Skip to content
CAI
Software that uses CAICheck a score

Etoile-Bleu/ZamSync

54.5

Adequate · 21 September 2026

7.5k

lines of production code

Rust

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add TCP and TLS transport layers for network communication

The network layer now supports unencrypted TCP and mutual TLS (mTLS) connections. Users can choose between a basic TCP transport for local or trusted networks and a TLS transport that enforces mutual certificate-based authentication, ensuring that only nodes with valid certificates can establish connections. Both transports support concurrent hub serving via split-connection handling.

crates/zamsync-network/src/transport · high confidence

Add mutual TLS (mTLS) transport and TLS credential management

The network crate now exposes a full TLS stack for secure node-to-node communication. It provides \TlsConfig\ to load and configure mutual TLS (mTLS) using the \rustls\ library, requiring both server and client certificate validation. Additionally, it includes utilities to generate CA and node certificates via \rcgen\, supporting both self-signed and CA-signed node certificates for deployment and signing workflows.

crates/zamsync-network/src · high confidence

Introduce access control policies, payload schema validation, and core replication types

The core library now enforces data visibility and integrity through new configuration options and types. Users can configure access control via the \AccessPolicy\ enum (\All\ or \OwnOnly\) to restrict event replication scope, and validate incoming data using the \PayloadSchema\ enum (\None\, \Json\, or \JsonRequired\ with specific fields). Additionally, the crate exposes foundational types for replication, including \VersionVector\ for tracking peer state, \Hlc\ (Hybrid Logical Clock) for ordering, and \NodeId\/\SequenceNumber\ identifiers.

crates/zamsync-core/src · high confidence

Introduce embedded HTTP dashboard and CLI color support

Users can now access a built-in web dashboard at /ui that displays live event streams, node status, and system metrics, alongside a new /health endpoint for health checks. The CLI now supports colored terminal output for commands, with automatic detection of TTY and environment variables to disable colors when appropriate. Additionally, a Prometheus metrics endpoint is exposed for monitoring.

src · high confidence

Introduce file-based storage adapters for peers and events

The storage layer now includes concrete adapter implementations for persisting replication state and event logs. A new FilePeerStore provides a file-backed PeerStore implementation that serializes and deserializes ReplicationState using rkyv. Additionally, a WalEventStore adapter is introduced to manage a write-ahead log for events, supporting both plain and encrypted (ChaCha20-Poly1305) modes, and offering methods to compact the log by dropping events older than a specified cutoff or frontier. These adapters implement the core ports defined in the hexagonal architecture, enabling the system to store and retrieve data from the local filesystem.

crates/zamsync-storage/src/adapters · medium confidence

Introduce new CLI commands for auditing, benchmarking, and data management

The \zamsync\ CLI now includes several new subcommands. The \audit\ command displays an event log with filtering by time, node, and head/tail limits, supporting text, CSV, and JSON output formats. The \bench\ command provides performance profiling for event submission, WAL reload, and sync bandwidth. The \expire\ command enforces data retention policies by dropping events older than a specified date. The \compact\ command reduces WAL size by removing confirmed events. The \daemon\ command enables autonomous periodic synchronization for clinic nodes. Additionally, the \project\ command now supports projecting events to a PostgreSQL database in addition to the existing SQLite support, and the \keygen\ command generates TLS credentials and WAL encryption keys.

src/cmd · high confidence

Introduces a binary wire protocol with zstd compression and reliable frame buffering

The network layer now uses a new binary protocol codec that serializes messages with rkyv and wraps them in a length-prefixed frame. Each frame includes a flag byte indicating whether the payload is raw or zstd-compressed, automatically applying compression for payloads over 64 bytes to reduce bandwidth. To handle slow or intermittent network links, a new FrameBuffer accumulates partial reads so that timeouts do not corrupt the framing. This change replaces the previous read\_exact approach, ensuring that partial reads on slow links are buffered and reassembled correctly.

crates/zamsync-network/src/protocol · high confidence

Introduces encrypted Write-Ahead Log (WAL) with CRC verification and deterministic event ordering

The storage crate now supports an encrypted WAL using ChaCha20-Poly1305, with each record protected by a CRC32 checksum to detect corruption. The \ZamEngine\ coordinates state and replication, while \LogSorter\ enforces deterministic global ordering of events using Hybrid Logical Clocks. Additionally, the \SyncSession\ implements a per-session bandwidth budgeting mechanism that caps the bytes sent during synchronization.

crates/zamsync-storage/src · high confidence

New testing crate with in-memory adapters and direct sync helper

A new \zamsync-testing\ crate has been added to the workspace, providing in-memory implementations of the \EventStore\ and \PeerStore\ ports, along with a \MockTransport\ for network simulation. The crate also exposes a \run\_direct\_sync\ function that synchronizes two engines in both directions without a transport layer, enabling convergence tests that do not need to exercise the wire protocol.

crates/zamsync-testing · high confidence

Project governance and infrastructure files added

The repository now includes foundational governance and infrastructure files: a Code of Conduct, a Security policy with coordinated disclosure process, a Contributor Covenant-based Code of Conduct, a CONTRIBUTING guide with build and test instructions, a ROADMAP detailing development phases, an ACKNOWLEDGEMENTS file crediting academic and ecosystem dependencies, a .all-contributorsrc configuration, a CONTRIBUTORS.md auto-generated list, and supporting files like .gitignore, .dockerignore, .gitattributes, Dockerfile, Dockerfile.release, docker-compose.yml, and the MIT LICENSE. These changes establish the project's legal, security, and community frameworks.

(repo-wide) · high confidence

Unattended deployment via systemd units and install script

The deploy directory now includes an install.sh script and systemd unit files (zamsync.service, zamsync-daemon.service) to automate the installation of the zamsync binary and configure it as a background service. The install script handles creating the zamsync user, setting up the /etc/zamsync configuration directory, and registering the systemd units. The zamsync.service unit manages the offline-first sync engine, while zamsync-daemon.service handles periodic outbound synchronization to a hub node, with configuration options for bind address, hub address, and sync interval.

deploy · medium confidence

Behavioural changes

Introduces core domain ports for event, peer, state, and transport operations

The codebase now defines four new traits in the \zamsync-core\ crate that serve as the internal API boundaries for the application's domain logic. The \EventStore\ trait manages event sequencing, appending, scanning, and synchronization, while also exposing a \byte\_size\ method for metrics. The \PeerStore\ trait handles loading and saving replication state. The \StateStore\ trait defines how events are applied and tracks the last applied sequence number. Finally, the \Transport\ trait specifies how sync messages are sent and received between nodes, including byte counts for bandwidth tracking. These interfaces decouple the core business logic from specific implementations, enabling the use of different storage and transport mechanisms.

crates/zamsync-core/src/ports · high confidence

Test coverage

Add E2E test infrastructure for network resilience and security; Added comprehensive test coverage for zamsync-storage; Added end-to-end TCP sync tests.

Dependencies

Initial dependency and workspace configuration for ZamSync

The project is initialized as a Rust workspace containing five crates: zamsync, zamsync-core, zamsync-network, zamsync-storage, and zamsync-testing. The Cargo.lock file and individual Cargo.toml files establish the dependency graph, including libraries such as axum, tokio, rusqlite, sqlx, and rustls. This commit sets up the foundational build structure and version constraints for the synchronization engine.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 53 → 55 (+2.0)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 96 → 96 (-0.0)
  • Architecture 100 → 93 (-7.5)
  • Maturity 71 → 79 (+7.3)
  • Readiness 69 → 71 (+1.6)
  • Security 66 → 72 (+6.8)
  • Domain Modelling 100 → 100 (+0.0)
  • Accessibility 29 → 29 (+0.0)

Resolved (42)

  • Build action pinned to a mutable branch
  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Further sole-owners (lower concentration)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 22 more

New (81)

  • Dependency hygiene PARTLY measured — Cargo dependencies read, dependency currency not (crates.io unreachable)
  • Documentation: no installation or build instructions (docs/src/README.md)
  • Documentation: no installation or build instructions (docs/src/architecture/overview.md)
  • Documentation: no usage examples (README.md)
  • Documentation: no usage examples (docs/src/cli-reference.md)
  • Duplicated block (10 lines × 2) (src/cmd/bench.rs)
  • Duplicated block (10–11 lines × 2) (crates/zamsync-storage/src/adapters/wal_event_store.rs)
  • Duplicated block (12 lines × 2) (crates/zamsync-storage/src/sync_session.rs)
  • Duplicated block (13 lines × 2) (crates/zamsync-network/src/transport/tcp/peer.rs)
  • Duplicated block (13–14 lines × 2) (src/cmd/serve.rs)
  • Duplicated block (14–15 lines × 2) (crates/zamsync-storage/src/sync_session.rs)
  • Duplicated block (16 lines × 2) (crates/zamsync-network/src/transport/tls_tcp/transport.rs)
  • Duplicated block (18 lines × 2) (crates/zamsync-network/src/transport/tcp/transport.rs)
  • Duplicated block (18 lines × 2) (crates/zamsync-storage/src/adapters/wal_event_store.rs)
  • Duplicated block (5 lines × 2) (crates/zamsync-network/src/tls.rs)
  • Duplicated block (5 lines × 2) (crates/zamsync-storage/src/adapters/wal_event_store.rs)
  • Duplicated block (5 lines × 2) (src/cmd/bench.rs)
  • Duplicated block (6 lines × 2) (crates/zamsync-network/src/transport/tcp/transport.rs)
  • Duplicated block (6 lines × 2) (crates/zamsync-storage/src/sync_session.rs)
  • Duplicated block (6–7 lines × 2) (crates/zamsync-storage/src/adapters/wal_event_store.rs)
  • …and 61 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Etoile-Bleu/ZamSync was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 376dc0ac4a27cf21be3c79ed1a90bb9f3b0e755e — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.