fix(connect)!: upgrade libp2p to 0.57 and refresh native carriers - #110
Conversation
…engine Pin the workspace libp2p to =0.57.0 with the same nine explicit features and resolve only the 0.57 dependency family. The activated spoke-connect graph now carries libp2p-yamux 0.48.0 -> yamux 0.14.1; yamux 0.12.1 (and the 0.13 line) are gone from the lockfile, and libp2p-noise 0.47.0 moves the Noise recorder engine to snow 0.10.0. - Realign the spoke-connect dev-dependencies to the resolved runtime family (libp2p-identity 0.3, x25519-dalek 3, snow 0.10 with ring-resolver) so the dev-only Noise recorder does not retain a second, older engine family. All three resolve to the very nodes the runtime graph already activates. - Adapt noise_recorder to the snow 0.10 API: prologue / local_private_key now return Result and snow::types::Dh::generate returns Result. No filler change; the recorded transcript is byte-identical to the committed golden fixture, so the expected Noise bytes are preserved rather than rewritten. - Update the libp2p pin fact in the crate README and the recorder / TS interop provenance strings, plus the two knowledge docs that pinned the old engine versions. Hickory is reported independently: the hickory 0.26.3 trio (hickory-net, hickory-proto, hickory-resolver) is lockfile-only, pulled by the non-activated optional libp2p-dns 0.45.0 node; it is not reachable from any workspace member. BREAKING CHANGE: the public Rust boundary exposes libp2p-identity ^0.3 and multiaddr ^0.19 types (Keypair, PublicKey, PeerId, Multiaddr), so consumers must upgrade their direct libp2p dependency together with spoke-connect. Wire protocol, session authentication, allowlist and correlation behavior are unchanged; the release is 0.14.0.
There was a problem hiding this comment.
Risk: high. Not approved — this breaking libp2p 0.57 / Noise / native-carrier upgrade exceeds the medium approval threshold and needs human review. Cursor Bugbot and Cursor Security Agent were not present after the first poll; one reviewer was assigned.
Sent by Cursor Approval Agent: Pull Request Router and Approver
|
|
Both findings are addressed in the open follow-up PR #112. The C header is pinned to LF, Windows native provenance was regenerated from a genuine Windows CI artifact, and final Windows/macOS provenance and native smoke checks pass: https://github.com/42ch-dev/spoke/actions/runs/35720241741 . The complete specification evidence cell is restored, with the current eight runtime dependencies documented. The follow-up also migrates C++ DLL/dylib carriers to LFS and requires the complete current PR validation set, including Greptile. PR #112 remains open for confirmation; these fixes have not yet been merged or released. |


Summary
Compatibility and release
Target release: 0.14.0. Public Rust identity and multiaddr types now come from libp2p-identity 0.3 and multiaddr 0.19. Consumers align their direct libp2p dependency with SPOKE. The activated transport graph uses libp2p-yamux 0.48.0 and yamux 0.14.1.
Hickory is reported separately: it is lockfile-only in the exercised SPOKE feature sets. Nexus dependency resolution remains a consumer-side verification step.
Verification
Review state
Independent task reviews, three-seat quality review and mandatory QA acceptance passed with zero open findings. All applicable CI checks passed on 6ae7888, including the final Swift artifact consistency check: https://github.com/42ch-dev/spoke/actions/runs/35712482973. Publication follows the existing signed New release and Trusted Publishing workflows.