Skip to content

chore(deps): update rust crate reqwest to 0.13 - #2

Merged
BryanFRD merged 5 commits into
mainfrom
renovate/reqwest-0.x
Sep 20, 2026
Merged

BryanFRD merged 5 commits into
mainfrom
renovate/reqwest-0.x

Conversation

@ferrlabs-renovate

@ferrlabs-renovate ferrlabs-renovate Bot commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
reqwest workspace.dependencies minor 0.120.13

Release Notes

seanmonstar/reqwest (reqwest)

v0.13.5

Compare Source

  • Add Error::is_dns() to identify errors caused by DNS resolution failures.
  • Add ClientBuilder::http1_max_headers(usize) to configure the maximum number of headers accepted in an HTTP/1 response (default 100).
  • Add TLS version to TlsInfo extension.
  • Fix hickory-dns feature to use Ipv6AndIpv4 strategy to prefer IPv6.
  • Fix sending wrong proxy-auth if multiple proxies intercept a given URL.

v0.13.4

Compare Source

  • Add ClientBuilder::tls_sslkeylogfile(bool) option to allow using the related environment variable.
  • Add ClientBuilder::http2_keep_alive_* options for the blocking client.
  • Add TLS 1.3 support when using native-tls backend.
  • Fix redirect handling to strip sensitive headers when the scheme changes.
  • Fix HTTP/3 happy-eyeball connection creation.
  • Upgrade hickory-resolver to 0.26.

v0.13.3

Compare Source

  • Fix CertificateRevocationList parsing of PEM values.
  • Fix logging in resolver to only show host, not full URL.
  • Fix hickory-dns to fallback to a default if /etc/resolv.conf fails.
  • Fix HTTP/3 to handle STOP_SENDING as not an error.
  • Fix HTTP/3 pool to remove timed out QUIC connections.
  • Fix HTTP/3 connection establishment picking IPv4 and IPv6.
  • Upgrade rustls-platform-verifier.
  • (wasm) Only use wasm-bindgen on unknown-* targets.

v0.13.2

Compare Source

  • Fix HTTP/2 and native-tls ALPN feature combinations.
  • Fix HTTP/3 to send h3 ALPN.
  • (wasm) fix RequestBuilder::json() from override previously set content-type.

v0.13.1

Compare Source

  • Fixes compiling with rustls on Android targets.

v0.13.0

Compare Source

  • Breaking changes:
    • rustls is now the default TLS backend, instead of native-tls.
    • rustls crypto provider defaults to aws-lc instead of ring. (rustls-no-provider exists if you want a different crypto provider)
    • rustls-tls has been renamed to rustls.
    • rustls roots features removed, rustls-platform-verifier is used by default.
      • To use different roots, call tls_certs_only(your_roots).
    • native-tls now includes ALPN. To disable, use native-tls-no-alpn.
    • query and form are now crate features, disabled by default.
    • Long-deprecated methods and crate features have been removed (such as trust-dns, which was renamed hickory-dns a while ago).
  • Many TLS-related methods renamed to improve autocompletion and discovery, but previous name left in place with a "soft" deprecation. (just documented, no warnings)
    • For example, prefer tls_backend_rustls() over use_rustls_tls().

v0.12.28

  • Fix compiling on Windows if TLS and SOCKS features are not enabled.

v0.12.27

  • Add ClientBuilder::windows_named_pipe(name) option that will force all requests over that Windows Named Piper.

v0.12.26

  • Fix sending Accept-Encoding header only with values configured with reqwest, regardless of underlying tower-http config.

v0.12.25

  • Add Error::is_upgrade() to determine if the error was from an HTTP upgrade.
  • Fix sending Proxy-Authorization if only username is configured.
  • Fix sending Proxy-Authorization to HTTPS proxies when the target is HTTP.
  • Refactor internal decompression handling to use tower-http.

v0.12.24

  • Refactor cookie handling to an internal middleware.
  • Refactor internal random generator.
  • Refactor base64 encoding to reduce a copy.
  • Documentation updates.

v0.12.23

  • Add ClientBuilder::unix_socket(path) option that will force all requests over that Unix Domain Socket.
  • Add ClientBuilder::retry(policy) and reqwest::retry::Builder to configure automatic retries.
  • Add ClientBuilder::dns_resolver2() with more ergonomic argument bounds, allowing more resolver implementations.
  • Add http3_* options to blocking::ClientBuilder.
  • Fix default TCP timeout values to enabled and faster.
  • Fix SOCKS proxies to default to port 1080
  • (wasm) Add cache methods to RequestBuilder.

v0.12.22

  • Fix socks proxies when resolving IPv6 destinations.

v0.12.21

  • Fix socks proxy to use socks4a:// instead of socks4h://.
  • Fix Error::is_timeout() to check for hyper and IO timeouts too.
  • Fix request Error to again include URLs when possible.
  • Fix socks connect error to include more context.
  • (wasm) implement Default for Body.

v0.12.20

  • Add ClientBuilder::tcp_user_timeout(Duration) option to set TCP_USER_TIMEOUT.
  • Fix proxy headers only using the first matched proxy.
  • (wasm) Fix re-adding Error::is_status().

v0.12.19

  • Fix redirect that changes the method to GET should remove payload headers.
  • Fix redirect to only check the next scheme if the policy action is to follow.
  • (wasm) Fix compilation error if cookies feature is enabled (by the way, it's a noop feature in wasm).

v0.12.18

  • Fix compilation when socks enabled without TLS.

v0.12.17

  • Fix compilation on macOS.

v0.12.16

  • Add ClientBuilder::http3_congestion_bbr() to enable BBR congestion control.
  • Add ClientBuilder::http3_send_grease() to configure whether to send use QUIC grease.
  • Add ClientBuilder::http3_max_field_section_size() to configure the maximum response headers.
  • Add ClientBuilder::tcp_keepalive_interval() to configure TCP probe interval.
  • Add ClientBuilder::tcp_keepalive_retries() to configure TCP probe count.
  • Add Proxy::headers() to add extra headers that should be sent to a proxy.
  • Fix redirect::Policy::limit() which had an off-by-1 error, allowing 1 more redirect than specified.
  • Fix HTTP/3 to support streaming request bodies.
  • (wasm) Fix null bodies when calling Response::bytes_stream().

v0.12.15

  • Fix Windows to support both ProxyOverride and NO_PROXY.
  • Fix http3 to support streaming response bodies.
  • Fix http3 dependency from public API misuse.

v0.12.14

  • Fix missing fetch_mode_no_cors(), marking as deprecated when not on WASM.

v0.12.13

  • Add Form::into_reader() for blocking multipart forms.
  • Add Form::into_stream() for async multipart forms.
  • Add support for SOCKS4a proxies.
  • Fix decoding responses with multiple zstd frames.
  • Fix RequestBuilder::form() from overwriting a previously set Content-Type header, like the other builder methods.
  • Fix cloning of request timeout in blocking::Request.
  • Fix http3 synchronization of connection creation, reducing unneccesary extra connections.
  • Fix Windows system proxy to use ProxyOverride as a NO_PROXY value.
  • Fix blocking read to correctly reserve and zero read buffer.
  • (wasm) Add support for request timeouts.
  • (wasm) Fix Error::is_timeout() to return true when from a request timeout.

v0.12.12

  • (wasm) Fix compilation by not compiler tokio/time on WASM.

v0.12.11

  • Fix decompression returning an error when HTTP/2 ends with an empty data frame.

v0.12.10

  • Add ClientBuilder::connector_layer() to allow customizing the connector stack.
  • Add ClientBuilder::http2_max_header_list_size() option.
  • Fix propagating body size hint (content-length) information when wrapping bodies.
  • Fix decompression of chunked bodies so the connections can be reused more often.

v0.12.9

  • Add tls::CertificateRevocationLists support.
  • Add crate features to enable webpki roots without selecting a rustls provider.
  • Fix connection_verbose() to output read logs.
  • Fix multipart::Part::file() to automatically include content-length.
  • Fix proxy to internally no longer cache system proxy settings.

v0.12.8

  • Add support for SOCKS4 proxies.
  • Add multipart::Form::file() method for adding files easily.
  • Add Body::wrap() to wrap any http_body::Body type.
  • Fix the pool configuration to use a timer to remove expired connections.

v0.12.7

  • Revert adding impl Service<http::Request<_>> for Client.

v0.12.6

  • Add support for danger_accept_invalid_hostnames for rustls.
  • Add impl Service<http::Request<Body>> for Client and &'_ Client.
  • Add support for !Sync bodies in Body::wrap_stream().
  • Enable happy eyeballs when hickory-dns is used.
  • Fix Proxy so that HTTP(S)_PROXY values take precedence over ALL_PROXY.
  • Fix blocking::RequestBuilder::header() from unsetting sensitive on passed header values.

v0.12.5

  • Add blocking::ClientBuilder::dns_resolver() method to change DNS resolver in blocking client.
  • Add http3 feature back, still requiring reqwest_unstable.
  • Add rustls-tls-no-provider Cargo feature to use rustls without a crypto provider.
  • Fix Accept-Encoding header combinations.
  • Fix http3 resolving IPv6 addresses.
  • Internal: upgrade to rustls 0.23.

v0.12.4

  • Add zstd support, enabled with zstd Cargo feature.
  • Add ClientBuilder::read_timeout(Duration), which applies the duration for each read operation. The timeout resets after a successful read.

v0.12.3

  • Add FromStr for dns::Name.
  • Add ClientBuilder::built_in_webpki_certs(bool) to enable them separately.
  • Add ClientBuilder::built_in_native_certs(bool) to enable them separately.
  • Fix sending content-length: 0 for GET requests.
  • Fix response body content_length() to return value when timeout is configured.
  • Fix ClientBuilder::resolve() to use lowercase domain names.

v0.12.2

  • Fix missing ALPN when connecting to socks5 proxy with rustls.
  • Fix TLS version limits with rustls.
  • Fix not detected ALPN h2 from server with native-tls.

v0.12.1

  • Fix ClientBuilder::interface() when no TLS is enabled.
  • Fix TlsInfo::peer_certificate() being truncated with rustls.
  • Fix panic if http2 feature disabled but TLS negotiated h2 in ALPN.
  • Fix Display for Error to not include its source error.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@ferrlabs-renovate

ferrlabs-renovate Bot commented Sep 6, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: Cargo.lock
    Updating crates.io index
error: failed to select a version for `reqwest`.
    ... required by package `ferrfleet-runner v2026.9.2 (/cache/repos/github/FerrLabs/FerrFleet-Runner/runner)`
versions that meet the requirements `^0.13` are: 0.13.5, 0.13.4, 0.13.3, 0.13.2, 0.13.1, 0.13.0

package `ferrfleet-runner` depends on `reqwest` with feature `rustls-tls` but `reqwest` does not have that feature.
help: available features: __native-tls, __native-tls-alpn, __rustls, __rustls-aws-lc-rs, __tls, blocking, brotli, charset, cookies, default, default-tls, deflate, form, gzip, h2, hickory-dns, http2, http3, json, multipart, native-tls, native-tls-no-alpn, native-tls-vendored, native-tls-vendored-no-alpn, query, rustls, rustls-native-certs, rustls-no-provider, socks, stream, system-proxy, webpki-roots, zstd


failed to select a version for `reqwest` which could resolve this conflict

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What changed: reqwest 0.13 makes rustls the default backend and, per the changelog, hard-renames the rustls-tls crate feature to rustls (this one is a breaking rename, unlike the TLS method renames further down which keep a soft-deprecated alias). It also gates query/form behind new opt-in features.

What breaks here: Cargo.toml still requests the old rustls-tls feature name, which no longer exists in 0.13:

reqwest = { version = "0.13", default-features = false, features = ["json", "rustls-tls"] }

Blocking: this feature name doesn't exist in 0.13 and will fail to resolve/compile.

reqwest = { version = "0.13", default-features = false, features = ["json", "rustls"] }

runner/src/sender.rs and runner/src/review_threads.rs only use reqwest::Client/Client::builder() with generic options, no .query()/.form() calls, so the new opt-in feature gating for those doesn't affect this repo.

Why CI fails: Both Check and Image builds fail immediately (~24s each). I couldn't read the raw logs (sign-in required), but the timing and the unknown-feature name in Cargo.toml line up with a cargo feature-resolution failure, not a flake — fixing the feature name above should resolve it.

@BryanFRD

BryanFRD commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

The diagnosis above is right and matches the CI log exactly: package ferrfleet-runner depends on reqwest with feature rustls-tls but reqwest does not have that feature.

