seabored 0.0.7

Implementation of the CBOR data format. Implements RFC8949 with the preferred-plus recommendations
Documentation

Seabored

Crates.io docs.rs

Description

Implementation of the CBOR data format. Compatible with Serde (optional), Facet incoming.

Compatible with WASM.

Complies to the following RFCs:

Documentation

Here: https://docs.rs/seabored

Not great as of now, will get better in subsequent releases. If you want examples, please head to the benches folder.

Quirks

  • It's fast. Like, seriously fast. See BENCHMARKS.md
  • As of now, it IS vulnerable to billion laughs attacks. There is no recursion depth tracking, but it will be addressed soon.
  • As always, Serde de/ser is quirky as hell with CBOR since the Rust types do not map very well to CBOR primitives.
    • Option::None is serialized as CBOR Null SimpleValue
    • () unit type is serialized as CBOR Undefined SimpleValue
    • TODO: list more quirks?
  • The library might serialize things a bit differently than what it deserialized. The reason being is that the library prefers the preferred-plus serialization scheme, and things like indefinite length sequences are forbidden in this scheme. We still tolerate them but might avoid reserializing them.
  • There's some unsafe here and there to juice out more performance where applicable. If you don't like it, then use something else. Fuzzing is in place to minimize risk here.

Features

  • inline-nontrivial: Enabled by default, adds the #[inline] attributes to most non-trivial functions. This is for performance at the cost of codesize (even though those reports are usually greatly exaggerated). Disable it (by using default-features = false) if you absolutely need smol code size.
  • serde: Enables Serde compatibility
  • facet: Enables Facet compatibility (does nothing for now: TODO)

Roadmap

  • Billion Laughs protection (recursion depth tracking)
  • Add CBOR RFC compat feature flag, to reduce branches
  • Make a homebrew derive for people who don't care about serde/facet/etc
    • This would have more power as you'll be able to be more in control as to how stuff gets de/serialized (like tags, simple values, etc)
  • Facet compat
  • Improve performance (yes, there's still some to get)
  • Docs improvements, examples, etc

AI Disclaimer

Unlike a lot of things being created currently, this library was written WITHOUT the use of any LLM.

Yes crazy I know, but I'm an actual engineer, not a meat proxy to a bunch of GPUs.

License

Licensed under either of these: