From 177ce013c7ce8cb9acf3e83a365c330fd133cc98 Mon Sep 17 00:00:00 2001 From: Yuansheng Date: Wed, 12 Aug 2026 19:21:17 +0800 Subject: [PATCH 1/2] build(deps): drop an unused dependency and narrow unused features Hygiene pass backed by a zero-usage search across src/ and tests/ of every crate: - aisix-a2a: remove the unused direct http dependency (its tests use axum's re-export; the crate itself never names http::) - tower-http: keep only set-header out of [trace, cors, limit, compression-gzip, set-header] - the other four have no call sites; body limiting is axum DefaultBodyLimit plus the crate's own enforce_request_body_limit - axum: drop macros (no debug_handler / derive(FromRef) users); the axum-macros proc-macro leaves the tree - uuid: drop serde (no Uuid crosses a serde boundary) - tracing-subscriber: drop json (no JSON formatter is constructible and no config knob selects one); tracing-serde leaves the tree axum's tracing feature is kept on purpose (it gates axum-internal rejection logging and exposes no API), now recorded in a comment. --- Cargo.lock | 28 ---------------------------- Cargo.toml | 12 +++++++----- crates/aisix-a2a/Cargo.toml | 1 - 3 files changed, 7 insertions(+), 34 deletions(-) diff --git a/Cargo.lock b/Cargo.lock index a0255b8bf..233c240f4 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -41,7 +41,6 @@ dependencies = [ "async-trait", "axum 0.7.9", "futures", - "http 1.4.0", "reqwest 0.12.28", "serde", "serde_json", @@ -1078,7 +1077,6 @@ checksum = "edca88bc138befd0323b20752846e6587272d3b03b0343c8ea28a6f819e6e71f" dependencies = [ "async-trait", "axum-core 0.4.5", - "axum-macros", "base64 0.22.1", "bytes", "futures-util", @@ -1173,17 +1171,6 @@ dependencies = [ "tower-service", ] -[[package]] -name = "axum-macros" -version = "0.4.2" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "57d123550fa8d071b7255cb0cc04dc302baa6c8c4a79f55701552684d8399bce" -dependencies = [ - "proc-macro2", - "quote", - "syn", -] - [[package]] name = "axum-server" version = "0.7.3" @@ -5205,7 +5192,6 @@ dependencies = [ "tower 0.5.3", "tower-layer", "tower-service", - "tracing", ] [[package]] @@ -5264,16 +5250,6 @@ dependencies = [ "tracing-core", ] -[[package]] -name = "tracing-serde" -version = "0.2.0" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "704b1aeb7be0d0a84fc9828cae51dab5970fee5088f83d1dd7ee6f6246fc6ff1" -dependencies = [ - "serde", - "tracing-core", -] - [[package]] name = "tracing-subscriber" version = "0.3.23" @@ -5284,15 +5260,12 @@ dependencies = [ "nu-ansi-term", "once_cell", "regex-automata", - "serde", - "serde_json", "sharded-slab", "smallvec", "thread_local", "tracing", "tracing-core", "tracing-log", - "tracing-serde", ] [[package]] @@ -5442,7 +5415,6 @@ checksum = "ddd74a9687298c6858e9b88ec8935ec45d22e8fd5e6394fa1bd4e99a87789c76" dependencies = [ "getrandom 0.4.2", "js-sys", - "serde_core", "sha1_smol", "wasm-bindgen", ] diff --git a/Cargo.toml b/Cargo.toml index 7313b7f51..285f4617a 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -36,11 +36,13 @@ futures = "0.3" tokio-tungstenite = { version = "0.24", features = ["rustls-tls-webpki-roots"] } async-trait = "0.1" -# HTTP server -axum = { version = "0.7", features = ["macros", "ws", "tracing", "multipart"] } +# HTTP server. axum's `tracing` feature has no API surface — it gates +# axum's internal logging of extractor rejections; a zero-hit grep is +# its normal appearance, keep it. +axum = { version = "0.7", features = ["ws", "tracing", "multipart"] } axum-server = { version = "0.7", features = ["tls-rustls"] } tower = "0.5" -tower-http = { version = "0.6", features = ["trace", "cors", "limit", "compression-gzip", "set-header"] } +tower-http = { version = "0.6", features = ["set-header"] } http = "1.2" http-body-util = "0.1" # Trusted-proxy CIDR matching for real-ip resolution (#492) @@ -113,12 +115,12 @@ yaml-rust2 = "0.8" # Time / IDs chrono = { version = "0.4", features = ["serde"] } chrono-tz = "0.10" -uuid = { version = "1.11", features = ["v4", "v5", "serde"] } +uuid = { version = "1.11", features = ["v4", "v5"] } hostname = "0.4" # Observability tracing = "0.1" -tracing-subscriber = { version = "0.3", features = ["env-filter", "json", "fmt", "registry"] } +tracing-subscriber = { version = "0.3", features = ["env-filter", "fmt", "registry"] } metrics = "0.24" metrics-exporter-prometheus = "0.16" diff --git a/crates/aisix-a2a/Cargo.toml b/crates/aisix-a2a/Cargo.toml index 1209c99b4..fb0c0a2c6 100644 --- a/crates/aisix-a2a/Cargo.toml +++ b/crates/aisix-a2a/Cargo.toml @@ -22,7 +22,6 @@ serde.workspace = true serde_json.workspace = true thiserror.workspace = true tracing.workspace = true -http.workspace = true # A2A has no official Rust SDK (the reference SDKs are Python/JS/Java/Go/.NET), # so the JSON-RPC 2.0 + agent-card plumbing is hand-rolled directly on the # workspace HTTP client rather than pulled from an SDK. From 11374ec6b772d466f3ad506488c34c489c5c6e64 Mon Sep 17 00:00:00 2001 From: Yuansheng Date: Wed, 12 Aug 2026 19:45:48 +0800 Subject: [PATCH 2/2] build(deps): clarify that axum's tracing feature is also a default feature The comment claimed removing the entry would drop rejection logging; with default features on, the entry documents intent rather than being what enables it (audit finding on #961). --- Cargo.toml | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/Cargo.toml b/Cargo.toml index 285f4617a..83b86c713 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -37,8 +37,10 @@ tokio-tungstenite = { version = "0.24", features = ["rustls-tls-webpki-roots"] } async-trait = "0.1" # HTTP server. axum's `tracing` feature has no API surface — it gates -# axum's internal logging of extractor rejections; a zero-hit grep is -# its normal appearance, keep it. +# axum's internal logging of extractor rejections, so a zero-hit grep is +# its normal appearance. It is also an axum default feature (defaults +# stay on here), so the explicit entry documents intent rather than +# being what enables it. axum = { version = "0.7", features = ["ws", "tracing", "multipart"] } axum-server = { version = "0.7", features = ["tls-rustls"] } tower = "0.5"