chore: bump rain-lib-hash 0.1.10 -> 0.1.27 - #138
Conversation
The library source is unchanged between the two revisions. A probe contract exposing HASH_NIL, hashBytes, both hashWords overloads and combineHashes compiles to identical deployed bytecode against either revision, so no hash LibContext computes moves. src/LibHashNoAlloc.sol moved to src/lib/LibHashNoAlloc.sol upstream, so the import changes path as well as version prefix. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01V8ViHcKLVk2YoS2joH4HdN
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (3)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe project updates Changesrain-lib-hash dependency update
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Other Merge Risk: ⚪ Minimal · up to The dependency update preserves the existing hash behavior and has no unresolved merge-blocking risk. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai assess this PR size classification for the totality of the PR with the following criterias and report it in your comment: S/M/L PR Classification Guidelines:This guide helps classify merged pull requests by effort and complexity rather than just line count. The goal is to assess the difficulty and scope of changes after they have been completed. Small (S)Characteristics:
Review Effort: Would have taken 5-10 minutes Examples:
Medium (M)Characteristics:
Review Effort: Would have taken 15-30 minutes Examples:
Large (L)Characteristics:
Review Effort: Would have taken 45+ minutes Examples:
Additional Factors to ConsiderWhen deciding between sizes, also consider:
Notes:
|
Moves the
rain-lib-hashpin from 0.1.10 to 0.1.27, the newest published revision.No behaviour change in the library
The published packages for both revisions were pulled from the registry and compared directly, independently of this repo.
Stripped of comments, blank lines and indentation,
LibHashNoAlloc.solis byte identical between the two (sha256067baf156529becf2188a818b3e8e4585b517e7e7891f6df693fee1ece8b3ca6either side). Everything that changed between 0.1.10 and 0.1.27 is prose in the header NatSpec.Confirmed at the bytecode level rather than by reading: a probe contract exposing
HASH_NIL,hashBytes, bothhashWordsoverloads andcombineHasheswas compiled against each revision under matching solc settings with metadata stripped, and both produce the same deployed bytecode, sha256e0561eac7566a6d1f0fd03b91cf24a27226c709e62c260821b123e76896c72b0. The library's functions areinternal, so they inline into the probe: identical bytecode means identical hashing. No preimage moved, so no context hash orEvaluableV4hash this repo computes changes, and signatures over existing context stay valid.What the bump touches
src/LibHashNoAlloc.solbecamesrc/lib/LibHashNoAlloc.solupstream, so the import changes path as well as version prefix. Two importers:src/lib/caller/LibContext.solandtest/src/lib/caller/LibContextSlow.sol.0.1.27 also drops the library's own
test/directory from the package. Nothing here imported from it.QA
testBuildCalldataUnpatchedSucceedsintest/src/lib/caller/LibContext.t.solis the one that would catch a moved preimage, and it passes. It signs via thesignWordshelper, which builds the digest askeccak256(abi.encodePacked(words))without touchingLibHashNoAlloc, then assertsbuildaccepts the signature — andbuildverifies againstLibHashNoAlloc.hashWords(...). Any change to whathashWordsfeeds keccak breaks that equality and the assertion fails. The fourtestBuildSignedContext*Revertscases sign through the same helper and pin the same preimage from the negative side.dependencies/rain-lib-hash-0.1.27/src/LibHashNoAlloc.soldoes not exist (the package now ships onlysrc/lib/LibHashNoAlloc.sol), so leaving the old path in place fails to compile rather than silently resolving. Note thatLibContextSlow, the differential reference, callsLibHashNoAllocitself and so moves in lockstep withLibContext— it is not a discriminator for this change, which is why the independent-oracle test above is the one cited.keccak256(abi.encodePacked(words))computed in the test without reference to the library.Verification
forge test: 128 tests passed across 17 suites at 0.1.10 and 128 passed across 17 suites at 0.1.27 — unchanged.forge fmt --checkclean.Both gates that were red here were red on unmodified
maintoo, neither caused by this bump. They are now fixed onmain, in their own PRs, and merged in here:forge lint -D warnings, 37 findings, fixed by chore: scope forge-lint disables for the 37 findings on main #140.pre-commit run --all-files,denofmtandyamlfmt, fixed by chore: apply pre-commit formatting to main #139.Re-verified on this branch with
mainmerged in, insidegithub:rainlanguage/rainix/8657b83b68f41957ab85da91132c3f652c1f32c0#sol-shell:slither .,forge fmt --check,forge lint -D warnings,pre-commit run --all-filesandrainix-sol-single-contractall exit 0 with a clean tree, andforge testis 128 passed across 17 suites.🤖 Generated with Claude Code
https://claude.ai/code/session_01V8ViHcKLVk2YoS2joH4HdN