Runasmidja — Decode. Transform. Understand.
A security-first Rust data-transformation workbench with a portable no_std engine.
Runasmidja is planned as a modern online CyberChef-style website and API. The same Rust engine will execute in a browser worker and native hosts. Browser processing is the default; saving, sharing, server execution and external network operations are distinct explicit actions.
Current status: foundations through v0.2.3 are signed and tagged with
accepted pentests and green GitHub checks. The 0.3.0 candidate replaces textual
workflow-reference checks with bounded YAML admission. Maintainer pentest is
PASS; final release commits await GitHub and tagging. No workbench, transformation, browser UI, production HTTP server or
CyberChef parity is implemented yet. See the 0.3.0 scope
and candidate assessment.
GitHub checks code and dependencies; CodeQL uses Default setup. Container builds, image scans and real service tests run locally before pushing. See the verification split.
The release plan defines 386 small pre-1.0 passes,
through 0.386.0, with further versions whenever needed. 1.0.0 is the first
serious production release with complete declared website/API functionality.
Desktop/mobile GUIs follow afterward.
The gap reconciliation adds verified
prerequisite owners and stronger acceptance while preserving all 240 reference
workstreams. These are planned controls, not implemented remediation.
Rust 1.99.0, edition 2024; EUPL-1.2. Weekly automation checks stable Rust,
crates, security tools, the pinned tooling-only PyYAML parser, GitHub Actions and
service upstream releases. Python checks use the private .local/check-tools
environment; no Rust/runtime dependency is added. See workflow policy.
rustup target add --toolchain 1.99.0 thumbv7em-none-eabihf wasm32-unknown-unknown
scripts/install_python_tools.sh
scripts/checks.sh
cargo run -p runasmidja-server -- 18080The development probe binds loopback and serves only GET /healthz.
It is disposable test infrastructure and will be replaced by a qualified HTTP
adapter. It is not the planned public API.
python3 scripts/install_image_tools.py
python3 scripts/stack.py up
python3 scripts/stack.py smoke
python3 scripts/stack.py stopDependencies run in rootless Podman: PostgreSQL 19 beta 4, OpenBao 2.7.1
and Valkey 9.1.2. PostgreSQL is built automatically from pinned official source
on a verified Wolfi base. Private custody lives in ignored .local/stacks/v023-wolfi-bao;
earlier .local/stacks/* and .local/stack data remain separate and retained.
OpenBao is initialized over TLS with declarative audit, KV v2, scoped AppRole
and revoked bootstrap root token. Image provenance and exact-digest scans run
before startup. Untriaged UNKNOWN and all HIGH/CRITICAL findings block execution.
OpenBao retains one digest-specific, expiring not-affected review; no other
blocking findings were reported. See local stack and the
PostgreSQL recipe and
OpenBao recipe.
The new fixture obtains database/cache passwords from OpenBao before dependent
startup, using separate scoped provisioning/runtime identities and version reuse.
Private password/ACL delivery copies remain until the v0.8 qualification. All project-operated secrets, including initialization/private
build/release credentials, must come through OpenBao; public Rust builds need
none. See secret lifecycle for bootstrap custody.
| Crate | Boundary | Current behavior |
|---|---|---|
runasmidja |
Public no_std facade | Re-exports portable boundaries |
runasmidja-core |
Allocation-free portable domain | Reserved foundation |
runasmidja-ports |
Application-owned integration contracts | Reserved foundation |
runasmidja-html |
HTML/formatting extraction to future Vef | Reserved foundation |
runasmidja-crypto |
Crypto/TLS extraction to future Brynja | Reserved foundation |
runasmidja-server |
Linux process/I/O adapter | Loopback health probe |
Portable crates are always no_std, forbid unsafe code and have no external
runtime dependencies. Hosted adapters may use reviewed dependencies. The
website and service SDKs are not claimed to be allocation-free or no_std.
Every code file has a hard 500-line ceiling.
Implementation plan, version plan, architecture, testing, release runbook, security controls, dependency policy, candidate release notes, tagged foundation notes.
The original idea and supplied planning bundle are retained as design inputs. Their historical compiler/provider statements are not current implementation evidence.
Operation search will work locally over descriptors. Saved-recipe metadata search has an early portable SearchService contract and two planned backends: repository search and optional Meilisearch. Both will be implemented/tested with hosted persistence; operators may enable or disable Meilisearch without changing the UI/API or recipe schema. Payloads/secrets are excluded and current database permissions govern results. See search design.
European Union Public Licence 1.2: LICENSE.
