Skip to content

chore(deps): bump the cargo group with 5 updates - #3

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/cargo/cargo-ff2c0eb50d
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/cargo/cargo-ff2c0eb50d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the cargo group with 5 updates:

Package From To
encoding_rs 0.8.41 0.8.42
rust-samp-sdk 3.4.0 3.5.0
rust-samp 3.4.0 3.5.0
rust-samp-codegen 1.4.0 1.5.0
smallvec 1.16.1 1.16.2

Updates encoding_rs from 0.8.41 to 0.8.42

Commits
  • a155adc Increment version number to 0.8.42
  • 6603aed Attach the multiversion crate to the std feature instead
  • f718b07 docs: multiversion is compiled only with simd-accel
  • 4434afa chore: pull in multiversion only when it is actually used
  • 96138f6 Update main branch in URLs
  • See full diff in compare view

Updates rust-samp-sdk from 3.4.0 to 3.5.0

Release notes

Sourced from rust-samp-sdk's releases.

v3.5.0

Feature release for debugger tooling: the SDK now carries the AMX facts a debugger had to reimplement — opcode numbering and the computed-goto decoder, call-stack walking, and range reads of the data segment. Extracted from the PawnPro Debugger, where each piece was already running against live SA-MP and open.mp servers.

Added

  • samp::debug::opcode — AMX opcode numbering and instruction sizes. The opcode constants (OP_SDIV, OP_BOUNDS, OP_BREAK, OP_PROC, OP_CALL, the load/store and stack/heap opcodes…), OP_NUM_OPCODES, the VM's STK_MARGIN, and operand_cells(op) — how many inline operand cells an instruction carries, so a scanner can step to the next one. It returns None for a variable-length instruction (casetbl) or an out-of-range opcode: the signal to stop scanning rather than guess. Numbering follows the opcode enum in amx.c, identical on SA-MP and open.mp.
  • OpcodeMap — decoding a relocated code segment. Inverts the VM's dispatch table (label address → opcode) to undo the computed-goto rewrite the loader applies on GCC/Clang builds, so read_code values become real opcodes. is_identity() reports a non-relocated image, where code values are already opcode numbers. Amx::opcode_map() builds one straight from a VM; consumers no longer hand-roll the HashMap the docs used to show.
  • samp::debug::stack::walk — call-stack walking. Follows the AMX frame chain ([frm] = the caller's FRM, [frm + CELL] = the return address) and returns the (cip, frm) of every frame, top first. It takes an injected cell reader, so it is unit-testable against a fake memory map and usable host-side; MAX_DEPTH caps it so a corrupted stack cannot spin a debug hook. Amx::call_stack(top_cip) is the wired-up version.
  • Amx::read_cells / Amx::read_bytes — range reads. Read consecutive cells, or raw bytes for a hex view, with the same amx_GetAddr bounds checking as read_cell. Both stop early at the first inaccessible address and return what they read — the natural case at the end of the data segment — returning None only when the start itself is inaccessible. read_bytes needs no alignment: it starts at the enclosing cell and trims. Unlike the get_ref-based Buffer/AmxString path, they need no function table, so they work inside a debug hook.
  • Amx::data_only(ptr). Wraps a raw *mut AMX for data-side access only — registers, cell reads/writes, code reads — stating the intent instead of passing a bare 0 as the function table, the usual situation while a VM is paused.
  • Amx::hlw() — heap low-water mark (#54). The last VM register the accessors were missing (hlw is where the heap starts, below which a release is a AMX_ERR_HEAPLOW underflow). Reading it is what lets a debugger predict that error the way amx.c's CHKHEAP raises it.
  • AmxDbg::function_address. Resolves a function name to its entry address in the code segment, the missing half of lookup_function and what a debugger needs to place a breakpoint on a function by name.

... (truncated)

Changelog

Sourced from rust-samp-sdk's changelog.

rust-samp-sdk (lib samp_sdk) — 3.5.0

Additive public API plus two deprecations.

Fixed

  • getUID() returned garbage on Linux. The secondary IUIDProvider vtable the SDK hands the server carried two destructor thunks before getUID. It has none: IUIDProvider declares no virtual destructor, so the secondary vtable holds a single slot, on Itanium exactly as on MSVC. The server called slot [0] and got the no-op thunk, so every component reported whatever happened to be in the return registers — a different UID on each run. The primary vtable also gains the getUID override at slot [17], where Itanium places it. Verified on a live server: the component now reports the UID from Cargo.toml instead of a value that changed every start.
  • ITimersComponent::create used the wrong overload on Windows. MSVC emits an overload set in reverse declaration order, so slot [16] is create(handler, initial, interval, count) and the three-argument overload the SDK calls is [17]. Calling the wrong one passed four arguments' worth of cleanup against three arguments pushed, corrupting the stack. Confirmed by disassembly: slot [16] ends in ret 0x18, slot [17] in ret 0x10.
  • IExtensible::removeExtension overloads were swapped on Windows, by the same rule. In the vtable the SDK hands the server, slot [2] must be the UID overload and [3] the pointer one. Under thiscall the callee pops the arguments, so the previous order popped 4 bytes where the server had pushed 8.
  • on_tick never fired for native open.mp components on Linux. The ITimersComponent and ITimer slot indices were the MSVC ones, used on both ABIs. On Itanium every method shifts: the destructor takes two slots (D1 + D0) instead of one, and the getUID() override from PROVIDE_UID sits in the primary vtable. So create(handler, interval, repeating) is slot 18, not 16, and ITimer::kill() is 11, not 10. The SDK was calling TimersComponent::reset(), which returns non-null, so no warning was logged and the plugin believed the timer existed. Slots now confirmed against the official Timers.so and Timers.dll of open.mp 1.5.8.3079, pinned by a regression test, and verified on a live server: a component that logged nothing before now delivers its callbacks to Pawn. SA-MP (ProcessTick) and MSVC builds were never affected.
  • component_name() / component_version() read the wrong slots on Linux, for the same reason: componentName() is [7] and componentVersion() is [9] on Itanium, against [6] and [8] on MSVC. Both returned None instead of the component's data. The correct per-ABI numbers were already in docs/internals/omp-abi.md; the code disagreed with its own documentation.
  • Calls through server vtables (core_print_ln, core_log_ln, the _u8 variants, component_name, component_version, the repeating timer helpers) rebuilt the function pointer from a usize, which carries no provenance. They now use the _ptr helpers below.
  • A data_only view panicked instead of failing. Amx::data_only builds a view for reading VM memory with no function table, and its documentation says that calls needing one "will fail" — they asserted instead, which on an FFI boundary means aborting the server. Every such call now returns

... (truncated)

Commits
  • df66c77 feat(debug): opcode decoding, call-stack walking and range reads (#56)
  • a21c704 feat(debug): add AmxDbg::function_address for function breakpoints (#55)
  • 336f8de feat(amx): add Amx::hlw() accessor for the heap low-water mark (#54)
  • d167dd8 chore(deps): bump the github-actions group across 1 directory with 3 updates ...
  • 69c452d chore(deps): bump memcache from 0.20.0 to 0.21.0 (#49)
  • aa21e14 ci: add stable ci-status gate as the required status check (#51)
  • a9ae59f ci: migrate CodeQL from default to advanced setup (#52)
  • 6410f60 chore(deps): bump the cargo group with 3 updates (#48)
  • 686487d chore(deps): bump pymdown-extensions in /docs in the pip group (#47)
  • 866a6a0 chore(deps): bump github/codeql-action/upload-sarif (#46)
  • Additional commits viewable in compare view

Updates rust-samp from 3.4.0 to 3.5.0

Release notes

Sourced from rust-samp's releases.

v3.5.0

Feature release for debugger tooling: the SDK now carries the AMX facts a debugger had to reimplement — opcode numbering and the computed-goto decoder, call-stack walking, and range reads of the data segment. Extracted from the PawnPro Debugger, where each piece was already running against live SA-MP and open.mp servers.

Added

  • samp::debug::opcode — AMX opcode numbering and instruction sizes. The opcode constants (OP_SDIV, OP_BOUNDS, OP_BREAK, OP_PROC, OP_CALL, the load/store and stack/heap opcodes…), OP_NUM_OPCODES, the VM's STK_MARGIN, and operand_cells(op) — how many inline operand cells an instruction carries, so a scanner can step to the next one. It returns None for a variable-length instruction (casetbl) or an out-of-range opcode: the signal to stop scanning rather than guess. Numbering follows the opcode enum in amx.c, identical on SA-MP and open.mp.
  • OpcodeMap — decoding a relocated code segment. Inverts the VM's dispatch table (label address → opcode) to undo the computed-goto rewrite the loader applies on GCC/Clang builds, so read_code values become real opcodes. is_identity() reports a non-relocated image, where code values are already opcode numbers. Amx::opcode_map() builds one straight from a VM; consumers no longer hand-roll the HashMap the docs used to show.
  • samp::debug::stack::walk — call-stack walking. Follows the AMX frame chain ([frm] = the caller's FRM, [frm + CELL] = the return address) and returns the (cip, frm) of every frame, top first. It takes an injected cell reader, so it is unit-testable against a fake memory map and usable host-side; MAX_DEPTH caps it so a corrupted stack cannot spin a debug hook. Amx::call_stack(top_cip) is the wired-up version.
  • Amx::read_cells / Amx::read_bytes — range reads. Read consecutive cells, or raw bytes for a hex view, with the same amx_GetAddr bounds checking as read_cell. Both stop early at the first inaccessible address and return what they read — the natural case at the end of the data segment — returning None only when the start itself is inaccessible. read_bytes needs no alignment: it starts at the enclosing cell and trims. Unlike the get_ref-based Buffer/AmxString path, they need no function table, so they work inside a debug hook.
  • Amx::data_only(ptr). Wraps a raw *mut AMX for data-side access only — registers, cell reads/writes, code reads — stating the intent instead of passing a bare 0 as the function table, the usual situation while a VM is paused.
  • Amx::hlw() — heap low-water mark (#54). The last VM register the accessors were missing (hlw is where the heap starts, below which a release is a AMX_ERR_HEAPLOW underflow). Reading it is what lets a debugger predict that error the way amx.c's CHKHEAP raises it.
  • AmxDbg::function_address. Resolves a function name to its entry address in the code segment, the missing half of lookup_function and what a debugger needs to place a breakpoint on a function by name.

... (truncated)

Changelog

Sourced from rust-samp's changelog.

rust-samp-sdk (lib samp_sdk) — 3.5.0

Additive public API plus two deprecations.

Fixed

  • getUID() returned garbage on Linux. The secondary IUIDProvider vtable the SDK hands the server carried two destructor thunks before getUID. It has none: IUIDProvider declares no virtual destructor, so the secondary vtable holds a single slot, on Itanium exactly as on MSVC. The server called slot [0] and got the no-op thunk, so every component reported whatever happened to be in the return registers — a different UID on each run. The primary vtable also gains the getUID override at slot [17], where Itanium places it. Verified on a live server: the component now reports the UID from Cargo.toml instead of a value that changed every start.
  • ITimersComponent::create used the wrong overload on Windows. MSVC emits an overload set in reverse declaration order, so slot [16] is create(handler, initial, interval, count) and the three-argument overload the SDK calls is [17]. Calling the wrong one passed four arguments' worth of cleanup against three arguments pushed, corrupting the stack. Confirmed by disassembly: slot [16] ends in ret 0x18, slot [17] in ret 0x10.
  • IExtensible::removeExtension overloads were swapped on Windows, by the same rule. In the vtable the SDK hands the server, slot [2] must be the UID overload and [3] the pointer one. Under thiscall the callee pops the arguments, so the previous order popped 4 bytes where the server had pushed 8.
  • on_tick never fired for native open.mp components on Linux. The ITimersComponent and ITimer slot indices were the MSVC ones, used on both ABIs. On Itanium every method shifts: the destructor takes two slots (D1 + D0) instead of one, and the getUID() override from PROVIDE_UID sits in the primary vtable. So create(handler, interval, repeating) is slot 18, not 16, and ITimer::kill() is 11, not 10. The SDK was calling TimersComponent::reset(), which returns non-null, so no warning was logged and the plugin believed the timer existed. Slots now confirmed against the official Timers.so and Timers.dll of open.mp 1.5.8.3079, pinned by a regression test, and verified on a live server: a component that logged nothing before now delivers its callbacks to Pawn. SA-MP (ProcessTick) and MSVC builds were never affected.
  • component_name() / component_version() read the wrong slots on Linux, for the same reason: componentName() is [7] and componentVersion() is [9] on Itanium, against [6] and [8] on MSVC. Both returned None instead of the component's data. The correct per-ABI numbers were already in docs/internals/omp-abi.md; the code disagreed with its own documentation.
  • Calls through server vtables (core_print_ln, core_log_ln, the _u8 variants, component_name, component_version, the repeating timer helpers) rebuilt the function pointer from a usize, which carries no provenance. They now use the _ptr helpers below.
  • A data_only view panicked instead of failing. Amx::data_only builds a view for reading VM memory with no function table, and its documentation says that calls needing one "will fail" — they asserted instead, which on an FFI boundary means aborting the server. Every such call now returns

... (truncated)

Commits
  • df66c77 feat(debug): opcode decoding, call-stack walking and range reads (#56)
  • a21c704 feat(debug): add AmxDbg::function_address for function breakpoints (#55)
  • 336f8de feat(amx): add Amx::hlw() accessor for the heap low-water mark (#54)
  • d167dd8 chore(deps): bump the github-actions group across 1 directory with 3 updates ...
  • 69c452d chore(deps): bump memcache from 0.20.0 to 0.21.0 (#49)
  • aa21e14 ci: add stable ci-status gate as the required status check (#51)
  • a9ae59f ci: migrate CodeQL from default to advanced setup (#52)
  • 6410f60 chore(deps): bump the cargo group with 3 updates (#48)
  • 686487d chore(deps): bump pymdown-extensions in /docs in the pip group (#47)
  • 866a6a0 chore(deps): bump github/codeql-action/upload-sarif (#46)
  • Additional commits viewable in compare view

Updates rust-samp-codegen from 1.4.0 to 1.5.0

Changelog

Sourced from rust-samp-codegen's changelog.

rust-samp-codegen (lib samp_codegen) — 1.5.0

Added

  • #[native] also emits a hidden accessor with the native's Pawn declaration, which initialize_plugin! collects for the generated include described under rust-samp.

Security

  • rustls 0.23.44 → 0.23.45 (RUSTSEC-2026-0285, via #66). Reaches the lockfile through the sink-demo example only — sentry → reqwest → hyper-rustls. No shipped crate depends on it.

Dependencies

  • Weekly lockfile refresh across 70 packages (#64), plus flate2 1.1.9 → 1.1.10 (#57). All transitive or build-time; no manifest requirement and no public API changed.
  • Docs toolchain: pymdown-extensions 11.0.2 → 12.0.1 (#62).
  • GitHub Actions: bumps to the codeql, scorecard, docs and release workflows (#58, #60).

Internal

  • Runtime::logger(), which asserted when the server passed no logprintf — every native Open Multiplayer run — is replaced by try_logger(), returning Option. Internal to the crate (Runtime is pub(crate)), so no plugin sees the change.

Tooling

  • scripts/check-abi-slots.py re-derives every vtable slot index from the official server binaries and fails when the source disagrees. On Linux the .so files keep their symbols, so each slot is identified by name; on Windows it locates vtables through RTTI and identifies methods by the ret N of each slot — which is exactly what pins the create overload pair MSVC emits in reverse. It would have caught all four defects above on its own. Not part of CI, since it needs servers that cannot be redistributed.

  • Both scripts find their inputs instead of hardcoding them. The SDK checkout comes from --sdk, $OPENMP_SDK or the usual locations, and the servers from --linux/--win, $OPENMP_LINUX_SERVER/$OPENMP_WIN_SERVER or likewise; a checkout missing its submodules is reported as such rather than failing three steps later. The fuzzing seed was regenerated: the previous one was compiled from an absolute path, which the AMX debug block stores verbatim.

  • scripts/omp-vtable.py --rust emits the cfg-gated slot constants ready to paste, with --filter to pick methods. Wrapping the next interface is then

... (truncated)

Commits

Updates smallvec from 1.16.1 to 1.16.2

Release notes

Sourced from smallvec's releases.

v1.16.2

What's Changed

New Contributors

Full Changelog: servo/rust-smallvec@v1.16.1...v1.16.2

Commits
  • ccf5fc7 chore: bump version (#617)
  • af207cc Merge pull request #608 from Rayan-and-beyond/fix/manual-readme-warning-606
  • cda4b73 Merge pull request #594 from astral-sh/charlie/codex-fix-may-dangle
  • d0556cb Merge pull request #596 from astral-sh/charlie/codex-v1-compact
  • f73914c Flatten retain tests into the unit test module
  • 954d599 Move retain tests into the unit test module
  • 8d93633 Remove added retain benchmark harness
  • 88c6bfa Limit compaction optimization to retain
  • b9ef17d Fix element ownership tracking with may_dangle
  • 42029c2 Compact retained elements directly in retain and dedup_by
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the cargo group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [encoding_rs](https://github.com/hsivonen/encoding_rs) | `0.8.41` | `0.8.42` |
| [rust-samp-sdk](https://github.com/NullSablex/rust-samp) | `3.4.0` | `3.5.0` |
| [rust-samp](https://github.com/NullSablex/rust-samp) | `3.4.0` | `3.5.0` |
| [rust-samp-codegen](https://github.com/NullSablex/rust-samp) | `1.4.0` | `1.5.0` |
| [smallvec](https://github.com/servo/rust-smallvec) | `1.16.1` | `1.16.2` |


Updates `encoding_rs` from 0.8.41 to 0.8.42
- [Commits](hsivonen/encoding_rs@v0.8.41...v0.8.42)

Updates `rust-samp-sdk` from 3.4.0 to 3.5.0
- [Release notes](https://github.com/NullSablex/rust-samp/releases)
- [Changelog](https://github.com/NullSablex/rust-samp/blob/master/CHANGELOG.md)
- [Commits](NullSablex/rust-samp@v3.4.0...v3.5.0)

Updates `rust-samp` from 3.4.0 to 3.5.0
- [Release notes](https://github.com/NullSablex/rust-samp/releases)
- [Changelog](https://github.com/NullSablex/rust-samp/blob/master/CHANGELOG.md)
- [Commits](NullSablex/rust-samp@v3.4.0...v3.5.0)

Updates `rust-samp-codegen` from 1.4.0 to 1.5.0
- [Release notes](https://github.com/NullSablex/rust-samp/releases)
- [Changelog](https://github.com/NullSablex/rust-samp/blob/master/CHANGELOG.md)
- [Commits](https://github.com/NullSablex/rust-samp/commits)

Updates `smallvec` from 1.16.1 to 1.16.2
- [Release notes](https://github.com/servo/rust-smallvec/releases)
- [Commits](servo/rust-smallvec@v1.16.1...v1.16.2)

---
updated-dependencies:
- dependency-name: encoding_rs
  dependency-version: 0.8.42
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: rust-samp-sdk
  dependency-version: 3.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo
- dependency-name: rust-samp
  dependency-version: 3.5.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: cargo
- dependency-name: rust-samp-codegen
  dependency-version: 1.5.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: cargo
- dependency-name: smallvec
  dependency-version: 1.16.2
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: cargo
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 1, 2026
@dependabot
dependabot Bot requested a review from NullSablex as a code owner October 1, 2026 21:20
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants