Skip to content

Migrate line protocol and nickname support - #11

Open
TonyTown6033 wants to merge 2 commits into
mainfrom
migrate/4-line-protocol-nickname
Open

TonyTown6033 wants to merge 2 commits into
mainfrom
migrate/4-line-protocol-nickname

Conversation

@TonyTown6033

Copy link
Copy Markdown
Owner

Summary

  • port the stable line-based text protocol from feature to main
    • client commands: MSG, NICK
    • server responses: SYS, MSG, NICK, YOU, ERR
  • add server-side nickname validation (length, charset, case-insensitive uniqueness)
  • add token authentication, per-client rate limiting and temporary IP bans
  • reject malformed input (empty messages, unknown commands, oversized lines) with ERR
  • make the client token-aware (/connect <ip> <port> [token]), add /nickname, and parse line-based server responses
  • add parser/validation tests and document the protocol in PROTOCOL.md

Out of scope

  • file transfer (PUT/GET/LS), remote execution (EXEC) and LLM (LLM)
  • chat history and rendering changes

Validation

  • cargo fmt --all -- --check
  • cargo check --all-targets
  • cargo test --all-targets (9 tests)
  • manual end-to-end check: auth rejection, nickname validation, duplicate nickname, broadcast, empty/oversized/unknown input, rate limiting

Closes #4

TonyTown6033 and others added 2 commits October 2, 2026 23:59
…patcher

Migrate minimal client command dispatcher, good job
Port the stable text protocol from feature to main:

- line-based client commands MSG and NICK
- server responses SYS, MSG, NICK, YOU and ERR
- access-token authentication on connect
- server-side nickname validation (length, charset, case-insensitive
  uniqueness)
- per-client rate limiting and temporary IP bans
- safe rejection of malformed input (empty messages, unknown commands,
  oversized lines)
- parser/validation tests and PROTOCOL.md documentation

File transfer, remote execution, LLM and chat-history changes are
intentionally excluded.
@TonyTown6033

Copy link
Copy Markdown
Owner Author

@codex

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-06T05:50:11.201056Z 37717ea Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 37717ea2e1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/server.rs
)?;

println!("get buffer {buffer}");
let (outbound_tx, outbound_rx) = mpsc::channel::<Outbound>();

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Bound queued output for non-reading clients

Once an authenticated peer stops reading, its writer thread can block on the TCP send buffer while send_to continues to enqueue every broadcast on this unbounded channel. A client that authenticates and then does not read can therefore make normal chat traffic retain an unbounded number of Strings and exhaust server memory; use a bounded queue and disconnect or drop output for lagging peers.

Useful? React with 👍 / 👎.

Comment thread src/server.rs
return Err(());
loop {
let mut line = String::new();
match reader.read_line(&mut line) {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Cap reads before allocating the entire line

read_line appends until it sees a newline before the following branch tests line.len(), so a client can send an arbitrarily large line, or continuously omit its newline, and force this connection thread to allocate it. The advertised 4 KiB limit therefore does not protect server memory; enforce the byte limit while reading, before extending the String.

Useful? React with 👍 / 👎.

Comment thread src/client.rs
ctx.stream = None;
pending.clear();
}
Ok(n) => match from_utf8(&buffer[..n]) {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Preserve partial UTF-8 bytes between socket reads

TCP can split a valid UTF-8 MSG or SYS frame at any byte. When a read ends inside a multibyte character, this conversion fails and the error path discards the entire chunk rather than retaining it for the next read, so ordinary Unicode chat messages can lose their prefix or never render; buffer raw bytes through a newline before decoding a complete frame.

Useful? React with 👍 / 👎.

Comment thread src/server.rs
Comment on lines +159 to +162
client.last_message_at = Some(now);
if too_quick {
client.rate_limit_violations += 1;
send_to(client, "ERR you are sending messages too quickly");

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Apply rate limiting only to chat messages

The limiter runs before command parsing, so a user can be rate-limited and eventually banned merely by rapidly retrying /nickname, an invalid request, or an unknown command, even though none is a chat MSG. This contradicts the documented per-message limit and makes nickname correction fail immediately after another command; parse first and rate-limit only message sends.

Useful? React with 👍 / 👎.

@TonyTown6033
TonyTown6033 force-pushed the main branch 2 times, most recently from 1875b35 to a220c83 Compare October 6, 2026 06:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Migrate the line protocol and nickname support

2 participants