ia-rust-systems
Rust patterns for CLI tools, backend services, and general application code. Use when working with Rust, Cargo workspaces, axum/tokio services, clap CLIs, async concurrency, or configuring clippy, rustfmt, cargo-nextest, or Cargo.toml. Skill: ia-rust-systems Owner: iliaal Summary: Rust patterns for CLI tools, backend services, and general application code. Use when working with Rust, Cargo workspaces, axum/tokio services, clap CLIs, async concurrency, or configuring clippy, rustfmt, cargo-nextest, or Cargo.toml. Tags: latest:5.0.1 Version history: v5.0.1 | 2026-10-03T17:11:32.769Z | user v5.0.1 v5.0.0 | 2026-09-26T23:21:13.634Z | user v5.0.0 v4.5.3
Rank
62
Safety
84
Downloads
2.1k
Updated
Oct 9, 2026
Version
5.0.1
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 2.1K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 2.1K downloadsadoption · observed Oct 9, 2026
- Latest release
- 5.0.1release · observed Oct 3, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17bcar8wq0xhegs0ny6f57ypd8484bw:compound-eng-rust-systems- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-iliaal-compound-eng-rust-systems/snapshot"
Documentation
CLAWHUB
147,682 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
--- name: ia-rust-systems class: language description: >- Rust patterns for CLI tools, backend services, and general application code. Use when working with Rust, Cargo workspaces, axum/tokio services, clap CLIs, async concurrency, or configuring clippy, rustfmt, cargo-nextest, or Cargo.toml. paths: "**/*.rs,**/Cargo.toml" --- # Rust Systems & Services Covers modern application-layer Rust (edition 2024): CLIs, web services, libraries. Not `no_std`/embedded. ## Working rules - Preserve error variants in libraries and add operational context at application boundaries. - Distinguish missing configuration from unreadable or invalid files before writing replacements. - Keep blocking work off async workers, bound queues and spawned work, and define shutdown behavior. - Trace exported interfaces before treating a change as internal; verify installed runtime capabilities. - Do not mutate process-wide state in concurrent tests; exercise the real binary and relevant feature combinations. ## Unsafe Discipline - Default: no `unsafe`. If clippy flags it, don't `#[allow]` it; refactor. The `#[expect]` escape hatch below does not apply here; unsafe findings get fixed, not annotated. - Every `unsafe` block gets a `// SAFETY:` comment above it explaining why each invariant holds. No comment = reviewer rejects. - Keep `unsafe` blocks minimal: wrap in a safe abstraction at module boundary, mark the module `pub(crate)`. - Use `miri` (`cargo +nightly miri test`) on any crate containing `unsafe` or raw pointer arithmetic; it catches UB that optimizers mask. - Prefer `bytemuck`, `zerocopy`, `bytes` over hand-rolled transmutes for zero-copy patterns. - **Env-var writes are `unsafe` in edition 2024. Write them only in `main`, before the runtime starts or any thread spawns.** Concurrent `getenv` is UB; `OnceLock` does not make it safe. Watch for lazy `LD_LIBRARY_PATH`-style writes on first use; hoist them to startup. ## Discipline - Simplicity first: every change as simple as possible, impact minimal code. - Only touch what's necessary; avoid unrelated changes in a PR. - No `#[allow(clippy::...)]` as a shortcut; fix the underlying issue. When a suppression is genuinely warranted, write `#[expect(clippy::lint_name, reason = "...")]` instead: `expect` warns once the lint stops firing, so a suppression that has outlived its cause reports itself, where `allow` rots silently forever. (`expect` needs Rust 1.81+; edition 2024 clears that floor.) - Before adding a trait or generic, verify it's used in 3+ places. Otherwise a concrete type is clearer. - **`bool::then_some(x)` takes `x` by value: the argument is computed before the bool is consulted**, so a guard written as a condition plus a fixed-width slice panics on exactly the inputs the condition was checking for: `(b.len() >= 19 && b[4] == b'-').then_some(&v[..19])` panics on any shorter value, exiting 101 inside the one function written to report the case as undetermined. Use `then(|| …)`, which is lazy. Clipp
_meta.json
{
"ownerId": "kn715jrbbh71q9zncr0bqdkr8n848q1a",
"slug": "compound-eng-rust-systems",
"version": "5.0.1",
"publishedAt": 1791047492769
}references/applications-and-testing.md
# Applications and testing
## CLI Tools (clap)
- Use the derive API: `#[derive(Parser)]` + `#[derive(Subcommand)]`. Less boilerplate, types drive the help text.
- One `enum Commands` variant per subcommand; flatten shared flags into a `#[command(flatten)] struct CommonArgs`.
- `--json` flag on query commands for agent/pipe consumption. Emit via `serde_json::to_string(&value)?`.
- Exit codes: 0 success, 1 for errors `main` returned, 2 for argparse (clap handles this), reserve 3+ for domain meanings documented in `--help`.
- Provide `--version` automatically via `#[command(version)]`.
See [cli-tools.md](./cli-tools.md) for config layering, logging setup, progress reporting, and shell completions.
## HTTP Services (axum)
- Framework default: **axum** (tokio-native, tower middleware, extractor-based handlers). Pick `actix-web` only if an existing codebase uses it.
- Handlers return `Result<impl IntoResponse, AppError>`. Implement `IntoResponse` for `AppError` to centralize error → status mapping.
- Validate input at the boundary: `axum::extract::Json<T>` where `T: Deserialize + Validate` (use `validator` crate). Internal services trust input was validated.
- Share state via `State<Arc<AppState>>`, not globals, not `lazy_static`.
- Middleware via `tower::ServiceBuilder`: tracing → timeout → auth → CORS → handler. Order matters.
- **Resilience layers** (outbound clients, shared services): combine `LoadShed` + `ConcurrencyLimit` for backpressure, not unbounded queueing; full tower stack in [production-resilience.md](./production-resilience.md).
See [axum-service.md](./axum-service.md) for project layout, extractors, error types, graceful shutdown, and OpenAPI generation.
## Testing
- Built-in `#[test]`. Prefer `cargo nextest run --workspace` over `cargo test`; it runs tests in parallel processes with proper isolation.
- Unit tests live in `mod tests { ... }` at the bottom of the file (access to private items).
- Integration tests in `tests/` directory. One file per public surface area.
- `#[tokio::test]` for async tests. Add `flavor = "multi_thread"` when the code under test spawns tasks.
- `rstest` for parametrized tests and fixtures. `proptest` / `quickcheck` for property-based tests on pure logic.
- `insta` for snapshot testing CLI output, serialization, large structs. Review diffs with `cargo insta review`.
- `assert_cmd` + `predicates` for CLI integration tests (invokes the binary, asserts on stdout/stderr/exit code).
- **Assert on error variants with `matches!`**: `assert!(matches!(result.unwrap_err(), MyError::Validation(_)))`. No `match` arms to update when unrelated variants are added.
- Coverage: `cargo llvm-cov --workspace --html`. Target 70%+ on application code, higher on library crates.
- **Fuzzing for parsers**: `cargo fuzz` + `libfuzzer-sys` on any code parsing untrusted input; nightly runs surface panics and UB unit tests miss.
- **Never mutate process-global state in a test.** `set_var("TMPDIR", …)` in one test makes every *creferences/axum-service.md
# Axum HTTP Services
Patterns for building production HTTP services with `axum` + `tokio` + `tower`.
## Project Layout
```
src/
main.rs # Entrypoint: config load, tracing init, server bind, graceful shutdown
app.rs # Router assembly: `pub fn router(state: AppState) -> Router`
state.rs # AppState struct (pools, clients, config)
error.rs # AppError enum + IntoResponse impl
routes/
mod.rs
users.rs # One module per resource
health.rs
services/ # Business logic, no HTTP types
repo/ # Data access (sqlx), no HTTP types
config.rs
telemetry.rs # tracing + metrics setup
tests/
api.rs # Integration tests hitting the router directly
```
Rules mirror the layered architecture from `ia-nodejs-backend`:
- Routes parse + call services + format response. No business logic.
- Services never import from `axum` or `http`. No HTTP status codes leak in.
- Repos never construct `AppError` variants that map to HTTP; they return typed storage errors that services convert.
## AppState
```rust
#[derive(Clone)]
pub struct AppState {
pub db: sqlx::PgPool,
pub http: reqwest::Client,
pub config: Arc<Config>,
}
```
`Clone` is cheap because the expensive members are `Arc` inside. Inject with `State<AppState>` extractor; don't use globals or `OnceCell`.
## Error Type
```rust
use axum::{http::StatusCode, response::{IntoResponse, Response}, Json};
use serde_json::json;
use thiserror::Error;
#[derive(Debug, Error)]
pub enum AppError {
#[error("not found")]
NotFound,
#[error("invalid input: {0}")]
Validation(String),
#[error("unauthorized")]
Unauthorized,
#[error(transparent)]
Sqlx(#[from] sqlx::Error),
#[error(transparent)]
Other(#[from] anyhow::Error),
}
impl IntoResponse for AppError {
fn into_response(self) -> Response {
let (status, code) = match &self {
AppError::NotFound => (StatusCode::NOT_FOUND, "not_found"),
AppError::Validation(_) => (StatusCode::BAD_REQUEST, "validation"),
AppError::Unauthorized => (StatusCode::UNAUTHORIZED, "unauthorized"),
AppError::Sqlx(_) | AppError::Other(_) => {
tracing::error!(error = ?self, "internal error");
(StatusCode::INTERNAL_SERVER_ERROR, "internal")
}
};
let message = if status == StatusCode::INTERNAL_SERVER_ERROR {
"internal server error".to_owned()
} else {
self.to_string()
};
let body = Json(json!({
"error": { "code": code, "message": message }
}));
(status, body).into_response()
}
}
```
- One error envelope shape across every handler. Callers parse `.error.code` once.
- Log the full error with `?self` for `INTERNAL_SERVER_ERROR` paths; never leak internal messages to the client.
- Use `?` in handlers freely; `From` impls convert `sqlx::Error`, `anyhow::Error` into `Apreferences/build-profiles.md
# Build Profiles
Load this reference when setting up or tuning a Rust project's Cargo build profiles. Tune profiles for the shape of the binary: defaults ship fast debug builds and modest-optimization release builds, but application Rust benefits from more aggressive profiles.
## Profile definitions (Cargo.toml)
```toml
# Production release with task/request panic recovery
[profile.release]
lto = "fat" # Link-time optimization across all crates
codegen-units = 1 # Single codegen unit trades compile time for runtime perf
strip = true # Strip symbols from the final binary
panic = "unwind"
# Release with symbols kept for profiling (perf, flamegraph, pprof)
[profile.release-dbg]
inherits = "release"
strip = false
debug = true
# Size-minimized release for distributable CLIs
[profile.release-min]
inherits = "release"
opt-level = "z" # Optimize for size over speed
```
Keep `panic = "unwind"` when a task boundary or `catch_unwind` must convert a panic into an error response. Choose `panic = "abort"` only when immediate process termination is the intended failure policy; Tokio cannot return a panic as `JoinError` after the process aborts. Panic hooks run in both modes and provide diagnostics, not recovery. Select panic policy at the final application's profile rather than promising recovery from a library's profile setting.
## Dev-machine compile speedups (.cargo/config.toml)
Cut PR compile time on Linux with mold:
```toml
[build]
rustflags = ["-C", "link-arg=-fuse-ld=mold"]
[target.x86_64-unknown-linux-gnu]
rustflags = [
"-C", "link-arg=-fuse-ld=mold",
"-C", "target-cpu=native", # dev machines only — bakes in CPU features
"-Z", "share-generics=y", # share monomorphizations across crates (nightly)
]
[alias]
t = "nextest run"
```
Mold is Linux-only (`lld` on other platforms). `target-cpu=native` is a developer-machine convenience; remove for reproducible CI and distributable binaries.AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/iliaal/skills/compound-eng-rust-systems",
"sourceUrl": "https://clawhub.ai/iliaal/skills/compound-eng-rust-systems",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T18:36:50.795Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-iliaal-compound-eng-rust-systems/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-iliaal-compound-eng-rust-systems/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T18:36:50.795Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "2.1K downloads",
"href": "https://clawhub.ai/iliaal/compound-eng-rust-systems",
"sourceUrl": "https://clawhub.ai/iliaal/compound-eng-rust-systems",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T18:36:50.795Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "5.0.1",
"href": "https://clawhub.ai/iliaal/compound-eng-rust-systems",
"sourceUrl": "https://clawhub.ai/iliaal/compound-eng-rust-systems",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-03T17:11:32.769Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-iliaal-compound-eng-rust-systems/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-iliaal-compound-eng-rust-systems/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 5.0.1",
"description": "v5.0.1",
"href": "https://clawhub.ai/iliaal/compound-eng-rust-systems",
"sourceUrl": "https://clawhub.ai/iliaal/compound-eng-rust-systems",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-03T17:11:32.769Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
