The inside story of building the largest pure-Rust sovereignty stack
324 posts
OxiXML 0.1.0 is the first release of the COOLJAPAN Pure-Rust foundation for all XML and RDF processing — 44 crates spanning a quick-xml-compatible parser, DOM/SAX/HTML5 trees, XSD 1.1/RELAX NG/Schematron validation, XPath/XQuery/XSLT, XMLDSig/XMLEnc, and the full RDF 1.2/Turtle/JSON-LD/RDFa/SPARQL stack. 137,656 of 138,249 W3C conformance cases passing (99.6%), 0 external crates in default features.
OxiRS 0.4.1 closes a full oxirs-fuseki authentication bypass, makes Raft storage genuinely fsync-durable, fixes a SPARQL parser that silently dropped FILTER clauses, and removes fabricated results from SHACL/AutoML/federation — 308 findings audited, ~300 fixed, 46,255 tests passing across 27 crates.
OxiGeo 0.2.1 is a production-hardening release: a multi-agent defect sweep found 342 bugs and fixed 314, including two CRITICAL silent-corruption decoders (JPEG2000, GRIB2) and a WFS-T fail-open security hole. A new axum gateway serving layer ships, and retiring oxigeo-kafka makes the workspace fully C-toolchain-free.
SciRS2 0.6.4 is a fast follow-up to 0.6.3: oxifft 0.4.1 added a hard compile_error! for its threading (rayon) feature on wasm32 targets, which scirs2-fft and scirs2-signal didn't gate for that target -- silently blocking scirs2-wasm and the scirs2 meta-crate from publishing. Both catch up now, with target-gated dependencies fixing wasm32 builds for good. Pure Rust, Apache-2.0.
OxiCUDA 0.5.2 fixes a class of PTX portability bugs that CUDA 11.x silently tolerated and CUDA 12.9+ toolchains reject outright (non-ASCII bytes in generated comments), closes several Windows-specific test and lock-contention bugs, and fixes a numerical-correctness bug in the tensor-network DMRG excited-states solver. 38,675 tests, ~1.30M SLoC, 74 crates.
OxiCUDA 0.5.3 fixes an async-copy race condition where cuMemcpyDtoHAsync/cuMemcpyHtoDAsync and DeviceBuffer::copy_from_host could return before the transfer had actually landed, letting the very next read observe stale or zeroed device/host memory. 38,675 tests, ~1.30M SLoC, 74 crates.
Pure Rust FFT and the rustfft replacement. OxiFFT 0.4.0 adds distributed real (r2c/c2r) MPI transforms, wires wisdom-based auto-tuning into MEASURE/PATIENT/EXHAUSTIVE planning so it really compares candidate algorithms, corrects the MSRV to 1.87, and ships a breaking cleanup of dead planner code plus a v2 wisdom binary format.
OxiFFT 0.4.1 is a small, focused release: it pulls in OxiCUDA 0.5.3, which fixes a race condition where async CUDA memory copies in oxicuda-fft could return before the transfer landed — risking silently corrupted or all-zero GPU transform results under load.
OxiProto 0.1.4 ships oxiproto-protoc — a protoc-argv-compatible binary letting any prost-build/tonic-build project skip the C++ compiler entirely by pointing PROTOC at pure Rust. This release also closes an unbounded-recursion decode DoS across all three nested-message paths and removes OxiProto's own last internal protoc dependency. Pure Rust, Apache-2.0.
SciRS2 0.6.3 fixes seven Windows-only crash-and-corruption bugs invisible on Linux CI: an alloc/dealloc alignment mismatch that corrupted the heap, a recursive Drop impl that overflowed the 1MB default stack, a ~5.5GB eager-allocation process abort, and a path validator that rejected every C:\ path — plus two numerical-correctness fixes in ESPRIT and N4SID system identification. Pure Rust, Apache-2.0.
OxiBonsai 0.2.3 ships a two-pass, 109-agent production-hardening audit: a P0 fix for a silent CUDA prefill/decode KV-cache desync, full Metal GPU coverage for Q4_0/Q8_0/K-quant and FP8 batch prefill, real OpenAI-compatible penalties and logprobs, and tokenizer fidelity fixes for CJK/emoji text — 91 confirmed findings closed, 5,158 tests passing. Sub-2-bit Pure Rust sovereign AI inference for the COOLJAPAN ecosystem.
OxiCUDA 0.5.1 adds oxicuda-nvrtc, a pure-Rust runtime loader for NVIDIA's NVRTC CUDA-C-to-PTX JIT compiler, completing the zero-SDK-dependency story alongside oxicuda-driver. Graceful degradation, process-wide caching, and direct PTX handoff to oxicuda-driver. 38,646 tests, ~1.30M SLoC, 74 crates.
