Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
# RENDERED by `busbar-release plugin sync` from GetBusbar/busbar-release template/.
* @MattJackson
10 changes: 7 additions & 3 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,8 @@
# RENDERED by `cargo xtask fleet render busbar-store-sqlite` from GetBusbar/busbar's plugins.yaml and
# .github/fleet/ templates; `cargo xtask fleet check` is red on any edit here. The CI itself is
# busbar's plugin-ci.yml, taken at the busbar commit this repo pins (.busbar-ref).
# RENDERED by `busbar-release plugin sync busbar-store-sqlite` from GetBusbar/busbar-release template/; a hand
# edit is overwritten by the next sync. THIS REPO TESTS ITSELF AGAINST BUSBAR with the fleet's ONE
# harness: busbar's reusable plugin-ci.yml, taken at the busbar commit this repo pins (.busbar-ref), so
# the CI logic, the gates (busbar scripts/fleet/plugin-gates.py), the dependency policy
# (.github/fleet/deps.toml) and the contract move together (OWNER 2026-10-02). No CI logic lives here.
name: ci

on:
Expand All @@ -9,6 +11,8 @@ on:
pull_request:
branches: [dev, qa, main]
workflow_dispatch: {}
# release.yml runs this file on the tagged commit before it publishes.
workflow_call: {}

permissions:
contents: read
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/consumer-verify.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# RENDERED by `cargo xtask fleet render busbar-store-sqlite` from GetBusbar/busbar's plugins.yaml and
# .github/fleet/ templates; `cargo xtask fleet check` is red on any edit here. Daily: does the newest
# RENDERED by `busbar-release plugin sync busbar-store-sqlite` from GetBusbar/busbar-release template/; a hand
# edit is overwritten by the next sync. Daily: does the newest
# PUBLISHED release still work for a user (busbar's plugin-consumer-verify.yml)? A publish-time check
# cannot see an artifact that rots afterwards; release.yml verifies each release as it publishes.
name: consumer-verify
Expand Down
58 changes: 58 additions & 0 deletions .github/workflows/dependabot-bundle.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,58 @@
# RENDERED by `busbar-release plugin sync busbar-store-sqlite` from GetBusbar/busbar-release template/; a hand
# edit is overwritten by the next sync (DEPENDABOT-ONE).
# dependabot-bundle: every open dependabot PR (whatever its base today) is merged into ONE branch (deps/bundle),
# which carries ONE PR with auto-merge on. Merged PRs are closed with a link; a PR that conflicts
# is listed in the bundle PR body and left open. The branch is only ever fast-forwarded (no force).
# Secrets: BUNDLE_TOKEN (or FLEET_TOKEN) lets the bundle PR run CI and lets a github-actions bump
# (a workflow-file change) be pushed; without one GITHUB_TOKEN is used and those cases fail loudly.
# pull_request_target runs the BASE branch's copy of this file and never executes PR code: it only
# fetches and merges the PR heads.
name: dependabot-bundle
on:
pull_request_target:
types: [opened, synchronize]
branches: [dev]
schedule:
- cron: "23 5 * * *"
workflow_dispatch:
permissions:
contents: write
pull-requests: write
concurrency:
group: dependabot-bundle
env:
TARGET: dev
BUNDLE: deps/bundle
GH_TOKEN: ${{ secrets.BUNDLE_TOKEN || secrets.FLEET_TOKEN || github.token }}
jobs:
bundle:
if: github.event_name != 'pull_request_target' || github.actor == 'dependabot[bot]'
runs-on: ubuntu-latest
steps:
- run: |
set -euo pipefail
gh auth setup-git
git clone -q "https://github.com/$GITHUB_REPOSITORY" w && cd w
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
if git ls-remote --exit-code --heads origin "$BUNDLE" >/dev/null; then
git checkout -q -B "$BUNDLE" "origin/$BUNDLE"
git merge -q -m "deps: merge $TARGET" "origin/$TARGET"
else
git checkout -q -B "$BUNDLE" "origin/$TARGET"
fi
merged=(); bad=()
while IFS=$'\t' read -r n t; do
[ -n "$n" ] || continue
git fetch -q origin "pull/$n/head"
if git merge -q -m "deps: merge #$n $t" FETCH_HEAD; then merged+=("$n"); else git merge --abort; bad+=("$n"); fi
done < <(gh pr list --state open --author 'app/dependabot' --json number,title --jq '.[]|"\(.number)\t\(.title)"')
[ "$(git rev-list --count "origin/$TARGET..HEAD")" -gt 0 ] || { echo "nothing to bundle"; exit 0; }
git push -q origin "$BUNDLE"
body="Bundled dependabot updates, merged from: $(printf '#%s ' "${merged[@]}")"
[ ${#bad[@]} -eq 0 ] || body="$body"$'\n\n'"CONFLICT, left open (resolve or close by hand): $(printf '#%s ' "${bad[@]}")"
pr=$(gh pr list --head "$BUNDLE" --base "$TARGET" --state open --json number --jq '.[0].number // empty')
if [ -n "$pr" ]; then gh pr edit "$pr" --body "$body"
else pr=$(gh pr create --head "$BUNDLE" --base "$TARGET" --title "deps: bundled dependabot updates" --body "$body" | sed 's|.*/||'); fi
gh pr merge "$pr" --auto --merge || echo "::warning::auto-merge not enabled on #$pr"
for n in "${merged[@]}"; do gh pr close "$n" --comment "Merged into the bundle branch; continues in #$pr."; done
15 changes: 5 additions & 10 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# RENDERED by `cargo xtask fleet render busbar-store-sqlite` from GetBusbar/busbar's plugins.yaml and
# .github/fleet/ templates; `cargo xtask fleet check` is red on any edit here. On a v* tag: this
# repo's CI on the tagged commit, then busbar's plugin-release.yml (build, sign, pack, publish), then
# the consumer verification of what was published, each at the busbar commit this repo pins.
# RENDERED by `busbar-release plugin sync busbar-store-sqlite` from GetBusbar/busbar-release template/; a hand
# edit is overwritten by the next sync. On a v* tag: this repo's own ci.yml (the fleet harness) on the
# tagged commit, then busbar's plugin-release.yml (build, sign, pack, publish), then the consumer
# verification of what was published, each at the busbar commit this repo pins.
name: release

on:
Expand All @@ -21,12 +21,7 @@ permissions:

jobs:
ci:
uses: GetBusbar/busbar/.github/workflows/plugin-ci.yml@bf32f11ba9634c77afbe1dc89a8c3986499b38af
with:
service: none
busbar_checkout: true
macos_test: "cargo test --workspace --locked"
extra_test: ""
uses: ./.github/workflows/ci.yml
secrets: inherit
release:
needs: ci
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/repin.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# RENDERED by `cargo xtask fleet render busbar-store-sqlite` from GetBusbar/busbar's plugins.yaml and
# .github/fleet/ templates; `cargo xtask fleet check` is red on any edit here. Moves this repo's
# RENDERED by `busbar-release plugin sync busbar-store-sqlite` from GetBusbar/busbar-release template/; a hand
# edit is overwritten by the next sync. Moves this repo's
# busbar pin (busbar's plugin-repin.yml) when busbar dispatches `busbar-repin` or on demand; the
# cut/skip decision is by commit, and the commit goes to dev only.
name: repin
Expand Down
4 changes: 2 additions & 2 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# RENDERED by `cargo xtask fleet render` from GetBusbar/busbar's plugins.yaml (the entry's
# `gitignore:` lines follow the fleet's own) and .github/fleet/gitignore.
# RENDERED by `busbar-release plugin sync` from GetBusbar/busbar-release template/ (the plugins.yaml
# entry's `gitignore:` lines follow the fleet's own).
/target
/mutants.out*
busbar-governance.db*
2 changes: 1 addition & 1 deletion .mailmap
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# RENDERED by `cargo xtask fleet render` from GetBusbar/busbar's plugins.yaml and .github/fleet/.
# RENDERED by `busbar-release plugin sync` from GetBusbar/busbar-release template/.
# Canonical authorship. Commits go out under Matthew Jackson's GitHub noreply only.
Matthew Jackson <1085847+MattJackson@users.noreply.github.com> <dev3@getbusbar.com>
Matthew Jackson <1085847+MattJackson@users.noreply.github.com> Matthew <dev3@getbusbar.com>
Expand Down
19 changes: 16 additions & 3 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,9 +13,22 @@ Thanks for your interest in improving `busbar-store-sqlite`.
## Layout

