Fixes a soundness bug in io::Take (#4428). The unsoundness is exposed when
leaking memory in the given AsyncRead implementation and then overwriting the
supplied buffer:
Added the std cargo feature, which enables implementations of std traits
for various things. Right now that is just std::io::Write for
bumpalo::collections::Vec, but could be more in the future.
3.13.0
Released 2023-05-22.
Added
New "allocator-api2" feature enables the use of the allocator API on
stable. This feature uses a crate that mirrors the API of the unstable Rust
allocator_api feature. If the feature is enabled, references to Bump will
implement allocator_api2::Allocator. This allows Bump to be used as an
allocator for collection types from allocator-api2 and any other crates that
support allocator-api2.
Changed
The minimum supported Rust version (MSRV) is now 1.63.0.
3.12.2
Released 2023-05-09.
Changed
Added rust-version metadata to Cargo.toml which helps cargo with version
resolution.
3.12.1
Released 2023-04-21.
Fixed
Fixed a bug where Bump::try_with_capacity(n) where n > isize::MAX could
lead to attempts to create invalid Layouts.
Remove the dependency on the once_cell crate to restore the MSRV. (#913)
Work around rust-lang#98302, which causes compile error on windows-gnu when LTO is enabled. (#913)
crossbeam-utils 0.8.11
Bump the minimum supported Rust version to 1.38. (#877)
crossbeam-utils 0.8.10
Fix unsoundness of AtomicCell on types containing niches. (#834)
This fix contains breaking changes, but they are allowed because this is a soundness bug fix. See #834 for more.
Add header_table_size(usize) option to client and server builders.
Improve throughput when vectored IO is not available.
Update indexmap to 2.
0.3.21 (August 21, 2023)
Fix opening of new streams over peer's max concurrent limit.
Fix RecvStream to return data even if it has received a CANCEL stream error.
Update MSRV to 1.63.
0.3.20 (June 26, 2023)
Fix panic if a server received a request with a :status pseudo header in the 1xx range.
Fix panic if a reset stream had pending push promises that were more than allowed.
Fix potential flow control overflow by subtraction, instead returning a connection error.
0.3.19 (May 12, 2023)
Fix counting reset streams when triggered by a GOAWAY.
Send too_many_resets in opaque debug data of GOAWAY when too many resets received.
0.3.18 (April 17, 2023)
Fix panic because of opposite check in is_remote_local().
0.3.17 (April 13, 2023)
Add Error::is_library() method to check if the originated inside h2.
Add max_pending_accept_reset_streams(usize) option to client and server
builders.
Fix theoretical memory growth when receiving too many HEADERS and then
RST_STREAM frames faster than an application can accept them off the queue.
(CVE-2023-26964)
0.3.16 (February 27, 2023)
Set Protocol extension on requests when received Extended CONNECT requests.
Remove B: Unpin + 'static bound requiremented of bufs
Fix releasing of frames when stream is finished, reducing memory usage.
Fix panic when trying to send data and connection window is available, but stream window is not.
Fix spurious wakeups when stream capacity is not available.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/gbip/sentry_tunnel/network/alerts).
⚠️ Dependabot is rebasing this PR ⚠️
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Bumps the cargo group with 6 updates in the /. directory:
1.12.0
1.16.1
3.7.1
3.14.0
0.8.5
0.8.19
0.3.6
0.3.22
111.16.0+1.1.1l
111.25.0+1.1.1t
1.5.4
1.7.3
Updates
tokio
from 1.12.0 to 1.16.1Release notes
Sourced from tokio's releases.
... (truncated)
Commits
91b9850
chore: prepare Tokio v1.16.1 release (#4438)3c46705
io: fix take pointer check (#4437)afd2189
chore: prepare Tokio v1.16 release (#4431)986b88b
chore: update year in LICENSE files (#4429)257053e
util: addspawn_pinned
(#3370)5af9e0d
sync: add blocking lock methods toRwLock
(#4425)8f77ee8
net: add generic trait to combine UnixListener and TcpListener (#4385)2747043
tests: enable running wasm32-unknown-unknown tests (#4421)2a5071f
feat: implementFramed::map_codec
(#4427)621790e
io: fixtake
when using evil reader (#4428)Updates
bumpalo
from 3.7.1 to 3.14.0Changelog
Sourced from bumpalo's changelog.
... (truncated)
Commits
c610d5a
Bump to version 3.14.07dbb89c
Merge pull request #216 from marmeladema/std-io-writecdaaae1
Implementstd::io::Write
forVec\<'bump, u8>
86c63a4
Merge pull request #214 from waywardmonkeys/typo-fixes9c6c38f
Fix some typos.9be533b
Merge pull request #212 from waywardmonkeys/clippy-unnecessary-cast4d4cb90
clippy: Remove unneccessary casts.2c3ded0
Merge pull request #211 from frisoft/mainb6ea857
Merge pull request #1 from frisoft/update-license-fieldabac21c
Update license field following SPDX 2.1 license expression standardUpdates
crossbeam-utils
from 0.8.5 to 0.8.19Release notes
Sourced from crossbeam-utils's releases.
... (truncated)
Commits
9c3182a
Prepare for the next release35a55d2
Remove dependency on cfg-if0935295
epoch: Remove unused autocfg dependencye02133b
Use const thread_local5a15fc2
More correct buffer allocation7389cdf
ci: Remove scripts that call single command4ef4f09
Ignore dead_code warnings for tuple structs95d0bd0
Prepare for the next release65f0b07
Automatically cancel outdated CI runs on PRecc994e
Update compile_fail doctestUpdates
h2
from 0.3.6 to 0.3.22Release notes
Sourced from h2's releases.
... (truncated)
Changelog
Sourced from h2's changelog.
... (truncated)
Commits
0f412d8
v0.3.22c7ca62f
docs: fix typos (#724)ef743ec
Add a setter for header_table_size (#638)56651e6
fix lint about unused import4aa7b16
Fix documentation for max_send_buffer_size (#718)d03c54a
chore(dependencies): update tracing minimal version to 0.1.353cdef96
fix(test): mark h2-support as private crate05cf352
chore(ci): add minimal versions checking on stable rustcbe7744
chore(ci): update to actions/checkout@v4 (#716)1f247de
Update indexmap to version 2 (#698)Updates
openssl-src
from 111.16.0+1.1.1l to 111.25.0+1.1.1tCommits
Updates
regex
from 1.5.4 to 1.7.3Changelog
Sourced from regex's changelog.
... (truncated)
Commits
9582040
1.7.39562ccd
changelog: 1.7.3d94f955
dfa: fix bug in how the reverse DFA is called32fed94
1.7.26a7ba1e
deps: bump to regex-syntax 0.6.2972d482f
regex-syntax-0.6.2948b3ba4
changelog: 1.7.2d8e22dd
syntax: tweak the "no stack overflow" testa9b2e02
1.7.198c1b63
changelog: 1.7.1Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show