Compare commits
2 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 02ca502a76 | |||
| 47382ddadc |
@@ -81,6 +81,8 @@ The ratified v1 boundaries, trust decisions, privacy rules, safety budgets, and
|
|||||||
threat model are indexed in [the architecture documentation](docs/architecture/README.md).
|
threat model are indexed in [the architecture documentation](docs/architecture/README.md).
|
||||||
The frozen v1 wire surface is documented in the
|
The frozen v1 wire surface is documented in the
|
||||||
[HTTP, UDP, and generated OpenAPI contracts](docs/contracts/README.md).
|
[HTTP, UDP, and generated OpenAPI contracts](docs/contracts/README.md).
|
||||||
|
Tenant policy, publisher/operator principals, and production key custody are
|
||||||
|
defined in [game provisioning and signing-key lifecycle](docs/security/provisioning.md).
|
||||||
|
|
||||||
## Development
|
## Development
|
||||||
|
|
||||||
@@ -97,5 +99,9 @@ dotnet test Rendezvous.slnx --configuration Release --no-build
|
|||||||
Run the bootstrap server with
|
Run the bootstrap server with
|
||||||
`dotnet run --project src/FinalFactory.Rendezvous.Server`. It serves HTTP health endpoints and binds
|
`dotnet run --project src/FinalFactory.Rendezvous.Server`. It serves HTTP health endpoints and binds
|
||||||
the configured UDP mediator port; both stop through normal host cancellation.
|
the configured UDP mediator port; both stop through normal host cancellation.
|
||||||
|
The launch profile uses an ephemeral development-only signing key. Production
|
||||||
|
startup fails closed until externally supplied game policies and `env:` signing
|
||||||
|
key references resolve to valid key material; no reusable game secret is stored
|
||||||
|
in this repository or the public Client package.
|
||||||
The project dependency rules and supported runtime choices are documented in
|
The project dependency rules and supported runtime choices are documented in
|
||||||
[project and dependency boundaries](docs/architecture/project-boundaries.md).
|
[project and dependency boundaries](docs/architecture/project-boundaries.md).
|
||||||
|
|||||||
@@ -0,0 +1,100 @@
|
|||||||
|
# ADR 0004: atomic ephemeral state and single-active availability
|
||||||
|
|
||||||
|
- Status: Accepted
|
||||||
|
- Date: 2026-07-16
|
||||||
|
- Tracking: #6
|
||||||
|
|
||||||
|
## Context
|
||||||
|
|
||||||
|
Listings, leases, endpoint observations, join attempts, and replay decisions must
|
||||||
|
move together. A partially committed authorization can expose an expired listing,
|
||||||
|
reuse a capability, or introduce an endpoint that was never authorized. V1 is a
|
||||||
|
single-active service, so it needs honest bounded in-memory behavior rather than
|
||||||
|
a database-shaped abstraction that implies unavailable durability or scale.
|
||||||
|
|
||||||
|
## Decision
|
||||||
|
|
||||||
|
`IEphemeralRendezvousStore` is the atomic boundary for directory, lease, presence,
|
||||||
|
attempt, endpoint, replay, revocation, and drain transitions. The v1 implementation
|
||||||
|
serializes each transition under one process-local lock. This deliberately favors
|
||||||
|
simple, auditable correctness at the initial 25,000-listing/10,000-attempt ceiling.
|
||||||
|
It retains only immutable listing data, opaque credential fingerprints, observed
|
||||||
|
endpoints, monotonic deadlines, and bounded idempotency/replay records.
|
||||||
|
|
||||||
|
Every collection has an independent configured ceiling. An operation checks all
|
||||||
|
of the capacity it needs before changing any collection. Exhaustion returns
|
||||||
|
`CapacityExceeded`; it does not evict live state, partially insert an operation,
|
||||||
|
or grow a fallback queue. Policy-provided per-owner listing and per-tenant active
|
||||||
|
attempt quotas are evaluated inside the same creation transition, so concurrent
|
||||||
|
requests cannot pass a check performed outside the store. New join authorization returns `ServiceUnavailable`
|
||||||
|
when the atomic store is unavailable and `Draining` once drain starts.
|
||||||
|
|
||||||
|
### Time and cleanup
|
||||||
|
|
||||||
|
Expiry uses an injected monotonic clock. Wall time is used only to return an
|
||||||
|
informational `ExpiresAt` value. Moving the wall clock forward or backward cannot
|
||||||
|
expire or prolong authority. Cleanup runs deterministically at the start of every
|
||||||
|
store operation and removes presence, attempts, listings, replay entries,
|
||||||
|
idempotency records, and revocations at their deadline. Removal of a listing also
|
||||||
|
removes its presence handle and every linked attempt before another caller can
|
||||||
|
observe the store.
|
||||||
|
|
||||||
|
### Concurrency and idempotency
|
||||||
|
|
||||||
|
- Listing registration and join-attempt creation use an owner-scoped idempotency
|
||||||
|
key plus a canonical request fingerprint. An exact duplicate returns the
|
||||||
|
original live result; reuse with different input returns `Conflict`; replay
|
||||||
|
after the resource has expired returns `Expired` until the bounded idempotency
|
||||||
|
record itself expires.
|
||||||
|
- Lease renewal is compare-and-swap by version. A stale renewal returns the latest
|
||||||
|
version as `Conflict`. Renew/delete races are serialized: renewal either commits
|
||||||
|
before deletion or observes the listing as absent.
|
||||||
|
- Host presence refresh is an atomic whole-endpoint replacement because NAT
|
||||||
|
mappings can legitimately change. Attempt capabilities are different: the
|
||||||
|
first endpoint bound for each role wins, an identical datagram is idempotent,
|
||||||
|
and a different replay is rejected. Introduction is consumed once atomically.
|
||||||
|
- Cancellation is checked before waiting for the lock and again after acquiring
|
||||||
|
it. A cancellation observed at either point makes no change. Once a synchronous
|
||||||
|
transition starts, it completes atomically and does not expose partial state.
|
||||||
|
|
||||||
|
### Visibility and revocation
|
||||||
|
|
||||||
|
A listing is visible or joinable only when its lease and authenticated UDP host
|
||||||
|
presence are both fresh. Public browsing is tenant/protocol scoped, excludes
|
||||||
|
unlisted sessions, and uses a stable listing-ID order with the contract page
|
||||||
|
ceiling. Revoking a listing or principal removes every listing, presence, and
|
||||||
|
attempt path in the same transition. A revocation is inserted before removal;
|
||||||
|
if the bounded revocation pool is full, the operation rejects without deleting
|
||||||
|
anything.
|
||||||
|
|
||||||
|
### Restart and graceful drain
|
||||||
|
|
||||||
|
A process restart creates a new store instance ID and starts empty. Old listing,
|
||||||
|
lease, attempt, endpoint, idempotency, and consumption state is not recovered.
|
||||||
|
Publishers must re-register; old callers receive typed `NotFound`, `Expired`, or
|
||||||
|
`ServiceUnavailable` outcomes rather than an ambiguous success. No database is
|
||||||
|
required or supported for the single-active MVP.
|
||||||
|
|
||||||
|
Drain is idempotent. It immediately rejects new registrations, attempts, and
|
||||||
|
lease extensions, while already-created attempts may bind endpoints and consume
|
||||||
|
their introduction during the configured window (at most 30 seconds). At the
|
||||||
|
deadline all active state is cleared atomically. Readiness is false while draining
|
||||||
|
or unavailable, and application shutdown starts drain before teardown.
|
||||||
|
|
||||||
|
## Future shared-store mapping
|
||||||
|
|
||||||
|
The interface uses explicit typed outcomes, TTLs, compare-and-swap versions,
|
||||||
|
idempotency records, and all-or-nothing multi-record transitions. A future Redis
|
||||||
|
implementation therefore requires authenticated transport, tenant-prefixed keys,
|
||||||
|
server-side scripts or transactions for each transition, TTLs based on the store's
|
||||||
|
authoritative time, and deterministic mediator routing. It must preserve these
|
||||||
|
semantics and pass the same contract tests before issue #18 may enable more than
|
||||||
|
one active instance.
|
||||||
|
|
||||||
|
## Consequences
|
||||||
|
|
||||||
|
- V1 has deterministic failure and restart behavior without durable gameplay state.
|
||||||
|
- A single lock is a measured capacity constraint, not a claim of horizontal scale.
|
||||||
|
- Transport and HTTP modules cannot bypass the store for authorization decisions.
|
||||||
|
- Operational code must treat `CapacityExceeded`, `Draining`, and
|
||||||
|
`ServiceUnavailable` as normal typed overload/availability outcomes.
|
||||||
@@ -6,9 +6,11 @@ decision requires a superseding ADR and corresponding contract/test updates.
|
|||||||
- [ADR 0001: v1 control-plane boundaries and domain](0001-v1-control-plane-boundaries.md)
|
- [ADR 0001: v1 control-plane boundaries and domain](0001-v1-control-plane-boundaries.md)
|
||||||
- [ADR 0002: publisher trust, discovery, compatibility, and fallback](0002-publisher-trust-and-connection-policy.md)
|
- [ADR 0002: publisher trust, discovery, compatibility, and fallback](0002-publisher-trust-and-connection-policy.md)
|
||||||
- [ADR 0003: state, privacy, availability, and safety budgets](0003-state-privacy-availability-and-budgets.md)
|
- [ADR 0003: state, privacy, availability, and safety budgets](0003-state-privacy-availability-and-budgets.md)
|
||||||
|
- [ADR 0004: atomic ephemeral state and single-active availability](0004-atomic-ephemeral-state.md)
|
||||||
- [Threat model](../security/threat-model.md)
|
- [Threat model](../security/threat-model.md)
|
||||||
- [Security promise and test matrix](../security/control-matrix.md)
|
- [Security promise and test matrix](../security/control-matrix.md)
|
||||||
- [Versioned HTTP and UDP contracts](../contracts/README.md)
|
- [Versioned HTTP and UDP contracts](../contracts/README.md)
|
||||||
|
- [Game provisioning and signing-key lifecycle](../security/provisioning.md)
|
||||||
|
|
||||||
These decisions intentionally leave gameplay authority, player identity,
|
These decisions intentionally leave gameplay authority, player identity,
|
||||||
simulation, persistence, social features, skill matchmaking, and gameplay
|
simulation, persistence, social features, skill matchmaking, and gameplay
|
||||||
|
|||||||
@@ -0,0 +1,84 @@
|
|||||||
|
# Game provisioning and signing-key lifecycle
|
||||||
|
|
||||||
|
Tracking: #5
|
||||||
|
|
||||||
|
Rendezvous treats game and environment scope as provisioned policy, not caller
|
||||||
|
input. Production starts only when it can build an enabled policy registry and
|
||||||
|
load at least one currently active signing key from an external secret provider.
|
||||||
|
Unknown and disabled scopes fail closed.
|
||||||
|
|
||||||
|
## Policy boundary
|
||||||
|
|
||||||
|
Each `GamePolicy` fixes the allowed:
|
||||||
|
|
||||||
|
- game/environment pair and regions;
|
||||||
|
- exact gameplay protocol versions;
|
||||||
|
- publisher trust and listing visibility modes;
|
||||||
|
- metadata keys, required keys, per-value limits, total bytes, and key count;
|
||||||
|
- listing, anonymous-host, and active-attempt quotas; and
|
||||||
|
- dedicated fallback feature policy.
|
||||||
|
|
||||||
|
Publisher authorization first authenticates a typed principal, then derives the
|
||||||
|
authoritative game/environment from that principal. Request fields are compared
|
||||||
|
for mismatch detection but never replace the authenticated scope. Dedicated
|
||||||
|
workloads, short-lived player-host grants, anonymous unlisted publishers, and
|
||||||
|
operators are distinct principal types. Operator credentials cannot be used as
|
||||||
|
publisher credentials, and anonymous publishers cannot escalate to public
|
||||||
|
visibility.
|
||||||
|
|
||||||
|
## Signed credentials
|
||||||
|
|
||||||
|
Signed principal credentials use the compact form
|
||||||
|
`rv1.<key-id>.<base64url-payload>.<base64url-HMAC-SHA256>`. The signed payload
|
||||||
|
contains version, issuer, audience, subject, principal kind, bounded scope,
|
||||||
|
issued/not-before/expiry times, and a random nonce. It contains no signing key,
|
||||||
|
reusable publisher secret, player identity, or gameplay state.
|
||||||
|
|
||||||
|
Validation is deliberately ordered and bounded:
|
||||||
|
|
||||||
|
1. enforce the v1 opaque-credential length and four-segment grammar;
|
||||||
|
2. resolve a known, non-revoked key in its verification window;
|
||||||
|
3. compare the HMAC in fixed time;
|
||||||
|
4. parse canonical bounded JSON;
|
||||||
|
5. require exact version, issuer, and audience;
|
||||||
|
6. enforce clock skew, expiry, key lifetime, principal kind, and scope shape.
|
||||||
|
|
||||||
|
Failures return typed internal reasons without echoing the credential. Logs and
|
||||||
|
metrics must record only allowlisted tenant/principal/result dimensions; token,
|
||||||
|
key, secret-reference value, and raw key material are excluded.
|
||||||
|
|
||||||
|
## Rotation and revocation
|
||||||
|
|
||||||
|
A key is bound either to operator credentials only or to allowed publisher
|
||||||
|
credential kinds for exactly one game/environment. The verifier checks this
|
||||||
|
authority after the signature, so even a compromised game grant issuer cannot
|
||||||
|
mint a valid cross-game or operator credential.
|
||||||
|
|
||||||
|
A key also has three times: `NotBefore`, `SignUntil`, and `VerifyUntil`. Issuance
|
||||||
|
picks the newest authorized non-revoked key inside its signing window. Older credentials continue
|
||||||
|
to verify until the old key's verification window ends, providing an explicit
|
||||||
|
overlap. After `VerifyUntil` they fail as retired. Configuration revocation and
|
||||||
|
runtime revocation both reject immediately. A configured revoked key retains
|
||||||
|
only its public key ID/lifecycle metadata and does not require retired secret
|
||||||
|
material to remain available.
|
||||||
|
|
||||||
|
Key IDs are non-secret base64url identifiers. Secret references are resolved
|
||||||
|
through `ISecretProvider`; production supports `env:<VARIABLE>` references and
|
||||||
|
the interface is replaceable by a deployment-specific vault/KMS adapter. The
|
||||||
|
committed development profile uses an in-memory random key identified by a
|
||||||
|
`development:ephemeral/...` reference. It never writes key material to disk and
|
||||||
|
all credentials become invalid when the process exits.
|
||||||
|
|
||||||
|
## Production configuration
|
||||||
|
|
||||||
|
`Rendezvous:Provisioning` supplies issuer, audience, clock skew, signing-key
|
||||||
|
descriptors, and game policies. A production key reference such as
|
||||||
|
`env:RENDEZVOUS_SIGNING_KEY_2026_01` expects that environment variable to hold at
|
||||||
|
least 32 random bytes encoded as base64. Missing, malformed, short, inactive, or
|
||||||
|
duplicate keys stop startup with a key-ID-only diagnostic. No game-wide secret
|
||||||
|
belongs in `appsettings`, source control, examples, the Client package, URLs,
|
||||||
|
responses, logs, metrics, exceptions, or diagnostic dumps.
|
||||||
|
|
||||||
|
Readiness becomes true only after provisioning and UDP startup both succeed.
|
||||||
|
OpenAPI generation uses a pinned build-only host and does not start listeners or
|
||||||
|
bypass provisioning in a deployed server process.
|
||||||
@@ -1,15 +1,16 @@
|
|||||||
using System.Net;
|
using System.Net;
|
||||||
using FinalFactory.Rendezvous.Contracts;
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
using FinalFactory.Rendezvous.Server.Http;
|
using FinalFactory.Rendezvous.Server.Http;
|
||||||
|
using FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
using FinalFactory.Rendezvous.Server.State;
|
||||||
using FinalFactory.Rendezvous.Server.Transport;
|
using FinalFactory.Rendezvous.Server.Transport;
|
||||||
using Microsoft.OpenApi;
|
using Microsoft.OpenApi;
|
||||||
|
|
||||||
WebApplicationBuilder builder = WebApplication.CreateBuilder(args);
|
WebApplicationBuilder builder = WebApplication.CreateBuilder(args);
|
||||||
bool isOpenApiGeneration = Environment.GetCommandLineArgs().Any(static argument =>
|
bool isOpenApiGeneration = string.Equals(
|
||||||
string.Equals(
|
System.Reflection.Assembly.GetEntryAssembly()?.GetName().Name,
|
||||||
Path.GetFileName(argument),
|
"GetDocument.Insider",
|
||||||
"dotnet-getdocument.dll",
|
StringComparison.Ordinal);
|
||||||
StringComparison.OrdinalIgnoreCase));
|
|
||||||
|
|
||||||
builder.Services.AddOpenApi("v1", static options =>
|
builder.Services.AddOpenApi("v1", static options =>
|
||||||
options.AddSchemaTransformer(static (schema, context, cancellationToken) =>
|
options.AddSchemaTransformer(static (schema, context, cancellationToken) =>
|
||||||
@@ -34,6 +35,37 @@ builder.Services.AddOpenApi("v1", static options =>
|
|||||||
}));
|
}));
|
||||||
builder.Services.ConfigureHttpJsonOptions(static options =>
|
builder.Services.ConfigureHttpJsonOptions(static options =>
|
||||||
ContractJson.Configure(options.SerializerOptions));
|
ContractJson.Configure(options.SerializerOptions));
|
||||||
|
|
||||||
|
SystemRendezvousClock rendezvousClock = new();
|
||||||
|
InMemoryEphemeralRendezvousStore stateStore = new(
|
||||||
|
new EphemeralStoreOptions(),
|
||||||
|
rendezvousClock,
|
||||||
|
rendezvousClock);
|
||||||
|
builder.Services.AddSingleton<IEphemeralRendezvousStore>(stateStore);
|
||||||
|
|
||||||
|
if (isOpenApiGeneration)
|
||||||
|
{
|
||||||
|
builder.Services.AddSingleton(new ProvisioningReadiness(false));
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
ProvisioningOptions provisioningOptions = builder.Configuration
|
||||||
|
.GetSection(ProvisioningOptions.SectionName)
|
||||||
|
.Get<ProvisioningOptions>() ?? new ProvisioningOptions();
|
||||||
|
ISecretProvider secretProvider = builder.Environment.IsDevelopment()
|
||||||
|
? new EphemeralDevelopmentSecretProvider()
|
||||||
|
: new EnvironmentSecretProvider();
|
||||||
|
ProvisioningRuntime provisioning = ProvisioningRuntime.Create(
|
||||||
|
provisioningOptions,
|
||||||
|
secretProvider,
|
||||||
|
DateTimeOffset.UtcNow);
|
||||||
|
builder.Services.AddSingleton(provisioning);
|
||||||
|
builder.Services.AddSingleton(provisioning.Policies);
|
||||||
|
builder.Services.AddSingleton(provisioning.Credentials);
|
||||||
|
builder.Services.AddSingleton(provisioning.PublisherAuthorization);
|
||||||
|
builder.Services.AddSingleton(new ProvisioningReadiness(true));
|
||||||
|
}
|
||||||
|
|
||||||
builder.Services
|
builder.Services
|
||||||
.AddOptions<UdpMediatorOptions>()
|
.AddOptions<UdpMediatorOptions>()
|
||||||
.BindConfiguration(UdpMediatorOptions.SectionName)
|
.BindConfiguration(UdpMediatorOptions.SectionName)
|
||||||
@@ -50,6 +82,7 @@ if (!isOpenApiGeneration)
|
|||||||
}
|
}
|
||||||
|
|
||||||
WebApplication app = builder.Build();
|
WebApplication app = builder.Build();
|
||||||
|
app.Lifetime.ApplicationStopping.Register(() => stateStore.BeginDrain());
|
||||||
|
|
||||||
app.MapOpenApi();
|
app.MapOpenApi();
|
||||||
app.MapRendezvousContractEndpoints();
|
app.MapRendezvousContractEndpoints();
|
||||||
@@ -61,7 +94,14 @@ app.MapGet(
|
|||||||
.WithTags("Health");
|
.WithTags("Health");
|
||||||
app.MapGet(
|
app.MapGet(
|
||||||
"/health/ready",
|
"/health/ready",
|
||||||
static (UdpMediatorService mediator) => mediator.LocalEndpoint is null
|
static (
|
||||||
|
UdpMediatorService mediator,
|
||||||
|
ProvisioningReadiness provisioning,
|
||||||
|
IEphemeralRendezvousStore state) =>
|
||||||
|
mediator.LocalEndpoint is null
|
||||||
|
|| !provisioning.IsReady
|
||||||
|
|| !state.IsAvailable
|
||||||
|
|| state.IsDraining
|
||||||
? Results.StatusCode(StatusCodes.Status503ServiceUnavailable)
|
? Results.StatusCode(StatusCodes.Status503ServiceUnavailable)
|
||||||
: Results.Ok(new HealthResponse { Status = "ready" }))
|
: Results.Ok(new HealthResponse { Status = "ready" }))
|
||||||
.Produces<HealthResponse>()
|
.Produces<HealthResponse>()
|
||||||
|
|||||||
@@ -0,0 +1,3 @@
|
|||||||
|
using System.Runtime.CompilerServices;
|
||||||
|
|
||||||
|
[assembly: InternalsVisibleTo("FinalFactory.Rendezvous.Tests")]
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
{
|
||||||
|
"$schema": "https://json.schemastore.org/launchsettings.json",
|
||||||
|
"profiles": {
|
||||||
|
"development": {
|
||||||
|
"commandName": "Project",
|
||||||
|
"dotnetRunMessages": true,
|
||||||
|
"launchBrowser": false,
|
||||||
|
"applicationUrl": "http://127.0.0.1:5096",
|
||||||
|
"environmentVariables": {
|
||||||
|
"ASPNETCORE_ENVIRONMENT": "Development"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,80 @@
|
|||||||
|
using System.Text.Json;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
internal sealed class GamePolicy
|
||||||
|
{
|
||||||
|
private readonly HashSet<uint> _protocolVersions;
|
||||||
|
private readonly HashSet<RegionId> _regions;
|
||||||
|
private readonly HashSet<ListingVisibility> _visibilityModes;
|
||||||
|
private readonly HashSet<PublisherTrustMode> _publisherTrustModes;
|
||||||
|
private readonly Dictionary<string, int> _metadataValueMaxBytes;
|
||||||
|
private readonly HashSet<string> _requiredMetadataKeys;
|
||||||
|
|
||||||
|
public GamePolicy(GamePolicyOptions options)
|
||||||
|
{
|
||||||
|
GameId = new GameId(options.GameId);
|
||||||
|
EnvironmentId = new EnvironmentId(options.EnvironmentId);
|
||||||
|
Enabled = options.Enabled;
|
||||||
|
_protocolVersions = new HashSet<uint>(options.ProtocolVersions);
|
||||||
|
_regions = options.Regions.Select(static region => new RegionId(region)).ToHashSet();
|
||||||
|
_visibilityModes = new HashSet<ListingVisibility>(options.VisibilityModes);
|
||||||
|
_publisherTrustModes = new HashSet<PublisherTrustMode>(options.PublisherTrustModes);
|
||||||
|
_metadataValueMaxBytes = new Dictionary<string, int>(
|
||||||
|
options.MetadataValueMaxBytes,
|
||||||
|
