SECURITY: track Rust advisory debt and unmaintained transitive crates #811

Open
opened 2026-10-02 13:13:34 +00:00 by kayg · 4 comments
Owner

Context

Supply-chain audit under #663 on origin/dev c4a61e8cf0. cargo-audit is not installed. A read-only comparison of the locks with RustSec revision 117edb3bed98e9be112f277b7615eea3252e7c43 found the following matches. Duplicate issue searches for lru, advisory, dependency and audit found no matching maintenance issue.

Evidence and impact

  • Cargo.lock:4476: lru 0.16.4 through tantivy 0.26.2 (crates/calternal-search/Cargo.toml:32). RUSTSEC-2026-0253 is fixed in lru >=0.18.2. The cached Tantivy source src/store/reader.rs:74 uses LruCache<usize, Block>. The advisory requires a key destructor that panics during pop, plus continued use after unwind. Integer keys do not meet that condition. No product memory corruption is proved.
  • Cargo.lock:6283: rsa 0.9.10, RUSTSEC-2023-0071. No fixed release exists in this RustSec snapshot. Production OIDC verifies public signatures. Auth's RSA private key generation is in the test module (crates/calternal-auth/src/oidc.rs:339). Notifications use an EC VAPID key. No product RSA decryption oracle was found.
  • Root lock unmaintained matches: smallstr 0.3.1 through yrs (RUSTSEC-2026-0215), async-std 1.13.2 as a vendored async-imap dev dependency (2025-0052), paste 1.0.15 through tokenizers (2024-0436), ttf-parser 0.25.1 through lopdf (2026-0192), fxhash 0.2.1 through selectors (2025-0057).
  • The fuzz lock repeats lru, rsa, smallstr, paste, ttf-parser and fxhash. The embedding bench lock has paste; the auth nested lock has rsa. Do not report the root lock alone as the full inventory.

Verified with offline locked Cargo metadata/tree, cached upstream source and the current RustSec records. cargo search confirms latest Tantivy 0.26.2 and lru 0.18.5; a cross-major lock bump alone cannot update Tantivy's lru requirement.

Concrete fix

Track an upstream Tantivy release that consumes patched lru, or use a small reviewed compatible backport. For rsa, document a narrow, expiring advisory exception for public verification only; do not suppress all future RSA advisories. Remove async-std from the Tokio-only vendor test path where possible. Upgrade the parents of the unmaintained crates or record a time-limited reason and upstream tracking issue. Refresh all affected committed locks.

Validation

Use cargo-audit 0.22.2 or a later verified version against each lock with a recorded RustSec revision. Require lru's advisory to disappear after its fix. Test Search and OIDC per crate. Add a dependency policy check that fails if a scoped exception is expired or a new private RSA operation is introduced.

Sources: https://rustsec.org/advisories/RUSTSEC-2026-0253.html and https://rustsec.org/advisories/RUSTSEC-2023-0071.html.

Non-blocking under CLAUDE.md: no reachable product vulnerability was proved.

## Context Supply-chain audit under #663 on origin/dev c4a61e8cf090170f35b1bed3350d9de20c83ecd5. cargo-audit is not installed. A read-only comparison of the locks with RustSec revision 117edb3bed98e9be112f277b7615eea3252e7c43 found the following matches. Duplicate issue searches for lru, advisory, dependency and audit found no matching maintenance issue. ## Evidence and impact - `Cargo.lock:4476`: lru 0.16.4 through tantivy 0.26.2 (`crates/calternal-search/Cargo.toml:32`). RUSTSEC-2026-0253 is fixed in lru >=0.18.2. The cached Tantivy source `src/store/reader.rs:74` uses LruCache<usize, Block>. The advisory requires a key destructor that panics during pop, plus continued use after unwind. Integer keys do not meet that condition. No product memory corruption is proved. - `Cargo.lock:6283`: rsa 0.9.10, RUSTSEC-2023-0071. No fixed release exists in this RustSec snapshot. Production OIDC verifies public signatures. Auth's RSA private key generation is in the test module (`crates/calternal-auth/src/oidc.rs:339`). Notifications use an EC VAPID key. No product RSA decryption oracle was found. - Root lock unmaintained matches: smallstr 0.3.1 through yrs (RUSTSEC-2026-0215), async-std 1.13.2 as a vendored async-imap dev dependency (2025-0052), paste 1.0.15 through tokenizers (2024-0436), ttf-parser 0.25.1 through lopdf (2026-0192), fxhash 0.2.1 through selectors (2025-0057). - The fuzz lock repeats lru, rsa, smallstr, paste, ttf-parser and fxhash. The embedding bench lock has paste; the auth nested lock has rsa. Do not report the root lock alone as the full inventory. Verified with offline locked Cargo metadata/tree, cached upstream source and the current RustSec records. `cargo search` confirms latest Tantivy 0.26.2 and lru 0.18.5; a cross-major lock bump alone cannot update Tantivy's lru requirement. ## Concrete fix Track an upstream Tantivy release that consumes patched lru, or use a small reviewed compatible backport. For rsa, document a narrow, expiring advisory exception for public verification only; do not suppress all future RSA advisories. Remove async-std from the Tokio-only vendor test path where possible. Upgrade the parents of the unmaintained crates or record a time-limited reason and upstream tracking issue. Refresh all affected committed locks. ## Validation Use cargo-audit 0.22.2 or a later verified version against each lock with a recorded RustSec revision. Require lru's advisory to disappear after its fix. Test Search and OIDC per crate. Add a dependency policy check that fails if a scoped exception is expired or a new private RSA operation is introduced. Sources: https://rustsec.org/advisories/RUSTSEC-2026-0253.html and https://rustsec.org/advisories/RUSTSEC-2023-0071.html. Non-blocking under CLAUDE.md: no reachable product vulnerability was proved.
Author
Owner

Starting #811 on branch job/deps, based at 2f4482ded066d9c5d9c59130377907f7fd2916c9 (job/merge-round-7a). I read the issue, audit evidence, CLAUDE.md, CONTEXT.md and relevant DESIGN sections. I will verify RustSec state and upstream constraints, address the reachable dependency debt, record any narrow exceptions, and add regression/policy checks across the committed locks.

Starting #811 on branch `job/deps`, based at `2f4482ded066d9c5d9c59130377907f7fd2916c9` (`job/merge-round-7a`). I read the issue, audit evidence, CLAUDE.md, CONTEXT.md and relevant DESIGN sections. I will verify RustSec state and upstream constraints, address the reachable dependency debt, record any narrow exceptions, and add regression/policy checks across the committed locks.
Author
Owner

Finding: the current root and fuzz locks resolve Tantivy 0.26.2 → lru 0.16.4. Tantivy 0.26.2 is still the latest release in the registry, and its LruCache<usize, Block> use does not meet RustSec RUSTSEC-2026-0253's panicking-key-drop precondition. A direct lru lock bump cannot satisfy Tantivy's semver requirement. I will keep this advisory exception limited to lru 0.16.4 in locks using Tantivy and give it a review expiry; I will not claim the dependency is patched.

The RSA 0.9.10 match is used for public OIDC signature verification; key generation is in the OIDC test module. The rsa dev dependency is present in the auth and fuzz locks. I am adding a package/advisory scoped exception and a source guard against private RSA operations outside test-only code. I am also checking whether the unmaintained async-std edge can be removed from the Tokio-only vendored package without deleting its supported runtime implementation.

