Bug 2071060 - Upgrade hyper dependency for nimbus-cli - #7608
Merged
Merged
Conversation
Move the nimbus-cli test server to axum 0.8 (hyper 1.x) from axum 0.6, along with tower-http 0.6, tower-livereload 0.10 and tokio 1.49. This drops the direct hyper and tower dependencies, so nimbus-cli's own tree no longer pulls the h2 0.3 flagged by RUSTSEC-2026-0258. The advisory ignore stays for now, since viaduct-hyper is still on hyper 0.14 until bug 2067851 lands.
bendk
approved these changes
Sep 17, 2026
bendk
left a comment
Contributor
There was a problem hiding this comment.
Looks great to me. I only briefly scanned the actual code, but it seems like the behavior should be the same. I spent most of my time looking through the dependency changes and this definitely does get rid of the h2 dependency.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
nimbus-cli'sstart-serverwas onaxum0.6 /hyper0.14, which pullsh20.3.26 and so trips RUSTSEC-2026-0258. This moves it toaxum0.8 (hyper 1.x),tower-http0.6,tower-livereload0.10 andtokio1.49, and drops the directhyperandtowerdependencies entirely —cargo tree -p nimbus-cli -i h2now reachesh20.3 only throughviaduct-hyper.Notable bits of the port:
axum::Server/hyper::server::conn::AddrIncomingare gone, socreate_serverfolds intostart_serverasaxum::serveover atokio::net::TcpListener.:nameto{name}and panics at router construction on the old form, so both remote-settings routes were rewritten.no_cache_layer()'sStack<Srhl, Stack<Srhl, Srhl>>nesting became three chained.layer()calls. That was the only use of baretower.hyper::Client, which only ever compiled becauseviaduct-hyperunified hyper'sclientfeature in. hyper 1.x has no built-in client, so they now usereqwest.I could not remove the
RUSTSEC-2026-0258ignore:viaduct-hyperis still on hyper 0.14 until bug 2067851 / #7596 lands. I updated the comment to point there as the last remaining path.http0.2/1.x andhyper0.14/1.x coexist inCargo.lockuntil then.DEPENDENCIES.md(and the two iOS ones) are regenerated; the only content change isnum_cpusdropping out, since tokio 1.53 no longer depends on it.Beyond
cargo test/clippy, I ran the server by hand, since no test covers the rewrittenstart_serverpath: index page returns 200 with all three no-cache headers, the{bucket}/{collection}routes match (503/nullbefore a POST, 200 with experiments after, 404 for a non-matching path), the 304 branch still returns an empty body, and the livereload event stream emitsevent: reloadon POST.Unrelated and left alone:
examples/fxa-client/src/oauth-flow.rs:14callsviaduct_hyper::init_backend_hyper(), which no longer exists. It only compiles because that file isn't registered as a build target.Pull Request checklist
[ci full]to the PR title.tower'soneshot.reqwestis the one new crate, and it is a dev-dependency only, used solely by theservertests. It's widely used, MPL-compatible (MIT/Apache-2.0), vendored into mozilla-central, and is the same client Bug 2067851 -viaduct-hyper->viaduct-backend-rust#7596 introduces forviaduct-hyper, so this doesn't fork the repo's HTTP story. Withdefault-features = falseit pulls no TLS (no rustls/ring/openssl), no h2 and no proxy probing — everything it brings is already in the tree via axum 0.8.tower-httpis pinned to 0.6 rather than 0.7 so it unifies with reqwest'stower-http ^0.6.8, and the unusedfsfeature was dropped (the assets areinclude_str!'d), which removesmime_guess,unicase,http-range-headerandpin-project.