Exact pins lock every dependent out - #4
Merged
Merged
Conversation
A library that writes `=1.0.134` does not pin its own build, it pins its callers'. `typesafe-sdk` pinned eleven dependencies that way, and the first real dependent hit the wall immediately: sqlx 0.9 requires serde_json ^1.0.142, this crate demanded exactly 1.0.134, and nothing satisfies both. The workspace did not fail to build, it failed to RESOLVE, which no feature flag or optional dependency can work around. Every `=` becomes a minimum. The versions named are unchanged, so a consumer that wants the old ones still gets them; what changes is that a consumer who needs newer is no longer refused. Resolution now picks serde_json 1.0.151 here, and the suite passes on it: 32 tests across lib, integration and blocking. Cargo.lock was the eleven-byte string "PLACEHOLDER" on main, so the crate could not be built or tested from a clean checkout at all. Regenerated.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Found by the first real dependent.
opengrok-servercould not addtypesafe-sdkat all, and not because of a build error.The problem
A library that writes
=1.0.134does not pin its own build. It pins its callers'.This crate pinned eleven dependencies exactly.
sqlx0.9 requiresserde_json ^1.0.142; this crate demanded exactly1.0.134. Nothing satisfies both, so the consuming workspace failed to resolve:Resolution, not compilation. No feature flag, and not even making the dependency optional, works around it: Cargo resolves optional dependencies too.
indexmap,idna,url,encoding_rsandreqwestare the same trap waiting for whichever neighbour moves next.The change
Every
=becomes a minimum. The versions named are unchanged, so a consumer who wants the old ones still gets them. What changes is that a consumer who needs newer is no longer refused.Resolution now picks
serde_json1.0.151 here, and the suite passes on it: 32 tests across lib, integration and blocking, with--all-features.Also fixed, because nothing could be built without it
Cargo.lockonmainis the eleven-byte stringPLACEHOLDER. Anycargocommand in a clean checkout fails with:so the crate could not be built or tested at all. Regenerated.
After this
typesafe-sdk = "0.1"resolves in a workspace that also uses sqlx, and hexuria/opengrok-server#128 merges with no change to it. That PR is currently held open because merging it would make its main branch unbuildable.Version bumped to 0.1.2. A release is needed for the fix to reach crates.io; 0.1.1 moved the version number but left the constraints as they were.
Not changed
reqweststays on 0.11, so hyper 0.14, http 0.2 and rustls 0.21 still enter a consumer's graph beside a modern reqwest. That is a real cost and a separate decision.