StringComparer.Ordinal);
|
||||||
|
_requiredMetadataKeys = new HashSet<string>(
|
||||||
|
options.RequiredMetadataKeys,
|
||||||
|
StringComparer.Ordinal);
|
||||||
|
MetadataMaxBytes = options.MetadataMaxBytes;
|
||||||
|
MetadataMaxKeys = options.MetadataMaxKeys;
|
||||||
|
MaxListingsPerPrincipal = options.MaxListingsPerPrincipal;
|
||||||
|
MaxAnonymousListingsPerAddress = options.MaxAnonymousListingsPerAddress;
|
||||||
|
MaxActiveJoinAttempts = options.MaxActiveJoinAttempts;
|
||||||
|
FallbackPolicy = options.FallbackPolicy;
|
||||||
|
}
|
||||||
|
|
||||||
|
public GameId GameId { get; }
|
||||||
|
public EnvironmentId EnvironmentId { get; }
|
||||||
|
public bool Enabled { get; }
|
||||||
|
public int MetadataMaxBytes { get; }
|
||||||
|
public int MetadataMaxKeys { get; }
|
||||||
|
public int MaxListingsPerPrincipal { get; }
|
||||||
|
public int MaxAnonymousListingsPerAddress { get; }
|
||||||
|
public int MaxActiveJoinAttempts { get; }
|
||||||
|
public FallbackPolicyMode FallbackPolicy { get; }
|
||||||
|
|
||||||
|
public bool AllowsProtocol(uint protocolVersion) =>
|
||||||
|
_protocolVersions.Contains(protocolVersion);
|
||||||
|
|
||||||
|
public bool AllowsRegion(RegionId regionId) => _regions.Contains(regionId);
|
||||||
|
|
||||||
|
public bool AllowsVisibility(ListingVisibility visibility) =>
|
||||||
|
_visibilityModes.Contains(visibility);
|
||||||
|
|
||||||
|
public bool AllowsPublisherTrust(PublisherTrustMode trustMode) =>
|
||||||
|
_publisherTrustModes.Contains(trustMode);
|
||||||
|
|
||||||
|
public bool AllowsMetadata(IReadOnlyDictionary<string, string>? metadata)
|
||||||
|
{
|
||||||
|
if (!ContractValidation.IsMetadataValid(metadata)
|
||||||
|
|| metadata!.Count > MetadataMaxKeys
|
||||||
|
|| !_requiredMetadataKeys.IsSubsetOf(metadata.Keys))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach (KeyValuePair<string, string> item in metadata)
|
||||||
|
{
|
||||||
|
if (!_metadataValueMaxBytes.TryGetValue(item.Key, out int maximumBytes)
|
||||||
|
|| !ContractValidation.IsUtf8LengthWithin(item.Value, maximumBytes))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return JsonSerializer.SerializeToUtf8Bytes(metadata, ContractJson.Options).Length
|
||||||
|
<= MetadataMaxBytes;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,118 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
internal sealed class GamePolicyRegistry
|
||||||
|
{
|
||||||
|
private readonly Dictionary<(GameId Game, EnvironmentId Environment), GamePolicy> _policies;
|
||||||
|
|
||||||
|
private GamePolicyRegistry(
|
||||||
|
Dictionary<(GameId Game, EnvironmentId Environment), GamePolicy> policies) =>
|
||||||
|
_policies = policies;
|
||||||
|
|
||||||
|
public bool HasEnabledPolicies => _policies.Values.Any(static policy => policy.Enabled);
|
||||||
|
public IEnumerable<GamePolicy> EnabledPolicies =>
|
||||||
|
_policies.Values.Where(static policy => policy.Enabled);
|
||||||
|
|
||||||
|
public static GamePolicyRegistry Create(IEnumerable<GamePolicyOptions> options)
|
||||||
|
{
|
||||||
|
GamePolicyOptions[] configuredPolicies = options.ToArray();
|
||||||
|
if (configuredPolicies.Length > ProvisioningLimits.MaxGamePolicies)
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"At most {ProvisioningLimits.MaxGamePolicies} game policies may be configured.");
|
||||||
|
}
|
||||||
|
|
||||||
|
Dictionary<(GameId Game, EnvironmentId Environment), GamePolicy> policies = [];
|
||||||
|
foreach (GamePolicyOptions policyOptions in configuredPolicies)
|
||||||
|
{
|
||||||
|
Validate(policyOptions);
|
||||||
|
GamePolicy policy = new(policyOptions);
|
||||||
|
if (!policies.TryAdd((policy.GameId, policy.EnvironmentId), policy))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Duplicate game/environment policy: {policy.GameId}/{policy.EnvironmentId}.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return new GamePolicyRegistry(policies);
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool TryGet(
|
||||||
|
GameId gameId,
|
||||||
|
EnvironmentId environmentId,
|
||||||
|
out GamePolicy? policy)
|
||||||
|
{
|
||||||
|
if (_policies.TryGetValue((gameId, environmentId), out GamePolicy? candidate)
|
||||||
|
&& candidate.Enabled)
|
||||||
|
{
|
||||||
|
policy = candidate;
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
policy = null;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void Validate(GamePolicyOptions options)
|
||||||
|
{
|
||||||
|
if (!GameId.TryParse(options.GameId, out _)
|
||||||
|
|| !EnvironmentId.TryParse(options.EnvironmentId, out _))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
"Game policies require valid game and environment IDs.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (options.ProtocolVersions.Count is 0 or > ProvisioningLimits.MaxProtocolVersionsPerPolicy
|
||||||
|
|| options.ProtocolVersions.Contains(0)
|
||||||
|
|| options.ProtocolVersions.Count != options.ProtocolVersions.Distinct().Count())
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Policy {options.GameId}/{options.EnvironmentId} requires unique non-zero protocol versions.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (options.Regions.Count is 0 or > ProvisioningLimits.MaxRegionsPerPolicy
|
||||||
|
|| options.Regions.Any(static region => !RegionId.TryParse(region, out _))
|
||||||
|
|| options.Regions.Count != options.Regions.Distinct(StringComparer.Ordinal).Count())
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Policy {options.GameId}/{options.EnvironmentId} requires unique valid regions.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (options.VisibilityModes.Count == 0
|
||||||
|
|| options.VisibilityModes.Any(static mode => !Enum.IsDefined(mode))
|
||||||
|
|| options.VisibilityModes.Count != options.VisibilityModes.Distinct().Count()
|
||||||
|
|| options.PublisherTrustModes.Count == 0
|
||||||
|
|| options.PublisherTrustModes.Any(static mode => !Enum.IsDefined(mode))
|
||||||
|
|| options.PublisherTrustModes.Count != options.PublisherTrustModes.Distinct().Count())
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Policy {options.GameId}/{options.EnvironmentId} requires valid visibility and trust modes.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (options.MetadataMaxBytes is < 2 or > ContractLimits.MetadataMaxBytes
|
||||||
|
|| options.MetadataMaxKeys is < 0 or > ContractLimits.MetadataMaxKeys
|
||||||
|
|| options.MetadataValueMaxBytes.Count > options.MetadataMaxKeys
|
||||||
|
|| options.MetadataValueMaxBytes.Any(static item =>
|
||||||
|
string.IsNullOrWhiteSpace(item.Key)
|
||||||
|
|| !ContractValidation.IsUtf8LengthWithin(item.Key, ContractLimits.MetadataKeyMaxBytes)
|
||||||
|
|| item.Value is < 0 or > ContractLimits.MetadataValueMaxBytes)
|
||||||
|
|| options.RequiredMetadataKeys.Any(key =>
|
||||||
|
!options.MetadataValueMaxBytes.ContainsKey(key)))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Policy {options.GameId}/{options.EnvironmentId} has an invalid metadata schema.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (options.MaxListingsPerPrincipal is < 1 or > ProvisioningLimits.MaxListingsPerPrincipal
|
||||||
|
|| options.MaxAnonymousListingsPerAddress < 0
|
||||||
|
|| options.MaxAnonymousListingsPerAddress > options.MaxListingsPerPrincipal
|
||||||
|
|| options.MaxActiveJoinAttempts is < 1
|
||||||
|
or > ProvisioningLimits.MaxActiveJoinAttemptsPerPolicy
|
||||||
|
|| !Enum.IsDefined(options.FallbackPolicy))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Policy {options.GameId}/{options.EnvironmentId} has invalid quotas or fallback policy.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,451 @@
|
|||||||
|
using System.Security.Cryptography;
|
||||||
|
using System.Text;
|
||||||
|
using System.Text.Json;
|
||||||
|
using System.Text.Json.Serialization;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
internal sealed class PrincipalCredentialService
|
||||||
|
{
|
||||||
|
private const string TokenPrefix = "rv1";
|
||||||
|
private readonly string _issuer;
|
||||||
|
private readonly string _audience;
|
||||||
|
private readonly TimeSpan _clockSkew;
|
||||||
|
private readonly SigningKeyRing _keyRing;
|
||||||
|
|
||||||
|
public PrincipalCredentialService(
|
||||||
|
string issuer,
|
||||||
|
string audience,
|
||||||
|
TimeSpan clockSkew,
|
||||||
|
SigningKeyRing keyRing)
|
||||||
|
{
|
||||||
|
if (!IsSafeAuthority(issuer) || !IsSafeAuthority(audience))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
"Credential issuer and audience are required.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (clockSkew < TimeSpan.Zero || clockSkew > TimeSpan.FromSeconds(30))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
"Credential clock skew must be between zero and 30 seconds.");
|
||||||
|
}
|
||||||
|
|
||||||
|
_issuer = issuer;
|
||||||
|
_audience = audience;
|
||||||
|
_clockSkew = clockSkew;
|
||||||
|
_keyRing = keyRing;
|
||||||
|
}
|
||||||
|
|
||||||
|
public string Issue(AuthenticatedPrincipal principal, DateTimeOffset now)
|
||||||
|
{
|
||||||
|
if (!IsSafeSubject(principal.Subject))
|
||||||
|
{
|
||||||
|
throw new ArgumentException(
|
||||||
|
"Principal subjects must be 1–128 visible ASCII characters.",
|
||||||
|
nameof(principal));
|
||||||
|
}
|
||||||
|
|
||||||
|
if (principal.ExpiresAt <= now)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("Cannot issue an already-expired principal.", nameof(principal));
|
||||||
|
}
|
||||||
|
|
||||||
|
CredentialPayload payload = CreatePayload(principal, now);
|
||||||
|
if (CreatePrincipal(payload, principal.ExpiresAt) is null)
|
||||||
|
{
|
||||||
|
throw new ArgumentException(
|
||||||
|
"The principal contains an invalid kind or scope.",
|
||||||
|
nameof(principal));
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!_keyRing.TryGetSigningKey(
|
||||||
|
now,
|
||||||
|
payload.Kind,
|
||||||
|
payload.GameId,
|
||||||
|
payload.EnvironmentId,
|
||||||
|
out SigningKey? signingKey)
|
||||||
|
|| signingKey is null)
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException("No active signing key is available.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (principal.ExpiresAt > signingKey.VerifyUntil)
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException(
|
||||||
|
"The active key verification window is shorter than the credential lifetime.");
|
||||||
|
}
|
||||||
|
|
||||||
|
string encodedPayload = Base64Url.Encode(
|
||||||
|
JsonSerializer.SerializeToUtf8Bytes(payload, ContractJson.Options));
|
||||||
|
string signedContent = $"{TokenPrefix}.{signingKey.KeyId}.{encodedPayload}";
|
||||||
|
string signature = Base64Url.Encode(signingKey.Sign(signedContent));
|
||||||
|
string token = $"{signedContent}.{signature}";
|
||||||
|
if (!ContractValidation.IsOpaqueHttpCredentialValid(token))
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException("The signed credential exceeds the v1 size limit.");
|
||||||
|
}
|
||||||
|
|
||||||
|
return token;
|
||||||
|
}
|
||||||
|
|
||||||
|
public CredentialValidationResult Validate(string? token, DateTimeOffset now)
|
||||||
|
{
|
||||||
|
if (!ContractValidation.IsOpaqueHttpCredentialValid(token))
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.Malformed);
|
||||||
|
}
|
||||||
|
|
||||||
|
string[] segments = token!.Split('.');
|
||||||
|
if (segments.Length != 4
|
||||||
|
|| !string.Equals(segments[0], TokenPrefix, StringComparison.Ordinal)
|
||||||
|
|| segments[1].Length == 0)
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.Malformed);
|
||||||
|
}
|
||||||
|
|
||||||
|
VerificationKeyLookup lookup = _keyRing.FindVerificationKey(
|
||||||
|
segments[1],
|
||||||
|
now,
|
||||||
|
out SigningKey? signingKey);
|
||||||
|
if (lookup != VerificationKeyLookup.Available || signingKey is null)
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(lookup switch
|
||||||
|
{
|
||||||
|
VerificationKeyLookup.Revoked => CredentialValidationError.KeyRevoked,
|
||||||
|
VerificationKeyLookup.NotYetValid => CredentialValidationError.KeyNotYetValid,
|
||||||
|
VerificationKeyLookup.Retired => CredentialValidationError.KeyRetired,
|
||||||
|
_ => CredentialValidationError.UnknownKey,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!Base64Url.TryDecode(segments[3], out byte[]? suppliedSignature))
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.Malformed);
|
||||||
|
}
|
||||||
|
|
||||||
|
string signedContent = $"{segments[0]}.{segments[1]}.{segments[2]}";
|
||||||
|
byte[] expectedSignature = signingKey.Sign(signedContent);
|
||||||
|
bool signatureMatches = suppliedSignature.Length == expectedSignature.Length
|
||||||
|
&& CryptographicOperations.FixedTimeEquals(suppliedSignature, expectedSignature);
|
||||||
|
CryptographicOperations.ZeroMemory(suppliedSignature);
|
||||||
|
CryptographicOperations.ZeroMemory(expectedSignature);
|
||||||
|
if (!signatureMatches)
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.SignatureInvalid);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!Base64Url.TryDecode(segments[2], out byte[]? encodedPayload))
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.Malformed);
|
||||||
|
}
|
||||||
|
|
||||||
|
CredentialPayload? payload;
|
||||||
|
try
|
||||||
|
{
|
||||||
|
payload = JsonSerializer.Deserialize<CredentialPayload>(
|
||||||
|
encodedPayload,
|
||||||
|
ContractJson.Options);
|
||||||
|
}
|
||||||
|
catch (JsonException)
|
||||||
|
{
|
||||||
|
payload = null;
|
||||||
|
}
|
||||||
|
finally
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(encodedPayload);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (payload is null || payload.Version != ContractLimits.ContractVersion)
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.PayloadInvalid);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!string.Equals(payload.Issuer, _issuer, StringComparison.Ordinal))
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.IssuerMismatch);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!string.Equals(payload.Audience, _audience, StringComparison.Ordinal))
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.AudienceMismatch);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!signingKey.Authorizes(payload.Kind, payload.GameId, payload.EnvironmentId))
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.KeyScopeMismatch);
|
||||||
|
}
|
||||||
|
|
||||||
|
DateTimeOffset issuedAt;
|
||||||
|
DateTimeOffset notBefore;
|
||||||
|
DateTimeOffset expiresAt;
|
||||||
|
try
|
||||||
|
{
|
||||||
|
issuedAt = DateTimeOffset.FromUnixTimeSeconds(payload.IssuedAtUnixSeconds);
|
||||||
|
notBefore = DateTimeOffset.FromUnixTimeSeconds(payload.NotBeforeUnixSeconds);
|
||||||
|
expiresAt = DateTimeOffset.FromUnixTimeSeconds(payload.ExpiresAtUnixSeconds);
|
||||||
|
}
|
||||||
|
catch (ArgumentOutOfRangeException)
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.PayloadInvalid);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (issuedAt > now + _clockSkew || notBefore > now + _clockSkew)
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.NotYetValid);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (expiresAt <= now - _clockSkew || expiresAt <= notBefore)
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.Expired);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (issuedAt > notBefore
|
||||||
|
|| issuedAt < signingKey.NotBefore - _clockSkew
|
||||||
|
|| expiresAt > signingKey.VerifyUntil)
|
||||||
|
{
|
||||||
|
return CredentialValidationResult.Invalid(CredentialValidationError.PayloadInvalid);
|
||||||
|
}
|
||||||
|
|
||||||
|
AuthenticatedPrincipal? principal = CreatePrincipal(payload, expiresAt);
|
||||||
|
return principal is null
|
||||||
|
? CredentialValidationResult.Invalid(CredentialValidationError.ScopeInvalid)
|
||||||
|
: CredentialValidationResult.Valid(principal);
|
||||||
|
}
|
||||||
|
|
||||||
|
public override string ToString() => "[PrincipalCredentialService: key material and credentials redacted]";
|
||||||
|
|
||||||
|
private CredentialPayload CreatePayload(AuthenticatedPrincipal principal, DateTimeOffset now)
|
||||||
|
{
|
||||||
|
CredentialPayload payload = new()
|
||||||
|
{
|
||||||
|
Version = ContractLimits.ContractVersion,
|
||||||
|
Issuer = _issuer,
|
||||||
|
Audience = _audience,
|
||||||
|
Subject = principal.Subject,
|
||||||
|
IssuedAtUnixSeconds = now.ToUnixTimeSeconds(),
|
||||||
|
NotBeforeUnixSeconds = now.ToUnixTimeSeconds(),
|
||||||
|
ExpiresAtUnixSeconds = principal.ExpiresAt.ToUnixTimeSeconds(),
|
||||||
|
Nonce = Guid.NewGuid().ToString("N"),
|
||||||
|
};
|
||||||
|
|
||||||
|
switch (principal)
|
||||||
|
{
|
||||||
|
case DedicatedPublisherPrincipal publisher:
|
||||||
|
SetPublisherPayload(payload, publisher, PrincipalCredentialKind.DedicatedPublisher);
|
||||||
|
break;
|
||||||
|
case PlayerHostGrantPrincipal publisher:
|
||||||
|
SetPublisherPayload(payload, publisher, PrincipalCredentialKind.PlayerHostGrant);
|
||||||
|
break;
|
||||||
|
case OperatorPrincipal operatorPrincipal:
|
||||||
|
payload.Kind = PrincipalCredentialKind.Operator;
|
||||||
|
payload.Permissions = operatorPrincipal.Permissions.Order().ToList();
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
throw new ArgumentException(
|
||||||
|
"Anonymous principals cannot receive reusable signed credentials.",
|
||||||
|
nameof(principal));
|
||||||
|
}
|
||||||
|
|
||||||
|
return payload;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void SetPublisherPayload(
|
||||||
|
CredentialPayload payload,
|
||||||
|
IPublisherPrincipal publisher,
|
||||||
|
PrincipalCredentialKind kind)
|
||||||
|
{
|
||||||
|
payload.Kind = kind;
|
||||||
|
payload.GameId = publisher.GameId.ToString();
|
||||||
|
payload.EnvironmentId = publisher.EnvironmentId.ToString();
|
||||||
|
payload.Regions = publisher.AllowedRegions
|
||||||
|
.Select(static region => region.ToString())
|
||||||
|
.Order(StringComparer.Ordinal)
|
||||||
|
.ToList();
|
||||||
|
}
|
||||||
|
|
||||||
|
private static AuthenticatedPrincipal? CreatePrincipal(
|
||||||
|
CredentialPayload payload,
|
||||||
|
DateTimeOffset expiresAt)
|
||||||
|
{
|
||||||
|
if (!IsSafeSubject(payload.Subject)
|
||||||
|
|| !Guid.TryParseExact(payload.Nonce, "N", out Guid nonce)
|
||||||
|
|| nonce == Guid.Empty)
|
||||||
|
{
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (payload.Kind == PrincipalCredentialKind.Operator)
|
||||||
|
{
|
||||||
|
if (payload.GameId is not null
|
||||||
|
|| payload.EnvironmentId is not null
|
||||||
|
|| payload.Regions.Count != 0
|
||||||
|
|| payload.Permissions.Count == 0
|
||||||
|
|| payload.Permissions.Any(static permission => !Enum.IsDefined(permission))
|
||||||
|
|| payload.Permissions.Count != payload.Permissions.Distinct().Count())
|
||||||
|
{
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
return new OperatorPrincipal(
|
||||||
|
payload.Subject,
|
||||||
|
expiresAt,
|
||||||
|
new HashSet<OperatorPermission>(payload.Permissions));
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!GameId.TryParse(payload.GameId, out GameId gameId)
|
||||||
|
|| !EnvironmentId.TryParse(payload.EnvironmentId, out EnvironmentId environmentId)
|
||||||
|
|| payload.Regions.Count == 0
|
||||||
|
|| payload.Regions.Any(static region => !RegionId.TryParse(region, out _))
|
||||||
|
|| payload.Regions.Count != payload.Regions.Distinct(StringComparer.Ordinal).Count()
|
||||||
|
|| payload.Permissions.Count != 0)
|
||||||
|
{
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
HashSet<RegionId> regions = payload.Regions.Select(static region => new RegionId(region)).ToHashSet();
|
||||||
|
return payload.Kind switch
|
||||||
|
{
|
||||||
|
PrincipalCredentialKind.DedicatedPublisher => new DedicatedPublisherPrincipal(
|
||||||
|
payload.Subject,
|
||||||
|
expiresAt,
|
||||||
|
gameId,
|
||||||
|
environmentId,
|
||||||
|
regions),
|
||||||
|
PrincipalCredentialKind.PlayerHostGrant => new PlayerHostGrantPrincipal(
|
||||||
|
payload.Subject,
|
||||||
|
expiresAt,
|
||||||
|
gameId,
|
||||||
|
environmentId,
|
||||||
|
regions),
|
||||||
|
_ => null,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool IsSafeSubject(string? value) =>
|
||||||
|
value is not null
|
||||||
|
&& value.Length is > 0 and <= 128
|
||||||
|
&& value.All(static character => character is >= '!' and <= '~');
|
||||||
|
|
||||||
|
private static bool IsSafeAuthority(string? value) =>
|
||||||
|
value is not null
|
||||||
|
&& value.Length is > 0 and <= 128
|
||||||
|
&& value.All(static character => character is >= '!' and <= '~');
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class CredentialPayload
|
||||||
|
{
|
||||||
|
[JsonRequired]
|
||||||
|
public int Version { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string Issuer { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string Audience { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string Subject { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public PrincipalCredentialKind Kind { get; set; }
|
||||||
|
|
||||||
|
public string? GameId { get; set; }
|
||||||
|
public string? EnvironmentId { get; set; }
|
||||||
|
public List<string> Regions { get; set; } = [];
|
||||||
|
public List<OperatorPermission> Permissions { get; set; } = [];
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public long IssuedAtUnixSeconds { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public long NotBeforeUnixSeconds { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public long ExpiresAtUnixSeconds { get; set; }
|
||||||
|
|
||||||
|
[JsonRequired]
|
||||||
|
public string Nonce { get; set; } = string.Empty;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal readonly record struct CredentialValidationResult(
|
||||||
|
bool IsValid,
|
||||||
|
CredentialValidationError Error,
|
||||||
|
AuthenticatedPrincipal? Principal)
|
||||||
|
{
|
||||||
|
public static CredentialValidationResult Valid(AuthenticatedPrincipal principal) =>
|
||||||
|
new(true, CredentialValidationError.None, principal);
|
||||||
|
|
||||||
|
public static CredentialValidationResult Invalid(CredentialValidationError error) =>
|
||||||
|
new(false, error, null);
|
||||||
|
|
||||||
|
public override string ToString() => $"[CredentialValidation: {Error}, credential redacted]";
|
||||||
|
}
|
||||||
|
|
||||||
|
internal enum CredentialValidationError
|
||||||
|
{
|
||||||
|
None = 0,
|
||||||
|
Malformed = 1,
|
||||||
|
UnknownKey = 2,
|
||||||
|
KeyRevoked = 3,
|
||||||
|
KeyNotYetValid = 4,
|
||||||
|
KeyRetired = 5,
|
||||||
|
SignatureInvalid = 6,
|
||||||
|
PayloadInvalid = 7,
|
||||||
|
IssuerMismatch = 8,
|
||||||
|
AudienceMismatch = 9,
|
||||||
|
KeyScopeMismatch = 10,
|
||||||
|
NotYetValid = 11,
|
||||||
|
Expired = 12,
|
||||||
|
ScopeInvalid = 13,
|
||||||
|
}
|
||||||
|
|
||||||
|
internal static class Base64Url
|
||||||
|
{
|
||||||
|
public static string Encode(ReadOnlySpan<byte> bytes) => Convert
|
||||||
|
.ToBase64String(bytes)
|
||||||
|
.TrimEnd('=')
|
||||||
|
.Replace('+', '-')
|
||||||
|
.Replace('/', '_');
|
||||||
|
|
||||||
|
public static bool TryDecode(string value, out byte[] bytes)
|
||||||
|
{
|
||||||
|
bytes = [];
|
||||||
|
if (string.IsNullOrEmpty(value)
|
||||||
|
|| value.Any(static character =>
|
||||||
|
character is not (>= 'A' and <= 'Z')
|
||||||
|
and not (>= 'a' and <= 'z')
|
||||||
|
and not (>= '0' and <= '9')
|
||||||
|
and not '-'
|
||||||
|
and not '_'))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
string padded = value.Replace('-', '+').Replace('_', '/');
|
||||||
|
int remainder = padded.Length % 4;
|
||||||
|
if (remainder == 1)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
padded += remainder switch
|
||||||
|
{
|
||||||
|
0 => string.Empty,
|
||||||
|
2 => "==",
|
||||||
|
3 => "=",
|
||||||
|
_ => string.Empty,
|
||||||
|
};
|
||||||
|
|
||||||
|
try
|
||||||
|
{
|
||||||
|
bytes = Convert.FromBase64String(padded);
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
catch (FormatException)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,107 @@
|
|||||||
|
using System.Collections.Frozen;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
internal abstract record AuthenticatedPrincipal(
|
||||||
|
string Subject,
|
||||||
|
DateTimeOffset ExpiresAt);
|
||||||
|
|
||||||
|
internal interface IPublisherPrincipal
|
||||||
|
{
|
||||||
|
string Subject { get; }
|
||||||
|
DateTimeOffset ExpiresAt { get; }
|
||||||
|
GameId GameId { get; }
|
||||||
|
EnvironmentId EnvironmentId { get; }
|
||||||
|
PublisherTrustMode TrustMode { get; }
|
||||||
|
IReadOnlySet<RegionId> AllowedRegions { get; }
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record DedicatedPublisherPrincipal : AuthenticatedPrincipal, IPublisherPrincipal
|
||||||
|
{
|
||||||
|
public DedicatedPublisherPrincipal(
|
||||||
|
string subject,
|
||||||
|
DateTimeOffset expiresAt,
|
||||||
|
GameId gameId,
|
||||||
|
EnvironmentId environmentId,
|
||||||
|
IEnumerable<RegionId> allowedRegions)
|
||||||
|
: base(subject, expiresAt)
|
||||||
|
{
|
||||||
|
GameId = gameId;
|
||||||
|
EnvironmentId = environmentId;
|
||||||
|
AllowedRegions = allowedRegions.ToFrozenSet();
|
||||||
|
}
|
||||||
|
|
||||||
|
public GameId GameId { get; }
|
||||||
|
public EnvironmentId EnvironmentId { get; }
|
||||||
|
public IReadOnlySet<RegionId> AllowedRegions { get; }
|
||||||
|
public PublisherTrustMode TrustMode => PublisherTrustMode.ManagedDedicated;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record PlayerHostGrantPrincipal : AuthenticatedPrincipal, IPublisherPrincipal
|
||||||
|
{
|
||||||
|
public PlayerHostGrantPrincipal(
|
||||||
|
string subject,
|
||||||
|
DateTimeOffset expiresAt,
|
||||||
|
GameId gameId,
|
||||||
|
EnvironmentId environmentId,
|
||||||
|
IEnumerable<RegionId> allowedRegions)
|
||||||
|
: base(subject, expiresAt)
|
||||||
|
{
|
||||||
|
GameId = gameId;
|
||||||
|
EnvironmentId = environmentId;
|
||||||
|
AllowedRegions = allowedRegions.ToFrozenSet();
|
||||||
|
}
|
||||||
|
|
||||||
|
public GameId GameId { get; }
|
||||||
|
public EnvironmentId EnvironmentId { get; }
|
||||||
|
public IReadOnlySet<RegionId> AllowedRegions { get; }
|
||||||
|
public PublisherTrustMode TrustMode => PublisherTrustMode.PlayerGrant;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record AnonymousUnlistedPrincipal : AuthenticatedPrincipal, IPublisherPrincipal
|
||||||
|
{
|
||||||
|
public AnonymousUnlistedPrincipal(
|
||||||
|
string subject,
|
||||||
|
DateTimeOffset expiresAt,
|
||||||
|
GameId gameId,
|
||||||
|
EnvironmentId environmentId,
|
||||||
|
IEnumerable<RegionId> allowedRegions)
|
||||||
|
: base(subject, expiresAt)
|
||||||
|
{
|
||||||
|
GameId = gameId;
|
||||||
|
EnvironmentId = environmentId;
|
||||||
|
AllowedRegions = allowedRegions.ToFrozenSet();
|
||||||
|
}
|
||||||
|
|
||||||
|
public GameId GameId { get; }
|
||||||
|
public EnvironmentId EnvironmentId { get; }
|
||||||
|
public IReadOnlySet<RegionId> AllowedRegions { get; }
|
||||||
|
public PublisherTrustMode TrustMode => PublisherTrustMode.AnonymousUnlisted;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record OperatorPrincipal : AuthenticatedPrincipal
|
||||||
|
{
|
||||||
|
public OperatorPrincipal(
|
||||||
|
string subject,
|
||||||
|
DateTimeOffset expiresAt,
|
||||||
|
IEnumerable<OperatorPermission> permissions)
|
||||||
|
: base(subject, expiresAt) => Permissions = permissions.ToFrozenSet();
|
||||||
|
|
||||||
|
public IReadOnlySet<OperatorPermission> Permissions { get; }
|
||||||
|
}
|
||||||
|
|
||||||
|
internal enum OperatorPermission
|
||||||
|
{
|
||||||
|
ReadPolicy = 1,
|
||||||
|
ManagePolicy = 2,
|
||||||
|
RevokePublisher = 3,
|
||||||
|
RotateKeys = 4,
|
||||||
|
}
|
||||||
|
|
||||||
|
internal enum PrincipalCredentialKind
|
||||||
|
{
|
||||||
|
DedicatedPublisher = 1,
|
||||||
|
PlayerHostGrant = 2,
|
||||||
|
Operator = 3,
|
||||||
|
}
|
||||||
@@ -0,0 +1,71 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
internal sealed class ProvisioningOptions
|
||||||
|
{
|
||||||
|
public const string SectionName = "Rendezvous:Provisioning";
|
||||||
|
|
||||||
|
public string Issuer { get; set; } = string.Empty;
|
||||||
|
public string Audience { get; set; } = string.Empty;
|
||||||
|
public int ClockSkewSeconds { get; set; } = 30;
|
||||||
|
public List<SigningKeyOptions> SigningKeys { get; set; } = [];
|
||||||
|
public List<GamePolicyOptions> Games { get; set; } = [];
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class SigningKeyOptions
|
||||||
|
{
|
||||||
|
public string KeyId { get; set; } = string.Empty;
|
||||||
|
public string SecretReference { get; set; } = string.Empty;
|
||||||
|
public List<PrincipalCredentialKind> CredentialKinds { get; set; } = [];
|
||||||
|
public string? GameId { get; set; }
|
||||||
|
public string? EnvironmentId { get; set; }
|
||||||
|
public DateTimeOffset NotBefore { get; set; }
|
||||||
|
public DateTimeOffset SignUntil { get; set; }
|
||||||
|
public DateTimeOffset VerifyUntil { get; set; }
|
||||||
|
public bool Revoked { get; set; }
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class GamePolicyOptions
|
||||||
|
{
|
||||||
|
public string GameId { get; set; } = string.Empty;
|
||||||
|
public string EnvironmentId { get; set; } = string.Empty;
|
||||||
|
public bool Enabled { get; set; } = true;
|
||||||
|
public List<uint> ProtocolVersions { get; set; } = [];
|
||||||
|
public List<string> Regions { get; set; } = [];
|
||||||
|
public List<ListingVisibility> VisibilityModes { get; set; } = [];
|
||||||
|
public List<PublisherTrustMode> PublisherTrustModes { get; set; } = [];
|
||||||
|
public Dictionary<string, int> MetadataValueMaxBytes { get; set; } =
|
||||||
|
new(StringComparer.Ordinal);
|
||||||
|
public List<string> RequiredMetadataKeys { get; set; } = [];
|
||||||
|
public int MetadataMaxBytes { get; set; } = ContractLimits.MetadataMaxBytes;
|
||||||
|
public int MetadataMaxKeys { get; set; } = ContractLimits.MetadataMaxKeys;
|
||||||
|
public int MaxListingsPerPrincipal { get; set; } = 100;
|
||||||
|
public int MaxAnonymousListingsPerAddress { get; set; } = 2;
|
||||||
|
public int MaxActiveJoinAttempts { get; set; } = 1_000;
|
||||||
|
public FallbackPolicyMode FallbackPolicy { get; set; }
|
||||||
|
}
|
||||||
|
|
||||||
|
internal enum FallbackPolicyMode
|
||||||
|
{
|
||||||
|
Disabled = 0,
|
||||||
|
DedicatedEndpointAllowed = 1,
|
||||||
|
}
|
||||||
|
|
||||||
|
internal static class ProvisioningLimits
|
||||||
|
{
|
||||||
|
public const int MaxGamePolicies = 1_024;
|
||||||
|
public const int MaxSigningKeys = 128;
|
||||||
|
public const int MaxProtocolVersionsPerPolicy = 64;
|
||||||
|
public const int MaxRegionsPerPolicy = 32;
|
||||||
|
public const int MaxListingsPerPrincipal = 25_000;
|
||||||
|
public const int MaxActiveJoinAttemptsPerPolicy = 10_000;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class ProvisioningConfigurationException : Exception
|
||||||
|
{
|
||||||
|
public ProvisioningConfigurationException(string message)
|
||||||
|
: base(message)
|
||||||
|
{
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,120 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
internal sealed class ProvisioningRuntime : IDisposable
|
||||||
|
{
|
||||||
|
private readonly IDisposable? _secretProviderLifetime;
|
||||||
|
|
||||||
|
private ProvisioningRuntime(
|
||||||
|
GamePolicyRegistry policies,
|
||||||
|
SigningKeyRing signingKeys,
|
||||||
|
PrincipalCredentialService credentials,
|
||||||
|
PublisherAuthorizationService publisherAuthorization,
|
||||||
|
IDisposable? secretProviderLifetime)
|
||||||
|
{
|
||||||
|
Policies = policies;
|
||||||
|
SigningKeys = signingKeys;
|
||||||
|
Credentials = credentials;
|
||||||
|
PublisherAuthorization = publisherAuthorization;
|
||||||
|
_secretProviderLifetime = secretProviderLifetime;
|
||||||
|
}
|
||||||
|
|
||||||
|
public GamePolicyRegistry Policies { get; }
|
||||||
|
public SigningKeyRing SigningKeys { get; }
|
||||||
|
public PrincipalCredentialService Credentials { get; }
|
||||||
|
public PublisherAuthorizationService PublisherAuthorization { get; }
|
||||||
|
|
||||||
|
public static ProvisioningRuntime Create(
|
||||||
|
ProvisioningOptions options,
|
||||||
|
ISecretProvider secretProvider,
|
||||||
|
DateTimeOffset now)
|
||||||
|
{
|
||||||
|
try
|
||||||
|
{
|
||||||
|
SigningKeyRing signingKeys = SigningKeyRing.Create(options.SigningKeys, secretProvider);
|
||||||
|
try
|
||||||
|
{
|
||||||
|
if (!signingKeys.HasKeys
|
||||||
|
|| !signingKeys.HasActiveSigningKey(now))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
"At least one active signing key with available production key material is required.");
|
||||||
|
}
|
||||||
|
|
||||||
|
GamePolicyRegistry policies = GamePolicyRegistry.Create(options.Games);
|
||||||
|
if (!policies.HasEnabledPolicies)
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
"At least one enabled game/environment policy is required.");
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach (GamePolicy policy in policies.EnabledPolicies)
|
||||||
|
{
|
||||||
|
RequirePublisherKey(
|
||||||
|
signingKeys,
|
||||||
|
policy,
|
||||||
|
PublisherTrustMode.ManagedDedicated,
|
||||||
|
PrincipalCredentialKind.DedicatedPublisher,
|
||||||
|
now);
|
||||||
|
RequirePublisherKey(
|
||||||
|
signingKeys,
|
||||||
|
policy,
|
||||||
|
PublisherTrustMode.PlayerGrant,
|
||||||
|
PrincipalCredentialKind.PlayerHostGrant,
|
||||||
|
now);
|
||||||
|
}
|
||||||
|
|
||||||
|
PrincipalCredentialService credentials = new(
|
||||||
|
options.Issuer,
|
||||||
|
options.Audience,
|
||||||
|
TimeSpan.FromSeconds(options.ClockSkewSeconds),
|
||||||
|
signingKeys);
|
||||||
|
PublisherAuthorizationService authorization = new(policies);
|
||||||
|
return new ProvisioningRuntime(
|
||||||
|
policies,
|
||||||
|
signingKeys,
|
||||||
|
credentials,
|
||||||
|
authorization,
|
||||||
|
secretProvider as IDisposable);
|
||||||
|
}
|
||||||
|
catch
|
||||||
|
{
|
||||||
|
signingKeys.Dispose();
|
||||||
|
throw;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
catch
|
||||||
|
{
|
||||||
|
(secretProvider as IDisposable)?.Dispose();
|
||||||
|
throw;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public void Dispose()
|
||||||
|
{
|
||||||
|
SigningKeys.Dispose();
|
||||||
|
_secretProviderLifetime?.Dispose();
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void RequirePublisherKey(
|
||||||
|
SigningKeyRing signingKeys,
|
||||||
|
GamePolicy policy,
|
||||||
|
PublisherTrustMode trustMode,
|
||||||
|
PrincipalCredentialKind credentialKind,
|
||||||
|
DateTimeOffset now)
|
||||||
|
{
|
||||||
|
if (policy.AllowsPublisherTrust(trustMode)
|
||||||
|
&& !signingKeys.HasActiveSigningKey(
|
||||||
|
now,
|
||||||
|
credentialKind,
|
||||||
|
policy.GameId.ToString(),
|
||||||
|
policy.EnvironmentId.ToString()))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Policy {policy.GameId}/{policy.EnvironmentId} has no active {credentialKind} key.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record ProvisioningReadiness(bool IsReady);
|
||||||
@@ -0,0 +1,119 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
internal sealed class PublisherAuthorizationService(GamePolicyRegistry policies)
|
||||||
|
{
|
||||||
|
public PublisherAuthorizationResult Authorize(
|
||||||
|
AuthenticatedPrincipal principal,
|
||||||
|
GameId requestedGameId,
|
||||||
|
EnvironmentId requestedEnvironmentId,
|
||||||
|
RegionId requestedRegionId,
|
||||||
|
uint requestedProtocolVersion,
|
||||||
|
ListingVisibility requestedVisibility,
|
||||||
|
IReadOnlyDictionary<string, string> requestedMetadata,
|
||||||
|
DateTimeOffset now)
|
||||||
|
{
|
||||||
|
if (principal.ExpiresAt <= now)
|
||||||
|
{
|
||||||
|
return PublisherAuthorizationResult.Denied(PublisherAuthorizationError.PrincipalExpired);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (principal is not IPublisherPrincipal publisher)
|
||||||
|
{
|
||||||
|
return PublisherAuthorizationResult.Denied(PublisherAuthorizationError.NotPublisher);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (publisher.GameId != requestedGameId
|
||||||
|
|| publisher.EnvironmentId != requestedEnvironmentId)
|
||||||
|
{
|
||||||
|
return PublisherAuthorizationResult.Denied(PublisherAuthorizationError.ScopeMismatch);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!policies.TryGet(publisher.GameId, publisher.EnvironmentId, out GamePolicy? policy)
|
||||||
|
|| policy is null)
|
||||||
|
{
|
||||||
|
return PublisherAuthorizationResult.Denied(PublisherAuthorizationError.PolicyNotFound);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!policy.AllowsPublisherTrust(publisher.TrustMode))
|
||||||
|
{
|
||||||
|
return PublisherAuthorizationResult.Denied(PublisherAuthorizationError.TrustModeNotAllowed);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!publisher.AllowedRegions.Contains(requestedRegionId)
|
||||||
|
|| !policy.AllowsRegion(requestedRegionId))
|
||||||
|
{
|
||||||
|
return PublisherAuthorizationResult.Denied(PublisherAuthorizationError.RegionNotAllowed);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!policy.AllowsProtocol(requestedProtocolVersion))
|
||||||
|
{
|
||||||
|
return PublisherAuthorizationResult.Denied(PublisherAuthorizationError.ProtocolNotAllowed);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (publisher.TrustMode == PublisherTrustMode.AnonymousUnlisted
|
||||||
|
&& requestedVisibility != ListingVisibility.Unlisted)
|
||||||
|
{
|
||||||
|
return PublisherAuthorizationResult.Denied(
|
||||||
|
PublisherAuthorizationError.AnonymousMustBeUnlisted);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!policy.AllowsVisibility(requestedVisibility))
|
||||||
|
{
|
||||||
|
return PublisherAuthorizationResult.Denied(PublisherAuthorizationError.VisibilityNotAllowed);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!policy.AllowsMetadata(requestedMetadata))
|
||||||
|
{
|
||||||
|
return PublisherAuthorizationResult.Denied(PublisherAuthorizationError.MetadataNotAllowed);
|
||||||
|
}
|
||||||
|
|
||||||
|
return PublisherAuthorizationResult.Allowed(new AuthorizedPublisherContext(
|
||||||
|
publisher.Subject,
|
||||||
|
publisher.GameId,
|
||||||
|
publisher.EnvironmentId,
|
||||||
|
requestedRegionId,
|
||||||
|
requestedProtocolVersion,
|
||||||
|
requestedVisibility,
|
||||||
|
publisher.TrustMode,
|
||||||
|
policy));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record AuthorizedPublisherContext(
|
||||||
|
string Subject,
|
||||||
|
GameId GameId,
|
||||||
|
EnvironmentId EnvironmentId,
|
||||||
|
RegionId RegionId,
|
||||||
|
uint ProtocolVersion,
|
||||||
|
ListingVisibility Visibility,
|
||||||
|
PublisherTrustMode TrustMode,
|
||||||
|
GamePolicy Policy);
|
||||||
|
|
||||||
|
internal readonly record struct PublisherAuthorizationResult(
|
||||||
|
bool IsAllowed,
|
||||||
|
PublisherAuthorizationError Error,
|
||||||
|
AuthorizedPublisherContext? Context)
|
||||||
|
{
|
||||||
|
public static PublisherAuthorizationResult Allowed(AuthorizedPublisherContext context) =>
|
||||||
|
new(true, PublisherAuthorizationError.None, context);
|
||||||
|
|
||||||
|
public static PublisherAuthorizationResult Denied(PublisherAuthorizationError error) =>
|
||||||
|
new(false, error, null);
|
||||||
|
}
|
||||||
|
|
||||||
|
internal enum PublisherAuthorizationError
|
||||||
|
{
|
||||||
|
None = 0,
|
||||||
|
NotPublisher = 1,
|
||||||
|
ScopeMismatch = 2,
|
||||||
|
PolicyNotFound = 3,
|
||||||
|
TrustModeNotAllowed = 4,
|
||||||
|
RegionNotAllowed = 5,
|
||||||
|
ProtocolNotAllowed = 6,
|
||||||
|
AnonymousMustBeUnlisted = 7,
|
||||||
|
VisibilityNotAllowed = 8,
|
||||||
|
MetadataNotAllowed = 9,
|
||||||
|
PrincipalExpired = 10,
|
||||||
|
}
|
||||||
@@ -0,0 +1,144 @@
|
|||||||
|
using System.Security.Cryptography;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
internal interface ISecretProvider
|
||||||
|
{
|
||||||
|
bool TryGetSecret(string reference, out SecretMaterial? secret);
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class SecretMaterial : IDisposable
|
||||||
|
{
|
||||||
|
private byte[]? _bytes;
|
||||||
|
|
||||||
|
public SecretMaterial(ReadOnlySpan<byte> bytes)
|
||||||
|
{
|
||||||
|
if (bytes.Length == 0)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("Secret material cannot be empty.", nameof(bytes));
|
||||||
|
}
|
||||||
|
|
||||||
|
_bytes = bytes.ToArray();
|
||||||
|
}
|
||||||
|
|
||||||
|
public int Length => _bytes?.Length ?? 0;
|
||||||
|
|
||||||
|
public byte[] CopyBytes() => _bytes?.ToArray()
|
||||||
|
?? throw new ObjectDisposedException(nameof(SecretMaterial));
|
||||||
|
|
||||||
|
public void Dispose()
|
||||||
|
{
|
||||||
|
if (_bytes is not null)
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(_bytes);
|
||||||
|
_bytes = null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public override string ToString() => "[REDACTED SECRET]";
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class EnvironmentSecretProvider : ISecretProvider
|
||||||
|
{
|
||||||
|
private const string Prefix = "env:";
|
||||||
|
|
||||||
|
public bool TryGetSecret(string reference, out SecretMaterial? secret)
|
||||||
|
{
|
||||||
|
secret = null;
|
||||||
|
if (!reference.StartsWith(Prefix, StringComparison.Ordinal)
|
||||||
|
|| reference.Length == Prefix.Length)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
string? encoded = Environment.GetEnvironmentVariable(reference[Prefix.Length..]);
|
||||||
|
if (string.IsNullOrEmpty(encoded))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
try
|
||||||
|
{
|
||||||
|
byte[] bytes = Convert.FromBase64String(encoded);
|
||||||
|
secret = new SecretMaterial(bytes);
|
||||||
|
CryptographicOperations.ZeroMemory(bytes);
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
catch (FormatException)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class EphemeralDevelopmentSecretProvider : ISecretProvider, IDisposable
|
||||||
|
{
|
||||||
|
private const string Prefix = "development:ephemeral/";
|
||||||
|
private readonly Dictionary<string, byte[]> _secrets = new(StringComparer.Ordinal);
|
||||||
|
|
||||||
|
public bool TryGetSecret(string reference, out SecretMaterial? secret)
|
||||||
|
{
|
||||||
|
secret = null;
|
||||||
|
if (!reference.StartsWith(Prefix, StringComparison.Ordinal)
|
||||||
|
|| reference.Length == Prefix.Length)
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!_secrets.TryGetValue(reference, out byte[]? bytes))
|
||||||
|
{
|
||||||
|
bytes = RandomNumberGenerator.GetBytes(32);
|
||||||
|
_secrets.Add(reference, bytes);
|
||||||
|
}
|
||||||
|
|
||||||
|
secret = new SecretMaterial(bytes);
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
public void Dispose()
|
||||||
|
{
|
||||||
|
foreach (byte[] bytes in _secrets.Values)
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(bytes);
|
||||||
|
}
|
||||||
|
|
||||||
|
_secrets.Clear();
|
||||||
|
}
|
||||||
|
|
||||||
|
public override string ToString() => "[EphemeralDevelopmentSecretProvider]";
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class DictionarySecretProvider : ISecretProvider, IDisposable
|
||||||
|
{
|
||||||
|
private readonly Dictionary<string, byte[]> _secrets;
|
||||||
|
|
||||||
|
public DictionarySecretProvider(IReadOnlyDictionary<string, byte[]> secrets) =>
|
||||||
|
_secrets = secrets.ToDictionary(
|
||||||
|
static item => item.Key,
|
||||||
|
static item => item.Value.ToArray(),
|
||||||
|
StringComparer.Ordinal);
|
||||||
|
|
||||||
|
public bool TryGetSecret(string reference, out SecretMaterial? secret)
|
||||||
|
{
|
||||||
|
if (_secrets.TryGetValue(reference, out byte[]? bytes))
|
||||||
|
{
|
||||||
|
secret = new SecretMaterial(bytes);
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
secret = null;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
public void Dispose()
|
||||||
|
{
|
||||||
|
foreach (byte[] bytes in _secrets.Values)
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(bytes);
|
||||||
|
}
|
||||||
|
|
||||||
|
_secrets.Clear();
|
||||||
|
}
|
||||||
|
|
||||||
|
public override string ToString() => "[DictionarySecretProvider: REDACTED]";
|
||||||
|
}
|
||||||
@@ -0,0 +1,275 @@
