From 81bb4aa95316eab5be542e7bd7bec6de0b6697b1 Mon Sep 17 00:00:00 2001 From: Travis Long Date: Thu, 17 Sep 2026 08:38:57 -0500 Subject: [PATCH] Bug 2071060 - Upgrade hyper dependency for nimbus-cli Move the nimbus-cli test server to axum 0.8 (hyper 1.x) from axum 0.6, along with tower-http 0.6, tower-livereload 0.10 and tokio 1.49. This drops the direct hyper and tower dependencies, so nimbus-cli's own tree no longer pulls the h2 0.3 flagged by RUSTSEC-2026-0258. The advisory ignore stays for now, since viaduct-hyper is still on hyper 0.14 until bug 2067851 lands. --- .github/workflows/dependency-check.yaml | 3 +- CHANGELOG.md | 4 + Cargo.lock | 325 ++++++++++++------ DEPENDENCIES.md | 41 +-- components/support/nimbus-cli/Cargo.toml | 17 +- .../support/nimbus-cli/src/output/server.rs | 113 +++--- megazords/ios-rust/DEPENDENCIES.md | 41 +-- megazords/ios-rust/focus/DEPENDENCIES.md | 41 +-- 8 files changed, 331 insertions(+), 254 deletions(-) diff --git a/.github/workflows/dependency-check.yaml b/.github/workflows/dependency-check.yaml index 7c7fb6fb577..a484cf8332b 100644 --- a/.github/workflows/dependency-check.yaml +++ b/.github/workflows/dependency-check.yaml @@ -64,7 +64,8 @@ jobs: # reading https://github.com/rustsec/advisory-db/issues/288, this is a false # positive for clap and based on our dependency tree, we only use `yaml-rust` in `clap`. # * RUSTSEC-2026-0258: The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. - # We're stuck with it for the moment until we upgrade hyper (bug 2067851). + # The only remaining hyper 0.14 path is viaduct-hyper, which is being moved to reqwest in + # bug 2067851 (PR #7596); this ignore can go away once that lands. # viaduct-hyper is only used for connecting to remote-settings, a server unser Mozilla's control # and thus not running into the issue. cargo audit --ignore RUSTSEC-2018-0006 --ignore RUSTSEC-2026-0258 diff --git a/CHANGELOG.md b/CHANGELOG.md index 177e54c19b2..4409cda0adf 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -9,6 +9,10 @@ ### Glean - Updated to v70.0.0 ([#7598](https://github.com/mozilla/application-services/pull/7598)) +### Nimbus + +- `nimbus-cli`'s `start-server` now runs on `axum` 0.8 (and so `hyper` 1.x) instead of `axum` 0.6 / `hyper` 0.14, which removes the `h2` 0.3 flagged by RUSTSEC-2026-0258 from its own dependencies. No change to the server's behaviour or its URLs. ([bug 2071060](https://bugzilla.mozilla.org/show_bug.cgi?id=2071060)) + # v157.0 (_2026-09-10_) ## ✨ What's Changed ✨ diff --git a/Cargo.lock b/Cargo.lock index 1b3187f0cca..9ed004920a3 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -250,6 +250,12 @@ dependencies = [ "syn 2.0.106", ] +[[package]] +name = "atomic-waker" +version = "1.1.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1505bd5d3d116872e7271a6d4e16d81d0c8570876c8de68093a09ac269d8aac0" + [[package]] name = "autocfg" version = "1.1.0" @@ -282,26 +288,26 @@ dependencies = [ [[package]] name = "axum" -version = "0.6.19" +version = "0.8.9" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "a6a1de45611fdb535bfde7b7de4fd54f4fd2b17b1737c0a59b69bf9b92074b8c" +checksum = "31b698c5f9a010f6573133b09e0de5408834d0c82f8d7475a89fc1867a71cd90" dependencies = [ - "async-trait", "axum-core", - "bitflags 1.3.2", "bytes", + "form_urlencoded", "futures-util", - "http", - "http-body", - "hyper", + "http 1.5.0", + "http-body 1.1.0", + "http-body-util", + "hyper 1.11.1", + "hyper-util", "itoa", "matchit", "memchr", "mime", "percent-encoding", "pin-project-lite", - "rustversion", - "serde", + "serde_core", "serde_json", "serde_path_to_error", "serde_urlencoded", @@ -310,23 +316,26 @@ dependencies = [ "tower", "tower-layer", "tower-service", + "tracing", ] [[package]] name = "axum-core" -version = "0.3.4" +version = "0.5.6" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "759fa577a247914fd3f7f76d62972792636412fbfd634cd452f6a385a74d2d2c" +checksum = "08c78f31d7b1291f7ee735c1c6780ccde7785daae9a9206026862dab7d8792d1" dependencies = [ - "async-trait", "bytes", - "futures-util", - "http", - "http-body", + "futures-core", + "http 1.5.0", + "http-body 1.1.0", + "http-body-util", "mime", - "rustversion", + "pin-project-lite", + "sync_wrapper", "tower-layer", "tower-service", + "tracing", ] [[package]] @@ -362,6 +371,12 @@ version = "0.22.1" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "72b3254f16251a8381aa12e40e3c4d2f0199f8c6508fbecb9d91f575e0fbb8c6" +[[package]] +name = "base64" +version = "0.23.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ac07cdecf99051d9a5238b80f35af32cdeba5b336e55d957b318b50137e18da5" + [[package]] name = "basic-toml" version = "0.1.2" @@ -579,7 +594,7 @@ dependencies = [ "num-traits", "serde", "wasm-bindgen", - "windows-link", + "windows-link 0.1.3", ] [[package]] @@ -1868,7 +1883,7 @@ dependencies = [ "futures-core", "futures-sink", "futures-util", - "http", + "http 0.2.9", "indexmap 2.5.0", "slab", "tokio", @@ -1973,6 +1988,16 @@ dependencies = [ "itoa", ] +[[package]] +name = "http" +version = "1.5.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "918d3568bebf352712bc2ef3d46a8bcf1a75b373be6539de198e9105cbbf9ce0" +dependencies = [ + "bytes", + "itoa", +] + [[package]] name = "http-body" version = "0.4.5" @@ -1980,15 +2005,32 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "d5f38f16d184e36f2408a55281cd658ecbd3ca05cce6d6510a176eca393e26d1" dependencies = [ "bytes", - "http", + "http 0.2.9", "pin-project-lite", ] [[package]] -name = "http-range-header" -version = "0.3.0" +name = "http-body" +version = "1.1.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "0bfe8eed0a9285ef776bb792479ea3834e8b94e13d615c2f66d03dd50a435a29" +checksum = "ca2a8f2913ee65f60facd6a5905613afaa448497a0230cc41ce022d93290bc2c" +dependencies = [ + "bytes", + "http 1.5.0", +] + +[[package]] +name = "http-body-util" +version = "0.1.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "23169fe34a5fbcdd3f3862e78fb9b6fccd5f02a6dc6f732547005d45631ce71c" +dependencies = [ + "bytes", + "futures-core", + "http 1.5.0", + "http-body 1.1.0", + "pin-project-lite", +] [[package]] name = "httparse" @@ -2019,19 +2061,40 @@ dependencies = [ "futures-core", "futures-util", "h2", - "http", - "http-body", + "http 0.2.9", + "http-body 0.4.5", "httparse", "httpdate", "itoa", "pin-project-lite", - "socket2", + "socket2 0.4.9", "tokio", "tower-service", "tracing", "want", ] +[[package]] +name = "hyper" +version = "1.11.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "27b501faa50e7a26c3d3560ca625132f4078a17771f4810baf70475ae48cbe43" +dependencies = [ + "atomic-waker", + "bytes", + "futures-channel", + "futures-core", + "http 1.5.0", + "http-body 1.1.0", + "httparse", + "httpdate", + "itoa", + "pin-project-lite", + "smallvec", + "tokio", + "want", +] + [[package]] name = "hyper-tls" version = "0.5.0" @@ -2039,12 +2102,35 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "d6183ddfa99b85da61a140bea0efc93fdf56ceaa041b37d553518030827f9905" dependencies = [ "bytes", - "hyper", + "hyper 0.14.27", "native-tls", "tokio", "tokio-native-tls", ] +[[package]] +name = "hyper-util" +version = "0.1.20" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "96547c2556ec9d12fb1578c4eaf448b04993e7fb79cbaad930a656880a6bdfa0" +dependencies = [ + "base64 0.22.1", + "bytes", + "futures-channel", + "futures-util", + "http 1.5.0", + "http-body 1.1.0", + "hyper 1.11.1", + "ipnet", + "libc", + "percent-encoding", + "pin-project-lite", + "socket2 0.6.5", + "tokio", + "tower-service", + "tracing", +] + [[package]] name = "iana-time-zone" version = "0.1.53" @@ -2333,6 +2419,12 @@ dependencies = [ "windows-sys 0.48.0", ] +[[package]] +name = "ipnet" +version = "2.12.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "791930b43c0d5973160d90a8f3894509f2b273430f5c5c73b668636d0287c5c0" + [[package]] name = "is-terminal" version = "0.4.7" @@ -2628,9 +2720,9 @@ dependencies = [ [[package]] name = "matchit" -version = "0.7.0" +version = "0.8.4" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "b87248edafb776e59e6ee64a79086f65890d3510f2c656c000bf2a7e8a0aea40" +checksum = "47e1ffaa40ddd1f3ed91f717a33c8c0ee23fff369e3aa8772b9605cc1d22f4c3" [[package]] name = "md-5" @@ -2771,16 +2863,6 @@ version = "0.3.17" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "6877bb514081ee2a7ff5ef9de3281f14a4dd4bceac4c09388074a6b5df8a139a" -[[package]] -name = "mime_guess" -version = "2.0.4" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "4192263c238a5f0d0c6bfd21f336a313a4ce1c450542449ca191bb657b4642ef" -dependencies = [ - "mime", - "unicase", -] - [[package]] name = "minimal-lexical" version = "0.2.1" @@ -2804,13 +2886,13 @@ checksum = "05015102dad0f7d61691ca347e9d9d9006685a64aefb3d79eecf62665de2153d" [[package]] name = "mio" -version = "0.8.11" +version = "1.2.3" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "a4a650543ca06a924e8b371db273b2756685faae30f8487da1b56505a8f78b0c" +checksum = "4b18443e9c262bfe8fa82f51666e2642c53393f7e5c27b3e1aeab922cff5b9d8" dependencies = [ "libc", "wasi 0.11.0+wasi-snapshot-preview1", - "windows-sys 0.48.0", + "windows-sys 0.61.2", ] [[package]] @@ -2920,11 +3002,11 @@ dependencies = [ "copypasta", "glob", "heck", - "hyper", "local-ip-address", "nimbus-fml", "percent-encoding", "remote_settings", + "reqwest", "serde", "serde_json", "serde_yaml 0.9.21", @@ -2932,7 +3014,6 @@ dependencies = [ "termcolor", "thiserror 2.0.20", "tokio", - "tower", "tower-http", "tower-livereload", "unicode-segmentation", @@ -3284,31 +3365,11 @@ version = "2.3.1" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "e3148f5046208a5d56bcfc03053e3ca6334e51da8dfb19b6cdc8b306fae3283e" -[[package]] -name = "pin-project" -version = "1.1.2" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "030ad2bc4db10a8944cb0d837f158bdfec4d4a4873ab701a95046770d11f8842" -dependencies = [ - "pin-project-internal", -] - -[[package]] -name = "pin-project-internal" -version = "1.1.2" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "ec2e072ecce94ec471b13398d5402c188e76ac03cf74dd1a975161b23a3f6d9c" -dependencies = [ - "proc-macro2", - "quote", - "syn 2.0.106", -] - [[package]] name = "pin-project-lite" -version = "0.2.16" +version = "0.2.17" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "3b3cff922bd51709b605d9ead9aa71031d81447142d828eb4a6eba76fe619f9b" +checksum = "a89322df9ebe1c1578d689c92318e070967d1042b512afbe49518723f4e6d5cd" [[package]] name = "pin-utils" @@ -3757,6 +3818,35 @@ dependencies = [ "viaduct-dev", ] +[[package]] +name = "reqwest" +version = "0.13.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "16a1cfa75cc186dd73d5818e510e042e40927bccc9c236b061cea97e1eb08029" +dependencies = [ + "base64 0.23.1", + "bytes", + "futures-core", + "http 1.5.0", + "http-body 1.1.0", + "http-body-util", + "hyper 1.11.1", + "hyper-util", + "js-sys", + "log", + "percent-encoding", + "pin-project-lite", + "sync_wrapper", + "tokio", + "tower", + "tower-http", + "tower-service", + "url", + "wasm-bindgen", + "wasm-bindgen-futures", + "web-sys", +] + [[package]] name = "restmail-client" version = "0.1.0" @@ -4194,6 +4284,16 @@ dependencies = [ "winapi", ] +[[package]] +name = "socket2" +version = "0.6.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c3d1e2c7f27f8d4cb10542a02c49005dbd6e93095799d6f3be745fae9f8fedd4" +dependencies = [ + "libc", + "windows-sys 0.61.2", +] + [[package]] name = "sql-support" version = "0.1.0" @@ -4418,9 +4518,12 @@ dependencies = [ [[package]] name = "sync_wrapper" -version = "0.1.2" +version = "1.0.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "2047c6ded9c721764247e62cd3b03c09ffc529b2ba5b10ec482ae507a4a70160" +checksum = "0bf256ce5efdfa370213c1dabab5935a12e49f2c58d15e9eac2870d3b4f27263" +dependencies = [ + "futures-core", +] [[package]] name = "synstructure" @@ -4603,31 +4706,28 @@ dependencies = [ [[package]] name = "tokio" -version = "1.29.1" +version = "1.53.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "532826ff75199d5833b9d2c5fe410f29235e25704ee5f0ef599fb51c21f4a4da" +checksum = "202caea871b69668250d242070849eb495be178ed697a3e98aebce5bc81a0bed" dependencies = [ - "autocfg", - "backtrace", "bytes", "libc", "mio", - "num_cpus", "pin-project-lite", - "socket2", + "socket2 0.6.5", "tokio-macros", - "windows-sys 0.48.0", + "windows-sys 0.61.2", ] [[package]] name = "tokio-macros" -version = "2.1.0" +version = "2.7.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "630bdcf245f78637c13ec01ffae6187cca34625e8c63150d424b59e55af2675e" +checksum = "78773a2a397f451582ce068015985c33193cf6dea8b74d2a639fe457b2f07b0e" dependencies = [ "proc-macro2", "quote", - "syn 2.0.106", + "syn 3.0.5", ] [[package]] @@ -4721,14 +4821,14 @@ checksum = "ab16f14aed21ee8bfd8ec22513f7287cd4a91aa92e44edfe2c17ddd004e92607" [[package]] name = "tower" -version = "0.4.13" +version = "0.5.3" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "b8fa9be0de6cf49e536ce1851f987bd21a43b771b09473c3549a6c853db37c1c" +checksum = "ebe5ef63511595f1344e2d5cfa636d973292adc0eec1f0ad45fae9f0851ab1d4" dependencies = [ "futures-core", "futures-util", - "pin-project", "pin-project-lite", + "sync_wrapper", "tokio", "tower-layer", "tower-service", @@ -4737,27 +4837,20 @@ dependencies = [ [[package]] name = "tower-http" -version = "0.4.2" +version = "0.6.11" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "7ac8060a61f8758a61562f6fb53ba3cbe1ca906f001df2e53cccddcdbee91e7c" +checksum = "4cfcf7e2740e6fc6d4d688b4ef00650406bb94adf4731e43c096c3a19fe40840" dependencies = [ "bitflags 2.11.0", "bytes", - "futures-core", "futures-util", - "http", - "http-body", - "http-range-header", - "httpdate", - "mime", - "mime_guess", - "percent-encoding", + "http 1.5.0", + "http-body 1.1.0", "pin-project-lite", - "tokio", - "tokio-util", + "tower", "tower-layer", "tower-service", - "tracing", + "url", ] [[package]] @@ -4768,13 +4861,13 @@ checksum = "121c2a6cda46980bb0fcd1647ffaf6cd3fc79a013de288782836f6df9c48780e" [[package]] name = "tower-livereload" -version = "0.8.0" +version = "0.10.3" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "7e90e6da0427c5e111e03c764d49c4e970f5a9f6569fe408e5a1cbe257f48388" +checksum = "7df210bd982165dee3c20e31deed79a3585ee6b255c070d9c73ae015cc40d2f3" dependencies = [ "bytes", - "http", - "http-body", + "http 1.5.0", + "http-body 1.1.0", "pin-project-lite", "tokio", "tower", @@ -4879,15 +4972,6 @@ dependencies = [ "serde_json", ] -[[package]] -name = "unicase" -version = "2.6.0" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "50f37be617794602aabbeee0be4f259dc1778fabe05e2d67ee8f79326d5cb4f6" -dependencies = [ - "version_check", -] - [[package]] name = "unicode-ident" version = "1.0.18" @@ -5172,7 +5256,7 @@ version = "0.2.0" dependencies = [ "async-trait", "error-support", - "hyper", + "hyper 0.14.27", "hyper-tls", "tokio", "uniffi", @@ -5247,6 +5331,18 @@ dependencies = [ "wasm-bindgen-shared", ] +[[package]] +name = "wasm-bindgen-futures" +version = "0.4.45" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "cc7ec4f8827a71586374db3e87abdb5a2bb3a15afed140221307c3ec06b1f63b" +dependencies = [ + "cfg-if", + "js-sys", + "wasm-bindgen", + "web-sys", +] + [[package]] name = "wasm-bindgen-macro" version = "0.2.100" @@ -5472,6 +5568,12 @@ version = "0.1.3" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "5e6ad25900d524eaabdbbb96d20b4311e1e7ae1699af4fb28c17ae66c80d798a" +[[package]] +name = "windows-link" +version = "0.2.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f0805222e57f7521d6a62e36fa9163bc891acd422f971defe97d64e70d0a4fe5" + [[package]] name = "windows-sys" version = "0.36.1" @@ -5509,6 +5611,15 @@ dependencies = [ "windows-targets 0.48.0", ] +[[package]] +name = "windows-sys" +version = "0.61.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ae137229bcbd6cdf0f7b80a31df61766145077ddf49416a728b02cb3921ff3fc" +dependencies = [ + "windows-link 0.2.1", +] + [[package]] name = "windows-targets" version = "0.48.0" diff --git a/DEPENDENCIES.md b/DEPENDENCIES.md index 079de3c1ea9..0721cc4df48 100644 --- a/DEPENDENCIES.md +++ b/DEPENDENCIES.md @@ -527,7 +527,6 @@ The following text applies to code linked from these dependencies: [minimal-lexical](https://github.com/Alexhuszagh/minimal-lexical), [native-tls](https://github.com/sfackler/rust-native-tls), [num-traits](https://github.com/rust-num/num-traits), -[num_cpus](https://github.com/seanmonstar/num_cpus), [ohttp](https://github.com/martinthomson/ohttp), [once_cell](https://github.com/matklad/once_cell), [openssl-macros](https://github.com/sfackler/rust-openssl), @@ -1518,31 +1517,27 @@ The following text applies to code linked from these dependencies: [tokio](https://github.com/tokio-rs/tokio) ``` -Copyright (c) 2023 Tokio Contributors +MIT License -Permission is hereby granted, free of charge, to any -person obtaining a copy of this software and associated -documentation files (the "Software"), to deal in the -Software without restriction, including without -limitation the rights to use, copy, modify, merge, -publish, distribute, sublicense, and/or sell copies of -the Software, and to permit persons to whom the Software -is furnished to do so, subject to the following -conditions: +Copyright (c) Tokio Contributors -The above copyright notice and this permission notice -shall be included in all copies or substantial portions -of the Software. +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: -THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF -ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED -TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A -PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT -SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY -CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION -OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR -IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER -DEALINGS IN THE SOFTWARE. +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. ``` ------------- diff --git a/components/support/nimbus-cli/Cargo.toml b/components/support/nimbus-cli/Cargo.toml index 233eb7c4deb..4ae84eab290 100644 --- a/components/support/nimbus-cli/Cargo.toml +++ b/components/support/nimbus-cli/Cargo.toml @@ -8,7 +8,7 @@ license = "MPL-2.0" [features] default = ["server"] -server = ["dep:axum", "dep:tokio", "dep:tower", "dep:tower-http", "dep:tower-livereload", "dep:hyper", "dep:local-ip-address"] +server = ["dep:axum", "dep:tokio", "dep:tower-http", "dep:tower-livereload", "dep:local-ip-address"] [dependencies] clap = {version = "4.2", default-features = false, features = ["std", "derive", "error-context", "help"]} @@ -29,13 +29,16 @@ serde_yaml = "0.9.21" percent-encoding = "2.3.0" copypasta = "0.8.2" chrono = "0.4.26" -axum = { version = "0.6.18", optional = true } -tokio = { version = "1.29.1", optional = true, features = ["sync", "rt", "macros", "rt-multi-thread"] } -tower = { version = "0.4.13", optional = true } -tower-http = { version = "0.4.1", optional = true, features = ["fs", "set-header"] } -tower-livereload = { version = "0.8.0", optional = true } -hyper = { version = "0.14.27", optional = true, features = ["server"] } +axum = { version = "0.8", optional = true } +tokio = { version = "1.49", optional = true, features = ["sync", "net", "rt", "macros", "rt-multi-thread"] } +tower-http = { version = "0.6", optional = true, features = ["set-header"] } +tower-livereload = { version = "0.10", optional = true } local-ip-address = { version = "0.5.4", optional = true } cfg-if = "1.0.0" termcolor = "1.4.1" tempfile = "3.1" + +[dev-dependencies] +# The server tests only talk plain HTTP to 127.0.0.1, so `default-features = false` keeps TLS and +# h2 out of the dependency tree entirely. +reqwest = { version = "0.13", default-features = false } diff --git a/components/support/nimbus-cli/src/output/server.rs b/components/support/nimbus-cli/src/output/server.rs index 1de49082d69..31eb98a2eb9 100644 --- a/components/support/nimbus-cli/src/output/server.rs +++ b/components/support/nimbus-cli/src/output/server.rs @@ -19,42 +19,41 @@ use axum::{ extract::{Path, State}, http, response::{Html, IntoResponse}, - routing::{get, post, IntoMakeService}, - Json, Router, Server, + routing::{get, post}, + Json, Router, }; -use hyper::server::conn::AddrIncoming; use serde_json::Value; -use tower::layer::util::Stack; +use tokio::net::TcpListener; use tower_http::set_header::SetResponseHeaderLayer; use tower_livereload::{LiveReloadLayer, Reloader}; -fn create_server( - livereload: LiveReloadLayer, - state: Db, -) -> Result>, anyhow::Error> { - let app = create_app(livereload, state); - - let addr = get_address()?; - eprintln!("Copy the address http://{}/ into your mobile browser", addr); - - let server = Server::try_bind(&addr)?.serve(app.into_make_service()); - - Ok(server) -} - fn create_app(livereload: LiveReloadLayer, state: Db) -> Router { Router::new() .route("/", get(index)) .route("/style.css", get(style)) .route("/script.js", get(script)) .route("/post", post(post_handler)) - .route("/buckets/:bucket/collections/:collection/records", get(rs)) .route( - "/v2/buckets/:bucket/collections/:collection/records", + "/buckets/{bucket}/collections/{collection}/records", + get(rs), + ) + .route( + "/v2/buckets/{bucket}/collections/{collection}/records", get(rs), ) .layer(livereload) - .layer(no_cache_layer()) + .layer(SetResponseHeaderLayer::overriding( + http::header::CACHE_CONTROL, + http::HeaderValue::from_static("no-cache, no-store, must-revalidate"), + )) + .layer(SetResponseHeaderLayer::overriding( + http::header::PRAGMA, + http::HeaderValue::from_static("no-cache"), + )) + .layer(SetResponseHeaderLayer::overriding( + http::header::EXPIRES, + http::HeaderValue::from_static("0"), + )) .with_state(state) } @@ -67,8 +66,13 @@ fn create_state(livereload: &LiveReloadLayer) -> Db { pub(crate) async fn start_server() -> Result { let livereload = LiveReloadLayer::new(); let state = create_state(&livereload); - let server = create_server(livereload, state)?; - server.await?; + let app = create_app(livereload, state); + + let addr = get_address()?; + eprintln!("Copy the address http://{}/ into your mobile browser", addr); + + let listener = TcpListener::bind(addr).await?; + axum::serve(listener, app).await?; Ok(true) } @@ -226,48 +230,23 @@ impl InMemoryDb { } } -type Srhl = SetResponseHeaderLayer; - -fn no_cache_layer() -> Stack> { - Stack::new( - SetResponseHeaderLayer::overriding( - http::header::CACHE_CONTROL, - http::HeaderValue::from_static("no-cache, no-store, must-revalidate"), - ), - Stack::new( - SetResponseHeaderLayer::overriding( - http::header::PRAGMA, - http::HeaderValue::from_static("no-cache"), - ), - SetResponseHeaderLayer::overriding( - http::header::EXPIRES, - http::HeaderValue::from_static("0"), - ), - ), - ) -} - #[cfg(test)] mod tests { - use hyper::{Body, Method, Request, Response}; use serde_json::json; - use std::net::TcpListener; use tokio::sync::oneshot::Sender; use super::*; - fn start_test_server(port: u32) -> Result<(Db, Sender<()>)> { + async fn start_test_server(port: u32) -> Result<(Db, Sender<()>)> { let livereload = LiveReloadLayer::new(); let state = create_state(&livereload); let app = create_app(livereload, state.clone()); let addr = format!("127.0.0.1:{port}"); - let listener = TcpListener::bind(addr)?; + let listener = TcpListener::bind(addr).await?; let (tx, rx) = tokio::sync::oneshot::channel::<()>(); tokio::spawn(async move { - Server::from_tcp(listener) - .unwrap() - .serve(app.into_make_service()) + axum::serve(listener, app) .with_graceful_shutdown(async { rx.await.ok(); }) @@ -281,36 +260,30 @@ mod tests { async fn get(port: u32, endpoint: &str) -> Result { let url = format!("http://127.0.0.1:{port}{endpoint}"); - let client = hyper::Client::new(); - let response = client - .request(Request::builder().uri(url).body(Body::empty()).unwrap()) - .await - .unwrap(); + let response = reqwest::Client::new().get(url).send().await?; - let body = hyper::body::to_bytes(response.into_body()).await.unwrap(); + let body = response.bytes().await?; let s = std::str::from_utf8(&body)?; Ok(s.to_string()) } - async fn post_payload(payload: &T, addr: &str) -> Result> { + async fn post_payload(payload: &T, addr: &str) -> Result { let url = format!("http://{addr}/post"); let body = serde_json::to_string(payload)?; - let request = Request::builder() - .method(Method::POST) - .uri(url) + Ok(reqwest::Client::new() + .post(url) .header("accept", "application/json") .header("Content-type", "application/json; charset=UTF-8") - .body(Body::from(body)) - .unwrap(); - let client = hyper::Client::new(); - Ok(client.request(request).await?) + .body(body) + .send() + .await?) } #[tokio::test] async fn test_smoke_test() -> Result<()> { let port = 1234; - let (_db, tx) = start_test_server(port)?; + let (_db, tx) = start_test_server(port).await?; let s = get(port, "/").await?; assert!(s.contains("")); @@ -322,7 +295,7 @@ mod tests { #[tokio::test] async fn test_posting_platform_url() -> Result<()> { let port = 1235; - let (db, tx) = start_test_server(port)?; + let (db, tx) = start_test_server(port).await?; let platform = "android"; let deeplink = "fenix-dev-test://open-now"; @@ -342,7 +315,7 @@ mod tests { #[tokio::test] async fn test_posting_platform_url_from_index_page() -> Result<()> { let port = 1236; - let (_, tx) = start_test_server(port)?; + let (_, tx) = start_test_server(port).await?; let platform = "android"; let deeplink = "fenix-dev-test://open-now"; @@ -361,7 +334,7 @@ mod tests { #[tokio::test] async fn test_posting_value_to_fake_remote_settings() -> Result<()> { let port = 1237; - let (_, tx) = start_test_server(port)?; + let (_, tx) = start_test_server(port).await?; let platform = "android"; let deeplink = "fenix-dev-test://open-now"; @@ -389,7 +362,7 @@ mod tests { #[tokio::test] async fn test_getting_null_values_from_fake_remote_settings() -> Result<()> { let port = 1238; - let (_, tx) = start_test_server(port)?; + let (_, tx) = start_test_server(port).await?; // Part 1: get from remote settings page before anything has been posted yet. let s = get(port, "/v2/buckets/BUCKET/collections/COLLECTION/records").await?; diff --git a/megazords/ios-rust/DEPENDENCIES.md b/megazords/ios-rust/DEPENDENCIES.md index e717560a898..d6e3d3f30d8 100644 --- a/megazords/ios-rust/DEPENDENCIES.md +++ b/megazords/ios-rust/DEPENDENCIES.md @@ -517,7 +517,6 @@ The following text applies to code linked from these dependencies: [minimal-lexical](https://github.com/Alexhuszagh/minimal-lexical), [native-tls](https://github.com/sfackler/rust-native-tls), [num-traits](https://github.com/rust-num/num-traits), -[num_cpus](https://github.com/seanmonstar/num_cpus), [ohttp](https://github.com/martinthomson/ohttp), [once_cell](https://github.com/matklad/once_cell), [parking_lot](https://github.com/Amanieu/parking_lot), @@ -1447,31 +1446,27 @@ The following text applies to code linked from these dependencies: [tokio](https://github.com/tokio-rs/tokio) ``` -Copyright (c) 2023 Tokio Contributors +MIT License -Permission is hereby granted, free of charge, to any -person obtaining a copy of this software and associated -documentation files (the "Software"), to deal in the -Software without restriction, including without -limitation the rights to use, copy, modify, merge, -publish, distribute, sublicense, and/or sell copies of -the Software, and to permit persons to whom the Software -is furnished to do so, subject to the following -conditions: +Copyright (c) Tokio Contributors -The above copyright notice and this permission notice -shall be included in all copies or substantial portions -of the Software. +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: -THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF -ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED -TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A -PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT -SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY -CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION -OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR -IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER -DEALINGS IN THE SOFTWARE. +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. ``` ------------- diff --git a/megazords/ios-rust/focus/DEPENDENCIES.md b/megazords/ios-rust/focus/DEPENDENCIES.md index aa80d10824d..481a0018af4 100644 --- a/megazords/ios-rust/focus/DEPENDENCIES.md +++ b/megazords/ios-rust/focus/DEPENDENCIES.md @@ -505,7 +505,6 @@ The following text applies to code linked from these dependencies: [minimal-lexical](https://github.com/Alexhuszagh/minimal-lexical), [native-tls](https://github.com/sfackler/rust-native-tls), [num-traits](https://github.com/rust-num/num-traits), -[num_cpus](https://github.com/seanmonstar/num_cpus), [ohttp](https://github.com/martinthomson/ohttp), [once_cell](https://github.com/matklad/once_cell), [parking_lot](https://github.com/Amanieu/parking_lot), @@ -1399,31 +1398,27 @@ The following text applies to code linked from these dependencies: [tokio](https://github.com/tokio-rs/tokio) ``` -Copyright (c) 2023 Tokio Contributors +MIT License -Permission is hereby granted, free of charge, to any -person obtaining a copy of this software and associated -documentation files (the "Software"), to deal in the -Software without restriction, including without -limitation the rights to use, copy, modify, merge, -publish, distribute, sublicense, and/or sell copies of -the Software, and to permit persons to whom the Software -is furnished to do so, subject to the following -conditions: +Copyright (c) Tokio Contributors -The above copyright notice and this permission notice -shall be included in all copies or substantial portions -of the Software. +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: -THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF -ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED -TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A -PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT -SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY -CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION -OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR -IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER -DEALINGS IN THE SOFTWARE. +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. ``` -------------