Skip to content

chore(rust): upgrade ed25519-dalek 2.x -> 3.x and rand 0.8 -> 0.10 (fixes #3355) - #3420

Merged
MohammadHaroonAbuomar merged 12 commits into
microsoft:mainfrom
chopmob-cloud:chore/rust-ed25519-dalek-3-rand-0.10
Sep 29, 2026
Merged

MohammadHaroonAbuomar merged 12 commits into
microsoft:mainfrom
chopmob-cloud:chore/rust-ed25519-dalek-3-rand-0.10

Conversation

@chopmob-cloud

@chopmob-cloud AlgoVoi (Christopher Hopley) (chopmob-cloud) commented Jul 22, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Upgrades ed25519-dalek 2.2.0 -> 3.0.0 and rand 0.8.6 -> 0.10.2 across the agent-governance-rust workspace, as requested in #3355.

Dependabot #3269 (dalek 3) and #3271 (rand 0.10) each failed build-rust because they bump one crate at a time. The two must move together: ed25519-dalek 3 rides rand_core 0.9, which rand 0.10 provides, so bumping either alone leaves a rand_core version mismatch. This is a single coordinated PR.

What actually changed

Bumping both together showed that the ed25519-dalek 2 -> 3 signing/verifying surface used in this crate is source-compatible (SigningKey::generate, Signature::from_bytes, VerifyingKey::from_bytes, Signer/Verifier). All the real edits are the rand 0.9/0.10 trait and module reshuffle:

  • rand::distributions -> rand::distr (clock.rs)
  • rand::thread_rng() -> rand::rng() in non-key-material paths (clock.rs, the AES-GCM nonce in credential_vault.rs)
  • the old Rng extension trait (providing sample_iter) is now RngExt (clock.rs)
  • the old RngCore core trait (providing fill_bytes) is now named Rng (credential_vault.rs)
  • rand::rngs::OsRng was removed; key generation now uses UnwrapErr(SysRng) (identity.rs, identity_support.rs, credential_vault.rs), see below

Note on key-generation RNG

SigningKey::generate in ed25519-dalek 3 requires an infallible CryptoRng (pub fn generate<R: CryptoRng + ?Sized>(csprng: &mut R)). The documented pattern in the ed25519-dalek 3.0.0 SigningKey::generate docs is OS entropy through the UnwrapErr adapter: let mut csprng = UnwrapErr(SysRng); SigningKey::generate(&mut csprng). SysRng (the getrandom 0.4 system source re-exported by rand 0.10 as rand::rngs::SysRng) implements the fallible TryCryptoRng, and rand_core's UnwrapErr wrapper turns it into an infallible CryptoRng via the blanket impl, satisfying the bound directly from OS entropy with no new dependency and no lockfile change.

Every key-material path draws from UnwrapErr(SysRng): AgentIdentity::generate/delegate, Credential::issue, KeyRotationManager::rotate, and the vault's AES-256-GCM CredentialVault::generate_key. Thread RNG (rand::rng()) remains only where key material is not involved (the AES-GCM nonce, generated identifiers, the attestation challenge nonce, and the MCP clock nonce). This draws long-lived key material straight from the OS CSPRNG and removes the thread-local reseed and fork-safety caveats from the keygen path. The dependency-audit doc records the split.

Validation

agent-governance-rust, from a green baseline:

baseline (2.2.0 / 0.8.6) this PR (3.0.0 / 0.10.2)
cargo build --workspace clean clean, no new warnings
cargo test --workspace --locked 514 pass, 0 fail 518 pass, 0 fail (Linux)
cargo clippy --workspace --all-targets 9 warnings 9 warnings (0 new)

The PR adds two keygen tests (distinct usable keys with cross-verification rejection; distinct non-zero vault keys), which is the +4 delta over the 514 baseline together with the branch's earlier additions. The suite still includes the signature-rejection tests (trust::test_verify_peer_rejects_mismatched_claimed_peer, trust::test_verify_peer_rejects_signature_not_created_by_peer, mcp::signing::tests::rejects_replayed_messages), so verification still refuses forged and replayed signatures, not merely accepts valid ones.

Fixes #3355.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@github-actions

github-actions Bot commented Jul 22, 2026 •

Copy link
Copy Markdown
🤖 AI Agent: code-reviewer — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

TL;DR: 0 blockers, 0 warnings. Safe and clean upgrade.

# Sev Issue Where

No issues found. Clean change.

@github-actions github-actions Bot added the size/L Large PR (< 500 lines) label Jul 22, 2026
@github-actions

Copy link
Copy Markdown
🤖 AI Agent: contributor-guide — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

Welcome, and thank you for your contribution! Great job coordinating the ed25519-dalek and rand upgrades to resolve dependency conflicts effectively.

Before we can merge, please address the following:

  1. Ensure that all removed dependencies in Cargo.lock are no longer required by any part of the project.
  2. Verify that the changes to rand usage (e.g., rand::rng() and RngExt) are consistent across all affected files.

For more details, refer to our CONTRIBUTING.md. Let us know if you need any help!

@github-actions

github-actions Bot commented Jul 22, 2026 •

Copy link
Copy Markdown
🤖 AI Agent: docs-sync-checker — Docs Sync

AI-generated review output. Treat it as untrusted analysis and verify before acting.

Docs Sync

  • README.md -- no updates found for the changes in the pull request.
  • CHANGELOG.md -- missing entry for the upgrade of ed25519-dalek and rand versions, as well as the associated behavioral changes (e.g., OsRng to rand::rng() for key generation).

Please ensure the CHANGELOG.md reflects these updates.

@github-actions

github-actions Bot commented Jul 22, 2026 •

Copy link
Copy Markdown
🤖 AI Agent: security-scanner — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

No security issues found.

@github-actions

github-actions Bot commented Jul 22, 2026 •

Copy link
Copy Markdown
🤖 AI Agent: test-generator — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

Test coverage looks good. No gaps identified.

@github-actions

github-actions Bot commented Jul 22, 2026 •

Copy link
Copy Markdown
🤖 AI Agent: breaking-change-detector — API Compatibility

AI-generated review output. Treat it as untrusted analysis and verify before acting.

API Compatibility

Severity Change Impact
High Upgrade ed25519-dalek from 2.x to 3.x Potential breaking change due to major version bump. While the PR notes that the signing/verifying surface is source-compatible, downstream consumers relying on internal or undocumented behavior may face issues.
High Upgrade rand from 0.8 to 0.10 Potential breaking change due to major version bump. Changes in trait and module structure (e.g., rand::distributions → rand::distr, OsRng replaced with ThreadRng) may impact consumers relying on the previous API.
Medium Replacement of rand::rngs::OsRng with rand::rng() May affect users who explicitly depend on OsRng for cryptographic random number generation.

@github-actions

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

@github-actions

Copy link
Copy Markdown

🔴 Contributor Check: HIGH

Check Result
Profile HIGH
Credential LOW
Overall HIGH

Automated check by AGT Contributor Check.

@github-actions github-actions Bot added the needs-review:HIGH Contributor reputation check flagged HIGH risk label Jul 22, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

TL;DR: 0 blockers, 0 warnings. No issues found. Clean change.

Changes:

  • Upgrade ed25519-dalek from 2.2.0 to 3.0.0 and rand from 0.8.6 to 0.10.2 across the agent-governance-rust workspace.
  • Update call sites for rand 0.10 API moves/renames (e.g., distributions → distr, thread_rng() → rng(), Rng → RngExt, RngCore → Rng).

Reviewed changes

Copilot reviewed 5 out of 6 changed files in this pull request and generated no comments.

Show a summary per file
File Description
agent-governance-rust/Cargo.toml Pins ed25519-dalek to =3.0.0 and rand to =0.10.2 at the workspace level.
agent-governance-rust/Cargo.lock Updates the resolved dependency graph for the coordinated ed25519-dalek/rand upgrade.
agent-governance-rust/agentmesh/src/identity.rs Switches key generation RNG call from OsRng to rand::rng() for SigningKey::generate.
agent-governance-rust/agentmesh/src/identity_support.rs Updates SigningKey::generate RNG call sites to rand::rng() for credential/key rotation paths.
agent-governance-rust/agentmesh/src/credential_vault.rs Adapts RNG trait usage (RngCore → Rng) and updates thread_rng() → rng() for byte filling.
agent-governance-rust/agentmesh-mcp/src/mcp/clock.rs Updates rand imports (distr, RngExt) and RNG creation (rng()) for nonce generation.

@imran-siddique

Copy link
Copy Markdown
Collaborator

MohammadHaroonAbuomar this is the closest Rust PR to merge: mergeable, CI clean, resolves #3355, and the duplicate #3418 is now closed. Could you give it a code-owner review when you have a moment? Thanks.

Copilot AI review requested due to automatic review settings July 27, 2026 22:21
@github-actions github-actions Bot added the documentation Improvements or additions to documentation label Jul 27, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 7 changed files in this pull request and generated no new comments.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 8 changed files in this pull request and generated no new comments.

@MohammadHaroonAbuomar MohammadHaroonAbuomar left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • Process: real CI has never run on this head (all green checks are pull_request_target bot jobs; build-rust/CodeQL/SBOM stuck action_required) and the PR is CONFLICTING on the exact Cargo.toml/lock block being upgraded. Rebase onto main, get workflow runs approved, require genuinely green CI. (Local compensating run at head: cargo test 514/514 pass; code content verified sound incl. dalek3 signing determinism and no seeded-RNG leaks.)

Minor:

  • audit doc omission: OsRng->ThreadRng is not strictly equivalent (thread-local ChaCha12, reseeds per 64KiB, not fork-safe; no fork usage in workspace today). Add a line.

@MohammadHaroonAbuomar MohammadHaroonAbuomar left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • Process: real CI has never run on this head (all green checks are pull_request_target bot jobs; build-rust/CodeQL/SBOM stuck action_required) and the PR is CONFLICTING on the exact Cargo.toml/lock block being upgraded. Rebase onto main, get workflow runs approved, require genuinely green CI. (Local compensating run at head: cargo test 514/514 pass; code content verified sound incl. dalek3 signing determinism and no seeded-RNG leaks.)

Minor:

  • audit doc omission: OsRng->ThreadRng is not strictly equivalent (thread-local ChaCha12, reseeds per 64KiB, not fork-safe; no fork usage in workspace today). Add a line.

@github-actions github-actions Bot added size/L Large PR (< 500 lines) and removed size/XL Extra large PR (500+ lines) labels Sep 18, 2026

@MohammadHaroonAbuomar MohammadHaroonAbuomar left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • .cspell.json:105: the rebase merge dropped "starlette" relative to main (added there by #3411/#3085). The word is used in agent-mesh (errors.py, http_middleware.py, request_auth.py, CHANGELOG.md), so the next PR touching those lines would fail Spell-check. Please re-add "starlette", to the words list.

Comment thread docs/dependency-audits/2026-07-27-ed25519-dalek-3-rand-0.10.md Outdated
@MohammadHaroonAbuomar

Copy link
Copy Markdown
Collaborator

Correction on the .cspell.json item above: main lists starlette twice (once earlier in the list, once near line 105), and this PR drops only the duplicate, so nothing is lost. Please ignore that ask; the audit-table refresh is the only item left.

@chopmob-cloud

Copy link
Copy Markdown
Contributor Author

Thanks for the careful read. I think starlette is actually still covered: it remains in the top-level words array of .cspell.json (line 69 on this branch), so cspell still accepts it and the Spell-check job is green on the current head. What the diff shows at line ~102 is a position move rather than a removal: the rebase dropped the entry at main's line and the branch keeps its own earlier one, so there is exactly one starlette in the list either way, and the agent-mesh usages (errors.py, http_middleware.py, request_auth.py, CHANGELOG.md) stay covered after merge.

Happy to relocate it to match main's ordering if you would prefer the list stay positionally aligned to avoid future diff noise, just let me know.

@Ricky-G

Copy link
Copy Markdown
Contributor

@AlgoVoi can you please rebase, resolve conflicts and push for review again, if its still stale for another week, this will have to come back in as a new PR.

--PR-older-than-a-month

@MohammadHaroonAbuomar

Copy link
Copy Markdown
Collaborator

AlgoVoi (Christopher Hopley) (@chopmob-cloud), a status note so you have the full picture. The one open item on this PR is the audit table at docs/dependency-audits/2026-07-27-ed25519-dalek-3-rand-0.10.md:38, plus a rebase (the branch now conflicts with main). Meanwhile #4104 by a maintainer implements the same upgrade; two of its files are byte-identical to yours and it now credits you as co-author. The earlier ping on this thread went to @AlgoVoi, which is not your GitHub login, so you may not have seen it.

If you can rebase and fix the audit table in the next few days, this PR is the one that should land, and the OS-entropy hardening from #4104 can follow on top. If you would rather not, say so and #4104 goes in with your credit. Either way, thank you for carrying this since July.

AlgoVoi (Christopher Hopley) (chopmob-cloud) added a commit to chopmob-cloud/agent-governance-toolkit that referenced this pull request Sep 24, 2026
… audit

Address review on microsoft#3420: the audit noted the ChaCha12 reseed behaviour of the
non-key-material thread-rng path but not its fork-safety. Add a line stating
rand::rng() is not fork-safe, that no key material and no forking process uses
it today, and that a future fork-using caller must re-check the nonce and
identifier paths. No code change.

Signed-off-by: AlgoVoi <chopmob@gmail.com>
AlgoVoi (Christopher Hopley) (chopmob-cloud) added a commit to chopmob-cloud/agent-governance-toolkit that referenced this pull request Sep 24, 2026
rand 0.10 pulls chacha20 as its ThreadRng CSPRNG backend. The lockfile
resolved chacha20 0.10.1, which crates.io has since yanked for undefined
behaviour: an SSE4.1 intrinsic reached from the SSE2-only backend, fixed in
0.10.2. cargo update -p chacha20 --precise 0.10.2 moves the single lock entry
to the fixed release; no Cargo.toml change. The dependency-audit table is
updated to match. Addresses review feedback on microsoft#3420.

Signed-off-by: AlgoVoi <chopmob@gmail.com>

@MohammadHaroonAbuomar MohammadHaroonAbuomar left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • agent-governance-rust/Cargo.lock:1 The rebase carries a downgrade: main has cedar-policy, cedar-policy-core and cedar-policy-formatter at 4.13.0, and this lock resolves them at 4.12.0, so a squash merge would move main backwards on those three crates. Please regenerate the lock against current main (for example cargo update -p cedar-policy -p cedar-policy-core -p cedar-policy-formatter --precise 4.13.0, or re-resolve from main's lock and re-apply only the dalek and rand changes) so the diff touches only the crates this upgrade changes.

Comment thread docs/dependency-audits/2026-07-27-ed25519-dalek-3-rand-0.10.md Outdated
Coordinated bump (fixes microsoft#3355). ed25519-dalek 3 rides rand_core 0.9 which
rand 0.10 provides, so the two must move together; dependabot's one-at-a-time
bumps (microsoft#3269, microsoft#3271) cannot align them. The dalek 2->3 signing/verifying
surface used here is source-compatible; the edits are the rand 0.9/0.10
reshuffle: distributions->distr, thread_rng->rng, the Rng extension trait
->RngExt, the RngCore core trait ->Rng, and OsRng (removed) -> rand::rng()
(ThreadRng, an infallible CryptoRng, which SigningKey::generate requires and
rand 0.10's SysRng -- only TryCryptoRng -- is not).

cargo build/test/clippy green: 514 tests pass, unchanged from baseline,
including the signature-reject tests (verification still refuses forged and
replayed signatures).

Signed-off-by: chopmob-cloud <250041792+chopmob-cloud@users.noreply.github.com>
Signed-off-by: AlgoVoi <chopmob@gmail.com>
The vendored-patch-audit gate requires a dated audit doc whenever a
lockfile changes, and this PR changes agent-governance-rust/Cargo.lock.

Records why ed25519-dalek and rand must move together, the full
transitive delta, the rand_core/getrandom duplicate collapse, the new
digest/sha2 major duplication, and the OsRng -> rand::rng() migration
that keeps an infallible CryptoRng for key generation. No CVE is being
remediated; this is a compatibility-driven upgrade.

Signed-off-by: chopmob-cloud <250041792+chopmob-cloud@users.noreply.github.com>
Signed-off-by: AlgoVoi <chopmob@gmail.com>
Signed-off-by: AlgoVoi <chopmob@gmail.com>
Signed-off-by: AlgoVoi <chopmob@gmail.com>
…ence

ThreadRng is a thread-local ChaCha12 CSPRNG that reseeds from the OS per
64 KiB of output. Unlike OsRng it is not fork-safe: a child that forks
without exec inherits the parent's RNG state. No code in this workspace
calls fork directly and neither Tokio nor the test harness uses a forking
model, so this is not a current risk. Documenting it so the constraint is
visible if a forking process model is introduced later.

Signed-off-by: AlgoVoi <chopmob@gmail.com>
Copilot reviewer noted the audit table listed getrandom After as 0.4.2 but
the actual lockfile has 0.4.3. On inspection the Before column also omitted
the 0.3.4 version that was already present on main before this PR.

Corrected changes:
- Before: 0.2.17 + 0.3.4 + 0.4.2 (0.3.4 was already present on main)
- After:  0.2.17 + 0.3.4 + 0.4.3 (minor patch bump driven by the rand 0.10 upgrade)

Prose corrections:
- Only rand_core collapses (2->1 version); getrandom stays at 3 versions.
- Security bullet updated to match.

Signed-off-by: AlgoVoi <chopmob@gmail.com>
…ed pattern

Key generation previously used rand's thread RNG (ThreadRng: thread-local
ChaCha12, reseeded from the OS per 64 KiB, not fork-safe). ed25519-dalek
3.0.0's SigningKey::generate documentation uses OS entropy directly via
the UnwrapErr adapter: UnwrapErr(SysRng). This change adopts that pattern
for every key-material path:

- AgentIdentity::generate and AgentIdentity::delegate (identity.rs)
- Credential::issue and KeyRotationManager::rotate (identity_support.rs)
- CredentialVault::generate_key, the AES-256-GCM key (credential_vault.rs)

rand::rngs::SysRng (re-export of getrandom 0.4 SysRng, TryCryptoRng with
Error = Infallible under UnwrapErr) satisfies the infallible CryptoRng
bound of SigningKey::generate via the rand_core blanket impl, so no new
dependency is needed and Cargo.lock is unchanged.

Thread rng remains only in non-key-material paths: the AES-GCM nonce,
generated identifiers (credential, link, chain, incident, violation,
report, grant, challenge, sandbox execution ids), the attestation
challenge nonce, and the MCP clock nonce.

The dependency-audit doc drops the ThreadRng-vs-OsRng caveat and now
records the OS-entropy keygen pattern and the surviving thread-rng uses.
Adds two tests: distinct usable Ed25519 keys with cross-verification
rejection, and distinct non-zero vault keys.

Validation: cargo test --workspace --locked green with the GNU host
toolchain (378 lib + 101 integration + 36 mcp + 2 doc tests), clippy
clean of new warnings.

Signed-off-by: AlgoVoi <chopmob@gmail.com>
…cation note

Signed-off-by: AlgoVoi <chopmob@gmail.com>
These rand-crate identifiers appear in the dalek-3/rand-0.10 dependency
audit docs and were missed in the initial spell commit (017d3c2).

Signed-off-by: AlgoVoi <chopmob@gmail.com>
… audit

Address review on microsoft#3420: the audit noted the ChaCha12 reseed behaviour of the
non-key-material thread-rng path but not its fork-safety. Add a line stating
rand::rng() is not fork-safe, that no key material and no forking process uses
it today, and that a future fork-using caller must re-check the nonce and
identifier paths. No code change.

Signed-off-by: AlgoVoi <chopmob@gmail.com>
rand 0.10 pulls chacha20 as its ThreadRng CSPRNG backend. The lockfile
resolved chacha20 0.10.1, which crates.io has since yanked for undefined
behaviour: an SSE4.1 intrinsic reached from the SSE2-only backend, fixed in
0.10.2. cargo update -p chacha20 --precise 0.10.2 moves the single lock entry
to the fixed release; no Cargo.toml change. The dependency-audit table is
updated to match. Addresses review feedback on microsoft#3420.

Signed-off-by: AlgoVoi <chopmob@gmail.com>
…dit table

Rebase the ed25519-dalek 3 / rand 0.10 upgrade onto current upstream/main and
regenerate the lockfile from main so the diff touches only the crates this
upgrade changes:

- Keep opentelemetry at main 0.33.0 and cedar-policy/-core/-formatter at main
  4.13.0 (the stale branch would have downgraded both). No unrelated crate is
  moved.
- chacha20 resolves to 0.10.2 (0.10.1 was yanked for UB).

Refresh docs/dependency-audits to match the regenerated lock: getrandom,
zerocopy and wasi are unchanged by this upgrade (main moved on); digest and
sha2 already carry both majors on main; const-oid collapses 0.9.6+0.10.2 to
0.10.2. Verification line updated to the measured 578-test run.

Signed-off-by: AlgoVoi <chopmob@gmail.com>
@chopmob-cloud

Copy link
Copy Markdown
Contributor Author

MohammadHaroonAbuomar Done, this is rebased onto current main and mergeable again (head 51540a67).

  • Rebase, no downgrades. The lockfile was regenerated from main, so the diff touches only the dalek/rand upgrade tree. cedar-policy/-core/-formatter stay at 4.13.0 and opentelemetry at 0.33.0 (the stale branch would have moved both backwards), and no unrelated crate changes. chacha20 resolves to 0.10.2, so the yanked 0.10.1 is avoided.
  • Audit table refreshed to match the regenerated lock: getrandom, zerocopy/zerocopy-derive, wasi, digest and sha2 are unchanged by this upgrade (main has moved since the doc was first written, so the earlier "removed"/"gains a major" rows were stale), and const-oid collapses 0.9.6 + 0.10.2 to 0.10.2.
  • Local verification at the rebased head: cargo build, cargo test and cargo clippy are green, full workspace suite 578 passed / 0 failed. The fork's build-rust/CodeQL/SBOM jobs are still action_required pending a maintainer approving the workflow run.

Happy to have the OS-entropy hardening from #4104 follow on top once this lands, per your note. Thanks for carrying the review.

@MohammadHaroonAbuomar MohammadHaroonAbuomar left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving at 51540a6. The lock now moves nothing backwards: ed25519-dalek, ed25519, curve25519-dalek, signature, fiat-crypto and rand go up, two duplicate crates collapse to their newer version, chacha20 0.10.2 is new (0.10.1 is yanked), six transitive crates drop out, and cedar-policy and opentelemetry stay at main's versions. Every newly pinned version is past the seven-day rule. The audit document's table and prose match the lock row for row. Key generation at all five sites uses SigningKey::generate(&mut UnwrapErr(SysRng)) or SysRng.fill_bytes, the stateless OS source the dalek 3 documentation prescribes, and it panics rather than degrading if the OS source fails; signing and verification paths are unchanged and the rejection tests still pass; the new tests cover distinct usable keys and cross-verify rejection. 578 workspace tests pass locally, the vendored-patch audit passes, and all 18 checks are green. Twelve signed commits. Thank you for carrying this from #3355 through two rebases.

For the record: cargo fmt --check and clippy -D warnings fail on main in files this PR does not touch, and CI does not gate them; that is a separate cleanup. #4104 carries the same upgrade on an older base and should close as superseded once this lands.

@MohammadHaroonAbuomar
MohammadHaroonAbuomar merged commit 47688e3 into microsoft:main Sep 29, 2026
104 checks passed
Yuvraj Singh (yuvrajsingh2428) pushed a commit to yuvrajsingh2428/agent-governance-toolkit that referenced this pull request Oct 1, 2026
…ixes microsoft#3355) (microsoft#3420)

* chore(rust): upgrade ed25519-dalek 2.x -> 3.x and rand 0.8 -> 0.10

Coordinated bump (fixes microsoft#3355). ed25519-dalek 3 rides rand_core 0.9 which
rand 0.10 provides, so the two must move together; dependabot's one-at-a-time
bumps (microsoft#3269, microsoft#3271) cannot align them. The dalek 2->3 signing/verifying
surface used here is source-compatible; the edits are the rand 0.9/0.10
reshuffle: distributions->distr, thread_rng->rng, the Rng extension trait
->RngExt, the RngCore core trait ->Rng, and OsRng (removed) -> rand::rng()
(ThreadRng, an infallible CryptoRng, which SigningKey::generate requires and
rand 0.10's SysRng -- only TryCryptoRng -- is not).

cargo build/test/clippy green: 514 tests pass, unchanged from baseline,
including the signature-reject tests (verification still refuses forged and
replayed signatures).

Signed-off-by: chopmob-cloud <250041792+chopmob-cloud@users.noreply.github.com>
Signed-off-by: AlgoVoi <chopmob@gmail.com>

* docs(dependency-audits): audit trail for the dalek 3 / rand 0.10 bump

The vendored-patch-audit gate requires a dated audit doc whenever a
lockfile changes, and this PR changes agent-governance-rust/Cargo.lock.

Records why ed25519-dalek and rand must move together, the full
transitive delta, the rand_core/getrandom duplicate collapse, the new
digest/sha2 major duplication, and the OsRng -> rand::rng() migration
that keeps an infallible CryptoRng for key generation. No CVE is being
remediated; this is a compatibility-driven upgrade.

Signed-off-by: chopmob-cloud <250041792+chopmob-cloud@users.noreply.github.com>
Signed-off-by: AlgoVoi <chopmob@gmail.com>

* chore(spell): add Rust crate names to cspell word list

Signed-off-by: AlgoVoi <chopmob@gmail.com>

* chore(docs): remove owner field and fix prose in dep-audit

Signed-off-by: AlgoVoi <chopmob@gmail.com>

* docs(dependency-audits): document OsRng->ThreadRng fork-safety difference

ThreadRng is a thread-local ChaCha12 CSPRNG that reseeds from the OS per
64 KiB of output. Unlike OsRng it is not fork-safe: a child that forks
without exec inherits the parent's RNG state. No code in this workspace
calls fork directly and neither Tokio nor the test harness uses a forking
model, so this is not a current risk. Documenting it so the constraint is
visible if a forking process model is introduced later.

Signed-off-by: AlgoVoi <chopmob@gmail.com>

* docs(dependency-audits): fix getrandom table and collapse prose

Copilot reviewer noted the audit table listed getrandom After as 0.4.2 but
the actual lockfile has 0.4.3. On inspection the Before column also omitted
the 0.3.4 version that was already present on main before this PR.

Corrected changes:
- Before: 0.2.17 + 0.3.4 + 0.4.2 (0.3.4 was already present on main)
- After:  0.2.17 + 0.3.4 + 0.4.3 (minor patch bump driven by the rand 0.10 upgrade)

Prose corrections:
- Only rand_core collapses (2->1 version); getrandom stays at 3 versions.
- Security bullet updated to match.

Signed-off-by: AlgoVoi <chopmob@gmail.com>

* fix(rust): generate Ed25519 keys from OS entropy per dalek 3 documented pattern

Key generation previously used rand's thread RNG (ThreadRng: thread-local
ChaCha12, reseeded from the OS per 64 KiB, not fork-safe). ed25519-dalek
3.0.0's SigningKey::generate documentation uses OS entropy directly via
the UnwrapErr adapter: UnwrapErr(SysRng). This change adopts that pattern
for every key-material path:

- AgentIdentity::generate and AgentIdentity::delegate (identity.rs)
- Credential::issue and KeyRotationManager::rotate (identity_support.rs)
- CredentialVault::generate_key, the AES-256-GCM key (credential_vault.rs)

rand::rngs::SysRng (re-export of getrandom 0.4 SysRng, TryCryptoRng with
Error = Infallible under UnwrapErr) satisfies the infallible CryptoRng
bound of SigningKey::generate via the rand_core blanket impl, so no new
dependency is needed and Cargo.lock is unchanged.

Thread rng remains only in non-key-material paths: the AES-GCM nonce,
generated identifiers (credential, link, chain, incident, violation,
report, grant, challenge, sandbox execution ids), the attestation
challenge nonce, and the MCP clock nonce.

The dependency-audit doc drops the ThreadRng-vs-OsRng caveat and now
records the OS-entropy keygen pattern and the surviving thread-rng uses.
Adds two tests: distinct usable Ed25519 keys with cross-verification
rejection, and distinct non-zero vault keys.

Validation: cargo test --workspace --locked green with the GNU host
toolchain (378 lib + 101 integration + 36 mcp + 2 doc tests), clippy
clean of new warnings.

Signed-off-by: AlgoVoi <chopmob@gmail.com>

* docs(dependency-audits): drop stale hard-coded test count from verification note

Signed-off-by: AlgoVoi <chopmob@gmail.com>

* chore(spell): add rngs, keygen, csprng to cspell word list

These rand-crate identifiers appear in the dalek-3/rand-0.10 dependency
audit docs and were missed in the initial spell commit (017d3c2).

Signed-off-by: AlgoVoi <chopmob@gmail.com>

* docs(audit): record rand::rng() fork-safety caveat in ed25519-dalek 3 audit

Address review on microsoft#3420: the audit noted the ChaCha12 reseed behaviour of the
non-key-material thread-rng path but not its fork-safety. Add a line stating
rand::rng() is not fork-safe, that no key material and no forking process uses
it today, and that a future fork-using caller must re-check the nonce and
identifier paths. No code change.

Signed-off-by: AlgoVoi <chopmob@gmail.com>

* fix(rust): pin chacha20 to 0.10.2 (0.10.1 yanked for UB)

rand 0.10 pulls chacha20 as its ThreadRng CSPRNG backend. The lockfile
resolved chacha20 0.10.1, which crates.io has since yanked for undefined
behaviour: an SSE4.1 intrinsic reached from the SSE2-only backend, fixed in
0.10.2. cargo update -p chacha20 --precise 0.10.2 moves the single lock entry
to the fixed release; no Cargo.toml change. The dependency-audit table is
updated to match. Addresses review feedback on microsoft#3420.

Signed-off-by: AlgoVoi <chopmob@gmail.com>

* chore(rust): rebase onto main, keep deps at main versions, refresh audit table

Rebase the ed25519-dalek 3 / rand 0.10 upgrade onto current upstream/main and
regenerate the lockfile from main so the diff touches only the crates this
upgrade changes:

- Keep opentelemetry at main 0.33.0 and cedar-policy/-core/-formatter at main
  4.13.0 (the stale branch would have downgraded both). No unrelated crate is
  moved.
- chacha20 resolves to 0.10.2 (0.10.1 was yanked for UB).

Refresh docs/dependency-audits to match the regenerated lock: getrandom,
zerocopy and wasi are unchanged by this upgrade (main moved on); digest and
sha2 already carry both majors on main; const-oid collapses 0.9.6+0.10.2 to
0.10.2. Verification line updated to the measured 578-test run.

Signed-off-by: AlgoVoi <chopmob@gmail.com>

---------

Signed-off-by: chopmob-cloud <250041792+chopmob-cloud@users.noreply.github.com>
Signed-off-by: AlgoVoi <chopmob@gmail.com>
Signed-off-by: yuvrajsingh2428 <offcyuvi2428@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation needs-review:HIGH Contributor reputation check flagged HIGH risk size/L Large PR (< 500 lines) tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

chore(rust): upgrade ed25519-dalek 2.x -> 3.x and rand 0.8 -> 0.10

6 participants