Security-first, no_std-first Rust crates for Swedish public APIs and public data.
One reviewed crate per source, explicit resource budgets, and small auditable releases.
sweden is the facade for a security-first Rust ecosystem for lawful, typed
access to Swedish public APIs and datasets. Shared logic is dependency-free,
no_std, and independently publishable. Future agency crates remain no_std;
future networking is isolated in focused std crates and is never enabled by
default.
The repository is at its 0.2.0 identifier/version milestone. The maintainer
pentest and retest passed; the release candidate now awaits green GitHub
Actions and CodeQL. It contains only the two crates needed now:
sweden-core and the sweden facade. It does not make real upstream requests,
and no agency integration has been introduced.
The default facade exposes only sweden-core:
[dependencies]
sweden = "0.2.0"Or depend directly on the foundation crate:
[dependencies]
sweden-core = "0.2.0"| Capability | Status | Evidence |
|---|---|---|
| Multi-crate workspace | Available | Two independently packageable crates |
no_std shared core and facade |
Available | Default builds contain no std import |
| Third-party dependencies | None | Workspace manifests contain first-party path dependencies only |
| Unsafe Rust | Forbidden | Every first-party crate uses #![forbid(unsafe_code)] |
| Canonical descriptive identifiers | Available | Borrowed source/operation/schema/policy/upstream IDs reject non-canonical input |
| Reviewed source spellings | Reserved only | Closed constants remain descriptive and cannot authorize execution |
| Agency integrations | Not introduced | Source crates begin only when their implementation milestone starts |
| HTTP/TLS implementation | Not implemented | The transport crate is deferred until its contract milestone |
| Production readiness | Not ready | Production admission is reserved for 1.0.0 after audit and pentest evidence |
| Crate | Environment | Purpose |
|---|---|---|
sweden |
no_std |
Facade and convenience re-exports |
sweden-core |
no_std |
Shared IDs, policy metadata, methods, and explicit budgets |
No empty placeholder crate is published. A crate is created and published only when its implementation begins:
| Planned introduction | Crate |
|---|---|
0.7.0 |
sweden-policy |
0.9.0 |
sweden-registry |
0.10.0 |
sweden-http |
0.13.0 |
sweden-codec-json |
0.16.0 |
sweden-codec-xml |
0.19.0 |
sweden-testkit |
0.20.0 |
sweden-schema |
0.21.0 |
sweden-executor, sweden-conformance |
0.22.0 |
sweden-trafikverket |
0.51.0 only if a reviewed 1.0 operation requires CSV |
sweden-codec-csv |
After 1.0.0 |
sweden-smhi, sweden-scb, sweden-jobtech, and sweden-skatteverket |
Every Rust crate introduced by this project is published to crates.io. Agency
and conformance crates use the shared core, policy, and codec crates they
require, never the root facade, registry, executor, HTTP, or another source
crate. sweden-registry owns generated source-specific authorization bindings;
generic execution belongs to sweden-executor; the facade aligns features,
wiring, and re-exports only.
The sweden facade always equals the repository tag and is published for every
release. Subcrates use independent versions and are published only when their
code, bugfixes, dependency requirements, or immutable package metadata change.
Unchanged subcrates keep their last crates.io version.
At v1.0.0, every crate then present in the workspace converges to 1.0.0 and
is published. The exact per-crate state is tracked in
the crate version matrix
and enforced by scripts/release_crates.py.
Rust 1.97.1 is the pinned development and release toolchain. The public
crates support every stable Rust release from 1.90.0 through 1.97.1.
| Rust toolchain | Support | Release-gate treatment |
|---|---|---|
1.90.0 |
Supported MSRV | Full workspace check |
1.91.0, 1.91.1 |
Supported | Compatibility check |
1.92.0 |
Supported | Compatibility check |
1.93.0, 1.93.1 |
Supported | Compatibility check |
1.94.0, 1.94.1 |
Supported | Compatibility check |
1.95.0 |
Supported | Compatibility check |
1.96.0, 1.96.1 |
Supported | Compatibility check |
1.97.0 |
Supported | Compatibility check |
1.97.1 |
Current development release | Full checks, Clippy, tests, docs, and packaging |
The latest-stable pin and Cargo tool versions are checked by
scripts/check_latest_tools.sh before a release.
Pure library crates are designed from day one for Linux, Windows, macOS, FreeBSD, NetBSD, Android, and iOS. Platform-independent code does not assume Unix paths, sockets, clocks, or environment variables. A future Aesynx transport can be added behind the same transport contracts without changing agency crates.
no_std support does not claim that TLS, DNS, or sockets are platform
independent. Applications provide those facilities through an explicit
transport implementation.
The repository starts fail-closed:
- no third-party project dependencies;
- no default networking, TLS, credentials, filesystem, clock, or telemetry;
- no arbitrary host or generic proxy surface;
- no unsafe Rust;
- explicit response budgets;
- source integrations stay
Foundationuntil their policy, fixtures, tests, upstream review, security review, and pentest gates pass; - CodeQL uses GitHub default setup rather than an advanced workflow;
- generated and handwritten Rust files over 500 lines fail the local gate.
Report vulnerabilities privately as described in the security policy.
Run the normal local gate:
scripts/checks.shVerify the locked local RFC reference baseline:
scripts/verify-rfcs.sh
python3 scripts/test-rfc-sources.pyRun the networked freshness and release gate only when preparing a release:
scripts/release_0_2_gate.shNo tag is created when implementation finishes. Every version stops for the
maintainer's pentest. Findings, fixes, retests, and later GitHub CI fixes stay
current in the same versioned repository report. The implementation and
AWAITING PENTEST report are committed as the exact pentest baseline. The
pentest outcome and any remediation are committed next; tagging happens only
after the maintainer confirms GitHub is green and explicitly requests the tag.
After that requested tag exists at HEAD, publish only the planned crates in
dependency order:
scripts/release_crates.py --check
scripts/release_crates.py --version 0.2.0 --require-tag- Implementation plan
- Release plan
- Crate version matrix
- Initial architecture discussion
- Modularity policy
- Toolchain policy
- Threat model
- Security controls
- Locked RFC reference baseline
- Supply-chain security
- Unsafe policy
Licensed under either the Apache License, Version 2.0 or the MIT license, at your option.