fix: clippy under Rust 1.99.0 (async-trait 0.1.92, try_update) - #1559
Conversation
Stable moved to Rust 1.99.0 on 2026-10-01 and the CI check job (floating stable) started failing cargo clippy on main: - async-trait 0.1.89 expansions trip clippy::double_must_use (16 errors in openab-core adapter.rs/dispatch.rs and openab-mcp sources.rs). Bump async-trait to 0.1.92 in Cargo.lock. - AtomicUsize::fetch_update is deprecated in favor of try_update (stable since 1.95.0) in openab-cp registry.rs.
This comment has been minimized.
This comment has been minimized.
Bump async-trait 0.1.89 -> 0.1.92 in openab-agent/Cargo.lock, pinning the new syn 3 edge to 3.0.3 to match the root lockfile. Keeps both lockfiles on the same async-trait version so a future #[async_trait] use in openab-agent does not re-trigger clippy::double_must_use on Rust >= 1.99. Verified on rustc 1.99.0 in openab-agent: cargo clippy --locked -- -D warnings exits 0; cargo test --locked: 62 passed, 0 failed.
|
Note LGTM ✅ - Both round-1 blockers are resolved on What This PR DoesStable Rust 1.99.0 turned How It Works
Findings
Finding Details🟢 F1:
|
| Round-1 finding | Status |
|---|---|
🟡 F1 openab-agent/Cargo.lock still on async-trait 0.1.89 |
✅ Addressed in 798c3d8b (option (a): in-PR bump, syn pinned to 3.0.3) |
| 🟡 F2 Reversibility line inaccurate | ✅ Addressed in the PR body |
There are no inline review threads or external review comments on this PR.
Non-blocking Follow-ups
- Toolchain pin policy before Rust 1.100. The pin must cover every floating-stable clippy gate (
ci.ymlcheck and operator jobs,ci-openab-agent.yml,ci-agy-acp.yml,ci-auth-proxy.yml, etc.), plusbuild-binaries.yml(runner-preinstalled Rust) andbuild-operator-branch.yml(rustup script). Whoever pins must also own a periodic bump process. - Declare
rust-version = "1.95"so the new floor is explicit rather than implied by theDockerfile.unifieddigest. Any future digest re-pin must stay >= 1.95. - Optional hardening for the existing
OutboundBudget(not introduced by this PR): achecked_addoverflow test and a concurrentreserve()test at the exact limit. - The one-line purity comment on
OutboundBudget::reserve's closure already listed in the PR body.
Baseline Check
- PR opened: 2026-10-03
- Base:
main@739c344d(merge-base739c344d, not stacked); head798c3d8b1ab5b112edbf54aa07e8800771af7ba3 - Diff: 3 files (
Cargo.lock,openab-agent/Cargo.lock,crates/openab-cp/src/registry.rs); the only source change is the one-line rename - Main already has:
syn 3.0.3in the rootCargo.lock; no otherfetch_updatecall sites anywhere in the tree;operator/,agy-acp/andcrates/platform-schema/lockfiles contain noasync-trait - Net-new value: unblocks
CI / checkon Rust 1.99.0 and removes the latent repeat inopenab-agent - CI on this head at the time of writing: completed checks are green (including
checkjobs,validate,changes,validate-packaged-pins, native-sandbox smoke test);build-builderand the remaining smoke tests are still running. This review status covers the review only; CI checks are gated separately.
What's Good (🟢)
- Root-cause fix at the smallest possible layer; no lint suppression.
- Both lockfiles now use identical, already-vetted artifacts.
- Review Contract is complete, and the updated body is accurate about scope, residual risks, and rollback.
5. Three Reasons We Might Not Need This PR
- Pin the toolchain instead - pinning CI to 1.98 would turn CI green with zero code churn. Rebuttal: it only defers the work, leaves local
stablebuilds and floating Docker builders red, and still needs a human withworkflowspermission. - Suppress the lints -
#[allow(deprecated)]on one call site plus adouble_must_useallow would avoid the lockfile bumps. Rebuttal: it weakens the gate and creates allow-debt that must be removed whenfetch_updateis eventually removed. - Manual multi-lockfile sync is fragile - this PR initially missed
openab-agent/Cargo.lock. Rebuttal: that is now fixed here; a repo-wide lockfile consistency check is a reasonable separate improvement, not a reason to block this fix.
Summary
Stable Rust moved to 1.99.0 on 2026-10-01. The
CI / checkjob installs floatingstable, so since thencargo clippy --workspace -- -D warningsfails onmainand on every PR that touches core code (for example #1557). The failures are in files no recent PR touched:async-trait0.1.89 expansions tripclippy::double_must_use. That is 16 errors atopenab-core/src/adapter.rs:334,openab-core/src/dispatch.rs:123andopenab-mcp/src/mcp/sources.rs:50. Fixed by bumpingasync-traitto 0.1.92 in the rootCargo.lock;openab-agent/Cargo.lockgets the same bump, with its newsyn3 entry pinned to the same 3.0.3 as root, so a future#[async_trait]use there cannot hit the same lint.syn3.0.3 was already in the rootCargo.lock, so this adds no new crate version to the repo. Only theasync-trait -> synedge changes.AtomicUsize::fetch_updateis deprecated in favor oftry_update(openab-cp/src/registry.rs:50). Since 1.99.0,fetch_updateis documented as an alias fortry_update(Stabilizeatomic_try_updateand deprecatefetch_updatestarting 1.99.0 rust-lang/rust#148590, tracking issue #135894). The two have the same parameter order (set_order,fetch_order), the same return contract (Ok(prev)/Err(prev)), and the same CAS retry loop: the closure may run more than once and is applied once. Memory orderings and the.is_ok()check are therefore unchanged.This is a stopgap that unblocks CI. It does not fix the root cause, which is that CI floats on
stable. See Follow-ups.Review Contract
Goal
cargo clippy --workspace -- -D warningsand--features unifiedpass on Rust 1.99.0, soCI / checkis green onmainagain.Non-goals
Accepted Residual Risks
operatorworkspace was not clippy-checked on 1.99.0 locally (out of memory compilingaws-sdk-ec2). This PR does not touchoperator/.Acceptance Criteria
CI / checkpasses on this PR.fetch_updatetotry_update.Follow-ups
toolchain:on the workflowdtolnay/rust-toolchainsteps. This needsworkflowspermission.rust-toolchain.toml. It does not needworkflowspermission, but the officialrust:*images are rustup-based, so it would also override the digest-pinned 1.96.0 builder inDockerfile.unifiedand add a toolchain download to every image build.rust:1-bookwormbuilders float in about 18 Dockerfiles. A CI-only pin leaves image builds drifting.OutboundBudget::reserverelies on its closure being pure, because it can run more than once. A one-line comment would prevent a future side effect from silently running repeatedly.git revertrestoresfetch_updateandasync-trait0.1.89 and re-breakscargo clippy -- -D warnings. A revert is only safe after the CI toolchain is pinned to <= 1.98.Validation
Linux x86_64, rustc/cargo/clippy 1.99.0:
739c344d):cargo clippy --workspace -- -D warningsexits 101 with the 16double_must_useerrors above.cargo clippy --workspace -- -D warnings: exit 0cargo clippy --workspace --features unified -- -D warnings: exit 0cargo test --workspace: all passed, 0 failedcargo test -p openab-cp:registry::tests::*pass, includingoutbound_queue_is_bounded_in_bytes_not_only_entriestry_updateis stable since 1.95.0, and the digest-pinned builder inDockerfile.unifiedis Rust 1.96.0.async-trait0.1.92 andsyn3.0.3 is 1.71.git grep fetch_update -- '*.rs'returns nothing after the change.a1143f0b:cargo clippyandcargo clippy (unified)pass on runner stable.openab-agent(standalone workspace, same steps asci-openab-agent.yml) on rustc 1.99.0:cargo clippy --locked -- -D warnings: exit 0cargo test --locked: 62 passed, 0 failed, 11 ignored