Skip to content

fix(deps): bump event-listener to 5.4.2 (RUSTSEC-2026-0221) - #208

Closed
dshakes wants to merge 1 commit into
masterfrom
fix/rustsec-2026-0221
Closed

dshakes wants to merge 1 commit into
masterfrom
fix/rustsec-2026-0221

Conversation

@dshakes

@dshakes dshakes commented Jul 31, 2026

Copy link
Copy Markdown
Owner

Lockfile-only. event-listener 5.4.1 → 5.4.2, clearing RUSTSEC-2026-0221 (!Send tags crossing thread boundaries via StackSlot, published 2026-07-13). It reaches runtime-manager transitively via async-broadcast, so no manifest edit and no API surface touched.

Turned up when the vuln gate went red on an unrelated PR — the advisory DB picked it up between this morning's runs and this afternoon's, so it fails on master too.

Not fixed here: RUSTSEC-2026-0222 (wasmtime)

cargo audit still reports wasmtime 45.0.3 — "Stores can mix up type indices between engines". Every patched line the advisory allows (46.0.2+, 47.0.3+) pulls cranelift crates that require Rust 1.94, while the repo pins 1.93 in rust-toolchain.toml, two CI workflows, and the service Dockerfiles.

That is a cross-cutting toolchain bump and needs its own decision — so vuln stays red until it's made.

Verification

  • cargo audit no longer reports 0221
  • cargo build --release clean

`event-listener` 5.4.1 allows `!Send` tags to cross thread boundaries via
`StackSlot` (RUSTSEC-2026-0221, published 2026-07-13). It reaches the
runtime-manager transitively through async-broadcast, so this is a lockfile-only
change: no manifest edit, no API surface touched.

Turned up when the vuln gate went red on an unrelated PR — the advisory database
picked it up between this morning's runs and this afternoon's, so it now fails on
master too.

This clears RUSTSEC-2026-0221 only. `cargo audit` still reports RUSTSEC-2026-0222
(wasmtime 45.0.3, "Stores can mix up type indices between engines"), which is NOT
fixable the same way: every patched line the advisory allows — 46.0.2+ and
47.0.3+ — pulls cranelift crates requiring Rust 1.94, while the repo pins 1.93 in
rust-toolchain.toml, two CI workflows, and the service Dockerfiles. That is a
cross-cutting toolchain decision and gets its own change rather than riding along
here.

Verified: cargo audit no longer reports 0221, release build clean.
@github-actions github-actions Bot added the domain:infra Touches infra / CI / deploy / migrations label Jul 31, 2026
@compass-sdlc-bot compass-sdlc-bot Bot added the agent:reviewed-clean Reviewer found no Blocking issues this round label Jul 31, 2026
@github-actions

Copy link
Copy Markdown
Contributor

🔎 Codex cross-audit (agent:audit)

No Blocking findings.

I found no correctness, security, or edge-case regressions introduced by this PR. The only change is services/runtime-manager/Cargo.lock, updating event-listener from 5.4.1 to 5.4.2 and removing its now-unused transitive concurrent-queue entry. No remaining lockfile or manifest references to concurrent-queue were found.

Verification:

  • Reviewed git diff origin/master...HEAD
  • Checked changed dependency references with rg
  • git diff --check origin/master...HEAD passed
  • Could not run cargo metadata --locked because the read-only sandbox prevents rustup from creating its temp file under /home/runner/.rustup/tmp before Cargo starts.

@github-actions

Copy link
Copy Markdown
Contributor

🔷 Gemini cross-audit (agent:audit-gemini)

Based on an audit of the unified diff in pr-diff.patch, there is a major Blocking correctness issue and security anti-pattern.


1. 🛑 Malformed Cargo.lock & Broken Dependency Graph (BLOCKING)

  • The Regression: The PR manually modifies services/runtime-manager/Cargo.lock to upgrade event-listener from 5.4.1 to 5.4.2, while concurrently deleting concurrent-queue and stripping it from event-listener's dependencies.
  • Why it is Broken: event-listener (including version 5.4.2) requires concurrent-queue under its default features (specifically the queue feature which is enabled by default under std).
  • Impact:
    1. Build Failure: In CI environments (or local builds using the --locked flag), cargo will fail to compile the service due to an inconsistent lockfile / missing transitive dependency.
    2. Auto-Revert: In typical local builds, Cargo will detect the missing dependency and automatically regenerate Cargo.lock, re-adding concurrent-queue and its sub-dependencies, completely undoing the changes in this PR.

2. ⚠️ Security Implications (Vulnerability Evasion)

  • Lockfile Manipulation: Manually stripping a transitive dependency from Cargo.lock while leaving it in the actual build path is a classic evasion technique used to bypass security scan tools (such as cargo-audit or static analysis gates).
  • The Risk: While concurrent-queue version 2.5.0 has no active CVEs, bypassing compliance/vulnerability scanning through lockfile obfuscation must be rejected. The compiled binary will still include concurrent-queue once cargo compiles the dependency tree.

3. 🔍 Missed Edge Cases & Maintenance Issues

  • Orphaned Sub-dependencies: concurrent-queue depends on crossbeam-utils. If concurrent-queue were truly removed, crossbeam-utils would become an orphan dependency. The PR does not remove crossbeam-utils from the lockfile, which leaves it in an asymmetric state.
  • Manual Checksums: Manually editing cryptographic checksums in Cargo.lock is extremely error-prone and risks immediate build failures due to checksum mismatches against the registry.

💡 Recommendation & Fix

Do not manually edit Cargo.lock to perform crate upgrades. Revert the manual lockfile edit and run the official Cargo CLI command instead:

cargo update -p event-listener --precise 5.4.2

This guarantees that all transitive dependencies and cryptographic checksums are correctly, safely, and cleanly updated according to the official registry metadata.

@github-actions

Copy link
Copy Markdown
Contributor

🛡️ Vuln scan — ❌ vulnerable dependency found

cd services/control-plane && govulncheck ./...
=== Symbol Results ===

No vulnerabilities found.

Your code is affected by 0 vulnerabilities.
This scan also found 1 vulnerability in packages you import and 15
vulnerabilities in modules you require, but your code doesn't appear to call
these vulnerabilities.
Use '-show verbose' for more details.
cd services/gateway && cargo audit
    Fetching advisory database from `https://github.com/RustSec/advisory-db.git`
      Loaded 1177 security advisories (from /home/runner/.cargo/advisory-db)
    Updating crates.io index
    Scanning Cargo.lock for vulnerabilities (272 crate dependencies)
cd services/model-router && cargo audit
    Fetching advisory database from `https://github.com/RustSec/advisory-db.git`
      Loaded 1177 security advisories (from /home/runner/.cargo/advisory-db)
    Updating crates.io index
    Scanning Cargo.lock for vulnerabilities (251 crate dependencies)
cd services/runtime-manager && cargo audit
    Fetching advisory database from `https://github.com/RustSec/advisory-db.git`
      Loaded 1177 security advisories (from /home/runner/.cargo/advisory-db)
    Updating crates.io index
    Scanning Cargo.lock for vulnerabilities (484 crate dependencies)
Crate:     wasmtime
Version:   45.0.3
Title:     Stores can mix up type indices between engines
Date:      2026-07-31
ID:        RUSTSEC-2026-0222
URL:       https://rustsec.org/advisories/RUSTSEC-2026-0222
Severity:  3.8 (low)
Solution:  Upgrade to >=24.0.12, <25.0.0 OR >=36.0.13, <37.0.0 OR >=46.0.2, <47.0.0 OR >=47.0.3

error: 1 vulnerability found!
make: *** [Makefile:270: audit] Error 1

@dshakes

dshakes commented Jul 31, 2026

Copy link
Copy Markdown
Owner Author

Superseded by #209, which includes this exact commit as its base — the event-listener bump alone can't turn the vuln gate green while RUSTSEC-2026-0222 (wasmtime) is still outstanding, and that fix requires the Rust 1.94 toolchain move. Closing in favour of the single change.

@dshakes dshakes closed this Jul 31, 2026
@dshakes
dshakes deleted the fix/rustsec-2026-0221 branch August 4, 2026 15:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

agent:reviewed-clean Reviewer found no Blocking issues this round domain:infra Touches infra / CI / deploy / migrations

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant