# Crate version incompatibility

**URL:** <https://internals.rust-lang.org/t/crate-version-incompatibility/19888>\
**Category:** tools and infrastructure\
**Created:** [November 19, 2023, 11:16am UTC](https://internals.rust-lang.org/t/crate-version-incompatibility/19888 "2023-11-19T11:16:50Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![cklein](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/cklein/32/10656_2.png) [@cklein](https://internals.rust-lang.org/u/cklein)\
**Post date:** [November 19, 2023, 11:16am UTC](https://internals.rust-lang.org/t/crate-version-incompatibility/19888/1 "2023-11-19T11:16:50Z")

</div>

Let's say I use crate A version 1.0 I depend Create B depend on create A version 0.2 I depend Create C depend on create A version 0.3

I am pretty much stuck, screwed! The current cargo does not provide any solution to this problem.

Is there anyway for me to specify: crate A, use version 1.0, for me, and all dependencies? If it does not compile, then boom, it won't work anyway. I am counting on my luck that it will work. Or maybe I am sure it will work. But Cargo does not give me a chance to try it at all.

Is it better to give me a way to specify a version, and I will take full responsibility of the compatibility?

---

<div class="post-metadata">

**Author:** ![steffahn](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/steffahn/32/13288_2.png) [@steffahn](https://internals.rust-lang.org/u/steffahn)\
**Post date:** [November 19, 2023, 11:39am UTC](https://internals.rust-lang.org/t/crate-version-incompatibility/19888/2 "2023-11-19T11:39:54Z")

</div>

I think this question could be a better fit on [users.rust-lang.org](http://users.rust-lang.org), rather than the internals forum.

---

<div class="post-metadata">

**Author:** ![Eh2406](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/eh2406/32/4839_2.png) [@Eh2406](https://internals.rust-lang.org/u/Eh2406)\
**Post date:** [November 19, 2023, 3:34pm UTC](https://internals.rust-lang.org/t/crate-version-incompatibility/19888/3 "2023-11-19T15:34:06Z")

</div>

Can you build a reproducible example of the problem you're seeing? Cargo should have no trouble building 1.0 and 0.2 and 0.3 of the same crate into the same project.

---

<div class="post-metadata">

**Author:** ![cklein](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/cklein/32/10656_2.png) [@cklein](https://internals.rust-lang.org/u/cklein)\
**Post date:** [November 20, 2023, 1:47am UTC](https://internals.rust-lang.org/t/crate-version-incompatibility/19888/4 "2023-11-20T01:47:25Z")

</div>

The real problem is to use the same version, not get 3 versions into the lib.

Here is my problem: Let c = ClientBuilder::new(URI:::fromstr(“[http://xxxx](http://xxxx)”)?); ClientBuilder is crate B requires a url of create http 0.2. And I am using http 1.0 The uri I passed to ClientBuilder is the wrong version. The error I throw away is will be the wrong version too.

---

<div class="post-metadata">

**Author:** ![Eh2406](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/eh2406/32/4839_2.png) [@Eh2406](https://internals.rust-lang.org/u/Eh2406)\
**Post date:** [November 20, 2023, 3:20pm UTC](https://internals.rust-lang.org/t/crate-version-incompatibility/19888/5 "2023-11-20T15:20:08Z")

</div>

There are a bunch of practical tools for dealing with this problem. Most of which are in the process of being improved.

Most crates re-export their public dependencies. This allows you to at least name the version of the transitive dependency that will work with the direct dependency.

This relies on people keeping track of which dependencies are part of the public API, it would be very convenient if you could record that in cargo.toml. Which is the public/private dependencies RFC. The original RFC had wanted the resolver to force picking the versions of your direct dependency is such that your transitive dependencies at the same version. This was very hard to implement, and prevented the other benefits we would get from that RFC. A new superseding RFC was just merged that does not affect the resolver.

Cargo can't automatically update your direct dependencies to have a different transitive dependency. Because the transitive dependency made a breaking change. It has told its users that they need to reevaluate their use of the API. Your direct dependencies need a human to evaluate what is involved in updating to the new version. If you would like to experiment with that you can pull their code and make the changes, then test them in your project either by using a git dependency or using the patch section to overrides the dependency. Both of which are intentionally designed to make it very easy for you to give your improvements back to the community.

I have some pipedreams about other tooling we should add to cargo.toml, but for now I mostly want to see how the community response to the tools that are already in the works.

---

<div class="post-metadata">

**Author:** ![pitaj](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/pitaj/32/11262_2.png) [@pitaj](https://internals.rust-lang.org/u/pitaj)\
**Post date:** [November 20, 2023, 10:48pm UTC](https://internals.rust-lang.org/t/crate-version-incompatibility/19888/6 "2023-11-20T22:48:36Z")

</div>

Overriding the version of a transitive dependency is a commonly requested option.

> <https://github.com/rust-lang/cargo/issues/5640>
>
> currently there is no way in replace or patch to specify a \_different\_ version t…han the original dependency.
> 
> with replace:
> 
> \`\`\`toml
> \[replace\]
> "openssl:0.9.24" = {git = "https://github.com/sfackler/rust-openssl.git"
> \`\`\`
> \`\`\`
> error: no matching package for override \`https://github.com/rust-lang/crates.io-index#openssl:0.9.24\` found
> location searched: https://github.com/sfackler/rust-openssl.git
> version required: = 0.9.24
> 
> \`\`\`
> with patch:
> 
> \`\`\`toml
> \[patch.crates-io\]
> openssl = {git = "https://github.com/sfackler/rust-openssl.git"}
> \`\`\`
> is simply ignored. 
> 
> \`\`\`
> error: failed to run custom build command for \`openssl v0.9.24\`
> \`\`\`
> 
> 
> With the complexity of packages growing, it is sometimes nessesary to override versions in Cargo.toml since upstream cant update the version yet if another dependency hasnt updated.

---

<div class="post-metadata">

**Author:** ![Vorpal](https://avatars.discourse-cdn.com/v4/letter/v/aca169/32.png) [@Vorpal](https://internals.rust-lang.org/u/Vorpal)\
**Post date:** [November 20, 2023, 11:02pm UTC](https://internals.rust-lang.org/t/crate-version-incompatibility/19888/7 "2023-11-20T23:02:15Z")

</div>

> [@pitaj](#):
>
> Overriding the version of a transitive dependency is a commonly requested option.

This would be very useful. Several times I have had transitive dependencies in multiple versions, simply because of semver changes that didn't matter (because the functionality that broke semver wasn't used by my dependencies).

Being able to override that would be very useful. Another thing that would be useful is to be able to specify that my library is compatible with multiple different semver versions of a direct dependency. That would lessen the headache for any downstream consumer of my code.

---

<div class="post-metadata">

**Author:** ![Eh2406](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/eh2406/32/4839_2.png) [@Eh2406](https://internals.rust-lang.org/u/Eh2406)\
**Post date:** [November 21, 2023, 2:21am UTC](https://internals.rust-lang.org/t/crate-version-incompatibility/19888/8 "2023-11-21T02:21:22Z")

</div>

> [@Vorpal](#):
>
> Another thing that would be useful is to be able to specify that my library is compatible with multiple different semver versions of a direct dependency. That would lessen the headache for any downstream consumer of my code.

This you can already do. `foo = ">2.0.0, <5.0.0"`, although cargo will try and provide you with the latest version even if that means more duplication in the tree.

---

<div class="post-metadata">

**Author:** ![Vorpal](https://avatars.discourse-cdn.com/v4/letter/v/aca169/32.png) [@Vorpal](https://internals.rust-lang.org/u/Vorpal)\
**Post date:** [November 21, 2023, 5:57am UTC](https://internals.rust-lang.org/t/crate-version-incompatibility/19888/9 "2023-11-21T05:57:58Z")

</div>

Thanks, didn't know that. But if it doesn't make cargo unify versions it doesn't seem very useful currently. Maybe it will be good for the MSRV-aware resolver also being discussed currently.

---

<div class="post-metadata">

**Author:** ![system](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/system/32/14092_2.png) [@system](https://internals.rust-lang.org/u/system)\
**Post date:** [February 19, 2024, 5:58am UTC](https://internals.rust-lang.org/t/crate-version-incompatibility/19888/10 "2024-02-19T05:58:03Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
