Urgent.News

What's breaking now, across thousands of outlets.

Tech

Rust's derive often implies inline

In Rust, the #[derive] attribute is frequently used to implement core traits such as Debug, Display, and Clone. However, developers may not be aware that Rust automatically adds #[inline] to these derived implementations. This feature, while often beneficial, can sometimes lead to unintended consequences.

Consider an error hierarchy, where each Error level inherits from a Debug implementation. In this case, the Debug implementation for Errors can be inlined numerous times, potentially causing the binary size to increase significantly. In one instance, preventing Rust from inlining these Debug implementations resulted in a 160KB reduction in binary size. This was surprising, as it showed the extent to which inlining can impact binary size.

The issue appears to be that Rust doesn't impose any limits on the number or size of inlined Debug implementations, which can be problematic in larger, more complex Rust applications. While it's likely that rustc made the right decision in many cases, developers should be aware of the potential size implications when dealing with deeply nested error hierarchies containing numerous fields.

Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at yossarian.net →

More in Tech

The Task Ahead of STN as National Telecoms Licence Operator in Nigeria

After 28 years of operating skeletal telecoms services under the umbrella, Swift Telephone Network (STN) has become a full-fledged telecoms operator after being granted the Universal Access Service…

  • Swift Telephone Network (STN) secured UASL from NCC, enabling nationwide telecom services.
  • Post-2017 revival, Oluwole Adetuyi focused on regulatory compliance before receiving UASL in 2022.

I Traced Unbound's DNSSEC Heap Overflow: 4 Checks to Run

[ attacker's zone ] ──► ┌────────────────────────────┐ │ Unbound (recursive, DNSSEC)│ │ CVE-2026-81642 CWE-122 │ │ DNSKEY -> digest buffer │ └────────────────────────────┘ A compression pointer inside…

  • Unbound has heap overflow in DNSSEC validator
  • CoreDNS accepts unauthenticated DNS UPDATEs over encrypted transport
  • Both vulnerabilities affect all releases up to 1.26.0

Add an FAQ bot and appointment booking to any website with 3 API calls

Most small-business sites need the same two things: answer the five questions everyone asks ("what are your hours?", "how much is…?") and let people book.

  • Add FAQ bot and booking to website via 3 API calls
  • Use CallChatSyn API with free first 1,000 businesses
  • Implement widget with 30 lines JavaScript code

Detecting Vulnerabilities in Go with gosec

En los laboratorios analizamos el código de una aplicación con SonarCloud, Snyk y Semgrep. En este ejercicio el punto de mira es el mismo código fuente, pero con una herramienta que no usamos en los…

  • gosec, a Go static analyzer, finds 17 vulnerabilities in deliberately flawed application
  • Five vulnerabilities are high severity, 11 are medium severity, one is low severity
  • gosec integration into automated pipelines crucial for comprehensive code analysis

MCP Servers Had a Rough 48 Hours: 4 Unauthenticated CVEs

Between Monday morning and Tuesday night this week, four Model Context Protocol servers published CVE records for the same basic failure: every tool they expose is reachable with no authentication.

  • Four unauthenticated CVEs discovered in MCP servers
  • Vulnerabilities allow unauthorized access and code execution
  • Fixes available but not widely adopted

More from Sunday 4 October →