Declaraciones públicas de zig/src/handshake.zig (spire-zig (SDK consumido)).
apps/docs/generated/zig/spire.jsonPágina generada desde
spire@spire-0.2.0-XvnrRek1BgCX4Bh8miuITCQgkn0FqeQrYYE3goFfDcQd (zig/src/root.zig). No se edita a mano:bun run docs:genla regenera ybun run docs:checkfalla si difiere.
Handshake de spire sobre unix socket (dec-0119 §3.2), autenticación mutua con las claves de servicio del keyring.
S → C HELLO ver=1 ‖ challenge_s[32] ‖ lp8(server_id) C → S AUTH ver=1 ‖ lp8(client_id) ‖ kid[8] ‖ challenge_c[32] ‖ sig[64] sig = Ed25519_c("spire/hs/v1/client\0" ‖ challenge_s ‖ lp8(server_id) ‖ lp8(client_id) ‖ challenge_c) S → C WELCOME ver=1 ‖ status (0 ok · 1 denied) ‖ [ok: kid[8] ‖ sig[64]] sig = Ed25519_s("spire/hs/v1/server\0" ‖ challenge_c ‖ challenge_s ‖ lp8(server_id) ‖ lp8(client_id))
El servidor no procesa ningún frame de sobre antes de un AUTH válido
(y lo exige en 2 s: lo hace el transporte). Las dos firmas cubren los dos
retos y las dos identidades: no se puede reenviar un AUTH a otro servidor
ni un WELCOME a otro cliente. SO_PEERCRED va aparte (transporte): el uid
no identifica al servicio en contenedores con uids compartidos, la clave sí.
handshake.VERSIONconst · línea 23
pub const VERSION: u8 = 1Sin ///.
handshake.CHALLENGE_LENconst · línea 24
pub const CHALLENGE_LEN: usize = 32Sin ///.
handshake.MAX_BODYconst · línea 27
pub const MAX_BODY: usize = 1 + 1 + envelope.MAX_SOURCE_LEN + 8 + CHALLENGE_LEN + 64Sin ///.
handshake.Errorconst · línea 29
pub const Error = error{ Malformed, UnsupportedVersion, UnknownKey, IdentityMismatch, BadSignature, Denied, NotAllowed, }Sin ///.
handshake.Challengeconst · línea 39
pub const Challenge = [CHALLENGE_LEN]u8Sin ///.
handshake.Hellotype · línea 77
pub const Hello = structSin ///.
handshake.encodeHellofn · línea 82
pub fn encodeHello(out: []u8, h: Hello) []const u8Sin ///.
handshake.decodeHellofn · línea 92
pub fn decodeHello(body: []const u8) Error!HelloSin ///.
handshake.Authtype · línea 104
pub const Auth = structSin ///.
handshake.buildAuthfn · línea 112
pub fn buildAuth(out: []u8, signer: *const envelope.Signer, client_id: []const u8, hello: Hello, client_challenge: Challenge) error{SigningFailed}![]const u8Construye el AUTH del cliente para un HELLO recibido.
handshake.decodeAuthfn · línea 129
pub fn decodeAuth(body: []const u8) Error!AuthSin ///.
handshake.verifyAuthfn · línea 143
pub fn verifyAuth(kr: *const keyring_mod.Keyring, hello: Hello, body: []const u8, allowed: ?[]const []const u8) Error!AuthServidor: valida el AUTH contra su HELLO. allowed (si no es null) es
la lista de servicios que pueden conectarse a este socket.
handshake.buildWelcomefn · línea 160
pub fn buildWelcome(out: []u8, signer: *const envelope.Signer, hello: Hello, auth: *const Auth) error{SigningFailed}![]const u8Sin ///.
handshake.deniedfn · línea 171
pub fn denied(out: []u8) []const u8Sin ///.
handshake.verifyWelcomefn · línea 178
pub fn verifyWelcome(kr: *const keyring_mod.Keyring, hello: Hello, client_id: []const u8, client_challenge: Challenge, expected_server: []const u8, body: []const u8) Error!voidCliente: el WELCOME lo firma de verdad hello.server_id y cubre nuestro reto.
handshake.newChallengefn · línea 199
pub fn newChallenge() ChallengeSin ///.