- Bump alkcall 0.8.0 -> 0.8.1 (duplicate adopt/open channel-state destruction fix from alkcall's fuzz campaign; AGENTS.md stale-pin fix). - Adopt fuzzing per docs/plans/fuzzing.md (mirrors alkcall's docs/research/fuzzing.md as-built layout): fuzz/ workspace with own [workspace] table, nightly pinned for the subtree only, invariant logic in a stable-toolchain shared crate. - Targets: chunk_frame (5-byte chunk codec), negotiation_frame (negotiation framing + NegotiateRequest + error_response_bytes + the cross-codec peek-disambiguation seam), control_json (ControlMessage JSON + signal_from_name). src/local/ out of scope (not wire-attacker-shaped). - 328 committed seeds (deterministic generator); grown corpora gitignored. Corpus replay on stable is the standing fuzz gate (cargo test --manifest-path fuzz/shared/Cargo.toml). - Detached-runner rule (fuzz/run-detached.sh): campaigns never run in the foreground of an agent session - OOM in a target must cost the fuzzer, never the session host. - Root Cargo.toml gained [workspace] members/exclude (MSRV vs fuzz nightly dev-deps footgun) and fuzz/ in the publish exclude. Verification: cargo test (113), cargo test --all-features (156), clippy stable + wasm32-unknown-unknown, fmt, doc, publish dry-run, corpus replay 328 seeds - all green. 10-min detached campaigns on all three targets: 0 crashes/hangs/OOMs/leaks (chunk_frame cov-saturated at 710 edges; negotiation_frame 3.69M execs cov 3157; control_json 8.6M execs cov 2035). Corpus replay caught three harness-model mismatches pre-campaign (payload-slice shape; the negotiation framing layer is length-prefix-only - Json unreachable from read_frame; zero-length frames admitted by the reader, rejected by the adapter's parse). Campaigns recorded in docs/plans/fuzzing.md section 8.
58 lines
2.0 KiB
TOML
58 lines
2.0 KiB
TOML
[package]
|
|
name = "alktty"
|
|
version = "0.5.0"
|
|
edition = "2021"
|
|
rust-version = "1.88"
|
|
license = "MIT OR Apache-2.0"
|
|
description = "Terminal session protocol: wire format, TtyBackend trait, TtyAdapter, and typed consumer client. Producer/consumer protocol crate on top of alkcall channels."
|
|
repository = "https://git.alk.dev/alkdev/alktty"
|
|
readme = "README.md"
|
|
keywords = ["tty", "terminal", "pty", "channels", "alkcall"]
|
|
categories = ["network-programming", "asynchronous"]
|
|
exclude = [".opencode/", "AGENTS.md", "docs/reviews/", "docs/plans/", "docs/sdd_process.md", "fuzz/"]
|
|
|
|
[workspace]
|
|
members = ["."]
|
|
exclude = ["fuzz"]
|
|
|
|
[lib]
|
|
name = "alktty"
|
|
|
|
[features]
|
|
default = []
|
|
# `local` is inherently non-wasm (portable-pty + tokio::process need a real
|
|
# OS). The default crate (no features) targets `wasm32-unknown-unknown`;
|
|
# enabling `local` on wasm is a build error by design — use a real OS for
|
|
# the local-process backend. The protocol crate (wire, negotiation,
|
|
# control, backend trait, adapter, session, channels) stays wasm-clean so
|
|
# downstream TS/Python adapters can compile it in a sandbox.
|
|
local = ["dep:portable-pty", "dep:tokio-util", "tokio/process", "tokio/rt-multi-thread"]
|
|
|
|
[dependencies]
|
|
alkcall = "0.8.1"
|
|
# Minimal, wasm-clean tokio features. `local` adds `process` +
|
|
# `rt-multi-thread` (non-wasm). Do NOT use `features = ["full"]` — it
|
|
# pulls in `signal`/`fs`/`net` which break `wasm32-unknown-unknown`.
|
|
tokio = { version = "1", default-features = false, features = ["rt", "sync", "io-util", "macros"] }
|
|
bytes = "1"
|
|
futures = "0.3"
|
|
futures-core = "0.3"
|
|
tokio-stream = "0.1"
|
|
serde = { version = "1", features = ["derive"] }
|
|
serde_json = "1"
|
|
async-trait = "0.1"
|
|
tracing = "0.1"
|
|
thiserror = "2"
|
|
|
|
portable-pty = { version = "0.9", optional = true }
|
|
tokio-util = { version = "0.7", features = ["io"], optional = true }
|
|
|
|
[target.'cfg(unix)'.dependencies]
|
|
libc = "0.2"
|
|
|
|
[dev-dependencies]
|
|
tokio = { version = "1", features = ["full", "test-util", "macros"] }
|
|
serde_json = "1"
|
|
tempfile = "3"
|
|
bytes = "1"
|