4 ms·
And no justification or explanation that I can see. David Tolnay's response: > Thanks for the comments everyone. I'll go ahead and close this. The precompiled
by jamincan 3y ago
And no justification or explanation that I can see. David Tolnay's response:
> Thanks for the comments everyone. I'll go ahead and close this. The precompiled implementation is the only supported way to use the macros that are published in serde_derive. If there is implementation work needed in some build tools to accommodate it, someone should feel free to do that work (as I have done for Buck and Bazel, which are tools I use and contribute significantly to) or publish your own fork of the source code under a different name. Separately, regarding the commentary above about security, the best path forward would be for one of the people who cares about this to invest in a Cargo or crates.io RFC around first-class precompiled macros so that there is an approach that would suit your preferences; serde_derive would adopt that when available.
- DoesntMatter22 3y agoI don't know what any of that means. I need an ELI 5
- __s 3y agoSerde is a Rust library for serialization. serde_derive allows creating serialzers/deserializers automatically by marking structs. It uses Rust's procedural macros to generate code at compile time. Rust compiles procedural macros at compile time before compiling rest of code. To speed up compillation of code using serde_derive, a recent change was made to implement the procedural macros with a precompiled binary
- DoesntMatter22 3y agoSo is this just because server is known to make rust really slow to build? I'm curious why rust doesn't just compile your binaries once and then you wouldn't have to compile them on each build
- Sprocklem 3y agoIt generally does cache built crates for future builds on the same system, so it is usually only the initial build on a given system and the build after dependencies are updated that requires rebuilding serde_derive. I honestly don't know why they thought it was worth doing.
- earthling8118 3y agoIt very much does this. The compile times are hardly a concern to the vast majority of rust devs in part because of that cache.
- jgerrish 3y agoserde is also used in a LOT of projects and pulled in as a dependency or subdependency often in the crates ecosystem. For organizations with internal transparent reproducible build guidelines or similar rules, this maybe complicates things and introduces uncertainty. So much uncertainty nowadays. It's exhausting. You can take the generous / positive view that this will encourage formalizing reproducible build policies in organizations. Water is wet, the sky is blue.
- gxt 3y agoI'll be pinning my versions of serde until this gets reverted, fixed, or forked. It's an extremely surprising move to disregard supply chain concerns in favor of non publicly benchmarked performance improvements.
- gxt 3y agoCorrection: It's benchmarked, https://github.com/serde-rs/serde/pull/2514 https://github.com/serde-rs/serde/pull/2514.