From 64ebc7b442b08ece46b8ffe6252415175879caae Mon Sep 17 00:00:00 2001 From: Matthew Jackson <1085847+MattJackson@users.noreply.github.com> Date: Thu, 1 Oct 2026 23:05:02 -0700 Subject: [PATCH 1/2] fleet: render the busbar-release plugin template (ed4db8079a1d) busbar-release plugin sync busbar-store-sqlite: template/ at ed4db8079a1d61a194d9505f6daeb31fcfc1ab97, busbar pin e1d3d8b097201859751d77208e66249d98b50a4b (unchanged), dependency policy at busbar dd9637da0c849b811238e108cbafabcb4c7c22a2, plugins.yaml at busbar dd9637da0c849b811238e108cbafabcb4c7c22a2. --- .github/CODEOWNERS | 2 + .github/dependabot.yml | 100 +++++++++- .github/workflows/ci.yml | 10 +- .github/workflows/consumer-verify.yml | 4 +- .github/workflows/dependabot-bundle.yml | 58 ++++++ .github/workflows/release.yml | 15 +- .github/workflows/repin.yml | 4 +- .gitignore | 4 +- .mailmap | 2 +- CONTRIBUTING.md | 21 ++- Cargo.lock | 237 +++++++++++++----------- Cargo.toml | 109 ++++++++++- LICENSE | 223 +++------------------- README.md | 4 +- clippy.toml | 6 +- codecov.yml | 9 +- deny.toml | 228 ++++++++++++++++++++++- rust-toolchain.toml | 6 +- store-sqlite-plugin/Cargo.toml | 12 +- store-sqlite/Cargo.toml | 8 +- store-sqlite/declares.json | 4 +- 21 files changed, 692 insertions(+), 374 deletions(-) create mode 100644 .github/CODEOWNERS create mode 100644 .github/workflows/dependabot-bundle.yml diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS new file mode 100644 index 0000000..45f159d --- /dev/null +++ b/.github/CODEOWNERS @@ -0,0 +1,2 @@ +# RENDERED by `busbar-release plugin sync` from GetBusbar/busbar-release template/. +* @MattJackson diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 0d128b3..00c127c 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,4 +1,10 @@ -# Dependency updates target dev; they reach main only through a release. +# RENDERED by `busbar-release plugin sync` from GetBusbar/busbar-release template/. +# Dependency updates target dev. GitHub Actions are pinned by the fleet template (busbar-release), +# so only cargo is watched here. Every update of an ecosystem is ONE grouped PR, and +# .github/workflows/dependabot-bundle.yml folds all of them into one branch and one PR (DEPENDABOT-ONE). +# The crates busbar's dependency policy owns (busbar's root [workspace.dependencies] and +# .github/fleet/deps.toml) are ignored here: they move centrally, in busbar, and reach this repo +# through `busbar-release plugin sync` with the pin, so Cargo.lock stays at parity with busbar's. version: 2 updates: - package-ecosystem: cargo @@ -6,8 +12,90 @@ updates: target-branch: dev schedule: interval: weekly - - package-ecosystem: github-actions - directory: "/" - target-branch: dev - schedule: - interval: weekly + groups: + all: + patterns: + - "*" + ignore: + - dependency-name: "a2a-lf" + - dependency-name: "a2a-pb" + - dependency-name: "arc-swap" + - dependency-name: "async-trait" + - dependency-name: "axum" + - dependency-name: "base64" + - dependency-name: "bumpalo" + - dependency-name: "bytes" + - dependency-name: "core_affinity" + - dependency-name: "crc32fast" + - dependency-name: "criterion" + - dependency-name: "dimpl" + - dependency-name: "ed25519-dalek" + - dependency-name: "flate2" + - dependency-name: "futures" + - dependency-name: "getrandom" + - dependency-name: "h2" + - dependency-name: "hex" + - dependency-name: "hmac" + - dependency-name: "http" + - dependency-name: "http-body" + - dependency-name: "http-body-util" + - dependency-name: "httpdate" + - dependency-name: "hyper" + - dependency-name: "hyper-rustls" + - dependency-name: "hyper-util" + - dependency-name: "indexmap" + - dependency-name: "jsonschema" + - dependency-name: "ldap3" + - dependency-name: "libc" + - dependency-name: "libloading" + - dependency-name: "log" + - dependency-name: "loom" + - dependency-name: "memchr" + - dependency-name: "metrics" + - dependency-name: "metrics-exporter-prometheus" + - dependency-name: "metrics-util" + - dependency-name: "mysql" + - dependency-name: "oauth-as" + - dependency-name: "opentelemetry-proto" + - dependency-name: "postgres" + - dependency-name: "proc-macro2" + - dependency-name: "proptest" + - dependency-name: "prost" + - dependency-name: "rcgen" + - dependency-name: "redis" + - dependency-name: "reqwest" + - dependency-name: "ring" + - dependency-name: "rmcp" + - dependency-name: "rusqlite" + - dependency-name: "rustls" + - dependency-name: "rustls-pki-types" + - dependency-name: "schemars" + - dependency-name: "serde" + - dependency-name: "serde_json" + - dependency-name: "serde_urlencoded" + - dependency-name: "serde_yaml" + - dependency-name: "sha2" + - dependency-name: "smallvec" + - dependency-name: "socket2" + - dependency-name: "sonic-rs" + - dependency-name: "syn" + - dependency-name: "tar" + - dependency-name: "tikv-jemalloc-ctl" + - dependency-name: "tikv-jemallocator" + - dependency-name: "tokio" + - dependency-name: "tokio-rustls" + - dependency-name: "tokio-tungstenite" + - dependency-name: "tokio-util" + - dependency-name: "tonic" + - dependency-name: "tonic-types" + - dependency-name: "tower" + - dependency-name: "tracing" + - dependency-name: "tracing-core" + - dependency-name: "tracing-log" + - dependency-name: "tracing-subscriber" + - dependency-name: "tungstenite" + - dependency-name: "ulid" + - dependency-name: "url" + - dependency-name: "webpki" + - dependency-name: "webpki-roots" + - dependency-name: "zeroize" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 023dd3c..546098c 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,6 +1,8 @@ -# RENDERED by `cargo xtask fleet render busbar-store-sqlite` from GetBusbar/busbar's plugins.yaml and -# .github/fleet/ templates; `cargo xtask fleet check` is red on any edit here. The CI itself is -# busbar's plugin-ci.yml, taken at the busbar commit this repo pins (.busbar-ref). +# RENDERED by `busbar-release plugin sync busbar-store-sqlite` from GetBusbar/busbar-release template/; a hand +# edit is overwritten by the next sync. THIS REPO TESTS ITSELF AGAINST BUSBAR with the fleet's ONE +# harness: busbar's reusable plugin-ci.yml, taken at the busbar commit this repo pins (.busbar-ref), so +# the CI logic, the gates (busbar scripts/fleet/plugin-gates.py), the dependency policy +# (.github/fleet/deps.toml) and the contract move together (OWNER 2026-10-02). No CI logic lives here. name: ci on: @@ -9,6 +11,8 @@ on: pull_request: branches: [dev, qa, main] workflow_dispatch: {} + # release.yml runs this file on the tagged commit before it publishes. + workflow_call: {} permissions: contents: read diff --git a/.github/workflows/consumer-verify.yml b/.github/workflows/consumer-verify.yml index 53cf732..e74d735 100644 --- a/.github/workflows/consumer-verify.yml +++ b/.github/workflows/consumer-verify.yml @@ -1,5 +1,5 @@ -# RENDERED by `cargo xtask fleet render busbar-store-sqlite` from GetBusbar/busbar's plugins.yaml and -# .github/fleet/ templates; `cargo xtask fleet check` is red on any edit here. Daily: does the newest +# RENDERED by `busbar-release plugin sync busbar-store-sqlite` from GetBusbar/busbar-release template/; a hand +# edit is overwritten by the next sync. Daily: does the newest # PUBLISHED release still work for a user (busbar's plugin-consumer-verify.yml)? A publish-time check # cannot see an artifact that rots afterwards; release.yml verifies each release as it publishes. name: consumer-verify diff --git a/.github/workflows/dependabot-bundle.yml b/.github/workflows/dependabot-bundle.yml new file mode 100644 index 0000000..d2cbe61 --- /dev/null +++ b/.github/workflows/dependabot-bundle.yml @@ -0,0 +1,58 @@ +# RENDERED by `busbar-release plugin sync busbar-store-sqlite` from GetBusbar/busbar-release template/; a hand +# edit is overwritten by the next sync (DEPENDABOT-ONE). +# dependabot-bundle: every open dependabot PR (whatever its base today) is merged into ONE branch (deps/bundle), +# which carries ONE PR with auto-merge on. Merged PRs are closed with a link; a PR that conflicts +# is listed in the bundle PR body and left open. The branch is only ever fast-forwarded (no force). +# Secrets: BUNDLE_TOKEN (or FLEET_TOKEN) lets the bundle PR run CI and lets a github-actions bump +# (a workflow-file change) be pushed; without one GITHUB_TOKEN is used and those cases fail loudly. +# pull_request_target runs the BASE branch's copy of this file and never executes PR code: it only +# fetches and merges the PR heads. +name: dependabot-bundle +on: + pull_request_target: + types: [opened, synchronize] + branches: [dev] + schedule: + - cron: "23 5 * * *" + workflow_dispatch: +permissions: + contents: write + pull-requests: write +concurrency: + group: dependabot-bundle +env: + TARGET: dev + BUNDLE: deps/bundle + GH_TOKEN: ${{ secrets.BUNDLE_TOKEN || secrets.FLEET_TOKEN || github.token }} +jobs: + bundle: + if: github.event_name != 'pull_request_target' || github.actor == 'dependabot[bot]' + runs-on: ubuntu-latest + steps: + - run: | + set -euo pipefail + gh auth setup-git + git clone -q "https://github.com/$GITHUB_REPOSITORY" w && cd w + git config user.name "github-actions[bot]" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + if git ls-remote --exit-code --heads origin "$BUNDLE" >/dev/null; then + git checkout -q -B "$BUNDLE" "origin/$BUNDLE" + git merge -q -m "deps: merge $TARGET" "origin/$TARGET" + else + git checkout -q -B "$BUNDLE" "origin/$TARGET" + fi + merged=(); bad=() + while IFS=$'\t' read -r n t; do + [ -n "$n" ] || continue + git fetch -q origin "pull/$n/head" + if git merge -q -m "deps: merge #$n $t" FETCH_HEAD; then merged+=("$n"); else git merge --abort; bad+=("$n"); fi + done < <(gh pr list --state open --author 'app/dependabot' --json number,title --jq '.[]|"\(.number)\t\(.title)"') + [ "$(git rev-list --count "origin/$TARGET..HEAD")" -gt 0 ] || { echo "nothing to bundle"; exit 0; } + git push -q origin "$BUNDLE" + body="Bundled dependabot updates, merged from: $(printf '#%s ' "${merged[@]}")" + [ ${#bad[@]} -eq 0 ] || body="$body"$'\n\n'"CONFLICT, left open (resolve or close by hand): $(printf '#%s ' "${bad[@]}")" + pr=$(gh pr list --head "$BUNDLE" --base "$TARGET" --state open --json number --jq '.[0].number // empty') + if [ -n "$pr" ]; then gh pr edit "$pr" --body "$body" + else pr=$(gh pr create --head "$BUNDLE" --base "$TARGET" --title "deps: bundled dependabot updates" --body "$body" | sed 's|.*/||'); fi + gh pr merge "$pr" --auto --merge || echo "::warning::auto-merge not enabled on #$pr" + for n in "${merged[@]}"; do gh pr close "$n" --comment "Merged into the bundle branch; continues in #$pr."; done diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index f35de79..0184e0b 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,7 +1,7 @@ -# RENDERED by `cargo xtask fleet render busbar-store-sqlite` from GetBusbar/busbar's plugins.yaml and -# .github/fleet/ templates; `cargo xtask fleet check` is red on any edit here. On a v* tag: this -# repo's CI on the tagged commit, then busbar's plugin-release.yml (build, sign, pack, publish), then -# the consumer verification of what was published, each at the busbar commit this repo pins. +# RENDERED by `busbar-release plugin sync busbar-store-sqlite` from GetBusbar/busbar-release template/; a hand +# edit is overwritten by the next sync. On a v* tag: this repo's own ci.yml (the fleet harness) on the +# tagged commit, then busbar's plugin-release.yml (build, sign, pack, publish), then the consumer +# verification of what was published, each at the busbar commit this repo pins. name: release on: @@ -21,12 +21,7 @@ permissions: jobs: ci: - uses: GetBusbar/busbar/.github/workflows/plugin-ci.yml@e1d3d8b097201859751d77208e66249d98b50a4b - with: - service: none - busbar_checkout: true - macos_test: "cargo test --workspace --locked" - extra_test: "" + uses: ./.github/workflows/ci.yml secrets: inherit release: needs: ci diff --git a/.github/workflows/repin.yml b/.github/workflows/repin.yml index ef6ea15..6491d62 100644 --- a/.github/workflows/repin.yml +++ b/.github/workflows/repin.yml @@ -1,5 +1,5 @@ -# RENDERED by `cargo xtask fleet render busbar-store-sqlite` from GetBusbar/busbar's plugins.yaml and -# .github/fleet/ templates; `cargo xtask fleet check` is red on any edit here. Moves this repo's +# RENDERED by `busbar-release plugin sync busbar-store-sqlite` from GetBusbar/busbar-release template/; a hand +# edit is overwritten by the next sync. Moves this repo's # busbar pin (busbar's plugin-repin.yml) when busbar dispatches `busbar-repin` or on demand; the # cut/skip decision is by commit, and the commit goes to dev only. name: repin diff --git a/.gitignore b/.gitignore index f9ec886..78a11ae 100644 --- a/.gitignore +++ b/.gitignore @@ -1,5 +1,5 @@ -# RENDERED by `cargo xtask fleet render` from GetBusbar/busbar's plugins.yaml (the entry's -# `gitignore:` lines follow the fleet's own) and .github/fleet/gitignore. +# RENDERED by `busbar-release plugin sync` from GetBusbar/busbar-release template/ (the plugins.yaml +# entry's `gitignore:` lines follow the fleet's own). /target /mutants.out* busbar-governance.db* diff --git a/.mailmap b/.mailmap index 080ad24..5f52e81 100644 --- a/.mailmap +++ b/.mailmap @@ -1,4 +1,4 @@ -# RENDERED by `cargo xtask fleet render` from GetBusbar/busbar's plugins.yaml and .github/fleet/. +# RENDERED by `busbar-release plugin sync` from GetBusbar/busbar-release template/. # Canonical authorship. Commits go out under Matthew Jackson's GitHub noreply only. Matthew Jackson <1085847+MattJackson@users.noreply.github.com> Matthew Jackson <1085847+MattJackson@users.noreply.github.com> Matthew diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 62f3744..281fdbc 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -7,15 +7,28 @@ Thanks for your interest in improving `busbar-store-sqlite`. - Be respectful and constructive in all project spaces (see [CODE_OF_CONDUCT.md](CODE_OF_CONDUCT.md)). - By contributing, you agree your contributions are licensed under the project's - [Apache-2.0](LICENSE) license. + [MIT](LICENSE) license. - Security issues go through [SECURITY.md](SECURITY.md), **not** public issues. ## Layout Every busbar plugin repo has the same skeleton. This one is a two-crate Cargo workspace: `store-sqlite/` holds the plugin's logic and `store-sqlite-plugin/` is the thin `cdylib` that packages it as a droppable `kind: store` plugin. busbar itself is a git dependency -pinned to the commit in `.busbar-ref`. The CI, release and lint configuration are -rendered from [busbar's plugin registry](https://github.com/GetBusbar/busbar/blob/main/plugins.yaml); -change them there, not here. +pinned to the commit in `.busbar-ref`. The CI, release, dependency and lint configuration +are rendered by `busbar-release plugin sync` from the fleet template (GetBusbar/busbar-release +`template/`), [busbar's plugin registry](https://github.com/GetBusbar/busbar/blob/main/plugins.yaml) +and busbar's dependency policy (`.github/fleet/deps.toml` and the root `[workspace.dependencies]` +at the pin); change them there, not here. + +## This repo tests itself against busbar + +CI runs the fleet's one harness, busbar's reusable `plugin-ci.yml`, at the busbar commit in +`.busbar-ref`: fmt, clippy -D warnings, the whole test suite, `cargo deny`, the dependency wall +(busbar-contract plus third-party only), the socket/TLS ban (no plugin opens its own socket, dials, +binds or does TLS), the C-dependency allow-list, `Cargo.lock` parity with busbar's lock at the pin, +the both-ways conformance and the busbar conformance kit for this kind. The tests are this repo's: +`store-sqlite-plugin/tests/conformance.rs` loads the LINKED door and the BUILT cdylib through busbar's +plugin loader and requires one transcript (a test named `the_linked_and_the_dropped_in_*`), and keeps +at least one RED arm (any other test in that target) that proves the comparison can fail. ## Before you open a pull request diff --git a/Cargo.lock b/Cargo.lock index e3c42eb..03013bb 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -10,9 +10,9 @@ checksum = "320119579fcad9c21884f5c4861d16174d0e06250625266f50fe6898340abefa" [[package]] name = "async-trait" -version = "0.1.91" +version = "0.1.92" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "ae36dc4177970ef04fde5178d3e2429882def40e57a451f919c098f72baa6cec" +checksum = "82f6aeea286b8eb4dd3431a1be1b59d290ace00f5bfd8e2a159bc2a05e2c1667" dependencies = [ "proc-macro2", "quote", @@ -39,9 +39,9 @@ checksum = "2af50177e190e07a26ab74f8b1efbfe2ef87da2116221318cb1c2e82baf7de06" [[package]] name = "bitflags" -version = "2.13.1" +version = "2.11.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "b588b76d00fde79687d7646a9b5bdf3cc0f655e0bbd080335a95d7e96f3587da" +checksum = "c4512299f36f043ab09a583e57bceb5a5aab7a73db1805848e8fef3c9e8c78b3" [[package]] name = "block-buffer" @@ -54,9 +54,9 @@ dependencies = [ [[package]] name = "block-buffer" -version = "0.12.1" +version = "0.12.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "d2f6c7dbe95a6ed67ad9f18e57daf93a2f034c524b99fd2b76d18fdfeb6660aa" +checksum = "cdd35008169921d80bc60d3d0ab416eecb028c4cd653352907921d95084790be" dependencies = [ "hybrid-array", ] @@ -164,9 +164,9 @@ checksum = "fc652a48c352aef3ea3aed32080501cf3ef6ed5da78602a020c991775b0aff04" [[package]] name = "cc" -version = "1.4.0" +version = "1.2.62" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "5add81bb678e6cb321aff7fa0dc7689ad82b112dbc032cea19f91d6b8e3582b9" +checksum = "a1dce859f0832a7d088c4f1119888ab94ef4b5d6795d1ce05afb7fe159d79f98" dependencies = [ "find-msvc-tools", "shlex", @@ -180,9 +180,9 @@ checksum = "9330f8b2ff13f34540b44e946ef35111825727b38d33286ef986142615121801" [[package]] name = "cfg_aliases" -version = "0.2.2" +version = "0.2.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "f079e83a288787bcd14a6aea84cee5c87a67c5a3e660c30f557a3d24761b3527" +checksum = "613afe47fcd5fac7ccf1db93babcb082c5994d996f20b8b159f2ad1658eb5724" [[package]] name = "chacha20" @@ -227,9 +227,9 @@ dependencies = [ [[package]] name = "crc32fast" -version = "1.5.0" +version = "1.5.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "9481c1c90cbf2ac953f07c8d4a58aa3945c425b7185c9154d67a65e4230da511" +checksum = "01a7799fd6b852db0e61728dde9a204c423b44d689dbd432522543614b490e78" dependencies = [ "cfg-if", ] @@ -277,7 +277,7 @@ checksum = "f46882e17999c6cc590af592290432be3bce0428cb0d5f8b6715e4dc7b383eb3" dependencies = [ "proc-macro2", "quote", - "syn 2.0.119", + "syn 2.0.117", ] [[package]] @@ -306,20 +306,20 @@ version = "0.11.3" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "f1dd6dbb5841937940781866fa1281a1ff7bd3bf827091440879f9994983d5c2" dependencies = [ - "block-buffer 0.12.1", + "block-buffer 0.12.0", "const-oid 0.10.2", "crypto-common 0.2.2", ] [[package]] name = "displaydoc" -version = "0.2.7" +version = "0.2.6" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "c6232dd377dcc64799954cbd3a9bb882e9cdc1308ccd87b1c098f1fb2eaf82a8" +checksum = "1ac70aa55017e108007fbaf5aa0f54b021c98f92ff8af59d42eda9da96e3dd4f" dependencies = [ "proc-macro2", "quote", - "syn 3.0.3", + "syn 2.0.117", ] [[package]] @@ -359,7 +359,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "39cab71617ae0d63f51a36d69f866391735b51691dbda63cf6f96d042b63efeb" dependencies = [ "libc", - "windows-sys 0.52.0", + "windows-sys 0.61.2", ] [[package]] @@ -398,9 +398,9 @@ checksum = "5baebc0774151f905a1a2cc41989300b1e6fbb29aff0ceffa1064fdd3088d582" [[package]] name = "flate2" -version = "1.1.9" +version = "1.1.10" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "843fba2746e448b37e26a819579957415c8cef339bf08564fe8b7ddbd959573c" +checksum = "6e634e2e0ebac1ee034020da1ca582e17ffe4e0f5e985823721e168928136dcb" dependencies = [ "crc32fast", "miniz_oxide", @@ -578,9 +578,9 @@ dependencies = [ [[package]] name = "hashlink" -version = "0.12.1" +version = "0.12.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "32069d97bb81e38fa67eab65e3393bf804bb85969f2bc06bf13f64aef5aba248" +checksum = "a596f1b20ed2cc5ecac41a164aaebc7258057060f06c0cf7a2ba3991ee7990fb" dependencies = [ "hashbrown 0.17.1", ] @@ -593,9 +593,9 @@ checksum = "7f24254aa9a54b5c858eaee2f5bccdb46aaf0e486a595ed5fd8f86ba55232a70" [[package]] name = "http" -version = "1.5.0" +version = "1.4.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "918d3568bebf352712bc2ef3d46a8bcf1a75b373be6539de198e9105cbbf9ce0" +checksum = "8be7462df143984c4598a256ef469b251d7d7f9e271135073e78fc535414f3d0" dependencies = [ "bytes", "itoa", @@ -613,9 +613,9 @@ dependencies = [ [[package]] name = "http-body-util" -version = "0.1.4" +version = "0.1.5" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "e9f41fd6a08e4d4ec69df65976da761afd5ad5e58a9d4acb46bd1c953a9e3ff2" +checksum = "23169fe34a5fbcdd3f3862e78fb9b6fccd5f02a6dc6f732547005d45631ce71c" dependencies = [ "bytes", "futures-core", @@ -632,18 +632,18 @@ checksum = "6dbf3de79e51f3d586ab4cb9d5c3e2c14aa28ed23d180cf89b4df0454a69cc87" [[package]] name = "hybrid-array" -version = "0.4.14" +version = "0.4.12" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "707114b52a152fa7bdb290cd7cd5912d9467273b6d74e21b8d81aca1f8533f6b" +checksum = "9155a582abd142abc056962c29e3ce5ff2ad5469f4246b537ed42c5deba857da" dependencies = [ "typenum", ] [[package]] name = "hyper" -version = "1.11.0" +version = "1.11.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "d22053281f852e11534f5198498373cbb59295120a20771d90f7ed1897490a72" +checksum = "27b501faa50e7a26c3d3560ca625132f4078a17771f4810baf70475ae48cbe43" dependencies = [ "atomic-waker", "bytes", @@ -827,12 +827,13 @@ checksum = "8f42a60cbdf9a97f5d2305f08a87dc4e09308d1276d28c869c684d7777685682" [[package]] name = "js-sys" -version = "0.3.103" +version = "0.3.99" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "53b44bfcdb3f8d5837a46dae1ca9660a837176eee74a28b229bc626816589102" +checksum = "142bc4740e452c1e57ade0cbc129f139c9093e354346f0872ef985f4f5cf5f11" dependencies = [ "cfg-if", "futures-util", + "once_cell", "wasm-bindgen", ] @@ -854,9 +855,9 @@ dependencies = [ [[package]] name = "libsqlite3-sys" -version = "0.38.1" +version = "0.38.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "f6c19a05435c21ac299d71b6a9c13db3e3f47c520517d58990a462a1397a61db" +checksum = "f1d20bef17f513b9b3004532233187769cd072d790971f4e4da0e346eb6401e8" dependencies = [ "cc", "pkg-config", @@ -877,9 +878,9 @@ checksum = "92daf443525c4cce67b150400bc2316076100ce0b3686209eb8cf3c31612e6f0" [[package]] name = "log" -version = "0.4.33" +version = "0.4.30" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "0ceec5bc11778974d1bcb055b18002eba7f4b3518b6a0081b3af5f21666da9ad" +checksum = "616ec5685824bcc94416c6d4a7a446eea774a31efd7062c8480ba6fd06d7a6e5" [[package]] name = "lru-slab" @@ -889,15 +890,15 @@ checksum = "112b39cec0b298b6c1999fee3e31427f74f676e4cb9879ed1a121b43661a4154" [[package]] name = "memchr" -version = "2.8.3" +version = "2.8.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "cf8baf1c55e62ffcace7a9f06f4bd9cd3f0c4beb022d3b367256b91b87513d98" +checksum = "6b947ae49db0d222b1dbc6b113ce7248a3fc3a6ca21b696717bfc000ba4484d8" [[package]] name = "miniz_oxide" -version = "0.8.9" +version = "0.9.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "1fa76a2c86f704bdb222d66965fb3d63269ce38518b83cb0575fca855ebb6316" +checksum = "b63fbc4a50860e98e7b2aa7804ded1db5cbc3aff9193adaff57a6931bf7c4b4c" dependencies = [ "adler2", "simd-adler32", @@ -905,9 +906,9 @@ dependencies = [ [[package]] name = "mio" -version = "1.2.2" +version = "1.2.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "30d65c71f1ce40ab09135ce117d742b9f8a19ff91a41a8b57ed50bc2de59c427" +checksum = "02bd0af71c67b473010cbbc60715ee815645a4dc942899111f494b4b737d6fda" dependencies = [ "libc", "wasi", @@ -959,18 +960,18 @@ dependencies = [ [[package]] name = "proc-macro2" -version = "1.0.107" +version = "1.0.106" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "985e7ec9bb745e6ce6535b544d84d6cd6f7ad8bd711c398938ae983b91a766d9" +checksum = "8fd00f0bb2e90d81d1044c2b32617f68fcb9fa3bb7640c23e9c748e53fb30934" dependencies = [ "unicode-ident", ] [[package]] name = "quinn" -version = "0.11.11" +version = "0.11.9" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "0c1a41e437b6bbd489372cd4971de128e85c855f56c57f283d20ff016cf7c0a8" +checksum = "b9e20a958963c291dc322d98411f541009df2ced7b5a4f2bd52337638cfccf20" dependencies = [ "bytes", "cfg_aliases", @@ -1010,9 +1011,9 @@ dependencies = [ [[package]] name = "quinn-udp" -version = "0.5.15" +version = "0.5.14" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "35a133f956daabe89a61a685c2649f13d82d5aa4bd5d12d1277e1072a21c0694" +checksum = "addec6a0dcad8a8d96a771f815f0eaf55f9d1805756410b39f5fa81332574cbd" dependencies = [ "cfg_aliases", "libc", @@ -1024,9 +1025,9 @@ dependencies = [ [[package]] name = "quote" -version = "1.0.47" +version = "1.0.45" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "1fbf4db142a473a8d80c26bbf18454ed458bf8d26c8219c331daecfdbd079001" +checksum = "41f2619966050689382d2b44f664f4bc593e129785a36d6ee376ddf37259b924" dependencies = [ "proc-macro2", ] @@ -1108,12 +1109,14 @@ dependencies = [ "sync_wrapper", "tokio", "tokio-rustls", + "tokio-util", "tower", "tower-http", "tower-service", "url", "wasm-bindgen", "wasm-bindgen-futures", + "wasm-streams", "web-sys", "webpki-roots", ] @@ -1144,9 +1147,9 @@ dependencies = [ [[package]] name = "rusqlite" -version = "0.40.1" +version = "0.40.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "11438310b19e3109b6446c33d1ed5e889428cf2e278407bc7896bc4aaea43323" +checksum = "23f2a97da3e3873c73cb2a2e71b35c40ff95e0b1eefa8d72d8499a6928c3b5b3" dependencies = [ "bitflags", "fallible-iterator", @@ -1159,9 +1162,9 @@ dependencies = [ [[package]] name = "rustc-hash" -version = "2.1.3" +version = "2.1.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "6b1e7f9a428571be2dc5bc0505c13fb6bf936822b894ec87abf8a08a4e51742d" +checksum = "94300abf3f1ae2e2b8ffb7b58043de3d399c73fa6f4b73826402a5c457614dbe" [[package]] name = "rustc_version" @@ -1182,14 +1185,14 @@ dependencies = [ "errno", "libc", "linux-raw-sys", - "windows-sys 0.52.0", + "windows-sys 0.61.2", ] [[package]] name = "rustls" -version = "0.23.43" +version = "0.23.45" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "0283386ce02abc0151e1761d08802dfe86c173b0b494af5cbc086574e453da06" +checksum = "0d41d731c7d2f962d1ccc364cec258de3c0e93b38c2fb3ba97ac74513048d634" dependencies = [ "once_cell", "ring", @@ -1211,9 +1214,9 @@ dependencies = [ [[package]] name = "rustls-webpki" -version = "0.103.13" +version = "0.103.15" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "61c429a8649f110dddef65e2a5ad240f747e85f7758a6bccc7e5777bd33f756e" +checksum = "f3c3cf1d8b1e7d4927e2d154c3fcb02979afb9939629c62cd9048d4f07b60ac2" dependencies = [ "ring", "rustls-pki-types", @@ -1222,9 +1225,9 @@ dependencies = [ [[package]] name = "rustversion" -version = "1.0.23" +version = "1.0.22" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "cf54715a573b99ac80df0bc206da022bcd442c974952c7b9720069370852e21f" +checksum = "b39cdef0fa800fc44525c84ccb54a029961a8215f9619753635a9c0d2538d46d" [[package]] name = "ryu" @@ -1330,9 +1333,9 @@ dependencies = [ [[package]] name = "shlex" -version = "2.0.1" +version = "1.3.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "f8fadd59c855ef2080decdef8ff161eb6661b86933c9d82e5ba29dc602a55aba" +checksum = "0fda2ff0d084019ba4d7c6f371c95d8fd75ce3524c3cb8fb653a3023f6323e64" [[package]] name = "signature" @@ -1357,15 +1360,15 @@ checksum = "0c790de23124f9ab44544d7ac05d60440adc586479ce501c1d6d7da3cd8c9cf5" [[package]] name = "smallvec" -version = "1.15.2" +version = "1.16.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "8ed6a63f02c8539c91a8685a86f4099661ba3da017932f6ebbea6de3f0fa7c90" +checksum = "ba467056f1b547ed52077911161fc86985becbc60e8e1857c8a144dab0def891" [[package]] name = "socket2" -version = "0.6.5" +version = "0.6.4" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "c3d1e2c7f27f8d4cb10542a02c49005dbd6e93095799d6f3be745fae9f8fedd4" +checksum = "52d1cfed4120b4d927bf7c0f86d2087a4a7d6027c906d9f9d525a80573b9be51" dependencies = [ "libc", "windows-sys 0.61.2", @@ -1407,9 +1410,9 @@ checksum = "13c2bddecc57b384dee18652358fb23172facb8a2c51ccc10d74c157bdea3292" [[package]] name = "syn" -version = "2.0.119" +version = "2.0.117" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "872831b642d1a07999a962a351ed35b955ea2cfc8f3862091e2a240a84f17297" +checksum = "e665b8803e7b1d2a727f4023456bbbbe74da67099c585258af0ad9c5013b9b99" dependencies = [ "proc-macro2", "quote", @@ -1444,7 +1447,7 @@ checksum = "728a70f3dbaf5bab7f0c4b1ac8d7ae5ea60a4b5549c8a5914361c99147a709d2" dependencies = [ "proc-macro2", "quote", - "syn 2.0.119", + "syn 2.0.117", ] [[package]] @@ -1460,22 +1463,22 @@ dependencies = [ [[package]] name = "thiserror" -version = "2.0.19" +version = "2.0.18" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "09a43598840e33d5b0331f38c5e30d13bb11c11210a4b58f0d9b18a5a5eefcd9" +checksum = "4288b5bcbc7920c07a1149a35cf9590a2aa808e0bc1eafaade0b80947865fbc4" dependencies = [ "thiserror-impl", ] [[package]] name = "thiserror-impl" -version = "2.0.19" +version = "2.0.18" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "43cbfe0cf76104d42a574802844187e84a305e531ed54455f11fbde0f10541cd" +checksum = "ebc4ee7f67670e9b64d05fa4253e753e016c6c95ff35b89b7941d6b856dec1d5" dependencies = [ "proc-macro2", "quote", - "syn 3.0.3", + "syn 2.0.117", ] [[package]] @@ -1490,9 +1493,9 @@ dependencies = [ [[package]] name = "tinyvec" -version = "1.12.0" +version = "1.11.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "bb4ebadaa0af04fab11ae01eb5f9fdb5f9c5b875506e210e71c07873528baa7f" +checksum = "3e61e67053d25a4e82c844e8424039d9745781b3fc4f32b8d55ed50f5f667ef3" dependencies = [ "tinyvec_macros", ] @@ -1519,14 +1522,27 @@ dependencies = [ [[package]] name = "tokio-rustls" -version = "0.26.4" +version = "0.26.5" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "1729aa945f29d91ba541258c8df89027d5792d85a8841fb65e8bf0f4ede4ef61" +checksum = "b0c85f2c3ef0b1cd58b36682f4b17aaa995f0e5db534d85692b4903abce21f67" dependencies = [ "rustls", "tokio", ] +[[package]] +name = "tokio-util" +version = "0.7.18" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9ae9cec805b01e8fc3fd2fe289f89149a9b66dd16786abd8b19cfa7b48cb0098" +dependencies = [ + "bytes", + "futures-core", + "futures-sink", + "pin-project-lite", + "tokio", +] + [[package]] name = "tower" version = "0.5.3" @@ -1591,7 +1607,7 @@ checksum = "7490cfa5ec963746568740651ac6781f701c9c5ea257c58e057f3ba8cf69e8da" dependencies = [ "proc-macro2", "quote", - "syn 2.0.119", + "syn 2.0.117", ] [[package]] @@ -1698,18 +1714,18 @@ checksum = "ccf3ec651a847eb01de73ccad15eb7d99f80485de043efb2f370cd654f4ea44b" [[package]] name = "wasip2" -version = "1.0.4+wasi-0.2.12" +version = "1.0.3+wasi-0.2.9" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "b67efb37e106e55ce722a510d6b5f9c17f083e5fc79afc2badeb12cc313d9487" +checksum = "20064672db26d7cdc89c7798c48a0fdfac8213434a1186e5ef29fd560ae223d6" dependencies = [ "wit-bindgen", ] [[package]] name = "wasm-bindgen" -version = "0.2.126" +version = "0.2.122" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "4b067c0c11094aef6b7a801c1e34a26affafdf3d051dba08456b868789aaf9a4" +checksum = "3ed04576f974d2b2fba0f38c51dbc5518011e38c36bf1143164be765528fd409" dependencies = [ "cfg-if", "once_cell", @@ -1720,9 +1736,9 @@ dependencies = [ [[package]] name = "wasm-bindgen-futures" -version = "0.4.76" +version = "0.4.72" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "c62df1340f32221cb9c54d6a27b030e3dba64361d4a95bed55f9aacb44da291d" +checksum = "9473dbd2991ae90b6291c3c32c30c6187ac49aa32f9905d1cce280ec1e110b0f" dependencies = [ "js-sys", "wasm-bindgen", @@ -1730,9 +1746,9 @@ dependencies = [ [[package]] name = "wasm-bindgen-macro" -version = "0.2.126" +version = "0.2.122" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "167ce5e579f6bcf889c4f7175a8a5a585de84e8ff93976ce393efa5f2837aab1" +checksum = "916151b09da36bd82f6615cbf3a419e2f0ba23a03c6160e8e92eb6bd4aa1dec6" dependencies = [ "quote", "wasm-bindgen-macro-support", @@ -1740,31 +1756,44 @@ dependencies = [ [[package]] name = "wasm-bindgen-macro-support" -version = "0.2.126" +version = "0.2.122" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "f3997c7839262f4ef12cf90b818d6340c18e80f263f1a94bf157d0ec4420380e" +checksum = "299047362ccbfce148b67ab7e73349f77748e00c8296f9542adfad2ad82c5c5e" dependencies = [ "bumpalo", "proc-macro2", "quote", - "syn 2.0.119", + "syn 2.0.117", "wasm-bindgen-shared", ] [[package]] name = "wasm-bindgen-shared" -version = "0.2.126" +version = "0.2.122" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "dc1b4cb0cc549fcf58d7dfc081778139b3d283a081644e833e84682ad71cea24" +checksum = "9a929b2c61f11ba3e9bc35b50c1f25cb38e0e892c0c231ae2b8cf78d5dad4437" dependencies = [ "unicode-ident", ] +[[package]] +name = "wasm-streams" +version = "0.4.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "15053d8d85c7eccdbefef60f06769760a563c7f0a9d6902a13d35c7800b0ad65" +dependencies = [ + "futures-util", + "js-sys", + "wasm-bindgen", + "wasm-bindgen-futures", + "web-sys", +] + [[package]] name = "web-sys" -version = "0.3.103" +version = "0.3.99" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "8622dcb61c0bcc9fffa6938bed81210af2da9a7e4a1a834b2e37a59b6dfb6141" +checksum = "6d621441cfc37b84979402712047321980c178f299193a3589d05b99e8763436" dependencies = [ "js-sys", "wasm-bindgen", @@ -1782,9 +1811,9 @@ dependencies = [ [[package]] name = "webpki-roots" -version = "1.0.9" +version = "1.0.7" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "7dcd9d09a39985f5344844e66b0c530a33843579125f23e21e9f0f220850f22a" +checksum = "52f5ee44c96cf55f1b349600768e3ece3a8f26010c05265ab73f945bb1a2eb9d" dependencies = [ "rustls-pki-types", ] @@ -1901,9 +1930,9 @@ dependencies = [ [[package]] name = "yoke" -version = "0.8.3" +version = "0.8.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "709fe23a0424b6a435d82152b1bd3fdfb0833487d5fa90d05d42762a9891fef5" +checksum = "abe8c5fda708d9ca3df187cae8bfb9ceda00dd96231bed36e445a1a48e66f9ca" dependencies = [ "stable_deref_trait", "yoke-derive", @@ -1918,7 +1947,7 @@ checksum = "de844c262c8848816172cef550288e7dc6c7b7814b4ee56b3e1553f275f1858e" dependencies = [ "proc-macro2", "quote", - "syn 2.0.119", + "syn 2.0.117", "synstructure", ] @@ -1939,7 +1968,7 @@ checksum = "11532158c46691caf0f2593ea8358fed6bbf68a0315e80aae9bd41fbade684a1" dependencies = [ "proc-macro2", "quote", - "syn 2.0.119", + "syn 2.0.117", "synstructure", ] @@ -1979,11 +2008,11 @@ checksum = "625dc425cab0dca6dc3c3319506e6593dcb08a9f387ea3b284dbd52a92c40555" dependencies = [ "proc-macro2", "quote", - "syn 2.0.119", + "syn 2.0.117", ] [[package]] name = "zmij" -version = "1.0.23" +version = "1.0.21" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "29666d0abbfad1e3dc4dcf6144730dd3a3ab225bbbdac83319345b1b44ccfc1b" +checksum = "b8848ee67ecc8aedbaf3e4122217aff892639231befc6a1b58d29fff4c2cabaa" diff --git a/Cargo.toml b/Cargo.toml index 98169bb..fd6bded 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -1,13 +1,19 @@ -# SPDX-License-Identifier: Apache-2.0 +# SPDX-License-Identifier: MIT # -# RENDERED by `cargo xtask fleet render busbar-store-sqlite` from GetBusbar/busbar's plugins.yaml and -# .github/fleet/workspace-Cargo.toml; `cargo xtask fleet check` is red on any edit here. +# RENDERED by `busbar-release plugin sync busbar-store-sqlite` from GetBusbar/busbar-release template/ and +# GetBusbar/busbar's dependency policy; a hand edit is overwritten by the next sync. # -# One repo per plugin, every repo a twin: this workspace is exactly two crates, the logic -# (`store-sqlite/`, the rlib a busbar build can link) and the thin cdylib that packages it as a -# droppable `kind: store` plugin (`store-sqlite-plugin/`, crate `busbar-store-sqlite-plugin`). Its busbar -# dependencies are git dependencies on GetBusbar/busbar at the fleet pin (`.busbar-ref` field 1); -# no sibling-checkout path dependency ships in any manifest. +# One repo per plugin, every repo a twin: this workspace is exactly two crates, the logic (the rlib a +# busbar build links) and the thin cdylib that packages it as a droppable `kind: store` plugin +# (crate `busbar-store-sqlite-plugin`). Its one busbar dependency is busbar-contract (busbar-plugin-loader is dev-only, +# for the both-ways conformance test), both git dependencies on GetBusbar/busbar at the pin in +# `.busbar-ref`; no sibling-checkout path dependency ships in any manifest. +# +# THIRD-PARTY VERSIONS ARE THE FLEET'S, NOT THIS REPO'S. The table below is busbar's own root +# `[workspace.dependencies]` (third-party rows) at busbar e1d3d8b097201859751d77208e66249d98b50a4b, followed by the plugin-only rows +# of busbar's `.github/fleet/deps.toml` at dd9637da0c849b811238e108cbafabcb4c7c22a2. A member takes a crate with +# `{ workspace = true }` (adding features if it needs them); a crate in neither table is a new +# `deps.toml` row in busbar first. CI holds this repo's Cargo.lock to busbar's lock at the pin. [workspace] resolver = "2" members = [ @@ -18,10 +24,95 @@ members = [ [workspace.package] edition = "2021" rust-version = "1.98" -license = "Apache-2.0" +license = "MIT" publish = false repository = "https://github.com/GetBusbar/busbar-store-sqlite" [workspace.dependencies] busbar-contract = { git = "https://github.com/GetBusbar/busbar", rev = "e1d3d8b097201859751d77208e66249d98b50a4b" } busbar-plugin-loader = { git = "https://github.com/GetBusbar/busbar", rev = "e1d3d8b097201859751d77208e66249d98b50a4b" } +# busbar's root [workspace.dependencies], third-party rows, at e1d3d8b097201859751d77208e66249d98b50a4b +a2a-lf = "0.3.0" +a2a-pb = "0.2.0" +arc-swap = "1" +async-trait = "0.1" +axum = "0.8" +base64 = "0.23" +bumpalo = "3" +bytes = "1" +core_affinity = "0.8" +crc32fast = "1" +criterion = { version = "0.7", default-features = false, features = ["cargo_bench_support"] } +dimpl = { version = "=0.7.4", default-features = false } +ed25519-dalek = { version = "2", default-features = false, features = ["std"] } +flate2 = { version = "1", default-features = false, features = ["rust_backend"] } +futures = "0.3" +getrandom = "0.3" +h2 = "0.4" +hex = "0.4.3" +hmac = "0.13.0" +http = "1" +http-body = "1" +http-body-util = "0.1" +httpdate = "1.0" +hyper = { version = "1", default-features = false, features = ["server", "client", "http1", "http2"] } +hyper-rustls = { version = "0.27", default-features = false, features = ["http1", "http2", "ring", "webpki-tokio"] } +hyper-util = { version = "0.1", default-features = false, features = ["client-legacy", "http1", "http2", "server-auto", "server-graceful", "service", "tokio"] } +indexmap = { version = "2", features = ["serde"] } +jsonschema = "0.49" +libc = "0.2" +libloading = "0.9" +log = "0.4" +loom = "0.7" +memchr = "2" +metrics = "0.24.6" +metrics-exporter-prometheus = { version = "0.18.3", default-features = false } +metrics-util = { version = "0.20.4", default-features = false } +oauth-as = { version = "1.0.0", features = ["http", "jwt", "consent", "resource-metadata"] } +opentelemetry-proto = { version = "0.32", default-features = false, features = ["gen-tonic-messages", "trace"] } +proc-macro2 = { version = "1", features = ["span-locations"] } +proptest = "1" +prost = { version = "0.14", default-features = false, features = ["std"] } +rcgen = "0.14" +reqwest = { version = "0.12", default-features = false, features = ["rustls-tls", "stream"] } +ring = "0.17" +rmcp = { version = "3.1.2", default-features = false } +rustls = { version = "0.23", default-features = false, features = ["ring", "std", "tls12"] } +rustls-pki-types = { version = "1", default-features = false, features = ["std"] } +schemars = "1" +serde = { version = "1", features = ["derive"] } +serde_json = "1" +serde_urlencoded = "0.7" +serde_yaml = { package = "serde_yaml_ng", version = "0.10" } +sha2 = "0.11.0" +smallvec = "1" +socket2 = { version = "0.6", features = ["all"] } +sonic-rs = "0.5" +syn = { version = "2", features = ["full", "visit", "parsing", "printing"] } +tar = "0.4" +tikv-jemalloc-ctl = "0.6" +tikv-jemallocator = "0.6" +tokio = "1" +tokio-rustls = { version = "0.26", default-features = false, features = ["ring"] } +tokio-tungstenite = { version = "0.29", default-features = false, features = ["handshake"] } +tokio-util = { version = "0.7", default-features = false, features = ["compat"] } +tonic = { version = "0.14", default-features = false } +tonic-types = "0.14" +tower = "0.5" +tracing = "0.1.44" +tracing-core = "0.1" +tracing-log = { version = "0.2", default-features = false, features = ["log-tracer", "std"] } +tracing-subscriber = "0.3.23" +tungstenite = { version = "0.29", default-features = false } +url = "2" +webpki = { package = "rustls-webpki", version = "0.103", default-features = false, features = ["std", "ring"] } +webpki-roots = "1" +zeroize = "1" +# busbar .github/fleet/deps.toml [plugin-deps], at dd9637da0c849b811238e108cbafabcb4c7c22a2 +ldap3 = { version = "0.12", default-features = false, features = ["sync"] } +mysql = { version = "26", default-features = false, features = ["minimal"] } +postgres = "0.19" +redis = { version = "1", default-features = false, features = ["script"] } +rusqlite = { version = "0.40", features = ["bundled"] } +ulid = "1" + diff --git a/LICENSE b/LICENSE index d645695..26e9150 100644 --- a/LICENSE +++ b/LICENSE @@ -1,202 +1,21 @@ - - Apache License - Version 2.0, January 2004 - http://www.apache.org/licenses/ - - TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION - - 1. Definitions. - - "License" shall mean the terms and conditions for use, reproduction, - and distribution as defined by Sections 1 through 9 of this document. - - "Licensor" shall mean the copyright owner or entity authorized by - the copyright owner that is granting the License. - - "Legal Entity" shall mean the union of the acting entity and all - other entities that control, are controlled by, or are under common - control with that entity. For the purposes of this definition, - "control" means (i) the power, direct or indirect, to cause the - direction or management of such entity, whether by contract or - otherwise, or (ii) ownership of fifty percent (50%) or more of the - outstanding shares, or (iii) beneficial ownership of such entity. - - "You" (or "Your") shall mean an individual or Legal Entity - exercising permissions granted by this License. - - "Source" form shall mean the preferred form for making modifications, - including but not limited to software source code, documentation - source, and configuration files. - - "Object" form shall mean any form resulting from mechanical - transformation or translation of a Source form, including but - not limited to compiled object code, generated documentation, - and conversions to other media types. - - "Work" shall mean the work of authorship, whether in Source or - Object form, made available under the License, as indicated by a - copyright notice that is included in or attached to the work - (an example is provided in the Appendix below). - - "Derivative Works" shall mean any work, whether in Source or Object - form, that is based on (or derived from) the Work and for which the - editorial revisions, annotations, elaborations, or other modifications - represent, as a whole, an original work of authorship. For the purposes - of this License, Derivative Works shall not include works that remain - separable from, or merely link (or bind by name) to the interfaces of, - the Work and Derivative Works thereof. - - "Contribution" shall mean any work of authorship, including - the original version of the Work and any modifications or additions - to that Work or Derivative Works thereof, that is intentionally - submitted to Licensor for inclusion in the Work by the copyright owner - or by an individual or Legal Entity authorized to submit on behalf of - the copyright owner. For the purposes of this definition, "submitted" - means any form of electronic, verbal, or written communication sent - to the Licensor or its representatives, including but not limited to - communication on electronic mailing lists, source code control systems, - and issue tracking systems that are managed by, or on behalf of, the - Licensor for the purpose of discussing and improving the Work, but - excluding communication that is conspicuously marked or otherwise - designated in writing by the copyright owner as "Not a Contribution." - - "Contributor" shall mean Licensor and any individual or Legal Entity - on behalf of whom a Contribution has been received by Licensor and - subsequently incorporated within the Work. - - 2. Grant of Copyright License. Subject to the terms and conditions of - this License, each Contributor hereby grants to You a perpetual, - worldwide, non-exclusive, no-charge, royalty-free, irrevocable - copyright license to reproduce, prepare Derivative Works of, - publicly display, publicly perform, sublicense, and distribute the - Work and such Derivative Works in Source or Object form. - - 3. Grant of Patent License. Subject to the terms and conditions of - this License, each Contributor hereby grants to You a perpetual, - worldwide, non-exclusive, no-charge, royalty-free, irrevocable - (except as stated in this section) patent license to make, have made, - use, offer to sell, sell, import, and otherwise transfer the Work, - where such license applies only to those patent claims licensable - by such Contributor that are necessarily infringed by their - Contribution(s) alone or by combination of their Contribution(s) - with the Work to which such Contribution(s) was submitted. If You - institute patent litigation against any entity (including a - cross-claim or counterclaim in a lawsuit) alleging that the Work - or a Contribution incorporated within the Work constitutes direct - or contributory patent infringement, then any patent licenses - granted to You under this License for that Work shall terminate - as of the date such litigation is filed. - - 4. Redistribution. You may reproduce and distribute copies of the - Work or Derivative Works thereof in any medium, with or without - modifications, and in Source or Object form, provided that You - meet the following conditions: - - (a) You must give any other recipients of the Work or - Derivative Works a copy of this License; and - - (b) You must cause any modified files to carry prominent notices - stating that You changed the files; and - - (c) You must retain, in the Source form of any Derivative Works - that You distribute, all copyright, patent, trademark, and - attribution notices from the Source form of the Work, - excluding those notices that do not pertain to any part of - the Derivative Works; and - - (d) If the Work includes a "NOTICE" text file as part of its - distribution, then any Derivative Works that You distribute must - include a readable copy of the attribution notices contained - within such NOTICE file, excluding those notices that do not - pertain to any part of the Derivative Works, in at least one - of the following places: within a NOTICE text file distributed - as part of the Derivative Works; within the Source form or - documentation, if provided along with the Derivative Works; or, - within a display generated by the Derivative Works, if and - wherever such third-party notices normally appear. The contents - of the NOTICE file are for informational purposes only and - do not modify the License. You may add Your own attribution - notices within Derivative Works that You distribute, alongside - or as an addendum to the NOTICE text from the Work, provided - that such additional attribution notices cannot be construed - as modifying the License. - - You may add Your own copyright statement to Your modifications and - may provide additional or different license terms and conditions - for use, reproduction, or distribution of Your modifications, or - for any such Derivative Works as a whole, provided Your use, - reproduction, and distribution of the Work otherwise complies with - the conditions stated in this License. - - 5. Submission of Contributions. Unless You explicitly state otherwise, - any Contribution intentionally submitted for inclusion in the Work - by You to the Licensor shall be under the terms and conditions of - this License, without any additional terms or conditions. - Notwithstanding the above, nothing herein shall supersede or modify - the terms of any separate license agreement you may have executed - with Licensor regarding such Contributions. - - 6. Trademarks. This