# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 63 → 66 (+2.9)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 88 → 88 (+0.1)
- Architecture 98 → 91 (-7.0)
- Maturity 54 → 54 (+0.1)
- Readiness 69 → 70 (+0.3)
- Security 57 → 71 (+14.4)
- Event Sourcing 100 → 100 (+0.0)
- Performance 89 (new)

## Resolved (9)

- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Hotspot: quinn-proto/src/connection/stats.rs (quinn-proto/src/connection/stats.rs)
- Hotspot: quinn-proto/src/transport_parameters.rs (quinn-proto/src/transport_parameters.rs)
- MethodTooLong: Connection.handle_packet (quinn-proto/src/connection/mod.rs)
- MethodTooLong: Endpoint.accept (quinn-proto/src/endpoint.rs)
- Off-boarding risk: anonymized user #1
- TodoComment (quinn-proto/src/connection/mod.rs)
- TodoComment (quinn-proto/src/connection/mod.rs)

## New (19)

- Ambiguous naming for similar operations. `closed()` and `close_reason()` both return a `ConnectionError`. It is unclear if they return the same error, different aspects of the error, or if one is deprecated. The names suggest `closed` might be a status check (bool) and `close_reason` the error, but both return `ConnectionError`.
- Duplicate constructors with different abstraction levels. Similar to `rebind`, `new` and `new_with_abstract_socket` create an Endpoint but differ only in the socket type. This forces users to choose the correct constructor based on whether they have a concrete socket or a boxed trait object, which is confusing.
- Duplicate operations with different abstraction levels. `rebind` and `rebind_abstract` perform the same logical operation (changing the underlying socket) but differ only in the type of the socket argument (concrete vs boxed trait object). This suggests an inconsistency in how the API handles abstraction, likely due to historical reasons or specific runtime requirements.
- Duplicate operations with unclear distinction. `accept` and `start_accept` in `quinn_proto.endpoint.Endpoint` have identical signatures and likely perform the same function. The naming suggests a two-phase acceptance process, but the signatures do not reflect this (both return `Result`).
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Low cohesion: EndpointConfig (LCOM4 4) (quinn-proto/src/config/mod.rs)
- Low cohesion: UdpSocketState (LCOM4 5) (quinn-udp/src/unix.rs)
- MethodTooLong: Connection.new (quinn-proto/src/connection/mod.rs)
- MethodTooLong: Endpoint.start_accept (quinn-proto/src/endpoint.rs)
- Off the main sequence: quinn-proto
- Off the main sequence: quinn-udp
- Off-boarding risk: anonymized user #1
- Projects may be oversized for their cohesion
- Redundant acceptance methods. `accept` is a convenience wrapper for `accept_with` using the default server config. This creates two entry points for the same operation, forcing users to choose between convenience and explicit configuration.
- Redundant connection initiation methods. `connect` is a convenience wrapper for `connect_with` using the default client config. This creates two entry points for the same operation, forcing users to choose between convenience and explicit configuration without a clear architectural distinction.
- Repeated repair: quinn-udp/src/windows.rs (quinn-udp/src/windows.rs)
- TodoComment (quinn-proto/src/connection/mod.rs)

## Changes since last survey

- 42 commits — 37 feature/other, 5 fixes

## By area

- quinn-proto/src — 23 commits
- (root) — 7 commits
- quinn-udp/src — 5 commits
- quinn/src — 4 commits
- .github/workflows — 3 commits

## Notable commits

- fix: fix: cleanup state if transmit failed
- fix: fix: potential CID leak in connect()
- fix: udp: fix aliasing violation in Linux error queue decoding
- fix: udp: fix aliasing violation in cmsg Encoder
- fix: udp: fix aliasing violation when decoding cmsgs
- change: Reject Retry packets bearing a SCID that matches the initial DCID
- change: Take semver-compatible dependency updates
- change: build(deps): bump aws-lc-rs from 1.18.0 to 1.18.1
- change: build(deps): bump rand from 0.10.2 to 0.10.3
- change: build(deps): bump rustls from 0.23.43 to 0.23.44
- change: build(deps): bump rustls-platform-verifier from 0.7.0 to 0.7.1
- change: build(deps): bump thiserror from 2.0.20 to 2.0.21
- change: build(deps): bump wasm-bindgen-test from 0.3.78 to 0.3.79
- change: ci: fix workflow formatting
- change: ci: run cmsg tests under Miri
- change: ci: work around Android SDK component changes
- change: proto: avoid panic on high minimum ACK delay
- change: proto: bound sent-packet storage by live entries
- change: proto: buffer 1-RTT packets that arrive during the handshake
- change: proto: factor packet post-processing out of handle_packet
- …and 22 more