OxiH5 0.2.2 ships a 44-agent interop audit against h5py 3.16 and netCDF4-python 1.7.4, fixing 33 conformance defects and closing 9 writer gaps — shuffle/Fletcher32 pipelines, custom fill values, true netCDF coordinate variables. 862 tests passing — the sovereign scientific-data layer for COOLJAPAN.
OxiZ 0.3.0 is a hardening-and-capability wave: a new ground string decision procedure and concrete floating-point model finder lift qf_s and qf_fp from partial to 10/10 on the Z3 parity suite, MBQI SAT certification advances three quantified logics, and a dozen soundness bugs are fixed — 8,119 tests passing, 0 Wrong verdicts across 154 decisive Z3 comparisons. Pure Rust, Apache-2.0.
SciRS2 0.6.2 replaces the C-linked hdf5 crate with pure-Rust oxih5, fixing a critical silent-data-loss bug in compressed HDF5 writes and a self-concealing dataspace-parsing bug along the way. libnuma, tracy-client, and opencl3 are gone from the dependency graph, plus a breaking TLS-provider hardening. Pure Rust, Apache-2.0.
OxiH5 0.2.1 adds DEFLATE compression on write, per-chunk tiling, in-place dataset overwrite, and nested groups — and fixes 9 correctness bugs, including a chunk B-tree defect that made every chunked dataset the writer produced unreadable by libhdf5. 682 tests passing — the sovereign scientific-data layer for COOLJAPAN.
OxiGDAL 0.1.7 is a production-hardening release: 233 verified defects fixed across 69 crates — a GeoTIFF corruption bug, JPEG2000 spec conformance, real FlatGeobuf/HDF5 codecs, an RBAC bypass — plus a blake3/Ed25519 attestation module and three new WASM demos. 76 crates, 16,909 tests. The sovereign geospatial layer for COOLJAPAN.
OxiGDAL is now OxiGeo. Version 0.2.0 is a rename-only release — functionally identical to v0.1.7 — that republishes all 74 crates, the CLI, and the Python/npm/WASM/mobile bindings under the oxigeo name. Old GitHub URLs redirect; v0.1.7 remains the final OxiGDAL release. The sovereign geospatial layer for the COOLJAPAN ecosystem, now under its permanent name.
OxiProj 0.1.2 is a hardening/correctness release for the Pure-Rust PROJ replacement: automatic epoch-aware datum pathfinding, exact-autodiff Tissot distortion reachable from the public engine API, guaranteed-bounds interval-arithmetic transforms, SIMD batch lane-correctness fixes, and an SQL-injection fix — still no C, no FFI.
OxiRS 0.4.0 ships oxirs-tdb as a genuinely durable on-disk backend (WAL, superblock, sorted bulk build), unifies SELECT/ASK/CONSTRUCT/DESCRIBE through a single real oxirs-arq dispatch, migrates every route to axum 0.8, and hardens DID crypto, SSO, and cluster BFT — 45,199 tests, zero warnings across 27 crates.
OxiZ is a high-performance SMT solver in pure Rust — a Z3 replacement. 0.2.4 lands the results of a 19-agent production-readiness audit and five fix waves — real Sturm sequences, sound SAT conflict analysis, honest Cooper QE, corrected BV division — plus new oxiz-py string, floating-point, and quantifier bindings, with 7,666 tests passing workspace-wide.
OxiCrypto 0.2.1 measures ML-DSA-87's worker-thread stack down to 2 MiB from a hardcoded 8 MiB, ships a default-on alloc feature for genuine no_std core-only builds, adds a PQ-to-AEAD hybrid encryption test, and fixes a truncated-HMAC panic — the sovereign Pure Rust cryptography layer for the COOLJAPAN ecosystem.
OxiH5 0.2.0 adds superblock v1 parsing, v2/v3 superblock-extension decoding (B-tree K values, shared message table, file space info, driver info), and fixes a silent OCHK object-header creation-order misdecode. 494 tests passing across four crates — the sovereign scientific-data layer for the COOLJAPAN ecosystem.
OxiSQL — the COOLJAPAN ecosystem's sovereign Pure-Rust SQL layer and C-free SQLite-compatible engine — ships 0.4.0: every inter-crate dependency floor across all 17 crates is pinned to the exact full-triple 0.4.0, a clean 0.4.x baseline no stale Cargo.lock can break. A packaging bump, no source changes since 0.3.3.