Repository navigation
Explore a Rust interface for CCF applications - #8200
Merged
Amaury Chamayou (achamayou) merged 41 commits intoSep 24, 2026
Merged
Conversation
Copilot started reviewing on behalf of
Amaury Chamayou (achamayou)
August 26, 2026 12:29
View session
Amaury Chamayou (achamayou)
force-pushed
the
achamayou-rust-interface-exploration
branch
from
August 26, 2026 12:31
fc3606c to
ae04da5
Compare
Contributor
There was a problem hiding this comment.
Pull request overview
Introduces exploratory Rust support for native CCF applications through a C ABI bridge and Rust SDK.
Changes:
- Adds endpoint, authentication, response, and raw KV APIs.
- Adds Cargo/CMake integration and packaging.
- Adds a sample application, E2E coverage, documentation, and changelog entry.
Custom instructions used
.github/copilot-instructions.md.github/instructions/changelog.instructions.md.github/instructions/reviewing.instructions.md
Reviewed changes
Copilot reviewed 17 out of 19 changed files in this pull request and generated 6 comments.
Show a summary per file
| File | Description |
|---|---|
CHANGELOG.md |
Announces Rust application support. |
CMakeLists.txt |
Installs Rust sources and registers the E2E test. |
cmake/ccf_app.cmake |
Adds the Rust application build helper. |
cmake/gersemi_definitions.cmake |
Registers the helper for CMake formatting. |
include/ccf/rust_ffi.h |
Defines the public C ABI. |
src/rust/app_bridge.cpp |
Implements the C++ bridge and endpoint registry. |
src/rust/ccf-app/Cargo.toml |
Defines the Rust SDK crate. |
src/rust/ccf-app/Cargo.lock |
Locks the SDK crate. |
src/rust/ccf-app/src/lib.rs |
Implements the Rust-facing API and handlers. |
samples/CMakeLists.txt |
Includes the Rust sample. |
samples/apps/basic_rust/CMakeLists.txt |
Builds the sample application. |
samples/apps/basic_rust/Cargo.toml |
Defines the sample crate. |
samples/apps/basic_rust/Cargo.lock |
Locks sample dependencies. |
samples/apps/basic_rust/rust-toolchain.toml |
Pins Rust 1.90. |
samples/apps/basic_rust/src/lib.rs |
Implements records and health endpoints. |
tests/basic_rust.py |
Exercises authentication and KV behavior. |
doc/build_apps/index.rst |
Adds Rust to the application overview. |
doc/build_apps/get_started.rst |
Links Rust build guidance. |
doc/build_apps/example_rust.rst |
Documents the initial Rust interface. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Amaury Chamayou (achamayou)
force-pushed
the
achamayou-rust-interface-exploration
branch
from
August 26, 2026 14:42
b50fb7c to
66b1b47
Compare
Co-authored-by: achamayou <4016369+achamayou@users.noreply.github.com>
Co-authored-by: achamayou <4016369+achamayou@users.noreply.github.com>
Co-authored-by: achamayou <4016369+achamayou@users.noreply.github.com>
Co-authored-by: achamayou <4016369+achamayou@users.noreply.github.com>
Co-authored-by: achamayou <4016369+achamayou@users.noreply.github.com>
Co-authored-by: achamayou <4016369+achamayou@users.noreply.github.com>
Co-authored-by: achamayou <4016369+achamayou@users.noreply.github.com>
Co-authored-by: achamayou <4016369+achamayou@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Preserve compaction retry semantics, reject unsupported HTTP status codes, and keep the CI test bucket inventory in sync. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Stabilize the C ABI, preserve Cargo dependency tracking, register Rust unit tests, enforce unwind panics, and clarify native application trust semantics. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Amaury Chamayou (achamayou)
force-pushed
the
achamayou-rust-interface-exploration
branch
from
August 28, 2026 14:05
fa47450 to
30b12d6
Compare
Copilot started reviewing on behalf of
Amaury Chamayou (achamayou)
August 28, 2026 17:22
View session
Co-authored-by: achamayou <4016369+achamayou@users.noreply.github.com>
Co-authored-by: achamayou <4016369+achamayou@users.noreply.github.com>
Co-authored-by: achamayou <4016369+achamayou@users.noreply.github.com>
Co-authored-by: achamayou <4016369+achamayou@users.noreply.github.com>
Co-authored-by: cjen1-msft <chrisjensen@microsoft.com>
cjen1-msft
reviewed
Sep 21, 2026
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Amaury Chamayou (achamayou)
requested review from
cjen1-msft
and
a balanced review from Copilot
September 22, 2026 17:26
Copilot started reviewing on behalf of
Amaury Chamayou (achamayou)
September 22, 2026 17:31
View session
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Panic output can expose sensitive data, and API and release documentation contracts remain inconsistent.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 1
Open (5)
Resolved since last review (5)
This validation permits CR/LF in values and separators or whitespace in names. The HTTP/1… Panic containment is only tested against the mocked FFI, whereset_erroralways fails; no test… This accepts every 4xx/5xx value, butccf_rust_response_erroraccepts only statuses in… The statement that map values borrow the callback is incorrect:ReadOnlyMap::getandMap::get…7.0.13is already the latest published release, so this new entry cannot be added to that…
- Install a panic hook from export_app! which does not report panics raised by the application's registration function, handlers, or handler destructors, since Rust's default hook writes panic messages, which may contain request or KV data, to host-visible stderr. Other panics, including those from CCF's own Rust code sharing the hook, are forwarded to the previous hook. - Permit empty EndpointError codes in the host bridge, matching RpcContext::set_error, instead of replacing them with a generic 500. - Assert in the e2e test that panic payloads do not reach node output, and cover empty error codes. - Move the changelog entry to 7.0.17 and state the experimental support status in the Rust docs, without implying API schema support. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Each Rust staticlib contains its own copy of the Rust standard library, so a Rust application's staticlib and libccf_rs.a could not both be linked into a release (LTO) build: rust_eh_personality, std::panicking::EMPTY_PANIC and ARGV_INIT_ARRAY were defined twice. Debug builds only linked because the linker skipped the second, identical copy of each std archive member. - ccf-app depends on ccf-rs, so a Rust application's staticlib contains CCF's own Rust code and a single standard library. - ccf-rs is also built as an rlib. CMake builds libccf_rs.a with cargo rustc --crate-type staticlib, because Cargo does not apply LTO to a library which is also built as an rlib. - ccf_rs links the consuming target's CCF_RUST_APP_LIB, set by add_ccf_rust_app, in place of libccf_rs.a. - Install the TAV sources needed to build ccf-rs against an installed CCF, pass the C toolchain to the SDK unit tests, and document that a binary can only link one Rust staticlib. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Each Rust staticlib exports its own Rust runtime, so linking libccf_rs.a with a Rust application archive failed in release builds with duplicate runtime symbols. Avoid rebuilding CCF's Rust dependency graph in every application by isolating the existing archive instead: - combine libccf_rs.a into one relocatable object; - keep only the cose_* and tav_* C ABI symbols global; - verify at build time that required exports remain and no implementation symbols escape; - restore ccf-app as a standalone SDK dependency, and install only that SDK rather than CCF's Rust implementation sources. CCF and the application then retain independent, locally scoped Rust runtimes while continuing to communicate exclusively through C ABIs. Rust application builds once again compile only the application, ccf-app, and their own Cargo dependencies. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
The CMake format check (gersemi 0.27.0) in scripts/ci-checks.sh failed on VMSS Virtual A because the FATAL_ERROR message() call exceeded the line length limit. Wrap the arguments as gersemi expects. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…1d8-603c-42a9-bde1-992ae86a3a32
Build and export the C++ Rust application bridge as a framework-owned object target rather than compiling its source in each application. This lets the bridge use CCF's private CompactedVersionConflict definition without promoting that implementation detail to the public C++ API. Restore the exception to src/kv, remove the public shim, make the panic strategy guard require unwind directly, and add an end-to-end regression which deterministically forces a Rust endpoint compaction conflict and observes its transparent retry. Also teach coverage handling about object libraries so the installed bridge remains instrumented without being reported as a standalone coverage binary. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Amaury Chamayou (achamayou)
requested a review
from Eddy Ashton (eddyashton)
September 24, 2026 15:14
cjen1-msft
reviewed
Sep 24, 2026
cjen1-msft
approved these changes
Sep 24, 2026
Select both supported Rust authentication policies explicitly and throw if an unexpected value reaches endpoint registration, rather than implicitly treating every non-user-cert value as unauthenticated. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Amaury Chamayou (achamayou)
deleted the
achamayou-rust-interface-exploration
branch
September 24, 2026 16:59
Amaury Chamayou (achamayou)
added a commit
that referenced
this pull request
Sep 28, 2026
#8200 was squash-merged into main, so resolve by taking main's final Rust interface and re-applying only this branch's documentation commit. Keep main's experimental warning, bridge/linking notes and panic-hook support, and update docs that described superseded behaviour: the installed bridge is now a precompiled object, and empty error codes are accepted. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Amaury Chamayou (achamayou)
added a commit
that referenced
this pull request
Sep 28, 2026
Restore the trait's summary from #8200, and name the trait in the guide's handler rules instead of listing its Send and Sync bounds. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
This PR explores what it would take to support native CCF applications written in Rust while keeping the integration boundary small and explicit.
It introduces:
ccf-appRust crate for endpoint registration, request and response handling, authentication selection, and raw-byte KV access;Goal
The goal is to evaluate the viability and ergonomics of Rust as another native CCF application language without exposing C++ implementation details across the boundary. The proposed API deliberately starts small so that ownership, lifetime, panic containment, transaction, concurrency, and packaging concerns can be reviewed before expanding the surface area.
Exploration status
This is exploratory work, not a commitment to a stable or production-supported Rust SDK. The current interface intentionally omits advanced endpoint configuration, custom authentication policies, historical queries, indexing, and commit callbacks. Feedback is especially welcome on the ABI design, safety guarantees, SDK ergonomics, and long-term maintenance implications.
This replays the work from achamayou/CCF#107 onto the current
microsoft/CCFmainbranch so it can be discussed and evaluated in the upstream repository.