diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index a0dd636c..1aeb347a 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -129,6 +129,43 @@ jobs: working-directory: audio-graph/src-tauri run: cargo audit + # `ignore` in audit.toml is an unconditional advisory-ID suppression, so a + # stanza whose justification is "this package is unreachable" would keep + # passing after the package became reachable. The RUSTSEC-2026-0235 + # (rkyv 0.7.46) stanza states exactly that condition and names this command + # as its own remediation trigger, so assert it here rather than trusting a + # reader to re-run it by hand. + # + # Matched against the advisory's AFFECTED RANGE (patched is ">= 0.8.17"), + # not a pinned version: a check keyed on rkyv@0.7.46 alone would pass + # silently if the lockfile later resolved 0.7.47 or 0.8.10, both still + # vulnerable and both still suppressed by the ID-level ignore. + # + # Version logic unit-checked against synthetic input before landing: + # 0.7.46 and 0.8.16 flag; 0.8.17, 0.9.0, and 1.0.0 do not. + - name: Assert no affected rkyv is reachable + working-directory: audio-graph/src-tauri + run: | + affected="$( + cargo tree --locked --target all --all-features --edges all \ + --format '{p}' --prefix none 2>/dev/null \ + | awk ' + $1 == "rkyv" { + v = $2; sub(/^v/, "", v); + split(v, p, "."); + if ((p[1]+0) == 0 && ((p[2]+0) < 8 || ((p[2]+0) == 8 && (p[3]+0) < 17))) + print $1 " " $2; + }' \ + | sort -u + )" + if [ -n "$affected" ]; then + echo "::error::RUSTSEC-2026-0235's ignore in .cargo/audit.toml is justified only while no affected rkyv (< 0.8.17) is reachable, but one now is:" + printf '%s\n' "$affected" + echo "::error::Remove that ignore and resolve the advisory, or replace its justification with one that matches reality." + exit 1 + fi + echo "No affected rkyv (< 0.8.17) is reachable; the RUSTSEC-2026-0235 ignore stays justified." + # ── Rust backend — Linux ─────────────────────────────────────────── # Tests use `tauri::test::mock_context` + `noop_assets` + `any_thread()` # in src/speech/tests_integration.rs. Even with MockRuntime, tao's Linux diff --git a/src-tauri/.cargo/audit.toml b/src-tauri/.cargo/audit.toml index 3b593823..6b682512 100644 --- a/src-tauri/.cargo/audit.toml +++ b/src-tauri/.cargo/audit.toml @@ -65,6 +65,28 @@ ignore = [ "RUSTSEC-2025-0100", "RUSTSEC-2025-0119", + # ── Resolver-retained rust_decimal rkyv 0.7 edge (inactive) ───── + # Source: Cargo.lock retains rust_decimal 1.42.1's optional + # `rkyv = "^0.7.46"` dependency even though no AudioGraph feature enables it. + # Blocker: rust_decimal 1.42.1 requires optional rkyv ^0.7.46; patched rkyv + # 0.8.17 is semver-incompatible with that requirement. Manual lock-stanza + # pruning is resolver-unstable because Cargo retains/re-adds the declared + # optional edge. Seed audio-graph-c65d separately owns the independent + # ci/storage-probe lock graph; its resolution is not covered by this ignore. + # Crate: rkyv Title: Insufficient archive validation can cause out-of-bounds + # reads in archives containing Rc/Arc. + # Reachability: `cargo tree --locked --offline -i rkyv@0.7.46 --target all + # --all-features --edges all` prints no reverse dependency; default and + # cloud-only resolution do not contain the package at all. Therefore the + # affected checked archive-access/deserialization APIs are not compiled into + # any current AudioGraph feature set. + # Risk acceptance: lockfile-scanner finding only while that edge stays + # inactive. Do not use this exception if a feature activates rkyv 0.7. + # Remediation: remove immediately if any default/cloud/all-features tree makes + # the command above non-empty. Otherwise remove when rust_decimal drops or + # raises the optional 0.7 requirement so a targeted lock update prunes it. + "RUSTSEC-2026-0235", # rkyv 0.7.46: inactive resolver-retained optional edge + # ── SurrealDB embedded adapter (gated, non-default, conformance-only) ── # Source: transitive via the optional `surrealdb-embedded` feature → # surrealdb 3.1.x → rsa 0.9.10 (pulled by surrealdb's RPC/auth stack). diff --git a/src-tauri/Cargo.lock b/src-tauri/Cargo.lock index 7247d3af..4771b76d 100644 --- a/src-tauri/Cargo.lock +++ b/src-tauri/Cargo.lock @@ -167,9 +167,9 @@ dependencies = [ [[package]] name = "ammonia" -version = "4.1.3" +version = "4.1.4" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "68b9d3370580a12f4b7a10fdcc18b28942c083ba570e3d954fe59d10951b85a2" +checksum = "dc6d763210e2eb7670d1a5183a08bebefa3f97db2a738a684f2ce00bd49f681d" dependencies = [ "cssparser 0.37.0", "html5ever 0.39.0",