Skip to content

deps: Bump vgi-rpc from 0.16.0 to 0.25.0 - #30

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/vgi-rpc-0.25.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/vgi-rpc-0.25.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor

Bumps vgi-rpc from 0.16.0 to 0.25.0.

Release notes

Sourced from vgi-rpc's releases.

v0.25.0

This is the multi-protocol (VGI 2.0) round. Three changes break the wire; each is listed with what to do about it. Rust now produces byte-identical protocol hashes to the Python reference, to Go, and to TypeScript, for all 88 conformance methods.

Upgrade note — this port's tokens are not rotated, and that is the divergence

Short version: upgrading a Rust-only deployment breaks no tokens. Cursor, call and sticky-session tokens minted by 0.24.4 all still open on 0.25.0, so a rolling upgrade needs no draining of open HTTP streams or sticky sessions. Read on only if you run a mixed-language fleet.

This is worth spelling out because the sibling ports went the other way. The Python reference and the TypeScript port rotated their AEAD associated data in this same window — prefixes bumped (vgi_rpc.state.v4/v5 → v6/v7, vgi_rpc.call.v1/v2 → v3/v4, and sticky sessions along with them) and a trailing protocol scope appended, so the break there is over-determined and every token class is a casualty. This port made neither change. Verified in source rather than assumed; all three AAD builders here are unchanged:

Token Builder Prefixes (unchanged)
Stream cursor compute_aad, vgi-rpc/src/http.rs vgi_rpc.state.v5\x00 / vgi_rpc.state.v4\x00
Call token compute_call_aad, vgi-rpc/src/http.rs vgi_rpc.call.v2\x00 / vgi_rpc.call.v1\x00
Sticky session compute_session_aad, vgi-rpc/src/sticky.rs vgi_rpc.session.v2\x00 / vgi_rpc.session.v1\x00

(The v5/v2/v2 spellings are the peer-evidence-bound variants; the lower number is used otherwise.) Note that sticky sessions do not share an AAD builder with the cursor and call tokens in this port — sticky.rs defines its own, structurally identical but separately maintained. A port-to-port comparison that assumes one shared builder will mis-describe this one.

No builder appends a protocol scope. compute_aad_with is prefix, then either the authenticated domain and principal or the anonymous marker, then an optional peer-evidence binding — and compute_session_aad mirrors it. So in this port the separation between co-hosted protocols is enforced by the path and the routing key, not by the AEAD tag: it is not the cryptography that refuses a cursor replayed onto another protocol's /exchange. That is unchanged from 0.24.4 rather than new, but multi-protocol hosting is what makes it reachable, and it is the gap the reference closed by binding the protocol into the AAD.

Two practical consequences:

  • A mixed-language fleet sharing a token_key can no longer resume across the language boundary. A cursor, call or session token minted by a reference Python or TypeScript worker on the rotated AAD fails this port's tag check, and vice versa. It surfaces as Malformed state token (or

... (truncated)

Changelog

Sourced from vgi-rpc's changelog.

[0.25.0] — 2026-09-16

This is the multi-protocol (VGI 2.0) round. Three changes break the wire; each is listed with what to do about it. Rust now produces byte-identical protocol hashes to the Python reference, to Go, and to TypeScript, for all 88 conformance methods.

Upgrade note — this port's tokens are not rotated, and that is the divergence

Short version: upgrading a Rust-only deployment breaks no tokens. Cursor, call and sticky-session tokens minted by 0.24.4 all still open on 0.25.0, so a rolling upgrade needs no draining of open HTTP streams or sticky sessions. Read on only if you run a mixed-language fleet.

This is worth spelling out because the sibling ports went the other way. The Python reference and the TypeScript port rotated their AEAD associated data in this same window — prefixes bumped (vgi_rpc.state.v4/v5 → v6/v7, vgi_rpc.call.v1/v2 → v3/v4, and sticky sessions along with them) and a trailing protocol scope appended, so the break there is over-determined and every token class is a casualty. This port made neither change. Verified in source rather than assumed; all three AAD builders here are unchanged:

Token Builder Prefixes (unchanged)
Stream cursor compute_aad, vgi-rpc/src/http.rs vgi_rpc.state.v5\x00 / vgi_rpc.state.v4\x00
Call token compute_call_aad, vgi-rpc/src/http.rs vgi_rpc.call.v2\x00 / vgi_rpc.call.v1\x00
Sticky session compute_session_aad, vgi-rpc/src/sticky.rs vgi_rpc.session.v2\x00 / vgi_rpc.session.v1\x00

(The v5/v2/v2 spellings are the peer-evidence-bound variants; the lower number is used otherwise.) Note that sticky sessions do not share an AAD builder with the cursor and call tokens in this port — sticky.rs defines its own, structurally identical but separately maintained. A port-to-port comparison that assumes one shared builder will mis-describe this one.

No builder appends a protocol scope. compute_aad_with is prefix, then either the authenticated domain and principal or the anonymous marker, then an optional peer-evidence binding — and compute_session_aad mirrors it. So in this port the separation between co-hosted protocols is enforced by the path and the routing key, not by the AEAD tag: it is not the cryptography that refuses a cursor replayed onto another protocol's /exchange. That is unchanged from 0.24.4 rather than new, but multi-protocol hosting is what makes it reachable, and it is the gap the reference closed by binding the protocol into the AAD.

Two practical consequences:

  • A mixed-language fleet sharing a token_key can no longer resume across the language boundary. A cursor, call or session token minted by a reference Python or TypeScript worker on the rotated AAD fails this port's tag check, and vice versa. It surfaces as Malformed state token (or

... (truncated)

Commits
  • 41fc0a8 changelog: state what this port did not rotate, and why that is the hazard
  • 2e94dee Release 0.25.0
  • 8c8722f The byte-stream client resolved no external pointers at all
  • f4c7b02 conformance: drive the shared client harness instead of a private copy
  • 165bbf8 CI: compare this port's protocol description to the reference
  • 85a7d9f The Rust client could not address the reference server
  • 3340ed3 conformance: wire the vgi_rpc.Identity.v1 fixtures
  • 9387e27 Reflection describes its own two methods
  • 9fd0500 changelog: the HTTP-streaming gap is closed, not known
  • 87b839c HTTP streams emit access records, one per turn
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [vgi-rpc](https://github.com/Query-farm/vgi-rpc-rust) from 0.16.0 to 0.25.0.
- [Release notes](https://github.com/Query-farm/vgi-rpc-rust/releases)
- [Changelog](https://github.com/Query-farm/vgi-rpc-rust/blob/main/CHANGELOG.md)
- [Commits](Query-farm/vgi-rpc-rust@v0.16.0...v0.25.0)

---
updated-dependencies:
- dependency-name: vgi-rpc
  dependency-version: 0.25.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 21, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #31.

@dependabot dependabot Bot closed this Sep 28, 2026
@dependabot
dependabot Bot deleted the dependabot/cargo/vgi-rpc-0.25.0 branch September 28, 2026 10:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants