COOLJAPAN

COOLJAPAN Blog

The inside story of building the largest pure-Rust sovereignty stack

324 posts

release 323 pure-rust 267 scirs2 84 rust 77 noffi 44 cooljapan 44 wasm 36 machine-learning 36 gpu 32 cuda 32 security 29 scientific-computing 29 simd 26 oxiarc 24 oxicuda 21 numpy 21
Aug 6, 2026 · 10 min

OxiCode 0.2.6 Released — Nine Bytes Was All It Took to Loop Forever

OxiCode 0.2.6 hardens the serde bridge, closing an infinite-decode-loop bug and unbounded allocations 0.2.5 missed. A wire-format-relevant fix restores byte compatibility with bincode::serde (migration note included). Adds bounded-length decode entry points and decode contexts in the derive macros. 20,198 tests passing.

releaseoxicodebincode
Aug 6, 2026 · 10 min

OxiCrypto 0.3.0 Released — All 12 FIPS 205 SLH-DSA Parameter Sets, TLS 1.3 AEAD Negotiation, and a Bcrypt Panic-DoS Fixed

OxiCrypto 0.3.0 completes the FIPS 205 SLH-DSA parameter-set matrix (all 12 of 12), ships a new negotiate_aead TLS 1.3 cipher-suite resolver alongside negotiate_mac/negotiate_sig/negotiate_kex, adds coverage-guided fuzzing across AEAD/MAC/PQ/KDF, gives every sub-crate a runnable example, and fixes a byte/char-boundary panic-DoS in bcrypt verification — the sovereign Pure Rust cryptography layer for the COOLJAPAN ecosystem.

releaseoxicryptopure-rust
Aug 6, 2026 · 7 min

OxiFFT 0.4.2 Released — Wrong FFT Answers on Every Non-AVX2 x86_64 CPU, Found and Fixed

OxiFFT 0.4.2 fixes a wrong-answer bug (not a precision bug) in the x86_64 SSE3 SIMD butterfly kernel that every non-AVX2 x86_64 CPU takes — a wrong complex-multiply lane order and twiddle-recurrence drift together failed 93 of 1447 tests by 10-100x the tolerance. Found by running the suite on x86_64 for the first time. Plus a Miri-driven pointer-provenance fix, four new soundness hardenings against attacker-influenceable wisdom strings, and a fuzz-harness tolerance bug of its own. Pure Rust FFT, no FFTW.

releaseoxifftfft
Aug 6, 2026 · 10 min

OxiFont 0.2.2 Released — Static-Instance Variable Fonts, Windows .ttc Collections, and a PDF-Ready Glyph-ID Map

OxiFont 0.2.2 ships oxifont-subset::instance() for pinning a variable font to one design location, a drop_variations subset option, TrueType Collection (.ttc) face-index support that unlocks stock Windows CJK fonts like msgothic.ttc, a public SubsetGidMap for PDF CIDFont embedding, and full GSUB/GPOS contextual-lookup remapping — the sovereign Pure Rust font layer for the COOLJAPAN ecosystem.

releaseoxifontpure-rust
Aug 6, 2026 · 10 min

OxiH5 0.2.3 Released — Six Writer Gaps Closed, Extensible-Array Chunk Indexes Now Readable

OxiH5 0.2.3 closes six writer roadmap gaps — compound records, vlen sequences, array/opaque/bitfield types, big-endian/half-precision floats, soft/external/hard links — makes extensible-array chunk indexes readable, fixes five crash/OOM classes. 987 tests passing — COOLJAPAN's sovereign scientific-data layer.

releaseoxih5pure-rust
Aug 6, 2026 · 7 min

OxiNum 0.1.4 Released — When a Perfectly Valid Number Tried to Allocate Past Its Budget

OxiNum 0.1.4 closes an unbounded-allocation class across add/sub, remainder, and binary-splitting transcendentals — a legitimately valid but extreme BigFloat exponent could previously drive memory proportional to the exponent gap, aborting the process. New MAX_EXACT_CONVERSION_BITS-guarded try_* fallible APIs, an enforced BigFloat exponent range (EMAX/EMIN, ilogb), a fixed IEEE-754 subnormal-rounding double-rounding bug, and a Rem correctness fix. Pure Rust, no GMP, no MPFR, no FFI.

releaseoxinumpure-rust
Aug 6, 2026 · 7 min

OxiProto 0.1.5 Released — Protobuf Editions Actually Work Now (prost-reflect Used to Panic on the Word)

OxiProto 0.1.5 ships Editions 2023 support end to end: full feature resolution (field_presence, enum_type, repeated_field_encoding, utf8_validation, message_encoding, json_format), enforcement at decode time, and a downlevel-to-proto2 rewrite so the prost-reflect facade — which panics trying to even format the 'unknown syntax editions' error — can handle Editions files at all. Plus a wrong-buffer bug in generated packed-repeated decode, a proto2 packing default that diverged from protoc, and two new nesting-depth DoS bounds. Pure Rust Protocol Buffers, no protoc required.

releaseoxiprotopure-rust
Aug 6, 2026 · 8 min

OxiQUIC 0.2.1 Released — Anti-Amplification, Per-Path Congestion Control, and ECN Close the RFC 9000 Security Gaps

OxiQUIC 0.2.1 closes five RFC 9000 security gaps — spoofed-source reflection amplification, unbounded per-stream and CRYPTO-buffer memory growth, and a forgeable Retry handshake — adds bidirectional ECN (RFC 9000 §13.4 / RFC 9002 §7.4) and true per-path congestion control for multipath, and ships runnable QUIC/HTTP-3 examples. 445 tests passing, the sovereign Pure Rust QUIC layer for the COOLJAPAN ecosystem.

releaseoxiquicpure-rust
Aug 6, 2026 · 10 min

OxiSound 0.2.1 Released — A Zero-C PulseAudio Backend, Three OSC Decoder DoS Bugs Closed

OxiSound 0.2.1 ships oxisound-pulse — a brand-new, 100% Pure Rust PulseAudio/PipeWire native-protocol backend with zero C in its Linux audio path — plus three denial-of-service fixes in oxisound-osc's untrusted-UDP decode path (an out-of-bounds read, unbounded nesting, and a 32-bit integer wraparound), a new fuzz workspace, and a stream_stats() correctness fix. The sovereign audio device I/O layer for the COOLJAPAN ecosystem.

releaseoxisoundpure-rust
Aug 6, 2026 · 9 min

OxiText 0.2.2 Released — Vendored Swash Fork Fixes Two Indic Shaping Bugs, Absorbs an Unfixed Upstream Panic

OxiText 0.2.2 vendors its own fork of swash to fix a Devanagari reph-duplication bug and an out-of-bounds panic that has sat open and unfixed upstream since April 2025, adds a Pure-Rust PNG decoder to fully remove the `png`/`flate2` dependency chain, and fixes color-glyph misdetection for sbix/CBDT/SVG fonts — 845 tests passing, the sovereign text layer for the COOLJAPAN ecosystem.

releaseoxitextpure-rust
Aug 6, 2026 · 8 min

OxiTLS 0.3.0 Released — Leaf-Only-Chain OCSP False-Rejections Fixed, HPKE LabeledExpand Panic Eliminated

OxiTLS 0.3.0 fixes an OCSP staple false-rejection on leaf-only certificate chains, converts an HPKE LabeledExpand panic into a propagated Result, and adds three new fuzz targets covering its own hand-rolled TLS parsers — 364 tests passing, the sovereign Pure Rust TLS layer for the COOLJAPAN ecosystem.

releaseoxitlspure-rust
Aug 6, 2026 · 9 min

OxiUI 0.2.2 Released — Multi-Window and the Menu Bar Actually Draw Now, and Two Backends Stop Lying About Success

OxiUI 0.2.2 wires the facade's multi-window registry and menu bar into a real rendering path for the first time (egui opens real OS viewports, iced/headless render the bar too), makes oxiui-slint and oxiui-dioxus return an honest error instead of a fabricated Ok(()), fixes GPU device-loss/OOM panics in oxiui-compute-wgpu, and restores wasm32 compilation for oxiui-web. 2,024 tests passing, the sovereign Pure Rust GUI layer for the COOLJAPAN ecosystem.

releaseoxiuipure-rust
Aug 6, 2026 · 7 min

OxiXML 0.1.1 Released — A Typed SVG Model, Unbounded Precision, and a Global-Variable Fix 156× Faster

OxiXML 0.1.1 is a hardening release: a new typed SVG 1.1/2.0 document model, arbitrary-precision xs:integer/xs:decimal by default, and the query/transform tier locked to its W3C suites — XPath and XQuery 100%, XSLT 98.9%, XSD 1.0/1.1 99.9%. Deliberately breaking, no compatibility shims: 0.1.0 is superseded. Pure Rust, 0 external crates in default features.

releaseoxixmlxml
Aug 5, 2026 · 8 min

OxiGeo 0.2.3 Released — Warped VRTs Finally Parse, and Vector Layers Get a Real `Dataset::layers()` API

OxiGeo 0.2.3 fixes GitHub issue #15 — every gdalwarp -of VRT product was rejected at parse time — with a real backward warp engine in oxigeo-vrt, and issue #16 — Dataset::open on a GeoPackage always reported 0 layers — with a new Dataset::layers()/Layer::features() vector API for GeoPackage, Shapefile, and GeoJSON.

releaseoxigeogdal
Aug 5, 2026 · 5 min

OxiProj 0.1.3 Released — No New Features, Five Inherited Fixes

OxiProj 0.1.3 is a maintenance release: no public API changes, no behavior changes. It pulls forward real hardening from five upstream COOLJAPAN crates — a 44-agent HDF5 interop audit, a CUDA async-copy race-condition fix, faster zero-copy DEFLATE decoding, and OxiZ's soundness sweep — plus a `wide` 1.6 deprecation cleanup in the SIMD scalar power path. Still 100% Pure Rust, no C, no FFI.

releaseoxiprojproj
Aug 5, 2026 · 9 min

OxiZ 0.3.2 Released — Eight Unmerged Pull Requests, One In-House Soundness Sweep, and 168/168 Correct Again

OxiZ 0.3.2 is a soundness release driven by an external differential-testing report: 8 pull requests, 0 merged, every fix independently reimplemented from scratch and backed by a regression test. EUF congruence, Bool/EUF encoding, Arithmetic⇄EUF combination, and NLSAT conflict analysis are all corrected — 168/168 Correct on the Z3 parity suite, 9,953 tests passing. Pure Rust, Apache-2.0.

releaseoxizsmt-solver
Jul 31, 2026 · 9 min

OxiZ 0.3.1 Released — Wide Bit-Vectors Stop Lying, MBQI Reaches Completeness, and 168/168 Correct on the Z3 Parity Suite

OxiZ 0.3.1 is a soundness-and-honesty release: five reported GitHub issues plus 40+ bugs of the same silently-wrong-answer shape are fixed, wide (>64-bit) bit-vectors are now exact via BigUint, and MBQI completeness brings the Z3 differential parity suite to 168/168 Correct, 0 Wrong. 9,668 tests passing. Pure Rust, Apache-2.0.

releaseoxizsmt-solver
Jul 31, 2026 · 10 min

SciRS2 0.6.5 Released — An Ignore-Audit Found the Backward Pass Was Mostly Dead Code

SciRS2 0.6.5 is a defect-hunting release: a workspace-wide audit of every #[ignore]d test found that scirs2-autograd's live backward pass silently identity-passed 223 of 281 differentiable ops instead of computing real gradients, plus real fixes across linalg, stats, graph, io, spatial, ndimage, and special. Pure Rust, Apache-2.0.

releasescirs2rust
Jul 30, 2026 · 7 min

OxiArc 0.4.0 Released — The Decoder Stops Writing Every Byte Twice

OxiArc 0.4.0 rewrites the DEFLATE/zlib decode path for throughput: a two-level Huffman table, a register-resident BitCache, and an output-buffer-as-history design that stops writing every decoded byte twice. New zero-copy inflate_into/zlib_decompress_into APIs, no wire-format change. 2,468 tests passing, Pure Rust.

releaseoxiarcdeflate
Jul 30, 2026 · 8 min

OxiCode 0.2.5 Released — Every Allocation Now Asks Permission First

OxiCode 0.2.5 is a hardening release: fixes decode-time allocation-DoS, decompression-bomb, and checksum-overflow issues across containers, streaming, and derive macros, and replaces a fabricated SIMD speedup claim with real AVX2/SSE2/NEON kernels. No wire-format change for valid input. 20,126 tests passing.

releaseoxicodebincode
Jul 30, 2026 · 7 min

OxiFont 0.2.1 Released — Pure Rust TrueType Hinting Execution Closes the Last Gap to FreeType

OxiFont 0.2.1 ships oxifont-hinting, a from-scratch Pure Rust TrueType bytecode hinting interpreter (grid-fitting VM) that never panics on hostile input, plus a WOFF2 spec-compliance fix and a closed large-allocation DoS in bundled CJK font resolution. The sovereign font layer for the COOLJAPAN ecosystem.

releaseoxifontpure-rust
Jul 30, 2026 · 8 min

OxiGeo 0.2.2 Released — `Dataset::read_band` Finally Returns One Band, and DEFLATE Decoding Is Up to 1.79× Faster

OxiGeo 0.2.2 fixes GitHub issue #14 — Dataset::read_band silently returned the whole multi-band image instead of one band, a defect pattern found and fixed in a dozen crates. Also ships 1.45-1.79x faster DEFLATE decoding and zero-allocation typed raster readers.

releaseoxigeogdal
Jul 30, 2026 · 8 min

OxiText 0.2.1 Released — Color Emoji Go From 0% Pixel Coverage to a Full COLRv1 Paint Graph

OxiText 0.2.1 fixes COLRv0/COLRv1 color-glyph rendering — previously 0% pixel coverage on every color emoji — into a complete paint-graph interpreter with gradients, transforms, clips, and all 28 composite modes, swaps in a Pure-Rust PNG encoder to clear the last banned dependency, and cuts font-cache overhead by up to 13,000x. The sovereign text layer for the COOLJAPAN ecosystem.

releaseoxitextpure-rust
Jul 30, 2026 · 8 min

OxiUI 0.2.1 Released — Lifecycle Hooks Go Live, Persistent State Finally Persists

OxiUI 0.2.1 wires on_close/on_resize/on_focus into the real egui and iced event loops for the first time, makes with_persistent_state actually write to disk via oxicode, and closes an integer-overflow bounds bypass plus an unbounded-iteration DoS in the CPU rasterizer. The sovereign GUI layer for the COOLJAPAN ecosystem.

releaseoxiuipure-rust