Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
37 changes: 37 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -129,6 +129,43 @@ jobs:
working-directory: audio-graph/src-tauri
run: cargo audit

# `ignore` in audit.toml is an unconditional advisory-ID suppression, so a
# stanza whose justification is "this package is unreachable" would keep
# passing after the package became reachable. The RUSTSEC-2026-0235
# (rkyv 0.7.46) stanza states exactly that condition and names this command
# as its own remediation trigger, so assert it here rather than trusting a
# reader to re-run it by hand.
#
# Matched against the advisory's AFFECTED RANGE (patched is ">= 0.8.17"),
# not a pinned version: a check keyed on rkyv@0.7.46 alone would pass
# silently if the lockfile later resolved 0.7.47 or 0.8.10, both still
# vulnerable and both still suppressed by the ID-level ignore.
#
# Version logic unit-checked against synthetic input before landing:
# 0.7.46 and 0.8.16 flag; 0.8.17, 0.9.0, and 1.0.0 do not.
- name: Assert no affected rkyv is reachable
working-directory: audio-graph/src-tauri
run: |
affected="$(
cargo tree --locked --target all --all-features --edges all \
--format '{p}' --prefix none 2>/dev/null \
| awk '
$1 == "rkyv" {
v = $2; sub(/^v/, "", v);
split(v, p, ".");
if ((p[1]+0) == 0 && ((p[2]+0) < 8 || ((p[2]+0) == 8 && (p[3]+0) < 17)))
print $1 " " $2;
}' \
| sort -u
)"
if [ -n "$affected" ]; then
echo "::error::RUSTSEC-2026-0235's ignore in .cargo/audit.toml is justified only while no affected rkyv (< 0.8.17) is reachable, but one now is:"
printf '%s\n' "$affected"
echo "::error::Remove that ignore and resolve the advisory, or replace its justification with one that matches reality."
exit 1
fi
echo "No affected rkyv (< 0.8.17) is reachable; the RUSTSEC-2026-0235 ignore stays justified."

# ── Rust backend — Linux ───────────────────────────────────────────
# Tests use `tauri::test::mock_context` + `noop_assets` + `any_thread()`
# in src/speech/tests_integration.rs. Even with MockRuntime, tao's Linux
Expand Down
22 changes: 22 additions & 0 deletions src-tauri/.cargo/audit.toml
Original file line number Diff line number Diff line change
Expand Up @@ -65,6 +65,28 @@ ignore = [
"RUSTSEC-2025-0100",
"RUSTSEC-2025-0119",

# ── Resolver-retained rust_decimal rkyv 0.7 edge (inactive) ─────
# Source: Cargo.lock retains rust_decimal 1.42.1's optional
# `rkyv = "^0.7.46"` dependency even though no AudioGraph feature enables it.
# Blocker: rust_decimal 1.42.1 requires optional rkyv ^0.7.46; patched rkyv
# 0.8.17 is semver-incompatible with that requirement. Manual lock-stanza
# pruning is resolver-unstable because Cargo retains/re-adds the declared
# optional edge. Seed audio-graph-c65d separately owns the independent
# ci/storage-probe lock graph; its resolution is not covered by this ignore.
# Crate: rkyv Title: Insufficient archive validation can cause out-of-bounds
# reads in archives containing Rc/Arc.
# Reachability: `cargo tree --locked --offline -i rkyv@0.7.46 --target all
# --all-features --edges all` prints no reverse dependency; default and
# cloud-only resolution do not contain the package at all. Therefore the
# affected checked archive-access/deserialization APIs are not compiled into
# any current AudioGraph feature set.
# Risk acceptance: lockfile-scanner finding only while that edge stays
# inactive. Do not use this exception if a feature activates rkyv 0.7.
# Remediation: remove immediately if any default/cloud/all-features tree makes
# the command above non-empty. Otherwise remove when rust_decimal drops or
# raises the optional 0.7 requirement so a targeted lock update prunes it.
"RUSTSEC-2026-0235", # rkyv 0.7.46: inactive resolver-retained optional edge

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Enforce the reachability condition for the rkyv ignore

If a future feature or dependency activates vulnerable rkyv 0.7, this unconditional ID-level suppression will still make the security audit pass: cargo-audit documents ignore as a list of advisory IDs to ignore, while the inspected audit job in .github/workflows/ci.yml:126-130 runs only cargo audit and never asserts the inverse-tree condition described above. Add a CI reachability check that fails when this package becomes active; otherwise the stated risk-acceptance boundary is not enforced.

Useful? React with 👍 / 👎.


Comment thread
coderabbitai[bot] marked this conversation as resolved.
# ── SurrealDB embedded adapter (gated, non-default, conformance-only) ──
# Source: transitive via the optional `surrealdb-embedded` feature →
# surrealdb 3.1.x → rsa 0.9.10 (pulled by surrealdb's RPC/auth stack).
Expand Down
4 changes: 2 additions & 2 deletions src-tauri/Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading