Repository navigation
release: netcode.rs 1.1.2 - #28
Merged
Merged
Conversation
Bump the crate version for the connect-token reuse fix (#27, fixes #24). The crate numbers itself independently of the C reference, so this is 1.1.2 and not 1.4.8. Cargo.toml is the only version site: Cargo.lock is gitignored here on purpose, and VERSION_INFO ("NETCODE 1.02") is the wire protocol version, not a release number, so it does not move. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
Author
Merge on the record: macOS legs substituted by local macOS runsAt this head every hosted check passes except the macOS leg(s), queued at zero seconds on GitHub's macOS runner pool. Glenn, live at 00:03Z: "Same for the other five, local runs on the record." Substitute, run on the Studio (macOS) at this exact head by the cold readers: cargo fmt --check, clippy -D warnings, cargo test 56+10+1 passed, cargo doc -D warnings, MSRV 1.85 check, C interop 2/2 against C v1.4.8 (the release-prep builder at 7a4d7a0). Reads: Rowan's own read of the one-line diff (Cargo.toml 1.1.1 to 1.1.2); the code it releases was read by Fable, Opus and Alex at 2404f58. An exception named per Glenn's flexibility rule, not the path; the hosted macOS legs run on main after the merge and are read back there. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Release preparation for netcode.rs 1.1.2, the connect-token reuse fix from #27 (fixes #24). No code change beyond the version bump. Do not merge until the notes below are edited to Glenn's satisfaction; tagging, the GitHub release and the crates.io publish are all separate and deliberate steps after this.
Version chosen: 1.1.2
The crate numbers itself; it does not track the C reference's release number. The deciding sentence is in CLAUDE.md's PUBLISHING block:
At that date the C reference was already on 1.4.x, so the crate's own line (1.0.0 published, 1.1.0 in tree) is independent of it. The HOT block's first sentence ("from-scratch Rust port of netcode 1.02") names the wire protocol version, not a release number, and the C reference this now matches is 1.4.8. The predecessor releases are v1.1.1 (2026-08-08) and v1.1.0, so the next patch is 1.1.2. netcode.go did the same for the same fix: it tagged v1.1.4, not v1.4.8.
Version sites
Cargo.tomlversionThat is the only one. Three candidate sites were checked and deliberately left alone:
Cargo.lock— not bumped, and must not be added. CLAUDE.md has a block headed "CARGO.LOCK IS GITIGNORED HERE ON PURPOSE":.gitignorelists it by decision, this is a library crate, and "Do not 'fix' the inconsistency by adding a lock here". There is no lock in the tree to update.src/lib.rsVERSION_INFO— not touched.pub(crate) const VERSION_INFO: [u8; 13] = *b"NETCODE 1.02\0"is the wire protocol version written into every unencrypted packet header and mixed into the AEAD associated data. It is asserted byte-for-byte bywire_compat.rs::version_info_matches_cand by the golden vectors, and C 1.4.8 still sendsNETCODE 1.02. Moving it to "1.4.8" would break every other netcode implementation. netcode.go draws the same line explicitly: itsversionInfo"never changes", while its separateVersionFullconstant carries the C release number.VersionFull/VersionMajor/VersionMinor/VersionPatchreporting 1.4.8; grep oversrc/,tests/,examples/,README.mdandCargo.tomlfinds no equivalent here, so there is nothing to set to 1.4.8. Adding one would be a new public API in a patch release and is out of scope for this PR — worth a follow-up issue if we want the ports to match.README.mdcarries no version string.Gates
Run locally on this branch at 7a4d7a0, as
.github/workflows/ci.ymlruns them:The 2 ignored tests in the
cargo testrun are the interop pair, which is exactly the trap CLAUDE.md names; they are run separately above. The C client and server were built with CMake frommas-bandwidth/netcodeat tip47a156b, which is tagged v1.4.8 — so the live interop leg is against the same C release whose connect-token lifecycle #27 ported.Not run locally:
cargo denyand the fuzz smoke leg. CI covers both.Release notes (draft, Rowan edits)
One thing to check before this goes out, Glenn: the notes say the C fix landed in 1.4.5, not 1.4.8. That is what issue #24 and the GHSA say (
C netcode 1.4.5 … spends a connect token when the client is installed), and the C v1.4.8 release notes are about libsodium nonnull attributes, not tokens. 1.4.8 is the C release this port is now tested and aligned against, which is how netcode.go's notes use it too. If you would rather the notes name only 1.4.8, say so and I will reword.🤖 Generated with Claude Code