* fix(deps): bump h2 to 0.4.16 to clear RUSTSEC-2026-0258
The Rust dependency audit step in Tauri Full Build fails on h2 0.4.13,
which RustSec patches at >=0.4.16. h2 is transitive (hyper -> reqwest),
so this is a lockfile-only bump.
Edited the h2 stanza directly rather than running
`cargo update -p h2 --precise`: that command also re-unified ten
unrelated windows-sys references down a minor, churn this change has no
reason to carry. `cargo metadata --locked` accepts the edited lockfile,
which is the resolver confirming it is a valid resolution.
reqwest (0.12.28, 0.13.2), hyper 1.8.1, hyper-rustls 0.27.7 and rustls
0.23.43 are all unchanged, so the preconfigured-ClientConfig seam that
tauri-plugin-updater's minor pin protects is untouched.
cargo audit now exits 0; the 19 remaining entries are unmaintained/yanked
warnings (atk and the rest of the GTK3 tree under wry), which the audit
does not fail on and which only Tauri upstream can retire.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* test(ws): join the load-soak drain goroutines instead of racing goleak
TestTheLoadTest closed each anchor's stopDrain channel and then relied on
a 300ms sleep for the drain goroutines to actually exit before the
deferred goleak.VerifyNone ran. Closing the channel only makes those
goroutines runnable — it does not wait for the scheduler to run them.
On windows-latest the whole test takes ~126s under -race with 20 churn
workers and 6 broadcasters saturating the runner, and goleak's bounded
retry window can expire while all 8 drains are still sitting in state
"runnable". CI then fails with "found unexpected goroutines" pointing at
load_soak_test.go:127 even though nothing actually leaks.
Track the drains on a WaitGroup and join them right after the stopDrain
channels close. The wait happens in the test body, and goleak.VerifyNone
is deferred, so the check can no longer observe a drain that has been
signalled but not yet scheduled.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>