Skip to content

Exact pins lock every dependent out - #4

Merged
codeitlikemiley merged 1 commit into
mainfrom
fix/relax-exact-pins
Sep 17, 2026
Merged

codeitlikemiley merged 1 commit into
mainfrom
fix/relax-exact-pins

Conversation

@codeitlikemiley

Copy link
Copy Markdown
Owner

Found by the first real dependent. opengrok-server could not add typesafe-sdk at all, and not because of a build error.

The problem

A library that writes =1.0.134 does not pin its own build. It pins its callers'.

This crate pinned eleven dependencies exactly. sqlx 0.9 requires serde_json ^1.0.142; this crate demanded exactly 1.0.134. Nothing satisfies both, so the consuming workspace failed to resolve:

error: failed to select a version for `serde_json`.
    ... required by package `sqlx-core v0.9.0`
versions that meet the requirements `^1.0.142` are: 1

Resolution, not compilation. No feature flag, and not even making the dependency optional, works around it: Cargo resolves optional dependencies too.

indexmap, idna, url, encoding_rs and reqwest are the same trap waiting for whichever neighbour moves next.

The change

Every = becomes a minimum. The versions named are unchanged, so a consumer who wants the old ones still gets them. What changes is that a consumer who needs newer is no longer refused.

Resolution now picks serde_json 1.0.151 here, and the suite passes on it: 32 tests across lib, integration and blocking, with --all-features.

Also fixed, because nothing could be built without it

Cargo.lock on main is the eleven-byte string PLACEHOLDER. Any cargo command in a clean checkout fails with:

error: failed to parse lock file at: Cargo.lock

so the crate could not be built or tested at all. Regenerated.

After this

typesafe-sdk = "0.1" resolves in a workspace that also uses sqlx, and hexuria/opengrok-server#128 merges with no change to it. That PR is currently held open because merging it would make its main branch unbuildable.

Version bumped to 0.1.2. A release is needed for the fix to reach crates.io; 0.1.1 moved the version number but left the constraints as they were.

Not changed

reqwest stays on 0.11, so hyper 0.14, http 0.2 and rustls 0.21 still enter a consumer's graph beside a modern reqwest. That is a real cost and a separate decision.

A library that writes `=1.0.134` does not pin its own build, it pins its
callers'. `typesafe-sdk` pinned eleven dependencies that way, and the first real
dependent hit the wall immediately: sqlx 0.9 requires serde_json ^1.0.142, this
crate demanded exactly 1.0.134, and nothing satisfies both. The workspace did
not fail to build, it failed to RESOLVE, which no feature flag or optional
dependency can work around.

Every `=` becomes a minimum. The versions named are unchanged, so a consumer
that wants the old ones still gets them; what changes is that a consumer who
needs newer is no longer refused. Resolution now picks serde_json 1.0.151 here,
and the suite passes on it: 32 tests across lib, integration and blocking.

Cargo.lock was the eleven-byte string "PLACEHOLDER" on main, so the crate could
not be built or tested from a clean checkout at all. Regenerated.
@codeitlikemiley
codeitlikemiley merged commit e7050df into main Sep 17, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant