From a2377cd947a933d1ca45b886a4805088c2a24ee2 Mon Sep 17 00:00:00 2001 From: devolutionsbot <31221910+devolutionsbot@users.noreply.github.com> Date: Thu, 1 Oct 2026 04:36:38 -0400 Subject: [PATCH 1/2] chore(release): prepare for publishing --- CHANGELOG.md | 30 ++++++++++++++++++++++++++++++ Cargo.lock | 24 ++++++++++++------------ Cargo.toml | 4 ++-- crates/dpapi-web/Cargo.toml | 2 +- crates/dpapi/Cargo.toml | 2 +- crates/winscard/CHANGELOG.md | 10 ++++++++++ crates/winscard/Cargo.toml | 2 +- 7 files changed, 57 insertions(+), 17 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index ca89d5f7..056c9867 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,6 +6,36 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). +## [[0.23.0](https://github.com/Devolutions/sspi-rs/compare/sspi-v0.22.1...sspi-v0.23.0)] - 2026-10-01 + +### Features + +- [**breaking**] Winscard: remove scars cache seed and make it global ([#755](https://github.com/Devolutions/sspi-rs/issues/755)) ([37ebbb8dcd](https://github.com/Devolutions/sspi-rs/commit/37ebbb8dcd07de8bdbacf2662508683213d6590c)) + + Makes smart-card caching process-global while removing cache seeding for system-provided cards. + +### Bug Fixes + +- Use minimal DER for KDC-REQ nonce and AP-REP seq-number ([#759](https://github.com/Devolutions/sspi-rs/issues/759)) ([c724a94076](https://github.com/Devolutions/sspi-rs/commit/c724a940763a115f4458195663aba69c49c20b4f)) + + Fixes intermittent Kerberos failures caused by non-minimal DER nonce encoding and variable-width AP-REP sequence numbers. + +- Isolate credential handles across acquisitions ([#758](https://github.com/Devolutions/sspi-rs/issues/758)) ([f7335d5eaa](https://github.com/Devolutions/sspi-rs/commit/f7335d5eaafb46103eae9bc2ba2fa35812ff08a6)) + + - Give simultaneous credential acquisitions independent handles so a + later password or credential attribute cannot replace an earlier + handle's state. + - Reuse a released handle only when the complete credentials match, + preserving automatic RDP reconnection; exclude mutable package-list + attributes from that match. + - Limit released-handle history to 128 entries and salt its fingerprints + with OS randomness. + - Clarify the opaque FFI handle documentation and add regression tests + for copied handles, changed passwords, attribute changes, and cache + eviction. + + + ## [[0.22.1](https://github.com/Devolutions/sspi-rs/compare/sspi-v0.22.0...sspi-v0.22.1)] - 2026-09-29 ### Bug Fixes diff --git a/Cargo.lock b/Cargo.lock index a9b839c0..2abfacb1 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -1636,9 +1636,9 @@ dependencies = [ [[package]] name = "lazy_static" -version = "1.5.0" +version = "1.5.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "bbd2bcb4c963f2ddae06a2efc7e9f3591312473c50c6685e1f298068316e66fe" +checksum = "20870f649af7073d53e38067b2a84312175d56ea15217e1b15bc83506ec50afb" [[package]] name = "libc" @@ -2103,9 +2103,9 @@ checksum = "a89322df9ebe1c1578d689c92318e070967d1042b512afbe49518723f4e6d5cd" [[package]] name = "pin-utils" -version = "0.1.0" +version = "0.1.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "8b870d8c151b6f2fb93e84a13146138f05d02ed11c7e7c54f8826aaaf7c9f184" +checksum = "13bee6c73da26345c729282832b60b0363cf3dd9f4bfd81d8551b7a1c889a113" [[package]] name = "pkcs1" @@ -2276,9 +2276,9 @@ dependencies = [ [[package]] name = "quinn-proto" -version = "0.11.18" +version = "0.11.19" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "a9746dbde176634f4f2f1faf2404e30a31b2bc1e9cafb5329c95d8177a18c9fc" +checksum = "0e750cca55fe4f0439a15d0bb529da9651e79993e8e72c61a899a36d462befbe" dependencies = [ "bytes", "getrandom 0.4.3", @@ -2298,9 +2298,9 @@ dependencies = [ [[package]] name = "quinn-udp" -version = "0.5.15" +version = "0.5.16" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "35a133f956daabe89a61a685c2649f13d82d5aa4bd5d12d1277e1072a21c0694" +checksum = "af66907df18639dcf4db56ca65490cabc4b27a97dbadd96f2926cca73298f016" dependencies = [ "cfg_aliases", "libc", @@ -2918,7 +2918,7 @@ checksum = "3a0219bd7d979d58245a4f41f695e1ac9f8befdffadd7f61f1bae9e39abc6620" [[package]] name = "sspi" -version = "0.22.1" +version = "0.23.0" dependencies = [ "async-dnssd", "async-recursion", @@ -3927,7 +3927,7 @@ dependencies = [ [[package]] name = "winscard" -version = "0.3.4" +version = "0.4.0" dependencies = [ "base64 0.23.1", "bitflags 2.13.2", @@ -4004,9 +4004,9 @@ dependencies = [ [[package]] name = "yoke-derive" -version = "0.8.3" +version = "0.8.4" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "33811428bee40dbceb6d545e95754741d17a6aef9a4849f0fd62e2ba4f412a78" +checksum = "ec8ebde2db3681e8c9980cc27822030e68752690ddfa9473e739aeb4dbde6d71" dependencies = [ "proc-macro2", "quote", diff --git a/Cargo.toml b/Cargo.toml index dd2048c9..3604c15e 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "sspi" -version = "0.22.1" +version = "0.23.0" edition = "2024" readme = "README.md" license = "MIT OR Apache-2.0" @@ -78,7 +78,7 @@ unused_result_ok = "warn" [workspace.dependencies] ffi-types = { path = "crates/ffi-types" } -winscard = { version = "0.3", path = "crates/winscard" } +winscard = { version = "0.4", path = "crates/winscard" } dpapi = { version = "0.0.0", path = "crates/dpapi" } dpapi-core = { version = "0.1.0", path = "crates/dpapi-core" } diff --git a/crates/dpapi-web/Cargo.toml b/crates/dpapi-web/Cargo.toml index 31718313..c99760f1 100644 --- a/crates/dpapi-web/Cargo.toml +++ b/crates/dpapi-web/Cargo.toml @@ -24,7 +24,7 @@ panic_hook = ["dep:console_error_panic_hook"] # DPAPI dpapi.workspace = true dpapi-transport.workspace = true -sspi = { path = "../..", version = "0.22" } +sspi = { path = "../..", version = "0.23" } # WASM wasm-bindgen = "0.2" diff --git a/crates/dpapi/Cargo.toml b/crates/dpapi/Cargo.toml index 608c268c..1bc2df40 100644 --- a/crates/dpapi/Cargo.toml +++ b/crates/dpapi/Cargo.toml @@ -38,7 +38,7 @@ whoami = "2.1" dpapi-core = { workspace = true, features = ["alloc"] } dpapi-pdu.workspace = true dpapi-transport.workspace = true -sspi = { path = "../..", version = "0.22" } # public +sspi = { path = "../..", version = "0.23" } # public kbkdf = "=0.1.0-rc.1" elliptic-curve = { version = "0.14.0", features = ["sec1", "std"] } diff --git a/crates/winscard/CHANGELOG.md b/crates/winscard/CHANGELOG.md index 691e4881..71944571 100644 --- a/crates/winscard/CHANGELOG.md +++ b/crates/winscard/CHANGELOG.md @@ -6,6 +6,16 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). +## [[0.4.0](https://github.com/Devolutions/sspi-rs/compare/winscard-v0.3.4...winscard-v0.4.0)] - 2026-10-01 + +### Features + +- [**breaking**] Winscard: remove scars cache seed and make it global ([#755](https://github.com/Devolutions/sspi-rs/issues/755)) ([37ebbb8dcd](https://github.com/Devolutions/sspi-rs/commit/37ebbb8dcd07de8bdbacf2662508683213d6590c)) + + Makes smart-card caching process-global while removing cache seeding for system-provided cards. + + + ## [[0.3.4](https://github.com/Devolutions/sspi-rs/compare/winscard-v0.3.3...winscard-v0.3.4)] - 2026-09-15 ### Build diff --git a/crates/winscard/Cargo.toml b/crates/winscard/Cargo.toml index 7404dc59..e0dd3d6d 100644 --- a/crates/winscard/Cargo.toml +++ b/crates/winscard/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "winscard" -version = "0.3.4" +version = "0.4.0" edition = "2024" readme = "README.md" license = "MIT/Apache-2.0" From 66ca9904d3de993a88a45f056fb51f770082c908 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Beno=C3=AEt=20CORTIER?= Date: Thu, 1 Oct 2026 22:46:20 +0900 Subject: [PATCH 2/2] chore(release): clean up changelogs Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- CHANGELOG.md | 23 +++-------------------- crates/winscard/CHANGELOG.md | 8 +++++--- 2 files changed, 8 insertions(+), 23 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 056c9867..30d7ea04 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -10,29 +10,12 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Features -- [**breaking**] Winscard: remove scars cache seed and make it global ([#755](https://github.com/Devolutions/sspi-rs/issues/755)) ([37ebbb8dcd](https://github.com/Devolutions/sspi-rs/commit/37ebbb8dcd07de8bdbacf2662508683213d6590c)) - - Makes smart-card caching process-global while removing cache seeding for system-provided cards. +- [**breaking**] Upgrade `winscard` to 0.4, so the public `From for sspi::Error` conversion now uses the `winscard` 0.4 error type ([#755](https://github.com/Devolutions/sspi-rs/issues/755)) ([37ebbb8dcd](https://github.com/Devolutions/sspi-rs/commit/37ebbb8dcd07de8bdbacf2662508683213d6590c)) ### Bug Fixes -- Use minimal DER for KDC-REQ nonce and AP-REP seq-number ([#759](https://github.com/Devolutions/sspi-rs/issues/759)) ([c724a94076](https://github.com/Devolutions/sspi-rs/commit/c724a940763a115f4458195663aba69c49c20b4f)) - - Fixes intermittent Kerberos failures caused by non-minimal DER nonce encoding and variable-width AP-REP sequence numbers. - -- Isolate credential handles across acquisitions ([#758](https://github.com/Devolutions/sspi-rs/issues/758)) ([f7335d5eaa](https://github.com/Devolutions/sspi-rs/commit/f7335d5eaafb46103eae9bc2ba2fa35812ff08a6)) - - - Give simultaneous credential acquisitions independent handles so a - later password or credential attribute cannot replace an earlier - handle's state. - - Reuse a released handle only when the complete credentials match, - preserving automatic RDP reconnection; exclude mutable package-list - attributes from that match. - - Limit released-handle history to 128 entries and salt its fingerprints - with OS randomness. - - Clarify the opaque FFI handle documentation and add regression tests - for copied handles, changed passwords, attribute changes, and cache - eviction. +- Encode the Kerberos KDC-REQ nonce as a minimal DER positive 32-bit integer, fixing intermittent `KRB_AP_ERR_MODIFIED` failures from Windows KDCs ([#759](https://github.com/Devolutions/sspi-rs/issues/759)) ([c724a94076](https://github.com/Devolutions/sspi-rs/commit/c724a940763a115f4458195663aba69c49c20b4f)) +- Accept AP-REP sequence numbers of any valid DER length, fixing intermittent mutual authentication failures against Windows acceptors ([#759](https://github.com/Devolutions/sspi-rs/issues/759)) ([c724a94076](https://github.com/Devolutions/sspi-rs/commit/c724a940763a115f4458195663aba69c49c20b4f)) diff --git a/crates/winscard/CHANGELOG.md b/crates/winscard/CHANGELOG.md index 71944571..9a3b5e95 100644 --- a/crates/winscard/CHANGELOG.md +++ b/crates/winscard/CHANGELOG.md @@ -10,9 +10,11 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Features -- [**breaking**] Winscard: remove scars cache seed and make it global ([#755](https://github.com/Devolutions/sspi-rs/issues/755)) ([37ebbb8dcd](https://github.com/Devolutions/sspi-rs/commit/37ebbb8dcd07de8bdbacf2662508683213d6590c)) - - Makes smart-card caching process-global while removing cache seeding for system-provided cards. +- Add the `Cache` trait for plugging in a shared, card-scoped smart card resource manager cache ([#755](https://github.com/Devolutions/sspi-rs/issues/755)) ([37ebbb8dcd](https://github.com/Devolutions/sspi-rs/commit/37ebbb8dcd07de8bdbacf2662508683213d6590c)) +- [**breaking**] `ScardContext::new` now takes a `card_id: Uuid` and a `Box`, and seeds the emulated card's cache items only once per card so later minidriver writes are preserved across contexts ([#755](https://github.com/Devolutions/sspi-rs/issues/755)) ([37ebbb8dcd](https://github.com/Devolutions/sspi-rs/commit/37ebbb8dcd07de8bdbacf2662508683213d6590c)) +- [**breaking**] `ScardContext` no longer implements `Clone` ([#755](https://github.com/Devolutions/sspi-rs/issues/755)) ([37ebbb8dcd](https://github.com/Devolutions/sspi-rs/commit/37ebbb8dcd07de8bdbacf2662508683213d6590c)) +- [**breaking**] `SmartCard::new` now takes a `card_id: Uuid`, which is reported as the stable CHUID GUID instead of a random value ([#755](https://github.com/Devolutions/sspi-rs/issues/755)) ([37ebbb8dcd](https://github.com/Devolutions/sspi-rs/commit/37ebbb8dcd07de8bdbacf2662508683213d6590c)) +- `ScardContext` cache reads and writes now honor the freshness counter ([#755](https://github.com/Devolutions/sspi-rs/issues/755)) ([37ebbb8dcd](https://github.com/Devolutions/sspi-rs/commit/37ebbb8dcd07de8bdbacf2662508683213d6590c))