Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion crates/ourios-querier/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -94,7 +94,7 @@ arrow-array = { version = "=58.3.0", default-features = false }
arrow-schema = { version = "=58.3.0", default-features = false }
# RFC0002.10 — proves the canonical β serialisation survives a YAML
# scalar round-trip (the Perses-embedding guarantee). Test-only.
serde_yaml = { version = "=0.9.34", default-features = false }
serde_yaml_ng = { version = "0.10", default-features = false }
# RFC0002.11 — validates the structured surface against its published JSON
# Schema in the acceptance test. `default-features = false` drops the
# reqwest/TLS remote-`$ref` resolver: the schema is self-contained
Expand Down
13 changes: 7 additions & 6 deletions crates/ourios-querier/tests/it/rfc0002_dsl.rs
Original file line number Diff line number Diff line change
Expand Up @@ -1280,14 +1280,14 @@ fn assert_round_trips_through_yaml(beta: &str, expected: &ourios_querier::dsl::Q
"canonical serialisation must be single-line: {beta:?}",
);

// serde_yaml emits a correctly-quoted scalar for any string, so building
// serde_yaml_ng emits a correctly-quoted scalar for any string, so building
// the document via the serializer is itself part of the round-trip.
let mut doc = std::collections::BTreeMap::new();
doc.insert("query".to_string(), beta.to_string());
let yaml = serde_yaml::to_string(&doc).expect("embed query as a YAML scalar");
let yaml = serde_yaml_ng::to_string(&doc).expect("embed query as a YAML scalar");

let recovered: std::collections::BTreeMap<String, String> =
serde_yaml::from_str(&yaml).expect("YAML round-trips");
serde_yaml_ng::from_str(&yaml).expect("YAML round-trips");
let extracted = recovered.get("query").expect("query scalar survives");

let reparsed = ourios_querier::dsl::parse(extracted)
Expand All @@ -1313,10 +1313,11 @@ fn yaml_round_trip_property() {

let mut doc = std::collections::BTreeMap::new();
doc.insert("query".to_string(), beta.clone());
let yaml = serde_yaml::to_string(&doc)
let yaml = serde_yaml_ng::to_string(&doc)
.map_err(|e| TestCaseError::fail(format!("YAML embed failed: {e}")))?;
let recovered: std::collections::BTreeMap<String, String> = serde_yaml::from_str(&yaml)
.map_err(|e| TestCaseError::fail(format!("YAML parse failed: {e}")))?;
let recovered: std::collections::BTreeMap<String, String> =
serde_yaml_ng::from_str(&yaml)
.map_err(|e| TestCaseError::fail(format!("YAML parse failed: {e}")))?;
let extracted = recovered
.get("query")
.ok_or_else(|| TestCaseError::fail("query scalar missing".to_string()))?;
Expand Down
9 changes: 5 additions & 4 deletions crates/ourios-server/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -61,10 +61,11 @@ tracing = { version = "0.1", default-features = false, features = ["std"] }
# RFC 0020 configuration-file schema (config::file): deserialise the YAML into
# the schema, then substitute `${env:…}` in the typed scalar leaves (schema
# validation runs on the raw text first, so an error never echoes a resolved
# secret — the order is security-relevant, see the module docs). Already vetted
# in the dep tree (ourios-querier pins the same version), so this adds no new
# cargo-deny surface.
serde_yaml = { version = "=0.9.34", default-features = false }
# secret — the order is security-relevant, see the module docs).
# `serde_yaml_ng` is the maintained continuation of the abandoned
# `serde_yaml` (same `from_str`/`Error` surface); ourios-querier depends on
# it too. MIT-licensed, so the cargo-deny license allow-list is unchanged.
serde_yaml_ng = { version = "0.10", default-features = false }
# `LogsServiceServer` to host the receiver's `LogsService` impl over gRPC.
opentelemetry-proto = { version = "0.32", default-features = false, features = ["gen-tonic", "logs"] }
# gRPC transport (server) for the OTLP/gRPC listener (RFC0003.16). `gzip`
Expand Down
11 changes: 6 additions & 5 deletions crates/ourios-server/src/config/file.rs
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@
//! resolved value without re-scanning it.
//!
//! **Type after substitution** (rule 7) is resolved at the typed boundary rather
//! than by re-tagging a node tree. `serde_yaml`'s `Value` does not preserve a
//! than by re-tagging a node tree. `serde_yaml_ng`'s `Value` does not preserve a
//! scalar's quoting style, so a literal "re-interpret the substituted scalar by
//! YAML's type rules" pass cannot tell a quoted string from a bare one and would
//! wrongly coerce `"01"` to an integer. Instead every leaf is captured as its
Expand Down Expand Up @@ -71,7 +71,7 @@ pub enum FileConfigError {
Substitution(MalformedReference),
/// A YAML syntax error, an unknown key (`deny_unknown_fields`), or a value
/// whose shape does not match the schema.
Schema(serde_yaml::Error),
Schema(serde_yaml_ng::Error),
/// A `storage.s3.*` credential holds an inline literal instead of an
/// `${env:…}` reference (RFC 0020 §3.5). Names the offending key only, never
/// the value.
Expand Down Expand Up @@ -396,13 +396,14 @@ pub fn parse(
yaml: &str,
lookup: &dyn Fn(&str) -> Option<String>,
) -> Result<FileConfig, FileConfigError> {
// Deserialise straight from the text (not via an intermediate `serde_yaml::
// Value`) so a schema error keeps its source location. Validation runs on the
// Deserialise straight from the text (not via an intermediate
// `serde_yaml_ng::Value`) so a schema error keeps its source location.
// Validation runs on the
// raw (pre-substitution) text, so any shape / unknown-key error names the
// file's own text, never a resolved secret (RFC 0020 §3.5). `Option` lets an
// empty / null document resolve to an all-default config (`None`) rather than
// fail the `null`-into-struct type check.
let mut config: FileConfig = serde_yaml::from_str::<Option<FileConfig>>(yaml)
let mut config: FileConfig = serde_yaml_ng::from_str::<Option<FileConfig>>(yaml)
.map_err(FileConfigError::Schema)?
.unwrap_or_default();
// Enforce §3.5 on the *raw* credential values — after substitution a
Expand Down