diff --git a/TODO.md b/TODO.md index ff41c96..7cb441b 100644 --- a/TODO.md +++ b/TODO.md @@ -2421,17 +2421,56 @@ and borrows `pr`'s conventions rather than inventing new ones beside them. a semver-incompatible bump `cargo update` cannot make. `rsa 0.9.10` (RUSTSEC-2023-0071, Marvin timing sidechannel) has no fixed version at all; it arrives through jose-jwk, for a key type atgc's ES256 DPoP keys - never exercise. Recheck both when jacquard next bumps: `cargo audit`. - Both still stood on 2026-08-15, confirmed independently by `cargo audit` - and cargo-deny 0.20.2 against the same lockfile, and both are now in - deny.toml's `advisories.ignore` with the condition for removing each — - visible rather than silenced, and cargo-deny reports - `advisory-not-detected` once an ignored id stops matching, so neither - can outlive its advisory unnoticed. `cargo audit` adds a third that - cargo-deny does not: `atomic-polyfill 1.0.3` (RUSTSEC-2023-0089, + never exercise. Both still stood on 2026-08-15, confirmed independently + by `cargo audit` and cargo-deny 0.20.2 against the same lockfile, and + both are now in deny.toml's `advisories.ignore` with the removal + condition for each — visible rather than silenced, and cargo-deny + reports `advisory-not-detected` once an ignored id stops matching, so + neither can outlive its advisory unnoticed. `cargo audit` adds a third + that cargo-deny does not: `atomic-polyfill 1.0.3` (RUSTSEC-2023-0089, unmaintained), four levels down through heapless <- postcard <- jacquard-common. That difference is deny.toml's `unmaintained = "workspace"` working as intended, not a disagreement about facts +- [ ] RUSTSEC-2026-0119 rechecked on 2026-08-17, and the answer is still no. + The blocker is one line upstream: jacquard-identity 0.12.1 declares + `hickory-resolver = "^0.24"`, and 0.12.1 is the newest release of every + jacquard crate — the crates.io index lists nothing above it for + jacquard, -identity, -oauth or -common, and the repo's last commits are + a month old and unrelated to DNS. 0.24.4 is the end of the 0.24 line, + there is no backport, and the advisory's `patched` list is exactly + `>= 0.26.1`. So `cargo update -p hickory-proto` locks 0 packages, and + `--precise 0.26.1` (or 0.25.2, on either hickory crate) fails outright + quoting the `^0.24` requirement. The part worth writing down is that + `[patch.crates-io]` aimed at hickory-resolver 0.26.1 is not an error + but a *silent no-op*: cargo printed no warning at all and + `cargo tree -i hickory-proto` still showed 0.24.4. Anyone who tries + that and does not re-run `cargo audit` will believe they fixed it. + Fixable when jacquard-identity requires hickory-resolver >= 0.26.1 and + jacquard depends on that release. No upstream issue tracks it — ten are + open and none mention hickory, DNS or RustSec — so the only thing to + watch is the version, and filing one upstream would be worth more than + another recheck here +- [ ] Two real routes to RUSTSEC-2026-0119, both rejected on 2026-08-17 and + recorded so they are not rediscovered as bright ideas. Vendoring a + forked hickory-proto still numbered 0.24.4 would satisfy cargo, and the + upstream fix is genuinely small — `COMPRESSION_CANDIDATE_LIMIT = 64` in + `serialize/binary/encoder.rs`, `COMPRESSED_NAME_LIMIT = 120` in + `rr/domain/name.rs` — but it lands in an API rewritten between 0.24 and + 0.26 (no_std `alloc`, `ProtoErrorKind` -> `ProtoError`, `EncodeMode` -> + `NameEncoding`), so it means hand-porting into a 46k-line DNS + wire-format crate this repo would then own, and a path-sourced fork is + invisible to `cargo audit` — silencing the tool rather than fixing the + code. The other route is dropping jacquard's `dns` feature, which drops + hickory outright; jacquard-identity then resolves `_atproto.` + TXT over DNS-over-HTTPS against a hardcoded `cloudflare-dns.com`. That + trades a DoS advisory for sending every handle lookup to one third + party and ignoring the system resolver, which is the wrong trade for an + ATProto CLI. Weighing against both: hickory-resolver 0.24.4 has no + non-test site that re-encodes a received message — `DnsResponse` keeps + the wire buffer it was handed — so the only `BinEncoder` run on atgc's + path is the single-question query it builds itself, which is not the + many-records encode the advisory needs. That lowers the practical + exposure; it does not clear the advisory, so the ignore stays - [x] `cargo deny check` runs, and passes. cargo-deny 0.20.2 (prebuilt Linux binary in ~/.local/bin, not a source build) parsed deny.toml on 2026-08-15 without complaint, so the version guesses in its header held. diff --git a/deny.toml b/deny.toml index 0d2f5ce..f3ae370 100644 --- a/deny.toml +++ b/deny.toml @@ -48,7 +48,12 @@ unsound = "workspace" ignore = [ # hickory-proto 0.24.4, under jacquard-identity. Fixed in 0.26.1, which # needs jacquard-identity off hickory-resolver 0.24 — a semver-major bump - # `cargo update` cannot make. Remove when jacquard makes it. + # `cargo update` cannot make. Rechecked 2026-08-17 and still true: every + # jacquard crate is still 0.12.1, and jacquard-identity 0.12.1 still + # declares `hickory-resolver = "^0.24"`. Remove when jacquard-identity + # requires hickory-resolver >= 0.26.1 and jacquard depends on that + # release — not before, since a `[patch.crates-io]` across that boundary + # is silently ignored rather than rejected. TODO.md has the evidence. { id = "RUSTSEC-2026-0119", reason = "hickory-proto 0.24.4 under jacquard-identity; no fix below a semver-major resolver bump" }, # rsa 0.9.10, under jose-jwk. No fixed version exists at all, and the key # type is one atgc's ES256 DPoP keys never exercise. Remove when rsa ships