# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 51 → 52 (+1.1)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.17) — scores are not directly comparable.

## Lenses

- Code Health 81 → 81 (-0.0)
- Architecture 98 → 93 (-5.3)
- Maturity 76 → 77 (+0.2)
- Readiness 43 → 47 (+3.8)
- Security 61 → 61 (+0.0)
- Event Sourcing 100 → 100 (+0.0)
- Accessibility 41 → 41 (+0.0)
- Performance 100 (new)

## Resolved (14)

- Documentation: no installation or build instructions (README.md)
- Documentation: no installation or build instructions (tokio-quiche/examples/README.md)
- Documentation: no usage examples (README.md)
- Documentation: written for insiders (README.md)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: quiche/src/h3/frame.rs (quiche/src/h3/frame.rs)
- Hotspot: quiche/src/recovery/mod.rs (quiche/src/recovery/mod.rs)
- Hotspot: quiche/src/stream/recv_buf.rs (quiche/src/stream/recv_buf.rs)
- Hotspot: tokio-quiche/src/quic/router/mod.rs (tokio-quiche/src/quic/router/mod.rs)
- Off-boarding risk: anonymized user #1
- Off-boarding risk: anonymized user #2
- TodoComment (quiche/src/tests.rs)
- TodoComment (quiche/src/tests.rs)

## New (18)

- Ambiguous intent between `get` and `get_empty`. It is unclear if `get` returns a buffer with existing data or if it is an alias for `get_empty`. If `get` is the standard allocator, `get_empty` is redundant or confusingly named.
- Change coupling: recv_buf.rs ↔ tests.rs (quiche/src/stream/recv_buf.rs)
- Dependency hygiene PARTLY measured — Cargo dependencies read, no committed lock to grade for currency
- Duplicate function signature with different parameter names (fd vs _fd) in the same module. This suggests copy-paste error or unresolved conflict.
- High: security finding (details withheld)
- Hotspot: apps/src/client.rs (apps/src/client.rs)
- Hotspot: quiche/src/recovery/gcongestion/bbr2.rs (quiche/src/recovery/gcongestion/bbr2.rs)
- Inconsistent error handling for similar operations. `ConsumeBuffer` returns a boolean (likely success/fail), while `DgramBuffer` returns a `Result`. This forces users to handle errors differently for conceptually identical buffer manipulation.
- Inconsistent return types for 'as' accessors. `as_raw_io` returns a typed borrow (`BorrowedFd`), while `as_buf_io` returns a `String` (likely a name or path). This breaks the expectation that `as_*` methods return references or borrows of the underlying type.
- Naming inconsistency between `send_headers_frame` and `send_headers_frame_literal`. The distinction (literal vs encoded?) is not obvious from the name alone and lacks a consistent pattern (e.g., `encode` vs `raw`).
- Off the main sequence: netlog
- Off the main sequence: octets
- Off the main sequence: qlog
- Off the main sequence: task-killswitch
- Off-boarding risk: anonymized user #1
- Projects may be oversized for their cohesion
- TodoComment (quiche/src/tests.rs)
- Unstable project tokio-quiche

## Changes since last survey

- 26 commits — 25 feature/other, 1 fixes

## By area

- quiche/src — 9 commits
- (root) — 6 commits
- qlog-dancer/Cargo.toml — 3 commits
- tokio-quiche/src — 2 commits
- .codex/skills — 1 commit
- .github/workflows — 1 commit
- h3i/src — 1 commit
- quiche/Cargo.toml — 1 commit
- quiche/examples — 1 commit
- tokio-quiche/tests — 1 commit

## Notable commits

- fix: fix connection flow-control double-counting from zero-length STREAM frames
- change: Add BBR param to configure cwnd lower bound (#2732)
- change: build(deps): update getrandom requirement from 0.3 to 0.4
- change: build(deps): update intrusive-collections to 0.10.3
- change: build(deps): update ipnetwork requirement from 0.20 to 0.21
- change: build(deps): update nix requirement from 0.30.1 to 0.31.3
- change: build(deps): update table_to_html requirement from 0.9.0 to 0.11.0
- change: build(deps): update wasm-streams requirement from 0.4 to 0.6
- change: build: upgrade boring to 5.2 with 4.19 compatibility
- change: ci: prepare i686 multiarch builds for boring 5
- change: ci: use MSYS2 for Windows MinGW jobs
- change: examples: link the C examples with the C++ compiler driver
- change: ffi: populate max_rtt in PathStats
- change: h3i: add send capacity factor config option
- change: h3i: release 0.7.0
- change: loosen initial_cwnd's bbr2_gcongestion tolerance in tests
- change: opencode: replace .opencode/skills/ with symlink to .codex
- change: path: add PMTU path event
- change: quiche: release 0.30.0
- change: recovery: emit app-limited state in qlog
- …and 6 more
