Skip to content

v0.7.0 - iOS and Mac Catalyst, and a faster core on Linux

Choose a tag to compare

@buvinghausen buvinghausen released this 07 Oct 01:26
· 11 commits to master since this release

Notes

0.7.0 brings HyperUuid to iPhone, iPad and Mac Catalyst apps from C#, Swift and Go. On Linux, single UUIDs and batches now get their randomness from a user-space ChaCha20 generator instead of a system call each time, which makes them much faster. The full list is in CHANGELOG.md.

Highlights

  • iOS and Mac Catalyst. These platforms can't load a native library, so the core is linked into the app.

    Language How
    C# A .NET iOS, MAUI or Mac Catalyst app needs only the PackageReference. The package carries the core for ios-arm64, iossimulator-arm64, maccatalyst-arm64 and maccatalyst-x64 (about 7 KB each), and the SDK links it. This works under Mono AOT, the interpreter and Native AOT.
    Swift The package builds for iOS, the iOS simulator and Mac Catalyst on arm64. On those platforms it links the core from a new HyperUuidCoreApple.xcframework, which Xcode can link. Linux, Windows and WebAssembly builds see the same package as before.
    Go cgo builds for an iOS device, the iOS simulator on Apple silicon (-tags iossimulator), and Mac Catalyst on both architectures (maccatalyst, which gomobile sets) each link their own archive from go/staticlib/.

    On every PR, CI tests all three on a Mac against archives built from that commit. The suites run in an iOS simulator and as a Mac Catalyst process, and an iOS device build is linked and checked for the core's symbols.

  • Faster single UUIDs on Linux. new_v4, new_v6 and new_v7 used to call getrandom for every UUID. They now take randomness from a pool of buffered ChaCha20 generators, built like the kernel's own vDSO generator: each key is erased as soon as the next one is made, and every pool slot is reseeded from getrandom.

    • Speedups on linux-x64: new_v4 went from 38 to 23 ns on glibc and from 228 to 24 ns on musl, and new_v6 is 1.3-1.4x faster.
    • Safe across fork: the pool's memory is marked MADV_WIPEONFORK, so a forked child never repeats its parent's bytes.
    • Safe across VM snapshots: no key is used for more than one second of wall-clock time. That covers cloned VMs, Lambda SnapStart, and CRaC or CRIU checkpoints.
    • Fallback: where neither guarantee can be trusted, the core keeps plain getrandom. Other platforms are unchanged.
  • Batches are about 2.5x faster on Linux, and 3.5x on musl. A large v6 or v7 batch makes one 32-byte getrandom call and expands it with a SIMD ChaCha20 keystream. Nothing outlives the call. A 1000-UUID v7 batch went from 10.6 to 4.4 µs on glibc.

  • new_v5 is about 13% faster (54.7 to 47.3 ns). A new test checks it against the uuid crate for every name length up to 300 bytes.

  • Every benchmark table re-measured. Single calls against each platform's own generator:

    • C#: 7.5-10x faster than Guid.NewGuid().
    • Java: 2.8-6.2x faster than UUID.randomUUID().
    • Swift: 11-16x faster than Foundation.UUID().
    • Ruby: 5.5x faster than SecureRandom.uuid for v4.
    • Batches: a 1000-UUID byte fill now costs 3.6-4.9 µs in every binding, down from 9-12 µs.

Fixes

  • Go on Android and iOS no longer links another platform's archive. Go treats GOOS=android as linux and GOOS=ios as darwin, so those builds used to get the Linux or macOS archive at link time. iOS now gets its own archive. Android and the iOS simulator on Intel, which have no archive, now stop with the same named compile error as any other unsupported build.

Upgrade notes

Drop-in for every binding.

  • Go: builds for Android and the Intel iOS simulator now fail at compile time, as other unsupported platforms already did. They never had a working core.
  • Linux kernels before 4.14 (no MADV_WIPEONFORK) keep calling getrandom for single UUIDs, as in 0.6.x.
  • C#: iOS and Mac Catalyst builds need the .NET ios/maccatalyst workloads and the matching Xcode, as any .NET iOS app does.

Verifying

Every native library, static archive and wasm32-wasip1 archive in this release is built by CI and carries a build-provenance attestation. That includes the new iOS and Mac Catalyst archives:

gh attestation verify go/staticlib/ios_arm64/libhyperuuid.a \
  --repo SkunkWerkx/HyperUuid --signer-repo SkunkWerkx/.github

The gems are attested by this repo's own release.yml, so --repo SkunkWerkx/HyperUuid alone verifies them. The Python wheels verify the same way, or with --owner SkunkWerkx.