Skip to content

fix(connect)!: upgrade libp2p to 0.57 and refresh native carriers - #110

Merged
auto-wood merged 4 commits into
mainfrom
fix/connect-libp2p-057
Sep 22, 2026
Merged

auto-wood merged 4 commits into
mainfrom
fix/connect-libp2p-057

Conversation

@auto-wood

@auto-wood auto-wood commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Pin the Rust reference to libp2p 0.57.0 and align the Noise recorder with libp2p-noise 0.47 / snow 0.10.
  • Refresh the committed Swift and C/C++ native carriers from the upgraded dependency graph.
  • Update current engine-version facts while preserving SPOKE wire behavior and Noise golden bytes.

Compatibility and release

Target release: 0.14.0. Public Rust identity and multiaddr types now come from libp2p-identity 0.3 and multiaddr 0.19. Consumers align their direct libp2p dependency with SPOKE. The activated transport graph uses libp2p-yamux 0.48.0 and yamux 0.14.1.

Hickory is reported separately: it is lockfile-only in the exercised SPOKE feature sets. Nexus dependency resolution remains a consumer-side verification step.

Verification

Review state

Independent task reviews, three-seat quality review and mandatory QA acceptance passed with zero open findings. All applicable CI checks passed on 6ae7888, including the final Swift artifact consistency check: https://github.com/42ch-dev/spoke/actions/runs/35712482973. Publication follows the existing signed New release and Trusted Publishing workflows.

…engine

Pin the workspace libp2p to =0.57.0 with the same nine explicit features and
resolve only the 0.57 dependency family. The activated spoke-connect graph
now carries libp2p-yamux 0.48.0 -> yamux 0.14.1; yamux 0.12.1 (and the 0.13
line) are gone from the lockfile, and libp2p-noise 0.47.0 moves the Noise
recorder engine to snow 0.10.0.

- Realign the spoke-connect dev-dependencies to the resolved runtime family
  (libp2p-identity 0.3, x25519-dalek 3, snow 0.10 with ring-resolver) so the
  dev-only Noise recorder does not retain a second, older engine family. All
  three resolve to the very nodes the runtime graph already activates.
- Adapt noise_recorder to the snow 0.10 API: prologue / local_private_key now
  return Result and snow::types::Dh::generate returns Result. No filler
  change; the recorded transcript is byte-identical to the committed golden
  fixture, so the expected Noise bytes are preserved rather than rewritten.
- Update the libp2p pin fact in the crate README and the recorder / TS
  interop provenance strings, plus the two knowledge docs that pinned the old
  engine versions.

Hickory is reported independently: the hickory 0.26.3 trio (hickory-net,
hickory-proto, hickory-resolver) is lockfile-only, pulled by the non-activated
optional libp2p-dns 0.45.0 node; it is not reachable from any workspace member.

BREAKING CHANGE: the public Rust boundary exposes libp2p-identity ^0.3 and
multiaddr ^0.19 types (Keypair, PublicKey, PeerId, Multiaddr), so consumers
must upgrade their direct libp2p dependency together with spoke-connect.
Wire protocol, session authentication, allowlist and correlation behavior are
unchanged; the release is 0.14.0.
@auto-wood
auto-wood marked this pull request as ready for review September 22, 2026 10:08
@auto-wood
auto-wood merged commit 8b4ae13 into main Sep 22, 2026
22 checks passed
@auto-wood
auto-wood deleted the fix/connect-libp2p-057 branch September 22, 2026 10:09
@cursor
cursor Bot requested a review from btspoony September 22, 2026 10:09

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk: high. Not approved — this breaking libp2p 0.57 / Noise / native-carrier upgrade exceeds the medium approval threshold and needs human review. Cursor Bugbot and Cursor Security Agent were not present after the first poll; one reviewer was assigned.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

@greptile-apps

greptile-apps Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 4/5

The PR is not yet safe to merge because the refreshed Windows native carrier claims a header hash that does not match the header shipped in the repository.

Fix All in CursorFindings

  1. P1 Windows header hash mismatch ▶
  2. P2 Maintenance rationale is unfinished ▶
Fix with agent prompt
### Issue 1
crates/spoke-connect/bindings/cpp/native/provenance.json:53
The refreshed Windows provenance records `headerSha256` as `a2cc9025…`, but the committed `include/spoke_connect.h` hashes to `7b4b4472…`. Because the provenance contract uses this hash to verify that the DLL and public header belong together, consumers cannot verify the shipped Windows carrier and may pair the DLL with a different header than the one used to build it.

### Issue 2
.mstar/specs/connect-publish-strategy.md:190
The updated js-libp2p evidence ends with the literal placeholder `**Maintenance:** …`. This leaves the maintained specification visibly incomplete and removes the maintenance rationale readers need to understand the decision. Replace it with the intended evidence or remove the unfinished label.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Summary

This PR upgrades the Rust connect stack to libp2p 0.57, aligns the deterministic Noise recorder with libp2p-noise 0.47 and snow 0.10, refreshes committed native carriers, and updates the corresponding interoperability documentation.

  • Preserves the committed Noise transcript and TypeScript wire assertions.
  • Refreshes C/C++ and Swift native artifacts for the new Rust dependency graph.
  • Contains a blocking Windows header-provenance mismatch.
  • Leaves one specification evidence cell with an unfinished maintenance placeholder.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[libp2p 0.57] --> B[spoke-connect Rust core]
  B --> C[libp2p-noise 0.47 / snow 0.10]
  C --> D[Deterministic Noise recorder]
  D --> E[Golden Noise fixture]
  E --> F[TypeScript interop tests]
  B --> G[C ABI carrier]
  G --> H[macOS dylib]
  G --> I[Windows DLL]
  G --> J[Swift XCFramework archives]
  K[Committed C header] --> L[Native provenance hashes]
  H --> L
  I --> L
Loading

Reviews (1) · Last reviewed commit: "docs(knowledge): normalize list frontmat..."

Comment thread crates/spoke-connect/bindings/cpp/native/provenance.json
Comment thread .mstar/specs/connect-publish-strategy.md
@auto-wood

Copy link
Copy Markdown
Contributor Author

Both findings are addressed in the open follow-up PR #112. The C header is pinned to LF, Windows native provenance was regenerated from a genuine Windows CI artifact, and final Windows/macOS provenance and native smoke checks pass: https://github.com/42ch-dev/spoke/actions/runs/35720241741 . The complete specification evidence cell is restored, with the current eight runtime dependencies documented. The follow-up also migrates C++ DLL/dylib carriers to LFS and requires the complete current PR validation set, including Greptile. PR #112 remains open for confirmation; these fixes have not yet been merged or released.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant