From f3d6d535292d8054ef495bd70a525c54d4aacc4b Mon Sep 17 00:00:00 2001 From: Matthew Jackson <1085847+MattJackson@users.noreply.github.com> Date: Mon, 5 Oct 2026 03:47:01 -0700 Subject: [PATCH 1/2] fleet: render the busbar-release plugin template (c7de1ab97982) busbar-release plugin sync busbar-store-sqlite: template/ at c7de1ab97982d790be6b02277afd681a3d9c2ba4, busbar pin bf32f11ba9634c77afbe1dc89a8c3986499b38af (unchanged), dependency policy at busbar bf32f11ba9634c77afbe1dc89a8c3986499b38af, plugins.yaml at busbar 5489d5f61537027db7c4abf2a049a4c6233735c0. --- .github/CODEOWNERS | 2 + .github/workflows/ci.yml | 10 +- .github/workflows/consumer-verify.yml | 4 +- .github/workflows/dependabot-bundle.yml | 58 +++++++ .github/workflows/release.yml | 15 +- .github/workflows/repin.yml | 4 +- .gitignore | 4 +- .mailmap | 2 +- CONTRIBUTING.md | 19 ++- Cargo.lock | 36 +++- Cargo.toml | 106 +++++++++++- README.md | 2 +- clippy.toml | 6 +- codecov.yml | 9 +- deny.toml | 216 +++++++++++++++++++++++- rust-toolchain.toml | 6 +- store-sqlite-plugin/Cargo.toml | 14 +- store-sqlite/Cargo.toml | 10 +- 18 files changed, 461 insertions(+), 62 deletions(-) create mode 100644 .github/CODEOWNERS create mode 100644 .github/workflows/dependabot-bundle.yml diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS new file mode 100644 index 0000000..45f159d --- /dev/null +++ b/.github/CODEOWNERS @@ -0,0 +1,2 @@ +# RENDERED by `busbar-release plugin sync` from GetBusbar/busbar-release template/. +* @MattJackson diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 03b2072..8f553dd 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,6 +1,8 @@ -# RENDERED by `cargo xtask fleet render busbar-store-sqlite` from GetBusbar/busbar's plugins.yaml and -# .github/fleet/ templates; `cargo xtask fleet check` is red on any edit here. The CI itself is -# busbar's plugin-ci.yml, taken at the busbar commit this repo pins (.busbar-ref). +# RENDERED by `busbar-release plugin sync busbar-store-sqlite` from GetBusbar/busbar-release template/; a hand +# edit is overwritten by the next sync. THIS REPO TESTS ITSELF AGAINST BUSBAR with the fleet's ONE +# harness: busbar's reusable plugin-ci.yml, taken at the busbar commit this repo pins (.busbar-ref), so +# the CI logic, the gates (busbar scripts/fleet/plugin-gates.py), the dependency policy +# (.github/fleet/deps.toml) and the contract move together (OWNER 2026-10-02). No CI logic lives here. name: ci on: @@ -9,6 +11,8 @@ on: pull_request: branches: [dev, qa, main] workflow_dispatch: {} + # release.yml runs this file on the tagged commit before it publishes. + workflow_call: {} permissions: contents: read diff --git a/.github/workflows/consumer-verify.yml b/.github/workflows/consumer-verify.yml index 50d5b0d..2dcebc0 100644 --- a/.github/workflows/consumer-verify.yml +++ b/.github/workflows/consumer-verify.yml @@ -1,5 +1,5 @@ -# RENDERED by `cargo xtask fleet render busbar-store-sqlite` from GetBusbar/busbar's plugins.yaml and -# .github/fleet/ templates; `cargo xtask fleet check` is red on any edit here. Daily: does the newest +# RENDERED by `busbar-release plugin sync busbar-store-sqlite` from GetBusbar/busbar-release template/; a hand +# edit is overwritten by the next sync. Daily: does the newest # PUBLISHED release still work for a user (busbar's plugin-consumer-verify.yml)? A publish-time check # cannot see an artifact that rots afterwards; release.yml verifies each release as it publishes. name: consumer-verify diff --git a/.github/workflows/dependabot-bundle.yml b/.github/workflows/dependabot-bundle.yml new file mode 100644 index 0000000..d2cbe61 --- /dev/null +++ b/.github/workflows/dependabot-bundle.yml @@ -0,0 +1,58 @@ +# RENDERED by `busbar-release plugin sync busbar-store-sqlite` from GetBusbar/busbar-release template/; a hand +# edit is overwritten by the next sync (DEPENDABOT-ONE). +# dependabot-bundle: every open dependabot PR (whatever its base today) is merged into ONE branch (deps/bundle), +# which carries ONE PR with auto-merge on. Merged PRs are closed with a link; a PR that conflicts +# is listed in the bundle PR body and left open. The branch is only ever fast-forwarded (no force). +# Secrets: BUNDLE_TOKEN (or FLEET_TOKEN) lets the bundle PR run CI and lets a github-actions bump +# (a workflow-file change) be pushed; without one GITHUB_TOKEN is used and those cases fail loudly. +# pull_request_target runs the BASE branch's copy of this file and never executes PR code: it only +# fetches and merges the PR heads. +name: dependabot-bundle +on: + pull_request_target: + types: [opened, synchronize] + branches: [dev] + schedule: + - cron: "23 5 * * *" + workflow_dispatch: +permissions: + contents: write + pull-requests: write +concurrency: + group: dependabot-bundle +env: + TARGET: dev + BUNDLE: deps/bundle + GH_TOKEN: ${{ secrets.BUNDLE_TOKEN || secrets.FLEET_TOKEN || github.token }} +jobs: + bundle: + if: github.event_name != 'pull_request_target' || github.actor == 'dependabot[bot]' + runs-on: ubuntu-latest + steps: + - run: | + set -euo pipefail + gh auth setup-git + git clone -q "https://github.com/$GITHUB_REPOSITORY" w && cd w + git config user.name "github-actions[bot]" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + if git ls-remote --exit-code --heads origin "$BUNDLE" >/dev/null; then + git checkout -q -B "$BUNDLE" "origin/$BUNDLE" + git merge -q -m "deps: merge $TARGET" "origin/$TARGET" + else + git checkout -q -B "$BUNDLE" "origin/$TARGET" + fi + merged=(); bad=() + while IFS=$'\t' read -r n t; do + [ -n "$n" ] || continue + git fetch -q origin "pull/$n/head" + if git merge -q -m "deps: merge #$n $t" FETCH_HEAD; then merged+=("$n"); else git merge --abort; bad+=("$n"); fi + done < <(gh pr list --state open --author 'app/dependabot' --json number,title --jq '.[]|"\(.number)\t\(.title)"') + [ "$(git rev-list --count "origin/$TARGET..HEAD")" -gt 0 ] || { echo "nothing to bundle"; exit 0; } + git push -q origin "$BUNDLE" + body="Bundled dependabot updates, merged from: $(printf '#%s ' "${merged[@]}")" + [ ${#bad[@]} -eq 0 ] || body="$body"$'\n\n'"CONFLICT, left open (resolve or close by hand): $(printf '#%s ' "${bad[@]}")" + pr=$(gh pr list --head "$BUNDLE" --base "$TARGET" --state open --json number --jq '.