|
|||||||
|
using System.Collections.Concurrent;
|
||||||
|
using System.Collections.Frozen;
|
||||||
|
using System.Security.Cryptography;
|
||||||
|
using System.Text;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
internal sealed class SigningKeyRing : IDisposable
|
||||||
|
{
|
||||||
|
private readonly Dictionary<string, SigningKey> _keys;
|
||||||
|
private readonly ConcurrentDictionary<string, byte> _runtimeRevocations =
|
||||||
|
new(StringComparer.Ordinal);
|
||||||
|
|
||||||
|
private SigningKeyRing(Dictionary<string, SigningKey> keys) => _keys = keys;
|
||||||
|
|
||||||
|
public bool HasKeys => _keys.Count > 0;
|
||||||
|
|
||||||
|
public static SigningKeyRing Create(
|
||||||
|
IEnumerable<SigningKeyOptions> options,
|
||||||
|
ISecretProvider secretProvider)
|
||||||
|
{
|
||||||
|
SigningKeyOptions[] configuredKeys = options.ToArray();
|
||||||
|
if (configuredKeys.Length > ProvisioningLimits.MaxSigningKeys)
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"At most {ProvisioningLimits.MaxSigningKeys} signing keys may be configured.");
|
||||||
|
}
|
||||||
|
|
||||||
|
Dictionary<string, SigningKey> keys = new(StringComparer.Ordinal);
|
||||||
|
try
|
||||||
|
{
|
||||||
|
foreach (SigningKeyOptions keyOptions in configuredKeys)
|
||||||
|
{
|
||||||
|
Validate(keyOptions);
|
||||||
|
if (keys.ContainsKey(keyOptions.KeyId))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Duplicate signing key ID '{keyOptions.KeyId}'.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (keyOptions.Revoked)
|
||||||
|
{
|
||||||
|
keys.Add(keyOptions.KeyId, new SigningKey(keyOptions, null));
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!secretProvider.TryGetSecret(
|
||||||
|
keyOptions.SecretReference,
|
||||||
|
out SecretMaterial? material)
|
||||||
|
|| material is null)
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Signing key '{keyOptions.KeyId}' has no available key material.");
|
||||||
|
}
|
||||||
|
|
||||||
|
using (material)
|
||||||
|
{
|
||||||
|
if (material.Length < 32)
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Signing key '{keyOptions.KeyId}' must contain at least 32 bytes.");
|
||||||
|
}
|
||||||
|
|
||||||
|
keys.Add(keyOptions.KeyId, new SigningKey(keyOptions, material.CopyBytes()));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return new SigningKeyRing(keys);
|
||||||
|
}
|
||||||
|
catch
|
||||||
|
{
|
||||||
|
foreach (SigningKey key in keys.Values)
|
||||||
|
{
|
||||||
|
key.Dispose();
|
||||||
|
}
|
||||||
|
|
||||||
|
throw;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool HasActiveSigningKey(DateTimeOffset now) => _keys.Values.Any(key =>
|
||||||
|
!IsRevoked(key)
|
||||||
|
&& key.NotBefore <= now
|
||||||
|
&& now < key.SignUntil);
|
||||||
|
|
||||||
|
public bool HasActiveSigningKey(
|
||||||
|
DateTimeOffset now,
|
||||||
|
PrincipalCredentialKind kind,
|
||||||
|
string? gameId,
|
||||||
|
string? environmentId) => _keys.Values.Any(key =>
|
||||||
|
!IsRevoked(key)
|
||||||
|
&& key.NotBefore <= now
|
||||||
|
&& now < key.SignUntil
|
||||||
|
&& key.Authorizes(kind, gameId, environmentId));
|
||||||
|
|
||||||
|
public bool TryGetSigningKey(
|
||||||
|
DateTimeOffset now,
|
||||||
|
PrincipalCredentialKind kind,
|
||||||
|
string? gameId,
|
||||||
|
string? environmentId,
|
||||||
|
out SigningKey? signingKey)
|
||||||
|
{
|
||||||
|
signingKey = _keys.Values
|
||||||
|
.Where(key => !IsRevoked(key)
|
||||||
|
&& key.NotBefore <= now
|
||||||
|
&& now < key.SignUntil
|
||||||
|
&& key.Authorizes(kind, gameId, environmentId))
|
||||||
|
.OrderByDescending(static key => key.NotBefore)
|
||||||
|
.ThenByDescending(static key => key.KeyId, StringComparer.Ordinal)
|
||||||
|
.FirstOrDefault();
|
||||||
|
return signingKey is not null;
|
||||||
|
}
|
||||||
|
|
||||||
|
public VerificationKeyLookup FindVerificationKey(
|
||||||
|
string keyId,
|
||||||
|
DateTimeOffset now,
|
||||||
|
out SigningKey? signingKey)
|
||||||
|
{
|
||||||
|
signingKey = null;
|
||||||
|
if (!_keys.TryGetValue(keyId, out SigningKey? candidate))
|
||||||
|
{
|
||||||
|
return VerificationKeyLookup.Unknown;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (IsRevoked(candidate))
|
||||||
|
{
|
||||||
|
return VerificationKeyLookup.Revoked;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (now < candidate.NotBefore)
|
||||||
|
{
|
||||||
|
return VerificationKeyLookup.NotYetValid;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (now >= candidate.VerifyUntil)
|
||||||
|
{
|
||||||
|
return VerificationKeyLookup.Retired;
|
||||||
|
}
|
||||||
|
|
||||||
|
signingKey = candidate;
|
||||||
|
return VerificationKeyLookup.Available;
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool Revoke(string keyId) =>
|
||||||
|
_keys.ContainsKey(keyId) && _runtimeRevocations.TryAdd(keyId, 0);
|
||||||
|
|
||||||
|
public void Dispose()
|
||||||
|
{
|
||||||
|
foreach (SigningKey key in _keys.Values)
|
||||||
|
{
|
||||||
|
key.Dispose();
|
||||||
|
}
|
||||||
|
|
||||||
|
_keys.Clear();
|
||||||
|
_runtimeRevocations.Clear();
|
||||||
|
}
|
||||||
|
|
||||||
|
public override string ToString() => $"[SigningKeyRing: {_keys.Count} keys, material redacted]";
|
||||||
|
|
||||||
|
private bool IsRevoked(SigningKey key) =>
|
||||||
|
key.ConfiguredRevoked || _runtimeRevocations.ContainsKey(key.KeyId);
|
||||||
|
|
||||||
|
private static void Validate(SigningKeyOptions options)
|
||||||
|
{
|
||||||
|
if (string.IsNullOrEmpty(options.KeyId)
|
||||||
|
|| options.KeyId.Length > 64
|
||||||
|
|| options.KeyId.Any(static character =>
|
||||||
|
character is not (>= 'A' and <= 'Z')
|
||||||
|
and not (>= 'a' and <= 'z')
|
||||||
|
and not (>= '0' and <= '9')
|
||||||
|
and not '-'
|
||||||
|
and not '_'))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
"Signing key IDs must be 1–64 base64url characters.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (string.IsNullOrWhiteSpace(options.SecretReference)
|
||||||
|
|| options.NotBefore >= options.SignUntil
|
||||||
|
|| options.SignUntil > options.VerifyUntil)
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Signing key '{options.KeyId}' has an invalid secret reference or lifetime.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (options.CredentialKinds.Count == 0
|
||||||
|
|| options.CredentialKinds.Any(static kind => !Enum.IsDefined(kind))
|
||||||
|
|| options.CredentialKinds.Count != options.CredentialKinds.Distinct().Count())
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Signing key '{options.KeyId}' requires unique valid credential kinds.");
|
||||||
|
}
|
||||||
|
|
||||||
|
bool operatorKey = options.CredentialKinds.Contains(PrincipalCredentialKind.Operator);
|
||||||
|
bool hasPublisherKind = options.CredentialKinds.Any(static kind =>
|
||||||
|
kind is PrincipalCredentialKind.DedicatedPublisher
|
||||||
|
or PrincipalCredentialKind.PlayerHostGrant);
|
||||||
|
if (operatorKey
|
||||||
|
? options.CredentialKinds.Count != 1
|
||||||
|
|| options.GameId is not null
|
||||||
|
|| options.EnvironmentId is not null
|
||||||
|
: !hasPublisherKind
|
||||||
|
|| !GameId.TryParse(options.GameId, out _)
|
||||||
|
|| !EnvironmentId.TryParse(options.EnvironmentId, out _))
|
||||||
|
{
|
||||||
|
throw new ProvisioningConfigurationException(
|
||||||
|
$"Signing key '{options.KeyId}' must be operator-only or bound to one game/environment.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class SigningKey : IDisposable
|
||||||
|
{
|
||||||
|
private byte[]? _material;
|
||||||
|
|
||||||
|
public SigningKey(SigningKeyOptions options, byte[]? material)
|
||||||
|
{
|
||||||
|
KeyId = options.KeyId;
|
||||||
|
NotBefore = options.NotBefore;
|
||||||
|
SignUntil = options.SignUntil;
|
||||||
|
VerifyUntil = options.VerifyUntil;
|
||||||
|
ConfiguredRevoked = options.Revoked;
|
||||||
|
CredentialKinds = options.CredentialKinds.ToFrozenSet();
|
||||||
|
GameId = options.GameId;
|
||||||
|
EnvironmentId = options.EnvironmentId;
|
||||||
|
_material = material;
|
||||||
|
}
|
||||||
|
|
||||||
|
public string KeyId { get; }
|
||||||
|
public DateTimeOffset NotBefore { get; }
|
||||||
|
public DateTimeOffset SignUntil { get; }
|
||||||
|
public DateTimeOffset VerifyUntil { get; }
|
||||||
|
public bool ConfiguredRevoked { get; }
|
||||||
|
public IReadOnlySet<PrincipalCredentialKind> CredentialKinds { get; }
|
||||||
|
public string? GameId { get; }
|
||||||
|
public string? EnvironmentId { get; }
|
||||||
|
|
||||||
|
public bool Authorizes(
|
||||||
|
PrincipalCredentialKind kind,
|
||||||
|
string? gameId,
|
||||||
|
string? environmentId) =>
|
||||||
|
CredentialKinds.Contains(kind)
|
||||||
|
&& (kind == PrincipalCredentialKind.Operator
|
||||||
|
? gameId is null && environmentId is null
|
||||||
|
: string.Equals(GameId, gameId, StringComparison.Ordinal)
|
||||||
|
&& string.Equals(EnvironmentId, environmentId, StringComparison.Ordinal));
|
||||||
|
|
||||||
|
public byte[] Sign(string input)
|
||||||
|
{
|
||||||
|
ObjectDisposedException.ThrowIf(_material is null, this);
|
||||||
|
|
||||||
|
return HMACSHA256.HashData(_material, Encoding.ASCII.GetBytes(input));
|
||||||
|
}
|
||||||
|
|
||||||
|
public void Dispose()
|
||||||
|
{
|
||||||
|
if (_material is not null)
|
||||||
|
{
|
||||||
|
CryptographicOperations.ZeroMemory(_material);
|
||||||
|
_material = null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public override string ToString() => $"[SigningKey {KeyId}: material redacted]";
|
||||||
|
}
|
||||||
|
|
||||||
|
internal enum VerificationKeyLookup
|
||||||
|
{
|
||||||
|
Available = 0,
|
||||||
|
Unknown = 1,
|
||||||
|
Revoked = 2,
|
||||||
|
NotYetValid = 3,
|
||||||
|
Retired = 4,
|
||||||
|
}
|
||||||
@@ -0,0 +1,279 @@
|
|||||||
|
using System.Collections.Frozen;
|
||||||
|
using System.Diagnostics;
|
||||||
|
using System.Net;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.State;
|
||||||
|
|
||||||
|
internal interface IWallClock
|
||||||
|
{
|
||||||
|
DateTimeOffset UtcNow { get; }
|
||||||
|
}
|
||||||
|
|
||||||
|
internal interface IMonotonicClock
|
||||||
|
{
|
||||||
|
TimeSpan Elapsed { get; }
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class SystemRendezvousClock : IWallClock, IMonotonicClock
|
||||||
|
{
|
||||||
|
private readonly long _origin = Stopwatch.GetTimestamp();
|
||||||
|
|
||||||
|
public DateTimeOffset UtcNow => DateTimeOffset.UtcNow;
|
||||||
|
|
||||||
|
public TimeSpan Elapsed => Stopwatch.GetElapsedTime(_origin);
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record EphemeralStoreOptions
|
||||||
|
{
|
||||||
|
public int MaxListings { get; init; } = 25_000;
|
||||||
|
public int MaxPresenceBindings { get; init; } = 25_000;
|
||||||
|
public int MaxJoinAttempts { get; init; } = 10_000;
|
||||||
|
public int MaxReplayEntries { get; init; } = 30_000;
|
||||||
|
public int MaxRevocations { get; init; } = 10_000;
|
||||||
|
public int MaxIdempotencyEntries { get; init; } = 35_000;
|
||||||
|
public TimeSpan LeaseLifetime { get; init; } = TimeSpan.FromSeconds(60);
|
||||||
|
public TimeSpan PresenceLifetime { get; init; } = TimeSpan.FromSeconds(20);
|
||||||
|
public TimeSpan JoinAttemptLifetime { get; init; } = TimeSpan.FromSeconds(30);
|
||||||
|
public TimeSpan ReplayLifetime { get; init; } = TimeSpan.FromSeconds(30);
|
||||||
|
public TimeSpan IdempotencyLifetime { get; init; } = TimeSpan.FromMinutes(2);
|
||||||
|
public TimeSpan GracefulDrainLifetime { get; init; } = TimeSpan.FromSeconds(30);
|
||||||
|
|
||||||
|
public void Validate()
|
||||||
|
{
|
||||||
|
RequirePositive(MaxListings, nameof(MaxListings));
|
||||||
|
RequirePositive(MaxPresenceBindings, nameof(MaxPresenceBindings));
|
||||||
|
RequirePositive(MaxJoinAttempts, nameof(MaxJoinAttempts));
|
||||||
|
RequirePositive(MaxReplayEntries, nameof(MaxReplayEntries));
|
||||||
|
RequirePositive(MaxRevocations, nameof(MaxRevocations));
|
||||||
|
RequirePositive(MaxIdempotencyEntries, nameof(MaxIdempotencyEntries));
|
||||||
|
RequireDuration(LeaseLifetime, TimeSpan.FromSeconds(60), nameof(LeaseLifetime));
|
||||||
|
RequireDuration(PresenceLifetime, TimeSpan.FromSeconds(20), nameof(PresenceLifetime));
|
||||||
|
RequireDuration(JoinAttemptLifetime, TimeSpan.FromSeconds(30), nameof(JoinAttemptLifetime));
|
||||||
|
RequireDuration(ReplayLifetime, TimeSpan.FromSeconds(30), nameof(ReplayLifetime));
|
||||||
|
RequireDuration(IdempotencyLifetime, TimeSpan.FromMinutes(10), nameof(IdempotencyLifetime));
|
||||||
|
RequireDuration(GracefulDrainLifetime, TimeSpan.FromSeconds(30), nameof(GracefulDrainLifetime));
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void RequirePositive(int value, string name)
|
||||||
|
{
|
||||||
|
if (value <= 0)
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(name, "Store capacity must be positive.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void RequireDuration(TimeSpan value, TimeSpan maximum, string name)
|
||||||
|
{
|
||||||
|
if (value <= TimeSpan.Zero || value > maximum)
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(name, $"Duration must be positive and no greater than {maximum}.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
internal readonly record struct TenantScope(GameId GameId, EnvironmentId EnvironmentId);
|
||||||
|
|
||||||
|
internal readonly record struct SecretFingerprint
|
||||||
|
{
|
||||||
|
public SecretFingerprint(string value)
|
||||||
|
{
|
||||||
|
if (string.IsNullOrWhiteSpace(value) || value.Length > 128)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("Secret fingerprints must contain 1-128 characters.", nameof(value));
|
||||||
|
}
|
||||||
|
|
||||||
|
Value = value;
|
||||||
|
}
|
||||||
|
|
||||||
|
public string Value { get; }
|
||||||
|
public bool IsValid => !string.IsNullOrWhiteSpace(Value) && Value.Length <= 128;
|
||||||
|
public override string ToString() => "[REDACTED]";
|
||||||
|
}
|
||||||
|
|
||||||
|
internal readonly record struct ObservedEndpoint
|
||||||
|
{
|
||||||
|
public ObservedEndpoint(AddressFamilyKind addressFamily, string address, int port)
|
||||||
|
{
|
||||||
|
if (!IPAddress.TryParse(address, out IPAddress? parsed)
|
||||||
|
|| (addressFamily == AddressFamilyKind.Ipv4 && parsed.AddressFamily != System.Net.Sockets.AddressFamily.InterNetwork)
|
||||||
|
|| (addressFamily == AddressFamilyKind.Ipv6 && parsed.AddressFamily != System.Net.Sockets.AddressFamily.InterNetworkV6))
|
||||||
|
{
|
||||||
|
throw new ArgumentException("The address must match the declared address family.", nameof(address));
|
||||||
|
}
|
||||||
|
|
||||||
|
if (port is < 1 or > 65_535)
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(nameof(port));
|
||||||
|
}
|
||||||
|
|
||||||
|
AddressFamily = addressFamily;
|
||||||
|
Address = parsed.ToString();
|
||||||
|
Port = port;
|
||||||
|
}
|
||||||
|
|
||||||
|
public AddressFamilyKind AddressFamily { get; }
|
||||||
|
public string Address { get; }
|
||||||
|
public int Port { get; }
|
||||||
|
public bool IsValid => !string.IsNullOrEmpty(Address)
|
||||||
|
&& Port is >= 1 and <= 65_535
|
||||||
|
&& AddressFamily is AddressFamilyKind.Ipv4 or AddressFamilyKind.Ipv6;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record ListingDefinition
|
||||||
|
{
|
||||||
|
public required SessionListingId ListingId { get; init; }
|
||||||
|
public required LeaseId LeaseId { get; init; }
|
||||||
|
public required TenantScope Scope { get; init; }
|
||||||
|
public required string OwnerSubject { get; init; }
|
||||||
|
public required RegionId RegionId { get; init; }
|
||||||
|
public required uint ProtocolVersion { get; init; }
|
||||||
|
public required string BuildVersion { get; init; }
|
||||||
|
public required string DisplayName { get; init; }
|
||||||
|
public required ListingVisibility Visibility { get; init; }
|
||||||
|
public required PublisherTrustMode TrustMode { get; init; }
|
||||||
|
public required int CurrentPlayers { get; init; }
|
||||||
|
public required int MaximumPlayers { get; init; }
|
||||||
|
public required IReadOnlyDictionary<string, string> Metadata { get; init; }
|
||||||
|
public required SecretFingerprint LeaseFingerprint { get; init; }
|
||||||
|
public required MediationHandle HostPresenceHandle { get; init; }
|
||||||
|
public required SecretFingerprint HostPresenceFingerprint { get; init; }
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record StoredListing
|
||||||
|
{
|
||||||
|
public required ListingDefinition Definition { get; init; }
|
||||||
|
public required DateTimeOffset LeaseExpiresAt { get; init; }
|
||||||
|
public required long Version { get; init; }
|
||||||
|
public required bool HasFreshPresence { get; init; }
|
||||||
|
|
||||||
|
public static ListingDefinition Freeze(ListingDefinition source) => source with
|
||||||
|
{
|
||||||
|
Metadata = source.Metadata.ToFrozenDictionary(StringComparer.Ordinal),
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record CreateListingCommand(
|
||||||
|
string IdempotencyKey,
|
||||||
|
string RequestFingerprint,
|
||||||
|
ListingDefinition Listing,
|
||||||
|
int OwnerListingLimit = int.MaxValue);
|
||||||
|
|
||||||
|
internal sealed record RenewLeaseCommand(
|
||||||
|
SessionListingId ListingId,
|
||||||
|
LeaseId LeaseId,
|
||||||
|
SecretFingerprint LeaseFingerprint,
|
||||||
|
long ExpectedVersion);
|
||||||
|
|
||||||
|
internal sealed record DeleteListingCommand(
|
||||||
|
SessionListingId ListingId,
|
||||||
|
LeaseId LeaseId,
|
||||||
|
SecretFingerprint LeaseFingerprint);
|
||||||
|
|
||||||
|
internal sealed record BindHostPresenceCommand(
|
||||||
|
MediationHandle Handle,
|
||||||
|
SecretFingerprint CapabilityFingerprint,
|
||||||
|
ObservedEndpoint PublicEndpoint,
|
||||||
|
ObservedEndpoint? LocalEndpoint);
|
||||||
|
|
||||||
|
internal sealed record VisibleListingQuery(
|
||||||
|
TenantScope Scope,
|
||||||
|
uint ProtocolVersion,
|
||||||
|
RegionId? RegionId,
|
||||||
|
int MaximumResults = ContractLimits.BrowserPageMaxItems);
|
||||||
|
|
||||||
|
internal enum AttemptPeerRole
|
||||||
|
{
|
||||||
|
Host = 1,
|
||||||
|
Client = 2,
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record CreateJoinAttemptCommand
|
||||||
|
{
|
||||||
|
public required string IdempotencyOwner { get; init; }
|
||||||
|
public required string IdempotencyKey { get; init; }
|
||||||
|
public required string RequestFingerprint { get; init; }
|
||||||
|
public required string ClientSubject { get; init; }
|
||||||
|
public required JoinAttemptId AttemptId { get; init; }
|
||||||
|
public required MediationHandle MediationHandle { get; init; }
|
||||||
|
public required TenantScope Scope { get; init; }
|
||||||
|
public required SessionListingId ListingId { get; init; }
|
||||||
|
public required uint ProtocolVersion { get; init; }
|
||||||
|
public required SecretFingerprint HostCapabilityFingerprint { get; init; }
|
||||||
|
public required SecretFingerprint ClientCapabilityFingerprint { get; init; }
|
||||||
|
public int ScopeAttemptLimit { get; init; } = int.MaxValue;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record AttemptEndpointBinding(
|
||||||
|
ObservedEndpoint PublicEndpoint,
|
||||||
|
ObservedEndpoint? LocalEndpoint);
|
||||||
|
|
||||||
|
internal sealed record StoredJoinAttempt
|
||||||
|
{
|
||||||
|
public required JoinAttemptId AttemptId { get; init; }
|
||||||
|
public required MediationHandle MediationHandle { get; init; }
|
||||||
|
public required TenantScope Scope { get; init; }
|
||||||
|
public required SessionListingId ListingId { get; init; }
|
||||||
|
public required string ClientSubject { get; init; }
|
||||||
|
public required uint ProtocolVersion { get; init; }
|
||||||
|
public required DateTimeOffset ExpiresAt { get; init; }
|
||||||
|
public AttemptEndpointBinding? HostEndpoint { get; init; }
|
||||||
|
public AttemptEndpointBinding? ClientEndpoint { get; init; }
|
||||||
|
public required bool IntroductionConsumed { get; init; }
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record BindAttemptEndpointCommand(
|
||||||
|
MediationHandle Handle,
|
||||||
|
AttemptPeerRole Role,
|
||||||
|
SecretFingerprint CapabilityFingerprint,
|
||||||
|
ObservedEndpoint PublicEndpoint,
|
||||||
|
ObservedEndpoint? LocalEndpoint);
|
||||||
|
|
||||||
|
internal sealed record IntroductionEndpoints(
|
||||||
|
JoinAttemptId AttemptId,
|
||||||
|
AttemptEndpointBinding Host,
|
||||||
|
AttemptEndpointBinding Client);
|
||||||
|
|
||||||
|
internal sealed record ReplayConsumption(
|
||||||
|
string Namespace,
|
||||||
|
string Key,
|
||||||
|
TimeSpan? Lifetime = null);
|
||||||
|
|
||||||
|
internal enum StoreResultCode
|
||||||
|
{
|
||||||
|
Success = 0,
|
||||||
|
NotFound = 1,
|
||||||
|
Expired = 2,
|
||||||
|
Revoked = 3,
|
||||||
|
Conflict = 4,
|
||||||
|
CapacityExceeded = 5,
|
||||||
|
Draining = 6,
|
||||||
|
ReplayRejected = 7,
|
||||||
|
ServiceUnavailable = 8,
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed record StoreResult<T>(StoreResultCode Code, T? Value = default, bool IsIdempotentReplay = false)
|
||||||
|
{
|
||||||
|
public bool Succeeded => Code == StoreResultCode.Success;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal interface IEphemeralRendezvousStore
|
||||||
|
{
|
||||||
|
Guid InstanceId { get; }
|
||||||
|
bool IsAvailable { get; }
|
||||||
|
bool IsDraining { get; }
|
||||||
|
|
||||||
|
StoreResult<StoredListing> CreateListing(CreateListingCommand command, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<StoredListing> RenewLease(RenewLeaseCommand command, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<bool> DeleteListing(DeleteListingCommand command, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<StoredListing> GetListing(SessionListingId listingId, bool requireFreshPresence, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<IReadOnlyList<StoredListing>> BrowseVisibleListings(VisibleListingQuery query, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<StoredListing> BindHostPresence(BindHostPresenceCommand command, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<StoredJoinAttempt> CreateJoinAttempt(CreateJoinAttemptCommand command, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<StoredJoinAttempt> BindAttemptEndpoint(BindAttemptEndpointCommand command, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<IntroductionEndpoints> ConsumeIntroduction(MediationHandle handle, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<bool> ConsumeReplay(ReplayConsumption consumption, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<bool> RevokeListing(SessionListingId listingId, CancellationToken cancellationToken = default);
|
||||||
|
StoreResult<int> RevokePrincipal(string subject, TimeSpan lifetime, CancellationToken cancellationToken = default);
|
||||||
|
void BeginDrain(CancellationToken cancellationToken = default);
|
||||||
|
}
|
||||||
@@ -0,0 +1,805 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Server.State;
|
||||||
|
|
||||||
|
internal sealed class InMemoryEphemeralRendezvousStore : IEphemeralRendezvousStore
|
||||||
|
{
|
||||||
|
private readonly object _gate = new();
|
||||||
|
private readonly EphemeralStoreOptions _options;
|
||||||
|
private readonly IMonotonicClock _monotonicClock;
|
||||||
|
private readonly DateTimeOffset _wallOrigin;
|
||||||
|
private readonly TimeSpan _monotonicOrigin;
|
||||||
|
private readonly Dictionary<SessionListingId, ListingEntry> _listings = [];
|
||||||
|
private readonly Dictionary<LeaseId, SessionListingId> _leases = [];
|
||||||
|
private readonly Dictionary<MediationHandle, SessionListingId> _presenceHandles = [];
|
||||||
|
private readonly Dictionary<MediationHandle, PresenceEntry> _presence = [];
|
||||||
|
private readonly Dictionary<JoinAttemptId, AttemptEntry> _attempts = [];
|
||||||
|
private readonly Dictionary<MediationHandle, JoinAttemptId> _attemptHandles = [];
|
||||||
|
private readonly Dictionary<string, IdempotencyEntry> _idempotency = new(StringComparer.Ordinal);
|
||||||
|
private readonly Dictionary<string, TimeSpan> _replay = new(StringComparer.Ordinal);
|
||||||
|
private readonly Dictionary<string, TimeSpan> _revocations = new(StringComparer.Ordinal);
|
||||||
|
private TimeSpan? _drainDeadline;
|
||||||
|
private bool _available = true;
|
||||||
|
|
||||||
|
public InMemoryEphemeralRendezvousStore(
|
||||||
|
EphemeralStoreOptions options,
|
||||||
|
IWallClock wallClock,
|
||||||
|
IMonotonicClock monotonicClock)
|
||||||
|
{
|
||||||
|
ArgumentNullException.ThrowIfNull(options);
|
||||||
|
ArgumentNullException.ThrowIfNull(wallClock);
|
||||||
|
ArgumentNullException.ThrowIfNull(monotonicClock);
|
||||||
|
options.Validate();
|
||||||
|
_options = options;
|
||||||
|
_monotonicClock = monotonicClock;
|
||||||
|
_wallOrigin = wallClock.UtcNow;
|
||||||
|
_monotonicOrigin = monotonicClock.Elapsed;
|
||||||
|
InstanceId = Guid.NewGuid();
|
||||||
|
}
|
||||||
|
|
||||||
|
public Guid InstanceId { get; }
|
||||||
|
|
||||||
|
public bool IsAvailable
|
||||||
|
{
|
||||||
|
get
|
||||||
|
{
|
||||||
|
lock (_gate)
|
||||||
|
{
|
||||||
|
return _available;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public bool IsDraining
|
||||||
|
{
|
||||||
|
get
|
||||||
|
{
|
||||||
|
lock (_gate)
|
||||||
|
{
|
||||||
|
return _drainDeadline.HasValue;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public StoreResult<StoredListing> CreateListing(
|
||||||
|
CreateListingCommand command,
|
||||||
|
CancellationToken cancellationToken = default) => Atomic<StoredListing>(now =>
|
||||||
|
{
|
||||||
|
ArgumentNullException.ThrowIfNull(command);
|
||||||
|
ValidateListing(command.Listing);
|
||||||
|
if (command.OwnerListingLimit <= 0)
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(nameof(command), "Owner listing limit must be positive.");
|
||||||
|
}
|
||||||
|
|
||||||
|
ValidateIdempotency(command.IdempotencyKey, command.RequestFingerprint);
|
||||||
|
|
||||||
|
StoreResult<StoredListing>? admission = CheckNewWorkAdmission<StoredListing>(command.Listing.OwnerSubject);
|
||||||
|
if (admission is not null)
|
||||||
|
{
|
||||||
|
return admission;
|
||||||
|
}
|
||||||
|
|
||||||
|
string idempotencyKey = $"listing:{command.Listing.OwnerSubject}:{command.IdempotencyKey}";
|
||||||
|
if (_idempotency.TryGetValue(idempotencyKey, out IdempotencyEntry? previous))
|
||||||
|
{
|
||||||
|
if (!string.Equals(previous.RequestFingerprint, command.RequestFingerprint, StringComparison.Ordinal))
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.Conflict);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (previous.ResourceId is SessionListingId listingId
|
||||||
|
&& _listings.TryGetValue(listingId, out ListingEntry? existing))
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.Success, Snapshot(existing), true);
|
||||||
|
}
|
||||||
|
|
||||||
|
return new(StoreResultCode.Expired);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (_listings.Count >= _options.MaxListings
|
||||||
|
|| _idempotency.Count >= _options.MaxIdempotencyEntries
|
||||||
|
|| _listings.Values.Count(entry => string.Equals(
|
||||||
|
entry.Definition.OwnerSubject,
|
||||||
|
command.Listing.OwnerSubject,
|
||||||
|
StringComparison.Ordinal)) >= command.OwnerListingLimit)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.CapacityExceeded);
|
||||||
|
}
|
||||||
|
|
||||||
|
ListingDefinition frozen = StoredListing.Freeze(command.Listing);
|
||||||
|
if (_listings.ContainsKey(frozen.ListingId)
|
||||||
|
|| _leases.ContainsKey(frozen.LeaseId)
|
||||||
|
|| HandleExists(frozen.HostPresenceHandle))
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.Conflict);
|
||||||
|
}
|
||||||
|
|
||||||
|
ListingEntry entry = new(
|
||||||
|
frozen,
|
||||||
|
now + _options.LeaseLifetime,
|
||||||
|
WallDeadline(now, _options.LeaseLifetime),
|
||||||
|
version: 1);
|
||||||
|
_listings.Add(frozen.ListingId, entry);
|
||||||
|
_leases.Add(frozen.LeaseId, frozen.ListingId);
|
||||||
|
_presenceHandles.Add(frozen.HostPresenceHandle, frozen.ListingId);
|
||||||
|
_idempotency.Add(idempotencyKey, new(
|
||||||
|
command.RequestFingerprint,
|
||||||
|
frozen.ListingId,
|
||||||
|
now + _options.IdempotencyLifetime));
|
||||||
|
return new(StoreResultCode.Success, Snapshot(entry));
|
||||||
|
}, cancellationToken);
|
||||||
|
|
||||||
|
public StoreResult<StoredListing> RenewLease(
|
||||||
|
RenewLeaseCommand command,
|
||||||
|
CancellationToken cancellationToken = default) => Atomic<StoredListing>(now =>
|
||||||
|
{
|
||||||
|
ArgumentNullException.ThrowIfNull(command);
|
||||||
|
if (!_available)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.ServiceUnavailable);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (_drainDeadline.HasValue)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.Draining);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!_listings.TryGetValue(command.ListingId, out ListingEntry? entry))
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.NotFound);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (entry.Definition.LeaseId != command.LeaseId
|
||||||
|
|| entry.Definition.LeaseFingerprint != command.LeaseFingerprint)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.NotFound);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (entry.Version != command.ExpectedVersion)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.Conflict, Snapshot(entry));
|
||||||
|
}
|
||||||
|
|
||||||
|
entry.LeaseDeadline = now + _options.LeaseLifetime;
|
||||||
|
entry.WallExpiresAt = WallDeadline(now, _options.LeaseLifetime);
|
||||||
|
entry.Version++;
|
||||||
|
return new(StoreResultCode.Success, Snapshot(entry));
|
||||||
|
}, cancellationToken);
|
||||||
|
|
||||||
|
public StoreResult<bool> DeleteListing(
|
||||||
|
DeleteListingCommand command,
|
||||||
|
CancellationToken cancellationToken = default) => Atomic<bool>(_ =>
|
||||||
|
{
|
||||||
|
ArgumentNullException.ThrowIfNull(command);
|
||||||
|
if (!_listings.TryGetValue(command.ListingId, out ListingEntry? entry)
|
||||||
|
|| entry.Definition.LeaseId != command.LeaseId
|
||||||
|
|| entry.Definition.LeaseFingerprint != command.LeaseFingerprint)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.NotFound);
|
||||||
|
}
|
||||||
|
|
||||||
|
RemoveListing(command.ListingId);
|
||||||
|
return new(StoreResultCode.Success, true);
|
||||||
|
}, cancellationToken);
|
||||||
|
|
||||||
|
public StoreResult<StoredListing> GetListing(
|
||||||
|
SessionListingId listingId,
|
||||||
|
bool requireFreshPresence,
|
||||||
|
CancellationToken cancellationToken = default) => Atomic<StoredListing>(_ =>
|
||||||
|
{
|
||||||
|
if (!_available)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.ServiceUnavailable);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!_listings.TryGetValue(listingId, out ListingEntry? entry))
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.NotFound);
|
||||||
|
}
|
||||||
|
|
||||||
|
bool fresh = _presence.ContainsKey(entry.Definition.HostPresenceHandle);
|
||||||
|
return requireFreshPresence && !fresh
|
||||||
|
? new(StoreResultCode.NotFound)
|
||||||
|
: new(StoreResultCode.Success, Snapshot(entry));
|
||||||
|
}, cancellationToken);
|
||||||
|
|
||||||
|
public StoreResult<StoredListing> BindHostPresence(
|
||||||
|
BindHostPresenceCommand command,
|
||||||
|
CancellationToken cancellationToken = default) => Atomic<StoredListing>(now =>
|
||||||
|
{
|
||||||
|
ArgumentNullException.ThrowIfNull(command);
|
||||||
|
if (command.Handle.Value == Guid.Empty || !command.CapabilityFingerprint.IsValid)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("Host presence binding is invalid.", nameof(command));
|
||||||
|
}
|
||||||
|
|
||||||
|
ValidateEndpoint(command.PublicEndpoint, command.LocalEndpoint);
|
||||||
|
if (!_available)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.ServiceUnavailable);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!_presenceHandles.TryGetValue(command.Handle, out SessionListingId listingId)
|
||||||
|
|| !_listings.TryGetValue(listingId, out ListingEntry? entry)
|
||||||
|
|| entry.Definition.HostPresenceFingerprint != command.CapabilityFingerprint)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.NotFound);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!_presence.ContainsKey(command.Handle) && _presence.Count >= _options.MaxPresenceBindings)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.CapacityExceeded);
|
||||||
|
}
|
||||||
|
|
||||||
|
_presence[command.Handle] = new(
|
||||||
|
command.PublicEndpoint,
|
||||||
|
command.LocalEndpoint,
|
||||||
|
now + _options.PresenceLifetime);
|
||||||
|
return new(StoreResultCode.Success, Snapshot(entry));
|
||||||
|
}, cancellationToken);
|
||||||
|
|
||||||
|
public StoreResult<IReadOnlyList<StoredListing>> BrowseVisibleListings(
|
||||||
|
VisibleListingQuery query,
|
||||||
|
CancellationToken cancellationToken = default) => Atomic<IReadOnlyList<StoredListing>>(_ =>
|
||||||
|
{
|
||||||
|
ArgumentNullException.ThrowIfNull(query);
|
||||||
|
if (!_available)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.ServiceUnavailable);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!IsScopeValid(query.Scope)
|
||||||
|
|| query.ProtocolVersion == 0
|
||||||
|
|| (query.RegionId.HasValue && string.IsNullOrEmpty(query.RegionId.Value.Value))
|
||||||
|
|| query.MaximumResults <= 0
|
||||||
|
|| query.MaximumResults > ContractLimits.BrowserPageMaxItems)
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(nameof(query));
|
||||||
|
}
|
||||||
|
|
||||||
|
IReadOnlyList<StoredListing> visible = _listings.Values
|
||||||
|
.Where(entry => entry.Definition.Scope == query.Scope
|
||||||
|
&& entry.Definition.ProtocolVersion == query.ProtocolVersion
|
||||||
|
&& entry.Definition.Visibility == ListingVisibility.Public
|
||||||
|
&& (!query.RegionId.HasValue || entry.Definition.RegionId == query.RegionId.Value)
|
||||||
|
&& _presence.ContainsKey(entry.Definition.HostPresenceHandle))
|
||||||
|
.OrderBy(static entry => entry.Definition.ListingId.Value)
|
||||||
|
.Take(query.MaximumResults)
|
||||||
|
.Select(Snapshot)
|
||||||
|
.ToArray();
|
||||||
|
return new(StoreResultCode.Success, visible);
|
||||||
|
}, cancellationToken);
|
||||||
|
|
||||||
|
public StoreResult<StoredJoinAttempt> CreateJoinAttempt(
|
||||||
|
CreateJoinAttemptCommand command,
|
||||||
|
CancellationToken cancellationToken = default) => Atomic<StoredJoinAttempt>(now =>
|
||||||
|
{
|
||||||
|
ArgumentNullException.ThrowIfNull(command);
|
||||||
|
ValidateAttempt(command);
|
||||||
|
ValidateIdempotency(command.IdempotencyKey, command.RequestFingerprint);
|
||||||
|
ValidateSubject(command.IdempotencyOwner, nameof(command.IdempotencyOwner));
|
||||||
|
ValidateSubject(command.ClientSubject, nameof(command.ClientSubject));
|
||||||
|
|
||||||
|
StoreResult<StoredJoinAttempt>? admission = CheckNewWorkAdmission<StoredJoinAttempt>(command.ClientSubject);
|
||||||
|
if (admission is not null)
|
||||||
|
{
|
||||||
|
return admission;
|
||||||
|
}
|
||||||
|
|
||||||
|
string idempotencyKey = $"attempt:{command.IdempotencyOwner}:{command.IdempotencyKey}";
|
||||||
|
if (_idempotency.TryGetValue(idempotencyKey, out IdempotencyEntry? previous))
|
||||||
|
{
|
||||||
|
if (!string.Equals(previous.RequestFingerprint, command.RequestFingerprint, StringComparison.Ordinal))
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.Conflict);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (previous.ResourceId is JoinAttemptId attemptId
|
||||||
|
&& _attempts.TryGetValue(attemptId, out AttemptEntry? priorAttempt))
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.Success, Snapshot(priorAttempt), true);
|
||||||
|
}
|
||||||
|
|
||||||
|
return new(StoreResultCode.Expired);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!_listings.TryGetValue(command.ListingId, out ListingEntry? listing)
|
||||||
|
|| listing.Definition.Scope != command.Scope
|
||||||
|
|| listing.Definition.ProtocolVersion != command.ProtocolVersion
|
||||||
|
|| !_presence.ContainsKey(listing.Definition.HostPresenceHandle))
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.NotFound);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (_attempts.Count >= _options.MaxJoinAttempts
|
||||||
|
|| _idempotency.Count >= _options.MaxIdempotencyEntries
|
||||||
|
|| _attempts.Values.Count(entry => entry.Command.Scope == command.Scope)
|
||||||
|
>= command.ScopeAttemptLimit)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.CapacityExceeded);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (_attempts.ContainsKey(command.AttemptId) || HandleExists(command.MediationHandle))
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.Conflict);
|
||||||
|
}
|
||||||
|
|
||||||
|
AttemptEntry attempt = new(
|
||||||
|
command,
|
||||||
|
now + _options.JoinAttemptLifetime,
|
||||||
|
WallDeadline(now, _options.JoinAttemptLifetime));
|
||||||
|
_attempts.Add(command.AttemptId, attempt);
|
||||||
|
_attemptHandles.Add(command.MediationHandle, command.AttemptId);
|
||||||
|
_idempotency.Add(idempotencyKey, new(
|
||||||
|
command.RequestFingerprint,
|
||||||
|
command.AttemptId,
|
||||||
|
now + _options.IdempotencyLifetime));
|
||||||
|
return new(StoreResultCode.Success, Snapshot(attempt));
|
||||||
|
}, cancellationToken);
|
||||||
|
|
||||||
|
public StoreResult<StoredJoinAttempt> BindAttemptEndpoint(
|
||||||
|
BindAttemptEndpointCommand command,
|
||||||
|
CancellationToken cancellationToken = default) => Atomic<StoredJoinAttempt>(_ =>
|
||||||
|
{
|
||||||
|
ArgumentNullException.ThrowIfNull(command);
|
||||||
|
if (command.Handle.Value == Guid.Empty
|
||||||
|
|| command.Role is not (AttemptPeerRole.Host or AttemptPeerRole.Client)
|
||||||
|
|| !command.CapabilityFingerprint.IsValid)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("Attempt endpoint binding is invalid.", nameof(command));
|
||||||
|
}
|
||||||
|
|
||||||
|
ValidateEndpoint(command.PublicEndpoint, command.LocalEndpoint);
|
||||||
|
if (!_available)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.ServiceUnavailable);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!_attemptHandles.TryGetValue(command.Handle, out JoinAttemptId attemptId)
|
||||||
|
|| !_attempts.TryGetValue(attemptId, out AttemptEntry? attempt))
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.NotFound);
|
||||||
|
}
|
||||||
|
|
||||||
|
SecretFingerprint expected = command.Role == AttemptPeerRole.Host
|
||||||
|
? attempt.HostCapabilityFingerprint
|
||||||
|
: attempt.ClientCapabilityFingerprint;
|
||||||
|
if (expected != command.CapabilityFingerprint)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.NotFound);
|
||||||
|
}
|
||||||
|
|
||||||
|
AttemptEndpointBinding binding = new(command.PublicEndpoint, command.LocalEndpoint);
|
||||||
|
AttemptEndpointBinding? current = command.Role == AttemptPeerRole.Host
|
||||||
|
? attempt.HostEndpoint
|
||||||
|
: attempt.ClientEndpoint;
|
||||||
|
if (current is not null)
|
||||||
|
{
|
||||||
|
return current == binding
|
||||||
|
? new(StoreResultCode.Success, Snapshot(attempt), true)
|
||||||
|
: new(StoreResultCode.ReplayRejected);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (command.Role == AttemptPeerRole.Host)
|
||||||
|
{
|
||||||
|
attempt.HostEndpoint = binding;
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
attempt.ClientEndpoint = binding;
|
||||||
|
}
|
||||||
|
|
||||||
|
return new(StoreResultCode.Success, Snapshot(attempt));
|
||||||
|
}, cancellationToken);
|
||||||
|
|
||||||
|
public StoreResult<IntroductionEndpoints> ConsumeIntroduction(
|
||||||
|
MediationHandle handle,
|
||||||
|
CancellationToken cancellationToken = default) => Atomic<IntroductionEndpoints>(_ =>
|
||||||
|
{
|
||||||
|
if (!_available)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.ServiceUnavailable);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!_attemptHandles.TryGetValue(handle, out JoinAttemptId attemptId)
|
||||||
|
|| !_attempts.TryGetValue(attemptId, out AttemptEntry? attempt))
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.NotFound);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (attempt.IntroductionConsumed)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.ReplayRejected);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (attempt.HostEndpoint is null || attempt.ClientEndpoint is null)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.Conflict);
|
||||||
|
}
|
||||||
|
|
||||||
|
attempt.IntroductionConsumed = true;
|
||||||
|
return new(StoreResultCode.Success, new(
|
||||||
|
attempt.Command.AttemptId,
|
||||||
|
attempt.HostEndpoint,
|
||||||
|
attempt.ClientEndpoint));
|
||||||
|
}, cancellationToken);
|
||||||
|
|
||||||
|
public StoreResult<bool> ConsumeReplay(
|
||||||
|
ReplayConsumption consumption,
|
||||||
|
CancellationToken cancellationToken = default) => Atomic<bool>(now =>
|
||||||
|
{
|
||||||
|
ArgumentNullException.ThrowIfNull(consumption);
|
||||||
|
if (!_available)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.ServiceUnavailable);
|
||||||
|
}
|
||||||
|
|
||||||
|
ValidateReplay(consumption);
|
||||||
|
string key = $"{consumption.Namespace}:{consumption.Key}";
|
||||||
|
if (_replay.ContainsKey(key))
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.ReplayRejected);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (_replay.Count >= _options.MaxReplayEntries)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.CapacityExceeded);
|
||||||
|
}
|
||||||
|
|
||||||
|
TimeSpan lifetime = consumption.Lifetime ?? _options.ReplayLifetime;
|
||||||
|
if (lifetime <= TimeSpan.Zero || lifetime > _options.ReplayLifetime)
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(nameof(consumption), "Replay lifetime exceeds the configured ceiling.");
|
||||||
|
}
|
||||||
|
|
||||||
|
_replay.Add(key, now + lifetime);
|
||||||
|
return new(StoreResultCode.Success, true);
|
||||||
|
}, cancellationToken);
|
||||||
|
|
||||||
|
public StoreResult<bool> RevokeListing(
|
||||||
|
SessionListingId listingId,
|
||||||
|
CancellationToken cancellationToken = default) => Atomic<bool>(_ =>
|
||||||
|
{
|
||||||
|
if (!_listings.ContainsKey(listingId))
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.NotFound);
|
||||||
|
}
|
||||||
|
|
||||||
|
RemoveListing(listingId);
|
||||||
|
return new(StoreResultCode.Success, true);
|
||||||
|
}, cancellationToken);
|
||||||
|
|
||||||
|
public StoreResult<int> RevokePrincipal(
|
||||||
|
string subject,
|
||||||
|
TimeSpan lifetime,
|
||||||
|
CancellationToken cancellationToken = default) => Atomic<int>(now =>
|
||||||
|
{
|
||||||
|
ValidateSubject(subject, nameof(subject));
|
||||||
|
if (lifetime <= TimeSpan.Zero || lifetime > TimeSpan.FromMinutes(10))
|
||||||
|
{
|
||||||
|
throw new ArgumentOutOfRangeException(nameof(lifetime));
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!_revocations.ContainsKey(subject) && _revocations.Count >= _options.MaxRevocations)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.CapacityExceeded);
|
||||||
|
}
|
||||||
|
|
||||||
|
_revocations[subject] = now + lifetime;
|
||||||
|
SessionListingId[] listings = _listings
|
||||||
|
.Where(item => string.Equals(item.Value.Definition.OwnerSubject, subject, StringComparison.Ordinal))
|
||||||
|
.Select(static item => item.Key)
|
||||||
|
.ToArray();
|
||||||
|
JoinAttemptId[] attempts = _attempts
|
||||||
|
.Where(item => string.Equals(item.Value.Command.ClientSubject, subject, StringComparison.Ordinal))
|
||||||
|
.Select(static item => item.Key)
|
||||||
|
.ToArray();
|
||||||
|
foreach (SessionListingId listingId in listings)
|
||||||
|
{
|
||||||
|
RemoveListing(listingId);
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach (JoinAttemptId attemptId in attempts)
|
||||||
|
{
|
||||||
|
RemoveAttempt(attemptId);
|
||||||
|
}
|
||||||
|
|
||||||
|
return new(StoreResultCode.Success, listings.Length + attempts.Length);
|
||||||
|
}, cancellationToken);
|
||||||
|
|
||||||
|
public void BeginDrain(CancellationToken cancellationToken = default)
|
||||||
|
{
|
||||||
|
cancellationToken.ThrowIfCancellationRequested();
|
||||||
|
lock (_gate)
|
||||||
|
{
|
||||||
|
cancellationToken.ThrowIfCancellationRequested();
|
||||||
|
if (!_drainDeadline.HasValue)
|
||||||
|
{
|
||||||
|
_drainDeadline = _monotonicClock.Elapsed + _options.GracefulDrainLifetime;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
internal void MarkUnavailable()
|
||||||
|
{
|
||||||
|
lock (_gate)
|
||||||
|
{
|
||||||
|
_available = false;
|
||||||
|
ClearActiveState();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private StoreResult<T> Atomic<T>(Func<TimeSpan, StoreResult<T>> operation, CancellationToken cancellationToken)
|
||||||
|
{
|
||||||
|
cancellationToken.ThrowIfCancellationRequested();
|
||||||
|
lock (_gate)
|
||||||
|
{
|
||||||
|
cancellationToken.ThrowIfCancellationRequested();
|
||||||
|
TimeSpan now = _monotonicClock.Elapsed;
|
||||||
|
Cleanup(now);
|
||||||
|
return operation(now);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private StoreResult<T>? CheckNewWorkAdmission<T>(string subject)
|
||||||
|
{
|
||||||
|
if (!_available)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.ServiceUnavailable);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (_drainDeadline.HasValue)
|
||||||
|
{
|
||||||
|
return new(StoreResultCode.Draining);
|
||||||
|
}
|
||||||
|
|
||||||
|
return _revocations.ContainsKey(subject)
|
||||||
|
? new(StoreResultCode.Revoked)
|
||||||
|
: null;
|
||||||
|
}
|
||||||
|
|
||||||
|
private void Cleanup(TimeSpan now)
|
||||||
|
{
|
||||||
|
if (_drainDeadline is TimeSpan drainDeadline && now >= drainDeadline)
|
||||||
|
{
|
||||||
|
ClearActiveState();
|
||||||
|
}
|
||||||
|
|
||||||
|
RemoveExpired(_revocations, now);
|
||||||
|
RemoveExpired(_replay, now);
|
||||||
|
foreach (string key in _idempotency
|
||||||
|
.Where(item => item.Value.Deadline <= now)
|
||||||
|
.Select(static item => item.Key)
|
||||||
|
.ToArray())
|
||||||
|
{
|
||||||
|
_idempotency.Remove(key);
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach (MediationHandle handle in _presence
|
||||||
|
.Where(item => item.Value.Deadline <= now)
|
||||||
|
.Select(static item => item.Key)
|
||||||
|
.ToArray())
|
||||||
|
{
|
||||||
|
_presence.Remove(handle);
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach (JoinAttemptId attemptId in _attempts
|
||||||
|
.Where(item => item.Value.Deadline <= now)
|
||||||
|
.Select(static item => item.Key)
|
||||||
|
.ToArray())
|
||||||
|
{
|
||||||
|
RemoveAttempt(attemptId);
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach (SessionListingId listingId in _listings
|
||||||
|
.Where(item => item.Value.LeaseDeadline <= now)
|
||||||
|
.Select(static item => item.Key)
|
||||||
|
.ToArray())
|
||||||
|
{
|
||||||
|
RemoveListing(listingId);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private void ClearActiveState()
|
||||||
|
{
|
||||||
|
_listings.Clear();
|
||||||
|
_leases.Clear();
|
||||||
|
_presenceHandles.Clear();
|
||||||
|
_presence.Clear();
|
||||||
|
_attempts.Clear();
|
||||||
|
_attemptHandles.Clear();
|
||||||
|
_idempotency.Clear();
|
||||||
|
_replay.Clear();
|
||||||
|
}
|
||||||
|
|
||||||
|
private void RemoveListing(SessionListingId listingId)
|
||||||
|
{
|
||||||
|
if (!_listings.Remove(listingId, out ListingEntry? listing))
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
_leases.Remove(listing.Definition.LeaseId);
|
||||||
|
_presenceHandles.Remove(listing.Definition.HostPresenceHandle);
|
||||||
|
_presence.Remove(listing.Definition.HostPresenceHandle);
|
||||||
|
foreach (JoinAttemptId attemptId in _attempts
|
||||||
|
.Where(item => item.Value.Command.ListingId == listingId)
|
||||||
|
.Select(static item => item.Key)
|
||||||
|
.ToArray())
|
||||||
|
{
|
||||||
|
RemoveAttempt(attemptId);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private void RemoveAttempt(JoinAttemptId attemptId)
|
||||||
|
{
|
||||||
|
if (_attempts.Remove(attemptId, out AttemptEntry? attempt))
|
||||||
|
{
|
||||||
|
_attemptHandles.Remove(attempt.Command.MediationHandle);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private bool HandleExists(MediationHandle handle) =>
|
||||||
|
_presenceHandles.ContainsKey(handle) || _attemptHandles.ContainsKey(handle);
|
||||||
|
|
||||||
|
private DateTimeOffset WallDeadline(TimeSpan now, TimeSpan lifetime) =>
|
||||||
|
_wallOrigin + (now - _monotonicOrigin) + lifetime;
|
||||||
|
|
||||||
|
private StoredListing Snapshot(ListingEntry entry) => new()
|
||||||
|
{
|
||||||
|
Definition = entry.Definition,
|
||||||
|
LeaseExpiresAt = entry.WallExpiresAt,
|
||||||
|
Version = entry.Version,
|
||||||
|
HasFreshPresence = _presence.ContainsKey(entry.Definition.HostPresenceHandle),
|
||||||
|
};
|
||||||
|
|
||||||
|
private static StoredJoinAttempt Snapshot(AttemptEntry entry) => new()
|
||||||
|
{
|
||||||
|
AttemptId = entry.Command.AttemptId,
|
||||||
|
MediationHandle = entry.Command.MediationHandle,
|
||||||
|
Scope = entry.Command.Scope,
|
||||||
|
ListingId = entry.Command.ListingId,
|
||||||
|
ClientSubject = entry.Command.ClientSubject,
|
||||||
|
ProtocolVersion = entry.Command.ProtocolVersion,
|
||||||
|
ExpiresAt = entry.WallExpiresAt,
|
||||||
|
HostEndpoint = entry.HostEndpoint,
|
||||||
|
ClientEndpoint = entry.ClientEndpoint,
|
||||||
|
IntroductionConsumed = entry.IntroductionConsumed,
|
||||||
|
};
|
||||||
|
|
||||||
|
private static void RemoveExpired(Dictionary<string, TimeSpan> entries, TimeSpan now)
|
||||||
|
{
|
||||||
|
foreach (string key in entries
|
||||||
|
.Where(item => item.Value <= now)
|
||||||
|
.Select(static item => item.Key)
|
||||||
|
.ToArray())
|
||||||
|
{
|
||||||
|
entries.Remove(key);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void ValidateListing(ListingDefinition listing)
|
||||||
|
{
|
||||||
|
ArgumentNullException.ThrowIfNull(listing);
|
||||||
|
ValidateSubject(listing.OwnerSubject, nameof(listing.OwnerSubject));
|
||||||
|
ArgumentNullException.ThrowIfNull(listing.Metadata);
|
||||||
|
if (listing.ListingId.Value == Guid.Empty
|
||||||
|
|| listing.LeaseId.Value == Guid.Empty
|
||||||
|
|| listing.HostPresenceHandle.Value == Guid.Empty
|
||||||
|
|| !IsScopeValid(listing.Scope)
|
||||||
|
|| string.IsNullOrEmpty(listing.RegionId.Value)
|
||||||
|
|| listing.ProtocolVersion == 0
|
||||||
|
|| !ContractValidation.IsBuildVersionValid(listing.BuildVersion)
|
||||||
|
|| !ContractValidation.IsDisplayNameValid(listing.DisplayName)
|
||||||
|
|| !Enum.IsDefined(listing.Visibility)
|
||||||
|
|| !Enum.IsDefined(listing.TrustMode)
|
||||||
|
|| listing.MaximumPlayers is <= 0 or > ContractLimits.SessionCapacityMaxPlayers
|
||||||
|
|| listing.CurrentPlayers < 0
|
||||||
|
|| listing.CurrentPlayers > listing.MaximumPlayers
|
||||||
|
|| !ContractValidation.IsMetadataValid(listing.Metadata)
|
||||||
|
|| !listing.LeaseFingerprint.IsValid
|
||||||
|
|| !listing.HostPresenceFingerprint.IsValid)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("Listing invariants are invalid.", nameof(listing));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void ValidateIdempotency(string key, string requestFingerprint)
|
||||||
|
{
|
||||||
|
if (string.IsNullOrWhiteSpace(key) || key.Length > 128)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("Idempotency keys must contain 1-128 characters.", nameof(key));
|
||||||
|
}
|
||||||
|
|
||||||
|
if (string.IsNullOrWhiteSpace(requestFingerprint) || requestFingerprint.Length > 128)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("Request fingerprints must contain 1-128 characters.", nameof(requestFingerprint));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void ValidateReplay(ReplayConsumption consumption)
|
||||||
|
{
|
||||||
|
if (string.IsNullOrWhiteSpace(consumption.Namespace) || consumption.Namespace.Length > 64
|
||||||
|
|| string.IsNullOrWhiteSpace(consumption.Key) || consumption.Key.Length > 128)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("Replay namespace/key is invalid.", nameof(consumption));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void ValidateAttempt(CreateJoinAttemptCommand command)
|
||||||
|
{
|
||||||
|
if (command.AttemptId.Value == Guid.Empty
|
||||||
|
|| command.MediationHandle.Value == Guid.Empty
|
||||||
|
|| command.ListingId.Value == Guid.Empty
|
||||||
|
|| !IsScopeValid(command.Scope)
|
||||||
|
|| command.ProtocolVersion == 0
|
||||||
|
|| !command.HostCapabilityFingerprint.IsValid
|
||||||
|
|| !command.ClientCapabilityFingerprint.IsValid
|
||||||
|
|| command.ScopeAttemptLimit <= 0)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("Join attempt invariants are invalid.", nameof(command));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void ValidateEndpoint(ObservedEndpoint publicEndpoint, ObservedEndpoint? localEndpoint)
|
||||||
|
{
|
||||||
|
if (!publicEndpoint.IsValid || (localEndpoint.HasValue && !localEndpoint.Value.IsValid))
|
||||||
|
{
|
||||||
|
throw new ArgumentException("Observed endpoints must be valid immutable endpoint values.", nameof(publicEndpoint));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static bool IsScopeValid(TenantScope scope) =>
|
||||||
|
!string.IsNullOrEmpty(scope.GameId.Value) && !string.IsNullOrEmpty(scope.EnvironmentId.Value);
|
||||||
|
|
||||||
|
private static void ValidateSubject(string subject, string parameterName)
|
||||||
|
{
|
||||||
|
if (string.IsNullOrWhiteSpace(subject) || subject.Length > 256)
|
||||||
|
{
|
||||||
|
throw new ArgumentException("Subjects must contain 1-256 characters.", parameterName);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private sealed class ListingEntry(
|
||||||
|
ListingDefinition definition,
|
||||||
|
TimeSpan leaseDeadline,
|
||||||
|
DateTimeOffset wallExpiresAt,
|
||||||
|
long version)
|
||||||
|
{
|
||||||
|
public ListingDefinition Definition { get; } = definition;
|
||||||
|
public TimeSpan LeaseDeadline { get; set; } = leaseDeadline;
|
||||||
|
public DateTimeOffset WallExpiresAt { get; set; } = wallExpiresAt;
|
||||||
|
public long Version { get; set; } = version;
|
||||||
|
}
|
||||||
|
|
||||||
|
private sealed class PresenceEntry(
|
||||||
|
ObservedEndpoint publicEndpoint,
|
||||||
|
ObservedEndpoint? localEndpoint,
|
||||||
|
TimeSpan deadline)
|
||||||
|
{
|
||||||
|
public ObservedEndpoint PublicEndpoint { get; } = publicEndpoint;
|
||||||
|
public ObservedEndpoint? LocalEndpoint { get; } = localEndpoint;
|
||||||
|
public TimeSpan Deadline { get; } = deadline;
|
||||||
|
}
|
||||||
|
|
||||||
|
private sealed class AttemptEntry(
|
||||||
|
CreateJoinAttemptCommand command,
|
||||||
|
TimeSpan deadline,
|
||||||
|
DateTimeOffset wallExpiresAt)
|
||||||
|
{
|
||||||
|
public CreateJoinAttemptCommand Command { get; } = command;
|
||||||
|
public SecretFingerprint HostCapabilityFingerprint { get; } = command.HostCapabilityFingerprint;
|
||||||
|
public SecretFingerprint ClientCapabilityFingerprint { get; } = command.ClientCapabilityFingerprint;
|
||||||
|
public TimeSpan Deadline { get; } = deadline;
|
||||||
|
public DateTimeOffset WallExpiresAt { get; } = wallExpiresAt;
|
||||||
|
public AttemptEndpointBinding? HostEndpoint { get; set; }
|
||||||
|
public AttemptEndpointBinding? ClientEndpoint { get; set; }
|
||||||
|
public bool IntroductionConsumed { get; set; }
|
||||||
|
}
|
||||||
|
|
||||||
|
private sealed record IdempotencyEntry(
|
||||||
|
string RequestFingerprint,
|
||||||
|
object ResourceId,
|
||||||
|
TimeSpan Deadline);
|
||||||
|
}
|
||||||
@@ -0,0 +1,43 @@
|
|||||||
|
{
|
||||||
|
"Rendezvous": {
|
||||||
|
"Provisioning": {
|
||||||
|
"Issuer": "final-factory-rendezvous-development",
|
||||||
|
"Audience": "final-factory-rendezvous",
|
||||||
|
"ClockSkewSeconds": 30,
|
||||||
|
"SigningKeys": [
|
||||||
|
{
|
||||||
|
"KeyId": "development-ephemeral-1",
|
||||||
|
"SecretReference": "development:ephemeral/rendezvous-signing",
|
||||||
|
"CredentialKinds": ["DedicatedPublisher", "PlayerHostGrant"],
|
||||||
|
"GameId": "space-game",
|
||||||
|
"EnvironmentId": "development",
|
||||||
|
"NotBefore": "2025-01-01T00:00:00Z",
|
||||||
|
"SignUntil": "2035-01-01T00:00:00Z",
|
||||||
|
"VerifyUntil": "2035-01-02T00:00:00Z"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"Games": [
|
||||||
|
{
|
||||||
|
"GameId": "space-game",
|
||||||
|
"EnvironmentId": "development",
|
||||||
|
"Enabled": true,
|
||||||
|
"ProtocolVersions": [1],
|
||||||
|
"Regions": ["local"],
|
||||||
|
"VisibilityModes": ["Public", "Unlisted"],
|
||||||
|
"PublisherTrustModes": ["ManagedDedicated", "PlayerGrant", "AnonymousUnlisted"],
|
||||||
|
"MetadataValueMaxBytes": {
|
||||||
|
"map": 64,
|
||||||
|
"mode": 32
|
||||||
|
},
|
||||||
|
"RequiredMetadataKeys": [],
|
||||||
|
"MetadataMaxBytes": 512,
|
||||||
|
"MetadataMaxKeys": 2,
|
||||||
|
"MaxListingsPerPrincipal": 10,
|
||||||
|
"MaxAnonymousListingsPerAddress": 1,
|
||||||
|
"MaxActiveJoinAttempts": 100,
|
||||||
|
"FallbackPolicy": "Disabled"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,83 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Tests.Provisioning;
|
||||||
|
|
||||||
|
public sealed class GamePolicyTests
|
||||||
|
{
|
||||||
|
[Fact]
|
||||||
|
public void RegistryFailsClosedForUnknownAndDisabledScopes()
|
||||||
|
{
|
||||||
|
GamePolicyRegistry registry = GamePolicyRegistry.Create(
|
||||||
|
[
|
||||||
|
ProvisioningTestData.CreatePolicy(),
|
||||||
|
ProvisioningTestData.CreatePolicy("unscouted", "staging", enabled: false),
|
||||||
|
]);
|
||||||
|
|
||||||
|
Assert.True(registry.TryGet(
|
||||||
|
new GameId("space-game"),
|
||||||
|
new EnvironmentId("production"),
|
||||||
|
out _));
|
||||||
|
Assert.False(registry.TryGet(
|
||||||
|
new GameId("space-game"),
|
||||||
|
new EnvironmentId("staging"),
|
||||||
|
out _));
|
||||||
|
Assert.False(registry.TryGet(
|
||||||
|
new GameId("unscouted"),
|
||||||
|
new EnvironmentId("staging"),
|
||||||
|
out _));
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void PerGamePolicyConstrainsProtocolMetadataQuotasAndFeatures()
|
||||||
|
{
|
||||||
|
GamePolicyRegistry registry = GamePolicyRegistry.Create(
|
||||||
|
[ProvisioningTestData.CreatePolicy()]);
|
||||||
|
Assert.True(registry.TryGet(
|
||||||
|
new GameId("space-game"),
|
||||||
|
new EnvironmentId("production"),
|
||||||
|
out GamePolicy? policy));
|
||||||
|
Assert.NotNull(policy);
|
||||||
|
|
||||||
|
Assert.True(policy.AllowsProtocol(7));
|
||||||
|
Assert.False(policy.AllowsProtocol(8));
|
||||||
|
Assert.True(policy.AllowsRegion(new RegionId("eu-central")));
|
||||||
|
Assert.False(policy.AllowsRegion(new RegionId("us-east")));
|
||||||
|
Assert.True(policy.AllowsVisibility(ListingVisibility.Public));
|
||||||
|
Assert.True(policy.AllowsPublisherTrust(PublisherTrustMode.PlayerGrant));
|
||||||
|
Assert.Equal(FallbackPolicyMode.DedicatedEndpointAllowed, policy.FallbackPolicy);
|
||||||
|
Assert.Equal(10, policy.MaxListingsPerPrincipal);
|
||||||
|
Assert.Equal(1, policy.MaxAnonymousListingsPerAddress);
|
||||||
|
Assert.Equal(100, policy.MaxActiveJoinAttempts);
|
||||||
|
Assert.True(policy.AllowsMetadata(new Dictionary<string, string>
|
||||||
|
{
|
||||||
|
["mode"] = "co-op",
|
||||||
|
["map"] = "europa",
|
||||||
|
}));
|
||||||
|
Assert.False(policy.AllowsMetadata(new Dictionary<string, string>
|
||||||
|
{
|
||||||
|
["map"] = "europa",
|
||||||
|
}));
|
||||||
|
Assert.False(policy.AllowsMetadata(new Dictionary<string, string>
|
||||||
|
{
|
||||||
|
["mode"] = "co-op",
|
||||||
|
["unknown"] = "value",
|
||||||
|
}));
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void InvalidOrDuplicatePolicyConfigurationFailsAtStartup()
|
||||||
|
{
|
||||||
|
GamePolicyOptions invalid = ProvisioningTestData.CreatePolicy();
|
||||||
|
invalid.ProtocolVersions = [];
|
||||||
|
Assert.Throws<ProvisioningConfigurationException>(() =>
|
||||||
|
GamePolicyRegistry.Create([invalid]));
|
||||||
|
|
||||||
|
Assert.Throws<ProvisioningConfigurationException>(() =>
|
||||||
|
GamePolicyRegistry.Create(
|
||||||
|
[
|
||||||
|
ProvisioningTestData.CreatePolicy(),
|
||||||
|
ProvisioningTestData.CreatePolicy(),
|
||||||
|
]));
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,225 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Tests.Provisioning;
|
||||||
|
|
||||||
|
public sealed class PrincipalCredentialTests
|
||||||
|
{
|
||||||
|
[Fact]
|
||||||
|
public void DedicatedAndPlayerGrantCredentialsRoundtripToDistinctPrincipals()
|
||||||
|
{
|
||||||
|
using DictionarySecretProvider secrets = ProvisioningTestData.CreateSecrets("secret-1");
|
||||||
|
using SigningKeyRing keys = SigningKeyRing.Create(
|
||||||
|
[ProvisioningTestData.CreateKey()],
|
||||||
|
secrets);
|
||||||
|
PrincipalCredentialService service = CreateService(keys);
|
||||||
|
DedicatedPublisherPrincipal dedicated = ProvisioningTestData.CreateDedicatedPublisher();
|
||||||
|
PlayerHostGrantPrincipal playerGrant = new(
|
||||||
|
"host-grant-7",
|
||||||
|
ProvisioningTestData.Now.AddMinutes(5),
|
||||||
|
dedicated.GameId,
|
||||||
|
dedicated.EnvironmentId,
|
||||||
|
dedicated.AllowedRegions);
|
||||||
|
|
||||||
|
CredentialValidationResult dedicatedResult = service.Validate(
|
||||||
|
service.Issue(dedicated, ProvisioningTestData.Now),
|
||||||
|
ProvisioningTestData.Now);
|
||||||
|
CredentialValidationResult grantResult = service.Validate(
|
||||||
|
service.Issue(playerGrant, ProvisioningTestData.Now),
|
||||||
|
ProvisioningTestData.Now);
|
||||||
|
|
||||||
|
Assert.IsType<DedicatedPublisherPrincipal>(dedicatedResult.Principal);
|
||||||
|
Assert.IsType<PlayerHostGrantPrincipal>(grantResult.Principal);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void WrongIssuerAndAudienceAreRejectedAfterSignatureValidation()
|
||||||
|
{
|
||||||
|
using DictionarySecretProvider secrets = ProvisioningTestData.CreateSecrets("secret-1");
|
||||||
|
using SigningKeyRing keys = SigningKeyRing.Create(
|
||||||
|
[ProvisioningTestData.CreateKey()],
|
||||||
|
secrets);
|
||||||
|
PrincipalCredentialService issuer = CreateService(keys);
|
||||||
|
string token = issuer.Issue(
|
||||||
|
ProvisioningTestData.CreateDedicatedPublisher(),
|
||||||
|
ProvisioningTestData.Now);
|
||||||
|
|
||||||
|
PrincipalCredentialService wrongIssuer = new(
|
||||||
|
"other-issuer",
|
||||||
|
"rendezvous-service",
|
||||||
|
TimeSpan.FromSeconds(30),
|
||||||
|
keys);
|
||||||
|
PrincipalCredentialService wrongAudience = new(
|
||||||
|
"final-factory-rendezvous",
|
||||||
|
"other-audience",
|
||||||
|
TimeSpan.FromSeconds(30),
|
||||||
|
keys);
|
||||||
|
|
||||||
|
Assert.Equal(
|
||||||
|
CredentialValidationError.IssuerMismatch,
|
||||||
|
wrongIssuer.Validate(token, ProvisioningTestData.Now).Error);
|
||||||
|
Assert.Equal(
|
||||||
|
CredentialValidationError.AudienceMismatch,
|
||||||
|
wrongAudience.Validate(token, ProvisioningTestData.Now).Error);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void ExpiryTamperingAndRevocationAreRejected()
|
||||||
|
{
|
||||||
|
using DictionarySecretProvider secrets = ProvisioningTestData.CreateSecrets("secret-1");
|
||||||
|
using SigningKeyRing keys = SigningKeyRing.Create(
|
||||||
|
[ProvisioningTestData.CreateKey()],
|
||||||
|
secrets);
|
||||||
|
PrincipalCredentialService service = CreateService(keys);
|
||||||
|
string token = service.Issue(
|
||||||
|
ProvisioningTestData.CreateDedicatedPublisher(
|
||||||
|
ProvisioningTestData.Now.AddMinutes(1)),
|
||||||
|
ProvisioningTestData.Now);
|
||||||
|
char replacement = token[^1] == 'A' ? 'B' : 'A';
|
||||||
|
string tampered = token[..^1] + replacement;
|
||||||
|
|
||||||
|
Assert.Equal(
|
||||||
|
CredentialValidationError.Expired,
|
||||||
|
service.Validate(token, ProvisioningTestData.Now.AddSeconds(91)).Error);
|
||||||
|
Assert.Equal(
|
||||||
|
CredentialValidationError.SignatureInvalid,
|
||||||
|
service.Validate(tampered, ProvisioningTestData.Now).Error);
|
||||||
|
Assert.True(keys.Revoke("key-1"));
|
||||||
|
Assert.Equal(
|
||||||
|
CredentialValidationError.KeyRevoked,
|
||||||
|
service.Validate(token, ProvisioningTestData.Now).Error);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void KeyRotationHonorsOverlapAndRejectsRetiredKeys()
|
||||||
|
{
|
||||||
|
SigningKeyOptions oldKey = ProvisioningTestData.CreateKey(
|
||||||
|
"old-key",
|
||||||
|
"old-secret",
|
||||||
|
ProvisioningTestData.Now.AddHours(-1),
|
||||||
|
ProvisioningTestData.Now.AddMinutes(10),
|
||||||
|
ProvisioningTestData.Now.AddMinutes(60));
|
||||||
|
SigningKeyOptions newKey = ProvisioningTestData.CreateKey(
|
||||||
|
"new-key",
|
||||||
|
"new-secret",
|
||||||
|
ProvisioningTestData.Now.AddMinutes(10),
|
||||||
|
ProvisioningTestData.Now.AddHours(2),
|
||||||
|
ProvisioningTestData.Now.AddHours(3));
|
||||||
|
using DictionarySecretProvider secrets = ProvisioningTestData.CreateSecrets(
|
||||||
|
"old-secret",
|
||||||
|
"new-secret");
|
||||||
|
using SigningKeyRing keys = SigningKeyRing.Create([oldKey, newKey], secrets);
|
||||||
|
PrincipalCredentialService service = CreateService(keys);
|
||||||
|
string oldToken = service.Issue(
|
||||||
|
ProvisioningTestData.CreateDedicatedPublisher(
|
||||||
|
ProvisioningTestData.Now.AddMinutes(50)),
|
||||||
|
ProvisioningTestData.Now);
|
||||||
|
|
||||||
|
Assert.True(service.Validate(oldToken, ProvisioningTestData.Now.AddMinutes(20)).IsValid);
|
||||||
|
Assert.Equal(
|
||||||
|
CredentialValidationError.KeyRetired,
|
||||||
|
service.Validate(oldToken, ProvisioningTestData.Now.AddMinutes(61)).Error);
|
||||||
|
|
||||||
|
string newToken = service.Issue(
|
||||||
|
ProvisioningTestData.CreateDedicatedPublisher(
|
||||||
|
ProvisioningTestData.Now.AddMinutes(90)),
|
||||||
|
ProvisioningTestData.Now.AddMinutes(20));
|
||||||
|
Assert.True(service.Validate(newToken, ProvisioningTestData.Now.AddMinutes(20)).IsValid);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void OperatorCredentialNeverBecomesAPublisherPrincipal()
|
||||||
|
{
|
||||||
|
SigningKeyOptions operatorKey = ProvisioningTestData.CreateKey(
|
||||||
|
credentialKinds: [PrincipalCredentialKind.Operator],
|
||||||
|
gameId: null,
|
||||||
|
environmentId: null);
|
||||||
|