License does not grant permission to use the trade - names, trademarks, service marks, or product names of the Licensor, - except as required for reasonable and customary use in describing the - origin of the Work and reproducing the content of the NOTICE file. - - 7. Disclaimer of Warranty. Unless required by applicable law or - agreed to in writing, Licensor provides the Work (and each - Contributor provides its Contributions) on an "AS IS" BASIS, - WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or - implied, including, without limitation, any warranties or conditions - of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A - PARTICULAR PURPOSE. You are solely responsible for determining the - appropriateness of using or redistributing the Work and assume any - risks associated with Your exercise of permissions under this License. - - 8. Limitation of Liability. In no event and under no legal theory, - whether in tort (including negligence), contract, or otherwise, - unless required by applicable law (such as deliberate and grossly - negligent acts) or agreed to in writing, shall any Contributor be - liable to You for damages, including any direct, indirect, special, - incidental, or consequential damages of any character arising as a - result of this License or out of the use or inability to use the - Work (including but not limited to damages for loss of goodwill, - work stoppage, computer failure or malfunction, or any and all - other commercial damages or losses), even if such Contributor - has been advised of the possibility of such damages. - - 9. Accepting Warranty or Additional Liability. While redistributing - the Work or Derivative Works thereof, You may choose to offer, - and charge a fee for, acceptance of support, warranty, indemnity, - or other liability obligations and/or rights consistent with this - License. However, in accepting such obligations, You may act only - on Your own behalf and on Your sole responsibility, not on behalf - of any other Contributor, and only if You agree to indemnify, - defend, and hold each Contributor harmless for any liability - incurred by, or claims asserted against, such Contributor by reason - of your accepting any such warranty or additional liability. - - END OF TERMS AND CONDITIONS - - APPENDIX: How to apply the Apache License to your work. - - To apply the Apache License to your work, attach the following - boilerplate notice, with the fields enclosed by brackets "[]" - replaced with your own identifying information. (Don't include - the brackets!) The text should be enclosed in the appropriate - comment syntax for the file format. We also recommend that a - file or class name and description of purpose be included on the - same "printed page" as the copyright notice for easier - identification within third-party archives. - - Copyright [yyyy] [name of copyright owner] - - Licensed under the Apache License, Version 2.0 (the "License"); - you may not use this file except in compliance with the License. - You may obtain a copy of the License at - - http://www.apache.org/licenses/LICENSE-2.0 - - Unless required by applicable law or agreed to in writing, software - distributed under the License is distributed on an "AS IS" BASIS, - WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - See the License for the specific language governing permissions and - limitations under the License. +MIT License + +Copyright (c) 2026 Busbar Inc and contributors + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/README.md b/README.md index f7f554d..6a1251d 100644 --- a/README.md +++ b/README.md @@ -1,11 +1,11 @@ - + # busbar-store-sqlite First-party signed kind:store plugin cdylib: the SQLite governance store packaged as a droppable busbar plugin exporting the store C ABI. Drop the built library into the plugins folder and set store.module: sqlite. | kind | alias | crate | busbar | license | |---|---|---|---|---| -| `store` | `sqlite` | `busbar-store-sqlite-plugin` | 1.6.0 (pinned in `.busbar-ref`) | Apache-2.0 | +| `store` | `sqlite` | `busbar-store-sqlite-plugin` | 1.6.0 (pinned in `.busbar-ref`) | MIT | [![ci](https://github.com/GetBusbar/busbar-store-sqlite/actions/workflows/ci.yml/badge.svg?branch=dev)](https://github.com/GetBusbar/busbar-store-sqlite/actions/workflows/ci.yml) diff --git a/clippy.toml b/clippy.toml index 9cabef7..fd71967 100644 --- a/clippy.toml +++ b/clippy.toml @@ -1,4 +1,4 @@ -# RENDERED by `cargo xtask fleet render` from GetBusbar/busbar's plugins.yaml and .github/fleet/ -# templates. CI runs clippy with -D warnings (busbar's plugin-ci.yml) on the 1.98.0 toolchain; -# the MSRV clippy judges against is each crate's own `rust-version`, so none is restated here. +# RENDERED by `busbar-release plugin sync` from GetBusbar/busbar-release template/; a hand edit is +# overwritten by the next sync. CI (busbar's plugin-ci.yml at the pin) runs clippy with -D warnings on +# the 1.98.0 toolchain; the MSRV clippy judges against is each crate's own `rust-version`. too-many-arguments-threshold = 7 diff --git a/codecov.yml b/codecov.yml index a9c60ed..f1b9b9a 100644 --- a/codecov.yml +++ b/codecov.yml @@ -1,8 +1,7 @@ -# RENDERED by `cargo xtask fleet render` from GetBusbar/busbar's plugins.yaml and .github/fleet/. -# Codecov is INFORMATIONAL, never a gate: the correctness gate is the `ci` job (busbar's -# plugin-ci.yml). Coverage is an observation on the README badge and the Codecov UI, so every status -# is informational, there are no PR comments, and test-only paths plus the busbar checkout the -# end-to-end tests build are excluded from the percentage. +# RENDERED by `busbar-release plugin sync` from GetBusbar/busbar-release template/. +# Codecov is INFORMATIONAL, never a gate: the correctness gate is the `ci` workflow (busbar's +# plugin-ci.yml at the pin). Every status is informational, there are no PR comments, and test-only paths +# plus the busbar checkout the end-to-end tests build are excluded from the percentage. coverage: status: project: diff --git a/deny.toml b/deny.toml index ddbdadd..6cb499e 100644 --- a/deny.toml +++ b/deny.toml @@ -1,6 +1,10 @@ -# RENDERED by `cargo xtask fleet render` from GetBusbar/busbar's plugins.yaml and .github/fleet/ -# templates. cargo-deny policy for a first-party plugin: the license allowlist busbar's own deny.toml -# holds, and ONE reviewed git source (busbar itself, at the pin). +# RENDERED by `busbar-release plugin sync` from GetBusbar/busbar-release template/ and busbar's +# `.github/fleet/deps.toml` at dd9637da0c849b811238e108cbafabcb4c7c22a2; a hand edit is overwritten by the next sync. CI runs +# `cargo deny check` on it (busbar's plugin-ci.yml at the pin). The license allowlist is busbar's own; +# the one reviewed git source is busbar itself, at the pin. +[graph] +all-features = false + [advisories] version = 2 @@ -27,9 +31,225 @@ allow = [ confidence-threshold = 0.9 [bans] -multiple-versions = "warn" +multiple-versions = "deny" wildcards = "deny" allow-wildcard-paths = true +# busbar .github/fleet/deps.toml [bans].deny (one stack per concern), then ONE VERSION OF EVERYTHING +# BUSBAR USES (OWNER 2026-10-02): every version of a shared crate outside the line busbar's own +# Cargo.lock resolves it to, at the pin. +deny = [ + # ONE Ed25519 = ed25519-dalek 2 (ARCHITECT ruling 2026-10-02; mirrors busbar deny.toml): no older + # dalek and no other Ed25519 implementation may enter a plugin's closure. + { crate = "ed25519-dalek@1", reason = "ONE Ed25519: ed25519-dalek 2" }, + { crate = "ed25519-dalek@0", reason = "ONE Ed25519: ed25519-dalek 2" }, + { crate = "ed25519-compact", reason = "ONE Ed25519: ed25519-dalek 2" }, + { crate = "ed25519-zebra", reason = "ONE Ed25519: ed25519-dalek 2" }, + { crate = "ed25519-consensus", reason = "ONE Ed25519: ed25519-dalek 2" }, + { crate = "openssl", reason = "TLS is rustls (core-only); no OpenSSL anywhere in the fleet" }, + { crate = "openssl-sys", reason = "TLS is rustls (core-only); no OpenSSL anywhere in the fleet" }, + { crate = "native-tls", reason = "TLS is rustls (core-only); no platform TLS anywhere in the fleet" }, + { crate = "hyper:<1", reason = "HTTP is hyper 1; no hyper 0.14 stack" }, + { crate = "rustls:<0.23", reason = "one rustls major (0.23) fleet-wide" }, + { crate = "ring:<0.17", reason = "one ring major (0.17) fleet-wide" }, + { crate = "serde_yaml", reason = "unmaintained; busbar uses serde_yaml_ng" }, + { crate = "a2a-lf:<0.3.0", reason = "busbar resolves a2a-lf to 0.3.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "a2a-lf:>=0.4.0", reason = "busbar resolves a2a-lf to 0.3.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "a2a-pb:<0.2.0", reason = "busbar resolves a2a-pb to 0.2.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "a2a-pb:>=0.3.0", reason = "busbar resolves a2a-pb to 0.2.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "arc-swap:<1.0.0", reason = "busbar resolves arc-swap to 1.9.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "arc-swap:>=2.0.0", reason = "busbar resolves arc-swap to 1.9.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "async-trait:<0.1.0", reason = "busbar resolves async-trait to 0.1.92; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "async-trait:>=0.2.0", reason = "busbar resolves async-trait to 0.1.92; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "axum:<0.8.0", reason = "busbar resolves axum to 0.8.9; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "axum:>=0.9.0", reason = "busbar resolves axum to 0.8.9; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "base64:<0.22.0", reason = "busbar resolves base64 to 0.22.1, 0.23.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "base64:>=0.24.0", reason = "busbar resolves base64 to 0.22.1, 0.23.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "bumpalo:<3.0.0", reason = "busbar resolves bumpalo to 3.20.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "bumpalo:>=4.0.0", reason = "busbar resolves bumpalo to 3.20.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "bytes:<1.0.0", reason = "busbar resolves bytes to 1.12.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "bytes:>=2.0.0", reason = "busbar resolves bytes to 1.12.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "core_affinity:<0.8.0", reason = "busbar resolves core_affinity to 0.8.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "core_affinity:>=0.9.0", reason = "busbar resolves core_affinity to 0.8.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "crc32fast:<1.0.0", reason = "busbar resolves crc32fast to 1.5.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "crc32fast:>=2.0.0", reason = "busbar resolves crc32fast to 1.5.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "criterion:<0.7.0", reason = "busbar resolves criterion to 0.7.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "criterion:>=0.8.0", reason = "busbar resolves criterion to 0.7.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "dimpl:<0.7.0", reason = "busbar resolves dimpl to 0.7.4; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "dimpl:>=0.8.0", reason = "busbar resolves dimpl to 0.7.4; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "ed25519-dalek:<2.0.0", reason = "busbar resolves ed25519-dalek to 2.2.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "ed25519-dalek:>=3.0.0", reason = "busbar resolves ed25519-dalek to 2.2.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "flate2:<1.0.0", reason = "busbar resolves flate2 to 1.1.10; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "flate2:>=2.0.0", reason = "busbar resolves flate2 to 1.1.10; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "futures:<0.3.0", reason = "busbar resolves futures to 0.3.34; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "futures:>=0.4.0", reason = "busbar resolves futures to 0.3.34; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "getrandom:<0.2.0", reason = "busbar resolves getrandom to 0.2.17, 0.3.4, 0.4.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "getrandom:>=0.5.0", reason = "busbar resolves getrandom to 0.2.17, 0.3.4, 0.4.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "h2:<0.4.0", reason = "busbar resolves h2 to 0.4.18; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "h2:>=0.5.0", reason = "busbar resolves h2 to 0.4.18; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "hex:<0.4.0", reason = "busbar resolves hex to 0.4.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "hex:>=0.5.0", reason = "busbar resolves hex to 0.4.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "hmac:<0.13.0", reason = "busbar resolves hmac to 0.13.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "hmac:>=0.14.0", reason = "busbar resolves hmac to 0.13.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "http:<1.0.0", reason = "busbar resolves http to 1.4.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "http:>=2.0.0", reason = "busbar resolves http to 1.4.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "http-body:<1.0.0", reason = "busbar resolves http-body to 1.1.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "http-body:>=2.0.0", reason = "busbar resolves http-body to 1.1.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "http-body-util:<0.1.0", reason = "busbar resolves http-body-util to 0.1.5; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "http-body-util:>=0.2.0", reason = "busbar resolves http-body-util to 0.1.5; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "httpdate:<1.0.0", reason = "busbar resolves httpdate to 1.0.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "httpdate:>=2.0.0", reason = "busbar resolves httpdate to 1.0.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "hyper:<1.0.0", reason = "busbar resolves hyper to 1.11.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "hyper:>=2.0.0", reason = "busbar resolves hyper to 1.11.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "hyper-rustls:<0.27.0", reason = "busbar resolves hyper-rustls to 0.27.9; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "hyper-rustls:>=0.28.0", reason = "busbar resolves hyper-rustls to 0.27.9; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "hyper-util:<0.1.0", reason = "busbar resolves hyper-util to 0.1.20; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "hyper-util:>=0.2.0", reason = "busbar resolves hyper-util to 0.1.20; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "indexmap:<2.0.0", reason = "busbar resolves indexmap to 2.14.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "indexmap:>=3.0.0", reason = "busbar resolves indexmap to 2.14.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "jsonschema:<0.49.0", reason = "busbar resolves jsonschema to 0.49.9; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "jsonschema:>=0.50.0", reason = "busbar resolves jsonschema to 0.49.9; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "libc:<0.2.0", reason = "busbar resolves libc to 0.2.189; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "libc:>=0.3.0", reason = "busbar resolves libc to 0.2.189; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "libloading:<0.9.0", reason = "busbar resolves libloading to 0.9.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "libloading:>=0.10.0", reason = "busbar resolves libloading to 0.9.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "log:<0.4.0", reason = "busbar resolves log to 0.4.30; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "log:>=0.5.0", reason = "busbar resolves log to 0.4.30; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "loom:<0.7.0", reason = "busbar resolves loom to 0.7.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "loom:>=0.8.0", reason = "busbar resolves loom to 0.7.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "memchr:<2.0.0", reason = "busbar resolves memchr to 2.8.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "memchr:>=3.0.0", reason = "busbar resolves memchr to 2.8.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "metrics:<0.24.0", reason = "busbar resolves metrics to 0.24.6; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "metrics:>=0.25.0", reason = "busbar resolves metrics to 0.24.6; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "metrics-exporter-prometheus:<0.18.0", reason = "busbar resolves metrics-exporter-prometheus to 0.18.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "metrics-exporter-prometheus:>=0.19.0", reason = "busbar resolves metrics-exporter-prometheus to 0.18.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "metrics-util:<0.20.0", reason = "busbar resolves metrics-util to 0.20.4; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "metrics-util:>=0.21.0", reason = "busbar resolves metrics-util to 0.20.4; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "oauth-as:<1.0.0", reason = "busbar resolves oauth-as to 1.0.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "oauth-as:>=2.0.0", reason = "busbar resolves oauth-as to 1.0.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "opentelemetry-proto:<0.32.0", reason = "busbar resolves opentelemetry-proto to 0.32.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "opentelemetry-proto:>=0.33.0", reason = "busbar resolves opentelemetry-proto to 0.32.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "proc-macro2:<1.0.0", reason = "busbar resolves proc-macro2 to 1.0.106; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "proc-macro2:>=2.0.0", reason = "busbar resolves proc-macro2 to 1.0.106; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "proptest:<1.0.0", reason = "busbar resolves proptest to 1.11.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "proptest:>=2.0.0", reason = "busbar resolves proptest to 1.11.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "prost:<0.14.0", reason = "busbar resolves prost to 0.14.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "prost:>=0.15.0", reason = "busbar resolves prost to 0.14.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "rcgen:<0.14.0", reason = "busbar resolves rcgen to 0.14.10; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "rcgen:>=0.15.0", reason = "busbar resolves rcgen to 0.14.10; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "reqwest:<0.12.0", reason = "busbar resolves reqwest to 0.12.28, 0.13.4; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "reqwest:>=0.14.0", reason = "busbar resolves reqwest to 0.12.28, 0.13.4; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "ring:<0.17.0", reason = "busbar resolves ring to 0.17.14; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "ring:>=0.18.0", reason = "busbar resolves ring to 0.17.14; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "rmcp:<3.0.0", reason = "busbar resolves rmcp to 3.1.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "rmcp:>=4.0.0", reason = "busbar resolves rmcp to 3.1.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "rustls:<0.23.0", reason = "busbar resolves rustls to 0.23.45; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "rustls:>=0.24.0", reason = "busbar resolves rustls to 0.23.45; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "rustls-pki-types:<1.0.0", reason = "busbar resolves rustls-pki-types to 1.15.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "rustls-pki-types:>=2.0.0", reason = "busbar resolves rustls-pki-types to 1.15.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "schemars:<1.0.0", reason = "busbar resolves schemars to 1.2.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "schemars:>=2.0.0", reason = "busbar resolves schemars to 1.2.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "serde:<1.0.0", reason = "busbar resolves serde to 1.0.229; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "serde:>=2.0.0", reason = "busbar resolves serde to 1.0.229; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "serde_json:<1.0.0", reason = "busbar resolves serde_json to 1.0.151; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "serde_json:>=2.0.0", reason = "busbar resolves serde_json to 1.0.151; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "serde_urlencoded:<0.7.0", reason = "busbar resolves serde_urlencoded to 0.7.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "serde_urlencoded:>=0.8.0", reason = "busbar resolves serde_urlencoded to 0.7.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "serde_yaml_ng:<0.10.0", reason = "busbar resolves serde_yaml_ng to 0.10.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "serde_yaml_ng:>=0.11.0", reason = "busbar resolves serde_yaml_ng to 0.10.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "sha2:<0.10.0", reason = "busbar resolves sha2 to 0.10.9, 0.11.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "sha2:>=0.12.0", reason = "busbar resolves sha2 to 0.10.9, 0.11.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "smallvec:<1.0.0", reason = "busbar resolves smallvec to 1.16.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "smallvec:>=2.0.0", reason = "busbar resolves smallvec to 1.16.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "socket2:<0.6.0", reason = "busbar resolves socket2 to 0.6.4; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "socket2:>=0.7.0", reason = "busbar resolves socket2 to 0.6.4; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "sonic-rs:<0.5.0", reason = "busbar resolves sonic-rs to 0.5.10; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "sonic-rs:>=0.6.0", reason = "busbar resolves sonic-rs to 0.5.10; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "syn:<2.0.0", reason = "busbar resolves syn to 2.0.117, 3.0.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "syn:>=4.0.0", reason = "busbar resolves syn to 2.0.117, 3.0.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tar:<0.4.0", reason = "busbar resolves tar to 0.4.46; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tar:>=0.5.0", reason = "busbar resolves tar to 0.4.46; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tikv-jemalloc-ctl:<0.6.0", reason = "busbar resolves tikv-jemalloc-ctl to 0.6.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tikv-jemalloc-ctl:>=0.7.0", reason = "busbar resolves tikv-jemalloc-ctl to 0.6.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tikv-jemallocator:<0.6.0", reason = "busbar resolves tikv-jemallocator to 0.6.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tikv-jemallocator:>=0.7.0", reason = "busbar resolves tikv-jemallocator to 0.6.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tokio:<1.0.0", reason = "busbar resolves tokio to 1.53.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tokio:>=2.0.0", reason = "busbar resolves tokio to 1.53.1; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tokio-rustls:<0.26.0", reason = "busbar resolves tokio-rustls to 0.26.5; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tokio-rustls:>=0.27.0", reason = "busbar resolves tokio-rustls to 0.26.5; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tokio-tungstenite:<0.29.0", reason = "busbar resolves tokio-tungstenite to 0.29.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tokio-tungstenite:>=0.30.0", reason = "busbar resolves tokio-tungstenite to 0.29.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tokio-util:<0.7.0", reason = "busbar resolves tokio-util to 0.7.18; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tokio-util:>=0.8.0", reason = "busbar resolves tokio-util to 0.7.18; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tonic:<0.14.0", reason = "busbar resolves tonic to 0.14.6; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tonic:>=0.15.0", reason = "busbar resolves tonic to 0.14.6; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tonic-types:<0.14.0", reason = "busbar resolves tonic-types to 0.14.6; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tonic-types:>=0.15.0", reason = "busbar resolves tonic-types to 0.14.6; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tower:<0.5.0", reason = "busbar resolves tower to 0.5.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tower:>=0.6.0", reason = "busbar resolves tower to 0.5.