anvilsign in

collin/anvil · a60d607b

Remove three unused dependencies and gix's blob-diff feature

Collin Richards · 2026-08-25 06:35 UTC · a60d607b17fdb7f62a29e6bb2cbfc02dae7d40d6 · parent 0b6dde80 · browse files

modifiedCargo.lock+0 −64
⋯ 138 unchanged lines
139139 version = "0.0.0"
140140 dependencies = [
141141 "anvil-core",
142- "anvil-docker",
143142 "anvil-git",
144143 "anvil-job",
145144 "flate2",
⋯ 24 unchanged lines
170169 "ssh-key",
171170 "time",
172171 "tokio",
173- "tracing",
174172 "tracing-subscriber",
175173 ]
176174
⋯ 81 unchanged lines
258256 "anvil-core",
259257 "anvil-git",
260258 "anvil-job",
261- "argon2",
262259 "axum",
263260 "axum-extra",
264261 "base64",
⋯ 748 unchanged lines
10131010 ]
10141011
10151012 [[package]]
1016-name = "dashmap"
1017-version = "6.2.1"
1018-source = "registry+https://github.com/rust-lang/crates.io-index"
1019-checksum = "e6361d5c062261c78a176addb82d4c821ae42bed6089de0e12603cd25de2059c"
1020-dependencies = [
1021- "cfg-if",
1022- "crossbeam-utils",
1023- "hashbrown 0.14.5",
1024- "lock_api",
1025- "once_cell",
1026- "parking_lot_core",
1027-]
1028-
1029-[[package]]
10301013 name = "data-encoding"
10311014 version = "2.11.1"
10321015 source = "registry+https://github.com/rust-lang/crates.io-index"
⋯ 570 unchanged lines
16031586 dependencies = [
16041587 "gix-actor",
16051588 "gix-attributes",
1606- "gix-command",
16071589 "gix-commitgraph",
16081590 "gix-config",
16091591 "gix-date",
⋯ 6 unchanged lines
16161598 "gix-glob",
16171599 "gix-hash",
16181600 "gix-hashtable",
1619- "gix-ignore",
16201601 "gix-index",
16211602 "gix-lock",
16221603 "gix-note",
⋯ 10 unchanged lines
16331614 "gix-revwalk",
16341615 "gix-sec",
16351616 "gix-shallow",
1636- "gix-submodule",
16371617 "gix-tempfile",
16381618 "gix-trace",
16391619 "gix-traverse",
⋯ 132 unchanged lines
17721752 checksum = "1b1689ff5ddeee4acfb2a43e875a1072a76d208624b15a9065c938b39cb0da2a"
17731753 dependencies = [
17741754 "bstr",
1775- "gix-command",
1776- "gix-filter",
1777- "gix-fs",
17781755 "gix-hash",
1779- "gix-imara-diff",
17801756 "gix-object",
1781- "gix-path",
1782- "gix-tempfile",
1783- "gix-trace",
1784- "gix-traverse",
1785- "gix-worktree",
17861757 "thiserror",
17871758 ]
17881759
⋯ 123 unchanged lines
19121883 ]
19131884
19141885 [[package]]
1915-name = "gix-imara-diff"
1916-version = "0.2.5"
1917-source = "registry+https://github.com/rust-lang/crates.io-index"
1918-checksum = "1c91d8cffac8849493a82233811bd02b2b183b8cf39bf704de0fa0841b737595"
1919-dependencies = [
1920- "bstr",
1921- "hashbrown 0.17.1",
1922-]
1923-
1924-[[package]]
19251886 name = "gix-index"
19261887 version = "0.55.0"
19271888 source = "registry+https://github.com/rust-lang/crates.io-index"
⋯ 63 unchanged lines
19911952 dependencies = [
19921953 "bstr",
19931954 "gix-actor",
1994- "gix-command",
19951955 "gix-date",
19961956 "gix-features",
19971957 "gix-hash",
19981958 "gix-hashtable",
1999- "gix-tempfile",
20001959 "gix-utils",
20011960 "gix-validate",
20021961 "itoa",
⋯ 212 unchanged lines
22152174 ]
22162175
22172176 [[package]]
2218-name = "gix-submodule"
2219-version = "0.34.0"
2220-source = "registry+https://github.com/rust-lang/crates.io-index"
2221-checksum = "da85564d6725c483b8d95d7b31d1db0b78c29e462a2b481949e2f18e1ed55a6a"
2222-dependencies = [
2223- "bstr",
2224- "gix-config",
2225- "gix-path",
2226- "gix-pathspec",
2227- "gix-refspec",
2228- "gix-url",
2229- "thiserror",
2230-]
2231-
2232-[[package]]
22332177 name = "gix-tempfile"
22342178 version = "24.0.0"
22352179 source = "registry+https://github.com/rust-lang/crates.io-index"
22362180 checksum = "b675b920bd5a61d17ad542772f03ec34c60feb8ff683e1560c03ae967363731e"
22372181 dependencies = [
2238- "dashmap",
22392182 "gix-fs",
22402183 "libc",
22412184 "parking_lot",
⋯ 90 unchanged lines
23322275 "gix-index",
23332276 "gix-object",
23342277 "gix-path",
2335- "gix-validate",
23362278 ]
23372279
23382280 [[package]]
⋯ 43 unchanged lines
23822324 dependencies = [
23832325 "byteorder",
23842326 ]
2385-
2386-[[package]]
2387-name = "hashbrown"
2388-version = "0.14.5"
2389-source = "registry+https://github.com/rust-lang/crates.io-index"
2390-checksum = "e5274423e17b7c9fc20b6e7e208532f9b19825d82dfd615708b70edd83df41f1"
23912327
23922328 [[package]]
23932329 name = "hashbrown"
⋯ 3564 unchanged lines
modifiedCargo.toml+1 −1
⋯ 91 unchanged lines
9292 flate2 = { version = "1" }
9393 futures-util = { version = "0.3" }
9494 gitserver-core = { path = "vendor/gitserver-core" }
95-gix = { version = "0.87.1", default-features = false, features = ["sha1", "max-performance-safe", "blob-diff", "revision"] }
95+gix = { version = "0.87.1", default-features = false, features = ["sha1", "max-performance-safe", "revision"] }
9696 gix-pack = { version = "0.74.2", features = ["sha1"] }
9797 hmac = { version = "0.13.0" }
9898 lru = { version = "0.18.2" }
⋯ 26 unchanged lines
modifiedclippy.toml+33 −30
11 # Duplicates `clippy::multiple_crate_versions` is allowed to ignore.
22 #
3-# The lint is on (see `[workspace.lints.clippy]` in Cargo.toml) so that a *new*
4-# duplicate has to be argued for. Everything below is a duplicate we cannot
5-# remove from here: some other crate in the tree pins the older copy, and the
6-# only fix is that crate moving. Each entry says who is holding it, so this
7-# list doubles as the "what are we waiting on" record — when a bump makes an
8-# entry unnecessary, delete it rather than leaving it to rot.
3+# The lint is on (see `[workspace.lints.clippy]` in Cargo.toml) so a *new*
4+# duplicate has to be argued for. Everything below is one we cannot remove from
5+# here: another crate in the tree pins the older copy and the only fix is that
6+# crate moving. Each entry names who is holding it, so the list doubles as a
7+# record of what we are waiting on — when a bump makes an entry unnecessary,
8+# delete it rather than leaving it to rot.
9+#
10+# Five have left that way rather than by being tolerated:
11+# argon2, blake2, password-hash taking argon2 0.6, which ssh-key was on
12+# base64 holding at 0.22 to match axum, since 0.23
13+# added nothing we use
14+# tower-http it was declared and never used, so the
15+# whole dependency went
16+#
17+# `rand` is the one that looks collapsible and is not. axum's websockets pull
18+# 0.9 and we are on 0.10, which is the base64 situation exactly — except
19+# ssh-key rc.11 only accepts an RNG implementing rand_core 0.10's traits, so
20+# moving to 0.9 trades the duplicate for a compile error in anvil-ssh. It waits
21+# for axum.
922 #
10-# Nothing here is ours to collapse today: `argon2` was, and was taken, which
11-# is what removed argon2, blake2 and password-hash from this list.
23+# Note this list is checked against the dev- and build-dependency graph too,
24+# not just `cargo tree -e normal`: several entries here are duplicated only
25+# once test targets are counted.
1226
1327 allowed-duplicate-crates = [
14- # --- The RustCrypto `digest` 0.10 -> 0.11 seam ------------------------
15- # Half the tree has moved to digest 0.11 (aes-gcm, ssh-key, russh, our own
16- # sha2/hmac) and half has not (gix's sha1, `rsa` 0.9 in anvil-web's tests,
17- # argon2 0.5). Every crate below is simply the same crate on both sides of
18- # that line, and they collapse when the stragglers move — mostly gix.
28+ # The RustCrypto `digest` 0.10 -> 0.11 seam. Half the tree has crossed it
29+ # (aes-gcm, argon2, ssh-key, russh, our sha2/hmac) and half has not — gix's
30+ # sha1, and `rsa` 0.9 in anvil-web's tests. Each crate here is the same
31+ # crate on both sides of that line; they collapse together when gix moves.
1932 "block-buffer",
2033 "const-oid",
2134 "cpufeatures",
⋯ 3 unchanged lines
2538 "sha1",
2639 "sha3",
2740
28- # --- Held by direct dependencies of ours ------------------------------
29- "hashlink", # rusqlite 0.40 moved to 0.12; something older wants 0.11.
30- "rand", # axum's websockets are on 0.9; ssh-key needs rand_core 0.10,
31- # so we cannot meet them — see the note below.
32- # `base64` used to sit here: we were on 0.23 and axum 0.8 on 0.22. We hold
33- # at 0.22 to match axum rather than carry two copies — 0.23 bought us
34- # nothing we use, so the duplicate was the whole cost. Revisit when axum
35- # moves. `tower-http` also used to sit here and turned out to be declared
36- # and never used at all, so it left with the dependency.
37- #
38- # `rand` is the case where meeting in the middle does not work: axum's
39- # websockets pull 0.9, but ssh-key rc.11 will only take an RNG on
40- # rand_core 0.10, which is rand 0.10. Downgrading trades one duplicate for
41- # a compile error, so this one waits for axum.
41+ # Held apart by our own direct dependencies, with no version suiting both.
42+ # See the note on `rand` above.
43+ "rand",
44+ "rand_core",
4245
43- # --- Entirely inside other crates' trees ------------------------------
46+ # Entirely inside other crates' trees; nothing we declare picks these.
4447 "bitflags", # 1.x lingers under a few transitive crates.
4548 "foldhash", # gix-pack's clru vs jaq-json.
4649 "getrandom", # 0.2/0.3/0.4 across rand, ring and gix.
47- "hashbrown", # three copies, all within gix's own sub-crates.
50+ "hashbrown", # two copies, both within gix's own sub-crates.
51+ "hashlink", # rusqlite 0.40 is on 0.12; something older wants 0.11.
4852 "r-efi", # a getrandom UEFI backend, one per getrandom major.
49- "rand_core", # tracks the getrandom split above.
5053 "syn", # proc-macro crates mid-migration from 2.x to 3.x.
5154 ]
modifiedcrates/anvil-ci/Cargo.toml+0 −1
⋯ 11 unchanged lines
1212
1313 [dependencies]
1414 anvil-core.workspace = true
15-anvil-docker.workspace = true
1615 anvil-job.workspace = true
1716 anvil-git.workspace = true
1817 flate2.workspace = true
⋯ 8 unchanged lines
modifiedcrates/anvil-cli/Cargo.toml+0 −1
⋯ 32 unchanged lines
3333 # `encryption` so a passphrase-protected private key can be opened locally —
3434 # the CLI is the only half of anvil that ever holds a private key.
3535 ssh-key = { workspace = true, features = ["encryption"] }
36-tracing.workspace = true
3736 tracing-subscriber.workspace = true
modifiedcrates/anvil-web/Cargo.toml+0 −1
⋯ 37 unchanged lines
3838 [dev-dependencies]
3939 tempfile = { version = "3" }
4040 serde_json.workspace = true
41-argon2.workspace = true
4241 rand.workspace = true
4342 ssh-key = { workspace = true, features = ["ed25519"] }
4443 tokio = { workspace = true }
⋯ 9 unchanged lines