Mirrors the worthwhile device-support wins from iVentoy 1.0.24→1.0.35 onto our
(very different) proxy-DHCP + iPXE-chainload architecture. iVentoy's other
changes are inapplicable (arm64-server / distro-display fixes live in its
injected Linux, which we don't have), niche (iSCSI), or closed-source
(Matrix Boot).
iPXE refreshed (mirrors 1.0.35 "Update iPXE")
- Pin the from-source build to ipxe/ipxe master @ 2026-06-09
(95ffbf4745553e8a207922389929e1943c0237c0) — newer NIC drivers + EFI fixes.
The pin also busts the cached ipxe-build Docker layer so the release
actually recompiles iPXE; build-ipxe.sh now shallow-fetches an exact SHA.
Automatic NIC driver fallback (mirrors 1.0.34 "driver/boot-file mode" — but
no operator toggle, per request)
- New DriverMode {Firmware, Builtin} in core; ClientArch::ipxe_bootfile_mode
maps each arch to either the firmware-net build (snponly/undionly, default)
or the all-drivers build (ipxe.efi/ipxe.pxe/ipxe-i386.efi/ipxe-arm64.efi).
- The DHCP proxy serves Firmware by default — byte-for-byte unchanged, so
hardware that boots today never regresses. A new DriverEscalation state
machine watches for the tell-tale failure: a MAC re-PXE-boots (fresh
firmware DISCOVER) without ever completing the iPXE-user-class handoff that
proves the firmware NIC stack worked. That MAC is automatically escalated to
iPXE's own NIC drivers, and the choice is sticky after a confirmed handoff
(debounced for the :67/:4011 same-boot pair, TTL-pruned, capped). It just
works — no settings, no UI.
- All-drivers binaries fetched per arch (ipxe.pxe + i386/arm64 native EFI;
x86_64 ipxe.efi already built from source with PNG); ipxe-assets embeds
*.pxe and logs availability per (arch, mode).
Core principles intact: DHCP-proxy-only, container-first, Rust-focused (the
logic is all Rust; only the iPXE fetch/build stays shell), Windows hard-rules
untouched (this never goes near Windows boot).
Validation: clippy clean; full workspace test suite green (core 99 incl. new
DriverMode tests, dhcp-proxy +4 escalation tests, http-api 31+68, iso-store
61, tftp 6, bin 2); fmt-clean.
Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
149 lines
5.6 KiB
TOML
149 lines
5.6 KiB
TOML
[workspace]
|
|
resolver = "2"
|
|
members = [
|
|
"crates/core",
|
|
"crates/dhcp-proxy",
|
|
"crates/tftp",
|
|
"crates/http-api",
|
|
"crates/iso-store",
|
|
"crates/ipxe-assets",
|
|
"crates/webui",
|
|
"crates/openpxe",
|
|
]
|
|
|
|
[workspace.package]
|
|
version = "0.6.1"
|
|
edition = "2021"
|
|
rust-version = "1.95"
|
|
license = "MIT OR Apache-2.0"
|
|
repository = "https://gitea.milesward.dev/mward4/OpenPXE"
|
|
authors = ["OpenPXE contributors"]
|
|
|
|
[workspace.dependencies]
|
|
tokio = { version = "1.40", features = ["full"] }
|
|
tokio-util = { version = "0.7", features = ["io"] }
|
|
tokio-stream = { version = "0.1", features = ["sync"] }
|
|
futures = "0.3"
|
|
async-trait = "0.1"
|
|
|
|
dhcproto = "0.12"
|
|
socket2 = { version = "0.5", features = ["all"] }
|
|
bytes = "1.7"
|
|
nom = "7.1"
|
|
|
|
axum = { version = "0.7", features = ["macros", "multipart", "http2"] }
|
|
tower = "0.5"
|
|
tower-http = { version = "0.6", features = ["fs", "trace", "cors", "limit"] }
|
|
hyper = "1.4"
|
|
reqwest = { version = "0.12", default-features = false, features = ["rustls-tls", "stream", "json"] }
|
|
|
|
serde = { version = "1.0", features = ["derive"] }
|
|
serde_json = "1.0"
|
|
toml = "0.8"
|
|
# v0.5.4: layered config (TOML file + env). Pure-Rust, no C deps; keeps the
|
|
# static-musl build OpenSSL-free. Replaces the hand-rolled apply_env mapping.
|
|
figment = { version = "0.10", features = ["toml", "env"] }
|
|
|
|
tracing = "0.1"
|
|
tracing-subscriber = { version = "0.3", features = ["env-filter", "json"] }
|
|
|
|
anyhow = "1.0"
|
|
thiserror = "2.0"
|
|
clap = { version = "4.5", features = ["derive", "env"] }
|
|
uuid = { version = "1.10", features = ["v4", "serde"] }
|
|
time = { version = "0.3", features = ["serde", "serde-human-readable", "formatting", "macros"] }
|
|
sha2 = "0.10"
|
|
hex = "0.4"
|
|
bcrypt = "0.15"
|
|
parking_lot = "0.12"
|
|
rust-embed = { version = "8.5", features = ["include-exclude"] }
|
|
|
|
# v0.4.67: pure-Rust NFSv3 client. Replaces the (deleted-in-v0.4.65)
|
|
# kernel-mount NFS path with an in-process implementation that works
|
|
# in any container — no kernel modules, no CAP_SYS_ADMIN, no
|
|
# subprocess. Ships alongside the userspace SMB consumer; operators
|
|
# pick whichever protocol their NAS prefers.
|
|
nfs3_client = { version = "0.9", features = ["tokio"] }
|
|
nfs3_types = "0.5"
|
|
|
|
# v0.5.0: SMTP for webhook notifications (Slack/Teams/Discord go over
|
|
# plain HTTP via reqwest; email needs a real SMTP client). rustls TLS
|
|
# to match reqwest and stay musl-static-friendly — no OpenSSL.
|
|
lettre = { version = "0.11", default-features = false, features = ["smtp-transport", "tokio1-rustls-tls", "builder", "hostname"] }
|
|
|
|
# v0.5.1: pure-Rust SAML 2.0 Service Provider. bergshamra does XML-DSig
|
|
# verification + exclusive c14n with RustCrypto (no OpenSSL/xmlsec/libxml2
|
|
# C deps), so the static musl binary stays OpenSSL-free — samael was
|
|
# rejected precisely because it hard-requires OpenSSL. We build the thin
|
|
# SP layer (AuthnRequest, metadata parse, SAMLResponse semantics) on top.
|
|
bergshamra = "0.4"
|
|
roxmltree = "0.21"
|
|
quick-xml = "0.40"
|
|
x509-parser = "0.18"
|
|
# flate2 default backend is miniz_oxide (pure Rust) — do NOT enable the
|
|
# zlib/zlib-ng C backends, which would break the musl-static build.
|
|
flate2 = "1.1"
|
|
base64 = "0.22"
|
|
|
|
# v0.5.5: pure-Rust SSH/SFTP client for reading remote ISO libraries
|
|
# over SFTP without a kernel mount.
|
|
#
|
|
# CRITICAL #1 — crypto backend: `default-features = false` +
|
|
# `features = ["ring"]`. russh's *default* backend is `aws-lc-rs`, which
|
|
# pulls `aws-lc-sys` (C code, fiddly under musl); the `ring` feature
|
|
# instead reuses `ring 0.17` — the exact crate+version already in the
|
|
# binary via rustls + bergshamra — so SFTP adds ZERO new C/crypto deps
|
|
# and the static-musl build stays OpenSSL-free.
|
|
#
|
|
# CRITICAL #2 — pinned to EXACTLY 0.55.0, the newest russh that
|
|
# coexists with bergshamra-crypto (our SAML core). The RustCrypto
|
|
# ecosystem is mid-transition: bergshamra-crypto pins a constellation of
|
|
# release-CANDIDATE crates (`pkcs8 =0.11.0-rc.11` and its matching
|
|
# pkcs5/spki RCs) that are API-incompatible with the STABLE versions of
|
|
# the same crates in the same semver bucket. russh 0.56+ pulls those
|
|
# stable crates (`pkcs5 0.8`), which silently replaces bergshamra's RC
|
|
# copies and breaks compilation. russh ≤0.55 stays on the previous stable
|
|
# generation (`pkcs5 0.7`, `ssh-key 0.6`), which unifies with bergshamra's
|
|
# *stable* deps and leaves the RC bucket untouched — verified to compile.
|
|
# 0.55 still has the merged `russh::keys` API (keys merged at 0.50).
|
|
# IMPORTANT: do NOT bump russh past 0.55 until bergshamra-crypto adopts
|
|
# the stable RustCrypto generation; 0.56+ will not compile in this tree.
|
|
#
|
|
# SCP was deliberately rejected: the protocol is sequential-only (no
|
|
# random access → no HTTP Range, unlike SFTP/NFS) and the mature SCP
|
|
# crates wrap libssh2 (C + OpenSSL), which would break this build.
|
|
russh = { version = "=0.55.0", default-features = false, features = ["ring"] }
|
|
russh-sftp = "2.3"
|
|
|
|
openpxe-core = { path = "crates/core" }
|
|
openpxe-dhcp-proxy = { path = "crates/dhcp-proxy" }
|
|
openpxe-tftp = { path = "crates/tftp" }
|
|
openpxe-http-api = { path = "crates/http-api" }
|
|
openpxe-iso-store = { path = "crates/iso-store" }
|
|
openpxe-ipxe-assets = { path = "crates/ipxe-assets" }
|
|
openpxe-webui = { path = "crates/webui" }
|
|
|
|
[workspace.lints.rust]
|
|
unsafe_code = "deny"
|
|
rust_2018_idioms = { level = "warn", priority = -1 }
|
|
|
|
[workspace.lints.clippy]
|
|
pedantic = { level = "warn", priority = -1 }
|
|
module_name_repetitions = "allow"
|
|
missing_errors_doc = "allow"
|
|
missing_panics_doc = "allow"
|
|
must_use_candidate = "allow"
|
|
doc_markdown = "allow"
|
|
items_after_statements = "allow"
|
|
cast_possible_truncation = "allow"
|
|
cast_lossless = "allow"
|
|
cast_sign_loss = "allow"
|
|
similar_names = "allow"
|
|
too_many_lines = "allow"
|
|
|
|
[profile.release]
|
|
lto = "thin"
|
|
codegen-units = 1
|
|
strip = "symbols"
|
|
opt-level = 3
|