Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1,808 changes: 1,115 additions & 693 deletions Cargo.lock

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -45,9 +45,9 @@ description = "Self-hosted, end-to-end-encrypted chat, voice, and screen-share s
repository = "https://github.com/Fossferous/Puca"

[dependencies]
axum = { version = "0.7", features = ["ws", "multipart"] }
axum = { version = "0.8", features = ["ws", "multipart"] }
tokio = { version = "1", features = ["full"] }
sqlx = { version = "0.8", features = ["postgres", "runtime-tokio", "tls-native-tls", "chrono"] }
sqlx = { version = "0.9", features = ["postgres", "runtime-tokio", "tls-native-tls", "chrono"] }
serde = { version = "1", features = ["derive"] }
serde_json = "1"
# mediasoup = "0.20"
Expand All @@ -58,51 +58,51 @@ tracing = "0.1"
tracing-subscriber = { version = "0.3", features = ["env-filter", "fmt", "registry"] }
anyhow = "1.0"
hex = "0.4"
sha2 = "0.10"
sha2 = "0.11"
chrono = { version = "0.4", features = ["serde"] }
rand = "0.8"
rand = "0.10"
dotenv = "0.15"
uuid = { version = "1", features = ["v4", "fast-rng"] }
dashmap = "6.1.0"
jsonwebtoken = { version = "10.2.0", features = ["rust_crypto"] }
jsonwebtoken = { version = "11.0.0", features = ["rust_crypto"] }
futures = "0.3.31"
tower-http = { version = "0.6.7", features = ["cors", "fs"] }
tower_governor = "0.4.2"
governor = "0.6.3"
tower-http = { version = "0.7.1", features = ["cors", "fs"] }
tower_governor = "0.8.0"
governor = "0.10.4"
tokio-util = { version = "0.7", features = ["io"] }
# For TURN credential generation
hmac = "0.12"
sha1 = "0.10"
base64 = "0.22"
hmac = "0.13"
sha1 = "0.11"
base64 = "0.23"
# E2EE account recovery: X25519 DH proof-of-possession + HKDF (must match the
# frontend's @noble x25519/hkdf byte-for-byte).
x25519-dalek = { version = "2", features = ["static_secrets"] }
x25519-dalek = { version = "3", features = ["static_secrets"] }
# Device attestation: verifies the Ed25519 signature a client produces to prove
# WHICH of the account's devices a connection is (see ws.rs). Already present
# transitively via jsonwebtoken; promoted to a direct dependency because we now
# call it ourselves.
ed25519-dalek = "2"
ed25519-dalek = "3"
# The wake transport is a trait object (src/wake) so the FCM doorbell, the
# no-credentials no-op and test recorders are interchangeable — what makes the
# layer testable without a Firebase project. Already present transitively;
# promoted because we call it ourselves (same as ed25519-dalek above).
async-trait = "0.1"
hkdf = "0.12"
hkdf = "0.13"
# For email sending
lettre = { version = "0.11", features = ["tokio1-native-tls", "builder", "smtp-transport"] }
# Used by the SFU control plane for the LiveKit RemoveParticipant admin call
# (src/sfu.rs), so it must be a real dependency, not dev-only.
reqwest = { version = "0.11", features = ["json", "blocking"] }
reqwest = { version = "0.13", features = ["json", "blocking"] }

[dev-dependencies]
axum-test = "14"
tower = "0.4"
axum-test = "21"
tower = "0.5"
tokio-test = "0.4"
rsa = { version = "0.9", features = ["pem"] } # test-only: mints the throwaway FCM signing key in-process
# Cross-language known-answer test for the media frame AEAD (tests/media_aead_kat.rs).
# The SERVER never encrypts media — it relays opaque frames — so this is a dev
# dependency only. The native host agent (Phase 6) will take it as a real one.
aes-gcm = "0.10"
aes-gcm = "0.11"

# Workaround for Windows PDB linker errors (LNK1318)
# WORKSPACE-WIDE since the [workspace] above: a root profile governs every
Expand Down
20 changes: 10 additions & 10 deletions crates/puca-agent/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -37,25 +37,25 @@ puca-rtc = { path = "../puca-rtc" }
# MD5(username:realm:password). The same hmac/sha1 the SERVER already uses to
# mint these REST credentials, so the two ends of the scheme agree by
# construction rather than by two independent implementations of it.
hmac = "0.12"
hmac = "0.13"
# The device-control session key now lives in the agent rather than above it —
# see src/control_key.rs for why. Versions match the root Cargo.toml so the two
# implementations of the same wire format cannot drift apart.
hkdf = "0.12"
sha2 = "0.10"
aes-gcm = "0.10"
getrandom = "0.2"
x25519-dalek = { version = "2", features = ["static_secrets"] }
sha1 = "0.10"
md-5 = "0.10"
hkdf = "0.13"
sha2 = "0.11"
aes-gcm = "0.11"
getrandom = "0.4"
x25519-dalek = { version = "3", features = ["static_secrets"] }
sha1 = "0.11"
md-5 = "0.11"
# The agent owns the socket and the clock, so it drives str0m directly rather
# than through puca-rtc — sans-IO means the event loop lives with whoever
# has the socket.
str0m = "0.23"
base64 = "0.23.0"

