You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Consolidates every open dependency PR into one reviewed change, takes the remaining updates Dependabot had not proposed, and fixes the nightly fuzz workflow, which has failed every night since at least 2026-09-21.
Every Fuzz Testing matrix job died about 20 s in at cargo install cargo-fuzz --version 0.13.1. Without --locked that resolves a fresh dependency graph on each run and compiles it with the nightly toolchain the job selects; from September it picked up a rustix whose nightly-only build path uses rustc_* attributes current nightly rejects (attributes starting with rustc are reserved, rustc_layout_scalar_valid_range_start not found).
Reproduced locally on nightly 2026-09-23: 0.13.1 unlocked fails with exactly that error; 0.13.2 --locked builds. CI now installs the prebuilt cargo-fuzz 0.13.2 release binary via taiki-e/install-action@v2, so no nightly compiler change can break the install. The duration dispatch input now reaches the script through env: (it was template-expanded into the script text) and is validated as an integer in a step that is not continue-on-error.
Two more defects appeared once the install worked, both fixed here: the prebuilt binary is a static musl build and cargo-fuzz defaults --target to its own triple, where ASan cannot link, so the workflow now names x86_64-unknown-linux-gnu; and the fuzzers had never actually run -- libFuzzer exits at startup when -artifact_prefix names a missing directory, and the job hid it (exit code read after | tee without pipefail, step continue-on-error, gate only looked for crash files). The directory is created now, and a new step fails any target that neither completed cleanly nor recorded a crash. Dispatch run on this branch: https://github.com/doublegate/ProRT-IP/actions/runs/36095088608 -- all five targets green with 6.8M-15.9M executions each in 60 s.
Verified: cargo +nightly fuzz build <target> succeeds locally for all five targets (fuzz_ipv6_parser, fuzz_icmpv6_parser, fuzz_udp_parser, fuzz_tcp_parser, fuzz_tls_parser) with the bumped fuzz dependencies. A dispatch run on this branch is linked in the comments.
Bumps
Package
Old
New
Notes
rand
0.9
0.10
random/random_range moved from Rng to RngExt; 11 imports changed, no call sites
criterion (dev)
0.5
0.8
criterion::black_box deprecated -> std::hint::black_box in 5 bench files
dirs
6.0
7.0
drop-in
x509-parser (fuzz)
0.16
0.18
matches the workspace; drops the duplicate asn1-rs/der-parser/x509-parser stack from the fuzz build
rustls (lock)
0.23.43
0.23.45
fixes RUSTSEC-2026-0285, which fails cargo deny and the fuzz cargo audit on main today
Cargo.lock
68 packages to latest semver-compatible
fuzz/Cargo.lock
52 packages to latest semver-compatible
Docker builder
rust:1.88-bookworm
rust:1.88-trixie
Docker runtime
debian:bookworm-slim
debian:trixie-slim
runtime package renamed libpcap0.8 -> libpcap0.8t64 (checked with apt-cache policy in debian:trixie-slim)
actions-rust-lang/setup-rust-toolchain
v1
v2
benchmarks.yml; v2 drops the default RUSTFLAGS=-D warnings for CARGO_BUILD_WARNINGS
github/codeql-action
v3
v4
taiki-e/install-action
-
v2
new, fuzz.yml
Every other uses: was already on its latest major. The SHA pins in the Gemini workflows were already the latest releases, but their ratchet: comments said checkout@v5, create-github-app-token@v2, github-script@v7; the comments now name the versions the SHAs actually resolve to (checkout v7.0.1, create-github-app-token v3.2.0, github-script v9.0.0). alpine:3.24 is the newest Alpine.
Held back
Package
Current
Latest
Why
sysinfo
0.38
0.39
requires Rust 1.95; workspace MSRV is 1.88 (already documented in Cargo.toml)
sqlx
0.8
0.9
requires Rust 1.94; it is a normal dependency of prtip-scanner, so it would break the MSRV build. #12 proposed it; it moves with the MSRV
Checked by metadata, not only by building: 0 of 502 resolved workspace packages and 0 of 362 fuzz packages declare a rust-version above 1.88.
Not bumped: docker/test-environment/docker-compose.yml deliberately runs old/vulnerable services (Metasploitable2, mysql 8.0, postgres 15) as scan targets. rusqlite, tera, printpdf, pcap, rayon, csv (as a workspace entry) and tokio-util are declared in [workspace.dependencies] but consumed by no crate, so they never resolve into the lockfile; bumping them would be unverifiable. Removing them is left to the owner.
cargo test --workspace --locked --lib --bins --tests
2349 passed, 0 failed, 100 ignored
2349 passed, 0 failed, 100 ignored
cargo +1.88 build --workspace --locked (MSRV)
pass
pass
cargo deny --all-features check
fail (RUSTSEC-2026-0285)
pass
cargo audit in fuzz/
fail (RUSTSEC-2026-0285)
pass
generated-data --check (both generators)
pass
pass
cargo +nightly fuzz build x5 targets
pass
pass
review / review (Gemini) fails with "Please set an Auth method ... GEMINI_API_KEY": the repository has no Gemini credentials configured. Pre-existing -- it failed identically on #7 -- and not a required check.
Workflows this PR does not exercise: fuzz.yml (schedule/dispatch; dispatched on this branch), benchmarks.yml (schedule/dispatch), release.yml/packages.yml (tag/release), mdbook.yml, coverage.yml (push to main). The Docker image build itself runs in the CI Docker Images job on this PR.
The scheduled fuzz workflow had failed every night since at least
2026-09-21 at `cargo install cargo-fuzz --version 0.13.1`. Without
--locked it resolved a fresh graph on each run and compiled it with the
job's nightly toolchain, which now rejects the rustc_* attributes used by
the rustix version it picked. Install the pinned 0.13.2 release binary via
taiki-e/install-action instead, and pass the duration dispatch input
through the environment with validation rather than template expansion.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Supersedes Dependabot #9, #12 and #13.
- rand 0.9 -> 0.10 (Rng convenience methods moved to RngExt)
- criterion 0.5 -> 0.8 (benches use std::hint::black_box)
- dirs 6 -> 7; fuzz x509-parser 0.16 -> 0.18
- refresh Cargo.lock and fuzz/Cargo.lock; rustls 0.23.45 fixes
RUSTSEC-2026-0285, which was failing cargo-deny and cargo-audit on main
- hold sysinfo 0.39 (Rust 1.95) and sqlx 0.9 (Rust 1.94) at the 1.88 MSRV
- Docker images move from bookworm to trixie (libpcap0.8t64)
- setup-rust-toolchain v2, codeql-action v4; correct stale ratchet
comments on the SHA-pinned Gemini workflow actions
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Files not reviewed due to moderation or processing errors (1)
.github/workflows/fuzz.yml
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.
📝 Summary
Summary by CodeRabbit
Bug Fixes
Improved fuzz-test runs so invalid durations are rejected and unsuccessful or incomplete runs are reported as failures.
Updates
Updated the container base image and packet-capture runtime package.
Refreshed Rust dependencies and benchmark tooling.
Updated GitHub Actions used for security analysis, benchmarks, and automated workflows.
Documentation
Updated fuzzing and Docker setup instructions, including pinned fuzzing-tool versions.
Walkthrough
The pull request changes fuzz workflow installation, target selection, duration validation, and run-status checks. It also updates Rust dependencies and imports, Debian container images, GitHub Actions references, and related setup documentation.
Changes
Fuzz workflow
Layer / File(s)
Summary
Fuzz execution and status checks .github/workflows/fuzz.yml
The workflow sets an explicit GNU target, validates duration input, installs prebuilt cargo-fuzz 0.13.2, and captures run status. A new step fails the job when final statistics are absent or the fuzzer exits nonzero and no crash was recorded.
The setup instructions pin cargo-fuzz to 0.13.2 and use --locked. The changelog describes the workflow changes.
Rust dependencies and container images
Layer / File(s)
Summary
Dependency versions and API imports Cargo.toml, crates/*/Cargo.toml, fuzz/Cargo.toml, crates/prtip-core/src/retry.rs, crates/prtip-network/src/*, crates/prtip-scanner/src/*, crates/*/benches/*, crates/prtip-scanner/tests/common/error_injection.rs, tests/performance/benchmarks.rs, CLAUDE.md, CHANGELOG.md
The workspace updates dirs and rand; crate development dependencies update Criterion, and the fuzz package updates x509-parser. Random-number imports change to rand::RngExt, and benchmark imports use std::hint::black_box. Documented dependency versions are revised.
The Docker builder and runtime images change from Bookworm to Trixie. The runtime package changes to libpcap0.8t64, and the user-guide example reflects the image and package updates.
GitHub Actions updates
Layer / File(s)
Summary
Workflow action version references .github/workflows/benchmarks.yml, .github/workflows/codeql.yml, .github/workflows/gemini-*.yml
The Rust toolchain setup and CodeQL actions use newer version references. Gemini workflows update action version annotations; the pinned SHAs remain unchanged where specified.
sequenceDiagram
participant Workflow as Fuzz workflow
participant Installer as cargo-fuzz installer
participant Fuzzer as cargo-fuzz
participant Artifacts as Artifact directory
participant Summary as Job summary
Workflow->>Workflow: Validate duration and set target triple
Workflow->>Installer: Install pinned cargo-fuzz 0.13.2
Workflow->>Fuzzer: Build and run target with duration
Fuzzer->>Artifacts: Write run artifacts
Fuzzer-->>Workflow: Exit status and final-statistics output
Workflow->>Workflow: Check run status when no crash was recorded
Workflow->>Summary: Pass duration through DURATION_INPUT
Loading
Merge Risk:⚪ Minimal · up to 0b25f
The updated fuzz workflow detects failed runs, and no actionable risk introduced by this change remains after normal checks.
Security Architecture Review
Security architecture risk:🟡 Moderate · up to 0b25f
The fuzzing changes address runs that could previously appear successful without actually fuzzing. They also add a new third-party installation step to CI. A separately verified concern about a changeable action reference remains in the benchmark workflow, although that condition existed before this PR.
Retained concerns
Medium · security · inferred: The fuzz job adds a third-party installation action referenced by a mutable major-version tag. Control of that tag is a new independent route to executing code on the CI runner. Other external actions and dependency installation already existed, and the job’s effective token authority has not been established.
Security review details
Security Blast Radius
inferred — The new fuzz installation action’s independently controlled reference exposes its CI runner to that action’s resolved code. The available evidence does not establish a write-scoped token or production credentials for this job.
observed — The changed container image is used by a scanner configuration with host networking and network capabilities, but the supplied changes do not alter those grants.
Security Findings and Attack Paths
observed — A verified security finding identifies execution through the benchmark workflow’s mutable setup-action tag. Base and head both use mutable major-version tags under the same declared triggers and permissions, so the evidence does not establish that this PR introduced or widened that condition.
Trust Boundaries and Controls
observed — The benchmark workflow’s action executes within a job granted pull-request write permission, but pull-request triggers are disabled in the inspected workflow; manual and scheduled triggers remain. The fuzz job adds duration validation and a separate incomplete-run failure gate.
Resilience and Maintainability Implications
observed — The fuzz run retains error-tolerant execution so crash artifacts can be handled, while subsequent steps fail recorded crashes or a run lacking clean completion. This separates artifact collection from the final job result.
Hardening Proposals
proposed — Pin the new fuzz installation action and the benchmark setup action to reviewed commit SHAs, and explicitly limit each job’s token permissions to what its steps require.
The description clearly explains the dependency consolidation, nightly fuzzing fixes, compatibility constraints, validation results, and workflow updates.
Title check
✅ Passed
The title concisely identifies the two main changes: dependency consolidation and the nightly fuzzing fix.
Docstring Coverage
✅ Passed
Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 17 functions across 16 files. (25 skipped:…
Linked Issues check
✅ Passed
Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check
✅ Passed
Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches📝 Generate docstrings
Commit to this branch
Create a new PR
🧪 Generate unit tests (beta)
Commit to this branch
Create a new PR
Warning
Review coverage is incomplete: 1 file could not be fully reviewed. Findings from completed review steps are included; see review info for details.
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.
cargo-fuzz defaults --target to its own build triple. The release binary
is a static musl build, and ASan cannot link against static musl libc, so
every fuzz build failed with "sanitizer is incompatible with statically
linked libc". Pass x86_64-unknown-linux-gnu on build and run. Reproduced
and verified locally with the 0.13.2 release binary on all five targets.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.
libFuzzer exits 1 at startup when the -artifact_prefix directory does not
exist, and /tmp/fuzzing-artifacts/ was never created. The run step read
the exit code after `| tee` without pipefail and is continue-on-error, so
every target "passed" without executing a single input. Create the
directory, record the real exit code and whether final stats were
printed, and fail the job when a target neither completed nor crashed.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Two further defects surfaced on the way, both fixed in this PR:
The prebuilt cargo-fuzz is a static musl binary and defaults --target to its own triple, where ASan cannot link ("sanitizer is incompatible with statically linked libc") -- run 36094462460. The workflow now passes --target x86_64-unknown-linux-gnu. Reproduced and fixed locally with the 0.13.2 release binary (negative control without --target fails the same way).
Even once built, the fuzzers never ran and the job still went green -- run 36094645676 is all-success with ERROR: The required directory "/tmp/fuzzing-artifacts/" does not exist in every job. The exit code was read after | tee without pipefail, the step is continue-on-error, and the only failing gate looked for crash files. The directory is now created, and a new step fails any target that neither printed final stats with exit 0 nor recorded a crash. This had been hidden behind the install failure; it means scheduled fuzzing had not been exercising anything even before 2026-09-21.
Also noted, pre-existing and not changed: the targets dispatch input is declared but never read (the matrix always runs all five), and the target-directory cache keys on target while cargo-fuzz builds into fuzz/target, so that cache never hits.
libFuzzer treats -max_total_time=0 as unlimited, so a dispatch with
duration=0 would only stop at the timeout backstop. The other maintained
setup pages still told readers to run an unlocked `cargo install
cargo-fuzz`, the command that broke CI; they now match the fuzzing guide.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.
The reason will be displayed to describe this comment to others. Learn more.
Copilot review overview
🔵 Needs a closer look
The fuzz duration input needs an upper bound, and several maintained documentation examples remain inconsistent with the dependency and workflow updates.
Moving the workspace to rand 0.10 also makes several maintained documentation snippets stale: for example docs/src/development/testing-infrastructure.md:239-240, docs/src/development/implementation.md:259-267, and docs/src/reference/timing-templates.md:561-569 still import Rng and call thread_rng/gen/gen_range. Those APIs are the pre-0.10 form, whereas the production code in this PR uses RngExt/rng/random; please update the copy-pastable examples so they compile against the declared dependency.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Consolidates every open dependency PR into one reviewed change, takes the remaining updates Dependabot had not proposed, and fixes the nightly fuzz workflow, which has failed every night since at least 2026-09-21.
Supersedes #9, #12, #13.
Nightly fuzzing fix
Every
Fuzz Testingmatrix job died about 20 s in atcargo install cargo-fuzz --version 0.13.1. Without--lockedthat resolves a fresh dependency graph on each run and compiles it with the nightly toolchain the job selects; from September it picked up arustixwhose nightly-only build path usesrustc_*attributes current nightly rejects (attributes starting with rustc are reserved,rustc_layout_scalar_valid_range_startnot found).Reproduced locally on nightly 2026-09-23: 0.13.1 unlocked fails with exactly that error; 0.13.2
--lockedbuilds. CI now installs the prebuilt cargo-fuzz 0.13.2 release binary viataiki-e/install-action@v2, so no nightly compiler change can break the install. Thedurationdispatch input now reaches the script throughenv:(it was template-expanded into the script text) and is validated as an integer in a step that is notcontinue-on-error.Two more defects appeared once the install worked, both fixed here: the prebuilt binary is a static musl build and cargo-fuzz defaults
--targetto its own triple, where ASan cannot link, so the workflow now namesx86_64-unknown-linux-gnu; and the fuzzers had never actually run -- libFuzzer exits at startup when-artifact_prefixnames a missing directory, and the job hid it (exit code read after| teewithoutpipefail, stepcontinue-on-error, gate only looked for crash files). The directory is created now, and a new step fails any target that neither completed cleanly nor recorded a crash. Dispatch run on this branch: https://github.com/doublegate/ProRT-IP/actions/runs/36095088608 -- all five targets green with 6.8M-15.9M executions each in 60 s.Verified:
cargo +nightly fuzz build <target>succeeds locally for all five targets (fuzz_ipv6_parser, fuzz_icmpv6_parser, fuzz_udp_parser, fuzz_tcp_parser, fuzz_tls_parser) with the bumped fuzz dependencies. A dispatch run on this branch is linked in the comments.Bumps
randrandom/random_rangemoved fromRngtoRngExt; 11 imports changed, no call sitescriterion(dev)criterion::black_boxdeprecated ->std::hint::black_boxin 5 bench filesdirsx509-parser(fuzz)asn1-rs/der-parser/x509-parserstack from the fuzz buildrustls(lock)cargo denyand the fuzzcargo auditonmaintodayCargo.lockfuzz/Cargo.lockbuilderrust:1.88-bookwormrust:1.88-trixieruntimedebian:bookworm-slimdebian:trixie-slimlibpcap0.8->libpcap0.8t64(checked withapt-cache policyindebian:trixie-slim)actions-rust-lang/setup-rust-toolchainRUSTFLAGS=-D warningsforCARGO_BUILD_WARNINGSgithub/codeql-actiontaiki-e/install-actionEvery other
uses:was already on its latest major. The SHA pins in the Gemini workflows were already the latest releases, but theirratchet:comments saidcheckout@v5,create-github-app-token@v2,github-script@v7; the comments now name the versions the SHAs actually resolve to (checkout v7.0.1, create-github-app-token v3.2.0, github-script v9.0.0).alpine:3.24is the newest Alpine.Held back
sysinfoCargo.toml)sqlxprtip-scanner, so it would break the MSRV build. #12 proposed it; it moves with the MSRVChecked by metadata, not only by building: 0 of 502 resolved workspace packages and 0 of 362 fuzz packages declare a
rust-versionabove 1.88.Not bumped:
docker/test-environment/docker-compose.ymldeliberately runs old/vulnerable services (Metasploitable2, mysql 8.0, postgres 15) as scan targets.rusqlite,tera,printpdf,pcap,rayon,csv(as a workspace entry) andtokio-utilare declared in[workspace.dependencies]but consumed by no crate, so they never resolve into the lockfile; bumping them would be unverifiable. Removing them is left to the owner.Local gate (same commands as CI)
mainbaselinecargo fmt --all -- --checkcargo clippy --workspace --all-targets --locked -- -D warningscargo test --workspace --locked --lib --bins --testscargo +1.88 build --workspace --locked(MSRV)cargo deny --all-features checkcargo auditinfuzz/--check(both generators)cargo +nightly fuzz buildx5 targetsreview / review(Gemini) fails with "Please set an Auth method ... GEMINI_API_KEY": the repository has no Gemini credentials configured. Pre-existing -- it failed identically on #7 -- and not a required check.Workflows this PR does not exercise:
fuzz.yml(schedule/dispatch; dispatched on this branch),benchmarks.yml(schedule/dispatch),release.yml/packages.yml(tag/release),mdbook.yml,coverage.yml(push to main). The Docker image build itself runs in the CIDocker Imagesjob on this PR.🤖 Generated with Claude Code