Repository navigation
chore #353: upgrade tonic 0.12 → 0.13 to eliminate rand 0.8.5 transitive dependency - #361
Conversation
|
Warning Rate limit exceeded
Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 17 minutes and 56 seconds. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (6)
📒 Files selected for processing (48)
📝 WalkthroughWalkthroughUpgrades gRPC-related workspace dependencies to 0.13 (tonic, tonic-health, tonic-build), bumps rand in benches, replaces Changes
Sequence Diagram(s)sequenceDiagram
participant Leader
participant Follower as Follower/Learner
participant SnapshotApplier as SnapshotApply
participant AckDrain as ACK-Drain-Task
Leader->>Follower: InstallSnapshotChunk (stream of chunks)
Follower->>SnapshotApplier: apply_snapshot_stream_from_leader(chunk)
SnapshotApplier-->>Follower: per-chunk result (await)
Follower->>Leader: send ACK (ack_tx.try_send or send)
Note right of Follower: spawn ACK-Drain-Task to continuously recv from ack_rx
AckDrain->>Follower: drain ack_rx (prevent backpressure)
Leader-->>Follower: continue streaming next chunk
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~30 minutes Possibly related issues
Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 2 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (2 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
5fe9c7e to
f1131e4
Compare
…ive dependency tower 0.4 (pulled in by tonic 0.12) depended on rand 0.8.5, triggering RUSTSEC-2026-0097. tonic 0.13 uses tower 0.5 which drops rand entirely. - tonic/tonic-health/tonic-build: 0.12 → 0.13 - tls feature renamed: `tls` → `tls-ring` (tonic 0.13 breaking change) - Replace `use tonic::async_trait` with `use async_trait::async_trait` across 41 files (removed in tonic 0.13) - Remove mut on health_reporter (now returns immutable in tonic-health 0.13) - Remove RUSTSEC-2026-0097 ignore from deny.toml - Fix embedded-bench: rand 0.8 → 0.9, migrate SmallRng/gen/Alphanumeric API
…large snapshots With _ack_rx dropped, process_snapshot_stream's ack_tx.send().await blocks once the 32-slot buffer fills on chunk 33+, hanging the entire snapshot install. Spawn a drain task so ack_tx never backpressures.
f1131e4 to
9d99e63
Compare
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
What Does This PR Do?
Upgrades tonic 0.12 → 0.13 to eliminate the
rand 0.8.5transitivedependency that triggered security advisory RUSTSEC-2026-0097.
Type:
Why Is This Needed?
tonic 0.12pulls intower 0.4, which depends onrand 0.8.5,triggering RUSTSEC-2026-0097 (unsound
ThreadRngaliasing undercustom logger). The advisory was previously suppressed via
deny.tomlignore.
tonic 0.13usestower 0.5, which drops theranddependencyentirely — this is the only clean fix.
Checklist
Required:
make testpassesTesting
How tested:
cargo check --all-featurespasses with zero warningscargo tree | grep "rand 0.8"returns emptycargo deny check advisoriespasses with RUSTSEC-2026-0097 ignore removedDoes This Follow d-engine's Principles?
Reviewer Notes
All source changes are mechanical:
use tonic::async_trait→use async_trait::async_trait(41 files, tonic 0.13 removed this re-export)tlsfeature →tls-ring(tonic 0.13 split TLS backends)mut health_reporter→health_reporter(tonic-health 0.13 returns immutable)embedded-bench: pre-existingSmallRng/gen/AlphanumericAPI bug fixed by upgrading rand 0.8 → 0.9No logic changes. No API surface changes.
Estimated review complexity:
Summary by CodeRabbit