Skip to content

old rand_core versions import from core::intrinsics module #82

Description

@mejrs

In rust-lang/rust#157082 (comment) we discovered that, through old rand_core versions, many crates are relying on the accidental stabilization of (in this case) core::intrinsics::transmute. We would like to be able to get rid of the hack required to support this, and the first step for that is fixing it in affected projects.

The affected rand_core versions are:

rand_core-0.1.0
rand_core-0.1.0-pre
rand_core-0.2.0
rand_core-0.2.1
rand_core-0.2.2
rand_core-0.3.0
rand_core-0.4.0
rand_core-0.4.2
rand_core-0.5.0 (but not 0.5.1)

The required change is in impls.rs

-use core::intrinsics::transmute;
+use core::mem::transmute;

Would you be willing to fix these and create new minor releases for these versions? I'd be willing to do it myself, but as I understand this, I'd need write access to create new branches.

Thanks in advance, mejrs on behalf of the Rust project.

Activity

  1. RalfJung commented on Sep 1, 2026

    @RalfJung
    Contributor

    Based on what we see in crater, rand_core-0.1 is not very relevant. But having semver-compatible fixes for 0.2, 0.3, and 0.4 would be great (in increasing order of importance, as one would expect 0.4 has the most use among these -- it alone accounts for more than half of the regressions across the entire crater run).

  2. newpavlov commented on Sep 1, 2026

    @newpavlov
    Member

    It's a bit surprising that those versions are still in use (I guess by mostly unmaintained crates).

    The fix releases seems easy enough (though a bit annoying) to do. But it has to be done as part of https://github.com/rust-random/rand since the listed versions were developed there at the time. Publishing would also have to be manual.

    @dhardy
    Could you handle it?

  3. RalfJung commented on Sep 1, 2026

    @RalfJung
    Contributor

    In absolute numbers there were around 5200 regressions attributed to rand-core 0.4.x. That's a small fraction of the overall crater run, but it's still a lot.

    Based on a tiny amount of random sampling, even crates released "just" 4 or 2 years ago seem to depend on ancient versions of criterion which then pulls in ancient versions of rand.

  4. dhardy commented on Sep 2, 2026

    @dhardy
    Member

    It may just be a one-line change, but dealing with the test infrastructure for anything that old is quite painful in my experience (especially since this is before MSRV testing was properly supported and Cargo from that era struggles to deal with today's crates.io database). Oh, and we were using Travis for testing at the time.

    I'll give it a go ...

  5. dhardy commented on Sep 2, 2026

    @dhardy
    Member

    Done: 0.1.1, 0.2.3, 0.3.2, 0.4.3. Basic local testing only; it turns out these all have the same MSRV (1.22.0).

  6. RalfJung commented on Sep 2, 2026

    @RalfJung
    Contributor

    Thanks a lot ❤️

  7. thomcc commented on Sep 2, 2026

    @thomcc

    Done: 0.1.1, 0.2.3, 0.3.2, 0.4.3. Basic local testing only; it turns out these all have the same MSRV (1.22.0).

    It's very nice that you did this. I often complain about compiler breakage going unfixed in old versions of crates, and while I totally get why that is (it's pretty tedious to do), it's really nice to see it fixed. Thank you.

  8. added a commit that references this issue on Oct 3, 2026
  9. added 2 commits that reference this issue on Oct 3, 2026
  10. added a commit that references this issue on Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions