Skip to content

Releases: needletails/binary-codable

v1.1.1

Choose a tag to compare

@Cartisim Cartisim released this 01 Sep 08:09

BinaryCodable 1.1.1

Fixed

  • Alias CurvePrivateKey / CurvePublicKey wire headers to X25519*

v1.1.0

Choose a tag to compare

@Cartisim Cartisim released this 06 Jul 13:14

Release Version 1.1.0

Fixed

  • Wire-header normalization (stdlib-first, reflection cleanup, cross-module arrays)
  • Fixes decode failures

v1.0.5

Choose a tag to compare

@Cartisim Cartisim released this 26 Mar 14:48

Release Version 1.0.5

Fixed

  • Fixed root type-header matching for custom model types inside generic containers (Array, Set, Dictionary) when sender and receiver use different Swift module names.
  • Resolved decode mismatches such as:
    • Array<NudgeServer.UserDeviceConfiguration> vs Array<SessionModels.UserDeviceConfiguration>

Changed

  • Normalization of generic-argument type identity now strips module qualifier chains and compares custom types by simple name in generic contexts.
  • This aligns generic-container behavior with existing non-generic custom-type compatibility semantics.

Compatibility

  • No public API changes.
  • Existing BinaryEncoder / BinaryDecoder usage remains unchanged.
  • Strict compatibility for primitives and standard container shape remains in place.

Tests

  • Added regression test coverage for cross-namespace array decoding:
    • [IRC.AuthPacket] decoded as [Server.AuthPacket]
  • Full test suite passing: 137 tests.

v1.0.4

Choose a tag to compare

@Cartisim Cartisim released this 20 Mar 01:12

Release Version 1.0.4

Highlights

  • Cross-module type headers: Normalizes Swift / Foundation / FoundationEssentials qualifiers in generic wire type names so equivalent stdlib types decode reliably across toolchains.
  • Untrusted-input hardening: Optional decode limits reduce DoS risk from malicious length fields.
  • Regression tests: Broad coverage for normalization, spacing variants, and limit behavior.

New

BinaryDecodingLimits

Configurable caps for decoding (see BinaryDecoder.init(limits:)):

Limit Purpose
maximumInputByteCount Reject oversized Data before parsing
maximumTypeHeaderUTF8ByteCount Cap wire type-name UTF-8 length (always enforced)
maximumStringUTF8ByteCount Cap declared UTF-8 length per string
maximumDataByteCount Cap declared byte length per Data value
maximumCollectionElementCount Cap dictionary key count and array element count

Presets

  • BinaryDecodingLimits.default — prior openness for trusted payloads, with a 256 KiB cap on the type-name header.
  • BinaryDecodingLimits.recommendedForUntrustedInput — starting profile for peer/untrusted blobs (tune per protocol).

BinaryDecoder

  • public init(limits: BinaryDecodingLimits = .default)

Existing BinaryDecoder() call sites remain valid.

Fixed

  • Module splits: Fewer spurious typeMismatch errors when the same logical type reflects as Foundation.* vs FoundationEssentials.* (and related stdlib spellings).
  • Generic whitespace: Type identity comparison ignores insignificant spaces in generic lists (e.g. Dictionary<A,B> vs Dictionary<A, B>).
  • Misconfiguration: Negative optional limits are treated as unset; negative type-header cap falls back to the safe default (262_144).

Security & robustness

  • Decode limits help mitigate allocation / work amplification from untrusted inputs; they are not a substitute for MAC/signature or transport security.
  • README Security section updated with guidance on signing, encryption, replay handling, and how limits fit in.

Tests

  • Added regression tests for:
    • Forged/alternate wire headers (FoundationEssentials, nested generics)
    • Dictionary header spacing variants
    • All limit fields and negative-limit behavior
    • Type mismatch messages referencing normalized identity

Compatibility

  • Wire format: Unchanged for valid payloads produced by existing encoders.
  • API: Backward compatible for typical BinaryDecoder() usage.
  • Behavior: Some invalid or pathological inputs may fail earlier or with clearer errors due to stricter checks.

Upgrade notes

For data from untrusted sources, prefer:

let decoder = BinaryDecoder(limits: .recommendedForUntrustedInput)

v1.0.3

Choose a tag to compare

@Cartisim Cartisim released this 22 Nov 12:17

Full Changelog: 1.0.2...1.0.3

v1.0.2

Choose a tag to compare

@Cartisim Cartisim released this 19 Nov 12:18

Full Changelog: 1.0.1...1.0.2

1.0.1

Choose a tag to compare

@Cartisim Cartisim released this 18 Nov 07:38

Full Changelog: 1.0.0...1.0.1

1.0.0

Choose a tag to compare

@Cartisim Cartisim released this 18 Nov 07:35