[target.'cfg(windows)'.dependencies]
windows = { version = "0.58", features = [
windows = { version = "0.62", features = [
"Win32_Foundation",
"Win32_Storage_FileSystem",
"Win32_System_Pipes",
Expand Down Expand Up @@ -97,7 +97,7 @@ vp8 = ["puca-encode/vp8"]
# Only to PLAY the controller in tests: sign a real unattended-access challenge
# the way a peer would, so the authorisation gate is exercised end to end
# rather than stubbed into always-true.
ed25519-dalek = "2"
ed25519-dalek = "3"

# The Unix-socket transport (src/unix_sock.rs): SO_PEERCRED, getuid/getppid,
# dup2 for the log redirect. Linux only — that is the platform with capture
Expand Down
6 changes: 3 additions & 3 deletions crates/puca-capture/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ license = "AGPL-3.0-or-later"
# screen) — but neither can WGC, and that boundary belongs to the SYSTEM service
# work regardless.
[target.'cfg(windows)'.dependencies]
windows = { version = "0.58", features = [
windows = { version = "0.62", features = [
"Win32_Foundation",
"Win32_Graphics_Dxgi",
"Win32_Graphics_Dxgi_Common",
Expand All @@ -38,10 +38,10 @@ windows = { version = "0.58", features = [
# a persisted restore_token plus PipeWire, which is a much larger piece — and
# per the plan, X11 first covers most self-hosters at about a third of the cost.
[target.'cfg(target_os = "linux")'.dependencies]
x11rb = { version = "0.13", default-features = false, features = ["shm"] }
x11rb = { version = "0.14", default-features = false, features = ["shm"] }

# The X11 live test draws a known colour on the display and asserts the capture
# returns exactly that -- an assertion a stub or a black buffer cannot pass.
# Drawing needs the same X client the implementation uses.
[target.'cfg(target_os = "linux")'.dev-dependencies]
x11rb = { version = "0.13", default-features = false, features = ["shm"] }
x11rb = { version = "0.14", default-features = false, features = ["shm"] }
2 changes: 1 addition & 1 deletion crates/puca-encode/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ puca-capture = { path = "../puca-capture" }
# software MFT has a fixed CLSID and the hardware ones must be enumerated and
# driven asynchronously. See the header of src/windows_impl.rs.
[target.'cfg(windows)'.dependencies]
windows = { version = "0.58", features = [
windows = { version = "0.62", features = [
"Win32_Foundation",
"Win32_Media_MediaFoundation",
"Win32_System_Com",
Expand Down
8 changes: 4 additions & 4 deletions crates/puca-input/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -51,8 +51,8 @@ puca-capture = { path = "../puca-capture" }
# that silently accepted input it cannot inject would look connected and do
# nothing.
[target.'cfg(windows)'.dependencies]
sysinfo = "0.32"
windows = { version = "0.58", features = [
sysinfo = "0.39"
windows = { version = "0.62", features = [
"Win32_Foundation",
"Win32_UI_WindowsAndMessaging",
"Win32_UI_Input_KeyboardAndMouse",
Expand All @@ -67,10 +67,10 @@ windows = { version = "0.58", features = [
# /dev/uinput -- which is why it is the X11 path and uinput is left to the
# Wayland work, where a portal is required anyway.
[target.'cfg(target_os = "linux")'.dependencies]
x11rb = { version = "0.13", default-features = false, features = ["xtest"] }
x11rb = { version = "0.14", default-features = false, features = ["xtest"] }

