Skip to content

chore: bump rain-lib-hash 0.1.10 -> 0.1.27 - #138

Merged
thedavidmeister merged 2 commits into
mainfrom
2026-09-16-bump-lib-hash
Sep 16, 2026
Merged

thedavidmeister merged 2 commits into
mainfrom
2026-09-16-bump-lib-hash

Conversation

@thedavidmeister

@thedavidmeister thedavidmeister commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Moves the rain-lib-hash pin from 0.1.10 to 0.1.27, the newest published revision.

No behaviour change in the library

The published packages for both revisions were pulled from the registry and compared directly, independently of this repo.

Stripped of comments, blank lines and indentation, LibHashNoAlloc.sol is byte identical between the two (sha256 067baf156529becf2188a818b3e8e4585b517e7e7891f6df693fee1ece8b3ca6 either side). Everything that changed between 0.1.10 and 0.1.27 is prose in the header NatSpec.

Confirmed at the bytecode level rather than by reading: a probe contract exposing HASH_NIL, hashBytes, both hashWords overloads and combineHashes was compiled against each revision under matching solc settings with metadata stripped, and both produce the same deployed bytecode, sha256 e0561eac7566a6d1f0fd03b91cf24a27226c709e62c260821b123e76896c72b0. The library's functions are internal, so they inline into the probe: identical bytecode means identical hashing. No preimage moved, so no context hash or EvaluableV4 hash this repo computes changes, and signatures over existing context stay valid.

What the bump touches

src/LibHashNoAlloc.sol became src/lib/LibHashNoAlloc.sol upstream, so the import changes path as well as version prefix. Two importers: src/lib/caller/LibContext.sol and test/src/lib/caller/LibContextSlow.sol.

0.1.27 also drops the library's own test/ directory from the package. Nothing here imported from it.

QA

  • Discriminating tests: testBuildCalldataUnpatchedSucceeds in test/src/lib/caller/LibContext.t.sol is the one that would catch a moved preimage, and it passes. It signs via the signWords helper, which builds the digest as keccak256(abi.encodePacked(words)) without touching LibHashNoAlloc, then asserts build accepts the signature — and build verifies against LibHashNoAlloc.hashWords(...). Any change to what hashWords feeds keccak breaks that equality and the assertion fails. The four testBuildSignedContext*Reverts cases sign through the same helper and pin the same preimage from the negative side.
  • Mutations applied: no repo source changed, so there is no line to mutate. The one substantive edit, the import path, is checked by the build itself: dependencies/rain-lib-hash-0.1.27/src/LibHashNoAlloc.sol does not exist (the package now ships only src/lib/LibHashNoAlloc.sol), so leaving the old path in place fails to compile rather than silently resolving. Note that LibContextSlow, the differential reference, calls LibHashNoAlloc itself and so moves in lockstep with LibContext — it is not a discriminator for this change, which is why the independent-oracle test above is the one cited.
  • Oracle: the two published zips from the soldeer registry, decompiled and compiled side by side; and, inside the suite, keccak256(abi.encodePacked(words)) computed in the test without reference to the library.
  • Category check: the ask is the pin bump in this repo and a check that no hash moved; both covered. No other finding is fixed here.

Verification

forge test: 128 tests passed across 17 suites at 0.1.10 and 128 passed across 17 suites at 0.1.27 — unchanged. forge fmt --check clean.

Both gates that were red here were red on unmodified main too, neither caused by this bump. They are now fixed on main, in their own PRs, and merged in here:

Re-verified on this branch with main merged in, inside github:rainlanguage/rainix/8657b83b68f41957ab85da91132c3f652c1f32c0#sol-shell: slither ., forge fmt --check, forge lint -D warnings, pre-commit run --all-files and rainix-sol-single-contract all exit 0 with a clean tree, and forge test is 128 passed across 17 suites.

🤖 Generated with Claude Code

https://claude.ai/code/session_01V8ViHcKLVk2YoS2joH4HdN

The library source is unchanged between the two revisions. A probe
contract exposing HASH_NIL, hashBytes, both hashWords overloads and
combineHashes compiles to identical deployed bytecode against either
revision, so no hash LibContext computes moves.

src/LibHashNoAlloc.sol moved to src/lib/LibHashNoAlloc.sol upstream, so
the import changes path as well as version prefix.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V8ViHcKLVk2YoS2joH4HdN
@coderabbitai

coderabbitai Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: ebb9f7df-13b6-4f5a-9bbe-5dd47e4225a8

📥 Commits

Reviewing files that changed from the base of the PR and between a89b874 and b338dfa.

⛔ Files ignored due to path filters (1)
  • soldeer.lock is excluded by !**/*.lock
📒 Files selected for processing (3)
  • foundry.toml
  • src/lib/caller/LibContext.sol
  • test/src/lib/caller/LibContextSlow.sol

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The project updates rain-lib-hash from version 0.1.10 to 0.1.27. Production and test imports change to the dependency's new src/lib/LibHashNoAlloc.sol path.

Changes

rain-lib-hash dependency update

Layer / File(s) Summary
Update dependency and import paths
foundry.toml, src/lib/caller/LibContext.sol, test/src/lib/caller/LibContextSlow.sol
The dependency version changes to 0.1.27. Production and test imports reference the new src/lib/LibHashNoAlloc.sol path while preserving the imported symbols.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to b338d

The dependency update preserves the existing hash behavior and has no unresolved merge-blocking risk.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: updating the rain-lib-hash dependency from version 0.1.10 to 0.1.27.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch 2026-09-16-bump-lib-hash

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@thedavidmeister
thedavidmeister merged commit 6fe73f7 into main Sep 16, 2026
4 checks passed
@github-actions

Copy link
Copy Markdown

@coderabbitai assess this PR size classification for the totality of the PR with the following criterias and report it in your comment:

S/M/L PR Classification Guidelines:

This guide helps classify merged pull requests by effort and complexity rather than just line count. The goal is to assess the difficulty and scope of changes after they have been completed.

Small (S)

Characteristics:

  • Simple bug fixes, typos, or minor refactoring
  • Single-purpose changes affecting 1-2 files
  • Documentation updates
  • Configuration tweaks
  • Changes that require minimal context to review

Review Effort: Would have taken 5-10 minutes

Examples:

  • Fix typo in variable name
  • Update README with new instructions
  • Adjust configuration values
  • Simple one-line bug fixes
  • Import statement cleanup

Medium (M)

Characteristics:

  • Feature additions or enhancements
  • Refactoring that touches multiple files but maintains existing behavior
  • Breaking changes with backward compatibility
  • Changes requiring some domain knowledge to review

Review Effort: Would have taken 15-30 minutes

Examples:

  • Add new feature or component
  • Refactor common utility functions
  • Update dependencies with minor breaking changes
  • Add new component with tests
  • Performance optimizations
  • More complex bug fixes

Large (L)

Characteristics:

  • Major feature implementations
  • Breaking changes or API redesigns
  • Complex refactoring across multiple modules
  • New architectural patterns or significant design changes
  • Changes requiring deep context and multiple review rounds

Review Effort: Would have taken 45+ minutes

Examples:

  • Complete new feature with frontend/backend changes
  • Protocol upgrades or breaking changes
  • Major architectural refactoring
  • Framework or technology upgrades

Additional Factors to Consider

When deciding between sizes, also consider:

  • Test coverage impact: More comprehensive test changes lean toward larger classification
  • Risk level: Changes to critical systems bump up a size category
  • Team familiarity: Novel patterns or technologies increase complexity

Notes:

  • the assessment must be for the totality of the PR, that means comparing the base branch to the last commit of the PR
  • the assessment output must be exactly one of: S, M or L (single-line comment) in format of: SIZE={S/M/L}
  • do not include any additional text, only the size classification
  • your assessment comment must not include tips or additional sections
  • do NOT tag me or anyone else on your comment

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant