Referencia Zigmedia-daemon: socket de control

media-daemon/ipc/control.zig

Declaraciones públicas de media-daemon/ipc/control.zig (media-daemon: socket de control).

ImplementadoSin versión del tren todavía· generada desde apps/docs/generated/zig/media-daemon-ipc.json

Página generada desde native/zig/media-daemon/ipc/control.zig. No se edita a mano: bun run docs:gen la regenera y bun run docs:check falla si difiere.

Control socket of the daemon (dec-0120; protocols/session-ipc v2): Bun decides, the daemon executes (r01). The wire, identity and authorization are spire's (dec-0119), the one implementation shared with every other process of styx:

  • unix transport: SO_PEERCRED (uid/gid allowlist) and a signed mutual handshake within 2 s before any envelope is read;
  • every message is a signed envelope v2 (Ed25519, anti-replay window, deadline) that the router verifies before anything else;
  • every handler is registered with its contract (generated from @styx/api-contracts/bus, contracts.generated.zig) and its policy (generated from BUS_ROUTES): a handler without policy does not compile, a sender outside the allowlist is denied and audited, input and output are validated against the contract, memory per message is budgeted.

What stays here is the daemon's business: sessions over the data plane (WebTransport / HTTP/3), capability binding (dec-0117 I2), packaging (dec-0110), probes by the media engine (dec-0110 ME1, probe_ipc.zig) and ingest sessions (dec-0121, ingest_ipc.zig). Media bytes never travel on this socket.

DEFAULT_SOCKET_PATH

const · línea 44

pub const DEFAULT_SOCKET_PATH = "/tmp/styx-media-daemon.sock"

Sin ///.

SELF_SERVICE

const · línea 46

pub const SELF_SERVICE = "media-daemon"

Identity of the daemon on the bus (source of its envelopes).

REPLAY_WINDOW_MS

const · línea 53

pub const REPLAY_WINDOW_MS: u64 = 10_000

Anti-replay window of the control socket. Its peers share the host clock; the nonce cache is sized as rate × window per sender (spire ReplayGuard.reserve), so the window is also its memory.

MAX_REQUEST_ID_LEN

const · línea 55

pub const MAX_REQUEST_ID_LEN: usize = 64

Bound of the requestId a client can use to cancel (contract pattern).

Identity

type · línea 61

pub const Identity = struct

The daemon's key on the bus and the public keys it trusts. Immutable once built; shared read-only by every connection thread.

Identity.Error

const · línea 65

pub const Error = error{ IdentityMissing, IdentityInvalid }

Sin ///.

Identity.fromText

fn · línea 71

pub fn fromText(seed_b64: []const u8, keyring_text: []const u8) Error!Identity

SPIRE_SEED (base64url Ed25519 seed) and SPIRE_KEYRING (service=<public key>,…), the same variables as every TS service. The daemon's own key must be in the keyring as media-daemon: a crossed configuration would sign envelopes nobody can verify.

App

type · línea 144

pub const App = struct

State the handlers act on. Every field is either immutable after startup or synchronized by its owner (registry, manager, authority, store).

Options

type · línea 480

pub const Options = struct

Sin ///.

ControlServer

type · línea 493

pub const ControlServer = struct

Sin ///.

ControlServer.init

fn · línea 505

pub fn init(self: *ControlServer, allocator: std.mem.Allocator, identity: *const Identity, opts: Options) !void

In place: the router and the server keep pointers into self.

ControlServer.deinit

fn · línea 542

pub fn deinit(self: *ControlServer) void

Sin ///.

ControlServer.start

fn · línea 550

pub fn start(self: *ControlServer) !void

Binds the socket and starts accepting (own thread).

ControlServer.stop

fn · línea 558

pub fn stop(self: *ControlServer) void

Closes the socket and every connection, joining their threads.

ControlServer.listen

fn · línea 569

pub fn listen(self: *ControlServer, running: *const std.atomic.Value(bool)) !void

Serves until running goes false (the daemon's main thread).

ControlServer.sessionCount

fn · línea 576

pub fn sessionCount(self: *ControlServer) usize

Sin ///.

ControlServer.controlLiveBytes

fn · línea 580

pub fn controlLiveBytes(self: *const ControlServer) u64

Sin ///.

ControlServer.attachAuthority

fn · línea 584

pub fn attachAuthority(self: *ControlServer, authority: *authority_mod.Authority) void

Sin ///.

ControlServer.attachIngest

fn · línea 590

pub fn attachIngest(self: *ControlServer, sink: *ingest_mod.IngestSink, endpoint: []const u8) void

dec-0121: wire the IngestSink and the URL clients upload to. Both must outlive the server.

ControlServer.attachManager

fn · línea 597

pub fn attachManager(self: *ControlServer, manager: *MediaSessionManager) void

Wire the MediaSessionManager, independent of which transports came up (m4#08: a WT that fails to bind must not leave H3 without sessions).

ControlServer.attachPackaging

fn · línea 601

pub fn attachPackaging(self: *ControlServer, store: *packaging_store.Store) void

Sin ///.

ControlServer.setEndpointHost

fn · línea 606

pub fn setEndpointHost(self: *ControlServer, host: []const u8) void

Public host of every data-plane URL, whatever transports came up.

ControlServer.attachTransport

fn · línea 612

pub fn attachTransport(self: *ControlServer, transport: *QuicZigTransport, wt_host: []const u8, wt_port: u16) void

Wire WebTransport: new sessions are served over it (and the manager routes requestIds to it for O(1) cancel).

ControlServer.attachH3Transport

fn · línea 623

pub fn attachH3Transport(self: *ControlServer, h3: *h3z_transport.H3ZTransport) void

Wire HTTP/3, in addition to (or instead of) WebTransport.