lgwks-std — the + in std+
The rule, in the Director's words: if a library is not in std or std+,
it is not an approved dependency, and the code does not compile until a human
has registered it in the semantic contract.
This crate is the +. lgwks-std-gate is the "does not compile."
Supported Rust policy
lgwks_std and lgwks_std_gate are governed by two Rust contracts:
- Current stable contract: workspace and CI run against Rust 1.98.0.
- MSRV contract:
Cargo.tomlrust-versionfields are the minimum supported compiler, not the active CI compiler. They move forward only when code or dependency requirements require it.
What it provides
Every module is a declarative primitive — one import, one function call, done. The crate wraps a vetted dependency stack that bottoms out at zero external deps. Core modules are in the default feature set; heavier stacks are optional features so path-only consumers do not pull heavyweight transitive dependencies.
// core — zero external deps
use hex;
use time;
let hex_str = encode;
let now = now_rfc3339;
// random — opt-in, adds getrandom
let id = new_v4.unwrap;
// hash — opt-in, adds blake3
let digest = blake3;
// pattern — opt-in, adds regex
let re = new.unwrap;
Modules
Default feature set: core (enabled by default).
| feature | module | what it owns | replaces |
|---|---|---|---|
core |
encoding |
Base64/percent primitives | base64, percent-encoding |
core |
fs |
Recursive directory walking with sandbox enforcement | walkdir |
core |
glob |
Shell-style path pattern matching (DP, O(M*N)) | glob |
core |
hex |
Hex encode/decode | hex |
core |
leb128 |
LEB128 variable-length integer encoding | — |
core |
task |
Minimal single-threaded async executor | — |
core |
time |
RFC 3339 timestamps, calendar math | chrono / time |
random |
random |
OS entropy | getrandom |
random |
id |
UUID v4 generation and parsing | uuid |
hash |
hash |
BLAKE3 content-addressable hashing | blake3 |
pattern |
pattern |
Compiled regex matching (linear-time) | regex |
json |
json |
JSON encoding and decoding | serde, serde_json |
ron |
ron |
Rusty Object Notation encoding and decoding | ron |
wire |
wire |
Internal binary wire serialization | rkyv |
Feature presets:
core(default): zero external dependencies.random,hash,pattern,json,ron,wire: each unlocks one capability.full: all of the above.
INV-STDPLUS-APPROVED-ONLY
The crate declares six external crates, all vetted leaf stacks, enabled by features:
blake3(featurehash; 3 zero-dep leaves: arrayvec, cfg-if, constant_time_eq)regex(featurepattern; 4 crates, all BurntSushi, all internal: memchr, regex-syntax, aho-corasick, regex-automata — zero external deps)serde(featurejson; derive stack shared with serde_json)serde_json(featurejson)rkyv(featurewire; 5 djkoloski crates: rend, ptr_meta, rancor, munge + derive; zero external deps)getrandom(featurerandom; supported on linux/macOS/windows)ron(featureron; bitflags — one zero-dep leaf beyond serde)
The gate test deps_are_approved_leaves in lgwks-std-gate mechanically
verifies no unapproved dependency appears in the manifest.
Contract source-of-truth
crates/lgwks-std/Cargo.tomlis authoritative for dependency declarations.contract/APPROVED.tomlis authoritative for approved versions.crates/lgwks-std-gate/src/lib.rsis authoritative for enforcement behavior.
Distribution lane
lgwks_std is prepared as a normal Cargo package artifact:
- distribution lane: crates.io (public package) / manifest-only dependency.
- package entrypoint:
crates/lgwks-std/Cargo.toml. - release check:
cargo package --manifest-path crates/lgwks-std/Cargo.toml.
Smoke-test fixture
Run the package smoke test from this repo root:
The script packages the crate, unpacks the produced .crate, and consumes it as a
standalone dependency from outside the Braid workspace dependency graph.
The gate
Three lines in a consumer's build.rs turn INV-DEP-REGISTERED into a compile
error:
// build.rs
License
BSD-3-Clause