1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
[]
= "mkit-cli"
= "The mkit command-line tool: a content-addressed VCS with native attestation support"
= ["mkit", "vcs", "cli", "attestation", "content-addressed"]
= ["command-line-utilities", "cryptography"]
= "README.md"
# Published to crates.io so `cargo install mkit-cli` works (it installs the
# `mkit` binary). It ALSO ships as a signed binary via the GitHub Release
# archives and `cargo install --git` (see docs/INSTALL.md). NOTE: this crate's
# library surface is the CLI's internals and is NOT a stable API — it is
# deliberately excluded from cargo-semver-checks; depend on the `mkit-*`
# library crates instead, not on `mkit_cli::…`.
= true
= true
= true
= true
= true
= true
# The binary is named `mkit` (src/main.rs); set explicitly because it differs
# from the crate name. Install via `cargo install mkit-cli`, the release
# archives, or `cargo install --git … mkit-cli`.
= "mkit"
# `cargo binstall mkit-cli` metadata. Points cargo-binstall at the
# GitHub Release archive layout so users can install the prebuilt
# binary without building from source. The crate is published to
# crates.io, so plain `cargo binstall mkit-cli` resolves this manifest;
# the `--git` form below works too when targeting an unpublished revision:
#
# cargo binstall --git https://github.com/officialunofficial/mkit mkit-cli
#
# Archive layout pinned by release.yml:
# mkit-<version>-<target>.tar.gz
# └── mkit-<version>-<target>/mkit
[]
= "{ repo }/releases/download/v{ version }/mkit-{ version }-{ target }.{ archive-format }"
= "tgz"
= "mkit-{ version }-{ target }/{ bin }{ binary-ext }"
# Cosign bundle / SHA256 sidecar files live next to the tarball.
# cargo-binstall will pull the .sha256 automatically via the same URL
# pattern + ".sha256" suffix. Cosign verification is out-of-band.
= ""
[]
= true
[[]]
= "mkit"
= "src/main.rs"
[]
# Inter-workspace deps need explicit `version = ...` alongside the
# path so `cargo publish` accepts them; path-only deps are rejected by
# the registry. Track workspace.package.version.
# `batch-verify` (not a default feature — see mkit-core's Cargo.toml)
# is required by `verify_new_object_signatures`'s batch fast path.
= { = "0.5", = "../mkit-core", = ["batch-verify"] }
= { = "0.5", = "../mkit-attest", = ["grants"] }
= { = "0.5", = "../mkit-git-bridge", = true }
= { = "0.5", = "../mkit-keystore" }
# `mkit-transport-memory` is a dev-only (test) dependency — see
# `[dev-dependencies]`. It is intentionally NOT a normal dependency so it
# does not ship in `cargo install mkit-cli`.
= { = "0.5", = "../mkit-transport-file" }
# `mkit-transport-http`'s bespoke JSON dialect is retired as the ACTIVE
# `mkit+https://`/`mkit+http://` implementation (see `mkit-transport-connect`
# below) as of mkit#701 (SPEC-TRANSPORT-CONNECT verb parity). The dependency
# stays: its `sparse-checkout`/`pack-shards` cargo features are not yet
# covered by `mkit.transport.v1` (SPEC-TRANSPORT-CONNECT §8), and
# `config.rs` still reads its `TOKEN_ENV` constant (identical value to
# `mkit-transport-connect::TOKEN_ENV`, so callers of either transport read
# the same `MKIT_API_TOKEN` env var).
= { = "0.5", = "../mkit-transport-http" }
# `mkit-transport-connect` is the native ConnectRPC client — the active
# implementation behind `mkit+https://` / loopback `mkit+http://` dispatch
# (mkit#701). Required unconditionally (client dispatch, not
# feature-gated). The CLI hosts no Connect server and has no HTTP
# server stack.
= { = "0.5", = "../mkit-transport-connect" }
= { = "0.5", = "../mkit-transport-s3" }
= { = "0.5", = "../mkit-transport-ssh" }
# Optional: encrypted-stream transport. Off by default so the
# default `mkit-cli` build doesn't compile its tcp stack (tokio's `net`,
# governor, rand) or commonware. Turn on via `--features enc-transport`. See SPEC-TRANSPORT-ENC §6.
# Version-locked to the workspace (0.3); now that mkit-transport-enc is
# published, release-plz rewrites this requirement on each lockstep bump.
= { = "0.5", = "../mkit-transport-enc", = true }
# Optional: the tokio runtime `mkit mcp --http` (the `mcp-v2` feature) runs
# on, with the hyper server. Off by default, so the default `mkit-cli`
# build stays server-free (scripts/check-cli-baseline.sh): tokio is in the
# default graph only as the Connect and reqwest clients' runtime.
= { = "1", = false, = [
"rt-multi-thread",
"net",
"time",
"sync",
"macros",
], = true }
# Optional: `mkit mcp`'s modern (MCP 2026-07-28) local server, behind the
# `mcp-v2` feature. `default-features = false`: no reqwest/client-side bits —
# `transport-io` is the default stdio server, `transport-streamable-http-server`
# is `mkit mcp --http <addr>` (SEP-2567 dropped sessions for 2026-07-28
# traffic; `legacy_session_mode` still serves pre-2026-07-28 clients over
# reconnect-friendly SSE, same dual-era design as apps/mcp's TS server). Off
# by default so the default `mkit-cli` build compiles no MCP HTTP server,
# mirroring `enc-transport`. See `commands/mcp_v2.rs`.
= { = "3", = false, = [
"server",
"transport-io",
"transport-streamable-http-server",
], = true }
# `--http`'s server, matching rmcp's own documented hyper/hyper-util idiom
# (examples/servers/src/counter_hyper_streamable_http.rs) rather than pulling
# in axum: `StreamableHttpService` implements `tower::Service` directly, so
# raw hyper is all the glue this needs.
= { = "1", = ["server", "http1"], = true }
= { = "0.1", = ["tokio", "server-auto", "service"], = true }
# Constant-time bearer-token comparison for `mkit mcp --http-token` —
# already resolved transitively (ed25519-dalek pulls it), so this is not a
# new supply-chain root.
= { = "2", = true }
# HeaderMap/header names for `mkit mcp --http`'s bearer-auth wrapper — already resolved
# transitively (reqwest pulls it), not a new supply-chain root.
= { = "1", = true }
# `tower_service::Service` — the trait `mkit mcp --http`'s bearer-auth
# wrapper (`mcp_v2.rs`'s `BearerAuthHttp`) implements around
# `StreamableHttpService` before handing it to `TowerToHyperService`.
# Already resolved transitively (rmcp/hyper-util pull it), not a new
# supply-chain root.
= { = "0.3", = true }
