Findings now carry a level: ok, warn or FAIL. The distinction between the middle two is the part worth getting right — warn is something the agent runs without and that the user can fix from the line printed beneath it, FAIL is something it cannot work around. A diagnostic that grades those the wrong way round is worse than an ungraded one, so each check states which it is. The clearest case is storage: the same failure on the state directory is FAIL and on the cache directory is warn, because one is mandatory and the other is disposable. That asymmetry is central to the design and the report now shows it. The control plane check also became real — it binds a UDP socket rather than asserting that it could. Colour is redundant by construction. Every row carries its grade as a word, so the report reads identically when the escapes are gone: piped to a file, on a dumb terminal, under NO_COLOR, or to someone who cannot distinguish the colours. anstream decides whether they survive, which also gets virtual terminal processing right on Windows; it and anstyle were already in the tree through clap. What is reported and how it looks are separated, so the rendering is tested without a terminal: that a plain render contains no escapes, that a styled one says the same thing once they are stripped, that columns line up across sections whose labels differ in length, and that the summary names the worst thing found. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
78 lines
3.0 KiB
TOML
78 lines
3.0 KiB
TOML
[package]
|
|
name = "tsunagi"
|
|
version = "0.1.0"
|
|
edition = "2024"
|
|
rust-version = "1.91"
|
|
license = "MIT OR Apache-2.0"
|
|
description = "Proof-of-concept library for small private mesh networks: persistent agent identity, deterministic network spaces, iroh-based control plane."
|
|
repository = "https://github.com/tsunagi-net/tsunagi"
|
|
readme = "README.md"
|
|
keywords = ["mesh", "p2p", "iroh", "networking"]
|
|
categories = ["network-programming"]
|
|
|
|
[features]
|
|
default = ["cli"]
|
|
# The `tsunagi` command line binary. Library users can opt out.
|
|
cli = ["dep:clap", "dep:anstream", "dep:anstyle", "dep:tracing-subscriber", "tokio/signal", "tun-device"]
|
|
# A real TUN device, so the WireGuard plugin can carry actual IP traffic.
|
|
# Needs CAP_NET_ADMIN at run time; without it the plugin still runs and its
|
|
# in-memory device can be used for tests.
|
|
tun-device = ["dep:tun", "dep:rtnetlink", "dep:caps", "dep:futures-util"]
|
|
|
|
[[bin]]
|
|
name = "tsunagi"
|
|
path = "src/bin/tsunagi.rs"
|
|
required-features = ["cli"]
|
|
|
|
[dependencies]
|
|
clap = { version = "4.5", features = ["derive", "env"], optional = true }
|
|
# Already in the tree through clap. `anstream` strips the escapes when stdout
|
|
# is not a terminal and turns on virtual terminal processing on Windows, so
|
|
# colour is never written where it would show up as rubbish.
|
|
anstream = { version = "1.0", optional = true }
|
|
anstyle = { version = "1.0", optional = true }
|
|
tracing-subscriber = { version = "0.3", features = ["env-filter"], optional = true }
|
|
iroh = { version = "1.2", default-features = false, features = ["tls-ring"] }
|
|
tokio = { version = "1.53", features = ["rt", "rt-multi-thread", "sync", "time", "macros"] }
|
|
rusqlite = { version = "0.40", features = ["bundled"] }
|
|
hkdf = "0.13"
|
|
hmac = "0.13"
|
|
sha2 = "0.11"
|
|
subtle = "2.6"
|
|
zeroize = { version = "1.9", features = ["derive"] }
|
|
rand = "0.10"
|
|
serde = { version = "1.0", features = ["derive"] }
|
|
postcard = { version = "1.1", default-features = false, features = ["use-std"] }
|
|
data-encoding = "2.11"
|
|
hex = "0.4"
|
|
thiserror = "2.0"
|
|
tracing = "0.1"
|
|
fs4 = { version = "1.1", features = ["sync"] }
|
|
directories = "6.0"
|
|
netwatch = "0.19.3"
|
|
bytes = "1.12.1"
|
|
boringtun = { version = "0.7.1", default-features = false }
|
|
tun = { version = "0.8", features = ["async"], optional = true }
|
|
|
|
# Linux-only interface provisioning. `rtnetlink` configures the interface in
|
|
# process, so no `ip` invocation is ever needed; `caps` keeps CAP_NET_ADMIN
|
|
# out of the effective set except during the moments it is used.
|
|
[target.'cfg(target_os = "linux")'.dependencies]
|
|
rtnetlink = { version = "0.23", optional = true }
|
|
caps = { version = "0.5", optional = true }
|
|
futures-util = { version = "0.3", default-features = false, optional = true }
|
|
|
|
[dev-dependencies]
|
|
tokio = { version = "1.53", features = ["rt", "rt-multi-thread", "sync", "time", "macros", "process"] }
|
|
tempfile = "3.24"
|
|
tracing-subscriber = { version = "0.3", features = ["env-filter"] }
|
|
|
|
[lints.rust]
|
|
missing_docs = "warn"
|
|
unsafe_code = "forbid"
|
|
|
|
[lints.clippy]
|
|
unwrap_used = "warn"
|
|
expect_used = "warn"
|
|
panic = "warn"
|