Finding: the current root and fuzz locks resolve Tantivy 0.26.2 → lru 0.16.4. Tantivy 0.26.2 is still the latest release in the registry, and its `LruCache<usize, Block>` use does not meet RustSec RUSTSEC-2026-0253's panicking-key-drop precondition. A direct lru lock bump cannot satisfy Tantivy's semver requirement. I will keep this advisory exception limited to lru 0.16.4 in locks using Tantivy and give it a review expiry; I will not claim the dependency is patched. The RSA 0.9.10 match is used for public OIDC signature verification; key generation is in the OIDC test module. The `rsa` dev dependency is present in the auth and fuzz locks. I am adding a package/advisory scoped exception and a source guard against private RSA operations outside test-only code. I am also checking whether the unmaintained async-std edge can be removed from the Tokio-only vendored package without deleting its supported runtime implementation.
Author
Owner

Additional finding from the required cargo-audit 0.22.2 run against RustSec revision 117edb3bed98e9be112f277b7615eea3252e7c43: it reports yoke-derive 0.8.3 as yanked in the root lock (no advisory ID). cargo search confirmed 0.8.4 is current, and yoke 0.8.3 accepts it via its ^0.8.2 requirement. I updated root, fuzz, bench and nested auth locks to 0.8.4. The exact unreviewed yanked warning now has a regression fixture so future yanked packages fail the policy check. The lru item is classified as unsound by the actual RustSec report, so its exception uses that exact kind.

Additional finding from the required cargo-audit 0.22.2 run against RustSec revision `117edb3bed98e9be112f277b7615eea3252e7c43`: it reports yoke-derive 0.8.3 as yanked in the root lock (no advisory ID). `cargo search` confirmed 0.8.4 is current, and yoke 0.8.3 accepts it via its `^0.8.2` requirement. I updated root, fuzz, bench and nested auth locks to 0.8.4. The exact unreviewed yanked warning now has a regression fixture so future yanked packages fail the policy check. The lru item is classified as `unsound` by the actual RustSec report, so its exception uses that exact kind.
Author
Owner

Completed on branch job/deps. Final head: 306fd0a953.

Updated yanked yoke-derive 0.8.3 to 0.8.4 in all four Cargo locks. Corrected the LRU advisory kind to unsound and retained exact, expiring exceptions for the existing RSA and unmaintained/unsound advisories. The policy parses RustSec JSON warning categories and tests lock coverage and exceptions.

Gate output:

Ran 10 tests in 0.343s

OK
cargo-audit 0.22.2; release SHA-256 ab28a1bdb54db4d5d8ad5981cf1f959410370b3d28250dbd35f6a44248620e39
PASS dependency advisories and licences; RustSec database 117edb3bed98e9be112f277b7615eea3252e7c43

Known gap: cargo test -p calternal-search was stopped at the four-hour timebox during dependency compilation (exit 130, no test summary); calternal-auth tests and clippy were not run. The license and advisory policy itself passes across the merged locks.

Decision: used the exact official cargo-audit 0.22.2 release asset with SHA-256 verification rather than compiling the tool in CI.

Completed on branch job/deps. Final head: 306fd0a953f342395af64cc62f0b18f3416ea95a. Updated yanked yoke-derive 0.8.3 to 0.8.4 in all four Cargo locks. Corrected the LRU advisory kind to unsound and retained exact, expiring exceptions for the existing RSA and unmaintained/unsound advisories. The policy parses RustSec JSON warning categories and tests lock coverage and exceptions. Gate output: ``` Ran 10 tests in 0.343s OK cargo-audit 0.22.2; release SHA-256 ab28a1bdb54db4d5d8ad5981cf1f959410370b3d28250dbd35f6a44248620e39 PASS dependency advisories and licences; RustSec database 117edb3bed98e9be112f277b7615eea3252e7c43 ``` Known gap: cargo test -p calternal-search was stopped at the four-hour timebox during dependency compilation (exit 130, no test summary); calternal-auth tests and clippy were not run. The license and advisory policy itself passes across the merged locks. Decision: used the exact official cargo-audit 0.22.2 release asset with SHA-256 verification rather than compiling the tool in CI.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#811
No description provided.