Skip to content

Bump hmac, pbkdf2, sha1 and sha2 to the digest 0.11 generation - #475

Merged
Tryanks merged 1 commit into
mainfrom
bump-rustcrypto
Sep 20, 2026
Merged

Tryanks merged 1 commit into
mainfrom
bump-rustcrypto

Conversation

@Tryanks

@Tryanks Tryanks commented Sep 20, 2026

Copy link
Copy Markdown
Owner

Supersedes #468 and #472.

hmac 0.13 and pbkdf2 0.13 are built on digest 0.11, so bumping them alone leaves Hmac<Sha256> without a matching Digest/KeyInit impl for the sha2 0.10 type. This moves the whole RustCrypto set used by crates/remote together: hmac 0.13, pbkdf2 0.13, sha2 0.11 and the optional sha1 0.11.

Source changes are limited to the new API surface:

  • identity.rs: new_from_slice now comes from hmac::KeyInit, which is imported alongside Mac.
  • server.rs: digest 0.11 output arrays no longer implement LowerHex, so the device cache prefix uses the crate's existing encode_hex helper (same lowercase hex output).

ring, rustls and futures-rustls are untouched. Cargo.lock keeps sha2 0.10.9 and sha1 0.10.7 only for their remaining consumers (lb-wry on non-macOS targets, tungstenite 0.27 until #474 lands).

The external wire fixture test (host_proof_matches_the_external_wire_fixture) and the identity/auth tests pass unchanged, so HMAC/PBKDF2 outputs are byte-identical.

Local evidence (macOS arm64):

  • cargo fmt --all --check ✅
  • cargo clippy --workspace --all-targets --locked -- -D warnings ✅
  • cargo build --workspace --locked ✅
  • cargo test --workspace --locked ✅
  • cargo check -p tcode-remote --no-default-features --features server / --features client ✅
  • cargo machete ✅

@Tryanks
Tryanks merged commit 8822e82 into main Sep 20, 2026
6 checks passed
@Tryanks
Tryanks deleted the bump-rustcrypto branch September 20, 2026 12:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant