v0.5.5: SFTP-over-SSH remote shares (russh, pure-Rust, ring backend)
Adds SFTP as a third remote ISO-library protocol alongside SMB and NFS. Pure-Rust russh + russh-sftp on the ring crypto backend — no kernel mount, no subprocess, no OpenSSL, no new C deps. Like NFS (and unlike SMB), SFTP-sourced ISOs support HTTP Range requests because SFTP opens a seekable file handle. - iso-store: SftpShareManager (connect/auth/READDIR/seekable stream), IsoSource::Sftp, password OR SSH-key auth, trust-on-first-use host-key pinning, 0600 credential sidecar with a restart-safe derived path. - http-api: /api/sftp-shares routes, Range-aware ISO dispatch arm, status/metrics counts, /api/docs entry, `sftp` terminal commands. - webui: "SFTP (SSH)" protocol option with a password/key auth toggle, host-key fingerprint display, dashboard tile, updated copy. SCP was deliberately rejected: sequential-only (no Range) and its crates wrap libssh2 (C + OpenSSL), which would break the static-musl build. russh is pinned to =0.55.0: russh 0.61 needs the stable RustCrypto generation (pkcs8 0.11), which is API-incompatible with the release- candidate crates bergshamra-crypto pins (pkcs8 =0.11.0-rc.11). 0.55 is the newest russh on the prior generation (pkcs8 0.7) that coexists. Do not bump past 0.55 until bergshamra adopts stable RustCrypto. 252 tests pass, clippy clean, static musl x86_64 binary (ring already present via rustls + bergshamra, so no new crypto/C deps). Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
674a69f93b
commit
44a2212abe
+31
-1
@@ -12,7 +12,7 @@ members = [
|
||||
]
|
||||
|
||||
[workspace.package]
|
||||
version = "0.5.4"
|
||||
version = "0.5.5"
|
||||
edition = "2021"
|
||||
rust-version = "1.95"
|
||||
license = "MIT OR Apache-2.0"
|
||||
@@ -85,6 +85,36 @@ x509-parser = "0.18"
|
||||
flate2 = "1.1"
|
||||
base64 = "0.22"
|
||||
|
||||
# v0.5.5: pure-Rust SSH/SFTP client for reading remote ISO libraries
|
||||
# over SFTP without a kernel mount.
|
||||
#
|
||||
# CRITICAL #1 — crypto backend: `default-features = false` +
|
||||
# `features = ["ring"]`. russh's *default* backend is `aws-lc-rs`, which
|
||||
# pulls `aws-lc-sys` (C code, fiddly under musl); the `ring` feature
|
||||
# instead reuses `ring 0.17` — the exact crate+version already in the
|
||||
# binary via rustls + bergshamra — so SFTP adds ZERO new C/crypto deps
|
||||
# and the static-musl build stays OpenSSL-free.
|
||||
#
|
||||
# CRITICAL #2 — pinned to EXACTLY 0.55.0, the newest russh that
|
||||
# coexists with bergshamra-crypto (our SAML core). The RustCrypto
|
||||
# ecosystem is mid-transition: bergshamra-crypto pins a constellation of
|
||||
# release-CANDIDATE crates (`pkcs8 =0.11.0-rc.11` and its matching
|
||||
# pkcs5/spki RCs) that are API-incompatible with the STABLE versions of
|
||||
# the same crates in the same semver bucket. russh 0.56+ pulls those
|
||||
# stable crates (`pkcs5 0.8`), which silently replaces bergshamra's RC
|
||||
# copies and breaks compilation. russh ≤0.55 stays on the previous stable
|
||||
# generation (`pkcs5 0.7`, `ssh-key 0.6`), which unifies with bergshamra's
|
||||
# *stable* deps and leaves the RC bucket untouched — verified to compile.
|
||||
# 0.55 still has the merged `russh::keys` API (keys merged at 0.50).
|
||||
# IMPORTANT: do NOT bump russh past 0.55 until bergshamra-crypto adopts
|
||||
# the stable RustCrypto generation; 0.56+ will not compile in this tree.
|
||||
#
|
||||
# SCP was deliberately rejected: the protocol is sequential-only (no
|
||||
# random access → no HTTP Range, unlike SFTP/NFS) and the mature SCP
|
||||
# crates wrap libssh2 (C + OpenSSL), which would break this build.
|
||||
russh = { version = "=0.55.0", default-features = false, features = ["ring"] }
|
||||
russh-sftp = "2.3"
|
||||
|
||||
openpxe-core = { path = "crates/core" }
|
||||
openpxe-dhcp-proxy = { path = "crates/dhcp-proxy" }
|
||||
openpxe-tftp = { path = "crates/tftp" }
|
||||
|
||||
Reference in New Issue
Block a user