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tracing:<0.1.0", reason = "busbar resolves tracing to 0.1.44; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tracing:>=0.2.0", reason = "busbar resolves tracing to 0.1.44; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tracing-core:<0.1.0", reason = "busbar resolves tracing-core to 0.1.36; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tracing-core:>=0.2.0", reason = "busbar resolves tracing-core to 0.1.36; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tracing-log:<0.2.0", reason = "busbar resolves tracing-log to 0.2.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tracing-log:>=0.3.0", reason = "busbar resolves tracing-log to 0.2.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tracing-subscriber:<0.3.0", reason = "busbar resolves tracing-subscriber to 0.3.23; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tracing-subscriber:>=0.4.0", reason = "busbar resolves tracing-subscriber to 0.3.23; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tungstenite:<0.29.0", reason = "busbar resolves tungstenite to 0.29.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "tungstenite:>=0.30.0", reason = "busbar resolves tungstenite to 0.29.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "url:<2.0.0", reason = "busbar resolves url to 2.5.8; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "url:>=3.0.0", reason = "busbar resolves url to 2.5.8; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "rustls-webpki:<0.103.0", reason = "busbar resolves rustls-webpki to 0.103.15; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "rustls-webpki:>=0.104.0", reason = "busbar resolves rustls-webpki to 0.103.15; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "webpki-roots:<1.0.0", reason = "busbar resolves webpki-roots to 1.0.7; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "webpki-roots:>=2.0.0", reason = "busbar resolves webpki-roots to 1.0.7; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "zeroize:<1.0.0", reason = "busbar resolves zeroize to 1.9.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "zeroize:>=2.0.0", reason = "busbar resolves zeroize to 1.9.0; a plugin may not pull a second version (OWNER 2026-10-02)" }, +] +# The duplicates busbar itself accepts: deps.toml [bans].skip, then every duplicate busbar's own +# Cargo.lock holds at the pin. Nothing else may appear twice (multiple-versions = "deny"). +skip = [ + { crate = "base64@0.22.1", reason = "busbar's own lock holds this duplicate" }, + { crate = "base64@0.23.1", reason = "busbar's own lock holds this duplicate" }, + { crate = "bit-vec@0.8.0", reason = "busbar's own lock holds this duplicate" }, + { crate = "bit-vec@0.9.1", reason = "busbar's own lock holds this duplicate" }, + { crate = "block-buffer@0.10.4", reason = "busbar's own lock holds this duplicate" }, + { crate = "block-buffer@0.12.0", reason = "busbar's own lock holds this duplicate" }, + { crate = "const-oid@0.10.2", reason = "busbar's own lock holds this duplicate" }, + { crate = "const-oid@0.9.6", reason = "busbar's own lock holds this duplicate" }, + { crate = "cpufeatures@0.2.17", reason = "busbar's own lock holds this duplicate" }, + { crate = "cpufeatures@0.3.0", reason = "busbar's own lock holds this duplicate" }, + { crate = "crypto-common@0.1.7", reason = "busbar's own lock holds this duplicate" }, + { crate = "crypto-common@0.2.2", reason = "busbar's own lock holds this duplicate" }, + { crate = "digest@0.10.7", reason = "busbar's own lock holds this duplicate" }, + { crate = "digest@0.11.3", reason = "busbar's own lock holds this duplicate" }, + { crate = "foldhash@0.1.5", reason = "busbar's own lock holds this duplicate" }, + { crate = "foldhash@0.2.0", reason = "busbar's own lock holds this duplicate" }, + { crate = "getrandom@0.2.17", reason = "busbar's own lock holds this duplicate" }, + { crate = "getrandom@0.3.4", reason = "busbar's own lock holds this duplicate" }, + { crate = "getrandom@0.4.3", reason = "busbar's own lock holds this duplicate" }, + { crate = "hashbrown@0.15.5", reason = "busbar's own lock holds this duplicate" }, + { crate = "hashbrown@0.16.1", reason = "busbar's own lock holds this duplicate" }, + { crate = "hashbrown@0.17.1", reason = "busbar's own lock holds this duplicate" }, + { crate = "itertools@0.13.0", reason = "busbar's own lock holds this duplicate" }, + { crate = "itertools@0.14.0", reason = "busbar's own lock holds this duplicate" }, + { crate = "nom@7.1.3", reason = "busbar's own lock holds this duplicate" }, + { crate = "nom@8.0.0", reason = "busbar's own lock holds this duplicate" }, + { crate = "r-efi@5.3.0", reason = "busbar's own lock holds this duplicate" }, + { crate = "r-efi@6.0.0", reason = "busbar's own lock holds this duplicate" }, + { crate = "rand@0.10.2", reason = "busbar's own lock holds this duplicate" }, + { crate = "rand@0.9.4", reason = "busbar's own lock holds this duplicate" }, + { crate = "rand_core@0.10.1", reason = "busbar's own lock holds this duplicate" }, + { crate = "rand_core@0.6.4", reason = "busbar's own lock holds this duplicate" }, + { crate = "rand_core@0.9.5", reason = "busbar's own lock holds this duplicate" }, + { crate = "reqwest@0.12.28", reason = "busbar's own lock holds this duplicate" }, + { crate = "reqwest@0.13.4", reason = "busbar's own lock holds this duplicate" }, + { crate = "sha2@0.10.9", reason = "busbar's own lock holds this duplicate" }, + { crate = "sha2@0.11.0", reason = "busbar's own lock holds this duplicate" }, + { crate = "syn@2.0.117", reason = "busbar's own lock holds this duplicate" }, + { crate = "syn@3.0.3", reason = "busbar's own lock holds this duplicate" }, + { crate = "windows-sys@0.52.0", reason = "busbar's own lock holds this duplicate" }, + { crate = "windows-sys@0.61.2", reason = "busbar's own lock holds this duplicate" }, +] [sources] unknown-registry = "deny" diff --git a/rust-toolchain.toml b/rust-toolchain.toml index 1efc2d3..42c3341 100644 --- a/rust-toolchain.toml +++ b/rust-toolchain.toml @@ -1,6 +1,6 @@ -# RENDERED by `cargo xtask fleet render` from GetBusbar/busbar's plugins.yaml and .github/fleet/ -# templates. The toolchain is busbar's own pin (its rust-toolchain.toml), so a plugin and the core -# that links it compile with one compiler. +# RENDERED by `busbar-release plugin sync` from GetBusbar/busbar-release template/. The toolchain is +# busbar's own pin (its rust-toolchain.toml at the pin), so a plugin and the core that links it compile +# with one compiler. [toolchain] channel = "1.98.0" components = ["clippy", "rustfmt"] diff --git a/store-sqlite-plugin/Cargo.toml b/store-sqlite-plugin/Cargo.toml index 8894521..79716ed 100644 --- a/store-sqlite-plugin/Cargo.toml +++ b/store-sqlite-plugin/Cargo.toml @@ -16,21 +16,21 @@ crate-type = ["cdylib", "rlib"] [dependencies] # THE LOGIC, same repo: its `door::door` is the door this image exports. busbar-store-sqlite = { path = "../store-sqlite" } -busbar-contract = { git = "https://github.com/GetBusbar/busbar", rev = "e1d3d8b097201859751d77208e66249d98b50a4b" } +busbar-contract = { workspace = true } [dev-dependencies] # The conformance and e2e tests load the built cdylib and the linked door over the REAL loader (the # one dispatcher, the store v3 table) — dev-only, never in the shipped artifact. Same pinned rev as # the logic crate's busbar-contract, so one busbar source resolves. -busbar-plugin-loader = { git = "https://github.com/GetBusbar/busbar", rev = "e1d3d8b097201859751d77208e66249d98b50a4b" } -serde_json = "1" +busbar-plugin-loader = { workspace = true } +serde_json = { workspace = true } # Dev-only: the conformance test awaits the store v3 calls (`StoreCalls`), which are futures. -tokio = { version = "1", features = ["rt"] } +tokio = { workspace = true, features = ["rt"] } # Dev-only: the `busy_timeout_ms_is_actually_applied`-style checks open a second, independent # connection to the SAME sqlite file. Same version/feature as `busbar-store-sqlite`'s dependency so # only one sqlite is ever linked in. -rusqlite = { version = "0.40.0", features = ["bundled"] } +rusqlite = { workspace = true } # Dev-only: the admin-API install e2e test drives a REAL running busbar process's admin HTTP API # (POST /api/v1/admin/plugins, POST /api/v1/admin/keys) — the actual operator install path. -reqwest = { version = "0.12", default-features = false, features = ["rustls-tls", "json", "blocking"] } +reqwest = { workspace = true, features = ["json", "blocking"] } base64 = "0.22" diff --git a/store-sqlite/Cargo.toml b/store-sqlite/Cargo.toml index 747ff01..b0d0e10 100644 --- a/store-sqlite/Cargo.toml +++ b/store-sqlite/Cargo.toml @@ -20,13 +20,13 @@ crate-type = ["rlib"] # as `busbar_contract::abi::sdk`). Pinned by git rev to the busbar commit in `.busbar-ref`; a busbar # build that links this crate `[patch]`es the busbar git source to its own tree, so ONE copy of the # contract links. -busbar-contract = { git = "https://github.com/GetBusbar/busbar", rev = "e1d3d8b097201859751d77208e66249d98b50a4b" } +busbar-contract = { workspace = true } # `bundled` compiles SQLite from source so the plugin has no system libsqlite3 dependency at all. -rusqlite = { version = "0.40.0", features = ["bundled"] } -serde_json = "1" +rusqlite = { workspace = true } +serde_json = { workspace = true } # `derive` for the v10 migration's legacy row encoders, the v3 dedupe log's stored answers (and the # conformance suite's stand-in bodies). -serde = { version = "1", features = ["derive"] } +serde = { workspace = true } # NO DEV-DEPENDENCIES. The `RecordStore` contract conformance suite lives in this crate's own # `src/tests/store_conformance.rs` (#2/#31 forbid a shared test util between plugins); all it needs is diff --git a/store-sqlite/declares.json b/store-sqlite/declares.json index 344abf0..985cfd5 100644 --- a/store-sqlite/declares.json +++ b/store-sqlite/declares.json @@ -1,6 +1,6 @@ { "contract_abi": { - "min": 3, - "max": 3 + "min": 4, + "max": 4 } } From 50d4aaaff2ecf4d9c91f7061ed6ab41ed69c4bdf Mon Sep 17 00:00:00 2001 From: Matthew Jackson <1085847+MattJackson@users.noreply.github.com> Date: Fri, 2 Oct 2026 08:53:36 -0700 Subject: [PATCH 2/2] fleet: one busbar pin for the whole fleet (8fc3b1b2a6d1) busbar-release plugin repin busbar-store-sqlite: busbar e1d3d8b097201859751d77208e66249d98b50a4b -> 8fc3b1b2a6d123575a77ce505e501b595fb24cef (1.6.0); .busbar-ref, every manifest's busbar rev, the busbar workflow refs and the rendered files at the new pin; Cargo.lock re-resolved from busbar's lock there. --- .busbar-ref | 2 +- .github/workflows/ci.yml | 2 +- .github/workflows/consumer-verify.yml | 2 +- .github/workflows/release.yml | 4 +-- .github/workflows/repin.yml | 2 +- Cargo.lock | 52 ++++----------------------- Cargo.toml | 20 +++++------ deny.toml | 8 ++--- store-sqlite-plugin/Cargo.toml | 2 +- 9 files changed, 26 insertions(+), 68 deletions(-) diff --git a/.busbar-ref b/.busbar-ref index 3e77816..8c266c0 100644 --- a/.busbar-ref +++ b/.busbar-ref @@ -1 +1 @@ -e1d3d8b097201859751d77208e66249d98b50a4b 1.6.0 +8fc3b1b2a6d123575a77ce505e501b595fb24cef 1.6.0 diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 546098c..d330adf 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -19,7 +19,7 @@ permissions: jobs: ci: - uses: GetBusbar/busbar/.github/workflows/plugin-ci.yml@e1d3d8b097201859751d77208e66249d98b50a4b + uses: GetBusbar/busbar/.github/workflows/plugin-ci.yml@8fc3b1b2a6d123575a77ce505e501b595fb24cef with: service: none busbar_checkout: true diff --git a/.github/workflows/consumer-verify.yml b/.github/workflows/consumer-verify.yml index e74d735..d5cd3f8 100644 --- a/.github/workflows/consumer-verify.yml +++ b/.github/workflows/consumer-verify.yml @@ -21,7 +21,7 @@ permissions: jobs: consumer: - uses: GetBusbar/busbar/.github/workflows/plugin-consumer-verify.yml@e1d3d8b097201859751d77208e66249d98b50a4b + uses: GetBusbar/busbar/.github/workflows/plugin-consumer-verify.yml@8fc3b1b2a6d123575a77ce505e501b595fb24cef with: version: ${{ inputs.version || '' }} asset_prefix: busbar-store-sqlite diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 0184e0b..f8ad8a8 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -25,7 +25,7 @@ jobs: secrets: inherit release: needs: ci - uses: GetBusbar/busbar/.github/workflows/plugin-release.yml@e1d3d8b097201859751d77208e66249d98b50a4b + uses: GetBusbar/busbar/.github/workflows/plugin-release.yml@8fc3b1b2a6d123575a77ce505e501b595fb24cef with: plugin_crate: busbar-store-sqlite-plugin manifest_name: busbar-store-sqlite @@ -41,7 +41,7 @@ jobs: consumer-verify: needs: release if: ${{ !cancelled() }} - uses: GetBusbar/busbar/.github/workflows/plugin-consumer-verify.yml@e1d3d8b097201859751d77208e66249d98b50a4b + uses: GetBusbar/busbar/.github/workflows/plugin-consumer-verify.yml@8fc3b1b2a6d123575a77ce505e501b595fb24cef with: version: ${{ github.ref_name }} asset_prefix: busbar-store-sqlite diff --git a/.github/workflows/repin.yml b/.github/workflows/repin.yml index 6491d62..3f6fe15 100644 --- a/.github/workflows/repin.yml +++ b/.github/workflows/repin.yml @@ -28,7 +28,7 @@ permissions: jobs: repin: - uses: GetBusbar/busbar/.github/workflows/plugin-repin.yml@e1d3d8b097201859751d77208e66249d98b50a4b + uses: GetBusbar/busbar/.github/workflows/plugin-repin.yml@8fc3b1b2a6d123575a77ce505e501b595fb24cef with: busbar_sha: ${{ github.event.client_payload.sha || inputs.busbar_sha }} busbar_version: ${{ github.event.client_payload.version || inputs.busbar_version }} diff --git a/Cargo.lock b/Cargo.lock index 03013bb..db5f9f7 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -70,7 +70,7 @@ checksum = "72f5acc6cb2ba439de613abc23857ec3d78374d8ed5ac84e9d11336e87da8649" [[package]] name = "busbar-contract" version = "1.6.0" -source = "git+https://github.com/GetBusbar/busbar?rev=e1d3d8b097201859751d77208e66249d98b50a4b#e1d3d8b097201859751d77208e66249d98b50a4b" +source = "git+https://github.com/GetBusbar/busbar?rev=8fc3b1b2a6d123575a77ce505e501b595fb24cef#8fc3b1b2a6d123575a77ce505e501b595fb24cef" dependencies = [ "async-trait", "futures", @@ -92,7 +92,7 @@ dependencies = [ [[package]] name = "busbar-kernel-ledger" version = "1.6.0" -source = "git+https://github.com/GetBusbar/busbar?rev=e1d3d8b097201859751d77208e66249d98b50a4b#e1d3d8b097201859751d77208e66249d98b50a4b" +source = "git+https://github.com/GetBusbar/busbar?rev=8fc3b1b2a6d123575a77ce505e501b595fb24cef#8fc3b1b2a6d123575a77ce505e501b595fb24cef" dependencies = [ "busbar-contract", "serde", @@ -102,7 +102,7 @@ dependencies = [ [[package]] name = "busbar-kernel-wal" version = "1.6.0" -source = "git+https://github.com/GetBusbar/busbar?rev=e1d3d8b097201859751d77208e66249d98b50a4b#e1d3d8b097201859751d77208e66249d98b50a4b" +source = "git+https://github.com/GetBusbar/busbar?rev=8fc3b1b2a6d123575a77ce505e501b595fb24cef#8fc3b1b2a6d123575a77ce505e501b595fb24cef" dependencies = [ "busbar-contract", "sha2 0.11.0", @@ -111,7 +111,7 @@ dependencies = [ [[package]] name = "busbar-plugin-loader" version = "1.5.0" -source = "git+https://github.com/GetBusbar/busbar?rev=e1d3d8b097201859751d77208e66249d98b50a4b#e1d3d8b097201859751d77208e66249d98b50a4b" +source = "git+https://github.com/GetBusbar/busbar?rev=8fc3b1b2a6d123575a77ce505e501b595fb24cef#8fc3b1b2a6d123575a77ce505e501b595fb24cef" dependencies = [ "async-trait", "busbar-contract", @@ -352,16 +352,6 @@ version = "1.0.2" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "877a4ace8713b0bcf2a4e7eec82529c029f1d0619886d18145fea96c3ffe5c0f" -[[package]] -name = "errno" -version = "0.3.14" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "39cab71617ae0d63f51a36d69f866391735b51691dbda63cf6f96d042b63efeb" -dependencies = [ - "libc", - "windows-sys 0.61.2", -] - [[package]] name = "fallible-iterator" version = "0.3.0" @@ -864,12 +854,6 @@ dependencies = [ "vcpkg", ] -[[package]] -name = "linux-raw-sys" -version = "0.12.1" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "32a66949e030da00e8c7d4434b251670a91556f4144941d37452769c25d58a53" - [[package]] name = "litemap" version = "0.8.2" @@ -945,9 +929,9 @@ dependencies = [ [[package]] name = "pkg-config" -version = "0.3.33" +version = "0.3.34" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "19f132c84eca552bf34cab8ec81f1c1dcc229b811638f9d283dceabe58c5569e" +checksum = "f6b464fbc74e149a392436b17d523f769e057cb6877f6a5c4618bc6f11800548" [[package]] name = "potential_utf" @@ -1175,19 +1159,6 @@ dependencies = [ "semver", ] -[[package]] -name = "rustix" -version = "1.1.4" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "b6fe4565b9518b83ef4f91bb47ce29620ca828bd32cb7e408f0062e9930ba190" -dependencies = [ - "bitflags", - "errno", - "libc", - "linux-raw-sys", - "windows-sys 0.61.2", -] - [[package]] name = "rustls" version = "0.23.45" @@ -1458,7 +1429,6 @@ checksum = "3f6221d9a6003c78398e3b239969f352578258df48c8eb051caadae0015bc840" dependencies = [ "filetime", "libc", - "xattr", ] [[package]] @@ -1918,16 +1888,6 @@ version = "0.6.3" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "1ffae5123b2d3fc086436f8834ae3ab053a283cfac8fe0a0b8eaae044768a4c4" -[[package]] -name = "xattr" -version = "1.6.1" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "32e45ad4206f6d2479085147f02bc2ef834ac85886624a23575ae137c8aa8156" -dependencies = [ - "libc", - "rustix", -] - [[package]] name = "yoke" version = "0.8.2" diff --git a/Cargo.toml b/Cargo.toml index fd6bded..01a0dce 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -10,8 +10,8 @@ # `.busbar-ref`; no sibling-checkout path dependency ships in any manifest. # # THIRD-PARTY VERSIONS ARE THE FLEET'S, NOT THIS REPO'S. The table below is busbar's own root -# `[workspace.dependencies]` (third-party rows) at busbar e1d3d8b097201859751d77208e66249d98b50a4b, followed by the plugin-only rows -# of busbar's `.github/fleet/deps.toml` at dd9637da0c849b811238e108cbafabcb4c7c22a2. A member takes a crate with +# `[workspace.dependencies]` (third-party rows) at busbar 8fc3b1b2a6d123575a77ce505e501b595fb24cef, followed by the plugin-only rows +# of busbar's `.github/fleet/deps.toml` at 8fc3b1b2a6d123575a77ce505e501b595fb24cef. A member takes a crate with # `{ workspace = true }` (adding features if it needs them); a crate in neither table is a new # `deps.toml` row in busbar first. CI holds this repo's Cargo.lock to busbar's lock at the pin. [workspace] @@ -29,15 +29,15 @@ publish = false repository = "https://github.com/GetBusbar/busbar-store-sqlite" [workspace.dependencies] -busbar-contract = { git = "https://github.com/GetBusbar/busbar", rev = "e1d3d8b097201859751d77208e66249d98b50a4b" } -busbar-plugin-loader = { git = "https://github.com/GetBusbar/busbar", rev = "e1d3d8b097201859751d77208e66249d98b50a4b" } -# busbar's root [workspace.dependencies], third-party rows, at e1d3d8b097201859751d77208e66249d98b50a4b +busbar-contract = { git = "https://github.com/GetBusbar/busbar", rev = "8fc3b1b2a6d123575a77ce505e501b595fb24cef" } +busbar-plugin-loader = { git = "https://github.com/GetBusbar/busbar", rev = "8fc3b1b2a6d123575a77ce505e501b595fb24cef" } +# busbar's root [workspace.dependencies], third-party rows, at 8fc3b1b2a6d123575a77ce505e501b595fb24cef a2a-lf = "0.3.0" a2a-pb = "0.2.0" arc-swap = "1" async-trait = "0.1" axum = "0.8" -base64 = "0.23" +base64 = "0.22" bumpalo = "3" bytes = "1" core_affinity = "0.8" @@ -59,7 +59,7 @@ hyper = { version = "1", default-features = false, features = ["server", "client hyper-rustls = { version = "0.27", default-features = false, features = ["http1", "http2", "ring", "webpki-tokio"] } hyper-util = { version = "0.1", default-features = false, features = ["client-legacy", "http1", "http2", "server-auto", "server-graceful", "service", "tokio"] } indexmap = { version = "2", features = ["serde"] } -jsonschema = "0.49" +jsonschema = { version = "0.49", default-features = false } libc = "0.2" libloading = "0.9" log = "0.4" @@ -73,7 +73,7 @@ opentelemetry-proto = { version = "0.32", default-features = false, features = [ proc-macro2 = { version = "1", features = ["span-locations"] } proptest = "1" prost = { version = "0.14", default-features = false, features = ["std"] } -rcgen = "0.14" +rcgen = { version = "0.14", default-features = false, features = ["crypto", "ring"] } reqwest = { version = "0.12", default-features = false, features = ["rustls-tls", "stream"] } ring = "0.17" rmcp = { version = "3.1.2", default-features = false } @@ -89,7 +89,7 @@ smallvec = "1" socket2 = { version = "0.6", features = ["all"] } sonic-rs = "0.5" syn = { version = "2", features = ["full", "visit", "parsing", "printing"] } -tar = "0.4" +tar = { version = "0.4", default-features = false } tikv-jemalloc-ctl = "0.6" tikv-jemallocator = "0.6" tokio = "1" @@ -108,7 +108,7 @@ url = "2" webpki = { package = "rustls-webpki", version = "0.103", default-features = false, features = ["std", "ring"] } webpki-roots = "1" zeroize = "1" -# busbar .github/fleet/deps.toml [plugin-deps], at dd9637da0c849b811238e108cbafabcb4c7c22a2 +# busbar .github/fleet/deps.toml [plugin-deps], at 8fc3b1b2a6d123575a77ce505e501b595fb24cef ldap3 = { version = "0.12", default-features = false, features = ["sync"] } mysql = { version = "26", default-features = false, features = ["minimal"] } postgres = "0.19" diff --git a/deny.toml b/deny.toml index 6cb499e..a76e4f0 100644 --- a/deny.toml +++ b/deny.toml @@ -1,5 +1,5 @@ # RENDERED by `busbar-release plugin sync` from GetBusbar/busbar-release template/ and busbar's -# `.github/fleet/deps.toml` at dd9637da0c849b811238e108cbafabcb4c7c22a2; a hand edit is overwritten by the next sync. CI runs +# `.github/fleet/deps.toml` at 8fc3b1b2a6d123575a77ce505e501b595fb24cef; a hand edit is overwritten by the next sync. CI runs # `cargo deny check` on it (busbar's plugin-ci.yml at the pin). The license allowlist is busbar's own; # the one reviewed git source is busbar itself, at the pin. [graph] @@ -136,8 +136,8 @@ deny = [ { crate = "prost:>=0.15.0", reason = "busbar resolves prost to 0.14.3; a plugin may not pull a second version (OWNER 2026-10-02)" }, { crate = "rcgen:<0.14.0", reason = "busbar resolves rcgen to 0.14.10; a plugin may not pull a second version (OWNER 2026-10-02)" }, { crate = "rcgen:>=0.15.0", reason = "busbar resolves rcgen to 0.14.10; a plugin may not pull a second version (OWNER 2026-10-02)" }, - { crate = "reqwest:<0.12.0", reason = "busbar resolves reqwest to 0.12.28, 0.13.4; a plugin may not pull a second version (OWNER 2026-10-02)" }, - { crate = "reqwest:>=0.14.0", reason = "busbar resolves reqwest to 0.12.28, 0.13.4; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "reqwest:<0.12.0", reason = "busbar resolves reqwest to 0.12.28; a plugin may not pull a second version (OWNER 2026-10-02)" }, + { crate = "reqwest:>=0.13.0", reason = "busbar resolves reqwest to 0.12.28; a plugin may not pull a second version (OWNER 2026-10-02)" }, { crate = "ring:<0.17.0", reason = "busbar resolves ring to 0.17.14; a plugin may not pull a second version (OWNER 2026-10-02)" }, { crate = "ring:>=0.18.0", reason = "busbar resolves ring to 0.17.14; a plugin may not pull a second version (OWNER 2026-10-02)" }, { crate = "rmcp:<3.0.0", reason = "busbar resolves rmcp to 3.1.2; a plugin may not pull a second version (OWNER 2026-10-02)" }, @@ -241,8 +241,6 @@ skip = [ { crate = "rand_core@0.10.1", reason = "busbar's own lock holds this duplicate" }, { crate = "rand_core@0.6.4", reason = "busbar's own lock holds this duplicate" }, { crate = "rand_core@0.9.5", reason = "busbar's own lock holds this duplicate" }, - { crate = "reqwest@0.12.28", reason = "busbar's own lock holds this duplicate" }, - { crate = "reqwest@0.13.4", reason = "busbar's own lock holds this duplicate" }, { crate = "sha2@0.10.9", reason = "busbar's own lock holds this duplicate" }, { crate = "sha2@0.11.0", reason = "busbar's own lock holds this duplicate" }, { crate = "syn@2.0.117", reason = "busbar's own lock holds this duplicate" }, diff --git a/store-sqlite-plugin/Cargo.toml b/store-sqlite-plugin/Cargo.toml index 79716ed..142939a 100644 --- a/store-sqlite-plugin/Cargo.toml +++ b/store-sqlite-plugin/Cargo.toml @@ -33,4 +33,4 @@ rusqlite = { workspace = true } # Dev-only: the admin-API install e2e test drives a REAL running busbar process's admin HTTP API # (POST /api/v1/admin/plugins, POST /api/v1/admin/keys) — the actual operator install path. reqwest = { workspace = true, features = ["json", "blocking"] } -base64 = "0.22" +base64 = { workspace = true }