From 26911e05bc32ceb70595eecbb4a878d9d925156f Mon Sep 17 00:00:00 2001 From: "@permadeath.com" Date: Mon, 17 Aug 2026 12:32:57 -0400 Subject: [PATCH] build(cargo): ship an allowlist rather than the whole repository MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit There was no `exclude` before, so this is the first statement of what a tarball should carry: `cargo package --list` drops from 249 entries to 136, and 3.9 MB to 2.7 MB. An allowlist rather than a denylist because the two differ only in how they fail — a denylist publishes whatever nobody thought to name, and nothing anywhere announces that it did, whereas an unnamed file here is merely missing, and missing breaks the packaged build where someone will see it. Two config files are the reason this is worth doing, not the byte count. `.cargo/config.toml` sets `rustdocflags = ["-D", "warnings"]`, and cargo reads config from the build's cwd upward — docs.rs builds inside the extracted crate directory, so shipping it would turn any rustdoc warning into a failed docs build. `rust-toolchain.toml` would pin 1.97.1 in someone else's build directory. `docs/` stays: src/docs.rs pulls its five pages in with `#![doc = include_str!(...)]`, so a tarball without them does not compile. `lexicons/` stays as the provenance of the generated bindings, and `brand/` goes, nothing having loaded it since the mark was inlined into src/html/pages.rs. Dropping `tests/` does mean the suite cannot be run from a crates.io tarball — some fixtures are `include_str!`'d from `#[cfg(test)]` code, so test compilation would fail there. --- Cargo.toml | 38 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 38 insertions(+) diff --git a/Cargo.toml b/Cargo.toml index 8d9fe31..3e97afa 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -19,6 +19,44 @@ homepage = "https://tangled.org/permadeath.com/atgc" readme = "README.md" keywords = ["atproto", "tangled", "git", "cli", "pull-request"] categories = ["command-line-utilities", "development-tools"] +# An allowlist, not an `exclude` denylist. Either can describe today's tree; +# they differ only in what becomes of the file nobody thought about. A denylist +# publishes it — every config, note and asset added later ships by default, and +# nothing anywhere announces that it did. Named this way round, an unnamed file +# is merely missing, and missing is the failure that gets caught: the packaged +# crate stops building, in `cargo package --verify`, before a release. +# +# What that buys is not the byte count. `.cargo/config.toml` sets +# `rustdocflags = ["-D", "warnings"]`, and cargo reads config from the build's +# cwd upward — docs.rs builds inside the extracted crate directory, so shipping +# that file would turn any rustdoc warning into a failed docs build for +# everyone. `rust-toolchain.toml` would pin 1.97.1 inside someone else's build +# directory. Neither belongs to anyone but this checkout. +include = [ + "/src", + "/build.rs", + # Load-bearing at compile time, not documentation that happens to ship: + # src/docs.rs pulls every page under docs/ in with + # `#![doc = include_str!(...)]`, so a tarball without them does not + # compile. Confirmed by packaging without it and watching it fail. + "/docs", + # The schemas the generated Rust bindings were generated from, and the + # manifest recording which upstream commit they were taken at. 164 KB to + # let the tarball account for its own generated code, which is a fair rate. + "/lexicons", + "/lexicons.json", + # Its first line names brand/png/lockup-512.png, which is deliberately not + # here. That reference is already dead on a crate page — crates.io rewrites + # relative README links only for hosts it knows, and tangled.org is not one + # — as are the five docs/ links below it. Making this one absolute would + # render one image above five links that still go nowhere, which reads as + # more working than the page is; the README is left to be fixed whole. + "/README.md", + # `license = "MIT OR Apache-2.0"` offers a choice between two documents. A + # tarball carrying neither makes that an offer with nothing behind it. + "/LICENSE-MIT", + "/LICENSE-APACHE", +] # These apply to this package only. vendor/jacquard-oauth is a separate # package with its own manifest, so it is not linted by them. -- 2.51.2