Re: [PATCH 1/7] xdiff: introduce rust
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Jul 17, 2025, 21:54 UTC
- Message-ID
- <xmqq1pqe5vpv.fsf@gitster.g>
- In-Reply-To
- <aHlrg7pbFqi2qNWH@fruit.crustytoothpaste.net>
"brian m. carlson" <sandals@crustytoothpaste.net> writes:
Show 28 quoted lines
>> +# This file is automatically @generated by Cargo. >> +# It is not intended for manual editing. >> +version = 4 >> + >> +[[package]] >> +name = "interop" >> +version = "0.1.0" >> + >> +[[package]] >> +name = "xdiff" >> +version = "0.1.0" >> +dependencies = [ >> + "interop", >> +] > > I would prefer that we not check in Cargo.lock in Git. Part of the > reason is that it changes across versions and so building with a > different version of the toolchain can update the file. > > In addition, as I mentioned downthread, because our intention is to > support the Debian stable toolchain for a year after the new stable > release, unless we are exceptionally careful about dependencies, we may > end up with a case where distros need to use older dependencies patched > for security but other users may want to update the versions to newer > dependencies with security fixes but that do not work on our pinned Rust > version. We can't possibly satisfy both sets of people if we pin > dependencies in Cargo.lock, so we probably want to avoid checking it in > and ignore it instead.
Yup.
The comment in first few lines of the file says it very well ;-) Thanks for flagging it.