Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
68 changes: 15 additions & 53 deletions .github/workflows/integration.yml
Original file line number Diff line number Diff line change
Expand Up @@ -63,9 +63,10 @@ jobs:
BASE_URL: http://localhost:8787
LOG_NAME: dev2026h1a

integration-tlog-witness:
name: TLog Witness Integration Tests
integration-tlog-mirror:
name: TLog Mirror Integration Tests
runs-on: ubuntu-latest
timeout-minutes: 20

steps:
- uses: actions/checkout@v4
Expand All @@ -75,62 +76,18 @@ jobs:
with:
node-version: "22"

# wasm-pack is intentionally NOT installed here: witness_worker only
# uses worker-build for its wasm build, unlike the CT and MTC jobs
# which also compile *_wasm sibling crates that need wasm-pack.
- name: Install worker-build
run: cargo install worker-build@0.8.5 --locked

# RUSTFLAGS: force legacy Wasm EH (see ct_worker build comment).
- name: Build witness_worker (dev environment)
working-directory: crates/witness_worker
run: DEPLOY_ENV=dev RUSTFLAGS='-Cllvm-args=-wasm-use-legacy-eh' worker-build --release --panic-unwind

# .dev.vars contains the WITNESS_SIGNING_KEY used by wrangler dev. This
# is a dev-only key (not a production secret) and is committed to the
# repository.
- name: Start wrangler dev
working-directory: crates/witness_worker
run: npx wrangler@4.80.0 -e=dev dev --port 8787 --persist-to .wrangler/state &

- name: Wait for wrangler dev to be ready
run: |
for i in $(seq 1 30); do
if curl -sf http://localhost:8787/metadata > /dev/null 2>&1; then
echo "wrangler dev is ready"
exit 0
fi
echo "Waiting for wrangler dev... attempt $i/30"
sleep 2
done
echo "wrangler dev failed to start in time"
exit 1

- name: Run TLog Witness integration tests
run: cargo test -p integration_tests --test tlog_witness --verbose
env:
BASE_URL: http://localhost:8787

integration-tlog-mirror:
name: TLog Mirror Integration Tests
runs-on: ubuntu-latest
timeout-minutes: 15

steps:
- uses: actions/checkout@v4

- name: Install Node.js
uses: actions/setup-node@v4
with:
node-version: "22"

- name: Install Wrangler
run: npm install --global wrangler@4.80.0

- name: Install worker-build
run: cargo install worker-build@0.8.5 --locked
- name: Check standalone mirror worker modes
run: |
DEPLOY_ENV=witness cargo check -p mirror_worker --all-targets
DEPLOY_ENV=mirror cargo check -p mirror_worker --all-targets

- name: Build mirror_worker (dev environment)
- name: Build mirror_worker (combined dev environment)
working-directory: crates/mirror_worker
run: DEPLOY_ENV=dev RUSTFLAGS='-Cllvm-args=-wasm-use-legacy-eh' worker-build --release --panic-unwind

Expand All @@ -151,7 +108,12 @@ jobs:
echo "wrangler dev failed to start in time"
exit 1

- name: Run TLog Mirror integration tests
run: cargo test -p integration_tests --test tlog_mirror --verbose
- name: Run TLog integration tests
run: cargo test -p integration_tests --test tlog_witness --verbose
env:
BASE_URL: http://localhost:8787
RUST_TEST_THREADS: "1"
- run: cargo test -p integration_tests --test tlog_mirror --verbose
env:
BASE_URL: http://localhost:8787
RUST_TEST_THREADS: "1"
5 changes: 3 additions & 2 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@ Azul is a Rust workspace implementing tiled transparency logs for deployment on

```
crates/ct_worker/ - Static CT API Worker (deployable); wrangler.jsonc here
crates/mirror_worker/ - Configurable tlog mirror/witness Worker (deployable)
crates/generic_log_worker/ - Shared Durable Object logic (Sequencer, Batcher, Cleaner)
crates/tlog_tiles/ - C2SP tlog-tiles spec impl (published to crates.io)
crates/static_ct_api/ - C2SP static-ct-api spec impl (published to crates.io)
Expand Down Expand Up @@ -48,9 +49,9 @@ npx wrangler -e=${ENV} tail

- Worker crates use `crate-type = ["cdylib"]`; library crates use `rlib`
- Worker build is handled by `worker-build`, not `cargo build` directly — wrangler.jsonc invokes it automatically
- Config types live in separate sub-crates such as `crates/ct_worker/config/`
- Config types live in separate sub-crates such as `crates/ct_worker/config/` and `crates/mirror_worker/config/`
- `DEPLOY_ENV=<env>` env var must be set when invoking `worker-build` manually; wrangler.jsonc sets it per environment
- Route HTTP with `axum::Router` (worker features `["http", "axum"]`), not the `worker::Router`. The `#[event(fetch)]` handler takes a `HttpRequest`, returns `axum::http::Response<axum::body::Body>`, and dispatches via `tower_service::Service::call`; handlers return `impl IntoResponse`. See `witness_worker`/`ct_worker` for the pattern.
- Route HTTP with `axum::Router` (worker features `["http", "axum"]`), not the `worker::Router`. The `#[event(fetch)]` handler takes a `HttpRequest`, returns `axum::http::Response<axum::body::Body>`, and dispatches via `tower_service::Service::call`; handlers return `impl IntoResponse`. See `mirror_worker`/`ct_worker` for the pattern.


## Workflow
Expand Down
43 changes: 1 addition & 42 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

12 changes: 4 additions & 8 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -10,8 +10,6 @@ members = [
"crates/generic_log_worker",
"crates/integration_tests",
"crates/length_prefixed",
"crates/mirror_worker",
"crates/mirror_worker/config",
"crates/sct_validator",
"crates/signed_note",
"crates/signed_note_wasm",
Expand All @@ -21,11 +19,11 @@ members = [
"crates/tlog_cosignature",
"crates/tlog_entry",
"crates/tlog_mirror",
"crates/mirror_worker",
"crates/mirror_worker/config",
"crates/tlog_tiles",
"crates/tlog_tiles_wasm",
"crates/tlog_witness",
"crates/witness_worker",
"crates/witness_worker/config",
"crates/worker_build_config",
"crates/x509_util",
"fuzz",
Expand All @@ -46,8 +44,6 @@ default-members = [
"crates/ct_worker",
"crates/generic_log_worker",
"crates/length_prefixed",
"crates/mirror_worker",
"crates/mirror_worker/config",
"crates/sct_validator",
"crates/signed_note",
"crates/signed_note_wasm",
Expand All @@ -57,11 +53,11 @@ default-members = [
"crates/tlog_cosignature",
"crates/tlog_entry",
"crates/tlog_mirror",
"crates/mirror_worker",
"crates/mirror_worker/config",
"crates/tlog_tiles",
"crates/tlog_tiles_wasm",
"crates/tlog_witness",
"crates/witness_worker",
"crates/witness_worker/config",
"crates/worker_build_config",
"crates/x509_util",
]
Expand Down
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ Azul (short for [azulejos](https://en.wikipedia.org/wiki/Azulejo), the colorful
The crates in the repository are organized as follows:

- **[ct_worker](crates/ct_worker)**: A Static CT API log implementation for deployment on Cloudflare Workers.
- **[mirror_worker](crates/mirror_worker)**: A configurable [tlog-mirror](https://c2sp.org/tlog-mirror), [tlog-witness](https://c2sp.org/tlog-witness), or combined worker. Logs are keyed by exact checkpoint origin with Ed25519 or ML-DSA-44 checkpoint signers.
- **[static_ct_api](crates/static_ct_api)** ([crates.io](https://crates.io/crates/static_ct_api)): An implementation of the [C2SP static-ct-api](https://c2sp.org/static-ct-api) specification.
- **[signed_note](crates/signed_note)** ([crates.io](https://crates.io/crates/signed_note)): An implementation of the [C2SP signed-note](https://c2sp.org/signed-note) specification.
- **[tlog_tiles](crates/tlog_tiles)** ([crates.io](https://crates.io/crates/tlog_tiles)): An implementation of the [C2SP tlog-tiles](https://c2sp.org/tlog-tiles) and [C2SP checkpoint](https://c2sp.org/tlog-checkpoint) specifications.
Expand Down
Loading
Loading