From 531cd8cc333f3bb13a95529a06c971f148dd62be Mon Sep 17 00:00:00 2001 From: RCSnyder <44173311+RCSnyder@users.noreply.github.com> Date: Sat, 15 Aug 2026 20:15:55 -0500 Subject: [PATCH] fix(ci): resolve cargo-deny advisories Update vulnerable crossbeam-epoch and postgres-protocol lockfile entries to patched compatible releases. Keep the stable clippy gate green by avoiding eager-closure lint failures and compiling Linux-only audit state only where it is consumed.\n\nEvidence: cargo deny check advisories bans licenses sources; cargo clippy --all-targets -- -D warnings; cargo fmt --all -- --check; cargo test --all -- --test-threads=1 with PostgreSQL 16. Assisted-by: GitHub-Copilot:Unknown-Model --- Cargo.lock | 10 +++++----- src/runtime/sandbox/bwrap.rs | 2 +- src/runtime/sandbox/mod.rs | 2 +- src/runtime/tools.rs | 5 +++++ 4 files changed, 12 insertions(+), 7 deletions(-) diff --git a/Cargo.lock b/Cargo.lock index 62b1225..123be00 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -618,9 +618,9 @@ dependencies = [ [[package]] name = "crossbeam-epoch" -version = "0.9.18" +version = "0.9.20" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "5b82ac4a3c2ca9c3460964f020e1402edd5753411d7737aa39c3714ad1b5420e" +checksum = "2d6914041f254d6e9176c01941b21115dcfb7089e55135a35411081bd106ef3f" dependencies = [ "crossbeam-utils", ] @@ -2324,9 +2324,9 @@ checksum = "c33a9471896f1c69cecef8d20cbe2f7accd12527ce60845ff44c153bb2a21b49" [[package]] name = "postgres-protocol" -version = "0.6.11" +version = "0.6.12" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "56201207dac53e2f38e848e31b4b91616a6bb6e0c7205b77718994a7f49e70fc" +checksum = "08808e3c483c46e999108051c78334f473d5adb59d78bb80a1268c7e6aa6c514" dependencies = [ "base64", "byteorder", @@ -3529,7 +3529,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "32497e9a4c7b38532efcdebeef879707aa9f794296a4f0244f6f69e9bc8574bd" dependencies = [ "fastrand", - "getrandom 0.4.2", + "getrandom 0.3.4", "once_cell", "rustix", "windows-sys 0.61.2", diff --git a/src/runtime/sandbox/bwrap.rs b/src/runtime/sandbox/bwrap.rs index 591d093..56271b8 100644 --- a/src/runtime/sandbox/bwrap.rs +++ b/src/runtime/sandbox/bwrap.rs @@ -805,7 +805,7 @@ impl ToolExecutor for RealSandbox { // convention `128 + signum` so callers can detect // SIGSYS (signal 31 -> exit_code 159) without a // schema change. - exit_code: out.status.code().unwrap_or_else(|| { + exit_code: out.status.code().unwrap_or({ use std::os::unix::process::ExitStatusExt; out.status.signal().map(|s| 128 + s).unwrap_or(-1) }), diff --git a/src/runtime/sandbox/mod.rs b/src/runtime/sandbox/mod.rs index d3e8ff4..0abaaa2 100644 --- a/src/runtime/sandbox/mod.rs +++ b/src/runtime/sandbox/mod.rs @@ -216,7 +216,7 @@ impl ToolExecutor for ProcessExecutor { // via the POSIX `128 + signum` convention so SIGSYS // (31) appears as exit_code 159 to callers, matching // the bwrap path. - exit_code: out.status.code().unwrap_or_else(|| { + exit_code: out.status.code().unwrap_or({ #[cfg(unix)] { use std::os::unix::process::ExitStatusExt; diff --git a/src/runtime/tools.rs b/src/runtime/tools.rs index 6ba5145..dbcc29a 100644 --- a/src/runtime/tools.rs +++ b/src/runtime/tools.rs @@ -628,6 +628,7 @@ struct ShellExecution { /// terminations are translated to `128 + signum` (POSIX /// convention) so SIGSYS appears as 159. -1 if no code and no /// signal could be observed (e.g. wait error / timeout). + #[cfg(target_os = "linux")] exit_code: i32, #[cfg(target_os = "linux")] audit_pids: Vec, @@ -661,6 +662,7 @@ async fn execute_shell( }; ShellExecution { result: ToolResult::Output(truncated), + #[cfg(target_os = "linux")] exit_code, #[cfg(target_os = "linux")] audit_pids: _audit_pids, @@ -668,18 +670,21 @@ async fn execute_shell( } ExecResult::Timeout => ShellExecution { result: ToolResult::Error("Shell execution timed out".into()), + #[cfg(target_os = "linux")] exit_code: -1, #[cfg(target_os = "linux")] audit_pids: Vec::new(), }, ExecResult::Rejected(reason) => ShellExecution { result: ToolResult::Error(format!("Shell execution rejected: {reason}")), + #[cfg(target_os = "linux")] exit_code: -1, #[cfg(target_os = "linux")] audit_pids: Vec::new(), }, ExecResult::Err(e) => ShellExecution { result: ToolResult::Error(format!("Shell execution failed: {e}")), + #[cfg(target_os = "linux")] exit_code: -1, #[cfg(target_os = "linux")] audit_pids: Vec::new(),