Compare commits
13 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 88ef946af5 | |||
| 2ff7cd6d9d | |||
| 7e3be2cad1 | |||
| 94aba8a3bb | |||
| b4b6072fe1 | |||
| 6d076c281a | |||
| 1baa1055dc | |||
| 06c3973ce7 | |||
| a9a2b3db35 | |||
| 49564c7e7e | |||
| 02ca502a76 | |||
| 47382ddadc | |||
| 69c8b2d2bc |
@@ -30,5 +30,61 @@ jobs:
|
|||||||
- name: Build
|
- name: Build
|
||||||
run: dotnet build Rendezvous.slnx --configuration Release --no-restore
|
run: dotnet build Rendezvous.slnx --configuration Release --no-restore
|
||||||
|
|
||||||
|
- name: Verify generated API contract
|
||||||
|
run: git diff --exit-code -- docs/api
|
||||||
|
|
||||||
- name: Test
|
- name: Test
|
||||||
run: dotnet test Rendezvous.slnx --configuration Release --no-build
|
run: dotnet test Rendezvous.slnx --configuration Release --no-build
|
||||||
|
|
||||||
|
- name: Test privileged Linux namespace topology when available
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
probe="rendezvous-probe-$$"
|
||||||
|
suffix="$(( $$ % 100000 ))"
|
||||||
|
bridge="rvb${suffix}"
|
||||||
|
veth_root="rvr${suffix}"
|
||||||
|
veth_peer="rvp${suffix}"
|
||||||
|
cleanup_probe() {
|
||||||
|
if [[ -n "$veth_root" ]]; then
|
||||||
|
ip link delete "$veth_root" >/dev/null 2>&1 || true
|
||||||
|
fi
|
||||||
|
if [[ -n "$bridge" ]]; then
|
||||||
|
ip link delete "$bridge" >/dev/null 2>&1 || true
|
||||||
|
fi
|
||||||
|
if [[ -n "$probe" ]]; then
|
||||||
|
ip netns delete "$probe" >/dev/null 2>&1 || true
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
trap cleanup_probe EXIT
|
||||||
|
if command -v ip >/dev/null 2>&1 \
|
||||||
|
&& command -v iptables >/dev/null 2>&1 \
|
||||||
|
&& command -v sysctl >/dev/null 2>&1 \
|
||||||
|
&& ip netns add "$probe" 2>/dev/null \
|
||||||
|
&& ip link add "$bridge" type bridge \
|
||||||
|
&& ip link add "$veth_root" type veth peer name "$veth_peer" \
|
||||||
|
&& ip link set "$veth_root" master "$bridge" \
|
||||||
|
&& ip link set "$veth_peer" netns "$probe" \
|
||||||
|
&& ip netns exec "$probe" sysctl -q -w net.ipv4.ip_forward=1 \
|
||||||
|
&& ip netns exec "$probe" iptables -t nat -A POSTROUTING -o "$veth_peer" -j MASQUERADE \
|
||||||
|
&& ip netns exec "$probe" iptables -A FORWARD -i "$veth_peer" -o lo \
|
||||||
|
-m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT; then
|
||||||
|
ip link delete "$veth_root"
|
||||||
|
veth_root=""
|
||||||
|
ip link delete "$bridge"
|
||||||
|
bridge=""
|
||||||
|
ip netns delete "$probe"
|
||||||
|
probe=""
|
||||||
|
results="${RUNNER_TEMP:-/tmp}/rendezvous-netns-results"
|
||||||
|
mkdir -p "$results"
|
||||||
|
RENDEZVOUS_RUN_NETNS_TESTS=1 dotnet test Rendezvous.slnx \
|
||||||
|
--configuration Release \
|
||||||
|
--no-build \
|
||||||
|
--filter FullyQualifiedName~PrivilegedLinuxNatNamespacesCompleteDirectTrafficAcrossSeparateObservedEndpoints \
|
||||||
|
--logger "trx;LogFileName=netns.trx" \
|
||||||
|
--results-directory "$results"
|
||||||
|
grep -q 'testName="[^"]*\.PrivilegedLinuxNatNamespacesCompleteDirectTrafficAcrossSeparateObservedEndpoints"' \
|
||||||
|
"$results/netns.trx"
|
||||||
|
else
|
||||||
|
echo "Network namespaces/NAT tooling unavailable; deterministic loopback topology remains the required gate."
|
||||||
|
fi
|
||||||
|
|||||||
@@ -5,7 +5,11 @@
|
|||||||
</PropertyGroup>
|
</PropertyGroup>
|
||||||
<ItemGroup>
|
<ItemGroup>
|
||||||
<PackageVersion Include="LiteNetLib" Version="2.1.4" />
|
<PackageVersion Include="LiteNetLib" Version="2.1.4" />
|
||||||
|
<PackageVersion Include="Microsoft.AspNetCore.OpenApi" Version="10.0.9" />
|
||||||
|
<PackageVersion Include="Microsoft.Extensions.ApiDescription.Server" Version="10.0.9" />
|
||||||
<PackageVersion Include="Microsoft.NET.Test.Sdk" Version="18.4.0" />
|
<PackageVersion Include="Microsoft.NET.Test.Sdk" Version="18.4.0" />
|
||||||
|
<PackageVersion Include="Microsoft.OpenApi" Version="2.7.5" />
|
||||||
|
<PackageVersion Include="System.Text.Json" Version="10.0.10" />
|
||||||
<PackageVersion Include="xunit" Version="2.9.3" />
|
<PackageVersion Include="xunit" Version="2.9.3" />
|
||||||
<PackageVersion Include="xunit.runner.visualstudio" Version="3.1.5" />
|
<PackageVersion Include="xunit.runner.visualstudio" Version="3.1.5" />
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ Rendezvous is intended to provide:
|
|||||||
- Isolation by game, environment, protocol version, and region.
|
- Isolation by game, environment, protocol version, and region.
|
||||||
- Operational health, metrics, logging, administration, and rate limiting.
|
- Operational health, metrics, logging, administration, and rate limiting.
|
||||||
|
|
||||||
UDP hole punching cannot guarantee a direct connection through every network. Symmetric NAT, carrier-grade NAT, restrictive firewalls, and platform policies can prevent it. Consumers must therefore support a defined fallback, such as a dedicated server or a future relay service.
|
UDP hole punching cannot guarantee a direct connection through every network. Symmetric NAT, carrier-grade NAT, restrictive firewalls, and platform policies can prevent it. Consumers must therefore support a defined fallback, such as a dedicated server. The v1 SDK returns an optional game-configured endpoint for an explicit caller decision; it never routes automatically, and v1 does not provide a relay.
|
||||||
|
|
||||||
## Connection flow
|
## Connection flow
|
||||||
|
|
||||||
@@ -75,10 +75,27 @@ The initial service does not provide:
|
|||||||
|
|
||||||
## Project status
|
## Project status
|
||||||
|
|
||||||
Rendezvous is currently in its initial design and bootstrap stage. The first implementation should establish the contracts, directory leases, LiteNetLib mediator, client SDK, thin test client, and a three-party integration test before either game depends on it for production connectivity.
|
Rendezvous is under active roadmap development. The versioned contracts,
|
||||||
|
directory leases, authenticated join attempts, LiteNetLib mediator, caller-owned
|
||||||
|
SDK coordination, typed connection outcomes, and thin public-SDK diagnostic client
|
||||||
|
are implemented. Deployment hardening, the broader NAT-topology harness, and
|
||||||
|
the production-readiness roadmap remain in progress;
|
||||||
|
participating games must not treat the current repository as a finished production
|
||||||
|
service until those gates land.
|
||||||
|
|
||||||
The ratified v1 boundaries, trust decisions, privacy rules, safety budgets, and
|
The ratified v1 boundaries, trust decisions, privacy rules, safety budgets, and
|
||||||
threat model are indexed in [the architecture documentation](docs/architecture/README.md).
|
threat model are indexed in [the architecture documentation](docs/architecture/README.md).
|
||||||
|
The frozen v1 wire surface is documented in the
|
||||||
|
[HTTP, UDP, and generated OpenAPI contracts](docs/contracts/README.md).
|
||||||
|
Tenant policy, publisher/operator principals, and production key custody are
|
||||||
|
defined in [game provisioning and signing-key lifecycle](docs/security/provisioning.md).
|
||||||
|
Layered HTTP/UDP budgets, overload behavior, and safe operational tuning are
|
||||||
|
defined in [hostile-input and overload protection](docs/security/abuse-protection.md).
|
||||||
|
The scriptable host/browser/join diagnostic and its stable automation contract are
|
||||||
|
documented in the [TestClient integration guide](docs/integration/test-client.md).
|
||||||
|
The always-on three-party scenarios, optional Linux namespace topology, and
|
||||||
|
simulation limits are documented in the
|
||||||
|
[deterministic topology harness](docs/integration/topology-harness.md).
|
||||||
|
|
||||||
## Development
|
## Development
|
||||||
|
|
||||||
@@ -95,5 +112,9 @@ dotnet test Rendezvous.slnx --configuration Release --no-build
|
|||||||
Run the bootstrap server with
|
Run the bootstrap server with
|
||||||
`dotnet run --project src/FinalFactory.Rendezvous.Server`. It serves HTTP health endpoints and binds
|
`dotnet run --project src/FinalFactory.Rendezvous.Server`. It serves HTTP health endpoints and binds
|
||||||
the configured UDP mediator port; both stop through normal host cancellation.
|
the configured UDP mediator port; both stop through normal host cancellation.
|
||||||
|
The launch profile uses an ephemeral development-only signing key. Production
|
||||||
|
startup fails closed until externally supplied game policies and `env:` signing
|
||||||
|
key references resolve to valid key material; no reusable game secret is stored
|
||||||
|
in this repository or the public Client package.
|
||||||
The project dependency rules and supported runtime choices are documented in
|
The project dependency rules and supported runtime choices are documented in
|
||||||
[project and dependency boundaries](docs/architecture/project-boundaries.md).
|
[project and dependency boundaries](docs/architecture/project-boundaries.md).
|
||||||
|
|||||||
File diff suppressed because it is too large
Load Diff
@@ -64,7 +64,7 @@ them but must not raise them without security review.
|
|||||||
| Browser page | 100 listings and 256 KiB encoded response; opaque cursor; stable bounded sort |
|
| Browser page | 100 listings and 256 KiB encoded response; opaque cursor; stable bounded sort |
|
||||||
| UDP datagram accepted | 1,200 bytes; oversized or fragmented application payloads are dropped without response |
|
| UDP datagram accepted | 1,200 bytes; oversized or fragmented application payloads are dropped without response |
|
||||||
| Opaque HTTP credential | 1,024 bytes encoded |
|
| Opaque HTTP credential | 1,024 bytes encoded |
|
||||||
| UDP capability or ticket | 768 bytes encoded, with the complete datagram still at most 1,200 bytes |
|
| UDP capability or connection ticket | 192 base64url characters; NAT punch capabilities also remain below LiteNetLib's 256-character token ceiling; complete datagram at most 1,200 bytes |
|
||||||
| Clock skew | 30 seconds maximum when validating issued/not-before/expiry times |
|
| Clock skew | 30 seconds maximum when validating issued/not-before/expiry times |
|
||||||
| Lease lifetime | 60 seconds; renewal accepted from 30 seconds; no client-selected extension |
|
| Lease lifetime | 60 seconds; renewal accepted from 30 seconds; no client-selected extension |
|
||||||
| Host presence freshness | 20 seconds |
|
| Host presence freshness | 20 seconds |
|
||||||
|
|||||||
@@ -0,0 +1,101 @@
|
|||||||
|
# ADR 0004: atomic ephemeral state and single-active availability
|
||||||
|
|
||||||
|
- Status: Accepted
|
||||||
|
- Date: 2026-07-16
|
||||||
|
- Tracking: #6
|
||||||
|
|
||||||
|
## Context
|
||||||
|
|
||||||
|
Listings, leases, endpoint observations, join attempts, and replay decisions must
|
||||||
|
move together. A partially committed authorization can expose an expired listing,
|
||||||
|
reuse a capability, or introduce an endpoint that was never authorized. V1 is a
|
||||||
|
single-active service, so it needs honest bounded in-memory behavior rather than
|
||||||
|
a database-shaped abstraction that implies unavailable durability or scale.
|
||||||
|
|
||||||
|
## Decision
|
||||||
|
|
||||||
|
`IEphemeralRendezvousStore` is the atomic boundary for directory, lease, presence,
|
||||||
|
attempt, endpoint, replay, revocation, and drain transitions. The v1 implementation
|
||||||
|
serializes each transition under one process-local lock. This deliberately favors
|
||||||
|
simple, auditable correctness at the initial 25,000-listing/10,000-attempt ceiling.
|
||||||
|
It retains only immutable listing data, opaque credential fingerprints, observed
|
||||||
|
endpoints, monotonic deadlines, and bounded idempotency/replay records.
|
||||||
|
|
||||||
|
Every collection has an independent configured ceiling. An operation checks all
|
||||||
|
of the capacity it needs before changing any collection. Exhaustion returns
|
||||||
|
`CapacityExceeded`; it does not evict live state, partially insert an operation,
|
||||||
|
or grow a fallback queue. Policy-provided per-owner listing and per-tenant active
|
||||||
|
attempt quotas are evaluated inside the same creation transition, so concurrent
|
||||||
|
requests cannot pass a check performed outside the store. New join authorization returns `ServiceUnavailable`
|
||||||
|
when the atomic store is unavailable and `Draining` once drain starts.
|
||||||
|
|
||||||
|
### Time and cleanup
|
||||||
|
|
||||||
|
Expiry uses an injected monotonic clock. Wall time is used only to return an
|
||||||
|
informational `ExpiresAt` value. Moving the wall clock forward or backward cannot
|
||||||
|
expire or prolong authority. Cleanup runs deterministically at the start of every
|
||||||
|
store operation and removes presence, attempts, listings, replay entries,
|
||||||
|
idempotency records, and revocations at their deadline. Removal of a listing also
|
||||||
|
removes its presence handle and every linked attempt before another caller can
|
||||||
|
observe the store.
|
||||||
|
|
||||||
|
### Concurrency and idempotency
|
||||||
|
|
||||||
|
- Listing registration and join-attempt creation use a tenant-and-owner-scoped idempotency
|
||||||
|
key plus a canonical request fingerprint. An exact duplicate returns the
|
||||||
|
original live result; reuse with different input returns `Conflict`; replay
|
||||||
|
after the resource has expired returns `Expired` until the bounded idempotency
|
||||||
|
record itself expires. Configuration requires idempotency retention to cover
|
||||||
|
every listing and attempt lifetime, preventing a live duplicate after eviction.
|
||||||
|
- Lease renewal is compare-and-swap by version. A stale renewal returns the latest
|
||||||
|
version as `Conflict`. Renew/delete races are serialized: renewal either commits
|
||||||
|
before deletion or observes the listing as absent.
|
||||||
|
- Host presence refresh is an atomic whole-endpoint replacement because NAT
|
||||||
|
mappings can legitimately change. Attempt capabilities are different: the
|
||||||
|
first endpoint bound for each role wins, an identical datagram is idempotent,
|
||||||
|
and a different replay is rejected. Introduction is consumed once atomically.
|
||||||
|
- Cancellation is checked before waiting for the lock and again after acquiring
|
||||||
|
it. A cancellation observed at either point makes no change. Once a synchronous
|
||||||
|
transition starts, it completes atomically and does not expose partial state.
|
||||||
|
|
||||||
|
### Visibility and revocation
|
||||||
|
|
||||||
|
A listing is visible or joinable only when its lease and authenticated UDP host
|
||||||
|
presence are both fresh. Public browsing is tenant/protocol scoped, excludes
|
||||||
|
unlisted sessions, and uses a stable listing-ID order with the contract page
|
||||||
|
ceiling. Revoking a listing or principal removes every listing, presence, and
|
||||||
|
attempt path in the same transition. A revocation is inserted before removal;
|
||||||
|
if the bounded revocation pool is full, the operation rejects without deleting
|
||||||
|
anything.
|
||||||
|
|
||||||
|
### Restart and graceful drain
|
||||||
|
|
||||||
|
A process restart creates a new store instance ID and starts empty. Old listing,
|
||||||
|
lease, attempt, endpoint, idempotency, and consumption state is not recovered.
|
||||||
|
Publishers must re-register; old callers receive typed `NotFound`, `Expired`, or
|
||||||
|
`ServiceUnavailable` outcomes rather than an ambiguous success. No database is
|
||||||
|
required or supported for the single-active MVP.
|
||||||
|
|
||||||
|
Drain is idempotent. It immediately rejects new registrations, attempts, and
|
||||||
|
lease extensions, while already-created attempts may bind endpoints and consume
|
||||||
|
their introduction during the configured window (at most 30 seconds). At the
|
||||||
|
deadline all active state is cleared atomically. Readiness is false while draining
|
||||||
|
or unavailable, and application shutdown starts drain before teardown.
|
||||||
|
|
||||||
|
## Future shared-store mapping
|
||||||
|
|
||||||
|
The interface uses explicit typed outcomes, TTLs, compare-and-swap versions,
|
||||||
|
idempotency records, and all-or-nothing multi-record transitions. A future Redis
|
||||||
|
implementation therefore requires authenticated transport, tenant-prefixed keys,
|
||||||
|
server-side scripts or transactions for each transition, TTLs based on the store's
|
||||||
|
authoritative time, and deterministic mediator routing. It must preserve these
|
||||||
|
semantics and pass the same contract tests before issue #18 may enable more than
|
||||||
|
one active instance.
|
||||||
|
|
||||||
|
## Consequences
|
||||||
|
|
||||||
|
- V1 has deterministic failure and restart behavior without durable gameplay state.
|
||||||
|
- A single lock is a measured capacity constraint, not a claim of horizontal scale.
|
||||||
|
- Transport and HTTP modules cannot bypass the store for authorization decisions.
|
||||||
|
- Operational code must treat `CapacityExceeded`, `Draining`, and
|
||||||
|
`ServiceUnavailable` as normal typed overload/availability outcomes.
|
||||||
@@ -0,0 +1,93 @@
|
|||||||
|
# ADR 0005: authenticated session lease and presence lifecycle
|
||||||
|
|
||||||
|
- Status: Accepted
|
||||||
|
- Date: 2026-07-16
|
||||||
|
- Tracking: #7
|
||||||
|
|
||||||
|
## Context
|
||||||
|
|
||||||
|
A host needs to publish a player-facing session without letting an HTTP request
|
||||||
|
claim a public endpoint or remain visible after the gameplay socket disappears.
|
||||||
|
Registration retries must be safe, credentials must remain opaque, and policy or
|
||||||
|
ownership checks cannot race state mutation.
|
||||||
|
|
||||||
|
## Decision
|
||||||
|
|
||||||
|
The four host HTTP operations require `Authorization: Bearer <publisher credential>`.
|
||||||
|
The signed principal supplies the authoritative game, environment, publisher trust
|
||||||
|
mode, subject, and allowed regions. Request fields never widen that scope. Creation
|
||||||
|
and update apply the enabled `GamePolicy` to exact protocol, region, visibility,
|
||||||
|
bounded display/build/capacity values, and the allowlisted metadata schema.
|
||||||
|
|
||||||
|
Capacity reported by a host is advisory directory information. Rendezvous bounds
|
||||||
|
and publishes it but never treats it as final admission authority; the game host
|
||||||
|
still decides identity, bans, reserved slots, and whether a connection may join.
|
||||||
|
|
||||||
|
```mermaid
|
||||||
|
stateDiagram-v2
|
||||||
|
[*] --> AwaitingPresence: authorized register
|
||||||
|
AwaitingPresence --> Listed: valid host UDP presence
|
||||||
|
Listed --> AwaitingPresence: presence deadline passes
|
||||||
|
AwaitingPresence --> AwaitingPresence: lease renew or data update
|
||||||
|
Listed --> Listed: lease renew, data update, or presence refresh
|
||||||
|
AwaitingPresence --> Removed: lease expiry or delete
|
||||||
|
Listed --> Removed: lease expiry or delete
|
||||||
|
Removed --> [*]
|
||||||
|
```
|
||||||
|
|
||||||
|
Registration returns a listing ID, lease ID/token, host-presence handle/capability,
|
||||||
|
lease expiry, a 30-second renewal suggestion, and a 10-second presence-refresh
|
||||||
|
suggestion. The authoritative ceilings remain 60 seconds for the lease and 20
|
||||||
|
seconds for presence. Timing suggestions are server-controlled, not client-selected.
|
||||||
|
|
||||||
|
The lease token and presence capability are 256-bit opaque values derived with
|
||||||
|
HMAC-SHA256 from an in-memory per-process secret, a purpose label, the publisher
|
||||||
|
subject, the idempotency key, a canonical request fingerprint, and a random
|
||||||
|
per-registration derivation salt. Opaque IDs use separate purpose labels. Exact
|
||||||
|
retries read the retained non-secret salt and therefore reproduce the original
|
||||||
|
response without retaining plaintext credentials. Once the bounded idempotency
|
||||||
|
record expires, a new salt rotates IDs and capabilities so an old token cannot
|
||||||
|
regain authority. Metadata order is canonicalized before fingerprinting. The store
|
||||||
|
retains the salt and only a second keyed fingerprint of each token. Restart rotates
|
||||||
|
the derivation secret while the matching ephemeral state disappears.
|
||||||
|
|
||||||
|
Renew, update, and delete require both the same publisher subject and the lease
|
||||||
|
capability. Cross-owner or wrong-capability access returns the same not-found shape.
|
||||||
|
Update may change display name, build label, advisory capacity, and metadata only;
|
||||||
|
game, environment, region, protocol, visibility, trust mode, and opaque IDs remain
|
||||||
|
canonical. Delete is idempotent and does not reveal whether another publisher owns
|
||||||
|
the supplied ID.
|
||||||
|
|
||||||
|
### UDP presence
|
||||||
|
|
||||||
|
Only a structurally valid frozen `HostPresence` envelope or native LiteNetLib
|
||||||
|
host-presence request with the issued capability can refresh presence. The public
|
||||||
|
endpoint is the UDP packet's observed source on the host's gameplay socket; the
|
||||||
|
HTTP API never accepts one. The bounded local candidate comes from the authenticated
|
||||||
|
packet. Invalid or unknown inputs receive no response. ADR 0009 defines the later
|
||||||
|
attempt-role use of frozen `ClientPresence` and native host/client requests.
|
||||||
|
Presence expiry demotes public visibility but keeps the lease, so the same handle
|
||||||
|
can restore visibility without changing session identity.
|
||||||
|
|
||||||
|
Public listing responses contain bounded listing data only. They never contain
|
||||||
|
public/local endpoints, lease tokens, presence capabilities, fingerprints, store
|
||||||
|
keys, or canonical player identity.
|
||||||
|
|
||||||
|
## Failure semantics
|
||||||
|
|
||||||
|
- malformed or policy-invalid fields return a stable typed `InvalidRequest`;
|
||||||
|
- an unsupported gameplay protocol returns `IncompatibleProtocol`;
|
||||||
|
- missing/invalid publisher authentication returns `AuthenticationRequired`;
|
||||||
|
- cross-scope authorization returns `Forbidden` without resource disclosure;
|
||||||
|
- wrong owner/capability or expired state returns the tenant-hidden `NotFound`;
|
||||||
|
- idempotency reuse with changed input returns `Conflict`;
|
||||||
|
- publisher/global exhaustion returns `CapacityExceeded`; and
|
||||||
|
- drain or loss of atomic state returns `ServiceUnavailable` and authorizes no join.
|
||||||
|
|
||||||
|
## Consequences
|
||||||
|
|
||||||
|
- HTTP registration alone can never make a public session browseable.
|
||||||
|
- Plaintext session capabilities are returned to the intended host but are not
|
||||||
|
retained, logged, included in public listing DTOs, or exported as metrics.
|
||||||
|
- Re-registration after restart is the recovery path; there is no durable session
|
||||||
|
identity or gameplay state in Rendezvous.
|
||||||
@@ -0,0 +1,51 @@
|
|||||||
|
# ADR 0006: bounded compatible session browser
|
||||||
|
|
||||||
|
- Status: Accepted
|
||||||
|
- Date: 2026-07-16
|
||||||
|
- Tracking: #8
|
||||||
|
|
||||||
|
## Decision
|
||||||
|
|
||||||
|
The public list endpoint requires game, environment, and exact gameplay protocol.
|
||||||
|
Region is optional, page size is 1–100, and callers may exclude sessions whose
|
||||||
|
advisory current-player count has reached the advertised maximum. Lists contain
|
||||||
|
public sessions only and only while both lease and authenticated host presence are
|
||||||
|
fresh. Unlisted sessions never appear in a list; they may be retrieved directly by
|
||||||
|
their 128-bit unguessable listing ID only when the caller also supplies the exact
|
||||||
|
game, environment, and protocol scope.
|
||||||
|
|
||||||
|
Results use ascending opaque listing ID as a deterministic keyset. A cursor carries
|
||||||
|
the last ID plus every compatibility/filter field, a five-minute expiry, and an
|
||||||
|
HMAC-SHA256 signature under a per-process key. Tampering, expiry, or reuse with a
|
||||||
|
different tenant/protocol/region/full filter returns `InvalidRequest`. Restart
|
||||||
|
rotates the key, matching the loss of ephemeral listings.
|
||||||
|
|
||||||
|
Pagination is a bounded live view, not a database snapshot. A record that remains
|
||||||
|
eligible and whose ID is greater than the cursor is returned exactly once. Records
|
||||||
|
removed or made stale disappear immediately. A record created after a page whose ID
|
||||||
|
sorts before that page's cursor is outside that traversal; callers refresh from the
|
||||||
|
first page to discover new sessions. This avoids skips or duplicates among stable
|
||||||
|
eligible records without retaining per-browser snapshot state.
|
||||||
|
|
||||||
|
The store reads at most page size plus one record. The service serializes against
|
||||||
|
the 256 KiB response ceiling and shortens a page before returning it when metadata
|
||||||
|
makes the requested count too large. A continuation cursor is emitted whenever an
|
||||||
|
extra or byte-trimmed record remains. All cursor, page, metadata, property, scalar,
|
||||||
|
and collection sizes are bounded before untrusted allocation can grow without a
|
||||||
|
ceiling.
|
||||||
|
|
||||||
|
Browser DTOs are fresh copies containing only opaque listing ID, exact compatibility,
|
||||||
|
region, visibility/trust presentation, advisory capacity, build/display labels, and
|
||||||
|
policy-validated string metadata. They contain no observed endpoint, lease,
|
||||||
|
capability, ticket, credential fingerprint, derivation salt, principal subject, or
|
||||||
|
store key. Metadata is display text: JSON encoding escapes markup, but game UI must
|
||||||
|
still render values as text and must never execute markup, interpret endpoints, or
|
||||||
|
use metadata for authorization.
|
||||||
|
|
||||||
|
## Consequences
|
||||||
|
|
||||||
|
- Cross-game, cross-environment, incompatible, stale, revoked, expired, unlisted,
|
||||||
|
and optionally full sessions are removed before response construction.
|
||||||
|
- Direct unlisted lookup is suitable for an out-of-band invite carrying the opaque
|
||||||
|
ID; human join codes remain future work and require their own bounded abuse model.
|
||||||
|
- Host capacity remains advisory. The host makes the final admission decision.
|
||||||
@@ -0,0 +1,53 @@
|
|||||||
|
# ADR 0007: caller-owned .NET publisher and browser SDK
|
||||||
|
|
||||||
|
- Status: Accepted
|
||||||
|
- Date: 2026-07-16
|
||||||
|
- Tracking: #9
|
||||||
|
|
||||||
|
## Decision
|
||||||
|
|
||||||
|
The .NET client package exposes separate publisher and browser interfaces plus
|
||||||
|
concrete clients over a caller-supplied `HttpClient`. The caller owns that client,
|
||||||
|
its handler, base address, connection pool, proxy, and lifetime. SDK operations
|
||||||
|
dispose every request, response, and response body they create, but never dispose
|
||||||
|
the supplied client. The package targets `netstandard2.1`, depends only on the
|
||||||
|
wire-contract package and LiteNetLib, and contains no Godot types, global client,
|
||||||
|
service URL, publisher secret, or embedded game credential.
|
||||||
|
|
||||||
|
Every operation returns `RendezvousClientResult<T>` with a stable error code,
|
||||||
|
message, and optional retry guidance. Cancellation remains exceptional through
|
||||||
|
the caller's `CancellationToken`; transport failures become `ServiceUnavailable`.
|
||||||
|
Response bodies are streamed under the contract's 256 KiB browser ceiling before
|
||||||
|
deserialization. Invalid or oversized success bodies become `InternalError` and
|
||||||
|
never escape as partially trusted contract objects.
|
||||||
|
|
||||||
|
The SDK retries only operations whose duplicate execution is safe: scoped reads,
|
||||||
|
idempotency-keyed registration, lease renewal with the same lease token, complete
|
||||||
|
resource update, and lease-token deregistration. It honors bounded server retry
|
||||||
|
guidance and otherwise uses capped exponential backoff with jitter. Each retry
|
||||||
|
creates a fresh HTTP request while preserving the caller's registration
|
||||||
|
idempotency key. Configuration is copied on construction so later option mutation
|
||||||
|
cannot change an in-flight client's behavior.
|
||||||
|
|
||||||
|
`PublishedSession` holds the server-issued lease and presence capabilities needed
|
||||||
|
by the host. Its string representation always redacts them. Update requests are
|
||||||
|
copied before the lease token is attached, so the SDK never mutates caller-owned
|
||||||
|
DTOs. The browser exposes one-page calls and bounded cursor traversal; cursor
|
||||||
|
values remain opaque and caller requests remain unchanged.
|
||||||
|
|
||||||
|
Lease maintenance is explicit. Creating a `SessionLeaseMaintainer` starts no task;
|
||||||
|
the game chooses when to call `RunAsync`, owns cancellation, and awaits
|
||||||
|
`DisposeAsync`. The loop uses the latest server-provided renewal interval and
|
||||||
|
returns a distinct cancelled, disposed, lost-lease, or failed result. Terminal
|
||||||
|
authorization, expiry, and missing-lease responses also raise `LeaseLost` so the
|
||||||
|
host can stop advertising or re-register deliberately.
|
||||||
|
|
||||||
|
## Consequences
|
||||||
|
|
||||||
|
- SpaceGame and Unscouted can inject the publisher/browser interfaces in tests
|
||||||
|
without an engine runtime or real network.
|
||||||
|
- Games must configure an absolute `HttpClient.BaseAddress` (or equivalent
|
||||||
|
handler routing), obtain publisher credentials from their deployment boundary,
|
||||||
|
and explicitly run and dispose lease maintenance.
|
||||||
|
- The versioned client public-API snapshot and live-server integration tests fail
|
||||||
|
together when SDK and HTTP contracts drift.
|
||||||
@@ -0,0 +1,78 @@
|
|||||||
|
# ADR 0008: scoped join attempts and one-time connection tickets
|
||||||
|
|
||||||
|
- Status: Accepted
|
||||||
|
- Date: 2026-07-16
|
||||||
|
- Tracking: #10
|
||||||
|
|
||||||
|
## Decision
|
||||||
|
|
||||||
|
Join creation is an unauthenticated public operation because v1 does not treat a
|
||||||
|
Rendezvous caller as game identity. The HTTP source address is normalized and
|
||||||
|
converted to a process-keyed opaque subject for idempotency and bounded policy
|
||||||
|
accounting; raw addresses and the derived subject are never returned or logged.
|
||||||
|
A successful request means only that this network client may try to connect to
|
||||||
|
this active session. It does not reserve capacity or grant gameplay admission.
|
||||||
|
|
||||||
|
Creation validates the v1 contract, caller idempotency key, enabled tenant policy,
|
||||||
|
exact gameplay protocol, listing scope, live lease, and fresh authenticated host
|
||||||
|
presence in one atomic store operation. A listing advertised as full remains
|
||||||
|
joinable because its player count is advisory and the game host owns the final
|
||||||
|
capacity, identity, ban, and admission decision.
|
||||||
|
|
||||||
|
Each attempt derives independent host-punch, client-punch, and connection-ticket
|
||||||
|
credentials plus opaque attempt and mediation IDs from a process-ephemeral HMAC
|
||||||
|
key, the client subject, the complete canonical request fingerprint, a fresh salt,
|
||||||
|
and a purpose/role label. Credentials are 32-byte base64url values (43 characters),
|
||||||
|
below both the 192-character Rendezvous capability ceiling and LiteNetLib's
|
||||||
|
256-character NAT token ceiling. The connection ticket uses half of that payload
|
||||||
|
for its attempt ID and half for an independently derived 128-bit authenticator, so
|
||||||
|
the SDK can correlate concurrent introductions without increasing UDP response
|
||||||
|
size. State retains keyed credential fingerprints, derivation inputs, and salt—not
|
||||||
|
issued plaintext. All diagnostic string representations redact credentials and
|
||||||
|
derivation material.
|
||||||
|
|
||||||
|
The client receives only its punch capability. A host polls its own listing with
|
||||||
|
the lease token in `X-Rendezvous-Lease-Token` and receives only host-role
|
||||||
|
capabilities through a signed, listing-bound, five-minute cursor. Replaying an
|
||||||
|
identical join request returns the same live attempt; changing the request under
|
||||||
|
the same owner/key conflicts. A client may cancel with its punch capability in
|
||||||
|
`X-Rendezvous-Client-Punch-Capability`; cancellation atomically marks the attempt
|
||||||
|
and retains a bounded tombstone until its original expiry. Host polling returns
|
||||||
|
that tombstone so a coordinator can revoke any local ticket authorization, while
|
||||||
|
endpoint binding, introduction, ticket issuance, and ticket consumption all
|
||||||
|
reject the cancelled attempt. Listing deletion, expiry, revocation, or process
|
||||||
|
restart removes every associated attempt and credential fingerprint.
|
||||||
|
|
||||||
|
Endpoint binding remains role- and capability-specific. The first endpoint
|
||||||
|
observed for a role wins atomically; an exact UDP duplicate is idempotent, while
|
||||||
|
endpoint or role substitution is rejected. An introduction is consumable once
|
||||||
|
only after both roles bind, so concurrent attempts for the same listing cannot
|
||||||
|
cross-wire.
|
||||||
|
|
||||||
|
The connection ticket is distinct from both punch capabilities and is reproduced
|
||||||
|
only after introduction succeeds. Its window begins at that moment and lasts at
|
||||||
|
most 20 seconds without outliving the 30-second attempt. The server has an atomic
|
||||||
|
fingerprint-consumption seam for mediator tests and revocation. On the game host,
|
||||||
|
the SDK's bounded `ConnectionTicketValidator` stores a process-keyed digest,
|
||||||
|
accepts an exact ticket once under a lock, rejects altered/cross-attempt/expired/
|
||||||
|
revoked/replayed tickets, and zeroes retained digests and key material on disposal.
|
||||||
|
Issue #11 carries the fixed-size ticket in the authenticated introduction. Issue
|
||||||
|
#12 extracts its embedded attempt ID, bounds the host's local authorization window
|
||||||
|
by both the host-polled attempt expiry and the configured ticket lifetime, then
|
||||||
|
wires one-time consumption into the caller-owned coordinator. Both peers receive
|
||||||
|
a digest of the exact expected ticket over HTTP and reject any syntactically valid
|
||||||
|
but unauthenticated introduction token. Embedding the ID prevents concurrent or
|
||||||
|
late introductions from cross-binding a valid ticket while preserving the
|
||||||
|
mediator's 2.0 response-byte amplification ceiling.
|
||||||
|
|
||||||
|
## Consequences
|
||||||
|
|
||||||
|
- A join attempt is transport authorization, never proof of player identity or a
|
||||||
|
game slot.
|
||||||
|
- Network-address-derived subjects are process-local abuse/idempotency scopes,
|
||||||
|
not stable user identifiers; stronger authenticated player scopes require a
|
||||||
|
future game-owned identity contract.
|
||||||
|
- Cancellation after a ticket has reached a host must also revoke that host's
|
||||||
|
local validator entry; coordinator wiring owns that race in issue #12.
|
||||||
|
- Capability and ticket plaintext never enter browser results, state snapshots,
|
||||||
|
logs, metrics, or generated string representations.
|
||||||
@@ -0,0 +1,68 @@
|
|||||||
|
# ADR 0009: authenticated bounded LiteNetLib NAT mediator
|
||||||
|
|
||||||
|
- Status: Accepted
|
||||||
|
- Date: 2026-07-16
|
||||||
|
- Tracking: #11
|
||||||
|
|
||||||
|
## Decision
|
||||||
|
|
||||||
|
The server owns one LiteNetLib `NetManager` and its `NatPunchModule` on the
|
||||||
|
configured UDP endpoint. It runs in manual mode with a configured maximum number
|
||||||
|
of datagrams per poll and a short caller-owned poll interval. LiteNetLib events
|
||||||
|
are unsynchronized so authenticated requests are processed immediately on that
|
||||||
|
single polling path rather than accumulated in an unbounded event queue. The
|
||||||
|
mediator never accepts a LiteNetLib gameplay connection or handles application
|
||||||
|
payloads.
|
||||||
|
|
||||||
|
The packet layer also consumes the frozen v1 presence envelope on the same
|
||||||
|
socket. Native NAT requests use a canonical fixed-size 192-character token that
|
||||||
|
binds a role (`HostPresence`, attempt `Host`, or attempt `Client`), mediation
|
||||||
|
handle, and the already-issued capability. Both transports enter one processor
|
||||||
|
and the same atomic store operations. No transport-supplied public address is
|
||||||
|
trusted; the socket source is authoritative.
|
||||||
|
|
||||||
|
LiteNetLib's native NAT packet family also contains introduction-response and
|
||||||
|
punch frames that are appropriate for peers but unsafe on a public mediator: a
|
||||||
|
forged response can name arbitrary destinations. The packet layer therefore
|
||||||
|
decodes only the pinned `NatIntroduceRequest` wire shape and consumes every
|
||||||
|
inbound packet before `NatPunchModule` sees it. The module is outbound-only and
|
||||||
|
may send introductions solely from a completed authorized plan.
|
||||||
|
|
||||||
|
Listing presence refreshes authorize no response. Attempt contributions bind the
|
||||||
|
first observed endpoint for exactly one capability role. Exact duplicates are
|
||||||
|
idempotent; a different endpoint, the opposite role, an expired/cancelled
|
||||||
|
attempt, or a stale listing presence cannot replace it. The introduction is
|
||||||
|
consumed atomically only after both roles bind and their observed address
|
||||||
|
families match, preventing concurrent attempts for one listing from cross-wiring.
|
||||||
|
|
||||||
|
A reported local candidate is eligible only when it is RFC 1918 IPv4 or IPv6
|
||||||
|
unique-local unicast, matches the observed family, and both peers have the same
|
||||||
|
observed public address. Otherwise `NatIntroduce` receives the observed public
|
||||||
|
endpoint in the local slot. Loopback, link-local, multicast, unspecified,
|
||||||
|
documentation IPv6, global-address claims, and cross-family claims are never
|
||||||
|
disclosed as local targets. IPv4 is required; observed global IPv6 can be used
|
||||||
|
when both peers contribute IPv6, without claiming guaranteed IPv6 NAT traversal.
|
||||||
|
|
||||||
|
The introduction carries only the distinct connection ticket and is emitted at
|
||||||
|
most once to each verified observed endpoint. The fixed authenticated native
|
||||||
|
request and bounded frozen envelope keep the combined response bytes within the
|
||||||
|
2.0 verified amplification budget; unauthenticated inputs receive zero bytes.
|
||||||
|
Malformed, truncated, oversized, spoofed, or unrelated LiteNetLib packets do not
|
||||||
|
grow Rendezvous state. Raw endpoints and credentials are never logged or exposed
|
||||||
|
through diagnostic string representations.
|
||||||
|
|
||||||
|
Frozen IPv6 listing-presence refresh remains valid because it emits no response.
|
||||||
|
IPv6 attempt roles require the fixed-size native LiteNetLib request; accepting the
|
||||||
|
short frozen envelope would exceed the 2.0 byte budget for two IPv6 introduction
|
||||||
|
frames. The required IPv4 listen address and optional IPv6 listen address are
|
||||||
|
configured separately so enabling one family never widens the other family to a
|
||||||
|
wildcard bind.
|
||||||
|
|
||||||
|
## Consequences
|
||||||
|
|
||||||
|
- Hosts refresh listing presence and answer invitations from their actual
|
||||||
|
gameplay socket; a separate mediator socket would observe the wrong mapping.
|
||||||
|
- Caller-owned SDK coordination in #12 must poll the host invitation endpoint,
|
||||||
|
send the corresponding native role token, and consume the returned ticket.
|
||||||
|
- UDP loss can prevent traversal, but it cannot cause an arbitrary destination,
|
||||||
|
replay, role substitution, or cross-attempt introduction.
|
||||||
@@ -0,0 +1,117 @@
|
|||||||
|
# ADR 0010: typed connection outcomes, deadlines, and caller-owned fallback
|
||||||
|
|
||||||
|
- Status: Accepted
|
||||||
|
- Date: 2026-07-16
|
||||||
|
- Tracking: #13
|
||||||
|
|
||||||
|
## Context
|
||||||
|
|
||||||
|
A connection can stop in the directory, authorization, mediation, NAT traversal,
|
||||||
|
or direct-connection phase. Those failures have different authorities: an HTTP
|
||||||
|
response can authoritatively reject a join, the SDK can observe a local timeout,
|
||||||
|
and only the remote host can reject a direct connection. Treating all of them as
|
||||||
|
one message or generic timeout would make player guidance, retry policy, tests,
|
||||||
|
and operational measurements unreliable.
|
||||||
|
|
||||||
|
UDP loss, service silence, cancellation, and late LiteNetLib callbacks also make
|
||||||
|
completion races unavoidable. Games need one terminal result and bounded work,
|
||||||
|
not a sequence of contradictory callbacks. Direct traversal cannot be guaranteed,
|
||||||
|
but v1 has no gameplay relay and must not imply otherwise.
|
||||||
|
|
||||||
|
## Decision
|
||||||
|
|
||||||
|
### Closed typed outcome model
|
||||||
|
|
||||||
|
`ConnectionOutcomeKind` is the stable wire-level terminal set: connected,
|
||||||
|
cancelled, directory not found, attempt expired, incompatible protocol,
|
||||||
|
unauthorized, rate limited, no host presence, service unavailable or rejected,
|
||||||
|
mediator unavailable, punch timeout, direct-connect timeout, host rejection,
|
||||||
|
transport error, manager stopped, and disposed.
|
||||||
|
|
||||||
|
The already-frozen v1 members `TimedOut`, `StaleHost`, `TransportFailed`, and
|
||||||
|
`FallbackOffered` retain their original numeric values for source and wire
|
||||||
|
compatibility. New SDK code never emits them. The report service accepts them,
|
||||||
|
normalizes the first three to their precise modern equivalents, and does not let
|
||||||
|
legacy compatibility weaken the typed coordinator result.
|
||||||
|
|
||||||
|
The client adds `RendezvousConnectionOutcomeSource`, failure category, and phase.
|
||||||
|
These fields preserve authority instead of guessing from text:
|
||||||
|
|
||||||
|
- `RendezvousService` is used only for an HTTP decision or bounded service
|
||||||
|
silence. Its optional `ServiceError` retains the stable service error code.
|
||||||
|
- `LocalTraversal` reports local punch, direct-connect, and transport
|
||||||
|
observations.
|
||||||
|
- `RemoteHost` reports an explicit direct-connection rejection.
|
||||||
|
- `Caller` and `Lifecycle` distinguish cancellation from manager shutdown or
|
||||||
|
disposal.
|
||||||
|
|
||||||
|
Messages remain diagnostic and are never parsed into outcomes. A successful NAT
|
||||||
|
introduction is only a transition to direct connection; `Connected` is emitted
|
||||||
|
only after LiteNetLib reports the authenticated peer connected.
|
||||||
|
|
||||||
|
Join issuance is exposed as `RendezvousConnectionStartResult`, containing exactly
|
||||||
|
one issued attempt or one terminal service outcome. Once an attempt is issued,
|
||||||
|
the coordinator owns its local terminal outcome. Completion is exactly once;
|
||||||
|
terminal paths release SDK subscriptions so late introductions, peer callbacks,
|
||||||
|
network errors, cancellation, and polling are inert.
|
||||||
|
|
||||||
|
### Bounded phases and retries
|
||||||
|
|
||||||
|
Each HTTP try has a five-second default silence budget, configurable from above
|
||||||
|
zero through thirty seconds. Only safe operations use the existing bounded retry
|
||||||
|
policy, honoring caller cancellation and server retry guidance. Exhausting that
|
||||||
|
budget returns `ServiceUnavailable`; it never waits indefinitely.
|
||||||
|
|
||||||
|
Traversal has independent defaults: ten seconds for punch/mediation and five
|
||||||
|
seconds for the direct connection. Both are configurable up to thirty seconds.
|
||||||
|
Local budgets, retry schedules, and elapsed duration use monotonic time, so a
|
||||||
|
wall-clock correction cannot extend them or produce a negative duration. The
|
||||||
|
signed attempt expiry is converted to an additional monotonic upper bound when
|
||||||
|
the attempt is received. Punch retries retain
|
||||||
|
their bounded request count and exponential backoff; crossing a phase deadline
|
||||||
|
completes exactly once even if a delayed packet later arrives. Tests use an
|
||||||
|
injected clock and do not depend on wall-clock sleeps.
|
||||||
|
|
||||||
|
### Explicit dedicated fallback handoff
|
||||||
|
|
||||||
|
A publisher may attach one validated dedicated endpoint to registration or
|
||||||
|
update only when the tenant's provisioned fallback policy allows it. The server
|
||||||
|
copies that endpoint into browser and issued-attempt contracts.
|
||||||
|
The client coordinator defensively copies it into every terminal outcome; a game
|
||||||
|
may override it locally through `DedicatedFallbackOverride`.
|
||||||
|
|
||||||
|
The SDK never opens, dials, reserves, probes, or authenticates the fallback. The
|
||||||
|
game decides whether the outcome permits fallback, presents any player choice,
|
||||||
|
and connects through its own gameplay transport and admission rules. Absence of
|
||||||
|
an endpoint is an honest no-fallback result. Gameplay relay is absent from v1.
|
||||||
|
|
||||||
|
### Privacy-safe optional reporting
|
||||||
|
|
||||||
|
After an issued attempt completes, the game may explicitly report its outcome
|
||||||
|
with the short-lived client punch capability. Reporting is authenticated and
|
||||||
|
idempotent: an exact repeat succeeds as a duplicate, while a conflicting repeat
|
||||||
|
is rejected. Reports contain only an allowlisted outcome enum and one coarse
|
||||||
|
elapsed bucket (`<1s`, `1–5s`, `5–15s`, `15–30s`, or `30s+`). They contain no
|
||||||
|
diagnostic message, exact duration, endpoint, metadata, player identifier, or
|
||||||
|
credential.
|
||||||
|
|
||||||
|
Frozen v1 DTOs still expose `elapsedMilliseconds` and `diagnosticCode`. They are
|
||||||
|
deprecated compatibility inputs: the current SDK omits them, the service
|
||||||
|
immediately buckets legacy elapsed time, and neither exact timing nor diagnostic
|
||||||
|
text is retained, logged, or used as a metric dimension.
|
||||||
|
|
||||||
|
The store retains a bounded capability-fingerprint tombstone long enough to
|
||||||
|
accept a report after the live attempt expires. Metrics count the first accepted
|
||||||
|
outcome only and use only outcome plus elapsed bucket as dimensions. Service
|
||||||
|
issuance failures cannot be reported because no attempt capability was issued.
|
||||||
|
|
||||||
|
## Consequences
|
||||||
|
|
||||||
|
- Player-facing UI can map stable outcome/category pairs to localized guidance
|
||||||
|
without exposing diagnostic strings.
|
||||||
|
- Service rejection, remote-host rejection, and local observation remain
|
||||||
|
distinguishable for retry and support decisions.
|
||||||
|
- Games own fallback policy and gameplay admission; Rendezvous does not claim a
|
||||||
|
guaranteed connection path.
|
||||||
|
- Outcome additions are contract changes and require OpenAPI, serialization,
|
||||||
|
public API, fake-clock, late-event, and idempotency coverage.
|
||||||
@@ -6,8 +6,17 @@ decision requires a superseding ADR and corresponding contract/test updates.
|
|||||||
- [ADR 0001: v1 control-plane boundaries and domain](0001-v1-control-plane-boundaries.md)
|
- [ADR 0001: v1 control-plane boundaries and domain](0001-v1-control-plane-boundaries.md)
|
||||||
- [ADR 0002: publisher trust, discovery, compatibility, and fallback](0002-publisher-trust-and-connection-policy.md)
|
- [ADR 0002: publisher trust, discovery, compatibility, and fallback](0002-publisher-trust-and-connection-policy.md)
|
||||||
- [ADR 0003: state, privacy, availability, and safety budgets](0003-state-privacy-availability-and-budgets.md)
|
- [ADR 0003: state, privacy, availability, and safety budgets](0003-state-privacy-availability-and-budgets.md)
|
||||||
|
- [ADR 0004: atomic ephemeral state and single-active availability](0004-atomic-ephemeral-state.md)
|
||||||
|
- [ADR 0005: authenticated session lease and presence lifecycle](0005-session-lease-lifecycle.md)
|
||||||
|
- [ADR 0006: bounded compatible session browser](0006-compatible-session-browser.md)
|
||||||
|
- [ADR 0007: caller-owned .NET publisher and browser SDK](0007-caller-owned-dotnet-client-sdk.md)
|
||||||
|
- [ADR 0008: scoped join attempts and one-time connection tickets](0008-scoped-join-attempts-and-tickets.md)
|
||||||
|
- [ADR 0009: authenticated bounded LiteNetLib NAT mediator](0009-authenticated-litenet-nat-mediator.md)
|
||||||
|
- [ADR 0010: typed connection outcomes, deadlines, and caller-owned fallback](0010-typed-connection-outcomes-and-fallback.md)
|
||||||
- [Threat model](../security/threat-model.md)
|
- [Threat model](../security/threat-model.md)
|
||||||
- [Security promise and test matrix](../security/control-matrix.md)
|
- [Security promise and test matrix](../security/control-matrix.md)
|
||||||
|
- [Versioned HTTP and UDP contracts](../contracts/README.md)
|
||||||
|
- [Game provisioning and signing-key lifecycle](../security/provisioning.md)
|
||||||
|
|
||||||
These decisions intentionally leave gameplay authority, player identity,
|
These decisions intentionally leave gameplay authority, player identity,
|
||||||
simulation, persistence, social features, skill matchmaking, and gameplay
|
simulation, persistence, social features, skill matchmaking, and gameplay
|
||||||
|
|||||||
@@ -11,11 +11,13 @@ FinalFactory.Rendezvous.Server FinalFactory.Rendezvous.TestClient
|
|||||||
|
|
||||||
- `Contracts` targets `netstandard2.1` and contains only versioned,
|
- `Contracts` targets `netstandard2.1` and contains only versioned,
|
||||||
transport-neutral IDs and wire contracts. It cannot reference Server,
|
transport-neutral IDs and wire contracts. It cannot reference Server,
|
||||||
LiteNetLib, or Godot.
|
LiteNetLib, or Godot. Its only package is `System.Text.Json`, used for the
|
||||||
|
canonical cross-runtime JSON contract.
|
||||||
- `Client` targets `netstandard2.1`, references Contracts and the pinned
|
- `Client` targets `netstandard2.1`, references Contracts and the pinned
|
||||||
LiteNetLib package, and contains no Godot or Server dependency.
|
LiteNetLib package, and contains no Godot or Server dependency.
|
||||||
- `Server` targets .NET 10 LTS, references Contracts and LiteNetLib, and owns
|
- `Server` targets .NET 10 LTS, references Contracts, LiteNetLib, and the
|
||||||
HTTP hosting, UDP mediation, application policy, and ephemeral state.
|
first-party ASP.NET Core OpenAPI generator, and owns HTTP hosting, UDP
|
||||||
|
mediation, application policy, and ephemeral state.
|
||||||
- `TestClient` targets .NET 8, references only the public Client/Contracts seams
|
- `TestClient` targets .NET 8, references only the public Client/Contracts seams
|
||||||
and LiteNetLib, and must never reach into Server internals.
|
and LiteNetLib, and must never reach into Server internals.
|
||||||
- `Tests` target .NET 10 and may reference every project solely to verify public
|
- `Tests` target .NET 10 and may reference every project solely to verify public
|
||||||
@@ -32,6 +34,8 @@ engine, transport, or server dependency therefore fails the normal test gate.
|
|||||||
.NET 8-or-later runtime used by current Godot 4 C# projects.
|
.NET 8-or-later runtime used by current Godot 4 C# projects.
|
||||||
- TestClient runtime: .NET 8.
|
- TestClient runtime: .NET 8.
|
||||||
- LiteNetLib: 2.1.4, pinned centrally and restored from the lock files.
|
- LiteNetLib: 2.1.4, pinned centrally and restored from the lock files.
|
||||||
|
- Microsoft.OpenApi: patched 2.7.5 line, centrally pinned because the version
|
||||||
|
originally pulled by the .NET 10 generator is affected by CVE-2026-49451.
|
||||||
|
|
||||||
The repository uses central package versions, per-project lock files,
|
The repository uses central package versions, per-project lock files,
|
||||||
deterministic compilation, nullable reference types, warnings as errors, current
|
deterministic compilation, nullable reference types, warnings as errors, current
|
||||||
@@ -43,3 +47,5 @@ Primary compatibility references:
|
|||||||
- [.NET support policy](https://dotnet.microsoft.com/en-us/platform/support/policy)
|
- [.NET support policy](https://dotnet.microsoft.com/en-us/platform/support/policy)
|
||||||
- [Godot stable C# prerequisites](https://docs.godotengine.org/en/stable/tutorials/scripting/c_sharp/c_sharp_basics.html)
|
- [Godot stable C# prerequisites](https://docs.godotengine.org/en/stable/tutorials/scripting/c_sharp/c_sharp_basics.html)
|
||||||
- [LiteNetLib 2.1.4 on NuGet](https://www.nuget.org/packages/LiteNetLib/2.1.4)
|
- [LiteNetLib 2.1.4 on NuGet](https://www.nuget.org/packages/LiteNetLib/2.1.4)
|
||||||
|
- [ASP.NET Core OpenAPI generation](https://learn.microsoft.com/en-us/aspnet/core/fundamentals/openapi/overview?view=aspnetcore-10.0)
|
||||||
|
- [Microsoft.OpenApi security advisory](https://github.com/advisories/GHSA-v5pm-xwqc-g5wc)
|
||||||
|
|||||||
@@ -0,0 +1,18 @@
|
|||||||
|
# Versioned contracts
|
||||||
|
|
||||||
|
Tracking: #4
|
||||||
|
|
||||||
|
The v1 contract is defined by three artifacts that are reviewed and versioned
|
||||||
|
together:
|
||||||
|
|
||||||
|
- [HTTP v1 semantics](http-v1.md)
|
||||||
|
- [UDP v1 wire format](udp-v1.md)
|
||||||
|
- [Generated OpenAPI 3.1 document](../api/rendezvous-v1.json)
|
||||||
|
|
||||||
|
The public .NET types live in `FinalFactory.Rendezvous.Contracts`, target
|
||||||
|
`netstandard2.1`, and contain no Server, Godot, or LiteNetLib dependency. Golden
|
||||||
|
vectors and a public-API snapshot make accidental wire or source compatibility
|
||||||
|
changes fail the normal test gate.
|
||||||
|
|
||||||
|
Any incompatible change requires a new contract version. Additive JSON fields
|
||||||
|
may be introduced within v1 because v1 readers ignore unknown object members.
|
||||||
@@ -0,0 +1,127 @@
|
|||||||
|
# HTTP contract v1
|
||||||
|
|
||||||
|
Tracking: #4
|
||||||
|
|
||||||
|
All production endpoints require HTTPS. JSON uses UTF-8, camel-case property
|
||||||
|
names, compact output, string-valued camel-case enums, and ISO 8601 timestamps.
|
||||||
|
Every request that contains a body carries `contractVersion: 1`; browse carries
|
||||||
|
the same value as a required query parameter.
|
||||||
|
|
||||||
|
## Compatibility and parsing
|
||||||
|
|
||||||
|
- Contract version matching is exact. Any value other than `1` fails with
|
||||||
|
`unsupportedContractVersion`; it is never guessed or downgraded.
|
||||||
|
- Gameplay protocol matching is exact. `buildVersion` is display and diagnostic
|
||||||
|
text only and never decides compatibility.
|
||||||
|
- Unknown JSON object properties are ignored so additive v1 responses remain
|
||||||
|
readable. Unknown enum names, numeric enum values, comments, trailing commas,
|
||||||
|
invalid identifier strings, and excessive nesting are rejected.
|
||||||
|
- Game, environment, and region IDs are lowercase URL-safe slugs. Listing,
|
||||||
|
lease, join-attempt, and mediation IDs are non-empty UUIDs serialized as JSON
|
||||||
|
strings.
|
||||||
|
- Clients must honor request cancellation. A disconnected or cancelled request
|
||||||
|
does not promise a response body; the server should stop work where safe.
|
||||||
|
|
||||||
|
## Endpoints
|
||||||
|
|
||||||
|
| Method | Path | Purpose |
|
||||||
|
| --- | --- | --- |
|
||||||
|
| `POST` | `/v1/sessions` | Register a session and create its renewable lease. |
|
||||||
|
| `POST` | `/v1/sessions/{listingId}/renew` | Renew the listing lease. |
|
||||||
|
| `PUT` | `/v1/sessions/{listingId}` | Replace mutable browser fields and capacity. |
|
||||||
|
| `DELETE` | `/v1/sessions/{listingId}` | Withdraw a listing. |
|
||||||
|
| `GET` | `/v1/sessions` | Browse compatible public sessions. |
|
||||||
|
| `GET` | `/v1/sessions/{listingId}` | Resolve a public or explicitly shared unlisted listing. |
|
||||||
|
| `POST` | `/v1/join-attempts` | Authorize and create a short-lived join attempt. |
|
||||||
|
| `DELETE` | `/v1/join-attempts/{attemptId}` | Cancel an attempt using its client punch capability. |
|
||||||
|
| `GET` | `/v1/sessions/{listingId}/join-attempts` | Let an authenticated host poll pending attempts. |
|
||||||
|
| `POST` | `/v1/join-attempts/{attemptId}/outcome` | Report a bounded connection outcome. |
|
||||||
|
| `GET` | `/health/live` | Report that the HTTP process is alive. |
|
||||||
|
| `GET` | `/health/ready` | Report whether the UDP mediator is bound and ready. |
|
||||||
|
|
||||||
|
The generated [OpenAPI document](../api/rendezvous-v1.json) is the normative
|
||||||
|
shape reference for parameters, bodies, and responses.
|
||||||
|
|
||||||
|
Host polling sends its reusable lease credential in
|
||||||
|
`X-Rendezvous-Lease-Token`; it must never be placed in a URL. Lease credentials
|
||||||
|
for mutation operations are carried in their request bodies. Public browser
|
||||||
|
responses contain no IP endpoints, lease tokens, punch capabilities, connection
|
||||||
|
tickets, player identifiers, or gameplay state.
|
||||||
|
|
||||||
|
Attempt cancellation sends the short-lived client punch capability in
|
||||||
|
`X-Rendezvous-Client-Punch-Capability`. Join creation uses the observed HTTP
|
||||||
|
source only for a process-keyed, short-lived idempotency/abuse scope; this is not
|
||||||
|
player authentication and is never returned to callers.
|
||||||
|
|
||||||
|
Outcome reporting uses that same short-lived capability. It accepts only outcomes
|
||||||
|
for an issued attempt and carries one stable outcome enum plus one coarse elapsed
|
||||||
|
bucket. Exact duplicate reports are idempotent; conflicting repeats fail. Reports
|
||||||
|
never carry exact timing, diagnostics, endpoints, metadata, player identifiers,
|
||||||
|
or credentials.
|
||||||
|
|
||||||
|
The frozen v1 .NET request also retains deprecated `elapsedMilliseconds` and
|
||||||
|
`diagnosticCode` properties for source/wire compatibility. Current clients omit
|
||||||
|
them. If a legacy client supplies them, the server immediately converts elapsed
|
||||||
|
milliseconds to the coarse bucket and discards diagnostic text; neither value is
|
||||||
|
retained or used as a metric dimension.
|
||||||
|
|
||||||
|
Registration and update may include one validated `dedicatedFallback`. The
|
||||||
|
endpoint must be enabled by the tenant's provisioned fallback policy, is visible
|
||||||
|
browser data, and is copied into subsequently issued attempts.
|
||||||
|
It is a handoff for caller-owned policy: neither the HTTP service nor the SDK
|
||||||
|
automatically connects to it. V1 provides no gameplay relay.
|
||||||
|
|
||||||
|
## Idempotency, cursors, and retries
|
||||||
|
|
||||||
|
Registration and join creation require a caller-generated visible-ASCII
|
||||||
|
`idempotencyKey`. A repeat in the same authorization scope returns the original
|
||||||
|
result while the key is retained; reusing a key with a different payload fails
|
||||||
|
with `conflict`. Keys are opaque and must not contain credentials.
|
||||||
|
|
||||||
|
Cursors are opaque, endpoint-specific, short-lived values. A client may echo a
|
||||||
|
cursor only to the endpoint and filters that produced it. Invalid or expired
|
||||||
|
cursors fail with `invalidRequest`; clients restart browsing from the first page.
|
||||||
|
Renew, update, delete, and outcome reporting are safe to retry with the same
|
||||||
|
lease/attempt identity after a transport-level failure.
|
||||||
|
|
||||||
|
## Limits
|
||||||
|
|
||||||
|
Limits are measured after UTF-8 encoding where stated. Servers reject the
|
||||||
|
entire request rather than truncate values.
|
||||||
|
|
||||||
|
| Item | v1 limit |
|
||||||
|
| --- | ---: |
|
||||||
|
| HTTP request body | 16 KiB |
|
||||||
|
| Browser response body | 256 KiB |
|
||||||
|
| Browser page | 100 listings |
|
||||||
|
| Metadata document | 4 KiB, 32 keys |
|
||||||
|
| Metadata key / value | 64 / 256 UTF-8 bytes |
|
||||||
|
| Game / environment / region ID | 64 / 32 / 32 characters |
|
||||||
|
| Display name / build version | 128 / 64 UTF-8 bytes |
|
||||||
|
| Idempotency key | 64 visible ASCII characters |
|
||||||
|
| Cursor | 512 visible ASCII characters |
|
||||||
|
| Diagnostic code | 64 visible ASCII characters |
|
||||||
|
| Error message | 256 UTF-8 bytes |
|
||||||
|
| Reusable HTTP credential | 1,024 characters |
|
||||||
|
| Session capacity | 1–10,000 players |
|
||||||
|
|
||||||
|
## Error mapping
|
||||||
|
|
||||||
|
Errors use `ApiError` with a stable `code`, bounded safe `message`, optional
|
||||||
|
`correlationId`, and optional `retryAfterSeconds`. Messages are diagnostic and
|
||||||
|
must not be parsed. Secrets and raw credentials are never echoed.
|
||||||
|
|
||||||
|
| HTTP | Codes |
|
||||||
|
| ---: | --- |
|
||||||
|
| 400 | `invalidRequest`, `unsupportedContractVersion` |
|
||||||
|
| 401 | `authenticationRequired` |
|
||||||
|
| 403 | `forbidden` |
|
||||||
|
| 404 | `notFound` |
|
||||||
|
| 409 | `conflict`, `incompatibleProtocol`, `replayRejected` |
|
||||||
|
| 410 | `expired`, `staleHost` |
|
||||||
|
| 429 | `rateLimited`, `capacityExceeded` (with retry guidance when known) |
|
||||||
|
| 503 | `serviceUnavailable` (with retry guidance when known) |
|
||||||
|
| 500 | `internalError` |
|
||||||
|
|
||||||
|
Malformed input must receive the same bounded error family regardless of which
|
||||||
|
parser or validation stage rejected it.
|
||||||
@@ -0,0 +1,96 @@
|
|||||||
|
# UDP presence and NAT-punch contract v1
|
||||||
|
|
||||||
|
Tracking: #4, #11
|
||||||
|
|
||||||
|
The UDP mediator accepts the frozen bounded presence envelope below and native
|
||||||
|
LiteNetLib NAT-introduction requests. Both forms associate an authenticated
|
||||||
|
mediation handle with the packet's observed public source endpoint and the
|
||||||
|
sender's reported local endpoint. Neither form carries gameplay packets.
|
||||||
|
|
||||||
|
All multi-byte integers use network byte order. UUID bytes use the canonical
|
||||||
|
RFC 4122 textual order (the byte pairs from the 32 hexadecimal digits), not the
|
||||||
|
mixed-endian layout returned by `Guid.ToByteArray()`.
|
||||||
|
|
||||||
|
## Datagram layout
|
||||||
|
|
||||||
|
| Offset | Size | Field |
|
||||||
|
| ---: | ---: | --- |
|
||||||
|
| 0 | 2 | Magic bytes `52 56` (`RV`). |
|
||||||
|
| 2 | 1 | Contract version, exactly `01`. |
|
||||||
|
| 3 | 1 | Message type: host presence `01`, client presence `02`. |
|
||||||
|
| 4 | 1 | Flags, exactly `00` in v1. |
|
||||||
|
| 5 | 16 | Non-empty mediation-handle UUID. |
|
||||||
|
| 21 | 1 | Address family: IPv4 `04`, IPv6 `06`. |
|
||||||
|
| 22 | 1 | Address length: `04` for IPv4, `10` for IPv6. |
|
||||||
|
| 23 | 4 or 16 | Raw local IP address bytes. |
|
||||||
|
| next | 2 | Local UDP port, 1–65535. |
|
||||||
|
| next | 1 | Capability length, 1–192. |
|
||||||
|
| next | variable | ASCII base64url capability, without padding. |
|
||||||
|
|
||||||
|
No trailing bytes are permitted. The whole datagram is limited to 1,200 bytes,
|
||||||
|
well below common Internet path MTUs. The v1 capability limit is 192 characters,
|
||||||
|
which also keeps any value passed through LiteNetLib's 256-character NAT token
|
||||||
|
surface safely below that library boundary.
|
||||||
|
|
||||||
|
## Validation and failure behavior
|
||||||
|
|
||||||
|
Decoders return one stable failure category: oversized, truncated, invalid
|
||||||
|
magic, unsupported version, unknown message type, non-zero flags, invalid
|
||||||
|
handle, invalid address family, invalid address, invalid port, invalid
|
||||||
|
capability, or trailing data. Unknown versions and message types are rejected;
|
||||||
|
they are never interpreted as v1.
|
||||||
|
|
||||||
|
The address-family byte, encoded address length, and parsed address must agree.
|
||||||
|
The service derives the public endpoint from the UDP packet source and never
|
||||||
|
trusts a client-supplied public address. Reported local endpoints are candidates
|
||||||
|
only and grant no authority.
|
||||||
|
|
||||||
|
Capabilities are short-lived, single-purpose, scoped to one mediation handle,
|
||||||
|
and compared without exposing them in logs. A valid-looking packet does not
|
||||||
|
prove authorization until the capability is checked. Invalid packets receive
|
||||||
|
no UDP response, preventing the mediator from becoming an amplification oracle.
|
||||||
|
For the frozen envelope, `HostPresence` is resolved against either the listing's
|
||||||
|
host-presence capability or an attempt's host-role capability. `ClientPresence`
|
||||||
|
is resolved only against the attempt's client-role capability. Handles are
|
||||||
|
globally distinct in the active store, so this does not permit role confusion.
|
||||||
|
|
||||||
|
## Native LiteNetLib request token
|
||||||
|
|
||||||
|
A game using LiteNetLib sends `NatPunchModule.SendNatIntroduceRequest` from its
|
||||||
|
gameplay `NetManager`. The `additionalInfo` value is produced by
|
||||||
|
`NatPunchRequestTokenCodec` and is exactly 192 ASCII characters:
|
||||||
|
|
||||||
|
```text
|
||||||
|
rv1:<role>:<32 lowercase handle hex>:<43-character capability><dot padding>
|
||||||
|
```
|
||||||
|
|
||||||
|
`role` is `p` for listing host-presence refresh, `h` for the host side of a join
|
||||||
|
attempt, or `c` for its client side. Padding is canonical and leaves the token
|
||||||
|
below LiteNetLib's 256-character ceiling. Its fixed size also ensures that the
|
||||||
|
two authenticated introduction responses remain within the 2.0 response-byte
|
||||||
|
budget. Tokens with a wrong length, role, handle, capability, or padding receive
|
||||||
|
no response.
|
||||||
|
|
||||||
|
The mediator runs LiteNetLib in bounded manual-poll mode. Its packet layer admits
|
||||||
|
only the pinned native `NatIntroduceRequest` frame, consumes every inbound frame
|
||||||
|
before LiteNetLib can act on it, and uses `NatPunchModule` only to emit authorized
|
||||||
|
introductions. Native and frozen v1 inputs reach the same atomic role/capability
|
||||||
|
checks. Only the packet source is
|
||||||
|
used as the public endpoint. A claimed private candidate is retained only when
|
||||||
|
it is private unicast, matches the observed address family, and both authorized
|
||||||
|
peers were observed behind the same public address; otherwise the observed
|
||||||
|
public endpoint is substituted. IPv4 punching is required. IPv6 sources must be
|
||||||
|
observed global unicast and both roles must use IPv6; IPv6 NAT traversal remains
|
||||||
|
best-effort rather than a v1 release requirement.
|
||||||
|
|
||||||
|
The second valid contribution atomically consumes the introduction and starts
|
||||||
|
the connection-ticket lifetime. `NatIntroduce` is called once with the distinct
|
||||||
|
43-character connection ticket. Reordered and exact duplicate requests are
|
||||||
|
idempotent. Endpoint substitution, cross-role use, stale host presence, expired
|
||||||
|
or cancelled attempts, malformed packets, and gameplay payloads produce no
|
||||||
|
introduction and create no mediator queue or endpoint state.
|
||||||
|
|
||||||
|
Frozen envelopes may refresh listing presence over IPv6 because that operation
|
||||||
|
has no response. IPv6 attempt contributions must use the fixed-size native token;
|
||||||
|
the shorter frozen IPv6 envelope cannot fund two IPv6 introduction frames within
|
||||||
|
the 2.0 response-byte ceiling and is therefore dropped without response.
|
||||||
@@ -0,0 +1,97 @@
|
|||||||
|
# Diagnostic TestClient integration guide
|
||||||
|
|
||||||
|
Tracking: #25
|
||||||
|
|
||||||
|
`FinalFactory.Rendezvous.TestClient` is the smallest supported public-SDK consumer.
|
||||||
|
It exists for integration development, CI smoke checks, deployment verification,
|
||||||
|
and operator diagnosis. It is intentionally not a production game client, game
|
||||||
|
server, matchmaking UI, or relay.
|
||||||
|
|
||||||
|
The automated scenario matrix, privileged Linux namespace run, and topology
|
||||||
|
limitations are documented in the [deterministic topology harness](topology-harness.md).
|
||||||
|
|
||||||
|
## Prerequisites
|
||||||
|
|
||||||
|
Start a configured Rendezvous service and note both its HTTP base URL and UDP
|
||||||
|
mediator endpoint. The host needs a tenant-scoped publisher credential from the
|
||||||
|
deployment secret boundary. Put it in an environment variable and pass only that
|
||||||
|
variable's name when the default is unsuitable:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
export RENDEZVOUS_PUBLISHER_CREDENTIAL='<deployment-supplied value>'
|
||||||
|
```
|
||||||
|
|
||||||
|
Never put the credential in a command argument, URL, checked-in configuration,
|
||||||
|
shell trace, or captured test fixture. The development server's signing material
|
||||||
|
is process-ephemeral; credentials from a prior development process are invalid.
|
||||||
|
|
||||||
|
## Manual three-terminal flow
|
||||||
|
|
||||||
|
Start the host:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
dotnet run --project src/FinalFactory.Rendezvous.TestClient -- \
|
||||||
|
host --service http://127.0.0.1:5000/ --mediator 127.0.0.1:9050 \
|
||||||
|
--game space-game --environment development --region local --protocol 1
|
||||||
|
```
|
||||||
|
|
||||||
|
Browse from another terminal:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
dotnet run --project src/FinalFactory.Rendezvous.TestClient -- \
|
||||||
|
browse --service http://127.0.0.1:5000/ \
|
||||||
|
--game space-game --environment development --region local --protocol 1
|
||||||
|
```
|
||||||
|
|
||||||
|
Join from a third terminal. Omit `--listing` for an interactive choice:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
dotnet run --project src/FinalFactory.Rendezvous.TestClient -- \
|
||||||
|
join --service http://127.0.0.1:5000/ --mediator 127.0.0.1:9050 \
|
||||||
|
--game space-game --environment development --region local --protocol 1 \
|
||||||
|
--listing 00000000-0000-0000-0000-000000000000
|
||||||
|
```
|
||||||
|
|
||||||
|
Replace the sample UUID with the public listing ID printed by host or browse.
|
||||||
|
Host and join each create one caller-owned LiteNetLib manager. That same socket
|
||||||
|
sends presence/punch traffic, establishes the authenticated direct connection,
|
||||||
|
and carries the ping/echo/ack/completion payload. The final completion confirms
|
||||||
|
that the host received the reliable acknowledgement; none of this traffic passes through the HTTP
|
||||||
|
service or UDP mediator.
|
||||||
|
|
||||||
|
## CI and deployment smoke flow
|
||||||
|
|
||||||
|
Use `--script --json`, set `--listing` when deterministic selection matters, and
|
||||||
|
check the documented process exit code. `--timeout-seconds` bounds each startup,
|
||||||
|
traversal, or direct-traffic stage; a script host also uses it as its total runtime
|
||||||
|
unless `--run-seconds` is explicit. A host can add `--exit-after-echo` so it
|
||||||
|
terminates after the joining peer acknowledges direct traffic and receives the
|
||||||
|
host's completion confirmation. Every wait is
|
||||||
|
bounded by coordinator state and `--timeout-seconds`; no orchestration should use
|
||||||
|
an unbounded sleep.
|
||||||
|
|
||||||
|
The normal test suite contains a real process gate that starts the built Server,
|
||||||
|
host TestClient, and join TestClient, waits for readiness and versioned events,
|
||||||
|
and verifies direct traffic, cleanup, JSON shape, and secret canaries. Process
|
||||||
|
trees are force-terminated in the test cleanup path if normal shutdown fails.
|
||||||
|
|
||||||
|
Useful success events are:
|
||||||
|
|
||||||
|
- `host.registered`, `host.ready`, `host.direct-traffic`, and `host.deregistered`;
|
||||||
|
- `browse.completed` and `browse.session`; and
|
||||||
|
- `join.connected`, `join.direct-traffic`, and `join.outcome-report`.
|
||||||
|
|
||||||
|
Failure events preserve stable typed phases and outcomes. When a terminal outcome
|
||||||
|
contains a configured dedicated endpoint, `join.fallback` reports `available`
|
||||||
|
with endpoint type `dedicated`; no raw address is printed and no fallback is
|
||||||
|
started implicitly.
|
||||||
|
|
||||||
|
## What the proof does and does not establish
|
||||||
|
|
||||||
|
The deterministic loopback test proves the complete service/host/client protocol,
|
||||||
|
ticket admission, and peer-to-peer payload path. Loopback is not evidence that all
|
||||||
|
consumer routers, carrier-grade NATs, symmetric NATs, firewalls, VPNs, IPv6 paths,
|
||||||
|
or platform policies permit hole punching. Same-LAN, separated observed endpoints,
|
||||||
|
network namespaces/containers, mediator restart, and adverse topology coverage
|
||||||
|
belong to the topology harness tracked by #14. Production rollout still requires
|
||||||
|
tests from representative networks and a game-owned fallback policy.
|
||||||
@@ -0,0 +1,91 @@
|
|||||||
|
# Deterministic topology harness
|
||||||
|
|
||||||
|
Issue #14 is verified at three layers. The layers are deliberately separate so
|
||||||
|
the always-on gate remains deterministic while privileged CI workers can add a
|
||||||
|
stronger operating-system topology without overstating what local emulation
|
||||||
|
proves about the public Internet.
|
||||||
|
|
||||||
|
## Always-on public-process gate
|
||||||
|
|
||||||
|
`TestClientProcessIntegrationTests` launches the built server and the same
|
||||||
|
`FinalFactory.Rendezvous.TestClient` executable shipped to operators. Every
|
||||||
|
child process uses `--script --json`, dynamic HTTP and UDP ports, bounded
|
||||||
|
state-driven waits, and enforced process-tree cleanup.
|
||||||
|
|
||||||
|
The suite proves:
|
||||||
|
|
||||||
|
| Scenario | Required observation |
|
||||||
|
| --- | --- |
|
||||||
|
| Three-party happy path | register, presence-ready, browse, authorize, punch, authenticated LiteNetLib connection, direct ping/echo/ack/completion traffic, outcome report, disconnect, deregister |
|
||||||
|
| Same-LAN candidate | the connected peer is reported as `loopback` or `private`, never inferred merely from an introduction callback |
|
||||||
|
| Empty and missing selection | browse exits `11`; exact missing lookup exits `10` |
|
||||||
|
| Wrong tenant/protocol | no listing is returned for an incompatible protocol; exact joins with either mismatch fail before `join.punch` |
|
||||||
|
| Traversal timeout | an unreachable mediator produces typed `PunchTimedOut`, exits `12`, advertises the configured dedicated fallback, and never connects to it |
|
||||||
|
| Caller cancellation | POSIX `SIGINT` exits `130`, deregisters the listing, and removes it from public lookup |
|
||||||
|
| Abrupt host loss | the listing disappears after the presence window and before its lease expires; public exact lookup intentionally reports `NotFound` |
|
||||||
|
| Bounded host without a peer | exits `13` and still deregisters |
|
||||||
|
|
||||||
|
Captured output is parsed as the stable JSON v1 event schema. Publisher
|
||||||
|
credentials and signing-key material are checked against all captured output.
|
||||||
|
The direct traffic payload is handled only by the caller-owned host and client
|
||||||
|
LiteNetLib managers; the HTTP service and mediator do not implement or observe
|
||||||
|
the echo protocol.
|
||||||
|
|
||||||
|
Run the always-on scenarios with:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
dotnet test Rendezvous.slnx --configuration Release --no-build \
|
||||||
|
--filter FullyQualifiedName~TestClientProcessIntegrationTests
|
||||||
|
```
|
||||||
|
|
||||||
|
## Deterministic protocol and adverse-state gate
|
||||||
|
|
||||||
|
The following real service-boundary tests cover conditions that a public CLI
|
||||||
|
cannot safely manufacture by accepting raw capabilities or tickets:
|
||||||
|
|
||||||
|
| Scenario | Test evidence |
|
||||||
|
| --- | --- |
|
||||||
|
| Same-NAT private candidates | `NatMediationProcessorTests.MatchedPeersReceiveOneIntroductionAndSameNatPrivateCandidates` |
|
||||||
|
| Separate observed endpoints | `NatMediationProcessorTests.DifferentNatsAndInvalidLocalClaimsExposeOnlyObservedPublicEndpoints` |
|
||||||
|
| One-time introduction and replay | `InMemoryEphemeralRendezvousStoreTests.AttemptCapabilitiesAndIntroductionAreOneTime` |
|
||||||
|
| Direct ticket replay | `RendezvousCoordinatorIntegrationTests.CallerOwnedManagersCompleteAuthenticatedDirectConnectionAndRejectTicketReplay` |
|
||||||
|
| Wrong tenant/protocol and stale presence | `InMemoryEphemeralRendezvousStoreTests.JoinRequiresExactScopeProtocolAndFreshHostPresence` |
|
||||||
|
| Cancellation and late callbacks | `RendezvousCoordinatorBehaviorTests.CancellationCompletesExactlyOnceAndLateCallbacksCannotReopenTheAttempt` |
|
||||||
|
| Mediator restart | both cases of `UdpMediatorServiceTests.NativeLiteNetLibRequestsIntroduceTheAuthorizedPair`; the restarted case rebinds the same UDP port and completes a native LiteNetLib introduction |
|
||||||
|
|
||||||
|
These tests use fake monotonic clocks or state predicates where expiry and race
|
||||||
|
ordering matter. They do not use fixed sleeps as proof of state.
|
||||||
|
|
||||||
|
## Privileged Linux namespace gate
|
||||||
|
|
||||||
|
When a Linux CI worker can create network namespaces, the workflow sets
|
||||||
|
`RENDEZVOUS_RUN_NETNS_TESTS=1` and reruns
|
||||||
|
`PrivilegedLinuxNatNamespacesCompleteDirectTrafficAcrossSeparateObservedEndpoints`.
|
||||||
|
The test creates a temporary WAN bridge, an isolated service namespace, two NAT
|
||||||
|
router namespaces, and isolated host/client LAN namespaces. Each NAT has its own
|
||||||
|
inside subnet and WAN address. Linux forwarding plus per-router MASQUERADE rules
|
||||||
|
force the service to observe separate translated endpoints; the public TestClient
|
||||||
|
processes must then complete authenticated direct traffic through those mappings
|
||||||
|
using the public candidate. Namespaces, rules, veth pairs, bridge, processes, and
|
||||||
|
sockets are removed in bounded async-disposal paths. A cleanup failure fails the
|
||||||
|
test.
|
||||||
|
|
||||||
|
If `ip netns add`/`iptables` is unavailable or the worker lacks `CAP_NET_ADMIN`,
|
||||||
|
CI records the limitation and keeps the always-on loopback suite as the required gate.
|
||||||
|
To request the privileged run explicitly:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
RENDEZVOUS_RUN_NETNS_TESTS=1 dotnet test Rendezvous.slnx \
|
||||||
|
--configuration Release --no-build \
|
||||||
|
--filter FullyQualifiedName~PrivilegedLinuxNatNamespacesCompleteDirectTrafficAcrossSeparateObservedEndpoints
|
||||||
|
```
|
||||||
|
|
||||||
|
## What this does not prove
|
||||||
|
|
||||||
|
Loopback, MASQUERADE, and namespace routing cannot reproduce every consumer router,
|
||||||
|
carrier-grade NAT, firewall, IPv6 transition mechanism, symmetric NAT mapping,
|
||||||
|
or real-world packet-loss pattern. The separate-observed-endpoint processor
|
||||||
|
test proves that untrusted private claims are excluded and public candidates are
|
||||||
|
selected; it is not presented as universal Internet traversal proof. Real
|
||||||
|
network canaries and measured production readiness remain the scope of issue
|
||||||
|
#23.
|
||||||
@@ -0,0 +1,98 @@
|
|||||||
|
# Hostile-input and overload protection
|
||||||
|
|
||||||
|
Tracking: #15
|
||||||
|
|
||||||
|
Rendezvous treats every public HTTP request and UDP datagram as hostile. The
|
||||||
|
server applies bounded fixed-window request budgets and concurrency ceilings in
|
||||||
|
two stages so malformed input is discarded before expensive work while valid
|
||||||
|
traffic is also isolated by its authenticated scope.
|
||||||
|
|
||||||
|
## Enforcement order
|
||||||
|
|
||||||
|
1. Kestrel and the HTTP abuse middleware cap request bodies at 16 KiB. A known
|
||||||
|
oversized body receives a typed `413` response before endpoint dispatch.
|
||||||
|
2. Every HTTP request consumes global, source-prefix, and operation budgets and
|
||||||
|
acquires the corresponding concurrency leases. IPv4 sources share a `/24`
|
||||||
|
budget and IPv6 sources share a `/56` budget; raw addresses are not retained.
|
||||||
|
Non-lease operations also consume a smaller optional-work budget, leaving a
|
||||||
|
configured global and source-prefix reserve for renew, update, and delete
|
||||||
|
operations during shedding.
|
||||||
|
Health probes use their own source-prefix budget so public API overload cannot
|
||||||
|
make a healthy instance fail its orchestrator probes, while health traffic is
|
||||||
|
still bounded.
|
||||||
|
3. Once an endpoint has safely derived identities, it also acquires applicable
|
||||||
|
tenant, principal or capability, and listing/attempt budgets. Secret
|
||||||
|
capabilities are represented only by bounded SHA-256 fingerprints.
|
||||||
|
4. Every UDP envelope consumes global, source-prefix, and wire-operation
|
||||||
|
budgets before decoding. A structurally and cryptographically valid request
|
||||||
|
then consumes capability, role, and mediation-handle budgets before state
|
||||||
|
mutation or introduction.
|
||||||
|
5. HTTP overload returns the stable `RateLimited` error, status `429`, and a
|
||||||
|
bounded `Retry-After` value in both the header and response contract. UDP
|
||||||
|
overload and every invalid UDP input are silently dropped.
|
||||||
|
|
||||||
|
The same HTTP identity budget is computed whether or not a listing or attempt
|
||||||
|
exists. Rejection therefore does not disclose resource existence. Publisher
|
||||||
|
authentication also completes before any tenant/resource operation, while the
|
||||||
|
pre-authentication source budget prevents invalid credentials from bypassing
|
||||||
|
load shedding.
|
||||||
|
|
||||||
|
## Bounded state and recovery
|
||||||
|
|
||||||
|
`Rendezvous:AbuseProtection:MaxTrackedKeys` is a hard combined ceiling for rate
|
||||||
|
and active-concurrency keys. General HTTP and UDP traffic cannot consume the
|
||||||
|
configured `CriticalTrackedKeyReserve`; lease operations and health probes may
|
||||||
|
use that reserve but never exceed the hard ceiling. A request that would exceed
|
||||||
|
its applicable ceiling fails closed without adding state. Fixed-window rate keys
|
||||||
|
are cleared at the next window boundary; concurrency keys are removed as their
|
||||||
|
request leases finish. HTTP and UDP trackers have separate locks and cardinality
|
||||||
|
partitions, so a UDP flood cannot block HTTP admission on a shared lock or
|
||||||
|
consume HTTP key capacity. This gives
|
||||||
|
deterministic burst recovery and prevents an attacker from growing a permanent
|
||||||
|
high-cardinality address, credential, or resource table.
|
||||||
|
|
||||||
|
The complete default profile is checked into
|
||||||
|
`src/FinalFactory.Rendezvous.Server/appsettings.json`. Operators may lower or
|
||||||
|
tune limits for a measured deployment profile, but must preserve all dimensions
|
||||||
|
and leave the tracker ceiling above the maximum simultaneous key set. A rolling
|
||||||
|
deployment should use the same profile on every instance. These per-process
|
||||||
|
limits are a final service boundary; an edge proxy may add stricter distributed
|
||||||
|
limits but is not a substitute for them.
|
||||||
|
|
||||||
|
When an HTTP reverse proxy is used, every immediate proxy address must be
|
||||||
|
allowlisted in `Rendezvous:AbuseProtection:TrustedProxyAddresses` (or indexed
|
||||||
|
environment variables such as
|
||||||
|
`Rendezvous__AbuseProtection__TrustedProxyAddresses__0`). Only one forwarded
|
||||||
|
hop is accepted. With an empty allowlist, forwarded headers are ignored and the
|
||||||
|
direct TCP peer is the source. Never add a broad network range or accept
|
||||||
|
untrusted `X-Forwarded-For` input: that would let a caller choose its own rate
|
||||||
|
partition.
|
||||||
|
|
||||||
|
## Reflection, disclosure, and logging rules
|
||||||
|
|
||||||
|
- UDP sends nothing for malformed, oversized, unauthenticated, stale,
|
||||||
|
replayed, wrong-role, or rate-limited input.
|
||||||
|
- Introductions are emitted only after both role-scoped capabilities bind to
|
||||||
|
their observed gameplay-socket sources. HTTP never supplies a public
|
||||||
|
introduction target.
|
||||||
|
- Private candidates must be same-family private unicast addresses and are used
|
||||||
|
only for peers observed behind the same public address.
|
||||||
|
- Abuse keys, exceptions, and responses never include bearer credentials,
|
||||||
|
capabilities, tickets, raw endpoints, metadata values, or hostile markup.
|
||||||
|
- Endpoint and capability values are not used as metric labels or log fields.
|
||||||
|
|
||||||
|
## Verification
|
||||||
|
|
||||||
|
The deterministic test corpora use the recorded seeds `0x152026`, `0x154A50`,
|
||||||
|
and `0x1557A7E`. They exercise 10,000 arbitrary UDP envelopes through the
|
||||||
|
production decoder, 5,000 arbitrary HTTP/credential parser inputs, and 1,000
|
||||||
|
mutated state transitions, including the oversized and configured-capacity
|
||||||
|
boundaries.
|
||||||
|
Focused tests cover IPv4 and IPv6 prefix
|
||||||
|
partitioning, tenant/principal/resource concurrency, tracker exhaustion,
|
||||||
|
window recovery, wire-operation isolation, a steady-state allocation ceiling,
|
||||||
|
typed `429`/`413` responses, secret fingerprint redaction, and silent
|
||||||
|
authenticated UDP shedding. The existing state, contract, HTTP, client,
|
||||||
|
and mediator suites continue to cover cross-tenant access, replay, role swaps,
|
||||||
|
credential rotation, bounded metadata, endpoint validation, and one-shot
|
||||||
|
amplification behavior.
|
||||||
@@ -11,7 +11,7 @@ backlog where the control is implemented and verified.
|
|||||||
| Per-game credentials and signing keys | Provisioned principals and versioned keys are scoped to game/environment; secrets come from a provider and never a public binary. (#5) | Cross-tenant authorization tests, rotation/overlap/revocation tests, and secret scans. |
|
| Per-game credentials and signing keys | Provisioned principals and versioned keys are scoped to game/environment; secrets come from a provider and never a public binary. (#5) | Cross-tenant authorization tests, rotation/overlap/revocation tests, and secret scans. |
|
||||||
| Short-lived, single-purpose tokens resistant to replay | Issuer fixes audience, tenant, attempt, role, issued/expiry times, nonce, and key ID; store atomically consumes nonce/ticket. (#4, #6, #10) | Golden vectors; expired, future, mutated, wrong-role, wrong-tenant, and concurrent replay tests. |
|
| Short-lived, single-purpose tokens resistant to replay | Issuer fixes audience, tenant, attempt, role, issued/expiry times, nonce, and key ID; store atomically consumes nonce/ticket. (#4, #6, #10) | Golden vectors; expired, future, mutated, wrong-role, wrong-tenant, and concurrent replay tests. |
|
||||||
| Strict payload, metadata, and token size limits | ADR 0003 ceilings are checked before allocation/deserialization and again at domain construction. (#4, #15) | Boundary/property tests, malformed corpus, and allocation-aware fuzzing. |
|
| Strict payload, metadata, and token size limits | ADR 0003 ceilings are checked before allocation/deserialization and again at domain construction. (#4, #15) | Boundary/property tests, malformed corpus, and allocation-aware fuzzing. |
|
||||||
| Registration, query, and introduction rate limits | Layered per-address, principal, tenant, and global token buckets with bounded queues and stable retry guidance. (#15) | Limit partition/isolation tests and overload/soak profiles. |
|
| Registration, query, and introduction rate limits | Layered fixed-window budgets and concurrency leases cover global, operation, IPv4 `/24` or IPv6 `/56`, tenant, principal/capability, and listing/attempt dimensions with a bounded key table and stable retry guidance. (#15) | Deterministic partition, concurrency, tracker-exhaustion, recovery, typed-overload, and silent-UDP-shedding tests. |
|
||||||
| Lease expiry removes abandoned servers | Visibility and join eligibility atomically require a fresh lease and fresh authenticated presence. (#6, #7) | Fake-clock expiry, renew/expire race, restart, and stale-host join tests. |
|
| Lease expiry removes abandoned servers | Visibility and join eligibility atomically require a fresh lease and fresh authenticated presence. (#6, #7) | Fake-clock expiry, renew/expire race, restart, and stale-host join tests. |
|
||||||
| Validate game, environment, room, and protocol boundaries | Every identifier is a validated type; store keys and authorization decisions include server-derived tenant scope; protocol is exact-match in v1. (#4-#10) | Contract, tenant-isolation, incompatible-version, and confused-deputy tests. |
|
| Validate game, environment, room, and protocol boundaries | Every identifier is a validated type; store keys and authorization decisions include server-derived tenant scope; protocol is exact-match in v1. (#4-#10) | Contract, tenant-isolation, incompatible-version, and confused-deputy tests. |
|
||||||
| Structured audit events without secrets or reusable credentials | Allowlisted audit schema excludes metadata values, raw endpoints, tokens, and key material; event volume is bounded. (#16) | Captured-log/audit assertions and credential canary scans. |
|
| Structured audit events without secrets or reusable credentials | Allowlisted audit schema excludes metadata values, raw endpoints, tokens, and key material; event volume is bounded. (#16) | Captured-log/audit assertions and credential canary scans. |
|
||||||
|
|||||||
@@ -0,0 +1,84 @@
|
|||||||
|
# Game provisioning and signing-key lifecycle
|
||||||
|
|
||||||
|
Tracking: #5
|
||||||
|
|
||||||
|
Rendezvous treats game and environment scope as provisioned policy, not caller
|
||||||
|
input. Production starts only when it can build an enabled policy registry and
|
||||||
|
load at least one currently active signing key from an external secret provider.
|
||||||
|
Unknown and disabled scopes fail closed.
|
||||||
|
|
||||||
|
## Policy boundary
|
||||||
|
|
||||||
|
Each `GamePolicy` fixes the allowed:
|
||||||
|
|
||||||
|
- game/environment pair and regions;
|
||||||
|
- exact gameplay protocol versions;
|
||||||
|
- publisher trust and listing visibility modes;
|
||||||
|
- metadata keys, required keys, per-value limits, total bytes, and key count;
|
||||||
|
- listing, anonymous-host, and active-attempt quotas; and
|
||||||
|
- dedicated fallback feature policy.
|
||||||
|
|
||||||
|
Publisher authorization first authenticates a typed principal, then derives the
|
||||||
|
authoritative game/environment from that principal. Request fields are compared
|
||||||
|
for mismatch detection but never replace the authenticated scope. Dedicated
|
||||||
|
workloads, short-lived player-host grants, anonymous unlisted publishers, and
|
||||||
|
operators are distinct principal types. Operator credentials cannot be used as
|
||||||
|
publisher credentials, and anonymous publishers cannot escalate to public
|
||||||
|
visibility.
|
||||||
|
|
||||||
|
## Signed credentials
|
||||||
|
|
||||||
|
Signed principal credentials use the compact form
|
||||||
|
`rv1.<key-id>.<base64url-payload>.<base64url-HMAC-SHA256>`. The signed payload
|
||||||
|
contains version, issuer, audience, subject, principal kind, bounded scope,
|
||||||
|
issued/not-before/expiry times, and a random nonce. It contains no signing key,
|
||||||
|
reusable publisher secret, player identity, or gameplay state.
|
||||||
|
|
||||||
|
Validation is deliberately ordered and bounded:
|
||||||
|
|
||||||
|
1. enforce the v1 opaque-credential length and four-segment grammar;
|
||||||
|
2. resolve a known, non-revoked key in its verification window;
|
||||||
|
3. compare the HMAC in fixed time;
|
||||||
|
4. parse canonical bounded JSON;
|
||||||
|
5. require exact version, issuer, and audience;
|
||||||
|
6. enforce clock skew, expiry, key lifetime, principal kind, and scope shape.
|
||||||
|
|
||||||
|
Failures return typed internal reasons without echoing the credential. Logs and
|
||||||
|
metrics must record only allowlisted tenant/principal/result dimensions; token,
|
||||||
|
key, secret-reference value, and raw key material are excluded.
|
||||||
|
|
||||||
|
## Rotation and revocation
|
||||||
|
|
||||||
|
A key is bound either to operator credentials only or to allowed publisher
|
||||||
|
credential kinds for exactly one game/environment. The verifier checks this
|
||||||
|
authority after the signature, so even a compromised game grant issuer cannot
|
||||||
|
mint a valid cross-game or operator credential.
|
||||||
|
|
||||||
|
A key also has three times: `NotBefore`, `SignUntil`, and `VerifyUntil`. Issuance
|
||||||
|
picks the newest authorized non-revoked key inside its signing window. Older credentials continue
|
||||||
|
to verify until the old key's verification window ends, providing an explicit
|
||||||
|
overlap. After `VerifyUntil` they fail as retired. Configuration revocation and
|
||||||
|
runtime revocation both reject immediately. A configured revoked key retains
|
||||||
|
only its public key ID/lifecycle metadata and does not require retired secret
|
||||||
|
material to remain available.
|
||||||
|
|
||||||
|
Key IDs are non-secret base64url identifiers. Secret references are resolved
|
||||||
|
through `ISecretProvider`; production supports `env:<VARIABLE>` references and
|
||||||
|
the interface is replaceable by a deployment-specific vault/KMS adapter. The
|
||||||
|
committed development profile uses an in-memory random key identified by a
|
||||||
|
`development:ephemeral/...` reference. It never writes key material to disk and
|
||||||
|
all credentials become invalid when the process exits.
|
||||||
|
|
||||||
|
## Production configuration
|
||||||
|
|
||||||
|
`Rendezvous:Provisioning` supplies issuer, audience, clock skew, signing-key
|
||||||
|
descriptors, and game policies. A production key reference such as
|
||||||
|
`env:RENDEZVOUS_SIGNING_KEY_2026_01` expects that environment variable to hold at
|
||||||
|
least 32 random bytes encoded as base64. Missing, malformed, short, inactive, or
|
||||||
|
duplicate keys stop startup with a key-ID-only diagnostic. No game-wide secret
|
||||||
|
belongs in `appsettings`, source control, examples, the Client package, URLs,
|
||||||
|
responses, logs, metrics, exceptions, or diagnostic dumps.
|
||||||
|
|
||||||
|
Readiness becomes true only after provisioning and UDP startup both succeed.
|
||||||
|
OpenAPI generation uses a pinned build-only host and does not start listeners or
|
||||||
|
bypass provisioning in a deployed server process.
|
||||||
@@ -0,0 +1,183 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using LiteNetLib;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Client;
|
||||||
|
|
||||||
|
public enum RendezvousConnectionOutcomeSource
|
||||||
|
{
|
||||||
|
RendezvousService = 1,
|
||||||
|
LocalTraversal = 2,
|
||||||
|
RemoteHost = 3,
|
||||||
|
Caller = 4,
|
||||||
|
Lifecycle = 5,
|
||||||
|
}
|
||||||
|
|
||||||
|
public enum RendezvousConnectionFailureCategory
|
||||||
|
{
|
||||||
|
None = 0,
|
||||||
|
Directory = 1,
|
||||||
|
Compatibility = 2,
|
||||||
|
Authorization = 3,
|
||||||
|
Capacity = 4,
|
||||||
|
HostPresence = 5,
|
||||||
|
Service = 6,
|
||||||
|
Mediation = 7,
|
||||||
|
NatTraversal = 8,
|
||||||
|
DirectConnection = 9,
|
||||||
|
Lifecycle = 10,
|
||||||
|
}
|
||||||
|
|
||||||
|
public enum RendezvousConnectionPhase
|
||||||
|
{
|
||||||
|
Directory = 1,
|
||||||
|
Authorization = 2,
|
||||||
|
Mediation = 3,
|
||||||
|
NatTraversal = 4,
|
||||||
|
DirectConnection = 5,
|
||||||
|
Complete = 6,
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class RendezvousConnectionOutcome
|
||||||
|
{
|
||||||
|
private readonly NetworkEndpoint? _dedicatedFallback;
|
||||||
|
|
||||||
|
private RendezvousConnectionOutcome(
|
||||||
|
ConnectionOutcomeKind kind,
|
||||||
|
RendezvousConnectionOutcomeSource source,
|
||||||
|
RendezvousConnectionFailureCategory category,
|
||||||
|
RendezvousConnectionPhase phase,
|
||||||
|
TimeSpan elapsed,
|
||||||
|
RendezvousErrorCode? serviceError,
|
||||||
|
NetworkEndpoint? dedicatedFallback,
|
||||||
|
NetPeer? peer)
|
||||||
|
{
|
||||||
|
if (elapsed < TimeSpan.Zero)
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(nameof(elapsed));
|
||||||
|
}
|
||||||
|
|
||||||
|
if (dedicatedFallback is not null
|
||||||
|
&& !ContractValidation.IsNetworkEndpointValid(dedicatedFallback))
|
||||||
|
{
|
||||||
|
throw new ArgumentException("The dedicated fallback endpoint is invalid.", nameof(dedicatedFallback));
|
||||||
|
}
|
||||||
|
|
||||||
|
Kind = kind;
|
||||||
|
Source = source;
|
||||||
|
Category = category;
|
||||||
|
Phase = phase;
|
||||||
|
Elapsed = elapsed;
|
||||||
|
ServiceError = serviceError;
|
||||||
|
_dedicatedFallback = RendezvousEndpoint.Copy(dedicatedFallback);
|
||||||
|
Peer = peer;
|
||||||
|
}
|
||||||
|
|
||||||
|
public ConnectionOutcomeKind Kind { get; }
|
||||||
|
public RendezvousConnectionOutcomeSource Source { get; }
|
||||||
|
public RendezvousConnectionFailureCategory Category { get; }
|
||||||
|
public RendezvousConnectionPhase Phase { get; }
|
||||||
|
public TimeSpan Elapsed { get; }
|
||||||
|
public RendezvousErrorCode? ServiceError { get; }
|
||||||
|
public NetworkEndpoint? DedicatedFallback => RendezvousEndpoint.Copy(_dedicatedFallback);
|
||||||
|
public NetPeer? Peer { get; }
|
||||||
|
public bool IsSuccess => Kind == ConnectionOutcomeKind.Connected;
|
||||||
|
public bool HasDedicatedFallback => _dedicatedFallback is not null;
|
||||||
|
|
||||||
|
public static RendezvousConnectionOutcome FromServiceError(
|
||||||
|
RendezvousErrorCode error,
|
||||||
|
TimeSpan elapsed,
|
||||||
|
NetworkEndpoint? dedicatedFallback = null)
|
||||||
|
{
|
||||||
|
if (error == RendezvousErrorCode.None)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("A service failure outcome requires an error.", nameof(error));
|
||||||
|
}
|
||||||
|
|
||||||
|
(ConnectionOutcomeKind kind, RendezvousConnectionFailureCategory category, RendezvousConnectionPhase phase) =
|
||||||
|
error switch
|
||||||
|
{
|
||||||
|
RendezvousErrorCode.NotFound => (
|
||||||
|
ConnectionOutcomeKind.DirectoryNotFound,
|
||||||
|
RendezvousConnectionFailureCategory.Directory,
|
||||||
|
RendezvousConnectionPhase.Directory),
|
||||||
|
RendezvousErrorCode.Expired => (
|
||||||
|
ConnectionOutcomeKind.AttemptExpired,
|
||||||
|
RendezvousConnectionFailureCategory.Authorization,
|
||||||
|
RendezvousConnectionPhase.Authorization),
|
||||||
|
RendezvousErrorCode.IncompatibleProtocol => (
|
||||||
|
ConnectionOutcomeKind.IncompatibleProtocol,
|
||||||
|
RendezvousConnectionFailureCategory.Compatibility,
|
||||||
|
RendezvousConnectionPhase.Directory),
|
||||||
|
RendezvousErrorCode.AuthenticationRequired
|
||||||
|
or RendezvousErrorCode.Forbidden
|
||||||
|
or RendezvousErrorCode.ReplayRejected => (
|
||||||
|
ConnectionOutcomeKind.Unauthorized,
|
||||||
|
RendezvousConnectionFailureCategory.Authorization,
|
||||||
|
RendezvousConnectionPhase.Authorization),
|
||||||
|
RendezvousErrorCode.RateLimited
|
||||||
|
or RendezvousErrorCode.CapacityExceeded => (
|
||||||
|
ConnectionOutcomeKind.RateLimited,
|
||||||
|
RendezvousConnectionFailureCategory.Capacity,
|
||||||
|
RendezvousConnectionPhase.Authorization),
|
||||||
|
RendezvousErrorCode.StaleHost => (
|
||||||
|
ConnectionOutcomeKind.NoHostPresence,
|
||||||
|
RendezvousConnectionFailureCategory.HostPresence,
|
||||||
|
RendezvousConnectionPhase.Mediation),
|
||||||
|
RendezvousErrorCode.ServiceUnavailable => (
|
||||||
|
ConnectionOutcomeKind.ServiceUnavailable,
|
||||||
|
RendezvousConnectionFailureCategory.Service,
|
||||||
|
RendezvousConnectionPhase.Authorization),
|
||||||
|
_ => (
|
||||||
|
ConnectionOutcomeKind.ServiceRejected,
|
||||||
|
RendezvousConnectionFailureCategory.Service,
|
||||||
|
RendezvousConnectionPhase.Authorization),
|
||||||
|
};
|
||||||
|
return new(
|
||||||
|
kind,
|
||||||
|
RendezvousConnectionOutcomeSource.RendezvousService,
|
||||||
|
category,
|
||||||
|
phase,
|
||||||
|
elapsed,
|
||||||
|
error,
|
||||||
|
dedicatedFallback,
|
||||||
|
null);
|
||||||
|
}
|
||||||
|
|
||||||
|
public static ConnectionElapsedBucket BucketElapsed(TimeSpan elapsed)
|
||||||
|
{
|
||||||
|
if (elapsed < TimeSpan.Zero)
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(nameof(elapsed));
|
||||||
|
}
|
||||||
|
|
||||||
|
return elapsed.TotalSeconds switch
|
||||||
|
{
|
||||||
|
< 1 => ConnectionElapsedBucket.UnderOneSecond,
|
||||||
|
< 5 => ConnectionElapsedBucket.OneToFiveSeconds,
|
||||||
|
< 15 => ConnectionElapsedBucket.FiveToFifteenSeconds,
|
||||||
|
< 30 => ConnectionElapsedBucket.FifteenToThirtySeconds,
|
||||||
|
_ => ConnectionElapsedBucket.ThirtySecondsOrMore,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
public override string ToString() =>
|
||||||
|
$"[RendezvousConnectionOutcome {Kind}; {Source}; credentials redacted]";
|
||||||
|
|
||||||
|
internal static RendezvousConnectionOutcome Create(
|
||||||
|
ConnectionOutcomeKind kind,
|
||||||
|
RendezvousConnectionOutcomeSource source,
|
||||||
|
RendezvousConnectionFailureCategory category,
|
||||||
|
RendezvousConnectionPhase phase,
|
||||||
|
TimeSpan elapsed,
|
||||||
|
NetworkEndpoint? dedicatedFallback = null,
|
||||||
|
NetPeer? peer = null) => new(
|
||||||
|
kind,
|
||||||
|
source,
|
||||||
|
category,
|
||||||
|
phase,
|
||||||
|
elapsed,
|
||||||
|
null,
|
||||||
|
dedicatedFallback,
|
||||||
|
peer);
|
||||||
|
|
||||||
|
}
|
||||||
+35
@@ -0,0 +1,35 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Client;
|
||||||
|
|
||||||
|
public sealed class RendezvousConnectionStartResult
|
||||||
|
{
|
||||||
|
internal RendezvousConnectionStartResult(
|
||||||
|
CreateJoinAttemptResponse? attempt,
|
||||||
|
RendezvousConnectionOutcome? outcome)
|
||||||
|
{
|
||||||
|
if ((attempt is null) == (outcome is null))
|
||||||
|
{
|
||||||
|
throw new ArgumentException(
|
||||||
|
"A connection start result requires exactly one attempt or terminal outcome.");
|
||||||
|
}
|
||||||
|
|
||||||
|
Attempt = attempt;
|
||||||
|
Outcome = outcome;
|
||||||
|
}
|
||||||
|
|
||||||
|
public CreateJoinAttemptResponse? Attempt { get; }
|
||||||
|
public RendezvousConnectionOutcome? Outcome { get; }
|
||||||
|
public bool IsReadyForTraversal => Attempt is not null;
|
||||||
|
public bool IsCompleted => Outcome is not null;
|
||||||
|
|
||||||
|
public static RendezvousConnectionStartResult ReadyForTraversal(
|
||||||
|
CreateJoinAttemptResponse attempt) => new(
|
||||||
|
attempt ?? throw new ArgumentNullException(nameof(attempt)),
|
||||||
|
null);
|
||||||
|
|
||||||
|
public static RendezvousConnectionStartResult Completed(
|
||||||
|
RendezvousConnectionOutcome outcome) => new(
|
||||||
|
null,
|
||||||
|
outcome ?? throw new ArgumentNullException(nameof(outcome)));
|
||||||
|
}
|
||||||
@@ -0,0 +1,232 @@
|
|||||||
|
using System.Security.Cryptography;
|
||||||
|
using System.Text;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Client;
|
||||||
|
|
||||||
|
public enum ConnectionTicketConsumptionResult
|
||||||
|
{
|
||||||
|
Accepted = 1,
|
||||||
|
NotFound = 2,
|
||||||
|
Expired = 3,
|
||||||
|
Rejected = 4,
|
||||||
|
AlreadyConsumed = 5,
|
||||||
|
Revoked = 6,
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class ConnectionTicketValidator : IDisposable
|
||||||
|
{
|
||||||
|
private readonly object _gate = new();
|
||||||
|
private readonly Dictionary<JoinAttemptId, TicketEntry> _tickets = [];
|
||||||
|
private readonly int _maximumAuthorizedTickets;
|
||||||
|
private readonly IConnectionTicketClock _clock;
|
||||||
|
private readonly byte[] _fingerprintKey = new byte[32];
|
||||||
|
private bool _disposed;
|
||||||
|
|
||||||
|
public ConnectionTicketValidator(int maximumAuthorizedTickets = 1_024)
|
||||||
|
: this(maximumAuthorizedTickets, new SystemConnectionTicketClock())
|
||||||
|
{
|
||||||
|
}
|
||||||
|
|
||||||
|
internal ConnectionTicketValidator(
|
||||||
|
int maximumAuthorizedTickets,
|
||||||
|
IConnectionTicketClock clock)
|
||||||
|
{
|
||||||
|
if (maximumAuthorizedTickets is < 1 or > 10_000)
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(nameof(maximumAuthorizedTickets));
|
||||||
|
}
|
||||||
|
|
||||||
|
_maximumAuthorizedTickets = maximumAuthorizedTickets;
|
||||||
|
_clock = clock ?? throw new ArgumentNullException(nameof(clock));
|
||||||
|
RandomNumberGenerator.Fill(_fingerprintKey);
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool TryAuthorize(
|
||||||
|
JoinAttemptId attemptId,
|
||||||
|
string connectionTicket,
|
||||||
|
DateTimeOffset expiresAt)
|
||||||
|
{
|
||||||
|
lock (_gate)
|
||||||
|
{
|
||||||
|
ThrowIfDisposed();
|
||||||
|
DateTimeOffset now = _clock.UtcNow;
|
||||||
|
if (attemptId.Value == Guid.Empty
|
||||||
|
|| !ContractValidation.IsConnectionTicketValid(connectionTicket)
|
||||||
|
|| expiresAt <= now)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
RemoveExpired(now);
|
||||||
|
byte[] fingerprint = Fingerprint(connectionTicket);
|
||||||
|
if (_tickets.TryGetValue(attemptId, out TicketEntry? current))
|
||||||
|
{
|
||||||
|
bool idempotent = current.State == TicketState.Active
|
||||||
|
&& current.ExpiresAt == expiresAt
|
||||||
|
&& CryptographicOperations.FixedTimeEquals(current.Fingerprint, fingerprint);
|
||||||
|
CryptographicOperations.ZeroMemory(fingerprint);
|
||||||
|
return idempotent;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (_tickets.Count >= _maximumAuthorizedTickets)
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(fingerprint);
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
_tickets.Add(attemptId, new(fingerprint, expiresAt));
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public ConnectionTicketConsumptionResult Consume(
|
||||||
|
JoinAttemptId attemptId,
|
||||||
|
string connectionTicket)
|
||||||
|
{
|
||||||
|
lock (_gate)
|
||||||
|
{
|
||||||
|
ThrowIfDisposed();
|
||||||
|
DateTimeOffset now = _clock.UtcNow;
|
||||||
|
if (attemptId.Value == Guid.Empty
|
||||||
|
|| !ContractValidation.IsConnectionTicketValid(connectionTicket))
|
||||||
|
{
|
||||||
|
return ConnectionTicketConsumptionResult.Rejected;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!_tickets.TryGetValue(attemptId, out TicketEntry? entry))
|
||||||
|
{
|
||||||
|
RemoveExpired(now);
|
||||||
|
return ConnectionTicketConsumptionResult.NotFound;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (entry.ExpiresAt <= now)
|
||||||
|
{
|
||||||
|
Remove(attemptId, entry);
|
||||||
|
return ConnectionTicketConsumptionResult.Expired;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (entry.State == TicketState.Revoked)
|
||||||
|
{
|
||||||
|
return ConnectionTicketConsumptionResult.Revoked;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (entry.State == TicketState.Consumed)
|
||||||
|
{
|
||||||
|
return ConnectionTicketConsumptionResult.AlreadyConsumed;
|
||||||
|
}
|
||||||
|
|
||||||
|
byte[] supplied = Fingerprint(connectionTicket);
|
||||||
|
bool matches = CryptographicOperations.FixedTimeEquals(entry.Fingerprint, supplied);
|
||||||
|
CryptographicOperations.ZeroMemory(supplied);
|
||||||
|
if (!matches)
|
||||||
|
{
|
||||||
|
return ConnectionTicketConsumptionResult.Rejected;
|
||||||
|
}
|
||||||
|
|
||||||
|
entry.State = TicketState.Consumed;
|
||||||
|
return ConnectionTicketConsumptionResult.Accepted;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool Revoke(JoinAttemptId attemptId)
|
||||||
|
{
|
||||||
|
lock (_gate)
|
||||||
|
{
|
||||||
|
ThrowIfDisposed();
|
||||||
|
RemoveExpired(_clock.UtcNow);
|
||||||
|
if (!_tickets.TryGetValue(attemptId, out TicketEntry? entry))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
entry.State = TicketState.Revoked;
|
||||||
|
CryptographicOperations.ZeroMemory(entry.Fingerprint);
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public void Dispose()
|
||||||
|
{
|
||||||
|
lock (_gate)
|
||||||
|
{
|
||||||
|
if (_disposed)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach (TicketEntry entry in _tickets.Values)
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(entry.Fingerprint);
|
||||||
|
}
|
||||||
|
|
||||||
|
_tickets.Clear();
|
||||||
|
CryptographicOperations.ZeroMemory(_fingerprintKey);
|
||||||
|
_disposed = true;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public override string ToString() => "[ConnectionTicketValidator: tickets and key redacted]";
|
||||||
|
|
||||||
|
private byte[] Fingerprint(string ticket)
|
||||||
|
{
|
||||||
|
byte[] encoded = Encoding.ASCII.GetBytes(ticket);
|
||||||
|
try
|
||||||
|
{
|
||||||
|
using HMACSHA256 hmac = new(_fingerprintKey);
|
||||||
|
return hmac.ComputeHash(encoded);
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(encoded);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private void RemoveExpired(DateTimeOffset now)
|
||||||
|
{
|
||||||
|
foreach (KeyValuePair<JoinAttemptId, TicketEntry> item in _tickets
|
||||||
|
.Where(item => item.Value.ExpiresAt <= now)
|
||||||
|
.ToArray())
|
||||||
|
{
|
||||||
|
Remove(item.Key, item.Value);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private void Remove(JoinAttemptId attemptId, TicketEntry entry)
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(entry.Fingerprint);
|
||||||
|
_tickets.Remove(attemptId);
|
||||||
|
}
|
||||||
|
|
||||||
|
private void ThrowIfDisposed()
|
||||||
|
{
|
||||||
|
if (_disposed)
|
||||||
|
{
|
||||||
|
throw new ObjectDisposedException(nameof(ConnectionTicketValidator));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private sealed class TicketEntry(byte[] fingerprint, DateTimeOffset expiresAt)
|
||||||
|
{
|
||||||
|
public byte[] Fingerprint { get; } = fingerprint;
|
||||||
|
public DateTimeOffset ExpiresAt { get; } = expiresAt;
|
||||||
|
public TicketState State { get; set; }
|
||||||
|
}
|
||||||
|
|
||||||
|
private enum TicketState
|
||||||
|
{
|
||||||
|
Active = 0,
|
||||||
|
Consumed = 1,
|
||||||
|
Revoked = 2,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
internal interface IConnectionTicketClock
|
||||||
|
{
|
||||||
|
DateTimeOffset UtcNow { get; }
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class SystemConnectionTicketClock : IConnectionTicketClock
|
||||||
|
{
|
||||||
|
public DateTimeOffset UtcNow => DateTimeOffset.UtcNow;
|
||||||
|
}
|
||||||
@@ -5,10 +5,12 @@
|
|||||||
<RootNamespace>FinalFactory.Rendezvous.Client</RootNamespace>
|
<RootNamespace>FinalFactory.Rendezvous.Client</RootNamespace>
|
||||||
<IsPackable>true</IsPackable>
|
<IsPackable>true</IsPackable>
|
||||||
<PackageId>FinalFactory.Rendezvous.Client</PackageId>
|
<PackageId>FinalFactory.Rendezvous.Client</PackageId>
|
||||||
|
<PackageReadmeFile>README.md</PackageReadmeFile>
|
||||||
<Description>Godot-independent client SDK for Final Factory Rendezvous.</Description>
|
<Description>Godot-independent client SDK for Final Factory Rendezvous.</Description>
|
||||||
</PropertyGroup>
|
</PropertyGroup>
|
||||||
<ItemGroup>
|
<ItemGroup>
|
||||||
<ProjectReference Include="../FinalFactory.Rendezvous.Contracts/FinalFactory.Rendezvous.Contracts.csproj" />
|
<ProjectReference Include="../FinalFactory.Rendezvous.Contracts/FinalFactory.Rendezvous.Contracts.csproj" />
|
||||||
<PackageReference Include="LiteNetLib" />
|
<PackageReference Include="LiteNetLib" />
|
||||||
|
<None Update="README.md" Pack="true" PackagePath="\" />
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
</Project>
|
</Project>
|
||||||
|
|||||||
@@ -0,0 +1,236 @@
|
|||||||
|
using System.Diagnostics;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Client;
|
||||||
|
|
||||||
|
public sealed class RendezvousJoinClient : IRendezvousJoinClient
|
||||||
|
{
|
||||||
|
private const string LeaseTokenHeader = "X-Rendezvous-Lease-Token";
|
||||||
|
private const string ClientPunchCapabilityHeader = "X-Rendezvous-Client-Punch-Capability";
|
||||||
|
|
||||||
|
private readonly RendezvousHttpTransport _transport;
|
||||||
|
|
||||||
|
public RendezvousJoinClient(
|
||||||
|
HttpClient httpClient,
|
||||||
|
RendezvousClientOptions? options = null,
|
||||||
|
IRendezvousDelay? delay = null)
|
||||||
|
{
|
||||||
|
_transport = new(httpClient, options, delay);
|
||||||
|
}
|
||||||
|
|
||||||
|
public Task<RendezvousClientResult<CreateJoinAttemptResponse>> CreateAsync(
|
||||||
|
CreateJoinAttemptRequest request,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
if (request is null)
|
||||||
|
{
|
||||||
|
throw new ArgumentNullException(nameof(request));
|
||||||
|
}
|
||||||
|
CreateJoinAttemptRequest body = new()
|
||||||
|
{
|
||||||
|
ContractVersion = request.ContractVersion,
|
||||||
|
IdempotencyKey = request.IdempotencyKey,
|
||||||
|
GameId = request.GameId,
|
||||||
|
EnvironmentId = request.EnvironmentId,
|
||||||
|
ListingId = request.ListingId,
|
||||||
|
ProtocolVersion = request.ProtocolVersion,
|
||||||
|
};
|
||||||
|
return _transport.SendSafeAsync<CreateJoinAttemptResponse>(
|
||||||
|
() => RendezvousHttpTransport.JsonRequest(HttpMethod.Post, "v1/join-attempts", body),
|
||||||
|
cancellationToken);
|
||||||
|
}
|
||||||
|
|
||||||
|
public async Task<RendezvousConnectionStartResult> CreateConnectionAttemptAsync(
|
||||||
|
CreateJoinAttemptRequest request,
|
||||||
|
NetworkEndpoint? dedicatedFallback = null,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
if (dedicatedFallback is not null
|
||||||
|
&& !ContractValidation.IsNetworkEndpointValid(dedicatedFallback))
|
||||||
|
{
|
||||||
|
throw new ArgumentException("The dedicated fallback endpoint is invalid.", nameof(dedicatedFallback));
|
||||||
|
}
|
||||||
|
|
||||||
|
Stopwatch elapsed = Stopwatch.StartNew();
|
||||||
|
try
|
||||||
|
{
|
||||||
|
RendezvousClientResult<CreateJoinAttemptResponse> result = await CreateAsync(
|
||||||
|
request,
|
||||||
|
cancellationToken).ConfigureAwait(false);
|
||||||
|
elapsed.Stop();
|
||||||
|
return result.IsSuccess && result.Value is not null
|
||||||
|
? RendezvousConnectionStartResult.ReadyForTraversal(result.Value)
|
||||||
|
: RendezvousConnectionStartResult.Completed(
|
||||||
|
RendezvousConnectionOutcome.FromServiceError(
|
||||||
|
result.Error,
|
||||||
|
elapsed.Elapsed,
|
||||||
|
dedicatedFallback));
|
||||||
|
}
|
||||||
|
catch (OperationCanceledException) when (cancellationToken.IsCancellationRequested)
|
||||||
|
{
|
||||||
|
elapsed.Stop();
|
||||||
|
return RendezvousConnectionStartResult.Completed(
|
||||||
|
RendezvousConnectionOutcome.Create(
|
||||||
|
ConnectionOutcomeKind.Cancelled,
|
||||||
|
RendezvousConnectionOutcomeSource.Caller,
|
||||||
|
RendezvousConnectionFailureCategory.Lifecycle,
|
||||||
|
RendezvousConnectionPhase.Authorization,
|
||||||
|
elapsed.Elapsed,
|
||||||
|
dedicatedFallback));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public Task<RendezvousClientResult<bool>> CancelAsync(
|
||||||
|
CreateJoinAttemptResponse attempt,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
if (attempt is null)
|
||||||
|
{
|
||||||
|
throw new ArgumentNullException(nameof(attempt));
|
||||||
|
}
|
||||||
|
return _transport.SendSafeAsync<bool>(
|
||||||
|
() => HeaderRequest(
|
||||||
|
HttpMethod.Delete,
|
||||||
|
$"v1/join-attempts/{attempt.AttemptId}",
|
||||||
|
ClientPunchCapabilityHeader,
|
||||||
|
RequireHeaderValue(attempt.ClientPunchCapability, nameof(attempt))),
|
||||||
|
cancellationToken);
|
||||||
|
}
|
||||||
|
|
||||||
|
public Task<RendezvousClientResult<BrowseHostJoinAttemptsResponse>> BrowseForHostAsync(
|
||||||
|
PublishedSession session,
|
||||||
|
int pageSize = ContractLimits.BrowserPageMaxItems,
|
||||||
|
string? cursor = null,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
if (session is null)
|
||||||
|
{
|
||||||
|
throw new ArgumentNullException(nameof(session));
|
||||||
|
}
|
||||||
|
if (pageSize is < 1 or > ContractLimits.BrowserPageMaxItems)
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(nameof(pageSize));
|
||||||
|
}
|
||||||
|
|
||||||
|
string query = $"v1/sessions/{session.ListingId}/join-attempts"
|
||||||
|
+ $"?contractVersion={ContractLimits.ContractVersion}"
|
||||||
|
+ $"&pageSize={pageSize}"
|
||||||
|
+ (cursor is null ? string.Empty : $"&cursor={Uri.EscapeDataString(cursor)}");
|
||||||
|
return _transport.SendSafeAsync<BrowseHostJoinAttemptsResponse>(
|
||||||
|
() => HeaderRequest(
|
||||||
|
HttpMethod.Get,
|
||||||
|
query,
|
||||||
|
LeaseTokenHeader,
|
||||||
|
RequireHeaderValue(session.LeaseToken, nameof(session))),
|
||||||
|
cancellationToken);
|
||||||
|
}
|
||||||
|
|
||||||
|
public async Task<RendezvousClientResult<IReadOnlyList<HostJoinAttempt>>> BrowseAllForHostAsync(
|
||||||
|
PublishedSession session,
|
||||||
|
int maximumPages = 100,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
if (session is null)
|
||||||
|
{
|
||||||
|
throw new ArgumentNullException(nameof(session));
|
||||||
|
}
|
||||||
|
if (maximumPages is < 1 or > 1_000)
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(nameof(maximumPages));
|
||||||
|
}
|
||||||
|
|
||||||
|
List<HostJoinAttempt> attempts = [];
|
||||||
|
string? cursor = null;
|
||||||
|
for (int page = 0; page < maximumPages; page++)
|
||||||
|
{
|
||||||
|
RendezvousClientResult<BrowseHostJoinAttemptsResponse> result =
|
||||||
|
await BrowseForHostAsync(
|
||||||
|
session,
|
||||||
|
ContractLimits.BrowserPageMaxItems,
|
||||||
|
cursor,
|
||||||
|
cancellationToken).ConfigureAwait(false);
|
||||||
|
if (!result.IsSuccess || result.Value is null)
|
||||||
|
{
|
||||||
|
return RendezvousClientResult.Failure<IReadOnlyList<HostJoinAttempt>>(
|
||||||
|
result.Error,
|
||||||
|
result.Message,
|
||||||
|
result.RetryAfterSeconds);
|
||||||
|
}
|
||||||
|
|
||||||
|
attempts.AddRange(result.Value.Items);
|
||||||
|
cursor = result.Value.NextCursor;
|
||||||
|
if (string.IsNullOrEmpty(cursor))
|
||||||
|
{
|
||||||
|
return RendezvousClientResult.Success<IReadOnlyList<HostJoinAttempt>>(
|
||||||
|
attempts.AsReadOnly());
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return RendezvousClientResult.Failure<IReadOnlyList<HostJoinAttempt>>(
|
||||||
|
RendezvousErrorCode.CapacityExceeded,
|
||||||
|
$"Host invitation polling exceeded the configured {maximumPages}-page limit.");
|
||||||
|
}
|
||||||
|
|
||||||
|
public Task<RendezvousClientResult<ReportConnectionOutcomeResponse>> ReportOutcomeAsync(
|
||||||
|
CreateJoinAttemptResponse attempt,
|
||||||
|
RendezvousConnectionOutcome outcome,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
if (attempt is null)
|
||||||
|
{
|
||||||
|
throw new ArgumentNullException(nameof(attempt));
|
||||||
|
}
|
||||||
|
if (outcome is null)
|
||||||
|
{
|
||||||
|
throw new ArgumentNullException(nameof(outcome));
|
||||||
|
}
|
||||||
|
if (!ContractValidation.IsReportableConnectionOutcome(outcome.Kind))
|
||||||
|
{
|
||||||
|
throw new ArgumentException(
|
||||||
|
"This outcome cannot be reported for an issued join attempt.",
|
||||||
|
nameof(outcome));
|
||||||
|
}
|
||||||
|
|
||||||
|
ReportConnectionOutcomeRequest body = new()
|
||||||
|
{
|
||||||
|
Outcome = outcome.Kind,
|
||||||
|
ElapsedBucket = RendezvousConnectionOutcome.BucketElapsed(outcome.Elapsed),
|
||||||
|
};
|
||||||
|
return _transport.SendSafeAsync<ReportConnectionOutcomeResponse>(
|
||||||
|
() => HeaderJsonRequest(
|
||||||
|
HttpMethod.Post,
|
||||||
|
$"v1/join-attempts/{attempt.AttemptId}/outcome",
|
||||||
|
ClientPunchCapabilityHeader,
|
||||||
|
RequireHeaderValue(attempt.ClientPunchCapability, nameof(attempt)),
|
||||||
|
body),
|
||||||
|
cancellationToken);
|
||||||
|
}
|
||||||
|
|
||||||
|
private static HttpRequestMessage HeaderRequest(
|
||||||
|
HttpMethod method,
|
||||||
|
string uri,
|
||||||
|
string header,
|
||||||
|
string value)
|
||||||
|
{
|
||||||
|
HttpRequestMessage request = new(method, uri);
|
||||||
|
request.Headers.TryAddWithoutValidation(header, value);
|
||||||
|
return request;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static HttpRequestMessage HeaderJsonRequest<T>(
|
||||||
|
HttpMethod method,
|
||||||
|
string uri,
|
||||||
|
string header,
|
||||||
|
string value,
|
||||||
|
T body)
|
||||||
|
{
|
||||||
|
HttpRequestMessage request = RendezvousHttpTransport.JsonRequest(method, uri, body);
|
||||||
|
request.Headers.TryAddWithoutValidation(header, value);
|
||||||
|
return request;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static string RequireHeaderValue(string value, string parameterName) =>
|
||||||
|
!string.IsNullOrWhiteSpace(value)
|
||||||
|
? value
|
||||||
|
: throw new ArgumentException("The required capability is missing.", parameterName);
|
||||||
|
}
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
using System.Runtime.CompilerServices;
|
||||||
|
|
||||||
|
[assembly: InternalsVisibleTo("FinalFactory.Rendezvous.Tests")]
|
||||||
@@ -0,0 +1,197 @@
|
|||||||
|
# FinalFactory.Rendezvous.Client
|
||||||
|
|
||||||
|
Godot-independent .NET publisher, browser, join, and LiteNetLib traversal SDK for Rendezvous v1.
|
||||||
|
The package targets `netstandard2.1` and uses a caller-owned `HttpClient`.
|
||||||
|
|
||||||
|
```csharp
|
||||||
|
using FinalFactory.Rendezvous.Client;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
using HttpClient http = new()
|
||||||
|
{
|
||||||
|
BaseAddress = new Uri("https://rendezvous.example/"),
|
||||||
|
};
|
||||||
|
|
||||||
|
string publisherCredential = Environment.GetEnvironmentVariable(
|
||||||
|
"RENDEZVOUS_PUBLISHER_CREDENTIAL")
|
||||||
|
?? throw new InvalidOperationException("Publisher credential is not configured.");
|
||||||
|
CancellationToken cancellationToken = default;
|
||||||
|
RendezvousPublisherClient publisher = new(http);
|
||||||
|
RendezvousClientResult<PublishedSession> registered = await publisher.RegisterAsync(
|
||||||
|
new RegisterSessionRequest
|
||||||
|
{
|
||||||
|
IdempotencyKey = Guid.NewGuid().ToString("N"),
|
||||||
|
GameId = new("space-game"),
|
||||||
|
EnvironmentId = new("production"),
|
||||||
|
RegionId = new("eu-central"),
|
||||||
|
ProtocolVersion = 7,
|
||||||
|
BuildVersion = "1.0.0",
|
||||||
|
DisplayName = "My server",
|
||||||
|
Visibility = ListingVisibility.Public,
|
||||||
|
Capacity = new() { CurrentPlayers = 1, MaximumPlayers = 8 },
|
||||||
|
DedicatedFallback = new()
|
||||||
|
{
|
||||||
|
AddressFamily = AddressFamilyKind.Ipv4,
|
||||||
|
Address = "203.0.113.40",
|
||||||
|
Port = 7777,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
publisherCredential,
|
||||||
|
cancellationToken);
|
||||||
|
if (!registered.IsSuccess || registered.Value is null)
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException(
|
||||||
|
$"Registration failed: {registered.Error} ({registered.Message})");
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
Load `publisherCredential` from the game's deployment secret boundary; never
|
||||||
|
embed it in a client build or source control. A successful registration returns a
|
||||||
|
`PublishedSession` containing the lease and host-presence capabilities.
|
||||||
|
Send a periodic presence request from the host's gameplay `NetManager` using the
|
||||||
|
server-controlled refresh interval and the fixed-size native token:
|
||||||
|
|
||||||
|
```csharp
|
||||||
|
string presenceToken = NatPunchRequestTokenCodec.Encode(
|
||||||
|
NatPunchPeerRole.HostPresence,
|
||||||
|
session.HostPresenceHandle,
|
||||||
|
session.HostPresenceCapability);
|
||||||
|
gameplayNetManager.NatPunchModule.SendNatIntroduceRequest(mediator, presenceToken);
|
||||||
|
```
|
||||||
|
|
||||||
|
For direct connections, let the SDK drive those tokens from the same caller-owned
|
||||||
|
LiteNetLib socket that carries gameplay. Ask the routing listener to create the
|
||||||
|
bound manager, then configure and start that caller-owned manager yourself. The
|
||||||
|
factory does not open a socket, and synchronized events must remain enabled:
|
||||||
|
|
||||||
|
```csharp
|
||||||
|
RendezvousNetListener networkEvents = new();
|
||||||
|
NetManager gameplayNetManager = networkEvents.CreateManager();
|
||||||
|
if (!gameplayNetManager.Start(0))
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException("The gameplay UDP socket could not start.");
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
The host polls join invitations asynchronously; that method only queues a
|
||||||
|
snapshot and never calls the manager. `Poll()` is the sole SDK path that invokes
|
||||||
|
LiteNetLib and dispatches its synchronized callbacks. Call it once per game
|
||||||
|
frame on the thread that owns the manager:
|
||||||
|
|
||||||
|
```csharp
|
||||||
|
RendezvousJoinClient joins = new(http);
|
||||||
|
using RendezvousHostCoordinator host = new(
|
||||||
|
gameplayNetManager,
|
||||||
|
networkEvents,
|
||||||
|
mediatorEndPoint,
|
||||||
|
session,
|
||||||
|
joins);
|
||||||
|
|
||||||
|
// Run periodically from the game's normal async scheduling path.
|
||||||
|
await host.RefreshJoinAttemptsAsync(cancellationToken);
|
||||||
|
|
||||||
|
// Godot _Process, Update, or the equivalent main-thread frame callback.
|
||||||
|
host.Poll();
|
||||||
|
```
|
||||||
|
|
||||||
|
Do not also call `gameplayNetManager.PollEvents()` or
|
||||||
|
`gameplayNetManager.NatPunchModule.PollEvents()` when a coordinator owns polling.
|
||||||
|
The host coordinator refreshes host presence, punches for queued invitations,
|
||||||
|
validates the introduction ticket, and accepts the direct request. Subscribe to
|
||||||
|
`AttemptCompleted`; a `Connected` result is raised only after LiteNetLib reports
|
||||||
|
the accepted peer as connected. Register ordinary gameplay callbacks on
|
||||||
|
`networkEvents.GameplayEvents`; the routing listener reserves Rendezvous direct
|
||||||
|
requests for ticket validation and forwards every other callback normally.
|
||||||
|
|
||||||
|
The joining game first requests an attempt through the typed start API. It returns
|
||||||
|
exactly one issued attempt or one terminal service outcome, so service authority
|
||||||
|
is not confused with a later locally observed traversal failure:
|
||||||
|
|
||||||
|
```csharp
|
||||||
|
RendezvousConnectionStartResult start = await joins.CreateConnectionAttemptAsync(
|
||||||
|
createJoinRequest,
|
||||||
|
cancellationToken: cancellationToken);
|
||||||
|
if (start.Outcome is { } serviceOutcome)
|
||||||
|
{
|
||||||
|
ShowConnectionFailure(serviceOutcome.Kind, serviceOutcome.Category);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
CreateJoinAttemptResponse attempt = start.Attempt
|
||||||
|
?? throw new InvalidOperationException("The typed start result was invalid.");
|
||||||
|
using RendezvousClientCoordinator client = new(
|
||||||
|
gameplayNetManager,
|
||||||
|
networkEvents,
|
||||||
|
mediatorEndPoint,
|
||||||
|
attempt);
|
||||||
|
|
||||||
|
// Godot _Process, Update, or the equivalent main-thread frame callback.
|
||||||
|
client.Poll();
|
||||||
|
```
|
||||||
|
|
||||||
|
NAT introduction changes the client state to `Connecting`; it is not success.
|
||||||
|
Only a `Connected` outcome supplies `Peer`. Completion exposes a stable kind,
|
||||||
|
source, category, phase, and elapsed duration. The default HTTP silence, punch,
|
||||||
|
and direct-connect budgets are five, ten, and five seconds respectively; configure
|
||||||
|
them through `RendezvousClientOptions` and `RendezvousCoordinatorOptions` when a
|
||||||
|
game has measured reasons to do so. The signed attempt expiry is always the
|
||||||
|
absolute upper bound.
|
||||||
|
|
||||||
|
Call `Cancel()` and then `Poll()` for local cancellation, or
|
||||||
|
`CancelAsync(joins, cancellationToken)` to also revoke the service attempt.
|
||||||
|
Terminal client paths complete exactly once and release all event subscriptions,
|
||||||
|
so late packets and callbacks are inert. Disposing a coordinator never stops or
|
||||||
|
disposes the caller-owned manager and does not touch an in-flight peer; call
|
||||||
|
`Cancel()` followed by `Poll()` first when that peer must also be disconnected.
|
||||||
|
|
||||||
|
After terminal completion, reporting is explicit and safe to retry. It sends only
|
||||||
|
the authenticated outcome enum and a coarse elapsed bucket—never the endpoint,
|
||||||
|
exact duration, diagnostic text, metadata, or player identity:
|
||||||
|
|
||||||
|
```csharp
|
||||||
|
RendezvousClientResult<ReportConnectionOutcomeResponse> report =
|
||||||
|
await client.ReportOutcomeAsync(joins, cancellationToken);
|
||||||
|
```
|
||||||
|
|
||||||
|
An optional `DedicatedFallback` is copied from the authoritative listing into the
|
||||||
|
issued attempt and terminal outcome. A local deployment may replace it with
|
||||||
|
`RendezvousCoordinatorOptions.DedicatedFallbackOverride`. The SDK only returns
|
||||||
|
the endpoint; it never connects automatically. The game must explicitly decide
|
||||||
|
whether to use it and then connect and authenticate through its own gameplay
|
||||||
|
transport. If the outcome has no fallback, v1 offers no relay.
|
||||||
|
|
||||||
|
Lease renewal is explicit and caller-controlled:
|
||||||
|
|
||||||
|
```csharp
|
||||||
|
PublishedSession session = registered.Value;
|
||||||
|
await using SessionLeaseMaintainer maintainer = publisher.CreateLeaseMaintainer(
|
||||||
|
session,
|
||||||
|
publisherCredential);
|
||||||
|
LeaseMaintenanceResult stopped = await maintainer.RunAsync(cancellationToken);
|
||||||
|
```
|
||||||
|
|
||||||
|
Creating the maintainer does not start background work. Await its run and dispose
|
||||||
|
it when hosting stops. Use `IRendezvousPublisherClient` and
|
||||||
|
`IRendezvousSessionBrowserClient` as injection seams in game tests. The SDK disposes
|
||||||
|
the requests and responses it creates but never disposes the supplied `HttpClient`.
|
||||||
|
|
||||||
|
The host-side `ConnectionTicketValidator` is a bounded, thread-safe one-time gate.
|
||||||
|
Authorize only tickets delivered by the authenticated Rendezvous introduction,
|
||||||
|
then consume the exact ticket presented by the direct LiteNetLib connection:
|
||||||
|
|
||||||
|
```csharp
|
||||||
|
using ConnectionTicketValidator tickets = new();
|
||||||
|
tickets.TryAuthorize(attemptId, expectedTicket, expiresAt);
|
||||||
|
ConnectionTicketConsumptionResult admission = tickets.Consume(
|
||||||
|
attemptId,
|
||||||
|
presentedTicket);
|
||||||
|
```
|
||||||
|
|
||||||
|
An `Accepted` ticket authorizes only this connection attempt. The game must still
|
||||||
|
apply its own player identity, capacity, ban, and gameplay admission rules. Revoke
|
||||||
|
the attempt on cancellation and dispose the validator during host shutdown so its
|
||||||
|
keyed ticket digests are zeroed.
|
||||||
|
|
||||||
|
See the repository's ADR 0007 for HTTP ownership/retry semantics, ADR 0008 for
|
||||||
|
join-capability and connection-ticket security semantics, and ADR 0010 for typed
|
||||||
|
outcomes, deadlines, reporting, and caller-owned fallback.
|
||||||
@@ -0,0 +1,225 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Client;
|
||||||
|
|
||||||
|
public sealed class RendezvousClientResult<T>
|
||||||
|
{
|
||||||
|
internal RendezvousClientResult(
|
||||||
|
RendezvousErrorCode error,
|
||||||
|
T? value,
|
||||||
|
string message,
|
||||||
|
int? retryAfterSeconds)
|
||||||
|
{
|
||||||
|
Error = error;
|
||||||
|
Value = value;
|
||||||
|
Message = message;
|
||||||
|
RetryAfterSeconds = retryAfterSeconds;
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool IsSuccess => Error == RendezvousErrorCode.None;
|
||||||
|
public RendezvousErrorCode Error { get; }
|
||||||
|
public T? Value { get; }
|
||||||
|
public string Message { get; }
|
||||||
|
public int? RetryAfterSeconds { get; }
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
public static class RendezvousClientResult
|
||||||
|
{
|
||||||
|
public static RendezvousClientResult<T> Success<T>(T value) =>
|
||||||
|
value is null
|
||||||
|
? throw new ArgumentNullException(nameof(value))
|
||||||
|
: new(RendezvousErrorCode.None, value, string.Empty, null);
|
||||||
|
|
||||||
|
public static RendezvousClientResult<T> Failure<T>(
|
||||||
|
RendezvousErrorCode error,
|
||||||
|
string message,
|
||||||
|
int? retryAfterSeconds = null) =>
|
||||||
|
error == RendezvousErrorCode.None
|
||||||
|
? throw new ArgumentException("A failure requires a non-success error.", nameof(error))
|
||||||
|
: new(error, default, message ?? string.Empty, retryAfterSeconds);
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class PublishedSession
|
||||||
|
{
|
||||||
|
private readonly object _timingGate = new();
|
||||||
|
private DateTimeOffset _expiresAt;
|
||||||
|
private int _leaseRenewAfterSeconds;
|
||||||
|
|
||||||
|
internal PublishedSession(RegisterSessionResponse response)
|
||||||
|
{
|
||||||
|
ListingId = response.ListingId;
|
||||||
|
LeaseId = response.LeaseId;
|
||||||
|
LeaseToken = response.LeaseToken;
|
||||||
|
HostPresenceHandle = response.HostPresenceHandle;
|
||||||
|
HostPresenceCapability = response.HostPresenceCapability;
|
||||||
|
_expiresAt = response.ExpiresAt;
|
||||||
|
_leaseRenewAfterSeconds = response.LeaseRenewAfterSeconds;
|
||||||
|
HostPresenceRefreshAfterSeconds = response.HostPresenceRefreshAfterSeconds;
|
||||||
|
}
|
||||||
|
|
||||||
|
public SessionListingId ListingId { get; }
|
||||||
|
public LeaseId LeaseId { get; }
|
||||||
|
public string LeaseToken { get; }
|
||||||
|
public MediationHandle HostPresenceHandle { get; }
|
||||||
|
public string HostPresenceCapability { get; }
|
||||||
|
public DateTimeOffset ExpiresAt
|
||||||
|
{
|
||||||
|
get
|
||||||
|
{
|
||||||
|
lock (_timingGate)
|
||||||
|
{
|
||||||
|
return _expiresAt;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
internal set
|
||||||
|
{
|
||||||
|
lock (_timingGate)
|
||||||
|
{
|
||||||
|
_expiresAt = value;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public int LeaseRenewAfterSeconds
|
||||||
|
{
|
||||||
|
get
|
||||||
|
{
|
||||||
|
lock (_timingGate)
|
||||||
|
{
|
||||||
|
return _leaseRenewAfterSeconds;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
internal set
|
||||||
|
{
|
||||||
|
lock (_timingGate)
|
||||||
|
{
|
||||||
|
_leaseRenewAfterSeconds = value;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
public int HostPresenceRefreshAfterSeconds { get; }
|
||||||
|
|
||||||
|
public override string ToString() => $"[PublishedSession {ListingId}; credentials redacted]";
|
||||||
|
}
|
||||||
|
|
||||||
|
public interface IRendezvousPublisherClient
|
||||||
|
{
|
||||||
|
Task<RendezvousClientResult<PublishedSession>> RegisterAsync(
|
||||||
|
RegisterSessionRequest request,
|
||||||
|
string publisherCredential,
|
||||||
|
CancellationToken cancellationToken = default);
|
||||||
|
|
||||||
|
Task<RendezvousClientResult<RenewLeaseResponse>> RenewAsync(
|
||||||
|
PublishedSession session,
|
||||||
|
string publisherCredential,
|
||||||
|
CancellationToken cancellationToken = default);
|
||||||
|
|
||||||
|
Task<RendezvousClientResult<bool>> UpdateAsync(
|
||||||
|
PublishedSession session,
|
||||||
|
UpdateSessionRequest request,
|
||||||
|
string publisherCredential,
|
||||||
|
CancellationToken cancellationToken = default);
|
||||||
|
|
||||||
|
Task<RendezvousClientResult<bool>> DeregisterAsync(
|
||||||
|
PublishedSession session,
|
||||||
|
string publisherCredential,
|
||||||
|
CancellationToken cancellationToken = default);
|
||||||
|
}
|
||||||
|
|
||||||
|
public interface IRendezvousSessionBrowserClient
|
||||||
|
{
|
||||||
|
Task<RendezvousClientResult<BrowseSessionsResponse>> BrowseAsync(
|
||||||
|
BrowseSessionsRequest request,
|
||||||
|
CancellationToken cancellationToken = default);
|
||||||
|
|
||||||
|
Task<RendezvousClientResult<IReadOnlyList<SessionListing>>> BrowseAllAsync(
|
||||||
|
BrowseSessionsRequest request,
|
||||||
|
int maximumPages = 100,
|
||||||
|
CancellationToken cancellationToken = default);
|
||||||
|
|
||||||
|
Task<RendezvousClientResult<GetSessionResponse>> GetAsync(
|
||||||
|
SessionListingId listingId,
|
||||||
|
GameId gameId,
|
||||||
|
EnvironmentId environmentId,
|
||||||
|
uint protocolVersion,
|
||||||
|
CancellationToken cancellationToken = default);
|
||||||
|
}
|
||||||
|
|
||||||
|
public interface IRendezvousJoinClient
|
||||||
|
{
|
||||||
|
Task<RendezvousConnectionStartResult> CreateConnectionAttemptAsync(
|
||||||
|
CreateJoinAttemptRequest request,
|
||||||
|
NetworkEndpoint? dedicatedFallback = null,
|
||||||
|
CancellationToken cancellationToken = default);
|
||||||
|
|
||||||
|
Task<RendezvousClientResult<CreateJoinAttemptResponse>> CreateAsync(
|
||||||
|
CreateJoinAttemptRequest request,
|
||||||
|
CancellationToken cancellationToken = default);
|
||||||
|
|
||||||
|
Task<RendezvousClientResult<bool>> CancelAsync(
|
||||||
|
CreateJoinAttemptResponse attempt,
|
||||||
|
CancellationToken cancellationToken = default);
|
||||||
|
|
||||||
|
Task<RendezvousClientResult<BrowseHostJoinAttemptsResponse>> BrowseForHostAsync(
|
||||||
|
PublishedSession session,
|
||||||
|
int pageSize = ContractLimits.BrowserPageMaxItems,
|
||||||
|
string? cursor = null,
|
||||||
|
CancellationToken cancellationToken = default);
|
||||||
|
|
||||||
|
Task<RendezvousClientResult<IReadOnlyList<HostJoinAttempt>>> BrowseAllForHostAsync(
|
||||||
|
PublishedSession session,
|
||||||
|
int maximumPages = 100,
|
||||||
|
CancellationToken cancellationToken = default);
|
||||||
|
|
||||||
|
Task<RendezvousClientResult<ReportConnectionOutcomeResponse>> ReportOutcomeAsync(
|
||||||
|
CreateJoinAttemptResponse attempt,
|
||||||
|
RendezvousConnectionOutcome outcome,
|
||||||
|
CancellationToken cancellationToken = default);
|
||||||
|
}
|
||||||
|
|
||||||
|
public interface IRendezvousDelay
|
||||||
|
{
|
||||||
|
Task DelayAsync(TimeSpan delay, CancellationToken cancellationToken);
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class RendezvousClientOptions
|
||||||
|
{
|
||||||
|
public int MaximumSafeRetries { get; set; } = 2;
|
||||||
|
public TimeSpan RequestTimeout { get; set; } = TimeSpan.FromSeconds(5);
|
||||||
|
public TimeSpan InitialRetryDelay { get; set; } = TimeSpan.FromMilliseconds(200);
|
||||||
|
public TimeSpan MaximumRetryDelay { get; set; } = TimeSpan.FromSeconds(2);
|
||||||
|
public double JitterRatio { get; set; } = 0.2;
|
||||||
|
|
||||||
|
internal void Validate()
|
||||||
|
{
|
||||||
|
if (MaximumSafeRetries is < 0 or > 5
|
||||||
|
|| RequestTimeout <= TimeSpan.Zero
|
||||||
|
|| RequestTimeout > TimeSpan.FromSeconds(30)
|
||||||
|
|| InitialRetryDelay < TimeSpan.Zero
|
||||||
|
|| MaximumRetryDelay < InitialRetryDelay
|
||||||
|
|| MaximumRetryDelay > TimeSpan.FromSeconds(30)
|
||||||
|
|| JitterRatio is < 0 or > 1)
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(nameof(RendezvousClientOptions));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class SystemRendezvousDelay : IRendezvousDelay
|
||||||
|
{
|
||||||
|
public Task DelayAsync(TimeSpan delay, CancellationToken cancellationToken) =>
|
||||||
|
Task.Delay(delay, cancellationToken);
|
||||||
|
}
|
||||||
|
|
||||||
|
internal static class RendezvousEndpoint
|
||||||
|
{
|
||||||
|
internal static NetworkEndpoint? Copy(NetworkEndpoint? endpoint) => endpoint is null
|
||||||
|
? null
|
||||||
|
: new NetworkEndpoint
|
||||||
|
{
|
||||||
|
AddressFamily = endpoint.AddressFamily,
|
||||||
|
Address = endpoint.Address,
|
||||||
|
Port = endpoint.Port,
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,247 @@
|
|||||||
|
using System.Net;
|
||||||
|
using System.Net.Http.Headers;
|
||||||
|
using System.Security.Cryptography;
|
||||||
|
using System.Text;
|
||||||
|
using System.Text.Json;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Client;
|
||||||
|
|
||||||
|
internal sealed class RendezvousHttpTransport
|
||||||
|
{
|
||||||
|
private readonly HttpClient _httpClient;
|
||||||
|
private readonly RendezvousClientOptions _options;
|
||||||
|
private readonly IRendezvousDelay _delay;
|
||||||
|
|
||||||
|
internal RendezvousHttpTransport(
|
||||||
|
HttpClient httpClient,
|
||||||
|
RendezvousClientOptions? options,
|
||||||
|
IRendezvousDelay? delay)
|
||||||
|
{
|
||||||
|
_httpClient = httpClient ?? throw new ArgumentNullException(nameof(httpClient));
|
||||||
|
RendezvousClientOptions suppliedOptions = options ?? new RendezvousClientOptions();
|
||||||
|
suppliedOptions.Validate();
|
||||||
|
_options = new RendezvousClientOptions
|
||||||
|
{
|
||||||
|
MaximumSafeRetries = suppliedOptions.MaximumSafeRetries,
|
||||||
|
RequestTimeout = suppliedOptions.RequestTimeout,
|
||||||
|
InitialRetryDelay = suppliedOptions.InitialRetryDelay,
|
||||||
|
MaximumRetryDelay = suppliedOptions.MaximumRetryDelay,
|
||||||
|
JitterRatio = suppliedOptions.JitterRatio,
|
||||||
|
};
|
||||||
|
_delay = delay ?? new SystemRendezvousDelay();
|
||||||
|
}
|
||||||
|
|
||||||
|
internal async Task<RendezvousClientResult<T>> SendSafeAsync<T>(
|
||||||
|
Func<HttpRequestMessage> requestFactory,
|
||||||
|
CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
for (int attempt = 0; ; attempt++)
|
||||||
|
{
|
||||||
|
cancellationToken.ThrowIfCancellationRequested();
|
||||||
|
using CancellationTokenSource requestTimeout =
|
||||||
|
CancellationTokenSource.CreateLinkedTokenSource(cancellationToken);
|
||||||
|
requestTimeout.CancelAfter(_options.RequestTimeout);
|
||||||
|
CancellationToken requestCancellation = requestTimeout.Token;
|
||||||
|
try
|
||||||
|
{
|
||||||
|
using HttpRequestMessage request = requestFactory();
|
||||||
|
using HttpResponseMessage response = await _httpClient
|
||||||
|
.SendAsync(request, HttpCompletionOption.ResponseHeadersRead, requestCancellation)
|
||||||
|
.ConfigureAwait(false);
|
||||||
|
if (response.IsSuccessStatusCode)
|
||||||
|
{
|
||||||
|
if (typeof(T) == typeof(bool) && response.StatusCode == HttpStatusCode.NoContent)
|
||||||
|
{
|
||||||
|
return RendezvousClientResult.Success((T)(object)true);
|
||||||
|
}
|
||||||
|
|
||||||
|
byte[] payload;
|
||||||
|
try
|
||||||
|
{
|
||||||
|
payload = await ReadBoundedAsync(response.Content, requestCancellation)
|
||||||
|
.ConfigureAwait(false);
|
||||||
|
}
|
||||||
|
catch (InvalidDataException)
|
||||||
|
{
|
||||||
|
return RendezvousClientResult.Failure<T>(
|
||||||
|
RendezvousErrorCode.InternalError,
|
||||||
|
"The service returned an oversized success response.");
|
||||||
|
}
|
||||||
|
|
||||||
|
T? value;
|
||||||
|
try
|
||||||
|
{
|
||||||
|
value = JsonSerializer.Deserialize<T>(payload, ContractJson.Options);
|
||||||
|
}
|
||||||
|
catch (JsonException)
|
||||||
|
{
|
||||||
|
value = default;
|
||||||
|
}
|
||||||
|
|
||||||
|
return value is null
|
||||||
|
? RendezvousClientResult.Failure<T>(
|
||||||
|
RendezvousErrorCode.InternalError,
|
||||||
|
"The service returned an invalid success response.")
|
||||||
|
: RendezvousClientResult.Success(value);
|
||||||
|
}
|
||||||
|
|
||||||
|
ApiError error = await ReadErrorAsync(response, requestCancellation).ConfigureAwait(false);
|
||||||
|
int? retryAfter = error.RetryAfterSeconds ?? GetRetryAfterSeconds(response.Headers.RetryAfter);
|
||||||
|
if (attempt < _options.MaximumSafeRetries && IsTransient(error.Code))
|
||||||
|
{
|
||||||
|
await _delay.DelayAsync(
|
||||||
|
GetRetryDelay(attempt, retryAfter),
|
||||||
|
cancellationToken).ConfigureAwait(false);
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
return RendezvousClientResult.Failure<T>(error.Code, error.Message, retryAfter);
|
||||||
|
}
|
||||||
|
catch (Exception exception) when (
|
||||||
|
IsTransientTransportFailure(exception, cancellationToken)
|
||||||
|
&& attempt < _options.MaximumSafeRetries)
|
||||||
|
{
|
||||||
|
await _delay.DelayAsync(GetRetryDelay(attempt, null), cancellationToken)
|
||||||
|
.ConfigureAwait(false);
|
||||||
|
}
|
||||||
|
catch (Exception exception) when (IsTransientTransportFailure(exception, cancellationToken))
|
||||||
|
{
|
||||||
|
return RendezvousClientResult.Failure<T>(
|
||||||
|
RendezvousErrorCode.ServiceUnavailable,
|
||||||
|
"The Rendezvous service did not return a valid response.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
internal static HttpRequestMessage JsonRequest<T>(
|
||||||
|
HttpMethod method,
|
||||||
|
string uri,
|
||||||
|
T body,
|
||||||
|
string? publisherCredential = null)
|
||||||
|
{
|
||||||
|
HttpRequestMessage request = new(method, uri)
|
||||||
|
{
|
||||||
|
Content = new StringContent(
|
||||||
|
JsonSerializer.Serialize(body, ContractJson.Options),
|
||||||
|
Encoding.UTF8,
|
||||||
|
"application/json"),
|
||||||
|
};
|
||||||
|
if (publisherCredential is not null)
|
||||||
|
{
|
||||||
|
request.Headers.Authorization = new AuthenticationHeaderValue(
|
||||||
|
"Bearer",
|
||||||
|
RequireCredential(publisherCredential));
|
||||||
|
}
|
||||||
|
|
||||||
|
return request;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal static string RequireCredential(string credential) =>
|
||||||
|
!string.IsNullOrWhiteSpace(credential)
|
||||||
|
? credential
|
||||||
|
: throw new ArgumentException("A publisher credential is required.", nameof(credential));
|
||||||
|
|
||||||
|
private static async Task<ApiError> ReadErrorAsync(
|
||||||
|
HttpResponseMessage response,
|
||||||
|
CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
try
|
||||||
|
{
|
||||||
|
byte[] payload = await ReadBoundedAsync(response.Content, cancellationToken)
|
||||||
|
.ConfigureAwait(false);
|
||||||
|
ApiError? error = JsonSerializer.Deserialize<ApiError>(payload, ContractJson.Options);
|
||||||
|
return error is not null && error.Code != RendezvousErrorCode.None
|
||||||
|
? error
|
||||||
|
: FallbackError(response.StatusCode);
|
||||||
|
}
|
||||||
|
catch (Exception exception) when (exception is JsonException or InvalidDataException)
|
||||||
|
{
|
||||||
|
return FallbackError(response.StatusCode);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static async Task<byte[]> ReadBoundedAsync(
|
||||||
|
HttpContent content,
|
||||||
|
CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
using Stream source = await content.ReadAsStreamAsync().ConfigureAwait(false);
|
||||||
|
using MemoryStream destination = new();
|
||||||
|
byte[] buffer = new byte[8192];
|
||||||
|
while (true)
|
||||||
|
{
|
||||||
|
int read = await source.ReadAsync(buffer.AsMemory(), cancellationToken)
|
||||||
|
.ConfigureAwait(false);
|
||||||
|
if (read == 0)
|
||||||
|
{
|
||||||
|
return destination.ToArray();
|
||||||
|
}
|
||||||
|
|
||||||
|
if (destination.Length + read > ContractLimits.BrowserResponseMaxBytes)
|
||||||
|
{
|
||||||
|
throw new InvalidDataException("The service response exceeded the SDK limit.");
|
||||||
|
}
|
||||||
|
|
||||||
|
await destination.WriteAsync(buffer.AsMemory(0, read), cancellationToken)
|
||||||
|
.ConfigureAwait(false);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private TimeSpan GetRetryDelay(int attempt, int? retryAfterSeconds)
|
||||||
|
{
|
||||||
|
TimeSpan basis = retryAfterSeconds.HasValue
|
||||||
|
? TimeSpan.FromSeconds(Math.Max(0, retryAfterSeconds.Value))
|
||||||
|
: TimeSpan.FromMilliseconds(
|
||||||
|
_options.InitialRetryDelay.TotalMilliseconds * Math.Pow(2, attempt));
|
||||||
|
double bounded = Math.Min(basis.TotalMilliseconds, _options.MaximumRetryDelay.TotalMilliseconds);
|
||||||
|
if (_options.JitterRatio == 0 || bounded == 0)
|
||||||
|
{
|
||||||
|
return TimeSpan.FromMilliseconds(bounded);
|
||||||
|
}
|
||||||
|
|
||||||
|
byte[] random = new byte[1];
|
||||||
|
RandomNumberGenerator.Fill(random);
|
||||||
|
double unit = random[0] / 255d;
|
||||||
|
double multiplier = 1 - _options.JitterRatio + (2 * _options.JitterRatio * unit);
|
||||||
|
return TimeSpan.FromMilliseconds(Math.Min(
|
||||||
|
bounded * multiplier,
|
||||||
|
_options.MaximumRetryDelay.TotalMilliseconds));
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool IsTransient(RendezvousErrorCode code) => code is
|
||||||
|
RendezvousErrorCode.RateLimited
|
||||||
|
or RendezvousErrorCode.CapacityExceeded
|
||||||
|
or RendezvousErrorCode.ServiceUnavailable;
|
||||||
|
|
||||||
|
private static bool IsTransientTransportFailure(
|
||||||
|
Exception exception,
|
||||||
|
CancellationToken callerCancellation) =>
|
||||||
|
exception is HttpRequestException
|
||||||
|
or IOException
|
||||||
|
|| exception is OperationCanceledException && !callerCancellation.IsCancellationRequested;
|
||||||
|
|
||||||
|
private static int? GetRetryAfterSeconds(RetryConditionHeaderValue? retryAfter) =>
|
||||||
|
retryAfter?.Delta is TimeSpan delta
|
||||||
|
? Math.Max(0, (int)Math.Ceiling(delta.TotalSeconds))
|
||||||
|
: null;
|
||||||
|
|
||||||
|
private static ApiError FallbackError(HttpStatusCode statusCode) => new()
|
||||||
|
{
|
||||||
|
Code = statusCode switch
|
||||||
|
{
|
||||||
|
HttpStatusCode.BadRequest => RendezvousErrorCode.InvalidRequest,
|
||||||
|
HttpStatusCode.Unauthorized => RendezvousErrorCode.AuthenticationRequired,
|
||||||
|
HttpStatusCode.Forbidden => RendezvousErrorCode.Forbidden,
|
||||||
|
HttpStatusCode.NotFound => RendezvousErrorCode.NotFound,
|
||||||
|
HttpStatusCode.Conflict => RendezvousErrorCode.Conflict,
|
||||||
|
HttpStatusCode.Gone => RendezvousErrorCode.Expired,
|
||||||
|
HttpStatusCode.TooManyRequests => RendezvousErrorCode.RateLimited,
|
||||||
|
HttpStatusCode.RequestTimeout => RendezvousErrorCode.ServiceUnavailable,
|
||||||
|
HttpStatusCode.BadGateway => RendezvousErrorCode.ServiceUnavailable,
|
||||||
|
HttpStatusCode.ServiceUnavailable => RendezvousErrorCode.ServiceUnavailable,
|
||||||
|
HttpStatusCode.GatewayTimeout => RendezvousErrorCode.ServiceUnavailable,
|
||||||
|
_ => RendezvousErrorCode.InternalError,
|
||||||
|
},
|
||||||
|
Message = "The service returned an error without a valid Rendezvous envelope.",
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,154 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Client;
|
||||||
|
|
||||||
|
public sealed class RendezvousPublisherClient : IRendezvousPublisherClient
|
||||||
|
{
|
||||||
|
private readonly RendezvousHttpTransport _transport;
|
||||||
|
private readonly IRendezvousDelay _delay;
|
||||||
|
|
||||||
|
public RendezvousPublisherClient(
|
||||||
|
HttpClient httpClient,
|
||||||
|
RendezvousClientOptions? options = null,
|
||||||
|
IRendezvousDelay? delay = null)
|
||||||
|
{
|
||||||
|
_delay = delay ?? new SystemRendezvousDelay();
|
||||||
|
_transport = new(httpClient, options, _delay);
|
||||||
|
}
|
||||||
|
|
||||||
|
public async Task<RendezvousClientResult<PublishedSession>> RegisterAsync(
|
||||||
|
RegisterSessionRequest request,
|
||||||
|
string publisherCredential,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
if (request is null)
|
||||||
|
{
|
||||||
|
throw new ArgumentNullException(nameof(request));
|
||||||
|
}
|
||||||
|
|
||||||
|
RegisterSessionRequest body = CopyRegistration(request);
|
||||||
|
RendezvousClientResult<RegisterSessionResponse> result = await _transport.SendSafeAsync<RegisterSessionResponse>(
|
||||||
|
() => RendezvousHttpTransport.JsonRequest(HttpMethod.Post, "v1/sessions", body, publisherCredential),
|
||||||
|
cancellationToken).ConfigureAwait(false);
|
||||||
|
return result.IsSuccess && result.Value is not null
|
||||||
|
? RendezvousClientResult.Success(new PublishedSession(result.Value))
|
||||||
|
: RendezvousClientResult.Failure<PublishedSession>(
|
||||||
|
result.Error,
|
||||||
|
result.Message,
|
||||||
|
result.RetryAfterSeconds);
|
||||||
|
}
|
||||||
|
|
||||||
|
public async Task<RendezvousClientResult<RenewLeaseResponse>> RenewAsync(
|
||||||
|
PublishedSession session,
|
||||||
|
string publisherCredential,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
if (session is null)
|
||||||
|
{
|
||||||
|
throw new ArgumentNullException(nameof(session));
|
||||||
|
}
|
||||||
|
|
||||||
|
RendezvousClientResult<RenewLeaseResponse> result = await _transport.SendSafeAsync<RenewLeaseResponse>(
|
||||||
|
() => RendezvousHttpTransport.JsonRequest(
|
||||||
|
HttpMethod.Post,
|
||||||
|
$"v1/sessions/{session.ListingId}/renew",
|
||||||
|
new RenewLeaseRequest { LeaseToken = session.LeaseToken },
|
||||||
|
publisherCredential),
|
||||||
|
cancellationToken).ConfigureAwait(false);
|
||||||
|
if (result.IsSuccess && result.Value is not null)
|
||||||
|
{
|
||||||
|
session.ExpiresAt = result.Value.ExpiresAt;
|
||||||
|
session.LeaseRenewAfterSeconds = result.Value.RenewAfterSeconds;
|
||||||
|
}
|
||||||
|
|
||||||
|
return result;
|
||||||
|
}
|
||||||
|
|
||||||
|
public Task<RendezvousClientResult<bool>> UpdateAsync(
|
||||||
|
PublishedSession session,
|
||||||
|
UpdateSessionRequest request,
|
||||||
|
string publisherCredential,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
if (session is null)
|
||||||
|
{
|
||||||
|
throw new ArgumentNullException(nameof(session));
|
||||||
|
}
|
||||||
|
|
||||||
|
if (request is null)
|
||||||
|
{
|
||||||
|
throw new ArgumentNullException(nameof(request));
|
||||||
|
}
|
||||||
|
|
||||||
|
UpdateSessionRequest body = new()
|
||||||
|
{
|
||||||
|
ContractVersion = request.ContractVersion,
|
||||||
|
LeaseToken = session.LeaseToken,
|
||||||
|
BuildVersion = request.BuildVersion,
|
||||||
|
DisplayName = request.DisplayName,
|
||||||
|
Capacity = CopyCapacity(request.Capacity),
|
||||||
|
Metadata = CopyMetadata(request.Metadata),
|
||||||
|
DedicatedFallback = RendezvousEndpoint.Copy(request.DedicatedFallback),
|
||||||
|
};
|
||||||
|
return _transport.SendSafeAsync<bool>(
|
||||||
|
() => RendezvousHttpTransport.JsonRequest(
|
||||||
|
HttpMethod.Put,
|
||||||
|
$"v1/sessions/{session.ListingId}",
|
||||||
|
body,
|
||||||
|
publisherCredential),
|
||||||
|
cancellationToken);
|
||||||
|
}
|
||||||
|
|
||||||
|
public Task<RendezvousClientResult<bool>> DeregisterAsync(
|
||||||
|
PublishedSession session,
|
||||||
|
string publisherCredential,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
if (session is null)
|
||||||
|
{
|
||||||
|
throw new ArgumentNullException(nameof(session));
|
||||||
|
}
|
||||||
|
|
||||||
|
return _transport.SendSafeAsync<bool>(
|
||||||
|
() => RendezvousHttpTransport.JsonRequest(
|
||||||
|
HttpMethod.Delete,
|
||||||
|
$"v1/sessions/{session.ListingId}",
|
||||||
|
new DeleteSessionRequest { LeaseToken = session.LeaseToken },
|
||||||
|
publisherCredential),
|
||||||
|
cancellationToken);
|
||||||
|
}
|
||||||
|
|
||||||
|
public SessionLeaseMaintainer CreateLeaseMaintainer(
|
||||||
|
PublishedSession session,
|
||||||
|
string publisherCredential) => new(
|
||||||
|
this,
|
||||||
|
session ?? throw new ArgumentNullException(nameof(session)),
|
||||||
|
RendezvousHttpTransport.RequireCredential(publisherCredential),
|
||||||
|
_delay);
|
||||||
|
|
||||||
|
private static RegisterSessionRequest CopyRegistration(RegisterSessionRequest request) => new()
|
||||||
|
{
|
||||||
|
ContractVersion = request.ContractVersion,
|
||||||
|
IdempotencyKey = request.IdempotencyKey,
|
||||||
|
GameId = request.GameId,
|
||||||
|
EnvironmentId = request.EnvironmentId,
|
||||||
|
RegionId = request.RegionId,
|
||||||
|
ProtocolVersion = request.ProtocolVersion,
|
||||||
|
BuildVersion = request.BuildVersion,
|
||||||
|
DisplayName = request.DisplayName,
|
||||||
|
Visibility = request.Visibility,
|
||||||
|
Capacity = CopyCapacity(request.Capacity),
|
||||||
|
Metadata = CopyMetadata(request.Metadata),
|
||||||
|
DedicatedFallback = RendezvousEndpoint.Copy(request.DedicatedFallback),
|
||||||
|
};
|
||||||
|
|
||||||
|
private static SessionCapacity CopyCapacity(SessionCapacity capacity) => new()
|
||||||
|
{
|
||||||
|
CurrentPlayers = capacity.CurrentPlayers,
|
||||||
|
MaximumPlayers = capacity.MaximumPlayers,
|
||||||
|
};
|
||||||
|
|
||||||
|
private static Dictionary<string, string> CopyMetadata(Dictionary<string, string> metadata) =>
|
||||||
|
new(metadata, StringComparer.Ordinal);
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1,110 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Client;
|
||||||
|
|
||||||
|
public sealed class RendezvousSessionBrowserClient : IRendezvousSessionBrowserClient
|
||||||
|
{
|
||||||
|
private readonly RendezvousHttpTransport _transport;
|
||||||
|
|
||||||
|
public RendezvousSessionBrowserClient(
|
||||||
|
HttpClient httpClient,
|
||||||
|
RendezvousClientOptions? options = null,
|
||||||
|
IRendezvousDelay? delay = null)
|
||||||
|
{
|
||||||
|
_transport = new(httpClient, options, delay);
|
||||||
|
}
|
||||||
|
|
||||||
|
public Task<RendezvousClientResult<BrowseSessionsResponse>> BrowseAsync(
|
||||||
|
BrowseSessionsRequest request,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
if (request is null)
|
||||||
|
{
|
||||||
|
throw new ArgumentNullException(nameof(request));
|
||||||
|
}
|
||||||
|
|
||||||
|
string query = $"v1/sessions?contractVersion={request.ContractVersion}"
|
||||||
|
+ $"&gameId={Escape(request.GameId.Value)}"
|
||||||
|
+ $"&environmentId={Escape(request.EnvironmentId.Value)}"
|
||||||
|
+ $"&protocolVersion={request.ProtocolVersion}"
|
||||||
|
+ $"&pageSize={request.PageSize}"
|
||||||
|
+ $"&excludeFull={request.ExcludeFull.ToString().ToLowerInvariant()}"
|
||||||
|
+ (request.RegionId.HasValue ? $"®ionId={Escape(request.RegionId.Value.Value)}" : string.Empty)
|
||||||
|
+ (request.Cursor is not null ? $"&cursor={Escape(request.Cursor)}" : string.Empty);
|
||||||
|
return _transport.SendSafeAsync<BrowseSessionsResponse>(
|
||||||
|
() => new HttpRequestMessage(HttpMethod.Get, query),
|
||||||
|
cancellationToken);
|
||||||
|
}
|
||||||
|
|
||||||
|
public async Task<RendezvousClientResult<IReadOnlyList<SessionListing>>> BrowseAllAsync(
|
||||||
|
BrowseSessionsRequest request,
|
||||||
|
int maximumPages = 100,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
if (request is null)
|
||||||
|
{
|
||||||
|
throw new ArgumentNullException(nameof(request));
|
||||||
|
}
|
||||||
|
|
||||||
|
if (maximumPages is < 1 or > 1000)
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(nameof(maximumPages));
|
||||||
|
}
|
||||||
|
|
||||||
|
List<SessionListing> items = [];
|
||||||
|
string? cursor = request.Cursor;
|
||||||
|
for (int page = 0; page < maximumPages; page++)
|
||||||
|
{
|
||||||
|
BrowseSessionsRequest pageRequest = new()
|
||||||
|
{
|
||||||
|
ContractVersion = request.ContractVersion,
|
||||||
|
GameId = request.GameId,
|
||||||
|
EnvironmentId = request.EnvironmentId,
|
||||||
|
ProtocolVersion = request.ProtocolVersion,
|
||||||
|
RegionId = request.RegionId,
|
||||||
|
PageSize = request.PageSize,
|
||||||
|
ExcludeFull = request.ExcludeFull,
|
||||||
|
Cursor = cursor,
|
||||||
|
};
|
||||||
|
RendezvousClientResult<BrowseSessionsResponse> result = await BrowseAsync(
|
||||||
|
pageRequest,
|
||||||
|
cancellationToken).ConfigureAwait(false);
|
||||||
|
if (!result.IsSuccess || result.Value is null)
|
||||||
|
{
|
||||||
|
return RendezvousClientResult.Failure<IReadOnlyList<SessionListing>>(
|
||||||
|
result.Error,
|
||||||
|
result.Message,
|
||||||
|
result.RetryAfterSeconds);
|
||||||
|
}
|
||||||
|
|
||||||
|
items.AddRange(result.Value.Items);
|
||||||
|
cursor = result.Value.NextCursor;
|
||||||
|
if (string.IsNullOrEmpty(cursor))
|
||||||
|
{
|
||||||
|
return RendezvousClientResult.Success<IReadOnlyList<SessionListing>>(items.AsReadOnly());
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return RendezvousClientResult.Failure<IReadOnlyList<SessionListing>>(
|
||||||
|
RendezvousErrorCode.CapacityExceeded,
|
||||||
|
$"Browsing exceeded the configured {maximumPages}-page limit.");
|
||||||
|
}
|
||||||
|
|
||||||
|
public Task<RendezvousClientResult<GetSessionResponse>> GetAsync(
|
||||||
|
SessionListingId listingId,
|
||||||
|
GameId gameId,
|
||||||
|
EnvironmentId environmentId,
|
||||||
|
uint protocolVersion,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
string query = $"v1/sessions/{listingId}?contractVersion={ContractLimits.ContractVersion}"
|
||||||
|
+ $"&gameId={Escape(gameId.Value)}"
|
||||||
|
+ $"&environmentId={Escape(environmentId.Value)}"
|
||||||
|
+ $"&protocolVersion={protocolVersion}";
|
||||||
|
return _transport.SendSafeAsync<GetSessionResponse>(
|
||||||
|
() => new HttpRequestMessage(HttpMethod.Get, query),
|
||||||
|
cancellationToken);
|
||||||
|
}
|
||||||
|
|
||||||
|
private static string Escape(string value) => Uri.EscapeDataString(value ?? string.Empty);
|
||||||
|
}
|
||||||
@@ -0,0 +1,150 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Client;
|
||||||
|
|
||||||
|
public enum LeaseMaintenanceStopReason
|
||||||
|
{
|
||||||
|
Cancelled = 1,
|
||||||
|
Disposed = 2,
|
||||||
|
LeaseLost = 3,
|
||||||
|
Failed = 4,
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class LeaseMaintenanceResult
|
||||||
|
{
|
||||||
|
internal LeaseMaintenanceResult(LeaseMaintenanceStopReason reason, RendezvousErrorCode error)
|
||||||
|
{
|
||||||
|
Reason = reason;
|
||||||
|
Error = error;
|
||||||
|
}
|
||||||
|
|
||||||
|
public LeaseMaintenanceStopReason Reason { get; }
|
||||||
|
public RendezvousErrorCode Error { get; }
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class SessionLeaseMaintainer : IAsyncDisposable
|
||||||
|
{
|
||||||
|
private readonly object _gate = new();
|
||||||
|
private readonly IRendezvousPublisherClient _publisher;
|
||||||
|
private readonly PublishedSession _session;
|
||||||
|
private readonly string _publisherCredential;
|
||||||
|
private readonly IRendezvousDelay _delay;
|
||||||
|
private readonly CancellationTokenSource _disposeCancellation = new();
|
||||||
|
private Task<LeaseMaintenanceResult>? _activeRun;
|
||||||
|
private Task? _disposeTask;
|
||||||
|
private bool _disposed;
|
||||||
|
|
||||||
|
internal SessionLeaseMaintainer(
|
||||||
|
IRendezvousPublisherClient publisher,
|
||||||
|
PublishedSession session,
|
||||||
|
string publisherCredential,
|
||||||
|
IRendezvousDelay? delay = null)
|
||||||
|
{
|
||||||
|
_publisher = publisher;
|
||||||
|
_session = session;
|
||||||
|
_publisherCredential = publisherCredential;
|
||||||
|
_delay = delay ?? new SystemRendezvousDelay();
|
||||||
|
}
|
||||||
|
|
||||||
|
public event EventHandler? LeaseLost;
|
||||||
|
|
||||||
|
public Task<LeaseMaintenanceResult> RunAsync(CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
lock (_gate)
|
||||||
|
{
|
||||||
|
if (_disposed)
|
||||||
|
{
|
||||||
|
throw new ObjectDisposedException(nameof(SessionLeaseMaintainer));
|
||||||
|
}
|
||||||
|
if (_activeRun is not null)
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException("Lease maintenance is already running.");
|
||||||
|
}
|
||||||
|
|
||||||
|
_activeRun = RunCoreAsync(cancellationToken);
|
||||||
|
return _activeRun;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public ValueTask DisposeAsync()
|
||||||
|
{
|
||||||
|
lock (_gate)
|
||||||
|
{
|
||||||
|
if (_disposeTask is not null)
|
||||||
|
{
|
||||||
|
return new(_disposeTask);
|
||||||
|
}
|
||||||
|
|
||||||
|
_disposed = true;
|
||||||
|
_disposeCancellation.Cancel();
|
||||||
|
_disposeTask = FinishDisposeAsync(_activeRun);
|
||||||
|
return new(_disposeTask);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private async Task FinishDisposeAsync(Task<LeaseMaintenanceResult>? active)
|
||||||
|
{
|
||||||
|
try
|
||||||
|
{
|
||||||
|
if (active is not null)
|
||||||
|
{
|
||||||
|
await active.ConfigureAwait(false);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
_disposeCancellation.Dispose();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private async Task<LeaseMaintenanceResult> RunCoreAsync(CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
await Task.Yield();
|
||||||
|
using CancellationTokenSource linked = CancellationTokenSource.CreateLinkedTokenSource(
|
||||||
|
cancellationToken,
|
||||||
|
_disposeCancellation.Token);
|
||||||
|
try
|
||||||
|
{
|
||||||
|
while (true)
|
||||||
|
{
|
||||||
|
await _delay.DelayAsync(
|
||||||
|
TimeSpan.FromSeconds(Math.Max(1, _session.LeaseRenewAfterSeconds)),
|
||||||
|
linked.Token).ConfigureAwait(false);
|
||||||
|
RendezvousClientResult<RenewLeaseResponse> renewed = await _publisher.RenewAsync(
|
||||||
|
_session,
|
||||||
|
_publisherCredential,
|
||||||
|
linked.Token).ConfigureAwait(false);
|
||||||
|
if (renewed.IsSuccess)
|
||||||
|
{
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (renewed.Error is RendezvousErrorCode.NotFound
|
||||||
|
or RendezvousErrorCode.Expired
|
||||||
|
or RendezvousErrorCode.Forbidden
|
||||||
|
or RendezvousErrorCode.AuthenticationRequired)
|
||||||
|
{
|
||||||
|
LeaseLost?.Invoke(this, EventArgs.Empty);
|
||||||
|
return new(LeaseMaintenanceStopReason.LeaseLost, renewed.Error);
|
||||||
|
}
|
||||||
|
|
||||||
|
return new(LeaseMaintenanceStopReason.Failed, renewed.Error);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
catch (OperationCanceledException) when (linked.IsCancellationRequested)
|
||||||
|
{
|
||||||
|
return new(
|
||||||
|
_disposeCancellation.IsCancellationRequested
|
||||||
|
? LeaseMaintenanceStopReason.Disposed
|
||||||
|
: LeaseMaintenanceStopReason.Cancelled,
|
||||||
|
RendezvousErrorCode.None);
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
lock (_gate)
|
||||||
|
{
|
||||||
|
_activeRun = null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,83 @@
|
|||||||
|
using System.Text;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Client;
|
||||||
|
|
||||||
|
public sealed class DirectConnectionRequest
|
||||||
|
{
|
||||||
|
public JoinAttemptId AttemptId { get; set; }
|
||||||
|
public string ConnectionTicket { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
public override string ToString() =>
|
||||||
|
$"[DirectConnectionRequest {AttemptId}; ticket redacted]";
|
||||||
|
}
|
||||||
|
|
||||||
|
public static class DirectConnectionRequestCodec
|
||||||
|
{
|
||||||
|
public const int EncodedLength = 63;
|
||||||
|
|
||||||
|
private const int MagicLength = 4;
|
||||||
|
private const int AttemptIdLength = 16;
|
||||||
|
private const int TicketLength = ContractLimits.DerivedCredentialCharacters;
|
||||||
|
private static readonly byte[] Magic = [(byte)'R', (byte)'V', (byte)'D', (byte)'1'];
|
||||||
|
|
||||||
|
public static bool IsRendezvousRequest(ReadOnlySpan<byte> encoded) =>
|
||||||
|
encoded.Length >= MagicLength && encoded[..MagicLength].SequenceEqual(Magic);
|
||||||
|
|
||||||
|
public static byte[] Encode(JoinAttemptId attemptId, string connectionTicket)
|
||||||
|
{
|
||||||
|
if (attemptId.Value == Guid.Empty
|
||||||
|
|| connectionTicket is null
|
||||||
|
|| connectionTicket.Length != TicketLength
|
||||||
|
|| !ContractValidation.IsConnectionTicketValid(connectionTicket))
|
||||||
|
{
|
||||||
|
throw new ArgumentException("The direct connection request fields are invalid.");
|
||||||
|
}
|
||||||
|
|
||||||
|
byte[] encoded = new byte[EncodedLength];
|
||||||
|
Magic.CopyTo(encoded, 0);
|
||||||
|
if (!attemptId.Value.TryWriteBytes(encoded.AsSpan(MagicLength, AttemptIdLength)))
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException("The join attempt identifier could not be encoded.");
|
||||||
|
}
|
||||||
|
|
||||||
|
Encoding.ASCII.GetBytes(
|
||||||
|
connectionTicket,
|
||||||
|
0,
|
||||||
|
connectionTicket.Length,
|
||||||
|
encoded,
|
||||||
|
MagicLength + AttemptIdLength);
|
||||||
|
return encoded;
|
||||||
|
}
|
||||||
|
|
||||||
|
public static bool TryDecode(
|
||||||
|
ReadOnlySpan<byte> encoded,
|
||||||
|
out DirectConnectionRequest? request)
|
||||||
|
{
|
||||||
|
request = null;
|
||||||
|
if (encoded.Length != EncodedLength
|
||||||
|
|| !encoded[..MagicLength].SequenceEqual(Magic))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
Guid attemptId = new(encoded.Slice(MagicLength, AttemptIdLength));
|
||||||
|
if (attemptId == Guid.Empty)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
string ticket = Encoding.ASCII.GetString(encoded[(MagicLength + AttemptIdLength)..]);
|
||||||
|
if (!ContractValidation.IsConnectionTicketValid(ticket))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
request = new DirectConnectionRequest
|
||||||
|
{
|
||||||
|
AttemptId = new JoinAttemptId(attemptId),
|
||||||
|
ConnectionTicket = ticket,
|
||||||
|
};
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,462 @@
|
|||||||
|
using System.Net;
|
||||||
|
using System.Net.Sockets;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using LiteNetLib;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Client;
|
||||||
|
|
||||||
|
public sealed class RendezvousClientCoordinator : IDisposable
|
||||||
|
{
|
||||||
|
private readonly NetManager _manager;
|
||||||
|
private readonly RendezvousNetListener _networkEvents;
|
||||||
|
private readonly EventBasedNatPunchListener _punchEvents;
|
||||||
|
private readonly IPEndPoint _mediator;
|
||||||
|
private readonly CreateJoinAttemptResponse _attempt;
|
||||||
|
private readonly IRendezvousCoordinatorClock _clock;
|
||||||
|
private readonly RendezvousCoordinatorOptions _options;
|
||||||
|
private readonly RendezvousPunchRetrySchedule _retry;
|
||||||
|
private readonly object _completionGate = new();
|
||||||
|
private readonly TimeSpan _startedAt;
|
||||||
|
private readonly TimeSpan _attemptDeadline;
|
||||||
|
private readonly TimeSpan _punchDeadline;
|
||||||
|
private readonly NetworkEndpoint? _dedicatedFallback;
|
||||||
|
private NetPeer? _connectingPeer;
|
||||||
|
private IPEndPoint? _directEndpoint;
|
||||||
|
private TimeSpan? _directDeadline;
|
||||||
|
private RendezvousConnectionOutcome? _outcome;
|
||||||
|
private bool _cancelRequested;
|
||||||
|
private int _polling;
|
||||||
|
private bool _subscriptionsReleased;
|
||||||
|
private int _disposed;
|
||||||
|
|
||||||
|
public RendezvousClientCoordinator(
|
||||||
|
NetManager manager,
|
||||||
|
RendezvousNetListener networkEvents,
|
||||||
|
IPEndPoint mediator,
|
||||||
|
CreateJoinAttemptResponse attempt,
|
||||||
|
RendezvousCoordinatorOptions? options = null)
|
||||||
|
: this(
|
||||||
|
manager,
|
||||||
|
networkEvents,
|
||||||
|
mediator,
|
||||||
|
attempt,
|
||||||
|
options,
|
||||||
|
new SystemRendezvousCoordinatorClock())
|
||||||
|
{
|
||||||
|
}
|
||||||
|
|
||||||
|
internal RendezvousClientCoordinator(
|
||||||
|
NetManager manager,
|
||||||
|
RendezvousNetListener networkEvents,
|
||||||
|
IPEndPoint mediator,
|
||||||
|
CreateJoinAttemptResponse attempt,
|
||||||
|
RendezvousCoordinatorOptions? options,
|
||||||
|
IRendezvousCoordinatorClock clock)
|
||||||
|
{
|
||||||
|
_manager = manager ?? throw new ArgumentNullException(nameof(manager));
|
||||||
|
_networkEvents = networkEvents ?? throw new ArgumentNullException(nameof(networkEvents));
|
||||||
|
_punchEvents = _networkEvents.PunchEvents;
|
||||||
|
_mediator = mediator ?? throw new ArgumentNullException(nameof(mediator));
|
||||||
|
_attempt = attempt ?? throw new ArgumentNullException(nameof(attempt));
|
||||||
|
_clock = clock ?? throw new ArgumentNullException(nameof(clock));
|
||||||
|
_options = (options ?? new RendezvousCoordinatorOptions())
|
||||||
|
.CopyAndValidate();
|
||||||
|
_retry = new(_options, _clock);
|
||||||
|
|
||||||
|
RendezvousManagerGuard.Validate(_manager, _networkEvents);
|
||||||
|
DateTimeOffset startedUtc = _clock.UtcNow;
|
||||||
|
if (_mediator.Port is < 1 or > 65_535
|
||||||
|
|| _attempt.AttemptId.Value == Guid.Empty
|
||||||
|
|| _attempt.MediationHandle.Value == Guid.Empty
|
||||||
|
|| !ContractValidation.IsCapabilityValid(_attempt.ClientPunchCapability)
|
||||||
|
|| !ContractValidation.IsConnectionTicketValid(_attempt.ConnectionTicketDigest)
|
||||||
|
|| _attempt.ExpiresAt <= startedUtc)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("The client traversal inputs are invalid.");
|
||||||
|
}
|
||||||
|
|
||||||
|
_startedAt = _clock.Elapsed;
|
||||||
|
_attemptDeadline = _startedAt + (_attempt.ExpiresAt - startedUtc);
|
||||||
|
_punchDeadline = Min(_attemptDeadline, _startedAt + _options.PunchTimeout);
|
||||||
|
_dedicatedFallback = RendezvousEndpoint.Copy(
|
||||||
|
_options.DedicatedFallbackOverride ?? _attempt.DedicatedFallback);
|
||||||
|
|
||||||
|
_networkEvents.RendezvousPeerConnected += OnPeerConnected;
|
||||||
|
_networkEvents.RendezvousPeerDisconnected += OnPeerDisconnected;
|
||||||
|
_networkEvents.RendezvousNetworkError += OnNetworkError;
|
||||||
|
_punchEvents.NatIntroductionSuccess += OnNatIntroductionSuccess;
|
||||||
|
}
|
||||||
|
|
||||||
|
public event EventHandler<RendezvousConnectionCompletedEventArgs>? Completed;
|
||||||
|
|
||||||
|
public RendezvousConnectionState State { get; private set; } = RendezvousConnectionState.Punching;
|
||||||
|
public NetPeer? ConnectedPeer { get; private set; }
|
||||||
|
public RendezvousConnectionOutcome? Outcome => Volatile.Read(ref _outcome);
|
||||||
|
public bool IsCompleted => Outcome is not null;
|
||||||
|
|
||||||
|
public void Cancel() => Volatile.Write(ref _cancelRequested, true);
|
||||||
|
|
||||||
|
public async Task<RendezvousClientResult<bool>> CancelAsync(
|
||||||
|
IRendezvousJoinClient joinClient,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
if (joinClient is null)
|
||||||
|
{
|
||||||
|
throw new ArgumentNullException(nameof(joinClient));
|
||||||
|
}
|
||||||
|
|
||||||
|
ThrowIfDisposed();
|
||||||
|
Cancel();
|
||||||
|
return await joinClient.CancelAsync(_attempt, cancellationToken).ConfigureAwait(false);
|
||||||
|
}
|
||||||
|
|
||||||
|
public Task<RendezvousClientResult<ReportConnectionOutcomeResponse>> ReportOutcomeAsync(
|
||||||
|
IRendezvousJoinClient joinClient,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
if (joinClient is null)
|
||||||
|
{
|
||||||
|
throw new ArgumentNullException(nameof(joinClient));
|
||||||
|
}
|
||||||
|
ThrowIfDisposed();
|
||||||
|
if (Outcome is null)
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException("The connection attempt has not completed.");
|
||||||
|
}
|
||||||
|
|
||||||
|
return joinClient.ReportOutcomeAsync(_attempt, Outcome, cancellationToken);
|
||||||
|
}
|
||||||
|
|
||||||
|
public void Poll()
|
||||||
|
{
|
||||||
|
ThrowIfDisposed();
|
||||||
|
if (IsCompleted)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (Interlocked.Exchange(ref _polling, 1) != 0)
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException("The Rendezvous coordinator cannot be polled concurrently or recursively.");
|
||||||
|
}
|
||||||
|
|
||||||
|
try
|
||||||
|
{
|
||||||
|
if (Volatile.Read(ref _cancelRequested))
|
||||||
|
{
|
||||||
|
DisconnectPendingPeer();
|
||||||
|
Complete(
|
||||||
|
RendezvousConnectionState.Cancelled,
|
||||||
|
ConnectionOutcomeKind.Cancelled,
|
||||||
|
RendezvousConnectionOutcomeSource.Caller,
|
||||||
|
RendezvousConnectionFailureCategory.Lifecycle,
|
||||||
|
CurrentPhase());
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!_manager.IsRunning)
|
||||||
|
{
|
||||||
|
CompleteManagerStopped();
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
_manager.PollEvents();
|
||||||
|
_manager.NatPunchModule.PollEvents();
|
||||||
|
if (IsCompleted)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
DateTimeOffset now = _clock.UtcNow;
|
||||||
|
TimeSpan elapsed = _clock.Elapsed;
|
||||||
|
if (Volatile.Read(ref _cancelRequested))
|
||||||
|
{
|
||||||
|
DisconnectPendingPeer();
|
||||||
|
Complete(
|
||||||
|
RendezvousConnectionState.Cancelled,
|
||||||
|
ConnectionOutcomeKind.Cancelled,
|
||||||
|
RendezvousConnectionOutcomeSource.Caller,
|
||||||
|
RendezvousConnectionFailureCategory.Lifecycle,
|
||||||
|
CurrentPhase());
|
||||||
|
}
|
||||||
|
else if (!_manager.IsRunning)
|
||||||
|
{
|
||||||
|
CompleteManagerStopped();
|
||||||
|
}
|
||||||
|
else if (now >= _attempt.ExpiresAt || elapsed >= _attemptDeadline)
|
||||||
|
{
|
||||||
|
DisconnectPendingPeer();
|
||||||
|
Complete(
|
||||||
|
RendezvousConnectionState.TimedOut,
|
||||||
|
ConnectionOutcomeKind.AttemptExpired,
|
||||||
|
RendezvousConnectionOutcomeSource.RendezvousService,
|
||||||
|
RendezvousConnectionFailureCategory.Authorization,
|
||||||
|
RendezvousConnectionPhase.Authorization);
|
||||||
|
}
|
||||||
|
else if (State == RendezvousConnectionState.Punching)
|
||||||
|
{
|
||||||
|
if (elapsed >= _punchDeadline
|
||||||
|
|| _retry.IsExhausted && _retry.IsDue(elapsed))
|
||||||
|
{
|
||||||
|
Complete(
|
||||||
|
RendezvousConnectionState.TimedOut,
|
||||||
|
ConnectionOutcomeKind.PunchTimedOut,
|
||||||
|
RendezvousConnectionOutcomeSource.LocalTraversal,
|
||||||
|
RendezvousConnectionFailureCategory.NatTraversal,
|
||||||
|
RendezvousConnectionPhase.NatTraversal);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (_retry.IsDue(elapsed))
|
||||||
|
{
|
||||||
|
_manager.NatPunchModule.SendNatIntroduceRequest(
|
||||||
|
_mediator,
|
||||||
|
NatPunchRequestTokenCodec.Encode(
|
||||||
|
NatPunchPeerRole.Client,
|
||||||
|
_attempt.MediationHandle,
|
||||||
|
_attempt.ClientPunchCapability));
|
||||||
|
_retry.RecordRequest();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
else if (State == RendezvousConnectionState.Connecting
|
||||||
|
&& _directDeadline is TimeSpan directDeadline
|
||||||
|
&& directDeadline <= elapsed)
|
||||||
|
{
|
||||||
|
DisconnectPendingPeer();
|
||||||
|
Complete(
|
||||||
|
RendezvousConnectionState.TimedOut,
|
||||||
|
ConnectionOutcomeKind.DirectConnectTimedOut,
|
||||||
|
RendezvousConnectionOutcomeSource.LocalTraversal,
|
||||||
|
RendezvousConnectionFailureCategory.DirectConnection,
|
||||||
|
RendezvousConnectionPhase.DirectConnection);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
Volatile.Write(ref _polling, 0);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public void Dispose()
|
||||||
|
{
|
||||||
|
if (Interlocked.Exchange(ref _disposed, 1) != 0)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!IsCompleted)
|
||||||
|
{
|
||||||
|
Complete(
|
||||||
|
RendezvousConnectionState.Disposed,
|
||||||
|
ConnectionOutcomeKind.Disposed,
|
||||||
|
RendezvousConnectionOutcomeSource.Lifecycle,
|
||||||
|
RendezvousConnectionFailureCategory.Lifecycle,
|
||||||
|
CurrentPhase());
|
||||||
|
}
|
||||||
|
|
||||||
|
ReleaseSubscriptions();
|
||||||
|
}
|
||||||
|
|
||||||
|
public override string ToString() =>
|
||||||
|
$"[RendezvousClientCoordinator {_attempt.AttemptId}; credentials redacted]";
|
||||||
|
|
||||||
|
private void OnNatIntroductionSuccess(
|
||||||
|
IPEndPoint target,
|
||||||
|
NatAddressType addressType,
|
||||||
|
string encodedIntroduction)
|
||||||
|
{
|
||||||
|
_ = addressType;
|
||||||
|
if (State != RendezvousConnectionState.Punching
|
||||||
|
|| !NatIntroductionTokenCodec.TryDecode(
|
||||||
|
encodedIntroduction,
|
||||||
|
out NatIntroductionToken? introduction)
|
||||||
|
|| introduction is null
|
||||||
|
|| introduction.AttemptId != _attempt.AttemptId
|
||||||
|
|| !NatIntroductionTokenCodec.MatchesDigest(
|
||||||
|
introduction.ConnectionTicket,
|
||||||
|
_attempt.ConnectionTicketDigest))
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
byte[] connectionData = DirectConnectionRequestCodec.Encode(
|
||||||
|
introduction.AttemptId,
|
||||||
|
introduction.ConnectionTicket);
|
||||||
|
_directEndpoint = target;
|
||||||
|
_connectingPeer = _manager.Connect(target, connectionData);
|
||||||
|
if (_connectingPeer is null
|
||||||
|
|| _connectingPeer.ConnectionState != ConnectionState.Outgoing)
|
||||||
|
{
|
||||||
|
_connectingPeer = null;
|
||||||
|
Complete(
|
||||||
|
RendezvousConnectionState.Rejected,
|
||||||
|
ConnectionOutcomeKind.TransportError,
|
||||||
|
RendezvousConnectionOutcomeSource.LocalTraversal,
|
||||||
|
RendezvousConnectionFailureCategory.DirectConnection,
|
||||||
|
RendezvousConnectionPhase.DirectConnection);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
State = RendezvousConnectionState.Connecting;
|
||||||
|
_directDeadline = Min(
|
||||||
|
_attemptDeadline,
|
||||||
|
_clock.Elapsed + _options.DirectConnectTimeout);
|
||||||
|
}
|
||||||
|
|
||||||
|
private void OnPeerConnected(NetPeer peer)
|
||||||
|
{
|
||||||
|
if (State != RendezvousConnectionState.Connecting
|
||||||
|
|| !ReferenceEquals(peer, _connectingPeer))
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
Complete(
|
||||||
|
RendezvousConnectionState.Connected,
|
||||||
|
ConnectionOutcomeKind.Connected,
|
||||||
|
RendezvousConnectionOutcomeSource.LocalTraversal,
|
||||||
|
RendezvousConnectionFailureCategory.None,
|
||||||
|
RendezvousConnectionPhase.Complete,
|
||||||
|
peer);
|
||||||
|
}
|
||||||
|
|
||||||
|
private void OnPeerDisconnected(NetPeer peer, DisconnectInfo disconnectInfo)
|
||||||
|
{
|
||||||
|
if (State == RendezvousConnectionState.Connecting
|
||||||
|
&& ReferenceEquals(peer, _connectingPeer))
|
||||||
|
{
|
||||||
|
ConnectionOutcomeKind kind = disconnectInfo.Reason == DisconnectReason.Timeout
|
||||||
|
? ConnectionOutcomeKind.DirectConnectTimedOut
|
||||||
|
: disconnectInfo.Reason == DisconnectReason.ConnectionFailed
|
||||||
|
? ConnectionOutcomeKind.TransportError
|
||||||
|
: ConnectionOutcomeKind.HostRejected;
|
||||||
|
Complete(
|
||||||
|
kind == ConnectionOutcomeKind.DirectConnectTimedOut
|
||||||
|
? RendezvousConnectionState.TimedOut
|
||||||
|
: RendezvousConnectionState.Rejected,
|
||||||
|
kind,
|
||||||
|
kind == ConnectionOutcomeKind.HostRejected
|
||||||
|
? RendezvousConnectionOutcomeSource.RemoteHost
|
||||||
|
: RendezvousConnectionOutcomeSource.LocalTraversal,
|
||||||
|
RendezvousConnectionFailureCategory.DirectConnection,
|
||||||
|
RendezvousConnectionPhase.DirectConnection);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private void OnNetworkError(IPEndPoint endpoint, SocketError socketError)
|
||||||
|
{
|
||||||
|
_ = socketError;
|
||||||
|
if (State == RendezvousConnectionState.Punching && endpoint.Equals(_mediator))
|
||||||
|
{
|
||||||
|
Complete(
|
||||||
|
RendezvousConnectionState.Rejected,
|
||||||
|
ConnectionOutcomeKind.MediatorUnavailable,
|
||||||
|
RendezvousConnectionOutcomeSource.LocalTraversal,
|
||||||
|
RendezvousConnectionFailureCategory.Mediation,
|
||||||
|
RendezvousConnectionPhase.Mediation);
|
||||||
|
}
|
||||||
|
else if (State == RendezvousConnectionState.Connecting
|
||||||
|
&& endpoint.Equals(_directEndpoint))
|
||||||
|
{
|
||||||
|
DisconnectPendingPeer();
|
||||||
|
Complete(
|
||||||
|
RendezvousConnectionState.Rejected,
|
||||||
|
ConnectionOutcomeKind.TransportError,
|
||||||
|
RendezvousConnectionOutcomeSource.LocalTraversal,
|
||||||
|
RendezvousConnectionFailureCategory.DirectConnection,
|
||||||
|
RendezvousConnectionPhase.DirectConnection);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private void DisconnectPendingPeer()
|
||||||
|
{
|
||||||
|
if (_connectingPeer is not null && State == RendezvousConnectionState.Connecting)
|
||||||
|
{
|
||||||
|
_connectingPeer.Disconnect();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private void Complete(
|
||||||
|
RendezvousConnectionState terminalState,
|
||||||
|
ConnectionOutcomeKind kind,
|
||||||
|
RendezvousConnectionOutcomeSource source,
|
||||||
|
RendezvousConnectionFailureCategory category,
|
||||||
|
RendezvousConnectionPhase phase,
|
||||||
|
NetPeer? peer = null)
|
||||||
|
{
|
||||||
|
RendezvousConnectionCompletedEventArgs completion;
|
||||||
|
lock (_completionGate)
|
||||||
|
{
|
||||||
|
if (_outcome is not null)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
RendezvousConnectionOutcome outcome = RendezvousConnectionOutcome.Create(
|
||||||
|
kind,
|
||||||
|
source,
|
||||||
|
category,
|
||||||
|
phase,
|
||||||
|
_clock.Elapsed - _startedAt,
|
||||||
|
ShouldOfferFallback(kind) ? _dedicatedFallback : null,
|
||||||
|
peer);
|
||||||
|
State = terminalState;
|
||||||
|
if (kind == ConnectionOutcomeKind.Connected)
|
||||||
|
{
|
||||||
|
ConnectedPeer = peer;
|
||||||
|
}
|
||||||
|
Volatile.Write(ref _outcome, outcome);
|
||||||
|
ReleaseSubscriptions();
|
||||||
|
completion = new(terminalState, outcome);
|
||||||
|
}
|
||||||
|
|
||||||
|
Completed?.Invoke(this, completion);
|
||||||
|
}
|
||||||
|
|
||||||
|
private void ReleaseSubscriptions()
|
||||||
|
{
|
||||||
|
lock (_completionGate)
|
||||||
|
{
|
||||||
|
if (_subscriptionsReleased)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
_networkEvents.RendezvousPeerConnected -= OnPeerConnected;
|
||||||
|
_networkEvents.RendezvousPeerDisconnected -= OnPeerDisconnected;
|
||||||
|
_networkEvents.RendezvousNetworkError -= OnNetworkError;
|
||||||
|
_punchEvents.NatIntroductionSuccess -= OnNatIntroductionSuccess;
|
||||||
|
_subscriptionsReleased = true;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private void CompleteManagerStopped() => Complete(
|
||||||
|
RendezvousConnectionState.ManagerStopped,
|
||||||
|
ConnectionOutcomeKind.ManagerStopped,
|
||||||
|
RendezvousConnectionOutcomeSource.Lifecycle,
|
||||||
|
RendezvousConnectionFailureCategory.Lifecycle,
|
||||||
|
CurrentPhase());
|
||||||
|
|
||||||
|
private RendezvousConnectionPhase CurrentPhase() => State switch
|
||||||
|
{
|
||||||
|
RendezvousConnectionState.Punching => RendezvousConnectionPhase.NatTraversal,
|
||||||
|
RendezvousConnectionState.Connecting => RendezvousConnectionPhase.DirectConnection,
|
||||||
|
_ => RendezvousConnectionPhase.Complete,
|
||||||
|
};
|
||||||
|
|
||||||
|
private static bool ShouldOfferFallback(ConnectionOutcomeKind kind) => kind is not (
|
||||||
|
ConnectionOutcomeKind.Connected
|
||||||
|
or ConnectionOutcomeKind.Cancelled
|
||||||
|
or ConnectionOutcomeKind.Disposed);
|
||||||
|
|
||||||
|
private static TimeSpan Min(TimeSpan left, TimeSpan right) =>
|
||||||
|
left <= right ? left : right;
|
||||||
|
|
||||||
|
private void ThrowIfDisposed()
|
||||||
|
{
|
||||||
|
if (Volatile.Read(ref _disposed) != 0)
|
||||||
|
{
|
||||||
|
throw new ObjectDisposedException(nameof(RendezvousClientCoordinator));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,228 @@
|
|||||||
|
using System.Diagnostics;
|
||||||
|
using System.Security.Cryptography;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using LiteNetLib;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Client;
|
||||||
|
|
||||||
|
public enum RendezvousConnectionState
|
||||||
|
{
|
||||||
|
Punching = 1,
|
||||||
|
Connecting = 2,
|
||||||
|
Connected = 3,
|
||||||
|
Cancelled = 4,
|
||||||
|
TimedOut = 5,
|
||||||
|
Rejected = 6,
|
||||||
|
ManagerStopped = 7,
|
||||||
|
Disposed = 8,
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class RendezvousConnectionCompletedEventArgs : EventArgs
|
||||||
|
{
|
||||||
|
[Obsolete("Completion events now expose a typed Outcome. Construct these arguments only for legacy test doubles.")]
|
||||||
|
public RendezvousConnectionCompletedEventArgs(
|
||||||
|
RendezvousConnectionState state,
|
||||||
|
NetPeer? peer)
|
||||||
|
: this(state, RendezvousCompletionInvariant.FromLegacy(state, peer))
|
||||||
|
{
|
||||||
|
}
|
||||||
|
|
||||||
|
internal RendezvousConnectionCompletedEventArgs(
|
||||||
|
RendezvousConnectionState state,
|
||||||
|
RendezvousConnectionOutcome outcome)
|
||||||
|
{
|
||||||
|
RendezvousCompletionInvariant.Validate(state, outcome);
|
||||||
|
State = state;
|
||||||
|
Outcome = outcome;
|
||||||
|
}
|
||||||
|
|
||||||
|
public RendezvousConnectionState State { get; }
|
||||||
|
public RendezvousConnectionOutcome Outcome { get; }
|
||||||
|
public NetPeer? Peer => Outcome.Peer;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal static class RendezvousCompletionInvariant
|
||||||
|
{
|
||||||
|
internal static RendezvousConnectionOutcome FromLegacy(
|
||||||
|
RendezvousConnectionState state,
|
||||||
|
NetPeer? peer) => state switch
|
||||||
|
{
|
||||||
|
RendezvousConnectionState.Connected when peer is not null => RendezvousConnectionOutcome.Create(
|
||||||
|
ConnectionOutcomeKind.Connected,
|
||||||
|
RendezvousConnectionOutcomeSource.LocalTraversal,
|
||||||
|
RendezvousConnectionFailureCategory.None,
|
||||||
|
RendezvousConnectionPhase.Complete,
|
||||||
|
TimeSpan.Zero,
|
||||||
|
peer: peer),
|
||||||
|
RendezvousConnectionState.Cancelled => RendezvousConnectionOutcome.Create(
|
||||||
|
ConnectionOutcomeKind.Cancelled,
|
||||||
|
RendezvousConnectionOutcomeSource.Caller,
|
||||||
|
RendezvousConnectionFailureCategory.Lifecycle,
|
||||||
|
RendezvousConnectionPhase.Complete,
|
||||||
|
TimeSpan.Zero),
|
||||||
|
RendezvousConnectionState.TimedOut => RendezvousConnectionOutcome.Create(
|
||||||
|
ConnectionOutcomeKind.DirectConnectTimedOut,
|
||||||
|
RendezvousConnectionOutcomeSource.LocalTraversal,
|
||||||
|
RendezvousConnectionFailureCategory.DirectConnection,
|
||||||
|
RendezvousConnectionPhase.DirectConnection,
|
||||||
|
TimeSpan.Zero),
|
||||||
|
RendezvousConnectionState.Rejected => RendezvousConnectionOutcome.Create(
|
||||||
|
ConnectionOutcomeKind.HostRejected,
|
||||||
|
RendezvousConnectionOutcomeSource.RemoteHost,
|
||||||
|
RendezvousConnectionFailureCategory.Authorization,
|
||||||
|
RendezvousConnectionPhase.Authorization,
|
||||||
|
TimeSpan.Zero),
|
||||||
|
RendezvousConnectionState.ManagerStopped => RendezvousConnectionOutcome.Create(
|
||||||
|
ConnectionOutcomeKind.ManagerStopped,
|
||||||
|
RendezvousConnectionOutcomeSource.Lifecycle,
|
||||||
|
RendezvousConnectionFailureCategory.Lifecycle,
|
||||||
|
RendezvousConnectionPhase.Complete,
|
||||||
|
TimeSpan.Zero),
|
||||||
|
RendezvousConnectionState.Disposed => RendezvousConnectionOutcome.Create(
|
||||||
|
ConnectionOutcomeKind.Disposed,
|
||||||
|
RendezvousConnectionOutcomeSource.Lifecycle,
|
||||||
|
RendezvousConnectionFailureCategory.Lifecycle,
|
||||||
|
RendezvousConnectionPhase.Complete,
|
||||||
|
TimeSpan.Zero),
|
||||||
|
RendezvousConnectionState.Connected => throw new ArgumentNullException(
|
||||||
|
nameof(peer),
|
||||||
|
"A connected completion requires a peer."),
|
||||||
|
_ => throw new ArgumentOutOfRangeException(
|
||||||
|
nameof(state),
|
||||||
|
state,
|
||||||
|
"A completion event requires a terminal connection state."),
|
||||||
|
};
|
||||||
|
|
||||||
|
internal static void Validate(
|
||||||
|
RendezvousConnectionState state,
|
||||||
|
RendezvousConnectionOutcome outcome)
|
||||||
|
{
|
||||||
|
if (outcome is null)
|
||||||
|
{
|
||||||
|
throw new ArgumentNullException(nameof(outcome));
|
||||||
|
}
|
||||||
|
if ((state == RendezvousConnectionState.Connected) != outcome.IsSuccess)
|
||||||
|
{
|
||||||
|
throw new ArgumentException(
|
||||||
|
"The connection state and typed outcome contradict each other.",
|
||||||
|
nameof(outcome));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class RendezvousCoordinatorOptions
|
||||||
|
{
|
||||||
|
public int MaximumPunchRequests { get; set; } = 5;
|
||||||
|
public int MaximumAttemptChecksPerPoll { get; set; } = 128;
|
||||||
|
public TimeSpan InitialPunchRetryDelay { get; set; } = TimeSpan.FromMilliseconds(200);
|
||||||
|
public TimeSpan MaximumPunchRetryDelay { get; set; } = TimeSpan.FromSeconds(2);
|
||||||
|
public TimeSpan PunchTimeout { get; set; } = TimeSpan.FromSeconds(10);
|
||||||
|
public TimeSpan DirectConnectTimeout { get; set; } = TimeSpan.FromSeconds(5);
|
||||||
|
public TimeSpan ConnectionTicketLifetime { get; set; } = TimeSpan.FromSeconds(20);
|
||||||
|
public double JitterRatio { get; set; } = 0.2;
|
||||||
|
public NetworkEndpoint? DedicatedFallbackOverride { get; set; }
|
||||||
|
|
||||||
|
internal RendezvousCoordinatorOptions CopyAndValidate()
|
||||||
|
{
|
||||||
|
if (MaximumPunchRequests is < 1 or > 20
|
||||||
|
|| MaximumAttemptChecksPerPoll is < 1 or > 1_024
|
||||||
|
|| InitialPunchRetryDelay < TimeSpan.FromMilliseconds(10)
|
||||||
|
|| MaximumPunchRetryDelay < InitialPunchRetryDelay
|
||||||
|
|| MaximumPunchRetryDelay > TimeSpan.FromSeconds(10)
|
||||||
|
|| PunchTimeout <= TimeSpan.Zero
|
||||||
|
|| PunchTimeout > TimeSpan.FromSeconds(30)
|
||||||
|
|| DirectConnectTimeout <= TimeSpan.Zero
|
||||||
|
|| DirectConnectTimeout > TimeSpan.FromSeconds(30)
|
||||||
|
|| ConnectionTicketLifetime <= TimeSpan.Zero
|
||||||
|
|| ConnectionTicketLifetime > TimeSpan.FromSeconds(20)
|
||||||
|
|| JitterRatio is < 0 or > 1
|
||||||
|
|| DedicatedFallbackOverride is not null
|
||||||
|
&& !ContractValidation.IsNetworkEndpointValid(DedicatedFallbackOverride))
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(nameof(RendezvousCoordinatorOptions));
|
||||||
|
}
|
||||||
|
|
||||||
|
return new RendezvousCoordinatorOptions
|
||||||
|
{
|
||||||
|
MaximumPunchRequests = MaximumPunchRequests,
|
||||||
|
MaximumAttemptChecksPerPoll = MaximumAttemptChecksPerPoll,
|
||||||
|
InitialPunchRetryDelay = InitialPunchRetryDelay,
|
||||||
|
MaximumPunchRetryDelay = MaximumPunchRetryDelay,
|
||||||
|
PunchTimeout = PunchTimeout,
|
||||||
|
DirectConnectTimeout = DirectConnectTimeout,
|
||||||
|
ConnectionTicketLifetime = ConnectionTicketLifetime,
|
||||||
|
JitterRatio = JitterRatio,
|
||||||
|
DedicatedFallbackOverride = RendezvousEndpoint.Copy(DedicatedFallbackOverride),
|
||||||
|
};
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
internal interface IRendezvousCoordinatorClock
|
||||||
|
{
|
||||||
|
DateTimeOffset UtcNow { get; }
|
||||||
|
TimeSpan Elapsed { get; }
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class SystemRendezvousCoordinatorClock : IRendezvousCoordinatorClock
|
||||||
|
{
|
||||||
|
private readonly long _origin = Stopwatch.GetTimestamp();
|
||||||
|
|
||||||
|
public DateTimeOffset UtcNow => DateTimeOffset.UtcNow;
|
||||||
|
public TimeSpan Elapsed => TimeSpan.FromSeconds(
|
||||||
|
(Stopwatch.GetTimestamp() - _origin) / (double)Stopwatch.Frequency);
|
||||||
|
}
|
||||||
|
|
||||||
|
internal static class RendezvousManagerGuard
|
||||||
|
{
|
||||||
|
internal static void Validate(
|
||||||
|
NetManager manager,
|
||||||
|
RendezvousNetListener networkEvents)
|
||||||
|
{
|
||||||
|
networkEvents.ValidateManager(manager);
|
||||||
|
if (!manager.IsRunning)
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException("The caller-owned LiteNetLib manager must be running.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!manager.NatPunchEnabled
|
||||||
|
|| manager.UnsyncedEvents
|
||||||
|
|| manager.NatPunchModule.UnsyncedEvents)
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException(
|
||||||
|
"The caller-owned manager must enable NAT punching and synchronized event dispatch.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class RendezvousPunchRetrySchedule(
|
||||||
|
RendezvousCoordinatorOptions options,
|
||||||
|
IRendezvousCoordinatorClock clock)
|
||||||
|
{
|
||||||
|
public int RequestsSent { get; private set; }
|
||||||
|
public TimeSpan NextRequestAt { get; private set; } = TimeSpan.Zero;
|
||||||
|
|
||||||
|
public bool IsExhausted => RequestsSent >= options.MaximumPunchRequests;
|
||||||
|
|
||||||
|
public bool IsDue(TimeSpan elapsed) => elapsed >= NextRequestAt;
|
||||||
|
|
||||||
|
public void RecordRequest()
|
||||||
|
{
|
||||||
|
int exponent = Math.Min(RequestsSent, 30);
|
||||||
|
RequestsSent++;
|
||||||
|
double milliseconds = Math.Min(
|
||||||
|
options.InitialPunchRetryDelay.TotalMilliseconds * Math.Pow(2, exponent),
|
||||||
|
options.MaximumPunchRetryDelay.TotalMilliseconds);
|
||||||
|
if (options.JitterRatio > 0)
|
||||||
|
{
|
||||||
|
Span<byte> random = stackalloc byte[1];
|
||||||
|
RandomNumberGenerator.Fill(random);
|
||||||
|
double unit = random[0] / 255d;
|
||||||
|
double multiplier = 1 - options.JitterRatio + (2 * options.JitterRatio * unit);
|
||||||
|
milliseconds = Math.Min(
|
||||||
|
milliseconds * multiplier,
|
||||||
|
options.MaximumPunchRetryDelay.TotalMilliseconds);
|
||||||
|
}
|
||||||
|
|
||||||
|
NextRequestAt = clock.Elapsed + TimeSpan.FromMilliseconds(milliseconds);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,813 @@
|
|||||||
|
using System.Net;
|
||||||
|
using System.Net.Sockets;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using LiteNetLib;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Client;
|
||||||
|
|
||||||
|
public enum RendezvousHostState
|
||||||
|
{
|
||||||
|
Active = 1,
|
||||||
|
ManagerStopped = 2,
|
||||||
|
Disposed = 3,
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class RendezvousHostAttemptCompletedEventArgs : EventArgs
|
||||||
|
{
|
||||||
|
[Obsolete("Completion events now expose a typed Outcome. Construct these arguments only for legacy test doubles.")]
|
||||||
|
public RendezvousHostAttemptCompletedEventArgs(
|
||||||
|
JoinAttemptId attemptId,
|
||||||
|
RendezvousConnectionState state,
|
||||||
|
NetPeer? peer)
|
||||||
|
: this(attemptId, state, RendezvousCompletionInvariant.FromLegacy(state, peer))
|
||||||
|
{
|
||||||
|
}
|
||||||
|
|
||||||
|
internal RendezvousHostAttemptCompletedEventArgs(
|
||||||
|
JoinAttemptId attemptId,
|
||||||
|
RendezvousConnectionState state,
|
||||||
|
RendezvousConnectionOutcome outcome)
|
||||||
|
{
|
||||||
|
if (attemptId.Value == Guid.Empty)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("The completed attempt ID is invalid.", nameof(attemptId));
|
||||||
|
}
|
||||||
|
|
||||||
|
RendezvousCompletionInvariant.Validate(state, outcome);
|
||||||
|
AttemptId = attemptId;
|
||||||
|
State = state;
|
||||||
|
Outcome = outcome;
|
||||||
|
}
|
||||||
|
|
||||||
|
public JoinAttemptId AttemptId { get; }
|
||||||
|
public RendezvousConnectionState State { get; }
|
||||||
|
public RendezvousConnectionOutcome Outcome { get; }
|
||||||
|
public NetPeer? Peer => Outcome.Peer;
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class RendezvousHostCoordinator : IDisposable
|
||||||
|
{
|
||||||
|
private readonly NetManager _manager;
|
||||||
|
private readonly RendezvousNetListener _networkEvents;
|
||||||
|
private readonly EventBasedNatPunchListener _punchEvents;
|
||||||
|
private readonly IPEndPoint _mediator;
|
||||||
|
private readonly PublishedSession _session;
|
||||||
|
private readonly IRendezvousJoinClient _joinClient;
|
||||||
|
private readonly RendezvousCoordinatorOptions _options;
|
||||||
|
private readonly IRendezvousCoordinatorClock _clock;
|
||||||
|
private readonly ConnectionTicketValidator _tickets;
|
||||||
|
private readonly Dictionary<JoinAttemptId, PendingHostAttempt> _attempts = [];
|
||||||
|
private readonly Dictionary<NetPeer, JoinAttemptId> _acceptedPeers = [];
|
||||||
|
private readonly Dictionary<JoinAttemptId, DeferredConnectionRequest> _deferredRequests = [];
|
||||||
|
private readonly Dictionary<JoinAttemptId, DateTimeOffset> _terminalAttempts = [];
|
||||||
|
private readonly Queue<JoinAttemptId> _attemptSchedule = [];
|
||||||
|
private readonly SortedDictionary<long, Queue<HostAttemptDeadline>> _deadlines = [];
|
||||||
|
private readonly List<JoinAttemptId> _cleanupScratch = [];
|
||||||
|
private HostJoinAttempt[]? _latestSnapshot;
|
||||||
|
private DateTimeOffset _nextPresenceAt = DateTimeOffset.MinValue;
|
||||||
|
private DateTimeOffset _nextTerminalCleanupAt = DateTimeOffset.MinValue;
|
||||||
|
private int _refreshing;
|
||||||
|
private int _polling;
|
||||||
|
private bool _subscriptionsReleased;
|
||||||
|
private int _disposed;
|
||||||
|
|
||||||
|
public RendezvousHostCoordinator(
|
||||||
|
NetManager manager,
|
||||||
|
RendezvousNetListener networkEvents,
|
||||||
|
IPEndPoint mediator,
|
||||||
|
PublishedSession session,
|
||||||
|
IRendezvousJoinClient joinClient,
|
||||||
|
RendezvousCoordinatorOptions? options = null)
|
||||||
|
: this(
|
||||||
|
manager,
|
||||||
|
networkEvents,
|
||||||
|
mediator,
|
||||||
|
session,
|
||||||
|
joinClient,
|
||||||
|
options,
|
||||||
|
new SystemRendezvousCoordinatorClock(),
|
||||||
|
null)
|
||||||
|
{
|
||||||
|
}
|
||||||
|
|
||||||
|
internal RendezvousHostCoordinator(
|
||||||
|
NetManager manager,
|
||||||
|
RendezvousNetListener networkEvents,
|
||||||
|
IPEndPoint mediator,
|
||||||
|
PublishedSession session,
|
||||||
|
IRendezvousJoinClient joinClient,
|
||||||
|
RendezvousCoordinatorOptions? options,
|
||||||
|
IRendezvousCoordinatorClock clock,
|
||||||
|
ConnectionTicketValidator? tickets)
|
||||||
|
{
|
||||||
|
_manager = manager ?? throw new ArgumentNullException(nameof(manager));
|
||||||
|
_networkEvents = networkEvents ?? throw new ArgumentNullException(nameof(networkEvents));
|
||||||
|
_punchEvents = _networkEvents.PunchEvents;
|
||||||
|
_mediator = mediator ?? throw new ArgumentNullException(nameof(mediator));
|
||||||
|
_session = session ?? throw new ArgumentNullException(nameof(session));
|
||||||
|
_joinClient = joinClient ?? throw new ArgumentNullException(nameof(joinClient));
|
||||||
|
_options = (options ?? new RendezvousCoordinatorOptions()).CopyAndValidate();
|
||||||
|
_clock = clock ?? throw new ArgumentNullException(nameof(clock));
|
||||||
|
_tickets = tickets ?? new ConnectionTicketValidator();
|
||||||
|
|
||||||
|
RendezvousManagerGuard.Validate(_manager, _networkEvents);
|
||||||
|
ValidateInputs();
|
||||||
|
_networkEvents.RendezvousConnectionRequest += OnConnectionRequest;
|
||||||
|
_networkEvents.RendezvousPeerConnected += OnPeerConnected;
|
||||||
|
_networkEvents.RendezvousPeerDisconnected += OnPeerDisconnected;
|
||||||
|
_networkEvents.RendezvousNetworkError += OnNetworkError;
|
||||||
|
_punchEvents.NatIntroductionSuccess += OnNatIntroductionSuccess;
|
||||||
|
}
|
||||||
|
|
||||||
|
public event EventHandler<RendezvousHostAttemptCompletedEventArgs>? AttemptCompleted;
|
||||||
|
|
||||||
|
public RendezvousHostState State { get; private set; } = RendezvousHostState.Active;
|
||||||
|
public int PendingAttemptCount => _attempts.Count;
|
||||||
|
internal int DeferredRequestCount => _deferredRequests.Count;
|
||||||
|
|
||||||
|
public async Task<RendezvousClientResult<int>> RefreshJoinAttemptsAsync(
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
ThrowIfDisposed();
|
||||||
|
if (Interlocked.Exchange(ref _refreshing, 1) != 0)
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException("A host invitation refresh is already running.");
|
||||||
|
}
|
||||||
|
|
||||||
|
try
|
||||||
|
{
|
||||||
|
RendezvousClientResult<IReadOnlyList<HostJoinAttempt>> result =
|
||||||
|
await _joinClient.BrowseAllForHostAsync(
|
||||||
|
_session,
|
||||||
|
cancellationToken: cancellationToken).ConfigureAwait(false);
|
||||||
|
if (!result.IsSuccess || result.Value is null)
|
||||||
|
{
|
||||||
|
return RendezvousClientResult.Failure<int>(
|
||||||
|
result.Error,
|
||||||
|
result.Message,
|
||||||
|
result.RetryAfterSeconds);
|
||||||
|
}
|
||||||
|
|
||||||
|
HostJoinAttempt[] snapshot = result.Value.Select(CopyAttempt).ToArray();
|
||||||
|
if (Volatile.Read(ref _disposed) != 0)
|
||||||
|
{
|
||||||
|
throw new ObjectDisposedException(nameof(RendezvousHostCoordinator));
|
||||||
|
}
|
||||||
|
|
||||||
|
Interlocked.Exchange(ref _latestSnapshot, snapshot);
|
||||||
|
if (Volatile.Read(ref _disposed) != 0)
|
||||||
|
{
|
||||||
|
Interlocked.Exchange(ref _latestSnapshot, null);
|
||||||
|
throw new ObjectDisposedException(nameof(RendezvousHostCoordinator));
|
||||||
|
}
|
||||||
|
|
||||||
|
return RendezvousClientResult.Success(snapshot.Length);
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
Volatile.Write(ref _refreshing, 0);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public void Poll()
|
||||||
|
{
|
||||||
|
ThrowIfDisposed();
|
||||||
|
if (State != RendezvousHostState.Active)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (Interlocked.Exchange(ref _polling, 1) != 0)
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException("The Rendezvous coordinator cannot be polled concurrently or recursively.");
|
||||||
|
}
|
||||||
|
|
||||||
|
try
|
||||||
|
{
|
||||||
|
ApplySnapshots();
|
||||||
|
if (!_manager.IsRunning)
|
||||||
|
{
|
||||||
|
Stop(
|
||||||
|
RendezvousHostState.ManagerStopped,
|
||||||
|
RendezvousConnectionState.ManagerStopped,
|
||||||
|
ConnectionOutcomeKind.ManagerStopped);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
_manager.NatPunchModule.PollEvents();
|
||||||
|
_manager.PollEvents();
|
||||||
|
_manager.NatPunchModule.PollEvents();
|
||||||
|
if (State != RendezvousHostState.Active)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
DateTimeOffset now = _clock.UtcNow;
|
||||||
|
TimeSpan elapsed = _clock.Elapsed;
|
||||||
|
if (!_manager.IsRunning)
|
||||||
|
{
|
||||||
|
Stop(
|
||||||
|
RendezvousHostState.ManagerStopped,
|
||||||
|
RendezvousConnectionState.ManagerStopped,
|
||||||
|
ConnectionOutcomeKind.ManagerStopped);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
RefreshPresence(now);
|
||||||
|
ProcessDueDeadlines(elapsed);
|
||||||
|
if (State != RendezvousHostState.Active)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
int checks = Math.Min(
|
||||||
|
_attemptSchedule.Count,
|
||||||
|
_options.MaximumAttemptChecksPerPoll);
|
||||||
|
for (int index = 0; index < checks; index++)
|
||||||
|
{
|
||||||
|
JoinAttemptId attemptId = _attemptSchedule.Dequeue();
|
||||||
|
if (!_attempts.TryGetValue(attemptId, out PendingHostAttempt? attempt))
|
||||||
|
{
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (attempt.State != RendezvousConnectionState.Punching)
|
||||||
|
{
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (attempt.Retry.IsDue(elapsed))
|
||||||
|
{
|
||||||
|
if (attempt.Retry.IsExhausted)
|
||||||
|
{
|
||||||
|
CompleteAttempt(
|
||||||
|
attemptId,
|
||||||
|
RendezvousConnectionState.TimedOut,
|
||||||
|
ConnectionOutcomeKind.PunchTimedOut,
|
||||||
|
RendezvousConnectionOutcomeSource.LocalTraversal,
|
||||||
|
RendezvousConnectionFailureCategory.NatTraversal,
|
||||||
|
RendezvousConnectionPhase.NatTraversal);
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
_manager.NatPunchModule.SendNatIntroduceRequest(
|
||||||
|
_mediator,
|
||||||
|
NatPunchRequestTokenCodec.Encode(
|
||||||
|
NatPunchPeerRole.Host,
|
||||||
|
attempt.Invitation.MediationHandle,
|
||||||
|
attempt.Invitation.HostPunchCapability));
|
||||||
|
attempt.Retry.RecordRequest();
|
||||||
|
}
|
||||||
|
|
||||||
|
_attemptSchedule.Enqueue(attemptId);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (now >= _nextTerminalCleanupAt)
|
||||||
|
{
|
||||||
|
_cleanupScratch.Clear();
|
||||||
|
foreach (KeyValuePair<JoinAttemptId, DateTimeOffset> terminal in _terminalAttempts)
|
||||||
|
{
|
||||||
|
if (terminal.Value <= now)
|
||||||
|
{
|
||||||
|
_cleanupScratch.Add(terminal.Key);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach (JoinAttemptId attemptId in _cleanupScratch)
|
||||||
|
{
|
||||||
|
_terminalAttempts.Remove(attemptId);
|
||||||
|
}
|
||||||
|
|
||||||
|
_nextTerminalCleanupAt = now + TimeSpan.FromSeconds(1);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
Volatile.Write(ref _polling, 0);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public void Dispose()
|
||||||
|
{
|
||||||
|
if (Interlocked.Exchange(ref _disposed, 1) != 0)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
Stop(
|
||||||
|
RendezvousHostState.Disposed,
|
||||||
|
RendezvousConnectionState.Disposed,
|
||||||
|
ConnectionOutcomeKind.Disposed);
|
||||||
|
Interlocked.Exchange(ref _latestSnapshot, null);
|
||||||
|
_attemptSchedule.Clear();
|
||||||
|
_deadlines.Clear();
|
||||||
|
_terminalAttempts.Clear();
|
||||||
|
_cleanupScratch.Clear();
|
||||||
|
_tickets.Dispose();
|
||||||
|
}
|
||||||
|
|
||||||
|
public override string ToString() =>
|
||||||
|
$"[RendezvousHostCoordinator {_session.ListingId}; credentials redacted]";
|
||||||
|
|
||||||
|
private void ApplySnapshots()
|
||||||
|
{
|
||||||
|
HostJoinAttempt[]? latest = Interlocked.Exchange(ref _latestSnapshot, null);
|
||||||
|
|
||||||
|
if (latest is null)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
DateTimeOffset now = _clock.UtcNow;
|
||||||
|
TimeSpan elapsed = _clock.Elapsed;
|
||||||
|
foreach (HostJoinAttempt invitation in latest)
|
||||||
|
{
|
||||||
|
if (invitation.AttemptId.Value == Guid.Empty
|
||||||
|
|| invitation.MediationHandle.Value == Guid.Empty
|
||||||
|
|| !ContractValidation.IsCapabilityValid(invitation.HostPunchCapability)
|
||||||
|
|| !ContractValidation.IsConnectionTicketValid(
|
||||||
|
invitation.ConnectionTicketDigest))
|
||||||
|
{
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (invitation.IsCancelled)
|
||||||
|
{
|
||||||
|
if (_attempts.ContainsKey(invitation.AttemptId))
|
||||||
|
{
|
||||||
|
CompleteAttempt(
|
||||||
|
invitation.AttemptId,
|
||||||
|
RendezvousConnectionState.Cancelled,
|
||||||
|
ConnectionOutcomeKind.Cancelled,
|
||||||
|
RendezvousConnectionOutcomeSource.RendezvousService,
|
||||||
|
RendezvousConnectionFailureCategory.Lifecycle,
|
||||||
|
RendezvousConnectionPhase.Authorization);
|
||||||
|
}
|
||||||
|
|
||||||
|
_terminalAttempts[invitation.AttemptId] = invitation.ExpiresAt;
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (invitation.ExpiresAt <= now
|
||||||
|
|| _attempts.ContainsKey(invitation.AttemptId)
|
||||||
|
|| _terminalAttempts.ContainsKey(invitation.AttemptId))
|
||||||
|
{
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
TimeSpan attemptDeadline = elapsed + (invitation.ExpiresAt - now);
|
||||||
|
TimeSpan punchDeadline = Min(
|
||||||
|
attemptDeadline,
|
||||||
|
elapsed + _options.PunchTimeout);
|
||||||
|
_attempts.Add(
|
||||||
|
invitation.AttemptId,
|
||||||
|
new PendingHostAttempt(
|
||||||
|
CopyAttempt(invitation),
|
||||||
|
new RendezvousPunchRetrySchedule(_options, _clock),
|
||||||
|
elapsed,
|
||||||
|
attemptDeadline,
|
||||||
|
punchDeadline));
|
||||||
|
EnqueueDeadline(
|
||||||
|
new HostAttemptDeadline(
|
||||||
|
invitation.AttemptId,
|
||||||
|
RendezvousConnectionState.Punching,
|
||||||
|
punchDeadline));
|
||||||
|
_attemptSchedule.Enqueue(invitation.AttemptId);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private void RefreshPresence(DateTimeOffset now)
|
||||||
|
{
|
||||||
|
if (now < _nextPresenceAt || now >= _session.ExpiresAt)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
_manager.NatPunchModule.SendNatIntroduceRequest(
|
||||||
|
_mediator,
|
||||||
|
NatPunchRequestTokenCodec.Encode(
|
||||||
|
NatPunchPeerRole.HostPresence,
|
||||||
|
_session.HostPresenceHandle,
|
||||||
|
_session.HostPresenceCapability));
|
||||||
|
_nextPresenceAt = now + TimeSpan.FromSeconds(_session.HostPresenceRefreshAfterSeconds);
|
||||||
|
}
|
||||||
|
|
||||||
|
private void OnNatIntroductionSuccess(
|
||||||
|
IPEndPoint target,
|
||||||
|
NatAddressType addressType,
|
||||||
|
string encodedIntroduction)
|
||||||
|
{
|
||||||
|
_ = target;
|
||||||
|
_ = addressType;
|
||||||
|
if (!NatIntroductionTokenCodec.TryDecode(
|
||||||
|
encodedIntroduction,
|
||||||
|
out NatIntroductionToken? introduction)
|
||||||
|
|| introduction is null
|
||||||
|
|| !_attempts.TryGetValue(introduction.AttemptId, out PendingHostAttempt? attempt)
|
||||||
|
|| !NatIntroductionTokenCodec.MatchesDigest(
|
||||||
|
introduction.ConnectionTicket,
|
||||||
|
attempt.Invitation.ConnectionTicketDigest)
|
||||||
|
|| !_tickets.TryAuthorize(
|
||||||
|
introduction.AttemptId,
|
||||||
|
introduction.ConnectionTicket,
|
||||||
|
Min(
|
||||||
|
attempt.Invitation.ExpiresAt,
|
||||||
|
_clock.UtcNow + _options.ConnectionTicketLifetime)))
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
attempt.State = RendezvousConnectionState.Connecting;
|
||||||
|
attempt.DirectDeadline = Min(
|
||||||
|
attempt.AttemptDeadline,
|
||||||
|
_clock.Elapsed + _options.DirectConnectTimeout);
|
||||||
|
EnqueueDeadline(new HostAttemptDeadline(
|
||||||
|
introduction.AttemptId,
|
||||||
|
RendezvousConnectionState.Connecting,
|
||||||
|
attempt.DirectDeadline.Value));
|
||||||
|
if (_deferredRequests.Remove(
|
||||||
|
introduction.AttemptId,
|
||||||
|
out DeferredConnectionRequest? deferred))
|
||||||
|
{
|
||||||
|
AcceptAuthorizedRequest(
|
||||||
|
introduction.AttemptId,
|
||||||
|
attempt,
|
||||||
|
deferred.Request,
|
||||||
|
deferred.ConnectionTicket);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private void OnConnectionRequest(ConnectionRequest request)
|
||||||
|
{
|
||||||
|
ReadOnlySpan<byte> data = request.Data.GetRemainingBytesSpan();
|
||||||
|
if (!DirectConnectionRequestCodec.IsRendezvousRequest(data))
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!DirectConnectionRequestCodec.TryDecode(data, out DirectConnectionRequest? connection)
|
||||||
|
|| connection is null
|
||||||
|
|| !_attempts.TryGetValue(connection.AttemptId, out PendingHostAttempt? attempt)
|
||||||
|
|| !NatIntroductionTokenCodec.MatchesDigest(
|
||||||
|
connection.ConnectionTicket,
|
||||||
|
attempt.Invitation.ConnectionTicketDigest))
|
||||||
|
{
|
||||||
|
request.RejectForce([]);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (attempt.State == RendezvousConnectionState.Punching)
|
||||||
|
{
|
||||||
|
_deferredRequests[connection.AttemptId] = new(
|
||||||
|
request,
|
||||||
|
connection.ConnectionTicket);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (attempt.State != RendezvousConnectionState.Connecting)
|
||||||
|
{
|
||||||
|
request.RejectForce([]);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
AcceptAuthorizedRequest(
|
||||||
|
connection.AttemptId,
|
||||||
|
attempt,
|
||||||
|
request,
|
||||||
|
connection.ConnectionTicket);
|
||||||
|
}
|
||||||
|
|
||||||
|
private void OnPeerConnected(NetPeer peer)
|
||||||
|
{
|
||||||
|
if (_acceptedPeers.TryGetValue(peer, out JoinAttemptId attemptId))
|
||||||
|
{
|
||||||
|
CompleteAttempt(
|
||||||
|
attemptId,
|
||||||
|
RendezvousConnectionState.Connected,
|
||||||
|
ConnectionOutcomeKind.Connected,
|
||||||
|
RendezvousConnectionOutcomeSource.LocalTraversal,
|
||||||
|
RendezvousConnectionFailureCategory.None,
|
||||||
|
RendezvousConnectionPhase.Complete,
|
||||||
|
peer);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private void OnPeerDisconnected(NetPeer peer, DisconnectInfo disconnectInfo)
|
||||||
|
{
|
||||||
|
_ = disconnectInfo;
|
||||||
|
if (_acceptedPeers.TryGetValue(peer, out JoinAttemptId attemptId))
|
||||||
|
{
|
||||||
|
ConnectionOutcomeKind kind = disconnectInfo.Reason == DisconnectReason.Timeout
|
||||||
|
? ConnectionOutcomeKind.DirectConnectTimedOut
|
||||||
|
: ConnectionOutcomeKind.TransportError;
|
||||||
|
CompleteAttempt(
|
||||||
|
attemptId,
|
||||||
|
kind == ConnectionOutcomeKind.DirectConnectTimedOut
|
||||||
|
? RendezvousConnectionState.TimedOut
|
||||||
|
: RendezvousConnectionState.Rejected,
|
||||||
|
kind,
|
||||||
|
RendezvousConnectionOutcomeSource.LocalTraversal,
|
||||||
|
RendezvousConnectionFailureCategory.DirectConnection,
|
||||||
|
RendezvousConnectionPhase.DirectConnection);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private void OnNetworkError(IPEndPoint endpoint, SocketError socketError)
|
||||||
|
{
|
||||||
|
_ = socketError;
|
||||||
|
if (!endpoint.Equals(_mediator))
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach (JoinAttemptId attemptId in _attempts
|
||||||
|
.Where(static item => item.Value.State == RendezvousConnectionState.Punching)
|
||||||
|
.Select(static item => item.Key)
|
||||||
|
.ToArray())
|
||||||
|
{
|
||||||
|
CompleteAttempt(
|
||||||
|
attemptId,
|
||||||
|
RendezvousConnectionState.Rejected,
|
||||||
|
ConnectionOutcomeKind.MediatorUnavailable,
|
||||||
|
RendezvousConnectionOutcomeSource.LocalTraversal,
|
||||||
|
RendezvousConnectionFailureCategory.Mediation,
|
||||||
|
RendezvousConnectionPhase.Mediation);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private void CompleteAttempt(
|
||||||
|
JoinAttemptId attemptId,
|
||||||
|
RendezvousConnectionState state,
|
||||||
|
ConnectionOutcomeKind kind,
|
||||||
|
RendezvousConnectionOutcomeSource source,
|
||||||
|
RendezvousConnectionFailureCategory category,
|
||||||
|
RendezvousConnectionPhase phase,
|
||||||
|
NetPeer? peer = null)
|
||||||
|
{
|
||||||
|
if (TryCompleteAttempt(
|
||||||
|
attemptId,
|
||||||
|
state,
|
||||||
|
kind,
|
||||||
|
source,
|
||||||
|
category,
|
||||||
|
phase,
|
||||||
|
peer,
|
||||||
|
out RendezvousHostAttemptCompletedEventArgs? completion))
|
||||||
|
{
|
||||||
|
AttemptCompleted?.Invoke(this, completion!);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private bool TryCompleteAttempt(
|
||||||
|
JoinAttemptId attemptId,
|
||||||
|
RendezvousConnectionState state,
|
||||||
|
ConnectionOutcomeKind kind,
|
||||||
|
RendezvousConnectionOutcomeSource source,
|
||||||
|
RendezvousConnectionFailureCategory category,
|
||||||
|
RendezvousConnectionPhase phase,
|
||||||
|
NetPeer? peer,
|
||||||
|
out RendezvousHostAttemptCompletedEventArgs? completion)
|
||||||
|
{
|
||||||
|
completion = null;
|
||||||
|
if (!_attempts.Remove(attemptId, out PendingHostAttempt? attempt))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (attempt.AcceptedPeer is not null)
|
||||||
|
{
|
||||||
|
_acceptedPeers.Remove(attempt.AcceptedPeer);
|
||||||
|
if (kind != ConnectionOutcomeKind.Connected)
|
||||||
|
{
|
||||||
|
attempt.AcceptedPeer.Disconnect();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (_deferredRequests.Remove(attemptId, out DeferredConnectionRequest? deferred))
|
||||||
|
{
|
||||||
|
deferred.Request.RejectForce([]);
|
||||||
|
}
|
||||||
|
_tickets.Revoke(attemptId);
|
||||||
|
_terminalAttempts[attemptId] = attempt.Invitation.ExpiresAt;
|
||||||
|
RendezvousConnectionOutcome outcome = RendezvousConnectionOutcome.Create(
|
||||||
|
kind,
|
||||||
|
source,
|
||||||
|
category,
|
||||||
|
phase,
|
||||||
|
_clock.Elapsed - attempt.StartedAt,
|
||||||
|
peer: peer);
|
||||||
|
completion = new(attemptId, state, outcome);
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
private void Stop(
|
||||||
|
RendezvousHostState hostState,
|
||||||
|
RendezvousConnectionState attemptState,
|
||||||
|
ConnectionOutcomeKind outcomeKind)
|
||||||
|
{
|
||||||
|
if (State != RendezvousHostState.Active)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
State = hostState;
|
||||||
|
List<RendezvousHostAttemptCompletedEventArgs> completions = [];
|
||||||
|
foreach (JoinAttemptId attemptId in _attempts.Keys.ToArray())
|
||||||
|
{
|
||||||
|
RendezvousConnectionPhase phase = _attempts[attemptId].State
|
||||||
|
== RendezvousConnectionState.Connecting
|
||||||
|
? RendezvousConnectionPhase.DirectConnection
|
||||||
|
: RendezvousConnectionPhase.NatTraversal;
|
||||||
|
if (TryCompleteAttempt(
|
||||||
|
attemptId,
|
||||||
|
attemptState,
|
||||||
|
outcomeKind,
|
||||||
|
RendezvousConnectionOutcomeSource.Lifecycle,
|
||||||
|
RendezvousConnectionFailureCategory.Lifecycle,
|
||||||
|
phase,
|
||||||
|
null,
|
||||||
|
out RendezvousHostAttemptCompletedEventArgs? completion))
|
||||||
|
{
|
||||||
|
completions.Add(completion!);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
ReleaseSubscriptions();
|
||||||
|
foreach (RendezvousHostAttemptCompletedEventArgs completion in completions)
|
||||||
|
{
|
||||||
|
AttemptCompleted?.Invoke(this, completion);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private void ReleaseSubscriptions()
|
||||||
|
{
|
||||||
|
if (_subscriptionsReleased)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
_networkEvents.RendezvousConnectionRequest -= OnConnectionRequest;
|
||||||
|
_networkEvents.RendezvousPeerConnected -= OnPeerConnected;
|
||||||
|
_networkEvents.RendezvousPeerDisconnected -= OnPeerDisconnected;
|
||||||
|
_networkEvents.RendezvousNetworkError -= OnNetworkError;
|
||||||
|
_punchEvents.NatIntroductionSuccess -= OnNatIntroductionSuccess;
|
||||||
|
_subscriptionsReleased = true;
|
||||||
|
}
|
||||||
|
|
||||||
|
private void ValidateInputs()
|
||||||
|
{
|
||||||
|
if (_mediator.Port is < 1 or > 65_535
|
||||||
|
|| _session.HostPresenceHandle.Value == Guid.Empty
|
||||||
|
|| !ContractValidation.IsCapabilityValid(_session.HostPresenceCapability)
|
||||||
|
|| _session.HostPresenceRefreshAfterSeconds < 1
|
||||||
|
|| _session.ExpiresAt <= _clock.UtcNow)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("The host traversal inputs are invalid.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static HostJoinAttempt CopyAttempt(HostJoinAttempt attempt) => new()
|
||||||
|
{
|
||||||
|
AttemptId = attempt.AttemptId,
|
||||||
|
MediationHandle = attempt.MediationHandle,
|
||||||
|
HostPunchCapability = attempt.HostPunchCapability,
|
||||||
|
ConnectionTicketDigest = attempt.ConnectionTicketDigest,
|
||||||
|
IsCancelled = attempt.IsCancelled,
|
||||||
|
ExpiresAt = attempt.ExpiresAt,
|
||||||
|
};
|
||||||
|
|
||||||
|
private static TimeSpan Min(TimeSpan left, TimeSpan right) =>
|
||||||
|
left <= right ? left : right;
|
||||||
|
|
||||||
|
private static DateTimeOffset Min(DateTimeOffset left, DateTimeOffset right) =>
|
||||||
|
left <= right ? left : right;
|
||||||
|
|
||||||
|
private void EnqueueDeadline(HostAttemptDeadline deadline)
|
||||||
|
{
|
||||||
|
if (!_deadlines.TryGetValue(deadline.Deadline.Ticks, out Queue<HostAttemptDeadline>? bucket))
|
||||||
|
{
|
||||||
|
bucket = new Queue<HostAttemptDeadline>();
|
||||||
|
_deadlines.Add(deadline.Deadline.Ticks, bucket);
|
||||||
|
}
|
||||||
|
|
||||||
|
bucket.Enqueue(deadline);
|
||||||
|
}
|
||||||
|
|
||||||
|
private void ProcessDueDeadlines(TimeSpan elapsed)
|
||||||
|
{
|
||||||
|
while (_deadlines.Count > 0)
|
||||||
|
{
|
||||||
|
KeyValuePair<long, Queue<HostAttemptDeadline>> first = _deadlines.First();
|
||||||
|
if (first.Key > elapsed.Ticks)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
HostAttemptDeadline deadline = first.Value.Dequeue();
|
||||||
|
if (first.Value.Count == 0)
|
||||||
|
{
|
||||||
|
_deadlines.Remove(first.Key);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!_attempts.TryGetValue(deadline.AttemptId, out PendingHostAttempt? attempt)
|
||||||
|
|| attempt.State != deadline.ExpectedState
|
||||||
|
|| (deadline.ExpectedState == RendezvousConnectionState.Punching
|
||||||
|
? attempt.PunchDeadline
|
||||||
|
: attempt.DirectDeadline) != deadline.Deadline)
|
||||||
|
{
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
bool expired = elapsed >= attempt.AttemptDeadline;
|
||||||
|
CompleteAttempt(
|
||||||
|
deadline.AttemptId,
|
||||||
|
RendezvousConnectionState.TimedOut,
|
||||||
|
expired
|
||||||
|
? ConnectionOutcomeKind.AttemptExpired
|
||||||
|
: deadline.ExpectedState == RendezvousConnectionState.Punching
|
||||||
|
? ConnectionOutcomeKind.PunchTimedOut
|
||||||
|
: ConnectionOutcomeKind.DirectConnectTimedOut,
|
||||||
|
expired
|
||||||
|
? RendezvousConnectionOutcomeSource.RendezvousService
|
||||||
|
: RendezvousConnectionOutcomeSource.LocalTraversal,
|
||||||
|
expired
|
||||||
|
? RendezvousConnectionFailureCategory.Authorization
|
||||||
|
: deadline.ExpectedState == RendezvousConnectionState.Punching
|
||||||
|
? RendezvousConnectionFailureCategory.NatTraversal
|
||||||
|
: RendezvousConnectionFailureCategory.DirectConnection,
|
||||||
|
expired
|
||||||
|
? RendezvousConnectionPhase.Authorization
|
||||||
|
: deadline.ExpectedState == RendezvousConnectionState.Punching
|
||||||
|
? RendezvousConnectionPhase.NatTraversal
|
||||||
|
: RendezvousConnectionPhase.DirectConnection);
|
||||||
|
|
||||||
|
if (State != RendezvousHostState.Active)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private void AcceptAuthorizedRequest(
|
||||||
|
JoinAttemptId attemptId,
|
||||||
|
PendingHostAttempt attempt,
|
||||||
|
ConnectionRequest request,
|
||||||
|
string connectionTicket)
|
||||||
|
{
|
||||||
|
ConnectionTicketConsumptionResult consumption = _tickets.Consume(
|
||||||
|
attemptId,
|
||||||
|
connectionTicket);
|
||||||
|
if (consumption != ConnectionTicketConsumptionResult.Accepted)
|
||||||
|
{
|
||||||
|
request.RejectForce([]);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
NetPeer peer = request.Accept();
|
||||||
|
attempt.AcceptedPeer = peer;
|
||||||
|
_acceptedPeers[peer] = attemptId;
|
||||||
|
}
|
||||||
|
|
||||||
|
private void ThrowIfDisposed()
|
||||||
|
{
|
||||||
|
if (Volatile.Read(ref _disposed) != 0)
|
||||||
|
{
|
||||||
|
throw new ObjectDisposedException(nameof(RendezvousHostCoordinator));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private sealed class PendingHostAttempt(
|
||||||
|
HostJoinAttempt invitation,
|
||||||
|
RendezvousPunchRetrySchedule retry,
|
||||||
|
TimeSpan startedAt,
|
||||||
|
TimeSpan attemptDeadline,
|
||||||
|
TimeSpan punchDeadline)
|
||||||
|
{
|
||||||
|
internal HostJoinAttempt Invitation { get; } = invitation;
|
||||||
|
internal RendezvousPunchRetrySchedule Retry { get; } = retry;
|
||||||
|
internal TimeSpan StartedAt { get; } = startedAt;
|
||||||
|
internal TimeSpan AttemptDeadline { get; } = attemptDeadline;
|
||||||
|
internal TimeSpan PunchDeadline { get; } = punchDeadline;
|
||||||
|
internal TimeSpan? DirectDeadline { get; set; }
|
||||||
|
internal RendezvousConnectionState State { get; set; } = RendezvousConnectionState.Punching;
|
||||||
|
internal NetPeer? AcceptedPeer { get; set; }
|
||||||
|
}
|
||||||
|
|
||||||
|
private sealed class HostAttemptDeadline(
|
||||||
|
JoinAttemptId attemptId,
|
||||||
|
RendezvousConnectionState expectedState,
|
||||||
|
TimeSpan deadline)
|
||||||
|
{
|
||||||
|
internal JoinAttemptId AttemptId { get; } = attemptId;
|
||||||
|
internal RendezvousConnectionState ExpectedState { get; } = expectedState;
|
||||||
|
internal TimeSpan Deadline { get; } = deadline;
|
||||||
|
}
|
||||||
|
|
||||||
|
private sealed class DeferredConnectionRequest(
|
||||||
|
ConnectionRequest request,
|
||||||
|
string connectionTicket)
|
||||||
|
{
|
||||||
|
internal ConnectionRequest Request { get; } = request;
|
||||||
|
internal string ConnectionTicket { get; } = connectionTicket;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,114 @@
|
|||||||
|
using System.Net;
|
||||||
|
using System.Net.Sockets;
|
||||||
|
using LiteNetLib;
|
||||||
|
using LiteNetLib.Utils;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Client;
|
||||||
|
|
||||||
|
public sealed class RendezvousNetListener : INetEventListener
|
||||||
|
{
|
||||||
|
private NetManager? _manager;
|
||||||
|
|
||||||
|
public EventBasedNetListener GameplayEvents { get; } = new();
|
||||||
|
public EventBasedNatPunchListener PunchEvents { get; } = new();
|
||||||
|
|
||||||
|
public NetManager CreateManager()
|
||||||
|
{
|
||||||
|
if (_manager is not null)
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException(
|
||||||
|
"This Rendezvous listener is already bound to a LiteNetLib manager.");
|
||||||
|
}
|
||||||
|
|
||||||
|
NetManager manager = new(this) { NatPunchEnabled = true };
|
||||||
|
manager.NatPunchModule.Init(PunchEvents);
|
||||||
|
_manager = manager;
|
||||||
|
return manager;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal event Action<NetPeer>? RendezvousPeerConnected;
|
||||||
|
internal event Action<NetPeer, DisconnectInfo>? RendezvousPeerDisconnected;
|
||||||
|
internal event Action<ConnectionRequest>? RendezvousConnectionRequest;
|
||||||
|
internal event Action<IPEndPoint, SocketError>? RendezvousNetworkError;
|
||||||
|
|
||||||
|
internal void ValidateManager(NetManager manager)
|
||||||
|
{
|
||||||
|
if (!ReferenceEquals(_manager, manager))
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException(
|
||||||
|
"The LiteNetLib manager must be created by this Rendezvous listener.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public void OnPeerConnected(NetPeer peer)
|
||||||
|
{
|
||||||
|
RendezvousPeerConnected?.Invoke(peer);
|
||||||
|
((INetEventListener)GameplayEvents).OnPeerConnected(peer);
|
||||||
|
}
|
||||||
|
|
||||||
|
public void OnPeerDisconnected(NetPeer peer, DisconnectInfo disconnectInfo)
|
||||||
|
{
|
||||||
|
RendezvousPeerDisconnected?.Invoke(peer, disconnectInfo);
|
||||||
|
((INetEventListener)GameplayEvents).OnPeerDisconnected(peer, disconnectInfo);
|
||||||
|
}
|
||||||
|
|
||||||
|
public void OnNetworkError(IPEndPoint endPoint, SocketError socketError)
|
||||||
|
{
|
||||||
|
RendezvousNetworkError?.Invoke(endPoint, socketError);
|
||||||
|
((INetEventListener)GameplayEvents).OnNetworkError(endPoint, socketError);
|
||||||
|
}
|
||||||
|
|
||||||
|
public void OnNetworkReceive(
|
||||||
|
NetPeer peer,
|
||||||
|
NetPacketReader reader,
|
||||||
|
byte channelNumber,
|
||||||
|
DeliveryMethod deliveryMethod) =>
|
||||||
|
((INetEventListener)GameplayEvents).OnNetworkReceive(
|
||||||
|
peer,
|
||||||
|
reader,
|
||||||
|
channelNumber,
|
||||||
|
deliveryMethod);
|
||||||
|
|
||||||
|
public void OnNetworkReceiveUnconnected(
|
||||||
|
IPEndPoint remoteEndPoint,
|
||||||
|
NetPacketReader reader,
|
||||||
|
UnconnectedMessageType messageType) =>
|
||||||
|
((INetEventListener)GameplayEvents).OnNetworkReceiveUnconnected(
|
||||||
|
remoteEndPoint,
|
||||||
|
reader,
|
||||||
|
messageType);
|
||||||
|
|
||||||
|
public void OnNetworkLatencyUpdate(NetPeer peer, int latency) =>
|
||||||
|
((INetEventListener)GameplayEvents).OnNetworkLatencyUpdate(peer, latency);
|
||||||
|
|
||||||
|
public void OnConnectionRequest(ConnectionRequest request)
|
||||||
|
{
|
||||||
|
int position = request.Data.Position;
|
||||||
|
bool isRendezvous = DirectConnectionRequestCodec.IsRendezvousRequest(
|
||||||
|
request.Data.GetRemainingBytesSpan());
|
||||||
|
request.Data.SetPosition(position);
|
||||||
|
if (!isRendezvous)
|
||||||
|
{
|
||||||
|
((INetEventListener)GameplayEvents).OnConnectionRequest(request);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
Action<ConnectionRequest>? handler = RendezvousConnectionRequest;
|
||||||
|
if (handler is null)
|
||||||
|
{
|
||||||
|
request.RejectForce([]);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
handler(request);
|
||||||
|
}
|
||||||
|
|
||||||
|
public void OnMessageDelivered(NetPeer peer, object userData) =>
|
||||||
|
((INetEventListener)GameplayEvents).OnMessageDelivered(peer, userData);
|
||||||
|
|
||||||
|
public void OnNtpResponse(NtpPacket packet) =>
|
||||||
|
((INetEventListener)GameplayEvents).OnNtpResponse(packet);
|
||||||
|
|
||||||
|
public void OnPeerAddressChanged(NetPeer peer, IPEndPoint previousAddress) =>
|
||||||
|
((INetEventListener)GameplayEvents).OnPeerAddressChanged(peer, previousAddress);
|
||||||
|
}
|
||||||
@@ -8,8 +8,71 @@
|
|||||||
"resolved": "2.1.4",
|
"resolved": "2.1.4",
|
||||||
"contentHash": "KWlxvMw3Urpqj9joD96LRiK+LC62pQNs/zkXRJc+rHnxgkGp+vV703xzDrxRmv+V1YhCFfIGzs5nrVWtREIlyA=="
|
"contentHash": "KWlxvMw3Urpqj9joD96LRiK+LC62pQNs/zkXRJc+rHnxgkGp+vV703xzDrxRmv+V1YhCFfIGzs5nrVWtREIlyA=="
|
||||||
},
|
},
|
||||||
|
"Microsoft.Bcl.AsyncInterfaces": {
|
||||||
|
"type": "Transitive",
|
||||||
|
"resolved": "10.0.10",
|
||||||
|
"contentHash": "TFI6OKYE1XZz4SGuTSH70c6SBdPpFktXsoa1gCxTr3mKrhmXirnvaS0tKz+J3ZWICEAmMpEGn59nO4ICtUpQXA=="
|
||||||
|
},
|
||||||
|
"System.Buffers": {
|
||||||
|
"type": "Transitive",
|
||||||
|
"resolved": "4.6.1",
|
||||||
|
"contentHash": "N8GXpmiLMtljq7gwvyS+1QvKT/W2J8sNAvx+HVg4NGmsG/H+2k/y9QI23auLJRterrzCiDH+IWAw4V/GPwsMlw=="
|
||||||
|
},
|
||||||
|
"System.IO.Pipelines": {
|
||||||
|
"type": "Transitive",
|
||||||
|
"resolved": "10.0.10",
|
||||||
|
"contentHash": "7WX0W96y3dpQdYG4sEGdh38g3/0lOD4/dKbn2rRVOVzKhzoZUn2gKNIKaFeKWs8RCbpFfmmEWsRhSy95hMpvqA==",
|
||||||
|
"dependencies": {
|
||||||
|
"System.Buffers": "4.6.1",
|
||||||
|
"System.Memory": "4.6.3",
|
||||||
|
"System.Threading.Tasks.Extensions": "4.6.3"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"System.Memory": {
|
||||||
|
"type": "Transitive",
|
||||||
|
"resolved": "4.6.3",
|
||||||
|
"contentHash": "qdcDOgnFZY40+Q9876JUHnlHu7bosOHX8XISRoH94fwk6hgaeQGSgfZd8srWRZNt5bV9ZW2TljcegDNxsf+96A=="
|
||||||
|
},
|
||||||
|
"System.Runtime.CompilerServices.Unsafe": {
|
||||||
|
"type": "Transitive",
|
||||||
|
"resolved": "6.1.2",
|
||||||
|
"contentHash": "2hBr6zdbIBTDE3EhK7NSVNdX58uTK6iHW/P/Axmm9sl1xoGSLqDvMtpecn226TNwHByFokYwJmt/aQQNlO5CRw=="
|
||||||
|
},
|
||||||
|
"System.Text.Encodings.Web": {
|
||||||
|
"type": "Transitive",
|
||||||
|
"resolved": "10.0.10",
|
||||||
|
"contentHash": "o16m2YpDN/pjHsnxf9pTGwkpcuvjW8v1/wGUwJtM1c3QZUKm7ZEO/eYRJg7iIx6GxS2Zv9lAMHpiQwHDdgqauA==",
|
||||||
|
"dependencies": {
|
||||||
|
"System.Buffers": "4.6.1",
|
||||||
|
"System.Memory": "4.6.3",
|
||||||
|
"System.Runtime.CompilerServices.Unsafe": "6.1.2"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"System.Threading.Tasks.Extensions": {
|
||||||
|
"type": "Transitive",
|
||||||
|
"resolved": "4.6.3",
|
||||||
|
"contentHash": "7sCiwilJLYbTZELaKnc7RecBBXWXA+xMLQWZKWawBxYjp6DBlSE3v9/UcvKBvr1vv2tTOhipiogM8rRmxlhrVA=="
|
||||||
|
},
|
||||||
"finalfactory.rendezvous.contracts": {
|
"finalfactory.rendezvous.contracts": {
|
||||||
"type": "Project"
|
"type": "Project",
|
||||||
|
"dependencies": {
|
||||||
|
"System.Text.Json": "[10.0.10, )"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"System.Text.Json": {
|
||||||
|
"type": "CentralTransitive",
|
||||||
|
"requested": "[10.0.10, )",
|
||||||
|
"resolved": "10.0.10",
|
||||||
|
"contentHash": "bmsO6UdYtBdtn32zYXfsh7KlyTIzV/3V9hdT9RIb4pXKgYOsNxXR+VbWigNwBtNFVGYGm6Hwmqw5a+/IWFd36Q==",
|
||||||
|
"dependencies": {
|
||||||
|
"Microsoft.Bcl.AsyncInterfaces": "10.0.10",
|
||||||
|
"System.Buffers": "4.6.1",
|
||||||
|
"System.IO.Pipelines": "10.0.10",
|
||||||
|
"System.Memory": "4.6.3",
|
||||||
|
"System.Runtime.CompilerServices.Unsafe": "6.1.2",
|
||||||
|
"System.Text.Encodings.Web": "10.0.10",
|
||||||
|
"System.Threading.Tasks.Extensions": "4.6.3"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,96 @@
|
|||||||
|
namespace FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
public enum RendezvousErrorCode
|
||||||
|
{
|
||||||
|
None = 0,
|
||||||
|
InvalidRequest = 1,
|
||||||
|
UnsupportedContractVersion = 2,
|
||||||
|
IncompatibleProtocol = 3,
|
||||||
|
AuthenticationRequired = 4,
|
||||||
|
Forbidden = 5,
|
||||||
|
NotFound = 6,
|
||||||
|
Conflict = 7,
|
||||||
|
RateLimited = 8,
|
||||||
|
StaleHost = 9,
|
||||||
|
Expired = 10,
|
||||||
|
ReplayRejected = 11,
|
||||||
|
CapacityExceeded = 12,
|
||||||
|
ServiceUnavailable = 13,
|
||||||
|
InternalError = 14,
|
||||||
|
}
|
||||||
|
|
||||||
|
public enum ListingVisibility
|
||||||
|
{
|
||||||
|
Public = 1,
|
||||||
|
Unlisted = 2,
|
||||||
|
}
|
||||||
|
|
||||||
|
public enum PublisherTrustMode
|
||||||
|
{
|
||||||
|
ManagedDedicated = 1,
|
||||||
|
PlayerGrant = 2,
|
||||||
|
AnonymousUnlisted = 3,
|
||||||
|
}
|
||||||
|
|
||||||
|
public enum AddressFamilyKind
|
||||||
|
{
|
||||||
|
Ipv4 = 4,
|
||||||
|
Ipv6 = 6,
|
||||||
|
}
|
||||||
|
|
||||||
|
public enum ConnectionOutcomeKind
|
||||||
|
{
|
||||||
|
Connected = 1,
|
||||||
|
Cancelled = 2,
|
||||||
|
TimedOut = 3,
|
||||||
|
IncompatibleProtocol = 4,
|
||||||
|
StaleHost = 5,
|
||||||
|
ServiceRejected = 6,
|
||||||
|
HostRejected = 7,
|
||||||
|
TransportFailed = 8,
|
||||||
|
FallbackOffered = 9,
|
||||||
|
DirectoryNotFound = 10,
|
||||||
|
AttemptExpired = 11,
|
||||||
|
Unauthorized = 12,
|
||||||
|
RateLimited = 13,
|
||||||
|
NoHostPresence = 14,
|
||||||
|
ServiceUnavailable = 15,
|
||||||
|
MediatorUnavailable = 16,
|
||||||
|
PunchTimedOut = 17,
|
||||||
|
DirectConnectTimedOut = 18,
|
||||||
|
TransportError = 19,
|
||||||
|
ManagerStopped = 20,
|
||||||
|
Disposed = 21,
|
||||||
|
}
|
||||||
|
|
||||||
|
public enum ConnectionElapsedBucket
|
||||||
|
{
|
||||||
|
UnderOneSecond = 1,
|
||||||
|
OneToFiveSeconds = 2,
|
||||||
|
FiveToFifteenSeconds = 3,
|
||||||
|
FifteenToThirtySeconds = 4,
|
||||||
|
ThirtySecondsOrMore = 5,
|
||||||
|
}
|
||||||
|
|
||||||
|
public enum UdpPresenceMessageType : byte
|
||||||
|
{
|
||||||
|
HostPresence = 1,
|
||||||
|
ClientPresence = 2,
|
||||||
|
}
|
||||||
|
|
||||||
|
public enum UdpDecodeError
|
||||||
|
{
|
||||||
|
None = 0,
|
||||||
|
DatagramTooLarge = 1,
|
||||||
|
Truncated = 2,
|
||||||
|
InvalidMagic = 3,
|
||||||
|
UnsupportedVersion = 4,
|
||||||
|
UnknownMessageType = 5,
|
||||||
|
InvalidFlags = 6,
|
||||||
|
InvalidHandle = 7,
|
||||||
|
InvalidAddressFamily = 8,
|
||||||
|
InvalidAddress = 9,
|
||||||
|
InvalidPort = 10,
|
||||||
|
InvalidCapability = 11,
|
||||||
|
TrailingData = 12,
|
||||||
|
}
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
namespace FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
public static class ContractLimits
|
||||||
|
{
|
||||||
|
public const int ContractVersion = 1;
|
||||||
|
public const int HttpRequestMaxBytes = 16 * 1024;
|
||||||
|
public const int BrowserResponseMaxBytes = 256 * 1024;
|
||||||
|
public const int UdpDatagramMaxBytes = 1_200;
|
||||||
|
public const int MetadataMaxBytes = 4 * 1024;
|
||||||
|
public const int MetadataMaxKeys = 32;
|
||||||
|
public const int MetadataKeyMaxBytes = 64;
|
||||||
|
public const int MetadataValueMaxBytes = 256;
|
||||||
|
public const int BrowserPageMaxItems = 100;
|
||||||
|
public const int GameIdMaxCharacters = 64;
|
||||||
|
public const int EnvironmentIdMaxCharacters = 32;
|
||||||
|
public const int RegionIdMaxCharacters = 32;
|
||||||
|
public const int DisplayNameMaxBytes = 128;
|
||||||
|
public const int BuildVersionMaxBytes = 64;
|
||||||
|
public const int IdempotencyKeyMaxCharacters = 64;
|
||||||
|
public const int CursorMaxCharacters = 512;
|
||||||
|
public const int DiagnosticCodeMaxCharacters = 64;
|
||||||
|
public const int ErrorMessageMaxBytes = 256;
|
||||||
|
public const int OpaqueHttpCredentialMaxCharacters = 1_024;
|
||||||
|
public const int UdpCapabilityMaxCharacters = 192;
|
||||||
|
public const int ConnectionTicketMaxCharacters = 192;
|
||||||
|
public const int DerivedCredentialCharacters = 43;
|
||||||
|
public const int NatPunchRequestTokenCharacters = 192;
|
||||||
|
public const int LiteNetLibNatTokenMaxCharacters = 256;
|
||||||
|
public const int SessionCapacityMaxPlayers = 10_000;
|
||||||
|
}
|
||||||
@@ -0,0 +1,47 @@
|
|||||||
|
using System.Text.Json.Serialization;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
public sealed class SessionCapacity
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public int CurrentPlayers { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public int MaximumPlayers { get; set; }
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class NetworkEndpoint
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public AddressFamilyKind AddressFamily { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string Address { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public int Port { get; set; }
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class ApiError
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public int ContractVersion { get; set; } = ContractLimits.ContractVersion;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public RendezvousErrorCode Code { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string Message { get; set; } = string.Empty;
|
||||||
|
public string? CorrelationId { get; set; }
|
||||||
|
public int? RetryAfterSeconds { get; set; }
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class HealthResponse
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public int ContractVersion { get; set; } = ContractLimits.ContractVersion;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string Status { get; set; } = string.Empty;
|
||||||
|
}
|
||||||
@@ -0,0 +1,153 @@
|
|||||||
|
using System.Net;
|
||||||
|
using System.Net.Sockets;
|
||||||
|
using System.Text;
|
||||||
|
using System.Text.Json;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
public static class ContractValidation
|
||||||
|
{
|
||||||
|
private const string CapabilityAlphabet =
|
||||||
|
"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_";
|
||||||
|
|
||||||
|
public static RendezvousErrorCode ValidateContractVersion(int contractVersion) =>
|
||||||
|
contractVersion == ContractLimits.ContractVersion
|
||||||
|
? RendezvousErrorCode.None
|
||||||
|
: RendezvousErrorCode.UnsupportedContractVersion;
|
||||||
|
|
||||||
|
public static bool AreProtocolsCompatible(uint requested, uint offered) => requested == offered;
|
||||||
|
|
||||||
|
public static bool IsHttpRequestSizeValid(int byteCount) =>
|
||||||
|
byteCount is >= 0 and <= ContractLimits.HttpRequestMaxBytes;
|
||||||
|
|
||||||
|
public static bool IsBrowserResponseSizeValid(int byteCount) =>
|
||||||
|
byteCount is >= 0 and <= ContractLimits.BrowserResponseMaxBytes;
|
||||||
|
|
||||||
|
public static bool IsUtf8LengthWithin(string? value, int maximumBytes)
|
||||||
|
{
|
||||||
|
if (maximumBytes < 0)
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(nameof(maximumBytes));
|
||||||
|
}
|
||||||
|
|
||||||
|
return value is not null && Encoding.UTF8.GetByteCount(value) <= maximumBytes;
|
||||||
|
}
|
||||||
|
|
||||||
|
public static bool IsPageSizeValid(int pageSize) =>
|
||||||
|
pageSize is >= 1 and <= ContractLimits.BrowserPageMaxItems;
|
||||||
|
|
||||||
|
public static bool IsIdempotencyKeyValid(string? value) =>
|
||||||
|
IsVisibleAsciiWithin(value, ContractLimits.IdempotencyKeyMaxCharacters);
|
||||||
|
|
||||||
|
public static bool IsCursorValid(string? value) =>
|
||||||
|
value is null || IsVisibleAsciiWithin(value, ContractLimits.CursorMaxCharacters);
|
||||||
|
|
||||||
|
public static bool IsDiagnosticCodeValid(string? value) =>
|
||||||
|
value is null || IsVisibleAsciiWithin(value, ContractLimits.DiagnosticCodeMaxCharacters);
|
||||||
|
|
||||||
|
public static bool IsReportableConnectionOutcome(ConnectionOutcomeKind outcome) => outcome is
|
||||||
|
ConnectionOutcomeKind.Connected
|
||||||
|
or ConnectionOutcomeKind.Cancelled
|
||||||
|
or ConnectionOutcomeKind.TimedOut
|
||||||
|
or ConnectionOutcomeKind.StaleHost
|
||||||
|
or ConnectionOutcomeKind.TransportFailed
|
||||||
|
or ConnectionOutcomeKind.FallbackOffered
|
||||||
|
or ConnectionOutcomeKind.AttemptExpired
|
||||||
|
or ConnectionOutcomeKind.NoHostPresence
|
||||||
|
or ConnectionOutcomeKind.MediatorUnavailable
|
||||||
|
or ConnectionOutcomeKind.PunchTimedOut
|
||||||
|
or ConnectionOutcomeKind.DirectConnectTimedOut
|
||||||
|
or ConnectionOutcomeKind.HostRejected
|
||||||
|
or ConnectionOutcomeKind.TransportError
|
||||||
|
or ConnectionOutcomeKind.ManagerStopped
|
||||||
|
or ConnectionOutcomeKind.Disposed;
|
||||||
|
|
||||||
|
public static bool IsBuildVersionValid(string? value) =>
|
||||||
|
!string.IsNullOrWhiteSpace(value)
|
||||||
|
&& IsUtf8LengthWithin(value, ContractLimits.BuildVersionMaxBytes);
|
||||||
|
|
||||||
|
public static bool IsDisplayNameValid(string? value) =>
|
||||||
|
!string.IsNullOrWhiteSpace(value)
|
||||||
|
&& IsUtf8LengthWithin(value, ContractLimits.DisplayNameMaxBytes);
|
||||||
|
|
||||||
|
public static bool IsOpaqueHttpCredentialValid(string? value) =>
|
||||||
|
value is not null
|
||||||
|
&& value.Length is > 0 and <= ContractLimits.OpaqueHttpCredentialMaxCharacters;
|
||||||
|
|
||||||
|
public static bool IsCapacityValid(SessionCapacity? capacity) =>
|
||||||
|
capacity is not null
|
||||||
|
&& capacity.MaximumPlayers is >= 1 and <= ContractLimits.SessionCapacityMaxPlayers
|
||||||
|
&& capacity.CurrentPlayers >= 0
|
||||||
|
&& capacity.CurrentPlayers <= capacity.MaximumPlayers;
|
||||||
|
|
||||||
|
public static bool IsCapabilityValid(string? capability) =>
|
||||||
|
IsBase64UrlValueValid(capability, ContractLimits.UdpCapabilityMaxCharacters);
|
||||||
|
|
||||||
|
public static bool IsConnectionTicketValid(string? ticket) =>
|
||||||
|
IsBase64UrlValueValid(ticket, ContractLimits.ConnectionTicketMaxCharacters);
|
||||||
|
|
||||||
|
public static bool IsNetworkEndpointValid(NetworkEndpoint? endpoint)
|
||||||
|
{
|
||||||
|
if (endpoint is null
|
||||||
|
|| endpoint.Port is < 1 or > ushort.MaxValue
|
||||||
|
|| !IPAddress.TryParse(endpoint.Address, out IPAddress? address))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
return endpoint.AddressFamily switch
|
||||||
|
{
|
||||||
|
AddressFamilyKind.Ipv4 => address.AddressFamily == AddressFamily.InterNetwork,
|
||||||
|
AddressFamilyKind.Ipv6 => address.AddressFamily == AddressFamily.InterNetworkV6,
|
||||||
|
_ => false,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
public static bool IsMetadataValid(IReadOnlyDictionary<string, string>? metadata)
|
||||||
|
{
|
||||||
|
if (metadata is null || metadata.Count > ContractLimits.MetadataMaxKeys)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach (KeyValuePair<string, string> item in metadata)
|
||||||
|
{
|
||||||
|
if (string.IsNullOrWhiteSpace(item.Key)
|
||||||
|
|| !IsUtf8LengthWithin(item.Key, ContractLimits.MetadataKeyMaxBytes)
|
||||||
|
|| !IsUtf8LengthWithin(item.Value, ContractLimits.MetadataValueMaxBytes))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
byte[] encoded = JsonSerializer.SerializeToUtf8Bytes(metadata, ContractJson.Options);
|
||||||
|
return encoded.Length <= ContractLimits.MetadataMaxBytes;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal static bool IsSlug(string? value, int maximumCharacters)
|
||||||
|
{
|
||||||
|
if (string.IsNullOrEmpty(value)
|
||||||
|
|| value.Length > maximumCharacters
|
||||||
|
|| value[0] is < 'a' or > 'z')
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
return value.All(static character =>
|
||||||
|
character is >= 'a' and <= 'z'
|
||||||
|
or >= '0' and <= '9'
|
||||||
|
or '-');
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool IsBase64UrlValueValid(string? value, int maximumCharacters) =>
|
||||||
|
value is not null
|
||||||
|
&& value.Length is > 0
|
||||||
|
&& value.Length <= maximumCharacters
|
||||||
|
&& value.All(static character => CapabilityAlphabet.Contains(character));
|
||||||
|
|
||||||
|
private static bool IsVisibleAsciiWithin(string? value, int maximumCharacters) =>
|
||||||
|
value is not null
|
||||||
|
&& value.Length is > 0
|
||||||
|
&& value.Length <= maximumCharacters
|
||||||
|
&& value.All(static character => character is >= '!' and <= '~');
|
||||||
|
}
|
||||||
@@ -7,4 +7,7 @@
|
|||||||
<PackageId>FinalFactory.Rendezvous.Contracts</PackageId>
|
<PackageId>FinalFactory.Rendezvous.Contracts</PackageId>
|
||||||
<Description>Versioned transport-neutral contracts for Final Factory Rendezvous.</Description>
|
<Description>Versioned transport-neutral contracts for Final Factory Rendezvous.</Description>
|
||||||
</PropertyGroup>
|
</PropertyGroup>
|
||||||
|
<ItemGroup>
|
||||||
|
<PackageReference Include="System.Text.Json" />
|
||||||
|
</ItemGroup>
|
||||||
</Project>
|
</Project>
|
||||||
|
|||||||
@@ -0,0 +1,33 @@
|
|||||||
|
using System.Text.Json.Serialization;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
public sealed class ReportConnectionOutcomeRequest
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public int ContractVersion { get; set; } = ContractLimits.ContractVersion;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public ConnectionOutcomeKind Outcome { get; set; }
|
||||||
|
|
||||||
|
public ConnectionElapsedBucket ElapsedBucket { get; set; }
|
||||||
|
|
||||||
|
[Obsolete("Use ElapsedBucket. Exact elapsed time is accepted only for v1 compatibility and is not retained.")]
|
||||||
|
[JsonIgnore(Condition = JsonIgnoreCondition.WhenWritingDefault)]
|
||||||
|
public int ElapsedMilliseconds { get; set; }
|
||||||
|
|
||||||
|
[Obsolete("Diagnostic codes are accepted only for v1 compatibility and are not retained.")]
|
||||||
|
public string? DiagnosticCode { get; set; }
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class ReportConnectionOutcomeResponse
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public int ContractVersion { get; set; } = ContractLimits.ContractVersion;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public bool Accepted { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public bool IsDuplicate { get; set; }
|
||||||
|
}
|
||||||
@@ -0,0 +1,78 @@
|
|||||||
|
using System.Text.Json.Serialization;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
public sealed class CreateJoinAttemptRequest
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public int ContractVersion { get; set; } = ContractLimits.ContractVersion;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string IdempotencyKey { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public GameId GameId { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public EnvironmentId EnvironmentId { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public SessionListingId ListingId { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public uint ProtocolVersion { get; set; }
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class CreateJoinAttemptResponse
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public int ContractVersion { get; set; } = ContractLimits.ContractVersion;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public JoinAttemptId AttemptId { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public MediationHandle MediationHandle { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string ClientPunchCapability { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string ConnectionTicketDigest { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public DateTimeOffset ExpiresAt { get; set; }
|
||||||
|
public NetworkEndpoint? DedicatedFallback { get; set; }
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class HostJoinAttempt
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public JoinAttemptId AttemptId { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public MediationHandle MediationHandle { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string HostPunchCapability { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string ConnectionTicketDigest { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public bool IsCancelled { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public DateTimeOffset ExpiresAt { get; set; }
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class BrowseHostJoinAttemptsResponse
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public int ContractVersion { get; set; } = ContractLimits.ContractVersion;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public List<HostJoinAttempt> Items { get; set; } = [];
|
||||||
|
|
||||||
|
public string? NextCursor { get; set; }
|
||||||
|
}
|
||||||
@@ -0,0 +1,206 @@
|
|||||||
|
using System.Text.Json.Serialization;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
public sealed class SessionListing
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public int ContractVersion { get; set; } = ContractLimits.ContractVersion;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public SessionListingId ListingId { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public GameId GameId { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public EnvironmentId EnvironmentId { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public RegionId RegionId { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public uint ProtocolVersion { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string BuildVersion { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string DisplayName { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public ListingVisibility Visibility { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public PublisherTrustMode PublisherTrustMode { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public SessionCapacity Capacity { get; set; } = new();
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public Dictionary<string, string> Metadata { get; set; } = new(StringComparer.Ordinal);
|
||||||
|
|
||||||
|
public NetworkEndpoint? DedicatedFallback { get; set; }
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class RegisterSessionRequest
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public int ContractVersion { get; set; } = ContractLimits.ContractVersion;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string IdempotencyKey { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public GameId GameId { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public EnvironmentId EnvironmentId { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public RegionId RegionId { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public uint ProtocolVersion { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string BuildVersion { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string DisplayName { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public ListingVisibility Visibility { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public SessionCapacity Capacity { get; set; } = new();
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public Dictionary<string, string> Metadata { get; set; } = new(StringComparer.Ordinal);
|
||||||
|
|
||||||
|
public NetworkEndpoint? DedicatedFallback { get; set; }
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class RegisterSessionResponse
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public int ContractVersion { get; set; } = ContractLimits.ContractVersion;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public SessionListingId ListingId { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public LeaseId LeaseId { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string LeaseToken { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public MediationHandle HostPresenceHandle { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string HostPresenceCapability { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public DateTimeOffset ExpiresAt { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public int LeaseRenewAfterSeconds { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public int HostPresenceRefreshAfterSeconds { get; set; }
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class RenewLeaseRequest
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public int ContractVersion { get; set; } = ContractLimits.ContractVersion;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string LeaseToken { get; set; } = string.Empty;
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class RenewLeaseResponse
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public int ContractVersion { get; set; } = ContractLimits.ContractVersion;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public DateTimeOffset ExpiresAt { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public int RenewAfterSeconds { get; set; }
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class UpdateSessionRequest
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public int ContractVersion { get; set; } = ContractLimits.ContractVersion;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string LeaseToken { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string BuildVersion { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string DisplayName { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public SessionCapacity Capacity { get; set; } = new();
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public Dictionary<string, string> Metadata { get; set; } = new(StringComparer.Ordinal);
|
||||||
|
|
||||||
|
public NetworkEndpoint? DedicatedFallback { get; set; }
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class DeleteSessionRequest
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public int ContractVersion { get; set; } = ContractLimits.ContractVersion;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string LeaseToken { get; set; } = string.Empty;
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class BrowseSessionsRequest
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public int ContractVersion { get; set; } = ContractLimits.ContractVersion;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public GameId GameId { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public EnvironmentId EnvironmentId { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public uint ProtocolVersion { get; set; }
|
||||||
|
public RegionId? RegionId { get; set; }
|
||||||
|
public int PageSize { get; set; } = ContractLimits.BrowserPageMaxItems;
|
||||||
|
|
||||||
|
public bool ExcludeFull { get; set; }
|
||||||
|
|
||||||
|
public string? Cursor { get; set; }
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class BrowseSessionsResponse
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public int ContractVersion { get; set; } = ContractLimits.ContractVersion;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public List<SessionListing> Items { get; set; } = [];
|
||||||
|
|
||||||
|
public string? NextCursor { get; set; }
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class GetSessionResponse
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public int ContractVersion { get; set; } = ContractLimits.ContractVersion;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public SessionListing Session { get; set; } = new();
|
||||||
|
}
|
||||||
@@ -0,0 +1,112 @@
|
|||||||
|
using System.Text.Json.Serialization;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
[JsonConverter(typeof(SessionListingIdJsonConverter))]
|
||||||
|
public readonly struct SessionListingId : IEquatable<SessionListingId>
|
||||||
|
{
|
||||||
|
public SessionListingId(Guid value) => Value = GuidIdentifier.RequireNonEmpty(value, nameof(value));
|
||||||
|
public Guid Value { get; }
|
||||||
|
public static bool TryParse(string? value, out SessionListingId id) =>
|
||||||
|
GuidIdentifier.TryParse(value, static guid => new SessionListingId(guid), out id);
|
||||||
|
public bool Equals(SessionListingId other) => Value.Equals(other.Value);
|
||||||
|
public override bool Equals(object? obj) => obj is SessionListingId other && Equals(other);
|
||||||
|
public override int GetHashCode() => Value.GetHashCode();
|
||||||
|
public override string ToString() => Value.ToString("D");
|
||||||
|
public static bool operator ==(SessionListingId left, SessionListingId right) => left.Equals(right);
|
||||||
|
public static bool operator !=(SessionListingId left, SessionListingId right) => !left.Equals(right);
|
||||||
|
}
|
||||||
|
|
||||||
|
[JsonConverter(typeof(LeaseIdJsonConverter))]
|
||||||
|
public readonly struct LeaseId : IEquatable<LeaseId>
|
||||||
|
{
|
||||||
|
public LeaseId(Guid value) => Value = GuidIdentifier.RequireNonEmpty(value, nameof(value));
|
||||||
|
public Guid Value { get; }
|
||||||
|
public static bool TryParse(string? value, out LeaseId id) =>
|
||||||
|
GuidIdentifier.TryParse(value, static guid => new LeaseId(guid), out id);
|
||||||
|
public bool Equals(LeaseId other) => Value.Equals(other.Value);
|
||||||
|
public override bool Equals(object? obj) => obj is LeaseId other && Equals(other);
|
||||||
|
public override int GetHashCode() => Value.GetHashCode();
|
||||||
|
public override string ToString() => Value.ToString("D");
|
||||||
|
public static bool operator ==(LeaseId left, LeaseId right) => left.Equals(right);
|
||||||
|
public static bool operator !=(LeaseId left, LeaseId right) => !left.Equals(right);
|
||||||
|
}
|
||||||
|
|
||||||
|
[JsonConverter(typeof(JoinAttemptIdJsonConverter))]
|
||||||
|
public readonly struct JoinAttemptId : IEquatable<JoinAttemptId>
|
||||||
|
{
|
||||||
|
public JoinAttemptId(Guid value) => Value = GuidIdentifier.RequireNonEmpty(value, nameof(value));
|
||||||
|
public Guid Value { get; }
|
||||||
|
public static bool TryParse(string? value, out JoinAttemptId id) =>
|
||||||
|
GuidIdentifier.TryParse(value, static guid => new JoinAttemptId(guid), out id);
|
||||||
|
public bool Equals(JoinAttemptId other) => Value.Equals(other.Value);
|
||||||
|
public override bool Equals(object? obj) => obj is JoinAttemptId other && Equals(other);
|
||||||
|
public override int GetHashCode() => Value.GetHashCode();
|
||||||
|
public override string ToString() => Value.ToString("D");
|
||||||
|
public static bool operator ==(JoinAttemptId left, JoinAttemptId right) => left.Equals(right);
|
||||||
|
public static bool operator !=(JoinAttemptId left, JoinAttemptId right) => !left.Equals(right);
|
||||||
|
}
|
||||||
|
|
||||||
|
[JsonConverter(typeof(MediationHandleJsonConverter))]
|
||||||
|
public readonly struct MediationHandle : IEquatable<MediationHandle>
|
||||||
|
{
|
||||||
|
public MediationHandle(Guid value) => Value = GuidIdentifier.RequireNonEmpty(value, nameof(value));
|
||||||
|
public Guid Value { get; }
|
||||||
|
public static bool TryParse(string? value, out MediationHandle id) =>
|
||||||
|
GuidIdentifier.TryParse(value, static guid => new MediationHandle(guid), out id);
|
||||||
|
public bool Equals(MediationHandle other) => Value.Equals(other.Value);
|
||||||
|
public override bool Equals(object? obj) => obj is MediationHandle other && Equals(other);
|
||||||
|
public override int GetHashCode() => Value.GetHashCode();
|
||||||
|
public override string ToString() => Value.ToString("D");
|
||||||
|
public static bool operator ==(MediationHandle left, MediationHandle right) => left.Equals(right);
|
||||||
|
public static bool operator !=(MediationHandle left, MediationHandle right) => !left.Equals(right);
|
||||||
|
}
|
||||||
|
|
||||||
|
internal static class GuidIdentifier
|
||||||
|
{
|
||||||
|
public static Guid RequireNonEmpty(Guid value, string parameterName) =>
|
||||||
|
value != Guid.Empty
|
||||||
|
? value
|
||||||
|
: throw new ArgumentException("Opaque identifiers cannot be empty.", parameterName);
|
||||||
|
|
||||||
|
public static bool TryParse<TIdentifier>(
|
||||||
|
string? value,
|
||||||
|
Func<Guid, TIdentifier> factory,
|
||||||
|
out TIdentifier identifier)
|
||||||
|
{
|
||||||
|
if (Guid.TryParseExact(value, "D", out Guid guid) && guid != Guid.Empty)
|
||||||
|
{
|
||||||
|
identifier = factory(guid);
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
identifier = default!;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
internal abstract class GuidIdentifierJsonConverter<TIdentifier> :
|
||||||
|
StringIdentifierJsonConverter<TIdentifier>
|
||||||
|
{
|
||||||
|
protected sealed override string Format(TIdentifier value) => value?.ToString() ?? string.Empty;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class SessionListingIdJsonConverter : GuidIdentifierJsonConverter<SessionListingId>
|
||||||
|
{
|
||||||
|
protected override SessionListingId Parse(string value) => new(Guid.ParseExact(value, "D"));
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class LeaseIdJsonConverter : GuidIdentifierJsonConverter<LeaseId>
|
||||||
|
{
|
||||||
|
protected override LeaseId Parse(string value) => new(Guid.ParseExact(value, "D"));
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class JoinAttemptIdJsonConverter : GuidIdentifierJsonConverter<JoinAttemptId>
|
||||||
|
{
|
||||||
|
protected override JoinAttemptId Parse(string value) => new(Guid.ParseExact(value, "D"));
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class MediationHandleJsonConverter : GuidIdentifierJsonConverter<MediationHandle>
|
||||||
|
{
|
||||||
|
protected override MediationHandle Parse(string value) => new(Guid.ParseExact(value, "D"));
|
||||||
|
}
|
||||||
@@ -0,0 +1,126 @@
|
|||||||
|
using System.Text.Json.Serialization;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
[JsonConverter(typeof(GameIdJsonConverter))]
|
||||||
|
public readonly struct GameId : IEquatable<GameId>
|
||||||
|
{
|
||||||
|
public GameId(string value)
|
||||||
|
{
|
||||||
|
if (!ContractValidation.IsSlug(value, ContractLimits.GameIdMaxCharacters))
|
||||||
|
{
|
||||||
|
throw new ArgumentException("Game IDs must be lowercase URL-safe slugs.", nameof(value));
|
||||||
|
}
|
||||||
|
|
||||||
|
Value = value;
|
||||||
|
}
|
||||||
|
|
||||||
|
public string Value { get; }
|
||||||
|
|
||||||
|
public static bool TryParse(string? value, out GameId gameId)
|
||||||
|
{
|
||||||
|
if (ContractValidation.IsSlug(value, ContractLimits.GameIdMaxCharacters))
|
||||||
|
{
|
||||||
|
gameId = new GameId(value!);
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
gameId = default;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool Equals(GameId other) => string.Equals(Value, other.Value, StringComparison.Ordinal);
|
||||||
|
public override bool Equals(object? obj) => obj is GameId other && Equals(other);
|
||||||
|
public override int GetHashCode() => StringComparer.Ordinal.GetHashCode(Value ?? string.Empty);
|
||||||
|
public override string ToString() => Value ?? string.Empty;
|
||||||
|
public static bool operator ==(GameId left, GameId right) => left.Equals(right);
|
||||||
|
public static bool operator !=(GameId left, GameId right) => !left.Equals(right);
|
||||||
|
}
|
||||||
|
|
||||||
|
[JsonConverter(typeof(EnvironmentIdJsonConverter))]
|
||||||
|
public readonly struct EnvironmentId : IEquatable<EnvironmentId>
|
||||||
|
{
|
||||||
|
public EnvironmentId(string value)
|
||||||
|
{
|
||||||
|
if (!ContractValidation.IsSlug(value, ContractLimits.EnvironmentIdMaxCharacters))
|
||||||
|
{
|
||||||
|
throw new ArgumentException("Environment IDs must be lowercase URL-safe slugs.", nameof(value));
|
||||||
|
}
|
||||||
|
|
||||||
|
Value = value;
|
||||||
|
}
|
||||||
|
|
||||||
|
public string Value { get; }
|
||||||
|
|
||||||
|
public static bool TryParse(string? value, out EnvironmentId environmentId)
|
||||||
|
{
|
||||||
|
if (ContractValidation.IsSlug(value, ContractLimits.EnvironmentIdMaxCharacters))
|
||||||
|
{
|
||||||
|
environmentId = new EnvironmentId(value!);
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
environmentId = default;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool Equals(EnvironmentId other) => string.Equals(Value, other.Value, StringComparison.Ordinal);
|
||||||
|
public override bool Equals(object? obj) => obj is EnvironmentId other && Equals(other);
|
||||||
|
public override int GetHashCode() => StringComparer.Ordinal.GetHashCode(Value ?? string.Empty);
|
||||||
|
public override string ToString() => Value ?? string.Empty;
|
||||||
|
public static bool operator ==(EnvironmentId left, EnvironmentId right) => left.Equals(right);
|
||||||
|
public static bool operator !=(EnvironmentId left, EnvironmentId right) => !left.Equals(right);
|
||||||
|
}
|
||||||
|
|
||||||
|
[JsonConverter(typeof(RegionIdJsonConverter))]
|
||||||
|
public readonly struct RegionId : IEquatable<RegionId>
|
||||||
|
{
|
||||||
|
public RegionId(string value)
|
||||||
|
{
|
||||||
|
if (!ContractValidation.IsSlug(value, ContractLimits.RegionIdMaxCharacters))
|
||||||
|
{
|
||||||
|
throw new ArgumentException("Region IDs must be lowercase URL-safe slugs.", nameof(value));
|
||||||
|
}
|
||||||
|
|
||||||
|
Value = value;
|
||||||
|
}
|
||||||
|
|
||||||
|
public string Value { get; }
|
||||||
|
|
||||||
|
public static bool TryParse(string? value, out RegionId regionId)
|
||||||
|
{
|
||||||
|
if (ContractValidation.IsSlug(value, ContractLimits.RegionIdMaxCharacters))
|
||||||
|
{
|
||||||
|
regionId = new RegionId(value!);
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
regionId = default;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool Equals(RegionId other) => string.Equals(Value, other.Value, StringComparison.Ordinal);
|
||||||
|
public override bool Equals(object? obj) => obj is RegionId other && Equals(other);
|
||||||
|
public override int GetHashCode() => StringComparer.Ordinal.GetHashCode(Value ?? string.Empty);
|
||||||
|
public override string ToString() => Value ?? string.Empty;
|
||||||
|
public static bool operator ==(RegionId left, RegionId right) => left.Equals(right);
|
||||||
|
public static bool operator !=(RegionId left, RegionId right) => !left.Equals(right);
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class GameIdJsonConverter : StringIdentifierJsonConverter<GameId>
|
||||||
|
{
|
||||||
|
protected override GameId Parse(string value) => new(value);
|
||||||
|
protected override string Format(GameId value) => value.Value;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class EnvironmentIdJsonConverter : StringIdentifierJsonConverter<EnvironmentId>
|
||||||
|
{
|
||||||
|
protected override EnvironmentId Parse(string value) => new(value);
|
||||||
|
protected override string Format(EnvironmentId value) => value.Value;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class RegionIdJsonConverter : StringIdentifierJsonConverter<RegionId>
|
||||||
|
{
|
||||||
|
protected override RegionId Parse(string value) => new(value);
|
||||||
|
protected override string Format(RegionId value) => value.Value;
|
||||||
|
}
|
||||||
@@ -0,0 +1,37 @@
|
|||||||
|
using System.Text.Json;
|
||||||
|
using System.Text.Json.Serialization;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
internal abstract class StringIdentifierJsonConverter<TIdentifier> : JsonConverter<TIdentifier>
|
||||||
|
{
|
||||||
|
public sealed override TIdentifier Read(
|
||||||
|
ref Utf8JsonReader reader,
|
||||||
|
Type typeToConvert,
|
||||||
|
JsonSerializerOptions options)
|
||||||
|
{
|
||||||
|
if (reader.TokenType != JsonTokenType.String)
|
||||||
|
{
|
||||||
|
throw new JsonException($"{typeof(TIdentifier).Name} must be a JSON string.");
|
||||||
|
}
|
||||||
|
|
||||||
|
string value = reader.GetString() ?? string.Empty;
|
||||||
|
|
||||||
|
try
|
||||||
|
{
|
||||||
|
return Parse(value);
|
||||||
|
}
|
||||||
|
catch (Exception exception) when (exception is ArgumentException or FormatException)
|
||||||
|
{
|
||||||
|
throw new JsonException($"Invalid {typeof(TIdentifier).Name}.", exception);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed override void Write(
|
||||||
|
Utf8JsonWriter writer,
|
||||||
|
TIdentifier value,
|
||||||
|
JsonSerializerOptions options) => writer.WriteStringValue(Format(value));
|
||||||
|
|
||||||
|
protected abstract TIdentifier Parse(string value);
|
||||||
|
protected abstract string Format(TIdentifier value);
|
||||||
|
}
|
||||||
@@ -0,0 +1,51 @@
|
|||||||
|
using System.Text.Json;
|
||||||
|
using System.Text.Json.Serialization;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
public static class ContractJson
|
||||||
|
{
|
||||||
|
private static readonly JsonSerializerOptions SharedOptions = CreateReadOnlyOptions();
|
||||||
|
|
||||||
|
public static JsonSerializerOptions Options => SharedOptions;
|
||||||
|
|
||||||
|
public static JsonSerializerOptions CreateOptions()
|
||||||
|
{
|
||||||
|
JsonSerializerOptions options = new(JsonSerializerDefaults.Web);
|
||||||
|
Configure(options);
|
||||||
|
return options;
|
||||||
|
}
|
||||||
|
|
||||||
|
public static void Configure(JsonSerializerOptions options)
|
||||||
|
{
|
||||||
|
if (options is null)
|
||||||
|
{
|
||||||
|
throw new ArgumentNullException(nameof(options));
|
||||||
|
}
|
||||||
|
|
||||||
|
options.AllowTrailingCommas = false;
|
||||||
|
options.DefaultIgnoreCondition = JsonIgnoreCondition.WhenWritingNull;
|
||||||
|
// Nine is the minimum that lets ASP.NET generate the nullable fallback
|
||||||
|
// OpenAPI schema; the 16 KiB HTTP body limit still bounds parser work.
|
||||||
|
options.MaxDepth = 9;
|
||||||
|
options.NumberHandling = JsonNumberHandling.Strict;
|
||||||
|
options.PropertyNameCaseInsensitive = false;
|
||||||
|
options.PropertyNamingPolicy = JsonNamingPolicy.CamelCase;
|
||||||
|
options.ReadCommentHandling = JsonCommentHandling.Disallow;
|
||||||
|
options.UnmappedMemberHandling = JsonUnmappedMemberHandling.Skip;
|
||||||
|
options.WriteIndented = false;
|
||||||
|
|
||||||
|
if (!options.Converters.OfType<JsonStringEnumConverter>().Any())
|
||||||
|
{
|
||||||
|
options.Converters.Add(
|
||||||
|
new JsonStringEnumConverter(JsonNamingPolicy.CamelCase, allowIntegerValues: false));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static JsonSerializerOptions CreateReadOnlyOptions()
|
||||||
|
{
|
||||||
|
JsonSerializerOptions options = CreateOptions();
|
||||||
|
options.MakeReadOnly(populateMissingResolver: true);
|
||||||
|
return options;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,149 @@
|
|||||||
|
using System.Security.Cryptography;
|
||||||
|
using System.Text;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
public sealed class NatIntroductionToken
|
||||||
|
{
|
||||||
|
public JoinAttemptId AttemptId { get; set; }
|
||||||
|
public string ConnectionTicket { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
public override string ToString() =>
|
||||||
|
$"[NatIntroductionToken {AttemptId}; ticket redacted]";
|
||||||
|
}
|
||||||
|
|
||||||
|
public static class NatIntroductionTokenCodec
|
||||||
|
{
|
||||||
|
public const int EncodedLength = ContractLimits.DerivedCredentialCharacters;
|
||||||
|
|
||||||
|
private const int DecodedLength = 32;
|
||||||
|
private const int AttemptIdLength = 16;
|
||||||
|
private const int AuthenticatorLength = DecodedLength - AttemptIdLength;
|
||||||
|
|
||||||
|
public static string Encode(JoinAttemptId attemptId, string derivedAuthenticator)
|
||||||
|
{
|
||||||
|
if (attemptId.Value == Guid.Empty
|
||||||
|
|| !ContractValidation.IsConnectionTicketValid(derivedAuthenticator)
|
||||||
|
|| !TryDecodeBase64Url(derivedAuthenticator, out byte[]? authenticator)
|
||||||
|
|| authenticator.Length != DecodedLength)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("The NAT introduction token fields are invalid.");
|
||||||
|
}
|
||||||
|
|
||||||
|
byte[] payload = new byte[DecodedLength];
|
||||||
|
try
|
||||||
|
{
|
||||||
|
if (!attemptId.Value.TryWriteBytes(payload.AsSpan(0, AttemptIdLength)))
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException("The join attempt identifier could not be encoded.");
|
||||||
|
}
|
||||||
|
|
||||||
|
authenticator.AsSpan(0, AuthenticatorLength).CopyTo(payload.AsSpan(AttemptIdLength));
|
||||||
|
return EncodeBase64Url(payload);
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(authenticator);
|
||||||
|
CryptographicOperations.ZeroMemory(payload);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public static bool TryDecode(string? encoded, out NatIntroductionToken? token)
|
||||||
|
{
|
||||||
|
token = null;
|
||||||
|
if (!ContractValidation.IsConnectionTicketValid(encoded)
|
||||||
|
|| !TryDecodeBase64Url(encoded!, out byte[]? payload)
|
||||||
|
|| payload.Length != DecodedLength)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
try
|
||||||
|
{
|
||||||
|
Guid attemptId = new(payload.AsSpan(0, AttemptIdLength));
|
||||||
|
if (attemptId == Guid.Empty)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
token = new NatIntroductionToken
|
||||||
|
{
|
||||||
|
AttemptId = new JoinAttemptId(attemptId),
|
||||||
|
ConnectionTicket = encoded!,
|
||||||
|
};
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(payload);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public static string ComputeDigest(string connectionTicket)
|
||||||
|
{
|
||||||
|
if (!ContractValidation.IsConnectionTicketValid(connectionTicket))
|
||||||
|
{
|
||||||
|
throw new ArgumentException("The connection ticket is invalid.", nameof(connectionTicket));
|
||||||
|
}
|
||||||
|
|
||||||
|
byte[] encoded = Encoding.ASCII.GetBytes(connectionTicket);
|
||||||
|
byte[] digest;
|
||||||
|
using (SHA256 sha256 = SHA256.Create())
|
||||||
|
{
|
||||||
|
digest = sha256.ComputeHash(encoded);
|
||||||
|
}
|
||||||
|
CryptographicOperations.ZeroMemory(encoded);
|
||||||
|
try
|
||||||
|
{
|
||||||
|
return EncodeBase64Url(digest);
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(digest);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public static bool MatchesDigest(string? connectionTicket, string? expectedDigest)
|
||||||
|
{
|
||||||
|
if (!ContractValidation.IsConnectionTicketValid(connectionTicket)
|
||||||
|
|| !ContractValidation.IsConnectionTicketValid(expectedDigest))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
byte[] actual = Encoding.ASCII.GetBytes(ComputeDigest(connectionTicket!));
|
||||||
|
byte[] expected = Encoding.ASCII.GetBytes(expectedDigest!);
|
||||||
|
try
|
||||||
|
{
|
||||||
|
return CryptographicOperations.FixedTimeEquals(actual, expected);
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(actual);
|
||||||
|
CryptographicOperations.ZeroMemory(expected);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool TryDecodeBase64Url(string? encoded, out byte[] bytes)
|
||||||
|
{
|
||||||
|
bytes = [];
|
||||||
|
if (encoded is null || encoded.Length != EncodedLength)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
try
|
||||||
|
{
|
||||||
|
bytes = Convert.FromBase64String(
|
||||||
|
encoded.Replace('-', '+').Replace('_', '/') + "=");
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
catch (FormatException)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static string EncodeBase64Url(byte[] value) =>
|
||||||
|
Convert.ToBase64String(value).TrimEnd('=').Replace('+', '-').Replace('/', '_');
|
||||||
|
}
|
||||||
@@ -0,0 +1,131 @@
|
|||||||
|
namespace FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
public enum NatPunchPeerRole
|
||||||
|
{
|
||||||
|
HostPresence = 1,
|
||||||
|
Host = 2,
|
||||||
|
Client = 3,
|
||||||
|
}
|
||||||
|
|
||||||
|
public sealed class NatPunchRequestToken
|
||||||
|
{
|
||||||
|
public NatPunchPeerRole Role { get; set; }
|
||||||
|
public MediationHandle MediationHandle { get; set; }
|
||||||
|
public string Capability { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
public override string ToString() => "[NatPunchRequestToken: capability redacted]";
|
||||||
|
}
|
||||||
|
|
||||||
|
public static class NatPunchRequestTokenCodec
|
||||||
|
{
|
||||||
|
public const int EncodedLength = ContractLimits.NatPunchRequestTokenCharacters;
|
||||||
|
|
||||||
|
private const string VersionPrefix = "rv1:";
|
||||||
|
private const int HandleLength = 32;
|
||||||
|
private const int CapabilityLength = ContractLimits.DerivedCredentialCharacters;
|
||||||
|
private const char Separator = ':';
|
||||||
|
private const char Padding = '.';
|
||||||
|
|
||||||
|
public static string Encode(
|
||||||
|
NatPunchPeerRole role,
|
||||||
|
MediationHandle mediationHandle,
|
||||||
|
string capability)
|
||||||
|
{
|
||||||
|
if (!TryGetRoleCode(role, out char roleCode)
|
||||||
|
|| mediationHandle.Value == Guid.Empty
|
||||||
|
|| capability is null
|
||||||
|
|| capability.Length != CapabilityLength
|
||||||
|
|| !ContractValidation.IsCapabilityValid(capability))
|
||||||
|
{
|
||||||
|
throw new ArgumentException("The NAT punch request token fields are invalid.");
|
||||||
|
}
|
||||||
|
|
||||||
|
string payload = string.Concat(
|
||||||
|
VersionPrefix,
|
||||||
|
roleCode,
|
||||||
|
Separator,
|
||||||
|
mediationHandle.Value.ToString("N"),
|
||||||
|
Separator,
|
||||||
|
capability);
|
||||||
|
return payload.PadRight(EncodedLength, Padding);
|
||||||
|
}
|
||||||
|
|
||||||
|
public static bool TryDecode(string? encoded, out NatPunchRequestToken? token)
|
||||||
|
{
|
||||||
|
token = null;
|
||||||
|
if (encoded is null
|
||||||
|
|| encoded.Length != EncodedLength
|
||||||
|
|| !encoded.StartsWith(VersionPrefix, StringComparison.Ordinal)
|
||||||
|
|| !TryParseRole(encoded[VersionPrefix.Length], out NatPunchPeerRole role))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
int roleSeparator = VersionPrefix.Length + 1;
|
||||||
|
int handleOffset = roleSeparator + 1;
|
||||||
|
int capabilitySeparator = handleOffset + HandleLength;
|
||||||
|
int capabilityOffset = capabilitySeparator + 1;
|
||||||
|
int paddingOffset = capabilityOffset + CapabilityLength;
|
||||||
|
string handleText = encoded.Substring(handleOffset, HandleLength);
|
||||||
|
if (encoded[roleSeparator] != Separator
|
||||||
|
|| encoded[capabilitySeparator] != Separator
|
||||||
|
|| !Guid.TryParseExact(handleText, "N", out Guid handle)
|
||||||
|
|| handle == Guid.Empty
|
||||||
|
|| !string.Equals(handleText, handle.ToString("N"), StringComparison.Ordinal)
|
||||||
|
|| !ContainsOnlyPadding(encoded, paddingOffset))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
string capability = encoded.Substring(capabilityOffset, CapabilityLength);
|
||||||
|
if (!ContractValidation.IsCapabilityValid(capability))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
token = new NatPunchRequestToken
|
||||||
|
{
|
||||||
|
Role = role,
|
||||||
|
MediationHandle = new MediationHandle(handle),
|
||||||
|
Capability = capability,
|
||||||
|
};
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool TryGetRoleCode(NatPunchPeerRole role, out char code)
|
||||||
|
{
|
||||||
|
code = role switch
|
||||||
|
{
|
||||||
|
NatPunchPeerRole.HostPresence => 'p',
|
||||||
|
NatPunchPeerRole.Host => 'h',
|
||||||
|
NatPunchPeerRole.Client => 'c',
|
||||||
|
_ => default,
|
||||||
|
};
|
||||||
|
return code != default;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool TryParseRole(char code, out NatPunchPeerRole role)
|
||||||
|
{
|
||||||
|
role = code switch
|
||||||
|
{
|
||||||
|
'p' => NatPunchPeerRole.HostPresence,
|
||||||
|
'h' => NatPunchPeerRole.Host,
|
||||||
|
'c' => NatPunchPeerRole.Client,
|
||||||
|
_ => default,
|
||||||
|
};
|
||||||
|
return role != default;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool ContainsOnlyPadding(string value, int offset)
|
||||||
|
{
|
||||||
|
for (int index = offset; index < value.Length; index++)
|
||||||
|
{
|
||||||
|
if (value[index] != Padding)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,12 @@
|
|||||||
|
namespace FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
public sealed class PresenceDatagram
|
||||||
|
{
|
||||||
|
public int ContractVersion { get; set; } = ContractLimits.ContractVersion;
|
||||||
|
public UdpPresenceMessageType MessageType { get; set; }
|
||||||
|
public MediationHandle MediationHandle { get; set; }
|
||||||
|
public AddressFamilyKind AddressFamily { get; set; }
|
||||||
|
public string LocalAddress { get; set; } = string.Empty;
|
||||||
|
public int LocalPort { get; set; }
|
||||||
|
public string Capability { get; set; } = string.Empty;
|
||||||
|
}
|
||||||
@@ -0,0 +1,281 @@
|
|||||||
|
using System.Net;
|
||||||
|
using System.Net.Sockets;
|
||||||
|
using System.Text;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
public static class RendezvousUdpCodec
|
||||||
|
{
|
||||||
|
public const byte MagicFirst = 0x52;
|
||||||
|
public const byte MagicSecond = 0x56;
|
||||||
|
public const byte FlagsNone = 0;
|
||||||
|
|
||||||
|
private const int FixedPrefixLength = 23;
|
||||||
|
private const int FixedSuffixLength = 3;
|
||||||
|
|
||||||
|
public static byte[] Encode(PresenceDatagram datagram)
|
||||||
|
{
|
||||||
|
if (datagram is null)
|
||||||
|
{
|
||||||
|
throw new ArgumentNullException(nameof(datagram));
|
||||||
|
}
|
||||||
|
|
||||||
|
if (ContractValidation.ValidateContractVersion(datagram.ContractVersion)
|
||||||
|
!= RendezvousErrorCode.None)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("The UDP contract version is unsupported.", nameof(datagram));
|
||||||
|
}
|
||||||
|
|
||||||
|
if (datagram.MessageType is not UdpPresenceMessageType.HostPresence
|
||||||
|
and not UdpPresenceMessageType.ClientPresence)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("The UDP presence message type is unknown.", nameof(datagram));
|
||||||
|
}
|
||||||
|
|
||||||
|
if (datagram.MediationHandle.Value == Guid.Empty)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("The mediation handle cannot be empty.", nameof(datagram));
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!TryGetAddressBytes(datagram.LocalAddress, datagram.AddressFamily, out byte[] addressBytes))
|
||||||
|
{
|
||||||
|
throw new ArgumentException("The local address does not match its address family.", nameof(datagram));
|
||||||
|
}
|
||||||
|
|
||||||
|
if (datagram.LocalPort is < 1 or > ushort.MaxValue)
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(nameof(datagram), "The local port must be between 1 and 65535.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!ContractValidation.IsCapabilityValid(datagram.Capability))
|
||||||
|
{
|
||||||
|
throw new ArgumentException("The UDP capability is invalid.", nameof(datagram));
|
||||||
|
}
|
||||||
|
|
||||||
|
byte[] capabilityBytes = Encoding.ASCII.GetBytes(datagram.Capability);
|
||||||
|
int encodedLength = FixedPrefixLength + addressBytes.Length + FixedSuffixLength
|
||||||
|
+ capabilityBytes.Length;
|
||||||
|
if (encodedLength > ContractLimits.UdpDatagramMaxBytes)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("The encoded UDP datagram exceeds its size limit.", nameof(datagram));
|
||||||
|
}
|
||||||
|
|
||||||
|
byte[] encoded = new byte[encodedLength];
|
||||||
|
int offset = 0;
|
||||||
|
encoded[offset++] = MagicFirst;
|
||||||
|
encoded[offset++] = MagicSecond;
|
||||||
|
encoded[offset++] = checked((byte)datagram.ContractVersion);
|
||||||
|
encoded[offset++] = (byte)datagram.MessageType;
|
||||||
|
encoded[offset++] = FlagsNone;
|
||||||
|
WriteGuid(datagram.MediationHandle.Value, encoded, offset);
|
||||||
|
offset += 16;
|
||||||
|
encoded[offset++] = (byte)datagram.AddressFamily;
|
||||||
|
encoded[offset++] = checked((byte)addressBytes.Length);
|
||||||
|
addressBytes.CopyTo(encoded, offset);
|
||||||
|
offset += addressBytes.Length;
|
||||||
|
encoded[offset++] = checked((byte)(datagram.LocalPort >> 8));
|
||||||
|
encoded[offset++] = checked((byte)(datagram.LocalPort & 0xff));
|
||||||
|
encoded[offset++] = checked((byte)capabilityBytes.Length);
|
||||||
|
capabilityBytes.CopyTo(encoded, offset);
|
||||||
|
return encoded;
|
||||||
|
}
|
||||||
|
|
||||||
|
public static bool TryDecode(
|
||||||
|
ReadOnlySpan<byte> encoded,
|
||||||
|
out PresenceDatagram? datagram,
|
||||||
|
out UdpDecodeError error)
|
||||||
|
{
|
||||||
|
datagram = null;
|
||||||
|
error = UdpDecodeError.None;
|
||||||
|
|
||||||
|
if (encoded.Length > ContractLimits.UdpDatagramMaxBytes)
|
||||||
|
{
|
||||||
|
error = UdpDecodeError.DatagramTooLarge;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (encoded.Length < FixedPrefixLength)
|
||||||
|
{
|
||||||
|
error = UdpDecodeError.Truncated;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
int offset = 0;
|
||||||
|
if (encoded[offset++] != MagicFirst || encoded[offset++] != MagicSecond)
|
||||||
|
{
|
||||||
|
error = UdpDecodeError.InvalidMagic;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
int version = encoded[offset++];
|
||||||
|
if (ContractValidation.ValidateContractVersion(version) != RendezvousErrorCode.None)
|
||||||
|
{
|
||||||
|
error = UdpDecodeError.UnsupportedVersion;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
UdpPresenceMessageType messageType = (UdpPresenceMessageType)encoded[offset++];
|
||||||
|
if (messageType is not UdpPresenceMessageType.HostPresence
|
||||||
|
and not UdpPresenceMessageType.ClientPresence)
|
||||||
|
{
|
||||||
|
error = UdpDecodeError.UnknownMessageType;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (encoded[offset++] != FlagsNone)
|
||||||
|
{
|
||||||
|
error = UdpDecodeError.InvalidFlags;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!TryReadGuid(encoded.Slice(offset, 16), out Guid handle)
|
||||||
|
|| handle == Guid.Empty)
|
||||||
|
{
|
||||||
|
error = UdpDecodeError.InvalidHandle;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
offset += 16;
|
||||||
|
AddressFamilyKind addressFamily = (AddressFamilyKind)encoded[offset++];
|
||||||
|
int expectedAddressLength = addressFamily switch
|
||||||
|
{
|
||||||
|
AddressFamilyKind.Ipv4 => 4,
|
||||||
|
AddressFamilyKind.Ipv6 => 16,
|
||||||
|
_ => 0,
|
||||||
|
};
|
||||||
|
if (expectedAddressLength == 0)
|
||||||
|
{
|
||||||
|
error = UdpDecodeError.InvalidAddressFamily;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
int addressLength = encoded[offset++];
|
||||||
|
if (addressLength != expectedAddressLength)
|
||||||
|
{
|
||||||
|
error = UdpDecodeError.InvalidAddress;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (encoded.Length < offset + addressLength + FixedSuffixLength)
|
||||||
|
{
|
||||||
|
error = UdpDecodeError.Truncated;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
string address;
|
||||||
|
try
|
||||||
|
{
|
||||||
|
address = new IPAddress(encoded.Slice(offset, addressLength).ToArray()).ToString();
|
||||||
|
}
|
||||||
|
catch (ArgumentException)
|
||||||
|
{
|
||||||
|
error = UdpDecodeError.InvalidAddress;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
offset += addressLength;
|
||||||
|
int port = (encoded[offset++] << 8) | encoded[offset++];
|
||||||
|
if (port == 0)
|
||||||
|
{
|
||||||
|
error = UdpDecodeError.InvalidPort;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
int capabilityLength = encoded[offset++];
|
||||||
|
if (capabilityLength == 0 || capabilityLength > ContractLimits.UdpCapabilityMaxCharacters)
|
||||||
|
{
|
||||||
|
error = UdpDecodeError.InvalidCapability;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (encoded.Length < offset + capabilityLength)
|
||||||
|
{
|
||||||
|
error = UdpDecodeError.Truncated;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (encoded.Length > offset + capabilityLength)
|
||||||
|
{
|
||||||
|
error = UdpDecodeError.TrailingData;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
string capability = Encoding.ASCII.GetString(encoded.Slice(offset, capabilityLength).ToArray());
|
||||||
|
if (!ContractValidation.IsCapabilityValid(capability))
|
||||||
|
{
|
||||||
|
error = UdpDecodeError.InvalidCapability;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
datagram = new PresenceDatagram
|
||||||
|
{
|
||||||
|
ContractVersion = version,
|
||||||
|
MessageType = messageType,
|
||||||
|
MediationHandle = new MediationHandle(handle),
|
||||||
|
AddressFamily = addressFamily,
|
||||||
|
LocalAddress = address,
|
||||||
|
LocalPort = port,
|
||||||
|
Capability = capability,
|
||||||
|
};
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool TryGetAddressBytes(
|
||||||
|
string value,
|
||||||
|
AddressFamilyKind addressFamily,
|
||||||
|
out byte[] addressBytes)
|
||||||
|
{
|
||||||
|
addressBytes = [];
|
||||||
|
if (!IPAddress.TryParse(value, out IPAddress? address))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
bool familyMatches = addressFamily switch
|
||||||
|
{
|
||||||
|
AddressFamilyKind.Ipv4 => address.AddressFamily == AddressFamily.InterNetwork,
|
||||||
|
AddressFamilyKind.Ipv6 => address.AddressFamily == AddressFamily.InterNetworkV6,
|
||||||
|
_ => false,
|
||||||
|
};
|
||||||
|
if (!familyMatches)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
addressBytes = address.GetAddressBytes();
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void WriteGuid(Guid value, byte[] destination, int offset)
|
||||||
|
{
|
||||||
|
string hexadecimal = value.ToString("N");
|
||||||
|
for (int index = 0; index < 16; index++)
|
||||||
|
{
|
||||||
|
int high = ParseHexadecimal(hexadecimal[index * 2]);
|
||||||
|
int low = ParseHexadecimal(hexadecimal[(index * 2) + 1]);
|
||||||
|
destination[offset + index] = checked((byte)((high << 4) | low));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool TryReadGuid(ReadOnlySpan<byte> encoded, out Guid value)
|
||||||
|
{
|
||||||
|
char[] hexadecimal = new char[32];
|
||||||
|
for (int index = 0; index < encoded.Length; index++)
|
||||||
|
{
|
||||||
|
hexadecimal[index * 2] = FormatHexadecimal(encoded[index] >> 4);
|
||||||
|
hexadecimal[(index * 2) + 1] = FormatHexadecimal(encoded[index] & 0x0f);
|
||||||
|
}
|
||||||
|
|
||||||
|
return Guid.TryParseExact(new string(hexadecimal), "N", out value);
|
||||||
|
}
|
||||||
|
|
||||||
|
private static int ParseHexadecimal(char value) => value switch
|
||||||
|
{
|
||||||
|
>= '0' and <= '9' => value - '0',
|
||||||
|
>= 'a' and <= 'f' => value - 'a' + 10,
|
||||||
|
_ => throw new FormatException("A GUID contained a non-hexadecimal character."),
|
||||||
|
};
|
||||||
|
|
||||||
|
private static char FormatHexadecimal(int value) =>
|
||||||
|
(char)(value < 10 ? '0' + value : 'a' + value - 10);
|
||||||
|
}
|
||||||
@@ -1,6 +1,67 @@
|
|||||||
{
|
{
|
||||||
"version": 2,
|
"version": 2,
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
".NETStandard,Version=v2.1": {}
|
".NETStandard,Version=v2.1": {
|
||||||
|
"System.Text.Json": {
|
||||||
|
"type": "Direct",
|
||||||
|
"requested": "[10.0.10, )",
|
||||||
|
"resolved": "10.0.10",
|
||||||
|
"contentHash": "bmsO6UdYtBdtn32zYXfsh7KlyTIzV/3V9hdT9RIb4pXKgYOsNxXR+VbWigNwBtNFVGYGm6Hwmqw5a+/IWFd36Q==",
|
||||||
|
"dependencies": {
|
||||||
|
"Microsoft.Bcl.AsyncInterfaces": "10.0.10",
|
||||||
|
"System.Buffers": "4.6.1",
|
||||||
|
"System.IO.Pipelines": "10.0.10",
|
||||||
|
"System.Memory": "4.6.3",
|
||||||
|
"System.Runtime.CompilerServices.Unsafe": "6.1.2",
|
||||||
|
"System.Text.Encodings.Web": "10.0.10",
|
||||||
|
"System.Threading.Tasks.Extensions": "4.6.3"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"Microsoft.Bcl.AsyncInterfaces": {
|
||||||
|
"type": "Transitive",
|
||||||
|
"resolved": "10.0.10",
|
||||||
|
"contentHash": "TFI6OKYE1XZz4SGuTSH70c6SBdPpFktXsoa1gCxTr3mKrhmXirnvaS0tKz+J3ZWICEAmMpEGn59nO4ICtUpQXA=="
|
||||||
|
},
|
||||||
|
"System.Buffers": {
|
||||||
|
"type": "Transitive",
|
||||||
|
"resolved": "4.6.1",
|
||||||
|
"contentHash": "N8GXpmiLMtljq7gwvyS+1QvKT/W2J8sNAvx+HVg4NGmsG/H+2k/y9QI23auLJRterrzCiDH+IWAw4V/GPwsMlw=="
|
||||||
|
},
|
||||||
|
"System.IO.Pipelines": {
|
||||||
|
"type": "Transitive",
|
||||||
|
"resolved": "10.0.10",
|
||||||
|
"contentHash": "7WX0W96y3dpQdYG4sEGdh38g3/0lOD4/dKbn2rRVOVzKhzoZUn2gKNIKaFeKWs8RCbpFfmmEWsRhSy95hMpvqA==",
|
||||||
|
"dependencies": {
|
||||||
|
"System.Buffers": "4.6.1",
|
||||||
|
"System.Memory": "4.6.3",
|
||||||
|
"System.Threading.Tasks.Extensions": "4.6.3"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"System.Memory": {
|
||||||
|
"type": "Transitive",
|
||||||
|
"resolved": "4.6.3",
|
||||||
|
"contentHash": "qdcDOgnFZY40+Q9876JUHnlHu7bosOHX8XISRoH94fwk6hgaeQGSgfZd8srWRZNt5bV9ZW2TljcegDNxsf+96A=="
|
||||||
|
},
|
||||||
|
"System.Runtime.CompilerServices.Unsafe": {
|
||||||
|
"type": "Transitive",
|
||||||
|
"resolved": "6.1.2",
|
||||||
|
"contentHash": "2hBr6zdbIBTDE3EhK7NSVNdX58uTK6iHW/P/Axmm9sl1xoGSLqDvMtpecn226TNwHByFokYwJmt/aQQNlO5CRw=="
|
||||||
|
},
|
||||||
|
"System.Text.Encodings.Web": {
|
||||||
|
"type": "Transitive",
|
||||||
|
"resolved": "10.0.10",
|
||||||
|
"contentHash": "o16m2YpDN/pjHsnxf9pTGwkpcuvjW8v1/wGUwJtM1c3QZUKm7ZEO/eYRJg7iIx6GxS2Zv9lAMHpiQwHDdgqauA==",
|
||||||
|
"dependencies": {
|
||||||
|
"System.Buffers": "4.6.1",
|
||||||
|
"System.Memory": "4.6.3",
|
||||||
|
"System.Runtime.CompilerServices.Unsafe": "6.1.2"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"System.Threading.Tasks.Extensions": {
|
||||||
|
"type": "Transitive",
|
||||||
|
"resolved": "4.6.3",
|
||||||
|
"contentHash": "7sCiwilJLYbTZELaKnc7RecBBXWXA+xMLQWZKWawBxYjp6DBlSE3v9/UcvKBvr1vv2tTOhipiogM8rRmxlhrVA=="
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -0,0 +1,97 @@
|
|||||||
|
using System.ComponentModel.DataAnnotations;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Abuse;
|
||||||
|
|
||||||
|
internal sealed class AbuseProtectionOptions
|
||||||
|
{
|
||||||
|
public const string SectionName = "Rendezvous:AbuseProtection";
|
||||||
|
|
||||||
|
[Range(1, 60)]
|
||||||
|
public int WindowSeconds { get; set; } = 1;
|
||||||
|
|
||||||
|
[Range(1_000, 1_000_000)]
|
||||||
|
public int MaxTrackedKeys { get; set; } = 100_000;
|
||||||
|
|
||||||
|
[Range(0, 100_000)]
|
||||||
|
public int CriticalTrackedKeyReserve { get; set; } = 2_048;
|
||||||
|
|
||||||
|
[Range(1_000, 999_999)]
|
||||||
|
public int UdpTrackedKeyLimit { get; set; } = 70_000;
|
||||||
|
|
||||||
|
public string[] TrustedProxyAddresses { get; set; } = [];
|
||||||
|
|
||||||
|
[Range(1, 100_000)]
|
||||||
|
public int HealthGlobalRequestsPerWindow { get; set; } = 1_000;
|
||||||
|
|
||||||
|
[Range(1, 10_000)]
|
||||||
|
public int HealthGlobalConcurrency { get; set; } = 32;
|
||||||
|
|
||||||
|
[Range(1, 100_000)]
|
||||||
|
public int HealthIpPrefixRequestsPerWindow { get; set; } = 120;
|
||||||
|
|
||||||
|
[Range(1, 1_000)]
|
||||||
|
public int HealthIpPrefixConcurrency { get; set; } = 8;
|
||||||
|
|
||||||
|
[Range(1, 1_000_000)]
|
||||||
|
public int HttpGlobalRequestsPerWindow { get; set; } = 20_000;
|
||||||
|
|
||||||
|
[Range(1, 1_000_000)]
|
||||||
|
public int HttpOptionalRequestsPerWindow { get; set; } = 18_000;
|
||||||
|
|
||||||
|
[Range(1, 100_000)]
|
||||||
|
public int HttpIpPrefixRequestsPerWindow { get; set; } = 500;
|
||||||
|
|
||||||
|
[Range(1, 100_000)]
|
||||||
|
public int HttpOptionalIpPrefixRequestsPerWindow { get; set; } = 450;
|
||||||
|
|
||||||
|
[Range(1, 1_000_000)]
|
||||||
|
public int HttpOperationRequestsPerWindow { get; set; } = 5_000;
|
||||||
|
|
||||||
|
[Range(1, 1_000_000)]
|
||||||
|
public int HttpTenantRequestsPerWindow { get; set; } = 2_000;
|
||||||
|
|
||||||
|
[Range(1, 100_000)]
|
||||||
|
public int HttpPrincipalRequestsPerWindow { get; set; } = 500;
|
||||||
|
|
||||||
|
[Range(1, 100_000)]
|
||||||
|
public int HttpResourceRequestsPerWindow { get; set; } = 200;
|
||||||
|
|
||||||
|
[Range(1, 100_000)]
|
||||||
|
public int HttpGlobalConcurrency { get; set; } = 1_024;
|
||||||
|
|
||||||
|
[Range(1, 100_000)]
|
||||||
|
public int HttpOptionalConcurrency { get; set; } = 768;
|
||||||
|
|
||||||
|
[Range(1, 10_000)]
|
||||||
|
public int HttpIpPrefixConcurrency { get; set; } = 64;
|
||||||
|
|
||||||
|
[Range(1, 10_000)]
|
||||||
|
public int HttpOptionalIpPrefixConcurrency { get; set; } = 48;
|
||||||
|
|
||||||
|
[Range(1, 100_000)]
|
||||||
|
public int HttpOperationConcurrency { get; set; } = 256;
|
||||||
|
|
||||||
|
[Range(1, 100_000)]
|
||||||
|
public int HttpTenantConcurrency { get; set; } = 256;
|
||||||
|
|
||||||
|
[Range(1, 10_000)]
|
||||||
|
public int HttpPrincipalConcurrency { get; set; } = 32;
|
||||||
|
|
||||||
|
[Range(1, 10_000)]
|
||||||
|
public int HttpResourceConcurrency { get; set; } = 16;
|
||||||
|
|
||||||
|
[Range(1, 10_000_000)]
|
||||||
|
public int UdpGlobalDatagramsPerWindow { get; set; } = 100_000;
|
||||||
|
|
||||||
|
[Range(1, 1_000_000)]
|
||||||
|
public int UdpIpPrefixDatagramsPerWindow { get; set; } = 2_000;
|
||||||
|
|
||||||
|
[Range(1, 10_000_000)]
|
||||||
|
public int UdpOperationDatagramsPerWindow { get; set; } = 50_000;
|
||||||
|
|
||||||
|
[Range(1, 100_000)]
|
||||||
|
public int UdpCapabilityDatagramsPerWindow { get; set; } = 120;
|
||||||
|
|
||||||
|
[Range(1, 100_000)]
|
||||||
|
public int UdpResourceDatagramsPerWindow { get; set; } = 240;
|
||||||
|
}
|
||||||
@@ -0,0 +1,458 @@
|
|||||||
|
using System.Buffers;
|
||||||
|
using System.Net;
|
||||||
|
using System.Security.Cryptography;
|
||||||
|
using System.Text;
|
||||||
|
using Microsoft.Extensions.Options;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Abuse;
|
||||||
|
|
||||||
|
internal sealed class AbuseProtectionService
|
||||||
|
{
|
||||||
|
private readonly AbuseProtectionOptions _options;
|
||||||
|
private readonly TimeProvider _timeProvider;
|
||||||
|
private readonly TrackerState _httpTracker;
|
||||||
|
private readonly TrackerState _udpTracker;
|
||||||
|
|
||||||
|
public AbuseProtectionService(
|
||||||
|
IOptions<AbuseProtectionOptions> options,
|
||||||
|
TimeProvider? timeProvider = null)
|
||||||
|
{
|
||||||
|
_options = options.Value;
|
||||||
|
_timeProvider = timeProvider ?? TimeProvider.System;
|
||||||
|
DateTimeOffset now = _timeProvider.GetUtcNow();
|
||||||
|
_httpTracker = new(now);
|
||||||
|
_udpTracker = new(now);
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool TryAcquireHttpIngress(
|
||||||
|
IPAddress? remoteAddress,
|
||||||
|
string operation,
|
||||||
|
out AbuseLease? lease,
|
||||||
|
out int retryAfterSeconds)
|
||||||
|
{
|
||||||
|
string prefix = GetNetworkPrefix(remoteAddress);
|
||||||
|
List<RateDimension> rates =
|
||||||
|
[
|
||||||
|
new("http:rate:global", _options.HttpGlobalRequestsPerWindow),
|
||||||
|
new($"http:rate:ip:{prefix}", _options.HttpIpPrefixRequestsPerWindow),
|
||||||
|
new($"http:rate:operation:{operation}", _options.HttpOperationRequestsPerWindow),
|
||||||
|
];
|
||||||
|
List<RateDimension> concurrency =
|
||||||
|
[
|
||||||
|
new("http:concurrency:global", _options.HttpGlobalConcurrency),
|
||||||
|
new($"http:concurrency:ip:{prefix}", _options.HttpIpPrefixConcurrency),
|
||||||
|
new($"http:concurrency:operation:{operation}", _options.HttpOperationConcurrency),
|
||||||
|
];
|
||||||
|
if (!IsLeaseCriticalOperation(operation))
|
||||||
|
{
|
||||||
|
rates.Add(new("http:rate:optional", _options.HttpOptionalRequestsPerWindow));
|
||||||
|
rates.Add(new($"http:rate:optional-ip:{prefix}",
|
||||||
|
_options.HttpOptionalIpPrefixRequestsPerWindow));
|
||||||
|
concurrency.Add(new("http:concurrency:optional", _options.HttpOptionalConcurrency));
|
||||||
|
concurrency.Add(new($"http:concurrency:optional-ip:{prefix}",
|
||||||
|
_options.HttpOptionalIpPrefixConcurrency));
|
||||||
|
}
|
||||||
|
|
||||||
|
return TryAcquire(
|
||||||
|
[.. rates],
|
||||||
|
[.. concurrency],
|
||||||
|
TrackerDomain.Http,
|
||||||
|
IsLeaseCriticalOperation(operation),
|
||||||
|
out lease,
|
||||||
|
out retryAfterSeconds);
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool TryAcquireHealthIngress(
|
||||||
|
IPAddress? remoteAddress,
|
||||||
|
out AbuseLease? lease,
|
||||||
|
out int retryAfterSeconds)
|
||||||
|
{
|
||||||
|
string prefix = GetNetworkPrefix(remoteAddress);
|
||||||
|
RateDimension[] rates =
|
||||||
|
[
|
||||||
|
new("health:rate:global", _options.HealthGlobalRequestsPerWindow),
|
||||||
|
new($"health:rate:ip:{prefix}", _options.HealthIpPrefixRequestsPerWindow),
|
||||||
|
];
|
||||||
|
RateDimension[] concurrency =
|
||||||
|
[
|
||||||
|
new("health:concurrency:global", _options.HealthGlobalConcurrency),
|
||||||
|
new($"health:concurrency:ip:{prefix}", _options.HealthIpPrefixConcurrency),
|
||||||
|
];
|
||||||
|
return TryAcquire(
|
||||||
|
rates,
|
||||||
|
concurrency,
|
||||||
|
TrackerDomain.Http,
|
||||||
|
true,
|
||||||
|
out lease,
|
||||||
|
out retryAfterSeconds);
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool TryAcquireHttpIdentity(
|
||||||
|
string operation,
|
||||||
|
string? tenant,
|
||||||
|
string? principal,
|
||||||
|
string? resource,
|
||||||
|
out AbuseLease? lease,
|
||||||
|
out int retryAfterSeconds) => TryAcquireHttpIdentity(
|
||||||
|
operation,
|
||||||
|
null,
|
||||||
|
tenant,
|
||||||
|
principal,
|
||||||
|
resource,
|
||||||
|
out lease,
|
||||||
|
out retryAfterSeconds);
|
||||||
|
|
||||||
|
public bool TryAcquireHttpIdentity(
|
||||||
|
string operation,
|
||||||
|
IPAddress? remoteAddress,
|
||||||
|
string? tenant,
|
||||||
|
string? principal,
|
||||||
|
string? resource,
|
||||||
|
out AbuseLease? lease,
|
||||||
|
out int retryAfterSeconds)
|
||||||
|
{
|
||||||
|
string sourcePrefix = GetNetworkPrefix(remoteAddress);
|
||||||
|
List<RateDimension> rates = [];
|
||||||
|
List<RateDimension> concurrency = [];
|
||||||
|
AddDimension(rates, concurrency, "tenant", tenant,
|
||||||
|
_options.HttpTenantRequestsPerWindow, _options.HttpTenantConcurrency);
|
||||||
|
AddDimension(rates, concurrency, "principal", principal,
|
||||||
|
_options.HttpPrincipalRequestsPerWindow, _options.HttpPrincipalConcurrency);
|
||||||
|
AddDimension(rates, concurrency, "resource", resource,
|
||||||
|
_options.HttpResourceRequestsPerWindow, _options.HttpResourceConcurrency);
|
||||||
|
return TryAcquire(
|
||||||
|
[.. rates],
|
||||||
|
[.. concurrency],
|
||||||
|
TrackerDomain.Http,
|
||||||
|
IsLeaseCriticalOperation(operation),
|
||||||
|
out lease,
|
||||||
|
out retryAfterSeconds);
|
||||||
|
|
||||||
|
void AddDimension(
|
||||||
|
List<RateDimension> rateDimensions,
|
||||||
|
List<RateDimension> concurrencyDimensions,
|
||||||
|
string kind,
|
||||||
|
string? value,
|
||||||
|
int rateLimit,
|
||||||
|
int concurrencyLimit)
|
||||||
|
{
|
||||||
|
if (string.IsNullOrEmpty(value))
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (kind == "resource")
|
||||||
|
{
|
||||||
|
string validationKey =
|
||||||
|
$"http:source-resource:{operation}:{sourcePrefix}:{value}";
|
||||||
|
rateDimensions.Add(new($"{validationKey}:rate", rateLimit));
|
||||||
|
concurrencyDimensions.Add(new($"{validationKey}:concurrency", concurrencyLimit));
|
||||||
|
}
|
||||||
|
|
||||||
|
string key = kind == "resource"
|
||||||
|
? $"http:resource-scoped:{operation}:{tenant ?? string.Empty}|{principal ?? string.Empty}:{value}"
|
||||||
|
: $"http:{kind}:{operation}:{value}";
|
||||||
|
rateDimensions.Add(new($"{key}:rate", rateLimit));
|
||||||
|
concurrencyDimensions.Add(new($"{key}:concurrency", concurrencyLimit));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool TryAcceptUdpIngress(IPAddress? remoteAddress, string operation)
|
||||||
|
{
|
||||||
|
string prefix = GetNetworkPrefix(remoteAddress);
|
||||||
|
RateDimension[] rates =
|
||||||
|
[
|
||||||
|
new("udp:rate:global", _options.UdpGlobalDatagramsPerWindow),
|
||||||
|
new($"udp:rate:ip:{prefix}", _options.UdpIpPrefixDatagramsPerWindow),
|
||||||
|
new($"udp:rate:operation:{operation}", _options.UdpOperationDatagramsPerWindow),
|
||||||
|
];
|
||||||
|
return TryAcquire(
|
||||||
|
rates,
|
||||||
|
[],
|
||||||
|
TrackerDomain.Udp,
|
||||||
|
false,
|
||||||
|
out AbuseLease? lease,
|
||||||
|
out _)
|
||||||
|
&& DisposeAccepted(lease);
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool TryAcceptUdpIdentity(
|
||||||
|
string operation,
|
||||||
|
string capability,
|
||||||
|
string resource) => TryAcceptUdpIdentity(
|
||||||
|
operation,
|
||||||
|
null,
|
||||||
|
capability,
|
||||||
|
resource);
|
||||||
|
|
||||||
|
public bool TryAcceptUdpIdentity(
|
||||||
|
string operation,
|
||||||
|
IPAddress? remoteAddress,
|
||||||
|
string capability,
|
||||||
|
string resource)
|
||||||
|
{
|
||||||
|
string sourcePrefix = GetNetworkPrefix(remoteAddress);
|
||||||
|
string capabilityFingerprint = FingerprintSecret(capability);
|
||||||
|
RateDimension[] rates =
|
||||||
|
[
|
||||||
|
new($"udp:rate:capability:{operation}:{capabilityFingerprint}",
|
||||||
|
_options.UdpCapabilityDatagramsPerWindow),
|
||||||
|
new($"udp:rate:source-resource:{operation}:{sourcePrefix}:{resource}",
|
||||||
|
_options.UdpResourceDatagramsPerWindow),
|
||||||
|
new($"udp:rate:resource:{operation}:{capabilityFingerprint}:{resource}",
|
||||||
|
_options.UdpResourceDatagramsPerWindow),
|
||||||
|
];
|
||||||
|
return TryAcquire(
|
||||||
|
rates,
|
||||||
|
[],
|
||||||
|
TrackerDomain.Udp,
|
||||||
|
false,
|
||||||
|
out AbuseLease? lease,
|
||||||
|
out _)
|
||||||
|
&& DisposeAccepted(lease);
|
||||||
|
}
|
||||||
|
|
||||||
|
public static string FingerprintSecret(string secret)
|
||||||
|
{
|
||||||
|
int byteCount = Encoding.UTF8.GetByteCount(secret);
|
||||||
|
byte[]? rented = null;
|
||||||
|
Span<byte> encoded = byteCount <= 1_024
|
||||||
|
? stackalloc byte[byteCount]
|
||||||
|
: (rented = ArrayPool<byte>.Shared.Rent(byteCount)).AsSpan(0, byteCount);
|
||||||
|
Span<byte> digest = stackalloc byte[32];
|
||||||
|
try
|
||||||
|
{
|
||||||
|
_ = Encoding.UTF8.GetBytes(secret, encoded);
|
||||||
|
_ = SHA256.HashData(encoded, digest);
|
||||||
|
return Convert.ToHexString(digest[..12]);
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(encoded);
|
||||||
|
CryptographicOperations.ZeroMemory(digest);
|
||||||
|
if (rented is not null)
|
||||||
|
{
|
||||||
|
ArrayPool<byte>.Shared.Return(rented);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
internal int TrackedKeyCount
|
||||||
|
{
|
||||||
|
get
|
||||||
|
{
|
||||||
|
int http;
|
||||||
|
int udp;
|
||||||
|
lock (_httpTracker.Gate)
|
||||||
|
{
|
||||||
|
http = _httpTracker.WindowCounts.Count + _httpTracker.ConcurrencyCounts.Count;
|
||||||
|
}
|
||||||
|
|
||||||
|
lock (_udpTracker.Gate)
|
||||||
|
{
|
||||||
|
udp = _udpTracker.WindowCounts.Count + _udpTracker.ConcurrencyCounts.Count;
|
||||||
|
}
|
||||||
|
|
||||||
|
return http + udp;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private bool TryAcquire(
|
||||||
|
ReadOnlySpan<RateDimension> rates,
|
||||||
|
ReadOnlySpan<RateDimension> concurrency,
|
||||||
|
TrackerDomain domain,
|
||||||
|
bool canUseCriticalReserve,
|
||||||
|
out AbuseLease? lease,
|
||||||
|
out int retryAfterSeconds)
|
||||||
|
{
|
||||||
|
TrackerState tracker = domain == TrackerDomain.Udp ? _udpTracker : _httpTracker;
|
||||||
|
lock (tracker.Gate)
|
||||||
|
{
|
||||||
|
DateTimeOffset now = _timeProvider.GetUtcNow();
|
||||||
|
TimeSpan window = TimeSpan.FromSeconds(_options.WindowSeconds);
|
||||||
|
if (now - tracker.WindowStartedAt >= window || now < tracker.WindowStartedAt)
|
||||||
|
{
|
||||||
|
tracker.WindowCounts.Clear();
|
||||||
|
tracker.WindowStartedAt = now;
|
||||||
|
}
|
||||||
|
|
||||||
|
retryAfterSeconds = Math.Max(
|
||||||
|
1,
|
||||||
|
(int)Math.Ceiling((window - (now - tracker.WindowStartedAt)).TotalSeconds));
|
||||||
|
int stagedNewKeys = 0;
|
||||||
|
int partitionLimit = domain == TrackerDomain.Udp
|
||||||
|
? _options.UdpTrackedKeyLimit
|
||||||
|
: _options.MaxTrackedKeys - _options.UdpTrackedKeyLimit;
|
||||||
|
int maxTrackedKeys = domain == TrackerDomain.Udp || canUseCriticalReserve
|
||||||
|
? partitionLimit
|
||||||
|
: partitionLimit - _options.CriticalTrackedKeyReserve;
|
||||||
|
if (!CanAcquireAll(
|
||||||
|
tracker,
|
||||||
|
tracker.WindowCounts,
|
||||||
|
rates,
|
||||||
|
maxTrackedKeys,
|
||||||
|
ref stagedNewKeys)
|
||||||
|
|| !CanAcquireAll(
|
||||||
|
tracker,
|
||||||
|
tracker.ConcurrencyCounts,
|
||||||
|
concurrency,
|
||||||
|
maxTrackedKeys,
|
||||||
|
ref stagedNewKeys))
|
||||||
|
{
|
||||||
|
lease = null;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach (RateDimension dimension in rates)
|
||||||
|
{
|
||||||
|
tracker.WindowCounts[dimension.Key] =
|
||||||
|
tracker.WindowCounts.GetValueOrDefault(dimension.Key) + 1;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (concurrency.IsEmpty)
|
||||||
|
{
|
||||||
|
lease = null;
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
string[] acquiredConcurrency = new string[concurrency.Length];
|
||||||
|
for (int index = 0; index < concurrency.Length; index++)
|
||||||
|
{
|
||||||
|
RateDimension dimension = concurrency[index];
|
||||||
|
tracker.ConcurrencyCounts[dimension.Key] =
|
||||||
|
tracker.ConcurrencyCounts.GetValueOrDefault(dimension.Key) + 1;
|
||||||
|
acquiredConcurrency[index] = dimension.Key;
|
||||||
|
}
|
||||||
|
|
||||||
|
lease = new AbuseLease(this, tracker, acquiredConcurrency);
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool CanAcquireAll(
|
||||||
|
TrackerState tracker,
|
||||||
|
Dictionary<string, int> counts,
|
||||||
|
ReadOnlySpan<RateDimension> dimensions,
|
||||||
|
int maxTrackedKeys,
|
||||||
|
ref int stagedNewKeys)
|
||||||
|
{
|
||||||
|
foreach (RateDimension dimension in dimensions)
|
||||||
|
{
|
||||||
|
if (counts.TryGetValue(dimension.Key, out int current))
|
||||||
|
{
|
||||||
|
if (current >= dimension.Limit)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
stagedNewKeys++;
|
||||||
|
if (tracker.WindowCounts.Count + tracker.ConcurrencyCounts.Count + stagedNewKeys
|
||||||
|
> maxTrackedKeys)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void Release(TrackerState tracker, string[] keys)
|
||||||
|
{
|
||||||
|
lock (tracker.Gate)
|
||||||
|
{
|
||||||
|
foreach (string key in keys)
|
||||||
|
{
|
||||||
|
if (!tracker.ConcurrencyCounts.TryGetValue(key, out int current))
|
||||||
|
{
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (current <= 1)
|
||||||
|
{
|
||||||
|
tracker.ConcurrencyCounts.Remove(key);
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
tracker.ConcurrencyCounts[key] = current - 1;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool DisposeAccepted(AbuseLease? lease)
|
||||||
|
{
|
||||||
|
lease?.Dispose();
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool IsLeaseCriticalOperation(string operation) => operation is
|
||||||
|
"RenewSessionLease" or "UpdateSession" or "DeleteSession";
|
||||||
|
|
||||||
|
private static string GetNetworkPrefix(IPAddress? address)
|
||||||
|
{
|
||||||
|
if (address is null)
|
||||||
|
{
|
||||||
|
return "unknown";
|
||||||
|
}
|
||||||
|
|
||||||
|
IPAddress normalized = address.IsIPv4MappedToIPv6 ? address.MapToIPv4() : address;
|
||||||
|
byte[] bytes = normalized.GetAddressBytes();
|
||||||
|
if (bytes.Length == 4)
|
||||||
|
{
|
||||||
|
bytes[3] = 0;
|
||||||
|
return $"4:{Convert.ToHexString(bytes)}:24";
|
||||||
|
}
|
||||||
|
|
||||||
|
if (bytes.Length == 16)
|
||||||
|
{
|
||||||
|
Array.Clear(bytes, 7, 9);
|
||||||
|
return $"6:{Convert.ToHexString(bytes)}:56";
|
||||||
|
}
|
||||||
|
|
||||||
|
return "unknown";
|
||||||
|
}
|
||||||
|
|
||||||
|
private readonly record struct RateDimension(string Key, int Limit);
|
||||||
|
|
||||||
|
private enum TrackerDomain
|
||||||
|
{
|
||||||
|
Http,
|
||||||
|
Udp,
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class TrackerState(DateTimeOffset windowStartedAt)
|
||||||
|
{
|
||||||
|
public object Gate { get; } = new();
|
||||||
|
public Dictionary<string, int> WindowCounts { get; } = new(StringComparer.Ordinal);
|
||||||
|
public Dictionary<string, int> ConcurrencyCounts { get; } = new(StringComparer.Ordinal);
|
||||||
|
public DateTimeOffset WindowStartedAt { get; set; } = windowStartedAt;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class AbuseLease : IDisposable
|
||||||
|
{
|
||||||
|
private AbuseProtectionService? _owner;
|
||||||
|
private readonly TrackerState _tracker;
|
||||||
|
private readonly string[] _keys;
|
||||||
|
|
||||||
|
internal AbuseLease(
|
||||||
|
AbuseProtectionService owner,
|
||||||
|
TrackerState tracker,
|
||||||
|
string[] keys)
|
||||||
|
{
|
||||||
|
_owner = owner;
|
||||||
|
_tracker = tracker;
|
||||||
|
_keys = keys;
|
||||||
|
}
|
||||||
|
|
||||||
|
public void Dispose()
|
||||||
|
{
|
||||||
|
if (Interlocked.Exchange(ref _owner, null) is not null)
|
||||||
|
{
|
||||||
|
Release(_tracker, _keys);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,80 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using Microsoft.AspNetCore.Http.Features;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Abuse;
|
||||||
|
|
||||||
|
internal sealed class HttpAbuseProtectionMiddleware(
|
||||||
|
RequestDelegate next,
|
||||||
|
AbuseProtectionService protection)
|
||||||
|
{
|
||||||
|
public async Task InvokeAsync(HttpContext context)
|
||||||
|
{
|
||||||
|
IHttpMaxRequestBodySizeFeature? bodySize =
|
||||||
|
context.Features.Get<IHttpMaxRequestBodySizeFeature>();
|
||||||
|
if (bodySize is { IsReadOnly: false })
|
||||||
|
{
|
||||||
|
bodySize.MaxRequestBodySize = ContractLimits.HttpRequestMaxBytes;
|
||||||
|
}
|
||||||
|
|
||||||
|
string operation = context.GetEndpoint()?.Metadata.GetMetadata<IEndpointNameMetadata>()
|
||||||
|
?.EndpointName ?? "Unmatched";
|
||||||
|
bool healthEndpoint = operation is "GetLiveness" or "GetReadiness";
|
||||||
|
bool acquired = healthEndpoint
|
||||||
|
? protection.TryAcquireHealthIngress(
|
||||||
|
context.Connection.RemoteIpAddress,
|
||||||
|
out AbuseProtectionService.AbuseLease? lease,
|
||||||
|
out int retryAfterSeconds)
|
||||||
|
: protection.TryAcquireHttpIngress(
|
||||||
|
context.Connection.RemoteIpAddress,
|
||||||
|
operation,
|
||||||
|
out lease,
|
||||||
|
out retryAfterSeconds);
|
||||||
|
if (!acquired)
|
||||||
|
{
|
||||||
|
context.Response.Headers.RetryAfter = retryAfterSeconds.ToString(
|
||||||
|
System.Globalization.CultureInfo.InvariantCulture);
|
||||||
|
await WriteErrorAsync(
|
||||||
|
context,
|
||||||
|
StatusCodes.Status429TooManyRequests,
|
||||||
|
RendezvousErrorCode.RateLimited,
|
||||||
|
"The request rate limit was exceeded.",
|
||||||
|
retryAfterSeconds).ConfigureAwait(false);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
using (lease)
|
||||||
|
{
|
||||||
|
if (context.Request.ContentLength > ContractLimits.HttpRequestMaxBytes)
|
||||||
|
{
|
||||||
|
await WriteErrorAsync(
|
||||||
|
context,
|
||||||
|
StatusCodes.Status413PayloadTooLarge,
|
||||||
|
RendezvousErrorCode.InvalidRequest,
|
||||||
|
"The request body exceeds the supported size.").ConfigureAwait(false);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
await next(context).ConfigureAwait(false);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static Task WriteErrorAsync(
|
||||||
|
HttpContext context,
|
||||||
|
int status,
|
||||||
|
RendezvousErrorCode code,
|
||||||
|
string message,
|
||||||
|
int? retryAfterSeconds = null)
|
||||||
|
{
|
||||||
|
context.Response.StatusCode = status;
|
||||||
|
return context.Response.WriteAsJsonAsync(
|
||||||
|
new ApiError
|
||||||
|
{
|
||||||
|
Code = code,
|
||||||
|
Message = message,
|
||||||
|
RetryAfterSeconds = retryAfterSeconds,
|
||||||
|
},
|
||||||
|
ContractJson.Options,
|
||||||
|
contentType: "application/json",
|
||||||
|
cancellationToken: context.RequestAborted);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,24 @@
|
|||||||
|
using System.Net;
|
||||||
|
using Microsoft.AspNetCore.HttpOverrides;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Abuse;
|
||||||
|
|
||||||
|
internal static class TrustedProxyForwarding
|
||||||
|
{
|
||||||
|
public static bool IsEnabled(AbuseProtectionOptions options) =>
|
||||||
|
options.TrustedProxyAddresses is { Length: > 0 };
|
||||||
|
|
||||||
|
public static void Configure(
|
||||||
|
ForwardedHeadersOptions forwarded,
|
||||||
|
AbuseProtectionOptions abuse)
|
||||||
|
{
|
||||||
|
forwarded.ForwardedHeaders = ForwardedHeaders.XForwardedFor;
|
||||||
|
forwarded.ForwardLimit = 1;
|
||||||
|
forwarded.KnownProxies.Clear();
|
||||||
|
forwarded.KnownIPNetworks.Clear();
|
||||||
|
foreach (string address in abuse.TrustedProxyAddresses ?? [])
|
||||||
|
{
|
||||||
|
forwarded.KnownProxies.Add(IPAddress.Parse(address));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,103 @@
|
|||||||
|
using System.Security.Cryptography;
|
||||||
|
using System.Text;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Browser;
|
||||||
|
|
||||||
|
internal sealed class EphemeralCursorProtector : IDisposable
|
||||||
|
{
|
||||||
|
private readonly byte[] _key = RandomNumberGenerator.GetBytes(32);
|
||||||
|
private bool _disposed;
|
||||||
|
|
||||||
|
public string Protect(string prefix, ReadOnlySpan<byte> payload)
|
||||||
|
{
|
||||||
|
ObjectDisposedException.ThrowIf(_disposed, this);
|
||||||
|
string content = $"{prefix}.{EncodeBytes(payload)}";
|
||||||
|
byte[] signature = HMACSHA256.HashData(_key, Encoding.ASCII.GetBytes(content));
|
||||||
|
try
|
||||||
|
{
|
||||||
|
string cursor = $"{content}.{EncodeBytes(signature)}";
|
||||||
|
return ContractValidation.IsCursorValid(cursor)
|
||||||
|
? cursor
|
||||||
|
: throw new InvalidOperationException("The protected cursor exceeds its contract limit.");
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(signature);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool TryUnprotect(string prefix, string? cursor, out byte[] payload)
|
||||||
|
{
|
||||||
|
payload = [];
|
||||||
|
if (_disposed || !ContractValidation.IsCursorValid(cursor))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
string[] segments = cursor!.Split('.');
|
||||||
|
if (segments.Length != 3 || !string.Equals(segments[0], prefix, StringComparison.Ordinal))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
byte[] expected = HMACSHA256.HashData(
|
||||||
|
_key,
|
||||||
|
Encoding.ASCII.GetBytes($"{segments[0]}.{segments[1]}"));
|
||||||
|
if (!TryDecodeBytes(segments[2], out byte[] supplied))
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(expected);
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
bool validSignature = supplied.Length == expected.Length
|
||||||
|
&& CryptographicOperations.FixedTimeEquals(supplied, expected);
|
||||||
|
CryptographicOperations.ZeroMemory(supplied);
|
||||||
|
CryptographicOperations.ZeroMemory(expected);
|
||||||
|
return validSignature && TryDecodeBytes(segments[1], out payload);
|
||||||
|
}
|
||||||
|
|
||||||
|
public void Dispose()
|
||||||
|
{
|
||||||
|
if (!_disposed)
|
||||||
|
{
|
||||||
|
_disposed = true;
|
||||||
|
CryptographicOperations.ZeroMemory(_key);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public override string ToString() => "[EphemeralCursorProtector: key redacted]";
|
||||||
|
|
||||||
|
private static string EncodeBytes(ReadOnlySpan<byte> bytes) => Convert
|
||||||
|
.ToBase64String(bytes)
|
||||||
|
.TrimEnd('=')
|
||||||
|
.Replace('+', '-')
|
||||||
|
.Replace('/', '_');
|
||||||
|
|
||||||
|
private static bool TryDecodeBytes(string value, out byte[] bytes)
|
||||||
|
{
|
||||||
|
bytes = [];
|
||||||
|
if (string.IsNullOrEmpty(value)
|
||||||
|
|| value.Any(static character =>
|
||||||
|
character is not (>= 'A' and <= 'Z')
|
||||||
|
and not (>= 'a' and <= 'z')
|
||||||
|
and not (>= '0' and <= '9')
|
||||||
|
and not '-'
|
||||||
|
and not '_'))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
string padded = value.Replace('-', '+').Replace('_', '/');
|
||||||
|
padded += (padded.Length % 4) switch { 0 => "", 2 => "==", 3 => "=", _ => "!" };
|
||||||
|
try
|
||||||
|
{
|
||||||
|
bytes = Convert.FromBase64String(padded);
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
catch (FormatException)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,115 @@
|
|||||||
|
using System.Security.Cryptography;
|
||||||
|
using System.Text.Json;
|
||||||
|
using System.Text.Json.Serialization;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using FinalFactory.Rendezvous.Server.State;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Browser;
|
||||||
|
|
||||||
|
internal sealed class SessionBrowserCursorCodec : IDisposable
|
||||||
|
{
|
||||||
|
private const string Prefix = "rvc1";
|
||||||
|
private readonly EphemeralCursorProtector _protector = new();
|
||||||
|
|
||||||
|
public string Encode(VisibleListingQuery query, SessionListingId after, DateTimeOffset now)
|
||||||
|
{
|
||||||
|
BrowserCursorPayload payload = new()
|
||||||
|
{
|
||||||
|
GameId = query.Scope.GameId.Value,
|
||||||
|
EnvironmentId = query.Scope.EnvironmentId.Value,
|
||||||
|
ProtocolVersion = query.ProtocolVersion,
|
||||||
|
RegionId = query.RegionId?.Value,
|
||||||
|
ExcludeFull = query.ExcludeFull,
|
||||||
|
AfterListingId = after.ToString(),
|
||||||
|
ExpiresAtUnixSeconds = now.AddMinutes(5).ToUnixTimeSeconds(),
|
||||||
|
};
|
||||||
|
byte[] encoded = JsonSerializer.SerializeToUtf8Bytes(payload, ContractJson.Options);
|
||||||
|
try
|
||||||
|
{
|
||||||
|
return _protector.Protect(Prefix, encoded);
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(encoded);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool TryDecode(
|
||||||
|
string? cursor,
|
||||||
|
TenantScope scope,
|
||||||
|
uint protocolVersion,
|
||||||
|
RegionId? regionId,
|
||||||
|
bool excludeFull,
|
||||||
|
DateTimeOffset now,
|
||||||
|
out SessionListingId? after)
|
||||||
|
{
|
||||||
|
after = null;
|
||||||
|
if (cursor is null)
|
||||||
|
{
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!_protector.TryUnprotect(Prefix, cursor, out byte[] encodedPayload))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
BrowserCursorPayload? payload;
|
||||||
|
try
|
||||||
|
{
|
||||||
|
payload = JsonSerializer.Deserialize<BrowserCursorPayload>(
|
||||||
|
encodedPayload,
|
||||||
|
ContractJson.Options);
|
||||||
|
}
|
||||||
|
catch (JsonException)
|
||||||
|
{
|
||||||
|
payload = null;
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(encodedPayload);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (payload is null
|
||||||
|
|| payload.ExpiresAtUnixSeconds <= now.ToUnixTimeSeconds()
|
||||||
|
|| !string.Equals(payload.GameId, scope.GameId.Value, StringComparison.Ordinal)
|
||||||
|
|| !string.Equals(payload.EnvironmentId, scope.EnvironmentId.Value, StringComparison.Ordinal)
|
||||||
|
|| payload.ProtocolVersion != protocolVersion
|
||||||
|
|| !string.Equals(payload.RegionId, regionId?.Value, StringComparison.Ordinal)
|
||||||
|
|| payload.ExcludeFull != excludeFull
|
||||||
|
|| !SessionListingId.TryParse(payload.AfterListingId, out SessionListingId listingId))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
after = listingId;
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
public void Dispose() => _protector.Dispose();
|
||||||
|
|
||||||
|
public override string ToString() => "[SessionBrowserCursorCodec: key and cursors redacted]";
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class BrowserCursorPayload
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public string GameId { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string EnvironmentId { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public uint ProtocolVersion { get; set; }
|
||||||
|
|
||||||
|
public string? RegionId { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public bool ExcludeFull { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string AfterListingId { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public long ExpiresAtUnixSeconds { get; set; }
|
||||||
|
}
|
||||||
@@ -0,0 +1,158 @@
|
|||||||
|
using System.Text.Json;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using FinalFactory.Rendezvous.Server.State;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Browser;
|
||||||
|
|
||||||
|
internal sealed record BrowserServiceResult<T>(RendezvousErrorCode Error, T? Value = default)
|
||||||
|
{
|
||||||
|
public bool Succeeded => Error == RendezvousErrorCode.None;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class SessionBrowserService(
|
||||||
|
IEphemeralRendezvousStore store,
|
||||||
|
SessionBrowserCursorCodec cursors,
|
||||||
|
IWallClock clock)
|
||||||
|
{
|
||||||
|
public BrowserServiceResult<BrowseSessionsResponse> Browse(
|
||||||
|
BrowseSessionsRequest request,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
ArgumentNullException.ThrowIfNull(request);
|
||||||
|
RendezvousErrorCode validation = Validate(request);
|
||||||
|
if (validation != RendezvousErrorCode.None)
|
||||||
|
{
|
||||||
|
return new(validation);
|
||||||
|
}
|
||||||
|
|
||||||
|
TenantScope scope = new(request.GameId, request.EnvironmentId);
|
||||||
|
if (!cursors.TryDecode(
|
||||||
|
request.Cursor,
|
||||||
|
scope,
|
||||||
|
request.ProtocolVersion,
|
||||||
|
request.RegionId,
|
||||||
|
request.ExcludeFull,
|
||||||
|
clock.UtcNow,
|
||||||
|
out SessionListingId? after))
|
||||||
|
{
|
||||||
|
return new(RendezvousErrorCode.InvalidRequest);
|
||||||
|
}
|
||||||
|
|
||||||
|
VisibleListingQuery query = new(
|
||||||
|
scope,
|
||||||
|
request.ProtocolVersion,
|
||||||
|
request.RegionId,
|
||||||
|
request.PageSize + 1,
|
||||||
|
after,
|
||||||
|
request.ExcludeFull);
|
||||||
|
StoreResult<IReadOnlyList<StoredListing>> found = store.BrowseVisibleListings(
|
||||||
|
query,
|
||||||
|
cancellationToken);
|
||||||
|
if (!found.Succeeded || found.Value is null)
|
||||||
|
{
|
||||||
|
return new(found.Code == StoreResultCode.ServiceUnavailable
|
||||||
|
? RendezvousErrorCode.ServiceUnavailable
|
||||||
|
: RendezvousErrorCode.InternalError);
|
||||||
|
}
|
||||||
|
|
||||||
|
List<SessionListing> items = found.Value
|
||||||
|
.Take(request.PageSize)
|
||||||
|
.Select(ToContract)
|
||||||
|
.ToList();
|
||||||
|
bool hasMore = found.Value.Count > request.PageSize;
|
||||||
|
while (items.Count > 0)
|
||||||
|
{
|
||||||
|
string? nextCursor = hasMore
|
||||||
|
? cursors.Encode(query, items[^1].ListingId, clock.UtcNow)
|
||||||
|
: null;
|
||||||
|
BrowseSessionsResponse response = new() { Items = items, NextCursor = nextCursor };
|
||||||
|
if (JsonSerializer.SerializeToUtf8Bytes(response, ContractJson.Options).Length
|
||||||
|
<= ContractLimits.BrowserResponseMaxBytes)
|
||||||
|
{
|
||||||
|
return new(RendezvousErrorCode.None, response);
|
||||||
|
}
|
||||||
|
|
||||||
|
items.RemoveAt(items.Count - 1);
|
||||||
|
hasMore = true;
|
||||||
|
}
|
||||||
|
|
||||||
|
return new(RendezvousErrorCode.None, new BrowseSessionsResponse());
|
||||||
|
}
|
||||||
|
|
||||||
|
public BrowserServiceResult<GetSessionResponse> Get(
|
||||||
|
SessionListingId listingId,
|
||||||
|
GameId gameId,
|
||||||
|
EnvironmentId environmentId,
|
||||||
|
uint protocolVersion,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
if (listingId.Value == Guid.Empty
|
||||||
|
|| string.IsNullOrEmpty(gameId.Value)
|
||||||
|
|| string.IsNullOrEmpty(environmentId.Value)
|
||||||
|
|| protocolVersion == 0)
|
||||||
|
{
|
||||||
|
return new(RendezvousErrorCode.InvalidRequest);
|
||||||
|
}
|
||||||
|
|
||||||
|
StoreResult<StoredListing> found = store.GetListing(listingId, true, cancellationToken);
|
||||||
|
if (!found.Succeeded || found.Value is null)
|
||||||
|
{
|
||||||
|
return new(found.Code == StoreResultCode.ServiceUnavailable
|
||||||
|
? RendezvousErrorCode.ServiceUnavailable
|
||||||
|
: RendezvousErrorCode.NotFound);
|
||||||
|
}
|
||||||
|
|
||||||
|
StoredListing listing = found.Value;
|
||||||
|
if (listing.Definition.Scope != new TenantScope(gameId, environmentId)
|
||||||
|
|| listing.Definition.ProtocolVersion != protocolVersion)
|
||||||
|
{
|
||||||
|
return new(RendezvousErrorCode.NotFound);
|
||||||
|
}
|
||||||
|
|
||||||
|
return new(RendezvousErrorCode.None, new GetSessionResponse
|
||||||
|
{
|
||||||
|
Session = ToContract(listing),
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
private static RendezvousErrorCode Validate(BrowseSessionsRequest request)
|
||||||
|
{
|
||||||
|
RendezvousErrorCode version = ContractValidation.ValidateContractVersion(request.ContractVersion);
|
||||||
|
if (version != RendezvousErrorCode.None)
|
||||||
|
{
|
||||||
|
return version;
|
||||||
|
}
|
||||||
|
|
||||||
|
return string.IsNullOrEmpty(request.GameId.Value)
|
||||||
|
|| string.IsNullOrEmpty(request.EnvironmentId.Value)
|
||||||
|
|| request.ProtocolVersion == 0
|
||||||
|
|| (request.RegionId.HasValue && string.IsNullOrEmpty(request.RegionId.Value.Value))
|
||||||
|
|| !ContractValidation.IsPageSizeValid(request.PageSize)
|
||||||
|
|| !ContractValidation.IsCursorValid(request.Cursor)
|
||||||
|
? RendezvousErrorCode.InvalidRequest
|
||||||
|
: RendezvousErrorCode.None;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static SessionListing ToContract(StoredListing stored) => new()
|
||||||
|
{
|
||||||
|
ListingId = stored.Definition.ListingId,
|
||||||
|
GameId = stored.Definition.Scope.GameId,
|
||||||
|
EnvironmentId = stored.Definition.Scope.EnvironmentId,
|
||||||
|
RegionId = stored.Definition.RegionId,
|
||||||
|
ProtocolVersion = stored.Definition.ProtocolVersion,
|
||||||
|
BuildVersion = stored.Definition.BuildVersion,
|
||||||
|
DisplayName = stored.Definition.DisplayName,
|
||||||
|
Visibility = stored.Definition.Visibility,
|
||||||
|
PublisherTrustMode = stored.Definition.TrustMode,
|
||||||
|
Capacity = new()
|
||||||
|
{
|
||||||
|
CurrentPlayers = stored.Definition.CurrentPlayers,
|
||||||
|
MaximumPlayers = stored.Definition.MaximumPlayers,
|
||||||
|
},
|
||||||
|
Metadata = stored.Definition.Metadata.ToDictionary(
|
||||||
|
static item => item.Key,
|
||||||
|
static item => item.Value,
|
||||||
|
StringComparer.Ordinal),
|
||||||
|
DedicatedFallback = StoredListing.CopyEndpoint(stored.Definition.DedicatedFallback),
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,134 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using FinalFactory.Rendezvous.Server.Sessions;
|
||||||
|
using FinalFactory.Rendezvous.Server.State;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.ConnectionOutcomes;
|
||||||
|
|
||||||
|
internal sealed record ConnectionOutcomeServiceResult(
|
||||||
|
RendezvousErrorCode Error,
|
||||||
|
ReportConnectionOutcomeResponse? Value = null)
|
||||||
|
{
|
||||||
|
public bool Succeeded => Error == RendezvousErrorCode.None;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class ConnectionOutcomeMetrics
|
||||||
|
{
|
||||||
|
private readonly object _gate = new();
|
||||||
|
private readonly Dictionary<(ConnectionOutcomeKind, ConnectionElapsedBucket), long> _counts = [];
|
||||||
|
|
||||||
|
internal void Record(ConnectionOutcomeKind outcome, ConnectionElapsedBucket elapsedBucket)
|
||||||
|
{
|
||||||
|
lock (_gate)
|
||||||
|
{
|
||||||
|
(ConnectionOutcomeKind, ConnectionElapsedBucket) key = (outcome, elapsedBucket);
|
||||||
|
_counts.TryGetValue(key, out long count);
|
||||||
|
_counts[key] = count + 1;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
internal long GetCount(ConnectionOutcomeKind outcome, ConnectionElapsedBucket elapsedBucket)
|
||||||
|
{
|
||||||
|
lock (_gate)
|
||||||
|
{
|
||||||
|
return _counts.GetValueOrDefault((outcome, elapsedBucket));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class ConnectionOutcomeService(
|
||||||
|
IEphemeralRendezvousStore store,
|
||||||
|
ISessionCapabilityService capabilities,
|
||||||
|
ConnectionOutcomeMetrics metrics)
|
||||||
|
{
|
||||||
|
internal ConnectionOutcomeServiceResult Report(
|
||||||
|
JoinAttemptId attemptId,
|
||||||
|
string? clientPunchCapability,
|
||||||
|
ReportConnectionOutcomeRequest request,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
ArgumentNullException.ThrowIfNull(request);
|
||||||
|
RendezvousErrorCode version = ContractValidation.ValidateContractVersion(
|
||||||
|
request.ContractVersion);
|
||||||
|
if (version != RendezvousErrorCode.None)
|
||||||
|
{
|
||||||
|
return new(version);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (attemptId.Value == Guid.Empty
|
||||||
|
|| !ContractValidation.IsCapabilityValid(clientPunchCapability)
|
||||||
|
|| !TryNormalizeReport(request, out ConnectionOutcomeKind outcome, out ConnectionElapsedBucket elapsedBucket)
|
||||||
|
|| !capabilities.TryFingerprint(
|
||||||
|
clientPunchCapability,
|
||||||
|
out SecretFingerprint capabilityFingerprint))
|
||||||
|
{
|
||||||
|
return new(RendezvousErrorCode.InvalidRequest);
|
||||||
|
}
|
||||||
|
|
||||||
|
StoreResult<StoredConnectionOutcome> reported = store.ReportConnectionOutcome(new(
|
||||||
|
attemptId,
|
||||||
|
capabilityFingerprint,
|
||||||
|
outcome,
|
||||||
|
elapsedBucket), cancellationToken);
|
||||||
|
if (!reported.Succeeded)
|
||||||
|
{
|
||||||
|
return new(reported.Code.ToContractError());
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!reported.IsIdempotentReplay)
|
||||||
|
{
|
||||||
|
metrics.Record(outcome, elapsedBucket);
|
||||||
|
}
|
||||||
|
|
||||||
|
return new(RendezvousErrorCode.None, new ReportConnectionOutcomeResponse
|
||||||
|
{
|
||||||
|
Accepted = true,
|
||||||
|
IsDuplicate = reported.IsIdempotentReplay,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool TryNormalizeReport(
|
||||||
|
ReportConnectionOutcomeRequest request,
|
||||||
|
out ConnectionOutcomeKind outcome,
|
||||||
|
out ConnectionElapsedBucket elapsedBucket)
|
||||||
|
{
|
||||||
|
outcome = request.Outcome switch
|
||||||
|
{
|
||||||
|
ConnectionOutcomeKind.TimedOut => ConnectionOutcomeKind.PunchTimedOut,
|
||||||
|
ConnectionOutcomeKind.StaleHost => ConnectionOutcomeKind.NoHostPresence,
|
||||||
|
ConnectionOutcomeKind.TransportFailed => ConnectionOutcomeKind.TransportError,
|
||||||
|
_ => request.Outcome,
|
||||||
|
};
|
||||||
|
if (!ContractValidation.IsReportableConnectionOutcome(request.Outcome))
|
||||||
|
{
|
||||||
|
elapsedBucket = default;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (Enum.IsDefined(request.ElapsedBucket))
|
||||||
|
{
|
||||||
|
elapsedBucket = request.ElapsedBucket;
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
#pragma warning disable CS0618 // Frozen v1 compatibility input; never retained at exact precision.
|
||||||
|
if (request.ElapsedBucket == default && request.ElapsedMilliseconds >= 0)
|
||||||
|
{
|
||||||
|
elapsedBucket = BucketElapsedMilliseconds(request.ElapsedMilliseconds);
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
#pragma warning restore CS0618
|
||||||
|
|
||||||
|
elapsedBucket = default;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static ConnectionElapsedBucket BucketElapsedMilliseconds(int elapsedMilliseconds) =>
|
||||||
|
elapsedMilliseconds switch
|
||||||
|
{
|
||||||
|
< 1_000 => ConnectionElapsedBucket.UnderOneSecond,
|
||||||
|
< 5_000 => ConnectionElapsedBucket.OneToFiveSeconds,
|
||||||
|
< 15_000 => ConnectionElapsedBucket.FiveToFifteenSeconds,
|
||||||
|
< 30_000 => ConnectionElapsedBucket.FifteenToThirtySeconds,
|
||||||
|
_ => ConnectionElapsedBucket.ThirtySecondsOrMore,
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -4,9 +4,14 @@
|
|||||||
<AssemblyName>FinalFactory.Rendezvous.Server</AssemblyName>
|
<AssemblyName>FinalFactory.Rendezvous.Server</AssemblyName>
|
||||||
<RootNamespace>FinalFactory.Rendezvous.Server</RootNamespace>
|
<RootNamespace>FinalFactory.Rendezvous.Server</RootNamespace>
|
||||||
<IsPackable>false</IsPackable>
|
<IsPackable>false</IsPackable>
|
||||||
|
<OpenApiGenerateDocuments>true</OpenApiGenerateDocuments>
|
||||||
|
<OpenApiDocumentsDirectory>$(MSBuildProjectDirectory)/../../docs/api</OpenApiDocumentsDirectory>
|
||||||
|
<OpenApiGenerateDocumentsOptions>--document-name v1 --file-name rendezvous-v1 --openapi-version OpenApi3_1</OpenApiGenerateDocumentsOptions>
|
||||||
</PropertyGroup>
|
</PropertyGroup>
|
||||||
<ItemGroup>
|
<ItemGroup>
|
||||||
<ProjectReference Include="../FinalFactory.Rendezvous.Contracts/FinalFactory.Rendezvous.Contracts.csproj" />
|
<ProjectReference Include="../FinalFactory.Rendezvous.Contracts/FinalFactory.Rendezvous.Contracts.csproj" />
|
||||||
<PackageReference Include="LiteNetLib" />
|
<PackageReference Include="LiteNetLib" />
|
||||||
|
<PackageReference Include="Microsoft.AspNetCore.OpenApi" />
|
||||||
|
<PackageReference Include="Microsoft.Extensions.ApiDescription.Server" PrivateAssets="all" />
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
</Project>
|
</Project>
|
||||||
|
|||||||
@@ -0,0 +1,652 @@
|
|||||||
|
using System.Net;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using FinalFactory.Rendezvous.Server.Abuse;
|
||||||
|
using FinalFactory.Rendezvous.Server.Browser;
|
||||||
|
using FinalFactory.Rendezvous.Server.ConnectionOutcomes;
|
||||||
|
using FinalFactory.Rendezvous.Server.JoinAttempts;
|
||||||
|
using FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
using FinalFactory.Rendezvous.Server.Sessions;
|
||||||
|
using FinalFactory.Rendezvous.Server.State;
|
||||||
|
using Microsoft.AspNetCore.Mvc;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Http;
|
||||||
|
|
||||||
|
internal static class ContractEndpoints
|
||||||
|
{
|
||||||
|
public static IEndpointRouteBuilder MapRendezvousContractEndpoints(
|
||||||
|
this IEndpointRouteBuilder endpoints)
|
||||||
|
{
|
||||||
|
RouteGroupBuilder sessions = endpoints.MapGroup("/v1/sessions").WithTags("Sessions");
|
||||||
|
sessions.MapPost("/", RegisterSession)
|
||||||
|
.Accepts<RegisterSessionRequest>("application/json")
|
||||||
|
.Produces<RegisterSessionResponse>(StatusCodes.Status201Created)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status400BadRequest)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status413PayloadTooLarge)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status401Unauthorized)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status403Forbidden)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status409Conflict)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status410Gone)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status429TooManyRequests)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status503ServiceUnavailable)
|
||||||
|
.WithName("RegisterSession");
|
||||||
|
sessions.MapPost("/{listingId}/renew", RenewLease)
|
||||||
|
.Accepts<RenewLeaseRequest>("application/json")
|
||||||
|
.Produces<RenewLeaseResponse>()
|
||||||
|
.Produces<ApiError>(StatusCodes.Status400BadRequest)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status413PayloadTooLarge)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status401Unauthorized)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status403Forbidden)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status404NotFound)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status409Conflict)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status410Gone)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status429TooManyRequests)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status503ServiceUnavailable)
|
||||||
|
.WithName("RenewSessionLease");
|
||||||
|
sessions.MapPut("/{listingId}", UpdateSession)
|
||||||
|
.Accepts<UpdateSessionRequest>("application/json")
|
||||||
|
.Produces(StatusCodes.Status204NoContent)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status400BadRequest)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status413PayloadTooLarge)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status401Unauthorized)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status403Forbidden)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status404NotFound)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status429TooManyRequests)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status503ServiceUnavailable)
|
||||||
|
.WithName("UpdateSession");
|
||||||
|
sessions.MapDelete("/{listingId}", DeleteSession)
|
||||||
|
.Accepts<DeleteSessionRequest>("application/json")
|
||||||
|
.Produces(StatusCodes.Status204NoContent)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status400BadRequest)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status413PayloadTooLarge)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status401Unauthorized)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status403Forbidden)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status429TooManyRequests)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status503ServiceUnavailable)
|
||||||
|
.WithName("DeleteSession");
|
||||||
|
sessions.MapGet("/", BrowseSessions)
|
||||||
|
.Produces<BrowseSessionsResponse>()
|
||||||
|
.Produces<ApiError>(StatusCodes.Status400BadRequest)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status429TooManyRequests)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status503ServiceUnavailable)
|
||||||
|
.WithName("BrowseSessions");
|
||||||
|
sessions.MapGet("/{listingId}", GetSession)
|
||||||
|
.Produces<GetSessionResponse>()
|
||||||
|
.Produces<ApiError>(StatusCodes.Status400BadRequest)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status404NotFound)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status429TooManyRequests)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status503ServiceUnavailable)
|
||||||
|
.WithName("GetSession");
|
||||||
|
sessions.MapGet("/{listingId}/join-attempts", BrowseHostJoinAttempts)
|
||||||
|
.Produces<BrowseHostJoinAttemptsResponse>()
|
||||||
|
.Produces<ApiError>(StatusCodes.Status400BadRequest)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status404NotFound)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status429TooManyRequests)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status503ServiceUnavailable)
|
||||||
|
.WithName("BrowseHostJoinAttempts");
|
||||||
|
|
||||||
|
RouteGroupBuilder attempts = endpoints
|
||||||
|
.MapGroup("/v1/join-attempts")
|
||||||
|
.WithTags("Join attempts");
|
||||||
|
attempts.MapPost("/", CreateJoinAttempt)
|
||||||
|
.Accepts<CreateJoinAttemptRequest>("application/json")
|
||||||
|
.Produces<CreateJoinAttemptResponse>(StatusCodes.Status201Created)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status400BadRequest)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status413PayloadTooLarge)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status404NotFound)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status409Conflict)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status410Gone)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status429TooManyRequests)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status503ServiceUnavailable)
|
||||||
|
.WithName("CreateJoinAttempt");
|
||||||
|
attempts.MapDelete("/{attemptId}", CancelJoinAttempt)
|
||||||
|
.Produces(StatusCodes.Status204NoContent)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status400BadRequest)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status404NotFound)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status429TooManyRequests)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status503ServiceUnavailable)
|
||||||
|
.WithName("CancelJoinAttempt");
|
||||||
|
attempts.MapPost("/{attemptId}/outcome", ReportConnectionOutcome)
|
||||||
|
.Accepts<ReportConnectionOutcomeRequest>("application/json")
|
||||||
|
.Produces<ReportConnectionOutcomeResponse>()
|
||||||
|
.Produces<ApiError>(StatusCodes.Status400BadRequest)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status413PayloadTooLarge)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status404NotFound)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status409Conflict)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status429TooManyRequests)
|
||||||
|
.Produces<ApiError>(StatusCodes.Status503ServiceUnavailable)
|
||||||
|
.WithName("ReportConnectionOutcome");
|
||||||
|
|
||||||
|
return endpoints;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static IResult RegisterSession(
|
||||||
|
[FromBody] RegisterSessionRequest request,
|
||||||
|
[FromHeader(Name = "Authorization")] string? authorizationHeader,
|
||||||
|
[FromServices] PrincipalCredentialService credentials,
|
||||||
|
[FromServices] SessionLeaseService sessions,
|
||||||
|
[FromServices] AbuseProtectionService abuseProtection,
|
||||||
|
[FromServices] IWallClock clock,
|
||||||
|
HttpContext httpContext,
|
||||||
|
CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
if (!TryAuthenticatePublisher(
|
||||||
|
authorizationHeader,
|
||||||
|
credentials,
|
||||||
|
clock,
|
||||||
|
out AuthenticatedPrincipal? principal))
|
||||||
|
{
|
||||||
|
return AuthenticationRequired(httpContext);
|
||||||
|
}
|
||||||
|
|
||||||
|
IPublisherPrincipal publisher = (IPublisherPrincipal)principal!;
|
||||||
|
if (!TryAcquireIdentity(
|
||||||
|
abuseProtection,
|
||||||
|
httpContext,
|
||||||
|
"RegisterSession",
|
||||||
|
Tenant(publisher.GameId, publisher.EnvironmentId),
|
||||||
|
publisher.Subject,
|
||||||
|
null,
|
||||||
|
out AbuseProtectionService.AbuseLease? abuseLease))
|
||||||
|
{
|
||||||
|
return RateLimited(httpContext);
|
||||||
|
}
|
||||||
|
|
||||||
|
using (abuseLease)
|
||||||
|
{
|
||||||
|
SessionServiceResult<RegisterSessionResponse> result = sessions.Register(
|
||||||
|
principal!,
|
||||||
|
request,
|
||||||
|
cancellationToken);
|
||||||
|
return result.Succeeded && result.Value is not null
|
||||||
|
? Results.Created($"/v1/sessions/{result.Value.ListingId}", result.Value)
|
||||||
|
: Error(result.Error);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static IResult RenewLease(
|
||||||
|
SessionListingId listingId,
|
||||||
|
[FromBody] RenewLeaseRequest request,
|
||||||
|
[FromHeader(Name = "Authorization")] string? authorizationHeader,
|
||||||
|
[FromServices] PrincipalCredentialService credentials,
|
||||||
|
[FromServices] SessionLeaseService sessions,
|
||||||
|
[FromServices] AbuseProtectionService abuseProtection,
|
||||||
|
[FromServices] IWallClock clock,
|
||||||
|
HttpContext httpContext,
|
||||||
|
CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
if (!TryAuthenticatePublisher(
|
||||||
|
authorizationHeader,
|
||||||
|
credentials,
|
||||||
|
clock,
|
||||||
|
out AuthenticatedPrincipal? principal))
|
||||||
|
{
|
||||||
|
return AuthenticationRequired(httpContext);
|
||||||
|
}
|
||||||
|
|
||||||
|
IPublisherPrincipal publisher = (IPublisherPrincipal)principal!;
|
||||||
|
if (!TryAcquireIdentity(
|
||||||
|
abuseProtection,
|
||||||
|
httpContext,
|
||||||
|
"RenewSessionLease",
|
||||||
|
Tenant(publisher.GameId, publisher.EnvironmentId),
|
||||||
|
publisher.Subject,
|
||||||
|
listingId.ToString(),
|
||||||
|
out AbuseProtectionService.AbuseLease? abuseLease))
|
||||||
|
{
|
||||||
|
return RateLimited(httpContext);
|
||||||
|
}
|
||||||
|
|
||||||
|
using (abuseLease)
|
||||||
|
{
|
||||||
|
SessionServiceResult<RenewLeaseResponse> result = sessions.Renew(
|
||||||
|
principal!,
|
||||||
|
listingId,
|
||||||
|
request,
|
||||||
|
cancellationToken);
|
||||||
|
return result.Succeeded && result.Value is not null
|
||||||
|
? Results.Ok(result.Value)
|
||||||
|
: Error(result.Error);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static IResult UpdateSession(
|
||||||
|
SessionListingId listingId,
|
||||||
|
[FromBody] UpdateSessionRequest request,
|
||||||
|
[FromHeader(Name = "Authorization")] string? authorizationHeader,
|
||||||
|
[FromServices] PrincipalCredentialService credentials,
|
||||||
|
[FromServices] SessionLeaseService sessions,
|
||||||
|
[FromServices] AbuseProtectionService abuseProtection,
|
||||||
|
[FromServices] IWallClock clock,
|
||||||
|
HttpContext httpContext,
|
||||||
|
CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
if (!TryAuthenticatePublisher(
|
||||||
|
authorizationHeader,
|
||||||
|
credentials,
|
||||||
|
clock,
|
||||||
|
out AuthenticatedPrincipal? principal))
|
||||||
|
{
|
||||||
|
return AuthenticationRequired(httpContext);
|
||||||
|
}
|
||||||
|
|
||||||
|
IPublisherPrincipal publisher = (IPublisherPrincipal)principal!;
|
||||||
|
if (!TryAcquireIdentity(
|
||||||
|
abuseProtection,
|
||||||
|
httpContext,
|
||||||
|
"UpdateSession",
|
||||||
|
Tenant(publisher.GameId, publisher.EnvironmentId),
|
||||||
|
publisher.Subject,
|
||||||
|
listingId.ToString(),
|
||||||
|
out AbuseProtectionService.AbuseLease? abuseLease))
|
||||||
|
{
|
||||||
|
return RateLimited(httpContext);
|
||||||
|
}
|
||||||
|
|
||||||
|
using (abuseLease)
|
||||||
|
{
|
||||||
|
SessionServiceResult<bool> result = sessions.Update(
|
||||||
|
principal!,
|
||||||
|
listingId,
|
||||||
|
request,
|
||||||
|
cancellationToken);
|
||||||
|
return result.Succeeded ? Results.NoContent() : Error(result.Error);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static IResult DeleteSession(
|
||||||
|
SessionListingId listingId,
|
||||||
|
[FromBody] DeleteSessionRequest request,
|
||||||
|
[FromHeader(Name = "Authorization")] string? authorizationHeader,
|
||||||
|
[FromServices] PrincipalCredentialService credentials,
|
||||||
|
[FromServices] SessionLeaseService sessions,
|
||||||
|
[FromServices] AbuseProtectionService abuseProtection,
|
||||||
|
[FromServices] IWallClock clock,
|
||||||
|
HttpContext httpContext,
|
||||||
|
CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
if (!TryAuthenticatePublisher(
|
||||||
|
authorizationHeader,
|
||||||
|
credentials,
|
||||||
|
clock,
|
||||||
|
out AuthenticatedPrincipal? principal))
|
||||||
|
{
|
||||||
|
return AuthenticationRequired(httpContext);
|
||||||
|
}
|
||||||
|
|
||||||
|
IPublisherPrincipal publisher = (IPublisherPrincipal)principal!;
|
||||||
|
if (!TryAcquireIdentity(
|
||||||
|
abuseProtection,
|
||||||
|
httpContext,
|
||||||
|
"DeleteSession",
|
||||||
|
Tenant(publisher.GameId, publisher.EnvironmentId),
|
||||||
|
publisher.Subject,
|
||||||
|
listingId.ToString(),
|
||||||
|
out AbuseProtectionService.AbuseLease? abuseLease))
|
||||||
|
{
|
||||||
|
return RateLimited(httpContext);
|
||||||
|
}
|
||||||
|
|
||||||
|
using (abuseLease)
|
||||||
|
{
|
||||||
|
SessionServiceResult<bool> result = sessions.Delete(
|
||||||
|
principal!,
|
||||||
|
listingId,
|
||||||
|
request,
|
||||||
|
cancellationToken);
|
||||||
|
return result.Succeeded ? Results.NoContent() : Error(result.Error);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static IResult BrowseSessions(
|
||||||
|
[FromQuery] int contractVersion,
|
||||||
|
[FromQuery] string gameId,
|
||||||
|
[FromQuery] string environmentId,
|
||||||
|
[FromQuery] uint protocolVersion,
|
||||||
|
[FromQuery] string? regionId,
|
||||||
|
[FromQuery] int? pageSize,
|
||||||
|
[FromQuery] bool? excludeFull,
|
||||||
|
[FromQuery] string? cursor,
|
||||||
|
[FromServices] SessionBrowserService browser,
|
||||||
|
[FromServices] AbuseProtectionService abuseProtection,
|
||||||
|
HttpContext httpContext,
|
||||||
|
CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
if (!GameId.TryParse(gameId, out GameId parsedGameId)
|
||||||
|
|| !EnvironmentId.TryParse(environmentId, out EnvironmentId parsedEnvironmentId)
|
||||||
|
|| (regionId is not null && !RegionId.TryParse(regionId, out _)))
|
||||||
|
{
|
||||||
|
return Error(RendezvousErrorCode.InvalidRequest);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!TryAcquireIdentity(
|
||||||
|
abuseProtection,
|
||||||
|
httpContext,
|
||||||
|
"BrowseSessions",
|
||||||
|
Tenant(parsedGameId, parsedEnvironmentId),
|
||||||
|
null,
|
||||||
|
null,
|
||||||
|
out AbuseProtectionService.AbuseLease? abuseLease))
|
||||||
|
{
|
||||||
|
return RateLimited(httpContext);
|
||||||
|
}
|
||||||
|
|
||||||
|
using (abuseLease)
|
||||||
|
{
|
||||||
|
BrowserServiceResult<BrowseSessionsResponse> result = browser.Browse(new()
|
||||||
|
{
|
||||||
|
ContractVersion = contractVersion,
|
||||||
|
GameId = parsedGameId,
|
||||||
|
EnvironmentId = parsedEnvironmentId,
|
||||||
|
ProtocolVersion = protocolVersion,
|
||||||
|
RegionId = regionId is null ? null : new RegionId(regionId),
|
||||||
|
PageSize = pageSize ?? ContractLimits.BrowserPageMaxItems,
|
||||||
|
ExcludeFull = excludeFull ?? false,
|
||||||
|
Cursor = cursor,
|
||||||
|
}, cancellationToken);
|
||||||
|
return result.Succeeded && result.Value is not null
|
||||||
|
? Results.Ok(result.Value)
|
||||||
|
: Error(result.Error);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static IResult GetSession(
|
||||||
|
SessionListingId listingId,
|
||||||
|
[FromQuery] int contractVersion,
|
||||||
|
[FromQuery] string gameId,
|
||||||
|
[FromQuery] string environmentId,
|
||||||
|
[FromQuery] uint protocolVersion,
|
||||||
|
[FromServices] SessionBrowserService browser,
|
||||||
|
[FromServices] AbuseProtectionService abuseProtection,
|
||||||
|
HttpContext httpContext,
|
||||||
|
CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
if (ContractValidation.ValidateContractVersion(contractVersion) != RendezvousErrorCode.None)
|
||||||
|
{
|
||||||
|
return Error(RendezvousErrorCode.UnsupportedContractVersion);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!GameId.TryParse(gameId, out GameId parsedGameId)
|
||||||
|
|| !EnvironmentId.TryParse(environmentId, out EnvironmentId parsedEnvironmentId))
|
||||||
|
{
|
||||||
|
return Error(RendezvousErrorCode.InvalidRequest);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!TryAcquireIdentity(
|
||||||
|
abuseProtection,
|
||||||
|
httpContext,
|
||||||
|
"GetSession",
|
||||||
|
Tenant(parsedGameId, parsedEnvironmentId),
|
||||||
|
null,
|
||||||
|
listingId.ToString(),
|
||||||
|
out AbuseProtectionService.AbuseLease? abuseLease))
|
||||||
|
{
|
||||||
|
return RateLimited(httpContext);
|
||||||
|
}
|
||||||
|
|
||||||
|
using (abuseLease)
|
||||||
|
{
|
||||||
|
BrowserServiceResult<GetSessionResponse> result = browser.Get(
|
||||||
|
listingId,
|
||||||
|
parsedGameId,
|
||||||
|
parsedEnvironmentId,
|
||||||
|
protocolVersion,
|
||||||
|
cancellationToken);
|
||||||
|
return result.Succeeded && result.Value is not null
|
||||||
|
? Results.Ok(result.Value)
|
||||||
|
: Error(result.Error);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static IResult BrowseHostJoinAttempts(
|
||||||
|
SessionListingId listingId,
|
||||||
|
[FromQuery] int contractVersion,
|
||||||
|
[FromHeader(Name = "X-Rendezvous-Lease-Token")] string leaseToken,
|
||||||
|
[FromQuery] int? pageSize,
|
||||||
|
[FromQuery] string? cursor,
|
||||||
|
[FromServices] JoinAttemptService attempts,
|
||||||
|
[FromServices] AbuseProtectionService abuseProtection,
|
||||||
|
HttpContext httpContext,
|
||||||
|
CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
if (!TryAcquireIdentity(
|
||||||
|
abuseProtection,
|
||||||
|
httpContext,
|
||||||
|
"BrowseHostJoinAttempts",
|
||||||
|
null,
|
||||||
|
AbuseProtectionService.FingerprintSecret(leaseToken ?? string.Empty),
|
||||||
|
listingId.ToString(),
|
||||||
|
out AbuseProtectionService.AbuseLease? abuseLease))
|
||||||
|
{
|
||||||
|
return RateLimited(httpContext);
|
||||||
|
}
|
||||||
|
|
||||||
|
using (abuseLease)
|
||||||
|
{
|
||||||
|
JoinAttemptServiceResult<BrowseHostJoinAttemptsResponse> result = attempts.BrowseForHost(
|
||||||
|
listingId,
|
||||||
|
contractVersion,
|
||||||
|
leaseToken,
|
||||||
|
pageSize ?? ContractLimits.BrowserPageMaxItems,
|
||||||
|
cursor,
|
||||||
|
cancellationToken);
|
||||||
|
return result.Succeeded && result.Value is not null
|
||||||
|
? Results.Ok(result.Value)
|
||||||
|
: Error(result.Error);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static IResult CreateJoinAttempt(
|
||||||
|
[FromBody] CreateJoinAttemptRequest request,
|
||||||
|
[FromServices] JoinAttemptService attempts,
|
||||||
|
[FromServices] AbuseProtectionService abuseProtection,
|
||||||
|
HttpContext httpContext,
|
||||||
|
CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
if (httpContext.Connection.RemoteIpAddress is not IPAddress remoteAddress)
|
||||||
|
{
|
||||||
|
return Error(RendezvousErrorCode.InvalidRequest);
|
||||||
|
}
|
||||||
|
|
||||||
|
string clientSubject = attempts.CreateAnonymousClientSubject(remoteAddress);
|
||||||
|
if (!TryAcquireIdentity(
|
||||||
|
abuseProtection,
|
||||||
|
httpContext,
|
||||||
|
"CreateJoinAttempt",
|
||||||
|
Tenant(request.GameId, request.EnvironmentId),
|
||||||
|
clientSubject,
|
||||||
|
request.ListingId.ToString(),
|
||||||
|
out AbuseProtectionService.AbuseLease? abuseLease))
|
||||||
|
{
|
||||||
|
return RateLimited(httpContext);
|
||||||
|
}
|
||||||
|
|
||||||
|
using (abuseLease)
|
||||||
|
{
|
||||||
|
JoinAttemptServiceResult<CreateJoinAttemptResponse> result = attempts.Create(
|
||||||
|
clientSubject,
|
||||||
|
request,
|
||||||
|
cancellationToken);
|
||||||
|
return result.Succeeded && result.Value is not null
|
||||||
|
? Results.Created($"/v1/join-attempts/{result.Value.AttemptId}", result.Value)
|
||||||
|
: Error(result.Error);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static IResult CancelJoinAttempt(
|
||||||
|
JoinAttemptId attemptId,
|
||||||
|
[FromHeader(Name = "X-Rendezvous-Client-Punch-Capability")] string clientPunchCapability,
|
||||||
|
[FromServices] JoinAttemptService attempts,
|
||||||
|
[FromServices] AbuseProtectionService abuseProtection,
|
||||||
|
HttpContext httpContext,
|
||||||
|
CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
if (!TryAcquireIdentity(
|
||||||
|
abuseProtection,
|
||||||
|
httpContext,
|
||||||
|
"CancelJoinAttempt",
|
||||||
|
null,
|
||||||
|
AbuseProtectionService.FingerprintSecret(clientPunchCapability ?? string.Empty),
|
||||||
|
attemptId.ToString(),
|
||||||
|
out AbuseProtectionService.AbuseLease? abuseLease))
|
||||||
|
{
|
||||||
|
return RateLimited(httpContext);
|
||||||
|
}
|
||||||
|
|
||||||
|
using (abuseLease)
|
||||||
|
{
|
||||||
|
JoinAttemptServiceResult<bool> result = attempts.Cancel(
|
||||||
|
attemptId,
|
||||||
|
clientPunchCapability,
|
||||||
|
cancellationToken);
|
||||||
|
return result.Succeeded ? Results.NoContent() : Error(result.Error);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static IResult ReportConnectionOutcome(
|
||||||
|
JoinAttemptId attemptId,
|
||||||
|
[FromHeader(Name = "X-Rendezvous-Client-Punch-Capability")] string clientPunchCapability,
|
||||||
|
[FromBody] ReportConnectionOutcomeRequest request,
|
||||||
|
[FromServices] ConnectionOutcomeService outcomes,
|
||||||
|
[FromServices] AbuseProtectionService abuseProtection,
|
||||||
|
HttpContext httpContext,
|
||||||
|
CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
if (!TryAcquireIdentity(
|
||||||
|
abuseProtection,
|
||||||
|
httpContext,
|
||||||
|
"ReportConnectionOutcome",
|
||||||
|
null,
|
||||||
|
AbuseProtectionService.FingerprintSecret(clientPunchCapability ?? string.Empty),
|
||||||
|
attemptId.ToString(),
|
||||||
|
out AbuseProtectionService.AbuseLease? abuseLease))
|
||||||
|
{
|
||||||
|
return RateLimited(httpContext);
|
||||||
|
}
|
||||||
|
|
||||||
|
using (abuseLease)
|
||||||
|
{
|
||||||
|
ConnectionOutcomeServiceResult result = outcomes.Report(
|
||||||
|
attemptId,
|
||||||
|
clientPunchCapability,
|
||||||
|
request,
|
||||||
|
cancellationToken);
|
||||||
|
return result.Succeeded && result.Value is not null
|
||||||
|
? Results.Ok(result.Value)
|
||||||
|
: Error(result.Error);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool TryAuthenticatePublisher(
|
||||||
|
string? authorizationHeader,
|
||||||
|
PrincipalCredentialService credentials,
|
||||||
|
IWallClock clock,
|
||||||
|
out AuthenticatedPrincipal? principal)
|
||||||
|
{
|
||||||
|
principal = null;
|
||||||
|
const string bearerPrefix = "Bearer ";
|
||||||
|
if (authorizationHeader is null
|
||||||
|
|| !authorizationHeader.StartsWith(bearerPrefix, StringComparison.OrdinalIgnoreCase))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
string token = authorizationHeader[bearerPrefix.Length..];
|
||||||
|
CredentialValidationResult validation = credentials.Validate(token, clock.UtcNow);
|
||||||
|
if (!validation.IsValid || validation.Principal is not IPublisherPrincipal)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
principal = validation.Principal;
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool TryAcquireIdentity(
|
||||||
|
AbuseProtectionService abuseProtection,
|
||||||
|
HttpContext httpContext,
|
||||||
|
string operation,
|
||||||
|
string? tenant,
|
||||||
|
string? principal,
|
||||||
|
string? resource,
|
||||||
|
out AbuseProtectionService.AbuseLease? lease)
|
||||||
|
{
|
||||||
|
if (abuseProtection.TryAcquireHttpIdentity(
|
||||||
|
operation,
|
||||||
|
httpContext.Connection.RemoteIpAddress,
|
||||||
|
tenant,
|
||||||
|
principal,
|
||||||
|
resource,
|
||||||
|
out lease,
|
||||||
|
out int retryAfterSeconds))
|
||||||
|
{
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
httpContext.Response.Headers.RetryAfter = retryAfterSeconds.ToString(
|
||||||
|
System.Globalization.CultureInfo.InvariantCulture);
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static string Tenant(GameId gameId, EnvironmentId environmentId) =>
|
||||||
|
$"{gameId.Value}/{environmentId.Value}";
|
||||||
|
|
||||||
|
private static IResult Error(RendezvousErrorCode code, int? retryAfterSeconds = null) => Results.Json(
|
||||||
|
new ApiError
|
||||||
|
{
|
||||||
|
Code = code,
|
||||||
|
Message = ErrorMessage(code),
|
||||||
|
RetryAfterSeconds = retryAfterSeconds,
|
||||||
|
},
|
||||||
|
ContractJson.Options,
|
||||||
|
statusCode: ErrorStatus(code));
|
||||||
|
|
||||||
|
private static IResult AuthenticationRequired(HttpContext context)
|
||||||
|
{
|
||||||
|
context.Response.Headers.WWWAuthenticate = "Bearer";
|
||||||
|
return Error(RendezvousErrorCode.AuthenticationRequired);
|
||||||
|
}
|
||||||
|
|
||||||
|
private static IResult RateLimited(HttpContext context)
|
||||||
|
{
|
||||||
|
int? retryAfterSeconds = int.TryParse(
|
||||||
|
context.Response.Headers.RetryAfter,
|
||||||
|
System.Globalization.NumberStyles.None,
|
||||||
|
System.Globalization.CultureInfo.InvariantCulture,
|
||||||
|
out int parsed)
|
||||||
|
? Math.Clamp(parsed, 1, 60)
|
||||||
|
: null;
|
||||||
|
return Error(RendezvousErrorCode.RateLimited, retryAfterSeconds);
|
||||||
|
}
|
||||||
|
|
||||||
|
private static int ErrorStatus(RendezvousErrorCode code) => code switch
|
||||||
|
{
|
||||||
|
RendezvousErrorCode.AuthenticationRequired => StatusCodes.Status401Unauthorized,
|
||||||
|
RendezvousErrorCode.Forbidden => StatusCodes.Status403Forbidden,
|
||||||
|
RendezvousErrorCode.NotFound => StatusCodes.Status404NotFound,
|
||||||
|
RendezvousErrorCode.Conflict
|
||||||
|
or RendezvousErrorCode.IncompatibleProtocol
|
||||||
|
or RendezvousErrorCode.ReplayRejected => StatusCodes.Status409Conflict,
|
||||||
|
RendezvousErrorCode.Expired or RendezvousErrorCode.StaleHost => StatusCodes.Status410Gone,
|
||||||
|
RendezvousErrorCode.RateLimited or RendezvousErrorCode.CapacityExceeded =>
|
||||||
|
StatusCodes.Status429TooManyRequests,
|
||||||
|
RendezvousErrorCode.ServiceUnavailable => StatusCodes.Status503ServiceUnavailable,
|
||||||
|
RendezvousErrorCode.InternalError => StatusCodes.Status500InternalServerError,
|
||||||
|
_ => StatusCodes.Status400BadRequest,
|
||||||
|
};
|
||||||
|
|
||||||
|
private static string ErrorMessage(RendezvousErrorCode code) => code switch
|
||||||
|
{
|
||||||
|
RendezvousErrorCode.AuthenticationRequired => "A valid publisher bearer credential is required.",
|
||||||
|
RendezvousErrorCode.Forbidden => "The publisher is not authorized for this operation.",
|
||||||
|
RendezvousErrorCode.NotFound => "The session was not found or is not owned by this publisher.",
|
||||||
|
RendezvousErrorCode.Conflict => "The session changed concurrently; retry with current state.",
|
||||||
|
RendezvousErrorCode.Expired => "The session lease has expired.",
|
||||||
|
RendezvousErrorCode.StaleHost => "The session has no fresh host presence.",
|
||||||
|
RendezvousErrorCode.IncompatibleProtocol => "The gameplay protocol is not enabled for this game.",
|
||||||
|
RendezvousErrorCode.RateLimited => "The request rate limit was exceeded.",
|
||||||
|
RendezvousErrorCode.CapacityExceeded => "The configured session capacity is currently exhausted.",
|
||||||
|
RendezvousErrorCode.ServiceUnavailable => "Session state is temporarily unavailable.",
|
||||||
|
RendezvousErrorCode.UnsupportedContractVersion => "The requested contract version is not supported.",
|
||||||
|
_ => "The session request is invalid.",
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,45 @@
|
|||||||
|
using System.Text.Json;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using Microsoft.AspNetCore.Diagnostics;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Http;
|
||||||
|
|
||||||
|
internal sealed class RendezvousExceptionHandler : IExceptionHandler
|
||||||
|
{
|
||||||
|
public async ValueTask<bool> TryHandleAsync(
|
||||||
|
HttpContext httpContext,
|
||||||
|
Exception exception,
|
||||||
|
CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
if (httpContext.Response.HasStarted)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
bool invalidRequest = exception is BadHttpRequestException or JsonException;
|
||||||
|
bool payloadTooLarge = exception is BadHttpRequestException
|
||||||
|
{
|
||||||
|
StatusCode: StatusCodes.Status413PayloadTooLarge,
|
||||||
|
};
|
||||||
|
httpContext.Response.StatusCode = payloadTooLarge
|
||||||
|
? StatusCodes.Status413PayloadTooLarge
|
||||||
|
: invalidRequest
|
||||||
|
? StatusCodes.Status400BadRequest
|
||||||
|
: StatusCodes.Status500InternalServerError;
|
||||||
|
await httpContext.Response.WriteAsJsonAsync(
|
||||||
|
new ApiError
|
||||||
|
{
|
||||||
|
Code = invalidRequest
|
||||||
|
? RendezvousErrorCode.InvalidRequest
|
||||||
|
: RendezvousErrorCode.InternalError,
|
||||||
|
Message = payloadTooLarge
|
||||||
|
? "The request body exceeds the supported size."
|
||||||
|
: invalidRequest
|
||||||
|
? "The request body, route, or query value is invalid."
|
||||||
|
: "The service could not complete the request.",
|
||||||
|
},
|
||||||
|
ContractJson.Options,
|
||||||
|
cancellationToken).ConfigureAwait(false);
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,96 @@
|
|||||||
|
using System.Security.Cryptography;
|
||||||
|
using System.Text.Json;
|
||||||
|
using System.Text.Json.Serialization;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using FinalFactory.Rendezvous.Server.Browser;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.JoinAttempts;
|
||||||
|
|
||||||
|
internal sealed class JoinAttemptCursorCodec : IDisposable
|
||||||
|
{
|
||||||
|
private const string Prefix = "rvj1";
|
||||||
|
private readonly EphemeralCursorProtector _protector = new();
|
||||||
|
|
||||||
|
public string Encode(
|
||||||
|
SessionListingId listingId,
|
||||||
|
JoinAttemptId after,
|
||||||
|
DateTimeOffset now)
|
||||||
|
{
|
||||||
|
JoinAttemptCursorPayload payload = new()
|
||||||
|
{
|
||||||
|
ListingId = listingId.ToString(),
|
||||||
|
AfterAttemptId = after.ToString(),
|
||||||
|
ExpiresAtUnixSeconds = now.AddMinutes(5).ToUnixTimeSeconds(),
|
||||||
|
};
|
||||||
|
byte[] encoded = JsonSerializer.SerializeToUtf8Bytes(payload, ContractJson.Options);
|
||||||
|
try
|
||||||
|
{
|
||||||
|
return _protector.Protect(Prefix, encoded);
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(encoded);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool TryDecode(
|
||||||
|
string? cursor,
|
||||||
|
SessionListingId listingId,
|
||||||
|
DateTimeOffset now,
|
||||||
|
out JoinAttemptId? after)
|
||||||
|
{
|
||||||
|
after = null;
|
||||||
|
if (cursor is null)
|
||||||
|
{
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!_protector.TryUnprotect(Prefix, cursor, out byte[] encodedPayload))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
JoinAttemptCursorPayload? payload;
|
||||||
|
try
|
||||||
|
{
|
||||||
|
payload = JsonSerializer.Deserialize<JoinAttemptCursorPayload>(
|
||||||
|
encodedPayload,
|
||||||
|
ContractJson.Options);
|
||||||
|
}
|
||||||
|
catch (JsonException)
|
||||||
|
{
|
||||||
|
payload = null;
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(encodedPayload);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (payload is null
|
||||||
|
|| payload.ExpiresAtUnixSeconds <= now.ToUnixTimeSeconds()
|
||||||
|
|| !string.Equals(payload.ListingId, listingId.ToString(), StringComparison.Ordinal)
|
||||||
|
|| !JoinAttemptId.TryParse(payload.AfterAttemptId, out JoinAttemptId attemptId))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
after = attemptId;
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
public void Dispose() => _protector.Dispose();
|
||||||
|
|
||||||
|
public override string ToString() => "[JoinAttemptCursorCodec: key and cursors redacted]";
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class JoinAttemptCursorPayload
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public string ListingId { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string AfterAttemptId { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public long ExpiresAtUnixSeconds { get; set; }
|
||||||
|
}
|
||||||
@@ -0,0 +1,343 @@
|
|||||||
|
using System.Net;
|
||||||
|
using System.Security.Cryptography;
|
||||||
|
using System.Text.Json;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
using FinalFactory.Rendezvous.Server.Sessions;
|
||||||
|
using FinalFactory.Rendezvous.Server.State;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.JoinAttempts;
|
||||||
|
|
||||||
|
internal sealed record JoinAttemptServiceResult<T>(RendezvousErrorCode Error, T? Value = default)
|
||||||
|
{
|
||||||
|
public bool Succeeded => Error == RendezvousErrorCode.None;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record ConnectionTicketGrant(string Ticket, DateTimeOffset ExpiresAt)
|
||||||
|
{
|
||||||
|
public override string ToString() => "[ConnectionTicketGrant: ticket redacted]";
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class JoinAttemptService(
|
||||||
|
GamePolicyRegistry policies,
|
||||||
|
IEphemeralRendezvousStore store,
|
||||||
|
ISessionCapabilityService capabilities,
|
||||||
|
JoinAttemptCursorCodec cursors,
|
||||||
|
IWallClock clock)
|
||||||
|
{
|
||||||
|
public string CreateAnonymousClientSubject(IPAddress remoteAddress)
|
||||||
|
{
|
||||||
|
ArgumentNullException.ThrowIfNull(remoteAddress);
|
||||||
|
IPAddress normalized = remoteAddress.IsIPv4MappedToIPv6
|
||||||
|
? remoteAddress.MapToIPv4()
|
||||||
|
: remoteAddress;
|
||||||
|
return capabilities.DeriveOpaqueIdentifier("join-http-client", normalized.ToString());
|
||||||
|
}
|
||||||
|
|
||||||
|
public JoinAttemptServiceResult<CreateJoinAttemptResponse> Create(
|
||||||
|
string clientSubject,
|
||||||
|
CreateJoinAttemptRequest request,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
ArgumentNullException.ThrowIfNull(request);
|
||||||
|
if (string.IsNullOrWhiteSpace(clientSubject))
|
||||||
|
{
|
||||||
|
throw new ArgumentException("A bounded client subject is required.", nameof(clientSubject));
|
||||||
|
}
|
||||||
|
|
||||||
|
RendezvousErrorCode validation = ValidateCreate(request);
|
||||||
|
if (validation != RendezvousErrorCode.None)
|
||||||
|
{
|
||||||
|
return new(validation);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!policies.TryGet(request.GameId, request.EnvironmentId, out GamePolicy? policy)
|
||||||
|
|| policy is null)
|
||||||
|
{
|
||||||
|
return new(RendezvousErrorCode.NotFound);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!policy.AllowsProtocol(request.ProtocolVersion))
|
||||||
|
{
|
||||||
|
return new(RendezvousErrorCode.IncompatibleProtocol);
|
||||||
|
}
|
||||||
|
|
||||||
|
string requestFingerprint = ComputeRequestFingerprint(request);
|
||||||
|
string derivationSalt = capabilities.CreateDerivationSalt();
|
||||||
|
string hostCapability = Derive("join-host-punch", clientSubject, request, requestFingerprint, derivationSalt);
|
||||||
|
string clientCapability = Derive("join-client-punch", clientSubject, request, requestFingerprint, derivationSalt);
|
||||||
|
JoinAttemptId attemptId = new(capabilities.DeriveGuid(
|
||||||
|
"join-attempt-id",
|
||||||
|
clientSubject,
|
||||||
|
request.IdempotencyKey,
|
||||||
|
requestFingerprint,
|
||||||
|
derivationSalt));
|
||||||
|
string connectionTicket = NatIntroductionTokenCodec.Encode(
|
||||||
|
attemptId,
|
||||||
|
Derive("connection-ticket", clientSubject, request, requestFingerprint, derivationSalt));
|
||||||
|
if (!CredentialLengthsAreValid(hostCapability, clientCapability, connectionTicket)
|
||||||
|
|| !capabilities.TryFingerprint(hostCapability, out SecretFingerprint hostFingerprint)
|
||||||
|
|| !capabilities.TryFingerprint(clientCapability, out SecretFingerprint clientFingerprint)
|
||||||
|
|| !capabilities.TryFingerprint(connectionTicket, out SecretFingerprint ticketFingerprint))
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException("Derived join credentials violated their contract invariants.");
|
||||||
|
}
|
||||||
|
|
||||||
|
MediationHandle mediationHandle = new(capabilities.DeriveGuid(
|
||||||
|
"join-mediation-handle",
|
||||||
|
clientSubject,
|
||||||
|
request.IdempotencyKey,
|
||||||
|
requestFingerprint,
|
||||||
|
derivationSalt));
|
||||||
|
StoreResult<StoredJoinAttempt> created = store.CreateJoinAttempt(new()
|
||||||
|
{
|
||||||
|
IdempotencyOwner = clientSubject,
|
||||||
|
IdempotencyKey = request.IdempotencyKey,
|
||||||
|
RequestFingerprint = requestFingerprint,
|
||||||
|
ClientSubject = clientSubject,
|
||||||
|
AttemptId = attemptId,
|
||||||
|
MediationHandle = mediationHandle,
|
||||||
|
Scope = new(request.GameId, request.EnvironmentId),
|
||||||
|
ListingId = request.ListingId,
|
||||||
|
ProtocolVersion = request.ProtocolVersion,
|
||||||
|
HostCapabilityFingerprint = hostFingerprint,
|
||||||
|
ClientCapabilityFingerprint = clientFingerprint,
|
||||||
|
ConnectionTicketFingerprint = ticketFingerprint,
|
||||||
|
CapabilityDerivationSalt = derivationSalt,
|
||||||
|
ScopeAttemptLimit = policy.MaxActiveJoinAttempts,
|
||||||
|
}, cancellationToken);
|
||||||
|
if (!created.Succeeded || created.Value is null)
|
||||||
|
{
|
||||||
|
return new(created.Code.ToContractError());
|
||||||
|
}
|
||||||
|
|
||||||
|
StoredJoinAttempt persisted = created.Value;
|
||||||
|
clientCapability = Derive(
|
||||||
|
"join-client-punch",
|
||||||
|
persisted.ClientSubject,
|
||||||
|
persisted.IdempotencyKey,
|
||||||
|
persisted.RequestFingerprint,
|
||||||
|
persisted.CapabilityDerivationSalt);
|
||||||
|
if (!capabilities.TryFingerprint(clientCapability, out SecretFingerprint persistedFingerprint)
|
||||||
|
|| persistedFingerprint != persisted.ClientCapabilityFingerprint)
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException("Stored join state could not reproduce its client capability.");
|
||||||
|
}
|
||||||
|
return new(RendezvousErrorCode.None, new CreateJoinAttemptResponse
|
||||||
|
{
|
||||||
|
AttemptId = persisted.AttemptId,
|
||||||
|
MediationHandle = persisted.MediationHandle,
|
||||||
|
ClientPunchCapability = clientCapability,
|
||||||
|
ConnectionTicketDigest = NatIntroductionTokenCodec.ComputeDigest(
|
||||||
|
CreateConnectionTicket(persisted)),
|
||||||
|
ExpiresAt = persisted.ExpiresAt,
|
||||||
|
DedicatedFallback = StoredListing.CopyEndpoint(persisted.DedicatedFallback),
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public JoinAttemptServiceResult<BrowseHostJoinAttemptsResponse> BrowseForHost(
|
||||||
|
SessionListingId listingId,
|
||||||
|
int contractVersion,
|
||||||
|
string? leaseToken,
|
||||||
|
int pageSize,
|
||||||
|
string? cursor,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
RendezvousErrorCode version = ContractValidation.ValidateContractVersion(contractVersion);
|
||||||
|
if (version != RendezvousErrorCode.None)
|
||||||
|
{
|
||||||
|
return new(version);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!ContractValidation.IsOpaqueHttpCredentialValid(leaseToken)
|
||||||
|
|| !ContractValidation.IsPageSizeValid(pageSize)
|
||||||
|
|| !ContractValidation.IsCursorValid(cursor)
|
||||||
|
|| !capabilities.TryFingerprint(leaseToken, out SecretFingerprint leaseFingerprint))
|
||||||
|
{
|
||||||
|
return new(RendezvousErrorCode.InvalidRequest);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!cursors.TryDecode(cursor, listingId, clock.UtcNow, out JoinAttemptId? after))
|
||||||
|
{
|
||||||
|
return new(RendezvousErrorCode.InvalidRequest);
|
||||||
|
}
|
||||||
|
|
||||||
|
StoreResult<IReadOnlyList<StoredJoinAttempt>> found = store.BrowseHostJoinAttempts(new(
|
||||||
|
listingId,
|
||||||
|
leaseFingerprint,
|
||||||
|
pageSize + 1,
|
||||||
|
after), cancellationToken);
|
||||||
|
if (!found.Succeeded || found.Value is null)
|
||||||
|
{
|
||||||
|
return new(found.Code.ToContractError());
|
||||||
|
}
|
||||||
|
|
||||||
|
bool hasMore = found.Value.Count > pageSize;
|
||||||
|
StoredJoinAttempt[] page = found.Value.Take(pageSize).ToArray();
|
||||||
|
BrowseHostJoinAttemptsResponse response = new()
|
||||||
|
{
|
||||||
|
Items = page.Select(CreateHostAttempt).ToList(),
|
||||||
|
NextCursor = hasMore && page.Length > 0
|
||||||
|
? cursors.Encode(listingId, page[^1].AttemptId, clock.UtcNow)
|
||||||
|
: null,
|
||||||
|
};
|
||||||
|
int encodedBytes = JsonSerializer.SerializeToUtf8Bytes(response, ContractJson.Options).Length;
|
||||||
|
return ContractValidation.IsBrowserResponseSizeValid(encodedBytes)
|
||||||
|
? new(RendezvousErrorCode.None, response)
|
||||||
|
: new(RendezvousErrorCode.CapacityExceeded);
|
||||||
|
}
|
||||||
|
|
||||||
|
public JoinAttemptServiceResult<bool> Cancel(
|
||||||
|
JoinAttemptId attemptId,
|
||||||
|
string? clientPunchCapability,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
if (!ContractValidation.IsCapabilityValid(clientPunchCapability)
|
||||||
|
|| !capabilities.TryFingerprint(clientPunchCapability, out SecretFingerprint fingerprint))
|
||||||
|
{
|
||||||
|
return new(RendezvousErrorCode.InvalidRequest);
|
||||||
|
}
|
||||||
|
|
||||||
|
StoreResult<bool> cancelled = store.CancelJoinAttempt(new(attemptId, fingerprint), cancellationToken);
|
||||||
|
return cancelled.Succeeded
|
||||||
|
? new(RendezvousErrorCode.None, true)
|
||||||
|
: new(cancelled.Code.ToContractError());
|
||||||
|
}
|
||||||
|
|
||||||
|
public JoinAttemptServiceResult<ConnectionTicketGrant> IssueConnectionTicket(
|
||||||
|
StoredJoinAttempt attempt)
|
||||||
|
{
|
||||||
|
ArgumentNullException.ThrowIfNull(attempt);
|
||||||
|
if (!attempt.IntroductionConsumed || attempt.IsCancelled)
|
||||||
|
{
|
||||||
|
return new(RendezvousErrorCode.Conflict);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (attempt.ConnectionTicketExpiresAt <= clock.UtcNow)
|
||||||
|
{
|
||||||
|
return new(RendezvousErrorCode.Expired);
|
||||||
|
}
|
||||||
|
|
||||||
|
string ticket = CreateConnectionTicket(attempt);
|
||||||
|
if (!ContractValidation.IsConnectionTicketValid(ticket)
|
||||||
|
|| !capabilities.TryFingerprint(ticket, out SecretFingerprint fingerprint)
|
||||||
|
|| fingerprint != attempt.ConnectionTicketFingerprint)
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException("Stored join state could not reproduce its connection ticket.");
|
||||||
|
}
|
||||||
|
|
||||||
|
return new(RendezvousErrorCode.None, new(ticket, attempt.ConnectionTicketExpiresAt));
|
||||||
|
}
|
||||||
|
|
||||||
|
private HostJoinAttempt CreateHostAttempt(StoredJoinAttempt attempt)
|
||||||
|
{
|
||||||
|
string capability = Derive(
|
||||||
|
"join-host-punch",
|
||||||
|
attempt.ClientSubject,
|
||||||
|
attempt.IdempotencyKey,
|
||||||
|
attempt.RequestFingerprint,
|
||||||
|
attempt.CapabilityDerivationSalt);
|
||||||
|
if (!ContractValidation.IsCapabilityValid(capability)
|
||||||
|
|| !capabilities.TryFingerprint(capability, out SecretFingerprint fingerprint)
|
||||||
|
|| fingerprint != attempt.HostCapabilityFingerprint)
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException("Stored join state could not reproduce its host capability.");
|
||||||
|
}
|
||||||
|
|
||||||
|
return new()
|
||||||
|
{
|
||||||
|
AttemptId = attempt.AttemptId,
|
||||||
|
MediationHandle = attempt.MediationHandle,
|
||||||
|
HostPunchCapability = capability,
|
||||||
|
ConnectionTicketDigest = NatIntroductionTokenCodec.ComputeDigest(
|
||||||
|
CreateConnectionTicket(attempt)),
|
||||||
|
IsCancelled = attempt.IsCancelled,
|
||||||
|
ExpiresAt = attempt.ExpiresAt,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
private string CreateConnectionTicket(StoredJoinAttempt attempt) =>
|
||||||
|
NatIntroductionTokenCodec.Encode(
|
||||||
|
attempt.AttemptId,
|
||||||
|
Derive(
|
||||||
|
"connection-ticket",
|
||||||
|
attempt.ClientSubject,
|
||||||
|
attempt.IdempotencyKey,
|
||||||
|
attempt.RequestFingerprint,
|
||||||
|
attempt.CapabilityDerivationSalt));
|
||||||
|
|
||||||
|
private static RendezvousErrorCode ValidateCreate(CreateJoinAttemptRequest request)
|
||||||
|
{
|
||||||
|
RendezvousErrorCode version = ContractValidation.ValidateContractVersion(request.ContractVersion);
|
||||||
|
if (version != RendezvousErrorCode.None)
|
||||||
|
{
|
||||||
|
return version;
|
||||||
|
}
|
||||||
|
|
||||||
|
return !ContractValidation.IsIdempotencyKeyValid(request.IdempotencyKey)
|
||||||
|
|| string.IsNullOrEmpty(request.GameId.Value)
|
||||||
|
|| string.IsNullOrEmpty(request.EnvironmentId.Value)
|
||||||
|
|| request.ListingId.Value == Guid.Empty
|
||||||
|
|| request.ProtocolVersion == 0
|
||||||
|
? RendezvousErrorCode.InvalidRequest
|
||||||
|
: RendezvousErrorCode.None;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static string ComputeRequestFingerprint(CreateJoinAttemptRequest request)
|
||||||
|
{
|
||||||
|
byte[] encoded = JsonSerializer.SerializeToUtf8Bytes(request, ContractJson.Options);
|
||||||
|
byte[] digest = SHA256.HashData(encoded);
|
||||||
|
CryptographicOperations.ZeroMemory(encoded);
|
||||||
|
try
|
||||||
|
{
|
||||||
|
return Encode(digest);
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(digest);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private string Derive(
|
||||||
|
string purpose,
|
||||||
|
string clientSubject,
|
||||||
|
CreateJoinAttemptRequest request,
|
||||||
|
string requestFingerprint,
|
||||||
|
string derivationSalt) => Derive(
|
||||||
|
purpose,
|
||||||
|
clientSubject,
|
||||||
|
request.IdempotencyKey,
|
||||||
|
requestFingerprint,
|
||||||
|
derivationSalt);
|
||||||
|
|
||||||
|
private string Derive(
|
||||||
|
string purpose,
|
||||||
|
string clientSubject,
|
||||||
|
string idempotencyKey,
|
||||||
|
string requestFingerprint,
|
||||||
|
string derivationSalt) => capabilities.DeriveCapability(
|
||||||
|
purpose,
|
||||||
|
clientSubject,
|
||||||
|
idempotencyKey,
|
||||||
|
requestFingerprint,
|
||||||
|
derivationSalt);
|
||||||
|
|
||||||
|
private static bool CredentialLengthsAreValid(
|
||||||
|
string hostCapability,
|
||||||
|
string clientCapability,
|
||||||
|
string ticket) =>
|
||||||
|
ContractValidation.IsCapabilityValid(hostCapability)
|
||||||
|
&& ContractValidation.IsCapabilityValid(clientCapability)
|
||||||
|
&& ContractValidation.IsConnectionTicketValid(ticket)
|
||||||
|
&& hostCapability.Length == ContractLimits.DerivedCredentialCharacters
|
||||||
|
&& clientCapability.Length == ContractLimits.DerivedCredentialCharacters
|
||||||
|
&& ticket.Length == ContractLimits.DerivedCredentialCharacters
|
||||||
|
&& hostCapability.Length <= ContractLimits.LiteNetLibNatTokenMaxCharacters
|
||||||
|
&& clientCapability.Length <= ContractLimits.LiteNetLibNatTokenMaxCharacters;
|
||||||
|
|
||||||
|
private static string Encode(ReadOnlySpan<byte> bytes) => Convert
|
||||||
|
.ToBase64String(bytes)
|
||||||
|
.TrimEnd('=')
|
||||||
|
.Replace('+', '-')
|
||||||
|
.Replace('/', '_');
|
||||||
|
}
|
||||||
@@ -1,27 +1,279 @@
|
|||||||
using System.Net;
|
using System.Net;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using FinalFactory.Rendezvous.Server.Abuse;
|
||||||
|
using FinalFactory.Rendezvous.Server.Browser;
|
||||||
|
using FinalFactory.Rendezvous.Server.ConnectionOutcomes;
|
||||||
|
using FinalFactory.Rendezvous.Server.Http;
|
||||||
|
using FinalFactory.Rendezvous.Server.JoinAttempts;
|
||||||
|
using FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
using FinalFactory.Rendezvous.Server.Sessions;
|
||||||
|
using FinalFactory.Rendezvous.Server.State;
|
||||||
using FinalFactory.Rendezvous.Server.Transport;
|
using FinalFactory.Rendezvous.Server.Transport;
|
||||||
|
using Microsoft.AspNetCore.HttpOverrides;
|
||||||
|
using Microsoft.OpenApi;
|
||||||
|
|
||||||
WebApplicationBuilder builder = WebApplication.CreateBuilder(args);
|
WebApplicationBuilder builder = WebApplication.CreateBuilder(args);
|
||||||
|
bool isOpenApiGeneration = string.Equals(
|
||||||
|
System.Reflection.Assembly.GetEntryAssembly()?.GetName().Name,
|
||||||
|
"GetDocument.Insider",
|
||||||
|
StringComparison.Ordinal);
|
||||||
|
|
||||||
|
builder.Services.AddOpenApi("v1", static options =>
|
||||||
|
{
|
||||||
|
options.AddSchemaTransformer(static (schema, context, cancellationToken) =>
|
||||||
|
{
|
||||||
|
Type type = context.JsonTypeInfo.Type;
|
||||||
|
if (type == typeof(GameId)
|
||||||
|
|| type == typeof(EnvironmentId)
|
||||||
|
|| type == typeof(RegionId))
|
||||||
|
{
|
||||||
|
schema.Type = JsonSchemaType.String;
|
||||||
|
}
|
||||||
|
else if (type == typeof(SessionListingId)
|
||||||
|
|| type == typeof(LeaseId)
|
||||||
|
|| type == typeof(JoinAttemptId)
|
||||||
|
|| type == typeof(MediationHandle))
|
||||||
|
{
|
||||||
|
schema.Type = JsonSchemaType.String;
|
||||||
|
schema.Format = "uuid";
|
||||||
|
}
|
||||||
|
|
||||||
|
return Task.CompletedTask;
|
||||||
|
});
|
||||||
|
options.AddDocumentTransformer(static (document, context, cancellationToken) =>
|
||||||
|
{
|
||||||
|
const string schemeName = "PublisherBearer";
|
||||||
|
document.Components ??= new OpenApiComponents();
|
||||||
|
document.Components.SecuritySchemes ??=
|
||||||
|
new Dictionary<string, IOpenApiSecurityScheme>(StringComparer.Ordinal);
|
||||||
|
document.Components.SecuritySchemes[schemeName] = new OpenApiSecurityScheme
|
||||||
|
{
|
||||||
|
Type = SecuritySchemeType.Http,
|
||||||
|
Scheme = "bearer",
|
||||||
|
BearerFormat = "rv1 publisher credential",
|
||||||
|
Description = "Tenant-scoped publisher credential issued during game provisioning.",
|
||||||
|
};
|
||||||
|
const string attemptSchemeName = "JoinAttemptCapability";
|
||||||
|
document.Components.SecuritySchemes[attemptSchemeName] = new OpenApiSecurityScheme
|
||||||
|
{
|
||||||
|
Type = SecuritySchemeType.ApiKey,
|
||||||
|
Name = "X-Rendezvous-Client-Punch-Capability",
|
||||||
|
In = ParameterLocation.Header,
|
||||||
|
Description = "Attempt-scoped client capability returned only to the joining caller.",
|
||||||
|
};
|
||||||
|
|
||||||
|
HashSet<string> securedOperations = new(StringComparer.Ordinal)
|
||||||
|
{
|
||||||
|
"RegisterSession",
|
||||||
|
"RenewSessionLease",
|
||||||
|
"UpdateSession",
|
||||||
|
"DeleteSession",
|
||||||
|
};
|
||||||
|
OpenApiSecuritySchemeReference reference = new(schemeName, document, null);
|
||||||
|
OpenApiSecuritySchemeReference attemptReference = new(attemptSchemeName, document, null);
|
||||||
|
foreach (OpenApiPathItem path in document.Paths.Values)
|
||||||
|
{
|
||||||
|
if (path.Operations is null)
|
||||||
|
{
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach (OpenApiOperation operation in path.Operations.Values.Where(
|
||||||
|
operation => securedOperations.Contains(operation.OperationId ?? string.Empty)))
|
||||||
|
{
|
||||||
|
operation.Security ??= [];
|
||||||
|
operation.Security.Add(new OpenApiSecurityRequirement
|
||||||
|
{
|
||||||
|
[reference] = [],
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach (OpenApiOperation operation in path.Operations.Values.Where(
|
||||||
|
operation => operation.OperationId is
|
||||||
|
"CancelJoinAttempt" or "ReportConnectionOutcome"))
|
||||||
|
{
|
||||||
|
operation.Security ??= [];
|
||||||
|
operation.Security.Add(new OpenApiSecurityRequirement
|
||||||
|
{
|
||||||
|
[attemptReference] = [],
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach (OpenApiOperation operation in path.Operations.Values)
|
||||||
|
{
|
||||||
|
if (operation.Responses is null
|
||||||
|
|| !operation.Responses.TryGetValue(
|
||||||
|
StatusCodes.Status429TooManyRequests.ToString(
|
||||||
|
System.Globalization.CultureInfo.InvariantCulture),
|
||||||
|
out IOpenApiResponse? response)
|
||||||
|
|| response is not OpenApiResponse concreteResponse)
|
||||||
|
{
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
concreteResponse.Headers ??=
|
||||||
|
new Dictionary<string, IOpenApiHeader>(StringComparer.OrdinalIgnoreCase);
|
||||||
|
concreteResponse.Headers["Retry-After"] = new OpenApiHeader
|
||||||
|
{
|
||||||
|
Description = "Whole seconds before the caller should retry (1-60).",
|
||||||
|
Schema = new OpenApiSchema
|
||||||
|
{
|
||||||
|
Type = JsonSchemaType.Integer,
|
||||||
|
Format = "int32",
|
||||||
|
},
|
||||||
|
};
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return Task.CompletedTask;
|
||||||
|
});
|
||||||
|
});
|
||||||
|
builder.Services.ConfigureHttpJsonOptions(static options =>
|
||||||
|
ContractJson.Configure(options.SerializerOptions));
|
||||||
|
builder.Services.Configure<RouteHandlerOptions>(static options =>
|
||||||
|
options.ThrowOnBadRequest = true);
|
||||||
|
builder.Services.AddProblemDetails();
|
||||||
|
builder.Services.AddExceptionHandler<RendezvousExceptionHandler>();
|
||||||
|
builder.WebHost.ConfigureKestrel(static options =>
|
||||||
|
options.Limits.MaxRequestBodySize = ContractLimits.HttpRequestMaxBytes);
|
||||||
|
|
||||||
|
builder.Services
|
||||||
|
.AddOptions<AbuseProtectionOptions>()
|
||||||
|
.BindConfiguration(AbuseProtectionOptions.SectionName)
|
||||||
|
.ValidateDataAnnotations()
|
||||||
|
.Validate(
|
||||||
|
options => options.HttpOptionalRequestsPerWindow
|
||||||
|
< options.HttpGlobalRequestsPerWindow,
|
||||||
|
"The optional HTTP request budget must leave global capacity for lease operations.")
|
||||||
|
.Validate(
|
||||||
|
options => options.HttpOptionalConcurrency < options.HttpGlobalConcurrency,
|
||||||
|
"The optional HTTP concurrency budget must leave global capacity for lease operations.")
|
||||||
|
.Validate(
|
||||||
|
options => options.HttpOptionalIpPrefixRequestsPerWindow
|
||||||
|
< options.HttpIpPrefixRequestsPerWindow,
|
||||||
|
"The optional HTTP source budget must leave capacity for lease operations.")
|
||||||
|
.Validate(
|
||||||
|
options => options.HttpOptionalIpPrefixConcurrency
|
||||||
|
< options.HttpIpPrefixConcurrency,
|
||||||
|
"The optional HTTP source concurrency must leave capacity for lease operations.")
|
||||||
|
.Validate(
|
||||||
|
options => options.CriticalTrackedKeyReserve >= 16
|
||||||
|
&& options.UdpTrackedKeyLimit + options.CriticalTrackedKeyReserve
|
||||||
|
< options.MaxTrackedKeys,
|
||||||
|
"The tracked-key reserve must leave at least 16 keys for critical operations.")
|
||||||
|
.Validate(
|
||||||
|
options => options.TrustedProxyAddresses is { Length: <= 32 } addresses
|
||||||
|
&& addresses.All(
|
||||||
|
static value => IPAddress.TryParse(value, out _)),
|
||||||
|
"Trusted proxy addresses must contain at most 32 literal IP addresses.")
|
||||||
|
.ValidateOnStart();
|
||||||
|
builder.Services.AddSingleton<AbuseProtectionService>();
|
||||||
|
AbuseProtectionOptions configuredAbuseProtection = builder.Configuration
|
||||||
|
.GetSection(AbuseProtectionOptions.SectionName)
|
||||||
|
.Get<AbuseProtectionOptions>() ?? new AbuseProtectionOptions();
|
||||||
|
builder.Services.Configure<ForwardedHeadersOptions>(options =>
|
||||||
|
TrustedProxyForwarding.Configure(options, configuredAbuseProtection));
|
||||||
|
|
||||||
|
SystemRendezvousClock rendezvousClock = new();
|
||||||
|
EphemeralStoreOptions stateOptions = new();
|
||||||
|
InMemoryEphemeralRendezvousStore stateStore = new(
|
||||||
|
stateOptions,
|
||||||
|
rendezvousClock,
|
||||||
|
rendezvousClock);
|
||||||
|
builder.Services.AddSingleton<IEphemeralRendezvousStore>(stateStore);
|
||||||
|
builder.Services.AddSingleton<IWallClock>(rendezvousClock);
|
||||||
|
|
||||||
|
if (isOpenApiGeneration)
|
||||||
|
{
|
||||||
|
builder.Services.AddSingleton(new ProvisioningReadiness(false));
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
ProvisioningOptions provisioningOptions = builder.Configuration
|
||||||
|
.GetSection(ProvisioningOptions.SectionName)
|
||||||
|
.Get<ProvisioningOptions>() ?? new ProvisioningOptions();
|
||||||
|
ISecretProvider secretProvider = builder.Environment.IsDevelopment()
|
||||||
|
? new EphemeralDevelopmentSecretProvider()
|
||||||
|
: new EnvironmentSecretProvider();
|
||||||
|
ProvisioningRuntime provisioning = ProvisioningRuntime.Create(
|
||||||
|
provisioningOptions,
|
||||||
|
secretProvider,
|
||||||
|
DateTimeOffset.UtcNow);
|
||||||
|
builder.Services.AddSingleton(provisioning);
|
||||||
|
builder.Services.AddSingleton(provisioning.Policies);
|
||||||
|
builder.Services.AddSingleton(provisioning.Credentials);
|
||||||
|
builder.Services.AddSingleton(provisioning.PublisherAuthorization);
|
||||||
|
EphemeralCapabilityIssuer sessionCapabilities = new();
|
||||||
|
builder.Services.AddSingleton(sessionCapabilities);
|
||||||
|
builder.Services.AddSingleton<ISessionCapabilityService>(sessionCapabilities);
|
||||||
|
builder.Services.AddSingleton(SessionLeaseTiming.From(stateOptions));
|
||||||
|
builder.Services.AddSingleton<SessionLeaseService>();
|
||||||
|
builder.Services.AddSingleton<SessionBrowserCursorCodec>();
|
||||||
|
builder.Services.AddSingleton<SessionBrowserService>();
|
||||||
|
builder.Services.AddSingleton<JoinAttemptCursorCodec>();
|
||||||
|
builder.Services.AddSingleton<JoinAttemptService>();
|
||||||
|
builder.Services.AddSingleton<ConnectionOutcomeMetrics>();
|
||||||
|
builder.Services.AddSingleton<ConnectionOutcomeService>();
|
||||||
|
builder.Services.AddSingleton(new ProvisioningReadiness(true));
|
||||||
|
}
|
||||||
|
|
||||||
builder.Services
|
builder.Services
|
||||||
.AddOptions<UdpMediatorOptions>()
|
.AddOptions<UdpMediatorOptions>()
|
||||||
.BindConfiguration(UdpMediatorOptions.SectionName)
|
.BindConfiguration(UdpMediatorOptions.SectionName)
|
||||||
.ValidateDataAnnotations()
|
.ValidateDataAnnotations()
|
||||||
.Validate(
|
.Validate(
|
||||||
options => IPAddress.TryParse(options.ListenAddress, out _),
|
options => IPAddress.TryParse(options.ListenAddress, out IPAddress? address)
|
||||||
$"{UdpMediatorOptions.SectionName}:ListenAddress must be an IP address.")
|
&& address.AddressFamily == System.Net.Sockets.AddressFamily.InterNetwork,
|
||||||
|
$"{UdpMediatorOptions.SectionName}:ListenAddress must be an IPv4 address.")
|
||||||
|
.Validate(
|
||||||
|
options => string.IsNullOrWhiteSpace(options.Ipv6ListenAddress)
|
||||||
|
|| (IPAddress.TryParse(options.Ipv6ListenAddress, out IPAddress? address)
|
||||||
|
&& address.AddressFamily == System.Net.Sockets.AddressFamily.InterNetworkV6),
|
||||||
|
$"{UdpMediatorOptions.SectionName}:Ipv6ListenAddress must be an IPv6 address when configured.")
|
||||||
.ValidateOnStart();
|
.ValidateOnStart();
|
||||||
builder.Services.AddSingleton<UdpMediatorService>();
|
builder.Services.AddSingleton<UdpMediatorService>();
|
||||||
builder.Services.AddHostedService(static services => services.GetRequiredService<UdpMediatorService>());
|
if (!isOpenApiGeneration)
|
||||||
|
{
|
||||||
|
builder.Services.AddSingleton<NatMediationProcessor>();
|
||||||
|
builder.Services.AddHostedService(static services =>
|
||||||
|
services.GetRequiredService<UdpMediatorService>());
|
||||||
|
}
|
||||||
|
|
||||||
WebApplication app = builder.Build();
|
WebApplication app = builder.Build();
|
||||||
|
app.Lifetime.ApplicationStopping.Register(() => stateStore.BeginDrain());
|
||||||
|
|
||||||
app.MapGet("/health/live", static () => Results.Ok(new { status = "live" }));
|
if (TrustedProxyForwarding.IsEnabled(configuredAbuseProtection))
|
||||||
|
{
|
||||||
|
app.UseForwardedHeaders();
|
||||||
|
}
|
||||||
|
app.UseExceptionHandler();
|
||||||
|
app.UseMiddleware<HttpAbuseProtectionMiddleware>();
|
||||||
|
app.MapOpenApi();
|
||||||
|
app.MapRendezvousContractEndpoints();
|
||||||
|
app.MapGet(
|
||||||
|
"/health/live",
|
||||||
|
static () => Results.Ok(new HealthResponse { Status = "live" }))
|
||||||
|
.Produces<HealthResponse>()
|
||||||
|
.Produces<ApiError>(StatusCodes.Status429TooManyRequests)
|
||||||
|
.WithName("GetLiveness")
|
||||||
|
.WithTags("Health");
|
||||||
app.MapGet(
|
app.MapGet(
|
||||||
"/health/ready",
|
"/health/ready",
|
||||||
static (UdpMediatorService mediator) => mediator.LocalEndpoint is null
|
static (
|
||||||
|
UdpMediatorService mediator,
|
||||||
|
ProvisioningReadiness provisioning,
|
||||||
|
IEphemeralRendezvousStore state) =>
|
||||||
|
mediator.LocalEndpoint is null
|
||||||
|
|| !provisioning.IsReady
|
||||||
|
|| !state.IsAvailable
|
||||||
|
|| state.IsDraining
|
||||||
? Results.StatusCode(StatusCodes.Status503ServiceUnavailable)
|
? Results.StatusCode(StatusCodes.Status503ServiceUnavailable)
|
||||||
: Results.Ok(new { status = "ready" }));
|
: Results.Ok(new HealthResponse { Status = "ready" }))
|
||||||
|
.Produces<HealthResponse>()
|
||||||
|
.Produces<ApiError>(StatusCodes.Status429TooManyRequests)
|
||||||
|
.Produces(StatusCodes.Status503ServiceUnavailable)
|
||||||
|
.WithName("GetReadiness")
|
||||||
|
.WithTags("Health");
|
||||||
|
|
||||||
await app.RunAsync();
|
await app.RunAsync();
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,3 @@
|
|||||||
|
using System.Runtime.CompilerServices;
|
||||||
|
|
||||||
|
[assembly: InternalsVisibleTo("FinalFactory.Rendezvous.Tests")]
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
{
|
||||||
|
"$schema": "https://json.schemastore.org/launchsettings.json",
|
||||||
|
"profiles": {
|
||||||
|
"development": {
|
||||||
|
"commandName": "Project",
|
||||||
|
"dotnetRunMessages": true,
|
||||||
|
"launchBrowser": false,
|
||||||
|
"applicationUrl": "http://127.0.0.1:5096",
|
||||||
|
"environmentVariables": {
|
||||||
|
"ASPNETCORE_ENVIRONMENT": "Development"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,80 @@
|
|||||||
|
using System.Text.Json;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
internal sealed class GamePolicy
|
||||||
|
{
|
||||||
|
private readonly HashSet<uint> _protocolVersions;
|
||||||
|
private readonly HashSet<RegionId> _regions;
|
||||||
|
private readonly HashSet<ListingVisibility> _visibilityModes;
|
||||||
|
private readonly HashSet<PublisherTrustMode> _publisherTrustModes;
|
||||||
|
private readonly Dictionary<string, int> _metadataValueMaxBytes;
|
||||||
|
private readonly HashSet<string> _requiredMetadataKeys;
|
||||||
|
|
||||||
|
public GamePolicy(GamePolicyOptions options)
|
||||||
|
{
|
||||||
|
GameId = new GameId(options.GameId);
|
||||||
|
EnvironmentId = new EnvironmentId(options.EnvironmentId);
|
||||||
|
Enabled = options.Enabled;
|
||||||
|
_protocolVersions = new HashSet<uint>(options.ProtocolVersions);
|
||||||
|
_regions = options.Regions.Select(static region => new RegionId(region)).ToHashSet();
|
||||||
|
_visibilityModes = new HashSet<ListingVisibility>(options.VisibilityModes);
|
||||||
|
_publisherTrustModes = new HashSet<PublisherTrustMode>(options.PublisherTrustModes);
|
||||||
|
_metadataValueMaxBytes = new Dictionary<string, int>(
|
||||||
|
options.MetadataValueMaxBytes,
|
||||||
|
StringComparer.Ordinal);
|
||||||
|
_requiredMetadataKeys = new HashSet<string>(
|
||||||
|
options.RequiredMetadataKeys,
|
||||||
|
StringComparer.Ordinal);
|
||||||
|
MetadataMaxBytes = options.MetadataMaxBytes;
|
||||||
|
MetadataMaxKeys = options.MetadataMaxKeys;
|
||||||
|
MaxListingsPerPrincipal = options.MaxListingsPerPrincipal;
|
||||||
|
MaxAnonymousListingsPerAddress = options.MaxAnonymousListingsPerAddress;
|
||||||
|
MaxActiveJoinAttempts = options.MaxActiveJoinAttempts;
|
||||||
|
FallbackPolicy = options.FallbackPolicy;
|
||||||
|
}
|
||||||
|
|
||||||
|
public GameId GameId { get; }
|
||||||
|
public EnvironmentId EnvironmentId { get; }
|
||||||
|
public bool Enabled { get; }
|
||||||
|
public int MetadataMaxBytes { get; }
|
||||||
|
public int MetadataMaxKeys { get; }
|
||||||
|
public int MaxListingsPerPrincipal { get; }
|
||||||
|
public int MaxAnonymousListingsPerAddress { get; }
|
||||||
|
public int MaxActiveJoinAttempts { get; }
|
||||||
|
public FallbackPolicyMode FallbackPolicy { get; }
|
||||||
|
|
||||||
|
public bool AllowsProtocol(uint protocolVersion) =>
|
||||||
|
_protocolVersions.Contains(protocolVersion);
|
||||||
|
|
||||||
|
public bool AllowsRegion(RegionId regionId) => _regions.Contains(regionId);
|
||||||
|
|
||||||
|
public bool AllowsVisibility(ListingVisibility visibility) =>
|
||||||
|
_visibilityModes.Contains(visibility);
|
||||||
|
|
||||||
|
public bool AllowsPublisherTrust(PublisherTrustMode trustMode) =>
|
||||||
|
_publisherTrustModes.Contains(trustMode);
|
||||||
|
|
||||||
|
public bool AllowsMetadata(IReadOnlyDictionary<string, string>? metadata)
|
||||||
|
{
|
||||||
|
if (!ContractValidation.IsMetadataValid(metadata)
|
||||||
|
|| metadata!.Count > MetadataMaxKeys
|
||||||
|
|| !_requiredMetadataKeys.IsSubsetOf(metadata.Keys))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach (KeyValuePair<string, string> item in metadata)
|
||||||
|
{
|
||||||
|
if (!_metadataValueMaxBytes.TryGetValue(item.Key, out int maximumBytes)
|
||||||
|
|| !ContractValidation.IsUtf8LengthWithin(item.Value, maximumBytes))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return JsonSerializer.SerializeToUtf8Bytes(metadata, ContractJson.Options).Length
|
||||||
|
<= MetadataMaxBytes;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,118 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
internal sealed class GamePolicyRegistry
|
||||||
|
{
|
||||||
|
private readonly Dictionary<(GameId Game, EnvironmentId Environment), GamePolicy> _policies;
|
||||||
|
|
||||||
|
private GamePolicyRegistry(
|
||||||
|
Dictionary<(GameId Game, EnvironmentId Environment), GamePolicy> policies) =>
|
||||||
|
_policies = policies;
|
||||||
|
|
||||||
|
public bool HasEnabledPolicies => _policies.Values.Any(static policy => policy.Enabled);
|
||||||
|
public IEnumerable<GamePolicy> EnabledPolicies =>
|
||||||
|
_policies.Values.Where(static policy => policy.Enabled);
|
||||||
|
|
||||||
|
public static GamePolicyRegistry Create(IEnumerable<GamePolicyOptions> options)
|
||||||
|
{
|
||||||
|
GamePolicyOptions[] configuredPolicies = options.ToArray();
|
||||||
|
if (configuredPolicies.Length > ProvisioningLimits.MaxGamePolicies)
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"At most {ProvisioningLimits.MaxGamePolicies} game policies may be configured.");
|
||||||
|
}
|
||||||
|
|
||||||
|
Dictionary<(GameId Game, EnvironmentId Environment), GamePolicy> policies = [];
|
||||||
|
foreach (GamePolicyOptions policyOptions in configuredPolicies)
|
||||||
|
{
|
||||||
|
Validate(policyOptions);
|
||||||
|
GamePolicy policy = new(policyOptions);
|
||||||
|
if (!policies.TryAdd((policy.GameId, policy.EnvironmentId), policy))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Duplicate game/environment policy: {policy.GameId}/{policy.EnvironmentId}.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return new GamePolicyRegistry(policies);
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool TryGet(
|
||||||
|
GameId gameId,
|
||||||
|
EnvironmentId environmentId,
|
||||||
|
out GamePolicy? policy)
|
||||||
|
{
|
||||||
|
if (_policies.TryGetValue((gameId, environmentId), out GamePolicy? candidate)
|
||||||
|
&& candidate.Enabled)
|
||||||
|
{
|
||||||
|
policy = candidate;
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
policy = null;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void Validate(GamePolicyOptions options)
|
||||||
|
{
|
||||||
|
if (!GameId.TryParse(options.GameId, out _)
|
||||||
|
|| !EnvironmentId.TryParse(options.EnvironmentId, out _))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
"Game policies require valid game and environment IDs.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (options.ProtocolVersions.Count is 0 or > ProvisioningLimits.MaxProtocolVersionsPerPolicy
|
||||||
|
|| options.ProtocolVersions.Contains(0)
|
||||||
|
|| options.ProtocolVersions.Count != options.ProtocolVersions.Distinct().Count())
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Policy {options.GameId}/{options.EnvironmentId} requires unique non-zero protocol versions.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (options.Regions.Count is 0 or > ProvisioningLimits.MaxRegionsPerPolicy
|
||||||
|
|| options.Regions.Any(static region => !RegionId.TryParse(region, out _))
|
||||||
|
|| options.Regions.Count != options.Regions.Distinct(StringComparer.Ordinal).Count())
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Policy {options.GameId}/{options.EnvironmentId} requires unique valid regions.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (options.VisibilityModes.Count == 0
|
||||||
|
|| options.VisibilityModes.Any(static mode => !Enum.IsDefined(mode))
|
||||||
|
|| options.VisibilityModes.Count != options.VisibilityModes.Distinct().Count()
|
||||||
|
|| options.PublisherTrustModes.Count == 0
|
||||||
|
|| options.PublisherTrustModes.Any(static mode => !Enum.IsDefined(mode))
|
||||||
|
|| options.PublisherTrustModes.Count != options.PublisherTrustModes.Distinct().Count())
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Policy {options.GameId}/{options.EnvironmentId} requires valid visibility and trust modes.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (options.MetadataMaxBytes is < 2 or > ContractLimits.MetadataMaxBytes
|
||||||
|
|| options.MetadataMaxKeys is < 0 or > ContractLimits.MetadataMaxKeys
|
||||||
|
|| options.MetadataValueMaxBytes.Count > options.MetadataMaxKeys
|
||||||
|
|| options.MetadataValueMaxBytes.Any(static item =>
|
||||||
|
string.IsNullOrWhiteSpace(item.Key)
|
||||||
|
|| !ContractValidation.IsUtf8LengthWithin(item.Key, ContractLimits.MetadataKeyMaxBytes)
|
||||||
|
|| item.Value is < 0 or > ContractLimits.MetadataValueMaxBytes)
|
||||||
|
|| options.RequiredMetadataKeys.Any(key =>
|
||||||
|
!options.MetadataValueMaxBytes.ContainsKey(key)))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Policy {options.GameId}/{options.EnvironmentId} has an invalid metadata schema.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (options.MaxListingsPerPrincipal is < 1 or > ProvisioningLimits.MaxListingsPerPrincipal
|
||||||
|
|| options.MaxAnonymousListingsPerAddress < 0
|
||||||
|
|| options.MaxAnonymousListingsPerAddress > options.MaxListingsPerPrincipal
|
||||||
|
|| options.MaxActiveJoinAttempts is < 1
|
||||||
|
or > ProvisioningLimits.MaxActiveJoinAttemptsPerPolicy
|
||||||
|
|| !Enum.IsDefined(options.FallbackPolicy))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Policy {options.GameId}/{options.EnvironmentId} has invalid quotas or fallback policy.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,458 @@
|
|||||||
|
using System.Security.Cryptography;
|
||||||
|
using System.Text;
|
||||||
|
using System.Text.Json;
|
||||||
|
using System.Text.Json.Serialization;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
internal sealed class PrincipalCredentialService
|
||||||
|
{
|
||||||
|
private const string TokenPrefix = "rv1";
|
||||||
|
private readonly string _issuer;
|
||||||
|
private readonly string _audience;
|
||||||
|
private readonly TimeSpan _clockSkew;
|
||||||
|
private readonly SigningKeyRing _keyRing;
|
||||||
|
|
||||||
|
public PrincipalCredentialService(
|
||||||
|
string issuer,
|
||||||
|
string audience,
|
||||||
|
TimeSpan clockSkew,
|
||||||
|
SigningKeyRing keyRing)
|
||||||
|
{
|
||||||
|
if (!IsSafeAuthority(issuer) || !IsSafeAuthority(audience))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
"Credential issuer and audience are required.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (clockSkew < TimeSpan.Zero || clockSkew > TimeSpan.FromSeconds(30))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
"Credential clock skew must be between zero and 30 seconds.");
|
||||||
|
}
|
||||||
|
|
||||||
|
_issuer = issuer;
|
||||||
|
_audience = audience;
|
||||||
|
_clockSkew = clockSkew;
|
||||||
|
_keyRing = keyRing;
|
||||||
|
}
|
||||||
|
|
||||||
|
public string Issue(AuthenticatedPrincipal principal, DateTimeOffset now)
|
||||||
|
{
|
||||||
|
if (!IsSafeSubject(principal.Subject))
|
||||||
|
{
|
||||||
|
throw new ArgumentException(
|
||||||
|
"Principal subjects must be 1–128 visible ASCII characters.",
|
||||||
|
nameof(principal));
|
||||||
|
}
|
||||||
|
|
||||||
|
if (principal.ExpiresAt <= now)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("Cannot issue an already-expired principal.", nameof(principal));
|
||||||
|
}
|
||||||
|
|
||||||
|
CredentialPayload payload = CreatePayload(principal, now);
|
||||||
|
if (CreatePrincipal(payload, principal.ExpiresAt) is null)
|
||||||
|
{
|
||||||
|
throw new ArgumentException(
|
||||||
|
"The principal contains an invalid kind or scope.",
|
||||||
|
nameof(principal));
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!_keyRing.TryGetSigningKey(
|
||||||
|
now,
|
||||||
|
payload.Kind,
|
||||||
|
payload.GameId,
|
||||||
|
payload.EnvironmentId,
|
||||||
|
out SigningKey? signingKey)
|
||||||
|
|| signingKey is null)
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException("No active signing key is available.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (principal.ExpiresAt > signingKey.VerifyUntil)
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException(
|
||||||
|
"The active key verification window is shorter than the credential lifetime.");
|
||||||
|
}
|
||||||
|
|
||||||
|
string encodedPayload = Base64Url.Encode(
|
||||||
|
JsonSerializer.SerializeToUtf8Bytes(payload, ContractJson.Options));
|
||||||
|
string signedContent = $"{TokenPrefix}.{signingKey.KeyId}.{encodedPayload}";
|
||||||
|
string signature = Base64Url.Encode(signingKey.Sign(signedContent));
|
||||||
|
string token = $"{signedContent}.{signature}";
|
||||||
|
if (!ContractValidation.IsOpaqueHttpCredentialValid(token))
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException("The signed credential exceeds the v1 size limit.");
|
||||||
|
}
|
||||||
|
|
||||||
|
return token;
|
||||||
|
}
|
||||||
|
|
||||||
|
public CredentialValidationResult Validate(string? token, DateTimeOffset now)
|
||||||
|
{
|
||||||
|
if (!ContractValidation.IsOpaqueHttpCredentialValid(token))
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.Malformed);
|
||||||
|
}
|
||||||
|
|
||||||
|
string[] segments = token!.Split('.');
|
||||||
|
if (segments.Length != 4
|
||||||
|
|| !string.Equals(segments[0], TokenPrefix, StringComparison.Ordinal)
|
||||||
|
|| segments[1].Length == 0)
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.Malformed);
|
||||||
|
}
|
||||||
|
|
||||||
|
VerificationKeyLookup lookup = _keyRing.FindVerificationKey(
|
||||||
|
segments[1],
|
||||||
|
now,
|
||||||
|
out SigningKey? signingKey);
|
||||||
|
if (lookup != VerificationKeyLookup.Available || signingKey is null)
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(lookup switch
|
||||||
|
{
|
||||||
|
VerificationKeyLookup.Revoked => CredentialValidationError.KeyRevoked,
|
||||||
|
VerificationKeyLookup.NotYetValid => CredentialValidationError.KeyNotYetValid,
|
||||||
|
VerificationKeyLookup.Retired => CredentialValidationError.KeyRetired,
|
||||||
|
_ => CredentialValidationError.UnknownKey,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!Base64Url.TryDecode(segments[3], out byte[]? suppliedSignature))
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.SignatureInvalid);
|
||||||
|
}
|
||||||
|
|
||||||
|
string signedContent = $"{segments[0]}.{segments[1]}.{segments[2]}";
|
||||||
|
byte[] expectedSignature = signingKey.Sign(signedContent);
|
||||||
|
bool signatureMatches = suppliedSignature.Length == expectedSignature.Length
|
||||||
|
&& CryptographicOperations.FixedTimeEquals(suppliedSignature, expectedSignature);
|
||||||
|
CryptographicOperations.ZeroMemory(suppliedSignature);
|
||||||
|
CryptographicOperations.ZeroMemory(expectedSignature);
|
||||||
|
if (!signatureMatches)
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.SignatureInvalid);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!Base64Url.TryDecode(segments[2], out byte[]? encodedPayload))
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.Malformed);
|
||||||
|
}
|
||||||
|
|
||||||
|
CredentialPayload? payload;
|
||||||
|
try
|
||||||
|
{
|
||||||
|
payload = JsonSerializer.Deserialize<CredentialPayload>(
|
||||||
|
encodedPayload,
|
||||||
|
ContractJson.Options);
|
||||||
|
}
|
||||||
|
catch (JsonException)
|
||||||
|
{
|
||||||
|
payload = null;
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(encodedPayload);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (payload is null || payload.Version != ContractLimits.ContractVersion)
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.PayloadInvalid);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!string.Equals(payload.Issuer, _issuer, StringComparison.Ordinal))
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.IssuerMismatch);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!string.Equals(payload.Audience, _audience, StringComparison.Ordinal))
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.AudienceMismatch);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!signingKey.Authorizes(payload.Kind, payload.GameId, payload.EnvironmentId))
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.KeyScopeMismatch);
|
||||||
|
}
|
||||||
|
|
||||||
|
DateTimeOffset issuedAt;
|
||||||
|
DateTimeOffset notBefore;
|
||||||
|
DateTimeOffset expiresAt;
|
||||||
|
try
|
||||||
|
{
|
||||||
|
issuedAt = DateTimeOffset.FromUnixTimeSeconds(payload.IssuedAtUnixSeconds);
|
||||||
|
notBefore = DateTimeOffset.FromUnixTimeSeconds(payload.NotBeforeUnixSeconds);
|
||||||
|
expiresAt = DateTimeOffset.FromUnixTimeSeconds(payload.ExpiresAtUnixSeconds);
|
||||||
|
}
|
||||||
|
catch (ArgumentOutOfRangeException)
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.PayloadInvalid);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (issuedAt > now + _clockSkew || notBefore > now + _clockSkew)
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.NotYetValid);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (expiresAt <= now - _clockSkew || expiresAt <= notBefore)
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.Expired);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (issuedAt > notBefore
|
||||||
|
|| issuedAt < signingKey.NotBefore - _clockSkew
|
||||||
|
|| expiresAt > signingKey.VerifyUntil)
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.PayloadInvalid);
|
||||||
|
}
|
||||||
|
|
||||||
|
AuthenticatedPrincipal? principal = CreatePrincipal(payload, expiresAt);
|
||||||
|
return principal is null
|
||||||
|
? CredentialValidationResult.Invalid(CredentialValidationError.ScopeInvalid)
|
||||||
|
: CredentialValidationResult.Valid(principal);
|
||||||
|
}
|
||||||
|
|
||||||
|
public override string ToString() => "[PrincipalCredentialService: key material and credentials redacted]";
|
||||||
|
|
||||||
|
private CredentialPayload CreatePayload(AuthenticatedPrincipal principal, DateTimeOffset now)
|
||||||
|
{
|
||||||
|
CredentialPayload payload = new()
|
||||||
|
{
|
||||||
|
Version = ContractLimits.ContractVersion,
|
||||||
|
Issuer = _issuer,
|
||||||
|
Audience = _audience,
|
||||||
|
Subject = principal.Subject,
|
||||||
|
IssuedAtUnixSeconds = now.ToUnixTimeSeconds(),
|
||||||
|
NotBeforeUnixSeconds = now.ToUnixTimeSeconds(),
|
||||||
|
ExpiresAtUnixSeconds = principal.ExpiresAt.ToUnixTimeSeconds(),
|
||||||
|
Nonce = Guid.NewGuid().ToString("N"),
|
||||||
|
};
|
||||||
|
|
||||||
|
switch (principal)
|
||||||
|
{
|
||||||
|
case DedicatedPublisherPrincipal publisher:
|
||||||
|
SetPublisherPayload(payload, publisher, PrincipalCredentialKind.DedicatedPublisher);
|
||||||
|
break;
|
||||||
|
case PlayerHostGrantPrincipal publisher:
|
||||||
|
SetPublisherPayload(payload, publisher, PrincipalCredentialKind.PlayerHostGrant);
|
||||||
|
break;
|
||||||
|
case OperatorPrincipal operatorPrincipal:
|
||||||
|
payload.Kind = PrincipalCredentialKind.Operator;
|
||||||
|
payload.Permissions = operatorPrincipal.Permissions.Order().ToList();
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
throw new ArgumentException(
|
||||||
|
"Anonymous principals cannot receive reusable signed credentials.",
|
||||||
|
nameof(principal));
|
||||||
|
}
|
||||||
|
|
||||||
|
return payload;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void SetPublisherPayload(
|
||||||
|
CredentialPayload payload,
|
||||||
|
IPublisherPrincipal publisher,
|
||||||
|
PrincipalCredentialKind kind)
|
||||||
|
{
|
||||||
|
payload.Kind = kind;
|
||||||
|
payload.GameId = publisher.GameId.ToString();
|
||||||
|
payload.EnvironmentId = publisher.EnvironmentId.ToString();
|
||||||
|
payload.Regions = publisher.AllowedRegions
|
||||||
|
.Select(static region => region.ToString())
|
||||||
|
.Order(StringComparer.Ordinal)
|
||||||
|
.ToList();
|
||||||
|
}
|
||||||
|
|
||||||
|
private static AuthenticatedPrincipal? CreatePrincipal(
|
||||||
|
CredentialPayload payload,
|
||||||
|
DateTimeOffset expiresAt)
|
||||||
|
{
|
||||||
|
if (!IsSafeSubject(payload.Subject)
|
||||||
|
|| !Guid.TryParseExact(payload.Nonce, "N", out Guid nonce)
|
||||||
|
|| nonce == Guid.Empty)
|
||||||
|
{
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (payload.Kind == PrincipalCredentialKind.Operator)
|
||||||
|
{
|
||||||
|
if (payload.GameId is not null
|
||||||
|
|| payload.EnvironmentId is not null
|
||||||
|
|| payload.Regions.Count != 0
|
||||||
|
|| payload.Permissions.Count == 0
|
||||||
|
|| payload.Permissions.Any(static permission => !Enum.IsDefined(permission))
|
||||||
|
|| payload.Permissions.Count != payload.Permissions.Distinct().Count())
|
||||||
|
{
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
return new OperatorPrincipal(
|
||||||
|
payload.Subject,
|
||||||
|
expiresAt,
|
||||||
|
new HashSet<OperatorPermission>(payload.Permissions));
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!GameId.TryParse(payload.GameId, out GameId gameId)
|
||||||
|
|| !EnvironmentId.TryParse(payload.EnvironmentId, out EnvironmentId environmentId)
|
||||||
|
|| payload.Regions.Count == 0
|
||||||
|
|| payload.Regions.Any(static region => !RegionId.TryParse(region, out _))
|
||||||
|
|| payload.Regions.Count != payload.Regions.Distinct(StringComparer.Ordinal).Count()
|
||||||
|
|| payload.Permissions.Count != 0)
|
||||||
|
{
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
HashSet<RegionId> regions = payload.Regions.Select(static region => new RegionId(region)).ToHashSet();
|
||||||
|
return payload.Kind switch
|
||||||
|
{
|
||||||
|
PrincipalCredentialKind.DedicatedPublisher => new DedicatedPublisherPrincipal(
|
||||||
|
payload.Subject,
|
||||||
|
expiresAt,
|
||||||
|
gameId,
|
||||||
|
environmentId,
|
||||||
|
regions),
|
||||||
|
PrincipalCredentialKind.PlayerHostGrant => new PlayerHostGrantPrincipal(
|
||||||
|
payload.Subject,
|
||||||
|
expiresAt,
|
||||||
|
gameId,
|
||||||
|
environmentId,
|
||||||
|
regions),
|
||||||
|
_ => null,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool IsSafeSubject(string? value) =>
|
||||||
|
value is not null
|
||||||
|
&& value.Length is > 0 and <= 128
|
||||||
|
&& value.All(static character => character is >= '!' and <= '~');
|
||||||
|
|
||||||
|
private static bool IsSafeAuthority(string? value) =>
|
||||||
|
value is not null
|
||||||
|
&& value.Length is > 0 and <= 128
|
||||||
|
&& value.All(static character => character is >= '!' and <= '~');
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class CredentialPayload
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public int Version { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string Issuer { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string Audience { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string Subject { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public PrincipalCredentialKind Kind { get; set; }
|
||||||
|
|
||||||
|
public string? GameId { get; set; }
|
||||||
|
public string? EnvironmentId { get; set; }
|
||||||
|
public List<string> Regions { get; set; } = [];
|
||||||
|
public List<OperatorPermission> Permissions { get; set; } = [];
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public long IssuedAtUnixSeconds { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public long NotBeforeUnixSeconds { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public long ExpiresAtUnixSeconds { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string Nonce { get; set; } = string.Empty;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal readonly record struct CredentialValidationResult(
|
||||||
|
bool IsValid,
|
||||||
|
CredentialValidationError Error,
|
||||||
|
AuthenticatedPrincipal? Principal)
|
||||||
|
{
|
||||||
|
public static CredentialValidationResult Valid(AuthenticatedPrincipal principal) =>
|
||||||
|
new(true, CredentialValidationError.None, principal);
|
||||||
|
|
||||||
|
public static CredentialValidationResult Invalid(CredentialValidationError error) =>
|
||||||
|
new(false, error, null);
|
||||||
|
|
||||||
|
public override string ToString() => $"[CredentialValidation: {Error}, credential redacted]";
|
||||||
|
}
|
||||||
|
|
||||||
|
internal enum CredentialValidationError
|
||||||
|
{
|
||||||
|
None = 0,
|
||||||
|
Malformed = 1,
|
||||||
|
UnknownKey = 2,
|
||||||
|
KeyRevoked = 3,
|
||||||
|
KeyNotYetValid = 4,
|
||||||
|
KeyRetired = 5,
|
||||||
|
SignatureInvalid = 6,
|
||||||
|
PayloadInvalid = 7,
|
||||||
|
IssuerMismatch = 8,
|
||||||
|
AudienceMismatch = 9,
|
||||||
|
KeyScopeMismatch = 10,
|
||||||
|
NotYetValid = 11,
|
||||||
|
Expired = 12,
|
||||||
|
ScopeInvalid = 13,
|
||||||
|
}
|
||||||
|
|
||||||
|
internal static class Base64Url
|
||||||
|
{
|
||||||
|
public static string Encode(ReadOnlySpan<byte> bytes) => Convert
|
||||||
|
.ToBase64String(bytes)
|
||||||
|
.TrimEnd('=')
|
||||||
|
.Replace('+', '-')
|
||||||
|
.Replace('/', '_');
|
||||||
|
|
||||||
|
public static bool TryDecode(string value, out byte[] bytes)
|
||||||
|
{
|
||||||
|
bytes = [];
|
||||||
|
if (string.IsNullOrEmpty(value)
|
||||||
|
|| value.Any(static character =>
|
||||||
|
character is not (>= 'A' and <= 'Z')
|
||||||
|
and not (>= 'a' and <= 'z')
|
||||||
|
and not (>= '0' and <= '9')
|
||||||
|
and not '-'
|
||||||
|
and not '_'))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
string padded = value.Replace('-', '+').Replace('_', '/');
|
||||||
|
int remainder = padded.Length % 4;
|
||||||
|
if (remainder == 1)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
padded += remainder switch
|
||||||
|
{
|
||||||
|
0 => string.Empty,
|
||||||
|
2 => "==",
|
||||||
|
3 => "=",
|
||||||
|
_ => string.Empty,
|
||||||
|
};
|
||||||
|
|
||||||
|
try
|
||||||
|
{
|
||||||
|
bytes = Convert.FromBase64String(padded);
|
||||||
|
if (string.Equals(Encode(bytes), value, StringComparison.Ordinal))
|
||||||
|
{
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
CryptographicOperations.ZeroMemory(bytes);
|
||||||
|
bytes = [];
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
catch (FormatException)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,107 @@
|
|||||||
|
using System.Collections.Frozen;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
internal abstract record AuthenticatedPrincipal(
|
||||||
|
string Subject,
|
||||||
|
DateTimeOffset ExpiresAt);
|
||||||
|
|
||||||
|
internal interface IPublisherPrincipal
|
||||||
|
{
|
||||||
|
string Subject { get; }
|
||||||
|
DateTimeOffset ExpiresAt { get; }
|
||||||
|
GameId GameId { get; }
|
||||||
|
EnvironmentId EnvironmentId { get; }
|
||||||
|
PublisherTrustMode TrustMode { get; }
|
||||||
|
IReadOnlySet<RegionId> AllowedRegions { get; }
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record DedicatedPublisherPrincipal : AuthenticatedPrincipal, IPublisherPrincipal
|
||||||
|
{
|
||||||
|
public DedicatedPublisherPrincipal(
|
||||||
|
string subject,
|
||||||
|
DateTimeOffset expiresAt,
|
||||||
|
GameId gameId,
|
||||||
|
EnvironmentId environmentId,
|
||||||
|
IEnumerable<RegionId> allowedRegions)
|
||||||
|
: base(subject, expiresAt)
|
||||||
|
{
|
||||||
|
GameId = gameId;
|
||||||
|
EnvironmentId = environmentId;
|
||||||
|
AllowedRegions = allowedRegions.ToFrozenSet();
|
||||||
|
}
|
||||||
|
|
||||||
|
public GameId GameId { get; }
|
||||||
|
public EnvironmentId EnvironmentId { get; }
|
||||||
|
public IReadOnlySet<RegionId> AllowedRegions { get; }
|
||||||
|
public PublisherTrustMode TrustMode => PublisherTrustMode.ManagedDedicated;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record PlayerHostGrantPrincipal : AuthenticatedPrincipal, IPublisherPrincipal
|
||||||
|
{
|
||||||
|
public PlayerHostGrantPrincipal(
|
||||||
|
string subject,
|
||||||
|
DateTimeOffset expiresAt,
|
||||||
|
GameId gameId,
|
||||||
|
EnvironmentId environmentId,
|
||||||
|
IEnumerable<RegionId> allowedRegions)
|
||||||
|
: base(subject, expiresAt)
|
||||||
|
{
|
||||||
|
GameId = gameId;
|
||||||
|
EnvironmentId = environmentId;
|
||||||
|
AllowedRegions = allowedRegions.ToFrozenSet();
|
||||||
|
}
|
||||||
|
|
||||||
|
public GameId GameId { get; }
|
||||||
|
public EnvironmentId EnvironmentId { get; }
|
||||||
|
public IReadOnlySet<RegionId> AllowedRegions { get; }
|
||||||
|
public PublisherTrustMode TrustMode => PublisherTrustMode.PlayerGrant;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record AnonymousUnlistedPrincipal : AuthenticatedPrincipal, IPublisherPrincipal
|
||||||
|
{
|
||||||
|
public AnonymousUnlistedPrincipal(
|
||||||
|
string subject,
|
||||||
|
DateTimeOffset expiresAt,
|
||||||
|
GameId gameId,
|
||||||
|
EnvironmentId environmentId,
|
||||||
|
IEnumerable<RegionId> allowedRegions)
|
||||||
|
: base(subject, expiresAt)
|
||||||
|
{
|
||||||
|
GameId = gameId;
|
||||||
|
EnvironmentId = environmentId;
|
||||||
|
AllowedRegions = allowedRegions.ToFrozenSet();
|
||||||
|
}
|
||||||
|
|
||||||
|
public GameId GameId { get; }
|
||||||
|
public EnvironmentId EnvironmentId { get; }
|
||||||
|
public IReadOnlySet<RegionId> AllowedRegions { get; }
|
||||||
|
public PublisherTrustMode TrustMode => PublisherTrustMode.AnonymousUnlisted;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record OperatorPrincipal : AuthenticatedPrincipal
|
||||||
|
{
|
||||||
|
public OperatorPrincipal(
|
||||||
|
string subject,
|
||||||
|
DateTimeOffset expiresAt,
|
||||||
|
IEnumerable<OperatorPermission> permissions)
|
||||||
|
: base(subject, expiresAt) => Permissions = permissions.ToFrozenSet();
|
||||||
|
|
||||||
|
public IReadOnlySet<OperatorPermission> Permissions { get; }
|
||||||
|
}
|
||||||
|
|
||||||
|
internal enum OperatorPermission
|
||||||
|
{
|
||||||
|
ReadPolicy = 1,
|
||||||
|
ManagePolicy = 2,
|
||||||
|
RevokePublisher = 3,
|
||||||
|
RotateKeys = 4,
|
||||||
|
}
|
||||||
|
|
||||||
|
internal enum PrincipalCredentialKind
|
||||||
|
{
|
||||||
|
DedicatedPublisher = 1,
|
||||||
|
PlayerHostGrant = 2,
|
||||||
|
Operator = 3,
|
||||||
|
}
|
||||||
@@ -0,0 +1,71 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
internal sealed class ProvisioningOptions
|
||||||
|
{
|
||||||
|
public const string SectionName = "Rendezvous:Provisioning";
|
||||||
|
|
||||||
|
public string Issuer { get; set; } = string.Empty;
|
||||||
|
public string Audience { get; set; } = string.Empty;
|
||||||
|
public int ClockSkewSeconds { get; set; } = 30;
|
||||||
|
public List<SigningKeyOptions> SigningKeys { get; set; } = [];
|
||||||
|
public List<GamePolicyOptions> Games { get; set; } = [];
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class SigningKeyOptions
|
||||||
|
{
|
||||||
|
public string KeyId { get; set; } = string.Empty;
|
||||||
|
public string SecretReference { get; set; } = string.Empty;
|
||||||
|
public List<PrincipalCredentialKind> CredentialKinds { get; set; } = [];
|
||||||
|
public string? GameId { get; set; }
|
||||||
|
public string? EnvironmentId { get; set; }
|
||||||
|
public DateTimeOffset NotBefore { get; set; }
|
||||||
|
public DateTimeOffset SignUntil { get; set; }
|
||||||
|
public DateTimeOffset VerifyUntil { get; set; }
|
||||||
|
public bool Revoked { get; set; }
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class GamePolicyOptions
|
||||||
|
{
|
||||||
|
public string GameId { get; set; } = string.Empty;
|
||||||
|
public string EnvironmentId { get; set; } = string.Empty;
|
||||||
|
public bool Enabled { get; set; } = true;
|
||||||
|
public List<uint> ProtocolVersions { get; set; } = [];
|
||||||
|
public List<string> Regions { get; set; } = [];
|
||||||
|
public List<ListingVisibility> VisibilityModes { get; set; } = [];
|
||||||
|
public List<PublisherTrustMode> PublisherTrustModes { get; set; } = [];
|
||||||
|
public Dictionary<string, int> MetadataValueMaxBytes { get; set; } =
|
||||||
|
new(StringComparer.Ordinal);
|
||||||
|
public List<string> RequiredMetadataKeys { get; set; } = [];
|
||||||
|
public int MetadataMaxBytes { get; set; } = ContractLimits.MetadataMaxBytes;
|
||||||
|
public int MetadataMaxKeys { get; set; } = ContractLimits.MetadataMaxKeys;
|
||||||
|
public int MaxListingsPerPrincipal { get; set; } = 100;
|
||||||
|
public int MaxAnonymousListingsPerAddress { get; set; } = 2;
|
||||||
|
public int MaxActiveJoinAttempts { get; set; } = 1_000;
|
||||||
|
public FallbackPolicyMode FallbackPolicy { get; set; }
|
||||||
|
}
|
||||||
|
|
||||||
|
internal enum FallbackPolicyMode
|
||||||
|
{
|
||||||
|
Disabled = 0,
|
||||||
|
DedicatedEndpointAllowed = 1,
|
||||||
|
}
|
||||||
|
|
||||||
|
internal static class ProvisioningLimits
|
||||||
|
{
|
||||||
|
public const int MaxGamePolicies = 1_024;
|
||||||
|
public const int MaxSigningKeys = 128;
|
||||||
|
public const int MaxProtocolVersionsPerPolicy = 64;
|
||||||
|
public const int MaxRegionsPerPolicy = 32;
|
||||||
|
public const int MaxListingsPerPrincipal = 25_000;
|
||||||
|
public const int MaxActiveJoinAttemptsPerPolicy = 10_000;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class ProvisioningConfigurationException : Exception
|
||||||
|
{
|
||||||
|
public ProvisioningConfigurationException(string message)
|
||||||
|
: base(message)
|
||||||
|
{
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,120 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
internal sealed class ProvisioningRuntime : IDisposable
|
||||||
|
{
|
||||||
|
private readonly IDisposable? _secretProviderLifetime;
|
||||||
|
|
||||||
|
private ProvisioningRuntime(
|
||||||
|
GamePolicyRegistry policies,
|
||||||
|
SigningKeyRing signingKeys,
|
||||||
|
PrincipalCredentialService credentials,
|
||||||
|
PublisherAuthorizationService publisherAuthorization,
|
||||||
|
IDisposable? secretProviderLifetime)
|
||||||
|
{
|
||||||
|
Policies = policies;
|
||||||
|
SigningKeys = signingKeys;
|
||||||
|
Credentials = credentials;
|
||||||
|
PublisherAuthorization = publisherAuthorization;
|
||||||
|
_secretProviderLifetime = secretProviderLifetime;
|
||||||
|
}
|
||||||
|
|
||||||
|
public GamePolicyRegistry Policies { get; }
|
||||||
|
public SigningKeyRing SigningKeys { get; }
|
||||||
|
public PrincipalCredentialService Credentials { get; }
|
||||||
|
public PublisherAuthorizationService PublisherAuthorization { get; }
|
||||||
|
|
||||||
|
public static ProvisioningRuntime Create(
|
||||||
|
ProvisioningOptions options,
|
||||||
|
ISecretProvider secretProvider,
|
||||||
|
DateTimeOffset now)
|
||||||
|
{
|
||||||
|
try
|
||||||
|
{
|
||||||
|
SigningKeyRing signingKeys = SigningKeyRing.Create(options.SigningKeys, secretProvider);
|
||||||
|
try
|
||||||
|
{
|
||||||
|
if (!signingKeys.HasKeys
|
||||||
|
|| !signingKeys.HasActiveSigningKey(now))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
"At least one active signing key with available production key material is required.");
|
||||||
|
}
|
||||||
|
|
||||||
|
GamePolicyRegistry policies = GamePolicyRegistry.Create(options.Games);
|
||||||
|
if (!policies.HasEnabledPolicies)
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
"At least one enabled game/environment policy is required.");
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach (GamePolicy policy in policies.EnabledPolicies)
|
||||||
|
{
|
||||||
|
RequirePublisherKey(
|
||||||
|
signingKeys,
|
||||||
|
policy,
|
||||||
|
PublisherTrustMode.ManagedDedicated,
|
||||||
|
PrincipalCredentialKind.DedicatedPublisher,
|
||||||
|
now);
|
||||||
|
RequirePublisherKey(
|
||||||
|
signingKeys,
|
||||||
|
policy,
|
||||||
|
PublisherTrustMode.PlayerGrant,
|
||||||
|
PrincipalCredentialKind.PlayerHostGrant,
|
||||||
|
now);
|
||||||
|
}
|
||||||
|
|
||||||
|
PrincipalCredentialService credentials = new(
|
||||||
|
options.Issuer,
|
||||||
|
options.Audience,
|
||||||
|
TimeSpan.FromSeconds(options.ClockSkewSeconds),
|
||||||
|
signingKeys);
|
||||||
|
PublisherAuthorizationService authorization = new(policies);
|
||||||
|
return new ProvisioningRuntime(
|
||||||
|
policies,
|
||||||
|
signingKeys,
|
||||||
|
credentials,
|
||||||
|
authorization,
|
||||||
|
secretProvider as IDisposable);
|
||||||
|
}
|
||||||
|
catch
|
||||||
|
{
|
||||||
|
signingKeys.Dispose();
|
||||||
|
throw;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
catch
|
||||||
|
{
|
||||||
|
(secretProvider as IDisposable)?.Dispose();
|
||||||
|
throw;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public void Dispose()
|
||||||
|
{
|
||||||
|
SigningKeys.Dispose();
|
||||||
|
_secretProviderLifetime?.Dispose();
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void RequirePublisherKey(
|
||||||
|
SigningKeyRing signingKeys,
|
||||||
|
GamePolicy policy,
|
||||||
|
PublisherTrustMode trustMode,
|
||||||
|
PrincipalCredentialKind credentialKind,
|
||||||
|
DateTimeOffset now)
|
||||||
|
{
|
||||||
|
if (policy.AllowsPublisherTrust(trustMode)
|
||||||
|
&& !signingKeys.HasActiveSigningKey(
|
||||||
|
now,
|
||||||
|
credentialKind,
|
||||||
|
policy.GameId.ToString(),
|
||||||
|
policy.EnvironmentId.ToString()))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Policy {policy.GameId}/{policy.EnvironmentId} has no active {credentialKind} key.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record ProvisioningReadiness(bool IsReady);
|
||||||
@@ -0,0 +1,119 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
internal sealed class PublisherAuthorizationService(GamePolicyRegistry policies)
|
||||||
|
{
|
||||||
|
public PublisherAuthorizationResult Authorize(
|
||||||
|
AuthenticatedPrincipal principal,
|
||||||
|
GameId requestedGameId,
|
||||||
|
EnvironmentId requestedEnvironmentId,
|
||||||
|
RegionId requestedRegionId,
|
||||||
|
uint requestedProtocolVersion,
|
||||||
|
ListingVisibility requestedVisibility,
|
||||||
|
IReadOnlyDictionary<string, string> requestedMetadata,
|
||||||
|
DateTimeOffset now)
|
||||||
|
{
|
||||||
|
if (principal.ExpiresAt <= now)
|
||||||
|
{
|
||||||
|
return PublisherAuthorizationResult.Denied(PublisherAuthorizationError.PrincipalExpired);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (principal is not IPublisherPrincipal publisher)
|
||||||
|
{
|
||||||
|
return PublisherAuthorizationResult.Denied(PublisherAuthorizationError.NotPublisher);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (publisher.GameId != requestedGameId
|
||||||
|
|| publisher.EnvironmentId != requestedEnvironmentId)
|
||||||
|
{
|
||||||
|
return PublisherAuthorizationResult.Denied(PublisherAuthorizationError.ScopeMismatch);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!policies.TryGet(publisher.GameId, publisher.EnvironmentId, out GamePolicy? policy)
|
||||||
|
|| policy is null)
|
||||||
|
{
|
||||||
|
return PublisherAuthorizationResult.Denied(PublisherAuthorizationError.PolicyNotFound);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!policy.AllowsPublisherTrust(publisher.TrustMode))
|
||||||
|
{
|
||||||
|
return PublisherAuthorizationResult.Denied(PublisherAuthorizationError.TrustModeNotAllowed);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!publisher.AllowedRegions.Contains(requestedRegionId)
|
||||||
|
|| !policy.AllowsRegion(requestedRegionId))
|
||||||
|
{
|
||||||
|
return PublisherAuthorizationResult.Denied(PublisherAuthorizationError.RegionNotAllowed);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!policy.AllowsProtocol(requestedProtocolVersion))
|
||||||
|
{
|
||||||
|
return PublisherAuthorizationResult.Denied(PublisherAuthorizationError.ProtocolNotAllowed);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (publisher.TrustMode == PublisherTrustMode.AnonymousUnlisted
|
||||||
|
&& requestedVisibility != ListingVisibility.Unlisted)
|
||||||
|
{
|
||||||
|
return PublisherAuthorizationResult.Denied(
|
||||||
|
PublisherAuthorizationError.AnonymousMustBeUnlisted);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!policy.AllowsVisibility(requestedVisibility))
|
||||||
|
{
|
||||||
|
return PublisherAuthorizationResult.Denied(PublisherAuthorizationError.VisibilityNotAllowed);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!policy.AllowsMetadata(requestedMetadata))
|
||||||
|
{
|
||||||
|
return PublisherAuthorizationResult.Denied(PublisherAuthorizationError.MetadataNotAllowed);
|
||||||
|
}
|
||||||
|
|
||||||
|
return PublisherAuthorizationResult.Allowed(new AuthorizedPublisherContext(
|
||||||
|
publisher.Subject,
|
||||||
|
publisher.GameId,
|
||||||
|
publisher.EnvironmentId,
|
||||||
|
requestedRegionId,
|
||||||
|
requestedProtocolVersion,
|
||||||
|
requestedVisibility,
|
||||||
|
publisher.TrustMode,
|
||||||
|
policy));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record AuthorizedPublisherContext(
|
||||||
|
string Subject,
|
||||||
|
GameId GameId,
|
||||||
|
EnvironmentId EnvironmentId,
|
||||||
|
RegionId RegionId,
|
||||||
|
uint ProtocolVersion,
|
||||||
|
ListingVisibility Visibility,
|
||||||
|
PublisherTrustMode TrustMode,
|
||||||
|
GamePolicy Policy);
|
||||||
|
|
||||||
|
internal readonly record struct PublisherAuthorizationResult(
|
||||||
|
bool IsAllowed,
|
||||||
|
PublisherAuthorizationError Error,
|
||||||
|
AuthorizedPublisherContext? Context)
|
||||||
|
{
|
||||||
|
public static PublisherAuthorizationResult Allowed(AuthorizedPublisherContext context) =>
|
||||||
|
new(true, PublisherAuthorizationError.None, context);
|
||||||
|
|
||||||
|
public static PublisherAuthorizationResult Denied(PublisherAuthorizationError error) =>
|
||||||
|
new(false, error, null);
|
||||||
|
}
|
||||||
|
|
||||||
|
internal enum PublisherAuthorizationError
|
||||||
|
{
|
||||||
|
None = 0,
|
||||||
|
NotPublisher = 1,
|
||||||
|
ScopeMismatch = 2,
|
||||||
|
PolicyNotFound = 3,
|
||||||
|
TrustModeNotAllowed = 4,
|
||||||
|
RegionNotAllowed = 5,
|
||||||
|
ProtocolNotAllowed = 6,
|
||||||
|
AnonymousMustBeUnlisted = 7,
|
||||||
|
VisibilityNotAllowed = 8,
|
||||||
|
MetadataNotAllowed = 9,
|
||||||
|
PrincipalExpired = 10,
|
||||||
|
}
|
||||||
@@ -0,0 +1,144 @@
|
|||||||
|
using System.Security.Cryptography;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
internal interface ISecretProvider
|
||||||
|
{
|
||||||
|
bool TryGetSecret(string reference, out SecretMaterial? secret);
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class SecretMaterial : IDisposable
|
||||||
|
{
|
||||||
|
private byte[]? _bytes;
|
||||||
|
|
||||||
|
public SecretMaterial(ReadOnlySpan<byte> bytes)
|
||||||
|
{
|
||||||
|
if (bytes.Length == 0)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("Secret material cannot be empty.", nameof(bytes));
|
||||||
|
}
|
||||||
|
|
||||||
|
_bytes = bytes.ToArray();
|
||||||
|
}
|
||||||
|
|
||||||
|
public int Length => _bytes?.Length ?? 0;
|
||||||
|
|
||||||
|
public byte[] CopyBytes() => _bytes?.ToArray()
|
||||||
|
?? throw new ObjectDisposedException(nameof(SecretMaterial));
|
||||||
|
|
||||||
|
public void Dispose()
|
||||||
|
{
|
||||||
|
if (_bytes is not null)
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(_bytes);
|
||||||
|
_bytes = null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public override string ToString() => "[REDACTED SECRET]";
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class EnvironmentSecretProvider : ISecretProvider
|
||||||
|
{
|
||||||
|
private const string Prefix = "env:";
|
||||||
|
|
||||||
|
public bool TryGetSecret(string reference, out SecretMaterial? secret)
|
||||||
|
{
|
||||||
|
secret = null;
|
||||||
|
if (!reference.StartsWith(Prefix, StringComparison.Ordinal)
|
||||||
|
|| reference.Length == Prefix.Length)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
string? encoded = Environment.GetEnvironmentVariable(reference[Prefix.Length..]);
|
||||||
|
if (string.IsNullOrEmpty(encoded))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
try
|
||||||
|
{
|
||||||
|
byte[] bytes = Convert.FromBase64String(encoded);
|
||||||
|
secret = new SecretMaterial(bytes);
|
||||||
|
CryptographicOperations.ZeroMemory(bytes);
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
catch (FormatException)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class EphemeralDevelopmentSecretProvider : ISecretProvider, IDisposable
|
||||||
|
{
|
||||||
|
private const string Prefix = "development:ephemeral/";
|
||||||
|
private readonly Dictionary<string, byte[]> _secrets = new(StringComparer.Ordinal);
|
||||||
|
|
||||||
|
public bool TryGetSecret(string reference, out SecretMaterial? secret)
|
||||||
|
{
|
||||||
|
secret = null;
|
||||||
|
if (!reference.StartsWith(Prefix, StringComparison.Ordinal)
|
||||||
|
|| reference.Length == Prefix.Length)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!_secrets.TryGetValue(reference, out byte[]? bytes))
|
||||||
|
{
|
||||||
|
bytes = RandomNumberGenerator.GetBytes(32);
|
||||||
|
_secrets.Add(reference, bytes);
|
||||||
|
}
|
||||||
|
|
||||||
|
secret = new SecretMaterial(bytes);
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
public void Dispose()
|
||||||
|
{
|
||||||
|
foreach (byte[] bytes in _secrets.Values)
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(bytes);
|
||||||
|
}
|
||||||
|
|
||||||
|
_secrets.Clear();
|
||||||
|
}
|
||||||
|
|
||||||
|
public override string ToString() => "[EphemeralDevelopmentSecretProvider]";
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class DictionarySecretProvider : ISecretProvider, IDisposable
|
||||||
|
{
|
||||||
|
private readonly Dictionary<string, byte[]> _secrets;
|
||||||
|
|
||||||
|
public DictionarySecretProvider(IReadOnlyDictionary<string, byte[]> secrets) =>
|
||||||
|
_secrets = secrets.ToDictionary(
|
||||||
|
static item => item.Key,
|
||||||
|
static item => item.Value.ToArray(),
|
||||||
|
StringComparer.Ordinal);
|
||||||
|
|
||||||
|
public bool TryGetSecret(string reference, out SecretMaterial? secret)
|
||||||
|
{
|
||||||
|
if (_secrets.TryGetValue(reference, out byte[]? bytes))
|
||||||
|
{
|
||||||
|
secret = new SecretMaterial(bytes);
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
secret = null;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
public void Dispose()
|
||||||
|
{
|
||||||
|
foreach (byte[] bytes in _secrets.Values)
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(bytes);
|
||||||
|
}
|
||||||
|
|
||||||
|
_secrets.Clear();
|
||||||
|
}
|
||||||
|
|
||||||
|
public override string ToString() => "[DictionarySecretProvider: REDACTED]";
|
||||||
|
}
|
||||||
@@ -0,0 +1,275 @@
|
|||||||
|
using System.Collections.Concurrent;
|
||||||
|
using System.Collections.Frozen;
|
||||||
|
using System.Security.Cryptography;
|
||||||
|
using System.Text;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
internal sealed class SigningKeyRing : IDisposable
|
||||||
|
{
|
||||||
|
private readonly Dictionary<string, SigningKey> _keys;
|
||||||
|
private readonly ConcurrentDictionary<string, byte> _runtimeRevocations =
|
||||||
|
new(StringComparer.Ordinal);
|
||||||
|
|
||||||
|
private SigningKeyRing(Dictionary<string, SigningKey> keys) => _keys = keys;
|
||||||
|
|
||||||
|
public bool HasKeys => _keys.Count > 0;
|
||||||
|
|
||||||
|
public static SigningKeyRing Create(
|
||||||
|
IEnumerable<SigningKeyOptions> options,
|
||||||
|
ISecretProvider secretProvider)
|
||||||
|
{
|
||||||
|
SigningKeyOptions[] configuredKeys = options.ToArray();
|
||||||
|
if (configuredKeys.Length > ProvisioningLimits.MaxSigningKeys)
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"At most {ProvisioningLimits.MaxSigningKeys} signing keys may be configured.");
|
||||||
|
}
|
||||||
|
|
||||||
|
Dictionary<string, SigningKey> keys = new(StringComparer.Ordinal);
|
||||||
|
try
|
||||||
|
{
|
||||||
|
foreach (SigningKeyOptions keyOptions in configuredKeys)
|
||||||
|
{
|
||||||
|
Validate(keyOptions);
|
||||||
|
if (keys.ContainsKey(keyOptions.KeyId))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Duplicate signing key ID '{keyOptions.KeyId}'.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (keyOptions.Revoked)
|
||||||
|
{
|
||||||
|
keys.Add(keyOptions.KeyId, new SigningKey(keyOptions, null));
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!secretProvider.TryGetSecret(
|
||||||
|
keyOptions.SecretReference,
|
||||||
|
out SecretMaterial? material)
|
||||||
|
|| material is null)
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Signing key '{keyOptions.KeyId}' has no available key material.");
|
||||||
|
}
|
||||||
|
|
||||||
|
using (material)
|
||||||
|
{
|
||||||
|
if (material.Length < 32)
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Signing key '{keyOptions.KeyId}' must contain at least 32 bytes.");
|
||||||
|
}
|
||||||
|
|
||||||
|
keys.Add(keyOptions.KeyId, new SigningKey(keyOptions, material.CopyBytes()));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return new SigningKeyRing(keys);
|
||||||
|
}
|
||||||
|
catch
|
||||||
|
{
|
||||||
|
foreach (SigningKey key in keys.Values)
|
||||||
|
{
|
||||||
|
key.Dispose();
|
||||||
|
}
|
||||||
|
|
||||||
|
throw;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool HasActiveSigningKey(DateTimeOffset now) => _keys.Values.Any(key =>
|
||||||
|
!IsRevoked(key)
|
||||||
|
&& key.NotBefore <= now
|
||||||
|
&& now < key.SignUntil);
|
||||||
|
|
||||||
|
public bool HasActiveSigningKey(
|
||||||
|
DateTimeOffset now,
|
||||||
|
PrincipalCredentialKind kind,
|
||||||
|
string? gameId,
|
||||||
|
string? environmentId) => _keys.Values.Any(key =>
|
||||||
|
!IsRevoked(key)
|
||||||
|
&& key.NotBefore <= now
|
||||||
|
&& now < key.SignUntil
|
||||||
|
&& key.Authorizes(kind, gameId, environmentId));
|
||||||
|
|
||||||
|
public bool TryGetSigningKey(
|
||||||
|
DateTimeOffset now,
|
||||||
|
PrincipalCredentialKind kind,
|
||||||
|
string? gameId,
|
||||||
|
string? environmentId,
|
||||||
|
out SigningKey? signingKey)
|
||||||
|
{
|
||||||
|
signingKey = _keys.Values
|
||||||
|
.Where(key => !IsRevoked(key)
|
||||||
|
&& key.NotBefore <= now
|
||||||
|
&& now < key.SignUntil
|
||||||
|
&& key.Authorizes(kind, gameId, environmentId))
|
||||||
|
.OrderByDescending(static key => key.NotBefore)
|
||||||
|
.ThenByDescending(static key => key.KeyId, StringComparer.Ordinal)
|
||||||
|
.FirstOrDefault();
|
||||||
|
return signingKey is not null;
|
||||||
|
}
|
||||||
|
|
||||||
|
public VerificationKeyLookup FindVerificationKey(
|
||||||
|
string keyId,
|
||||||
|
DateTimeOffset now,
|
||||||
|
out SigningKey? signingKey)
|
||||||
|
{
|
||||||
|
signingKey = null;
|
||||||
|
if (!_keys.TryGetValue(keyId, out SigningKey? candidate))
|
||||||
|
{
|
||||||
|
return VerificationKeyLookup.Unknown;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (IsRevoked(candidate))
|
||||||
|
{
|
||||||
|
return VerificationKeyLookup.Revoked;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (now < candidate.NotBefore)
|
||||||
|
{
|
||||||
|
return VerificationKeyLookup.NotYetValid;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (now >= candidate.VerifyUntil)
|
||||||
|
{
|
||||||
|
return VerificationKeyLookup.Retired;
|
||||||
|
}
|
||||||
|
|
||||||
|
signingKey = candidate;
|
||||||
|
return VerificationKeyLookup.Available;
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool Revoke(string keyId) =>
|
||||||
|
_keys.ContainsKey(keyId) && _runtimeRevocations.TryAdd(keyId, 0);
|
||||||
|
|
||||||
|
public void Dispose()
|
||||||
|
{
|
||||||
|
foreach (SigningKey key in _keys.Values)
|
||||||
|
{
|
||||||
|
key.Dispose();
|
||||||
|
}
|
||||||
|
|
||||||
|
_keys.Clear();
|
||||||
|
_runtimeRevocations.Clear();
|
||||||
|
}
|
||||||
|
|
||||||
|
public override string ToString() => $"[SigningKeyRing: {_keys.Count} keys, material redacted]";
|
||||||
|
|
||||||
|
private bool IsRevoked(SigningKey key) =>
|
||||||
|
key.ConfiguredRevoked || _runtimeRevocations.ContainsKey(key.KeyId);
|
||||||
|
|
||||||
|
private static void Validate(SigningKeyOptions options)
|
||||||
|
{
|
||||||
|
if (string.IsNullOrEmpty(options.KeyId)
|
||||||
|
|| options.KeyId.Length > 64
|
||||||
|
|| options.KeyId.Any(static character =>
|
||||||
|
character is not (>= 'A' and <= 'Z')
|
||||||
|
and not (>= 'a' and <= 'z')
|
||||||
|
and not (>= '0' and <= '9')
|
||||||
|
and not '-'
|
||||||
|
and not '_'))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
"Signing key IDs must be 1–64 base64url characters.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (string.IsNullOrWhiteSpace(options.SecretReference)
|
||||||
|
|| options.NotBefore >= options.SignUntil
|
||||||
|
|| options.SignUntil > options.VerifyUntil)
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Signing key '{options.KeyId}' has an invalid secret reference or lifetime.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (options.CredentialKinds.Count == 0
|
||||||
|
|| options.CredentialKinds.Any(static kind => !Enum.IsDefined(kind))
|
||||||
|
|| options.CredentialKinds.Count != options.CredentialKinds.Distinct().Count())
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Signing key '{options.KeyId}' requires unique valid credential kinds.");
|
||||||
|
}
|
||||||
|
|
||||||
|
bool operatorKey = options.CredentialKinds.Contains(PrincipalCredentialKind.Operator);
|
||||||
|
bool hasPublisherKind = options.CredentialKinds.Any(static kind =>
|
||||||
|
kind is PrincipalCredentialKind.DedicatedPublisher
|
||||||
|
or PrincipalCredentialKind.PlayerHostGrant);
|
||||||
|
if (operatorKey
|
||||||
|
? options.CredentialKinds.Count != 1
|
||||||
|
|| options.GameId is not null
|
||||||
|
|| options.EnvironmentId is not null
|
||||||
|
: !hasPublisherKind
|
||||||
|
|| !GameId.TryParse(options.GameId, out _)
|
||||||
|
|| !EnvironmentId.TryParse(options.EnvironmentId, out _))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Signing key '{options.KeyId}' must be operator-only or bound to one game/environment.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class SigningKey : IDisposable
|
||||||
|
{
|
||||||
|
private byte[]? _material;
|
||||||
|
|
||||||
|
public SigningKey(SigningKeyOptions options, byte[]? material)
|
||||||
|
{
|
||||||
|
KeyId = options.KeyId;
|
||||||
|
NotBefore = options.NotBefore;
|
||||||
|
SignUntil = options.SignUntil;
|
||||||
|
VerifyUntil = options.VerifyUntil;
|
||||||
|
ConfiguredRevoked = options.Revoked;
|
||||||
|
CredentialKinds = options.CredentialKinds.ToFrozenSet();
|
||||||
|
GameId = options.GameId;
|
||||||
|
EnvironmentId = options.EnvironmentId;
|
||||||
|
_material = material;
|
||||||
|
}
|
||||||
|
|
||||||
|
public string KeyId { get; }
|
||||||
|
public DateTimeOffset NotBefore { get; }
|
||||||
|
public DateTimeOffset SignUntil { get; }
|
||||||
|
public DateTimeOffset VerifyUntil { get; }
|
||||||
|
public bool ConfiguredRevoked { get; }
|
||||||
|
public IReadOnlySet<PrincipalCredentialKind> CredentialKinds { get; }
|
||||||
|
public string? GameId { get; }
|
||||||
|
public string? EnvironmentId { get; }
|
||||||
|
|
||||||
|
public bool Authorizes(
|
||||||
|
PrincipalCredentialKind kind,
|
||||||
|
string? gameId,
|
||||||
|
string? environmentId) =>
|
||||||
|
CredentialKinds.Contains(kind)
|
||||||
|
&& (kind == PrincipalCredentialKind.Operator
|
||||||
|
? gameId is null && environmentId is null
|
||||||
|
: string.Equals(GameId, gameId, StringComparison.Ordinal)
|
||||||
|
&& string.Equals(EnvironmentId, environmentId, StringComparison.Ordinal));
|
||||||
|
|
||||||
|
public byte[] Sign(string input)
|
||||||
|
{
|
||||||
|
ObjectDisposedException.ThrowIf(_material is null, this);
|
||||||
|
|
||||||
|
return HMACSHA256.HashData(_material, Encoding.ASCII.GetBytes(input));
|
||||||
|
}
|
||||||
|
|
||||||
|
public void Dispose()
|
||||||
|
{
|
||||||
|
if (_material is not null)
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(_material);
|
||||||
|
_material = null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public override string ToString() => $"[SigningKey {KeyId}: material redacted]";
|
||||||
|
}
|
||||||
|
|
||||||
|
internal enum VerificationKeyLookup
|
||||||
|
{
|
||||||
|
Available = 0,
|
||||||
|
Unknown = 1,
|
||||||
|
Revoked = 2,
|
||||||
|
NotYetValid = 3,
|
||||||
|
Retired = 4,
|
||||||
|
}
|
||||||
@@ -0,0 +1,172 @@
|
|||||||
|
using System.Buffers.Binary;
|
||||||
|
using System.Security.Cryptography;
|
||||||
|
using System.Text;
|
||||||
|
using FinalFactory.Rendezvous.Server.State;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Sessions;
|
||||||
|
|
||||||
|
internal interface ISessionCapabilityService
|
||||||
|
{
|
||||||
|
string CreateDerivationSalt();
|
||||||
|
string DeriveCapability(
|
||||||
|
string purpose,
|
||||||
|
string ownerSubject,
|
||||||
|
string idempotencyKey,
|
||||||
|
string requestFingerprint,
|
||||||
|
string derivationSalt);
|
||||||
|
Guid DeriveGuid(
|
||||||
|
string purpose,
|
||||||
|
string ownerSubject,
|
||||||
|
string idempotencyKey,
|
||||||
|
string requestFingerprint,
|
||||||
|
string derivationSalt);
|
||||||
|
string DeriveOpaqueIdentifier(string purpose, string value);
|
||||||
|
bool TryFingerprint(string? capability, out SecretFingerprint fingerprint);
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class EphemeralCapabilityIssuer : ISessionCapabilityService, IDisposable
|
||||||
|
{
|
||||||
|
private readonly byte[] _key = RandomNumberGenerator.GetBytes(32);
|
||||||
|
private bool _disposed;
|
||||||
|
|
||||||
|
public string CreateDerivationSalt()
|
||||||
|
{
|
||||||
|
ObjectDisposedException.ThrowIf(_disposed, this);
|
||||||
|
byte[] salt = RandomNumberGenerator.GetBytes(32);
|
||||||
|
try
|
||||||
|
{
|
||||||
|
return Encode(salt);
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(salt);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public string DeriveCapability(
|
||||||
|
string purpose,
|
||||||
|
string ownerSubject,
|
||||||
|
string idempotencyKey,
|
||||||
|
string requestFingerprint,
|
||||||
|
string derivationSalt)
|
||||||
|
{
|
||||||
|
byte[] digest = Derive(
|
||||||
|
purpose,
|
||||||
|
ownerSubject,
|
||||||
|
idempotencyKey,
|
||||||
|
requestFingerprint,
|
||||||
|
derivationSalt);
|
||||||
|
try
|
||||||
|
{
|
||||||
|
return Encode(digest);
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(digest);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public Guid DeriveGuid(
|
||||||
|
string purpose,
|
||||||
|
string ownerSubject,
|
||||||
|
string idempotencyKey,
|
||||||
|
string requestFingerprint,
|
||||||
|
string derivationSalt)
|
||||||
|
{
|
||||||
|
byte[] digest = Derive(
|
||||||
|
purpose,
|
||||||
|
ownerSubject,
|
||||||
|
idempotencyKey,
|
||||||
|
requestFingerprint,
|
||||||
|
derivationSalt);
|
||||||
|
try
|
||||||
|
{
|
||||||
|
Span<byte> guidBytes = digest.AsSpan(0, 16);
|
||||||
|
guidBytes[7] = (byte)((guidBytes[7] & 0x0f) | 0x80);
|
||||||
|
guidBytes[8] = (byte)((guidBytes[8] & 0x3f) | 0x80);
|
||||||
|
return new Guid(guidBytes);
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(digest);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public string DeriveOpaqueIdentifier(string purpose, string value)
|
||||||
|
{
|
||||||
|
byte[] digest = Derive(purpose, value);
|
||||||
|
try
|
||||||
|
{
|
||||||
|
return Encode(digest);
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(digest);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool TryFingerprint(string? capability, out SecretFingerprint fingerprint)
|
||||||
|
{
|
||||||
|
fingerprint = default;
|
||||||
|
if (_disposed
|
||||||
|
|| capability is null
|
||||||
|
|| capability.Length != 43
|
||||||
|
|| capability.Any(static character =>
|
||||||
|
character is not (>= 'A' and <= 'Z')
|
||||||
|
and not (>= 'a' and <= 'z')
|
||||||
|
and not (>= '0' and <= '9')
|
||||||
|
and not '-'
|
||||||
|
and not '_'))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
byte[] digest = Derive("fingerprint", capability);
|
||||||
|
try
|
||||||
|
{
|
||||||
|
fingerprint = new SecretFingerprint(Encode(digest));
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(digest);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public void Dispose()
|
||||||
|
{
|
||||||
|
if (_disposed)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
_disposed = true;
|
||||||
|
CryptographicOperations.ZeroMemory(_key);
|
||||||
|
}
|
||||||
|
|
||||||
|
public override string ToString() => "[EphemeralCapabilityIssuer: key and capabilities redacted]";
|
||||||
|
|
||||||
|
private byte[] Derive(params string[] segments)
|
||||||
|
{
|
||||||
|
ObjectDisposedException.ThrowIf(_disposed, this);
|
||||||
|
using IncrementalHash hmac = IncrementalHash.CreateHMAC(HashAlgorithmName.SHA256, _key);
|
||||||
|
Span<byte> length = stackalloc byte[sizeof(int)];
|
||||||
|
foreach (string segment in segments)
|
||||||
|
{
|
||||||
|
ArgumentException.ThrowIfNullOrEmpty(segment);
|
||||||
|
byte[] encoded = Encoding.UTF8.GetBytes(segment);
|
||||||
|
BinaryPrimitives.WriteInt32BigEndian(length, encoded.Length);
|
||||||
|
hmac.AppendData(length);
|
||||||
|
hmac.AppendData(encoded);
|
||||||
|
CryptographicOperations.ZeroMemory(encoded);
|
||||||
|
}
|
||||||
|
|
||||||
|
return hmac.GetHashAndReset();
|
||||||
|
}
|
||||||
|
|
||||||
|
private static string Encode(ReadOnlySpan<byte> bytes) => Convert
|
||||||
|
.ToBase64String(bytes)
|
||||||
|
.TrimEnd('=')
|
||||||
|
.Replace('+', '-')
|
||||||
|
.Replace('/', '_');
|
||||||
|
}
|
||||||
@@ -0,0 +1,466 @@
|
|||||||
|
using System.Security.Cryptography;
|
||||||
|
using System.Text.Json;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
using FinalFactory.Rendezvous.Server.State;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Sessions;
|
||||||
|
|
||||||
|
internal sealed record SessionLeaseTiming(
|
||||||
|
int LeaseRenewAfterSeconds,
|
||||||
|
int HostPresenceRefreshAfterSeconds)
|
||||||
|
{
|
||||||
|
public static SessionLeaseTiming From(EphemeralStoreOptions options) => new(
|
||||||
|
Math.Max(1, (int)(options.LeaseLifetime.TotalSeconds / 2)),
|
||||||
|
Math.Max(1, (int)(options.PresenceLifetime.TotalSeconds / 2)));
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record SessionServiceResult<T>(RendezvousErrorCode Error, T? Value = default)
|
||||||
|
{
|
||||||
|
public bool Succeeded => Error == RendezvousErrorCode.None;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class SessionLeaseService(
|
||||||
|
PublisherAuthorizationService authorization,
|
||||||
|
IEphemeralRendezvousStore store,
|
||||||
|
ISessionCapabilityService capabilities,
|
||||||
|
SessionLeaseTiming timing,
|
||||||
|
IWallClock clock)
|
||||||
|
{
|
||||||
|
public SessionServiceResult<RegisterSessionResponse> Register(
|
||||||
|
AuthenticatedPrincipal principal,
|
||||||
|
RegisterSessionRequest request,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
ArgumentNullException.ThrowIfNull(principal);
|
||||||
|
ArgumentNullException.ThrowIfNull(request);
|
||||||
|
RendezvousErrorCode validation = ValidateRegistration(request);
|
||||||
|
if (validation != RendezvousErrorCode.None)
|
||||||
|
{
|
||||||
|
return new(validation);
|
||||||
|
}
|
||||||
|
|
||||||
|
PublisherAuthorizationResult authorized = authorization.Authorize(
|
||||||
|
principal,
|
||||||
|
request.GameId,
|
||||||
|
request.EnvironmentId,
|
||||||
|
request.RegionId,
|
||||||
|
request.ProtocolVersion,
|
||||||
|
request.Visibility,
|
||||||
|
request.Metadata,
|
||||||
|
clock.UtcNow);
|
||||||
|
if (!authorized.IsAllowed || authorized.Context is null)
|
||||||
|
{
|
||||||
|
return new(MapAuthorization(authorized.Error));
|
||||||
|
}
|
||||||
|
|
||||||
|
AuthorizedPublisherContext context = authorized.Context;
|
||||||
|
if (!IsFallbackAllowed(context.Policy, request.DedicatedFallback))
|
||||||
|
{
|
||||||
|
return new(RendezvousErrorCode.Forbidden);
|
||||||
|
}
|
||||||
|
|
||||||
|
string requestFingerprint = ComputeRegistrationFingerprint(request);
|
||||||
|
string derivationSalt = capabilities.CreateDerivationSalt();
|
||||||
|
string leaseToken = capabilities.DeriveCapability(
|
||||||
|
"lease-token",
|
||||||
|
context.Subject,
|
||||||
|
request.IdempotencyKey,
|
||||||
|
requestFingerprint,
|
||||||
|
derivationSalt);
|
||||||
|
string presenceCapability = capabilities.DeriveCapability(
|
||||||
|
"host-presence",
|
||||||
|
context.Subject,
|
||||||
|
request.IdempotencyKey,
|
||||||
|
requestFingerprint,
|
||||||
|
derivationSalt);
|
||||||
|
if (!capabilities.TryFingerprint(leaseToken, out SecretFingerprint leaseFingerprint)
|
||||||
|
|| !capabilities.TryFingerprint(presenceCapability, out SecretFingerprint presenceFingerprint))
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException("Derived session capabilities could not be fingerprinted.");
|
||||||
|
}
|
||||||
|
|
||||||
|
SessionListingId listingId = new(capabilities.DeriveGuid(
|
||||||
|
"listing-id",
|
||||||
|
context.Subject,
|
||||||
|
request.IdempotencyKey,
|
||||||
|
requestFingerprint,
|
||||||
|
derivationSalt));
|
||||||
|
LeaseId leaseId = new(capabilities.DeriveGuid(
|
||||||
|
"lease-id",
|
||||||
|
context.Subject,
|
||||||
|
request.IdempotencyKey,
|
||||||
|
requestFingerprint,
|
||||||
|
derivationSalt));
|
||||||
|
MediationHandle presenceHandle = new(capabilities.DeriveGuid(
|
||||||
|
"presence-handle",
|
||||||
|
context.Subject,
|
||||||
|
request.IdempotencyKey,
|
||||||
|
requestFingerprint,
|
||||||
|
derivationSalt));
|
||||||
|
int ownerLimit = context.TrustMode == PublisherTrustMode.AnonymousUnlisted
|
||||||
|
? context.Policy.MaxAnonymousListingsPerAddress
|
||||||
|
: context.Policy.MaxListingsPerPrincipal;
|
||||||
|
if (ownerLimit <= 0)
|
||||||
|
{
|
||||||
|
return new(RendezvousErrorCode.CapacityExceeded);
|
||||||
|
}
|
||||||
|
|
||||||
|
StoreResult<StoredListing> created = store.CreateListing(new(
|
||||||
|
request.IdempotencyKey,
|
||||||
|
requestFingerprint,
|
||||||
|
new ListingDefinition
|
||||||
|
{
|
||||||
|
ListingId = listingId,
|
||||||
|
LeaseId = leaseId,
|
||||||
|
Scope = new(context.GameId, context.EnvironmentId),
|
||||||
|
OwnerSubject = context.Subject,
|
||||||
|
RegionId = context.RegionId,
|
||||||
|
ProtocolVersion = context.ProtocolVersion,
|
||||||
|
BuildVersion = request.BuildVersion,
|
||||||
|
DisplayName = request.DisplayName,
|
||||||
|
Visibility = context.Visibility,
|
||||||
|
TrustMode = context.TrustMode,
|
||||||
|
CurrentPlayers = request.Capacity.CurrentPlayers,
|
||||||
|
MaximumPlayers = request.Capacity.MaximumPlayers,
|
||||||
|
Metadata = request.Metadata,
|
||||||
|
DedicatedFallback = request.DedicatedFallback,
|
||||||
|
LeaseFingerprint = leaseFingerprint,
|
||||||
|
HostPresenceHandle = presenceHandle,
|
||||||
|
HostPresenceFingerprint = presenceFingerprint,
|
||||||
|
CapabilityDerivationSalt = derivationSalt,
|
||||||
|
},
|
||||||
|
ownerLimit), cancellationToken);
|
||||||
|
if (!created.Succeeded || created.Value is null)
|
||||||
|
{
|
||||||
|
return new(created.Code.ToContractError());
|
||||||
|
}
|
||||||
|
|
||||||
|
ListingDefinition persisted = created.Value.Definition;
|
||||||
|
leaseToken = capabilities.DeriveCapability(
|
||||||
|
"lease-token",
|
||||||
|
context.Subject,
|
||||||
|
request.IdempotencyKey,
|
||||||
|
requestFingerprint,
|
||||||
|
persisted.CapabilityDerivationSalt);
|
||||||
|
presenceCapability = capabilities.DeriveCapability(
|
||||||
|
"host-presence",
|
||||||
|
context.Subject,
|
||||||
|
request.IdempotencyKey,
|
||||||
|
requestFingerprint,
|
||||||
|
persisted.CapabilityDerivationSalt);
|
||||||
|
|
||||||
|
return new(RendezvousErrorCode.None, new RegisterSessionResponse
|
||||||
|
{
|
||||||
|
ListingId = persisted.ListingId,
|
||||||
|
LeaseId = persisted.LeaseId,
|
||||||
|
LeaseToken = leaseToken,
|
||||||
|
HostPresenceHandle = persisted.HostPresenceHandle,
|
||||||
|
HostPresenceCapability = presenceCapability,
|
||||||
|
ExpiresAt = created.Value.LeaseExpiresAt,
|
||||||
|
LeaseRenewAfterSeconds = timing.LeaseRenewAfterSeconds,
|
||||||
|
HostPresenceRefreshAfterSeconds = timing.HostPresenceRefreshAfterSeconds,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public SessionServiceResult<RenewLeaseResponse> Renew(
|
||||||
|
AuthenticatedPrincipal principal,
|
||||||
|
SessionListingId listingId,
|
||||||
|
RenewLeaseRequest request,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
ArgumentNullException.ThrowIfNull(principal);
|
||||||
|
ArgumentNullException.ThrowIfNull(request);
|
||||||
|
RendezvousErrorCode validation = ValidateLeaseRequest(request.ContractVersion, request.LeaseToken);
|
||||||
|
if (validation != RendezvousErrorCode.None)
|
||||||
|
{
|
||||||
|
return new(validation);
|
||||||
|
}
|
||||||
|
|
||||||
|
RendezvousErrorCode lookup = GetAuthorizedListing(
|
||||||
|
principal,
|
||||||
|
listingId,
|
||||||
|
request.LeaseToken,
|
||||||
|
cancellationToken,
|
||||||
|
out StoredListing? listing);
|
||||||
|
if (lookup != RendezvousErrorCode.None)
|
||||||
|
{
|
||||||
|
return new(lookup);
|
||||||
|
}
|
||||||
|
|
||||||
|
StoredListing ownedListing = listing!;
|
||||||
|
PublisherAuthorizationResult authorized = AuthorizeExisting(
|
||||||
|
principal,
|
||||||
|
ownedListing,
|
||||||
|
ownedListing.Definition.Metadata);
|
||||||
|
if (!authorized.IsAllowed)
|
||||||
|
{
|
||||||
|
return new(MapAuthorization(authorized.Error));
|
||||||
|
}
|
||||||
|
|
||||||
|
capabilities.TryFingerprint(request.LeaseToken, out SecretFingerprint fingerprint);
|
||||||
|
StoreResult<StoredListing> renewed = store.RenewLease(new(
|
||||||
|
listingId,
|
||||||
|
ownedListing.Definition.LeaseId,
|
||||||
|
fingerprint,
|
||||||
|
ownedListing.Definition.OwnerSubject,
|
||||||
|
ownedListing.Version), cancellationToken);
|
||||||
|
return renewed.Succeeded && renewed.Value is not null
|
||||||
|
? new(RendezvousErrorCode.None, new RenewLeaseResponse
|
||||||
|
{
|
||||||
|
ExpiresAt = renewed.Value.LeaseExpiresAt,
|
||||||
|
RenewAfterSeconds = timing.LeaseRenewAfterSeconds,
|
||||||
|
})
|
||||||
|
: new(renewed.Code.ToContractError());
|
||||||
|
}
|
||||||
|
|
||||||
|
public SessionServiceResult<bool> Update(
|
||||||
|
AuthenticatedPrincipal principal,
|
||||||
|
SessionListingId listingId,
|
||||||
|
UpdateSessionRequest request,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
ArgumentNullException.ThrowIfNull(principal);
|
||||||
|
ArgumentNullException.ThrowIfNull(request);
|
||||||
|
RendezvousErrorCode validation = ValidateUpdate(request);
|
||||||
|
if (validation != RendezvousErrorCode.None)
|
||||||
|
{
|
||||||
|
return new(validation);
|
||||||
|
}
|
||||||
|
|
||||||
|
RendezvousErrorCode lookup = GetAuthorizedListing(
|
||||||
|
principal,
|
||||||
|
listingId,
|
||||||
|
request.LeaseToken,
|
||||||
|
cancellationToken,
|
||||||
|
out StoredListing? listing);
|
||||||
|
if (lookup != RendezvousErrorCode.None)
|
||||||
|
{
|
||||||
|
return new(lookup);
|
||||||
|
}
|
||||||
|
|
||||||
|
StoredListing ownedListing = listing!;
|
||||||
|
PublisherAuthorizationResult authorized = AuthorizeExisting(principal, ownedListing, request.Metadata);
|
||||||
|
if (!authorized.IsAllowed || authorized.Context is null)
|
||||||
|
{
|
||||||
|
return new(MapAuthorization(authorized.Error));
|
||||||
|
}
|
||||||
|
if (!IsFallbackAllowed(authorized.Context.Policy, request.DedicatedFallback))
|
||||||
|
{
|
||||||
|
return new(RendezvousErrorCode.Forbidden);
|
||||||
|
}
|
||||||
|
|
||||||
|
capabilities.TryFingerprint(request.LeaseToken, out SecretFingerprint fingerprint);
|
||||||
|
StoreResult<StoredListing> updated = store.UpdateListing(new(
|
||||||
|
listingId,
|
||||||
|
ownedListing.Definition.LeaseId,
|
||||||
|
fingerprint,
|
||||||
|
ownedListing.Definition.OwnerSubject,
|
||||||
|
request.BuildVersion,
|
||||||
|
request.DisplayName,
|
||||||
|
request.Capacity.CurrentPlayers,
|
||||||
|
request.Capacity.MaximumPlayers,
|
||||||
|
request.Metadata,
|
||||||
|
request.DedicatedFallback), cancellationToken);
|
||||||
|
return updated.Succeeded
|
||||||
|
? new(RendezvousErrorCode.None, true)
|
||||||
|
: new(updated.Code.ToContractError());
|
||||||
|
}
|
||||||
|
|
||||||
|
public SessionServiceResult<bool> Delete(
|
||||||
|
AuthenticatedPrincipal principal,
|
||||||
|
SessionListingId listingId,
|
||||||
|
DeleteSessionRequest request,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
ArgumentNullException.ThrowIfNull(principal);
|
||||||
|
ArgumentNullException.ThrowIfNull(request);
|
||||||
|
RendezvousErrorCode validation = ValidateLeaseRequest(request.ContractVersion, request.LeaseToken);
|
||||||
|
if (validation != RendezvousErrorCode.None)
|
||||||
|
{
|
||||||
|
return new(validation);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (principal is not IPublisherPrincipal publisher
|
||||||
|
|| !capabilities.TryFingerprint(request.LeaseToken, out SecretFingerprint fingerprint))
|
||||||
|
{
|
||||||
|
return new(RendezvousErrorCode.Forbidden);
|
||||||
|
}
|
||||||
|
|
||||||
|
StoreResult<StoredListing> found = store.GetListing(listingId, false, cancellationToken);
|
||||||
|
if (!found.Succeeded || found.Value is null)
|
||||||
|
{
|
||||||
|
return found.Code == StoreResultCode.ServiceUnavailable
|
||||||
|
? new(RendezvousErrorCode.ServiceUnavailable)
|
||||||
|
: new(RendezvousErrorCode.None, true);
|
||||||
|
}
|
||||||
|
|
||||||
|
StoreResult<bool> deleted = store.DeleteListing(new(
|
||||||
|
listingId,
|
||||||
|
found.Value.Definition.LeaseId,
|
||||||
|
fingerprint,
|
||||||
|
publisher.Subject), cancellationToken);
|
||||||
|
return deleted.Succeeded || deleted.Code == StoreResultCode.NotFound
|
||||||
|
? new(RendezvousErrorCode.None, true)
|
||||||
|
: new(deleted.Code.ToContractError());
|
||||||
|
}
|
||||||
|
|
||||||
|
private RendezvousErrorCode GetAuthorizedListing(
|
||||||
|
AuthenticatedPrincipal principal,
|
||||||
|
SessionListingId listingId,
|
||||||
|
string leaseToken,
|
||||||
|
CancellationToken cancellationToken,
|
||||||
|
out StoredListing? listing)
|
||||||
|
{
|
||||||
|
listing = null;
|
||||||
|
if (principal is not IPublisherPrincipal publisher)
|
||||||
|
{
|
||||||
|
return RendezvousErrorCode.Forbidden;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!capabilities.TryFingerprint(leaseToken, out SecretFingerprint fingerprint))
|
||||||
|
{
|
||||||
|
return RendezvousErrorCode.NotFound;
|
||||||
|
}
|
||||||
|
|
||||||
|
StoreResult<StoredListing> found = store.GetListing(listingId, false, cancellationToken);
|
||||||
|
if (!found.Succeeded || found.Value is null)
|
||||||
|
{
|
||||||
|
return found.Code.ToContractError();
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!string.Equals(found.Value.Definition.OwnerSubject, publisher.Subject, StringComparison.Ordinal)
|
||||||
|
|| found.Value.Definition.LeaseFingerprint != fingerprint)
|
||||||
|
{
|
||||||
|
return RendezvousErrorCode.NotFound;
|
||||||
|
}
|
||||||
|
|
||||||
|
listing = found.Value;
|
||||||
|
return RendezvousErrorCode.None;
|
||||||
|
}
|
||||||
|
|
||||||
|
private PublisherAuthorizationResult AuthorizeExisting(
|
||||||
|
AuthenticatedPrincipal principal,
|
||||||
|
StoredListing listing,
|
||||||
|
IReadOnlyDictionary<string, string> metadata) => authorization.Authorize(
|
||||||
|
principal,
|
||||||
|
listing.Definition.Scope.GameId,
|
||||||
|
listing.Definition.Scope.EnvironmentId,
|
||||||
|
listing.Definition.RegionId,
|
||||||
|
listing.Definition.ProtocolVersion,
|
||||||
|
listing.Definition.Visibility,
|
||||||
|
metadata,
|
||||||
|
clock.UtcNow);
|
||||||
|
|
||||||
|
private static bool IsFallbackAllowed(GamePolicy policy, NetworkEndpoint? fallback) =>
|
||||||
|
fallback is null || policy.FallbackPolicy == FallbackPolicyMode.DedicatedEndpointAllowed;
|
||||||
|
|
||||||
|
private static RendezvousErrorCode ValidateRegistration(RegisterSessionRequest request)
|
||||||
|
{
|
||||||
|
RendezvousErrorCode version = ContractValidation.ValidateContractVersion(request.ContractVersion);
|
||||||
|
if (version != RendezvousErrorCode.None)
|
||||||
|
{
|
||||||
|
return version;
|
||||||
|
}
|
||||||
|
|
||||||
|
return !ContractValidation.IsIdempotencyKeyValid(request.IdempotencyKey)
|
||||||
|
|| string.IsNullOrEmpty(request.GameId.Value)
|
||||||
|
|| string.IsNullOrEmpty(request.EnvironmentId.Value)
|
||||||
|
|| string.IsNullOrEmpty(request.RegionId.Value)
|
||||||
|
|| request.ProtocolVersion == 0
|
||||||
|
|| !ContractValidation.IsBuildVersionValid(request.BuildVersion)
|
||||||
|
|| !ContractValidation.IsDisplayNameValid(request.DisplayName)
|
||||||
|
|| !Enum.IsDefined(request.Visibility)
|
||||||
|
|| !ContractValidation.IsCapacityValid(request.Capacity)
|
||||||
|
|| !ContractValidation.IsMetadataValid(request.Metadata)
|
||||||
|
|| request.DedicatedFallback is not null
|
||||||
|
&& !ContractValidation.IsNetworkEndpointValid(request.DedicatedFallback)
|
||||||
|
? RendezvousErrorCode.InvalidRequest
|
||||||
|
: RendezvousErrorCode.None;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static RendezvousErrorCode ValidateUpdate(UpdateSessionRequest request)
|
||||||
|
{
|
||||||
|
RendezvousErrorCode lease = ValidateLeaseRequest(request.ContractVersion, request.LeaseToken);
|
||||||
|
if (lease != RendezvousErrorCode.None)
|
||||||
|
{
|
||||||
|
return lease;
|
||||||
|
}
|
||||||
|
|
||||||
|
return !ContractValidation.IsBuildVersionValid(request.BuildVersion)
|
||||||
|
|| !ContractValidation.IsDisplayNameValid(request.DisplayName)
|
||||||
|
|| !ContractValidation.IsCapacityValid(request.Capacity)
|
||||||
|
|| !ContractValidation.IsMetadataValid(request.Metadata)
|
||||||
|
|| request.DedicatedFallback is not null
|
||||||
|
&& !ContractValidation.IsNetworkEndpointValid(request.DedicatedFallback)
|
||||||
|
? RendezvousErrorCode.InvalidRequest
|
||||||
|
: RendezvousErrorCode.None;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static RendezvousErrorCode ValidateLeaseRequest(int contractVersion, string leaseToken)
|
||||||
|
{
|
||||||
|
RendezvousErrorCode version = ContractValidation.ValidateContractVersion(contractVersion);
|
||||||
|
if (version != RendezvousErrorCode.None)
|
||||||
|
{
|
||||||
|
return version;
|
||||||
|
}
|
||||||
|
|
||||||
|
return ContractValidation.IsOpaqueHttpCredentialValid(leaseToken)
|
||||||
|
? RendezvousErrorCode.None
|
||||||
|
: RendezvousErrorCode.InvalidRequest;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static RendezvousErrorCode MapAuthorization(PublisherAuthorizationError error) => error switch
|
||||||
|
{
|
||||||
|
PublisherAuthorizationError.PrincipalExpired => RendezvousErrorCode.AuthenticationRequired,
|
||||||
|
PublisherAuthorizationError.ProtocolNotAllowed => RendezvousErrorCode.IncompatibleProtocol,
|
||||||
|
PublisherAuthorizationError.RegionNotAllowed
|
||||||
|
or PublisherAuthorizationError.VisibilityNotAllowed
|
||||||
|
or PublisherAuthorizationError.AnonymousMustBeUnlisted
|
||||||
|
or PublisherAuthorizationError.MetadataNotAllowed => RendezvousErrorCode.InvalidRequest,
|
||||||
|
_ => RendezvousErrorCode.Forbidden,
|
||||||
|
};
|
||||||
|
|
||||||
|
private static string ComputeRegistrationFingerprint(RegisterSessionRequest request)
|
||||||
|
{
|
||||||
|
RegisterSessionRequest canonical = new()
|
||||||
|
{
|
||||||
|
ContractVersion = request.ContractVersion,
|
||||||
|
IdempotencyKey = request.IdempotencyKey,
|
||||||
|
GameId = request.GameId,
|
||||||
|
EnvironmentId = request.EnvironmentId,
|
||||||
|
RegionId = request.RegionId,
|
||||||
|
ProtocolVersion = request.ProtocolVersion,
|
||||||
|
BuildVersion = request.BuildVersion,
|
||||||
|
DisplayName = request.DisplayName,
|
||||||
|
Visibility = request.Visibility,
|
||||||
|
Capacity = new SessionCapacity
|
||||||
|
{
|
||||||
|
CurrentPlayers = request.Capacity.CurrentPlayers,
|
||||||
|
MaximumPlayers = request.Capacity.MaximumPlayers,
|
||||||
|
},
|
||||||
|
Metadata = request.Metadata
|
||||||
|
.OrderBy(static item => item.Key, StringComparer.Ordinal)
|
||||||
|
.ToDictionary(static item => item.Key, static item => item.Value, StringComparer.Ordinal),
|
||||||
|
DedicatedFallback = request.DedicatedFallback is null
|
||||||
|
? null
|
||||||
|
: new NetworkEndpoint
|
||||||
|
{
|
||||||
|
AddressFamily = request.DedicatedFallback.AddressFamily,
|
||||||
|
Address = request.DedicatedFallback.Address,
|
||||||
|
Port = request.DedicatedFallback.Port,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
byte[] encoded = JsonSerializer.SerializeToUtf8Bytes(canonical, ContractJson.Options);
|
||||||
|
byte[] digest = SHA256.HashData(encoded);
|
||||||
|
CryptographicOperations.ZeroMemory(encoded);
|
||||||
|
try
|
||||||
|
{
|
||||||
|
return Convert.ToBase64String(digest).TrimEnd('=').Replace('+', '-').Replace('/', '_');
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(digest);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,398 @@
|
|||||||
|
using System.Collections.Frozen;
|
||||||
|
using System.Diagnostics;
|
||||||
|
using System.Net;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.State;
|
||||||
|
|
||||||
|
internal interface IWallClock
|
||||||
|
{
|
||||||
|
DateTimeOffset UtcNow { get; }
|
||||||
|
}
|
||||||
|
|
||||||
|
internal interface IMonotonicClock
|
||||||
|
{
|
||||||
|
TimeSpan Elapsed { get; }
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class SystemRendezvousClock : IWallClock, IMonotonicClock
|
||||||
|
{
|
||||||
|
private readonly long _origin = Stopwatch.GetTimestamp();
|
||||||
|
|
||||||
|
public DateTimeOffset UtcNow => DateTimeOffset.UtcNow;
|
||||||
|
|
||||||
|
public TimeSpan Elapsed => Stopwatch.GetElapsedTime(_origin);
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record EphemeralStoreOptions
|
||||||
|
{
|
||||||
|
public int MaxListings { get; init; } = 25_000;
|
||||||
|
public int MaxPresenceBindings { get; init; } = 25_000;
|
||||||
|
public int MaxJoinAttempts { get; init; } = 10_000;
|
||||||
|
public int MaxOutcomeReports { get; init; } = 35_000;
|
||||||
|
public int MaxReplayEntries { get; init; } = 30_000;
|
||||||
|
public int MaxRevocations { get; init; } = 10_000;
|
||||||
|
public int MaxIdempotencyEntries { get; init; } = 35_000;
|
||||||
|
public TimeSpan LeaseLifetime { get; init; } = TimeSpan.FromSeconds(60);
|
||||||
|
public TimeSpan PresenceLifetime { get; init; } = TimeSpan.FromSeconds(20);
|
||||||
|
public TimeSpan JoinAttemptLifetime { get; init; } = TimeSpan.FromSeconds(30);
|
||||||
|
public TimeSpan ConnectionTicketLifetime { get; init; } = TimeSpan.FromSeconds(20);
|
||||||
|
public TimeSpan ReplayLifetime { get; init; } = TimeSpan.FromSeconds(30);
|
||||||
|
public TimeSpan IdempotencyLifetime { get; init; } = TimeSpan.FromMinutes(2);
|
||||||
|
public TimeSpan GracefulDrainLifetime { get; init; } = TimeSpan.FromSeconds(30);
|
||||||
|
|
||||||
|
public void Validate()
|
||||||
|
{
|
||||||
|
RequirePositive(MaxListings, nameof(MaxListings));
|
||||||
|
RequirePositive(MaxPresenceBindings, nameof(MaxPresenceBindings));
|
||||||
|
RequirePositive(MaxJoinAttempts, nameof(MaxJoinAttempts));
|
||||||
|
RequirePositive(MaxOutcomeReports, nameof(MaxOutcomeReports));
|
||||||
|
RequirePositive(MaxReplayEntries, nameof(MaxReplayEntries));
|
||||||
|
RequirePositive(MaxRevocations, nameof(MaxRevocations));
|
||||||
|
RequirePositive(MaxIdempotencyEntries, nameof(MaxIdempotencyEntries));
|
||||||
|
RequireDuration(LeaseLifetime, TimeSpan.FromSeconds(60), nameof(LeaseLifetime));
|
||||||
|
RequireDuration(PresenceLifetime, TimeSpan.FromSeconds(20), nameof(PresenceLifetime));
|
||||||
|
RequireDuration(JoinAttemptLifetime, TimeSpan.FromSeconds(30), nameof(JoinAttemptLifetime));
|
||||||
|
RequireDuration(ConnectionTicketLifetime, TimeSpan.FromSeconds(20), nameof(ConnectionTicketLifetime));
|
||||||
|
RequireDuration(ReplayLifetime, TimeSpan.FromSeconds(30), nameof(ReplayLifetime));
|
||||||
|
RequireDuration(IdempotencyLifetime, TimeSpan.FromMinutes(10), nameof(IdempotencyLifetime));
|
||||||
|
RequireDuration(GracefulDrainLifetime, TimeSpan.FromSeconds(30), nameof(GracefulDrainLifetime));
|
||||||
|
if (ConnectionTicketLifetime > JoinAttemptLifetime)
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(
|
||||||
|
nameof(ConnectionTicketLifetime),
|
||||||
|
"Connection tickets cannot outlive their join attempt.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (IdempotencyLifetime < LeaseLifetime || IdempotencyLifetime < JoinAttemptLifetime)
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(
|
||||||
|
nameof(IdempotencyLifetime),
|
||||||
|
"Idempotency retention must cover every idempotent resource lifetime.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void RequirePositive(int value, string name)
|
||||||
|
{
|
||||||
|
if (value <= 0)
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(name, "Store capacity must be positive.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void RequireDuration(TimeSpan value, TimeSpan maximum, string name)
|
||||||
|
{
|
||||||
|
if (value <= TimeSpan.Zero || value > maximum)
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(name, $"Duration must be positive and no greater than {maximum}.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
internal readonly record struct TenantScope(GameId GameId, EnvironmentId EnvironmentId);
|
||||||
|
|
||||||
|
internal readonly struct SecretFingerprint : IEquatable<SecretFingerprint>
|
||||||
|
{
|
||||||
|
private readonly string? _value;
|
||||||
|
|
||||||
|
public SecretFingerprint(string value)
|
||||||
|
{
|
||||||
|
if (string.IsNullOrWhiteSpace(value) || value.Length > 128)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("Secret fingerprints must contain 1-128 characters.", nameof(value));
|
||||||
|
}
|
||||||
|
|
||||||
|
_value = value;
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool IsValid => !string.IsNullOrWhiteSpace(_value) && _value.Length <= 128;
|
||||||
|
public bool Equals(SecretFingerprint other)
|
||||||
|
{
|
||||||
|
ReadOnlySpan<char> left = _value.AsSpan();
|
||||||
|
ReadOnlySpan<char> right = other._value.AsSpan();
|
||||||
|
if (left.Length != right.Length)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
int difference = 0;
|
||||||
|
for (int index = 0; index < left.Length; index++)
|
||||||
|
{
|
||||||
|
difference |= left[index] ^ right[index];
|
||||||
|
}
|
||||||
|
|
||||||
|
return difference == 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
public override bool Equals(object? obj) => obj is SecretFingerprint other && Equals(other);
|
||||||
|
public override int GetHashCode() => StringComparer.Ordinal.GetHashCode(_value ?? string.Empty);
|
||||||
|
public override string ToString() => "[REDACTED]";
|
||||||
|
public static bool operator ==(SecretFingerprint left, SecretFingerprint right) => left.Equals(right);
|
||||||
|
public static bool operator !=(SecretFingerprint left, SecretFingerprint right) => !left.Equals(right);
|
||||||
|
}
|
||||||
|
|
||||||
|
internal readonly record struct ObservedEndpoint
|
||||||
|
{
|
||||||
|
public ObservedEndpoint(AddressFamilyKind addressFamily, string address, int port)
|
||||||
|
{
|
||||||
|
if (!IPAddress.TryParse(address, out IPAddress? parsed)
|
||||||
|
|| (addressFamily == AddressFamilyKind.Ipv4 && parsed.AddressFamily != System.Net.Sockets.AddressFamily.InterNetwork)
|
||||||
|
|| (addressFamily == AddressFamilyKind.Ipv6 && parsed.AddressFamily != System.Net.Sockets.AddressFamily.InterNetworkV6))
|
||||||
|
{
|
||||||
|
throw new ArgumentException("The address must match the declared address family.", nameof(address));
|
||||||
|
}
|
||||||
|
|
||||||
|
if (port is < 1 or > 65_535)
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(nameof(port));
|
||||||
|
}
|
||||||
|
|
||||||
|
AddressFamily = addressFamily;
|
||||||
|
Address = parsed.ToString();
|
||||||
|
Port = port;
|
||||||
|
}
|
||||||
|
|
||||||
|
public AddressFamilyKind AddressFamily { get; }
|
||||||
|
public string Address { get; }
|
||||||
|
public int Port { get; }
|
||||||
|
public bool IsValid => !string.IsNullOrEmpty(Address)
|
||||||
|
&& Port is >= 1 and <= 65_535
|
||||||
|
&& AddressFamily is AddressFamilyKind.Ipv4 or AddressFamilyKind.Ipv6;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record ListingDefinition
|
||||||
|
{
|
||||||
|
public required SessionListingId ListingId { get; init; }
|
||||||
|
public required LeaseId LeaseId { get; init; }
|
||||||
|
public required TenantScope Scope { get; init; }
|
||||||
|
public required string OwnerSubject { get; init; }
|
||||||
|
public required RegionId RegionId { get; init; }
|
||||||
|
public required uint ProtocolVersion { get; init; }
|
||||||
|
public required string BuildVersion { get; init; }
|
||||||
|
public required string DisplayName { get; init; }
|
||||||
|
public required ListingVisibility Visibility { get; init; }
|
||||||
|
public required PublisherTrustMode TrustMode { get; init; }
|
||||||
|
public required int CurrentPlayers { get; init; }
|
||||||
|
public required int MaximumPlayers { get; init; }
|
||||||
|
public required IReadOnlyDictionary<string, string> Metadata { get; init; }
|
||||||
|
public NetworkEndpoint? DedicatedFallback { get; init; }
|
||||||
|
public required SecretFingerprint LeaseFingerprint { get; init; }
|
||||||
|
public required MediationHandle HostPresenceHandle { get; init; }
|
||||||
|
public required SecretFingerprint HostPresenceFingerprint { get; init; }
|
||||||
|
public required string CapabilityDerivationSalt { get; init; }
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record StoredListing
|
||||||
|
{
|
||||||
|
public required ListingDefinition Definition { get; init; }
|
||||||
|
public required DateTimeOffset LeaseExpiresAt { get; init; }
|
||||||
|
public required long Version { get; init; }
|
||||||
|
public required bool HasFreshPresence { get; init; }
|
||||||
|
|
||||||
|
public static ListingDefinition Freeze(ListingDefinition source) => source with
|
||||||
|
{
|
||||||
|
Metadata = source.Metadata.ToFrozenDictionary(StringComparer.Ordinal),
|
||||||
|
DedicatedFallback = CopyEndpoint(source.DedicatedFallback),
|
||||||
|
};
|
||||||
|
|
||||||
|
internal static NetworkEndpoint? CopyEndpoint(NetworkEndpoint? endpoint) => endpoint is null
|
||||||
|
? null
|
||||||
|
: new NetworkEndpoint
|
||||||
|
{
|
||||||
|
AddressFamily = endpoint.AddressFamily,
|
||||||
|
Address = endpoint.Address,
|
||||||
|
Port = endpoint.Port,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record CreateListingCommand(
|
||||||
|
string IdempotencyKey,
|
||||||
|
string RequestFingerprint,
|
||||||
|
ListingDefinition Listing,
|
||||||
|
int OwnerListingLimit = int.MaxValue);
|
||||||
|
|
||||||
|
internal sealed record RenewLeaseCommand(
|
||||||
|
SessionListingId ListingId,
|
||||||
|
LeaseId LeaseId,
|
||||||
|
SecretFingerprint LeaseFingerprint,
|
||||||
|
string OwnerSubject,
|
||||||
|
long ExpectedVersion);
|
||||||
|
|
||||||
|
internal sealed record UpdateListingCommand(
|
||||||
|
SessionListingId ListingId,
|
||||||
|
LeaseId LeaseId,
|
||||||
|
SecretFingerprint LeaseFingerprint,
|
||||||
|
string OwnerSubject,
|
||||||
|
string BuildVersion,
|
||||||
|
string DisplayName,
|
||||||
|
int CurrentPlayers,
|
||||||
|
int MaximumPlayers,
|
||||||
|
IReadOnlyDictionary<string, string> Metadata,
|
||||||
|
NetworkEndpoint? DedicatedFallback);
|
||||||
|
|
||||||
|
internal sealed record DeleteListingCommand(
|
||||||
|
SessionListingId ListingId,
|
||||||
|
LeaseId LeaseId,
|
||||||
|
SecretFingerprint LeaseFingerprint,
|
||||||
|
string OwnerSubject);
|
||||||
|
|
||||||
|
internal sealed record BindHostPresenceCommand(
|
||||||
|
MediationHandle Handle,
|
||||||
|
SecretFingerprint CapabilityFingerprint,
|
||||||
|
ObservedEndpoint PublicEndpoint,
|
||||||
|
ObservedEndpoint? LocalEndpoint);
|
||||||
|
|
||||||
|
internal sealed record VisibleListingQuery(
|
||||||
|
TenantScope Scope,
|
||||||
|
uint ProtocolVersion,
|
||||||
|
RegionId? RegionId,
|
||||||
|
int MaximumResults = ContractLimits.BrowserPageMaxItems,
|
||||||
|
SessionListingId? AfterListingId = null,
|
||||||
|
bool ExcludeFull = false);
|
||||||
|
|
||||||
|
internal enum AttemptPeerRole
|
||||||
|
{
|
||||||
|
Host = 1,
|
||||||
|
Client = 2,
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record CreateJoinAttemptCommand
|
||||||
|
{
|
||||||
|
public required string IdempotencyOwner { get; init; }
|
||||||
|
public required string IdempotencyKey { get; init; }
|
||||||
|
public required string RequestFingerprint { get; init; }
|
||||||
|
public required string ClientSubject { get; init; }
|
||||||
|
public required JoinAttemptId AttemptId { get; init; }
|
||||||
|
public required MediationHandle MediationHandle { get; init; }
|
||||||
|
public required TenantScope Scope { get; init; }
|
||||||
|
public required SessionListingId ListingId { get; init; }
|
||||||
|
public required uint ProtocolVersion { get; init; }
|
||||||
|
public required SecretFingerprint HostCapabilityFingerprint { get; init; }
|
||||||
|
public required SecretFingerprint ClientCapabilityFingerprint { get; init; }
|
||||||
|
public required SecretFingerprint ConnectionTicketFingerprint { get; init; }
|
||||||
|
public required string CapabilityDerivationSalt { get; init; }
|
||||||
|
public NetworkEndpoint? DedicatedFallback { get; init; }
|
||||||
|
public int ScopeAttemptLimit { get; init; } = int.MaxValue;
|
||||||
|
|
||||||
|
public override string ToString() => "[CreateJoinAttemptCommand: credentials redacted]";
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record AttemptEndpointBinding(
|
||||||
|
ObservedEndpoint PublicEndpoint,
|
||||||
|
ObservedEndpoint? LocalEndpoint);
|
||||||
|
|
||||||
|
internal sealed record StoredJoinAttempt
|
||||||
|
{
|
||||||
|
public required JoinAttemptId AttemptId { get; init; }
|
||||||
|
public required MediationHandle MediationHandle { get; init; }
|
||||||
|
public required TenantScope Scope { get; init; }
|
||||||
|
public required SessionListingId ListingId { get; init; }
|
||||||
|
public required string ClientSubject { get; init; }
|
||||||
|
public required uint ProtocolVersion { get; init; }
|
||||||
|
public required string IdempotencyKey { get; init; }
|
||||||
|
public required string RequestFingerprint { get; init; }
|
||||||
|
public required string CapabilityDerivationSalt { get; init; }
|
||||||
|
public required SecretFingerprint HostCapabilityFingerprint { get; init; }
|
||||||
|
public required SecretFingerprint ClientCapabilityFingerprint { get; init; }
|
||||||
|
public required SecretFingerprint ConnectionTicketFingerprint { get; init; }
|
||||||
|
public NetworkEndpoint? DedicatedFallback { get; init; }
|
||||||
|
public required DateTimeOffset ExpiresAt { get; init; }
|
||||||
|
public required DateTimeOffset ConnectionTicketExpiresAt { get; init; }
|
||||||
|
public AttemptEndpointBinding? HostEndpoint { get; init; }
|
||||||
|
public AttemptEndpointBinding? ClientEndpoint { get; init; }
|
||||||
|
public required bool IntroductionConsumed { get; init; }
|
||||||
|
public required bool ConnectionTicketConsumed { get; init; }
|
||||||
|
public required bool IsCancelled { get; init; }
|
||||||
|
|
||||||
|
public override string ToString() => $"[StoredJoinAttempt {AttemptId}; credentials redacted]";
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record HostJoinAttemptQuery(
|
||||||
|
SessionListingId ListingId,
|
||||||
|
SecretFingerprint LeaseFingerprint,
|
||||||
|
int MaximumResults,
|
||||||
|
JoinAttemptId? AfterAttemptId = null);
|
||||||
|
|
||||||
|
internal sealed record BindAttemptEndpointCommand(
|
||||||
|
MediationHandle Handle,
|
||||||
|
AttemptPeerRole Role,
|
||||||
|
SecretFingerprint CapabilityFingerprint,
|
||||||
|
ObservedEndpoint PublicEndpoint,
|
||||||
|
ObservedEndpoint? LocalEndpoint);
|
||||||
|
|
||||||
|
internal sealed record IntroductionEndpoints(
|
||||||
|
StoredJoinAttempt Attempt,
|
||||||
|
AttemptEndpointBinding Host,
|
||||||
|
AttemptEndpointBinding Client)
|
||||||
|
{
|
||||||
|
public JoinAttemptId AttemptId => Attempt.AttemptId;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record CancelJoinAttemptCommand(
|
||||||
|
JoinAttemptId AttemptId,
|
||||||
|
SecretFingerprint ClientCapabilityFingerprint);
|
||||||
|
|
||||||
|
internal sealed record ReportConnectionOutcomeCommand(
|
||||||
|
JoinAttemptId AttemptId,
|
||||||
|
SecretFingerprint ClientCapabilityFingerprint,
|
||||||
|
ConnectionOutcomeKind Outcome,
|
||||||
|
ConnectionElapsedBucket ElapsedBucket);
|
||||||
|
|
||||||
|
internal sealed record StoredConnectionOutcome(
|
||||||
|
ConnectionOutcomeKind Outcome,
|
||||||
|
ConnectionElapsedBucket ElapsedBucket);
|
||||||
|
|
||||||
|
internal sealed record ConsumeConnectionTicketCommand(
|
||||||
|
JoinAttemptId AttemptId,
|
||||||
|
SecretFingerprint ConnectionTicketFingerprint);
|
||||||
|
|
||||||
|
internal sealed record ReplayConsumption(
|
||||||
|
string Namespace,
|
||||||
|
string Key,
|
||||||
|
TimeSpan? Lifetime = null);
|
||||||
|
|
||||||
|
internal enum StoreResultCode
|
||||||
|
{
|
||||||
|
Success = 0,
|
||||||
|
NotFound = 1,
|
||||||
|
Expired = 2,
|
||||||
|
Revoked = 3,
|
||||||
|
Conflict = 4,
|
||||||
|
CapacityExceeded = 5,
|
||||||
|
Draining = 6,
|
||||||
|
ReplayRejected = 7,
|
||||||
|
ServiceUnavailable = 8,
|
||||||
|
StaleHost = 9,
|
||||||
|
IncompatibleProtocol = 10,
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record StoreResult<T>(StoreResultCode Code, T? Value = default, bool IsIdempotentReplay = false)
|
||||||
|
{
|
||||||
|
public bool Succeeded => Code == StoreResultCode.Success;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal interface IEphemeralRendezvousStore
|
||||||
|
{
|
||||||
|
Guid InstanceId { get; }
|
||||||
|
bool IsAvailable { get; }
|
||||||
|
bool IsDraining { get; }
|
||||||
|
|
||||||
|
StoreResult<StoredListing> CreateListing(CreateListingCommand command, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<StoredListing> RenewLease(RenewLeaseCommand command, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<StoredListing> UpdateListing(UpdateListingCommand command, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<bool> DeleteListing(DeleteListingCommand command, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<StoredListing> GetListing(SessionListingId listingId, bool requireFreshPresence, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<IReadOnlyList<StoredListing>> BrowseVisibleListings(VisibleListingQuery query, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<StoredListing> BindHostPresence(BindHostPresenceCommand command, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<StoredJoinAttempt> CreateJoinAttempt(CreateJoinAttemptCommand command, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<IReadOnlyList<StoredJoinAttempt>> BrowseHostJoinAttempts(HostJoinAttemptQuery query, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<bool> CancelJoinAttempt(CancelJoinAttemptCommand command, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<StoredConnectionOutcome> ReportConnectionOutcome(ReportConnectionOutcomeCommand command, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<StoredJoinAttempt> BindAttemptEndpoint(BindAttemptEndpointCommand command, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<IntroductionEndpoints> ConsumeIntroduction(MediationHandle handle, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<bool> ConsumeConnectionTicket(ConsumeConnectionTicketCommand command, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<bool> ConsumeReplay(ReplayConsumption consumption, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<bool> RevokeListing(SessionListingId listingId, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<int> RevokePrincipal(string subject, TimeSpan lifetime, CancellationToken cancellationToken = default);
|
||||||
|
void BeginDrain(CancellationToken cancellationToken = default);
|
||||||
|
}
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,22 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.State;
|
||||||
|
|
||||||
|
internal static class StoreResultMapping
|
||||||
|
{
|
||||||
|
public static RendezvousErrorCode ToContractError(this StoreResultCode code) => code switch
|
||||||
|
{
|
||||||
|
StoreResultCode.Success => RendezvousErrorCode.None,
|
||||||
|
StoreResultCode.NotFound => RendezvousErrorCode.NotFound,
|
||||||
|
StoreResultCode.Expired => RendezvousErrorCode.Expired,
|
||||||
|
StoreResultCode.Revoked => RendezvousErrorCode.Forbidden,
|
||||||
|
StoreResultCode.Conflict => RendezvousErrorCode.Conflict,
|
||||||
|
StoreResultCode.CapacityExceeded => RendezvousErrorCode.CapacityExceeded,
|
||||||
|
StoreResultCode.ReplayRejected => RendezvousErrorCode.ReplayRejected,
|
||||||
|
StoreResultCode.StaleHost => RendezvousErrorCode.StaleHost,
|
||||||
|
StoreResultCode.IncompatibleProtocol => RendezvousErrorCode.IncompatibleProtocol,
|
||||||
|
StoreResultCode.Draining or StoreResultCode.ServiceUnavailable =>
|
||||||
|
RendezvousErrorCode.ServiceUnavailable,
|
||||||
|
_ => RendezvousErrorCode.InternalError,
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,73 @@
|
|||||||
|
using System.Buffers.Binary;
|
||||||
|
using System.Net;
|
||||||
|
using System.Text;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Transport;
|
||||||
|
|
||||||
|
internal static class LiteNetNatRequestCodec
|
||||||
|
{
|
||||||
|
private const byte NatMessageProperty = 17;
|
||||||
|
private const int TypeIdentifierLength = 8;
|
||||||
|
private const int TokenLengthPrefix = NatPunchRequestTokenCodec.EncodedLength + 1;
|
||||||
|
// LiteNetLib 2.1.4's private NatIntroduceRequest type ID. The native socket
|
||||||
|
// integration test deliberately fails if a package upgrade changes this wire value.
|
||||||
|
private static ReadOnlySpan<byte> RequestTypeIdentifier =>
|
||||||
|
[0x88, 0xbe, 0x10, 0x26, 0xbf, 0xb1, 0x66, 0x9c];
|
||||||
|
|
||||||
|
public static bool TryDecode(
|
||||||
|
ReadOnlySpan<byte> datagram,
|
||||||
|
out IPEndPoint? claimedLocalEndpoint,
|
||||||
|
out string? token)
|
||||||
|
{
|
||||||
|
claimedLocalEndpoint = null;
|
||||||
|
token = null;
|
||||||
|
if (datagram.Length < 1 + TypeIdentifierLength + 1 + 4 + 2 + 2
|
||||||
|
+ NatPunchRequestTokenCodec.EncodedLength
|
||||||
|
|| datagram[0] != NatMessageProperty
|
||||||
|
|| !datagram.Slice(1, TypeIdentifierLength).SequenceEqual(RequestTypeIdentifier))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
int offset = 1 + TypeIdentifierLength;
|
||||||
|
int addressLength = datagram[offset++] switch
|
||||||
|
{
|
||||||
|
0 => 4,
|
||||||
|
1 => 16,
|
||||||
|
_ => 0,
|
||||||
|
};
|
||||||
|
int expectedLength = offset + addressLength + 2 + 2
|
||||||
|
+ NatPunchRequestTokenCodec.EncodedLength;
|
||||||
|
if (addressLength == 0 || datagram.Length != expectedLength)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
IPAddress localAddress = new(datagram.Slice(offset, addressLength));
|
||||||
|
offset += addressLength;
|
||||||
|
int localPort = BinaryPrimitives.ReadUInt16LittleEndian(datagram.Slice(offset, 2));
|
||||||
|
offset += 2;
|
||||||
|
int encodedTokenLength = BinaryPrimitives.ReadUInt16LittleEndian(datagram.Slice(offset, 2));
|
||||||
|
offset += 2;
|
||||||
|
if (localPort == 0 || encodedTokenLength != TokenLengthPrefix)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
ReadOnlySpan<byte> tokenBytes = datagram.Slice(
|
||||||
|
offset,
|
||||||
|
NatPunchRequestTokenCodec.EncodedLength);
|
||||||
|
for (int index = 0; index < tokenBytes.Length; index++)
|
||||||
|
{
|
||||||
|
if (tokenBytes[index] > 0x7f)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
claimedLocalEndpoint = new(localAddress, localPort);
|
||||||
|
token = Encoding.ASCII.GetString(tokenBytes);
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,397 @@
|
|||||||
|
using System.Net;
|
||||||
|
using System.Net.Sockets;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using FinalFactory.Rendezvous.Server.Abuse;
|
||||||
|
using FinalFactory.Rendezvous.Server.JoinAttempts;
|
||||||
|
using FinalFactory.Rendezvous.Server.Sessions;
|
||||||
|
using FinalFactory.Rendezvous.Server.State;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Transport;
|
||||||
|
|
||||||
|
internal interface INatIntroductionSink
|
||||||
|
{
|
||||||
|
void Introduce(NatIntroductionPlan plan);
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record NatIntroductionPlan(
|
||||||
|
IPEndPoint HostLocal,
|
||||||
|
IPEndPoint HostPublic,
|
||||||
|
IPEndPoint ClientLocal,
|
||||||
|
IPEndPoint ClientPublic,
|
||||||
|
string IntroductionToken)
|
||||||
|
{
|
||||||
|
public override string ToString() => "[NatIntroductionPlan: endpoints and ticket redacted]";
|
||||||
|
}
|
||||||
|
|
||||||
|
internal enum NatMediationResult
|
||||||
|
{
|
||||||
|
Dropped = 0,
|
||||||
|
HostPresenceAccepted = 1,
|
||||||
|
HostPresenceRejected = 2,
|
||||||
|
WaitingForPeer = 3,
|
||||||
|
Introduced = 4,
|
||||||
|
Duplicate = 5,
|
||||||
|
Rejected = 6,
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class NatMediationProcessor(
|
||||||
|
IEphemeralRendezvousStore store,
|
||||||
|
ISessionCapabilityService capabilities,
|
||||||
|
JoinAttemptService joinAttempts,
|
||||||
|
AbuseProtectionService? abuseProtection = null)
|
||||||
|
{
|
||||||
|
public NatMediationResult ProcessDatagram(
|
||||||
|
ReadOnlySpan<byte> encoded,
|
||||||
|
IPEndPoint observedPublicEndpoint,
|
||||||
|
INatIntroductionSink introductionSink,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
if (!TryAcceptIngress(observedPublicEndpoint, "frozen"))
|
||||||
|
{
|
||||||
|
return NatMediationResult.Dropped;
|
||||||
|
}
|
||||||
|
|
||||||
|
return ProcessDatagramAfterIngress(
|
||||||
|
encoded,
|
||||||
|
observedPublicEndpoint,
|
||||||
|
introductionSink,
|
||||||
|
cancellationToken);
|
||||||
|
}
|
||||||
|
|
||||||
|
internal bool TryAcceptIngress(IPEndPoint observedPublicEndpoint, string operation) =>
|
||||||
|
abuseProtection is null
|
||||||
|
|| abuseProtection.TryAcceptUdpIngress(observedPublicEndpoint.Address, operation);
|
||||||
|
|
||||||
|
internal NatMediationResult ProcessDatagramAfterIngress(
|
||||||
|
ReadOnlySpan<byte> encoded,
|
||||||
|
IPEndPoint observedPublicEndpoint,
|
||||||
|
INatIntroductionSink introductionSink,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
|
||||||
|
if (!RendezvousUdpCodec.TryDecode(encoded, out PresenceDatagram? datagram, out _)
|
||||||
|
|| datagram is null
|
||||||
|
|| datagram.Capability.Length != ContractLimits.DerivedCredentialCharacters
|
||||||
|
|| !IPAddress.TryParse(datagram.LocalAddress, out IPAddress? localAddress))
|
||||||
|
{
|
||||||
|
return NatMediationResult.Dropped;
|
||||||
|
}
|
||||||
|
|
||||||
|
IPEndPoint claimedLocalEndpoint = new(localAddress, datagram.LocalPort);
|
||||||
|
NatPunchPeerRole role = datagram.MessageType == UdpPresenceMessageType.ClientPresence
|
||||||
|
? NatPunchPeerRole.Client
|
||||||
|
: NatPunchPeerRole.HostPresence;
|
||||||
|
bool observedIpv6 = observedPublicEndpoint.AddressFamily == AddressFamily.InterNetworkV6
|
||||||
|
&& !observedPublicEndpoint.Address.IsIPv4MappedToIPv6;
|
||||||
|
if (role == NatPunchPeerRole.Client && observedIpv6)
|
||||||
|
{
|
||||||
|
return NatMediationResult.Dropped;
|
||||||
|
}
|
||||||
|
|
||||||
|
NatMediationResult result = ProcessRequestCore(
|
||||||
|
claimedLocalEndpoint,
|
||||||
|
observedPublicEndpoint,
|
||||||
|
NatPunchRequestTokenCodec.Encode(role, datagram.MediationHandle, datagram.Capability),
|
||||||
|
introductionSink,
|
||||||
|
cancellationToken);
|
||||||
|
if (role != NatPunchPeerRole.HostPresence
|
||||||
|
|| result != NatMediationResult.HostPresenceRejected
|
||||||
|
|| observedIpv6)
|
||||||
|
{
|
||||||
|
return result;
|
||||||
|
}
|
||||||
|
|
||||||
|
return ProcessRequestCore(
|
||||||
|
claimedLocalEndpoint,
|
||||||
|
observedPublicEndpoint,
|
||||||
|
NatPunchRequestTokenCodec.Encode(
|
||||||
|
NatPunchPeerRole.Host,
|
||||||
|
datagram.MediationHandle,
|
||||||
|
datagram.Capability),
|
||||||
|
introductionSink,
|
||||||
|
cancellationToken);
|
||||||
|
}
|
||||||
|
|
||||||
|
public NatMediationResult ProcessRequest(
|
||||||
|
IPEndPoint claimedLocalEndpoint,
|
||||||
|
IPEndPoint observedPublicEndpoint,
|
||||||
|
string token,
|
||||||
|
INatIntroductionSink introductionSink,
|
||||||
|
CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
ArgumentNullException.ThrowIfNull(claimedLocalEndpoint);
|
||||||
|
ArgumentNullException.ThrowIfNull(observedPublicEndpoint);
|
||||||
|
ArgumentNullException.ThrowIfNull(introductionSink);
|
||||||
|
|
||||||
|
if (!TryAcceptIngress(observedPublicEndpoint, "litenet-or-invalid"))
|
||||||
|
{
|
||||||
|
return NatMediationResult.Dropped;
|
||||||
|
}
|
||||||
|
|
||||||
|
return ProcessRequestAfterIngress(
|
||||||
|
claimedLocalEndpoint,
|
||||||
|
observedPublicEndpoint,
|
||||||
|
token,
|
||||||
|
introductionSink,
|
||||||
|
cancellationToken);
|
||||||
|
}
|
||||||
|
|
||||||
|
internal NatMediationResult ProcessRequestAfterIngress(
|
||||||
|
IPEndPoint claimedLocalEndpoint,
|
||||||
|
IPEndPoint observedPublicEndpoint,
|
||||||
|
string token,
|
||||||
|
INatIntroductionSink introductionSink,
|
||||||
|
CancellationToken cancellationToken = default) => ProcessRequestCore(
|
||||||
|
claimedLocalEndpoint,
|
||||||
|
observedPublicEndpoint,
|
||||||
|
token,
|
||||||
|
introductionSink,
|
||||||
|
cancellationToken);
|
||||||
|
|
||||||
|
private NatMediationResult ProcessRequestCore(
|
||||||
|
IPEndPoint claimedLocalEndpoint,
|
||||||
|
IPEndPoint observedPublicEndpoint,
|
||||||
|
string token,
|
||||||
|
INatIntroductionSink introductionSink,
|
||||||
|
CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
|
||||||
|
if (!NatPunchRequestTokenCodec.TryDecode(token, out NatPunchRequestToken? request)
|
||||||
|
|| request is null
|
||||||
|
|| !TryCreateObservedEndpoint(observedPublicEndpoint, out ObservedEndpoint publicEndpoint)
|
||||||
|
|| !capabilities.TryFingerprint(request.Capability, out SecretFingerprint fingerprint))
|
||||||
|
{
|
||||||
|
return NatMediationResult.Dropped;
|
||||||
|
}
|
||||||
|
|
||||||
|
string operation = request.Role.ToString();
|
||||||
|
if (abuseProtection is not null
|
||||||
|
&& !abuseProtection.TryAcceptUdpIdentity(
|
||||||
|
operation,
|
||||||
|
observedPublicEndpoint.Address,
|
||||||
|
request.Capability,
|
||||||
|
request.MediationHandle.ToString()))
|
||||||
|
{
|
||||||
|
return NatMediationResult.Dropped;
|
||||||
|
}
|
||||||
|
|
||||||
|
ObservedEndpoint? localEndpoint = TryCreatePrivateCandidate(
|
||||||
|
claimedLocalEndpoint,
|
||||||
|
publicEndpoint.AddressFamily,
|
||||||
|
out ObservedEndpoint candidate)
|
||||||
|
? candidate
|
||||||
|
: null;
|
||||||
|
|
||||||
|
if (request.Role == NatPunchPeerRole.HostPresence)
|
||||||
|
{
|
||||||
|
StoreResult<StoredListing> presence = store.BindHostPresence(new(
|
||||||
|
request.MediationHandle,
|
||||||
|
fingerprint,
|
||||||
|
publicEndpoint,
|
||||||
|
localEndpoint), cancellationToken);
|
||||||
|
return presence.Succeeded
|
||||||
|
? NatMediationResult.HostPresenceAccepted
|
||||||
|
: NatMediationResult.HostPresenceRejected;
|
||||||
|
}
|
||||||
|
|
||||||
|
AttemptPeerRole role = request.Role switch
|
||||||
|
{
|
||||||
|
NatPunchPeerRole.Host => AttemptPeerRole.Host,
|
||||||
|
NatPunchPeerRole.Client => AttemptPeerRole.Client,
|
||||||
|
_ => default,
|
||||||
|
};
|
||||||
|
if (role == default)
|
||||||
|
{
|
||||||
|
return NatMediationResult.Dropped;
|
||||||
|
}
|
||||||
|
|
||||||
|
StoreResult<StoredJoinAttempt> bound = store.BindAttemptEndpoint(new(
|
||||||
|
request.MediationHandle,
|
||||||
|
role,
|
||||||
|
fingerprint,
|
||||||
|
publicEndpoint,
|
||||||
|
localEndpoint), cancellationToken);
|
||||||
|
if (!bound.Succeeded || bound.Value is null)
|
||||||
|
{
|
||||||
|
return bound.Code == StoreResultCode.ReplayRejected
|
||||||
|
? NatMediationResult.Rejected
|
||||||
|
: NatMediationResult.Dropped;
|
||||||
|
}
|
||||||
|
|
||||||
|
StoredJoinAttempt attempt = bound.Value;
|
||||||
|
if (attempt.IntroductionConsumed)
|
||||||
|
{
|
||||||
|
return NatMediationResult.Duplicate;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (attempt.HostEndpoint is null || attempt.ClientEndpoint is null)
|
||||||
|
{
|
||||||
|
return NatMediationResult.WaitingForPeer;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (attempt.HostEndpoint.PublicEndpoint.AddressFamily
|
||||||
|
!= attempt.ClientEndpoint.PublicEndpoint.AddressFamily)
|
||||||
|
{
|
||||||
|
return NatMediationResult.Rejected;
|
||||||
|
}
|
||||||
|
|
||||||
|
StoreResult<IntroductionEndpoints> consumed = store.ConsumeIntroduction(
|
||||||
|
request.MediationHandle,
|
||||||
|
cancellationToken);
|
||||||
|
if (!consumed.Succeeded || consumed.Value is null)
|
||||||
|
{
|
||||||
|
return consumed.Code == StoreResultCode.ReplayRejected
|
||||||
|
? NatMediationResult.Duplicate
|
||||||
|
: NatMediationResult.Rejected;
|
||||||
|
}
|
||||||
|
|
||||||
|
JoinAttemptServiceResult<ConnectionTicketGrant> ticket = joinAttempts.IssueConnectionTicket(
|
||||||
|
consumed.Value.Attempt);
|
||||||
|
if (!ticket.Succeeded || ticket.Value is null)
|
||||||
|
{
|
||||||
|
return NatMediationResult.Rejected;
|
||||||
|
}
|
||||||
|
|
||||||
|
try
|
||||||
|
{
|
||||||
|
introductionSink.Introduce(CreatePlan(consumed.Value, ticket.Value));
|
||||||
|
return NatMediationResult.Introduced;
|
||||||
|
}
|
||||||
|
catch (Exception exception) when (exception is SocketException
|
||||||
|
or InvalidOperationException
|
||||||
|
or ArgumentException)
|
||||||
|
{
|
||||||
|
return NatMediationResult.Rejected;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static NatIntroductionPlan CreatePlan(
|
||||||
|
IntroductionEndpoints endpoints,
|
||||||
|
ConnectionTicketGrant ticket)
|
||||||
|
{
|
||||||
|
IPEndPoint hostPublic = ToIpEndpoint(endpoints.Host.PublicEndpoint);
|
||||||
|
IPEndPoint clientPublic = ToIpEndpoint(endpoints.Client.PublicEndpoint);
|
||||||
|
bool sameNat = hostPublic.Address.Equals(clientPublic.Address);
|
||||||
|
IPEndPoint hostLocal = sameNat && endpoints.Host.LocalEndpoint is { } hostCandidate
|
||||||
|
? ToIpEndpoint(hostCandidate)
|
||||||
|
: hostPublic;
|
||||||
|
IPEndPoint clientLocal = sameNat && endpoints.Client.LocalEndpoint is { } clientCandidate
|
||||||
|
? ToIpEndpoint(clientCandidate)
|
||||||
|
: clientPublic;
|
||||||
|
return new(
|
||||||
|
hostLocal,
|
||||||
|
hostPublic,
|
||||||
|
clientLocal,
|
||||||
|
clientPublic,
|
||||||
|
ticket.Ticket);
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool TryCreateObservedEndpoint(
|
||||||
|
IPEndPoint source,
|
||||||
|
out ObservedEndpoint endpoint)
|
||||||
|
{
|
||||||
|
endpoint = default;
|
||||||
|
if (source.Port is < 1 or > 65_535)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
IPAddress address = source.Address.IsIPv4MappedToIPv6
|
||||||
|
? source.Address.MapToIPv4()
|
||||||
|
: source.Address;
|
||||||
|
if (address.Equals(IPAddress.Any)
|
||||||
|
|| address.Equals(IPAddress.IPv6Any)
|
||||||
|
|| address.IsIPv6Multicast
|
||||||
|
|| IsIpv4MulticastOrBroadcast(address)
|
||||||
|
|| (address.AddressFamily == AddressFamily.InterNetworkV6
|
||||||
|
&& !IsGlobalIpv6(address)))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
AddressFamilyKind family = address.AddressFamily switch
|
||||||
|
{
|
||||||
|
AddressFamily.InterNetwork => AddressFamilyKind.Ipv4,
|
||||||
|
AddressFamily.InterNetworkV6 => AddressFamilyKind.Ipv6,
|
||||||
|
_ => default,
|
||||||
|
};
|
||||||
|
if (family == default)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
endpoint = new(family, address.ToString(), source.Port);
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool TryCreatePrivateCandidate(
|
||||||
|
IPEndPoint source,
|
||||||
|
AddressFamilyKind publicFamily,
|
||||||
|
out ObservedEndpoint endpoint)
|
||||||
|
{
|
||||||
|
endpoint = default;
|
||||||
|
if (source.Port is < 1 or > 65_535)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
IPAddress address = source.Address.IsIPv4MappedToIPv6
|
||||||
|
? source.Address.MapToIPv4()
|
||||||
|
: source.Address;
|
||||||
|
AddressFamilyKind family = address.AddressFamily switch
|
||||||
|
{
|
||||||
|
AddressFamily.InterNetwork => AddressFamilyKind.Ipv4,
|
||||||
|
AddressFamily.InterNetworkV6 => AddressFamilyKind.Ipv6,
|
||||||
|
_ => default,
|
||||||
|
};
|
||||||
|
if (family != publicFamily || !IsPrivateUnicast(address))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
endpoint = new(family, address.ToString(), source.Port);
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool IsPrivateUnicast(IPAddress address)
|
||||||
|
{
|
||||||
|
byte[] bytes = address.GetAddressBytes();
|
||||||
|
return address.AddressFamily switch
|
||||||
|
{
|
||||||
|
AddressFamily.InterNetwork => bytes[0] == 10
|
||||||
|
|| (bytes[0] == 172 && bytes[1] is >= 16 and <= 31)
|
||||||
|
|| (bytes[0] == 192 && bytes[1] == 168),
|
||||||
|
AddressFamily.InterNetworkV6 => (bytes[0] & 0xfe) == 0xfc,
|
||||||
|
_ => false,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool IsGlobalIpv6(IPAddress address) =>
|
||||||
|
!address.Equals(IPAddress.IPv6Loopback)
|
||||||
|
&& !address.Equals(IPAddress.IPv6Any)
|
||||||
|
&& !address.IsIPv6LinkLocal
|
||||||
|
&& !address.IsIPv6Multicast
|
||||||
|
&& !address.IsIPv6SiteLocal
|
||||||
|
&& !IsPrivateUnicast(address)
|
||||||
|
&& !IsDocumentationIpv6(address);
|
||||||
|
|
||||||
|
private static bool IsIpv4MulticastOrBroadcast(IPAddress address)
|
||||||
|
{
|
||||||
|
if (address.AddressFamily != AddressFamily.InterNetwork)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
byte[] bytes = address.GetAddressBytes();
|
||||||
|
return bytes[0] >= 224 || bytes.All(static value => value == byte.MaxValue);
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool IsDocumentationIpv6(IPAddress address)
|
||||||
|
{
|
||||||
|
byte[] bytes = address.GetAddressBytes();
|
||||||
|
return bytes[0] == 0x20 && bytes[1] == 0x01 && bytes[2] == 0x0d && bytes[3] == 0xb8;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static IPEndPoint ToIpEndpoint(ObservedEndpoint endpoint) =>
|
||||||
|
new(IPAddress.Parse(endpoint.Address), endpoint.Port);
|
||||||
|
}
|
||||||
@@ -18,9 +18,17 @@ public sealed class UdpMediatorOptions
|
|||||||
[Required]
|
[Required]
|
||||||
public string ListenAddress { get; set; } = "0.0.0.0";
|
public string ListenAddress { get; set; } = "0.0.0.0";
|
||||||
|
|
||||||
|
public string? Ipv6ListenAddress { get; set; }
|
||||||
|
|
||||||
/// <summary>
|
/// <summary>
|
||||||
/// Gets or sets the UDP port. Zero requests an ephemeral port for tests.
|
/// Gets or sets the UDP port. Zero requests an ephemeral port for tests.
|
||||||
/// </summary>
|
/// </summary>
|
||||||
[Range(0, 65_535)]
|
[Range(0, 65_535)]
|
||||||
public int Port { get; set; } = 9050;
|
public int Port { get; set; } = 9050;
|
||||||
|
|
||||||
|
[Range(1, 4_096)]
|
||||||
|
public int MaxDatagramsPerPoll { get; set; } = 256;
|
||||||
|
|
||||||
|
[Range(1, 100)]
|
||||||
|
public int PollIntervalMilliseconds { get; set; } = 2;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,104 +1,138 @@
|
|||||||
|
using System.Diagnostics;
|
||||||
using System.Net;
|
using System.Net;
|
||||||
using System.Net.Sockets;
|
using System.Net.Sockets;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using LiteNetLib;
|
||||||
|
using LiteNetLib.Layers;
|
||||||
using Microsoft.Extensions.Options;
|
using Microsoft.Extensions.Options;
|
||||||
|
|
||||||
namespace FinalFactory.Rendezvous.Server.Transport;
|
namespace FinalFactory.Rendezvous.Server.Transport;
|
||||||
|
|
||||||
/// <summary>
|
internal sealed partial class UdpMediatorService : BackgroundService
|
||||||
/// Owns the cancellable UDP socket used by the future NAT mediator.
|
|
||||||
/// </summary>
|
|
||||||
public sealed partial class UdpMediatorService : BackgroundService
|
|
||||||
{
|
{
|
||||||
private readonly ILogger<UdpMediatorService> _logger;
|
private readonly ILogger<UdpMediatorService> _logger;
|
||||||
private readonly UdpMediatorOptions _options;
|
private readonly UdpMediatorOptions _options;
|
||||||
private UdpClient? _udpClient;
|
private readonly NatMediationProcessor _processor;
|
||||||
|
private LiteNetManager? _manager;
|
||||||
|
private LiteNetIntroductionSink? _introductionSink;
|
||||||
|
|
||||||
/// <summary>
|
|
||||||
/// Initializes a new UDP mediator service.
|
|
||||||
/// </summary>
|
|
||||||
public UdpMediatorService(
|
public UdpMediatorService(
|
||||||
IOptions<UdpMediatorOptions> options,
|
IOptions<UdpMediatorOptions> options,
|
||||||
ILogger<UdpMediatorService> logger)
|
ILogger<UdpMediatorService> logger,
|
||||||
|
NatMediationProcessor processor)
|
||||||
{
|
{
|
||||||
_options = options.Value;
|
_options = options.Value;
|
||||||
_logger = logger;
|
_logger = logger;
|
||||||
|
_processor = processor;
|
||||||
}
|
}
|
||||||
|
|
||||||
/// <summary>
|
|
||||||
/// Gets the bound endpoint after startup completes.
|
|
||||||
/// </summary>
|
|
||||||
public IPEndPoint? LocalEndpoint { get; private set; }
|
public IPEndPoint? LocalEndpoint { get; private set; }
|
||||||
|
public IPEndPoint? LocalIpv6Endpoint { get; private set; }
|
||||||
|
|
||||||
/// <inheritdoc />
|
|
||||||
public override Task StartAsync(CancellationToken cancellationToken)
|
public override Task StartAsync(CancellationToken cancellationToken)
|
||||||
{
|
{
|
||||||
cancellationToken.ThrowIfCancellationRequested();
|
cancellationToken.ThrowIfCancellationRequested();
|
||||||
|
if (_manager is not null)
|
||||||
if (_udpClient is not null)
|
|
||||||
{
|
{
|
||||||
throw new InvalidOperationException("The UDP mediator is already running.");
|
throw new InvalidOperationException("The UDP mediator is already running.");
|
||||||
}
|
}
|
||||||
|
|
||||||
IPAddress listenAddress = IPAddress.Parse(_options.ListenAddress);
|
IPAddress listenAddress = IPAddress.Parse(_options.ListenAddress);
|
||||||
UdpClient udpClient = new(new IPEndPoint(listenAddress, _options.Port));
|
if (listenAddress.AddressFamily != AddressFamily.InterNetwork)
|
||||||
_udpClient = udpClient;
|
{
|
||||||
IPEndPoint localEndpoint =
|
throw new InvalidOperationException("The required UDP listen address must be IPv4.");
|
||||||
(IPEndPoint?)udpClient.Client.LocalEndPoint
|
}
|
||||||
?? throw new InvalidOperationException("The UDP socket did not expose its bound endpoint.");
|
|
||||||
LocalEndpoint = localEndpoint;
|
|
||||||
|
|
||||||
LogMediatorListening(_logger, localEndpoint.Address, localEndpoint.Port);
|
IPAddress? ipv6ListenAddress = string.IsNullOrWhiteSpace(_options.Ipv6ListenAddress)
|
||||||
|
? null
|
||||||
|
: IPAddress.Parse(_options.Ipv6ListenAddress);
|
||||||
|
if (ipv6ListenAddress is not null
|
||||||
|
&& ipv6ListenAddress.AddressFamily != AddressFamily.InterNetworkV6)
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException("The optional UDP IPv6 listen address must be IPv6.");
|
||||||
|
}
|
||||||
|
|
||||||
|
EventBasedLiteNetListener listener = new();
|
||||||
|
RendezvousPacketLayer packetLayer = new(_processor);
|
||||||
|
LiteNetManager manager = new(listener, packetLayer)
|
||||||
|
{
|
||||||
|
NatPunchEnabled = true,
|
||||||
|
IPv6Enabled = ipv6ListenAddress is not null,
|
||||||
|
UnsyncedEvents = true,
|
||||||
|
MaxPacketPerManualReceive = _options.MaxDatagramsPerPoll,
|
||||||
|
};
|
||||||
|
manager.NatPunchModule.UnsyncedEvents = true;
|
||||||
|
_introductionSink = new(manager.NatPunchModule);
|
||||||
|
packetLayer.Attach(_introductionSink);
|
||||||
|
|
||||||
|
if (!manager.StartInManualMode(
|
||||||
|
listenAddress,
|
||||||
|
ipv6ListenAddress ?? IPAddress.IPv6Any,
|
||||||
|
_options.Port))
|
||||||
|
{
|
||||||
|
_introductionSink = null;
|
||||||
|
manager.Stop();
|
||||||
|
throw new InvalidOperationException("The UDP mediator could not bind its LiteNetLib socket.");
|
||||||
|
}
|
||||||
|
|
||||||
|
_manager = manager;
|
||||||
|
LocalEndpoint = new(listenAddress, manager.LocalPort);
|
||||||
|
LocalIpv6Endpoint = ipv6ListenAddress is null
|
||||||
|
? null
|
||||||
|
: new(ipv6ListenAddress, manager.LocalPort);
|
||||||
|
LogMediatorListening(_logger, listenAddress, manager.LocalPort);
|
||||||
return base.StartAsync(cancellationToken);
|
return base.StartAsync(cancellationToken);
|
||||||
}
|
}
|
||||||
|
|
||||||
/// <inheritdoc />
|
|
||||||
public override async Task StopAsync(CancellationToken cancellationToken)
|
public override async Task StopAsync(CancellationToken cancellationToken)
|
||||||
{
|
{
|
||||||
await base.StopAsync(cancellationToken).ConfigureAwait(false);
|
await base.StopAsync(cancellationToken).ConfigureAwait(false);
|
||||||
_udpClient?.Dispose();
|
StopManager();
|
||||||
_udpClient = null;
|
|
||||||
LocalEndpoint = null;
|
|
||||||
LogMediatorStopped(_logger);
|
LogMediatorStopped(_logger);
|
||||||
}
|
}
|
||||||
|
|
||||||
/// <inheritdoc />
|
|
||||||
public override void Dispose()
|
public override void Dispose()
|
||||||
{
|
{
|
||||||
_udpClient?.Dispose();
|
StopManager();
|
||||||
_udpClient = null;
|
|
||||||
LocalEndpoint = null;
|
|
||||||
base.Dispose();
|
base.Dispose();
|
||||||
}
|
}
|
||||||
|
|
||||||
/// <inheritdoc />
|
|
||||||
protected override async Task ExecuteAsync(CancellationToken stoppingToken)
|
protected override async Task ExecuteAsync(CancellationToken stoppingToken)
|
||||||
{
|
{
|
||||||
UdpClient udpClient = _udpClient
|
LiteNetManager manager = _manager
|
||||||
?? throw new InvalidOperationException("The UDP mediator socket was not initialized.");
|
?? throw new InvalidOperationException("The UDP mediator socket was not initialized.");
|
||||||
|
long previous = Stopwatch.GetTimestamp();
|
||||||
try
|
try
|
||||||
{
|
{
|
||||||
while (!stoppingToken.IsCancellationRequested)
|
while (!stoppingToken.IsCancellationRequested)
|
||||||
{
|
{
|
||||||
_ = await udpClient.ReceiveAsync(stoppingToken).ConfigureAwait(false);
|
manager.PollEvents();
|
||||||
// Bootstrap deliberately emits no UDP response. Protocol handling lands in #11.
|
manager.NatPunchModule.PollEvents();
|
||||||
|
long current = Stopwatch.GetTimestamp();
|
||||||
|
manager.ManualUpdate((float)Stopwatch.GetElapsedTime(previous, current).TotalMilliseconds);
|
||||||
|
previous = current;
|
||||||
|
await Task.Delay(_options.PollIntervalMilliseconds, stoppingToken).ConfigureAwait(false);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
catch (OperationCanceledException) when (stoppingToken.IsCancellationRequested)
|
catch (OperationCanceledException) when (stoppingToken.IsCancellationRequested)
|
||||||
{
|
{
|
||||||
// Expected during normal shutdown.
|
|
||||||
}
|
|
||||||
catch (ObjectDisposedException) when (stoppingToken.IsCancellationRequested)
|
|
||||||
{
|
|
||||||
// Disposing the socket is the fallback that releases a blocked receive.
|
|
||||||
}
|
}
|
||||||
finally
|
finally
|
||||||
{
|
{
|
||||||
LocalEndpoint = null;
|
LocalEndpoint = null;
|
||||||
|
LocalIpv6Endpoint = null;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
private void StopManager()
|
||||||
|
{
|
||||||
|
LiteNetManager? manager = Interlocked.Exchange(ref _manager, null);
|
||||||
|
_introductionSink = null;
|
||||||
|
LocalEndpoint = null;
|
||||||
|
LocalIpv6Endpoint = null;
|
||||||
|
manager?.Stop();
|
||||||
|
}
|
||||||
|
|
||||||
[LoggerMessage(
|
[LoggerMessage(
|
||||||
EventId = 1,
|
EventId = 1,
|
||||||
Level = LogLevel.Information,
|
Level = LogLevel.Information,
|
||||||
@@ -113,4 +147,72 @@ public sealed partial class UdpMediatorService : BackgroundService
|
|||||||
Level = LogLevel.Information,
|
Level = LogLevel.Information,
|
||||||
Message = "UDP mediator stopped")]
|
Message = "UDP mediator stopped")]
|
||||||
private static partial void LogMediatorStopped(ILogger logger);
|
private static partial void LogMediatorStopped(ILogger logger);
|
||||||
|
|
||||||
|
private sealed class LiteNetIntroductionSink(NatPunchModule module) : INatIntroductionSink
|
||||||
|
{
|
||||||
|
public void Introduce(NatIntroductionPlan plan) => module.NatIntroduce(
|
||||||
|
plan.HostLocal,
|
||||||
|
plan.HostPublic,
|
||||||
|
plan.ClientLocal,
|
||||||
|
plan.ClientPublic,
|
||||||
|
plan.IntroductionToken);
|
||||||
|
}
|
||||||
|
|
||||||
|
private sealed class RendezvousPacketLayer(NatMediationProcessor processor) : PacketLayerBase(0)
|
||||||
|
{
|
||||||
|
private INatIntroductionSink? _sink;
|
||||||
|
|
||||||
|
public void Attach(INatIntroductionSink sink) => _sink = sink;
|
||||||
|
|
||||||
|
public override void ProcessInboundPacket(
|
||||||
|
ref IPEndPoint endPoint,
|
||||||
|
ref byte[] data,
|
||||||
|
ref int length)
|
||||||
|
{
|
||||||
|
bool isFrozenEnvelope = length >= 2
|
||||||
|
&& data[0] == RendezvousUdpCodec.MagicFirst
|
||||||
|
&& data[1] == RendezvousUdpCodec.MagicSecond;
|
||||||
|
if (!processor.TryAcceptIngress(
|
||||||
|
endPoint,
|
||||||
|
isFrozenEnvelope ? "frozen" : "litenet-or-invalid"))
|
||||||
|
{
|
||||||
|
Drop(ref length);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
INatIntroductionSink? sink = _sink;
|
||||||
|
if (isFrozenEnvelope)
|
||||||
|
{
|
||||||
|
if (sink is not null)
|
||||||
|
{
|
||||||
|
_ = processor.ProcessDatagramAfterIngress(
|
||||||
|
data.AsSpan(0, length), endPoint, sink);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
else if (sink is not null
|
||||||
|
&& LiteNetNatRequestCodec.TryDecode(
|
||||||
|
data.AsSpan(0, length),
|
||||||
|
out IPEndPoint? claimedLocalEndpoint,
|
||||||
|
out string? token)
|
||||||
|
&& claimedLocalEndpoint is not null
|
||||||
|
&& token is not null)
|
||||||
|
{
|
||||||
|
_ = processor.ProcessRequestAfterIngress(
|
||||||
|
claimedLocalEndpoint, endPoint, token, sink);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Every inbound packet is consumed here. NatPunchModule is used only for outbound introductions.
|
||||||
|
Drop(ref length);
|
||||||
|
}
|
||||||
|
|
||||||
|
public override void ProcessOutBoundPacket(
|
||||||
|
ref IPEndPoint endPoint,
|
||||||
|
ref byte[] data,
|
||||||
|
ref int offset,
|
||||||
|
ref int length)
|
||||||
|
{
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void Drop(ref int length) => length = 0;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,43 @@
|
|||||||
|
{
|
||||||
|
"Rendezvous": {
|
||||||
|
"Provisioning": {
|
||||||
|
"Issuer": "final-factory-rendezvous-development",
|
||||||
|
"Audience": "final-factory-rendezvous",
|
||||||
|
"ClockSkewSeconds": 30,
|
||||||
|
"SigningKeys": [
|
||||||
|
{
|
||||||
|
"KeyId": "development-ephemeral-1",
|
||||||
|
"SecretReference": "development:ephemeral/rendezvous-signing",
|
||||||
|
"CredentialKinds": ["DedicatedPublisher", "PlayerHostGrant"],
|
||||||
|
"GameId": "space-game",
|
||||||
|
"EnvironmentId": "development",
|
||||||
|
"NotBefore": "2025-01-01T00:00:00Z",
|
||||||
|
"SignUntil": "2035-01-01T00:00:00Z",
|
||||||
|
"VerifyUntil": "2035-01-02T00:00:00Z"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"Games": [
|
||||||
|
{
|
||||||
|
"GameId": "space-game",
|
||||||
|
"EnvironmentId": "development",
|
||||||
|
"Enabled": true,
|
||||||
|
"ProtocolVersions": [1],
|
||||||
|
"Regions": ["local"],
|
||||||
|
"VisibilityModes": ["Public", "Unlisted"],
|
||||||
|
"PublisherTrustModes": ["ManagedDedicated", "PlayerGrant", "AnonymousUnlisted"],
|
||||||
|
"MetadataValueMaxBytes": {
|
||||||
|
"map": 64,
|
||||||
|
"mode": 32
|
||||||
|
},
|
||||||
|
"RequiredMetadataKeys": [],
|
||||||
|
"MetadataMaxBytes": 512,
|
||||||
|
"MetadataMaxKeys": 2,
|
||||||
|
"MaxListingsPerPrincipal": 10,
|
||||||
|
"MaxAnonymousListingsPerAddress": 1,
|
||||||
|
"MaxActiveJoinAttempts": 100,
|
||||||
|
"FallbackPolicy": "Disabled"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -2,7 +2,41 @@
|
|||||||
"Rendezvous": {
|
"Rendezvous": {
|
||||||
"Udp": {
|
"Udp": {
|
||||||
"ListenAddress": "0.0.0.0",
|
"ListenAddress": "0.0.0.0",
|
||||||
"Port": 9050
|
"Port": 9050,
|
||||||
|
"MaxDatagramsPerPoll": 256,
|
||||||
|
"PollIntervalMilliseconds": 2
|
||||||
|
},
|
||||||
|
"AbuseProtection": {
|
||||||
|
"WindowSeconds": 1,
|
||||||
|
"MaxTrackedKeys": 100000,
|
||||||
|
"CriticalTrackedKeyReserve": 2048,
|
||||||
|
"UdpTrackedKeyLimit": 70000,
|
||||||
|
"TrustedProxyAddresses": [],
|
||||||
|
"HealthGlobalRequestsPerWindow": 1000,
|
||||||
|
"HealthGlobalConcurrency": 32,
|
||||||
|
"HealthIpPrefixRequestsPerWindow": 120,
|
||||||
|
"HealthIpPrefixConcurrency": 8,
|
||||||
|
"HttpGlobalRequestsPerWindow": 20000,
|
||||||
|
"HttpOptionalRequestsPerWindow": 18000,
|
||||||
|
"HttpIpPrefixRequestsPerWindow": 500,
|
||||||
|
"HttpOptionalIpPrefixRequestsPerWindow": 450,
|
||||||
|
"HttpOperationRequestsPerWindow": 5000,
|
||||||
|
"HttpTenantRequestsPerWindow": 2000,
|
||||||
|
"HttpPrincipalRequestsPerWindow": 500,
|
||||||
|
"HttpResourceRequestsPerWindow": 200,
|
||||||
|
"HttpGlobalConcurrency": 1024,
|
||||||
|
"HttpOptionalConcurrency": 768,
|
||||||
|
"HttpIpPrefixConcurrency": 64,
|
||||||
|
"HttpOptionalIpPrefixConcurrency": 48,
|
||||||
|
"HttpOperationConcurrency": 256,
|
||||||
|
"HttpTenantConcurrency": 256,
|
||||||
|
"HttpPrincipalConcurrency": 32,
|
||||||
|
"HttpResourceConcurrency": 16,
|
||||||
|
"UdpGlobalDatagramsPerWindow": 100000,
|
||||||
|
"UdpIpPrefixDatagramsPerWindow": 2000,
|
||||||
|
"UdpOperationDatagramsPerWindow": 50000,
|
||||||
|
"UdpCapabilityDatagramsPerWindow": 120,
|
||||||
|
"UdpResourceDatagramsPerWindow": 240
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"Logging": {
|
"Logging": {
|
||||||
|
|||||||
@@ -8,8 +8,29 @@
|
|||||||
"resolved": "2.1.4",
|
"resolved": "2.1.4",
|
||||||
"contentHash": "KWlxvMw3Urpqj9joD96LRiK+LC62pQNs/zkXRJc+rHnxgkGp+vV703xzDrxRmv+V1YhCFfIGzs5nrVWtREIlyA=="
|
"contentHash": "KWlxvMw3Urpqj9joD96LRiK+LC62pQNs/zkXRJc+rHnxgkGp+vV703xzDrxRmv+V1YhCFfIGzs5nrVWtREIlyA=="
|
||||||
},
|
},
|
||||||
|
"Microsoft.AspNetCore.OpenApi": {
|
||||||
|
"type": "Direct",
|
||||||
|
"requested": "[10.0.9, )",
|
||||||
|
"resolved": "10.0.9",
|
||||||
|
"contentHash": "1ihb8FO9cGgEK1/m3CTtT/SfnynwmiZib0W2pcDVj3KSWk/Sca4VOXEtaptKQc582zpFrzTFiwkGRCglt6H+WQ==",
|
||||||
|
"dependencies": {
|
||||||
|
"Microsoft.OpenApi": "2.0.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"Microsoft.Extensions.ApiDescription.Server": {
|
||||||
|
"type": "Direct",
|
||||||
|
"requested": "[10.0.9, )",
|
||||||
|
"resolved": "10.0.9",
|
||||||
|
"contentHash": "n1m7EAbCbHMGiTy++F+mLSan4MrZe0t00XEpJrkai6BFpB6lwEcirflI9FiMm4G4u55h/2RnWToYBDwS+MnN6g=="
|
||||||
|
},
|
||||||
"finalfactory.rendezvous.contracts": {
|
"finalfactory.rendezvous.contracts": {
|
||||||
"type": "Project"
|
"type": "Project"
|
||||||
|
},
|
||||||
|
"Microsoft.OpenApi": {
|
||||||
|
"type": "CentralTransitive",
|
||||||
|
"requested": "[2.7.5, )",
|
||||||
|
"resolved": "2.7.5",
|
||||||
|
"contentHash": "0FA67RSnRM4tcBKqiqVu/HPdZ9+QOKbmeRjxRUGTCjPU4C0bmUhd97Dso7Yild5P7nOV6GxJ2xrK0Kv/O9xp0w=="
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,130 @@
|
|||||||
|
using System.Security.Cryptography;
|
||||||
|
using System.Text;
|
||||||
|
using LiteNetLib;
|
||||||
|
using LiteNetLib.Utils;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.TestClient;
|
||||||
|
|
||||||
|
internal sealed class DirectEchoProtocol : IDisposable
|
||||||
|
{
|
||||||
|
private const string PingPrefix = "rv1-ping:";
|
||||||
|
private const string EchoPrefix = "rv1-echo:";
|
||||||
|
private const string AckPrefix = "rv1-ack:";
|
||||||
|
private const string DonePrefix = "rv1-done:";
|
||||||
|
private readonly EventBasedNetListener _events;
|
||||||
|
private readonly bool _host;
|
||||||
|
private readonly Dictionary<NetPeer, string> _hostNonces = [];
|
||||||
|
private readonly TaskCompletionSource<bool> _completed = new(
|
||||||
|
TaskCreationOptions.RunContinuationsAsynchronously);
|
||||||
|
private string? _nonce;
|
||||||
|
private bool _disposed;
|
||||||
|
|
||||||
|
internal DirectEchoProtocol(EventBasedNetListener events, bool host)
|
||||||
|
{
|
||||||
|
_events = events ?? throw new ArgumentNullException(nameof(events));
|
||||||
|
_host = host;
|
||||||
|
_events.NetworkReceiveEvent += OnReceive;
|
||||||
|
_events.PeerDisconnectedEvent += OnPeerDisconnected;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal Task Completion => _completed.Task;
|
||||||
|
internal int PendingHostExchangeCount => _hostNonces.Count;
|
||||||
|
internal event Action<NetPeer>? ExchangeCompleted;
|
||||||
|
|
||||||
|
internal void BeginJoin(NetPeer peer)
|
||||||
|
{
|
||||||
|
ObjectDisposedException.ThrowIf(_disposed, this);
|
||||||
|
if (_host || _nonce is not null)
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException("The direct echo exchange is already active.");
|
||||||
|
}
|
||||||
|
|
||||||
|
_nonce = Convert.ToHexString(RandomNumberGenerator.GetBytes(16)).ToLowerInvariant();
|
||||||
|
Send(peer, PingPrefix + _nonce);
|
||||||
|
}
|
||||||
|
|
||||||
|
public void Dispose()
|
||||||
|
{
|
||||||
|
if (_disposed)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
_events.NetworkReceiveEvent -= OnReceive;
|
||||||
|
_events.PeerDisconnectedEvent -= OnPeerDisconnected;
|
||||||
|
_hostNonces.Clear();
|
||||||
|
_disposed = true;
|
||||||
|
}
|
||||||
|
|
||||||
|
private void OnReceive(
|
||||||
|
NetPeer peer,
|
||||||
|
NetPacketReader reader,
|
||||||
|
byte channel,
|
||||||
|
DeliveryMethod deliveryMethod)
|
||||||
|
{
|
||||||
|
try
|
||||||
|
{
|
||||||
|
ReadOnlySpan<byte> payload = reader.GetRemainingBytesSpan();
|
||||||
|
if (payload.Length is < 9 or > 64)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
string message = Encoding.ASCII.GetString(payload);
|
||||||
|
if (_host && TryNonce(message, PingPrefix, out string? pingNonce))
|
||||||
|
{
|
||||||
|
_hostNonces[peer] = pingNonce!;
|
||||||
|
Send(peer, EchoPrefix + pingNonce);
|
||||||
|
}
|
||||||
|
else if (_host
|
||||||
|
&& _hostNonces.TryGetValue(peer, out string? hostNonce)
|
||||||
|
&& string.Equals(message, AckPrefix + hostNonce, StringComparison.Ordinal))
|
||||||
|
{
|
||||||
|
_hostNonces.Remove(peer);
|
||||||
|
Send(peer, DonePrefix + hostNonce);
|
||||||
|
ExchangeCompleted?.Invoke(peer);
|
||||||
|
_completed.TrySetResult(true);
|
||||||
|
}
|
||||||
|
else if (!_host
|
||||||
|
&& _nonce is not null
|
||||||
|
&& string.Equals(message, EchoPrefix + _nonce, StringComparison.Ordinal))
|
||||||
|
{
|
||||||
|
Send(peer, AckPrefix + _nonce);
|
||||||
|
}
|
||||||
|
else if (!_host
|
||||||
|
&& _nonce is not null
|
||||||
|
&& string.Equals(message, DonePrefix + _nonce, StringComparison.Ordinal))
|
||||||
|
{
|
||||||
|
ExchangeCompleted?.Invoke(peer);
|
||||||
|
_completed.TrySetResult(true);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
reader.Recycle();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool TryNonce(string message, string prefix, out string? nonce)
|
||||||
|
{
|
||||||
|
nonce = null;
|
||||||
|
if (!message.StartsWith(prefix, StringComparison.Ordinal)
|
||||||
|
|| message.Length != prefix.Length + 32)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
string candidate = message[prefix.Length..];
|
||||||
|
if (!candidate.All(static character => character is >= '0' and <= '9'
|
||||||
|
or >= 'a' and <= 'f'))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
nonce = candidate;
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void Send(NetPeer peer, string message) => peer.Send(
|
||||||
|
Encoding.ASCII.GetBytes(message),
|
||||||
|
DeliveryMethod.ReliableOrdered);
|
||||||
|
|
||||||
|
private void OnPeerDisconnected(NetPeer peer, DisconnectInfo disconnectInfo) =>
|
||||||
|
_hostNonces.Remove(peer);
|
||||||
|
}
|
||||||
@@ -0,0 +1,36 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.TestClient;
|
||||||
|
|
||||||
|
internal sealed class HostServiceFailureBudget
|
||||||
|
{
|
||||||
|
private const int MaximumConsecutiveTransientFailures = 3;
|
||||||
|
private int _consecutiveTransientFailures;
|
||||||
|
|
||||||
|
internal bool ShouldStop(
|
||||||
|
RendezvousErrorCode error,
|
||||||
|
DateTimeOffset leaseExpiresAt,
|
||||||
|
DateTimeOffset now)
|
||||||
|
{
|
||||||
|
if (error == RendezvousErrorCode.None)
|
||||||
|
{
|
||||||
|
Reset();
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
if (!IsTransient(error))
|
||||||
|
{
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
_consecutiveTransientFailures++;
|
||||||
|
return _consecutiveTransientFailures >= MaximumConsecutiveTransientFailures
|
||||||
|
|| now >= leaseExpiresAt;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal void Reset() => _consecutiveTransientFailures = 0;
|
||||||
|
|
||||||
|
private static bool IsTransient(RendezvousErrorCode error) => error is
|
||||||
|
RendezvousErrorCode.RateLimited
|
||||||
|
or RendezvousErrorCode.ServiceUnavailable
|
||||||
|
or RendezvousErrorCode.InternalError;
|
||||||
|
}
|
||||||
@@ -1,16 +1,29 @@
|
|||||||
namespace FinalFactory.Rendezvous.TestClient;
|
namespace FinalFactory.Rendezvous.TestClient;
|
||||||
|
|
||||||
/// <summary>
|
|
||||||
/// Bootstrap entry point for the public-SDK-only diagnostic client.
|
|
||||||
/// </summary>
|
|
||||||
public static class Program
|
public static class Program
|
||||||
{
|
{
|
||||||
/// <summary>
|
public static async Task<int> Main(string[] args)
|
||||||
/// Runs the bootstrap diagnostic.
|
|
||||||
/// </summary>
|
|
||||||
public static int Main()
|
|
||||||
{
|
{
|
||||||
Console.WriteLine("Rendezvous TestClient bootstrap is ready.");
|
using CancellationTokenSource shutdown = new();
|
||||||
return 0;
|
ConsoleCancelEventHandler cancelHandler = (_, eventArgs) =>
|
||||||
|
{
|
||||||
|
eventArgs.Cancel = true;
|
||||||
|
shutdown.Cancel();
|
||||||
|
};
|
||||||
|
Console.CancelKeyPress += cancelHandler;
|
||||||
|
try
|
||||||
|
{
|
||||||
|
TestClientApplication application = new(new RendezvousCommandRunner());
|
||||||
|
return await application.RunAsync(
|
||||||
|
args,
|
||||||
|
Console.In,
|
||||||
|
Console.Out,
|
||||||
|
Console.Error,
|
||||||
|
shutdown.Token).ConfigureAwait(false);
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
Console.CancelKeyPress -= cancelHandler;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,3 @@
|
|||||||
|
using System.Runtime.CompilerServices;
|
||||||
|
|
||||||
|
[assembly: InternalsVisibleTo("FinalFactory.Rendezvous.Tests")]
|
||||||
@@ -0,0 +1,56 @@
|
|||||||
|
# FinalFactory.Rendezvous.TestClient
|
||||||
|
|
||||||
|
This is a diagnostic executable for exercising Rendezvous through the same public
|
||||||
|
Client and Contracts API available to a game. It is not a production game client,
|
||||||
|
server browser, dedicated server, relay, account system, or gameplay host.
|
||||||
|
|
||||||
|
The executable has three explicit modes:
|
||||||
|
|
||||||
|
- `host` publishes a session, maintains presence and its lease, accepts an
|
||||||
|
authenticated direct peer, and answers a bounded ping/echo/ack/completion exchange;
|
||||||
|
- `browse` prints compatible public listings; and
|
||||||
|
- `join` selects or accepts a listing, drives traversal on its caller-owned
|
||||||
|
LiteNetLib socket, proves direct traffic, reports the typed outcome, and exits.
|
||||||
|
|
||||||
|
Run `dotnet run --project src/FinalFactory.Rendezvous.TestClient -- --help` for
|
||||||
|
the complete option reference. A typical script-mode invocation is:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
export RENDEZVOUS_PUBLISHER_CREDENTIAL='<credential from the deployment boundary>'
|
||||||
|
dotnet run --project src/FinalFactory.Rendezvous.TestClient -- \
|
||||||
|
host --service http://127.0.0.1:5000/ --mediator 127.0.0.1:9050 \
|
||||||
|
--game space-game --environment development --region local --protocol 1 \
|
||||||
|
--script --json --exit-after-echo
|
||||||
|
```
|
||||||
|
|
||||||
|
Publisher credentials are accepted only through a named environment variable.
|
||||||
|
There is deliberately no command-line credential option because process command
|
||||||
|
lines are routinely exposed to other local tools and diagnostics. Output uses an
|
||||||
|
allowlisted event model and never includes lease tokens, punch capabilities,
|
||||||
|
connection tickets, raw metadata, signing material, or reusable credentials.
|
||||||
|
|
||||||
|
Script mode never prompts. Join mode selects the first compatible listing unless
|
||||||
|
`--listing UUID` fixes the choice. `--json` emits one JSON object per line with
|
||||||
|
`version: 1`; event names and the process exit codes below are stable automation
|
||||||
|
contracts. A script-mode host without `--run-seconds` uses `--timeout-seconds` as
|
||||||
|
its total runtime bound. New optional event properties may be added without changing
|
||||||
|
the version. JSON help and usage failures are versioned events as well; informational
|
||||||
|
events use stdout and failures use stderr.
|
||||||
|
|
||||||
|
| Exit | Meaning |
|
||||||
|
|---:|---|
|
||||||
|
| `0` | Requested diagnostic flow completed successfully |
|
||||||
|
| `2` | Invalid command or options |
|
||||||
|
| `3` | Missing or invalid local configuration |
|
||||||
|
| `10` | HTTP, registration, browser, lease, or socket failure |
|
||||||
|
| `11` | No compatible session was available or selected |
|
||||||
|
| `12` | Authorization or traversal reached a typed terminal failure |
|
||||||
|
| `13` | A requested direct ping/echo proof did not complete |
|
||||||
|
| `130` | Caller cancellation or Ctrl+C |
|
||||||
|
|
||||||
|
The client prints the selected direct endpoint category (`loopback`, `private`, or
|
||||||
|
`public`) but never the raw endpoint. A traversal failure reports whether an
|
||||||
|
authoritative dedicated fallback is available; the diagnostic does not connect to
|
||||||
|
that fallback automatically. A host may publish a policy-authorized endpoint with
|
||||||
|
`--fallback IP:PORT`. See the repository integration guide for process
|
||||||
|
orchestration and topology limitations.
|
||||||
@@ -0,0 +1,774 @@
|
|||||||
|
using System.Diagnostics;
|
||||||
|
using System.Net;
|
||||||
|
using System.Net.Sockets;
|
||||||
|
using FinalFactory.Rendezvous.Client;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using LiteNetLib;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.TestClient;
|
||||||
|
|
||||||
|
internal sealed class RendezvousCommandRunner : ITestClientCommandRunner
|
||||||
|
{
|
||||||
|
private static readonly TimeSpan PollDelay = TimeSpan.FromMilliseconds(5);
|
||||||
|
private static readonly TimeSpan HostRefreshInterval = TimeSpan.FromMilliseconds(250);
|
||||||
|
private static readonly TimeSpan DirectTrafficFlushGrace = TimeSpan.FromMilliseconds(500);
|
||||||
|
|
||||||
|
public Task<TestClientExitCode> RunAsync(
|
||||||
|
TestClientOptions options,
|
||||||
|
TestClientOutput output,
|
||||||
|
TextReader input,
|
||||||
|
CancellationToken cancellationToken) => options.Mode switch
|
||||||
|
{
|
||||||
|
TestClientMode.Host => RunHostAsync(options, output, cancellationToken),
|
||||||
|
TestClientMode.Browse => RunBrowseAsync(options, output, cancellationToken),
|
||||||
|
TestClientMode.Join => RunJoinAsync(options, output, input, cancellationToken),
|
||||||
|
_ => Task.FromResult(TestClientExitCode.Usage),
|
||||||
|
};
|
||||||
|
|
||||||
|
private static async Task<TestClientExitCode> RunHostAsync(
|
||||||
|
TestClientOptions options,
|
||||||
|
TestClientOutput output,
|
||||||
|
CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
string? publisherCredential = Environment.GetEnvironmentVariable(
|
||||||
|
options.PublisherCredentialEnvironmentVariable);
|
||||||
|
if (!ContractValidation.IsOpaqueHttpCredentialValid(publisherCredential))
|
||||||
|
{
|
||||||
|
output.WriteError(
|
||||||
|
"host.configuration",
|
||||||
|
"failed",
|
||||||
|
"The publisher credential environment variable is missing or invalid.",
|
||||||
|
phase: "configuration");
|
||||||
|
return TestClientExitCode.Configuration;
|
||||||
|
}
|
||||||
|
string credential = publisherCredential!;
|
||||||
|
|
||||||
|
using HttpClient http = CreateHttpClient(options);
|
||||||
|
RendezvousPublisherClient publisher = new(http, ClientOptions(options));
|
||||||
|
RendezvousSessionBrowserClient browser = new(http, ClientOptions(options));
|
||||||
|
RendezvousJoinClient joins = new(http, ClientOptions(options));
|
||||||
|
RendezvousNetListener events = new();
|
||||||
|
NetManager manager = events.CreateManager();
|
||||||
|
if (!manager.Start(options.LocalPort))
|
||||||
|
{
|
||||||
|
output.WriteError("host.socket", "failed", "The gameplay UDP socket could not start.", phase: "presence");
|
||||||
|
return TestClientExitCode.ServiceFailure;
|
||||||
|
}
|
||||||
|
|
||||||
|
PublishedSession? session = null;
|
||||||
|
using CancellationTokenSource hostOperations = CancellationTokenSource.CreateLinkedTokenSource(cancellationToken);
|
||||||
|
Task<RendezvousClientResult<int>>? refresh = null;
|
||||||
|
Task<RendezvousClientResult<RenewLeaseResponse>>? renewal = null;
|
||||||
|
Task<RendezvousClientResult<GetSessionResponse>>? readiness = null;
|
||||||
|
DirectEchoProtocol? echo = null;
|
||||||
|
RendezvousHostCoordinator? coordinator = null;
|
||||||
|
TestClientExitCode hostResult = TestClientExitCode.ServiceFailure;
|
||||||
|
bool cleanupFailed = false;
|
||||||
|
try
|
||||||
|
{
|
||||||
|
output.Write("host.registration", "started", phase: "registration");
|
||||||
|
RendezvousClientResult<PublishedSession> registration;
|
||||||
|
using (CancellationTokenSource registrationTimeout = CreateOperationTimeout(options, cancellationToken))
|
||||||
|
{
|
||||||
|
try
|
||||||
|
{
|
||||||
|
registration = await publisher.RegisterAsync(
|
||||||
|
new RegisterSessionRequest
|
||||||
|
{
|
||||||
|
IdempotencyKey = Guid.NewGuid().ToString("N"),
|
||||||
|
GameId = options.GameId,
|
||||||
|
EnvironmentId = options.EnvironmentId,
|
||||||
|
RegionId = options.RegionId,
|
||||||
|
ProtocolVersion = options.ProtocolVersion,
|
||||||
|
BuildVersion = options.BuildVersion,
|
||||||
|
DisplayName = options.DisplayName,
|
||||||
|
Visibility = ListingVisibility.Public,
|
||||||
|
Capacity = new SessionCapacity { CurrentPlayers = 1, MaximumPlayers = 8 },
|
||||||
|
Metadata = new Dictionary<string, string>(options.Metadata, StringComparer.Ordinal),
|
||||||
|
DedicatedFallback = options.DedicatedFallback,
|
||||||
|
},
|
||||||
|
credential,
|
||||||
|
registrationTimeout.Token).ConfigureAwait(false);
|
||||||
|
}
|
||||||
|
catch (OperationCanceledException) when (!cancellationToken.IsCancellationRequested)
|
||||||
|
{
|
||||||
|
output.WriteError(
|
||||||
|
"host.registration",
|
||||||
|
"timed-out",
|
||||||
|
"Host registration exceeded the bounded startup stage.",
|
||||||
|
phase: "registration");
|
||||||
|
return TestClientExitCode.ServiceFailure;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (!registration.IsSuccess || registration.Value is null)
|
||||||
|
{
|
||||||
|
WriteServiceFailure(output, "host.registration", "registration", registration);
|
||||||
|
return TestClientExitCode.ServiceFailure;
|
||||||
|
}
|
||||||
|
|
||||||
|
session = registration.Value;
|
||||||
|
output.Write(
|
||||||
|
"host.registered",
|
||||||
|
"registered",
|
||||||
|
phase: "registration",
|
||||||
|
listingId: session.ListingId.ToString(),
|
||||||
|
displayName: options.DisplayName);
|
||||||
|
echo = new DirectEchoProtocol(events.GameplayEvents, host: true);
|
||||||
|
echo.ExchangeCompleted += _ => output.Write(
|
||||||
|
"host.direct-traffic",
|
||||||
|
"verified",
|
||||||
|
phase: "direct-traffic",
|
||||||
|
endpointType: "peer-to-peer");
|
||||||
|
coordinator = new RendezvousHostCoordinator(
|
||||||
|
manager,
|
||||||
|
events,
|
||||||
|
options.Mediator,
|
||||||
|
session,
|
||||||
|
joins,
|
||||||
|
CoordinatorOptions(options));
|
||||||
|
coordinator.AttemptCompleted += (_, completion) =>
|
||||||
|
{
|
||||||
|
output.Write(
|
||||||
|
"host.attempt.completed",
|
||||||
|
completion.Outcome.IsSuccess ? "connected" : "failed",
|
||||||
|
phase: completion.Outcome.Phase.ToString(),
|
||||||
|
outcome: completion.Outcome.Kind.ToString(),
|
||||||
|
elapsedMilliseconds: ToMilliseconds(completion.Outcome.Elapsed));
|
||||||
|
if (completion.Outcome.IsSuccess)
|
||||||
|
{
|
||||||
|
output.Write(
|
||||||
|
"host.direct-connect",
|
||||||
|
"connected",
|
||||||
|
phase: "direct-connection",
|
||||||
|
endpointType: "peer-to-peer");
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
Stopwatch running = Stopwatch.StartNew();
|
||||||
|
TimeSpan nextRefresh = TimeSpan.Zero;
|
||||||
|
TimeSpan nextRenewal = TimeSpan.FromSeconds(session.LeaseRenewAfterSeconds);
|
||||||
|
TimeSpan nextReadinessProbe = TimeSpan.Zero;
|
||||||
|
bool directTrafficReported = false;
|
||||||
|
TimeSpan? directTrafficCompletedAt = null;
|
||||||
|
bool ready = false;
|
||||||
|
bool terminalFailure = false;
|
||||||
|
int previousPendingAttempts = 0;
|
||||||
|
HostServiceFailureBudget refreshFailures = new();
|
||||||
|
HostServiceFailureBudget renewalFailures = new();
|
||||||
|
using PeriodicTimer pollTimer = new(PollDelay);
|
||||||
|
while (!cancellationToken.IsCancellationRequested)
|
||||||
|
{
|
||||||
|
coordinator.Poll();
|
||||||
|
if (coordinator.State != RendezvousHostState.Active)
|
||||||
|
{
|
||||||
|
output.WriteError(
|
||||||
|
"host.lifecycle",
|
||||||
|
"failed",
|
||||||
|
"The host coordinator stopped before shutdown was requested.",
|
||||||
|
phase: "lifecycle",
|
||||||
|
outcome: coordinator.State.ToString());
|
||||||
|
terminalFailure = true;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
if (coordinator.PendingAttemptCount > previousPendingAttempts)
|
||||||
|
{
|
||||||
|
output.Write(
|
||||||
|
"host.punch",
|
||||||
|
"started",
|
||||||
|
phase: "nat-traversal",
|
||||||
|
count: coordinator.PendingAttemptCount);
|
||||||
|
}
|
||||||
|
previousPendingAttempts = coordinator.PendingAttemptCount;
|
||||||
|
if (readiness is { IsCompleted: true })
|
||||||
|
{
|
||||||
|
RendezvousClientResult<GetSessionResponse> result = await readiness.ConfigureAwait(false);
|
||||||
|
readiness = null;
|
||||||
|
if (result.IsSuccess)
|
||||||
|
{
|
||||||
|
ready = true;
|
||||||
|
output.Write(
|
||||||
|
"host.ready",
|
||||||
|
"ready",
|
||||||
|
phase: "presence",
|
||||||
|
listingId: session.ListingId.ToString());
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
nextReadinessProbe = running.Elapsed + TimeSpan.FromMilliseconds(50);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (!ready && readiness is null && running.Elapsed >= nextReadinessProbe)
|
||||||
|
{
|
||||||
|
readiness = browser.GetAsync(
|
||||||
|
session.ListingId,
|
||||||
|
options.GameId,
|
||||||
|
options.EnvironmentId,
|
||||||
|
options.ProtocolVersion,
|
||||||
|
hostOperations.Token);
|
||||||
|
}
|
||||||
|
if (refresh is { IsCompleted: true })
|
||||||
|
{
|
||||||
|
RendezvousClientResult<int> result = await refresh.ConfigureAwait(false);
|
||||||
|
refresh = null;
|
||||||
|
nextRefresh = running.Elapsed + (result.IsSuccess
|
||||||
|
? HostRefreshInterval
|
||||||
|
: TimeSpan.FromSeconds(1));
|
||||||
|
if (!result.IsSuccess)
|
||||||
|
{
|
||||||
|
WriteServiceFailure(output, "host.authorization", "authorization", result);
|
||||||
|
if (refreshFailures.ShouldStop(result.Error, session.ExpiresAt, DateTimeOffset.UtcNow))
|
||||||
|
{
|
||||||
|
terminalFailure = true;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
refreshFailures.Reset();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (refresh is null && running.Elapsed >= nextRefresh)
|
||||||
|
{
|
||||||
|
refresh = coordinator.RefreshJoinAttemptsAsync(hostOperations.Token);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (renewal is { IsCompleted: true })
|
||||||
|
{
|
||||||
|
RendezvousClientResult<RenewLeaseResponse> result = await renewal.ConfigureAwait(false);
|
||||||
|
renewal = null;
|
||||||
|
nextRenewal = running.Elapsed + (result.IsSuccess && result.Value is not null
|
||||||
|
? TimeSpan.FromSeconds(result.Value.RenewAfterSeconds)
|
||||||
|
: TimeSpan.FromSeconds(1));
|
||||||
|
output.Write(
|
||||||
|
"host.lease",
|
||||||
|
result.IsSuccess ? "renewed" : "failed",
|
||||||
|
phase: "lease",
|
||||||
|
message: result.IsSuccess ? null : SafeServiceMessage(result));
|
||||||
|
if (!result.IsSuccess
|
||||||
|
&& renewalFailures.ShouldStop(result.Error, session.ExpiresAt, DateTimeOffset.UtcNow))
|
||||||
|
{
|
||||||
|
terminalFailure = true;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
if (result.IsSuccess)
|
||||||
|
{
|
||||||
|
renewalFailures.Reset();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (renewal is null && running.Elapsed >= nextRenewal)
|
||||||
|
{
|
||||||
|
renewal = publisher.RenewAsync(session, credential, hostOperations.Token);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (echo.Completion.IsCompleted && !directTrafficReported)
|
||||||
|
{
|
||||||
|
directTrafficReported = true;
|
||||||
|
directTrafficCompletedAt = running.Elapsed;
|
||||||
|
}
|
||||||
|
if (options.ExitAfterEcho
|
||||||
|
&& directTrafficCompletedAt.HasValue
|
||||||
|
&& running.Elapsed - directTrafficCompletedAt.Value >= DirectTrafficFlushGrace)
|
||||||
|
{
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
if (options.RunDuration.HasValue && running.Elapsed >= options.RunDuration.Value)
|
||||||
|
{
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
if (!await pollTimer.WaitForNextTickAsync(cancellationToken).ConfigureAwait(false))
|
||||||
|
{
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (cancellationToken.IsCancellationRequested)
|
||||||
|
{
|
||||||
|
hostResult = TestClientExitCode.Cancelled;
|
||||||
|
}
|
||||||
|
else if (terminalFailure)
|
||||||
|
{
|
||||||
|
hostResult = TestClientExitCode.ServiceFailure;
|
||||||
|
}
|
||||||
|
else if (options.ExitAfterEcho && !directTrafficReported)
|
||||||
|
{
|
||||||
|
output.WriteError(
|
||||||
|
"host.direct-traffic",
|
||||||
|
"timed-out",
|
||||||
|
"No authenticated ping/echo/ack exchange completed within the host runtime.",
|
||||||
|
phase: "direct-traffic");
|
||||||
|
hostResult = TestClientExitCode.DirectTrafficFailed;
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
hostResult = TestClientExitCode.Success;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
hostOperations.Cancel();
|
||||||
|
await ObserveCancellationAsync(refresh).ConfigureAwait(false);
|
||||||
|
await ObserveCancellationAsync(renewal).ConfigureAwait(false);
|
||||||
|
await ObserveCancellationAsync(readiness).ConfigureAwait(false);
|
||||||
|
coordinator?.Dispose();
|
||||||
|
echo?.Dispose();
|
||||||
|
if (session is not null)
|
||||||
|
{
|
||||||
|
using CancellationTokenSource cleanup = new(TimeSpan.FromSeconds(5));
|
||||||
|
try
|
||||||
|
{
|
||||||
|
RendezvousClientResult<bool> deregistered = await publisher.DeregisterAsync(
|
||||||
|
session,
|
||||||
|
credential,
|
||||||
|
cleanup.Token).ConfigureAwait(false);
|
||||||
|
output.Write(
|
||||||
|
"host.deregistered",
|
||||||
|
deregistered.IsSuccess ? "complete" : "failed",
|
||||||
|
phase: "lifecycle",
|
||||||
|
listingId: session.ListingId.ToString());
|
||||||
|
if (!deregistered.IsSuccess)
|
||||||
|
{
|
||||||
|
cleanupFailed = true;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
catch (OperationCanceledException)
|
||||||
|
{
|
||||||
|
output.WriteError(
|
||||||
|
"host.deregistered",
|
||||||
|
"timed-out",
|
||||||
|
"Deregistration did not complete within the cleanup budget.",
|
||||||
|
phase: "lifecycle");
|
||||||
|
cleanupFailed = true;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
manager.Stop();
|
||||||
|
}
|
||||||
|
return cleanupFailed && !cancellationToken.IsCancellationRequested
|
||||||
|
? TestClientExitCode.ServiceFailure
|
||||||
|
: hostResult;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static async Task<TestClientExitCode> RunBrowseAsync(
|
||||||
|
TestClientOptions options,
|
||||||
|
TestClientOutput output,
|
||||||
|
CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
using CancellationTokenSource operation = CreateOperationTimeout(options, cancellationToken);
|
||||||
|
using HttpClient http = CreateHttpClient(options);
|
||||||
|
RendezvousSessionBrowserClient browser = new(http, ClientOptions(options));
|
||||||
|
output.Write("browse.sessions", "started", phase: "directory");
|
||||||
|
RendezvousClientResult<IReadOnlyList<SessionListing>> result = await browser.BrowseAllAsync(
|
||||||
|
BrowseRequest(options),
|
||||||
|
maximumPages: 10,
|
||||||
|
cancellationToken: operation.Token).ConfigureAwait(false);
|
||||||
|
if (!result.IsSuccess || result.Value is null)
|
||||||
|
{
|
||||||
|
WriteServiceFailure(output, "browse.sessions", "directory", result);
|
||||||
|
return TestClientExitCode.ServiceFailure;
|
||||||
|
}
|
||||||
|
|
||||||
|
WriteListings(output, result.Value);
|
||||||
|
return result.Value.Count == 0
|
||||||
|
? TestClientExitCode.NoCompatibleSession
|
||||||
|
: TestClientExitCode.Success;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static async Task<TestClientExitCode> RunJoinAsync(
|
||||||
|
TestClientOptions options,
|
||||||
|
TestClientOutput output,
|
||||||
|
TextReader input,
|
||||||
|
CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
using CancellationTokenSource operation = CreateOperationTimeout(options, cancellationToken);
|
||||||
|
using HttpClient http = CreateHttpClient(options);
|
||||||
|
RendezvousSessionBrowserClient browser = new(http, ClientOptions(options));
|
||||||
|
RendezvousJoinClient joins = new(http, ClientOptions(options));
|
||||||
|
SessionSelection selection = await SelectListingAsync(
|
||||||
|
options,
|
||||||
|
output,
|
||||||
|
input,
|
||||||
|
browser,
|
||||||
|
operation.Token).ConfigureAwait(false);
|
||||||
|
if (selection.Listing is null)
|
||||||
|
{
|
||||||
|
return selection.ExitCode;
|
||||||
|
}
|
||||||
|
SessionListing listing = selection.Listing;
|
||||||
|
|
||||||
|
RendezvousNetListener events = new();
|
||||||
|
NetManager manager = events.CreateManager();
|
||||||
|
if (!manager.Start(options.LocalPort))
|
||||||
|
{
|
||||||
|
output.WriteError("join.socket", "failed", "The gameplay UDP socket could not start.", phase: "mediation");
|
||||||
|
return TestClientExitCode.ServiceFailure;
|
||||||
|
}
|
||||||
|
|
||||||
|
RendezvousClientCoordinator? coordinator = null;
|
||||||
|
bool directConnected = false;
|
||||||
|
try
|
||||||
|
{
|
||||||
|
output.Write(
|
||||||
|
"join.authorization",
|
||||||
|
"started",
|
||||||
|
phase: "authorization",
|
||||||
|
listingId: listing.ListingId.ToString());
|
||||||
|
RendezvousConnectionStartResult start = await joins.CreateConnectionAttemptAsync(
|
||||||
|
new CreateJoinAttemptRequest
|
||||||
|
{
|
||||||
|
IdempotencyKey = Guid.NewGuid().ToString("N"),
|
||||||
|
GameId = options.GameId,
|
||||||
|
EnvironmentId = options.EnvironmentId,
|
||||||
|
ListingId = listing.ListingId,
|
||||||
|
ProtocolVersion = options.ProtocolVersion,
|
||||||
|
},
|
||||||
|
listing.DedicatedFallback,
|
||||||
|
operation.Token).ConfigureAwait(false);
|
||||||
|
if (start.Outcome is { } serviceOutcome)
|
||||||
|
{
|
||||||
|
cancellationToken.ThrowIfCancellationRequested();
|
||||||
|
WriteOutcome(output, "join.authorization", serviceOutcome);
|
||||||
|
WriteFallback(output, serviceOutcome);
|
||||||
|
return TestClientExitCode.TraversalFailed;
|
||||||
|
}
|
||||||
|
|
||||||
|
CreateJoinAttemptResponse attempt = start.Attempt
|
||||||
|
?? throw new InvalidOperationException("The typed start result had no attempt or outcome.");
|
||||||
|
using DirectEchoProtocol echo = new(events.GameplayEvents, host: false);
|
||||||
|
coordinator = new RendezvousClientCoordinator(
|
||||||
|
manager,
|
||||||
|
events,
|
||||||
|
options.Mediator,
|
||||||
|
attempt,
|
||||||
|
CoordinatorOptions(options));
|
||||||
|
output.Write("join.punch", "started", phase: "nat-traversal");
|
||||||
|
using (CancellationTokenSource traversal = CreateOperationTimeout(options, cancellationToken))
|
||||||
|
using (PeriodicTimer traversalPoll = new(PollDelay))
|
||||||
|
{
|
||||||
|
RendezvousConnectionState previousState = coordinator.State;
|
||||||
|
while (!coordinator.IsCompleted)
|
||||||
|
{
|
||||||
|
traversal.Token.ThrowIfCancellationRequested();
|
||||||
|
coordinator.Poll();
|
||||||
|
if (coordinator.State != previousState)
|
||||||
|
{
|
||||||
|
previousState = coordinator.State;
|
||||||
|
if (previousState == RendezvousConnectionState.Connecting)
|
||||||
|
{
|
||||||
|
output.Write(
|
||||||
|
"join.direct-connect",
|
||||||
|
"started",
|
||||||
|
phase: "direct-connection");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (!coordinator.IsCompleted
|
||||||
|
&& !await traversalPoll.WaitForNextTickAsync(traversal.Token).ConfigureAwait(false))
|
||||||
|
{
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
RendezvousConnectionOutcome outcome = coordinator.Outcome
|
||||||
|
?? throw new InvalidOperationException("The completed coordinator had no typed outcome.");
|
||||||
|
WriteOutcome(output, "join.traversal", outcome);
|
||||||
|
if (!outcome.IsSuccess || coordinator.ConnectedPeer is null)
|
||||||
|
{
|
||||||
|
WriteFallback(output, outcome);
|
||||||
|
await ReportOutcomeAsync(coordinator, joins, output, cancellationToken).ConfigureAwait(false);
|
||||||
|
return TestClientExitCode.TraversalFailed;
|
||||||
|
}
|
||||||
|
|
||||||
|
NetPeer peer = coordinator.ConnectedPeer;
|
||||||
|
directConnected = true;
|
||||||
|
string endpointType = EndpointType(peer.Address);
|
||||||
|
output.Write(
|
||||||
|
"join.connected",
|
||||||
|
"connected",
|
||||||
|
phase: "direct-connection",
|
||||||
|
endpointType: endpointType,
|
||||||
|
elapsedMilliseconds: ToMilliseconds(outcome.Elapsed));
|
||||||
|
await ReportOutcomeAsync(coordinator, joins, output, cancellationToken).ConfigureAwait(false);
|
||||||
|
echo.BeginJoin(peer);
|
||||||
|
using (CancellationTokenSource traffic = CreateOperationTimeout(options, cancellationToken))
|
||||||
|
using (PeriodicTimer trafficPoll = new(PollDelay))
|
||||||
|
{
|
||||||
|
while (!echo.Completion.IsCompleted)
|
||||||
|
{
|
||||||
|
traffic.Token.ThrowIfCancellationRequested();
|
||||||
|
manager.PollEvents();
|
||||||
|
if (!echo.Completion.IsCompleted
|
||||||
|
&& !await trafficPoll.WaitForNextTickAsync(traffic.Token).ConfigureAwait(false))
|
||||||
|
{
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
await echo.Completion.ConfigureAwait(false);
|
||||||
|
output.Write(
|
||||||
|
"join.direct-traffic",
|
||||||
|
"verified",
|
||||||
|
phase: "direct-traffic",
|
||||||
|
endpointType: endpointType);
|
||||||
|
peer.Disconnect();
|
||||||
|
manager.PollEvents();
|
||||||
|
return TestClientExitCode.Success;
|
||||||
|
}
|
||||||
|
catch (OperationCanceledException) when (!cancellationToken.IsCancellationRequested)
|
||||||
|
{
|
||||||
|
output.WriteError(
|
||||||
|
"join.timeout",
|
||||||
|
"timed-out",
|
||||||
|
"The bounded join operation timed out.",
|
||||||
|
phase: "lifecycle",
|
||||||
|
outcome: ConnectionOutcomeKind.TimedOut.ToString());
|
||||||
|
if (coordinator is not null && !coordinator.IsCompleted)
|
||||||
|
{
|
||||||
|
coordinator.Poll();
|
||||||
|
}
|
||||||
|
if (coordinator is not null && !coordinator.IsCompleted)
|
||||||
|
{
|
||||||
|
coordinator.Cancel();
|
||||||
|
coordinator.Poll();
|
||||||
|
if (coordinator.Outcome is { } timeoutOutcome)
|
||||||
|
{
|
||||||
|
WriteOutcome(output, "join.traversal", timeoutOutcome);
|
||||||
|
WriteFallback(output, timeoutOutcome, listing.DedicatedFallback);
|
||||||
|
await ReportOutcomeAsync(
|
||||||
|
coordinator,
|
||||||
|
joins,
|
||||||
|
output,
|
||||||
|
cancellationToken).ConfigureAwait(false);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return directConnected
|
||||||
|
? TestClientExitCode.DirectTrafficFailed
|
||||||
|
: TestClientExitCode.TraversalFailed;
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
coordinator?.Dispose();
|
||||||
|
manager.Stop();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static async Task<SessionSelection> SelectListingAsync(
|
||||||
|
TestClientOptions options,
|
||||||
|
TestClientOutput output,
|
||||||
|
TextReader input,
|
||||||
|
RendezvousSessionBrowserClient browser,
|
||||||
|
CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
if (options.ListingId.HasValue)
|
||||||
|
{
|
||||||
|
RendezvousClientResult<GetSessionResponse> exact = await browser.GetAsync(
|
||||||
|
options.ListingId.Value,
|
||||||
|
options.GameId,
|
||||||
|
options.EnvironmentId,
|
||||||
|
options.ProtocolVersion,
|
||||||
|
cancellationToken).ConfigureAwait(false);
|
||||||
|
if (!exact.IsSuccess || exact.Value is null)
|
||||||
|
{
|
||||||
|
WriteServiceFailure(output, "join.selection", "directory", exact);
|
||||||
|
return new(null, TestClientExitCode.ServiceFailure);
|
||||||
|
}
|
||||||
|
return new(exact.Value.Session, TestClientExitCode.Success);
|
||||||
|
}
|
||||||
|
|
||||||
|
RendezvousClientResult<IReadOnlyList<SessionListing>> result = await browser.BrowseAllAsync(
|
||||||
|
BrowseRequest(options),
|
||||||
|
maximumPages: 10,
|
||||||
|
cancellationToken: cancellationToken).ConfigureAwait(false);
|
||||||
|
if (!result.IsSuccess || result.Value is null)
|
||||||
|
{
|
||||||
|
WriteServiceFailure(output, "join.selection", "directory", result);
|
||||||
|
return new(null, TestClientExitCode.ServiceFailure);
|
||||||
|
}
|
||||||
|
if (result.Value.Count == 0)
|
||||||
|
{
|
||||||
|
output.Write("join.selection", "empty", phase: "directory", count: 0);
|
||||||
|
return new(null, TestClientExitCode.NoCompatibleSession);
|
||||||
|
}
|
||||||
|
WriteListings(output, result.Value);
|
||||||
|
if (options.Script)
|
||||||
|
{
|
||||||
|
return new(result.Value[0], TestClientExitCode.Success);
|
||||||
|
}
|
||||||
|
|
||||||
|
output.WritePrompt($"Select session [1-{result.Value.Count}]: ");
|
||||||
|
string? selection = await input.ReadLineAsync(cancellationToken).ConfigureAwait(false);
|
||||||
|
SessionListing? selected = int.TryParse(selection, out int index)
|
||||||
|
&& index >= 1
|
||||||
|
&& index <= result.Value.Count
|
||||||
|
? result.Value[index - 1]
|
||||||
|
: null;
|
||||||
|
return selected is null
|
||||||
|
? new(null, TestClientExitCode.NoCompatibleSession)
|
||||||
|
: new(selected, TestClientExitCode.Success);
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void WriteListings(TestClientOutput output, IReadOnlyList<SessionListing> listings)
|
||||||
|
{
|
||||||
|
output.Write("browse.completed", "complete", phase: "directory", count: listings.Count);
|
||||||
|
foreach (SessionListing listing in listings)
|
||||||
|
{
|
||||||
|
output.Write(
|
||||||
|
"browse.session",
|
||||||
|
"available",
|
||||||
|
phase: "directory",
|
||||||
|
listingId: listing.ListingId.ToString(),
|
||||||
|
displayName: listing.DisplayName);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static BrowseSessionsRequest BrowseRequest(TestClientOptions options) => new()
|
||||||
|
{
|
||||||
|
GameId = options.GameId,
|
||||||
|
EnvironmentId = options.EnvironmentId,
|
||||||
|
ProtocolVersion = options.ProtocolVersion,
|
||||||
|
RegionId = options.RegionId,
|
||||||
|
PageSize = options.PageSize,
|
||||||
|
ExcludeFull = true,
|
||||||
|
};
|
||||||
|
|
||||||
|
private static HttpClient CreateHttpClient(TestClientOptions options) => new()
|
||||||
|
{
|
||||||
|
BaseAddress = options.ServiceUri,
|
||||||
|
Timeout = Timeout.InfiniteTimeSpan,
|
||||||
|
};
|
||||||
|
|
||||||
|
private static RendezvousClientOptions ClientOptions(TestClientOptions options) => new()
|
||||||
|
{
|
||||||
|
RequestTimeout = TimeSpan.FromSeconds(Math.Min(30, options.OperationTimeout.TotalSeconds)),
|
||||||
|
};
|
||||||
|
|
||||||
|
private static RendezvousCoordinatorOptions CoordinatorOptions(TestClientOptions options)
|
||||||
|
{
|
||||||
|
TimeSpan phaseTimeout = TimeSpan.FromSeconds(
|
||||||
|
Math.Min(30, options.OperationTimeout.TotalSeconds * 0.45));
|
||||||
|
return new RendezvousCoordinatorOptions
|
||||||
|
{
|
||||||
|
PunchTimeout = phaseTimeout,
|
||||||
|
DirectConnectTimeout = phaseTimeout,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
private static CancellationTokenSource CreateOperationTimeout(
|
||||||
|
TestClientOptions options,
|
||||||
|
CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
CancellationTokenSource source = CancellationTokenSource.CreateLinkedTokenSource(cancellationToken);
|
||||||
|
source.CancelAfter(options.OperationTimeout);
|
||||||
|
return source;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static async Task ReportOutcomeAsync(
|
||||||
|
RendezvousClientCoordinator coordinator,
|
||||||
|
RendezvousJoinClient joins,
|
||||||
|
TestClientOutput output,
|
||||||
|
CancellationToken callerCancellationToken)
|
||||||
|
{
|
||||||
|
using CancellationTokenSource telemetry = CancellationTokenSource.CreateLinkedTokenSource(
|
||||||
|
callerCancellationToken);
|
||||||
|
telemetry.CancelAfter(TimeSpan.FromSeconds(5));
|
||||||
|
try
|
||||||
|
{
|
||||||
|
RendezvousClientResult<ReportConnectionOutcomeResponse> report =
|
||||||
|
await coordinator.ReportOutcomeAsync(joins, telemetry.Token).ConfigureAwait(false);
|
||||||
|
output.Write(
|
||||||
|
"join.outcome-report",
|
||||||
|
report.IsSuccess ? "accepted" : "failed",
|
||||||
|
phase: "telemetry",
|
||||||
|
message: report.IsSuccess ? null : SafeServiceMessage(report));
|
||||||
|
}
|
||||||
|
catch (OperationCanceledException) when (!callerCancellationToken.IsCancellationRequested)
|
||||||
|
{
|
||||||
|
output.WriteError(
|
||||||
|
"join.outcome-report",
|
||||||
|
"cancelled",
|
||||||
|
"Outcome reporting was cancelled within the operation budget.",
|
||||||
|
phase: "telemetry");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void WriteOutcome(
|
||||||
|
TestClientOutput output,
|
||||||
|
string eventName,
|
||||||
|
RendezvousConnectionOutcome outcome) => output.Write(
|
||||||
|
eventName,
|
||||||
|
outcome.IsSuccess ? "connected" : "failed",
|
||||||
|
phase: outcome.Phase.ToString(),
|
||||||
|
outcome: outcome.Kind.ToString(),
|
||||||
|
elapsedMilliseconds: ToMilliseconds(outcome.Elapsed));
|
||||||
|
|
||||||
|
private static void WriteFallback(
|
||||||
|
TestClientOutput output,
|
||||||
|
RendezvousConnectionOutcome outcome,
|
||||||
|
NetworkEndpoint? authoritativeFallback = null)
|
||||||
|
{
|
||||||
|
bool hasFallback = outcome.HasDedicatedFallback || authoritativeFallback is not null;
|
||||||
|
output.Write(
|
||||||
|
"join.fallback",
|
||||||
|
hasFallback ? "available" : "unavailable",
|
||||||
|
phase: "fallback",
|
||||||
|
outcome: outcome.Kind.ToString(),
|
||||||
|
endpointType: hasFallback ? "dedicated" : "none");
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void WriteServiceFailure<T>(
|
||||||
|
TestClientOutput output,
|
||||||
|
string eventName,
|
||||||
|
string phase,
|
||||||
|
RendezvousClientResult<T> result) => output.WriteError(
|
||||||
|
eventName,
|
||||||
|
"failed",
|
||||||
|
SafeServiceMessage(result),
|
||||||
|
phase,
|
||||||
|
result.Error.ToString());
|
||||||
|
|
||||||
|
private static string SafeServiceMessage<T>(RendezvousClientResult<T> result) =>
|
||||||
|
$"Rendezvous returned {result.Error}.";
|
||||||
|
|
||||||
|
private static async Task ObserveCancellationAsync<T>(Task<T>? task)
|
||||||
|
{
|
||||||
|
if (task is null)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
try
|
||||||
|
{
|
||||||
|
await task.ConfigureAwait(false);
|
||||||
|
}
|
||||||
|
catch (OperationCanceledException)
|
||||||
|
{
|
||||||
|
}
|
||||||
|
catch (ObjectDisposedException)
|
||||||
|
{
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static string EndpointType(IPAddress address)
|
||||||
|
{
|
||||||
|
if (IPAddress.IsLoopback(address))
|
||||||
|
{
|
||||||
|
return "loopback";
|
||||||
|
}
|
||||||
|
if (address.AddressFamily == AddressFamily.InterNetworkV6)
|
||||||
|
{
|
||||||
|
byte[] ipv6 = address.GetAddressBytes();
|
||||||
|
return address.IsIPv6LinkLocal || (ipv6[0] & 0xfe) == 0xfc
|
||||||
|
? "private"
|
||||||
|
: "public";
|
||||||
|
}
|
||||||
|
byte[] bytes = address.GetAddressBytes();
|
||||||
|
bool privateAddress = bytes[0] == 10
|
||||||
|
|| bytes[0] == 172 && bytes[1] is >= 16 and <= 31
|
||||||
|
|| bytes[0] == 192 && bytes[1] == 168;
|
||||||
|
return privateAddress ? "private" : "public";
|
||||||
|
}
|
||||||
|
|
||||||
|
private static long ToMilliseconds(TimeSpan elapsed) =>
|
||||||
|
(long)Math.Min(long.MaxValue, Math.Max(0, elapsed.TotalMilliseconds));
|
||||||
|
|
||||||
|
private sealed record SessionSelection(
|
||||||
|
SessionListing? Listing,
|
||||||
|
TestClientExitCode ExitCode);
|
||||||
|
}
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user