oxedyne/daimond/hand/Cargo.toml
4.1 KiB, 9 runs
created by r2519314175:891, which is this file's identity for as long as the history lasts, whatever it is later renamed to
download · who wrote it · its history
| 1 | [package] |
| 2 | name = "daimond_hand" |
| 3 | version = "0.1.0" |
| 4 | authors = ["Jason Hoogland <jason@oxedyne.io>"] |
| 5 | edition = "2021" |
| 6 | # The journal takes an exclusive lock with `File::try_lock`, which is safe and |
| 7 | # needs no dependency -- but it stabilised in 1.89. Recorded here so a build on |
| 8 | # an older toolchain fails saying why, rather than on a missing method. |
| 9 | rust-version = "1.89" |
| 10 | license = "LicenseRef-Proprietary" |
| 11 | description = "Daimond's machine hand — the program outside the page that runs commands on your behalf, fenced, journalled and revocable." |
| 12 | repository = "https://github.com/oxedyne-com/daimond" |
| 13 | |
| 14 | # Isolate this crate from any parent package/workspace, exactly as the gateway |
| 15 | # does: the repository root is a plain `[package]` (the wasm crate), so an empty |
| 16 | # `[workspace]` table here makes the hand its own workspace root and keeps the |
| 17 | # three builds independent. |
| 18 | [workspace] |
| 19 | |
| 20 | [[bin]] |
| 21 | # The native messaging host. Chrome launches it, speaks length-prefixed JSON |
| 22 | # over stdin/stdout, and kills it when the extension goes away. |
| 23 | name = "daimond-hand" |
| 24 | path = "src/main.rs" |
| 25 | |
| 26 | [lib] |
| 27 | name = "daimond_hand" |
| 28 | path = "src/lib.rs" |
| 29 | |
| 30 | [dependencies] |
| 31 | oxedyne_fe2o3_core = { git = "https://github.com/oxedyne-com/fe2o3", rev = "eac7e1ed60ad765b0f7393c2a791b66f903a35a7" } |
| 32 | oxedyne_fe2o3_jdat = { git = "https://github.com/oxedyne-com/fe2o3", rev = "eac7e1ed60ad765b0f7393c2a791b66f903a35a7" } |
| 33 | # The journal's chain. Each entry's hash covers the entry before it, so rewriting |
| 34 | # any past line breaks every line after it. |
| 35 | oxedyne_fe2o3_hash = { git = "https://github.com/oxedyne-com/fe2o3", rev = "eac7e1ed60ad765b0f7393c2a791b66f903a35a7" } |
| 36 | # The pty half of the wire carries raw bytes as base64, and `base64::decode` is |
| 37 | # strict where it matters: non-alphabet characters, misplaced padding, a length |
| 38 | # that is not a whole quantum and non-zero trailing bits are all refused rather |
| 39 | # than guessed at. Already in the tree, since fe2o3_jdat depends on it. |
| 40 | oxedyne_fe2o3_text = { git = "https://github.com/oxedyne-com/fe2o3", rev = "eac7e1ed60ad765b0f7393c2a791b66f903a35a7" } |
| 41 | |
| 42 | tokio = { version = "1.35", features = ["rt-multi-thread", "macros", "process", "io-util", "io-std", "sync", "time", "net"] } |
| 43 | |
| 44 | # The kernel fence. Landlock is a Linux LSM with no safe path through `std`, and |
| 45 | # fe2o3 has no process-sandbox abstraction to reach for -- so the choice was this |
| 46 | # crate or raw syscalls, and raw syscalls mean `unsafe`, which this project does |
| 47 | # not permit. The crate is a safe wrapper, so the rule holds where it matters: |
| 48 | # there is no `unsafe` in Daimond's own code. |
| 49 | # |
| 50 | # Four crates reach the binary (landlock, enumflags2, libc, thiserror); the other |
| 51 | # seven in its tree are proc-macros used at build time only, and five of the |
| 52 | # eleven were already here through tokio. |
| 53 | # |
| 54 | # TARGET-GATED, and it must stay that way. Landlock is Linux's, and an |
| 55 | # unconditional dependency would fail to build on exactly the two platforms the |
| 56 | # `Fence::MacOs` and `Fence::Windows` arms exist to be ready for. |
| 57 | [target.'cfg(target_os = "linux")'.dependencies] |
| 58 | landlock = "0.4.7" |
| 59 | |
| 60 | # The syscall filter, which closes the two escapes Landlock provably cannot: |
| 61 | # metadata syscalls have no Landlock access right, and a pathname unix socket is |
| 62 | # ungoverned below ABI 9 -- which made the user session bus a way to run a command |
| 63 | # OUTSIDE the fence entirely. Pure-Rust BPF assembly; its only dependency is `libc`, |
| 64 | # which landlock above has already brought in, so this is the cheapest of the two |
| 65 | # candidates rather than merely the smaller. Two `unsafe` blocks live inside the |
| 66 | # crate, at the prctl and syscall; Daimond's own code keeps none. |
| 67 | seccompiler = "0.5.0" |
| 68 | |
| 69 | # The terminal. A controlling terminal needs setsid + TIOCSCTTY and a resize needs |
| 70 | # TIOCSWINSZ; `nix` 0.31 wraps none of the three, offering only ioctl macros that |
| 71 | # generate `unsafe fn`, so the choice was this crate or breaking the no-unsafe rule. |
| 72 | # Four packages reach the binary (rustix, linux-raw-sys, bitflags, and socket2 via |
| 73 | # tokio's `net`, which AsyncFd needs). |
| 74 | [target.'cfg(unix)'.dependencies] |
| 75 | rustix = { version = "1.1", features = ["fs", "process", "pty", "termios"] } |
| 76 | |
| 77 | [profile.release] |
| 78 | opt-level = "z" |
| 79 | lto = true |
| 80 | codegen-units = 1 |
| 81 | strip = true |