mirror of
https://github.com/logos-blockchain/logos-execution-zone.git
synced 2026-07-25 07:03:13 +00:00
* refactor(keycard_wallet): replace keycard-py (pyo3) with native keycard-rs Rewrites the Keycard integration to talk to the LEE-flavored applet directly from Rust via keycard-rs (pinned git dependency), dropping the pyo3 shim, python_path.rs, and the vendored keycard-py Python library entirely. Verified end-to-end against real hardware: pairing, PIN verification, mnemonic loading, BIP340 Schnorr signing, and transfers between keycard and public/private accounts. Also cleans up the pyo3 usage that had leaked into wallet's signing path (signing.rs, account_manager.rs) beyond the keycard CLI itself, and trims wallet_with_keycard.sh's Python setup down to just pyscard, which is only needed by the force_unpower.py test helper now. * Updated to v2 secure communication * ci: install libpcsclite-dev for pcsc crate builds * docs(keycard): clarify personalization is mandatory and document default CA Reinstalling the applet via `./gradlew install` wipes any existing personalization regardless of firmware source, which wasn't previously called out and is a common source of "card not available" confusion. Also state plainly that personalization is required before any command works, and document keycard-rs's actual baked-in default CA public key instead of only describing the override mechanism. Export KEYCARD_CA_PUBLIC_KEY in all keycard test scripts so they work against the dev/test-CA personalization flow they rely on. * fix(keycard): address PR #595 review comments - Propagate the load_mnemonic error instead of swallowing it behind is_ok(), matching every other command handler in this file. - Add deny.toml allowing the keycard-rs git source, fixing the source-not-allowed failure in `cargo deny check`. Licenses and advisories checks still have pre-existing, separate failures not addressed here. - Drop the pinned rev for the keycard-rs git dependency so it tracks the upstream default branch instead. * chore(deny): trim deny.toml to essentials and allow all in-use licenses Replace the full cargo-deny init template with just the two sections that matter: the keycard-rs git-source allowance, and an explicit license allow-list covering every license currently in the dependency tree. cargo deny check now passes on sources, bans, and licenses; advisories still fails on a pre-existing, unrelated RUSTSEC advisory. * fix(deny): remove second config and add source to the original one * chore: pin keycard-rs dependency and fix factory-reset debug-gate doc * chore: regenerate test fixture and lockfile after rebase onto dev --------- Co-authored-by: Daniil Polyakov <arjentix@gmail.com>
72 lines
3.2 KiB
TOML
72 lines
3.2 KiB
TOML
# Config file reference can be found at https://embarkstudios.github.io/cargo-deny/checks/cfg.html.
|
|
|
|
[graph]
|
|
all-features = true
|
|
exclude-dev = true
|
|
no-default-features = true
|
|
|
|
[advisories]
|
|
ignore = [
|
|
{ id = "RUSTSEC-2023-0071", reason = "Marvin Attack: potential key recovery through timing sidechannels" },
|
|
{ id = "RUSTSEC-2024-0388", reason = "`derivative` is unmaintained; consider using an alternative. Use `cargo tree -p derivative -i > tmp.txt` to check the dependency tree." },
|
|
{ id = "RUSTSEC-2024-0436", reason = "`paste` has a security vulnerability; consider using an alternative. Use `cargo tree -p paste -i > tmp.txt` to check the dependency tree." },
|
|
{ id = "RUSTSEC-2025-0055", reason = "`tracing-subscriber` v0.2.25 pulled in by ark-relations v0.4.0 - will be addressed before mainnet" },
|
|
{ id = "RUSTSEC-2025-0141", reason = "`bincode` is unmaintained but continuing to use it." },
|
|
{ id = "RUSTSEC-2023-0089", reason = "atomic-polyfill is pulled transitively via risc0-zkvm; waiting on upstream fix (see https://github.com/risc0/risc0/issues/3453)" },
|
|
{ id = "RUSTSEC-2026-0118", reason = "`hickory-proto` v0.25.0-alpha.5 is present transitively from logos crates, modification may break integration" },
|
|
{ id = "RUSTSEC-2026-0119", reason = "`hickory-proto` v0.25.0-alpha.5 is present transitively from logos crates, modification may break integration" },
|
|
|
|
{ id = "RUSTSEC-2024-0370", reason = "transitive dependency of `logos-blockchain-http-api-common`, can't do anything than wait for upstream fix" },
|
|
{ id = "RUSTSEC-2026-0173", reason = "`proc-macro-error2` is unmaintained; pulled in transitively via `leptos_macro` and `overwatch-derive`, waiting on upstream fix" },
|
|
]
|
|
yanked = "deny"
|
|
unused-ignored-advisory = "deny"
|
|
|
|
[bans]
|
|
allow-wildcard-paths = false
|
|
multiple-versions = "allow"
|
|
|
|
[licenses]
|
|
allow = [
|
|
"Apache-2.0 WITH LLVM-exception",
|
|
"Apache-2.0",
|
|
"BSD-2-Clause",
|
|
"BSD-3-Clause",
|
|
"BSL-1.0",
|
|
"CC0-1.0",
|
|
"CDLA-Permissive-2.0",
|
|
"ISC",
|
|
"MIT",
|
|
"MPL-2.0",
|
|
"Unicode-3.0",
|
|
"Zlib",
|
|
]
|
|
exceptions = [
|
|
# TEMP: Pending legal review. Pulled transitively via `risc0-zkvm`
|
|
{ name = "downloader", version = "0.2.8", allow = ["LGPL-3.0-or-later"] },
|
|
{ name = "malachite", version = "0.4.22", allow = ["LGPL-3.0-only"] },
|
|
{ name = "malachite-base", version = "0.4.22", allow = ["LGPL-3.0-only"] },
|
|
{ name = "malachite-float", version = "0.4.22", allow = ["LGPL-3.0-only"] },
|
|
{ name = "malachite-nz", version = "0.4.22", allow = ["LGPL-3.0-only"] },
|
|
{ name = "malachite-q", version = "0.4.22", allow = ["LGPL-3.0-only"] },
|
|
{ name = "managed", version = "0.8.0", allow = ["0BSD"] },
|
|
]
|
|
private = { ignore = false }
|
|
unused-allowed-license = "deny"
|
|
|
|
[sources]
|
|
allow-git = [
|
|
"https://github.com/EspressoSystems/jellyfish.git",
|
|
"https://github.com/logos-blockchain/logos-blockchain.git",
|
|
"https://github.com/logos-blockchain/logos-blockchain-circuits.git",
|
|
"https://github.com/logos-blockchain/logos-blockchain-rust-rapidsnark.git",
|
|
"https://github.com/logos-blockchain/sponges",
|
|
"https://github.com/arkworks-rs/spongefish.git",
|
|
"https://github.com/keycard-tech/keycard-rs",
|
|
]
|
|
unknown-git = "deny"
|
|
unknown-registry = "deny"
|
|
|
|
[sources.allow-org]
|
|
github = ["logos-co"]
|