Repository navigation
chore(deps)(deps): bump rcgen from 0.13.2 to 0.14.8 - #28
Conversation
a5aecce to
2de1e8a
Compare
2de1e8a to
5add737
Compare
|
@dependabot recreate |
5add737 to
bb22576
Compare
|
✅ engrams review — complete. 2 findings posted. · View details |
There was a problem hiding this comment.
Engrams review
Verdict: 2 findings included in this summary.
Severity: Critical 0 · High 2 · Medium 0 · Low 0
Categories: 🎯 Functional Correctness: 2
Findings on the review page
crates/engram-egress-proxy/src/cert_mint.rs:L87— rcgen 0.14 bump breaks compile: signed_by() no longer takes (cert, key) — now takes &IssuerWHAT: The PR raises
rcgenfrom 0.13 to 0.14 inCargo.toml(line 265) but does not touch any source, so the 0.13-styleCertificateParams::signed_by(&subject_key, &issuer_cert, &issuer_key)call no longer compiles — rcgen 0.14 changedsigned_byto take a single&Issuerargument that bundles the issuer's params and signing key.WHEN: Every build of
engram-egress-proxy(and thus the whole workspace,just check, and CI) fails to compile after this bump.cert_mint.rs:87callsparams.signed_by(&leaf_kp, &ca_cert, &self.ca.key_pair)— three arguments — but the 0.14 signature issigned_by(&self, subject_key, &Issuer). The same 3-argument form is also used in the testcrates/engram-sandbox-firecracker/tests/proxy_e2e.rs:106(params.signed_by(&kp, &ca_cert, &ca_key)), which also breaks. Note this call site is the core TLS-MITM leaf-minting path for the egress proxy, so nothing that depends on rcgen can build.Scenario:
- Reviewer/CI checks out this PR.
cargo build/just checkcompilesengram-egress-proxy.cert_mint.rs:87fails with a wrong-arity / type-mismatch error becausesigned_byno longer accepts(subject_key, issuer_cert, issuer_key).Evidence basis for the API change: the official rcgen 0.14.0 release notes (release-planning issue rustls/rcgen#357) state "signed_by() methods now take a reference to an &Issuer type that contains both the issuer's relevant certificate parameters and the signing key," and that
from_ca_cert_pem/from_ca_cert_dermoved fromCertificateParamstoIssuer.</body_md>
Update the mint path to the 0.14 API: build anrcgen::Issuerfrom the CA's params + key pair once (e.g. store anIssueronCainstead of re-self-signing), then callparams.signed_by(&leaf_kp, &issuer). Also update the comment at cert_mint.rs:76-79 which still describes the old "sign API takes a&Certificate" contract, and update the test at proxy_e2e.rs:106.
crates/engram-egress-proxy/src/ca.rs:L92— rcgen 0.14 bump breaks compile: CertificateParams::from_ca_cert_pem moved to IssuerWHAT: The PR bumps
rcgen0.13 → 0.14 (Cargo.toml:265) without editing source, but rcgen 0.14 removedCertificateParams::from_ca_cert_pem— the CA-cert constructors were moved offCertificateParamsonto the newIssuertype — soca.rs:91no longer compiles.WHEN: Every build after this bump.
Ca::from_pem(used by bothEnvCaSource— the production/multi-host deploy path — andLocalDiskCaSource) callsCertificateParams::from_ca_cert_pem(cert_pem)at line 91. In 0.14 that associated function does not exist onCertificateParams; it is nowIssuer::from_ca_cert_pem(...). The regression-guard test atca.rs:363(CertificateParams::from_ca_cert_pem(&cert_pem)) breaks the same way.Scenario:
- Build the workspace on this PR.
engram-egress-proxyfails to compile atca.rs:91(and testca.rs:363): no such associated functionfrom_ca_cert_pemonCertificateParams.This function is load-bearing: the surrounding comment (ca.rs:75-90) explains that parsing the issuer DN from the loaded cert via
from_ca_cert_pemis exactly what keeps leaves validating against the delivered CA. Porting it must preserve that DN-round-trip behavior, not just make it compile.API-change basis: rcgen 0.14.0 release notes (rustls/rcgen#357): "The from_ca_cert_der() and from_ca_cert_pem() constructors that were previously attached to CertificateParams are now attached to Issuer instead."</body_md>
PortCato the 0.14IssuerAPI: construct the issuer viaIssuer::from_ca_cert_pem(cert_pem, key_pair)and store/use thatIssuerfor signing leaves (see the companion finding on cert_mint.rssigned_by). Preserve the DN-from-loaded-cert behavior the comment relies on, and update the test at ca.rs:363.
Bumps [rcgen](https://github.com/rustls/rcgen) from 0.13.2 to 0.14.8. - [Release notes](https://github.com/rustls/rcgen/releases) - [Commits](rustls/rcgen@v0.13.2...v0.14.8) --- updated-dependencies: - dependency-name: rcgen dependency-version: 0.14.8 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
rcgen 0.14 moved `from_ca_cert_pem` off `CertificateParams` and onto the new `Issuer` type, which now carries the signing key with it: CertificateParams::from_ca_cert_pem(pem) -> Issuer::from_ca_cert_pem(pem, key) params.signed_by(&pk, &issuer_cert, &issuer_key) -> params.signed_by(&pk, &issuer) `CertificateParams::from_ca_cert_der` is now `#[cfg(test)] pub(crate)`, so parsing a CA's params back out of its cert is no longer available — the `Issuer` round-trip is the supported path. `Issuer` is exactly the concept `cert_mint` was hand-rolling. It holds the distinguished name, key-id method, key usages and signing key, so we no longer re-self-sign the CA on every mint just to obtain a `&Certificate` to sign against. `Ca` drops its `params` field and grows `Ca::issuer()`, which derives the issuer from `cert_pem` — the same bytes delivered to guest trust stores. That strengthens the invariant behind the `Engram`->`Engrams` DN incident: X.509 path-building matches a leaf's issuer DN to the trusted CA's subject DN, so the issuer DN must come from the delivered cert and not from `build_params`'s constants. Previously that held because `from_pem` remembered to parse the cert; now it holds by construction, because the only source of the DN *is* the delivered PEM. A malformed cert is rejected in `from_pem` rather than at first mint, since `issuer()` parses on each call. `Issuer` does not expose its DN, so `from_pem_signs_with_the_loaded_cert_dn_not_the_constants` now asserts on a real signed leaf instead of an intermediate params field — the leaf's issuer field is what path-building actually reads, so the test pins the property end to end. I mutation-checked the guard: pointing `issuer()` at `build_params()` fails it. updated-dependencies: - dependency-name: rcgen dependency-version: 0.14.8 dependency-type: direct:production update-type: version-update:semver-minor Co-Authored-By: Claude <noreply@anthropic.com>
bb22576 to
2ff5436
Compare
|
✅ engrams review — complete. 0 findings posted. · View details |
Migrated to rcgen 0.14's
|
nikhilunni
left a comment
There was a problem hiding this comment.
rcgen 0.14 Issuer migration reviewed: deriving the issuer from cert_pem makes the delivered-DN invariant structural, and the leaf-DER regression test pins it end to end. All lanes green.
workspace-hack keeps its nom pin now: rcgen 0.14 (merged #28) pulls x509-parser, a second transitive nom consumer, so hakari still lists nom for feature unification. The direct workspace dependency stays gone — that is the change this branch makes. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Bumps rcgen from 0.13.2 to 0.14.8.
Release notes
Sourced from rcgen's releases.
... (truncated)
Commits
a70f083Bump version to 0.14.8a32fdb1Fix encoding of directoryName constraints7111a79update key_pair to signing_key10664c9Take semver-compatible dependency updates0ec4d09Add testing of CSR serializing basic constraints5f94ef9Add support for serializing BasicConstraints in CSR'sfb835c1Add writing basic constraints logic0cf161dBump codecov/codecov-action from 5 to 64909041Add testing of CSR Params parsing Basic Constraints variants6675a94Add support for is_ca in CSR Params