Skip to content

fix(deps): RUSTSEC-2026-0204 crossbeam-epoch bump — unbreaks cargo-deny on every PR - #5746

Merged
henrypark133 merged 1 commit into
mainfrom
fix-deny-crossbeam
Jul 7, 2026
Merged

henrypark133 merged 1 commit into
mainfrom
fix-deny-crossbeam

Conversation

@henrypark133

Copy link
Copy Markdown
Collaborator

What

Every open PR's cargo-deny check is red. Root cause (reproduced locally, not PR-specific): RUSTSEC-2026-0204 — invalid pointer dereference in crossbeam-epoch 0.9.18's fmt::Pointer impl. Transitive dep (via termimad/crossbeam-deque trees), so per the remediation playbook this is a lockfile bump, not a manifest change: cargo update -p crossbeam-epoch → 0.9.20 (patch, advisory's stated fix version).

Also drops the stale RUSTSEC-2026-0097 ignore — cargo-deny warns advisory-not-detected (the rand pattern left the dependency tree), and the ignore's own comment said revisit by 2026-06-30.

Verification

cargo deny check local: advisories ok, bans ok, licenses ok, sources ok (was advisories FAILED).

Merge-first candidate: unblocks the cargo-deny check on all open PRs once they merge/rebase past it.

🤖 Generated with Claude Code

…drop stale RUSTSEC-2026-0097 ignore

RUSTSEC-2026-0204 (invalid pointer deref in crossbeam-epoch's fmt::Pointer
impl) fails the advisories gate on every PR. Transitive dep → lockfile
bump per the remediation playbook. The 0097 ignore no longer matches any
crate (advisory-not-detected warning) — its rand pattern left the tree.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings July 7, 2026 00:19
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@ironloopai

ironloopai Bot commented Jul 7, 2026 •

Copy link
Copy Markdown
Contributor

✅ IronLoop Review Status

Head: 79c5a27f7f8688d2863f0c481c232a7d84163ab7
Result: 1/1 reviewers completed without blocking findings.
Next: Ready for normal human review and CI checks.
Updated: 2026-07-07T00:21:08.815Z

Current reviewers:

Reviewer State Verdict Findings Last update
ironloop/common-reviewer (reviewer) Completed Approved 0 blocking findings / 0 notes 2026-07-07T00:21:08.645Z
Reviewer summaries
Reviewer Detail
ironloop/common-reviewer (reviewer) Approved; 0 blocking findings; No blocking issues found. The PR is limited to a lockfile bump of crossbeam-epoch from 0.9.18 to 0.9.20 and removal of the stale RUSTSEC-2026-0097 advisory ignore; the changed dep…
Recent activity
Time Reviewer State Detail
2026-07-07T00:19:21.911Z ironloop/common-reviewer (reviewer) Queued Accepted review request for head 79c5a27.
2026-07-07T00:19:21.911Z ironloop/common-reviewer (reviewer) Queued Waiting for this reviewer lane to become available.
2026-07-07T00:19:22.079Z ironloop/common-reviewer (reviewer) Queued Added to the local review work handoff.
2026-07-07T00:19:22.976Z ironloop/common-reviewer (reviewer) Started Reviewer worker started attempt 1.
2026-07-07T00:19:25.928Z ironloop/common-reviewer (reviewer) Workspace ready Prepared isolated checkout (merge_ref) at 9ba3767.
2026-07-07T00:21:03.071Z ironloop/common-reviewer (reviewer) Running Codex is reviewing; process live; elapsed 1m 39s; timeout in 18m 21s; last heartbeat 2026-07-07T00:21:03.071Z. Activity (stderr): ...n every PR. Transitive dep → lockfile bump per the remediation playbook. The 0097 ignore no longer matches any crate….
2026-07-07T00:21:08.645Z ironloop/common-reviewer (reviewer) Result captured Approved; 0 blocking findings.
2026-07-07T00:21:08.645Z ironloop/common-reviewer (reviewer) Completed Review completed and terminal status was persisted.
Available commands
  • @ironloop agents
  • @ironloop review
  • @ironloop review --agent <agent-id-or-alias>
  • @ironloop status
Run metadata

Admission: webhook accepted the request and IronLoop persisted review state before this projection.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5746 July 7, 2026 00:19 Destroyed
@github-actions github-actions Bot added scope: dependencies Dependency updates size: XS < 10 changed lines (excluding docs) risk: low Changes to docs, tests, or low-risk modules labels Jul 7, 2026
@coderabbitai

coderabbitai Bot commented Jul 7, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 783e2804-b736-4d7e-b206-c4e3c6fd7d56

📥 Commits

Reviewing files that changed from the base of the PR and between 15260cb and 79c5a27.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock, !**/Cargo.lock
📒 Files selected for processing (1)
  • deny.toml
💤 Files with no reviewable changes (1)
  • deny.toml

📝 Walkthrough

Summary by CodeRabbit

  • Bug Fixes
    • Updated security settings by removing an outdated ignored advisory, strengthening dependency review coverage.

Walkthrough

Removed the RUSTSEC-2026-0097 entry from the advisories.ignore list in deny.toml, so cargo-deny no longer suppresses that advisory.

Changes

cargo-deny advisory ignore list update

Layer / File(s) Summary
Remove stale ignore entry
deny.toml
Removed the RUSTSEC-2026-0097 entry from [advisories].ignore, so cargo-deny will now flag that advisory instead of suppressing it.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Related PRs: None identified.

Suggested labels: dependencies, security

Suggested reviewers: None identified.

Advisory expired, ignore list trims tight,
Deny.toml sheds one line of night,
No panic, no clippy, no rule to invoke—
Just an old exemption gone up in smoke.

🚥 Pre-merge checks | ✅ 3 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description covers the change and verification, but it omits most required template sections and checklists. Add the template sections: Summary bullets, Change Type, Linked Issue, Security Impact, Blast Radius, Rollback Plan, and Review Follow-Through.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title is Conventional Commits-style and accurately summarizes the dependency bump and cargo-deny fix.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added the contributor: core 20+ merged PRs label Jul 7, 2026

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Verdict: ✅ Approved
Findings: 0 blocking / 0 notes
Next: No reviewer action needed.
Head: 79c5a27f7f8688d2863f0c481c232a7d84163ab7

Run details

Status: Current
Needs human: no
Needs validation: no

**Inline candidates:** 0

Summary

No blocking issues found. The PR is limited to a lockfile bump of crossbeam-epoch from 0.9.18 to 0.9.20 and removal of the stale RUSTSEC-2026-0097 advisory ignore; the changed dependency entry is internally consistent and no changed source behavior was introduced.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloop review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloop review when the fix may affect multiple areas.
  4. Use @ironloop status to check queued/running/completed/stale/stalled state while reviewers run.

@github-actions

github-actions Bot commented Jul 7, 2026

Copy link
Copy Markdown
Contributor

Coverage ratchet

Ratchet mode: ENFORCING

RATCHET PASS: global
  observed: 85.32% (273242 / 320255 lines)
  floor:    85.3% (tolerance 0.5pp -> effective floor 84.8%)
  denominator: 320255 lines now vs 320188 at floor capture (+67 lines, +0.02%) — not a material change

⚠️ 3 Reborn crate(s) have 0 int-tier coverage (target: 0) — ironclaw_prompt_envelope, ironclaw_scripts, ironclaw_skill_learning