[0].number // empty') + if [ -n "$pr" ]; then gh pr edit "$pr" --body "$body" + else pr=$(gh pr create --head "$BUNDLE" --base "$TARGET" --title "deps: bundled dependabot updates" --body "$body" | sed 's|.*/||'); fi + gh pr merge "$pr" --auto --merge || echo "::warning::auto-merge not enabled on #$pr" + for n in "${merged[@]}"; do gh pr close "$n" --comment "Merged into the bundle branch; continues in #$pr."; done diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 3113f8b..81b433f 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,7 +1,7 @@ -# RENDERED by `cargo xtask fleet render busbar-store-sqlite` from GetBusbar/busbar's plugins.yaml and -# .github/fleet/ templates; `cargo xtask fleet check` is red on any edit here. On a v* tag: this -# repo's CI on the tagged commit, then busbar's plugin-release.yml (build, sign, pack, publish), then -# the consumer verification of what was published, each at the busbar commit this repo pins. +# RENDERED by `busbar-release plugin sync busbar-store-sqlite` from GetBusbar/busbar-release template/; a hand +# edit is overwritten by the next sync. On a v* tag: this repo's own ci.yml (the fleet harness) on the +# tagged commit, then busbar's plugin-release.yml (build, sign, pack, publish), then the consumer +# verification of what was published, each at the busbar commit this repo pins. name: release on: @@ -21,12 +21,7 @@ permissions: jobs: ci: - uses: GetBusbar/busbar/.github/workflows/plugin-ci.yml@bf32f11ba9634c77afbe1dc89a8c3986499b38af - with: - service: none - busbar_checkout: true - macos_test: "cargo test --workspace --locked" - extra_test: "" + uses: ./.github/workflows/ci.yml secrets: inherit release: needs: ci diff --git a/.github/workflows/repin.yml b/.github/workflows/repin.yml index 16b7456..ffeffab 100644 --- a/.github/workflows/repin.yml +++ b/.github/workflows/repin.yml @@ -1,5 +1,5 @@ -# RENDERED by `cargo xtask fleet render busbar-store-sqlite` from GetBusbar/busbar's plugins.yaml and -# .github/fleet/ templates; `cargo xtask fleet check` is red on any edit here. Moves this repo's +# RENDERED by `busbar-release plugin sync busbar-store-sqlite` from GetBusbar/busbar-release template/; a hand +# edit is overwritten by the next sync. Moves this repo's # busbar pin (busbar's plugin-repin.yml) when busbar dispatches `busbar-repin` or on demand; the # cut/skip decision is by commit, and the commit goes to dev only. name: repin diff --git a/.gitignore b/.gitignore index f9ec886..78a11ae 100644 --- a/.gitignore +++ b/.gitignore @@ -1,5 +1,5 @@ -# RENDERED by `cargo xtask fleet render` from GetBusbar/busbar's plugins.yaml (the entry's -# `gitignore:` lines follow the fleet's own) and .github/fleet/gitignore. +# RENDERED by `busbar-release plugin sync` from GetBusbar/busbar-release template/ (the plugins.yaml +# entry's `gitignore:` lines follow the fleet's own). /target /mutants.out* busbar-governance.db* diff --git a/.mailmap b/.mailmap index 080ad24..5f52e81 100644 --- a/.mailmap +++ b/.mailmap @@ -1,4 +1,4 @@ -# RENDERED by `cargo xtask fleet render` from GetBusbar/busbar's plugins.yaml and .github/fleet/. +# RENDERED by `busbar-release plugin sync` from GetBusbar/busbar-release template/. # Canonical authorship. Commits go out under Matthew Jackson's GitHub noreply only. Matthew Jackson <1085847+MattJackson@users.noreply.github.com> Matthew Jackson <1085847+MattJackson@users.noreply.github.com> Matthew diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 62f3744..87cb875 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -13,9 +13,22 @@ Thanks for your interest in improving `busbar-store-sqlite`. ## Layout Every busbar plugin repo has the same skeleton. This one is a two-crate Cargo workspace: `store-sqlite/` holds the plugin's logic and `store-sqlite-plugin/` is the thin `cdylib` that packages it as a droppable `kind: store` plugin. busbar itself is a git dependency -pinned to the commit in `.busbar-ref`. The CI, release and lint configuration are -rendered from [busbar's plugin registry](https://github.com/GetBusbar/busbar/blob/main/plugins.yaml); -change them there, not here. +pinned to the commit in `.busbar-ref`. The CI, release, dependency and lint configuration +are rendered by `busbar-release plugin sync` from the fleet template (GetBusbar/busbar-release +`template/`), [busbar's plugin registry](https://github.com/GetBusbar/busbar/blob/main/plugins.yaml) +and busbar's dependency policy (`.github/fleet/deps.toml` and the root `[workspace.dependencies]` +at the pin); change them there, not here. + +## This repo tests itself against busbar + +CI runs the fleet's one harness, busbar's reusable `plugin-ci.yml`, at the busbar commit in +`.busbar-ref`: fmt, clippy -D warnings, the whole test suite, `cargo deny`, the dependency wall +(busbar-contract plus third-party only), the socket/TLS ban (no plugin opens its own socket, dials, +binds or does TLS), the C-dependency allow-list, `Cargo.lock` parity with busbar's lock at the pin, +the both-ways conformance and the busbar conformance kit for this kind. The tests are this repo's: +`store-sqlite-plugin/tests/conformance.rs` loads the LINKED door and the BUILT cdylib through busbar's +plugin loader and requires one transcript (a test named `the_linked_and_the_dropped_in_*`), and keeps +at least one RED arm (any other test in that target) that proves the comparison can fail. ## Before you open a pull request diff --git a/Cargo.lock b/Cargo.lock index f4bcbde..0b4585e 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -717,9 +717,9 @@ dependencies = [ [[package]] name = "libsqlite3-sys" -version = "0.38.1" +version = "0.38.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "f6c19a05435c21ac299d71b6a9c13db3e3f47c520517d58990a462a1397a61db" +checksum = "f1d20bef17f513b9b3004532233187769cd072d790971f4e4da0e346eb6401e8" dependencies = [ "cc", "pkg-config", @@ -950,12 +950,14 @@ dependencies = [ "sync_wrapper", "tokio", "tokio-rustls", + "tokio-util", "tower", "tower-http", "tower-service", "url", "wasm-bindgen", "wasm-bindgen-futures", + "wasm-streams", "web-sys", "webpki-roots", ] @@ -986,9 +988,9 @@ dependencies = [ [[package]] name = "rusqlite" -version = "0.40.1" +version = "0.40.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "11438310b19e3109b6446c33d1ed5e889428cf2e278407bc7896bc4aaea43323" +checksum = "23f2a97da3e3873c73cb2a2e71b35c40ff95e0b1eefa8d72d8499a6928c3b5b3" dependencies = [ "bitflags", "fallible-iterator", @@ -1317,6 +1319,19 @@ dependencies = [ "tokio", ] +[[package]] +name = "tokio-util" +version = "0.7.18" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9ae9cec805b01e8fc3fd2fe289f89149a9b66dd16786abd8b19cfa7b48cb0098" +dependencies = [ + "bytes", + "futures-core", + "futures-sink", + "pin-project-lite", + "tokio", +] + [[package]] name = "tower" version = "0.5.3" @@ -1571,6 +1586,19 @@ dependencies = [ "unicode-ident", ] +[[package]] +name = "wasm-streams" +version = "0.4.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "15053d8d85c7eccdbefef60f06769760a563c7f0a9d6902a13d35c7800b0ad65" +dependencies = [ + "futures-util", + "js-sys", + "wasm-bindgen", + "wasm-bindgen-futures", + "web-sys", +] + [[package]] name = "web-sys" version = "0.3.99" diff --git a/Cargo.toml b/Cargo.toml index 09ee4d3..df9e5d4 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -1,13 +1,19 @@ # SPDX-License-Identifier: Apache-2.0 # -# RENDERED by `cargo xtask fleet render busbar-store-sqlite` from GetBusbar/busbar's plugins.yaml and -# .github/fleet/workspace-Cargo.toml; `cargo xtask fleet check` is red on any edit here. +# RENDERED by `busbar-release plugin sync busbar-store-sqlite` from GetBusbar/busbar-release template/ and +# GetBusbar/busbar's dependency policy; a hand edit is overwritten by the next sync. # -# One repo per plugin, every repo a twin: this workspace is exactly two crates, the logic -# (`store-sqlite/`, the rlib a busbar build can link) and the thin cdylib that packages it as a -# droppable `kind: store` plugin (`store-sqlite-plugin/`, crate `busbar-store-sqlite-plugin`). Its busbar -# dependencies are git dependencies on GetBusbar/busbar at the fleet pin (`.busbar-ref` field 1); -# no sibling-checkout path dependency ships in any manifest. +# One repo per plugin, every repo a twin: this workspace is exactly two crates, the logic (the rlib a +# busbar build links) and the thin cdylib that packages it as a droppable `kind: store` plugin +# (crate `busbar-store-sqlite-plugin`). Its one busbar dependency is busbar-contract (busbar-plugin-loader is dev-only, +# for the both-ways conformance test), both git dependencies on GetBusbar/busbar at the pin in +# `.busbar-ref`; no sibling-checkout path dependency ships in any manifest. +# +# THIRD-PARTY VERSIONS ARE THE FLEET'S, NOT THIS REPO'S. The table below is busbar's own root +# `[workspace.dependencies]` (third-party rows) at busbar bf32f11ba9634c77afbe1dc89a8c3986499b38af, followed by the plugin-only rows +# of busbar's `.github/fleet/deps.toml` at bf32f11ba9634c77afbe1dc89a8c3986499b38af. A member takes a crate with +# `{ workspace = true }` (adding features if it needs them); a crate in neither table is a new +# `deps.toml` row in busbar first. CI holds this repo's Cargo.lock to busbar's lock at the pin. [workspace] resolver = "2" members = [ @@ -25,3 +31,89 @@ repository = "https://github.com/GetBusbar/busbar-store-sqlite" [workspace.dependencies] busbar-contract = { git = "https://github.com/GetBusbar/busbar", rev = "bf32f11ba9634c77afbe1dc89a8c3986499b38af" } busbar-plugin-loader = { git = "https://github.com/GetBusbar/busbar", rev = "bf32f11ba9634c77afbe1dc89a8c3986499b38af" } +# busbar's root [workspace.dependencies], third-party rows, at bf32f11ba9634c77afbe1dc89a8c3986499b38af +a2a-lf = "0.3.0" +a2a-pb = "0.2.0" +arc-swap = "1" +async-trait = "0.1" +axum = "0.8" +base64 = "0.22" +bumpalo = "3" +bytes = "1" +core_affinity = "0.8" +crc32fast = "1" +criterion = { version = "0.7", default-features = false, features = ["cargo_bench_support"] } +dimpl = { version = "=0.7.4", default-features = false } +ed25519-dalek = { version = "2", default-features = false, features = ["std"] } +flate2 = { version = "1", default-features = false, features = ["rust_backend"] } +futures = "0.3" +getrandom = "0.3" +h2 = "0.4" +hex = "0.4.3" +hmac = "0.13.0" +http = "1" +http-body = "1" +http-body-util = "0.1" +httpdate = "1.0" +hyper = { version = "1", default-features = false, features = ["server", "client", "http1", "http2"] } +hyper-rustls = { version = "0.27", default-features = false, features = ["http1", "http2", "ring", "webpki-tokio"] } +hyper-util = { version = "0.1", default-features = false, features = ["client-legacy", "http1", "http2", "server-auto", "server-graceful", "service", "tokio"] } +idna_adapter = "=1.1.0" +indexmap = { version = "2", features = ["serde"] } +jsonschema = { version = "0.49", default-features = false } +libc = "0.2" +libloading = "0.9" +log = "0.4" +loom = "0.7" +memchr = "2" +metrics = "0.24.6" +metrics-exporter-prometheus = { version = "0.18.3", default-features = false } +metrics-util = { version = "0.20.4", default-features = false } +oauth-as = { version = "1.0.0", features = ["http", "jwt", "consent", "resource-metadata", "par", "dpop", "client-assertion"] } +opentelemetry-proto = { version = "0.32", default-features = false, features = ["gen-tonic-messages", "trace"] } +proc-macro2 = { version = "1", features = ["span-locations"] } +proptest = "1" +prost = { version = "0.14", default-features = false, features = ["std"] } +rcgen = { version = "0.14", default-features = false, features = ["crypto", "ring"] } +reqwest = { version = "0.12", default-features = false, features = ["rustls-tls", "stream"] } +ring = "0.17" +rmcp = { version = "3.1.2", default-features = false } +rustls = { version = "0.23", default-features = false, features = ["ring", "std", "tls12"] } +rustls-pki-types = { version = "1", default-features = false, features = ["std"] } +schemars = "1" +serde = { version = "1", features = ["derive"] } +serde_json = "1" +serde_urlencoded = "0.7" +serde_yaml = { package = "serde_yaml_ng", version = "0.10" } +sha2 = "0.10" +smallvec = "1" +socket2 = { version = "0.6", features = ["all"] } +sonic-rs = "0.5" +syn = { version = "2", features = ["full", "visit", "parsing", "printing"] } +tar = { version = "0.4", default-features = false } +tikv-jemalloc-ctl = "0.6" +tikv-jemallocator = "0.6" +tokio = "1" +tokio-rustls = { version = "0.26", default-features = false, features = ["ring"] } +tokio-tungstenite = { version = "0.29", default-features = false, features = ["handshake"] } +tokio-util = { version = "0.7", default-features = false, features = ["compat"] } +tonic = { version = "0.14", default-features = false } +tonic-types = "0.14" +tower = "0.5" +tracing = "0.1.44" +tracing-core = "0.1" +tracing-log = { version = "0.2", default-features = false, features = ["log-tracer", "std"] } +tracing-subscriber = "0.3.23" +tungstenite = { version = "0.29", default-features = false } +url = "2" +webpki = { package = "rustls-webpki", version = "0.103", default-features = false, features = ["std", "ring"] } +webpki-roots = "1" +zeroize = "1" +# busbar .github/fleet/deps.toml [plugin-deps], at bf32f11ba9634c77afbe1dc89a8c3986499b38af +ldap3 = { version = "0.12", default-features = false, features = ["sync"] } +mysql = { version = "26", default-features = false, features = ["minimal"] } +postgres = "0.19" +redis = { version = "1", default-features = false, features = ["script"] } +rusqlite = { version = "0.40", features = ["bundled"] } +ulid = "1" + diff --git a/README.md b/README.md index ac07927..4cb16b9 100644 --- a/README.md +++ b/README.md @@ -1,4 +1,4 @@ - + # busbar-store-sqlite First-party signed kind:store plugin cdylib: the SQLite governance store packaged as a droppable busbar plugin exporting the store C ABI. Drop the built library into the plugins folder and set store.module: sqlite. diff --git a/clippy.toml b/clippy.toml index 9cabef7..fd71967 100644 --- a/clippy.toml +++ b/clippy.toml @@ -1,4 +1,4 @@ -# RENDERED by `cargo xtask fleet render` from GetBusbar/busbar's plugins.yaml and .github/fleet/ -# templates. CI runs clippy with -D warnings (busbar's plugin-ci.yml) on the 1.98.0 toolchain; -# the MSRV clippy judges against is each crate's own `rust-version`, so none is restated here. +# RENDERED by `busbar-release plugin sync` from GetBusbar/busbar-release template/; a hand edit is +# overwritten by the next sync. CI (busbar's plugin-ci.yml at the pin) runs clippy with -D warnings on +# the 1.98.0 toolchain; the MSRV clippy judges against is each crate's own `rust-version`. too-many-arguments-threshold = 7 diff --git a/codecov.yml b/codecov.yml index a9c60ed..f1b9b9a 100644 --- a/codecov.yml +++ b/codecov.yml @@ -1,8 +1,7 @@ -# RENDERED by `cargo xtask fleet render` from GetBusbar/busbar's plugins.yaml and .github/fleet/. -# Codecov is INFORMATIONAL, never a gate: the correctness gate is the `ci` job (busbar's -# plugin-ci.yml). Coverage is an observation on the README badge and the Codecov UI, so every status -# is informational, there are no PR comments, and test-only paths plus the busbar checkout the -# end-to-end tests build are excluded from the percentage. +# RENDERED by `busbar-release plugin sync` from GetBusbar/busbar-release template/. +# Codecov is INFORMATIONAL, never a gate: the correctness gate is the `ci` workflow (busbar's +# plugin-ci.yml at the pin). Every status is informational, there are no PR comments, and test-only paths +# plus the busbar checkout the end-to-end tests build are excluded from the percentage. coverage: status: project: diff --git a/deny.toml b/deny.toml index ddbdadd..62f5a43 100644 --- a/deny.toml +++ b/deny.toml @@ -1,6 +1,10 @@ -# RENDERED by `cargo xtask fleet render` from GetBusbar/busbar's plugins.yaml and .github/fleet/ -# templates. cargo-deny policy for a first-party plugin: the license allowlist busbar's own deny.toml -# holds, and ONE reviewed git source (busbar itself, at the pin). +# RENDERED by `busbar-release plugin sync` from GetBusbar/busbar-release template/ and busbar's +# `.github/fleet/deps.toml` at bf32f11ba9634c77afbe1dc89a8c3986499b38af; a hand edit is overwritten by the next sync. CI runs +# `cargo deny check` on it (busbar's plugin-ci.yml at the pin). The license allowlist is busbar's own; +# the one reviewed git source is busbar itself, at the pin. +[graph] +all-features = false + [advisories] version = 2 @@ -27,9 +31,213 @@ allow = [ confidence-threshold = 0.9 [bans] -multiple-versions = "warn" +multiple-versions = "deny" wildcards = "deny" allow-wildcard-paths = true +# busbar .github/fleet/deps.toml [bans].deny (one stack per concern), then ONE VERSION OF EVERYTHING +# BUSBAR USES (OWNER 2026-10-02): every version of a shared crate outside the line busbar's own +# Cargo.lock resolves it to, at the pin. +deny = [ + # ONE Ed25519 = ed25519-dalek 2 (ARCHITECT ruling 2026-10-02; mirrors busbar deny.toml): no older + # dalek and no other Ed25519 implementation may enter a plugin's closure. + { crate = "ed25519-dalek@1", reason = "ONE Ed25519: ed25519-dalek 2" }, + { crate = "ed25519-dalek@0", reason = "ONE Ed25519: ed25519-dalek 2" }, + { crate = "ed25519-compact", reason = "ONE Ed25519: ed25519-dalek 2" }, + { crate = "ed25519-zebra", reason = "ONE Ed25519: ed25519-dalek 2" }, + { crate = "ed25519-consensus", reason = "ONE Ed25519: ed25519-dalek 2" }, + { crate = "openssl", reason = "TLS is rustls (core-only); no OpenSSL anywhere in the fleet" }, + { crate = "openssl-sys", reason = "TLS is rustls (core-only); no OpenSSL anywhere in the fleet" }, + { crate = "native-tls", reason = "TLS is rustls (core-only); no platform TLS anywhere in the fleet" }, + { crate = "hyper:<1", reason = "HTTP is hyper 1; no hyper 0.14 stack" }, + { crate = "rustls:<0.23", reason = "one rustls major (0.23) fleet-wide" }, + { crate = "ring:<0.17", reason = "one ring major (0.17) fleet-wide" }, + { crate = "serde_yaml", reason = "unmaintained; busbar uses serde_yaml_ng" }, + { crate = "a2a-lf:<0.3.0", reason = "busbar resolves a2a-lf to 0.3.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "a2a-lf:>=0.4.0", reason = "busbar resolves a2a-lf to 0.3.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "a2a-pb:<0.2.0", reason = "busbar resolves a2a-pb to 0.2.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "a2a-pb:>=0.3.0", reason = "busbar resolves a2a-pb to 0.2.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "arc-swap:<1.0.0", reason = "busbar resolves arc-swap to 1.9.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "arc-swap:>=2.0.0", reason = "busbar resolves arc-swap to 1.9.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "async-trait:<0.1.0", reason = "busbar resolves async-trait to 0.1.92; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "async-trait:>=0.2.0", reason = "busbar resolves async-trait to 0.1.92; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "axum:<0.8.0", reason = "busbar resolves axum to 0.8.9; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "axum:>=0.9.0", reason = "busbar resolves axum to 0.8.9; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "base64:<0.22.0", reason = "busbar resolves base64 to 0.22.1, 0.23.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "base64:>=0.24.0", reason = "busbar resolves base64 to 0.22.1, 0.23.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "bumpalo:<3.0.0", reason = "busbar resolves bumpalo to 3.20.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "bumpalo:>=4.0.0", reason = "busbar resolves bumpalo to 3.20.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "bytes:<1.0.0", reason = "busbar resolves bytes to 1.12.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "bytes:>=2.0.0", reason = "busbar resolves bytes to 1.12.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "core_affinity:<0.8.0", reason = "busbar resolves core_affinity to 0.8.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "core_affinity:>=0.9.0", reason = "busbar resolves core_affinity to 0.8.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "crc32fast:<1.0.0", reason = "busbar resolves crc32fast to 1.5.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "crc32fast:>=2.0.0", reason = "busbar resolves crc32fast to 1.5.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "criterion:<0.7.0", reason = "busbar resolves criterion to 0.7.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "criterion:>=0.8.0", reason = "busbar resolves criterion to 0.7.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "dimpl:<0.7.0", reason = "busbar resolves dimpl to 0.7.4; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "dimpl:>=0.8.0", reason = "busbar resolves dimpl to 0.7.4; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "ed25519-dalek:<2.0.0", reason = "busbar resolves ed25519-dalek to 2.2.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "ed25519-dalek:>=3.0.0", reason = "busbar resolves ed25519-dalek to 2.2.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "flate2:<1.0.0", reason = "busbar resolves flate2 to 1.1.10; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "flate2:>=2.0.0", reason = "busbar resolves flate2 to 1.1.10; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "futures:<0.3.0", reason = "busbar resolves futures to 0.3.34; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "futures:>=0.4.0", reason = "busbar resolves futures to 0.3.34; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "getrandom:<0.2.0", reason = "busbar resolves getrandom to 0.2.17, 0.3.4, 0.4.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "getrandom:>=0.5.0", reason = "busbar resolves getrandom to 0.2.17, 0.3.4, 0.4.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "h2:<0.4.0", reason = "busbar resolves h2 to 0.4.18; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "h2:>=0.5.0", reason = "busbar resolves h2 to 0.4.18; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "hex:<0.4.0", reason = "busbar resolves hex to 0.4.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "hex:>=0.5.0", reason = "busbar resolves hex to 0.4.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "http:<1.0.0", reason = "busbar resolves http to 1.4.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "http:>=2.0.0", reason = "busbar resolves http to 1.4.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "http-body:<1.0.0", reason = "busbar resolves http-body to 1.1.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "http-body:>=2.0.0", reason = "busbar resolves http-body to 1.1.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "http-body-util:<0.1.0", reason = "busbar resolves http-body-util to 0.1.5; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "http-body-util:>=0.2.0", reason = "busbar resolves http-body-util to 0.1.5; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "httpdate:<1.0.0", reason = "busbar resolves httpdate to 1.0.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "httpdate:>=2.0.0", reason = "busbar resolves httpdate to 1.0.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "hyper:<1.0.0", reason = "busbar resolves hyper to 1.11.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "hyper:>=2.0.0", reason = "busbar resolves hyper to 1.11.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "hyper-rustls:<0.27.0", reason = "busbar resolves hyper-rustls to 0.27.9; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "hyper-rustls:>=0.28.0", reason = "busbar resolves hyper-rustls to 0.27.9; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "hyper-util:<0.1.0", reason = "busbar resolves hyper-util to 0.1.20; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "hyper-util:>=0.2.0", reason = "busbar resolves hyper-util to 0.1.20; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "idna_adapter:<1.0.0", reason = "busbar resolves idna_adapter to 1.1.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "idna_adapter:>=2.0.0", reason = "busbar resolves idna_adapter to 1.1.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "indexmap:<2.0.0", reason = "busbar resolves indexmap to 2.14.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "indexmap:>=3.0.0", reason = "busbar resolves indexmap to 2.14.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "jsonschema:<0.49.0", reason = "busbar resolves jsonschema to 0.49.9; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "jsonschema:>=0.50.0", reason = "busbar resolves jsonschema to 0.49.9; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "libc:<0.2.0", reason = "busbar resolves libc to 0.2.189; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "libc:>=0.3.0", reason = "busbar resolves libc to 0.2.189; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "libloading:<0.9.0", reason = "busbar resolves libloading to 0.9.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "libloading:>=0.10.0", reason = "busbar resolves libloading to 0.9.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "log:<0.4.0", reason = "busbar resolves log to 0.4.30; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "log:>=0.5.0", reason = "busbar resolves log to 0.4.30; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "loom:<0.7.0", reason = "busbar resolves loom to 0.7.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "loom:>=0.8.0", reason = "busbar resolves loom to 0.7.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "memchr:<2.0.0", reason = "busbar resolves memchr to 2.8.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "memchr:>=3.0.0", reason = "busbar resolves memchr to 2.8.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "metrics:<0.24.0", reason = "busbar resolves metrics to 0.24.6; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "metrics:>=0.25.0", reason = "busbar resolves metrics to 0.24.6; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "metrics-exporter-prometheus:<0.18.0", reason = "busbar resolves metrics-exporter-prometheus to 0.18.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "metrics-exporter-prometheus:>=0.19.0", reason = "busbar resolves metrics-exporter-prometheus to 0.18.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "metrics-util:<0.20.0", reason = "busbar resolves metrics-util to 0.20.4; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "metrics-util:>=0.21.0", reason = "busbar resolves metrics-util to 0.20.4; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "oauth-as:<1.0.0", reason = "busbar resolves oauth-as to 1.0.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "oauth-as:>=2.0.0", reason = "busbar resolves oauth-as to 1.0.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "opentelemetry-proto:<0.32.0", reason = "busbar resolves opentelemetry-proto to 0.32.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "opentelemetry-proto:>=0.33.0", reason = "busbar resolves opentelemetry-proto to 0.32.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "proc-macro2:<1.0.0", reason = "busbar resolves proc-macro2 to 1.0.106; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "proc-macro2:>=2.0.0", reason = "busbar resolves proc-macro2 to 1.0.106; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "proptest:<1.0.0", reason = "busbar resolves proptest to 1.11.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "proptest:>=2.0.0", reason = "busbar resolves proptest to 1.11.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "prost:<0.14.0", reason = "busbar resolves prost to 0.14.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "prost:>=0.15.0", reason = "busbar resolves prost to 0.14.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "rcgen:<0.14.0", reason = "busbar resolves rcgen to 0.14.10; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "rcgen:>=0.15.0", reason = "busbar resolves rcgen to 0.14.10; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "reqwest:<0.12.0", reason = "busbar resolves reqwest to 0.12.28; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "reqwest:>=0.13.0", reason = "busbar resolves reqwest to 0.12.28; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "ring:<0.17.0", reason = "busbar resolves ring to 0.17.14; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "ring:>=0.18.0", reason = "busbar resolves ring to 0.17.14; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "rmcp:<3.0.0", reason = "busbar resolves rmcp to 3.1.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "rmcp:>=4.0.0", reason = "busbar resolves rmcp to 3.1.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "rustls:<0.23.0", reason = "busbar resolves rustls to 0.23.45; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "rustls:>=0.24.0", reason = "busbar resolves rustls to 0.23.45; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "rustls-pki-types:<1.0.0", reason = "busbar resolves rustls-pki-types to 1.15.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "rustls-pki-types:>=2.0.0", reason = "busbar resolves rustls-pki-types to 1.15.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "schemars:<1.0.0", reason = "busbar resolves schemars to 1.2.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "schemars:>=2.0.0", reason = "busbar resolves schemars to 1.2.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "serde:<1.0.0", reason = "busbar resolves serde to 1.0.229; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "serde:>=2.0.0", reason = "busbar resolves serde to 1.0.229; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "serde_json:<1.0.0", reason = "busbar resolves serde_json to 1.0.151; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "serde_json:>=2.0.0", reason = "busbar resolves serde_json to 1.0.151; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "serde_urlencoded:<0.7.0", reason = "busbar resolves serde_urlencoded to 0.7.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "serde_urlencoded:>=0.8.0", reason = "busbar resolves serde_urlencoded to 0.7.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "serde_yaml_ng:<0.10.0", reason = "busbar resolves serde_yaml_ng to 0.10.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "serde_yaml_ng:>=0.11.0", reason = "busbar resolves serde_yaml_ng to 0.10.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "sha2:<0.10.0", reason = "busbar resolves sha2 to 0.10.9; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "sha2:>=0.11.0", reason = "busbar resolves sha2 to 0.10.9; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "smallvec:<1.0.0", reason = "busbar resolves smallvec to 1.16.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "smallvec:>=2.0.0", reason = "busbar resolves smallvec to 1.16.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "socket2:<0.6.0", reason = "busbar resolves socket2 to 0.6.4; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "socket2:>=0.7.0", reason = "busbar resolves socket2 to 0.6.4; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "sonic-rs:<0.5.0", reason = "busbar resolves sonic-rs to 0.5.10; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "sonic-rs:>=0.6.0", reason = "busbar resolves sonic-rs to 0.5.10; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "syn:<2.0.0", reason = "busbar resolves syn to 2.0.117, 3.0.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "syn:>=4.0.0", reason = "busbar resolves syn to 2.0.117, 3.0.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tar:<0.4.0", reason = "busbar resolves tar to 0.4.46; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tar:>=0.5.0", reason = "busbar resolves tar to 0.4.46; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tikv-jemalloc-ctl:<0.6.0", reason = "busbar resolves tikv-jemalloc-ctl to 0.6.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tikv-jemalloc-ctl:>=0.7.0", reason = "busbar resolves tikv-jemalloc-ctl to 0.6.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tikv-jemallocator:<0.6.0", reason = "busbar resolves tikv-jemallocator to 0.6.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tikv-jemallocator:>=0.7.0", reason = "busbar resolves tikv-jemallocator to 0.6.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tokio:<1.0.0", reason = "busbar resolves tokio to 1.53.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tokio:>=2.0.0", reason = "busbar resolves tokio to 1.53.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tokio-rustls:<0.26.0", reason = "busbar resolves tokio-rustls to 0.26.5; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tokio-rustls:>=0.27.0", reason = "busbar resolves tokio-rustls to 0.26.5; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tokio-tungstenite:<0.29.0", reason = "busbar resolves tokio-tungstenite to 0.29.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tokio-tungstenite:>=0.30.0", reason = "busbar resolves tokio-tungstenite to 0.29.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tokio-util:<0.7.0", reason = "busbar resolves tokio-util to 0.7.18; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tokio-util:>=0.8.0", reason = "busbar resolves tokio-util to 0.7.18; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tonic:<0.14.0", reason = "busbar resolves tonic to 0.14.6; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tonic:>=0.15.0", reason = "busbar resolves tonic to 0.14.6; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tonic-types:<0.14.0", reason = "busbar resolves tonic-types to 0.14.6; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tonic-types:>=0.15.0", reason = "busbar resolves tonic-types to 0.14.6; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tower:<0.5.0", reason = "busbar resolves tower to 0.5.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tower:>=0.6.0", reason = "busbar resolves tower to 0.5.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tracing:<0.1.0", reason = "busbar resolves tracing to 0.1.44; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tracing:>=0.2.0", reason = "busbar resolves tracing to 0.1.44; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tracing-core:<0.1.0", reason = "busbar resolves tracing-core to 0.1.36; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tracing-core:>=0.2.0", reason = "busbar resolves tracing-core to 0.1.36; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tracing-log:<0.2.0", reason = "busbar resolves tracing-log to 0.2.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tracing-log:>=0.3.0", reason = "busbar resolves tracing-log to 0.2.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tracing-subscriber:<0.3.0", reason = "busbar resolves tracing-subscriber to 0.3.23; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tracing-subscriber:>=0.4.0", reason = "busbar resolves tracing-subscriber to 0.3.23; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tungstenite:<0.29.0", reason = "busbar resolves tungstenite to 0.29.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tungstenite:>=0.30.0", reason = "busbar resolves tungstenite to 0.29.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "url:<2.0.0", reason = "busbar resolves url to 2.5.8; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "url:>=3.0.0", reason = "busbar resolves url to 2.5.8; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "rustls-webpki:<0.103.0", reason = "busbar resolves rustls-webpki to 0.103.15; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "rustls-webpki:>=0.104.0", reason = "busbar resolves rustls-webpki to 0.103.15; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "webpki-roots:<1.0.0", reason = "busbar resolves webpki-roots to 1.0.7; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "webpki-roots:>=2.0.0", reason = "busbar resolves webpki-roots to 1.0.7; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "zeroize:<1.0.0", reason = "busbar resolves zeroize to 1.9.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "zeroize:>=2.0.0", reason = "busbar resolves zeroize to 1.9.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, +] +# The duplicates busbar itself accepts: deps.toml [bans].skip, then every duplicate busbar's own +# Cargo.lock holds at the pin. Nothing else may appear twice (multiple-versions = "deny"). +skip = [ + { crate = "base64@0.22.1", reason = "busbar's own lock holds this duplicate" }, + { crate = "base64@0.23.1", reason = "busbar's own lock holds this duplicate" }, + { crate = "bit-vec@0.8.0", reason = "busbar's own lock holds this duplicate" }, + { crate = "bit-vec@0.9.1", reason = "busbar's own lock holds this duplicate" }, + { crate = "cpufeatures@0.2.17", reason = "busbar's own lock holds this duplicate" }, + { crate = "cpufeatures@0.3.0", reason = "busbar's own lock holds this duplicate" }, + { crate = "foldhash@0.1.5", reason = "busbar's own lock holds this duplicate" }, + { crate = "foldhash@0.2.0", reason = "busbar's own lock holds this duplicate" }, + { crate = "getrandom@0.2.17", reason = "busbar's own lock holds this duplicate" }, + { crate = "getrandom@0.3.4", reason = "busbar's own lock holds this duplicate" }, + { crate = "getrandom@0.4.3", reason = "busbar's own lock holds this duplicate" }, + { crate = "hashbrown@0.15.5", reason = "busbar's own lock holds this duplicate" }, + { crate = "hashbrown@0.16.1", reason = "busbar's own lock holds this duplicate" }, + { crate = "hashbrown@0.17.1", reason = "busbar's own lock holds this duplicate" }, + { crate = "itertools@0.13.0", reason = "busbar's own lock holds this duplicate" }, + { crate = "itertools@0.14.0", reason = "busbar's own lock holds this duplicate" }, + { crate = "nom@7.1.3", reason = "busbar's own lock holds this duplicate" }, + { crate = "nom@8.0.0", reason = "busbar's own lock holds this duplicate" }, + { crate = "r-efi@5.3.0", reason = "busbar's own lock holds this duplicate" }, + { crate = "r-efi@6.0.0", reason = "busbar's own lock holds this duplicate" }, + { crate = "rand@0.10.2", reason = "busbar's own lock holds this duplicate" }, + { crate = "rand@0.9.4", reason = "busbar's own lock holds this duplicate" }, + { crate = "rand_core@0.10.1", reason = "busbar's own lock holds this duplicate" }, + { crate = "rand_core@0.6.4", reason = "busbar's own lock holds this duplicate" }, + { crate = "rand_core@0.9.5", reason = "busbar's own lock holds this duplicate" }, + { crate = "syn@2.0.117", reason = "busbar's own lock holds this duplicate" }, + { crate = "syn@3.0.3", reason = "busbar's own lock holds this duplicate" }, + { crate = "windows-sys@0.52.0", reason = "busbar's own lock holds this duplicate" }, + { crate = "windows-sys@0.61.2", reason = "busbar's own lock holds this duplicate" }, +] [sources] unknown-registry = "deny" diff --git a/rust-toolchain.toml b/rust-toolchain.toml index 1efc2d3..42c3341 100644 --- a/rust-toolchain.toml +++ b/rust-toolchain.toml @@ -1,6 +1,6 @@ -# RENDERED by `cargo xtask fleet render` from GetBusbar/busbar's plugins.yaml and .github/fleet/ -# templates. The toolchain is busbar's own pin (its rust-toolchain.toml), so a plugin and the core -# that links it compile with one compiler. +# RENDERED by `busbar-release plugin sync` from GetBusbar/busbar-release template/. The toolchain is +# busbar's own pin (its rust-toolchain.toml at the pin), so a plugin and the core that links it compile +# with one compiler. [toolchain] channel = "1.98.0" components = ["clippy", "rustfmt"] diff --git a/store-sqlite-plugin/Cargo.toml b/store-sqlite-plugin/Cargo.toml index b06a9b3..142939a 100644 --- a/store-sqlite-plugin/Cargo.toml +++ b/store-sqlite-plugin/Cargo.toml @@ -16,21 +16,21 @@ crate-type = ["cdylib", "rlib"] [dependencies] # THE LOGIC, same repo: its `door::door` is the door this image exports. busbar-store-sqlite = { path = "../store-sqlite" } -busbar-contract = { git = "https://github.com/GetBusbar/busbar", rev = "bf32f11ba9634c77afbe1dc89a8c3986499b38af" } +busbar-contract = { workspace = true } [dev-dependencies] # The conformance and e2e tests load the built cdylib and the linked door over the REAL loader (the # one dispatcher, the store v3 table) — dev-only, never in the shipped artifact. Same pinned rev as # the logic crate's busbar-contract, so one busbar source resolves. -busbar-plugin-loader = { git = "https://github.com/GetBusbar/busbar", rev = "bf32f11ba9634c77afbe1dc89a8c3986499b38af" } -serde_json = "1" +busbar-plugin-loader = { workspace = true } +serde_json = { workspace = true } # Dev-only: the conformance test awaits the store v3 calls (`StoreCalls`), which are futures. -tokio = { version = "1", features = ["rt"] } +tokio = { workspace = true, features = ["rt"] } # Dev-only: the `busy_timeout_ms_is_actually_applied`-style checks open a second, independent # connection to the SAME sqlite file. Same version/feature as `busbar-store-sqlite`'s dependency so # only one sqlite is ever linked in. -rusqlite = { version = "0.40.0", features = ["bundled"] } +rusqlite = { workspace = true } # Dev-only: the admin-API install e2e test drives a REAL running busbar process's admin HTTP API # (POST /api/v1/admin/plugins, POST /api/v1/admin/keys) — the actual operator install path. -reqwest = { version = "0.12", default-features = false, features = ["rustls-tls", "json", "blocking"] } -base64 = "0.22" +reqwest = { workspace = true, features = ["json", "blocking"] } +base64 = { workspace = true } diff --git a/store-sqlite/Cargo.toml b/store-sqlite/Cargo.toml index 9368a3e..304d940 100644 --- a/store-sqlite/Cargo.toml +++ b/store-sqlite/Cargo.toml @@ -20,13 +20,13 @@ crate-type = ["rlib"] # as `busbar_contract::abi::sdk`). Pinned by git rev to the busbar commit in `.busbar-ref`; a busbar # build that links this crate `[patch]`es the busbar git source to its own tree, so ONE copy of the # contract links. -busbar-contract = { git = "https://github.com/GetBusbar/busbar", rev = "bf32f11ba9634c77afbe1dc89a8c3986499b38af" } +busbar-contract = { workspace = true } # `bundled` compiles SQLite from source so the plugin has no system libsqlite3 dependency at all. -rusqlite = { version = "0.40.0", features = ["bundled"] } -serde_json = "1" +rusqlite = { workspace = true } +serde_json = { workspace = true } # `derive` for the v10 migration's legacy row encoders, the v3 dedupe log's stored answers (and the # conformance suite's stand-in bodies). -serde = { version = "1", features = ["derive"] } +serde = { workspace = true } # The `RecordStore` contract conformance suite lives in this crate's own # `src/tests/store_conformance.rs` (#2/#31 forbid a shared test util between plugins). The one @@ -34,4 +34,4 @@ serde = { version = "1", features = ["derive"] } # whose `store_v3` cases are the store kind's epoch and slice-life spec every durable store runs # (`abi::store::SLICE_TTL_MS`). Same pinned rev, so one contract links. [dev-dependencies] -busbar-contract = { git = "https://github.com/GetBusbar/busbar", rev = "bf32f11ba9634c77afbe1dc89a8c3986499b38af", features = ["test-seal"] } +busbar-contract = { workspace = true, features = ["test-seal"] } From fb22fe57268de27627d4bd15997f705ac53f4711 Mon Sep 17 00:00:00 2001 From: Matthew Jackson <1085847+MattJackson@users.noreply.github.com> Date: Mon, 5 Oct 2026 03:59:41 -0700 Subject: [PATCH 2/2] Cargo.lock: libsqlite3-sys stays =0.38.1 (the fleet's C-dependency allow-list, bundled + pinned) and rusqlite at 0.40.1; the re-resolve had taken 0.38.2 / 0.40.2 --- Cargo.lock | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/Cargo.lock b/Cargo.lock index 0b4585e..97939cd 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -717,9 +717,9 @@ dependencies = [ [[package]] name = "libsqlite3-sys" -version = "0.38.2" +version = "0.38.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "f1d20bef17f513b9b3004532233187769cd072d790971f4e4da0e346eb6401e8" +checksum = "f6c19a05435c21ac299d71b6a9c13db3e3f47c520517d58990a462a1397a61db" dependencies = [ "cc", "pkg-config", @@ -988,9 +988,9 @@ dependencies = [ [[package]] name = "rusqlite" -version = "0.40.2" +version = "0.40.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "23f2a97da3e3873c73cb2a2e71b35c40ff95e0b1eefa8d72d8499a6928c3b5b3" +checksum = "11438310b19e3109b6446c33d1ed5e889428cf2e278407bc7896bc4aaea43323" dependencies = [ "bitflags", "fallible-iterator",