Skip to content

chore: update Rust dependencies (2026-09-25) - #25

Open
cohix wants to merge 1 commit into
mainfrom
chore/update-dependencies-2026-09-25
Open

cohix wants to merge 1 commit into
mainfrom
chore/update-dependencies-2026-09-25

Conversation

@cohix

@cohix cohix commented Sep 25, 2026

Copy link
Copy Markdown
Collaborator

Summary

Routine dependency refresh: cargo update at the repo root on 2026-09-25. Eight transitive lockfile entries moved. No source changes were needed.

Crates that moved (all transitive)

Crate Old New
hyper-util 0.1.20 0.1.21
rustls-platform-verifier 0.7.0 0.7.1
rustls-platform-verifier-android 0.1.1 0.2.0
smallvec 1.16.1 1.16.2
thiserror 2.0.20 2.0.21
thiserror-impl 2.0.20 2.0.21
zerocopy 0.8.57 0.8.58
zerocopy-derive 0.8.57 0.8.58

Side effects visible in the diff: hyper-util 0.1.21 now depends on base64 0.23.1 (already in the tree) instead of base64 0.22.1, and adds httparse (already in the tree). Every other hunk is a thiserror 2.0.20 -> 2.0.21 reference or a checksum.

rustls-platform-verifier-android is an Android-only artifact (the Kotlin verifier shim pulled in by rustls-platform-verifier); it is not compiled on any awman target.

What did not move, and why

  • Cargo.toml needed no change. All 43 direct requirements (dependencies, dev-dependencies and the cfg(unix) block) were checked against the crates.io index on 2026-09-25: the latest stable release of every one is already inside its existing caret range (e.g. clap 4.6.7, tokio 1.53.1, reqwest 0.13.5, axum 0.8.9, ratatui 0.30.2, rusqlite 0.40.2, toml 1.1.6, thiserror 2.0.21).
  • cargo update --verbose reports two crates "behind latest" that cannot move: matchit 0.8.4 (axum 0.8.9 requires =0.8.4) and generic-array 0.14.7 (crypto-common 0.1.7 requires =0.14.7, reached via sha2 0.10 → termwiz → ratatui-termwiz → ratatui). Exact pins held by parent crates; out of scope.
  • ~90 other lock entries sit below their absolute latest (bitflags 1.x, base64 0.22, thiserror 1.x, nix 0.28/0.29, syn 1.x, windows-* 0.52/0.62, getrandom 0.2/0.3, rand 0.8, …). These are cross-major pins held by parent crates; cargo update cannot move them and forcing them would break the build. Left alone deliberately.
  • GitHub Actions are already on their newest majors: actions/checkout@v7, actions/cache@v6, actions/upload-artifact@v7, actions/download-artifact@v8, softprops/action-gh-release@v3, dtolnay/rust-toolchain@stable (pinned to 1.94.0). Verified against each action's latest release tag.
  • tools/oci-runtime-spike/**/Cargo.lock left untouched on purpose. The four lockfiles under fixture/, sqlite-resolution/probe/, strict-embed/probe/ and strict-embed/full-probe/ belong to standalone throwaway probe crates for the OCI-runtime spike. The root Cargo.toml has no [workspace], and nothing in the Makefile, tools/*.sh, scripts/ or .github/workflows/ builds them (grepped). They exist to pin the specific versions the spike was run against, so bumping them would be churn with no benefit. This was a deliberate choice, not an oversight.

Validation

Run locally with Rust 1.94.0 (the CI toolchain) on linux/aarch64:

Command Result
make architecture-lint pass
cargo fmt --check pass
cargo clippy --all-targets -- -D warnings pass, no warnings
make test-fast pass: 3408 passed, 0 failed, 4 ignored across 33 test binaries
cargo build --release pass, binary runs (awman 0.12.0)

Environment caveat for make test-fast: the preparation VM sat on a nearly full host disk and silently zeroed large freshly written object files on the first attempts (ext4 reported block-device write errors). The passing run above was done after clearing target/, with CARGO_BUILD_JOBS=3, CARGO_INCREMENTAL=0 and CARGO_PROFILE_DEV_DEBUG=0 / CARGO_PROFILE_TEST_DEBUG=0 to keep artifacts small, and with the ext4 error counter confirmed unchanged for the whole run. Debuginfo level does not affect test semantics; CI runs the default profile and is the authoritative check.

make test-full was not run locally: Docker is not available in the environment this PR was prepared in. The "Full tests with Docker (Linux)" CI job covers it.

Reviewer notes

  • The diff is Cargo.lock only; review is mostly confirming the table above matches the hunks.
  • hyper-util's switch to base64 0.23 is the only dependency-graph shape change.

🤖 Generated with Claude Code

Run `cargo update` at the repo root. Eight transitive lockfile entries
moved; no Cargo.toml requirement changed.

  hyper-util                      0.1.20 -> 0.1.21
  rustls-platform-verifier        0.7.0  -> 0.7.1
  rustls-platform-verifier-android 0.1.1 -> 0.2.0
  smallvec                        1.16.1 -> 1.16.2
  thiserror                       2.0.20 -> 2.0.21
  thiserror-impl                  2.0.20 -> 2.0.21
  zerocopy                        0.8.57 -> 0.8.58
  zerocopy-derive                 0.8.57 -> 0.8.58

The four Cargo.lock files under tools/oci-runtime-spike/ are standalone
probe crates that nothing in the Makefile, tools/ or CI builds; they are
deliberately left untouched.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants