Documentation (14 pages)
Repository publication is pending. The instructions below describe the source tree as it will be published (AGPL-3.0). Until the public repository is live, treat them as the contribution guide-in-waiting.
Contributing
Tallow is open source under the AGPL-3.0 license. Contributions are welcome.
Repository
git clone https://github.com/tallowteam/Tallow.gitcd TallowBuild from Source
Requires Rust stable toolchain (1.86+):
# Build all cratescargo build --workspace
# Build the CLI onlycargo build -p tallow
# Build the relay servercargo build -p tallow-relay
# Build in release modecargo build --workspace --releaseTest Suite
# Run all testscargo test --workspace
# Run a specific crate's testscargo test -p tallow-cryptocargo test -p tallow-protocolcargo test -p tallow-net
# Run a specific testcargo test test_name
# Run with outputcargo test -- --nocaptureCode Quality
# Lint (warnings are errors)cargo clippy --workspace -- -D warnings
# Format checkcargo fmt --check
# Security auditcargo audit
# License and advisory checkscargo deny checkArchitecture
Tallow is organized as a 7-crate Rust workspace:
| Crate | Purpose |
|---|---|
tallow-crypto |
All cryptographic operations (zero I/O, pure functions) |
tallow-net |
Transport, NAT traversal, discovery, relay client |
tallow-protocol |
Wire protocol, file transfer, compression, rooms |
tallow-store |
Config, identity, trust, contacts, encrypted storage |
tallow-relay |
Self-hostable relay server binary |
tallow-tui |
Terminal UI engine (Ratatui + Crossterm) |
tallow |
Main CLI binary |
For detailed architecture, see docs/architecture.md in the repository.
Code Rules
Result<T, E>everywhere. No.unwrap()outside#[cfg(test)].thiserrorfor library errors,anyhowonly in the main binary.#![forbid(unsafe_code)]in all crates except where explicitly required.- All
unsafeblocks require a// SAFETY:comment. - All key material types must implement
Zeroize. - Use
subtle::ConstantTimeEqfor secret-dependent comparisons. - No
println!— usetracingmacros (info!,warn!,error!). - All public items get
///doc comments.
Security Rules
These are non-negotiable:
- Never commit secrets, keys, or credentials
- Never use
unsafewithout documented SAFETY justification - Never downgrade crypto algorithms without documented rationale
- Never use non-constant-time comparisons on secrets
- Never reuse AES-GCM nonces
- All key material must be zeroized on drop
Website Development
The website is an Astro 5 app in the website/ directory:
cd websitepnpm installpnpm run dev # Dev server at localhost:3000pnpm run build # Static export to dist/pnpm run check # Astro diagnosticsPull Request Process
- Fork the repository
- Create a feature branch:
feat/,fix/,security/,refactor/ - Write tests for your changes
- Ensure all checks pass:
cargo test,cargo clippy,cargo fmt - Submit a pull request with a clear description
- Squash merge to master after approval
Code of Conduct
We follow the Contributor Covenant Code of Conduct. Be respectful, inclusive, and constructive.
Reporting Security Issues
Please report security vulnerabilities responsibly via GitHub Security Advisories or email at tallowteam@proton.me. Do not open public issues for security bugs.