github doublegate/RustIRC v0.4.3
v0.4.3 - Protocol Integration & Dependency Security

2 hours ago

v0.4.3 - Protocol Integration & Dependency Security

RustIRC v0.4.3 collects the protocol and integration improvements, dependency maintenance,
and security remediations merged since v0.4.2.
It retains the Iced 0.14 graphical interface, ratatui terminal interface, Lua 5.4 scripting,
and six-crate workspace. This release is a maintenance milestone with additive protocol APIs;
it does not introduce a new GUI framework or require a configuration format migration.

The most significant changes are SCRAM-SHA-256 authentication, a borrowed IRC message
parser, additional IRCv3 routing and event bridges, DCC transfer improvements, and an updated
TLS/cryptography/font rendering dependency graph. Release packaging now consumes these
curated notes and verifies consistent version metadata before publishing checksummed assets.

Release Scope

Area v0.4.3 result
Authentication SCRAM-SHA-256 mechanism registered alongside PLAIN and EXTERNAL
Protocol Borrowed message/prefix/tag representations and parser entry points
IRCv3 integration Batch tracking, history request dispatch and CAP negotiation handling
Extensibility Script event-bus constructor and plugin event dispatch bridge
Dependency audit Zero vulnerability entries; three disclosed maintenance warnings
Source toolchain Rust 1.89 minimum; packaged binaries built using pinned Rust 1.99.0
Release targets Linux x86_64, Linux ARM64, Windows x86_64
Release metadata Seven Cargo packages, lockfile and VERSION synchronized to 0.4.3

Authentication: SCRAM-SHA-256

crates/rustirc-core/src/auth.rs adds ScramSha256Mechanism and registers
SCRAM-SHA-256 with SaslAuthenticator::new(). The implementation includes:

  • A state machine for the client-first, server-first, client-final and server-final exchange.
  • Random client nonce generation and server nonce validation.
  • PBKDF2-HMAC-SHA-256 salted-password derivation, client proof construction and server signature verification.
  • Authentication failures propagated through the existing SASL error path.
  • A deterministic RFC 7677 exchange test using the published user / pencil test vector,
    plus a registration test checking the available mechanisms.

PLAIN and EXTERNAL remain available. SCRAM is an additional mechanism rather than a claim
that every server offers it or that all UI authentication paths automatically select it.
TLS remains necessary for transport confidentiality and authenticated server connections.

IRC Protocol: Borrowed Parsing and Message Lengths

Borrowed message API

crates/rustirc-protocol/src/message.rs adds MessageRef, PrefixRef and TagRef.
Parser::parse_ref() and Parser::parse_message_ref() borrow command, parameter, prefix
and tag slices from the input instead of allocating an owned string for every field.
The existing owned Message and parser APIs remain available, and the borrowed forms can
be converted to owned messages when storage or asynchronous ownership requires it.

The borrowed API still uses collection storage for parameters and tags; “borrowed” does not
mean the entire parse is allocation-free. Parser benchmarks now exercise the borrowed path.
No throughput or latency gain is asserted without a measured benchmark on comparable hardware.

IRCv3 tag allowance

validation.rs separates IRCv3 tag data from the traditional message body when checking
lengths. Tagged messages can therefore carry longer metadata without treating every tag byte
as part of the 512-byte traditional IRC message allowance. Tests cover a valid longer tagged
message and rejection when the message body itself exceeds its limit.

Core Routing and Capability Integration

MessageRouter now owns shared BatchManager and ChatHistoryManager instances:

  • Incoming BATCH +... / BATCH -... messages update batch boundaries.
  • Messages carrying batch membership are recorded by the batch manager.
  • batch_manager() and chat_history_manager() expose the shared managers.
  • request_chat_history(connection_id, request) constructs a CHATHISTORY request,
    sends it through Command::Raw, and returns the request identifier.

The connection read loop handles CAP LS/ACK/NAK and requests the implemented capability
set including account tags, batch, extended join, message tags and server time. These changes
wire existing protocol components into core paths; they do not claim support for every IRCv3
extension or complete server interoperability across all networks.

DCC, Scripting and Plugin Changes

DCC transfer behavior

Changes under crates/rustirc-core/src/dcc/ add bounded waits around connection establishment
and receive reads, seek to resume positions, and exchange four-byte big-endian cumulative ACKs
while transferring file chunks. The sender attempts ACK reads between chunks with a timeout.
Transfer progress and completion continue through the existing DCC event channel. Direct chat
and session handling also receive integration updates.

DCC remains a direct peer connection protocol: accept transfers only from trusted peers and
use ordinary file hygiene. This release does not claim end-to-end encryption for DCC or a
complete redesign of its trust model.

Lua event integration and sandbox accounting

ScriptEngine::with_event_bus() supports constructing the engine with the core event bus.
The sandbox instruction hook now keeps its accounting state per sandbox instead of sharing
a process-wide static counter. It resets the instruction budget following an idle interval.
The timeout remains instruction-hook based; it is not a hard wall-clock isolation boundary.
Lua remains version 5.4 through the vendored mlua build.

Plugin event bridge

PluginManager::dispatch_event() forwards events to enabled plugins. PluginEventHandler
implements the core asynchronous event handler trait around a shared manager, and built-in
logger/highlight plugins participate in event dispatch. Existing plugin lifecycle methods and
trait-based registration remain in place.

Dependency and Security Maintenance

The release includes the consolidated dependency work and later security-specific updates
through PR #158. The following table compares the actual v0.4.2 and v0.4.3 lock graphs;
multiple versions are listed where compatibility still requires them.

Package v0.4.2 v0.4.3 Purpose
rustls 0.23.37 0.23.45 TLS security fixes
rustls-webpki 0.103.9 0.103.15 Certificate verification fixes
aws-lc-rs / aws-lc-sys 1.16.1 / 0.38.0 1.18.1 / 0.45.0 Cryptographic backend updates
quick-xml 0.37.5, 0.39.2 0.41.0 XML dependency advisory fixes
memmap2 0.9.10 0.9.11 Memory mapping advisory fix
lru 0.16.3 0.18.5 GUI text cache dependency fix
fontdb 0.23.0 0.24.0 Font loading dependency modernization
mlua 0.11.6 0.12.2 Lua bindings refresh
tokio 1.50.0 1.53.2 Async runtime refresh
time 0.3.45 0.3.55 Removes the previous pinned vulnerable version
rand 0.8.5, 0.9.2 0.8.8, 0.10.3 Randomness dependency refresh
ratatui 0.30.0 0.30.2 Terminal UI maintenance
dirs 6.0.0 7.0.0 Platform directory resolution
base64 0.22.1 0.22.1, 0.23.1 Core encoding API refresh with transitive compatibility

GUI text dependency patches

The [patch.crates-io] entries use local vendor/cryoglyph and vendor/cosmic-text
sources. The patches update the text cache to lru 0.18.5 and font discovery to fontdb
0.24.0 without replacing the Iced renderer. Keeping the patch sources in the repository makes
the exact changes available in the release tag rather than relying on an unpinned remote fork.

Advisory verification and remaining warnings

The regression suite tests/security_advisories_test.rs checks resolved lockfile versions
against patched minimums for the affected packages. Every resolved copy is checked, and
prerelease versions are rejected. Additional tests exercise error context mutation, listener
notification, XML duplicate attributes, bounded namespace declarations and null-pointer formatting.
The TLS smoke test checks root-store/configuration setup; it does not test certificate chains,
name constraints or CRL-specific behavior. Value assertions alone do not prove the absence of
undefined behavior; the updated dependency versions and independent audit provide separate evidence.

A fresh cargo audit --json reports zero vulnerabilities. It still reports these
unmaintained dependency warnings, which remain visible rather than being presented as fixes:

Advisory Package Disposition
RUSTSEC-2025-0141 bincode Transitive GUI dependency; maintenance warning remains
RUSTSEC-2024-0436 paste Transitive dependency; existing CI policy ignores this maintenance advisory
RUSTSEC-2026-0192 ttf-parser 0.25.1 Partial graph mitigation only; remaining transitive paths still use it

Updating fontdb removes one older font-parser dependency path; it does not remove every
ttf-parser consumer. This remaining maintenance warning is recorded explicitly here rather than called resolved.
The security updates also remove obsolete ignores for time and instant after the vulnerable
time version and the instant dependency disappear from the resolved graph.

CI, Developer Environment and Release Packaging

  • Updated checkout/cache/artifact/coverage actions and pinned the sccache installation version.
  • Updated the development container from the retired VS Code image namespace and an obsolete
    Rust 1.75 base to the current Debian Trixie Rust environment.
  • Fixed GUI formatting borrows rejected by current Clippy and corrected the advertised source MSRV.
  • Fixed DCC intra-doc method links and protocol bare URLs so strict Rustdoc succeeds.
  • Consolidated ordered-float back to 4.6.0 after a compatible dependency refresh selected 5.5.0,
    which declares Rust 1.90 and conflicts with the package's Rust 1.89 minimum.
  • Synchronized all seven package manifests, workspace lock entries and the formerly stale VERSION file.
  • Pinned the artifact build toolchain to Rust 1.99.0 and enabled Cargo --locked for release builds.
  • Added native Linux/Windows artifact version/help smoke tests before packaging; ARM64 remains cross-built.
  • Restricted publication downloads to the three release artifacts, excluding full intermediate build trees.
  • Expanded the existing pinned Rust 1.89.0 check to all workspace targets with --locked to guard the advertised minimum toolchain.
  • Set job-scoped RUSTUP_TOOLCHAIN so the repository's stable toolchain file cannot override
    the selected minimum, matrix or artifact compiler; compiler-version assertions verify the pins.
  • Automated reusable CI now honors its stable/beta matrix rather than forcing both entries to stable.
  • Required curated notes and matching manifest/VERSION/tag metadata before publication.
  • Consolidated the legacy Release workflow into an existing-tag dispatcher for Master Pipeline;
    removed branch-based tag arithmetic so releases always use an explicitly reviewed tag.
  • Aggregate pipeline status now fails for any failed or cancelled prerequisite.
  • Prepared all six download assets in a draft and published only after checksum verification;
    GitHub's remote asset names must exactly match those six files, rejecting missing or stale
    extra assets before publication. Partial drafts remain retryable; a rerun refuses to replace
    an already published version.
  • Publication additionally requires successful test, security, documentation and coverage jobs.
    Release-candidate PRs also run all three artifact builds before tagging. Transient failures
    can be retried through Master Pipeline workflow_dispatch on the existing version tag;
    code/workflow corrections require a new reviewed version rather than moving an existing tag.

Downloads and Installation

Platform Target triple Archive
Linux x86_64 x86_64-unknown-linux-gnu rustirc-linux-amd64.tar.gz
Linux ARM64 aarch64-unknown-linux-gnu rustirc-linux-arm64.tar.gz
Windows x86_64 x86_64-pc-windows-msvc rustirc-windows-amd64.exe.zip

Each archive has an adjacent .sha256 asset. Linux packages use GNU libc, not musl;
these are not fully static binaries. macOS binary packaging remains disabled in the existing
release matrix. The automatically generated source archives are also available on the release page.

For Linux, download the matching archive and checksum into the same directory:

sha256sum -c rustirc-linux-amd64.tar.gz.sha256
tar -xzf rustirc-linux-amd64.tar.gz
./rustirc --version
./rustirc --help

For ARM64 substitute arm64 for amd64. On Windows, compare Get-FileHash -Algorithm SHA256
with the downloaded checksum, extract the ZIP with Expand-Archive, and run rustirc.exe --version.
Run --help to select the supported interface and connection options. The archives contain the
executable; example scripts and detailed documentation are available in the tagged source tree.

To build from source:

git clone --branch v0.4.3 --depth 1 https://github.com/doublegate/RustIRC.git
cd RustIRC
cargo build --release --locked --bin rustirc
./target/release/rustirc --version

Install the native GUI/build prerequisites described in the project documentation first.
A display server and suitable GPU/software rendering support are required for graphical use;
successful CLI version output alone does not demonstrate graphical interoperability.

Compatibility, Upgrade and Rollback

  • Source builds require Rust 1.89 or newer, raised from the older release's advertised 1.75.
    Use Rust 1.99.0 to reproduce the packaged toolchain selection.
  • Existing configuration files retain their current TOML format. Back up configuration,
    scripts and plugins before replacing an installed executable.
  • Additive protocol and event APIs preserve the existing owned parsing interfaces.
  • Dependency major updates may affect downstream consumers that integrate the workspace crates
    directly; this release does not publish independent crate packages to crates.io.
  • If startup, rendering, authentication or transfer regressions appear, retain logs without
    credentials, stop using the affected operation, and restore the previous executable and
    configuration backup. Published assets remain immutable; a fix ships under a new version.
  • No new production deployment flags, automatic updates or host configuration changes are enabled.

Verification

The baseline and release candidate each pass 223 unit/integration tests (182 unit + 41 integration)
and 59 doctests, 282 checks in total. Earlier release notes advertised 266 tests;
this release reports actual executable test and doctest counts separately.

The release preparation report records the exact checks and their results in
v0.4.3-validation.md.
Cross-platform CI verifies the release candidate; the tag workflow builds the three packaged
binaries and checks their archive SHA256 files before final publication. Download verification
checks the final published assets and executable version separately from source tests.

Full Changelog: v0.4.2...v0.4.3


Build Information:

Don't miss a new RustIRC release

NewReleases is sending notifications on new releases.