Repository navigation
build(connector): remove the picky-krb cap - #2087
Benoît Cortier (CBenoit) merged 1 commit into
Conversation
picky-krb 0.12.5 added a variant to the exhaustive GssApiMessageError enum, breaking every published sspi release. That version has since been yanked from crates.io, so a fresh resolve selects 0.12.4 again and the cap added in #2074 is no longer needed. The same code will be re-released as picky-krb 0.13.0 (Devolutions/picky-rs#549). This reverts commit 4132836. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The focused change exactly reverts the obsolete dependency workaround while preserving the transitive 0.12.4 resolution.
Review effort: Balanced
Findings: None
What changed in this PR
Removes the temporary picky-krb cap after the incompatible release was yanked.
Changes:
- Removes the dependency cap and placeholder import.
- Updates the lockfile accordingly.
- No findings identified; protocol review was unnecessary.
| File | Description |
|---|---|
Cargo.lock |
Removes the direct connector dependency entry. |
crates/ironrdp-connector/Cargo.toml |
Removes the temporary version constraint. |
crates/ironrdp-connector/src/lib.rs |
Removes the placeholder import. |
|
This pull request may overlap with #2080. Both PRs manage the picky-krb version constraint in ironrdp-connector tied to sspi compatibility. PR 2080's description states picky-krb is held at 0.12.4 because sspi 0.23.0 does not build against 0.12.5, which is the exact cap this PR removes from the connector manifest, its dummy 'use picky_krb as _', and the lockfile. A human should confirm the dependency-resolution interplay. This notice is advisory only. Automated review continues as usual, and how these pull requests relate is for maintainers and authors to decide. Note LLM-assisted content (no human feedback). |
There was a problem hiding this comment.
PR #2087 is a clean, minimal revert of the picky-krb >=0.12.0,<0.12.5 version cap introduced in #2074: it removes the placeholder dependency from crates/ironrdp-connector/Cargo.toml, the `use picky_krb as _;` marker import from src/lib.rs, and the corresponding Cargo.lock edge. Verified independently: no dangling references to picky_krb remain in the connector crate, and picky-krb 0.12.4 is still correctly locked in Cargo.lock as a transitive dependency of sspi. The justification (0.12.5 — a patch release that added a variant to the exhaustive GssApiMessageError enum, breaking published sspi with E0004 — was yanked, with the same code slated for re-release as 0.13.0) is coherent and not contradicted by repository evidence. The only residual risk is that the crates.io yank becomes the sole guard against the breakage recurring (e.g., 0.12.5 un-yanked or another 0.12.x shipping the variant); that claim cannot be verified from repository evidence, so it is published as a low-severity open…
- [skeptical] Removing the picky-krb cap leaves the crates.io yank as the only guard against a repeat of the sspi E0004 breakage — low 🟡 ❓ — crates/ironrdp-connector/Cargo.toml
The cap existed because picky-krb 0.12.5 (a patch release) added a variant to the exhaustive public GssApiMessageError enum, breaking every published sspi (<=0.23.0) with E0004 on fresh resolves. After this change, no manifest constraint prevents selecting a 0.12.x containing that variant; protection rests entirely on 0.12.5 being yanked. The PR body asserts the same code will ship as 0.13.0, which would make the yank durable, but neither the yank nor the 0.13.0 plan is verifiable from repository evidence, and the 0.12-line precedent shows patch releases can reintroduce the breakage (or 0.12.5 could be un-yanked). If that occurs, every fresh resolve breaks with a confusing non-local E0004. Counterpoints keep this low: the cap also blocked legitimate 0.12.x fixes, the failure is build-time not runtime, and re-adding the two-line cap is trivial. Confirm the yank status and 0.13.0 plan, or note in the PR that the cap should be re-added if the yank is lifted.
picky-krb 0.12.5 added a variant to the exhaustive
GssApiMessageErrorenum, breaking every published sspi release. That version has since been yanked from crates.io, so a fresh resolve selects 0.12.4 again and the cap added in #2074 is no longer needed. The same code will be re-released as picky-krb 0.13.0 (Devolutions/picky-rs#549).This reverts commit 4132836.