Skip to content

MA-TUI 0.9.1

Choose a tag to compare

@brdweb brdweb released this 16 Sep 20:20
· 13 commits to main since this release

Patch release for a security advisory that 0.9.0 shipped.

RUSTSEC-2026-0285 — rustls updated to 0.23.45

Rustls accepted TLS 1.3 handshake messages sent at the wrong encryption level.
The handshake transcript stays authenticated, so this could not be used to
alter or complete a handshake; the practical effect is that a peer could send
messages in plaintext that should have been encrypted, without rustls refusing
the connection. It matters if you reach Music Assistant over HTTPS; it is not a
break of TLS.

The advisory was published two days before 0.9.0 and the audit caught it on that
release commit.

Also

  • uuid 1.26.1.
  • The README described a visualizer with a v key, a spectrum panel and a
    full-screen view. None of those exist — the spectrum is part of the player —
    and album art was undocumented. Corrected.
  • The advisory audit runs on main, on demand and weekly rather than on every
    pull request, where an advisory published after a branch opened failed it for
    reasons unrelated to its contents.

Nothing in this release changes how Music Assistant is talked to, beyond the TLS
library.

Install

Download an asset and SHA256SUMS, then verify before installing:

sha256sum --ignore-missing -c SHA256SUMS

Checksums verify file integrity; the packages are not signed, and this is not
a reproducible-build attestation.