1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
[]
= ["clients/rust-client", "sdbql-core", "benchmarks"]
= ["fuzz"]
[]
= "solidb"
= "2.0.2"
= "2021"
# Floor imposed by the dependency tree (rust-rocksdb 0.46 declares 1.89.0).
# Enforced by the `msrv` CI job, which builds with exactly this toolchain.
= "1.89"
= "solidb"
= "A lightweight, high-performance structured database server written in Rust."
= "LICENCE.md"
= "https://github.com/solisoft/solidb"
= ["database", "nosql", "json", "rest-api", "rust"]
= ["database", "web-programming::http-server"]
= ["src/**/*", "README.md", "LICENCE.md", "Cargo.toml", "docs/**/*"]
[]
# Async runtime
= { = "1.35", = ["full"] }
# HTTP server
= { = "0.8.7", = ["multipart", "ws", "macros"] }
# Drive HTTP connections manually (instead of `axum::serve`) so we can set an
# HTTP/1 header-read timeout — see the multiplexed HTTP server in main.rs.
= { = "0.1", = ["server-auto", "server-graceful", "service", "tokio", "http1", "http2"] }
= { = "0.5.2", = ["util"] }
= { = "0.6.8", = ["trace", "cors", "compression-gzip", "compression-zstd", "set-header"] }
= "0.3"
= "0.1"
# WebSocket Client (for global changefeed aggregation)
= { = "0.28", = ["rustls-tls-native-roots"] }
= "2.4"
# TLS termination for the API listener (--tls-cert/--tls-key). rustls keeps
# the build free of OpenSSL, same rationale as the outbound clients. PEM
# parsing uses rustls-pki-types' PemObject API — the `rustls-pemfile` crate
# is unmaintained (RUSTSEC-2025-0134) and fails cargo-deny.
= { = "0.26", = false, = ["ring", "tls12"] }
# JSON serialization
= { = "1.0", = ["derive"] }
= "0.7"
= "1.0"
# Hasher for SDBQL row contexts (per-row map, SipHash showed up at ~5%).
= "0.2"
= "0.11"
= "1.3"
= "0.12"
= "0.22"
= "0.5"
= "0.45"
# Error handling
= "1.0"
= "2.0"
# Logging
= "0.1"
= { = "0.3", = ["env-filter"] }
# Observability - OpenTelemetry trace context propagation
= { = "0.17", = ["trace"] }
= "0.17"
# CLI
= { = "4.4", = ["derive", "env"] }
= "0.15"
# Utilities
= { = "1.6", = ["v4", "v7", "serde"] }
= "0.4"
= { = "0.4", = ["serde"] }
= "0.10"
= "1.0"
= "1.1"
= "0.4"
= "1.10"
= "4.1" # Uniform hash distribution for sharding
# Storage
= "0.46"
# Authentication
= "0.5"
# Keep the aws_lc_rs backend: the `rust_crypto` alternative pulls in the `rsa` crate, which
# commit 7320477 deliberately removed (RUSTSEC-2023-0071, no fixed version). See the
# windows-gated aws-lc-rs entry below for how this stays buildable on windows-msvc.
= { = "10.3", = false, = ["aws_lc_rs", "use_pem"] }
= "1.19"
= "0.6"
= "0.8"
= "0.4"
= "0.10"
= "0.12"
= { = "2.0", = ["static_secrets"] }
= "0.8"
= "2.6"
# Temp directories (needed by benchmark)
= "3.10"
# HTTP client (for benchmarks)
# rustls rather than the default native-tls: it keeps the build free of OpenSSL, which
# otherwise needs Perl + NASM on Windows. default-features = false drops http2 and charset
# along with native-tls, so both are re-added explicitly.
= { = "0.13", = false, = [
"json",
"blocking",
"multipart",
"rustls",
"http2",
"charset",
"system-proxy",
] }
# FUSE filesystem (requires macFUSE on macOS)
= { = "0.16", = true }
# Daemon mode (Unix only)
# daemonize crate removed - using custom implementation in src/daemon.rs
# daemonize = "0.5"
= "0.2"
# Parallel processing (for concurrent benchmarks)
= "1.8"
= "1.4.0"
# CLI UX
= "0.18"
= "3.0"
= "17"
# System info for stats
= "0.38"
# Prometheus metrics
= "0.14"
= { = "0.3.31", = ["std"] }
# Embedded Lua scripting
= { = "0.11.5", = ["lua54", "vendored", "async", "serialize", "send"] }
= "1.3.1"
# Enhanced validation and sanitization
= "1.0"
= "0.1"
# UNACCENT: ASCII folding of Latin letters (already pulled in by slug)
= "1.6"
# Image processing
= { = "0.25", = false, = ["jpeg", "png", "webp", "gif"] }
# Cookie handling
= "0.18"
= "0.3.47"
# Caching
= "0.18"
= { = "0.17.0", = ["serde"] }
= { = "0.5", = ["serde_support"] }
= "0.12"
= "6"
# Self-update
= "1" # Gzip decompression
= "0.4" # Tar archive extraction
# CLI Script Development
= "8" # File system watcher
= "1.0" # Config file parsing
= "2" # Directory traversal
= "2" # Diff generation
= "7" # Secure password input
# TUI
= "0.29" # TUI framework
= "0.29" # Cross-platform terminal backend
= { = "0.7", = ["search"] } # Multi-line text editor widget
# Default binary
[[]]
= "solidb"
= "src/main.rs"
[[]]
= "solidb-dump"
= "src/bin/solidb-dump.rs"
[[]]
= "solidb-restore"
= "src/bin/solidb-restore.rs"
[]
= "thin"
= 16
= 3
[]
= "release"
# Profile for `cargo test`, in CI and for targeted local runs.
#
# Each of the ~96 files in tests/ becomes its own binary statically linking all
# of src/ (4.4 MB across 303 files) plus RocksDB. Under [profile.release] that
# is ~96 thin-LTO link steps to run 18 seconds of tests: CI measured 95m 07s of
# compilation against 18.4s of execution.
#
# `[profile.release]` cannot simply be relaxed — the `build-binaries` and
# `docker` CI jobs ship what it produces — hence a separate profile. Note this
# writes to target/ci/ *in addition to* target/release/, so a box that builds
# both keeps two trees.
[]
= "release"
# The whole game. Under release's `lto = "thin"` the dependency rlibs carry
# bitcode and codegen is deferred to the final artifact, so ThinLTO re-runs
# across the ~400-crate graph once per test binary — ~96 times. With LTO off,
# dependencies codegen once to object code and each test binary is a plain link.
#
# This is also why switching profiles forces one cold rebuild of every
# dependency: bitcode rlibs and object rlibs have different fingerprints.
#
# `lto` may only be set at profile top level; cargo rejects it (like `panic`
# and `rpath`) inside a `[profile.*.package.*]` override.
= false
# Applies to the workspace crates and the test harnesses; the overrides below
# keep dependencies at 3. Not 0 — O0 emits *more* code because it stops
# inlining wrappers, which makes all ~96 links slower and the suite 5-20x
# slower to run. O1 is the point where compile time drops but the tests still
# execute in seconds.
#
# Safe because no test that actually runs depends on optimisation: the only
# files under tests/ that touch `Instant::now()` / `.elapsed()` are the five
# benchmarks, and those are `#[ignore]`d behind the `bench-tests` feature.
= 1
# Deliberately NOT set here:
# codegen-units — release's 16 is right. ubuntu-latest has 4 vCPUs and cargo
# already has ~100 independent targets to fill them, so raising it buys no
# parallelism and costs cross-CGU inlining, i.e. a bigger rlib to link 96x.
# strip — `inherits = "release"` gives debug = 0, and cargo already passes
# `-Cstrip=debuginfo` at that debug level. Setting it is a no-op. (What
# would shrink target/ is `strip = "symbols"`, which is not worth losing
# panic backtrace symbolisation in the CI logs you read on a failure.)
# panic — cargo ignores it for test targets since libtest needs unwind, so it
# would apply only to the bins, and a panic=abort bin cannot share
# dependency artifacts with panic=unwind tests: it would double the
# dependency build.
# Dependencies stay fully optimised. Those 18 seconds of tests are spent almost
# entirely inside RocksDB, ring and aws-lc-sys, and an unoptimised RocksDB would
# trade the compile time we just saved straight back for runtime. They are built
# once and cached, so this costs nothing per run.
[]
= 3
# Whether the `"*"` glob above also matches workspace members that are path
# dependencies is the murky corner of cargo's override rules, and the whole
# saving depends on the answer. Restate the three crates that actually
# recompile on every run so the intent holds either way.
[]
= 1
[]
= 1
[]
= 1
[]
= "0.4"
= { = "clients/rust-client" }
# Memory allocator: jemalloc fragments far less than glibc malloc and returns
# freed memory to the OS. With one column family per collection plus many
# Tokio/RocksDB threads, glibc's per-thread arenas pin RSS at the allocation
# high-water mark (multi-GB) long after the memory is freed; jemalloc keeps
# RSS tracking the actual working set. Not used under MSVC (Windows).
[]
= { = "0.6", = [
# Route C and C++ `malloc` through jemalloc too, not just Rust's
# GlobalAlloc. Without this, jemalloc links with its `_rjem_` prefix and
# serves Rust only, so RocksDB's C++ allocations — block cache, table
# readers, memtables, iterators, compaction buffers, i.e. the bulk of a
# large instance's memory — still go to glibc, and the per-thread arena
# growth this dependency exists to avoid happens anyway.
#
# Measured on the same 613-collection checkpoint, importing 400k documents
# across 200 collections, prod profile, twice:
#
# glibc jemalloc
# peak RSS (VmHWM) 1881 MB 1356 MB
# glibc arenas 64MB 20 2
# still held after 1726 MB (swapped out, never returned)
#
# Note the symbol-name coupling: this feature makes the tuning symbol in
# main.rs plain `malloc_conf` instead of `_rjem_malloc_conf`. Change one
# without the other and the tuning is silently lost.
"unprefixed_malloc_on_supported_platforms",
] }
# Read back the allocator's effective options at startup. The tuning in
# `main.rs` is a link-time symbol: if the symbol name ever stops matching what
# jemalloc looks for, it silently does nothing. Logging the values it actually
# runs with turns that into something visible.
#
# The `stats` feature turns on jemalloc's own byte accounting, which /metrics
# exposes as solidb_jemalloc_*_bytes. It is what separates live data from
# fragmentation and from address space merely kept mapped — a process holding
# 21.7 GB resident was seen with 113 GB virtual, and without `stats.retained`
# there is no way to tell those apart. The flag propagates to
# tikv-jemalloc-sys, so the C library is built with its counters enabled;
# jemalloc documents that as low-overhead, but it is not free.
= { = "0.6", = ["stats"] }
# aws-lc-sys (pulled in by jsonwebtoken and by reqwest's rustls provider) assembles its
# x86_64 asm with NASM on windows-msvc, which is not on the GitHub runner image. The
# prebuilt-nasm feature uses the object files shipped in the crate instead, leaving CMake +
# MSVC as the only build requirements — both preinstalled on windows-latest. Feature
# unification applies this to every aws-lc-rs in the graph.
[]
= { = "1", = ["prebuilt-nasm"] }
[]
= ["dep:fuser"]
# The five files in tests/ that are benchmarks rather than tests. Off by
# default, so `cargo test` does not build them — see the [[test]] blocks below.
= []
# Benchmarks living in tests/. Every test in these five files is
# `#[test] #[ignore]`, so they were paying a full release link each and never
# running — five of the ~96 link steps for nothing. They are also the only
# files in tests/ that measure wall-clock time (`Instant::now()` / `elapsed()`),
# which is exactly why they must not be run as part of the suite.
#
# Declaring these explicitly does not disable autodiscovery of the other ~91
# files (`autotests` stays true), so nothing else needs listing here.
#
# Run them with:
# cargo test --profile ci --features bench-tests -- --ignored
[[]]
= "benchmark_sort"
= "tests/benchmark_sort.rs"
= ["bench-tests"]
[[]]
= "benchmark_perf_fixes"
= "tests/benchmark_perf_fixes.rs"
= ["bench-tests"]
[[]]
= "sdbql_compare_bench"
= "tests/sdbql_compare_bench.rs"
= ["bench-tests"]
[[]]
= "sdbql_datetime_bench"
= "tests/sdbql_datetime_bench.rs"
= ["bench-tests"]
[[]]
= "sdbql_string_bench"
= "tests/sdbql_string_bench.rs"
= ["bench-tests"]
[[]]
= "solidb-fuse"
= "src/bin/solidb-fuse.rs"
= ["fuse"]
[[]]
= "solidb-repl"
= "src/bin/solidb-repl.rs"
[]
= false
= false
= "origin"
= false
= "chore: release v{{version}}"
= "{{tag_name}}"
= "v{{version}}"
= []
= false