Technical Stack Details
Technical Stack Details
Detailed technical stack and dependencies for DuoKey PQC Scanner
Core Technology
Version: Stable (latest recommended)
Why Rust?
Memory Safety
No garbage collection, compile-time memory safety guarantees
Performance
Zero-cost abstractions, comparable to C/C++
Concurrency
Fearless concurrency with ownership system
Cross-Platform
First-class support for Linux, macOS, Windows
- Modern Tooling: Cargo package manager, rustfmt, clippy
- Strong Type System: Prevents many classes of bugs at compile time
Dependencies
rustls (v0.23+)
Pure Rust TLS 1.2/1.3 implementation, used together with rustls-pemfile for PEM loading.
Features:
- No OpenSSL dependency
- Memory-safe TLS
- Modern cipher suites
- TLS 1.3 support
x509-parser (v0.16+)
X.509 certificate parsing
Capabilities:
- Parse DER/PEM certificates
- Extract public keys
- Validate certificate chains
- OID parsing
der & pem (v0.7+ / v3.0+)
Low-level encoding/decoding of DER and PEM data.
tokio (v1.35+)
Asynchronous runtime (enabled with its full feature set).
Features Used:
fs: Async filesystem operationsnet: TCP/TLS networkingsync: Channels, mutexestime: Timers, timeoutsmacros:#[tokio::main]rt-multi-thread: Multi-threaded runtime
clap (v4.5+)
Command-line argument parsing (using the derive, env, and cargo features).
Features:
- Derive macros for easy CLI definition
- Subcommands
- Environment variable support
- Shell completions
- Help generation
serde (v1.0+)
Serialization framework, paired with serde_json and serde_yaml for the JSON and YAML output formats.
Formats Supported:
- JSON (default output)
- YAML (human-readable)
- Custom SARIF format
tracing (v0.1+)
Structured logging, with tracing-subscriber (env-filter feature) handling log output and filtering.
Features:
- Structured, contextual logging
- Multiple log levels
- Filtering by module
- JSON output support
anyhow & thiserror (v1.0+)
Usage:
anyhow: Application-level errorsthiserror: Library-level custom errors
walkdir (v2.4+)
Recursive directory traversal
Features:
- Efficient recursive scanning
- Symbolic link handling
- Filtering
- Metadata access
rayon (v1.8+)
Data parallelism
Use Cases:
- Parallel file processing
- Concurrent certificate analysis
- Multi-threaded scanning
pcap (v2.0+)
Packet capture (libpcap wrapper)
Platform Dependencies:
- Linux:
libpcap-dev - macOS: Built-in libpcap
- Windows: WinPcap or Npcap
pnet (v0.35+)
Packet parsing
Features:
- TCP/IP packet parsing
- Layer 2-4 protocol support
- Stream reassembly helpers
indicatif (v0.17+)
Progress bars
ratatui (v0.26+)
Terminal UI framework, used with crossterm for terminal control.
Used For:
- Network mode real-time display
- Interactive statistics
- Status monitoring
Build System
The project is built with Cargo. The package is published under the name dke-scanner-agent at version 1.0.0, targets the 2021 edition, and is dual-licensed under MIT or Apache-2.0. It produces a binary named dke-scanner-agent and a reusable library named pqc_scanner.
The runtime dependencies are grouped by purpose:
| Group | Crates |
|---|---|
| Core | tokio, anyhow, thiserror |
| Crypto | rustls, x509-parser, der, pem |
| CLI | clap |
| Serialization | serde, serde_json, serde_yaml |
| Logging | tracing, tracing-subscriber |
| File system | walkdir |
| Parallelism | rayon |
| Network | pcap, pnet |
| UI | indicatif, ratatui, crossterm |
Development dependencies include criterion for benchmarking and tempfile for tests. The release profile is tuned for size and speed: maximum optimization level, link-time optimization, a single codegen unit, and stripped debug symbols.
Platform-Specific Dependencies
System Packages:
# Ubuntu/Debian
sudo apt-get install libpcap-dev pkg-config build-essential
# RHEL/CentOS
sudo yum install libpcap-devel
# Arch
sudo pacman -S libpcap
System Packages:
# libpcap is included with macOS
# Optional: Homebrew for development tools
brew install pkg-config
Prerequisites:
- Visual Studio Build Tools or MSVC
- Npcap (for packet capture): https://npcap.com/
# Install Npcap
choco install npcap
Compilation
cargo build --release
Output: target/release/dke-scanner-agent
Performance Characteristics
Binary Size
| Build Type | Size | Description |
|---|---|---|
| Debug | ~50 MB | Unoptimized with debug symbols |
| Release | ~8 MB | Optimized, stripped |
| Release + UPX | ~3 MB | Compressed with UPX |
Memory Usage
| Mode | Typical | Peak |
|---|---|---|
| Agent | 30 MB | 50 MB |
| Filesystem | 50 MB | 100 MB |
| Domain | 40 MB | 80 MB |
| Network | 60 MB | 150 MB |
CPU Usage
- Single-threaded parsing: 1 core
- Parallel filesystem scan: All cores
- Network capture: 1-2 cores
Testing Dependencies
Tests rely on a small set of development-only crates:
| Crate | Purpose |
|---|---|
| criterion | Benchmarking |
| tempfile | Temporary files for tests |
| mockall | Mocking framework |
| proptest | Property-based testing |
CI/CD Integration
name: CI
on: [push, pull_request]
jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions-rs/toolchain@v1
with:
toolchain: stable
- run: cargo test --all-features
- run: cargo clippy -- -D warnings
Version Requirements
| Dependency | Minimum Version | Recommended |
|---|---|---|
| Rust | 1.70 | Latest stable |
| Cargo | 1.70 | Latest |
| libpcap | 1.9.0 | 1.10.0+ |