Files
KKRainbow 7af7bdc16a build: consolidate dependencies and select rustls ring explicitly (#2648)
* build(core): consolidate crypto dependencies and trim features

Align AES-GCM, ChaCha20Poly1305, HMAC, SHA2 and HKDF with the versions
already required by Snow and STUN. Align base64 with pbjson, and explain
the coordinated upgrade constraints beside the manifest entries. Adapt
AEAD and HMAC calls without changing packet or key formats, and pin the
WireGuard client key derivation with an independent HKDF vector.

Limit Snow to the Noise algorithms used by the core. Use crossbeam-utils
directly, keep the futures executor in tests, and remove UUID fast-rng
from the core while retaining existing features in native consumers.
Enable browser entropy and certificate time for the rustls backend.

Core default normal/build dependencies fall from 255 to 224 packages;
duplicated package names fall from 24 to 5 against upstream 4837468d.

Validation: Docker tests pass: 970 core, 33 proto (2 ignored), 5
WireGuard, and TCP/UDP three-node encrypted relays. Clippy passes with
warnings denied for core, proto, native and web targets. Browser
default/ChaCha20, WASI and minimal native compile checks pass. Workspace
formatting passes.

* fix(tls): select ring explicitly across application entry points

Building easytier and easytier-web together enabled both ring and aws-lc
through reqwest 0.13. HTTPS endpoint discovery used rustls automatic
provider selection and could panic before sending a ClientHello.

Use reqwest rustls-no-provider to share ring, and explicitly install the
process default before starting CLI, GUI and web services. Initialize it
for standalone webhook construction too, retaining any provider already
selected by the host.

Pass ring directly to HTTPS discovery and WebSocket TLS builders so
library use is independent of application initialization order. Keep
existing certificate verification, SNI and protocol settings.

Add a duplex-stream regression that reproduces the original panic with
both backends enabled, and run it in CI. Explain provider selection and
feature-unification constraints next to the relevant code.

Validation: the new regression fails before the fix and passes after it.
Docker tests pass: 10 discovery, 13 webhook, 2 WebSocket, WSS three-node
AES-GCM relay, and WSS credential connectivity. Clippy with warnings
denied and fmt pass. GUI, browser, WASI, minimal native, endpoint-only
and WebSocket-only compile checks pass. Linux and Windows release
dependency trees contain only the ring runtime backend.

Fixes #2607

* ci: remove the separate rustls backend regression step

Keep the HTTPS discovery regression in the existing test archive and
runner. Avoid an extra core test build solely to enable both rustls
backends; that combination was verified locally before the TLS fix.

* build(web): share reqwest 0.13 with the OIDC client

Disable the reqwest 0.12 client bundled with openidconnect/oauth2 and
use the official oauth2-reqwest adapter around the workspace reqwest
0.13 client. Pin the pre-release adapter version until its API
stabilizes.

Keep the existing redirect policy and 30-second timeout. Initialize the
ring provider when constructing OIDC configuration, including outside
the web application entry point.

Exercise discovery, JWKS fetching, token success and OAuth error
responses against a local mock provider. Verify redirects are not
followed. Refresh Cargo.lock to remove reqwest 0.12 without unrelated
upgrades.

Validation: Docker OIDC tests (2) and webhook tests (13) pass. Clippy
with warnings denied for native/core/proto/web all targets and full
features passes, as does workspace formatting. The default core/web
dependency graph has one reqwest version and 45 multi-version names
instead of 46; the TLS runtime still selects ring only.
2026-10-09 10:22:32 +08:00

179 lines
5.9 KiB
TOML

[package]
name = "easytier-core"
description = "EasyTier OS-free control-plane core primitives."
homepage = "https://github.com/EasyTier/EasyTier"
repository = "https://github.com/EasyTier/EasyTier"
version = "2.7.0"
edition.workspace = true
rust-version.workspace = true
authors = ["kkrainbow"]
keywords = ["vpn", "p2p", "network", "easytier"]
categories = ["network-programming"]
license-file = "../LICENSE"
[lib]
crate-type = ["rlib", "cdylib"]
[package.metadata.wasm-pack.profile.release]
wasm-opt = ["-Oz", "--enable-bulk-memory", "--enable-nontrapping-float-to-int"]
[dependencies]
anyhow.workspace = true
ariadne = { version = "0.6", optional = true }
arc-swap.workspace = true
async-ringbuf = "0.3.9"
async-trait.workspace = true
auto_impl.workspace = true
base64.workspace = true
bitflags = "2.13"
bytecodec.workspace = true
bytes.workspace = true
chrono = { workspace = true, features = ["clock"] }
cidr = { workspace = true, features = ["serde"] }
crossbeam-utils.workspace = true
dashmap.workspace = true
bon.workspace = true
easytier-proto = { workspace = true, features = ["core"] }
futures = { workspace = true, features = ["std", "async-await"] }
guarden.workspace = true
hmac.workspace = true
http-body-util = { workspace = true, optional = true }
hyper = { workspace = true, features = ["client", "http1"], optional = true }
hyper-util = { workspace = true, features = ["tokio"], optional = true }
idna = "1.1"
atomic-shim.workspace = true
ordered_hash_map = "0.6.1"
parking_lot.workspace = true
percent-encoding.workspace = true
petgraph = "0.8.3"
pin-project-lite.workspace = true
prefix-trie = { version = "0.10.1", features = ["cidr"] }
prost.workspace = true
prost-types.workspace = true
rand.workspace = true
quanta.workspace = true
ring = { version = "0.17", optional = true }
rustls = { workspace = true, features = ["ring", "std", "tls12"], optional = true }
serde = { workspace = true, features = ["derive"] }
serde_json.workspace = true
sha2.workspace = true
smoltcp = { workspace = true, optional = true }
# All core Noise handshakes use 25519_ChaChaPoly_SHA256. Snow's std feature
# also enables unused ring and BLAKE2 dependencies, so use its alloc support.
snow = { version = "0.10.0", default-features = false, features = [
"use-chacha20poly1305",
"use-sha2",
"use-curve25519",
"use-getrandom",
] }
stun_codec.workspace = true
thiserror.workspace = true
tracing.workspace = true
strum = { workspace = true, features = ["derive"] }
toml.workspace = true
tokio = { workspace = true, features = [
"rt",
"time",
"sync",
"macros",
"io-util",
] }
tokio-util = { workspace = true, features = ["io", "rt"] }
tokio-rustls = { workspace = true, optional = true }
url = { workspace = true, features = ["serde"] }
wildmatch = "2.6.1"
uuid = { workspace = true, features = ["v4", "serde"] }
webpki-roots = { version = "1.0", optional = true }
x25519-dalek = { workspace = true, features = ["static_secrets"] }
zerocopy = { workspace = true, features = ["derive", "simd"] }
zstd = { version = "0.14", optional = true }
# Match snow 0.10's AEAD generation to share aead, cipher and crypto-common.
# Upgrade together with snow rather than pulling in a second crypto stack.
aes-gcm = { version = "0.10.3", optional = true }
chacha20poly1305 = { version = "0.10.1", optional = true }
openssl = { version = "0.10", optional = true, features = ["vendored"] }
[target.'cfg(all(target_arch = "wasm32", target_os = "unknown"))'.dependencies]
getrandom-02 = { package = "getrandom", version = "0.2.17", features = ["js"] }
getrandom-03 = { package = "getrandom", version = "0.3.4", features = ["wasm_js"] }
ring = { version = "0.17", features = ["wasm32_unknown_unknown_js"], optional = true }
rustls-pki-types = { version = "1.15.1", features = ["web"], optional = true }
uuid = { workspace = true, features = ["js"] }
wasm-bindgen = "0.2"
[features]
default = ["aes-gcm", "endpoint-discovery", "extended-services", "management", "tcp-hole-punch"]
aes-gcm = ["dep:aes-gcm"]
browser-config = ["config-write", "easytier-proto/api", "easytier-proto/json-rpc"]
chacha20 = ["dep:chacha20poly1305"]
openssl-crypto = ["dep:openssl"]
ring-crypto = ["dep:ring"]
wasi-crypto-offload = ["ring-crypto"]
config-write = []
endpoint-discovery = [
"dep:http-body-util",
"dep:hyper",
"dep:hyper-util",
"dep:ring",
"dep:rustls",
"dep:rustls-pki-types",
"dep:tokio-rustls",
"dep:webpki-roots",
]
dhcp-ipv4 = []
public-ipv6-provider = []
vpn-portal = []
wrapped-transport = []
extended-services = [
"dhcp-ipv4",
"public-ipv6-provider",
"vpn-portal",
"wrapped-transport",
"proxy-cidr-monitor",
]
web-client = ["management-rpc", "config-write"]
management = ["web-client", "extended-services", "rich-config-errors", "easytier-proto/json-rpc"]
management-rpc = ["easytier-proto/api"]
proxy-cidr-monitor = []
rich-config-errors = ["dep:ariadne"]
tcp-hole-punch = []
proxy-packet = [
"wrapped-transport",
"dep:smoltcp",
"smoltcp/std",
"smoltcp/proto-ipv4",
"smoltcp/proto-ipv4-fragmentation",
"smoltcp/fragmentation-buffer-size-65536",
"smoltcp/assembler-max-segment-count-16",
"smoltcp/reassembly-buffer-size-65536",
"smoltcp/reassembly-buffer-count-16",
]
proxy-smoltcp-stack = [
"proxy-packet",
"smoltcp/medium-ip",
"smoltcp/socket-tcp",
"smoltcp/socket-udp",
"smoltcp/proto-ipv6",
"smoltcp/async",
]
wasm-host-tunnel = []
wasm-host-tunnel-outbound = ["wasm-host-tunnel"]
test-utils = []
tracing-log = ["tracing/log"]
zstd = ["dep:zstd"]
[dev-dependencies]
futures = { workspace = true, features = ["executor"] }
[target.'cfg(not(target_os = "wasi"))'.dev-dependencies]
tokio = { workspace = true, features = ["rt-multi-thread", "test-util"] }
[package.metadata.cargo-machete]
ignored = [
# Enable browser entropy backends for transitive rand/snow/AEAD dependencies.
"getrandom-02",
"getrandom-03",
# Enable browser time for rustls certificate validation.
"rustls-pki-types",
]