[package] name = "ai-server" version = "0.1.0" edition = "2024" [[bin]] name = "ai-server" path = "src/main.rs" [dependencies] # The link both this and dev-updater need in order to be reached from a # phone: wg binding, the pinned CA, QR enrollment, owner-only files, and # the RON house rules. Extracted from the two copies that had drifted -- # see that repo's README for the evidence and the bug the extraction found. wg-app-link = { path = "../wg-app-link/server" } # The event model, shared with `client-core` so a Rust client and this # server read the same `Event`/`SeqEvent` rather than the app hand-mirroring # it the way `Events.kt` used to. event-model = { path = "../event-model" } axum = { version = "0.8", features = ["json", "multipart"] } axum-server = { version = "0.8", features = ["tls-rustls"] } tokio = { version = "1", features = ["rt-multi-thread", "macros", "net", "sync", "time", "process", "io-util", "signal"] } # `sync` for BroadcastStream: the notifications route turns the manager's # broadcast channel straight into an SSE body, which is the one place here a # broadcast receiver has to be a Stream rather than something to poll. tokio-stream = { version = "0.1", features = ["sync"] } tracing = "0.1" tracing-subscriber = { version = "0.3", features = ["env-filter"] } serde = { version = "1", features = ["derive"] } # `float_roundtrip` because this server hands out the same transcript line two ways -- the # `/transcript` page and the SSE backlog both parse it out of the file and serialize it again -- # and serde_json's default float parser is not correctly rounded. Measured 2026-09-04: a `ts` of # 1788546972.6030757 in the file came back as ...0755, so the two answers to "what is line 30" # differed in the last bit while looking identical. What made that visible was the phone's # transcript cache, which compares a line it already holds against the server's own answer. serde_json = { version = "1", features = ["float_roundtrip"] } # The config file's format. Not JSON, because this file is written and read # by hand and RON says a sum type as syntax. The two house rules both # projects write it under live in wg-app-link; this is here for the error # types the schema's own signatures name. ron = "0.12.2" clap = { version = "4", features = ["derive"] } anyhow = "1" thiserror = "2" # Verifying a downloaded model against HuggingFace's published digest. sha2 = "0.11" # Naming a session directory, and an attachment inside one. rand = "0.10" # Decoding the images a phone attaches, and encoding them for a driver. base64 = "0.23" # Outbound HTTPS for the usage endpoint. A small blocking client fits an # every-few-minutes poll better than pulling in reqwest's tower stack; # rustls-backed like the rest of the TLS here. ureq = { version = "3", features = ["json"] } # Direct dependency only to pick the process-level CryptoProvider in main: # ureq pulls rustls-with-ring, axum-server rustls-with-aws-lc-rs, and with # both in the graph rustls refuses to auto-select one. rustls = "0.23" libc = "0.2.189" # One ISO-8601 timestamp: the reset time on the invented rate-limit window # an echo session's `/usage` puts up. Already in the tree behind the # certificate machinery, so this is a direct name for what is compiled # anyway rather than a new crate -- and the alternative was hand-rolling a # civil-from-days conversion to print one line. time = { version = "0.3", features = ["formatting"] } [dev-dependencies] tempfile = "3" # ServiceExt::oneshot, to drive the auth middleware without a socket. tower = { version = "0.5", features = ["util"] }