Some checks failed
control plane / chart (push) Has been cancelled
control plane / test (push) Has been cancelled
control plane / browser-e2e (push) Has been cancelled
control plane / Build control plane image (linux/amd64) (push) Has been cancelled
control plane / Build control plane image (linux/arm64) (push) Has been cancelled
control plane / Publish signed control plane image (push) Has been cancelled
helm chart / lint + unittest + render matrix (push) Has been cancelled
helm chart / install on kind (gated) (push) Has been cancelled
helm chart / publish chart to GHCR (push) Has been cancelled
Meridian Harness / Build (aarch64-unknown-linux-musl) (push) Has been cancelled
Meridian Harness / Build (x86_64-unknown-linux-musl) (push) Has been cancelled
Meridian Harness / Publish rolling release (push) Has been cancelled
Meridian Harness / Publish tagged release (push) Has been cancelled
CI / Detect Changed Paths (push) Has been cancelled
CI / Dead Token Reference Guard (push) Has been cancelled
Docker image / Build (linux/amd64) (push) Has been cancelled
Docker image / Build (linux/arm64) (push) Has been cancelled
Docker image / Build public push gateway (linux/amd64) (push) Has been cancelled
Docker image / Build public push gateway (linux/arm64) (push) Has been cancelled
CI / Rust Lint (push) Has been cancelled
CI / Unit Tests (push) Has been cancelled
CI / Isolated DB Gate (push) Has been cancelled
CI / Desktop Core (push) Has been cancelled
CI / Desktop Smoke E2E (1) (push) Has been cancelled
CI / Desktop Smoke E2E (2) (push) Has been cancelled
CI / Desktop Smoke E2E (3) (push) Has been cancelled
CI / Desktop Smoke E2E (4) (push) Has been cancelled
CI / Desktop (push) Has been cancelled
CI / Desktop E2E Relay (push) Has been cancelled
CI / Desktop E2E Integration (1/2) (push) Has been cancelled
CI / Desktop E2E Integration (2/2) (push) Has been cancelled
CI / Desktop E2E Integration (push) Has been cancelled
CI / Backend Integration (relay e2e) (push) Has been cancelled
CI / Relay E2E (push) Has been cancelled
CI / Web (push) Has been cancelled
CI / Admin Web (push) Has been cancelled
CI / Mobile (push) Has been cancelled
CI / Security (push) Has been cancelled
CI / Server Cross-Compile (push) Has been cancelled
CI / Server Cross-Compile-1 (push) Has been cancelled
CI / Windows Rust (x86_64-pc-windows-msvc) (push) Has been cancelled
CI / Desktop Build (macOS) (push) Has been cancelled
Docker image / Merge release multi-arch manifest (push) Has been cancelled
Docker image / Merge debug multi-arch manifest (push) Has been cancelled
Docker image / Publish public push gateway image (push) Has been cancelled
Charter Phase 1 of `.settings/features/feature-zenoh-transport.md`: one exact
Zenoh release for both the library and the daemon, off by default, with the
configuration policy asserted by tests rather than described in prose. No
adapter code, and no change to a default build.
Version: `zenoh = "=1.8.0"` and `eclipse/zenoh:1.8.0`
(index digest sha256:7aada0d1f86404c4c6ae3419618b7cfac3d8d261541a686da248ae90de40fa97).
crates.io offers 1.10.0 (published five days ago) and 1.9.0, and multi-arch
daemon images exist for all three, so the image is not the constraint. 1.8.0 is
chosen because the charter's adoption ledger and the reviewed source under
`.settings/reference-code/ZENOH/` are both 1.8.0. Every later phase reads that
checkout as its source of truth; compiling a different release would make each
of those reads quietly wrong, which is the drift this repo legislates against.
The requirement is `=1.8.0`, not `^1.8`, because `"1.8"` resolves to 1.10.0 —
a caret range here means the ledger silently stops describing what is built.
Five months of field time and an already-published daemon image are the
secondary reasons; the ledger alignment is the argument.
Ledger claims re-verified against the PUBLISHED 1.8.0 crates, not the +35-commit
reference checkout. All four hold:
(a) `zenoh-protocol-1.8.0/src/core/mod.rs:303` — eight values, `Control = 0`
reserved. `zenoh-1.8.0/src/api/publisher.rs:521` exposes seven,
`RealTime = 1` .. `Background = 7`. Pinned by
`seven_application_priorities_are_assignable`.
(b) `zenoh-1.8.0/src/api/builders/publisher.rs:130` — `express` bypasses
batching, and is NOT gated. `:154-159` and `:440-445` — `reliability` is
`#[zenoh_macros::unstable]` and documented to trigger no retransmission.
`unstable` is not enabled here, so `Reliability` is unreachable in this
build. Nothing is lost: it is a wire marker, and every non-lossy lane
needs a named recovery source regardless.
(c) `zenoh-transport-1.8.0/src/unicast/manager.rs:237` — `qos && lowlatency`
bails. Pinned by `rejects_qos_plus_lowlatency`, which opens a session
because the file parses fine and only `zenoh::open` rejects it.
(d) `zenoh-config-1.8.0/src/defaults.rs:75` and `:105` — multicast AND gossip
scouting both default `true`.
Four things the ledger does not yet say, each found by running the pinned
artifacts rather than reading docs:
- `transport.shared_memory.enabled` and `.transport_optimization.enabled`
both default `true` (`zenoh-config-1.8.0/src/lib.rs:795-816`). Omitting the
keys switches on charter Phase 6 — unscheduled, gated on a measured payload
crossover, and needing `CAP_IPC_LOCK`. The daemon image is built with the
feature even though this build is not, so it would announce SHM on a link
the other end cannot honour. Both pinned off, with a negative fixture.
- `zenohd/src/main.rs:136-137` unconditionally re-enables `adminspace` and
`plugins_loading` after reading the config file. `enabled: false` is honest
for the library and false for the daemon that ships REST and
storage-manager plugins in its image root. What survives, and is now
asserted against the daemon's own `Initial conf` line, is
`plugins_loading.search_dirs: []`, `plugins: {}` and
`adminspace.permissions.{read,write}: false`.
- `zenohd/src/main.rs:203-214` reads an ABSENT multicast-scouting key as
consent and force-enables it. Present-and-false takes the `(false, false)`
arm and survives. The assertion is `== "false"`, not "not true", so
deleting the key from a fixture fails instead of re-enabling discovery.
- `zenoh-runtime-1.8.0/src/lib.rs:149` panics outright on Tokio's
current-thread scheduler. Every Zenoh call site needs a multi-thread runtime.
Features: `default-features = false, features = ["transport_tcp"]`. TCP is the
only scheme the fixtures declare. `transport_tls` is deferred to the phase that
introduces the first non-local endpoint, and the deferral is executable — a
`tls/` endpoint is a negative fixture. `unstable`, `internal`, `plugins`,
`shared-memory` and `stats` are all off; each is justified in the workspace
manifest next to the pin.
Cost: the crate is optional behind a `zenoh` cargo feature that is off by
default. `cargo tree -p meridian-pubsub` is byte-identical to before (144
packages); with the feature it is 295. `Cargo.lock` grows 983 -> 1056. No
workspace crate's default build gains a single dependency.
deny.toml: no license needed permitting. `EPL-2.0 OR Apache-2.0` resolves to
the already-allowed Apache-2.0 path for all 20 zenoh crates, and no new advisory
appears. The one change is `[graph] all-features = true`, which is a widening,
not a waiver: cargo-deny defaults to the DEFAULT-feature graph, so an optional
dependency is invisible to every check and `cargo deny check` was reporting
`licenses ok` without ever looking at Zenoh. Verified by banning `zenoh` in a
throwaway edit and watching the bare `cargo deny check bans` fire. Measured to
change nothing else: the same 12 pre-existing advisories (h2, nostr,
nostr-relay-pool, webbrowser — identical on an untouched tree), `bans ok,
licenses ok, sources ok`.
MSRV: all 20 zenoh crates declare 1.75.0, under the workspace's 1.88.0 and the
pinned 1.95.0 toolchain. No conflict.
Tests are wrapped in `mod zenoh_config` on purpose: the documented filter
`cargo test -p meridian-pubsub --features zenoh zenoh_config` matches test
NAMES, and before the wrap it reported `0 passed; 11 filtered out` — exit 0 for
a suite that never ran.
Gates: cargo check (feature off / on) 0, clippy -D warnings 0, cargo test 0
(11 tests, incl. the Docker daemon check), just fmt-check 0, cargo deny check
licenses / bans / sources 0. `cargo deny check` exits 1 on the 12 pre-existing
advisories, identically to an untouched tree.
Signed-off-by: Joshua Belke <joshua@innovationhub-act.org>
109 lines
4 KiB
TOML
109 lines
4 KiB
TOML
# Dependency-graph scope.
|
|
#
|
|
# cargo-deny defaults to `all-features = false`, which resolves the graph with
|
|
# each crate's DEFAULT features — so an OPTIONAL dependency is invisible to every
|
|
# check below. `meridian-pubsub`'s `zenoh` feature is off by default (20 crates,
|
|
# `EPL-2.0 OR Apache-2.0`), and with the default scope `cargo deny check` reported
|
|
# `licenses ok` while never looking at any of them. A gate that cannot see the
|
|
# dependency it is meant to gate is worse than no gate, because it reads green.
|
|
#
|
|
# Measured before enabling: `cargo deny --all-features check` and the default
|
|
# scope produce the IDENTICAL result on this tree — the same 12 advisories, and
|
|
# `bans ok, licenses ok, sources ok`. So this widens coverage without waiving or
|
|
# reclassifying anything, and it keeps future optional dependencies covered by
|
|
# default rather than by remembering to pass a flag.
|
|
[graph]
|
|
all-features = true
|
|
|
|
[advisories]
|
|
ignore = [
|
|
# instant 0.1.13 — unmaintained crate. Transitive dep: nostr → instant.
|
|
# Will be resolved when nostr crate updates its dependencies.
|
|
{ id = "RUSTSEC-2024-0384", reason = "transitive dep via nostr; no upstream fix available" },
|
|
# paste 1.0.15 — unmaintained. Transitive dep: mesh-llm → iroh → netlink-* → paste.
|
|
# No safe upgrade available; tracked for upstream (iroh/netlink) replacement.
|
|
{ id = "RUSTSEC-2024-0436", reason = "transitive dep via mesh-llm → iroh → netlink; no upstream fix available" },
|
|
# quick-xml < 0.41: quadratic runtime on duplicate-attribute check (0194) and
|
|
# unbounded namespace-declaration allocation in NsReader (0195). Both DoS-class,
|
|
# requiring attacker-controlled XML. Our two locked versions only parse trusted
|
|
# input: 0.38.4 (rust-s3/aws-creds — responses from our own S3/MinIO endpoint)
|
|
# and 0.39.4 (mesh-llm → iroh → netdev → plist — local macOS system plists).
|
|
# Patched release (>= 0.41.0) is unreachable until rust-s3 and plist/netdev bump;
|
|
# remove these when upstream catches up.
|
|
{ id = "RUSTSEC-2026-0194", reason = "transitive via rust-s3 and mesh-llm→plist; trusted-input XML only; no upstream fix available yet" },
|
|
{ id = "RUSTSEC-2026-0195", reason = "transitive via rust-s3 and mesh-llm→plist; trusted-input XML only; no upstream fix available yet" },
|
|
]
|
|
|
|
[licenses]
|
|
allow = [
|
|
"MIT",
|
|
"Apache-2.0",
|
|
"Apache-2.0 WITH LLVM-exception",
|
|
"BSD-2-Clause",
|
|
"BSD-3-Clause",
|
|
"ISC",
|
|
"Unicode-3.0",
|
|
"Unicode-DFS-2016",
|
|
"Zlib",
|
|
"OpenSSL",
|
|
"CC0-1.0",
|
|
"CDLA-Permissive-2.0",
|
|
"MITNFA",
|
|
"MPL-2.0",
|
|
"BSL-1.0",
|
|
"Unlicense",
|
|
# minicbor's permissive, OSI-approved license. Used for strict App Attest
|
|
# assertion CBOR parsing and also transitively by appattest.
|
|
"BlueOak-1.0.0",
|
|
# bzip2/libbzip2's permissive BSD-like license. New via desktop zip/bzip2
|
|
# transitive deps; compatible with MIT distribution.
|
|
"bzip2-1.0.6",
|
|
]
|
|
confidence-threshold = 0.8
|
|
|
|
# mesh-llm workspace crates (pinned git dep) omit a per-crate `license` field in
|
|
# their manifests, so cargo-deny reports them as unlicensed. The mesh-llm repo is
|
|
# licensed "MIT OR Apache-2.0" (workspace Cargo.toml + top-level LICENSE = Apache-2.0);
|
|
# clarify each pulled-in member to that expression. Remove once mesh sets the field
|
|
# upstream (filed).
|
|
[[licenses.clarify]]
|
|
crate = "mesh-llm-config"
|
|
expression = "MIT OR Apache-2.0"
|
|
license-files = []
|
|
|
|
[[licenses.clarify]]
|
|
crate = "mesh-llm-gpu-bench"
|
|
expression = "MIT OR Apache-2.0"
|
|
license-files = []
|
|
|
|
[[licenses.clarify]]
|
|
crate = "mesh-llm-host-runtime"
|
|
expression = "MIT OR Apache-2.0"
|
|
license-files = []
|
|
|
|
[[licenses.clarify]]
|
|
crate = "mesh-llm-plugin"
|
|
expression = "MIT OR Apache-2.0"
|
|
license-files = []
|
|
|
|
[[licenses.clarify]]
|
|
crate = "mesh-llm-system"
|
|
expression = "MIT OR Apache-2.0"
|
|
license-files = []
|
|
|
|
[[licenses.clarify]]
|
|
crate = "mesh-mixture-of-agents"
|
|
expression = "MIT OR Apache-2.0"
|
|
license-files = []
|
|
|
|
[[licenses.clarify]]
|
|
crate = "meridian-desktop"
|
|
expression = "MIT"
|
|
license-files = []
|
|
|
|
[licenses.private]
|
|
ignore = true
|
|
|
|
[bans]
|
|
multiple-versions = "warn"
|
|
wildcards = "allow"
|