-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathCargo.toml
More file actions
200 lines (186 loc) · 9.49 KB
/
Copy pathCargo.toml
File metadata and controls
200 lines (186 loc) · 9.49 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
# Quiver — Cargo workspace.
# Crate responsibilities and the dependency DAG: docs/architecture/overview.md
# Scaffold rationale: docs/repo-scaffold-plan.md
[workspace]
resolver = "3"
members = ["crates/*"]
[workspace.package]
version = "1.1.0"
edition = "2024"
# MSRV: 1.88 — the minimum the dependency tree supports (ratatui 0.30's
# `ratatui-core`/`-widgets`/`-crossterm`). Bumped from 1.85 when updating ratatui
# to clear the transitive `lru` advisory (RUSTSEC-2026-0002).
rust-version = "1.88"
license = "AGPL-3.0-only"
repository = "https://github.com/achref-soua/quiver"
homepage = "https://github.com/achref-soua/quiver"
authors = ["Achref Soua <achref.soua@outlook.com>"]
# crates.io discovery metadata, inherited by every crate via `*.workspace = true`.
# Categories are crates.io slugs; keywords are <=5 and <=20 chars each.
keywords = ["vector-database", "embeddings", "search", "ann", "hnsw"]
categories = ["database", "data-structures"]
# Shared lint policy applied by every crate via `[lints] workspace = true`.
# See ADR-0017 (error handling) and ADR-0009 (unsafe discipline).
[workspace.lints.rust]
unsafe_op_in_unsafe_fn = "deny"
missing_docs = "warn"
[workspace.lints.clippy]
unwrap_used = "deny"
expect_used = "deny"
dbg_macro = "deny"
todo = "warn"
# External dependencies are pinned once here and referenced from crates with
# `dep = { workspace = true }`. Added as features land.
[workspace.dependencies]
# Internal crates (path deps with a version so `cargo deny` sees no wildcard),
# referenced as `quiver-x = { workspace = true }`.
quiver-core = { path = "crates/quiver-core", version = "1.1", package = "quiverdb-core" }
quiver-cluster = { path = "crates/quiver-cluster", version = "1.1", package = "quiverdb-cluster" }
quiver-crypto = { path = "crates/quiver-crypto", version = "1.1", package = "quiverdb-crypto" }
quiver-embed = { path = "crates/quiver-embed", version = "1.1", package = "quiverdb-embed" }
quiver-import = { path = "crates/quiver-import", version = "1.1", package = "quiverdb-import" }
quiver-index = { path = "crates/quiver-index", version = "1.1", package = "quiverdb-index" }
quiver-mcp = { path = "crates/quiver-mcp", version = "1.1", package = "quiverdb-mcp" }
quiver-proto = { path = "crates/quiver-proto", version = "1.1", package = "quiverdb-proto" }
quiver-providers = { path = "crates/quiver-providers", version = "1.1", package = "quiverdb-providers" }
quiver-query = { path = "crates/quiver-query", version = "1.1", package = "quiverdb-query" }
quiver-server = { path = "crates/quiver-server", version = "1.1", package = "quiverdb-server" }
quiver-simd = { path = "crates/quiver-simd", version = "1.1", package = "quiverdb-simd" }
quiver-tui = { path = "crates/quiver-tui", version = "1.1", package = "quiverdb-tui" }
anyhow = "1"
# Lock-free atomic `Arc` swap for the MVCC serving snapshot (ADR-0064): readers
# `load()` without a lock, the single writer `store()`s a new snapshot, and
# reclamation is the `Arc` refcount — no `unsafe`, no epoch GC.
arc-swap = "1.7"
axum = "0.8"
# TLS-in-transit (ADR-0010): rustls with the audited `ring` provider — no
# OpenSSL, and no `aws-lc-rs` (which needs a C toolchain unavailable on minimal
# builders). `ring` backs the rustls AEAD/handshake; the at-rest codec below
# uses RustCrypto. `axum-server` terminates TLS for REST; tonic's `tls-ring`
# feature does so for gRPC.
axum-server = { version = "0.8", default-features = false, features = [
"tls-rustls-no-provider",
] }
rustls = { version = "0.23", default-features = false, features = [
"ring",
"std",
"tls12",
"logging",
] }
# Maintained PEM parsing (the `PemObject` trait), replacing the now-unmaintained
# `rustls-pemfile`. Already in the tree via rustls.
rustls-pki-types = { version = "1", features = ["std"] }
tokio-rustls = { version = "0.26", default-features = false, features = [
"ring",
"tls12",
"logging",
] }
# Audited cryptography (RustCrypto) for encryption-at-rest: XChaCha20-Poly1305
# AEAD, HKDF-SHA256 per-page subkeys, and zeroized key material. See ADR-0010
# and docs/security/crypto.md.
chacha20poly1305 = { version = "0.10", features = ["getrandom"] }
# Raw ChaCha20 keystream as the deterministic CSPRNG for DCPE Scale-And-Perturb
# (ADR-0031): the same audited RustCrypto cipher stack as the AEAD above
# (chacha20 0.9 / cipher 0.4), so no new major lands. HMAC-SHA256 (digest 0.10 /
# sha2 0.10) provides the DCPE ciphertext integrity tag.
chacha20 = "0.9"
hmac = "0.12"
# Compact, dependency-free encoding for the client-side payload envelope
# (ADR-0012): nonce and ciphertext are base64 strings so the JSON envelope is
# identical across the Rust reference implementation and the language SDKs.
base64 = "0.22"
clap = { version = "4.5", features = ["derive", "env"] }
crc32c = "0.6"
hkdf = "0.12"
# Memory-mapped reads for the disk-resident index (ADR-0019): only the touched
# (ciphertext) pages stay resident; the OS pages them in and out.
memmap2 = "0.9"
sha2 = "0.10"
zeroize = "1"
criterion = { version = "0.8", default-features = false, features = [
"cargo_bench_support",
] }
postcard = { version = "1.1", default-features = false, features = ["use-std"] }
prost = "0.14"
roaring = "0.11"
# Snowball (Porter2) stemmer for the BM25 tokenizer (ADR-0048). Pure Rust, MIT.
rust-stemmers = "1"
figment = { version = "0.10", features = ["env", "toml"] }
serde = { version = "1", features = ["derive"] }
serde_json = "1"
thiserror = "2"
tokio = { version = "1", features = ["rt-multi-thread", "macros", "net", "signal"] }
tokio-stream = { version = "0.1", features = ["net"] }
futures-util = "0.3"
tonic = { version = "0.14", features = ["tls-ring"] }
tonic-prost = "0.14"
tracing = "0.1"
tracing-subscriber = { version = "0.3", features = ["env-filter", "fmt"] }
# OpenTelemetry traces export (ADR-0059), opt-in behind quiver-server's `otlp`
# feature and an endpoint at runtime — off by default. The OTLP/gRPC transport
# reuses the tonic/prost already in the tree (no reqwest). cargo-deny verified
# clean over the full opentelemetry tree even with the feature off.
opentelemetry = "0.32"
opentelemetry_sdk = "0.32"
opentelemetry-otlp = { version = "0.32", default-features = false, features = [
"grpc-tonic",
"trace",
] }
tracing-opentelemetry = "0.33"
# Per-shard Raft for write high availability (ADR-0067), opt-in behind
# quiver-server's `raft` feature — off by default, so a default build never pulls
# it. `openraft` is the audited consensus core (the ADR-0065 adoption gate settled
# the pick: openraft 0.9 is cargo-deny clean and async-native; raft-rs fails on a
# protobuf advisory). `storage-v2` selects the split log-store/state-machine API
# (ADR-0067); `serde` makes the Raft types (de)serializable. The reusable generic
# in-memory `LogStore<C>` is vendored into quiver-server (the published
# `openraft-memstore` implements the deprecated v1 storage that `storage-v2`
# removes); a durable, ADR-0050-snapshot-backed store arrives in increment 4c.
openraft = { version = "0.9.24", features = ["serde", "storage-v2"] }
# Retro terminal cockpit (quiver-tui): ratatui renders; crossterm drives input
# (its version is pinned to the one ratatui re-exports so they share a single
# backend). The `event-stream` feature gives an async input stream. ratatui 0.30
# pulls a patched `lru` (>= 0.16.3), resolving RUSTSEC-2026-0002; default
# features are off so only the crossterm backend is pulled (no termwiz/wezterm).
crossterm = { version = "0.29", features = ["event-stream"] }
ratatui = { version = "0.30", default-features = false, features = ["crossterm"] }
# Build-time codegen for the gRPC contract. protoc is vendored so a clean clone
# builds with no system protobuf compiler installed.
tonic-prost-build = "0.14"
protoc-bin-vendored = "3"
# Live migration connectors (ADR-0027): a blocking HTTP client on rustls over
# `ring` (matching the transport TLS), with no async runtime — it carries the
# synchronous Qdrant and Chroma connectors, where `reqwest` (async, dev-only
# here) would not.
ureq = { version = "2", default-features = false, features = ["tls", "json"] }
# Live Postgres / pgvector connector (ADR-0029): the blocking rust-postgres
# client (a synchronous wrapper over tokio-postgres) reads each row as
# `row_to_json`, reusing the offline pgvector mapper. `with-serde_json-1` lets a
# row column decode straight into a serde_json::Value. tokio is already a
# workspace dependency (ADR-0002, the server); the embeddable engine
# (quiver-embed / quiver-core) stays tokio-free — only the import crate gains the
# driver.
postgres = { version = "0.19", features = ["with-serde_json-1"] }
# TLS for the Postgres connector over the same rustls/`ring` stack as the rest of
# Quiver — no OpenSSL and no `aws-lc-rs` C toolchain: default features off so only
# `ring` is pulled. Whether TLS is used is governed by `sslmode` in the URL.
tokio-postgres-rustls = { version = "0.14", default-features = false, features = [
"ring",
] }
# Mozilla CA roots to verify the Postgres TLS peer; pinned to the same 0.26 line
# `ureq` already uses, so no third webpki-roots major lands in the tree.
webpki-roots = "0.26"
# Icon embedding: ICO container writer for build.rs; winresource embeds the ICO
# into the Windows PE binary so Explorer / taskbar show the Quiver arrowhead.
ico = "0.5"
winresource = "0.1"
# Dev-only dependencies (tests, property tests, fixtures).
proptest = "1"
# Self-signed certificate generation for TLS tests, ring-backed (no aws-lc-rs).
rcgen = "0.14"
reqwest = { version = "0.13", default-features = false, features = ["json"] }
tempfile = "3"
[profile.release]
lto = "thin"
codegen-units = 1
strip = true