- rename the two libraries: writeonce-framework -> writeonce-serve
(`use serve`), wo-html -> writeonce-view (`use view`). Names say the
ROLE now; every sample, script, gate and live doc follows
- stories/specs/plans keep the old names: they are dated records, and
both library READMEs carry a "renamed 2026-08-25" note
- serve/http/files.wo: StaticFiles { dir, max_bytes } — traversal
refused not normalised, extension content types, attachment
disposition for archives. Lifted out of the shop, which had said in
a comment that it belonged in the framework
- shop drops its private copy and mounts the framework's
- site: /dl/*path over $WO_DIST (default ./dist), 16 MiB ceiling
- /install gains supported systems — Linux x86-64, glibc >= 2.38,
not musl — read off `file` and the binaries' GLIBC_ symbol
versions, not off a wish list; plus GitHub release as primary,
/dl as mirror, and the sha256 verify step
- site-accept: 17 -> 21 checks (supported systems, gzip download with
a binary-safe probe, checksum, /dl traversal 404)
Verified on 192.168.0.165: the real 960,820-byte tarball downloads
as application/gzip and its sha256 matches the published digest.
Gates: oop-accept MET, site 21/0, web-app 46/0, fibers 10/0,
db-actor 8/0; shop rebuilt and its /assets served by the framework.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
153 lines
5.8 KiB
Text
153 lines
5.8 KiB
Text
-- internal/serve.wo — response serialization + the blocking keep-alive serve
|
|
-- loop. The dispatch seam is the Dispatcher interface (the router's App
|
|
-- satisfies it, Task 3); it is wrapped in `try`, so a trapping handler
|
|
-- answers 500 and the loop lives — a bad request must never kill the
|
|
-- server. Every accept path closes its fd; `env.stopping()` is honored
|
|
-- between connections and between keep-alive requests (a SIGTERM landing
|
|
-- in a blocking call already unwinds cleanly — the runtime's stop story).
|
|
use net
|
|
use env
|
|
-- iteration 17: serve.wo moved under internal/, so Req/Resp and the response
|
|
-- builders are no longer same-module — they live in the public `http` module.
|
|
use http
|
|
use internal
|
|
|
|
pub interface Dispatcher {
|
|
fn dispatch(mut req: Req) -> Resp
|
|
}
|
|
|
|
fn status_text(code: Int) -> Text {
|
|
switch code {
|
|
case 200: return "OK";
|
|
case 201: return "Created";
|
|
case 302: return "Found";
|
|
case 400: return "Bad Request";
|
|
case 401: return "Unauthorized";
|
|
case 404: return "Not Found";
|
|
case 405: return "Method Not Allowed";
|
|
case 409: return "Conflict";
|
|
case 500: return "Internal Server Error";
|
|
default: return "Status";
|
|
}
|
|
}
|
|
|
|
-- head_only: HEAD answers — full status line + headers (Content-Length of
|
|
-- the body a GET would have sent) with the body itself suppressed.
|
|
pub fn serialize(resp: Resp, keep: Bool, head_only: Bool) -> Text {
|
|
let head = "HTTP/1.1 ${resp.status} ${status_text(resp.status)}\r\n";
|
|
for k, v in resp.headers {
|
|
head = head .. "${k}: ${v}\r\n";
|
|
}
|
|
if keep {
|
|
head = head .. "Connection: keep-alive\r\n";
|
|
} else {
|
|
head = head .. "Connection: close\r\n";
|
|
}
|
|
head = head .. "Content-Length: ${len(resp.body)}\r\n\r\n";
|
|
if head_only { return head; }
|
|
return head .. resp.body;
|
|
}
|
|
|
|
-- iteration 35, the serving slice: ONE connection served to completion —
|
|
-- the keep-alive loop with per-read deadlines. Meant to run INSIDE an
|
|
-- app-spawned per-connection actor (fiber): a parked idle connection is
|
|
-- legal there (it blocks nobody), so keep-alive stays OPEN until the
|
|
-- idle deadline evicts it — close-when-idle retires. read_ms bounds a
|
|
-- slow peer mid-request (torn = 400-and-close); idle_ms bounds the wait
|
|
-- for a request's first bytes (expiry = clean close). ms <= 0 = forever.
|
|
-- Closes the fd on every path except a WS hijack (status 101).
|
|
pub fn serve_conn(c: net.Conn, d: Dispatcher, read_ms: Int, idle_ms: Int) {
|
|
let carry = "";
|
|
let alive = true;
|
|
let hijacked = false;
|
|
while alive {
|
|
if env.stopping() { alive = false; continue; }
|
|
let p = try parse_request(c, carry, idle_ms, read_ms) catch (e) nil;
|
|
if p == nil { alive = false; continue; }
|
|
if p.closed { alive = false; continue; }
|
|
if p.ok == false {
|
|
try net.write(c, serialize(bad_request("malformed request"), false, false)) catch (e) {}
|
|
alive = false;
|
|
continue;
|
|
}
|
|
let r = p.req;
|
|
if r == nil { alive = false; continue; }
|
|
carry = p.rest;
|
|
let is_head = r.method == "HEAD";
|
|
if is_head { r.method = "GET"; }
|
|
-- fiber-per-connection: keep-alive stays OPEN (the idle deadline is
|
|
-- the eviction policy), unless the client asks to close
|
|
let keep = true;
|
|
let conn = r.headers["connection"];
|
|
if conn != nil {
|
|
if to_lower(conn) == "close" { keep = false; }
|
|
}
|
|
let resp = try d.dispatch(r) catch (e) server_error();
|
|
if resp.status == 101 {
|
|
hijacked = true;
|
|
alive = false;
|
|
continue;
|
|
}
|
|
try net.write(c, serialize(resp, keep, is_head)) catch (e) { alive = false; }
|
|
if keep == false { alive = false; }
|
|
}
|
|
if hijacked == false {
|
|
net.close(c);
|
|
}
|
|
}
|
|
|
|
pub fn serve(host: Text, port: Int, d: Dispatcher) -> Int {
|
|
let srv = net.listen(host, port);
|
|
print("listening on ${host}:${port}");
|
|
while true {
|
|
if env.stopping() { net.close(srv); return 0; }
|
|
let c = net.accept(srv);
|
|
let carry = "";
|
|
let alive = true;
|
|
let hijacked = false;
|
|
while alive {
|
|
if env.stopping() { alive = false; continue; }
|
|
let p = try parse_request(c, carry, 0, 0) catch (e) nil; -- an IO trap = gone
|
|
if p == nil { alive = false; continue; }
|
|
if p.closed { alive = false; continue; }
|
|
if p.ok == false {
|
|
try net.write(c, serialize(bad_request("malformed request"), false, false)) catch (e) {}
|
|
alive = false;
|
|
continue;
|
|
}
|
|
let r = p.req;
|
|
if r == nil { alive = false; continue; }
|
|
carry = p.rest;
|
|
-- HEAD is GET with the body suppressed: route and dispatch as GET,
|
|
-- serialize with head_only so Content-Length still names the body a
|
|
-- GET would have carried (RFC 9110 §9.3.2).
|
|
let is_head = r.method == "HEAD";
|
|
if is_head { r.method = "GET"; }
|
|
-- Connection policy for a single-threaded server: serve PIPELINED
|
|
-- requests on one connection (bytes already buffered), but close when
|
|
-- the client would idle — a parked keep-alive connection would block
|
|
-- `accept` and starve every other client. A proxy in front simply
|
|
-- reconnects; this is the honest shape until shards/fibers (8/11).
|
|
let keep = len(carry) > 0;
|
|
let conn = r.headers["connection"];
|
|
if conn != nil {
|
|
if to_lower(conn) == "close" { keep = false; }
|
|
}
|
|
let resp = try d.dispatch(r) catch (e) server_error();
|
|
-- iteration 24: status 101 is the hijack sentinel (http/ws.wo).
|
|
-- The handler completed a WebSocket upgrade and now OWNS the fd
|
|
-- through its own actors: no serialization, no close — the loop
|
|
-- forgets this connection and returns to accept.
|
|
if resp.status == 101 {
|
|
hijacked = true;
|
|
alive = false;
|
|
continue;
|
|
}
|
|
try net.write(c, serialize(resp, keep, is_head)) catch (e) { alive = false; }
|
|
if keep == false { alive = false; }
|
|
}
|
|
if hijacked == false {
|
|
net.close(c);
|
|
}
|
|
}
|
|
}
|