forked from ZerosAndOnesLLC/AiFw
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathCargo.toml
More file actions
97 lines (92 loc) · 3.47 KB
/
Copy pathCargo.toml
File metadata and controls
97 lines (92 loc) · 3.47 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
[workspace]
members = [
"aifw-common",
"aifw-pf",
"aifw-core",
"aifw-conntrack",
"aifw-plugins",
"aifw-ai",
"aifw-ids",
"aifw-ids-bin",
"aifw-ids-ipc",
"aifw-metrics",
"aifw-api",
"aifw-tui",
"aifw-daemon",
"aifw-cli",
"aifw-setup",
]
resolver = "2"
[workspace.package]
version = "5.109.4"
edition = "2024"
license = "MIT"
repository = "https://github.com/ZerosAndOnesLLC/AiFw"
[workspace.dependencies]
aifw-common = { path = "aifw-common" }
aifw-pf = { path = "aifw-pf" }
aifw-core = { path = "aifw-core" }
aifw-conntrack = { path = "aifw-conntrack" }
aifw-plugins = { path = "aifw-plugins" }
aifw-ids = { path = "aifw-ids" }
aifw-ids-ipc = { path = "aifw-ids-ipc" }
aifw-metrics = { path = "aifw-metrics" }
axum = { version = "0.8", features = ["ws", "multipart"] }
# Only ServiceBuilder (tower core) is used directly — see aifw-api/src/main.rs.
# axum/tower-http pull their own tower features via cargo's per-graph union,
# so nothing broader is needed here (SEC-L6 #321).
tower = { version = "0.5", default-features = false }
tower-http = { version = "0.7", features = ["cors", "trace", "fs", "set-header", "compression-gzip", "compression-br"] }
jsonwebtoken = { version = "10", features = ["rust_crypto"] }
argon2 = { version = "0.5", features = ["std"] }
# tokio base carries no runtime features (PERF-H3 #347). Every crate — library
# and binary alike — opts into exactly the features it uses (no crate uses
# "full"). Cargo unions features per build graph, so validate a library crate's
# minimal set in isolation with `cargo check -p <crate>`; binaries are covered
# by the workspace union build + test suite.
tokio = { version = "1" }
serde = { version = "1", features = ["derive"] }
serde_json = "1"
sqlx = { version = "0.9", features = ["runtime-tokio", "sqlite", "migrate"] }
thiserror = "2"
tracing = "0.1"
tracing-subscriber = { version = "0.3", features = ["env-filter"] }
clap = { version = "4", features = ["derive"] }
chrono = { version = "0.4", features = ["serde"] }
uuid = { version = "1", features = ["v4", "serde"] }
async-trait = "0.1"
ratatui = "0.30"
crossterm = "0.29"
nix = { version = "0.31", features = ["fs", "process", "socket", "net", "fanotify", "feature", "hostname", "user"] }
anyhow = "1"
sha2 = "0.11"
hex = "0.4"
rcgen = "0.14"
libc = "0.2"
time = "0.3"
rustls = "0.23"
tokio-rustls = "0.26"
rustls-pemfile = "2"
reqwest = { version = "0.13", default-features = false, features = ["json", "rustls"] }
url = "2"
x25519-dalek = { version = "2", features = ["static_secrets"] }
getrandom = "0.3"
# Workspace-wide clippy lint posture. Stylistic-only lints are allowed —
# documented engine constructors legitimately have many parameters, the
# `tests` mod-inside-`tests.rs` pattern is project convention, and several
# engine signatures are intentionally complex types we don't want to alias.
# Real code-smell lints stay denied (default-deny via -D warnings in CI).
[workspace.lints.clippy]
module_inception = "allow"
too_many_arguments = "allow"
type_complexity = "allow"
should_implement_trait = "allow"
# Release profile (PERF-H2 #346). LTO + single codegen unit enable cross-crate
# inlining on hot paths (notably the aifw-ids ↔ aho-corasick prefilter);
# strip shrinks binaries for faster cold start on the appliance.
# `panic = "abort"` deliberately omitted: the long-running daemon/API must not
# let a panic in one request handler abort the whole firewall process.
[profile.release]
lto = "thin"
codegen-units = 1
strip = "symbols"