using DictionarySecretProvider secrets = ProvisioningTestData.CreateSecrets("secret-1");
|
||||||
|
using SigningKeyRing keys = SigningKeyRing.Create(
|
||||||
|
[operatorKey],
|
||||||
|
secrets);
|
||||||
|
PrincipalCredentialService service = CreateService(keys);
|
||||||
|
OperatorPrincipal operatorPrincipal = new(
|
||||||
|
"operator-1",
|
||||||
|
ProvisioningTestData.Now.AddMinutes(5),
|
||||||
|
new HashSet<OperatorPermission> { OperatorPermission.RotateKeys });
|
||||||
|
|
||||||
|
CredentialValidationResult result = service.Validate(
|
||||||
|
service.Issue(operatorPrincipal, ProvisioningTestData.Now),
|
||||||
|
ProvisioningTestData.Now);
|
||||||
|
|
||||||
|
Assert.IsType<OperatorPrincipal>(result.Principal);
|
||||||
|
Assert.IsNotAssignableFrom<IPublisherPrincipal>(result.Principal);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void ConfiguredRevocationDoesNotRequireRetiredSecretMaterial()
|
||||||
|
{
|
||||||
|
SigningKeyOptions revoked = ProvisioningTestData.CreateKey(
|
||||||
|
"revoked-key",
|
||||||
|
"removed-secret",
|
||||||
|
revoked: true);
|
||||||
|
SigningKeyOptions active = ProvisioningTestData.CreateKey(
|
||||||
|
"active-key",
|
||||||
|
"active-secret");
|
||||||
|
using DictionarySecretProvider secrets = ProvisioningTestData.CreateSecrets("active-secret");
|
||||||
|
using SigningKeyRing keys = SigningKeyRing.Create([revoked, active], secrets);
|
||||||
|
|
||||||
|
Assert.Equal(
|
||||||
|
VerificationKeyLookup.Revoked,
|
||||||
|
keys.FindVerificationKey("revoked-key", ProvisioningTestData.Now, out _));
|
||||||
|
Assert.True(keys.TryGetSigningKey(
|
||||||
|
ProvisioningTestData.Now,
|
||||||
|
PrincipalCredentialKind.DedicatedPublisher,
|
||||||
|
"space-game",
|
||||||
|
"production",
|
||||||
|
out SigningKey? signingKey));
|
||||||
|
Assert.Equal("active-key", signingKey?.KeyId);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void SigningKeyAuthorityRejectsCrossGameClaimsEvenWithAValidSignature()
|
||||||
|
{
|
||||||
|
using DictionarySecretProvider secrets = ProvisioningTestData.CreateSecrets("secret-1");
|
||||||
|
using SigningKeyRing keys = SigningKeyRing.Create(
|
||||||
|
[ProvisioningTestData.CreateKey()],
|
||||||
|
secrets);
|
||||||
|
Assert.Equal(
|
||||||
|
VerificationKeyLookup.Available,
|
||||||
|
keys.FindVerificationKey("key-1", ProvisioningTestData.Now, out SigningKey? signingKey));
|
||||||
|
Assert.NotNull(signingKey);
|
||||||
|
|
||||||
|
CredentialPayload payload = new()
|
||||||
|
{
|
||||||
|
Version = ContractLimits.ContractVersion,
|
||||||
|
Issuer = "final-factory-rendezvous",
|
||||||
|
Audience = "rendezvous-service",
|
||||||
|
Subject = "malicious-grant-issuer",
|
||||||
|
Kind = PrincipalCredentialKind.PlayerHostGrant,
|
||||||
|
GameId = "unscouted",
|
||||||
|
EnvironmentId = "production",
|
||||||
|
Regions = ["eu-central"],
|
||||||
|
IssuedAtUnixSeconds = ProvisioningTestData.Now.ToUnixTimeSeconds(),
|
||||||
|
NotBeforeUnixSeconds = ProvisioningTestData.Now.ToUnixTimeSeconds(),
|
||||||
|
ExpiresAtUnixSeconds = ProvisioningTestData.Now.AddMinutes(5).ToUnixTimeSeconds(),
|
||||||
|
Nonce = Guid.NewGuid().ToString("N"),
|
||||||
|
};
|
||||||
|
string encodedPayload = Base64Url.Encode(
|
||||||
|
System.Text.Json.JsonSerializer.SerializeToUtf8Bytes(payload, ContractJson.Options));
|
||||||
|
string signedContent = $"rv1.key-1.{encodedPayload}";
|
||||||
|
string token = $"{signedContent}.{Base64Url.Encode(signingKey.Sign(signedContent))}";
|
||||||
|
|
||||||
|
CredentialValidationResult result = CreateService(keys).Validate(
|
||||||
|
token,
|
||||||
|
ProvisioningTestData.Now);
|
||||||
|
|
||||||
|
Assert.Equal(CredentialValidationError.KeyScopeMismatch, result.Error);
|
||||||
|
Assert.Null(result.Principal);
|
||||||
|
}
|
||||||
|
|
||||||
|
private static PrincipalCredentialService CreateService(SigningKeyRing keys) => new(
|
||||||
|
"final-factory-rendezvous",
|
||||||
|
"rendezvous-service",
|
||||||
|
TimeSpan.FromSeconds(30),
|
||||||
|
keys);
|
||||||
|
}
|
||||||
@@ -0,0 +1,97 @@
|
|||||||
|
using System.Reflection;
|
||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Tests.Provisioning;
|
||||||
|
|
||||||
|
public sealed class ProvisioningSecurityTests
|
||||||
|
{
|
||||||
|
[Fact]
|
||||||
|
public void StartupFailsClearlyWhenKeyMaterialIsAbsent()
|
||||||
|
{
|
||||||
|
ProvisioningOptions options = ProvisioningTestData.CreateOptions(
|
||||||
|
ProvisioningTestData.CreateKey(secretReference: "missing-production-secret"));
|
||||||
|
using DictionarySecretProvider empty = ProvisioningTestData.CreateSecrets();
|
||||||
|
|
||||||
|
ProvisioningConfigurationException exception = Assert.Throws<ProvisioningConfigurationException>(
|
||||||
|
() => ProvisioningRuntime.Create(options, empty, ProvisioningTestData.Now));
|
||||||
|
|
||||||
|
Assert.Contains("key-1", exception.Message, StringComparison.Ordinal);
|
||||||
|
Assert.DoesNotContain("missing-production-secret", exception.Message, StringComparison.Ordinal);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void StartupRequiresAnActivePublisherKeyForEveryEnabledPolicy()
|
||||||
|
{
|
||||||
|
ProvisioningOptions options = ProvisioningTestData.CreateOptions();
|
||||||
|
options.Games.Add(ProvisioningTestData.CreatePolicy("unscouted", "production"));
|
||||||
|
using DictionarySecretProvider secrets = ProvisioningTestData.CreateSecrets("secret-1");
|
||||||
|
|
||||||
|
ProvisioningConfigurationException exception = Assert.Throws<ProvisioningConfigurationException>(
|
||||||
|
() => ProvisioningRuntime.Create(options, secrets, ProvisioningTestData.Now));
|
||||||
|
|
||||||
|
Assert.Contains("unscouted/production", exception.Message, StringComparison.Ordinal);
|
||||||
|
Assert.Contains("key", exception.Message, StringComparison.OrdinalIgnoreCase);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void SecretMaterialCredentialsAndKeysAreRedactedFromDiagnostics()
|
||||||
|
{
|
||||||
|
byte[] knownSecret = Enumerable.Range(1, 32).Select(static value => (byte)value).ToArray();
|
||||||
|
string encodedSecret = Convert.ToBase64String(knownSecret);
|
||||||
|
using SecretMaterial material = new(knownSecret);
|
||||||
|
using DictionarySecretProvider secrets = new(new Dictionary<string, byte[]>
|
||||||
|
{
|
||||||
|
["secret-1"] = knownSecret,
|
||||||
|
});
|
||||||
|
using SigningKeyRing keys = SigningKeyRing.Create(
|
||||||
|
[ProvisioningTestData.CreateKey()],
|
||||||
|
secrets);
|
||||||
|
PrincipalCredentialService service = new(
|
||||||
|
"final-factory-rendezvous",
|
||||||
|
"rendezvous-service",
|
||||||
|
TimeSpan.FromSeconds(30),
|
||||||
|
keys);
|
||||||
|
string token = service.Issue(
|
||||||
|
ProvisioningTestData.CreateDedicatedPublisher(),
|
||||||
|
ProvisioningTestData.Now);
|
||||||
|
CredentialValidationResult result = service.Validate(token, ProvisioningTestData.Now);
|
||||||
|
|
||||||
|
string diagnostics = string.Join(
|
||||||
|
'|',
|
||||||
|
material,
|
||||||
|
secrets,
|
||||||
|
keys,
|
||||||
|
service,
|
||||||
|
result);
|
||||||
|
Assert.DoesNotContain(encodedSecret, diagnostics, StringComparison.Ordinal);
|
||||||
|
Assert.DoesNotContain(token, diagnostics, StringComparison.Ordinal);
|
||||||
|
Assert.Contains("redacted", diagnostics, StringComparison.OrdinalIgnoreCase);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void PublicClientAndContractSurfacesContainNoProvisioningSecrets()
|
||||||
|
{
|
||||||
|
Type[] publicTypes = typeof(GameId).Assembly.GetExportedTypes()
|
||||||
|
.Concat(Assembly.Load("FinalFactory.Rendezvous.Client").GetExportedTypes())
|
||||||
|
.ToArray();
|
||||||
|
string[] forbiddenTerms =
|
||||||
|
[
|
||||||
|
"GameSecret",
|
||||||
|
"SigningKey",
|
||||||
|
"KeyMaterial",
|
||||||
|
"PublisherCredential",
|
||||||
|
"SecretProvider",
|
||||||
|
];
|
||||||
|
|
||||||
|
foreach (Type type in publicTypes)
|
||||||
|
{
|
||||||
|
IEnumerable<string> names = type
|
||||||
|
.GetMembers(BindingFlags.Public | BindingFlags.Instance | BindingFlags.Static)
|
||||||
|
.Select(static member => member.Name)
|
||||||
|
.Append(type.Name);
|
||||||
|
Assert.DoesNotContain(names, name => forbiddenTerms.Any(term =>
|
||||||
|
name.Contains(term, StringComparison.OrdinalIgnoreCase)));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,98 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Tests.Provisioning;
|
||||||
|
|
||||||
|
internal static class ProvisioningTestData
|
||||||
|
{
|
||||||
|
public static readonly DateTimeOffset Now = new(2026, 7, 16, 12, 0, 0, TimeSpan.Zero);
|
||||||
|
|
||||||
|
public static GamePolicyOptions CreatePolicy(
|
||||||
|
string gameId = "space-game",
|
||||||
|
string environmentId = "production",
|
||||||
|
bool enabled = true) => new()
|
||||||
|
{
|
||||||
|
GameId = gameId,
|
||||||
|
EnvironmentId = environmentId,
|
||||||
|
Enabled = enabled,
|
||||||
|
ProtocolVersions = [7],
|
||||||
|
Regions = ["eu-central"],
|
||||||
|
VisibilityModes = [ListingVisibility.Public, ListingVisibility.Unlisted],
|
||||||
|
PublisherTrustModes =
|
||||||
|
[
|
||||||
|
PublisherTrustMode.ManagedDedicated,
|
||||||
|
PublisherTrustMode.PlayerGrant,
|
||||||
|
PublisherTrustMode.AnonymousUnlisted,
|
||||||
|
],
|
||||||
|
MetadataValueMaxBytes = new Dictionary<string, int>(StringComparer.Ordinal)
|
||||||
|
{
|
||||||
|
["map"] = 32,
|
||||||
|
["mode"] = 16,
|
||||||
|
},
|
||||||
|
RequiredMetadataKeys = ["mode"],
|
||||||
|
MetadataMaxBytes = 256,
|
||||||
|
MetadataMaxKeys = 2,
|
||||||
|
MaxListingsPerPrincipal = 10,
|
||||||
|
MaxAnonymousListingsPerAddress = 1,
|
||||||
|
MaxActiveJoinAttempts = 100,
|
||||||
|
FallbackPolicy = FallbackPolicyMode.DedicatedEndpointAllowed,
|
||||||
|
};
|
||||||
|
|
||||||
|
public static SigningKeyOptions CreateKey(
|
||||||
|
string keyId = "key-1",
|
||||||
|
string secretReference = "secret-1",
|
||||||
|
DateTimeOffset? notBefore = null,
|
||||||
|
DateTimeOffset? signUntil = null,
|
||||||
|
DateTimeOffset? verifyUntil = null,
|
||||||
|
bool revoked = false,
|
||||||
|
IEnumerable<PrincipalCredentialKind>? credentialKinds = null,
|
||||||
|
string? gameId = "space-game",
|
||||||
|
string? environmentId = "production") => new()
|
||||||
|
{
|
||||||
|
KeyId = keyId,
|
||||||
|
SecretReference = secretReference,
|
||||||
|
CredentialKinds = credentialKinds?.ToList()
|
||||||
|
?? [
|
||||||
|
PrincipalCredentialKind.DedicatedPublisher,
|
||||||
|
PrincipalCredentialKind.PlayerHostGrant,
|
||||||
|
],
|
||||||
|
GameId = gameId,
|
||||||
|
EnvironmentId = environmentId,
|
||||||
|
NotBefore = notBefore ?? Now.AddHours(-1),
|
||||||
|
SignUntil = signUntil ?? Now.AddHours(1),
|
||||||
|
VerifyUntil = verifyUntil ?? Now.AddHours(2),
|
||||||
|
Revoked = revoked,
|
||||||
|
};
|
||||||
|
|
||||||
|
public static DictionarySecretProvider CreateSecrets(params string[] references)
|
||||||
|
{
|
||||||
|
Dictionary<string, byte[]> secrets = new(StringComparer.Ordinal);
|
||||||
|
for (int index = 0; index < references.Length; index++)
|
||||||
|
{
|
||||||
|
secrets.Add(
|
||||||
|
references[index],
|
||||||
|
Enumerable.Range(1 + index, 32).Select(static value => (byte)value).ToArray());
|
||||||
|
}
|
||||||
|
|
||||||
|
return new DictionarySecretProvider(secrets);
|
||||||
|
}
|
||||||
|
|
||||||
|
public static DedicatedPublisherPrincipal CreateDedicatedPublisher(
|
||||||
|
DateTimeOffset? expiresAt = null,
|
||||||
|
string gameId = "space-game",
|
||||||
|
string environmentId = "production") => new(
|
||||||
|
"workload-42",
|
||||||
|
expiresAt ?? Now.AddMinutes(10),
|
||||||
|
new GameId(gameId),
|
||||||
|
new EnvironmentId(environmentId),
|
||||||
|
new HashSet<RegionId> { new("eu-central") });
|
||||||
|
|
||||||
|
public static ProvisioningOptions CreateOptions(SigningKeyOptions? key = null) => new()
|
||||||
|
{
|
||||||
|
Issuer = "final-factory-rendezvous",
|
||||||
|
Audience = "rendezvous-service",
|
||||||
|
ClockSkewSeconds = 30,
|
||||||
|
SigningKeys = [key ?? CreateKey()],
|
||||||
|
Games = [CreatePolicy()],
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,124 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using FinalFactory.Rendezvous.Server.Provisioning;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Tests.Provisioning;
|
||||||
|
|
||||||
|
public sealed class PublisherAuthorizationTests
|
||||||
|
{
|
||||||
|
private static readonly IReadOnlyDictionary<string, string> ValidMetadata =
|
||||||
|
new Dictionary<string, string>(StringComparer.Ordinal)
|
||||||
|
{
|
||||||
|
["mode"] = "co-op",
|
||||||
|
["map"] = "europa",
|
||||||
|
};
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void AuthoritativeScopeComesFromThePublisherPrincipal()
|
||||||
|
{
|
||||||
|
PublisherAuthorizationService service = CreateService();
|
||||||
|
DedicatedPublisherPrincipal principal = ProvisioningTestData.CreateDedicatedPublisher();
|
||||||
|
|
||||||
|
PublisherAuthorizationResult result = service.Authorize(
|
||||||
|
principal,
|
||||||
|
new GameId("space-game"),
|
||||||
|
new EnvironmentId("production"),
|
||||||
|
new RegionId("eu-central"),
|
||||||
|
7,
|
||||||
|
ListingVisibility.Public,
|
||||||
|
ValidMetadata,
|
||||||
|
ProvisioningTestData.Now);
|
||||||
|
|
||||||
|
Assert.True(result.IsAllowed);
|
||||||
|
Assert.NotNull(result.Context);
|
||||||
|
Assert.Equal(principal.GameId, result.Context.GameId);
|
||||||
|
Assert.Equal(principal.EnvironmentId, result.Context.EnvironmentId);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Theory]
|
||||||
|
[InlineData("unscouted", "production")]
|
||||||
|
[InlineData("space-game", "staging")]
|
||||||
|
public void CrossGameAndEnvironmentScopeEscalationIsDenied(
|
||||||
|
string requestedGame,
|
||||||
|
string requestedEnvironment)
|
||||||
|
{
|
||||||
|
PublisherAuthorizationResult result = CreateService().Authorize(
|
||||||
|
ProvisioningTestData.CreateDedicatedPublisher(),
|
||||||
|
new GameId(requestedGame),
|
||||||
|
new EnvironmentId(requestedEnvironment),
|
||||||
|
new RegionId("eu-central"),
|
||||||
|
7,
|
||||||
|
ListingVisibility.Public,
|
||||||
|
ValidMetadata,
|
||||||
|
ProvisioningTestData.Now);
|
||||||
|
|
||||||
|
Assert.False(result.IsAllowed);
|
||||||
|
Assert.Equal(PublisherAuthorizationError.ScopeMismatch, result.Error);
|
||||||
|
Assert.Null(result.Context);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void OperatorCannotBeUsedAsAGamePublisher()
|
||||||
|
{
|
||||||
|
OperatorPrincipal principal = new(
|
||||||
|
"operator-1",
|
||||||
|
ProvisioningTestData.Now.AddMinutes(10),
|
||||||
|
new HashSet<OperatorPermission> { OperatorPermission.ReadPolicy });
|
||||||
|
|
||||||
|
PublisherAuthorizationResult result = CreateService().Authorize(
|
||||||
|
principal,
|
||||||
|
new GameId("space-game"),
|
||||||
|
new EnvironmentId("production"),
|
||||||
|
new RegionId("eu-central"),
|
||||||
|
7,
|
||||||
|
ListingVisibility.Public,
|
||||||
|
ValidMetadata,
|
||||||
|
ProvisioningTestData.Now);
|
||||||
|
|
||||||
|
Assert.Equal(PublisherAuthorizationError.NotPublisher, result.Error);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void AnonymousPublisherCanNeverEscalateToPublicVisibility()
|
||||||
|
{
|
||||||
|
AnonymousUnlistedPrincipal principal = new(
|
||||||
|
"anonymous-source-1",
|
||||||
|
ProvisioningTestData.Now.AddMinutes(2),
|
||||||
|
new GameId("space-game"),
|
||||||
|
new EnvironmentId("production"),
|
||||||
|
new HashSet<RegionId> { new("eu-central") });
|
||||||
|
|
||||||
|
PublisherAuthorizationResult result = CreateService().Authorize(
|
||||||
|
principal,
|
||||||
|
principal.GameId,
|
||||||
|
principal.EnvironmentId,
|
||||||
|
new RegionId("eu-central"),
|
||||||
|
7,
|
||||||
|
ListingVisibility.Public,
|
||||||
|
ValidMetadata,
|
||||||
|
ProvisioningTestData.Now);
|
||||||
|
|
||||||
|
Assert.Equal(PublisherAuthorizationError.AnonymousMustBeUnlisted, result.Error);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void ExpiredPrincipalIsRecheckedAtAuthorizationTime()
|
||||||
|
{
|
||||||
|
DedicatedPublisherPrincipal principal = ProvisioningTestData.CreateDedicatedPublisher(
|
||||||
|
ProvisioningTestData.Now.AddSeconds(-1));
|
||||||
|
|
||||||
|
PublisherAuthorizationResult result = CreateService().Authorize(
|
||||||
|
principal,
|
||||||
|
principal.GameId,
|
||||||
|
principal.EnvironmentId,
|
||||||
|
new RegionId("eu-central"),
|
||||||
|
7,
|
||||||
|
ListingVisibility.Public,
|
||||||
|
ValidMetadata,
|
||||||
|
ProvisioningTestData.Now);
|
||||||
|
|
||||||
|
Assert.Equal(PublisherAuthorizationError.PrincipalExpired, result.Error);
|
||||||
|
}
|
||||||
|
|
||||||
|
private static PublisherAuthorizationService CreateService() => new(
|
||||||
|
GamePolicyRegistry.Create([ProvisioningTestData.CreatePolicy()]));
|
||||||
|
}
|
||||||
@@ -0,0 +1,105 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using FinalFactory.Rendezvous.Server.State;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Tests.State;
|
||||||
|
|
||||||
|
internal sealed class ManualRendezvousClock : IWallClock, IMonotonicClock
|
||||||
|
{
|
||||||
|
public DateTimeOffset UtcNow { get; private set; } = new(2026, 7, 16, 0, 0, 0, TimeSpan.Zero);
|
||||||
|
public TimeSpan Elapsed { get; private set; }
|
||||||
|
|
||||||
|
public void Advance(TimeSpan duration)
|
||||||
|
{
|
||||||
|
Elapsed += duration;
|
||||||
|
UtcNow += duration;
|
||||||
|
}
|
||||||
|
|
||||||
|
public void MoveWall(TimeSpan duration) => UtcNow += duration;
|
||||||
|
}
|
||||||
|
|
||||||
|
internal sealed class EphemeralStateFixture
|
||||||
|
{
|
||||||
|
private int _sequence;
|
||||||
|
|
||||||
|
public EphemeralStateFixture(EphemeralStoreOptions? options = null)
|
||||||
|
{
|
||||||
|
Clock = new();
|
||||||
|
Store = new(options ?? new EphemeralStoreOptions(), Clock, Clock);
|
||||||
|
}
|
||||||
|
|
||||||
|
public ManualRendezvousClock Clock { get; }
|
||||||
|
public InMemoryEphemeralRendezvousStore Store { get; }
|
||||||
|
public TenantScope Scope { get; } = new(new GameId("space-game"), new EnvironmentId("test"));
|
||||||
|
|
||||||
|
public CreateListingCommand ListingCommand(
|
||||||
|
string owner = "publisher-1",
|
||||||
|
string? idempotencyKey = null,
|
||||||
|
string? requestFingerprint = null)
|
||||||
|
{
|
||||||
|
int sequence = Interlocked.Increment(ref _sequence);
|
||||||
|
return new(
|
||||||
|
idempotencyKey ?? $"register-{sequence}",
|
||||||
|
requestFingerprint ?? $"request-{sequence}",
|
||||||
|
new ListingDefinition
|
||||||
|
{
|
||||||
|
ListingId = NewListingId(),
|
||||||
|
LeaseId = NewLeaseId(),
|
||||||
|
Scope = Scope,
|
||||||
|
OwnerSubject = owner,
|
||||||
|
RegionId = new RegionId("eu-central"),
|
||||||
|
ProtocolVersion = 7,
|
||||||
|
BuildVersion = "1.2.3",
|
||||||
|
DisplayName = "Test host",
|
||||||
|
Visibility = ListingVisibility.Public,
|
||||||
|
TrustMode = PublisherTrustMode.ManagedDedicated,
|
||||||
|
CurrentPlayers = 1,
|
||||||
|
MaximumPlayers = 8,
|
||||||
|
Metadata = new Dictionary<string, string>(StringComparer.Ordinal) { ["mode"] = "coop" },
|
||||||
|
LeaseFingerprint = Fingerprint($"lease-{sequence}"),
|
||||||
|
HostPresenceHandle = NewHandle(),
|
||||||
|
HostPresenceFingerprint = Fingerprint($"presence-{sequence}"),
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public StoredListing CreateVisibleListing(out CreateListingCommand command)
|
||||||
|
{
|
||||||
|
command = ListingCommand();
|
||||||
|
StoreResult<StoredListing> created = Store.CreateListing(command);
|
||||||
|
Assert.True(created.Succeeded);
|
||||||
|
StoreResult<StoredListing> bound = Store.BindHostPresence(new(
|
||||||
|
command.Listing.HostPresenceHandle,
|
||||||
|
command.Listing.HostPresenceFingerprint,
|
||||||
|
PublicEndpoint(40_000),
|
||||||
|
LocalEndpoint(40_000)));
|
||||||
|
Assert.True(bound.Succeeded);
|
||||||
|
return bound.Value!;
|
||||||
|
}
|
||||||
|
|
||||||
|
public CreateJoinAttemptCommand AttemptCommand(StoredListing listing, string owner = "client-1")
|
||||||
|
{
|
||||||
|
int sequence = Interlocked.Increment(ref _sequence);
|
||||||
|
return new()
|
||||||
|
{
|
||||||
|
IdempotencyOwner = owner,
|
||||||
|
IdempotencyKey = $"join-{sequence}",
|
||||||
|
RequestFingerprint = $"join-request-{sequence}",
|
||||||
|
ClientSubject = owner,
|
||||||
|
AttemptId = NewAttemptId(),
|
||||||
|
MediationHandle = NewHandle(),
|
||||||
|
Scope = listing.Definition.Scope,
|
||||||
|
ListingId = listing.Definition.ListingId,
|
||||||
|
ProtocolVersion = listing.Definition.ProtocolVersion,
|
||||||
|
HostCapabilityFingerprint = Fingerprint($"host-{sequence}"),
|
||||||
|
ClientCapabilityFingerprint = Fingerprint($"client-{sequence}"),
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
public static SecretFingerprint Fingerprint(string value) => new(value);
|
||||||
|
public static ObservedEndpoint PublicEndpoint(int port) => new(AddressFamilyKind.Ipv4, "203.0.113.10", port);
|
||||||
|
public static ObservedEndpoint OtherPublicEndpoint(int port) => new(AddressFamilyKind.Ipv4, "198.51.100.20", port);
|
||||||
|
public static ObservedEndpoint LocalEndpoint(int port) => new(AddressFamilyKind.Ipv4, "192.168.1.20", port);
|
||||||
|
public static SessionListingId NewListingId() => new(Guid.NewGuid());
|
||||||
|
public static LeaseId NewLeaseId() => new(Guid.NewGuid());
|
||||||
|
public static JoinAttemptId NewAttemptId() => new(Guid.NewGuid());
|
||||||
|
public static MediationHandle NewHandle() => new(Guid.NewGuid());
|
||||||
|
}
|
||||||
@@ -0,0 +1,447 @@
|
|||||||
|
using FinalFactory.Rendezvous.Contracts;
|
||||||
|
using FinalFactory.Rendezvous.Server.State;
|
||||||
|
|
||||||
|
namespace FinalFactory.Rendezvous.Tests.State;
|
||||||
|
|
||||||
|
public sealed class InMemoryEphemeralRendezvousStoreTests
|
||||||
|
{
|
||||||
|
[Fact]
|
||||||
|
public void DuplicateRegistrationIsIdempotentButChangedRequestConflicts()
|
||||||
|
{
|
||||||
|
EphemeralStateFixture fixture = new();
|
||||||
|
CreateListingCommand command = fixture.ListingCommand();
|
||||||
|
|
||||||
|
StoreResult<StoredListing> first = fixture.Store.CreateListing(command);
|
||||||
|
StoreResult<StoredListing> duplicate = fixture.Store.CreateListing(command);
|
||||||
|
StoreResult<StoredListing> changed = fixture.Store.CreateListing(command with { RequestFingerprint = "different" });
|
||||||
|
|
||||||
|
Assert.True(first.Succeeded);
|
||||||
|
Assert.True(duplicate.Succeeded);
|
||||||
|
Assert.True(duplicate.IsIdempotentReplay);
|
||||||
|
Assert.Equal(first.Value!.Definition.ListingId, duplicate.Value!.Definition.ListingId);
|
||||||
|
Assert.Equal(StoreResultCode.Conflict, changed.Code);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void LeaseAndPresenceExpiryUseMonotonicTime()
|
||||||
|
{
|
||||||
|
EphemeralStateFixture fixture = new();
|
||||||
|
StoredListing listing = fixture.CreateVisibleListing(out _);
|
||||||
|
|
||||||
|
fixture.Clock.Advance(TimeSpan.FromSeconds(20));
|
||||||
|
Assert.Equal(StoreResultCode.NotFound, fixture.Store.GetListing(listing.Definition.ListingId, true).Code);
|
||||||
|
Assert.True(fixture.Store.GetListing(listing.Definition.ListingId, false).Succeeded);
|
||||||
|
|
||||||
|
fixture.Clock.Advance(TimeSpan.FromSeconds(40));
|
||||||
|
Assert.Equal(StoreResultCode.NotFound, fixture.Store.GetListing(listing.Definition.ListingId, false).Code);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void WallClockMovementDoesNotExpireOrExtendLease()
|
||||||
|
{
|
||||||
|
EphemeralStateFixture fixture = new();
|
||||||
|
StoredListing listing = fixture.CreateVisibleListing(out CreateListingCommand command);
|
||||||
|
|
||||||
|
fixture.Clock.MoveWall(TimeSpan.FromDays(30));
|
||||||
|
Assert.True(fixture.Store.GetListing(listing.Definition.ListingId, false).Succeeded);
|
||||||
|
fixture.Clock.Advance(TimeSpan.FromSeconds(1));
|
||||||
|
StoreResult<StoredListing> renewed = fixture.Store.RenewLease(new(
|
||||||
|
listing.Definition.ListingId,
|
||||||
|
listing.Definition.LeaseId,
|
||||||
|
listing.Definition.LeaseFingerprint,
|
||||||
|
listing.Version));
|
||||||
|
Assert.Equal(new DateTimeOffset(2026, 7, 16, 0, 1, 1, TimeSpan.Zero), renewed.Value!.LeaseExpiresAt);
|
||||||
|
fixture.Clock.MoveWall(TimeSpan.FromDays(-60));
|
||||||
|
fixture.Clock.Advance(TimeSpan.FromSeconds(59));
|
||||||
|
Assert.True(fixture.Store.GetListing(listing.Definition.ListingId, false).Succeeded);
|
||||||
|
fixture.Clock.Advance(TimeSpan.FromSeconds(1));
|
||||||
|
Assert.Equal(StoreResultCode.NotFound, fixture.Store.GetListing(command.Listing.ListingId, false).Code);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public async Task RenewDeleteRaceIsAtomicAndDeleteAlwaysWinsEventually()
|
||||||
|
{
|
||||||
|
EphemeralStateFixture fixture = new();
|
||||||
|
StoredListing listing = fixture.CreateVisibleListing(out CreateListingCommand command);
|
||||||
|
using ManualResetEventSlim start = new(false);
|
||||||
|
|
||||||
|
Task<StoreResult<StoredListing>> renew = Task.Run(() =>
|
||||||
|
{
|
||||||
|
start.Wait();
|
||||||
|
return fixture.Store.RenewLease(new(
|
||||||
|
listing.Definition.ListingId,
|
||||||
|
listing.Definition.LeaseId,
|
||||||
|
listing.Definition.LeaseFingerprint,
|
||||||
|
listing.Version));
|
||||||
|
});
|
||||||
|
Task<StoreResult<bool>> delete = Task.Run(() =>
|
||||||
|
{
|
||||||
|
start.Wait();
|
||||||
|
return fixture.Store.DeleteListing(new(
|
||||||
|
command.Listing.ListingId,
|
||||||
|
command.Listing.LeaseId,
|
||||||
|
command.Listing.LeaseFingerprint));
|
||||||
|
});
|
||||||
|
|
||||||
|
start.Set();
|
||||||
|
await Task.WhenAll(renew, delete);
|
||||||
|
StoreResult<StoredListing> renewResult = await renew;
|
||||||
|
StoreResult<bool> deleteResult = await delete;
|
||||||
|
|
||||||
|
Assert.True(deleteResult.Succeeded);
|
||||||
|
Assert.Contains(renewResult.Code, new[] { StoreResultCode.Success, StoreResultCode.NotFound });
|
||||||
|
Assert.Equal(StoreResultCode.NotFound, fixture.Store.GetListing(command.Listing.ListingId, false).Code);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void CompareAndSwapPreventsStaleRenewal()
|
||||||
|
{
|
||||||
|
EphemeralStateFixture fixture = new();
|
||||||
|
StoredListing listing = fixture.CreateVisibleListing(out _);
|
||||||
|
RenewLeaseCommand command = new(
|
||||||
|
listing.Definition.ListingId,
|
||||||
|
listing.Definition.LeaseId,
|
||||||
|
listing.Definition.LeaseFingerprint,
|
||||||
|
listing.Version);
|
||||||
|
|
||||||
|
StoreResult<StoredListing> first = fixture.Store.RenewLease(command);
|
||||||
|
StoreResult<StoredListing> stale = fixture.Store.RenewLease(command);
|
||||||
|
|
||||||
|
Assert.Equal(2, first.Value!.Version);
|
||||||
|
Assert.Equal(StoreResultCode.Conflict, stale.Code);
|
||||||
|
Assert.Equal(2, stale.Value!.Version);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void JoinRequiresExactScopeProtocolAndFreshHostPresence()
|
||||||
|
{
|
||||||
|
EphemeralStateFixture fixture = new();
|
||||||
|
CreateListingCommand listingCommand = fixture.ListingCommand();
|
||||||
|
StoredListing listing = fixture.Store.CreateListing(listingCommand).Value!;
|
||||||
|
CreateJoinAttemptCommand attempt = fixture.AttemptCommand(listing);
|
||||||
|
|
||||||
|
Assert.Equal(StoreResultCode.NotFound, fixture.Store.CreateJoinAttempt(attempt).Code);
|
||||||
|
fixture.Store.BindHostPresence(new(
|
||||||
|
listingCommand.Listing.HostPresenceHandle,
|
||||||
|
listingCommand.Listing.HostPresenceFingerprint,
|
||||||
|
EphemeralStateFixture.PublicEndpoint(40_000),
|
||||||
|
null));
|
||||||
|
Assert.Equal(StoreResultCode.NotFound, fixture.Store.CreateJoinAttempt(attempt with { ProtocolVersion = 8 }).Code);
|
||||||
|
Assert.Equal(StoreResultCode.NotFound, fixture.Store.CreateJoinAttempt(attempt with
|
||||||
|
{
|
||||||
|
Scope = new(new("other-game"), new("test")),
|
||||||
|
}).Code);
|
||||||
|
Assert.True(fixture.Store.CreateJoinAttempt(attempt).Succeeded);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void DuplicateJoinIsIdempotentAndDoesNotAllocateTwice()
|
||||||
|
{
|
||||||
|
EphemeralStateFixture fixture = new();
|
||||||
|
StoredListing listing = fixture.CreateVisibleListing(out _);
|
||||||
|
CreateJoinAttemptCommand command = fixture.AttemptCommand(listing);
|
||||||
|
|
||||||
|
StoreResult<StoredJoinAttempt> first = fixture.Store.CreateJoinAttempt(command);
|
||||||
|
StoreResult<StoredJoinAttempt> duplicate = fixture.Store.CreateJoinAttempt(command);
|
||||||
|
|
||||||
|
Assert.True(first.Succeeded);
|
||||||
|
Assert.True(duplicate.Succeeded);
|
||||||
|
Assert.True(duplicate.IsIdempotentReplay);
|
||||||
|
Assert.Equal(first.Value!.AttemptId, duplicate.Value!.AttemptId);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void BrowseReturnsOnlyFreshPublicCompatibleListingsInStableOrder()
|
||||||
|
{
|
||||||
|
EphemeralStateFixture fixture = new();
|
||||||
|
StoredListing visible = fixture.CreateVisibleListing(out _);
|
||||||
|
CreateListingCommand staleCommand = fixture.ListingCommand();
|
||||||
|
fixture.Store.CreateListing(staleCommand);
|
||||||
|
CreateListingCommand unlistedCommand = fixture.ListingCommand();
|
||||||
|
unlistedCommand = unlistedCommand with
|
||||||
|
{
|
||||||
|
Listing = unlistedCommand.Listing with { Visibility = ListingVisibility.Unlisted },
|
||||||
|
};
|
||||||
|
fixture.Store.CreateListing(unlistedCommand);
|
||||||
|
fixture.Store.BindHostPresence(new(
|
||||||
|
unlistedCommand.Listing.HostPresenceHandle,
|
||||||
|
unlistedCommand.Listing.HostPresenceFingerprint,
|
||||||
|
EphemeralStateFixture.PublicEndpoint(40_099),
|
||||||
|
null));
|
||||||
|
|
||||||
|
StoreResult<IReadOnlyList<StoredListing>> result = fixture.Store.BrowseVisibleListings(new(
|
||||||
|
fixture.Scope,
|
||||||
|
visible.Definition.ProtocolVersion,
|
||||||
|
visible.Definition.RegionId));
|
||||||
|
|
||||||
|
Assert.True(result.Succeeded);
|
||||||
|
Assert.Collection(result.Value!, item => Assert.Equal(visible.Definition.ListingId, item.Definition.ListingId));
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public async Task ConcurrentEndpointBindingAcceptsOneCompleteEndpointOnly()
|
||||||
|
{
|
||||||
|
EphemeralStateFixture fixture = new();
|
||||||
|
StoredListing listing = fixture.CreateVisibleListing(out _);
|
||||||
|
CreateJoinAttemptCommand command = fixture.AttemptCommand(listing);
|
||||||
|
fixture.Store.CreateJoinAttempt(command);
|
||||||
|
BindAttemptEndpointCommand first = new(
|
||||||
|
command.MediationHandle,
|
||||||
|
AttemptPeerRole.Client,
|
||||||
|
command.ClientCapabilityFingerprint,
|
||||||
|
EphemeralStateFixture.PublicEndpoint(40_001),
|
||||||
|
EphemeralStateFixture.LocalEndpoint(40_001));
|
||||||
|
BindAttemptEndpointCommand second = first with
|
||||||
|
{
|
||||||
|
PublicEndpoint = EphemeralStateFixture.OtherPublicEndpoint(50_001),
|
||||||
|
LocalEndpoint = null,
|
||||||
|
};
|
||||||
|
using ManualResetEventSlim start = new(false);
|
||||||
|
|
||||||
|
Task<StoreResult<StoredJoinAttempt>> left = Task.Run(() => { start.Wait(); return fixture.Store.BindAttemptEndpoint(first); });
|
||||||
|
Task<StoreResult<StoredJoinAttempt>> right = Task.Run(() => { start.Wait(); return fixture.Store.BindAttemptEndpoint(second); });
|
||||||
|
start.Set();
|
||||||
|
await Task.WhenAll(left, right);
|
||||||
|
StoreResult<StoredJoinAttempt> leftResult = await left;
|
||||||
|
StoreResult<StoredJoinAttempt> rightResult = await right;
|
||||||
|
|
||||||
|
Assert.Equal(1, new[] { leftResult, rightResult }.Count(static result => result.Succeeded));
|
||||||
|
Assert.Equal(1, new[] { leftResult, rightResult }.Count(static result => result.Code == StoreResultCode.ReplayRejected));
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void AttemptCapabilitiesAndIntroductionAreOneTime()
|
||||||
|
{
|
||||||
|
EphemeralStateFixture fixture = new();
|
||||||
|
StoredListing listing = fixture.CreateVisibleListing(out _);
|
||||||
|
CreateJoinAttemptCommand command = fixture.AttemptCommand(listing);
|
||||||
|
fixture.Store.CreateJoinAttempt(command);
|
||||||
|
BindAttemptEndpointCommand host = new(
|
||||||
|
command.MediationHandle,
|
||||||
|
AttemptPeerRole.Host,
|
||||||
|
command.HostCapabilityFingerprint,
|
||||||
|
EphemeralStateFixture.PublicEndpoint(40_010),
|
||||||
|
null);
|
||||||
|
BindAttemptEndpointCommand client = new(
|
||||||
|
command.MediationHandle,
|
||||||
|
AttemptPeerRole.Client,
|
||||||
|
command.ClientCapabilityFingerprint,
|
||||||
|
EphemeralStateFixture.OtherPublicEndpoint(40_020),
|
||||||
|
null);
|
||||||
|
|
||||||
|
Assert.True(fixture.Store.BindAttemptEndpoint(host).Succeeded);
|
||||||
|
Assert.True(fixture.Store.BindAttemptEndpoint(client).Succeeded);
|
||||||
|
Assert.True(fixture.Store.BindAttemptEndpoint(client).IsIdempotentReplay);
|
||||||
|
Assert.True(fixture.Store.ConsumeIntroduction(command.MediationHandle).Succeeded);
|
||||||
|
Assert.Equal(StoreResultCode.ReplayRejected, fixture.Store.ConsumeIntroduction(command.MediationHandle).Code);
|
||||||
|
Assert.Equal(StoreResultCode.ReplayRejected, fixture.Store.BindAttemptEndpoint(client with
|
||||||
|
{
|
||||||
|
PublicEndpoint = EphemeralStateFixture.OtherPublicEndpoint(40_021),
|
||||||
|
}).Code);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void ExpiredAttemptCannotBeObservedBoundOrConsumed()
|
||||||
|
{
|
||||||
|
EphemeralStateFixture fixture = new();
|
||||||
|
StoredListing listing = fixture.CreateVisibleListing(out _);
|
||||||
|
CreateJoinAttemptCommand command = fixture.AttemptCommand(listing);
|
||||||
|
fixture.Store.CreateJoinAttempt(command);
|
||||||
|
|
||||||
|
fixture.Clock.Advance(TimeSpan.FromSeconds(30));
|
||||||
|
|
||||||
|
Assert.Equal(StoreResultCode.NotFound, fixture.Store.BindAttemptEndpoint(new(
|
||||||
|
command.MediationHandle,
|
||||||
|
AttemptPeerRole.Client,
|
||||||
|
command.ClientCapabilityFingerprint,
|
||||||
|
EphemeralStateFixture.PublicEndpoint(40_050),
|
||||||
|
null)).Code);
|
||||||
|
Assert.Equal(StoreResultCode.NotFound, fixture.Store.ConsumeIntroduction(command.MediationHandle).Code);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void GenericReplayConsumptionIsBoundedAndExpires()
|
||||||
|
{
|
||||||
|
EphemeralStoreOptions options = new() { MaxReplayEntries = 1 };
|
||||||
|
EphemeralStateFixture fixture = new(options);
|
||||||
|
|
||||||
|
Assert.True(fixture.Store.ConsumeReplay(new("ticket", "one")).Succeeded);
|
||||||
|
Assert.Equal(StoreResultCode.ReplayRejected, fixture.Store.ConsumeReplay(new("ticket", "one")).Code);
|
||||||
|
Assert.Equal(StoreResultCode.CapacityExceeded, fixture.Store.ConsumeReplay(new("ticket", "two")).Code);
|
||||||
|
fixture.Clock.Advance(options.ReplayLifetime);
|
||||||
|
Assert.True(fixture.Store.ConsumeReplay(new("ticket", "two")).Succeeded);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void PresenceAttemptAndRevocationPoolsShedWithoutPartialMutation()
|
||||||
|
{
|
||||||
|
EphemeralStoreOptions options = new()
|
||||||
|
{
|
||||||
|
MaxPresenceBindings = 1,
|
||||||
|
MaxJoinAttempts = 1,
|
||||||
|
MaxRevocations = 1,
|
||||||
|
};
|
||||||
|
EphemeralStateFixture fixture = new(options);
|
||||||
|
StoredListing first = fixture.CreateVisibleListing(out CreateListingCommand firstCommand);
|
||||||
|
CreateListingCommand secondCommand = fixture.ListingCommand(owner: "publisher-2");
|
||||||
|
fixture.Store.CreateListing(secondCommand);
|
||||||
|
|
||||||
|
Assert.Equal(StoreResultCode.CapacityExceeded, fixture.Store.BindHostPresence(new(
|
||||||
|
secondCommand.Listing.HostPresenceHandle,
|
||||||
|
secondCommand.Listing.HostPresenceFingerprint,
|
||||||
|
EphemeralStateFixture.OtherPublicEndpoint(42_000),
|
||||||
|
null)).Code);
|
||||||
|
Assert.True(fixture.Store.CreateJoinAttempt(fixture.AttemptCommand(first)).Succeeded);
|
||||||
|
Assert.Equal(StoreResultCode.CapacityExceeded, fixture.Store.CreateJoinAttempt(fixture.AttemptCommand(first, "client-2")).Code);
|
||||||
|
Assert.True(fixture.Store.RevokePrincipal("unrelated", TimeSpan.FromMinutes(1)).Succeeded);
|
||||||
|
Assert.Equal(StoreResultCode.CapacityExceeded, fixture.Store.RevokePrincipal(firstCommand.Listing.OwnerSubject, TimeSpan.FromMinutes(1)).Code);
|
||||||
|
Assert.True(fixture.Store.GetListing(first.Definition.ListingId, true).Succeeded);
|
||||||
|
Assert.True(fixture.Store.GetListing(secondCommand.Listing.ListingId, false).Succeeded);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void ExhaustionShedsNewListingWithoutMutatingExistingState()
|
||||||
|
{
|
||||||
|
EphemeralStoreOptions options = new() { MaxListings = 1 };
|
||||||
|
EphemeralStateFixture fixture = new(options);
|
||||||
|
CreateListingCommand first = fixture.ListingCommand();
|
||||||
|
CreateListingCommand second = fixture.ListingCommand();
|
||||||
|
|
||||||
|
Assert.True(fixture.Store.CreateListing(first).Succeeded);
|
||||||
|
Assert.Equal(StoreResultCode.CapacityExceeded, fixture.Store.CreateListing(second).Code);
|
||||||
|
Assert.True(fixture.Store.GetListing(first.Listing.ListingId, false).Succeeded);
|
||||||
|
Assert.Equal(StoreResultCode.NotFound, fixture.Store.GetListing(second.Listing.ListingId, false).Code);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void IdempotencyPoolExhaustionDoesNotCreateUntrackedResource()
|
||||||
|
{
|
||||||
|
EphemeralStoreOptions options = new() { MaxListings = 2, MaxIdempotencyEntries = 1 };
|
||||||
|
EphemeralStateFixture fixture = new(options);
|
||||||
|
CreateListingCommand first = fixture.ListingCommand();
|
||||||
|
CreateListingCommand second = fixture.ListingCommand();
|
||||||
|
|
||||||
|
Assert.True(fixture.Store.CreateListing(first).Succeeded);
|
||||||
|
Assert.Equal(StoreResultCode.CapacityExceeded, fixture.Store.CreateListing(second).Code);
|
||||||
|
Assert.True(fixture.Store.GetListing(first.Listing.ListingId, false).Succeeded);
|
||||||
|
Assert.Equal(StoreResultCode.NotFound, fixture.Store.GetListing(second.Listing.ListingId, false).Code);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void PolicyQuotasAreCheckedInsideAtomicCreation()
|
||||||
|
{
|
||||||
|
EphemeralStateFixture fixture = new();
|
||||||
|
CreateListingCommand first = fixture.ListingCommand(owner: "publisher-quota") with { OwnerListingLimit = 1 };
|
||||||
|
CreateListingCommand second = fixture.ListingCommand(owner: "publisher-quota") with { OwnerListingLimit = 1 };
|
||||||
|
Assert.True(fixture.Store.CreateListing(first).Succeeded);
|
||||||
|
Assert.Equal(StoreResultCode.CapacityExceeded, fixture.Store.CreateListing(second).Code);
|
||||||
|
|
||||||
|
fixture.Store.BindHostPresence(new(
|
||||||
|
first.Listing.HostPresenceHandle,
|
||||||
|
first.Listing.HostPresenceFingerprint,
|
||||||
|
EphemeralStateFixture.PublicEndpoint(42_100),
|
||||||
|
null));
|
||||||
|
StoredListing listing = fixture.Store.GetListing(first.Listing.ListingId, true).Value!;
|
||||||
|
CreateJoinAttemptCommand attempt = fixture.AttemptCommand(listing) with { ScopeAttemptLimit = 1 };
|
||||||
|
Assert.True(fixture.Store.CreateJoinAttempt(attempt).Succeeded);
|
||||||
|
Assert.Equal(StoreResultCode.CapacityExceeded, fixture.Store.CreateJoinAttempt(
|
||||||
|
fixture.AttemptCommand(listing, "client-quota-2") with { ScopeAttemptLimit = 1 }).Code);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void InvalidDefaultSecurityValuesCannotEnterStore()
|
||||||
|
{
|
||||||
|
EphemeralStateFixture fixture = new();
|
||||||
|
CreateListingCommand command = fixture.ListingCommand();
|
||||||
|
|
||||||
|
Assert.Throws<ArgumentException>(() => fixture.Store.CreateListing(command with
|
||||||
|
{
|
||||||
|
Listing = command.Listing with { LeaseFingerprint = default },
|
||||||
|
}));
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void RevocationRemovesEveryPathAndBlocksNewWorkAtomically()
|
||||||
|
{
|
||||||
|
EphemeralStateFixture fixture = new();
|
||||||
|
StoredListing listing = fixture.CreateVisibleListing(out CreateListingCommand command);
|
||||||
|
CreateJoinAttemptCommand attempt = fixture.AttemptCommand(listing, command.Listing.OwnerSubject);
|
||||||
|
fixture.Store.CreateJoinAttempt(attempt);
|
||||||
|
|
||||||
|
StoreResult<int> revoked = fixture.Store.RevokePrincipal(command.Listing.OwnerSubject, TimeSpan.FromMinutes(1));
|
||||||
|
|
||||||
|
Assert.True(revoked.Succeeded);
|
||||||
|
Assert.Equal(2, revoked.Value);
|
||||||
|
Assert.Equal(StoreResultCode.NotFound, fixture.Store.GetListing(listing.Definition.ListingId, false).Code);
|
||||||
|
Assert.Equal(StoreResultCode.NotFound, fixture.Store.BindAttemptEndpoint(new(
|
||||||
|
attempt.MediationHandle,
|
||||||
|
AttemptPeerRole.Client,
|
||||||
|
attempt.ClientCapabilityFingerprint,
|
||||||
|
EphemeralStateFixture.PublicEndpoint(40_030),
|
||||||
|
null)).Code);
|
||||||
|
Assert.Equal(StoreResultCode.Revoked, fixture.Store.CreateListing(fixture.ListingCommand(owner: command.Listing.OwnerSubject)).Code);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void RestartHasNewGenerationAndNoEphemeralState()
|
||||||
|
{
|
||||||
|
EphemeralStateFixture before = new();
|
||||||
|
StoredListing listing = before.CreateVisibleListing(out _);
|
||||||
|
EphemeralStateFixture after = new();
|
||||||
|
|
||||||
|
Assert.NotEqual(before.Store.InstanceId, after.Store.InstanceId);
|
||||||
|
Assert.Equal(StoreResultCode.NotFound, after.Store.GetListing(listing.Definition.ListingId, false).Code);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void DrainRejectsNewWorkAllowsInflightCompletionThenClearsState()
|
||||||
|
{
|
||||||
|
EphemeralStoreOptions options = new() { GracefulDrainLifetime = TimeSpan.FromSeconds(5) };
|
||||||
|
EphemeralStateFixture fixture = new(options);
|
||||||
|
StoredListing listing = fixture.CreateVisibleListing(out _);
|
||||||
|
CreateJoinAttemptCommand attempt = fixture.AttemptCommand(listing);
|
||||||
|
fixture.Store.CreateJoinAttempt(attempt);
|
||||||
|
fixture.Store.BeginDrain();
|
||||||
|
|
||||||
|
Assert.Equal(StoreResultCode.Draining, fixture.Store.CreateListing(fixture.ListingCommand()).Code);
|
||||||
|
Assert.Equal(StoreResultCode.Draining, fixture.Store.CreateJoinAttempt(fixture.AttemptCommand(listing)).Code);
|
||||||
|
Assert.True(fixture.Store.BindAttemptEndpoint(new(
|
||||||
|
attempt.MediationHandle,
|
||||||
|
AttemptPeerRole.Client,
|
||||||
|
attempt.ClientCapabilityFingerprint,
|
||||||
|
EphemeralStateFixture.PublicEndpoint(41_000),
|
||||||
|
null)).Succeeded);
|
||||||
|
|
||||||
|
fixture.Clock.Advance(options.GracefulDrainLifetime);
|
||||||
|
Assert.Equal(StoreResultCode.NotFound, fixture.Store.GetListing(listing.Definition.ListingId, false).Code);
|
||||||
|
Assert.Equal(StoreResultCode.NotFound, fixture.Store.BindAttemptEndpoint(new(
|
||||||
|
attempt.MediationHandle,
|
||||||
|
AttemptPeerRole.Host,
|
||||||
|
attempt.HostCapabilityFingerprint,
|
||||||
|
EphemeralStateFixture.PublicEndpoint(41_001),
|
||||||
|
null)).Code);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void PrecancelledOperationHasNoPartialEffect()
|
||||||
|
{
|
||||||
|
EphemeralStateFixture fixture = new();
|
||||||
|
CreateListingCommand command = fixture.ListingCommand();
|
||||||
|
using CancellationTokenSource cancellation = new();
|
||||||
|
cancellation.Cancel();
|
||||||
|
|
||||||
|
Assert.Throws<OperationCanceledException>(() => fixture.Store.CreateListing(command, cancellation.Token));
|
||||||
|
Assert.Equal(StoreResultCode.NotFound, fixture.Store.GetListing(command.Listing.ListingId, false).Code);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void UnavailableStoreFailsNewAuthorizationClosedAndErasesActiveState()
|
||||||
|
{
|
||||||
|
EphemeralStateFixture fixture = new();
|
||||||
|
StoredListing listing = fixture.CreateVisibleListing(out _);
|
||||||
|
fixture.Store.MarkUnavailable();
|
||||||
|
|
||||||
|
Assert.Equal(StoreResultCode.ServiceUnavailable, fixture.Store.GetListing(listing.Definition.ListingId, false).Code);
|
||||||
|
Assert.Equal(StoreResultCode.ServiceUnavailable, fixture.Store.CreateJoinAttempt(fixture.AttemptCommand(listing)).Code);
|
||||||
|
}
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user