Adds SFTP as a third remote ISO-library protocol alongside SMB and NFS. Pure-Rust russh + russh-sftp on the ring crypto backend — no kernel mount, no subprocess, no OpenSSL, no new C deps. Like NFS (and unlike SMB), SFTP-sourced ISOs support HTTP Range requests because SFTP opens a seekable file handle. - iso-store: SftpShareManager (connect/auth/READDIR/seekable stream), IsoSource::Sftp, password OR SSH-key auth, trust-on-first-use host-key pinning, 0600 credential sidecar with a restart-safe derived path. - http-api: /api/sftp-shares routes, Range-aware ISO dispatch arm, status/metrics counts, /api/docs entry, `sftp` terminal commands. - webui: "SFTP (SSH)" protocol option with a password/key auth toggle, host-key fingerprint display, dashboard tile, updated copy. SCP was deliberately rejected: sequential-only (no Range) and its crates wrap libssh2 (C + OpenSSL), which would break the static-musl build. russh is pinned to =0.55.0: russh 0.61 needs the stable RustCrypto generation (pkcs8 0.11), which is API-incompatible with the release- candidate crates bergshamra-crypto pins (pkcs8 =0.11.0-rc.11). 0.55 is the newest russh on the prior generation (pkcs8 0.7) that coexists. Do not bump past 0.55 until bergshamra adopts stable RustCrypto. 252 tests pass, clippy clean, static musl x86_64 binary (ring already present via rustls + bergshamra, so no new crypto/C deps). Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
52 lines
1.7 KiB
TOML
52 lines
1.7 KiB
TOML
[package]
|
|
name = "openpxe-iso-store"
|
|
version.workspace = true
|
|
edition.workspace = true
|
|
license.workspace = true
|
|
authors.workspace = true
|
|
description = "ISO upload, storage, introspection, and boot-entry generation for OpenPXE"
|
|
|
|
[lints]
|
|
workspace = true
|
|
|
|
[dependencies]
|
|
openpxe-core.workspace = true
|
|
tokio = { workspace = true }
|
|
tokio-util = { workspace = true }
|
|
serde.workspace = true
|
|
serde_json.workspace = true
|
|
tracing.workspace = true
|
|
thiserror.workspace = true
|
|
anyhow.workspace = true
|
|
sha2.workspace = true
|
|
hex.workspace = true
|
|
bcrypt.workspace = true
|
|
uuid.workspace = true
|
|
time.workspace = true
|
|
parking_lot.workspace = true
|
|
bytes.workspace = true
|
|
tempfile = "3.12"
|
|
libc = "0.2"
|
|
# v0.4.61: server-side compose of the operator's uploaded raster into a
|
|
# fixed 1024x768 canvas so the PXE menu always gets a consistently-sized
|
|
# PNG regardless of what the operator uploaded. We use the bare-bones
|
|
# `image` crate (no default features) and explicitly enable only the
|
|
# decoders we accept on upload (PNG/JPEG/WebP/GIF) plus the PNG
|
|
# encoder. Keeps the build slim — no JPEG2000, TIFF, BMP, etc.
|
|
image = { version = "0.25", default-features = false, features = ["png", "jpeg", "webp", "gif"] }
|
|
|
|
# v0.4.67: pure-Rust NFSv3 client for reading remote ISOs without a
|
|
# kernel mount. See crates/iso-store/src/nfs_share.rs for usage.
|
|
nfs3_client = { workspace = true }
|
|
nfs3_types = { workspace = true }
|
|
# v0.5.5: pure-Rust SSH/SFTP client (ring backend) for the SFTP remote
|
|
# share path. See crates/iso-store/src/sftp_share.rs for usage.
|
|
russh = { workspace = true }
|
|
russh-sftp = { workspace = true }
|
|
# Needed for the Stream trait that wraps the mpsc receiver feeding
|
|
# NFS read-loop bytes into axum's Body::from_stream.
|
|
futures = { workspace = true }
|
|
|
|
[dev-dependencies]
|
|
tempfile = "3.12"
|