Vendored cargo warns cargo_multi_version_old_cargo ("declares no rust-version") when the root package inherits rust-version from [workspace.package]
Maintainer antworten meist innerhalb von 1 Tag
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 2/5
- Geschätzter Aufwand
- 1-3 Stunden
- Anfängerfreundlichkeit
- 84/100
Rechercherichtung
Beginne in crates/socket-patch-core/src/vendor/cargo.rs:90-99 bei declared_cargo_minor und untersuche anschließend crates/socket-patch-cli/tests/e2e_vendor_cargo_build.rs sowie dessen stage_two_versions-Fixture. Reproduziere den geerbten rust-version-Fall und füge Tests hinzu, die zeigen, dass die Workspace-Vererbung erkannt wird, während die no-rust-version-Kontrolle weiterhin warnt. Erledigt ist die Aufgabe, wenn der geerbte Workspace-Fall nicht mehr cargo_multi_version_old_cargo ausgibt.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
[agent] Found by the scheduled Cargo bug-hunt routine (ledger #315).
Summary
When a second version of one crate is vendored, vendor decides whether to emit cargo_multi_version_old_cargo by reading the project's declared cargo floor (declared_cargo_minor). A workspace-root manifest whose [package] inherits the floor with rust-version.workspace = true (and [workspace.package] rust-version = "1.70") is treated as declaring nothing. The project gets the warning, and the warning says it "declares no rust-version or toolchain, so the cargo that builds it is unknown".
The cause: [package].rust-version is present but is a table ({ workspace = true }), not a string. .get("rust-version") returns Some(table), so the .or_else fallback to [workspace.package].rust-version never runs, and then .as_str() yields None.
Impact
Low severity. It's a false, misleading warning, not a broken build. The build is fine. Workspace inheritance needs cargo 1.64+, so any project using rust-version.workspace = true already can't be built by the pre-1.45 cargo the warning is about. Root packages that inherit from [workspace.package] are the standard modern workspace layout, so every multi-version vendor in such a project emits a spurious warning, which trains users to ignore it.
Repro
This used a scratch copy of crates/socket-patch-cli/tests/e2e_vendor_cargo_build.rs (stage_two_versions fixture: cfg-if 1.x plus cfg_if_old = { package = "cfg-if", version = "0.1" }, a marker patch per version, and the prebuilt_common artifact server). Only the root Cargo.toml was swapped, then I ran socket-patch vendor --json --offline:
[workspace]
[workspace.package]
rust-version = "1.70"
[package]
name = "consumer"
version = "0.1.0"
edition = "2018"
rust-version.workspace = true
[dependencies]
cfg-if = "1.0"
cfg_if_old = { package = "cfg-if", version = "0.1" }
root Cargo.toml shape |
cargo build --locked before |
vendor exit |
cargo_multi_version_old_cargo |
cargo run --locked --offline after |
|---|---|---|---|---|
rust-version = "1.70" in [package] |
ok | 0 | no (correct) | MARKER:1:2 |
rust-version.workspace = true + [workspace.package] rust-version = "1.70" |
ok | 0 | yes (wrong) | MARKER:1:2 |
BOM + rust-version = "1.70" |
ok | 0 | no (correct) | MARKER:1:2 |
no rust-version (control) |
ok | 0 | yes (correct) | MARKER:1:2 |
I ran the scratch test twice with identical results. The warning text on the inherited shape:
cfg-if is now vendored at TWO versions (… beside …), which needs cargo 1.45 or newer — this project declares no
rust-versionor toolchain, so the cargo that builds it is unknown. …
Expected vs actual
- Expected. CLI_CONTRACT.md (cargo vendored row) says "a project that does not pin cargo ≥ 1.45 (
rust-versionor toolchain file) gets thecargo_multi_version_old_cargowarning", and docs/ecosystems.md says the warning is skipped when "the project'srust-version… promises cargo 1.45+". The doc comment ondeclared_cargo_minorreads "[package], else[workspace.package]". This project does pin 1.70, through cargo's documented inheritance, so it should get no warning. - Actual. The warning fires and claims the project declares no
rust-version.
OS × version
| OS | cargo | result |
|---|---|---|
| Linux (sandbox) | 1.93.1 | fail (reproduced twice) |
| macOS / Windows | — | untested (pure manifest parsing, so no OS dependence is expected) |
Main 045d7ec (CLI 4.0.0). I didn't bisect this: the multi-version warning was added with the v5 manifest wiring.
Suspect code
crates/socket-patch-core/src/vendor/cargo.rs:90-99 (declared_cargo_minor): doc.get("package").and_then(|p| p.get("rust-version")).or_else(...) short-circuits on the { workspace = true } table. Treat a non-string [package].rust-version (or rust-version.workspace = true) as "look in [workspace.package]". Optionally, treat any use of workspace inheritance as proof of cargo ≥ 1.64.
- Vorherrschende Sprache
- Rust
- Sterne
- 8
- Forks
- 0
- Ø Merge
- 15 Std. 39 Min.
- Gemergte PRs (30 T.)
- 104
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Keine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus SocketDev/socket-patch
-
agent:claimed agent:triaged arch-audit bug pm:hatch priority:p1
Schwierigkeit 2/5 Ein halber Tag Anfängerfreundlichkeit 88/100
SocketDev/socket-patch#613 · 3 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:claimed agent:triaged arch-audit bug priority:p3
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
SocketDev/socket-patch#571 · 5 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:composer priority:p2
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 90/100
SocketDev/socket-patch#515 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:npm priority:p1
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
SocketDev/socket-patch#464 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:npm priority:p1
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
SocketDev/socket-patch#433 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in SocketDev/socket-patch
Ähnliche Issues
-
area:release bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 86/100
registrystack/registry-stack#1874 ·
Maintainer antworten meist innerhalb von 1 Tag
-
component:midnight-toolkit status:untriaged
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
midnightntwrk/midnight-node#2237 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 88/100
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 78/100
Maintainer antworten meist innerhalb von 1 Tag