Every busbar plugin repo has the same skeleton. This one is a two-crate Cargo workspace: `store-sqlite/` holds the plugin's logic and `store-sqlite-plugin/` is the thin `cdylib` that packages it as a droppable `kind: store` plugin. busbar itself is a git dependency
pinned to the commit in `.busbar-ref`. The CI, release and lint configuration are
rendered from [busbar's plugin registry](https://github.com/GetBusbar/busbar/blob/main/plugins.yaml);
change them there, not here.
pinned to the commit in `.busbar-ref`. The CI, release, dependency and lint configuration
are rendered by `busbar-release plugin sync` from the fleet template (GetBusbar/busbar-release
`template/`), [busbar's plugin registry](https://github.com/GetBusbar/busbar/blob/main/plugins.yaml)
and busbar's dependency policy (`.github/fleet/deps.toml` and the root `[workspace.dependencies]`
at the pin); change them there, not here.

## This repo tests itself against busbar

CI runs the fleet's one harness, busbar's reusable `plugin-ci.yml`, at the busbar commit in
`.busbar-ref`: fmt, clippy -D warnings, the whole test suite, `cargo deny`, the dependency wall
(busbar-contract plus third-party only), the socket/TLS ban (no plugin opens its own socket, dials,
binds or does TLS), the C-dependency allow-list, `Cargo.lock` parity with busbar's lock at the pin,
the both-ways conformance and the busbar conformance kit for this kind. The tests are this repo's:
`store-sqlite-plugin/tests/conformance.rs` loads the LINKED door and the BUILT cdylib through busbar's
plugin loader and requires one transcript (a test named `the_linked_and_the_dropped_in_*`), and keeps
at least one RED arm (any other test in that target) that proves the comparison can fail.

## Before you open a pull request

Expand Down
28 changes: 28 additions & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

106 changes: 99 additions & 7 deletions Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,13 +1,19 @@
# SPDX-License-Identifier: Apache-2.0
#
# RENDERED by `cargo xtask fleet render busbar-store-sqlite` from GetBusbar/busbar's plugins.yaml and
# .github/fleet/workspace-Cargo.toml; `cargo xtask fleet check` is red on any edit here.
# RENDERED by `busbar-release plugin sync busbar-store-sqlite` from GetBusbar/busbar-release template/ and
# GetBusbar/busbar's dependency policy; a hand edit is overwritten by the next sync.
#
# One repo per plugin, every repo a twin: this workspace is exactly two crates, the logic
# (`store-sqlite/`, the rlib a busbar build can link) and the thin cdylib that packages it as a
# droppable `kind: store` plugin (`store-sqlite-plugin/`, crate `busbar-store-sqlite-plugin`). Its busbar
# dependencies are git dependencies on GetBusbar/busbar at the fleet pin (`.busbar-ref` field 1);
# no sibling-checkout path dependency ships in any manifest.
# One repo per plugin, every repo a twin: this workspace is exactly two crates, the logic (the rlib a
# busbar build links) and the thin cdylib that packages it as a droppable `kind: store` plugin
# (crate `busbar-store-sqlite-plugin`). Its one busbar dependency is busbar-contract (busbar-plugin-loader is dev-only,
# for the both-ways conformance test), both git dependencies on GetBusbar/busbar at the pin in
# `.busbar-ref`; no sibling-checkout path dependency ships in any manifest.
#
# THIRD-PARTY VERSIONS ARE THE FLEET'S, NOT THIS REPO'S. The table below is busbar's own root
# `[workspace.dependencies]` (third-party rows) at busbar bf32f11ba9634c77afbe1dc89a8c3986499b38af, followed by the plugin-only rows
# of busbar's `.github/fleet/deps.toml` at bf32f11ba9634c77afbe1dc89a8c3986499b38af. A member takes a crate with
# `{ workspace = true }` (adding features if it needs them); a crate in neither table is a new
# `deps.toml` row in busbar first. CI holds this repo's Cargo.lock to busbar's lock at the pin.
[workspace]
resolver = "2"
members = [
Expand All @@ -25,3 +31,89 @@ repository = "https://github.com/GetBusbar/busbar-store-sqlite"
[workspace.dependencies]
busbar-contract = { git = "https://github.com/GetBusbar/busbar", rev = "bf32f11ba9634c77afbe1dc89a8c3986499b38af" }
busbar-plugin-loader = { git = "https://github.com/GetBusbar/busbar", rev = "bf32f11ba9634c77afbe1dc89a8c3986499b38af" }
# busbar's root [workspace.dependencies], third-party rows, at bf32f11ba9634c77afbe1dc89a8c3986499b38af
a2a-lf = "0.3.0"
a2a-pb = "0.2.0"
arc-swap = "1"
async-trait = "0.1"
axum = "0.8"
base64 = "0.22"
bumpalo = "3"
bytes = "1"
core_affinity = "0.8"
crc32fast = "1"
criterion = { version = "0.7", default-features = false, features = ["cargo_bench_support"] }
dimpl = { version = "=0.7.4", default-features = false }
ed25519-dalek = { version = "2", default-features = false, features = ["std"] }
flate2 = { version = "1", default-features = false, features = ["rust_backend"] }
futures = "0.3"
getrandom = "0.3"
h2 = "0.4"
hex = "0.4.3"
hmac = "0.13.0"
http = "1"
http-body = "1"
http-body-util = "0.1"
httpdate = "1.0"
hyper = { version = "1", default-features = false, features = ["server", "client", "http1", "http2"] }
hyper-rustls = { version = "0.27", default-features = false, features = ["http1", "http2", "ring", "webpki-tokio"] }
hyper-util = { version = "0.1", default-features = false, features = ["client-legacy", "http1", "http2", "server-auto", "server-graceful", "service", "tokio"] }
idna_adapter = "=1.1.0"
indexmap = { version = "2", features = ["serde"] }
jsonschema = { version = "0.49", default-features = false }
libc = "0.2"
libloading = "0.9"
log = "0.4"
loom = "0.7"
memchr = "2"
metrics = "0.24.6"
metrics-exporter-prometheus = { version = "0.18.3", default-features = false }
metrics-util = { version = "0.20.4", default-features = false }
oauth-as = { version = "1.0.0", features = ["http", "jwt", "consent", "resource-metadata", "par", "dpop", "client-assertion"] }
opentelemetry-proto = { version = "0.32", default-features = false, features = ["gen-tonic-messages", "trace"] }
proc-macro2 = { version = "1", features = ["span-locations"] }
proptest = "1"
prost = { version = "0.14", default-features = false, features = ["std"] }
rcgen = { version = "0.14", default-features = false, features = ["crypto", "ring"] }
reqwest = { version = "0.12", default-features = false, features = ["rustls-tls", "stream"] }
ring = "0.17"
rmcp = { version = "3.1.2", default-features = false }
rustls = { version = "0.23", default-features = false, features = ["ring", "std", "tls12"] }
rustls-pki-types = { version = "1", default-features = false, features = ["std"] }
schemars = "1"
serde = { version = "1", features = ["derive"] }
serde_json = "1"
serde_urlencoded = "0.7"
serde_yaml = { package = "serde_yaml_ng", version = "0.10" }
sha2 = "0.10"
smallvec = "1"
socket2 = { version = "0.6", features = ["all"] }
sonic-rs = "0.5"
syn = { version = "2", features = ["full", "visit", "parsing", "printing"] }
tar = { version = "0.4", default-features = false }
tikv-jemalloc-ctl = "0.6"
tikv-jemallocator = "0.6"
tokio = "1"
tokio-rustls = { version = "0.26", default-features = false, features = ["ring"] }
tokio-tungstenite = { version = "0.29", default-features = false, features = ["handshake"] }
tokio-util = { version = "0.7", default-features = false, features = ["compat"] }
tonic = { version = "0.14", default-features = false }
tonic-types = "0.14"
tower = "0.5"
tracing = "0.1.44"
tracing-core = "0.1"
tracing-log = { version = "0.2", default-features = false, features = ["log-tracer", "std"] }
tracing-subscriber = "0.3.23"
tungstenite = { version = "0.29", default-features = false }
url = "2"
webpki = { package = "rustls-webpki", version = "0.103", default-features = false, features = ["std", "ring"] }
webpki-roots = "1"
zeroize = "1"
# busbar .github/fleet/deps.toml [plugin-deps], at bf32f11ba9634c77afbe1dc89a8c3986499b38af
ldap3 = { version = "0.12", default-features = false, features = ["sync"] }
mysql = { version = "26", default-features = false, features = ["minimal"] }
postgres = "0.19"
redis = { version = "1", default-features = false, features = ["script"] }
rusqlite = { version = "0.40", features = ["bundled"] }
ulid = "1"

2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
<!-- fleet:header:begin (rendered by `cargo xtask fleet render` from GetBusbar/busbar's plugins.yaml; edit it there) -->
<!-- fleet:header:begin (rendered by `busbar-release plugin sync` from GetBusbar/busbar-release template/ and busbar's plugins.yaml; edit it there) -->
# busbar-store-sqlite

First-party signed kind:store plugin cdylib: the SQLite governance store packaged as a droppable busbar plugin exporting the store C ABI. Drop the built library into the plugins folder and set store.module: sqlite.
Expand Down
6 changes: 3 additions & 3 deletions clippy.toml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# RENDERED by `cargo xtask fleet render` from GetBusbar/busbar's plugins.yaml and .github/fleet/
# templates. CI runs clippy with -D warnings (busbar's plugin-ci.yml) on the 1.98.0 toolchain;
# the MSRV clippy judges against is each crate's own `rust-version`, so none is restated here.
# RENDERED by `busbar-release plugin sync` from GetBusbar/busbar-release template/; a hand edit is
# overwritten by the next sync. CI (busbar's plugin-ci.yml at the pin) runs clippy with -D warnings on
# the 1.98.0 toolchain; the MSRV clippy judges against is each crate's own `rust-version`.
too-many-arguments-threshold = 7
9 changes: 4 additions & 5 deletions codecov.yml
Original file line number Diff line number Diff line change
@@ -1,8 +1,7 @@
# RENDERED by `cargo xtask fleet render` from GetBusbar/busbar's plugins.yaml and .github/fleet/.
# Codecov is INFORMATIONAL, never a gate: the correctness gate is the `ci` job (busbar's
# plugin-ci.yml). Coverage is an observation on the README badge and the Codecov UI, so every status
# is informational, there are no PR comments, and test-only paths plus the busbar checkout the
# end-to-end tests build are excluded from the percentage.
# RENDERED by `busbar-release plugin sync` from GetBusbar/busbar-release template/.
# Codecov is INFORMATIONAL, never a gate: the correctness gate is the `ci` workflow (busbar's
# plugin-ci.yml at the pin). Every status is informational, there are no PR comments, and test-only paths
# plus the busbar checkout the end-to-end tests build are excluded from the percentage.
coverage:
status:
project:
Expand Down
Loading
Loading