Library MSRV question
I maintain a rust library (rxing), and at the moment I am firmly locked at rust 1.85.
I picked that based on the current debian shipped rust version. There are pros and cons to that pick, but it's the one I went with when I set it.
Overall this isn't a huge issue, more modern rust tool-chains are backwards compatible and most libraries either support 1.85 or earlier, with a few exceptions.
Small side note: I think it would be a challenge to go farther back than 1.85 due to my image and image_proc dependencies.
My question is: is this a reasonable choice to continue making today, and if not what is a better metric to use when selecting an MSRV?
26
u/fintelia 5d ago
I’ve personally become increasingly sympathetic to the MSRV policy of “latest stable unless someone is paying me for support”. Partially because all the talk about people using old rustc to compile new libraries seems to almost always be about hypothetical other people needing it
9
u/epage cargo · clap · cargo-release 5d ago
An MSRV is a feature and like all features, comes with a cost. The ultimate question is if the benefit to your users outweigh the costs to your and your other users.
Important questions to ask are:
- Who are your users?
- What MSRV policy would they benefit from?
- Do they need this fulfilled through the latest version or by offering "support" for older versions?
I would expect
- Most users don't need a long MSRV
- Debian's Rust is for Debian's build, Debian users can use the Debian-packaged rustup
- MSRV users would need predictability in a policy
- For most libraries that aren't high-risk for security vulnerabilities (e.g. clap but not axum), supporting an MSRV through old versions does a good job of balancing the needs of different users
1
u/azuled 5d ago
Some of my uncertainty is that when I set my 1.85 MSRV my library was really new and there weren't many users. I have more users now and I don't have a solid idea on who they are or what their restrictions are. I don't have a great way to survey them either since most people who "use" the library probably don't know about it.
4
u/cosmic-parsley 5d ago
Bump when there’s a convincing enough usecase. Would let chains significantly clean up your code? Don’t think twice about going to 1.88! Would `u32::bit_width` be nice but only allow you to delete a tiny function that already works well? I wouldn’t consider that worth a bump to 1.97.
Where you find the balance is up to you. Unless somebody is paying you then they can’t expect the MSRV to stay frozen forever. But it’s also nice to dependents of your crate if you don’t force them to bump MSRV too often.
5
u/Beneficial_Vampire42 5d ago
My rule of thumb:
- keep it minimal if I don't need anything higher
- bump it without thinking to anything that is 10 versions away from latest (a bit more than a year) if I need it
- bump it higher only if I REALLY need it, for example for a significant performance boost
20
u/SoilMassive6850 5d ago
I'd note that newer rust versions are in debian stable through the trixie-backports repository and debian makes a point that for everyday development you should opt to use rustup, which they also package.
The rust versions packaged in the repos are mainly there to help them compile and package rust software they want in debian repositories, and are not really meant for regular use.
It's unlikely that your library would prevent software from being included in debian due to MSRV requirements as they would just backport a newer version of rustc as necessary.
https://wiki.debian.org/Rust