forked from unom/punktfunk
140 lines
7.8 KiB
TOML
140 lines
7.8 KiB
TOML
[package]
|
|
name = "punktfunk-core"
|
|
description = "punktfunk shared protocol/transport/FEC core, exposed over a stable C ABI"
|
|
version.workspace = true
|
|
edition.workspace = true
|
|
rust-version.workspace = true
|
|
license.workspace = true
|
|
authors.workspace = true
|
|
repository.workspace = true
|
|
|
|
[lib]
|
|
name = "punktfunk_core"
|
|
# `lib` — so punktfunk-host / punktfunk-probe / tools link it as a normal Rust crate.
|
|
# `staticlib` — `libpunktfunk_core.a` for the C test harness and static embedding.
|
|
# `cdylib` — `libpunktfunk_core.{so,dylib}` for Swift/Kotlin clients via the C ABI.
|
|
crate-type = ["lib", "cdylib", "staticlib"]
|
|
|
|
[features]
|
|
default = []
|
|
# Cert-fingerprint pinning shared across the clients (the one `PinVerify` in `tls.rs`). Light:
|
|
# rustls + sha2 only, no QUIC runtime — so a lean consumer (the tray's loopback status poll) can
|
|
# pin the host cert without pulling tokio/quinn. The heavier `quic` feature builds on top of it.
|
|
tls = ["dep:rustls", "dep:sha2", "dep:rustls-pki-types"]
|
|
# Control-plane QUIC (pairing, config, reverse audio). tokio is permitted ONLY here,
|
|
# never on the per-frame hot path. Off by default so the core stays runtime-free.
|
|
quic = ["tls", "dep:quinn", "dep:tokio", "dep:rcgen", "dep:hmac", "dep:spake2", "dep:opus"]
|
|
# Blocking-HTTP clients that must speak the SAME pinned TLS as the QUIC plane: `tls::ureq_agent`
|
|
# hands ureq a caller-built `rustls::ClientConfig` (which is how `PinVerify` gets installed —
|
|
# ureq's own `TlsConfig` has no hook for a custom verifier). Separate from `tls` because the
|
|
# cdylib/staticlib embedders (Apple, Android) pin the host themselves over QUIC and have no use
|
|
# for an HTTP stack; only the desktop clients and the tray turn this on.
|
|
ureq-tls = ["tls", "dep:ureq"]
|
|
|
|
[dependencies]
|
|
reed-solomon-simd = "3.1" # GF(2^16) Leopard-RS, SIMD, O(n log n) — the wall-breaker (P2)
|
|
# Vendored fork of fec-rs: GF(2^8) classic RS with the *Cauchy* generator matrix
|
|
# (M[j][i] = inv[(m+i)^j]) — byte-identical to the `nanors` library Moonlight uses, so our
|
|
# parity is decodable by a stock Moonlight client. (reed-solomon-erasure is Vandermonde and is
|
|
# NOT interoperable.) See vendor/fec-rs/LICENSE (BSD-2-Clause).
|
|
fec-rs = { path = "vendor/fec-rs" }
|
|
aes-gcm = "0.11" # AES-128-GCM session crypto, matches GameStream
|
|
# ChaCha20-Poly1305 session crypto, negotiated by clients without hardware AES (the soft-AES
|
|
# armv7 targets — webOS TVs — where GCM caps decrypt at ~100 Mbps; ARX runs 4-7x faster there).
|
|
# Same RustCrypto `aead 0.6` generation as aes-gcm: identical trait/nonce/tag shapes, pure Rust,
|
|
# cross-compiles like aes-gcm (no cmake). See design/chacha20-session-cipher.md.
|
|
chacha20poly1305 = "0.11"
|
|
zerocopy = { version = "0.8", features = ["derive"] }
|
|
socket2 = { version = "0.6", features = [
|
|
"all",
|
|
] } # SO_SNDBUF/SO_RCVBUF growth (default UDP buffers too small for 4K/5K bursts) + DSCP/SO_PRIORITY media QoS
|
|
thiserror = "2"
|
|
tracing = { version = "0.1", default-features = false, features = ["std"] }
|
|
rand = "0.9"
|
|
zeroize = "1"
|
|
# Interface enumeration for Wake-on-LAN: computes each NIC's subnet-directed broadcast so a
|
|
# magic packet reaches the host's L2 segment on multi-homed clients (VPN/docker/multiple LANs),
|
|
# not just the default route. Tiny, cross-platform (getifaddrs / GetAdaptersAddresses), no cmake.
|
|
# `link-local` is named EXPLICITLY, not inherited. mdns-sd declares if-addrs with it, so any build
|
|
# containing both (every host and every client) unifies it on regardless — and a crate whose
|
|
# enumeration silently changes depending on who else is in the selection is the worst of both. On
|
|
# means fe80::/169.254 interfaces are enumerated too, which for WoL is the behaviour we want: a NIC
|
|
# is wake-capable whether or not it currently holds a routable address.
|
|
if-addrs = { version = "0.15", features = ["link-local"] }
|
|
|
|
# Crypto backend is aws-lc-rs, and rustls/quinn/rcgen must all name it: they each select a
|
|
# backend independently, so one dissenter pulls a SECOND crypto stack in via feature unification.
|
|
# `prefer-post-quantum` puts the X25519MLKEM768 hybrid key exchange first in the TLS 1.3
|
|
# handshake, which is the reason the old `ring` pin is gone — ring has no ML-KEM.
|
|
# Windows needs no NASM: rustls's `aws_lc_rs` feature enables `aws-lc-rs/prebuilt-nasm`.
|
|
# quinn's feature list is its own default set with `rustls-ring` swapped out, nothing more.
|
|
quinn = { version = "0.11", optional = true, default-features = false, features = [
|
|
"log",
|
|
"platform-verifier",
|
|
"runtime-tokio",
|
|
"rustls-aws-lc-rs",
|
|
"bloom",
|
|
] }
|
|
rustls = { version = "0.23", optional = true, default-features = false, features = ["aws_lc_rs", "prefer-post-quantum", "std"] }
|
|
# `generate_simple_self_signed` is backend-agnostic, so the swap is transparent here.
|
|
rcgen = { version = "0.14", optional = true, default-features = false, features = ["aws_lc_rs", "pem"] }
|
|
rustls-pki-types = { version = "1", optional = true }
|
|
# `rustls-no-provider`, NOT the default `rustls` feature — ureq's `rustls` feature body pulls
|
|
# `_ring`, which would drag the whole ring backend back into a tree that has deliberately moved to
|
|
# aws-lc-rs. `rustls-webpki-roots` supplies the CA set for the non-pinned origins (cover-art CDNs).
|
|
ureq = { version = "3", optional = true, default-features = false, features = [
|
|
"rustls-no-provider",
|
|
"rustls-webpki-roots",
|
|
"gzip",
|
|
] }
|
|
sha2 = { version = "0.11", optional = true }
|
|
hmac = { version = "0.13", optional = true }
|
|
spake2 = { version = "0.4", optional = true }
|
|
tokio = { version = "1", optional = true, features = ["rt-multi-thread", "net", "sync", "macros"] }
|
|
# In-core Opus (multistream) DECODE for the C-ABI `punktfunk_connection_next_audio_pcm` path —
|
|
# used by embedders without a multistream-capable Opus decoder (Apple's AudioToolbox is
|
|
# stereo-only). The Rust clients link `opus` themselves and decode the raw `next_audio` frames,
|
|
# so this only matters when the connection API (quic) is built. Same libopus the host vendors;
|
|
# cargo unifies the build. Multistream API: `opus::MSDecoder` (lib.rs:1187).
|
|
opus = { version = "0.3", optional = true }
|
|
|
|
# `libc` for batched UDP syscalls: `sendmmsg`/`recvmmsg` on Linux (the 1 Gbps+ lever) and the
|
|
# `recv(MSG_DONTWAIT)` drain on the other unix (Apple/BSD) targets, which have no `recvmmsg`
|
|
# (see transport/udp.rs `recv_batch`). Needed on every unix target — non-unix (Windows) uses
|
|
# the scalar fallbacks. Cross-compiles (iOS/tvOS) don't pull libc transitively the way the
|
|
# macOS host build does, so it must be a direct dep here or those slices fail to link `libc::`.
|
|
[target.'cfg(unix)'.dependencies]
|
|
libc = "0.2"
|
|
|
|
# Windows UDP Send Offload (USO): `WSASendMsg` + `UDP_SEND_MSG_SIZE` is the Windows analogue of
|
|
# Linux UDP GSO — the 1 Gbps+ send lever (the host otherwise sends one packet per `send` syscall,
|
|
# which caps throughput at high packet rates). See transport/udp.rs.
|
|
[target.'cfg(windows)'.dependencies]
|
|
# windows-sys (raw FFI, the quinn-udp choice): the high-level `windows` crate doesn't bind the
|
|
# `WSASendMsg` extension function. WinSock feature gives WSASendMsg + WSAMSG/WSABUF/CMSGHDR.
|
|
# Win32_System_IO too: WSASendMsg's signature references OVERLAPPED, so it's gated on that feature.
|
|
# Win32_NetworkManagement_QoS + Win32_Foundation: the qWAVE flow API for real on-the-wire DSCP
|
|
# marking (transport/qos_windows.rs) — plain IP_TOS is stripped by the Windows stack.
|
|
windows-sys = { version = "0.59", features = [
|
|
"Win32_Networking_WinSock",
|
|
"Win32_System_IO",
|
|
"Win32_Foundation",
|
|
"Win32_NetworkManagement_QoS",
|
|
] }
|
|
|
|
[dev-dependencies]
|
|
proptest = "1"
|
|
# Tier-1 microbenchmarks (benches/pipeline.rs). default-features off → no plotters/HTML (headless
|
|
# CI just needs the measurement + target/criterion/**/estimates.json for the regression compare).
|
|
criterion = { version = "0.8", default-features = false, features = ["cargo_bench_support"] }
|
|
|
|
[[bench]]
|
|
name = "pipeline"
|
|
harness = false
|
|
|
|
[build-dependencies]
|
|
cbindgen = "0.29"
|
|
|
|
[lints]
|
|
workspace = true
|