What changed
v0.0.53 made the streaming deserializer honour every parser budget. An audit of the rest of the family looked for other places where input from outside could reach further than it should. It found three, and this release closes all of them.
Changed
- Readers stop at the size limit.
from_readerand its variants used to read the whole source into memory before checkingmax_document_length. They now stop one byte past the limit, so an endless or hostile stream fails fast instead of filling memory. - The MCP server stays in one directory. Its file tools resolve every path against a root, the working directory or
--root, and refuse anything outside it. A symbolic link that points out counts as out. - The MCP server parses strictly.
noyalib_parseandnoyalib_validateuse the strict YAML 1.2 profile by default. A duplicate key is an error, not a silent overwrite. - The CLI writes in one step.
noyafmt --writeandnoyavalidate --fixwrite to a temporary file and rename it over the original, keeping its permissions.noyavalidate --strictis new. - Release pages follow one shape. Every release in the family now opens with written highlights, then the merged changes and a checksum for every file.
Upgrading
Bump every noyalib crate you use to 0.0.54. The library's API is unchanged. Two MCP changes can refuse what was accepted before. If a client edits files outside the server's working directory, start it with --root. If a client relies on duplicate keys or YAML 1.1 booleans, start it with --profile standard.