Oregami
Repositories/oxedyne/daimond

oxedyne/daimond/Cargo.toml

8.4 KiB, 33 runs

created by r2519314175:7, which is this file's identity for as long as the history lasts, whatever it is later renamed to

download · who wrote it · its history

1[package]
2name = "oxedyne_daimond"
3version = "0.1.0"
4authors = ["Jason Hoogland <jason@oxedyne.io>"]
5edition = "2021"
6license-file = "LICENSE"
7description = "Daimond — the browser-first agentic workspace client, built on the Hematite (fe2o3) library. Source-available so the privacy claim can be verified."
8repository = "https://github.com/oxedyne-com/daimond"
9
10[lib]
11path = "src/lib.rs"
12# `cdylib` lets wasm-pack emit a browser wasm module; `rlib` keeps the
13# native consumers (Steel, the agent smoke example) linking as before.
14crate-type = ["cdylib", "rlib"]
15
16# Portable dependencies — build on both native and wasm32. These are
17# pulled in by the target-agnostic modules (protocol, session, syntax,
18# agent, tools, skills, and the transport-neutral half of llm).
19#
20# fe2o3 (the Hematite library) is pinned to a fixed revision, and it is pinned
21# by GIT rather than by path DELIBERATELY. This file is the public mirror's:
22# anyone who clones this repository must be able to build it, and a path
23# dependency resolves only inside the author's own tree. A path dep here makes
24# the whole verifiability claim untestable by the people it is for -- which is
25# what happened between 2026-07-21 and 2026-07-27, when a hand-carve from the
26# development tree overwrote this block. The revision below is the fe2o3 commit
27# these sources were built and sealed against.
28# Certificate verification cannot be switched off in a shipped build: the accept-anything
29# verifier and the extra-trust-root hook exist only under this feature, which is OFF, so
30# the types that could weaken the tunnel are not in the released wasm at all.
31[features]
32insecure_testing = []
33
34[dependencies]
35oxedyne_fe2o3_core = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" }
36oxedyne_fe2o3_jdat = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" }
37oxedyne_fe2o3_iop_hash = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" }
38oxedyne_fe2o3_iop_db = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" }
39oxedyne_fe2o3_iop_crypto = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" }
40oxedyne_fe2o3_syntax = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" }
41oxedyne_fe2o3_graphics = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" }
42# The regex engine and the glob matcher the file tools search with (`fe2o3_text::regex`,
43# `fe2o3_text::glob`). Portable, so the browser build searches by the same rules the native
44# build does -- two matchers would eventually disagree about what a pattern means.
45oxedyne_fe2o3_text = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" }
46# `fe2o3_stds::media` -- what a file IS, from its own bytes, so the viewer offers a
47# picture a picture and a document a document. PORTABLE, and it was native-only
48# below until the browser began asking the same question: the wasm build then would
49# not compile at all, which the reproducible build caught and the development tree
50# could not, since a path dependency there is portable by default.
51oxedyne_fe2o3_stds = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" }
52# `fe2o3_file::office`, which reads and writes the Microsoft Office formats, over
53# `fe2o3_file::zip`. Portable: the crate reaches no filesystem at all, so a `.docx`
54# dragged into the browser is read by the same code the native build reads one with.
55oxedyne_fe2o3_file = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" }
56# SHA3-256, the SBJ address function, which WebCrypto does not implement at all, and
57# the SHA-256 behind an identity fingerprint. Pure Rust, so it compiles to wasm32 as
58# it stands; it was native-only only while nothing but the native half hashed anything.
59oxedyne_fe2o3_hash = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" }
60oxedyne_fe2o3_ore = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" }
61# SBJ, the signed container a message and an identity card travel in. It is here and
62# not behind the gateway because the point of a signature is that the RECIPIENT checks
63# it: a server that verified and handed over a tidy result would have proved only that
64# the server says so. `default-features = false` drops the post-quantum schemes that
65# rest on C, leaving the pure-Rust subset -- Ed25519, SHA3 -- a browser can compile.
66oxedyne_fe2o3_sbj = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f", default-features = false }
67
68# The sans-io half of `fe2o3_mail` -- RFC 5322 message reading and draft building -- behind
69# the model's mail tools (`mail_read`, `mail_draft`). `default-features = false` drops the
70# server modules (the Maildir store, the passwd user file) that reach `fe2o3_net` and do not
71# build for wasm32; what is left needs only `fe2o3_core` and `fe2o3_text`, both portable.
72oxedyne_fe2o3_mail = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f", default-features = false }
73
74# Native-only dependencies. The Steel WebSocket handler, the O3db
75# session backend, and the hand-rolled TLS transport are all native
76# concerns; none of these crates target wasm32. Target-gated so Cargo
77# feature unification never touches the wasm build (F6).
78[target.'cfg(not(target_arch = "wasm32"))'.dependencies]
79oxedyne_fe2o3_net = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" }
80oxedyne_fe2o3_o3db_sync = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" }
81
82tokio = { version = "1.35", features = ["full"] }
83tokio-rustls = "0.26"
84rustls = { version = "0.23", features = ["ring"] }
85rustls-pemfile = "2"
86
87# Wasm-only dependencies. The browser transport replaces the native
88# TLS client with `fetch` + `ReadableStream` via web-sys, driven by
89# wasm-bindgen-futures. `getrandom`'s `js` backend must stay confined
90# to wasm32 so it never leaks onto native (F6).
91[target.'cfg(target_arch = "wasm32")'.dependencies]
92wasm-bindgen = "0.2"
93wasm-bindgen-futures = "0.4"
94js-sys = "0.3"
95getrandom = { version = "0.2", features = ["js"] }
96
97# The blind mail tunnel terminates TLS IN THE BROWSER, so the gateway relays
98# ciphertext and holds none of the keys. This is the one place where writing our own
99# would be strictly worse than depending: a subtly wrong certificate verifier means
100# the gateway CAN intercept while the user has been told it cannot.
101#
102# `default-features = false` is load bearing rather than tidy. rustls 0.23's default
103# set reaches `aws-lc-sys`, which is C and does not cross-compile to wasm32; left on,
104# the build dies in a build script a long way from the line that caused it.
105rustls = { version = "0.23.43", default-features = false, features = ["std", "ring", "tls12", "logging"] }
106# The `web` feature is what makes rustls compile for this target at all. pki-types
107# deliberately removes `UnixTime::now()` on wasm32 because `SystemTime::now()` panics
108# there, while rustls calls it unconditionally under `std` from `ticketer.rs`,
109# `client/handy.rs` and `time_provider.rs` -- call sites a caller never touches, so
110# supplying a `TimeProvider` does not save you. `web` restores it over `web-time`.
111rustls-pki-types = { version = "1.15.1", features = ["web"] }
112# The bundled Mozilla root store, 121 anchors. A browser cannot reach the platform's
113# own trust store from wasm, so the anchors travel in the bundle.
114webpki-roots = "1.0.9"
115web-sys = { version = "0.3", features = [
116 "AbortController",
117 "AbortSignal",
118 "Headers",
119 "ReadableStream",
120 "ReadableStreamDefaultReader",
121 "ReadableStreamReadResult",
122 "Request",
123 "RequestInit",
124 "RequestMode",
125 "Response",
126 "Window",
127 "WorkerGlobalScope",
128 # The cloud-storage index, which JS keeps in `localStorage` (see `wasm::cloud`).
129 "Storage",
130 # OPFS filesystem edge (main-thread async path).
131 "Navigator",
132 "StorageManager",
133 "FileSystemDirectoryHandle",
134 "FileSystemFileHandle",
135 "FileSystemGetFileOptions",
136 "FileSystemGetDirectoryOptions",
137 "FileSystemRemoveOptions",
138 "FileSystemWritableFileStream",
139 "WritableStream",
140 "Blob",
141 "File",
142 # Telling the page the real folder was taken away (see `opfs::notify_folder_lost`).
143 "CustomEvent",
144 "CustomEventInit",
145 "EventTarget",
146] }
147
148# ring arrives anyway through rustls's `ring` feature, but the feature that gives it a
149# random source on this target does not, and rustls cannot enable it. Without
150# `wasm32_unknown_unknown_js` ring has no `SecureRandom` impl for wasm32-unknown-unknown
151# at all and the build fails to compile.
152[target.'cfg(target_arch = "wasm32")'.dependencies.ring]
153version = "0.17.14"
154features = ["wasm32_unknown_unknown_js"]
155
156[dev-dependencies]
157tokio = { version = "1.35", features = ["full", "test-util"] }