From 8de5f408aea784b51d71fc1f0d79ef0386f283f4 Mon Sep 17 00:00:00 2001 From: zzstoatzz Date: Sun, 3 May 2026 16:01:40 -0500 Subject: [PATCH] release: v0.3.1 --- CHANGELOG.md | 8 ++++++++ build.zig.zon | 2 +- docs/roadmap.md | 11 ++++++----- 3 files changed, 15 insertions(+), 6 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 30c3072..29672c1 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,13 @@ # changelog +## 0.3.1 + +- **feat**: `XrpcClient.queryChecked` and `XrpcClient.procedureChecked` return a checked union of successful `Response` or structured `XrpcError`, preserving AT Protocol `error` / `message` envelopes for non-2xx responses. +- **feat**: `XrpcClient.RetryPolicy` adds status-driven retries for transient transport errors plus HTTP 429/5xx responses, with `retry-after` and rate-limit header support. +- **feat**: `HttpTransport.fetch` captures `ratelimit-limit`, `ratelimit-remaining`, `ratelimit-reset`, and `retry-after` headers on responses. +- **fix**: DID and handle resolution now reject unsafe network targets by default, including private, loopback, link-local, multicast, documentation, and unspecified IP ranges. +- **fix**: identity resolution validates DNS and redirect targets before issuing HTTP requests, reducing SSRF exposure when resolving untrusted AT Protocol identifiers. + ## 0.3.0 - **breaking**: zig 0.16 — all networking APIs take `io: std.Io` as first parameter diff --git a/build.zig.zon b/build.zig.zon index 6ef9829..a057b8f 100644 --- a/build.zig.zon +++ b/build.zig.zon @@ -1,6 +1,6 @@ .{ .name = .zat, - .version = "0.3.0-alpha.24", + .version = "0.3.1", .fingerprint = 0x8da9db57ee82fbe4, .minimum_zig_version = "0.16.0-dev.3070+b22eb176b", .dependencies = .{ diff --git a/docs/roadmap.md b/docs/roadmap.md index 15b4b0e..2112908 100644 --- a/docs/roadmap.md +++ b/docs/roadmap.md @@ -4,11 +4,11 @@ zat started as a small set of string primitives for AT Protocol — the types ev ## current status -**v0.3.0-alpha** — zig 0.16, `std.Io` throughout. +**v0.3.1** — zig 0.16, `std.Io` throughout. the v0.3.0 migration replaced all networking and concurrency primitives with zig 0.16's [`std.Io`](https://ziglang.org/documentation/master/std/#std.Io) interface. the API change is mechanical: every networking type takes `io: std.Io` as its first parameter. streaming clients moved from `connect()` + `next()` loops to `subscribe(handler)` with automatic reconnection, backoff, and host rotation. -the library is stable and tested. the alpha tag reflects that downstream consumers (zlay, labelz, pollz) are still validating in production. +the library is stable and tested. downstream consumers continue to drive hardening work, especially around network safety and XRPC error handling. ## history @@ -24,7 +24,8 @@ the library is stable and tested. the alpha tag reflects that downstream consume - CID hash verification in CAR parser (v0.2.1), size limits (v0.2.2) - OAuth 2.1 DPoP client (v0.2.14) - configurable keep-alive, transport options (v0.2.12–v0.2.18) -- `std.Io` migration, `subscribe(handler)` streaming API (v0.3.0-alpha) +- `std.Io` migration, `subscribe(handler)` streaming API (v0.3.0) +- checked XRPC results, retry policy, and identity network safety (v0.3.1) this pattern — start minimal, expand based on real pain — continues. @@ -33,8 +34,8 @@ this pattern — start minimal, expand based on real pain — continues. the library covers the full AT Protocol verification pipeline: identity resolution, repo parsing, signature verification, and MST validation. benchmarked against Go (indigo) and Rust (rsky) in [atproto-bench](https://tangled.org/zzstoatzz.io/atproto-bench). near-term: -- promote to v0.3.0-beta once production consumers stabilize -- cut v0.3.0 when the API surface is confirmed +- keep validating the v0.3.x surface in production consumers +- promote repeated downstream patterns into the library once they prove stable what's missing will show up when people build things. until then, no speculative features. -- 2.51.2