Skip to content

chore(openspec): archive nym-prefix-smol-crates change - #6997

Merged
mfahampshire merged 1 commit into
developfrom
chore/archive-nym-prefix-smol-crates
Jul 28, 2026
Merged

chore(openspec): archive nym-prefix-smol-crates change#6997
mfahampshire merged 1 commit into
developfrom
chore/archive-nym-prefix-smol-crates

Conversation

@mfahampshire

@mfahampshire mfahampshire commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

This change is Reviewable

Summary by CodeRabbit

  • Documentation
    • Updated specifications and design documentation to use the new nym- prefixed crate names.
    • Clarified naming conventions for installable crates, product names, directories, and WebAssembly artifacts.
    • Documented QUIC bridge, userspace WireGuard, TCP/IP stack, and command-line tool requirements under the updated names.
    • Confirmed existing APIs, protocol behavior, examples, and published package names remain unchanged.
    • Added validation guidance covering builds, tests, artifact naming, and documentation links.

@vercel

vercel Bot commented Jul 28, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
nym-explorer-v2 Ready Ready Preview, Comment Jul 28, 2026 3:04pm
2 Skipped Deployments
Project Deployment Actions Updated (UTC)
docs-nextra Ignored Ignored Jul 28, 2026 3:04pm
nym-node-status Ignored Ignored Jul 28, 2026 3:04pm

Request Review

@coderabbitai

coderabbitai Bot commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: f6f941d2-45b8-4464-b9ed-ace0bede85bd

📥 Commits

Reviewing files that changed from the base of the PR and between eceff6f and 9993c33.

📒 Files selected for processing (11)
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.md
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/proposal.md
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-quic-bridge/spec.md
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-tools/spec.md
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-tunnel/spec.md
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/smol-core-stack/spec.md
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/tasks.md
  • openspec/specs/dvpn-quic-bridge/spec.md
  • openspec/specs/dvpn-tools/spec.md
  • openspec/specs/dvpn-tunnel/spec.md
  • openspec/specs/smol-core-stack/spec.md

📝 Walkthrough

Walkthrough

The OpenSpec change documents the rename of smol crates to nym-* package and library names, defines wasm naming exceptions, updates archived requirements, and propagates renamed crate references into live specifications.

Changes

Nym-prefixed smol crates

Layer / File(s) Summary
Naming strategy and migration plan
openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/{design.md,proposal.md,tasks.md}
Defines crate rename mappings, product naming exceptions, wasm artifact pinning, specification update rules, verification tasks, and unchanged APIs and identifiers.
Archived specification updates
openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/*
Updates archived DVPN, QUIC, CLI, tunnel, and userspace networking requirements to use the renamed crates.
Live specification references
openspec/specs/{dvpn-quic-bridge,dvpn-tools,dvpn-tunnel,smol-core-stack}/spec.md
Replaces old crate references with nym-smoldvpn and nym-smol-core while retaining surrounding requirements and scenarios.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • nymtech/nym#6953: Renames smol dVPN stack and specification references to nym-* crate names.
  • nymtech/nym#6996: Updates the same DVPN and smol-core OpenSpec documents as part of the crate rename cascade.

Suggested reviewers: merve64, jstuczyn

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title is concise and accurately describes the archived openspec change for the nym-prefix-smol-crates work.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/archive-nym-prefix-smol-crates

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.md`:
- Around line 44-51: The live requirement bodies are duplicated outside the
OpenSpec delta, so retain the delta-only workflow. In
openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.md lines
44-51, preserve the existing guidance; in
openspec/specs/dvpn-quic-bridge/spec.md lines 26-32,
openspec/specs/dvpn-tools/spec.md lines 8-12, openspec/specs/dvpn-tunnel/spec.md
lines 8-11, and openspec/specs/smol-core-stack/spec.md lines 8-11, remove the
direct requirement-body renames and rely on the archived delta applied through
OpenSpec.

In
`@openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-quic-bridge/spec.md`:
- Around line 7-12: Clarify the QUIC bridge certificate validation requirements
in the inline client specification: require the client SNI to match an accepted
certificate subject alternative name, define whether CN is permitted only when
no applicable alt-name exists, and keep hostname validation separate from the
independent Ed25519 SPKI pin check.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: f6f941d2-45b8-4464-b9ed-ace0bede85bd

📥 Commits

Reviewing files that changed from the base of the PR and between eceff6f and 9993c33.

📒 Files selected for processing (11)
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.md
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/proposal.md
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-quic-bridge/spec.md
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-tools/spec.md
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-tunnel/spec.md
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/smol-core-stack/spec.md
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/tasks.md
  • openspec/specs/dvpn-quic-bridge/spec.md
  • openspec/specs/dvpn-tools/spec.md
  • openspec/specs/dvpn-tunnel/spec.md
  • openspec/specs/smol-core-stack/spec.md

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Inline review comments failed to post. This is likely due to GitHub's internal server error or limits when posting large numbers of comments. If you are seeing this consistently it is likely a permissions issue. Please check "Moderation" -> "Code review limits" under your organization settings.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.md`:
- Around line 44-51: The live requirement bodies are duplicated outside the
OpenSpec delta, so retain the delta-only workflow. In
openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.md lines
44-51, preserve the existing guidance; in
openspec/specs/dvpn-quic-bridge/spec.md lines 26-32,
openspec/specs/dvpn-tools/spec.md lines 8-12, openspec/specs/dvpn-tunnel/spec.md
lines 8-11, and openspec/specs/smol-core-stack/spec.md lines 8-11, remove the
direct requirement-body renames and rely on the archived delta applied through
OpenSpec.

In
`@openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-quic-bridge/spec.md`:
- Around line 7-12: Clarify the QUIC bridge certificate validation requirements
in the inline client specification: require the client SNI to match an accepted
certificate subject alternative name, define whether CN is permitted only when
no applicable alt-name exists, and keep hostname validation separate from the
independent Ed25519 SPKI pin check.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: f6f941d2-45b8-4464-b9ed-ace0bede85bd

📥 Commits

Reviewing files that changed from the base of the PR and between eceff6f and 9993c33.

📒 Files selected for processing (11)
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.md
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/proposal.md
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-quic-bridge/spec.md
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-tools/spec.md
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-tunnel/spec.md
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/smol-core-stack/spec.md
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/tasks.md
  • openspec/specs/dvpn-quic-bridge/spec.md
  • openspec/specs/dvpn-tools/spec.md
  • openspec/specs/dvpn-tunnel/spec.md
  • openspec/specs/smol-core-stack/spec.md
🛑 Comments failed to post (2)
openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.md (1)

44-51: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy lift

Keep live requirement edits in the OpenSpec delta only.

The design explicitly requires requirement bodies to propagate through openspec apply, but the same bodies are also edited directly in live specifications. Remove the duplicate live edits and let the archived delta provide the single source of truth.

  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.md#L44-L51: preserve the delta-only requirement-body workflow.
  • openspec/specs/dvpn-quic-bridge/spec.md#L26-L32: remove the direct requirement-body rename and apply the delta.
  • openspec/specs/dvpn-tools/spec.md#L8-L12: remove the direct requirement-body rename and apply the delta.
  • openspec/specs/dvpn-tunnel/spec.md#L8-L11: remove the direct requirement-body rename and apply the delta.
  • openspec/specs/smol-core-stack/spec.md#L8-L11: remove the direct requirement-body rename and apply the delta.

Based on learnings, OpenSpec follow-up updates should use change deltas and normal apply/archive propagation rather than direct live-spec edits.

📍 Affects 5 files
  • openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.md#L44-L51 (this comment)
  • openspec/specs/dvpn-quic-bridge/spec.md#L26-L32
  • openspec/specs/dvpn-tools/spec.md#L8-L12
  • openspec/specs/dvpn-tunnel/spec.md#L8-L11
  • openspec/specs/smol-core-stack/spec.md#L8-L11
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.md` around
lines 44 - 51, The live requirement bodies are duplicated outside the OpenSpec
delta, so retain the delta-only workflow. In
openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/design.md lines
44-51, preserve the existing guidance; in
openspec/specs/dvpn-quic-bridge/spec.md lines 26-32,
openspec/specs/dvpn-tools/spec.md lines 8-12, openspec/specs/dvpn-tunnel/spec.md
lines 8-11, and openspec/specs/smol-core-stack/spec.md lines 8-11, remove the
direct requirement-body renames and rely on the archived delta applied through
OpenSpec.

Source: Learnings

openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-quic-bridge/spec.md (1)

7-12: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "Files matching spec.md:"
fd 'spec\.md$' . | sed -n '1,120p'

echo
echo "Locate target file:"
target="openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-quic-bridge/spec.md"
if [ -f "$target" ]; then
  echo "FOUND $target"
  wc -l "$target"
  echo
  echo "First 80 lines:"
  sed -n '1,80p' "$target" | nl -ba
else
  echo "TARGET NOT FOUND; listing archive path candidates:"
  fd 'dvpn-quic-bridge|spec\.md' openspec 2>/dev/null | sed -n '1,120p'
fi

echo
echo "Search certificate/hostname/SNI/CN/SAN requirements:"
rg -n "SNI|hostname|CN|alt-name|alt.names|SAN|Subject Alternative|SPKI|certificate|pinned" openspec/changes/archive/2026-07-28-nym-prefix-smol-crates -S || true

Repository: nymtech/nym

Length of output: 6351


🏁 Script executed:

#!/bin/bash
set -euo pipefail

target="openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-quic-bridge/spec.md"

echo "Target line count:"
wc -l "$target"

echo
echo "First 80 lines with line numbers:"
awk '{printf "%6d\t%s\n", NR, $0}' "$target" | sed -n '1,80p'

echo
echo "Earlier related dvpn-quic-bridge specs:"
for f in \
  openspec/changes/archive/2026-07-27-smoldvpn-rename/specs/dvpn-quic-bridge/spec.md \
  openspec/changes/archive/2026-05-20-node-families-contract-spec/specs/node-families-contract/spec.md \
  openspec/specs/dvpn-quic-bridge/spec.md
do
  if [ -f "$f" ]; then
    echo "---- $f ($(wc -l < "$f") lines) ----"
    rg -n "SNI|hostname|CN|alt-name|alt.names|SAN|Subject Alternative|SPKI|certificate|pinned" "$f" || true
  fi
done

Repository: nymtech/nym

Length of output: 2783


Define certificate hostname validation precisely.

SNI/CN ∈ alt-names leaves CN fallback and the accepted bridge server name ambiguous. State whether the client SNI must match an accepted alt-name, whether certificate CN is only a fallback, and keep the SPKI pin check separate from hostname validation.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@openspec/changes/archive/2026-07-28-nym-prefix-smol-crates/specs/dvpn-quic-bridge/spec.md`
around lines 7 - 12, Clarify the QUIC bridge certificate validation requirements
in the inline client specification: require the client SNI to match an accepted
certificate subject alternative name, define whether CN is permitted only when
no applicable alt-name exists, and keep hostname validation separate from the
independent Ed25519 SPKI pin check.

@mfahampshire
mfahampshire merged commit 2e06c44 into develop Jul 28, 2026
8 of 10 checks passed
@mfahampshire
mfahampshire deleted the chore/archive-nym-prefix-smol-crates branch July 28, 2026 17:13
@coderabbitai coderabbitai Bot mentioned this pull request Jul 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants