Skip to content

release: libxmtp v1.11.0, FFI 0.2.0, SDK/CLI 0.10.0 - #78

Merged
gitctrlx merged 19 commits into
mainfrom
execute-plan/6906078f-pr-9-release-xmtp-and-xmtp-cli-0100
Aug 27, 2026
Merged

gitctrlx merged 19 commits into
mainfrom
execute-plan/6906078f-pr-9-release-xmtp-and-xmtp-cli-0100

Conversation

@gitctrlx

Copy link
Copy Markdown
Member

Summary

Upgrade qntx/xmtp to libxmtp v1.11.0, ship xmtp-ffi/xmtp-sys 0.2.0, and cut xmtp/xmtp-cli 0.10.0.

This is the linearized execute-plan stack (PLAN_ID 6906078f) as a single merge to main.

Changes

  • Pin rustc 1.97.1; cbindgen only when XMTP_GEN_HEADER=1; dual cargo deny; Makefile FFI targets
  • SHA-256 maps fail-closed when present; zip-slip-safe extract; no XMTP_SKIP_CHECKSUM
  • FFI checked_slice / 32-byte keys; stream join vs free; rustls install_crypto_provider
  • Append-only C ABI encryption_key_len; regenerate header + bindings
  • Remove Client::request_device_sync; explicit send_sync_request; archives; decode-only extra content
  • CLI: always-encrypted profiles (0700/0600); refuse missing db.key; drop --db; xmtp sync / xmtp archive

Breaking

  • ClientBuilder::encryption_key returns Result
  • C ABI appends encryption_key_len
  • Unencrypted CLI profiles are rejected
  • Workspace xmtp-sys 0.2.0 downloads ffi-v0.2.0 (tag that release before relying on crates.io/CI without XMTP_FFI_DIR)

Tests (local)

  • cargo test --manifest-path xmtp-ffi/Cargo.toml --lib — 17 passed
  • XMTP_FFI_DIR=xmtp-ffi/target/debug cargo test -p xmtp-sys --lib -- integrity — 11 passed
  • XMTP_FFI_DIR=... cargo test -p xmtp --lib --all-features — 39 passed (2 ignored network)
  • XMTP_FFI_DIR=... cargo test -p xmtp-cli --all-features — 8 passed
  • XMTP_FFI_DIR=... cargo check --workspace --all-features — ok

Operator follow-up

After merge: git tag ffi-v0.2.0 (or this PR's merge commit) so ffi-build.yml publishes the five staticlibs. Harvest SHA256SUMS into xmtp-sys/sha256sums/0.2.0. Dev smoke before v0.10.0 crates.io publish.

…kefile FFI targets

Pin workspace and xmtp-ffi to rustc 1.97.1, skip cbindgen unless XMTP_GEN_HEADER=1, add dual cargo-deny configs from a real deny run, and make Makefile/Justfile/CONTRIBUTING match the documented FFI workflow.
…en on stable, real cargo-deny, Makefile FFI targets
…xtract

Verify downloaded FFI archives against a committed GNU sha256sum map when the crate version has an entry. Reject zip path traversal. Do not fail closed on 0.1.11.
…meout

Reject non-32-byte encryption keys in the SDK, replace untrusted from_raw_parts with checked slice helpers, make to_c_string report NUL, and leak stream callback context on timeout. No C ABI or version bump.
Pin ffi-build to rustc 1.97.1, add ffi-check and MSRV jobs, drop submodules, upload SHA256SUMS with skip-if-absent compare.
Pin xmtp-ffi git deps to libxmtp v1.11.0 and copy the v1.11.0 crates-io patches (diesel, four hpke crates, tracing-oslog). Compile fixes only; no ABI or version bump.
Append encryption_key_len, add xmtp_stream_join and xmtp_shutdown, regenerate header and bindings, bump xmtp-ffi and xmtp-sys to 0.2.0.
Remove request_device_sync. Add Env history-sync URLs, explicit send_sync_request, archive wrap, decode-only extra content.
New profiles always encrypt (0600 db.key). Refuse missing db.key. Add sync/archive commands and logger wiring.
Bump SDK/CLI to 0.10.0 and record the libxmtp v1.11.0 / ffi 0.2.0 train in CHANGELOG.
Copilot AI lite review requested due to automatic review settings August 27, 2026 02:36

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@gitctrlx

Copy link
Copy Markdown
Member Author

Code review

No issues found. Checked for bugs and CLAUDE.md compliance.

Local tests on bba6a233275f0d6a1324563e442e4e1e40915ccf: xmtp-ffi lib 17 passed; xmtp-sys integrity 11 passed; xmtp lib 39 passed (2 network ignored); xmtp-cli 8 passed; workspace check ok. Guidance file is CONTRIBUTING.md (no CLAUDE.md). Two findings scored 50/100 and were filtered (<80): stale CONTRIBUTING SDK FFI-site bullet vs archive.rs allow-list; write_secret is fs::write then chmod 0600 under a 0700 directory.

🤖 Generated with Claude Code

cargo-deny 0.20 treats --config as unexpected unless passed after --.
Discovery already loads xmtp-ffi/deny.toml from the manifest directory.
Also list archive.rs in the SDK FFI-site convention.
@gitctrlx
gitctrlx merged commit a38805d into main Aug 27, 2026
10 of 13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants