Files
boxmaker/docs/plans/M4a/02-gatewayd-deps.md
T
kyleandClaude Opus 5.5 0339dc13b2 Plan M4a: gatewayd in 15 tasks, with skeletons and given tests
Each task's tests were run against a reference at its end state; the end states were replayed
from master in order with the gate at each step (650 to 762 tests); each skeleton compiles
against its tests and fails them. The reference is kept off this machine. Lessons T27 (every
wait in a test has a limit) and T28 (mutate the reference before hand-over) come from this work.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-23 19:05:44 -07:00

87 lines
4.1 KiB
Markdown

# M4a task 02: `gatewayd`'s dependencies and test certificates
**Branch:** `m4a` (run `git switch m4a`; `git status --short` must be empty, otherwise stop)
**Commit subject:** `gatewayd: dependencies for TLS and secrets; test-only certificates`
## Goal
`gatewayd` talks to Mattermost over TLS when the URL is `https` (the owner's decision: the tailnet
serves it that way). This task adds the dependencies it needs and nothing that uses them yet, so
that the next tasks can. It also copies in the test-only certificates the TLS tests use.
## Files
- Copy: `deny.toml` (replaces the old one), `crates/gatewayd/tests/fixtures/tls/` (the whole
directory: 9 files)
- Modify: `Cargo.toml`, `crates/gatewayd/Cargo.toml`, `crates/gatewayd/src/lib.rs`,
`docs/dependencies.md`, `docs/implementer-log.md`, `Cargo.lock`
## The changes, exactly
**`Cargo.toml`**, at the end of `[workspace.dependencies]`, after `emsha`:
```toml
rustls = { version = "0.23.45", default-features = false, features = ["ring", "std", "tls12"] }
rustls-native-certs = "0.8.4"
zeroize = "1.9.0"
```
**`crates/gatewayd/Cargo.toml`**, `[dependencies]` becomes:
```toml
[dependencies]
proto.workspace = true
rustls.workspace = true
rustls-native-certs.workspace = true
serde.workspace = true
serde_json.workspace = true
toml.workspace = true
zeroize.workspace = true
```
**`crates/gatewayd/src/lib.rs`**: replace its one comment line with
```rust
//! `gatewayd`: the Mattermost channel. It carries the owner's messages to `loopd` as turns and posts
//! the answers back, over outbound connections only. M4a spec: `docs/specs/2026-09-23-m4a-gateway.md`.
```
**`deny.toml`**: copied, not edited. It allows the licences ISC and BSD-3-Clause (owner's approval,
2026-09-23), and judges dependencies only for Linux and the Mac, since `rustls` pulls in a second
`windows-sys` for Windows that we never build.
**`docs/dependencies.md`**: in the table, the rows for `serde` and `serde_json` add `` `gatewayd` ``
to "Used by", the `toml` row adds `` `gatewayd` from M4a ``, and three rows are added at the end:
```markdown
| `rustls` | 0.23.45 | `gatewayd` | TLS to Mattermost over the tailnet (M4a, owner's decision). `default-features = false` with `ring`, `std`, `tls12`. With its dependencies on Linux: `ring` (Apache-2.0 AND ISC; builds C and assembly), `rustls-webpki` and `untrusted` (ISC), `rustls-pki-types`, `subtle` (BSD-3-Clause), `zeroize`, `once_cell`, `getrandom`, `libc`, `cfg-if`. Apache-2.0 OR ISC OR MIT. |
| `rustls-native-certs` | 0.8.4 | `gatewayd` | The host's trusted certificates, so a CA installed on the host is trusted too; adds `openssl-probe`. Apache-2.0 OR ISC OR MIT. |
| `zeroize` | 1.9.0 | `gatewayd` | Wipes a secret's memory when it is dropped (`Secret`). Already a dependency of `rustls`. Apache-2.0 OR MIT. |
```
The fixtures' `README.md` says what each certificate is. Every key in that directory is public and
for these tests only.
## Steps
- [ ] **1. Copy.** `git switch m4a`, then `cp docs/plans/M4a/files/deny.toml deny.toml` and
`mkdir -p crates/gatewayd/tests/fixtures && cp -r docs/plans/M4a/files/crates/gatewayd/tests/fixtures/tls crates/gatewayd/tests/fixtures/`
- [ ] **2. Make the four edits above.**
- [ ] **3. Build once.** `cargo build -p gatewayd`, so that `Cargo.lock` is updated. Expected: it
builds (the crates are already in the local cache; if cargo says it needs the network and cannot
reach it, stop and report).
- [ ] **4. Check.** `git status --short` lists `Cargo.lock`, `Cargo.toml`, `deny.toml`, the two
`gatewayd` files, `docs/dependencies.md` and the fixtures directory, and nothing else.
- [ ] **5. Run the gate.** `cargo fmt --all`, then `make gate`. Expected last line: `gate: ok`.
`cargo-deny` must pass: if it reports a licence or a duplicate, stop and report it word for word.
- [ ] **6. Log and commit.**
`git add Cargo.toml Cargo.lock deny.toml crates/gatewayd docs/dependencies.md docs/implementer-log.md && git commit`
## Done when
- `make gate` prints `gate: ok` with the new dependencies in `Cargo.lock`.
## Stop and report if
- `cargo-deny` fails, or cargo wants a version other than the ones above.