Skip to content

Bump the cargo group across 1 directory with 2 updates - #1314

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/main/cargo-b04323a604
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/main/cargo-b04323a604

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the cargo group with 2 updates in the / directory: clap and surge-ping.

Updates clap from 4.6.6 to 4.6.7

Release notes

Sourced from clap's releases.

v4.6.7

[4.6.7] - 2026-09-14

Features

  • (derive) Add #[command(defer = <bool>)] attribute to opt-in to lazy initialisation of subcommands
Changelog

Sourced from clap's changelog.

[4.6.7] - 2026-09-14

Features

  • (derive) Add #[command(defer = <bool>)] attribute to opt-in to lazy initialisation of subcommands
Commits
  • d3e59a9 chore: Release
  • d997f87 docs: Update changelog
  • fb6058c Merge pull request #6409 from heaths/pwsh-support
  • 2310870 test(complete): Add tests for completer_for_path
  • 5967c17 refactor(complete): Move shell detection to Shells
  • 594602b fix(complete): Detect pwsh for PowerShell
  • 3a4f2d0 Merge pull request #6427 from clap-rs/renovate/shlex-2.x
  • 67ebaed Merge pull request #6426 from clap-rs/renovate/actions-checkout-7.x
  • c968b13 chore(deps): Update Rust crate shlex to v2
  • 8f247cb chore(deps): Update actions/checkout action to v7
  • Additional commits viewable in compare view

Updates surge-ping from 0.9.0 to 0.9.1

Release notes

Sourced from surge-ping's releases.

v0.9.1

A bug-fix release. No public API was changed or removed.

Five defects broke the "one Client, many concurrent targets" use case that examples/multi_ping.rs is built on, and two more made ICMP error replies undeliverable. The whole test suite passed before these fixes: it covered the code, but not the guarantees.

Fixed

  • Dropping one Client clone broke every other clone. Client::drop marked the shared reply map destroyed unconditionally, so releasing any clone made the survivors fail with ClientDestroyed. The socket, reply map and receiving task now live in one Arc and are torn down only with the last handle — which also removes a race that could leak the receiving task when two clones were dropped concurrently.
  • A duplicate request destroyed the one already in flight. Registering a second waiter for the same (host, identifier, sequence) replaced the first one's sender, so the original ping failed with NetworkError. The existing waiter is now left untouched.
  • A cancelled ping leaked its registration, so that sequence number stayed unusable and the reply map grew without bound.
  • Dropping a Pinger cancelled unrelated requests. Cleanup was keyed by (host, identifier, sequence) alone, so a finished Pinger could unregister whichever request held that key.
  • Requests in flight waited out their timeout when the last Client was dropped, then reported NetworkError. They now return ClientDestroyed immediately.
  • ICMP errors never reached the request waiting for them. Time exceeded, destination unreachable and friends are sent by an intermediate router, but were routed on that router's address instead of the target quoted inside the error, so they surfaced as timeouts. A TTL-limited probe depends on this.
  • The quoted echo header was assumed to be at a fixed offset, so IPv4 header options or IPv6 extension headers shifted the identifier and sequence out from under the parser.
  • The IPv6 identifier and sequence were read 4 bytes early, off the quoted ICMPv6 type, code and checksum.

Added

  • IcmpPacket::real_destination() — the address the request being answered was originally sent to.

Internal

  • Regression tests for each fix. The reply-map, guard and packet-decoding tests open no socket and are fully deterministic.
  • A GitHub Actions workflow: rustfmt, clippy, docs, MSRV 1.85.0, cargo audit, and a build matrix over Linux, macOS and Windows.

Full notes in CHANGELOG.md.

Full Changelog: kolapapa/surge-ping@0.9.0...0.9.1

Changelog

Sourced from surge-ping's changelog.

[0.9.1] - 2026-09-16

A bug-fix release. No public API was changed or removed.

Fixed

  • Dropping one Client clone no longer breaks the others. Client::drop marked the shared reply map destroyed unconditionally, so releasing any clone made every surviving clone fail with ClientDestroyed — the pattern examples/multi_ping.rs is built on. The socket, reply map and receiving task now live in one Arc and are torn down only when the last handle goes. This also removes a race where two clones dropped concurrently could leave the receiving task running.
  • A duplicate request no longer destroys the request already in flight. Registering a second waiter for the same (host, identifier, sequence) replaced the first one's sender, so the original ping failed with NetworkError while the duplicate got IdenticalRequests. The existing waiter is now left untouched.
  • A cancelled ping releases its sequence number. Cancelling the future used to leave the registration behind, leaking memory and making that sequence unusable until the Pinger was dropped.
  • Dropping a Pinger no longer cancels an unrelated request. Cleanup was keyed by (host, identifier, sequence) alone, so a finished Pinger could unregister whichever request held that key at the time, failing it with NetworkError.
  • Requests in flight end as soon as the last Client is dropped. They used to stay parked until their own timeout expired and then report NetworkError; they now return ClientDestroyed immediately.
  • ICMP errors reach the request waiting for them. Time exceeded, destination unreachable and similar errors are sent by an intermediate router, but were routed on that router's address rather than on the target quoted inside the error, so they surfaced as timeouts. This is what a TTL-limited probe depends on.
  • The quoted echo header is located correctly when the original packet carried IPv4 header options or IPv6 extension headers. Its offset was assumed fixed, so the identifier and sequence were read out of the options or the extension headers.
  • The IPv6 identifier and sequence are read from the right offset. They were taken 4 bytes early, off the quoted ICMPv6 type, code and checksum.
  • Icmpv6Packet::get_real_dest is now set for ICMPv6 error messages; it previously kept its ::1 default.

Added

  • IcmpPacket::real_destination() — the address the request being answered was originally sent to. For an echo reply this is the sender; for an ICMP error it is read out of the request quoted inside the error.

Internal

... (truncated)

Commits
  • 641dda8 test: stop assuming the platform keeps the identifier hint
  • 8da7bd7 chore(release): bump version to 0.9.1
  • 3b2d6fb ci: add GitHub Actions workflow
  • 3c7e92b fix: correct concurrency and ICMP error routing defects
  • ba11a19 style: apply rustfmt and fix clippy warnings
  • 17a0873 docs: rewrite README and add architecture diagram
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update Rust code labels Sep 26, 2026
@dependabot dependabot Bot changed the title Bump the cargo group with 2 updates Bump the cargo group across 1 directory with 2 updates Oct 3, 2026
@dependabot
dependabot Bot force-pushed the dependabot/cargo/main/cargo-b04323a604 branch from 04d4214 to d31c728 Compare October 3, 2026 03:13
Bumps the cargo group with 2 updates in the / directory: [clap](https://github.com/clap-rs/clap) and [surge-ping](https://github.com/kolapapa/surge-ping).


Updates `clap` from 4.6.6 to 4.6.7
- [Release notes](https://github.com/clap-rs/clap/releases)
- [Changelog](https://github.com/clap-rs/clap/blob/main/CHANGELOG.md)
- [Commits](clap-rs/clap@clap_complete-v4.6.6...clap_complete-v4.6.7)

Updates `surge-ping` from 0.9.0 to 0.9.1
- [Release notes](https://github.com/kolapapa/surge-ping/releases)
- [Changelog](https://github.com/kolapapa/surge-ping/blob/main/CHANGELOG.md)
- [Commits](kolapapa/surge-ping@0.9.0...0.9.1)

---
updated-dependencies:
- dependency-name: clap
  dependency-version: 4.6.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: surge-ping
  dependency-version: 0.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/cargo/main/cargo-b04323a604 branch from d31c728 to 5303168 Compare October 4, 2026 18:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update Rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants