Patch releases within 0.44 that clear eleven RustSec advisories against
the versions in the lock: RUSTSEC-2026-0216, -0219, -0224 to -0232.
They cover NIP-04 and NIP-44 decryption panics and resource exhaustion,
Debug output exposing NIP-46 and NIP-60 credentials, and the relay pool's
handling of unverified events. No other package changes.
Lets an app grant the node's users owner rights, e.g. a Blossom server's
allowed uploaders. The value is the Nostr keys of the identities the app
identity picker offers for NIP-07 signing, chosen by the same rule as
NostrIdentityPicker.vue, so the node's own appliance identity is never
included. It is resolved only for manifests that template it, and an
empty set is an error rather than an empty owner list.
identity.list now shares its is_node test with the new helper.
Every paid download logged "filing into filebrowser/Music/... failed
(non-fatal): Permission denied". The purchase played in-app but never
appeared in Files. FileBrowser's folders belong to its rootless container
range (host uid 100000, mode 755). This service is host uid 1000, outside
that range, so it can read them but not create files in them.
New container::filebrowser::save_new_file:
- Writes directly when the folder allows it.
- Otherwise writes through `podman unshare`, where that uid range is
ours: to a temp file, then chowned to the folder's owner, set to 0644,
and hard-linked into place. FileBrowser never sees a partial file and an
existing file is never replaced. A missing folder is created and given
its parent's owner. No sudo.
- Keeps the "name (2).ext" de-duplication the RPC did inline.
Checked the unshare script on amishparadise in a scratch folder owned
like FileBrowser's: new folder + file OK, owner/mode right, no clobber,
no temp file left, and the service can read the result.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- mint_client: a stub mint shows swap() sends the full v2 keyset id when
given a cashuB short id, and leaves complete v1/v2 ids unchanged.
- fips::dial: the single-delivery decisions are now small functions
(fips_answer_is_final, fips_retryable). Tests cover them and, against a
silent local peer, check that a single-delivery request isn't resent
after a timeout while an ordinary one still is.
- content_server: an unreadable paid file returns Unavailable before the
payment gate runs, and a readable one still returns 402. Also covers
ensure_readable's grant/reopen behaviour. The podman grant is replaced
by a refusal under cfg(test) so results don't depend on the host.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>