| Author | Andy Green <andy@warmcat.com> 2026-10-05 19:50 UTC | | Committer | Andy Green <andy@warmcat.com> 2026-10-06 03:36 UTC | | Tree | 3f4d5822e8a50e9f33359fa41b0790c2cc38af44 Raw Patch | | | deps: admit miniz_oxide and adler2 for permessage-deflate | deps: admit miniz_oxide and adler2 for permessage-deflate
The first dependencies of the main workspace, as decided in
docs/dependencies.md, behind npro-ws's opt-in pmd feature, which the
next commits fill in.
- miniz_oxide 0.9.1 is permessage-deflate's raw deflate, inflater and
deflater, where C uses zlib. Writing an inflater was the alternative,
and a deflater as well; neither is worth it for a first pass. It is
maintained by oyvindln, actively, and Rust's own standard library
depends on it, so it is well exercised. #![forbid(unsafe_code)], no
build script, no_std with alloc (its with-alloc feature, nothing else
enabled), edition 2021, and it builds at npro's rust-version, 1.85,
and for the bare-metal targets sai builds. MIT OR Zlib OR
Apache-2.0.
- adler2 2.0.1 comes with it, for the Adler-32 of zlib streams, which
ws's raw deflate does not use. The same maintainer;
#![forbid(unsafe_code)], no build script, no_std. 0BSD OR MIT OR
Apache-2.0.
Both are named in deny.toml's allowlist and in the register, which no
longer lists them as decided but not admitted. Until the next commit
uses it, npro-ws names miniz_oxide so the dependency is not unused.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019kg5Eemy68ZaqDBcUJQG6J
|
diff --git a/Cargo.lock b/Cargo.lock
index e141682..b619179 100644
--- a/Cargo.lock
+++ b/Cargo.lock
@@ -3,6 +3,21 @@
version = 4
[[package]]
+name = "adler2"
+version = "2.0.1"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "320119579fcad9c21884f5c4861d16174d0e06250625266f50fe6898340abefa"
+
+[[package]]
+name = "miniz_oxide"
+version = "0.9.1"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "b63fbc4a50860e98e7b2aa7804ded1db5cbc3aff9193adaff57a6931bf7c4b4c"
+dependencies = [
+ "adler2",
+]
+
+[[package]]
name = "npro"
version = "0.0.2"
@@ -37,6 +52,7 @@ dependencies = [
name = "npro-ws"
version = "0.0.2"
dependencies = [
+ "miniz_oxide",
"npro-core",
"npro-h1",
]
diff --git a/crates/npro-ws/Cargo.toml b/crates/npro-ws/Cargo.toml
index 5ba6b5a..b98b5cc 100644
--- a/crates/npro-ws/Cargo.toml
+++ b/crates/npro-ws/Cargo.toml
@@ -14,6 +14,12 @@ repository.workspace = true
[dependencies]
npro-core.workspace = true
npro-h1.workspace = true
+# permessage-deflate's inflater and deflater: docs/dependencies.md
+miniz_oxide = { version = "0.9.1", default-features = false, features = ["with-alloc"], optional = true }
+
+[features]
+# permessage-deflate (RFC 7692): needs alloc, for the inflater and deflater
+pmd = ["dep:miniz_oxide"]
[dev-dependencies]
npro-core = { workspace = true, features = ["replay"] }
diff --git a/crates/npro-ws/src/lib.rs b/crates/npro-ws/src/lib.rs
index 0ddd2e0..df69843 100644
--- a/crates/npro-ws/src/lib.rs
+++ b/crates/npro-ws/src/lib.rs
@@ -13,3 +13,7 @@
pub mod conn;
pub mod handshake;
+
+// admitted for permessage-deflate, which is to use it
+#[cfg(feature = "pmd")]
+use miniz_oxide as _;
diff --git a/deny.toml b/deny.toml
index e3e32e3..8306d6e 100644
--- a/deny.toml
+++ b/deny.toml
@@ -44,7 +44,9 @@ allow = [
"npro-test",
# admitted dependencies, each with its entry in docs/dependencies.md:
- # (none)
+ # permessage-deflate, npro-ws's opt-in pmd feature
+ "miniz_oxide",
+ "adler2",
]
# A build script runs arbitrary code on the build machine at compile time,
diff --git a/docs/dependencies.md b/docs/dependencies.md
index c2da44b..410e98e 100644
--- a/docs/dependencies.md
+++ b/docs/dependencies.md
@@ -98,12 +98,17 @@ Removing a dependency is the same in reverse: take it out of
### The main workspace
-Admitted: **none**. npro builds from its own sources and the Rust
-toolchain alone.
+Without the opt-in features below, npro builds from its own sources and
+the Rust toolchain alone.
| crate | used by | feature | why | build script | unsafe | admitted in |
|---|---|---|---|---|---|---|
-| (none yet) | | | | | | |
+| `miniz_oxide` 0.9 | npro-ws | `pmd` | permessage-deflate's inflater and deflater (RFC 1951 raw deflate), where C uses zlib. An inflater of our own was the alternative, judged not worth it for a first pass; a deflater as well would be more again. Maintained by oyvindln under the Frommi organisation, actively, and used by Rust's own standard library (its `rustc-dep-of-std` feature), so it is well exercised. `no_std`, needing `alloc` (`with-alloc`); edition 2021, building at npro's `rust-version` | none | none: `#![forbid(unsafe_code)]` | the commit adding permessage-deflate's dependency |
+| `adler2` 2.0 | `miniz_oxide` | (`pmd`) | the Adler-32 checksum, which `miniz_oxide` needs for zlib streams; ws uses raw deflate, so it is only carried. The same maintainer, a maintained fork of `adler` | none | none: `#![forbid(unsafe_code)]` | the same |
+
+Both are licensed MIT among alternatives (`miniz_oxide` MIT OR Zlib OR
+Apache-2.0, `adler2` 0BSD OR MIT OR Apache-2.0), and bring nothing else:
+their other dependencies are optional, and not enabled.
### The fuzz workspace
@@ -134,13 +139,6 @@ targets, they are build-time only: they run on the fuzz builder while the
targets build. All were admitted
in the commit adding the libFuzzer targets.
-## Decided, not yet admitted
-
-- **`miniz_oxide`**, with its dependency `adler2`, for permessage-deflate,
- behind npro-ws's opt-in `pmd` feature. Pure Rust, `no_std` with
- `alloc`. It is admitted, with its register entry, in the commit that
- adds permessage-deflate.
-
## Decided against
- **`rand`**: random is an input the caller provides
|