Repository navigation
chore(deps)(deps): bump sha2 from 0.10.9 to 0.11.0 - #10
dependabot[bot] wants to merge 2 commits into
Conversation
|
@dependabot recreate |
0bc4b2a to
5125d45
Compare
|
@dependabot rebase |
5125d45 to
6bd8dd8
Compare
|
@claude please fix the failing CI on this PR. The Dependabot bump from sha2 0.10.9 to 0.11.0 has API/trait-bound changes that broke our hashing call sites. Investigate the cargo compile errors across the failing checks and push fix commits — keep the dep bump intact, adjust the call sites only. |
6bd8dd8 to
aabbf0a
Compare
Phase 10 of the chunked-storage rollout. Pulls everything we've shipped (Phases 1-3, 6-additive, 8, 9) into a single referenceable record. - docs/adr/0007-chunked-immutable-storage.md — the headline ADR: context, decision (16 MiB disk / 512 KB memory chunks, versioned content-addressed manifests, MAP_PRIVATE memory dedup, working-set R&R, the three free COW levels, wire protocol versioning), consequences, alternatives considered. Includes an explicit "what this ADR does NOT cover" section so the gaps (NBD, UFFD, schema reshape, observability) don't get lost. - docs/known-issues.md — six new entries (#9 NBD missing, #10 UFFD missing, #11 cold-tier columns linger, #12 no metrics, #13 materialize-dir leak, #14 bincode wire-compat caveat). Each cross-references the rollout doc's Tier 4 punch list so a future contributor sees both the symptom and the tracking. - README.md — Phase 7 paragraph added; "two snapshot tiers, one primitive" narrative replaced with the chunked-storage shape + pointer to ADR 0007. - DESIGN.md — ADR 0007 added to the ADR list with the "supersedes 0005's two-tier framing" note; deploy artifact pointers added. The narrative architecture sections below are flagged as ADR-0005-era pending Phase 6's schema reshape — a deep rewrite is queued (the new SnapshotRecord shape drives the new descriptions; rewriting before that lands risks drift). - docs/deploy.md — header callout supersedes the cold-tier framing; points at the live deployment artifacts. - docs/chunked-storage-rollout.md — Phase 10 status marked 🟡 partial with explicit cite of what's shipped vs the deep narrative refresh still pending. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
aabbf0a to
8f88cbd
Compare
- known-issues #9 (NBD) marked resolved with commit hashes - known-issues #10 (UFFD-from-chunks) marked resolved with the shipped surface enumerated (canonical capture, working-set R&R, cross-host materialize-from-chunks) - known-issues #13 (materialized-rootfs leak) marked resolved — reap_materialize_dir + admin endpoint + chunk_gc cron driver - rollout doc Phase 1 GC scheduler ⬜ → ✅ + Tier 4 #4 ditto - ADR 0007 "What this ADR does NOT cover" rewritten: NBD, UFFD, materialize-orphan-reap, 0018/0019 schema reshape all move from "not implemented" to shipped; observability + the Phase 6 destructive trait reshape remain the named gaps. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
8f88cbd to
178fe99
Compare
178fe99 to
20e9cc9
Compare
20e9cc9 to
bd7cc26
Compare
1834b25 to
e096ef9
Compare
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
1 similar comment
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
@dependabot recreate |
e096ef9 to
dec7d8a
Compare
|
✅ engrams review — complete. 0 findings posted. · View details |
|
@dependabot recreate |
dec7d8a to
38cb7c9
Compare
|
|
Bumps [sha2](https://github.com/RustCrypto/hashes) from 0.10.9 to 0.11.0. - [Commits](RustCrypto/hashes@sha2-v0.10.9...sha2-v0.11.0) --- updated-dependencies: - dependency-name: sha2 dependency-version: 0.11.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
sha2 0.11 moves its output from `generic_array::GenericArray` to
`hybrid_array::Array`. `Array` does not implement `LowerHex`, so the
16 `format!("{:x}", digest)` sites across the workspace stop compiling.
Replace each with `hex::encode`, which emits the same lowercase,
two-digits-per-byte string. Every digest value is therefore unchanged.
`hex` is promoted to a workspace dependency; it was already a direct
dependency of engram-egress-proxy and already resolved at 0.4.3, so no
new code enters the build graph.
`ChunkHash::to_hex` is deliberately untouched: it hand-rolls the same
encoding over a `[u8; 32]` and never depended on `LowerHex`.
The two known-answer content-addressing tests pass unmodified, which is
the evidence that the digests themselves did not move:
- chunk_hash_is_sha256_of_the_bytes (FIPS 180-4 vectors)
- content_ref_never_moves (pinned manifest uuid)
38cb7c9 to
bb1f9d4
Compare
|
✅ engrams review — complete. 0 findings posted. · View details |
Migrated and green locally — ready for reviewI took ownership of this branch in today's dependency sweep and pushed the What upstream changedsha2 0.11 moves the RustCrypto stack from
What I migratedEach - let squashfs_sha256 = format!("{:x}", Sha256::digest(&squashfs));
+ let squashfs_sha256 = hex::encode(Sha256::digest(&squashfs));
- let digest = format!("sha256:{:x}", sha2::Sha256::digest(&bytes));
+ let digest = format!("sha256:{}", hex::encode(sha2::Sha256::digest(&bytes)));Sites:
The content-addressing tests pass, unmodifiedThis is the part worth stating explicitly for a hashing dependency. Both So sha2 0.11 computes the same SHA-256 as 0.10 over the same framing, and
What a reviewer should look at closely
Verification
17 tests fail in this sandbox ( One thing worth flagging: three |
Campaign checkpoint — blocked on a coupling that was not visible before todayI own this branch across runs. Reporting what changed, because the conclusion What I said last time, and why it no longer holdsThat comment ended with:
That was true when written. It is not true now. // crates/engram-coordinator/src/oauth_redirect.rs:314
let mut mac = Hmac::<Sha256>::new_from_slice(client_secret.as_bytes())The coupling, proven both directions
So this PR can no longer go green on its own, and neither can #1031 Then I bumped both together on a scratch branch. The trait-bound wall is gone hmac 0.13 stopped re-exporting Why I am not just folding hmac into this branchOne dependency per branch. Folding the two bumps into one Dependabot branch
Done this run#1046 adds a The digest evidence still standsThis is a hashing dependency, so restating it: the known-answer tests passed sha2 0.11 computes the same SHA-256 over the same framing, so no chunk or What the next run does first
The one real hazard, and the test that pins it
The existing test only checks determinism and secret-dependence: let a = derive_pkce_verifier("secret-a", flow);
assert_eq!(a, derive_pkce_verifier("secret-a", flow));
assert_ne!(a, derive_pkce_verifier("secret-b", flow));Every one of those still passes if the bytes move, as long as they move #[test]
fn pkce_derivation_is_hmac_sha256_of_the_framing() {
let flow = uuid::Uuid::parse_str("10600000-0000-4000-8000-000000000021").unwrap();
let verifier = derive_pkce_verifier("secret-a", flow);
assert_eq!(verifier, "R8IOB9xpKznAUFbKQKINVF1IOiolYNo2S-5YbgUDVDc");
assert_eq!(
pkce_challenge(&verifier),
"IA9MPT0_Cos-8yoetow-s2AsvTR7CWIotS62jDRQSd0"
);
}I have not landed this yet — I could not get a clean run of it inside this |
|
Superseded by #1059. |
Bumps sha2 from 0.10.9 to 0.11.0.
Commits
ffe0939Release sha2 0.11.0 (#806)8991b65Use the standard order of the[package]section fields (#807)3d2bc57sha2: refactor backends (#802)faa55fbsha3: bumpkeccakto v0.2 (#803)d3e6489sha3 v0.11.0-rc.9 (#801)bbf6f51sha2: tweak backend docs (#800)155dbbfsha3: add default value for theDSgeneric parameter onTurboShake128/256...ed514f2Use published version ofkeccakv0.2 (#799)702bcd8Migrate to closure-basedkeccak(#796)827c043sha3 v0.11.0-rc.8 (#794)