Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions .changelog/aws-sigv4-aws-lc-rs.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
---
applies_to: ["client", "aws-sdk-rust"]
authors: ["jplock"]
references: ["smithy-rs#4681"]
breaking: false
new_feature: true
bug_fix: false
---
Add optional `aws-lc-rs` and `fips` cargo features to `aws-sigv4`. When `aws-lc-rs` is enabled, the SigV4 HMAC-SHA256 / SHA-256 primitives — and, when combined with `sigv4a`, the SigV4a ECDSA-P256 signing path — are routed through `aws-lc-rs` instead of RustCrypto's `hmac` / `sha2` / `p256`. The `fips` feature additionally activates `aws-lc-rs/fips`, routing those primitives through `aws-lc-fips-sys`. The default build is unchanged.
16 changes: 16 additions & 0 deletions .changelog/fix-candisable-blanket-from-impl.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
---
applies_to:
- client
- server
- aws-sdk-rust
authors:
- vcjana
references: []
breaking: false
new_feature: false
bug_fix: true
---

Make `CanDisable`'s `From` impl in `aws-smithy-types` concrete (`From<Duration>`) instead of a blanket `impl<T> From<T>`. The blanket impl could clash with `From` impls from other crates and break the build with `error[E0119]` on a routine dependency bump (it surfaced via `time 0.3.48`).

Additionally, constrain the `time` dependency to `<0.3.48` in `aws-smithy-types`. `time 0.3.48` introduced an E0119 coherence regression (<https://github.com/time-rs/time/issues/783>) that breaks any crate with a blanket `From` impl when `time` is in its dependency graph. Constraining `time` forces resolution to the last-good `0.3.47` across all build paths. Relax this bound once `time 0.3.49` ships.
9 changes: 9 additions & 0 deletions .changelog/msrv-1-94-1.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
---
applies_to: ["client", "server", "aws-sdk-rust"]
authors: ["ysaito1001"]
references: ["smithy-rs#4692"]
breaking: true
new_feature: false
bug_fix: false
---
Upgrade MSRV to Rust 1.94.1.
2 changes: 2 additions & 0 deletions .github/workflows/ci-tls.yml
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,8 @@ jobs:
uses: actions/checkout@v4
with:
repository: chromium/badssl.com
# TODO(smithy-rs#4687): Remove this pin once we upgrade OpenSSL to support @SECLEVEL=0
ref: 6e53ae0859e678724d54eb4f64f839174c9b82e3
path: ./badssl.com
- name: Install Rust
uses: dtolnay/rust-toolchain@master
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ on:
required: false

env:
rust_version: 1.91.1
rust_version: 1.94.1
rust_toolchain_components: clippy,rustfmt
ENCRYPTED_DOCKER_PASSWORD: ${{ secrets.ENCRYPTED_DOCKER_PASSWORD }}
DOCKER_LOGIN_TOKEN_PASSPHRASE: ${{ secrets.DOCKER_LOGIN_TOKEN_PASSPHRASE }}
Expand Down Expand Up @@ -412,8 +412,8 @@ jobs:
run: |
export RUST_STABLE_VERSION="$(rustc --version | cut -d' ' -f2)"
# Install the pinned toolchain from rust-toolchain.toml and add musl target
rustup toolchain install 1.91.1
rustup target add aarch64-unknown-linux-musl wasm32-wasip2 --toolchain 1.91.1
rustup toolchain install 1.94.1
rustup target add aarch64-unknown-linux-musl wasm32-wasip2 --toolchain 1.94.1
./smithy-rs/tools/ci-scripts/run-canary \
${{ secrets.CANARY_STACK_CDK_OUTPUTS_BUCKET_NAME }} \
${{ steps.creds.outputs.aws-access-key-id }} \
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/claim-crate-names.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ concurrency:
cancel-in-progress: true

env:
rust_version: 1.91.1
rust_version: 1.94.1

name: Claim unpublished crate names on crates.io
run-name: ${{ github.workflow }}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/github-pages.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ on:
name: Update GitHub Pages

env:
rust_version: 1.91.1
rust_version: 1.94.1

# Allow only one doc pages build to run at a time for the entire smithy-rs repo
concurrency:
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/manual-canary.yml
Original file line number Diff line number Diff line change
Expand Up @@ -159,8 +159,8 @@ jobs:
run: |
export RUST_STABLE_VERSION="$(rustc --version | cut -d' ' -f2)"
# Install the pinned toolchain from rust-toolchain.toml and add musl target
rustup toolchain install 1.91.1
rustup target add aarch64-unknown-linux-musl wasm32-wasip2 --toolchain 1.91.1
rustup toolchain install 1.94.1
rustup target add aarch64-unknown-linux-musl wasm32-wasip2 --toolchain 1.94.1
./smithy-rs/tools/ci-scripts/run-canary \
${{ secrets.CANARY_STACK_CDK_OUTPUTS_BUCKET_NAME }} \
${{ steps.creds.outputs.aws-access-key-id }} \
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/pull-request-bot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ env:
apt_dependencies: libssl-dev gnuplot jq
java_version: 17
rust_toolchain_components: clippy,rustfmt
rust_nightly_version: nightly-2025-10-18
rust_nightly_version: nightly-2026-03-20
ENCRYPTED_DOCKER_PASSWORD: ${{ secrets.ENCRYPTED_DOCKER_PASSWORD }}
DOCKER_LOGIN_TOKEN_PASSPHRASE: ${{ secrets.DOCKER_LOGIN_TOKEN_PASSPHRASE }}

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ concurrency:
cancel-in-progress: true

env:
rust_version: 1.91.1
rust_version: 1.94.1

name: Release smithy-rs
on:
Expand Down
10 changes: 10 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,14 @@
<!-- Do not manually edit this file. Use the `changelogger` tool. -->
June 11th, 2026
===============
**New this release:**
- :tada: (all, [smithy-rs#4473](https://github.com/smithy-lang/smithy-rs/issues/4473), @ethoman) Add CBOR encoding and decoding support for `BigInteger` using CBOR tags 2 (positive bignum) and 3 (negative bignum) as specified by RFC 8949 §3.4.3 and the Smithy RPC v2 CBOR protocol. Values that fit in CBOR major types 0 or 1 use preferred serialization (plain integers) instead of bignum tags.

**Contributors**
Thank you for your contributions! ❤
- @ethoman ([smithy-rs#4473](https://github.com/smithy-lang/smithy-rs/issues/4473))


June 1st, 2026
==============
**New this release:**
Expand Down
71 changes: 20 additions & 51 deletions aws/SDK_CHANGELOG.next.json
Original file line number Diff line number Diff line change
Expand Up @@ -5,37 +5,6 @@
{
"smithy-rs": [],
"aws-sdk-rust": [
{
"message": "Change sha1 calculation in aws-config from ring to sha1 crate.\n",
"meta": {
"bug": false,
"breaking": false,
"tada": false
},
"author": "markuskobler",
"references": [
"aws-sdk-rust#1317"
],
"since-commit": "81d71b3312e7063e663909d5bb14443ad57c9e2a",
"age": 5
},
{
"message": "Fix bug where initial-request messages in event stream operations are not signed.\n",
"meta": {
"bug": true,
"breaking": false,
"tada": false
},
"author": [
"rcoh",
"ysaito1001"
],
"references": [
"smithy-rs#4429"
],
"since-commit": "81d71b3312e7063e663909d5bb14443ad57c9e2a",
"age": 5
},
{
"message": "Fix null value handling in dense collections: SDK now correctly rejects null values in non-sparse collections instead of silently dropping them.\n",
"meta": {
Expand All @@ -46,7 +15,7 @@
"author": "vcjana",
"references": [],
"since-commit": "2d226ef3c59de83febdc6790e2bf2a44f43f1d1f",
"age": 4
"age": 5
},
{
"message": "Prevent memory leak in identity cache when overriding credentials via `config_override`. Each `config_override` that sets a credentials provider now uses an operation-scoped identity cache instead of the shared client-level cache, preventing unbounded partition growth. Additionally, the client-level identity cache now enforces a configurable `max_partitions` cap (default: 64) as a safety net.\n",
Expand All @@ -60,7 +29,7 @@
"smithy-rs#4340"
],
"since-commit": "00c6d6096f0d618545a7dece903770d8acb21114",
"age": 3
"age": 4
},
{
"message": "Fix `TokenBucket::is_full()` and `TokenBucket::is_empty()` to convert fractional tokens into whole permits before checking availability. Previously, accumulated fractional tokens from success rewards were not accounted for, causing these methods to return incorrect results.\n",
Expand All @@ -75,7 +44,7 @@
"aws-sdk-rust#1423"
],
"since-commit": "00c6d6096f0d618545a7dece903770d8acb21114",
"age": 3
"age": 4
},
{
"message": "Make `ProviderConfig::with_use_fips()` and `ProviderConfig::with_use_dual_stack()` public so that applications constructing a `ProviderConfig` directly can propagate FIPS and dual-stack settings to credential providers.\n",
Expand All @@ -89,7 +58,7 @@
"smithy-rs#4551"
],
"since-commit": "00c6d6096f0d618545a7dece903770d8acb21114",
"age": 3
"age": 4
},
{
"message": "Upgrade `sha2` from 0.10.x to 0.11.x. The previous version defaulted to software-based compression instead of hardware-accelerated compression, resulting in lower throughput. The new version automatically detects and uses hardware-accelerated instructions when available.\n",
Expand All @@ -103,7 +72,7 @@
"smithy-rs#4587"
],
"since-commit": "00c6d6096f0d618545a7dece903770d8acb21114",
"age": 3
"age": 4
},
{
"message": "Optimize `Encoder::str()` and `Encoder::blob()` by collapsing multiple `write_all` calls into a single buffer operation. This bypasses minicbor's generic writer to write the CBOR type+length header and payload directly into the underlying `Vec<u8>`, improving performance on serialization-heavy hot paths.\n",
Expand All @@ -117,7 +86,7 @@
"smithy-rs#4591"
],
"since-commit": "00c6d6096f0d618545a7dece903770d8acb21114",
"age": 3
"age": 4
},
{
"message": "Fix waiter codegen failure when JMESPath `&&` or `||` expressions have non-boolean operands (e.g., a list field used as a truthiness check). Non-boolean types are now coerced to booleans using JMESPath truthiness rules: arrays and strings check `!is_empty()`, all other non-null types are truthy.\n",
Expand All @@ -131,7 +100,7 @@
"smithy-rs#4599"
],
"since-commit": "00c6d6096f0d618545a7dece903770d8acb21114",
"age": 3
"age": 4
},
{
"message": "Add `sigv4a_signing_region_set` client configuration. Supports programmatic, environment variable (`AWS_SIGV4A_SIGNING_REGION_SET`), and shared config file (`sigv4a_signing_region_set`) configuration. User-provided values now take priority over endpoint-resolved values.\n",
Expand All @@ -145,7 +114,7 @@
"smithy-rs#4521"
],
"since-commit": "00c6d6096f0d618545a7dece903770d8acb21114",
"age": 3
"age": 4
},
{
"message": "Add missing `EventOrInitial`, `EventOrInitialMarshaller`, and `EventStreamSender::into_inner` to `aws-smithy-legacy-http` event_stream module, fixing compilation failures in generated SDKs that reference these types.\n",
Expand All @@ -159,7 +128,7 @@
"smithy-rs#4431"
],
"since-commit": "00c6d6096f0d618545a7dece903770d8acb21114",
"age": 3
"age": 4
},
{
"message": "Upgrade `p256` from 0.11 to 0.13.2 in `aws-sigv4` so the SigV4a signing path uses the same major version already pulled in elsewhere in the SDK and benefits from upstream maintenance fixes.\n",
Expand All @@ -173,7 +142,7 @@
"smithy-rs#4648"
],
"since-commit": "c29cba1fa16dbda9697f523e86ca9bb5ec2f6d67",
"age": 2
"age": 3
},
{
"message": "Implement retry behavior 2.1, opt-in via `AWS_NEW_RETRIES_2026=true` environment variable. Non-throttling errors now use 50ms base backoff (previously 1,000ms). Transient retry quota cost is 14 tokens (previously 5). DynamoDB and DynamoDB Streams use a 25ms base backoff and increase default max attempts to 4 (from 3). Long-polling operations (SQS `ReceiveMessage`, SFN `GetActivityTask`, SWF `PollForActivityTask`/`PollForDecisionTask`) backoff even when the retry token bucket is empty.\n",
Expand All @@ -187,7 +156,7 @@
"smithy-rs#4638"
],
"since-commit": "c29cba1fa16dbda9697f523e86ca9bb5ec2f6d67",
"age": 2
"age": 3
},
{
"message": "Remove the `ring` dependency from `aws-sigv4`. The `sigv4a` feature previously pulled in `ring` solely for HMAC-SHA256 in the SigV4a signing-key derivation; this is now done with the `hmac`/`sha2` (RustCrypto) crates that were already used by the SigV4 signer. `ring` is in maintenance hibernation, and the original reason for using it (a version conflict with the older `p256` crate at the time SigV4a was introduced) no longer applies. Users of the `sigv4a` feature will see `ring` removed from their dependency tree.\n",
Expand All @@ -201,7 +170,7 @@
"smithy-rs#4650"
],
"since-commit": "c29cba1fa16dbda9697f523e86ca9bb5ec2f6d67",
"age": 2
"age": 3
},
{
"message": "Fix `ProfileFileCredentialsProvider` so that profile-level `use_fips_endpoint` and `use_dualstack_endpoint` settings are propagated to the internal STS client used during assume-role credential chaining. Previously these settings were only applied when the provider was built through `aws_config::ConfigLoader::load`, so users constructing `ProfileFileCredentialsProvider` directly via its builder would see STS requests go to non-FIPS / non-dual-stack endpoints even when the selected profile enabled them.\n",
Expand All @@ -215,7 +184,7 @@
"smithy-rs#4614"
],
"since-commit": "c29cba1fa16dbda9697f523e86ca9bb5ec2f6d67",
"age": 2
"age": 3
},
{
"message": "Fix adaptive retry rate limiter to never allow negative token bucket capacity. Previously, `acquire_permission_to_send_a_request` unconditionally deducted the request cost even when returning a delay, causing capacity to go negative. With multiple concurrent tasks, this produced cascading sleep times proportional to the number of tasks (e.g., task 50 sleeping 100s), leading to near-zero request rates that never recovered after a throttling event. Now, capacity is only deducted when a token is actually granted, and the orchestrator re-acquires after sleeping to account for concurrent state changes.\n",
Expand All @@ -229,7 +198,7 @@
"smithy-rs#4632"
],
"since-commit": "c29cba1fa16dbda9697f523e86ca9bb5ec2f6d67",
"age": 2
"age": 3
},
{
"message": "Optimized BDD endpoint resolution performance by replacing HashMap-based auth schemes with a typed `EndpointAuthScheme` struct, inlining the BDD evaluation loop, and adding a single-entry endpoint cache. The BDD resolver is now up to 49% faster than the original implementation and outperforms the tree-based resolver on most benchmarks.\n",
Expand All @@ -241,7 +210,7 @@
"author": "lnj",
"references": [],
"since-commit": "c29cba1fa16dbda9697f523e86ca9bb5ec2f6d67",
"age": 2
"age": 3
},
{
"message": "Improve the `Debug` output of HTTP `Headers` and `Request` in `aws-smithy-runtime-api` to redact values of headers commonly used to carry sensitive data. The header name remains visible and the value is replaced with a placeholder that includes the original byte length to preserve diagnostic utility. The `aws-sigv4` signer applies the same redaction when logging the canonical request. The plain `Display` impl on `CanonicalRequest` is unchanged to preserve the raw canonical form used by downstream consumers.\n",
Expand All @@ -253,7 +222,7 @@
"author": "aajtodd",
"references": [],
"since-commit": "8f0882046c467981ba5b4fd91a10befa96bd262f",
"age": 1
"age": 2
},
{
"message": "Fix paginator codegen for operations whose `@paginated` `outputToken` targets a `@required` member. Previously, the generated `src/lens.rs` borrowing accessor emitted a direct field access (`input.field`) instead of a reference (`&input.field`) for required members, causing a type mismatch (`Option<&String>` vs `String`).\n",
Expand All @@ -265,7 +234,7 @@
"author": "vcjana",
"references": [],
"since-commit": "8f0882046c467981ba5b4fd91a10befa96bd262f",
"age": 1
"age": 2
},
{
"message": "Fix `ConnectorBuilder::default()` to enable `TCP_NODELAY` by default. Previously, the auto-derived `Default` impl left `enable_tcp_nodelay` at `false`, while the curated `Connector::builder()` initialized it to `true`. The `Default` impl on `ConnectorBuilder` is now hand-written to match `Connector::builder()`, so all construction paths, including the SDK's `default_https_client`, get `enable_tcp_nodelay = true` consistently. Without `TCP_NODELAY`, Nagle's algorithm can hold small writes in the kernel waiting for ACKs; on request shapes emitted as multiple small sub-MSS writes, such as the tested HTTP/2 small-body SDK path where HEADERS and DATA are flushed separately, this can add roughly one RTT plus delayed-ACK time. Callers who relied on the previous unintended `enable_tcp_nodelay = false` default of `ConnectorBuilder::default()` can restore that behavior with `.enable_tcp_nodelay(false)`.\n",
Expand All @@ -277,7 +246,7 @@
"author": "PeterUlb",
"references": [],
"since-commit": "8f0882046c467981ba5b4fd91a10befa96bd262f",
"age": 1
"age": 2
},
{
"message": "Implement `serde::Serializer` and `serde::Deserializer` traits for `aws_smithy_types::Document`, allowing it to be used as a self-describing data format. This enables converting any `Serialize` type into a `Document` via `to_document()` and deserializing a `Document` into any `Deserialize` type via `from_document()`.\n",
Expand All @@ -289,7 +258,7 @@
"author": "dnorred",
"references": [],
"since-commit": "8f0882046c467981ba5b4fd91a10befa96bd262f",
"age": 1
"age": 2
},
{
"message": "Redact the `AWS_CONTAINER_AUTHORIZATION_TOKEN` value from WARN log output and error `Display` output when the ECS/EKS container credential provider rejects the token as invalid for use as an HTTP header. Previously, if the token contained a byte rejected by `HeaderValue` validation, it was logged at WARN level and embedded in the error string propagated through the credential chain. The value is now redacted.\n",
Expand All @@ -301,7 +270,7 @@
"author": "aajtodd",
"references": [],
"since-commit": "8f0882046c467981ba5b4fd91a10befa96bd262f",
"age": 1
"age": 2
}
],
"aws-sdk-model": []
Expand Down
Loading
Loading