Files
rustfs/protocol/agent/v1/fixtures/version/field-registry.json
T
overtrue 3b5164032a feat(connect): add device identity store and registration proof
A RustFS cluster device needs a durable identity before it can exchange a
one-time registration token for a certificate. This adds the device-side
half of that exchange, which rustfs/connect already verifies.

`connect::identity` builds the canonical registration transcript frozen by
protocol/agent/v1/registration-proof.md, signs it as low-S ES256, and emits
the PKCS#10 certificate request Connect consumes for its SubjectPublicKeyInfo.
`connect::identity_store` seals the P-256 key at mode 0600 and publishes it
through a no-clobber link, so a retry or a concurrent start returns the
original identity rather than minting a second one, and a corrupt or widened
key is refused rather than silently replaced.

The protocol fixture set is copied here byte-identically because
fixture-sets.json names this repository as the consumer copy; the tests
verify it against its own manifests and cross-verify Connect-produced ECDSA
proofs against transcripts rebuilt locally.

Nothing starts a task or touches the S3 data path: an unenrolled deployment
generates no key and holds no identity.
2026-08-19 12:54:50 +08:00

35 lines
1.2 KiB
JSON

{
"protocolVersion": "v1",
"fixtureSet": "version",
"fixture": "field-registry",
"description": "The frozen v1 negotiation envelope. Registration and heartbeat both carry it. Any top-level field not listed here is unknown and is discarded after acceptance.",
"envelope": "AgentProtocolNegotiation",
"supportedMajorVersions": [1],
"protocolVersionPattern": "^v[1-9][0-9]{0,3}$",
"unknownFieldPolicy": "accept-and-discard",
"unknownCapabilityPolicy": "discard",
"fields": [
{
"name": "protocolVersion",
"requiredness": "required",
"type": "string",
"default": null,
"note": "Major version only. The minor and patch level of an agent is not negotiated."
},
{
"name": "agentVersion",
"requiredness": "optional",
"type": "string",
"default": null,
"note": "Informational. Connect never compares it for equality with its own version and never gates behavior on it."
},
{
"name": "capabilities",
"requiredness": "optional",
"type": "array",
"default": [],
"note": "Unordered token set. A capability an operation requires but the device did not report fails that operation with a structured result, not the connection."
}
]
}