The suggested fix makes it compile. Compiling is not the bar for this dependency, and resolving the two lockfiles shows why.

Today, 0.12 + rustls-tls:

ring, rustls, webpki-roots

Proposed, 0.13 + rustls:

aws-lc-rs, aws-lc-sys, ring, rustls, rustls-native-certs

Three things change, and none of them fail a build.

Two crypto providers instead of one. aws-lc-rs and ring both end up in the graph. That is the exact configuration FerrFleet-Cloud/api/Cargo.toml carries a comment about, having been bitten by it: rustls refuses to choose between two providers and dies at the first TLS connection with "Could not automatically determine the process-level CryptoProvider". That comment also records why it stayed invisible until production: nothing in CI opens a TLS connection from the built binary. Nothing in this repository's CI does either. cargo build and docker build both pass while the runner would fail its very first call to /runs/{id}/config.

Roots move from bundled to the system store. webpki-roots out, rustls-native-certs in. Fine inside our own image, which installs ca-certificates. Less fine for the case this repository exists to serve: someone building the binary and running it somewhere we did not choose.

aws-lc-sys adds a C and NASM build dependency. The README says "no private registry and no credentials: every dependency is public. That is deliberate, and worth keeping true." A toolchain requirement is not the same thing as a credential, but it is the same promise being quietly narrowed.

What actually preserves today's behaviour, resolved rather than guessed:

reqwest = { version = "0.13", default-features = false, features = ["json", "rustls-no-provider", "webpki-roots"] }
ring, rustls-native-certs, webpki-roots

rustls-no-provider means the application installs the provider itself, so this also needs a line in runner/src/main.rs doing what FerrFleet-Cloud/api/src/main.rs already does for the same reason.

So this is not a one-line merge. Either take that path with the code change, or accept aws-lc-rs deliberately and say so. Whichever way it goes, it needs a real HTTPS request out of the built binary before it lands: no job here performs one today, and that gap is what would let this reach a customer's pipeline.

@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/reqwest-0.x branch 2 times, most recently from 48fc6f2 to b9645ae Compare September 11, 2026 11:12
@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/reqwest-0.x branch 3 times, most recently from ed726c0 to 03513a5 Compare September 18, 2026 18:20
@ferrlabs-renovate
ferrlabs-renovate Bot enabled auto-merge (squash) September 18, 2026 20:23
@BryanFRD

Copy link
Copy Markdown
Contributor

Appliqué tel quel, rustls-tlsrustls. Vérifié dans un conteneur Linux plutôt qu'en local, le crate ne compile pas sous Windows (std::os::unix::fs::PermissionsExt) : clippy -D warnings propre et 45 tests verts.

@BryanFRD

Copy link
Copy Markdown
Contributor

Done in f632950, and the one-word fix that was on the branch is replaced rather than extended.

features = ["json", "rustls"] resolved to both providers plus a C toolchain:

aws-lc-rs, aws-lc-sys, ring, rustls-native-certs

Now:

reqwest = { version = "0.13", default-features = false, features = ["json", "rustls-no-provider", "webpki-roots"] }
rustls = { version = "0.23", default-features = false, features = ["ring"] }
ring, rustls, rustls-native-certs, webpki-roots

which is the 0.12 baseline. rustls-no-provider means the process installs one itself, so main now calls install_crypto_provider() before anything else, the same thing FerrFleet-Cloud/api/src/main.rs does and for the same reason.

Verified by making the binary talk to a real server, not by the build passing:

docker run --rm -e FERRFLEET_API_URL=https://api.github.com ... ferrfleet-runner:ci
Error: non-2xx from https://api.github.com/runs/.../config
Caused by: HTTP status client error (403 Forbidden)

A 403 is an application answer, so the handshake completed and webpki-roots verified the chain. With the broken configuration this is where it would have died instead.

That check is now a CI step on the image job. Nothing else in this repository opens a connection: cargo build, clippy and docker build all pass on a binary whose TLS cannot handshake, which is exactly how this would have reached a customer's pipeline.

Also merged origin/main in, the branch was four commits behind.

@BryanFRD
BryanFRD merged commit f163e65 into main Sep 20, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant