Draft: ci: Fix BCHN functional tests and win64 test jobs; bump rustls-webpki and rand for RUSTSEC advisories

Branch: ci-deps-fixes from the jQrgen/rostrum fork (6 commits on top of master efda92ba). Does not touch the bitcoincash crate bump in !459 (merged).

Why

Master's CI has been red since 15 Apr 2026 (pipeline 2455334744), and MR pipelines (e.g. !458 (merged)) fail for reasons that have nothing to do with the MRs themselves:

Symptom Root cause
All test-qa-bchn-* jobs fail: RPC is disabled. This version of Bitcoin Cash Node is old and may be out of consensus with the network bitcoin-cash-node 28.0.1 has reached its built-in expiry date
test-stable-{bch,nexa}-win64 fail: Library bcryptprimitives.dll ... not found, status c0000135 Since Rust 1.78, std on Windows imports ProcessPrng from bcryptprimitives.dll. Debian bookworm's Wine 8.0 doesn't provide it. Wine 9 and later do.
test-qa-nexa-win64 fails: Path '' set in environment variable PROCESS_WRAPPER does not exist which wine64-stable finds nothing, because bookworm's wine64 package has no binary by that name
lint-audit fails (the job that turns master red) RUSTSEC-2026-0098 and RUSTSEC-2026-0099 in rustls-webpki 0.103.10, plus advisories published since April (see change 6)

Changes

  1. ci: Upgrade bitcoin-cash-node to 29.2.0 for functional tests. This is the current BCHN release. The version now lives in a BCHN_VERSION variable, and the tarball is checked against a BCHN_SHA256 taken from the signed SHA256SUMS.29.2.0.asc (good signatures from Calin Culianu and im_uname, and it matches GitHub's asset digest). I chose the upgrade over expire=0 so the tests run against the node version operators actually run, rather than switching off a safety check. 29.2.0 drops -excessiveblocksize, but the functional tests never pass it.
  2. ci: Fix win64 test jobs by installing Wine from WineHQ. In .win64_common, INSTALL_EMULATOR now installs wine-stable pinned to 11.0.0.0~bookworm-1 from the WineHQ bookworm repo, following the official WineHQ Debian instructions (this needs dpkg --add-architecture i386). The cargo runner and PROCESS_WRAPPER now use /opt/wine-stable/bin/wine. I also added WINEDLLOVERRIDES=mscoree,mshtml= so creating the Wine prefix doesn't try to install mono/gecko without a display. Existing allow_failure flags are unchanged.
  3. deps: Bump rustls-webpki to 0.103.13. This fixes RUSTSEC-2026-0098/0099 and also RUSTSEC-2026-0104 (a CRL-parsing panic). It's the lowest release that covers all three, and it doesn't pull in aws-lc updates.
  4. deps: Bump rand to patched releases (RUSTSEC-2026-0097): 0.8.5 to 0.8.6, 0.9.2 to 0.9.3, 0.10.0 to 0.10.1. Lockfile only. These are the patched versions, so no audit ignore is needed.
  5. Cargo.toml: homepage and repository now point to https://gitlab.com/nexa/rostrum.
  6. deps: Update lockfile for advisories published since April. This goes beyond the original scope, and the commit can be dropped on its own. Without it, lint-audit still fails. All updates are semver-compatible and touch only the lockfile:
    • rustls 0.23.37 to 0.23.45 (RUSTSEC-2026-0285). This forces rustls-webpki 0.103.15 and aws-lc-rs 1.18.1 / aws-lc-sys 0.45.0.
    • crossbeam-epoch 0.9.18 to 0.9.21 (RUSTSEC-2026-0204).
    • rust_decimal 1.41.0 to 1.43.0. This removes rkyv 0.7.46 (RUSTSEC-2026-0235) from the lockfile; it was an optional dependency that never got built.
    • anyhow 1.0.102 to 1.0.104 (RUSTSEC-2026-0190).
    • Yanked chacha20 0.10.0 to 0.10.2, and spin 0.9.8 to 0.9.9.

Verification (local, on Debian 13 box, at branch head 2df0085)

Check Result
cargo fmt --all -- --check pass
cargo build --locked --features=bch (stable 1.99) pass (2 fetch_update deprecation warnings on 1.99, not caused by this branch)
cargo build --release --locked --features=bch pass
cargo test --locked --features=bch pass, 107 unit tests
cargo test --locked --features=nexa pass, 97 unit tests
cargo +1.88 test --locked --features=fail-on-warnings,bch (MSRV toolchain, warnings denied) pass
cargo audit --ignore RUSTSEC-2023-0089 --ignore RUSTSEC-2024-0436 (the lint-audit command, cargo-audit 0.22.2) pass, 0 vulnerabilities. Master failed with 2 vulnerabilities in April, and more advisories have appeared since.
cargo clippy -- -D warnings fails, but master fails the same way. On stable 1.99 the branch and master give the same 20 errors (new lints plus the fetch_update deprecation). On 1.88, uninlined_format_args fires about 180 times in untouched files. Master's lint-clippy passed in April with CI's toolchain, and this branch changes no Rust source.
Functional tests, BCH: test/functional/test_runner.py -parallel=4 with BCHN 29.2.0 and the branch's release binary pass, 36/36 tests (3 disabled by the runner: idle_timeout, doslimit and shutdownonerror don't support BCHN/spawn), 300 s
.gitlab-ci.yml parses as YAML; every extends target exists; every changed script/before_script line passes bash -n
Patch series git am onto master reproduces the branch tree exactly

Not verified / reviewer notes

  • This MR's pipeline is the first real run of the CI changes. Locally I parsed the YAML and ran every script/before_script line through bash -n.
  • The Wine fix was checked locally: a Rust 1.88 x86_64-pc-windows-gnu binary that imports bcryptprimitives.dll runs under the WineHQ 11.0 bookworm build. Debian's Wine 8.0 package has no bcryptprimitives.dll at all. I didn't run the install steps in a bookworm container.
  • Installing WineHQ adds about 100 MB of i386 packages to the win64 test jobs. APT_CACHE_DIR should cache them.
  • Not run: the Nexa functional tests, the aarch64/win64 CI jobs, and GitLab's own CI lint (it needs an API token).
  • On newer Rust (1.99), src/doslimit.rs warns about the deprecated AtomicI32::fetch_update (renamed to try_update). This is out of scope here, but it will trip fail-on-warnings / clippy -D warnings once CI's toolchain moves forward.

Merge request reports

Loading
Loading