release: libxmtp v1.11.0, FFI 0.2.0, SDK/CLI 0.10.0 - #78
Merged
gitctrlx merged 19 commits intoAug 27, 2026
Merged
Conversation
…kefile FFI targets Pin workspace and xmtp-ffi to rustc 1.97.1, skip cbindgen unless XMTP_GEN_HEADER=1, add dual cargo-deny configs from a real deny run, and make Makefile/Justfile/CONTRIBUTING match the documented FFI workflow.
…en on stable, real cargo-deny, Makefile FFI targets
…xtract Verify downloaded FFI archives against a committed GNU sha256sum map when the crate version has an entry. Reject zip path traversal. Do not fail closed on 0.1.11.
…only when present) and zip-slip extract
…meout Reject non-32-byte encryption keys in the SDK, replace untrusted from_raw_parts with checked slice helpers, make to_c_string report NUL, and leak stream callback context on timeout. No C ABI or version bump.
…ion-key length, stream leak-on-timeout
Pin ffi-build to rustc 1.97.1, add ffi-check and MSRV jobs, drop submodules, upload SHA256SUMS with skip-if-absent compare.
…ty, 1.97.1 compile, nightly fmt
Pin xmtp-ffi git deps to libxmtp v1.11.0 and copy the v1.11.0 crates-io patches (diesel, four hpke crates, tracing-oslog). Compile fixes only; no ABI or version bump.
Append encryption_key_len, add xmtp_stream_join and xmtp_shutdown, regenerate header and bindings, bump xmtp-ffi and xmtp-sys to 0.2.0.
Remove request_device_sync. Add Env history-sync URLs, explicit send_sync_request, archive wrap, decode-only extra content.
New profiles always encrypt (0600 db.key). Refuse missing db.key. Add sync/archive commands and logger wiring.
Bump SDK/CLI to 0.10.0 and record the libxmtp v1.11.0 / ffi 0.2.0 train in CHANGELOG.
Member
Author
Code reviewNo issues found. Checked for bugs and CLAUDE.md compliance. Local tests on 🤖 Generated with Claude Code |
cargo-deny 0.20 treats --config as unexpected unless passed after --. Discovery already loads xmtp-ffi/deny.toml from the manifest directory. Also list archive.rs in the SDK FFI-site convention.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Upgrade
qntx/xmtpto libxmtp v1.11.0, shipxmtp-ffi/xmtp-sys0.2.0, and cutxmtp/xmtp-cli0.10.0.This is the linearized execute-plan stack (
PLAN_ID6906078f) as a single merge tomain.Changes
XMTP_GEN_HEADER=1; dualcargo deny; Makefile FFI targetsXMTP_SKIP_CHECKSUMchecked_slice/ 32-byte keys; streamjoinvsfree; rustlsinstall_crypto_providerencryption_key_len; regenerate header + bindingsClient::request_device_sync; explicitsend_sync_request; archives; decode-only extra content0700/0600); refuse missingdb.key; drop--db;xmtp sync/xmtp archiveBreaking
ClientBuilder::encryption_keyreturnsResultencryption_key_lenxmtp-sys0.2.0 downloadsffi-v0.2.0(tag that release before relying on crates.io/CI withoutXMTP_FFI_DIR)Tests (local)
cargo test --manifest-path xmtp-ffi/Cargo.toml --lib— 17 passedXMTP_FFI_DIR=xmtp-ffi/target/debug cargo test -p xmtp-sys --lib -- integrity— 11 passedXMTP_FFI_DIR=... cargo test -p xmtp --lib --all-features— 39 passed (2 ignored network)XMTP_FFI_DIR=... cargo test -p xmtp-cli --all-features— 8 passedXMTP_FFI_DIR=... cargo check --workspace --all-features— okOperator follow-up
After merge:
git tag ffi-v0.2.0(or this PR's merge commit) soffi-build.ymlpublishes the five staticlibs. HarvestSHA256SUMSintoxmtp-sys/sha256sums/0.2.0. Dev smoke beforev0.10.0crates.io publish.