build(connector): cap picky-krb below 0.12.5 to unbreak a fresh dependency resolve - #2074
Open
Anton Mostovoy (antonmos) wants to merge 1 commit into
Open
Anton Mostovoy (antonmos) wants to merge 1 commit into
Anton Mostovoy (antonmos) wants to merge 1 commit into
Conversation
…dency resolve picky-krb 0.12.5 (published 2026-10-01) added a variant to the public `GssApiMessageError` enum in a patch release, so every published sspi, up to and including 0.23.0, fails to compile against it with E0004 (non-exhaustive match in sspi's error conversion). Anything that resolves without the committed Cargo.lock now picks 0.12.5 and breaks; the "Check public API compatibility" job does exactly that and fails on every open PR. picky-krb is not a direct dependency of any IronRDP crate, so the cap is a version-constrained dependency on ironrdp-connector (the crate that owns the sspi dependency), referenced with `use picky_krb as _` to satisfy `unused_crate_dependencies`. Remove it once sspi handles the new variant. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Anton Mostovoy (antonmos)
deployed
to
llm-providers
October 3, 2026 19:30 — with
GitHub Actions
Active
Contributor
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The targeted workaround preserves locked versions and introduces no runtime or public API changes.
Review effort: Balanced
Findings: None
What changed in this PR
Adds a targeted dependency cap to keep fresh ironrdp-connector dependency resolution compatible with sspi.
Changes:
- Excludes
picky-krb0.12.5 and later. - Adds a lint-compatible import and lockfile entry without changing resolved versions.
| File | Description |
|---|---|
crates/ironrdp-connector/src/lib.rs |
References the dependency to satisfy lint checks. |
crates/ironrdp-connector/Cargo.toml |
Adds and documents the temporary version cap. |
Cargo.lock |
Records the connector’s direct dependency. |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
picky-krb0.12.5 (published 2026-10-01) added a variant to the publicGssApiMessageErrorenum in a patch release. sspi's error conversion matches that enum exhaustively, so every publishedsspi— up to and including the latest, 0.23.0 — fails to compile against it:Anything that resolves dependencies without the committed
Cargo.locknow picks 0.12.5 and breaks. TheCheck public API compatibilityjob does exactly that, so it currently fails on every open PR (e.g. #1934, #2064, #2068, #2069, #2071) while master — whose last run predates the release — is green. The committed lockfile is on 0.12.4, so normal builds are unaffected.Why a cap, not an sspi bump
Bumping
sspidoes not help: 0.22.1 and 0.23.0 pin the samepicky-krb ^0.12and fail identically against 0.12.5 (verified by building 0.23.0 withpicky-krb0.12.5 and its newerpicky-asn1-*deps). The bump would also carry a 170-package lockfile churn and a source break (TsRequest::buffer_len()now returns aResult). So this PR only constrainspicky-krb.Change
picky-krbis not a direct dependency of any IronRDP crate, so the cap is a version-constrained dependency onironrdp-connector(which owns thesspidependency), referenced withuse picky_krb as _to satisfyunused_crate_dependencies(workspace lint,-D warningsin CI).Cargo.lockgains the one corresponding line; no resolved version changes. A comment inCargo.tomlsays to remove it once ansspirelease handles the new variant.Verified
picky-krb 0.12.4andironrdp/ironrdp-connectorcompile (the failing case in CI).cargo check --locked --workspace --all-targets,cargo fmt --check, andcargo clippy -D warningson the touched crates are clean.🤖 Generated with Claude Code