Skip to content

chore(deps): bump the cargo group across 1 directory with 4 updates - #400

Merged
kixelated merged 2 commits into
mainfrom
dependabot/cargo/cargo-37d6f2831a
Sep 27, 2026
Merged

kixelated merged 2 commits into
mainfrom
dependabot/cargo/cargo-37d6f2831a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 26, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on tokio-tungstenite, uniffi, boring and tokio-quiche to permit the latest version.
Updates tokio-tungstenite to 0.30.0

Changelog

Sourced from tokio-tungstenite's changelog.

0.30.0

0.29.0

0.28.0

0.27.0

0.26.2

0.26.1

  • Update tungstenite to address an issue that might cause UB in certain cases.

0.26.0

0.25.0

0.24.0

  • Update dependencies (TLS, tungstenite).
  • Return a runtime error when WSS URLs are used without a proper TLS feature enabled.

0.23.1

  • Introduce a url feature (proxies to tungstenite/url).

0.23.0

  • Update tungstenite to 0.23.0.
  • Disable default features on TLS crates.

0.22.0

  • Update TLS dependencies.
  • Update tungstenite to match 0.22.0.

... (truncated)

Commits

Updates uniffi to 0.32.1

Changelog

Sourced from uniffi's changelog.

v0.32.1 (backend crates: v0.32.1) - (2026-09-08)

What's Fixed

  • Kotlin: Fixed checksum failure on aarch64 (#2935)

All changes in v0.32.1.

v0.32.0 (backend crates: v0.32.0) - (2026-06-30)

⚠️ Breaking Changes ⚠️

  • Kotlin and Python now fail to generate bindings when there are async primary constructors. Previously these languages skipped the constructor in this case or generated a constructor that always threw. You can get similar behavior by adding the primary constructor to the uniffi.toml excludes list in uniffi.toml (e.g. `excludes = ["MyObject.new"])
  • Ruby: Force named parameters for enum constructors (#2880)
  • The --config flag now expects a global config file rather than a flat uniffi.toml-style override. Old-style files will produce a warning and be ignored. See #2866
  • [ByRef] bytes UDL arguments now map to &[u8] on the Rust side instead of &Vec<u8>. UDL-defined functions whose Rust implementations take &Vec<u8> must change to &[u8]. Proc-macro signatures (fn foo(x: &[u8])) are unchanged. On the Kotlin side, call sites must now pass a direct java.nio.ByteBuffer rather than ByteArray; migrate with ByteBuffer.allocateDirect(arr.size).put(arr).flip(). Swift (Data) and Python (bytes) call sites are unchanged. (#2878)
  • Reworked the experimental pipeline bindgen code. Any external binding generators using this will need to be reworked as well. See #2787 for examples of how this can be done.

⚠️ Breaking Changes for external bindings authors ⚠️

  • The signature for CrateConfigSupplier::from_cargo_metadata_command has changed. It now inputs a MetadataCommand instance and a CargoMetadataOptions rather than just a no_deps flag.

What's Fixed

  • Fixed bug that sometimes prevented renaming items inside a submodule #2792
  • Exempted UniFfiTag from clippy::exhaustive_structs since downstream projects may depend on it #2809
  • Fixed compile errors when exporting ambiguous method names #2937
  • Ruby: Code for all kinds of enums and custom types is now correctly generated #2880 and #2891

⚠️ Breaking Changes for external bindings authors ⚠️

  • There's a new GlobalConfig struct for managing config. It replaces BindgenPathsLayer::get_config() method which has been removed. See #2866.
  • [ByRef] bytes arguments now travel across the FFI as a ForeignBytes (pointer + length) value rather than a RustBuffer. External bindings need to accept the foreign-language byte buffer at the call site and lower it to ForeignBytes for the duration of the call (no copy). (#2878)

What's New?

  • Global config file support via --config. See the docs.

  • Traits can now be exported with #[uniffi::export(foreign)] for foreign-only implementations, or #[uniffi::export(rust, foreign)] for both Rust and foreign implementations. The with_foreign flag is deprecated in favor of rust, foreign.

  • Recursive enums are now supported. UniFFI automatically detects when enum and record types participate in cycles — self-referential, mutually recursive, or cycling through a record — and generates appropriate bindings: indirect in Swift, forward references in Python (#2834).

  • Box<T> now automatically implements FFI traits when T implements them, allowing direct use in enum variants and function parameters without NewType wrappers (#2808)

  • Record fields can now be renamed with the proc-macro name = "new_field_name" attribute (#2794)

  • Items can be excluded from the generated bindings using uniffi.toml.

  • Added mutable_records configuration option to allow specific records to remain mutable even when generate_immutable_records is enabled (Kotlin and Swift).

  • Kotlin objects now have an uniffiIsDestroyed property that returns true if the Rust reference no longer exists (#2825)

  • Updated askama version to 0.15.6

... (truncated)

Commits

Updates boring to 4.22.0

Changelog

Sourced from boring's changelog.

5.2.0

  • 2026-05-21 Export DEP_BORINGSSL_VERSION_MAJOR var
  • 2026-04-27 Expose DTLS version constants in SslVersion

5.1.0

  • 2026-04-13 Add EVP_AEAD-based detached AEAD module
  • 2026-04-13 Add generic PKey private key generation API
  • 2026-04-13 Add TLS 1.2 PRF module and bindings
  • 2026-03-25 Add used_hello_retry_request
  • 2026-03-28 Prebuilt lib export option
  • 2026-03-27 Display sys crate errors using cargo::error

5.0.2

  • 2026-02-13 Re-add fips-precompiled for v4 compat
  • 2026-02-12 Don't add build/ to non-FIPS pre-built path
  • 2026-02-13 Expose load_verify_locations like rust-openssl
  • 2026-02-12 Support static MSVC runtime

5.0.1

  • 2026-02-03 Make SslCredential optional
  • 2026-02-10 Make ML-KEM optional
  • 2026-02-10 Don't always require all headers from all versions of BoringSSL
  • 2026-02-10 Ensure we don't leave unit memory if generate_key fails

5.0.0

  • 2025-12-19 Update vendored boring to a newer version (2023.11 to 2025.11)
  • 2025-12-20 Rework RPK/SslMethod (c2f063cf4711f15b8b417b6926496fbf1c2a03ac)
  • 2025-09-29 Remove SslCurve API
  • 2025-09-30 Remove the "kx-*" features
  • 2025-09-25 Remove legacy FIPS options (they're controlled via BORING_BSSL_ env vars instead)
  • 2026-01-05 Remove deprecated X509CheckFlags flag
  • 2025-09-30 Remove "pq-experimental" Cargo feature, apply PQ patch by default + P256Kyber768Draft00
  • 2026-01-05 Safe clone for X509Store
  • 2025-03-08 Add set_ticket_key_callback (SSL_CTX_set_tlsext_ticket_key_cb)
  • 2025-09-30 Add SslRef::curve_name()
  • 2025-09-30 Expose a safe Rust interface for the session resumption callback
  • 2026-01-05 Fix leaky set_ex_data() API
  • 2025-12-12 Add boring specific api set_strict_cipher_list to SslContextBuilder
  • 2025-11-20 Introduce SslCipherRef::protocol_id
  • 2023-05-11 fix: BIO_set_retry_write when BIO_CTRL_FLUSH to allow writer returns WouldBlock on flush
  • 2025-11-14 Remove blanket Eq from FFI types
  • 2025-12-20 Never use the debug CRT on Windows
  • 2025-02-19 X509Builder::append_extension2 -> X509Builder::append_extension
  • 2025-02-19 Ssl::new_from_ref -> Ssl::new()
  • 2025-02-19 Align SslStream APIs with upstream
  • 2025-09-26 Remove support for Hyper v0

4.21.0

  • 2026-01-05 Warn about set_curves() removal
  • 2026-01-05 Deprecate set_ex_data()

... (truncated)

Commits

Updates tokio-quiche to 0.20.0

Release notes

Sourced from tokio-quiche's releases.

🔐 0.20.0

⚠️ Security:

  • Added a limit to how many PATH_CHALLENGE frames are queued. Without the limit an attacker could cause a server to queue an unbounded number of frames, leading to a slow but steady increase in memory usage (CVE-2023-6193).

Breaking Changes:

Highlights:

  • Many new methods are now exposed via the FFI API that can be used by non-Rust code.
  • Many more bug fixes and performance improvements.

Full changelog at cloudflare/quiche@0.19.0...0.20.0

Commits
  • 540d33a tokio-quiche: release 0.20.0
  • be47c50 quiche: release 0.30.0
  • b6281fb recovery: emit app-limited state in qlog
  • ad2fabd tokio-quiche: make Http3Settings non-exhaustive
  • a64d972 fix connection flow-control double-counting from zero-length STREAM frames
  • 5aff70b build(deps): update intrusive-collections to 0.10.3
  • 8b9a03c build(deps): update table_to_html requirement from 0.9.0 to 0.11.0
  • d7c7f26 build(deps): update wasm-streams requirement from 0.4 to 0.6
  • 89d01d2 build(deps): update getrandom requirement from 0.3 to 0.4
  • bb92c42 build(deps): update nix requirement from 0.30.1 to 0.31.3
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 26, 2026
@kixelated
kixelated force-pushed the dependabot/cargo/cargo-37d6f2831a branch from 4259966 to f0f7e72 Compare September 27, 2026 01:34
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T02:08:57.228516Z c2e4013 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

dependabot Bot and others added 2 commits September 26, 2026 19:04
Updates the requirements on [tokio-tungstenite](https://github.com/snapview/tokio-tungstenite), [uniffi](https://github.com/mozilla/uniffi-rs), [boring](https://github.com/cloudflare/boring) and [tokio-quiche](https://github.com/cloudflare/quiche) to permit the latest version.

Updates `tokio-tungstenite` to 0.30.0
- [Changelog](https://github.com/snapview/tokio-tungstenite/blob/master/CHANGELOG.md)
- [Commits](snapview/tokio-tungstenite@v0.29.0...v0.30.0)

Updates `uniffi` to 0.32.1
- [Changelog](https://github.com/mozilla/uniffi-rs/blob/main/CHANGELOG.md)
- [Commits](mozilla/uniffi-rs@v0.31.0...v0.32.1)

Updates `boring` to 4.22.0
- [Release notes](https://github.com/cloudflare/boring/releases)
- [Changelog](https://github.com/cloudflare/boring/blob/master/RELEASE_NOTES)
- [Commits](cloudflare/boring@v4.0.0...v4.22.0)

Updates `tokio-quiche` to 0.20.0
- [Release notes](https://github.com/cloudflare/quiche/releases)
- [Commits](cloudflare/quiche@tokio-quiche-0.19.0...tokio-quiche-0.20.0)

---
updated-dependencies:
- dependency-name: tokio-tungstenite
  dependency-version: 0.30.0
  dependency-type: direct:production
  dependency-group: cargo
- dependency-name: uniffi
  dependency-version: 0.32.1
  dependency-type: direct:production
  dependency-group: cargo
- dependency-name: boring
  dependency-version: 4.22.0
  dependency-type: direct:production
  dependency-group: cargo
- dependency-name: tokio-quiche
  dependency-version: 0.20.0
  dependency-type: direct:production
  dependency-group: cargo
...

Signed-off-by: dependabot[bot] <support@github.com>
tokio-quiche 0.20 removed ApplicationOverQuic::buffer; the IO worker now
owns its 64 KiB egress buffer (pooled per runtime thread), so the send path
keeps the same packet buffer size without the driver supplying one.

The driver's buffer was otherwise only scratch space for dgram_recv. Take
the owned datagram via dgram_recv_buf instead and hand it to Bytes without
copying, dropping the per-connection 64 KiB allocation.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kixelated
kixelated force-pushed the dependabot/cargo/cargo-37d6f2831a branch from f0f7e72 to c2e4013 Compare September 27, 2026 02:05
@kixelated

Copy link
Copy Markdown
Collaborator

Pushed a fix on top of the dependabot bump and rebased onto main.

tokio-quiche 0.20 removed ApplicationOverQuic::buffer. The IO worker now owns its 64 KiB egress buffer, pooled per runtime thread (QuicSettings::pool_send_buffer, on by default). It is the same size as the buffer the driver used to lend it, so outbound packet sizing is unchanged. The driver's buf was otherwise only scratch space for dgram_recv. Inbound datagrams now come from dgram_recv_buf(), and the owned DgramBuffer goes straight into Bytes with no copy. That removes a 64 KiB allocation per connection.

boring 5: web-transport-quiche compiles unchanged, and one boring 5.2 is shared with quiche 0.30 and tokio-quiche 0.20.

uniffi 0.32: none of its breaking changes apply here. There are no async constructors, and no &[u8] or [ByRef] bytes parameters are exported. We also don't use --config or UDL. Checked locally:

  • Python: maturin develop + pytest, 174 passed. tests/browser_interop was skipped because of a local libstdc++ issue in the playwright/greenlet environment.
  • Kotlin: kt/scripts/check.sh regenerates the bindings and jvmTest compiles against them. There are no JVM tests to run.
  • Swift: covered by CI's Generate bindings, XCFramework build and Package jobs, which pass.

just check and just test pass locally.

Unrelated to this PR: web-transport-quiche tests/priority.rs (higher_priority_finishes_first) sometimes stalls until its 30s timeout when the machine is under load. On main it failed 8 of 128 runs with 16 running in parallel, so it predates these bumps.

(Written by Opus 5.5)

@kixelated
kixelated merged commit 2d41255 into main Sep 27, 2026
28 checks passed
@kixelated
kixelated deleted the dependabot/cargo/cargo-37d6f2831a branch September 27, 2026 04:19
This was referenced Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant