`packaging/windows/drivers/*` has run `deny(unsafe_op_in_unsafe_fn)` +
`deny(clippy::undocumented_unsafe_blocks)` for a while, with `forbid(unsafe_code)`
on the modules that need no unsafe at all. The main workspace had no lint config
whatsoever, so nothing stopped a clean crate from quietly growing an `unsafe`, and
nothing distinguished the handful of genuinely-unsafe lines inside a 600-line
`unsafe fn` from the safe ones surrounding them.
Three things, all mechanical:
* `#![forbid(unsafe_code)]` on the eight crates that already contain zero unsafe
(`pf-driver-proto`, `pf-host-config`, `pf-paths`, the three clean clients, both
tools). These were clean by accident, not by contract; now they are clean by
contract.
* `unsafe_op_in_unsafe_fn = "warn"` workspace-wide. `unsafe fn` states a contract
the CALLER must uphold — it was never meant to switch off checking for the whole
body. Measured fallout is 300 sites on Linux, and they are concentrated: six
files carry all of them, while `punktfunk-core`, `pf-frame`, `pf-clipboard` and
`pf-vdisplay` are already at zero. `warn` (not `deny`) so the build stays green
while those six are worked down; it flips to `deny` once they are. This is also
the Rust 2024 default, so it pays off the edition migration early.
* `proc::current_uid()` replaces eight `unsafe { libc::getuid() }` blocks. Each
site had copied out the same SAFETY note verbatim, which is the tell: `getuid()`
is parameterless, always succeeds and touches no memory, so there is no contract
for a caller to uphold and no reason for the unsafe to be visible eight times.
One `unsafe` behind a safe wrapper, none at the call sites.
Verified: `pf-vdisplay` builds clean on Linux (Nobara) at zero E0133; the
macOS-buildable crates build clean locally. No behaviour change.
113 lines
6.0 KiB
TOML
113 lines
6.0 KiB
TOML
[package]
|
|
name = "punktfunk-core"
|
|
description = "punktfunk shared protocol/transport/FEC core, exposed over a stable C ABI"
|
|
version.workspace = true
|
|
edition.workspace = true
|
|
rust-version.workspace = true
|
|
license.workspace = true
|
|
authors.workspace = true
|
|
repository.workspace = true
|
|
|
|
[lib]
|
|
name = "punktfunk_core"
|
|
# `lib` — so punktfunk-host / punktfunk-probe / tools link it as a normal Rust crate.
|
|
# `staticlib` — `libpunktfunk_core.a` for the C test harness and static embedding.
|
|
# `cdylib` — `libpunktfunk_core.{so,dylib}` for Swift/Kotlin clients via the C ABI.
|
|
crate-type = ["lib", "cdylib", "staticlib"]
|
|
|
|
[features]
|
|
default = []
|
|
# Cert-fingerprint pinning shared across the clients (the one `PinVerify` in `tls.rs`). Light:
|
|
# rustls + sha2 only, no QUIC runtime — so a lean consumer (the tray's loopback status poll) can
|
|
# pin the host cert without pulling tokio/quinn. The heavier `quic` feature builds on top of it.
|
|
tls = ["dep:rustls", "dep:sha2", "dep:rustls-pki-types"]
|
|
# Control-plane QUIC (pairing, config, reverse audio). tokio is permitted ONLY here,
|
|
# never on the per-frame hot path. Off by default so the core stays runtime-free.
|
|
quic = ["tls", "dep:quinn", "dep:tokio", "dep:rcgen", "dep:hmac", "dep:spake2", "dep:opus"]
|
|
|
|
[dependencies]
|
|
reed-solomon-simd = "3.1" # GF(2^16) Leopard-RS, SIMD, O(n log n) — the wall-breaker (P2)
|
|
# Vendored fork of fec-rs: GF(2^8) classic RS with the *Cauchy* generator matrix
|
|
# (M[j][i] = inv[(m+i)^j]) — byte-identical to the `nanors` library Moonlight uses, so our
|
|
# parity is decodable by a stock Moonlight client. (reed-solomon-erasure is Vandermonde and is
|
|
# NOT interoperable.) See vendor/fec-rs/LICENSE (BSD-2-Clause).
|
|
fec-rs = { path = "vendor/fec-rs" }
|
|
aes-gcm = "0.10" # AES-128-GCM session crypto, matches GameStream
|
|
# ChaCha20-Poly1305 session crypto, negotiated by clients without hardware AES (the soft-AES
|
|
# armv7 targets — webOS TVs — where GCM caps decrypt at ~100 Mbps; ARX runs 4-7x faster there).
|
|
# Same RustCrypto `aead 0.5` generation as aes-gcm: identical trait/nonce/tag shapes, pure Rust,
|
|
# cross-compiles like aes-gcm (no cmake). See design/chacha20-session-cipher.md.
|
|
chacha20poly1305 = "0.10"
|
|
zerocopy = { version = "0.8", features = ["derive"] }
|
|
bytes = "1"
|
|
socket2 = { version = "0.6", features = [
|
|
"all",
|
|
] } # SO_SNDBUF/SO_RCVBUF growth (default UDP buffers too small for 4K/5K bursts) + DSCP/SO_PRIORITY media QoS
|
|
thiserror = "2"
|
|
tracing = { version = "0.1", default-features = false, features = ["std"] }
|
|
rand = "0.9"
|
|
zeroize = "1"
|
|
# Interface enumeration for Wake-on-LAN: computes each NIC's subnet-directed broadcast so a
|
|
# magic packet reaches the host's L2 segment on multi-homed clients (VPN/docker/multiple LANs),
|
|
# not just the default route. Tiny, cross-platform (getifaddrs / GetAdaptersAddresses), no cmake.
|
|
if-addrs = "0.13"
|
|
|
|
quinn = { version = "0.11", optional = true }
|
|
rustls = { version = "0.23", optional = true, default-features = false, features = ["ring", "std"] }
|
|
# Crypto backend pinned to `ring` (matching rustls/quinn above) so the whole quic tree is
|
|
# ring-only: no aws-lc-rs/aws-lc-sys (heavy C dep, needs cmake) is pulled in. Keeps the
|
|
# Android/iOS cdylib lean and the cross-compile cmake-free. `generate_simple_self_signed`
|
|
# is backend-agnostic, so the swap is transparent.
|
|
rcgen = { version = "0.13", optional = true, default-features = false, features = ["ring", "pem"] }
|
|
rustls-pki-types = { version = "1", optional = true }
|
|
sha2 = { version = "0.10", optional = true }
|
|
hmac = { version = "0.12", optional = true }
|
|
spake2 = { version = "0.4", optional = true }
|
|
tokio = { version = "1", optional = true, features = ["rt-multi-thread", "net", "sync", "macros"] }
|
|
# In-core Opus (multistream) DECODE for the C-ABI `punktfunk_connection_next_audio_pcm` path —
|
|
# used by embedders without a multistream-capable Opus decoder (Apple's AudioToolbox is
|
|
# stereo-only). The Rust clients link `opus` themselves and decode the raw `next_audio` frames,
|
|
# so this only matters when the connection API (quic) is built. Same libopus the host vendors;
|
|
# cargo unifies the build. Multistream API: `opus::MSDecoder` (lib.rs:1187).
|
|
opus = { version = "0.3", optional = true }
|
|
|
|
# `libc` for batched UDP syscalls: `sendmmsg`/`recvmmsg` on Linux (the 1 Gbps+ lever) and the
|
|
# `recv(MSG_DONTWAIT)` drain on the other unix (Apple/BSD) targets, which have no `recvmmsg`
|
|
# (see transport/udp.rs `recv_batch`). Needed on every unix target — non-unix (Windows) uses
|
|
# the scalar fallbacks. Cross-compiles (iOS/tvOS) don't pull libc transitively the way the
|
|
# macOS host build does, so it must be a direct dep here or those slices fail to link `libc::`.
|
|
[target.'cfg(unix)'.dependencies]
|
|
libc = "0.2"
|
|
|
|
# Windows UDP Send Offload (USO): `WSASendMsg` + `UDP_SEND_MSG_SIZE` is the Windows analogue of
|
|
# Linux UDP GSO — the 1 Gbps+ send lever (the host otherwise sends one packet per `send` syscall,
|
|
# which caps throughput at high packet rates). See transport/udp.rs.
|
|
[target.'cfg(windows)'.dependencies]
|
|
# windows-sys (raw FFI, the quinn-udp choice): the high-level `windows` crate doesn't bind the
|
|
# `WSASendMsg` extension function. WinSock feature gives WSASendMsg + WSAMSG/WSABUF/CMSGHDR.
|
|
# Win32_System_IO too: WSASendMsg's signature references OVERLAPPED, so it's gated on that feature.
|
|
# Win32_NetworkManagement_QoS + Win32_Foundation: the qWAVE flow API for real on-the-wire DSCP
|
|
# marking (transport/qos_windows.rs) — plain IP_TOS is stripped by the Windows stack.
|
|
windows-sys = { version = "0.59", features = [
|
|
"Win32_Networking_WinSock",
|
|
"Win32_System_IO",
|
|
"Win32_Foundation",
|
|
"Win32_NetworkManagement_QoS",
|
|
] }
|
|
|
|
[dev-dependencies]
|
|
proptest = "1"
|
|
# Tier-1 microbenchmarks (benches/pipeline.rs). default-features off → no plotters/HTML (headless
|
|
# CI just needs the measurement + target/criterion/**/estimates.json for the regression compare).
|
|
criterion = { version = "0.5", default-features = false, features = ["cargo_bench_support"] }
|
|
|
|
[[bench]]
|
|
name = "pipeline"
|
|
harness = false
|
|
|
|
[build-dependencies]
|
|
cbindgen = "0.29"
|
|
|
|
[lints]
|
|
workspace = true
|