From 0075b5d4e57328b39938b1977a9b98e4abae8100 Mon Sep 17 00:00:00 2001 From: Tim Date: Sun, 4 Oct 2026 09:07:55 -0700 Subject: [PATCH] bump rusty_alloc-api to =2.2.2 Follows 2ba0ba0 (=1.1.6) one major on, to the =2.2.2 house standard. This pin gates the allocator for everything downstream of thoth: the released v0.3.0 tag still carries =0.4.0, so a consumer bumping to it today would take on an allocator two majors stale rather than shed one. Also corrects the comment above the pin, which claimed to be in step with rusty_expressions "1.1.4" while the pin next to it read =1.1.6. rusty_expressions moves to =2.2.2 alongside this; the two must be RELEASED together, because the whole point of the in-step pin is that a consumer enabling both crates' allocators cannot pull two incompatible majors. thoth's own build does not depend on that ordering -- rusty_expressions is declared `default-features = false`, which keeps its optional allocator out of the graph entirely. Verified both ways: against published rusty_expressions 0.2.2 and against the =2.2.2 branch via [patch.crates-io], `cargo tree` shows exactly one rusty_alloc-api (v2.2.2) in each, and all 24 tests pass under --all-features. Co-Authored-By: Claude Opus 5 (1M context) --- Cargo.toml | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/Cargo.toml b/Cargo.toml index 0fa4332..cf95521 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -43,9 +43,10 @@ expr-count = ["expressions", "rusty_expressions/expr-count"] [dependencies] # Optional so `default-features = false` removes it from the graph entirely. # Pin exactly: earlier releases had UAFs on all targets. Kept in step with -# rusty_expressions, which moved to 1.1.4 -- a consumer that enables both -# crates' allocators would otherwise pull two incompatible majors. -rusty_alloc-api = { version = "=1.1.6", optional = true } +# rusty_expressions, which moves to =2.2.2 alongside this -- a consumer that +# enables both crates' allocators would otherwise pull two incompatible majors. +# Releasing one without the other re-opens exactly that hazard. +rusty_alloc-api = { version = "=2.2.2", optional = true } # The Oniguruma remake, split out of this repo and published standalone. # `default-features = false` is LOAD-BEARING: rusty_expressions installs # rusty_alloc as a #[global_allocator] by default, and so does this crate -- @@ -62,3 +63,4 @@ required-features = ["a11y", "css"] [[example]] name = "expressions_demo" required-features = ["expressions"] +