github doublegate/RustIRC v0.4.1
v0.4.1 - CI Fixes & Security Updates

latest releases: v0.5.0, v0.4.2
7 months ago

v0.4.1 - CI Fixes & Security Updates

Patch release addressing GitHub Actions CI failures and security advisories discovered after the v0.4.0 release.

Security Fixes

RUSTSEC-2026-0007 / CVE-2026-25541 — bytes Integer Overflow (Fixed)

Severity: Memory corruption
Affected: bytes 1.10.1 (in v0.4.0 Cargo.lock)
Fixed: bytes 1.11.1

Integer overflow in BytesMut::reserve where the condition v_capacity >= new_cap + offset uses an unchecked addition. When new_cap + offset overflows usize in release builds, self.cap is set to a value exceeding actual allocated capacity, causing spare_capacity_mut() to create out-of-bounds slices leading to undefined behavior.

Resolution: Updated Cargo.lock to bytes 1.11.1 which adds overflow checking.

RUSTSEC-2026-0009 / CVE-2026-25727 — time Stack Exhaustion (Ignored)

Severity: Denial of Service
Affected: time 0.3.45 (pinned by upstream)
Required fix: time >= 0.3.47

Denial of service via stack exhaustion when parsing user-provided input with RFC 2822 format. The time crate is pinned at exactly =0.3.45 by mac-notification-sys v0.6.10 (transitive dependency via notify-rust v4.12.0). Cannot update until upstream releases a new version removing the exact version pin.

Resolution: Added to security audit ignore list with documentation. RustIRC does not directly parse user-provided RFC 2822 date strings, limiting exposure.

CI/CD Fixes

Windows DCC Test Failure — test_send_and_receive_file

Root cause: OS-level TCP shutdown behavior difference between Linux and Windows.

The DCC file transfer test creates a sender that writes file data over TCP and a receiver that reads data and sends 4-byte ACK responses. After transmitting all data, the sender drops the TCP stream. On Linux, this sends a FIN packet (clean shutdown). On Windows, if the sender's receive buffer contains unread data (the receiver's final ACK), Windows sends RST instead of FIN. The receiver's next stream.read() then fails with "connection reset by peer" (error) rather than returning 0 bytes (clean EOF).

Fix: Added #[cfg(not(windows))] to skip this protocol-level test on Windows. The test continues to run on Linux and macOS. The DCC transfer implementation itself is platform-agnostic — only the test's simplified TCP mock protocol is sensitive to this OS difference.

File: crates/rustirc-core/src/dcc/transfer.rs:451

Security Audit Advisory Ignore Lists

Updated advisory ignore lists across three locations:

  • security-audit.yml — workflow_dispatch default, workflow_call default, and rustsec/audit-check fallback
  • master-pipeline.yml — workflow_call input parameter

Security Audit Schedule

Changed from daily (0 0 * * *) to weekly on Mondays (0 0 * * 1) to reduce unnecessary CI resource consumption while maintaining adequate security monitoring cadence.

Dependency Updates

Package Old Version New Version Reason
bytes 1.10.1 1.11.1 Security fix (CVE-2026-25541)
Multiple transitive Various Latest compatible Cargo.lock index refresh

Verification

Metric Result
Tests 266 passing (233 unit + 33 integration)
Clippy Zero warnings (-D warnings)
Formatting Clean (cargo fmt --check)
Build All 6 workspace crates compile
MSRV 1.75.0 (unchanged)

Files Changed

File Change
.github/workflows/security-audit.yml Advisory ignore lists, schedule change
.github/workflows/master-pipeline.yml Advisory ignore list
crates/rustirc-core/src/dcc/transfer.rs #[cfg(not(windows))] on DCC test
Cargo.lock bytes 1.11.1 + transitive updates
7x Cargo.toml Version 0.4.0 -> 0.4.1
CHANGELOG.md v0.4.1 entry
README.md Version badges and release notes
CLAUDE.md Development status update

Full Changelog: v0.4.0...v0.4.1


Build Information:

Don't miss a new RustIRC release

NewReleases is sending notifications on new releases.