8.4 KiB, 33 runs
created by r2519314175:7, which is this file's identity for as long as the history lasts, whatever it is later renamed to
download · who wrote it · its history
| 1 | [package] |
| 2 | name = "oxedyne_daimond" |
| 3 | version = "0.1.0" |
| 4 | authors = ["Jason Hoogland <jason@oxedyne.io>"] |
| 5 | edition = "2021" |
| 6 | license-file = "LICENSE" |
| 7 | description = "Daimond — the browser-first agentic workspace client, built on the Hematite (fe2o3) library. Source-available so the privacy claim can be verified." |
| 8 | repository = "https://github.com/oxedyne-com/daimond" |
| 9 | |
| 10 | [lib] |
| 11 | path = "src/lib.rs" |
| 12 | # `cdylib` lets wasm-pack emit a browser wasm module; `rlib` keeps the |
| 13 | # native consumers (Steel, the agent smoke example) linking as before. |
| 14 | crate-type = ["cdylib", "rlib"] |
| 15 | |
| 16 | # Portable dependencies — build on both native and wasm32. These are |
| 17 | # pulled in by the target-agnostic modules (protocol, session, syntax, |
| 18 | # agent, tools, skills, and the transport-neutral half of llm). |
| 19 | # |
| 20 | # fe2o3 (the Hematite library) is pinned to a fixed revision, and it is pinned |
| 21 | # by GIT rather than by path DELIBERATELY. This file is the public mirror's: |
| 22 | # anyone who clones this repository must be able to build it, and a path |
| 23 | # dependency resolves only inside the author's own tree. A path dep here makes |
| 24 | # the whole verifiability claim untestable by the people it is for -- which is |
| 25 | # what happened between 2026-07-21 and 2026-07-27, when a hand-carve from the |
| 26 | # development tree overwrote this block. The revision below is the fe2o3 commit |
| 27 | # these sources were built and sealed against. |
| 28 | # Certificate verification cannot be switched off in a shipped build: the accept-anything |
| 29 | # verifier and the extra-trust-root hook exist only under this feature, which is OFF, so |
| 30 | # the types that could weaken the tunnel are not in the released wasm at all. |
| 31 | [features] |
| 32 | insecure_testing = [] |
| 33 | |
| 34 | [dependencies] |
| 35 | oxedyne_fe2o3_core = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" } |
| 36 | oxedyne_fe2o3_jdat = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" } |
| 37 | oxedyne_fe2o3_iop_hash = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" } |
| 38 | oxedyne_fe2o3_iop_db = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" } |
| 39 | oxedyne_fe2o3_iop_crypto = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" } |
| 40 | oxedyne_fe2o3_syntax = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" } |
| 41 | oxedyne_fe2o3_graphics = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" } |
| 42 | # The regex engine and the glob matcher the file tools search with (`fe2o3_text::regex`, |
| 43 | # `fe2o3_text::glob`). Portable, so the browser build searches by the same rules the native |
| 44 | # build does -- two matchers would eventually disagree about what a pattern means. |
| 45 | oxedyne_fe2o3_text = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" } |
| 46 | # `fe2o3_stds::media` -- what a file IS, from its own bytes, so the viewer offers a |
| 47 | # picture a picture and a document a document. PORTABLE, and it was native-only |
| 48 | # below until the browser began asking the same question: the wasm build then would |
| 49 | # not compile at all, which the reproducible build caught and the development tree |
| 50 | # could not, since a path dependency there is portable by default. |
| 51 | oxedyne_fe2o3_stds = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" } |
| 52 | # `fe2o3_file::office`, which reads and writes the Microsoft Office formats, over |
| 53 | # `fe2o3_file::zip`. Portable: the crate reaches no filesystem at all, so a `.docx` |
| 54 | # dragged into the browser is read by the same code the native build reads one with. |
| 55 | oxedyne_fe2o3_file = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" } |
| 56 | # SHA3-256, the SBJ address function, which WebCrypto does not implement at all, and |
| 57 | # the SHA-256 behind an identity fingerprint. Pure Rust, so it compiles to wasm32 as |
| 58 | # it stands; it was native-only only while nothing but the native half hashed anything. |
| 59 | oxedyne_fe2o3_hash = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" } |
| 60 | oxedyne_fe2o3_ore = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" } |
| 61 | # SBJ, the signed container a message and an identity card travel in. It is here and |
| 62 | # not behind the gateway because the point of a signature is that the RECIPIENT checks |
| 63 | # it: a server that verified and handed over a tidy result would have proved only that |
| 64 | # the server says so. `default-features = false` drops the post-quantum schemes that |
| 65 | # rest on C, leaving the pure-Rust subset -- Ed25519, SHA3 -- a browser can compile. |
| 66 | oxedyne_fe2o3_sbj = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f", default-features = false } |
| 67 | |
| 68 | # The sans-io half of `fe2o3_mail` -- RFC 5322 message reading and draft building -- behind |
| 69 | # the model's mail tools (`mail_read`, `mail_draft`). `default-features = false` drops the |
| 70 | # server modules (the Maildir store, the passwd user file) that reach `fe2o3_net` and do not |
| 71 | # build for wasm32; what is left needs only `fe2o3_core` and `fe2o3_text`, both portable. |
| 72 | oxedyne_fe2o3_mail = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f", default-features = false } |
| 73 | |
| 74 | # Native-only dependencies. The Steel WebSocket handler, the O3db |
| 75 | # session backend, and the hand-rolled TLS transport are all native |
| 76 | # concerns; none of these crates target wasm32. Target-gated so Cargo |
| 77 | # feature unification never touches the wasm build (F6). |
| 78 | [target.'cfg(not(target_arch = "wasm32"))'.dependencies] |
| 79 | oxedyne_fe2o3_net = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" } |
| 80 | oxedyne_fe2o3_o3db_sync = { git = "https://github.com/oxedyne-com/fe2o3", rev = "3c2894f" } |
| 81 | |
| 82 | tokio = { version = "1.35", features = ["full"] } |
| 83 | tokio-rustls = "0.26" |
| 84 | rustls = { version = "0.23", features = ["ring"] } |
| 85 | rustls-pemfile = "2" |
| 86 | |
| 87 | # Wasm-only dependencies. The browser transport replaces the native |
| 88 | # TLS client with `fetch` + `ReadableStream` via web-sys, driven by |
| 89 | # wasm-bindgen-futures. `getrandom`'s `js` backend must stay confined |
| 90 | # to wasm32 so it never leaks onto native (F6). |
| 91 | [target.'cfg(target_arch = "wasm32")'.dependencies] |
| 92 | wasm-bindgen = "0.2" |
| 93 | wasm-bindgen-futures = "0.4" |
| 94 | js-sys = "0.3" |
| 95 | getrandom = { version = "0.2", features = ["js"] } |
| 96 | |
| 97 | # The blind mail tunnel terminates TLS IN THE BROWSER, so the gateway relays |
| 98 | # ciphertext and holds none of the keys. This is the one place where writing our own |
| 99 | # would be strictly worse than depending: a subtly wrong certificate verifier means |
| 100 | # the gateway CAN intercept while the user has been told it cannot. |
| 101 | # |
| 102 | # `default-features = false` is load bearing rather than tidy. rustls 0.23's default |
| 103 | # set reaches `aws-lc-sys`, which is C and does not cross-compile to wasm32; left on, |
| 104 | # the build dies in a build script a long way from the line that caused it. |
| 105 | rustls = { version = "0.23.43", default-features = false, features = ["std", "ring", "tls12", "logging"] } |
| 106 | # The `web` feature is what makes rustls compile for this target at all. pki-types |
| 107 | # deliberately removes `UnixTime::now()` on wasm32 because `SystemTime::now()` panics |
| 108 | # there, while rustls calls it unconditionally under `std` from `ticketer.rs`, |
| 109 | # `client/handy.rs` and `time_provider.rs` -- call sites a caller never touches, so |
| 110 | # supplying a `TimeProvider` does not save you. `web` restores it over `web-time`. |
| 111 | rustls-pki-types = { version = "1.15.1", features = ["web"] } |
| 112 | # The bundled Mozilla root store, 121 anchors. A browser cannot reach the platform's |
| 113 | # own trust store from wasm, so the anchors travel in the bundle. |
| 114 | webpki-roots = "1.0.9" |
| 115 | web-sys = { version = "0.3", features = [ |
| 116 | "AbortController", |
| 117 | "AbortSignal", |
| 118 | "Headers", |
| 119 | "ReadableStream", |
| 120 | "ReadableStreamDefaultReader", |
| 121 | "ReadableStreamReadResult", |
| 122 | "Request", |
| 123 | "RequestInit", |
| 124 | "RequestMode", |
| 125 | "Response", |
| 126 | "Window", |
| 127 | "WorkerGlobalScope", |
| 128 | # The cloud-storage index, which JS keeps in `localStorage` (see `wasm::cloud`). |
| 129 | "Storage", |
| 130 | # OPFS filesystem edge (main-thread async path). |
| 131 | "Navigator", |
| 132 | "StorageManager", |
| 133 | "FileSystemDirectoryHandle", |
| 134 | "FileSystemFileHandle", |
| 135 | "FileSystemGetFileOptions", |
| 136 | "FileSystemGetDirectoryOptions", |
| 137 | "FileSystemRemoveOptions", |
| 138 | "FileSystemWritableFileStream", |
| 139 | "WritableStream", |
| 140 | "Blob", |
| 141 | "File", |
| 142 | # Telling the page the real folder was taken away (see `opfs::notify_folder_lost`). |
| 143 | "CustomEvent", |
| 144 | "CustomEventInit", |
| 145 | "EventTarget", |
| 146 | ] } |
| 147 | |
| 148 | # ring arrives anyway through rustls's `ring` feature, but the feature that gives it a |
| 149 | # random source on this target does not, and rustls cannot enable it. Without |
| 150 | # `wasm32_unknown_unknown_js` ring has no `SecureRandom` impl for wasm32-unknown-unknown |
| 151 | # at all and the build fails to compile. |
| 152 | [target.'cfg(target_arch = "wasm32")'.dependencies.ring] |
| 153 | version = "0.17.14" |
| 154 | features = ["wasm32_unknown_unknown_js"] |
| 155 | |
| 156 | [dev-dependencies] |
| 157 | tokio = { version = "1.35", features = ["full", "test-util"] } |