diff --git a/CHANGELOG.md b/CHANGELOG.md index caa07b2..b050e94 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,9 @@ # changelog +## 0.3.12 + +- **fix**: CBOR decode accepts RFC 8949 bytewise map key order alongside RFC 7049 length-first. The production firehose (indigo/cbor-gen) emits length-first, but current DAG-CBOR spec encoders (e.g. bluesky's jetstream simulator) emit bytewise; decode now accepts either while still rejecting duplicates and orders satisfying neither. Canonical-form enforcement is unchanged on the encode/verify side. + ## 0.3.11 - **refactor**: remove `verifyRepo` and `VerifyResult` from the public API. Nothing called it — no downstream consumer, and even atproto-bench assembles the resolve/fetch/verify pipeline from the primitives. Real consumers verify with `verifyCommitCar` (zds `importRepo`) and `verifyCommitDiff` (firehose diffs), which are unchanged. The `fetchRepo` helper and the verifyRepo-only `VerifyError` members (`InvalidIdentifier`, `SigningKeyNotFound`, `PdsEndpointNotFound`, `FetchFailed`) go with it. diff --git a/build.zig.zon b/build.zig.zon index 7d72fbb..64c94aa 100644 --- a/build.zig.zon +++ b/build.zig.zon @@ -1,6 +1,6 @@ .{ .name = .zat, - .version = "0.3.11", + .version = "0.3.12", .fingerprint = 0x8da9db57ee82fbe4, .minimum_zig_version = "0.16.0-dev.3070+b22eb176b", .dependencies = .{ diff --git a/src/internal/repo/cbor.zig b/src/internal/repo/cbor.zig index 6cf88cb..8301c8f 100644 --- a/src/internal/repo/cbor.zig +++ b/src/internal/repo/cbor.zig @@ -1494,15 +1494,23 @@ test "decode still rejects duplicate and unsorted map keys" { // but {"b":1, "a":1} satisfies neither ordering. const unsorted = [_]u8{ 0xa2, - 0x61, 'b', 0x01, - 0x61, 'a', 0x01, + 0x61, + 'b', + 0x01, + 0x61, + 'a', + 0x01, }; try std.testing.expectError(error.UnsortedMapKeys, decode(arena.allocator(), &unsorted)); const duplicate = [_]u8{ 0xa2, - 0x61, 'a', 0x01, - 0x61, 'a', 0x02, + 0x61, + 'a', + 0x01, + 0x61, + 'a', + 0x02, }; try std.testing.expectError(error.DuplicateMapKey, decode(arena.allocator(), &duplicate)); }