Skip to content

chore(deps)(deps): bump tonic-build from 0.12.3 to 0.14.6 - #29

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/tonic-build-0.14.6
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/tonic-build-0.14.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 16, 2026 •

Copy link
Copy Markdown
Contributor

Bumps tonic-build from 0.12.3 to 0.14.6.

Release notes

Sourced from tonic-build's releases.

tonic-build-v0.14.6

Other

  • update rust edition and version to 2024 and 1.88, respectively (#2525)
Changelog

Sourced from tonic-build's changelog.

NOTE: ths changelog is no longer used and from version v0.13.0 onward we will be using github releases and the changes can be found here.

Commits
  • 6cb6056 chore: release v0.14.6 (#2624)
  • efde924 grpc: change helloworld example to pass request as a view (#2632)
  • d47b001 transport: add max_frame_size to client Endpoint (#2592)
  • 02c01c7 Allow setting the HTTP/2 client header table size (#2582)
  • 3185354 examples: add grpc version of helloworld (#2630)
  • f585303 fix(grpc): Fix grpc-google build (#2628)
  • ff7bcbb feat(grpc): Google call credentials (#2610)
  • f93037b feat(tonic-xds): make XdsChannelGrpc Sync (#2627)
  • d834beb grpc: Update Status to be a Result<> and make StatusErr which holds non-OK co...
  • 2392224 grpc: add route_guide example and make minor tweaks to the generated code API...
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels May 16, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved: all dependency bumps are patch or minor.

@github-actions
github-actions Bot enabled auto-merge May 16, 2026 17:19
@dependabot dependabot Bot changed the title chore(deps)(deps): bump tonic-build from 0.12.3 to 0.14.6 chore(deps)(deps): Bump tonic-build from 0.12.3 to 0.14.6 May 26, 2026
@dependabot
dependabot Bot force-pushed the dependabot/cargo/tonic-build-0.14.6 branch from 574a1f8 to dd4a656 Compare May 26, 2026 23:15
github-actions[bot]
github-actions Bot previously approved these changes May 26, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved: all dependency bumps are patch or minor.

@dependabot @github

dependabot Bot commented on behalf of github Jun 8, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

1 similar comment
@dependabot @github

dependabot Bot commented on behalf of github Jun 8, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

@dependabot dependabot Bot changed the title chore(deps)(deps): Bump tonic-build from 0.12.3 to 0.14.6 chore(deps)(deps): bump tonic-build from 0.12.3 to 0.14.6 Jun 10, 2026
@dependabot
dependabot Bot force-pushed the dependabot/cargo/tonic-build-0.14.6 branch from dd4a656 to 086f0eb Compare June 10, 2026 00:36
github-actions[bot]
github-actions Bot previously approved these changes Jun 10, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved: all dependency bumps are patch or minor.

@dependabot
dependabot Bot force-pushed the dependabot/cargo/tonic-build-0.14.6 branch from 086f0eb to 03f0122 Compare June 12, 2026 22:19
github-actions[bot]
github-actions Bot previously approved these changes Jun 12, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved: all dependency bumps are patch or minor.

@nikhilunni

Copy link
Copy Markdown
Contributor

@dependabot recreate

Bumps [tonic-build](https://github.com/hyperium/tonic) from 0.12.3 to 0.14.6.
- [Release notes](https://github.com/hyperium/tonic/releases)
- [Changelog](https://github.com/grpc/grpc-rust/blob/master/CHANGELOG.md)
- [Commits](grpc/grpc-rust@v0.12.3...tonic-build-v0.14.6)

---
updated-dependencies:
- dependency-name: tonic-build
  dependency-version: 0.14.6
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/cargo/tonic-build-0.14.6 branch from 03f0122 to 8a9253e Compare August 3, 2026 13:48
@engrams-agent

engrams-agent Bot commented Aug 3, 2026 •

Copy link
Copy Markdown
Contributor

✅ engrams review — complete. 1 finding posted. · View details

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved: all dependency bumps are patch or minor.

@engrams-agent engrams-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Engrams review

Verdict: 1 finding posted inline.
Severity: Critical 0 · High 1 · Medium 0 · Low 0
Categories: 🩺 Stability & Availability: 1

View the full engrams review

Comment thread Cargo.toml
# grpc
tonic = "0.12"
tonic-build = "0.12"
tonic-build = "0.14"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability · HIGH — tonic-build bumped to 0.14 while tonic stays 0.12 breaks the build.rs codegen

WHAT: This PR bumps only tonic-build from 0.12 to 0.14 while tonic and tonic-reflection stay at 0.12; tonic-build 0.14 removed the prost message-codegen path (the compile_protos / file_descriptor_set_path builder used by crates/engram-protocol/build.rs), so that build script no longer compiles and the workspace fails to build.

WHEN: Every build of engram-protocol (and therefore the whole workspace / coordinator) runs build.rs, which calls tonic_build::configure().build_server(true).build_client(true).file_descriptor_set_path(&descriptor_path).compile_protos(&protos, &includes). This chain is part of tonic-build's prost integration.

Two independent problems flow from the version skew:

  1. API removed. In the tonic 0.13/0.14 line the prost-specific codegen was split out of tonic-build into a separate tonic-prost-build crate. The Cargo.lock diff confirms this: tonic-build 0.14.6 no longer depends on prost-build or prost-types (both [[package]] entries were deleted). The compile_protos(...) method that runs protoc+prost is therefore gone from tonic_build, so build.rs will not compile as written.

  2. Runtime skew. Even if codegen were adapted, tonic-build 0.14 emits service code targeting the tonic 0.14 runtime API, but the tonic dependency is still 0.12.3. The 0.12→0.14 jump crosses breaking changes (codec/Body/NamedService surface), so the generated engram.host.v1 / engram.app.v1 bindings would not compile against the pinned tonic 0.12 runtime.

This is a self-inconsistent dependency bump: tonic-build must move in lockstep with tonic (and, for 0.13+, requires adding tonic-prost-build plus reworking build.rs). As submitted, the change does neither.

Suggested change
tonic-build = "0.14"
Either revert this bump, or upgrade the whole tonic family together: move `tonic`, `tonic-build`, and `tonic-reflection` to `0.14`, add the new `tonic-prost-build 0.14` build-dependency, and rewrite `crates/engram-protocol/build.rs` to use `tonic_prost_build::configure()` (which carries `compile_protos` / `file_descriptor_set_path`) instead of `tonic_build::configure()`.

@engrams-agent

engrams-agent Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Deferred — tonic-build 0.14 is the third leg of one indivisible change

I looked at this in today's dependency sweep and reproduced the failure locally on
the branch rebased onto current main. I am not pushing a migration: this branch
cannot be made green on its own, and the fix is in dependencies it must not carry.

The failure

error[E0425]: cannot find function `configure` in crate `tonic_build`
  --> crates/engram-protocol/build.rs:40:18
40 |     tonic_build::configure()
   |                  ^^^^^^^^^ not found in `tonic_build`

tonic-build 0.14.6 says it in its own source (src/lib.rs:13):

// Prost functionality has been moved to tonic-prost-build

Its entire public surface is now manual, CodeGenBuilder and Attributes.
configure() and compile_protos() are gone — tonic 0.14 split prost codegen
into a new tonic-prost-build crate, and the matching runtime prost codec
into tonic-prost. tonic-build itself is now transport/codec-agnostic.

Why this branch cannot fix it

crates/engram-protocol/build.rs compiles 11 protos through tonic_build::configure()
with build_server/build_client/file_descriptor_set_path. Porting it means
calling tonic_prost_build::configure() instead — a dependency this branch does
not have and must not add under one-dependency-per-branch.

And adding it would not be enough. This branch pins:

crate this branch needed
tonic-build 0.14 0.14
tonic 0.12 0.14
prost 0.13 0.14
prost-types 0.13 0.14
tonic-prost — new
tonic-prost-build — new

0.14 codegen emits code against the tonic 0.14 runtime and the prost 0.14 derives.
With tonic still at 0.12 and prost at 0.13, the generated types would not
satisfy tonic's Codec. Every one of these six has to move in a single commit.

The decision it turns on

Whether these become a Dependabot group. .github/dependabot.yml currently
groups only minor+patch, deliberately:

#   - Major bumps fall *outside* the group and arrive as individual PRs,
#     because that's where breaking changes hide and the review needs
#     to happen one crate / package / image at a time.

That policy is right in general and backfires precisely here. tonic and prost are
version-locked to each other, so "one crate at a time" is not a reviewable unit —
it is an unbuildable one. The result is three permanently-red PRs (#25 tonic,
#26 prost, this one) that each individually cannot go green, no matter how
many times they are recreated.

Concretely, the fix I would suggest — a named group that keeps the family together
even for majors, added to the cargo ecosystem entry:

      grpc:
        patterns: ["tonic", "tonic-*", "prost", "prost-*"]
        update-types: ["major", "minor", "patch"]

That turns three impossible PRs into one reviewable one, and it is the only PR
shape in which the build.rs port can be verified.

I wrote the full migration plan on #25, which is this same change from the
tonic side; #26 is the prost side. Whoever picks it up should start from a
fresh branch off current main and do all six at once — not from any of these
three branches.

Housekeeping

I am not adding @dependabot ignore this major version, deliberately and for
the same reason I gave on #26: tonic-build 0.14 should land — it just cannot land
alone. Suppressing the major would also hide later 0.14.x fixes. The right
suppression is the group above, which makes these PRs stop arriving individually.

I did not push to this branch, so Dependabot keeps ownership of it.

nikhilunni added a commit that referenced this pull request Aug 5, 2026
tonic 0.14 codegen emits code that only compiles against the prost
0.14 derives and the tonic 0.14 runtime. The one-crate-at-a-time major
policy therefore produced three PRs (#25, #26, #29) that can never go
green individually, no matter how often they are recreated.

Add a grpc group that keeps tonic, tonic-*, prost and prost-* together
at every update level, and exclude them from cargo-minor-patch so a
minor bump cannot land in a different group than a major.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
auto-merge was automatically disabled August 5, 2026 03:21

Pull request was closed

@dependabot @github

dependabot Bot commented on behalf of github Aug 5, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/cargo/tonic-build-0.14.6 branch August 5, 2026 03:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant