# Changelog

## Score

- CAI 71 → 72 (+1.8)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.

## Lenses

- Code Health 89 → 89 (+0.3)
- Architecture 88 → 84 (-4.2)
- Maturity 64 → 64 (+0.3)
- Readiness 82 → 84 (+1.9)
- Security 67 → 73 (+6.6)
- Performance 100 (new)

## Resolved (11)

- Documentation: written for insiders (docs/COLLABORATORS.md)
- Duplicated block (17–18 lines × 2) (src/client/conn/http1.rs)
- Duplicated block (20 lines × 2) (src/client/conn/http1.rs)
- Further sole-owners (lower concentration)
- Hotspot: src/proto/h1/dispatch.rs (src/proto/h1/dispatch.rs)
- Hotspot: src/proto/h2/client.rs (src/proto/h2/client.rs)
- Hotspot: src/proto/h2/mod.rs (src/proto/h2/mod.rs)
- Hotspot: src/proto/h2/upgrade.rs (src/proto/h2/upgrade.rs)
- Off-boarding risk: anonymized user #1
- TodoComment (src/ext/h1_reason_phrase.rs)
- UpgradedSendStreamTask::tick (cognitive 21) (src/proto/h2/upgrade.rs)

## New (11)

- Dependency hygiene PARTLY measured — Cargo dependencies read, no committed lock to grade for currency
- Duplicate accessor methods for the error field. `into_error` and `error` are redundant. In Rust, `into_*` usually implies consuming the value, while `*()` implies borrowing. Having both without clear distinction in signature (e.g., `&Error` vs `Error`) is confusing.
- Duplicate accessor methods for the same underlying data. `take_message` and `message` appear to provide identical functionality (accessing the contained request), likely differing only in ownership semantics (move vs borrow) but named inconsistently with standard Rust conventions (usually `into_inner`/`as_ref` or `take`/`get`).
- Duplicated block (12 lines × 2) (src/proto/h2/mod.rs)
- Duplicated block (17–18 lines × 2) (src/client/conn/http1.rs)
- Duplicated block (20 lines × 2) (src/client/conn/http1.rs)
- Inconsistent parameter naming across Builder methods. Some use `enabled: bool` (e.g., `http09_responses`, `title_case_headers`), while others use `val: bool` (e.g., `half_close`, `writev`, `keep_alive`). This creates visual noise and inconsistency in the API surface.
- Off-boarding risk: anonymized user #1
- Projects may be oversized for their cohesion
- Redundant readiness checks. `is_ready()` returns a boolean, while `ready()` returns a Result. In async contexts, `ready()` is typically the blocking/polling operation, while `is_ready()` is a non-blocking peek. However, having both on the same type often leads to misuse where `is_ready()` is checked before calling `ready()`, which is unnecessary if `ready()` is the correct async primitive.
- Signature collision or ambiguity. The list shows `Connection.without_shutdown()` appearing twice with different return types (`Result` vs `impl Future`). This suggests either an overload that isn't clearly distinguished by parameters, or a documentation error where one is a blocking version and one is async, but they share the same name.

## Changes since last survey

- 5 commits — 3 feature/other, 2 fixes

## By area

- src/proto — 2 commits
- (root) — 1 commit
- capi/README.md — 1 commit
- src/client — 1 commit

## Notable commits

- fix: fix(http1): preserve hop-by-hop when setting close or keep-alive (#4196)
- fix: fix(http2): do not reserve capacity for idle Upgraded streams (#4198)
- change: docs: fix three typos (#4204)
- change: style(lib): address clippy panics and missing_panics_doc lints (#4191)
- change: style(lib): address ignored_unit_patterns lint (#4193)
