This release includes 1 breaking change for platform teams planning a safe upgrade.
Published 2mo
Network Security
✓ No known CVEs patched
✓ No known CVEs patched in this version
Summary
AI summaryUpdated the minimum supported Rust version to 1.95.
Full changelog
Rust safety and formal verification
- Refactored unsafe-adjacent Rust logic into proof-friendly pure models for outbound admission, pending writes, connection IDs, recv-buffer accounting, cmsg cursor walking, and io_uring provided-buffer layout.
- Added Kani contracts and bounded harnesses for admission accounting, pending-write release accounting, cmsg cursor bounds, recv-buffer capacity, QUIC-LB CID encoding, and provided-buffer range validation.
- Added standalone Verus sidecar proofs with a bootstrap/smoke path that installs and verifies against the latest Verus binary locally.
- Added structured fuzz targets, Miri smoke coverage, sanitizer scripts, and a Rust safety CI workflow for the new proof/fuzz lanes.
Correctness
- Fixed deferred-FIN outbound admission accounting so a full payload write whose FIN is not accepted keeps one admission unit held until the FIN is accepted.
- Fixed the Docker curl interop harness so header capture no longer depends on
/dev/stderrbeing openable by a spawned curl process.
Release metadata
- Bumped the package line to
0.8.4, including Cargo metadata, native sidecar package manifests, and root optional sidecar pins. - Updated the minimum supported Rust version and Clippy MSRV setting to
1.95. - Hardened npm release publishing so the latest/canary dist-tag mirror can use either
NPM_TOKENorNODE_AUTH_TOKEN.
Breaking Changes
- Minimum supported Rust version raised to 1.95
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Http3
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]