Skip to content

show std-replacements & rustsec "unmaintained" in topbar - #3554

Merged
syphar merged 3 commits into
rust-lang:mainfrom
syphar:rustsec-maintainenance
Sep 30, 2026
Merged

syphar merged 3 commits into
rust-lang:mainfrom
syphar:rustsec-maintainenance

Conversation

@syphar

@syphar syphar commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

This is now a new approach for our integration with std-replacements and rustsec.

I still feel like it could be smaller, but also I want test coverage / testability to a certain extend, which enforces some design decisions.

Most important changes:

  • we only refresh the data in a scheduled task , right now once an hour
  • I ignore any remote cache headers
  • for now, the web handler caches for 10 minutes. This can be more, even forever at some point (when we then invalidate precisely)
  • For rustsec, we now just use the "standard" local git repository as source. It will be fetched in the scheduled job. rustsec::Database loads everything into memory on open anyways.
  • Instead of RwLock or something like that, ArcSwap is much better for our use-case. I hope you can excluse the additional dependency :)
old description Here we start showing _crate warnings_ in the topbar.

First is the std-replacement data, and rustsec "unmaintained" warnings.

For both we have a source on github pages, which is heavily cached, and also provides a TTL in the response. So my approach here is to fetch both data sources for the crate, generate the html partial, and set the caching headers in fastly based on the cache TTL responses from gh pages.

85% of docs_rs_reqwest is pretty standard but reduced browser / caching behaviour, but there is no usable crate in the wild that is not alpha, so I rebuilt the logic to some point. Exception from standard logic is caching of 404s even when github doesn't return a caching header for us.

To parse the rustsec response, we could use the rustsec library, but the structs don't provide the necessary accessors, and the osv-export feature pulls in gix, which we don't need and is huge). So I copied the structs as we need them for now. The logic when to show "unmaintained" and when not is coming from crates.io itself. There seem to be some progress in rustsec/rustsec#1710, let's see when that is released. Then I'll just switch back.

For std-replacements, I'll start by fetching all.json and just returning the crate that is asked for. Since we cache the thing, that's not too big of an issue. I'll see if we can also generate per-crate json files in gh pages later. This is also what crates.io is doing at the moment, every browser fetches the whole all.json, and then filters for the current crate. ( at the moment it's 3k compressed).

Since we only use that thing in one place / handler, I didn't invest time into adding mock / test clients to the std-replacement/rustsec libraries, for now. Of course t hat increases the amount of tests in handlers::status and implies the need for http mocks.

first UI draft

suuper basic. When both (unmaintained & std replacement) woud be active, I'm showing another element in the topbar.

image

First draft of the rendering, happy to take ideas? or help?

@syphar syphar self-assigned this Sep 24, 2026
@github-actions github-actions Bot added the S-waiting-on-review Status: This pull request has been implemented and needs to be reviewed label Sep 24, 2026
@syphar
syphar force-pushed the rustsec-maintainenance branch 3 times, most recently from 8444f49 to 8b8275c Compare September 24, 2026 09:49
@syphar
syphar marked this pull request as ready for review September 24, 2026 11:06
@syphar
syphar requested a review from a team as a code owner September 24, 2026 11:06
@syphar

syphar commented Sep 24, 2026

Copy link
Copy Markdown
Member Author

r? @GuillaumeGomez ready for a first review I think.

frontend wise : i would totally use it like this, but if you want we can also iterate on other approaches :)

@rustbot rustbot assigned GuillaumeGomez and unassigned syphar Sep 24, 2026
Comment thread crates/bin/docs_rs_web/static/menu.js
Comment thread crates/lib/docs_rs_rustsec/src/models/advisory/date.rs Outdated
Comment thread crates/lib/docs_rs_rustsec/src/models/osv.rs Outdated
Comment thread crates/lib/docs_rs_rustsec/src/testing/mod.rs Outdated
@syphar
syphar marked this pull request as draft September 24, 2026 11:23
@syphar
syphar marked this pull request as ready for review September 24, 2026 11:27
@syphar
syphar marked this pull request as draft September 24, 2026 11:43
@syphar

syphar commented Sep 25, 2026

Copy link
Copy Markdown
Member Author

@GuillaumeGomez fyi:

having slept over it I think I can simplify this quite far. I also checked how many advisories there are, and std-replacements, and that changes the game.

@syphar
syphar force-pushed the rustsec-maintainenance branch 9 times, most recently from 7bb243d to 14723d5 Compare September 30, 2026 07:20
@syphar
syphar marked this pull request as ready for review September 30, 2026 07:51
@syphar

syphar commented Sep 30, 2026

Copy link
Copy Markdown
Member Author

@GuillaumeGomez ready for a next round

@rustbot

rustbot commented Sep 30, 2026

Copy link
Copy Markdown
Collaborator

☔ The latest upstream changes (possibly #3558) made this pull request unmergeable. Please resolve the merge conflicts.

@syphar
syphar force-pushed the rustsec-maintainenance branch from 14723d5 to 2e1de84 Compare September 30, 2026 13:55
@rustbot

rustbot commented Sep 30, 2026

Copy link
Copy Markdown
Collaborator

This PR was rebased onto a different main commit. Here's a range-diff highlighting what actually changed.

Rebasing is a normal part of keeping PRs up to date, so no action is needed—this note is just to help reviewers.

@syphar
syphar merged commit ffbe0f3 into rust-lang:main Sep 30, 2026
8 checks passed
@syphar
syphar deleted the rustsec-maintainenance branch September 30, 2026 13:56
@github-actions github-actions Bot added S-waiting-on-deploy This PR is ready to be merged, but is waiting for an admin to have time to deploy it and removed S-waiting-on-review Status: This pull request has been implemented and needs to be reviewed labels Sep 30, 2026
@syphar syphar removed the S-waiting-on-deploy This PR is ready to be merged, but is waiting for an admin to have time to deploy it label Sep 30, 2026

This branch was successfully deployed

1 active deployment
github-pages — 2e1de843 Deployed Sep 30, 2026 by syphar via deploy #587
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants