Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

Vendored cargo warns cargo_multi_version_old_cargo ("declares no rust-version") when the root package inherits rust-version from [workspace.package]

未關閉 適合新手
#651 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

維護者通常 1 天內回覆

還沒有人認領這個 Issue。

評估

難度
2/5
預估耗時
1-3 小時
新手友好度
84/100
Issue 類型
缺陷
描述清晰度
描述清楚
活躍度
活躍
技術堆疊
rust
領域
cli

研究方向

從 crates/socket-patch-core/src/vendor/cargo.rs:90-99 的 declared_cargo_minor 開始,接著檢查 crates/socket-patch-cli/tests/e2e_vendor_cargo_build.rs 及其 stage_two_versions fixture。重現繼承的 rust-version 情況,並新增覆蓋以顯示 workspace 繼承已被辨識,同時 no-rust-version 控制仍會發出警告。繼承的 workspace 情況不再發出 cargo_multi_version_old_cargo 即表示完成。

由索引模型根據 Issue 內容生成。

描述

agent:triaged bug bughunt pm:cargo priority:p2

[agent] Found by the scheduled Cargo bug-hunt routine (ledger #315).

Summary

When a second version of one crate is vendored, vendor decides whether to emit cargo_multi_version_old_cargo by reading the project's declared cargo floor (declared_cargo_minor). A workspace-root manifest whose [package] inherits the floor with rust-version.workspace = true (and [workspace.package] rust-version = "1.70") is treated as declaring nothing. The project gets the warning, and the warning says it "declares no rust-version or toolchain, so the cargo that builds it is unknown".

The cause: [package].rust-version is present but is a table ({ workspace = true }), not a string. .get("rust-version") returns Some(table), so the .or_else fallback to [workspace.package].rust-version never runs, and then .as_str() yields None.

Impact

Low severity. It's a false, misleading warning, not a broken build. The build is fine. Workspace inheritance needs cargo 1.64+, so any project using rust-version.workspace = true already can't be built by the pre-1.45 cargo the warning is about. Root packages that inherit from [workspace.package] are the standard modern workspace layout, so every multi-version vendor in such a project emits a spurious warning, which trains users to ignore it.

Repro

This used a scratch copy of crates/socket-patch-cli/tests/e2e_vendor_cargo_build.rs (stage_two_versions fixture: cfg-if 1.x plus cfg_if_old = { package = "cfg-if", version = "0.1" }, a marker patch per version, and the prebuilt_common artifact server). Only the root Cargo.toml was swapped, then I ran socket-patch vendor --json --offline:

[workspace]

[workspace.package]
rust-version = "1.70"

[package]
name = "consumer"
version = "0.1.0"
edition = "2018"
rust-version.workspace = true

[dependencies]
cfg-if = "1.0"
cfg_if_old = { package = "cfg-if", version = "0.1" }
root Cargo.toml shape cargo build --locked before vendor exit cargo_multi_version_old_cargo cargo run --locked --offline after
rust-version = "1.70" in [package] ok 0 no (correct) MARKER:1:2
rust-version.workspace = true + [workspace.package] rust-version = "1.70" ok 0 yes (wrong) MARKER:1:2
BOM + rust-version = "1.70" ok 0 no (correct) MARKER:1:2
no rust-version (control) ok 0 yes (correct) MARKER:1:2

I ran the scratch test twice with identical results. The warning text on the inherited shape:

cfg-if is now vendored at TWO versions (… beside …), which needs cargo 1.45 or newer — this project declares no rust-version or toolchain, so the cargo that builds it is unknown. …

Expected vs actual

  • Expected. CLI_CONTRACT.md (cargo vendored row) says "a project that does not pin cargo ≥ 1.45 (rust-version or toolchain file) gets the cargo_multi_version_old_cargo warning", and docs/ecosystems.md says the warning is skipped when "the project's rust-version … promises cargo 1.45+". The doc comment on declared_cargo_minor reads "[package], else [workspace.package]". This project does pin 1.70, through cargo's documented inheritance, so it should get no warning.
  • Actual. The warning fires and claims the project declares no rust-version.

OS × version

OS cargo result
Linux (sandbox) 1.93.1 fail (reproduced twice)
macOS / Windows — untested (pure manifest parsing, so no OS dependence is expected)

Main 045d7ec (CLI 4.0.0). I didn't bisect this: the multi-version warning was added with the v5 manifest wiring.

Suspect code

crates/socket-patch-core/src/vendor/cargo.rs:90-99 (declared_cargo_minor): doc.get("package").and_then(|p| p.get("rust-version")).or_else(...) short-circuits on the { workspace = true } table. Treat a non-string [package].rust-version (or rust-version.workspace = true) as "look in [workspace.package]". Optionally, treat any use of workspace inheritance as proof of cargo ≥ 1.64.

主要語言
Rust
星號
8
分支
0
平均合併
15 小時 39 分鐘
30 天內合併 PR
104

環境準備

  • 沒有 Dockerfile 或 Docker Compose 檔案
  • 沒有 Pull Request 範本
  • 閱讀貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

SocketDev/socket-patch 的其他 Issue

查看 SocketDev/socket-patch 的全部 Issue

相似的 Issue

更多 Rust Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。