Repository navigation
fix(graphviz-rust): download release assets by default and link system libs by SONAME - #237
Merged
Merged
Conversation
…m libs by SONAME The published crate carries no native library, so with the GitHub release download gated behind GRAPHVIZ_ANYWHERE_ALLOW_DOWNLOAD every plain `cargo install` of a downstream binary failed in build.rs. Release assets are published before the crate, so make the download the default fallback; GRAPHVIZ_ANYWHERE_NO_DOWNLOAD=1 still keeps builds offline and ALLOW_DOWNLOAD is accepted as a no-op. Once downloaded, linking still failed on hosts without the -dev packages (`library not found: expat`). Link libstdc++, expat and zlib by their runtime SONAMEs via the +verbatim modifier, which requires Rust 1.67. Also point the release links in the docs at the supramark repository.
g65537
approved these changes
Sep 22, 2026
g65537
left a comment
Contributor
There was a problem hiding this comment.
Reviewed the three commits and the full diff; the description matches the code.
Verified:
graphviz-release.yml:publish-cargoneedsrelease, which needs every build job, so thev<version>tag always carries the assets before the crate is published; asset names and thev{CARGO_PKG_VERSION}URL matchtarget_triple_to_asset_nameand the release file list (v0.2.5 has all 14 assets).build.rs: only the opt-in gate is removed;GRAPHVIZ_ANYWHERE_NO_DOWNLOAD=1still short-circuits before any network access, the env override / prebuilt / repooutput/paths run first, wasm32 returns early, and Android/iOS/macOS/Windows link lines are unchanged (the SONAME block is gated ontarget_os == "linux", so Android keeps its empty list).+verbatimwas stabilized in Rust 1.67.0 (rust-lang/rust#104360) and build.rs already used let-else (1.65), sorust-version = "1.67"is accurate.- Local check on a host that has
libexpat.so.1/libstdc++.so.6but nolibexpat.so/libstdc++.sodev symlinks: the base build.rs fails at link time, the PR build.rs downloads the v0.2.5 asset, links, renders SVG, andlddresolves the three SONAMEs;GRAPHVIZ_ANYWHERE_NO_DOWNLOAD=1still gives the descriptive panic;cargo test -p graphviz-anywherepasses (65 tests);cargo metadata --lockedis clean. - rustls 0.23.45 is the patched version for RUSTSEC-2026-0285 / GHSA-2mjx-qc3c-rqvc; the lockfile change is limited to rustls + rustls-webpki.
- Version, CHANGELOG entry and links, and doc release URLs are consistent; all checks are green.
Non-blocking nits, fine to leave for a follow-up:
crates/graphviz-anywhere/examples/rust/Cargo.tomlstill saysrust-version = "1.64"while depending on a 1.67 crate.GRAPHVIZ_ANYWHERE_ALLOW_DOWNLOAD=1inci.yml(release runtime smoke) and inpublish-cargois now a no-op and could be dropped.- Until the v0.2.6 tag exists, an in-repo build without a local
output/tree will attempt the v0.2.6 download and fall through to the same panic as before, just with one extra curl attempt.
This was referenced Sep 23, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
cargo install markon markond(and any other downstream binary that pulls ingraphviz-anywherefrom crates.io) fails inbuild.rs:The published crate ships an empty
prebuilt/and there is no repooutput/tree, so the only viable path is the GitHub release download, which was opt-in viaGRAPHVIZ_ANYWHERE_ALLOW_DOWNLOAD=1(introduced in c48a49b when no release feed existed yet).After enabling the download, linking still failed on hosts without the -dev packages:
Changes
build.rs: the release download is now the default last-resort fallback.GRAPHVIZ_ANYWHERE_NO_DOWNLOAD=1still disables it;GRAPHVIZ_ANYWHERE_ALLOW_DOWNLOADis accepted as a no-op.publish-cargoruns afterrelease, so the tag for the crate version always has assets.build.rs: on Linux, linklibstdc++.so.6,libexpat.so.1andlibz.so.1by SONAME via+verbatim, so only runtime packages are needed. MSRV bumped to 1.67 (verbatim stabilization; build.rs already used let-else from 1.65).Actrium/graphviz-anywhererepo.Verification
cargo package, extracted the.crate, built an external consumer with no env vars on a host withoutlibexpat1-dev: downloaded v0.2.5 assets, linked, rendered DOT → SVG;lddshowslibexpat.so.1/libz.so.1/libstdc++.so.6.GRAPHVIZ_ANYWHERE_NO_DOWNLOAD=1still fails with the descriptive panic.cargo test(65 tests),cargo clippy --all-targets,cargo fmt --checkclean.