chore(openspec): archive nym-prefix-smol-crates change - #6997
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
2 Skipped Deployments
|
ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (11)
📝 WalkthroughWalkthroughThe OpenSpec change documents the rename of smol crates to ChangesNym-prefixed smol crates
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.md`:
- Around line 44-51: The live requirement bodies are duplicated outside the
OpenSpec delta, so retain the delta-only workflow. In
openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.md lines
44-51, preserve the existing guidance; in
openspec/specs/dvpn-quic-bridge/spec.md lines 26-32,
openspec/specs/dvpn-tools/spec.md lines 8-12, openspec/specs/dvpn-tunnel/spec.md
lines 8-11, and openspec/specs/smol-core-stack/spec.md lines 8-11, remove the
direct requirement-body renames and rely on the archived delta applied through
OpenSpec.
In
`@openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-quic-bridge/spec.md`:
- Around line 7-12: Clarify the QUIC bridge certificate validation requirements
in the inline client specification: require the client SNI to match an accepted
certificate subject alternative name, define whether CN is permitted only when
no applicable alt-name exists, and keep hostname validation separate from the
independent Ed25519 SPKI pin check.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: f6f941d2-45b8-4464-b9ed-ace0bede85bd
📒 Files selected for processing (11)
openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.mdopenspec/changes/archive/2026-07-28-nym-prefix-smol-crates/proposal.mdopenspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-quic-bridge/spec.mdopenspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-tools/spec.mdopenspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-tunnel/spec.mdopenspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/smol-core-stack/spec.mdopenspec/changes/archive/2026-07-28-nym-prefix-smol-crates/tasks.mdopenspec/specs/dvpn-quic-bridge/spec.mdopenspec/specs/dvpn-tools/spec.mdopenspec/specs/dvpn-tunnel/spec.mdopenspec/specs/smol-core-stack/spec.md
There was a problem hiding this comment.
Caution
Inline review comments failed to post. This is likely due to GitHub's internal server error or limits when posting large numbers of comments. If you are seeing this consistently it is likely a permissions issue. Please check "Moderation" -> "Code review limits" under your organization settings.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.md`:
- Around line 44-51: The live requirement bodies are duplicated outside the
OpenSpec delta, so retain the delta-only workflow. In
openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.md lines
44-51, preserve the existing guidance; in
openspec/specs/dvpn-quic-bridge/spec.md lines 26-32,
openspec/specs/dvpn-tools/spec.md lines 8-12, openspec/specs/dvpn-tunnel/spec.md
lines 8-11, and openspec/specs/smol-core-stack/spec.md lines 8-11, remove the
direct requirement-body renames and rely on the archived delta applied through
OpenSpec.
In
`@openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-quic-bridge/spec.md`:
- Around line 7-12: Clarify the QUIC bridge certificate validation requirements
in the inline client specification: require the client SNI to match an accepted
certificate subject alternative name, define whether CN is permitted only when
no applicable alt-name exists, and keep hostname validation separate from the
independent Ed25519 SPKI pin check.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: f6f941d2-45b8-4464-b9ed-ace0bede85bd
📒 Files selected for processing (11)
openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.mdopenspec/changes/archive/2026-07-28-nym-prefix-smol-crates/proposal.mdopenspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-quic-bridge/spec.mdopenspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-tools/spec.mdopenspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-tunnel/spec.mdopenspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/smol-core-stack/spec.mdopenspec/changes/archive/2026-07-28-nym-prefix-smol-crates/tasks.mdopenspec/specs/dvpn-quic-bridge/spec.mdopenspec/specs/dvpn-tools/spec.mdopenspec/specs/dvpn-tunnel/spec.mdopenspec/specs/smol-core-stack/spec.md
🛑 Comments failed to post (2)
openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.md (1)
44-51: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy lift
Keep live requirement edits in the OpenSpec delta only.
The design explicitly requires requirement bodies to propagate through
openspec apply, but the same bodies are also edited directly in live specifications. Remove the duplicate live edits and let the archived delta provide the single source of truth.
openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.md#L44-L51: preserve the delta-only requirement-body workflow.openspec/specs/dvpn-quic-bridge/spec.md#L26-L32: remove the direct requirement-body rename and apply the delta.openspec/specs/dvpn-tools/spec.md#L8-L12: remove the direct requirement-body rename and apply the delta.openspec/specs/dvpn-tunnel/spec.md#L8-L11: remove the direct requirement-body rename and apply the delta.openspec/specs/smol-core-stack/spec.md#L8-L11: remove the direct requirement-body rename and apply the delta.Based on learnings, OpenSpec follow-up updates should use change deltas and normal apply/archive propagation rather than direct live-spec edits.
📍 Affects 5 files
openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.md#L44-L51(this comment)openspec/specs/dvpn-quic-bridge/spec.md#L26-L32openspec/specs/dvpn-tools/spec.md#L8-L12openspec/specs/dvpn-tunnel/spec.md#L8-L11openspec/specs/smol-core-stack/spec.md#L8-L11🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.md` around lines 44 - 51, The live requirement bodies are duplicated outside the OpenSpec delta, so retain the delta-only workflow. In openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.md lines 44-51, preserve the existing guidance; in openspec/specs/dvpn-quic-bridge/spec.md lines 26-32, openspec/specs/dvpn-tools/spec.md lines 8-12, openspec/specs/dvpn-tunnel/spec.md lines 8-11, and openspec/specs/smol-core-stack/spec.md lines 8-11, remove the direct requirement-body renames and rely on the archived delta applied through OpenSpec.Source: Learnings
openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-quic-bridge/spec.md (1)
7-12: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash set -euo pipefail echo "Files matching spec.md:" fd 'spec\.md$' . | sed -n '1,120p' echo echo "Locate target file:" target="openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-quic-bridge/spec.md" if [ -f "$target" ]; then echo "FOUND $target" wc -l "$target" echo echo "First 80 lines:" sed -n '1,80p' "$target" | nl -ba else echo "TARGET NOT FOUND; listing archive path candidates:" fd 'dvpn-quic-bridge|spec\.md' openspec 2>/dev/null | sed -n '1,120p' fi echo echo "Search certificate/hostname/SNI/CN/SAN requirements:" rg -n "SNI|hostname|CN|alt-name|alt.names|SAN|Subject Alternative|SPKI|certificate|pinned" openspec/changes/archive/2026-07-28-nym-prefix-smol-crates -S || trueRepository: nymtech/nym
Length of output: 6351
🏁 Script executed:
#!/bin/bash set -euo pipefail target="openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-quic-bridge/spec.md" echo "Target line count:" wc -l "$target" echo echo "First 80 lines with line numbers:" awk '{printf "%6d\t%s\n", NR, $0}' "$target" | sed -n '1,80p' echo echo "Earlier related dvpn-quic-bridge specs:" for f in \ openspec/changes/archive/2026-07-27-smoldvpn-rename/specs/dvpn-quic-bridge/spec.md \ openspec/changes/archive/2026-05-20-node-families-contract-spec/specs/node-families-contract/spec.md \ openspec/specs/dvpn-quic-bridge/spec.md do if [ -f "$f" ]; then echo "---- $f ($(wc -l < "$f") lines) ----" rg -n "SNI|hostname|CN|alt-name|alt.names|SAN|Subject Alternative|SPKI|certificate|pinned" "$f" || true fi doneRepository: nymtech/nym
Length of output: 2783
Define certificate hostname validation precisely.
SNI/CN ∈ alt-namesleaves CN fallback and the accepted bridge server name ambiguous. State whether the client SNI must match an accepted alt-name, whether certificate CN is only a fallback, and keep the SPKI pin check separate from hostname validation.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-quic-bridge/spec.md` around lines 7 - 12, Clarify the QUIC bridge certificate validation requirements in the inline client specification: require the client SNI to match an accepted certificate subject alternative name, define whether CN is permitted only when no applicable alt-name exists, and keep hostname validation separate from the independent Ed25519 SPKI pin check.
This change is
Summary by CodeRabbit
nym-prefixed crate names.