Skip to content

v0.25.1 — audit fix pass (spec version, IDL silent stubs, CLI capabilities, CI gates)

Latest

Choose a tag to compare

@SoundMatt SoundMatt released this 30 Jul 21:29
· 3 commits to main since this release
c472ecb

Fixes 8 of 9 findings from the 2026-07-30 x-Net audit pass, each independently re-verified before applying:

  • kRelaySpecVersion/kSpecVersion: 1.11 → 2.0; dds::kSpecVersion is now a true alias of relay::kRelaySpecVersion instead of an independently hardcoded literal that could drift.
  • IDL generator (src/idl/gen.cpp) now hard-errors instead of silently emitting // TODO: encode/decode stub comments for nil sequence/array element types, unresolved struct references, and cyclic structs.
  • CLI capabilities now advertises "rtps" transport and "loaning"/"tsn" features (RELAY spec §12.2), reflecting shipped functionality that was previously under-reported.
  • from_message no longer silently discards a malformed dds.writer_guid; it clears the GUID and returns ErrSampleRejected.
  • ROADMAP.md/CLAUDE.md: corrected stale spec-version claims, hardcoded per-developer paths, stale close_with_drain() checkbox.
  • CI: removed || true masking from cpfusa init steps; aligned pinned --project-version with the actual project version.

Two CI-gate sub-changes proposed in the same finding were evaluated and not applied because they would have broken CI on every run: raising --sec-tested from 96 to 100 (real coverage measured at 96.7%) and switching cpfusa cyber --write to a --check flag that does not exist on the pinned cpp-FuSa v0.17.1 CLI. See CHANGELOG.md for full detail.

Build verified clean; full suite passes (ctest 666/666).

See CHANGELOG.md for full detail.