# Changelog

## Score

- CAI 71 → 72 (+0.4)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.17) — scores are not directly comparable.

## Lenses

- Code Health 90 → 90 (+0.0)
- Architecture 99 → 92 (-6.7)
- Maturity 67 → 67 (+0.0)
- Readiness 85 → 69 (-15.9)
- Security 63 → 69 (+6.1)
- Event Sourcing 100 → 100 (+0.0)
- Performance 100 (new)

## Resolved (8)

- Documentation: no installation or build instructions (README.md)
- Documentation: no licence statement (README.md)
- Documentation: no usage examples (README.md)
- Hotspot: iroh/src/net_report.rs (iroh/src/net_report.rs)
- Hotspot: iroh/src/socket.rs (iroh/src/socket.rs)
- Hotspot: iroh/src/socket/remote_map/remote_state.rs (iroh/src/socket/remote_map/remote_state.rs)
- Hotspot: iroh/src/socket/transports/relay/actor.rs (iroh/src/socket/transports/relay/actor.rs)
- Off-boarding risk: anonymized user #1

## New (17)

- Ambiguous naming. `closed()` typically implies a state check (boolean) or a future/stream of closure events. `close_reason()` implies getting the reason for closure. Returning the same type `ConnectionError` from both suggests they might be accessing the same internal state, but the names suggest different intents (state vs. reason).
- Consistent but confusing pattern across multiple types. The presence of `n0_dns()` alongside `builder()` in both Publisher and Resolver suggests a library-specific convention ('n0') that is not self-explanatory. It creates cognitive load to determine which factory method to use.
- Duplicate method name with different return types. This is a signature collision in the API surface (overloading by return type is not supported in Rust, so these must be on different types or one is a typo in the provided list, or they are methods on different traits/impls not shown as distinct types). Assuming they are on the same `Connection` type, this is a compilation error. If they are on different types (e.g., `Connection` vs `Incoming`), the naming is inconsistent. Looking at the list, `Incoming` has `remote_addr` etc., but `Connection` has two `alpn` methods listed. This is likely a data error or a severe API design flaw if they are on the same type.
- Inconsistent naming and return types for similar operations. `from_endpoint_info` is a constructor-like static method. `set_endpoint_info` returns `EndpointData` (likely the stored data), while `add_endpoint_info` returns `Self` (unit/void). The distinction between 'set' and 'add' is not immediately obvious from the signature alone (does set overwrite? does add append?).
- Off the main sequence: iroh-base
- Off-boarding risk: anonymized user #1
- Orphaned files with no living knowledge
- Outdated: hyper-util
- Outdated: lru
- Outdated: rustls-platform-verifier
- Outdated: smallvec
- Outdated: tokio-rustls
- Outdated: wasm-bindgen-futures
- Projects may be oversized for their cohesion
- Redundant factory methods with unclear distinction. Both return a builder, but it is unclear if `n0_dns` is a specialized version of `builder` or if they produce different default configurations. In other types (e.g., PkarrPublisher), `n0_dns` is also present alongside `builder`, suggesting a pattern, but the naming is confusing for users who don't know the internal 'n0' convention.
- Standard Rust naming convention violation or confusion. `to_` usually implies borrowing/converting without consuming, while `into_` implies consuming the source. However, both return the same type `EndpointAddr`. If `to_endpoint_addr` borrows internally, it should return a reference or a copy. If it consumes, it should be `into_`. Having both suggests one might be a legacy alias or they perform different internal operations (e.g., one clones, one moves) which is confusing.
- TooManyMethods: Connection (iroh/src/endpoint/connection.rs)

## Changes since last survey

- 11 commits — 6 feature/other, 5 fixes

## By area

- iroh/src — 6 commits
- (root) — 3 commits
- .github/workflows — 1 commit
- iroh-dns/src — 1 commit

## Notable commits

- fix: Revert "feat(metrics): lookup/resolver stats" (#4542)
- fix: chore: fix `qlog` feature gate error (#4556)
- fix: deps: bump rustls for RUSTSEC-2026-0285 & fix android CI (#4535)
- fix: fix(ci): run release builds on ephemeral instances (#4559)
- fix: fix(iroh): Preserve protocol ordering in the router (#4533)
- change: chore: fix typo (#4560)
- change: chore: release
- change: docs: update changelog for v1.3.0
- change: feat(iroh)!: expose batch datagram send/recv APIs (#4547)
- change: feat(metrics): lookup/resolver stats (#4543)
- change: refactor(iroh): simplify datagram send code and test setup (#4525)
