    /// [`Self::delegate_client`]. Both socket handles close on failure.
+    pub fn delegate_wss_client(
+        &self,
+        stream: TcpStream,
+        config: SharedTlsServerConfig,
+    ) -> Result<u128, SendError> {
+        self.ship_client_fd(stream, ClientTransportKind::Wss, |fd, meta| {
+            LifecycleFrame::ClientWssConnectionSetup { fd, meta, config }
+        })
+    }
+
+    #[must_use]
+    pub const fn total_shards(&self) -> u16 {
+        self.total_shards
+    }
+
+    fn ship_client_fd(

Review Comment:
   the client path has no global handshake cap, and moving it to workers widens 
the impact. this needs a separate client-admission change with explicit limits 
and cleanup.



##########
core/shard/src/coordinator.rs:
##########
@@ -358,31 +344,78 @@ impl ShardZeroCoordinator {
     /// fails or `dup(2)` fails. Returns [`SendError::RoutingFailed`]
     /// when the target shard's inbox refuses the setup frame.
     pub fn delegate_ws_client(&self, stream: TcpStream) -> Result<u128, 
SendError> {
+        self.ship_client_fd(stream, ClientTransportKind::Ws, |fd, meta| {
+            LifecycleFrame::ClientWsConnectionSetup { fd, meta }
+        })
+    }
+
+    /// Delegate a raw TCP socket and its listener's TLS configuration.
+    /// The destination shard owns the TLS handshake and encrypted I/O.
+    ///
+    /// # Errors
+    ///
+    /// Returns the same lookup, duplication and routing errors as
+    /// [`Self::delegate_client`]. Both socket handles close on failure.
+    pub fn delegate_tcp_tls_client(
+        &self,
+        stream: TcpStream,
+        config: SharedTlsServerConfig,
+    ) -> Result<u128, SendError> {
+        self.ship_client_fd(stream, ClientTransportKind::TcpTls, |fd, meta| {
+            LifecycleFrame::ClientTcpTlsConnectionSetup { fd, meta, config }
+        })
+    }
+
+    /// Delegate WSS before TLS or WebSocket state is created. Both
+    /// handshakes and all subsequent I/O run on the destination shard.
+    ///
+    /// # Errors
+    ///
+    /// Returns the same lookup, duplication and routing errors as
+    /// [`Self::delegate_client`]. Both socket handles close on failure.
+    pub fn delegate_wss_client(
+        &self,
+        stream: TcpStream,
+        config: SharedTlsServerConfig,
+    ) -> Result<u128, SendError> {
+        self.ship_client_fd(stream, ClientTransportKind::Wss, |fd, meta| {
+            LifecycleFrame::ClientWssConnectionSetup { fd, meta, config }
+        })
+    }
+
+    #[must_use]
+    pub const fn total_shards(&self) -> u16 {
+        self.total_shards
+    }
+
+    fn ship_client_fd(
+        &self,
+        stream: TcpStream,
+        transport: ClientTransportKind,
+        build_frame: impl FnOnce(fd_transfer::DupedFd, ClientConnMeta) -> 
LifecycleFrame,
+    ) -> Result<u128, SendError> {
         let target = self.next_client_target();

Review Comment:
   alternating TCP and TLS accepts can concentrate TLS on a subset of shards 
while total connection counts stay balanced. per-transport balancing needs a 
separate placement-policy change.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to