# The live injection test asserts on OBSERVED EFFECT -- where the pointer landed
# and which key event a real window received -- so it needs its own X client to
# create that window and read those events back.
[target.'cfg(target_os = "linux")'.dev-dependencies]
x11rb = { version = "0.13", default-features = false, features = ["xtest"] }
x11rb = { version = "0.14", default-features = false, features = ["xtest"] }
18 changes: 9 additions & 9 deletions crates/puca-service/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -11,15 +11,15 @@ publish = false
# The machine identity: its own device keypair, kept where no other account
# can read it. Versions match the root Cargo.toml so two implementations of one
# wire format cannot drift.
x25519-dalek = { version = "2", features = ["static_secrets"] }
ed25519-dalek = "2"
sha2 = "0.10"
base64 = "0.22"
x25519-dalek = { version = "3", features = ["static_secrets"] }
ed25519-dalek = "3"
sha2 = "0.11"
base64 = "0.23"
serde = { version = "1", features = ["derive"] }
serde_json = "1"
# Launch tokens come from the OS RNG: two agents started in the same millisecond
# (a fast-user-switch) must not share a secret.
getrandom = "0.2"
getrandom = "0.4"
# The unattended-access record: the machine-scope copy the agent is armed from.
puca-ua = { path = "../puca-ua" }

Expand All @@ -32,11 +32,11 @@ puca-ua = { path = "../puca-ua" }
#
# `current_thread`: one socket, one timer, one rare datagram.
tokio = { version = "1", features = ["rt", "macros", "net", "time", "io-util", "sync"] }
tokio-tungstenite = { version = "0.21", features = ["native-tls"] }
tokio-tungstenite = { version = "0.29", features = ["native-tls"] }
futures-util = { version = "0.3", default-features = false, features = ["sink", "std"] }
# Shares the TLS stack with tokio-tungstenite's native-tls rather than pulling
# in a second one.
reqwest = { version = "0.11", default-features = false, features = ["json", "native-tls"] }
reqwest = { version = "0.13", default-features = false, features = ["json", "native-tls"] }

[lib]
name = "puca_service"
Expand All @@ -61,8 +61,8 @@ tauri-winres = "0.3"
# state machine, SESSION_CHANGE plumbing) is fiddly and cannot be unit-tested
# without installing — so it is delegated to the established windows-service
# crate rather than hand-rolled in raw windows-rs.
windows-service = "0.7"
windows = { version = "0.58", features = [
windows-service = "0.8"
windows = { version = "0.62", features = [
"Win32_Foundation",
"Win32_Security",
"Win32_System_Pipes",
Expand Down
2 changes: 1 addition & 1 deletion crates/puca-spike-s5/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ path = "src/main.rs"
# the whole design down the wrong road.
puca-capture = { path = "../puca-capture" }
puca-input = { path = "../puca-input" }
windows = { version = "0.58", features = [
windows = { version = "0.62", features = [
"Win32_Foundation",
"Win32_Graphics_Gdi",
"Win32_Security",
Expand Down
4 changes: 2 additions & 2 deletions crates/puca-ua/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -10,11 +10,11 @@ publish = false
# Ed25519 verification only. The host never derives the key from the passphrase
# — the controller does that with Argon2id and signs — so nothing here needs a
# password KDF. verify_strict rejects the malleability plain verify tolerates.
ed25519-dalek = "2"
ed25519-dalek = "3"
serde = { version = "1", features = ["derive"] }
# Just for the challenge nonce. No rand feature on ed25519-dalek: test keypairs
# are built deterministically from fixed seeds.
getrandom = "0.2"
getrandom = "0.4"

[dev-dependencies]
serde_json = "1"
14 changes: 7 additions & 7 deletions crates/puca-waker/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -11,20 +11,20 @@ publish = false
# a multi-threaded runtime on a box already running Postgres, Caddy and coturn
# would be pure overhead.
tokio = { version = "1", features = ["rt", "macros", "net", "time", "signal", "io-util"] }
tokio-tungstenite = { version = "0.21", features = ["native-tls"] }
tokio-tungstenite = { version = "0.29", features = ["native-tls"] }
futures-util = { version = "0.3", default-features = false, features = ["sink", "std"] }

# The whole runtime crypto surface: sign the attestation transcript. Everything
# else the waker presents (device id, auth record, auth signature) is static
# text produced once at provisioning and read from a file.
ed25519-dalek = "2"
x25519-dalek = { version = "2", features = ["static_secrets"] }
sha2 = "0.10"
base64 = "0.22"
getrandom = "0.2"
ed25519-dalek = "3"
x25519-dalek = { version = "3", features = ["static_secrets"] }
sha2 = "0.11"
base64 = "0.23"
getrandom = "0.4"

serde = { version = "1", features = ["derive"] }
serde_json = "1"
# Shares the TLS stack with tokio-tungstenite's native-tls rather than pulling
# in a second one.
reqwest = { version = "0.11", default-features = false, features = ["json", "native-tls"] }
reqwest = { version = "0.13", default-features = false, features = ["json", "native-tls"] }
Loading