Skip to content

build(connector): cap picky-krb below 0.12.5 to unbreak a fresh dependency resolve - #2074

Open
Anton Mostovoy (antonmos) wants to merge 1 commit into
Devolutions:masterfrom
antonmos:fix/sspi-picky-krb-compat
Open

Anton Mostovoy (antonmos) wants to merge 1 commit into
Devolutions:masterfrom
antonmos:fix/sspi-picky-krb-compat

Conversation

@antonmos

Copy link
Copy Markdown
Contributor

Problem

picky-krb 0.12.5 (published 2026-10-01) added a variant to the public GssApiMessageError enum in a patch release. sspi's error conversion matches that enum exhaustively, so every published sspi — up to and including the latest, 0.23.0 — fails to compile against it:

error[E0004]: non-exhaustive patterns: `GssApiMessageError::InvalidMechanismOid(_, _)` not covered
   --> sspi-0.21.3/src/lib.rs:2356:15

Anything that resolves dependencies without the committed Cargo.lock now picks 0.12.5 and breaks. The Check public API compatibility job does exactly that, so it currently fails on every open PR (e.g. #1934, #2064, #2068, #2069, #2071) while master — whose last run predates the release — is green. The committed lockfile is on 0.12.4, so normal builds are unaffected.

Why a cap, not an sspi bump

Bumping sspi does not help: 0.22.1 and 0.23.0 pin the same picky-krb ^0.12 and fail identically against 0.12.5 (verified by building 0.23.0 with picky-krb 0.12.5 and its newer picky-asn1-* deps). The bump would also carry a 170-package lockfile churn and a source break (TsRequest::buffer_len() now returns a Result). So this PR only constrains picky-krb.

Change

picky-krb is not a direct dependency of any IronRDP crate, so the cap is a version-constrained dependency on ironrdp-connector (which owns the sspi dependency), referenced with use picky_krb as _ to satisfy unused_crate_dependencies (workspace lint, -D warnings in CI). Cargo.lock gains the one corresponding line; no resolved version changes. A comment in Cargo.toml says to remove it once an sspi release handles the new variant.

Verified

  • A resolve with no lockfile now lands on picky-krb 0.12.4 and ironrdp / ironrdp-connector compile (the failing case in CI).
  • cargo check --locked --workspace --all-targets, cargo fmt --check, and cargo clippy -D warnings on the touched crates are clean.

🤖 Generated with Claude Code

…dency resolve

picky-krb 0.12.5 (published 2026-10-01) added a variant to the public
`GssApiMessageError` enum in a patch release, so every published sspi,
up to and including 0.23.0, fails to compile against it with E0004
(non-exhaustive match in sspi's error conversion). Anything that resolves
without the committed Cargo.lock now picks 0.12.5 and breaks; the
"Check public API compatibility" job does exactly that and fails on every
open PR.

picky-krb is not a direct dependency of any IronRDP crate, so the cap is
a version-constrained dependency on ironrdp-connector (the crate that owns
the sspi dependency), referenced with `use picky_krb as _` to satisfy
`unused_crate_dependencies`. Remove it once sspi handles the new variant.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 3, 2026 19:30
@github-actions github-actions Bot added automation-failed Exact-head automated classification or review failed or was unavailable risk/unknown Risk could not be determined automatically; needs maintainer-level scrutiny scope/core Touches the core architectural tier size/S Size: up to 199 counted lines and 5 files; exceeds XS in either measure labels Oct 3, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The targeted workaround preserves locked versions and introduces no runtime or public API changes.

Review effort: Balanced
Findings: None

What changed in this PR

Adds a targeted dependency cap to keep fresh ironrdp-connector dependency resolution compatible with sspi.

Changes:

  • Excludes picky-krb 0.12.5 and later.
  • Adds a lint-compatible import and lockfile entry without changing resolved versions.
File Description
crates/​ironrdp-connector/​src/​lib.rs References the dependency to satisfy lint checks.
crates/​ironrdp-connector/​Cargo.toml Adds and documents the temporary version cap.
Cargo.lock Records the connector’s direct dependency.

This branch was successfully deployed

1 active deployment
llm-providers — 47b8ad09 Deployed Oct 3, 2026 by antonmos via Classify pull request #1598
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automation-failed Exact-head automated classification or review failed or was unavailable risk/unknown Risk could not be determined automatically; needs maintainer-level scrutiny scope/core Touches the core architectural tier size/S Size: up to 199 counted lines and 5 files; exceeds XS in either measure

Development

Successfully merging this pull request may close these issues.

2 participants