Reborn integration-tier coverage

Line coverage (Reborn crates): 85.32% — 273242 / 320255 lines

Per-crate breakdown (65 crates, lowest-covered first)
Crate Line % Covered / Total
ironclaw_prompt_envelope 0% 0 / 88
ironclaw_scripts 0% 0 / 347
ironclaw_skill_learning 0% 0 / 61
ironclaw_wasm_sandbox_core 7.37% 7 / 95
ironclaw_runtime_policy 33.2% 80 / 241
ironclaw_event_projections 43.34% 673 / 1553
ironclaw_run_state 52.73% 222 / 421
ironclaw_authorization 53.54% 461 / 861
ironclaw_triggers 60.32% 1736 / 2878
ironclaw_observability 61.54% 16 / 26
ironclaw_reborn_cli 64.58% 3988 / 6175
ironclaw_webui_v2 65.47% 2391 / 3652
ironclaw_filesystem 65.86% 3212 / 4877
ironclaw_reborn_migration 67.01% 1172 / 1749
ironclaw_memory 67.12% 747 / 1113
ironclaw_dispatcher 67.15% 92 / 137
ironclaw_mcp 67.42% 569 / 844
ironclaw_trust 72.88% 661 / 907
ironclaw_reborn_event_store 73.27% 940 / 1283
ironclaw_capabilities 74.08% 1658 / 2238
ironclaw_wasm_limiter 74.6% 47 / 63
ironclaw_extractors 74.72% 538 / 720
ironclaw_first_party_extensions 77.62% 5410 / 6970
ironclaw_llm 77.67% 19044 / 24519
ironclaw_product_context 78.57% 11 / 14
ironclaw_network 79.82% 621 / 778
ironclaw_wasm_product_adapters 80.58% 1510 / 1874
ironclaw_process_sandbox 80.65% 671 / 832
ironclaw_reborn_openai_compat 80.95% 956 / 1181
ironclaw_memory_native 81.86% 3226 / 3941
ironclaw_secrets 82.33% 2716 / 3299
ironclaw_wasm 82.54% 950 / 1151
ironclaw_events 83.44% 1759 / 2108
ironclaw_processes 84.06% 965 / 1148
ironclaw_host_api 84.5% 3119 / 3691
ironclaw_threads 84.9% 3251 / 3829
ironclaw_turns 85.63% 9819 / 11467
ironclaw_slack_v2_adapter 85.82% 1786 / 2081
ironclaw_projects 85.92% 659 / 767
ironclaw_product_workflow 86.26% 10656 / 12354
ironclaw_auth 86.32% 2727 / 3159
ironclaw_common 86.59% 1472 / 1700
ironclaw_product_adapters 86.66% 3152 / 3637
ironclaw_reborn_config 86.98% 1730 / 1989
ironclaw_hooks 87.25% 9782 / 11211
ironclaw_reborn_traces 87.35% 10325 / 11820
ironclaw_skills 87.36% 4335 / 4962
ironclaw_product_adapter_registry 87.96% 526 / 598
ironclaw_extensions 88.26% 2631 / 2981
ironclaw_reborn_identity 88.43% 344 / 389
ironclaw_reborn_composition 89.01% 68454 / 76908
ironclaw_host_runtime 89.12% 17250 / 19355
ironclaw_conversations 90.11% 2924 / 3245
ironclaw_approvals 90.51% 1507 / 1665
ironclaw_reborn 91.17% 17238 / 18908
ironclaw_event_streams 91.48% 1009 / 1103
ironclaw_reborn_webui_ingress 91.68% 2094 / 2284
ironclaw_loop_support 92.34% 14093 / 15262
ironclaw_attachments 93.06% 630 / 677
ironclaw_telegram_v2_adapter 94.01% 2447 / 2603
ironclaw_resources 94.25% 3625 / 3846
ironclaw_agent_loop 94.49% 8290 / 8773
ironclaw_safety 94.78% 3668 / 3870
ironclaw_first_party_extension_ports 95% 3094 / 3257
ironclaw_outbound 95.59% 3556 / 3720

This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors.

Exemptions (4 entry/entries excluded from the accounting above)
Module / Crate Reason Issue
crate: ironclaw_embeddings v1-only: consumed only by root ironclaw (src/app.rs, src/tools/builtin/memory.rs, src/workspace/mod.rs, src/config/{mod,embeddings}.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_gateway v1-only: consumed only by root ironclaw (src/channels/web/platform/static_files.rs, src/channels/web/handlers/frontend.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_oauth v1-only: consumed only by root ironclaw (src/auth/oauth.rs); no crates/* dependents. Crate's own doc comment confirms v1-only. Covered by "Tests (Legacy)". #5657
crate: ironclaw_tui v1-only: consumed only by root ironclaw (src/main.rs, src/channels/tui.rs); no crates/* dependents. Crate's own doc comment confirms it bridges INTO v1, not Reborn. Covered by "Tests (Legacy)". #5657

@henrypark133
henrypark133 merged commit 5787897 into main Jul 7, 2026
61 of 62 checks passed
@henrypark133
henrypark133 deleted the fix-deny-crossbeam branch July 7, 2026 00:55

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-5746 — 79c5a27f Deployed Jul 7, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules scope: dependencies Dependency updates size: XS < 10 changed lines (excluding docs)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants