ROneCOne 1.10.2
ROneCOne 1.10.2
This release adds a security policy and scans every change, and every release, with olevba and
mraptor. The runtime renames one private constant that both tools read as code that runs on its
own. Behavior and the public surface are unchanged, so upgrading is a drop-in replacement.
Added
SECURITY.md explains how to report a vulnerability privately, from the repository's Security
tab, and what the runtime can reach: the network through HttpClient and Xml.Load, commands
through Process, the files and databases your code names, and Windows APIs in four libraries,
each only when your code calls it. The README gains CI and Security badges and a Security section.
A Security workflow scans ROneCOne.cls and every demo workbook with olevba and MacroRaptor
(mraptor) on every push and pull request, and holds each file's results to a reviewed baseline.
It fails on a finding that appears or disappears, on changed mraptor flags, on code that runs on
its own, and on P-code that its source does not explain. mraptor rates every file Macro OK, with
flags -WX: the runtime writes files and memory and runs COM objects, commands, and Windows APIs
by design, and nothing in it runs on its own.
Each release from this one on carries a security report beside its SHA-256 manifest, here
v1.10.2-security-report.md. A workflow writes it from the published assets: each file's hash,
olevba findings, and mraptor verdict, and how they compare with the baseline at the release tag.
Changed
The runtime's private constant for a file watcher's change record is ROLE_FILE_EVENT rather
than ROLE_FILE_CHANGE. olevba and mraptor treat any name ending in _Change as an ActiveX
event handler, so they reported the runtime and every demo workbook as code that runs when the
file opens. None of them does.
Fixed
The demo worksheets' code cells hold only VBA. Three cells mixed English into the code, and the
Exceptions clean-import row wrote a fixed string where it now checks the trace for a skipped row.
Rows on the Files, Process, Query, Collections, and Zip sheets now show the calls the demo makes,
among them ReadAllText(helloPath) for the Files text row and a single sort for the Process
standard-input row. Start Here and Benchmarks titles say "and" where they said "+", the Excel
Table demo names its feature "Excel Tables", and benchmark counts show thousands separators.
The Zip demo's benchmark inflates a 50,000-line file rather than a 1,000-line one. VBA's Timer
returns a Single, which moves in 1/128-second steps after 18:12, and the smaller file inflated
inside one step often enough that about one evening run in three measured zero seconds and the
demo runner failed it. The benchmark now takes about 0.09 seconds against its 5-second gate.
Development
CI runs the newest pyVBAanalysis release, and the local pin moves from 2.2.0 to 2.3.1. That
release stops reporting the runtime's Item property, a Variant Property Get beside an Object
Property Set that Excel compiles. Its new --whole-project flag analyzes ROneCOne.cls alone,
as the complete project a user imports. In the combined run over the runtime, tests, and demos,
a call from the runtime into a test or demo module would resolve.
The live suite's hash-set read scenario makes 100,000 reads, ten passes over its 10,000 items.
One pass took about one Timer step in the evening, so it could have read zero.
Release evidence
Each of three fresh Microsoft 365 Excel processes passed all 1005 live assertions, and all ten
suite benchmark scenarios met their release gates in every sample. The medians ran invocation
0.11, collection 0.16, ordering 0.92, dictionary build and read 0.13, 100,000 indexed lookups
0.28, keyed mutation 0.66, 10,000 list writes 0.06, 2,000 row reads 0.06, 100,000 hash set reads
0.10, and constrained maintenance 0.50 seconds.
The Zip workbook was rebuilt from its builder. All sixteen were repackaged with the stamped
modules and run in place, and all 205 of their examples passed. An AutoFit check in Excel over
every cell reported what it reported for 1.10.1: only the two Text digests, which wrap inside rows
sized to hold them. Every rendered sheet was reviewed. The VBE casing round trip over the runtime,
all eighteen demo modules, and a host module brought every token back as written.
Static analysis on pyVBAanalysis 2.3.1 reported zero diagnostics across the runtime source, the
runtime on its own, the live test modules, the demo modules, and all sixteen final workbooks, with
inline suppressions disabled. olevba and mraptor found exactly the reviewed baseline in the
runtime and every workbook. 96 Python contract tests pass. Every packaged VBA module
round-tripped byte-for-byte, and after Excel saved each workbook, its modules still match their
sources apart from the VBE joining 27 continued Attribute lines in the runtime.