Skip to content

Bug 2071060 - Upgrade hyper dependency for nimbus-cli - #7608

Merged
travis79 merged 1 commit into
mainfrom
Bug2071060
Sep 17, 2026
Merged

travis79 merged 1 commit into
mainfrom
Bug2071060

Conversation

@travis79

@travis79 travis79 commented Sep 17, 2026 •

Copy link
Copy Markdown
Member

nimbus-cli's start-server was on axum 0.6 / hyper 0.14, which pulls h2 0.3.26 and so trips RUSTSEC-2026-0258. This moves it to axum 0.8 (hyper 1.x), tower-http 0.6, tower-livereload 0.10 and tokio 1.49, and drops the direct hyper and tower dependencies entirely — cargo tree -p nimbus-cli -i h2 now reaches h2 0.3 only through viaduct-hyper.

Notable bits of the port:

  • axum::Server / hyper::server::conn::AddrIncoming are gone, so create_server folds into start_server as axum::serve over a tokio::net::TcpListener.
  • axum 0.8 changed route params from :name to {name} and panics at router construction on the old form, so both remote-settings routes were rewritten.
  • no_cache_layer()'s Stack<Srhl, Stack<Srhl, Srhl>> nesting became three chained .layer() calls. That was the only use of bare tower.
  • The tests used hyper::Client, which only ever compiled because viaduct-hyper unified hyper's client feature in. hyper 1.x has no built-in client, so they now use reqwest.

I could not remove the RUSTSEC-2026-0258 ignore: viaduct-hyper is still on hyper 0.14 until bug 2067851 / #7596 lands. I updated the comment to point there as the last remaining path. http 0.2/1.x and hyper 0.14/1.x coexist in Cargo.lock until then.

DEPENDENCIES.md (and the two iOS ones) are regenerated; the only content change is num_cpus dropping out, since tokio 1.53 no longer depends on it.

Beyond cargo test / clippy, I ran the server by hand, since no test covers the rewritten start_server path: index page returns 200 with all three no-cache headers, the {bucket}/{collection} routes match (503/null before a POST, 200 with experiments after, 404 for a non-matching path), the 304 branch still returns an empty body, and the livereload event stream emits event: reload on POST.

Unrelated and left alone: examples/fxa-client/src/oauth-flow.rs:14 calls viaduct_hyper::init_backend_hyper(), which no longer exists. It only compiles because that file isn't registered as a build target.

Pull Request checklist

  • Breaking changes: This PR follows our breaking change policy
    • This PR follows the breaking change policy:
      • This PR has no breaking API changes, or
      • There are corresponding PRs for our consumer applications that resolve the breaking changes and have been approved
  • Quality: This PR builds and tests run cleanly
    • Note:
      • For changes that need extra cross-platform testing, consider adding [ci full] to the PR title.
      • If this pull request includes a breaking change, consider cutting a new release after merging.
  • Tests: This PR includes thorough tests or an explanation of why it does not
    • The five existing server tests are preserved as-is, including the assertion that the 304 branch has an empty body — that's hyper's wire-level framing rule, so the tests deliberately still go over a real socket rather than switching to tower's oneshot.
  • Changelog: This PR includes a changelog entry in CHANGELOG.md or an explanation of why it does not need one
    • Any breaking changes to Swift or Kotlin binding APIs are noted explicitly
  • Dependencies: This PR follows our dependency management guidelines
    • reqwest is the one new crate, and it is a dev-dependency only, used solely by the server tests. It's widely used, MPL-compatible (MIT/Apache-2.0), vendored into mozilla-central, and is the same client Bug 2067851 - viaduct-hyper -> viaduct-backend-rust #7596 introduces for viaduct-hyper, so this doesn't fork the repo's HTTP story. With default-features = false it pulls no TLS (no rustls/ring/openssl), no h2 and no proxy probing — everything it brings is already in the tree via axum 0.8.
    • tower-http is pinned to 0.6 rather than 0.7 so it unifies with reqwest's tower-http ^0.6.8, and the unused fs feature was dropped (the assets are include_str!'d), which removes mime_guess, unicase, http-range-header and pin-project.

Move the nimbus-cli test server to axum 0.8 (hyper 1.x) from axum 0.6,
along with tower-http 0.6, tower-livereload 0.10 and tokio 1.49. This
drops the direct hyper and tower dependencies, so nimbus-cli's own tree
no longer pulls the h2 0.3 flagged by RUSTSEC-2026-0258.

The advisory ignore stays for now, since viaduct-hyper is still on
hyper 0.14 until bug 2067851 lands.
@travis79
travis79 requested a review from bendk September 17, 2026 13:44

@bendk bendk left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks great to me. I only briefly scanned the actual code, but it seems like the behavior should be the same. I spent most of my time looking through the dependency changes and this definitely does get rid of the h2 dependency.

@travis79
travis79 added this pull request to the merge queue Sep 17, 2026
Merged via the queue into main with commit b0f0f51 Sep 17, 2026
15 checks passed
@travis79
travis79 deleted the Bug2071060 branch September 17, 2026 15:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants