Module http_service
http and std only.Expand description
Select a physical endpoint and HTTP protocol without changing the logical origin.
An alternative is another way to reach the same origin, not an HTTP redirect
(RFC 7838 §2). Its address goes in ConnectorTarget; the request authority,
TLS server name and verification policy still belong to the origin. Selection
happens before dispatch: this connector never consumes or replays an HTTP body.
The connection type is unchanged. HttpServiceSelection is published on the
winning input; EstablishedHttpService belongs to the connection. An HTTP
observer can use these public contracts without coupling this selector to its
service type. Compose response middleware separately, after selection.
ConnectRequest: logical origin + optional required HTTP version
|
v
Request-supplied candidates, otherwise Alt-Svc cache
|
v
Filter known HTTP protocols, required version and backoff
|
v
Try alternative ----------------------> Verify origin + protocol
| failure | valid
v v
Next alternative (repeat) Return connection + winning input
| none usable ^
v |
Original endpoint -------- success ------------+
Every attempt: proxy-route selection -> pool -> transport/TLS/HTTP
The actual connector enforces peer requirements using its effective policy.
Learning: response headers + H2 ALTSVC observer -> shared cachePlace HttpServiceConnector outside proxy-route selection and pooling:
each candidate is reached through the configured routes, with a pool key that
includes its physical target. Attempts fork the original connection input so
failed attempts cannot leave routing state behind; the winner returns its own
established input. One attempt is reserved for the original endpoint.
RFC 7838 §2.4 permits fallback. Rama tries alternatives sequentially, with a
per-alternative deadline and an optional overall deadline. Remote failures
allow fallback while preserving any required version. Candidate-specific local
failures also fall back; the original endpoint still enforces the unchanged
policy. Only exhaustion of the overall deadline stops selection early.
Unsupported protocols and routes are local refusals, not broken alternatives;
they consume the candidate limit but leave the connection-attempt budget intact.
A request-specific TLS failure does not mark an
alternative broken for clients using the default policy. Connectors report
ConnectionPolicyScope during setup and on pooled connections; an unknown
scope permits use of a verified connection but never shares policy failures.
Discovery and use are separate: HTTP advertisements can be cached, but this
selector currently uses alternatives only for HTTPS. It verifies the origin’s
authenticated identity (RFC 7838 §2.1), advertised ALPN and established HTTP
version even on pool hits. Serving http origins over TLS additionally needs
the opt-in checks of RFC 8164 §2, which are not implemented here. WebSocket
handshakes can learn hints but do not select alternative endpoints here.
Separately composed crate::layer::alt_svc::AltSvc handles response
headers (RFC 7838 §3), Alt-Used (§5) and 421
invalidation (§6). The H2 observer learns connection-level advertisements
(RFC 7838 §4); both feed the same cache in receive order.
Structs§
- Http
Service Attempt - Requirements and observations for one connection attempt, shared with address races and outer deadlines through request extensions.
- Http
Service Connector - Discover and select an HTTP service before invoking an inner route connector.
- Http
Service Layer - HTTP service discovery and bounded connection-selection policy.