Skip to content

chore(deps): consolidate dependency updates and fix nightly fuzzing - #14

Merged
doublegate merged 5 commits into
mainfrom
chore/consolidate-dependency-updates
Sep 25, 2026
Merged

doublegate merged 5 commits into
mainfrom
chore/consolidate-dependency-updates

Conversation

@doublegate

@doublegate doublegate commented Sep 25, 2026 •

Copy link
Copy Markdown
Owner

Motivation

Consolidates every open dependency PR into one reviewed change, takes the remaining updates Dependabot had not proposed, and fixes the nightly fuzz workflow, which has failed every night since at least 2026-09-21.

Supersedes #9, #12, #13.

Nightly fuzzing fix

Every Fuzz Testing matrix job died about 20 s in at cargo install cargo-fuzz --version 0.13.1. Without --locked that resolves a fresh dependency graph on each run and compiles it with the nightly toolchain the job selects; from September it picked up a rustix whose nightly-only build path uses rustc_* attributes current nightly rejects (attributes starting with rustc are reserved, rustc_layout_scalar_valid_range_start not found).

Reproduced locally on nightly 2026-09-23: 0.13.1 unlocked fails with exactly that error; 0.13.2 --locked builds. CI now installs the prebuilt cargo-fuzz 0.13.2 release binary via taiki-e/install-action@v2, so no nightly compiler change can break the install. The duration dispatch input now reaches the script through env: (it was template-expanded into the script text) and is validated as an integer in a step that is not continue-on-error.

Two more defects appeared once the install worked, both fixed here: the prebuilt binary is a static musl build and cargo-fuzz defaults --target to its own triple, where ASan cannot link, so the workflow now names x86_64-unknown-linux-gnu; and the fuzzers had never actually run -- libFuzzer exits at startup when -artifact_prefix names a missing directory, and the job hid it (exit code read after | tee without pipefail, step continue-on-error, gate only looked for crash files). The directory is created now, and a new step fails any target that neither completed cleanly nor recorded a crash. Dispatch run on this branch: https://github.com/doublegate/ProRT-IP/actions/runs/36095088608 -- all five targets green with 6.8M-15.9M executions each in 60 s.

Verified: cargo +nightly fuzz build <target> succeeds locally for all five targets (fuzz_ipv6_parser, fuzz_icmpv6_parser, fuzz_udp_parser, fuzz_tcp_parser, fuzz_tls_parser) with the bumped fuzz dependencies. A dispatch run on this branch is linked in the comments.

Bumps

Package Old New Notes
rand 0.9 0.10 random/random_range moved from Rng to RngExt; 11 imports changed, no call sites
criterion (dev) 0.5 0.8 criterion::black_box deprecated -> std::hint::black_box in 5 bench files
dirs 6.0 7.0 drop-in
x509-parser (fuzz) 0.16 0.18 matches the workspace; drops the duplicate asn1-rs/der-parser/x509-parser stack from the fuzz build
rustls (lock) 0.23.43 0.23.45 fixes RUSTSEC-2026-0285, which fails cargo deny and the fuzz cargo audit on main today
Cargo.lock 68 packages to latest semver-compatible
fuzz/Cargo.lock 52 packages to latest semver-compatible
Docker builder rust:1.88-bookworm rust:1.88-trixie
Docker runtime debian:bookworm-slim debian:trixie-slim runtime package renamed libpcap0.8 -> libpcap0.8t64 (checked with apt-cache policy in debian:trixie-slim)
actions-rust-lang/setup-rust-toolchain v1 v2 benchmarks.yml; v2 drops the default RUSTFLAGS=-D warnings for CARGO_BUILD_WARNINGS
github/codeql-action v3 v4
taiki-e/install-action - v2 new, fuzz.yml

Every other uses: was already on its latest major. The SHA pins in the Gemini workflows were already the latest releases, but their ratchet: comments said checkout@v5, create-github-app-token@v2, github-script@v7; the comments now name the versions the SHAs actually resolve to (checkout v7.0.1, create-github-app-token v3.2.0, github-script v9.0.0). alpine:3.24 is the newest Alpine.

Held back

Package Current Latest Why
sysinfo 0.38 0.39 requires Rust 1.95; workspace MSRV is 1.88 (already documented in Cargo.toml)
sqlx 0.8 0.9 requires Rust 1.94; it is a normal dependency of prtip-scanner, so it would break the MSRV build. #12 proposed it; it moves with the MSRV

Checked by metadata, not only by building: 0 of 502 resolved workspace packages and 0 of 362 fuzz packages declare a rust-version above 1.88.

Not bumped: docker/test-environment/docker-compose.yml deliberately runs old/vulnerable services (Metasploitable2, mysql 8.0, postgres 15) as scan targets. rusqlite, tera, printpdf, pcap, rayon, csv (as a workspace entry) and tokio-util are declared in [workspace.dependencies] but consumed by no crate, so they never resolve into the lockfile; bumping them would be unverifiable. Removing them is left to the owner.

Local gate (same commands as CI)

Check main baseline this branch
cargo fmt --all -- --check pass pass
cargo clippy --workspace --all-targets --locked -- -D warnings pass pass
cargo test --workspace --locked --lib --bins --tests 2349 passed, 0 failed, 100 ignored 2349 passed, 0 failed, 100 ignored
cargo +1.88 build --workspace --locked (MSRV) pass pass
cargo deny --all-features check fail (RUSTSEC-2026-0285) pass
cargo audit in fuzz/ fail (RUSTSEC-2026-0285) pass
generated-data --check (both generators) pass pass
cargo +nightly fuzz build x5 targets pass pass

review / review (Gemini) fails with "Please set an Auth method ... GEMINI_API_KEY": the repository has no Gemini credentials configured. Pre-existing -- it failed identically on #7 -- and not a required check.

Workflows this PR does not exercise: fuzz.yml (schedule/dispatch; dispatched on this branch), benchmarks.yml (schedule/dispatch), release.yml/packages.yml (tag/release), mdbook.yml, coverage.yml (push to main). The Docker image build itself runs in the CI Docker Images job on this PR.

🤖 Generated with Claude Code

doublegate and others added 2 commits September 25, 2026 00:26
The scheduled fuzz workflow had failed every night since at least
2026-09-21 at `cargo install cargo-fuzz --version 0.13.1`. Without
--locked it resolved a fresh graph on each run and compiled it with the
job's nightly toolchain, which now rejects the rustc_* attributes used by
the rustix version it picked. Install the pinned 0.13.2 release binary via
taiki-e/install-action instead, and pass the duration dispatch input
through the environment with validation rather than template expansion.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Supersedes Dependabot #9, #12 and #13.

- rand 0.9 -> 0.10 (Rng convenience methods moved to RngExt)
- criterion 0.5 -> 0.8 (benches use std::hint::black_box)
- dirs 6 -> 7; fuzz x509-parser 0.16 -> 0.18
- refresh Cargo.lock and fuzz/Cargo.lock; rustls 0.23.45 fixes
  RUSTSEC-2026-0285, which was failing cargo-deny and cargo-audit on main
- hold sysinfo 0.39 (Rust 1.95) and sqlx 0.9 (Rust 1.94) at the 1.88 MSRV
- Docker images move from bookworm to trixie (libpcap0.8t64)
- setup-rust-toolchain v2, codeql-action v4; correct stale ratchet
  comments on the SHA-pinned Gemini workflow actions

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 25, 2026 04:27
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 29ab8ae8-92fb-4d6b-a224-8299f9497043

📥 Commits

Reviewing files that changed from the base of the PR and between 3e0d196 and 0b25f58.

⛔ Files ignored due to path filters (2)
  • Cargo.lock is excluded by !**/*.lock
  • fuzz/Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (41)
  • .claude/commands/fuzz-check.md
  • .github/workflows/benchmarks.yml
  • .github/workflows/codeql.yml
  • .github/workflows/fuzz.yml
  • .github/workflows/gemini-dispatch.yml
  • .github/workflows/gemini-invoke.yml
  • .github/workflows/gemini-review.yml
  • .github/workflows/gemini-scheduled-triage.yml
  • .github/workflows/gemini-triage.yml
  • CHANGELOG.md
  • CLAUDE.md
  • Cargo.toml
  • crates/prtip-cli/Cargo.toml
  • crates/prtip-core/Cargo.toml
  • crates/prtip-core/benches/event_system.rs
  • crates/prtip-core/src/retry.rs
  • crates/prtip-network/Cargo.toml
  • crates/prtip-network/benches/batch_io.rs
  • crates/prtip-network/benches/packet_crafting.rs
  • crates/prtip-network/src/fragmentation.rs
  • crates/prtip-network/src/ipv6_packet.rs
  • crates/prtip-network/src/packet_builder.rs
  • crates/prtip-scanner/Cargo.toml
  • crates/prtip-scanner/benches/tls_performance.rs
  • crates/prtip-scanner/src/decoy_scanner.rs
  • crates/prtip-scanner/src/idle/idle_scanner.rs
  • crates/prtip-scanner/src/stealth_scanner.rs
  • crates/prtip-scanner/src/syn_scanner.rs
  • crates/prtip-scanner/src/timing.rs
  • crates/prtip-scanner/src/udp_scanner.rs
  • crates/prtip-scanner/tests/common/error_injection.rs
  • docker/Dockerfile
  • docs/06-TESTING.md
  • docs/29-FUZZING-GUIDE.md
  • docs/32-USER-GUIDE.md
  • docs/DEVELOPER-GUIDE.md
  • docs/src/advanced/security-best-practices.md
  • docs/src/development/fuzzing.md
  • docs/src/development/testing.md
  • fuzz/Cargo.toml
  • tests/performance/benchmarks.rs
Files not reviewed due to moderation or processing errors (1)
  • .github/workflows/fuzz.yml

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Summary

Summary by CodeRabbit

  • Bug Fixes
    • Improved fuzz-test runs so invalid durations are rejected and unsuccessful or incomplete runs are reported as failures.
  • Updates
    • Updated the container base image and packet-capture runtime package.
    • Refreshed Rust dependencies and benchmark tooling.
    • Updated GitHub Actions used for security analysis, benchmarks, and automated workflows.
  • Documentation
    • Updated fuzzing and Docker setup instructions, including pinned fuzzing-tool versions.

Walkthrough

The pull request changes fuzz workflow installation, target selection, duration validation, and run-status checks. It also updates Rust dependencies and imports, Debian container images, GitHub Actions references, and related setup documentation.

Changes

Fuzz workflow

Layer / File(s) Summary
Fuzz execution and status checks
.github/workflows/fuzz.yml
The workflow sets an explicit GNU target, validates duration input, installs prebuilt cargo-fuzz 0.13.2, and captures run status. A new step fails the job when final statistics are absent or the fuzzer exits nonzero and no crash was recorded.
Fuzz setup guidance
.claude/commands/fuzz-check.md, docs/06-TESTING.md, docs/29-FUZZING-GUIDE.md, docs/DEVELOPER-GUIDE.md, docs/src/advanced/security-best-practices.md, docs/src/development/{fuzzing,testing}.md, CHANGELOG.md
The setup instructions pin cargo-fuzz to 0.13.2 and use --locked. The changelog describes the workflow changes.

Rust dependencies and container images

Layer / File(s) Summary
Dependency versions and API imports
Cargo.toml, crates/*/Cargo.toml, fuzz/Cargo.toml, crates/prtip-core/src/retry.rs, crates/prtip-network/src/*, crates/prtip-scanner/src/*, crates/*/benches/*, crates/prtip-scanner/tests/common/error_injection.rs, tests/performance/benchmarks.rs, CLAUDE.md, CHANGELOG.md
The workspace updates dirs and rand; crate development dependencies update Criterion, and the fuzz package updates x509-parser. Random-number imports change to rand::RngExt, and benchmark imports use std::hint::black_box. Documented dependency versions are revised.
Trixie container images
docker/Dockerfile, docs/32-USER-GUIDE.md
The Docker builder and runtime images change from Bookworm to Trixie. The runtime package changes to libpcap0.8t64, and the user-guide example reflects the image and package updates.

GitHub Actions updates

Layer / File(s) Summary
Workflow action version references
.github/workflows/benchmarks.yml, .github/workflows/codeql.yml, .github/workflows/gemini-*.yml
The Rust toolchain setup and CodeQL actions use newer version references. Gemini workflows update action version annotations; the pinned SHAs remain unchanged where specified.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Bug fix

Sequence Diagram(s)

sequenceDiagram
  participant Workflow as Fuzz workflow
  participant Installer as cargo-fuzz installer
  participant Fuzzer as cargo-fuzz
  participant Artifacts as Artifact directory
  participant Summary as Job summary
  Workflow->>Workflow: Validate duration and set target triple
  Workflow->>Installer: Install pinned cargo-fuzz 0.13.2
  Workflow->>Fuzzer: Build and run target with duration
  Fuzzer->>Artifacts: Write run artifacts
  Fuzzer-->>Workflow: Exit status and final-statistics output
  Workflow->>Workflow: Check run status when no crash was recorded
  Workflow->>Summary: Pass duration through DURATION_INPUT
Loading

Merge Risk: ⚪ Minimal · up to 0b25f

The updated fuzz workflow detects failed runs, and no actionable risk introduced by this change remains after normal checks.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to 0b25f

The fuzzing changes address runs that could previously appear successful without actually fuzzing. They also add a new third-party installation step to CI. A separately verified concern about a changeable action reference remains in the benchmark workflow, although that condition existed before this PR.

Retained concerns

  • Medium · security · inferred: The fuzz job adds a third-party installation action referenced by a mutable major-version tag. Control of that tag is a new independent route to executing code on the CI runner. Other external actions and dependency installation already existed, and the job’s effective token authority has not been established.
Security review details

Security Blast Radius

  • inferred — The new fuzz installation action’s independently controlled reference exposes its CI runner to that action’s resolved code. The available evidence does not establish a write-scoped token or production credentials for this job.
  • observed — The changed container image is used by a scanner configuration with host networking and network capabilities, but the supplied changes do not alter those grants.

Security Findings and Attack Paths

  • observed — A verified security finding identifies execution through the benchmark workflow’s mutable setup-action tag. Base and head both use mutable major-version tags under the same declared triggers and permissions, so the evidence does not establish that this PR introduced or widened that condition.

Trust Boundaries and Controls

  • observed — The benchmark workflow’s action executes within a job granted pull-request write permission, but pull-request triggers are disabled in the inspected workflow; manual and scheduled triggers remain. The fuzz job adds duration validation and a separate incomplete-run failure gate.

Resilience and Maintainability Implications

  • observed — The fuzz run retains error-tolerant execution so crash artifacts can be handled, while subsequent steps fail recorded crashes or a run lacking clean completion. This separates artifact collection from the final job result.

Hardening Proposals

  • proposed — Pin the new fuzz installation action and the benchmark setup action to reviewed commit SHAs, and explicitly limit each job’s token permissions to what its steps require.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description check ✅ Passed The description clearly explains the dependency consolidation, nightly fuzzing fixes, compatibility constraints, validation results, and workflow updates.
Title check ✅ Passed The title concisely identifies the two main changes: dependency consolidation and the nightly fuzzing fix.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 17 functions across 16 files. (25 skipped:…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Warning

Review coverage is incomplete: 1 file could not be fully reviewed. Findings from completed review steps are included; see review info for details.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown

🤖 Hi @doublegate, I've received your request, and I'm working on it now! You can track my progress in the logs for more details.

@socket-security

socket-security Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

@github-actions

Copy link
Copy Markdown

🤖 I'm sorry @doublegate, but I was unable to process your request. Please see the logs for more details.

cargo-fuzz defaults --target to its own build triple. The release binary
is a static musl build, and ASan cannot link against static musl libc, so
every fuzz build failed with "sanitizer is incompatible with statically
linked libc". Pass x86_64-unknown-linux-gnu on build and run. Reproduced
and verified locally with the 0.13.2 release binary on all five targets.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@doublegate

Copy link
Copy Markdown
Owner Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Pull request base or head changed.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Moderate findings remain around zero-duration fuzz runs and Trixie package metadata, with additional documentation corrections pending.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Low severity

Open (1)
What changed in this PR

This PR consolidates dependency upgrades, refreshes lockfiles, fixes nightly fuzzing, and updates Debian Trixie support.

Changes:

  • Upgrades Rust dependencies and benchmark APIs.
  • Stabilizes fuzzing with a prebuilt cargo-fuzz.
  • Updates Docker images, CI actions, documentation, and changelog entries.
File Summary
tests/​performance/​benchmarks.rs Updates black_box import.
fuzz/​Cargo.toml Updates x509-parser.
fuzz/​Cargo.lock Refreshes fuzz dependencies.
docs/​32-USER-GUIDE.md Updates Docker instructions.
docs/​29-FUZZING-GUIDE.md Documents pinned cargo-fuzz installation.
docker/​Dockerfile Migrates images to Debian Trixie.
crates/​prtip-scanner/​tests/​common/​error_injection.rs Updates rand imports.
crates/​prtip-scanner/​src/​udp_scanner.rs Updates rand imports.
crates/​prtip-scanner/​src/​timing.rs Updates rand imports.
crates/​prtip-scanner/​src/​syn_scanner.rs Updates rand imports.
crates/​prtip-scanner/​src/​stealth_scanner.rs Updates rand imports.
crates/​prtip-scanner/​src/​idle/​idle_scanner.rs Updates rand imports.
crates/​prtip-scanner/​src/​decoy_scanner.rs Updates rand imports.
crates/​prtip-scanner/​Cargo.toml Updates Criterion.
crates/​prtip-scanner/​benches/​tls_performance.rs Migrates black_box.
crates/​prtip-network/​src/​packet_builder.rs Updates rand imports.
crates/​prtip-network/​src/​ipv6_packet.rs Updates rand imports.
crates/​prtip-network/​src/​fragmentation.rs Updates rand imports.
crates/​prtip-network/​Cargo.toml Updates Criterion.
crates/​prtip-network/​benches/​packet_crafting.rs Migrates black_box.
crates/​prtip-network/​benches/​batch_io.rs Migrates black_box.
crates/​prtip-core/​src/​retry.rs Updates rand imports and documentation.
crates/​prtip-core/​Cargo.toml Updates Criterion.
crates/​prtip-core/​benches/​event_system.rs Migrates black_box.
crates/​prtip-cli/​Cargo.toml Updates Criterion.
CLAUDE.md Synchronizes dependency documentation.
CHANGELOG.md Documents dependency and fuzzing changes.
Cargo.toml Updates workspace dependencies.
Cargo.lock Refreshes workspace dependencies.
.github/​workflows/​gemini-triage.yml Corrects action version annotations.
.github/​workflows/​gemini-scheduled-triage.yml Corrects action version annotations.
.github/​workflows/​gemini-review.yml Corrects action annotations.
.github/​workflows/​gemini-invoke.yml Corrects action version annotations.
.github/​workflows/​gemini-dispatch.yml Corrects action annotations.
.github/​workflows/​fuzz.yml Fixes cargo-fuzz installation and duration handling.
.github/​workflows/​codeql.yml Updates CodeQL action.
.github/​workflows/​benchmarks.yml Updates Rust toolchain action.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread docs/29-FUZZING-GUIDE.md
libFuzzer exits 1 at startup when the -artifact_prefix directory does not
exist, and /tmp/fuzzing-artifacts/ was never created. The run step read
the exit code after `| tee` without pipefail and is continue-on-error, so
every target "passed" without executing a single input. Create the
directory, record the real exit code and whether final stats were
printed, and fail the job when a target neither completed nor crashed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@doublegate

Copy link
Copy Markdown
Owner Author

Fuzz workflow dispatched on this branch (duration=60): https://github.com/doublegate/ProRT-IP/actions/runs/36095088608 -- all five targets green, and this time they actually fuzzed:

Target Executions in 61 s
fuzz_icmpv6_parser 15,744,930
fuzz_udp_parser 15,870,332
fuzz_ipv6_parser 10,763,510
fuzz_tcp_parser 7,620,053
fuzz_tls_parser 6,816,850

Two further defects surfaced on the way, both fixed in this PR:

  1. The prebuilt cargo-fuzz is a static musl binary and defaults --target to its own triple, where ASan cannot link ("sanitizer is incompatible with statically linked libc") -- run 36094462460. The workflow now passes --target x86_64-unknown-linux-gnu. Reproduced and fixed locally with the 0.13.2 release binary (negative control without --target fails the same way).
  2. Even once built, the fuzzers never ran and the job still went green -- run 36094645676 is all-success with ERROR: The required directory "/tmp/fuzzing-artifacts/" does not exist in every job. The exit code was read after | tee without pipefail, the step is continue-on-error, and the only failing gate looked for crash files. The directory is now created, and a new step fails any target that neither printed final stats with exit 0 nor recorded a crash. This had been hidden behind the install failure; it means scheduled fuzzing had not been exercising anything even before 2026-09-21.

Also noted, pre-existing and not changed: the targets dispatch input is declared but never read (the matrix always runs all five), and the target-directory cache keys on target while cargo-fuzz builds into fuzz/target, so that cache never hits.

libFuzzer treats -max_total_time=0 as unlimited, so a dispatch with
duration=0 would only stop at the timeout backstop. The other maintained
setup pages still told readers to run an unlocked `cargo install
cargo-fuzz`, the command that broke CI; they now match the fuzzing guide.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@doublegate

Copy link
Copy Markdown
Owner Author

@coderabbitai review

@doublegate
doublegate requested a lite review from Copilot September 25, 2026 05:02
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The fuzz duration input needs an upper bound, and several maintained documentation examples remain inconsistent with the dependency and workflow updates.

Review effort: Lite
Findings: None

Resolved since last review (1)
Previously missed (1)

In code that hasn't changed since last review

Low severity Update rand 0.10 APIs in documentation examples

Cargo.toml:78

Moving the workspace to rand 0.10 also makes several maintained documentation snippets stale: for example docs/src/development/testing-infrastructure.md:239-240, docs/src/development/implementation.md:259-267, and docs/src/reference/timing-templates.md:561-569 still import Rng and call thread_rng/gen/gen_range. Those APIs are the pre-0.10 form, whereas the production code in this PR uses RngExt/rng/random; please update the copy-pastable examples so they compile against the declared dependency.

@doublegate
doublegate merged commit 1238679 into main Sep 25, 2026
31 checks passed
@doublegate
doublegate deleted the chore/consolidate-dependency-updates branch September 25, 2026 05:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants