R2D2-MERIDIAN/Cargo.toml
Joshua Belke 5e3735da2a
Some checks failed
control plane / chart (push) Has been cancelled
control plane / test (push) Has been cancelled
control plane / browser-e2e (push) Has been cancelled
control plane / Build control plane image (linux/amd64) (push) Has been cancelled
control plane / Build control plane image (linux/arm64) (push) Has been cancelled
control plane / Publish signed control plane image (push) Has been cancelled
helm chart / lint + unittest + render matrix (push) Has been cancelled
helm chart / install on kind (gated) (push) Has been cancelled
helm chart / publish chart to GHCR (push) Has been cancelled
Meridian Harness / Build (aarch64-unknown-linux-musl) (push) Has been cancelled
Meridian Harness / Build (x86_64-unknown-linux-musl) (push) Has been cancelled
Meridian Harness / Publish rolling release (push) Has been cancelled
Meridian Harness / Publish tagged release (push) Has been cancelled
CI / Detect Changed Paths (push) Has been cancelled
CI / Dead Token Reference Guard (push) Has been cancelled
Docker image / Build (linux/amd64) (push) Has been cancelled
Docker image / Build (linux/arm64) (push) Has been cancelled
Docker image / Build public push gateway (linux/amd64) (push) Has been cancelled
Docker image / Build public push gateway (linux/arm64) (push) Has been cancelled
CI / Rust Lint (push) Has been cancelled
CI / Unit Tests (push) Has been cancelled
CI / Isolated DB Gate (push) Has been cancelled
CI / Desktop Core (push) Has been cancelled
CI / Desktop Smoke E2E (1) (push) Has been cancelled
CI / Desktop Smoke E2E (2) (push) Has been cancelled
CI / Desktop Smoke E2E (3) (push) Has been cancelled
CI / Desktop Smoke E2E (4) (push) Has been cancelled
CI / Desktop (push) Has been cancelled
CI / Desktop E2E Relay (push) Has been cancelled
CI / Desktop E2E Integration (1/2) (push) Has been cancelled
CI / Desktop E2E Integration (2/2) (push) Has been cancelled
CI / Desktop E2E Integration (push) Has been cancelled
CI / Backend Integration (relay e2e) (push) Has been cancelled
CI / Relay E2E (push) Has been cancelled
CI / Web (push) Has been cancelled
CI / Admin Web (push) Has been cancelled
CI / Mobile (push) Has been cancelled
CI / Security (push) Has been cancelled
CI / Server Cross-Compile (push) Has been cancelled
CI / Server Cross-Compile-1 (push) Has been cancelled
CI / Windows Rust (x86_64-pc-windows-msvc) (push) Has been cancelled
CI / Desktop Build (macOS) (push) Has been cancelled
Docker image / Merge release multi-arch manifest (push) Has been cancelled
Docker image / Merge debug multi-arch manifest (push) Has been cancelled
Docker image / Publish public push gateway image (push) Has been cancelled
feat(pubsub): pin zenoh 1.8.0 and make its config contract executable
Charter Phase 1 of `.settings/features/feature-zenoh-transport.md`: one exact
Zenoh release for both the library and the daemon, off by default, with the
configuration policy asserted by tests rather than described in prose. No
adapter code, and no change to a default build.

Version: `zenoh = "=1.8.0"` and `eclipse/zenoh:1.8.0`
(index digest sha256:7aada0d1f86404c4c6ae3419618b7cfac3d8d261541a686da248ae90de40fa97).

crates.io offers 1.10.0 (published five days ago) and 1.9.0, and multi-arch
daemon images exist for all three, so the image is not the constraint. 1.8.0 is
chosen because the charter's adoption ledger and the reviewed source under
`.settings/reference-code/ZENOH/` are both 1.8.0. Every later phase reads that
checkout as its source of truth; compiling a different release would make each
of those reads quietly wrong, which is the drift this repo legislates against.
The requirement is `=1.8.0`, not `^1.8`, because `"1.8"` resolves to 1.10.0 —
a caret range here means the ledger silently stops describing what is built.
Five months of field time and an already-published daemon image are the
secondary reasons; the ledger alignment is the argument.

Ledger claims re-verified against the PUBLISHED 1.8.0 crates, not the +35-commit
reference checkout. All four hold:

  (a) `zenoh-protocol-1.8.0/src/core/mod.rs:303` — eight values, `Control = 0`
      reserved. `zenoh-1.8.0/src/api/publisher.rs:521` exposes seven,
      `RealTime = 1` .. `Background = 7`. Pinned by
      `seven_application_priorities_are_assignable`.
  (b) `zenoh-1.8.0/src/api/builders/publisher.rs:130` — `express` bypasses
      batching, and is NOT gated. `:154-159` and `:440-445` — `reliability` is
      `#[zenoh_macros::unstable]` and documented to trigger no retransmission.
      `unstable` is not enabled here, so `Reliability` is unreachable in this
      build. Nothing is lost: it is a wire marker, and every non-lossy lane
      needs a named recovery source regardless.
  (c) `zenoh-transport-1.8.0/src/unicast/manager.rs:237` — `qos && lowlatency`
      bails. Pinned by `rejects_qos_plus_lowlatency`, which opens a session
      because the file parses fine and only `zenoh::open` rejects it.
  (d) `zenoh-config-1.8.0/src/defaults.rs:75` and `:105` — multicast AND gossip
      scouting both default `true`.

Four things the ledger does not yet say, each found by running the pinned
artifacts rather than reading docs:

  - `transport.shared_memory.enabled` and `.transport_optimization.enabled`
    both default `true` (`zenoh-config-1.8.0/src/lib.rs:795-816`). Omitting the
    keys switches on charter Phase 6 — unscheduled, gated on a measured payload
    crossover, and needing `CAP_IPC_LOCK`. The daemon image is built with the
    feature even though this build is not, so it would announce SHM on a link
    the other end cannot honour. Both pinned off, with a negative fixture.
  - `zenohd/src/main.rs:136-137` unconditionally re-enables `adminspace` and
    `plugins_loading` after reading the config file. `enabled: false` is honest
    for the library and false for the daemon that ships REST and
    storage-manager plugins in its image root. What survives, and is now
    asserted against the daemon's own `Initial conf` line, is
    `plugins_loading.search_dirs: []`, `plugins: {}` and
    `adminspace.permissions.{read,write}: false`.
  - `zenohd/src/main.rs:203-214` reads an ABSENT multicast-scouting key as
    consent and force-enables it. Present-and-false takes the `(false, false)`
    arm and survives. The assertion is `== "false"`, not "not true", so
    deleting the key from a fixture fails instead of re-enabling discovery.
  - `zenoh-runtime-1.8.0/src/lib.rs:149` panics outright on Tokio's
    current-thread scheduler. Every Zenoh call site needs a multi-thread runtime.

Features: `default-features = false, features = ["transport_tcp"]`. TCP is the
only scheme the fixtures declare. `transport_tls` is deferred to the phase that
introduces the first non-local endpoint, and the deferral is executable — a
`tls/` endpoint is a negative fixture. `unstable`, `internal`, `plugins`,
`shared-memory` and `stats` are all off; each is justified in the workspace
manifest next to the pin.

Cost: the crate is optional behind a `zenoh` cargo feature that is off by
default. `cargo tree -p meridian-pubsub` is byte-identical to before (144
packages); with the feature it is 295. `Cargo.lock` grows 983 -> 1056. No
workspace crate's default build gains a single dependency.

deny.toml: no license needed permitting. `EPL-2.0 OR Apache-2.0` resolves to
the already-allowed Apache-2.0 path for all 20 zenoh crates, and no new advisory
appears. The one change is `[graph] all-features = true`, which is a widening,
not a waiver: cargo-deny defaults to the DEFAULT-feature graph, so an optional
dependency is invisible to every check and `cargo deny check` was reporting
`licenses ok` without ever looking at Zenoh. Verified by banning `zenoh` in a
throwaway edit and watching the bare `cargo deny check bans` fire. Measured to
change nothing else: the same 12 pre-existing advisories (h2, nostr,
nostr-relay-pool, webbrowser — identical on an untouched tree), `bans ok,
licenses ok, sources ok`.

MSRV: all 20 zenoh crates declare 1.75.0, under the workspace's 1.88.0 and the
pinned 1.95.0 toolchain. No conflict.

Tests are wrapped in `mod zenoh_config` on purpose: the documented filter
`cargo test -p meridian-pubsub --features zenoh zenoh_config` matches test
NAMES, and before the wrap it reported `0 passed; 11 filtered out` — exit 0 for
a suite that never ran.

Gates: cargo check (feature off / on) 0, clippy -D warnings 0, cargo test 0
(11 tests, incl. the Docker daemon check), just fmt-check 0, cargo deny check
licenses / bans / sources 0. `cargo deny check` exits 1 on the 12 pre-existing
advisories, identically to an untouched tree.

Signed-off-by: Joshua Belke <joshua@innovationhub-act.org>
2026-08-19 14:16:42 -04:00

213 lines
8.9 KiB
TOML

[workspace]
members = [
"crates/meridian-relay",
"crates/meridian-core",
"crates/meridian-conformance",
"crates/meridian-push-gateway",
"crates/meridian-control-plane",
"crates/meridian-openapi",
"crates/meridian-db",
"crates/meridian-pubsub",
"crates/meridian-auth",
"crates/meridian-search",
"crates/meridian-audit",
"crates/meridian-acp",
"crates/meridian-agent",
"crates/meridian-harness",
"crates/meridian-test-client",
"crates/meridian-test-db",
"crates/meridian-ws-client",
"crates/meridian-admin",
"crates/meridian-workflow",
"crates/meridian-media",
"crates/meridian-cli",
"crates/meridian-pairing-cli",
"crates/meridian-sdk",
"crates/meridian-persona",
"crates/git-credential-nostr",
"crates/git-sign-nostr",
"crates/meridian-pair-relay",
"crates/meridian-relay-mesh",
"crates/meridian-dev-mcp",
"examples/countdown-bot",
]
exclude = ["REMAPPING/meridian-desktop/src-tauri"]
resolver = "2"
[workspace.package]
version = "0.1.0"
edition = "2021"
rust-version = "1.88.0"
license = "MIT"
repository = "https://git.office.ilab.zone/RAID/R2D2-MERIDIAN"
[workspace.dependencies]
# Runtime
tokio = { version = "1", features = ["rt-multi-thread", "macros", "net", "time", "sync", "io-util", "signal", "process"] }
tokio-util = { version = "0.7", features = ["rt", "codec"] }
# HTTP + WebSocket
axum = { version = "0.8", features = ["ws", "macros"] }
tower = { version = "0.5", features = ["timeout", "util", "limit"] }
tower-http = { version = "0.6", features = ["trace", "cors", "compression-gzip", "limit", "timeout", "fs"] }
# Database
sqlx = { version = "0.9", features = [
"runtime-tokio", "tls-rustls", "postgres", "uuid", "chrono", "json"
] }
# Redis
redis = { version = "1.0", features = ["tokio-comp", "connection-manager", "tokio-rustls-comp"] }
deadpool-redis = { version = "0.23", features = ["rt_tokio_1"] }
# Nostr
nostr = { version = "0.44", features = ["nip44", "nip98"] }
# Serialization
serde = { version = "1", features = ["derive"] }
postcard = { version = "1", default-features = false, features = ["use-std"] }
# Inter-pod event bus transport (meridian-pubsub, feature-gated `zenoh`, off by default).
# Pinned to one exact release, not a caret range: the adoption ledger in
# `.settings/features/feature-zenoh-transport.md` and the reviewed source under
# `.settings/reference-code/ZENOH/` are both 1.8.0, so a floating requirement would
# silently compile code the ledger was never checked against. `zenohd` runs at the
# same released version (`eclipse/zenoh:1.8.0`); library/daemon drift is a config
# and wire-compat hazard, not a convenience.
# default-features = false -> drops auth_pubkey, auth_usrpwd, transport_compression,
# transport_multilink, transport_quic, transport_quic_datagram,
# transport_tls, transport_udp, transport_unixsock-stream,
# transport_ws. None has a consumer in this repo yet, and an
# uncalled link type is inventory (root AGENTS.md, R8).
# transport_tcp -> the only link scheme the pinned config fixture declares
# (`tcp/...`); without it an explicit endpoint has no
# implementation and the session fails at open.
# Deliberately NOT enabled:
# unstable / internal / internal_config -> charter Phase 1 keeps the baseline off unstable
# and internal APIs. Consequence to know: `Publisher::reliability`
# is `#[zenoh_macros::unstable]`, so `Reliability` is
# unreachable in this build. It is a wire marker that triggers
# no retransmission anyway, so nothing is lost.
# plugins / runtime_plugins / shared-memory / stats -> no plugin runtime and no second
# storage mechanism (DIAGRAM.md); SHM is charter Phase 6 and
# gated; `stats` is a preflight experiment, not our metrics source.
# transport_tls -> deferred to the phase that introduces the first non-local
# endpoint. `tests/zenoh_config.rs` asserts a `tls/` endpoint is
# rejected by this build, so the deferral is executable.
zenoh = { version = "=1.8.0", default-features = false, features = ["transport_tcp"] }
# Inter-relay mesh transport (meridian-relay-mesh)
iroh = { version = "1.0.0-rc.0", default-features = false, features = ["tls-ring"] }
serde_json = "1"
serde_yaml = "0.9"
evalexpr = "11"
cron = "0.16"
# Observability
tracing = "0.1"
tracing-subscriber = { version = "0.3", features = ["env-filter", "json"] }
tracing-opentelemetry = { version = "0.33" }
opentelemetry = { version = "0.32", features = ["trace"] }
opentelemetry_sdk = { version = "0.32", features = ["trace", "rt-tokio"] }
opentelemetry-otlp = { version = "0.32", default-features = false, features = ["trace", "grpc-tonic", "tls-ring"] }
metrics = "0.24"
metrics-exporter-prometheus = "0.18"
metrics-util = "0.20"
# Error handling
thiserror = "2"
anyhow = "1"
# Utilities
uuid = { version = "1", features = ["v4", "serde"] }
chrono = { version = "0.4", features = ["serde"] }
# HTTP client (webhook delivery)
reqwest = { version = "0.13", features = ["json", "rustls"], default-features = false }
# Cryptography
sha2 = "0.11"
hex = "0.4"
hmac = "0.13"
base64 = "0.22"
# Randomness
rand = "0.10"
subtle = "2.6"
zeroize = "1.8"
# Concurrent data structures
dashmap = "6"
moka = { version = "0.12", features = ["sync"] }
# Async stream utilities
futures-util = "0.3"
# WebSocket client (test client)
tokio-tungstenite = { version = "0.29", features = ["rustls-tls-webpki-roots"] }
url = "2"
# Property-based testing (dev-only)
proptest = "1"
# MCP SDK (used by meridian-dev-mcp and meridian-agent)
rmcp = { version = "1.1.0", features = ["server", "transport-io", "macros"] }
schemars = { version = "1", default-features = false }
# OpenAPI. The document is generated from the handlers that serve it —
# `utoipa-axum`'s `OpenApiRouter` refuses to register a route without an
# operation, so a new endpoint cannot ship undocumented. Rendered by the
# vendored Scalar bundle in `meridian-openapi`, never a CDN.
utoipa = { version = "5", features = ["axum_extras", "uuid", "chrono"] }
utoipa-axum = "0.2"
# Internal crates
meridian-core = { path = "crates/meridian-core" }
meridian-conformance = { path = "crates/meridian-conformance" }
meridian-db = { path = "crates/meridian-db" }
meridian-auth = { path = "crates/meridian-auth" }
meridian-pubsub = { path = "crates/meridian-pubsub" }
meridian-search = { path = "crates/meridian-search" }
meridian-audit = { path = "crates/meridian-audit" }
meridian-workflow = { path = "crates/meridian-workflow" }
meridian-media = { path = "crates/meridian-media" }
meridian-sdk = { path = "crates/meridian-sdk" }
meridian-ws-client = { path = "crates/meridian-ws-client" }
meridian-relay-mesh = { path = "crates/meridian-relay-mesh" }
meridian-openapi = { path = "crates/meridian-openapi" }
meridian-test-db = { path = "crates/meridian-test-db" }
# CI profile — builds the relay for desktop e2e. Dependencies keep full
# release optimization (warm from main's cache; they carry the runtime hot
# path: tokio/sqlx/axum). Workspace crates build at opt-level 1 — enough for
# stable e2e timing (PR #307 flakiness was opt-0 + debug-assertions) at
# roughly half the codegen cost. `incremental` is irrelevant in CI:
# rust-cache exports CARGO_INCREMENTAL=0 and never caches member artifacts.
[profile.ci]
inherits = "release"
lto = false
opt-level = 1
[profile.ci.package."*"]
opt-level = 3
# Meridian Harness profile — optimized for deploy-anywhere Meridian Harness release artifacts.
# Meridian Harness is distributed over the network and installed on fresh hosts, so binary
# size matters more than compile speed here. Keep this separate from the normal
# `release` profile so desktop/dev release builds do not inherit the slower
# size-focused settings unless they opt in explicitly.
[profile.meridian-harness]
inherits = "release"
opt-level = "z"
lto = "fat"
codegen-units = 1
panic = "abort"
strip = true
# Temporary fork pin: aws-creds 0.39.1 (via rust-s3) cannot read EKS Pod Identity
# credentials (AWS_CONTAINER_CREDENTIALS_FULL_URI + AWS_CONTAINER_AUTHORIZATION_TOKEN_FILE),
# which the relay pod on bb-block requires for S3 media + git storage. This pins
# aws-creds to a fork that adopts the aws-creds portion of durch/rust-s3#449
# (FULL_URI + token-file + Authorization header, refresh-safe, with a loopback
# allowlist for the auth token). Revert to crates.io once #449 lands upstream.
[patch.crates-io]
aws-creds = { git = "https://github.com/tlongwell-block/rust-s3", rev = "c9fce3620dd434c1f810101d672cf384268dbb0f" }