# `BoxBody`/`Bytes` — used to construct the 401 response `BearerAuthHttp`
# returns without calling into `StreamableHttpService`, matching its
# `Response = http::Response<BoxBody<Bytes, Infallible>>` type exactly.
# Already resolved transitively (rmcp pulls both), not a new supply-chain
# root.
= { = "0.1", = true }
= { = "1", = true }
= { = "0.5", = "../mkit-rpc" }
# `mkit serve`'s engine: the ssh-frame session (`ssh`) over the pipeline
# with the `.mkit` layout stores (`fs`). `default-features = false` keeps
# out `connect` (the Connect binding: connectrpc, http) and every other
# feature: the CLI serves no Connect, SQL or test seam, and
# scripts/check-release-artifact-features.sh allows only these two.
# Nothing in it builds an async runtime (tokio's `sync` only, for a lock
# `mkit serve` never takes). First published at the 0.5.0 release.
= { = "0.5", = "../mkit-server", = false, = ["ssh", "fs"] }
# `mkit serve` drives the session future with `futures::executor::block_on`
# on the main thread: no async runtime. Already in the graph (via
# mkit-transport-connect and reqwest), so not a new supply-chain root.
= { = "0.3", = false, = ["executor", "std"] }
# commonware-cryptography's ed25519 PrivateKey is the static-key type
# the encrypted transport handshake takes. Pulled in here behind the
# `enc-transport` feature so the keystore-driven key-loading path in
# remote_dispatch can build a key from raw bytes without touching
# `mkit-transport-enc`'s internals.
= { = true, = ["std"], = true }
= "0.9.1"
# `mkit add -A`/`add .` hashes untracked/modified worktree files in
# parallel (commands/add.rs) — each file's read+BLAKE3 pass is
# independent and `WriteBatch` (mkit-core's batch.rs) was already built
# to accept concurrent writers (short-locked staged-dedup check, file
# I/O outside the lock). Native-only: mkit-core stays wasm-clean, so
# this lives in the CLI crate rather than mkit-core.
= "1"
# `wrap_help` is intentionally disabled so help-text output stays
# deterministic across terminal widths. `derive` is enabled so the
# per-command strangler migration (see clap_shim.rs) can use
# `#[derive(Parser)]`; the top-level `HELP_TEXT` constant remains
# the source of truth for `mkit --help` and is pinned by snapshot
# tests in cli.rs + tests/help_snapshot.rs.
= { = "4", = false, = ["std", "help", "error-context", "usage", "derive", "string"] }
= "3"
= "2"
# JSON-RPC parse/emit for the `mkit mcp` stdio server. Zero new supply
# chain: serde_json is already in this binary's normal dependency graph
# via mkit-attest (JCS tests) and the http/s3 transports (reqwest).
= "1"
= { = "1", = ["derive"] }
# `mkit self update` (commands/self_update.rs): release download over
# rustls (same feature set + version as mkit-transport-http — zero new
# TLS supply chain), sha256 sidecar check, and single-member tar.gz
# extraction of the new binary. Cert verification is via
# rustls-platform-verifier (OS trust store), reqwest 0.13's own default.
# Not the same trust model as mkit-transport-connect's hyper-rustls
# client, which pins an explicit webpki-roots list instead (see that
# crate's Cargo.toml and SPEC-TRANSPORT-CONNECT.md §7.3) — the two
# transports are independent and don't need to agree.
= { = "0.13", = false, = ["rustls", "blocking", "json"] }
= "0.11"
# `mkit grant`/`epoch`/`visibility` (grants/): base64url and hex for imported
# wallet and WebAuthn signatures, and secp256k1 point decompression to derive
# the 0x owner address of a keystore key. All three are already in the graph
# (mkit-attest, mkit-keystore), so no new supply-chain root.
= "0.23"
= "0.4"
= { = "0.14", = false, = ["ecdsa", "std"] }
= "1"
= "0.4"
# Used by `mkit keygen` to generate raw 32-byte secrets for non-ed25519
# algorithms (secp256k1 / p256). Same version mkit-core already pulls in.
# `sys_rng` provides `getrandom::SysRng`, the rand_core 0.10 `TryRng`
# source the bls-threshold trusted-dealer path wraps in `UnwrapErr`.
= { = "0.4", = ["sys_rng"] }
# Wraps the raw 32-byte secrets keygen pulls out of the RNG until they
# land inside the algorithm signer (which has its own scrubbing).
= "1"
# Used by `mkit key generate --algorithm bls12381-thr` to feed the
# trusted-dealer ceremony with `UnwrapErr(getrandom::SysRng)`. Gated on
# `bls-threshold` so the default build doesn't pull rand_core. 0.10 to
# match the rand_core edge commonware-cryptography 2026.9.0 depends on.
= { = "0.10", = true }
# Wire-encodes `Share` values for storage in the keystore — same
# version mkit-attest pulls. Tightened to `=` to match every other
# commonware-* pin in the workspace (previously the one outlier).
= { = "=2026.9.0", = true }
# POSIX uid + O_NOFOLLOW for keygen.rs's raw-32 load/save paths
# (secp256k1, p256). The Ed25519 path uses mkit_core::sign which has
# its own libc dependency; the cli's non-Ed25519 paths reach through
# the same primitives, so we add libc here too.
#
# signal-hook installs SIGINT/SIGTERM handlers via sigaction(2) for
# cooperative shutdown. We use only the `flag` module (atomic-bool
# stores; async-signal-safe) so this crate stays
# `#![deny(unsafe_code)]` — see signal.rs.
[]
= "0.2"
= { = "0.4", = false }
[]
= { = "0.5", = "../mkit-keystore", = ["backend-macos-keychain"] }
[]
= { = "0.5", = "../mkit-keystore", = ["backend-linux-secret-service", "backend-systemd-creds"] }
[]
# build.rs enforces CLI_VERSION == CARGO_PKG_VERSION at compile time by
# reading src/cli.rs. No external deps — plain file I/O + string match.
[]
= "3"
= { = "../mkit-test-util" }
= { = "../mkit-transport-memory" }
# Integration tests for HTTP/S3 scheme dispatch use a local mockito
# server. SSH dispatch tests only cover URL parsing (no live subprocess
# in CI), so the `mkit-transport-ssh` exports are enough on their own.
= "1"
# `attest_roundtrip` tests derive per-algorithm public keys at test time
# to build trust-roots TOML files. Dev-only: the CLI binary itself never
# imports these directly — signing goes through the mkit-attest signers.
= { = "3", = false, = ["alloc"] }
= { = "0.14", = false, = ["ecdsa", "std", "pkcs8"] }
= { = "0.14", = false, = ["ecdsa", "std", "pkcs8"] }
# Snapshot testing for CLI golden-output fixtures. See issue #164.
# `filters` feature enables regex-based redaction so version-string
# bumps don't churn snapshots.
= { = "1", = ["filters"] }
# Stateful end-to-end invariant suite (tests/state_machine.rs): proptest
# generates random op sequences driven through the real `mkit` binary,
# asserting a repo-invariant battery after each op. Same major as
# mkit-core's dev-dep. Bounded by default (32 cases); the nightly job
# raises PROPTEST_CASES under the `state-machine` nextest profile.
= "1"
# tests/remote_dispatch_connect.rs (mkit#701): drives push_all/pull_all
# against a REAL in-process mkit.transport.v1.TransportService server
# (connectrpc's hyper server, memory-backed) rather than a mockito stub —
# the regression gate proving `mkit+http://` round-trips through the
# generated Connect codebase end-to-end. `server` is additive on top of
# `mkit-transport-connect`'s own `client`/`client-tls` feature set (Cargo
# unions dependency features across dependency kinds).
= { = "0.9.0", = false, = ["server", "gzip", "zstd", "json"] }
# tests/grant_e2e.rs (WP-2.13/2.14, E1): the real `mkit` binary against a REAL
# in-process mkit-server pipeline over the memory stores, so grant selection,
# `epoch bump` and revocation are exercised against the actual verifier. A
# DEV-dependency only: `scripts/check-cli-baseline.sh` audits the normal
# graph, where mkit-server stays at `ssh` + `fs`.
= { = "0.5", = "../mkit-server", = false, = ["ssh", "fs", "connect", "memory"] }
= "1"
= { = "1", = false, = ["rt-multi-thread", "net", "time", "sync"] }
= "0.3"
# tests/cli_transcripts.rs: declarative `.trycmd` transcript tests for
# simple, deterministic CLI output (error messages, not full help text —
# that's already covered by help_snapshot.rs's insta snapshots). Pins
# exact user-facing text, not just exit codes.
= "1"
# tests/blackbox_smoke.rs: assert_cmd's fluent Command::assert() API,
# demonstrated on one existing hand-rolled Output-based test as a pattern
# reference for new tests — the existing tests/common/mod.rs `Repo`
# builder (sandboxed temp-dir + fixed signing key + `.ok()`/`.run()`)
# already covers the cargo-test-support-style sandboxed-repo role, so
# this is additive ergonomics on top of it, not a replacement.
= "2"
= "3"
= "1"
# tests/ssh_e2e_real.rs's containerized real-sshd test: a genuine
# OpenSSH daemon (lscr.io/linuxserver/openssh-server) via Docker, closing
# the gap the module docs' host-level skeleton left open ("would flake
# across runners" — the container sidesteps exactly that fragility, since
# the daemon's provisioning lives in a pinned, pre-built image instead of
# on the host). `blocking` feature: this suite's tests are plain `#[test]`,
# not async.
= { = "0.27", = ["blocking"] }
[]
= []
# Compile-time exhaustiveness mirror of mkit-attest's bls-threshold —
# pulls the BLS Algorithm variant into scope so the CLI's match arms
# cover it (returning UNAVAILABLE per-site). The release-party signer
# (issue #160) will later replace the inert arms.
= ["mkit-attest/bls-threshold", "mkit-keystore/bls-threshold", "dep:rand_core", "dep:commonware-codec"]
# Enables the `mkit+enc://` client dispatch path in
# `remote_dispatch::open`. Pulls in `mkit-transport-enc` with its `tcp`
# feature (tokio + governor + rand) for `connect_tcp`. The transport is deprecated:
# no maintained server hosts it. See SPEC-TRANSPORT-ENC §6.
= ["dep:mkit-transport-enc", "mkit-transport-enc/tcp", "dep:commonware-cryptography", "dep:commonware-codec"]
# Enables `mkit mcp`'s modern serving path (MCP 2026-07-28, via the official
# `rmcp` Rust SDK — see the doc comment above rmcp's Cargo.toml entry). Off by
# default: rmcp brings a hyper server and a tokio runtime, and the default
# build is server-free (scripts/check-cli-baseline.sh; see commands/mcp.rs's
# module doc); the pre-existing hand-rolled stdio
# server stays the default `mkit mcp` implementation either way. Turn on via
# `--features mcp-v2`.
= ["dep:rmcp", "dep:tokio", "dep:hyper", "dep:hyper-util", "dep:subtle", "dep:http", "dep:tower-service", "dep:http-body-util", "dep:bytes", "tokio/net", "tokio/signal"]
# The git bridge (`mkit git ...`, SPEC-GIT-BRIDGE / SPEC-GIT-IMPORT).
# Default-off while experimental; flip after the mapping has survived
# real mirrors. `git-export` is a back-compat alias from the bridge's
# export-only era.
= ["dep:mkit-git-bridge"]
= ["git-bridge"]
# Verifiable sparse-checkout (issue #158). Pulls the
# `mkit-core` sparse module and the matching transport-side fetchers
# into scope. Off by default — the upstream `commonware-storage` is
# ALPHA-tier.
= [
"mkit-core/sparse-checkout",
"mkit-transport-http/sparse-checkout",
"mkit-transport-s3/sparse-checkout",
]
# Issue #159 — `mkit pack-shard <hash>` producer subcommand
# and shard-aware HTTP / S3 downloads. Default-off because the
# commonware dep stack is large.
= [
"mkit-core/pack-shards",
"mkit-transport-http/pack-shards",
"mkit-transport-s3/pack-shards",
]
# Canonical first-parent ancestry snapshots and contextual proofs. Opt in for
# commit/branch/merge/rebase/cherry-pick publication and verified reflog output.
= ["mkit-core/history-mmr"]
[]
# Build docs with every feature so docs.rs renders the feature-gated API.
= true