Skip to content

Update Rust crate rand to 0.10 - #287

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/rand-0.x
Open

Update Rust crate rand to 0.10#287
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/rand-0.x

Conversation

@renovate

@renovate renovate Bot commented Mar 22, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
rand (source) dependencies minor 0.80.10
rand (source) dev-dependencies minor 0.90.10
rand (source) dependencies minor 0.90.10

Release Notes

rust-random/rand (rand)

v0.10.2

Compare Source

Fixes
  • Fix possible memory safety violation due to deserialization of UniformChar from bad source (#​1790)
Changes
  • Document required output order of fn partial_shuffle and apply #[must_use] (#​1769)
  • Avoid usage of unsafe in contexts where non-local memory corruption could invalidate contract (#​1791)

v0.10.1

Compare Source

This release includes a fix for a soundness bug; see #​1763.

Changes
  • Document panic behavior of make_rng and add #[track_caller] (#​1761)
  • Deprecate feature log (#​1763)

v0.10.0

Compare Source

Changes
  • The dependency on rand_chacha has been replaced with a dependency on chacha20. This changes the implementation behind StdRng, but the output remains the same. There may be some API breakage when using the ChaCha-types directly as these are now the ones in chacha20 instead of rand_chacha (#​1642).
  • Rename fns IndexedRandom::choose_multiple -> sample, choose_multiple_array -> sample_array, choose_multiple_weighted -> sample_weighted, struct SliceChooseIter -> IndexedSamples and fns IteratorRandom::choose_multiple -> sample, choose_multiple_fill -> sample_fill (#​1632)
  • Use Edition 2024 and MSRV 1.85 (#​1653)
  • Let Fill be implemented for element types, not sliceable types (#​1652)
  • Fix OsError::raw_os_error on UEFI targets by returning Option<usize> (#​1665)
  • Replace fn TryRngCore::read_adapter(..) -> RngReadAdapter with simpler struct RngReader (#​1669)
  • Remove fns SeedableRng::from_os_rng, try_from_os_rng (#​1674)
  • Remove Clone support for StdRng, ReseedingRng (#​1677)
  • Use postcard instead of bincode to test the serde feature (#​1693)
  • Avoid excessive allocation in IteratorRandom::sample when amount is much larger than iterator size (#​1695)
  • Rename os_rng -> sys_rng, OsRng -> SysRng, OsError -> SysError (#​1697)
  • Rename Rng -> RngExt as upstream rand_core has renamed RngCore -> Rng (#​1717)
Additions
  • Add fns IndexedRandom::choose_iter, choose_weighted_iter (#​1632)
  • Pub export Xoshiro128PlusPlus, Xoshiro256PlusPlus prngs (#​1649)
  • Pub export ChaCha8Rng, ChaCha12Rng, ChaCha20Rng behind chacha feature (#​1659)
  • Fn rand::make_rng() -> R where R: SeedableRng (#​1734)
Removals

v0.9.5

Compare Source

What's Changed

Full Changelog: rust-random/rand@0.9.4...0.9.5

v0.9.4

Compare Source

Fixes

Full Changelog: rust-random/rand@0.9.3...0.9.4

v0.9.3

Compare Source

v0.9.2

Compare Source

Deprecated
  • Deprecate rand::rngs::mock module and StepRng generator (#​1634)
Additions
  • Enable WeightedIndex<usize> (de)serialization (#​1646)

v0.9.1

Compare Source

Security and unsafe
  • Revise "not a crypto library" policy again (#​1565)
  • Remove zerocopy dependency from rand (#​1579)
Fixes
  • Fix feature simd_support for recent nightly rust (#​1586)
Changes
  • Allow fn rand::seq::index::sample_weighted and fn IndexedRandom::choose_multiple_weighted to return fewer than amount results (#​1623), reverting an undocumented change (#​1382) to the previous release.
Additions
  • Add rand::distr::Alphabetic distribution. (#​1587)
  • Re-export rand_core (#​1604)

v0.9.0

Compare Source

Security and unsafe
  • Policy: "rand is not a crypto library" (#​1514)
  • Remove fork-protection from ReseedingRng and ThreadRng. Instead, it is recommended to call ThreadRng::reseed on fork. (#​1379)
  • Use zerocopy to replace some unsafe code (#​1349, #​1393, #​1446, #​1502)
Dependencies
Features
  • Support std feature without getrandom or rand_chacha (#​1354)
  • Enable feature small_rng by default (#​1455)
  • Remove implicit feature rand_chacha; use std_rng instead. (#​1473)
  • Rename feature serde1 to serde (#​1477)
  • Rename feature getrandom to os_rng (#​1537)
  • Add feature thread_rng (#​1547)
API changes: rand_core traits
  • Add fn RngCore::read_adapter implementing std::io::Read (#​1267)
  • Add trait CryptoBlockRng: BlockRngCore; make trait CryptoRng: RngCore (#​1273)
  • Add traits TryRngCore, TryCryptoRng (#​1424, #​1499)
  • Rename fn SeedableRng::from_rng -> try_from_rng and add infallible variant fn from_rng (#​1424)
  • Rename fn SeedableRng::from_entropy -> from_os_rng and add fallible variant fn try_from_os_rng (#​1424)
  • Add bounds Clone and AsRef to associated type SeedableRng::Seed (#​1491)
API changes: Rng trait and top-level fns
  • Rename fn rand::thread_rng() to rand::rng() and remove from the prelude (#​1506)
  • Remove fn rand::random() from the prelude (#​1506)
  • Add top-level fns random_iter, random_range, random_bool, random_ratio, fill (#​1488)
  • Re-introduce fn Rng::gen_iter as random_iter (#​1305, #​1500)
  • Rename fn Rng::gen to random to avoid conflict with the new gen keyword in Rust 2024 (#​1438)
  • Rename fns Rng::gen_range to random_range, gen_bool to random_bool, gen_ratio to random_ratio (#​1505)
  • Annotate panicking methods with #[track_caller] (#​1442, #​1447)
API changes: RNGs
  • Fix <SmallRng as SeedableRng>::Seed size to 256 bits (#​1455)
  • Remove first parameter (rng) of ReseedingRng::new (#​1533)
API changes: Sequences
  • Split trait SliceRandom into IndexedRandom, IndexedMutRandom, SliceRandom (#​1382)
  • Add IndexedRandom::choose_multiple_array, index::sample_array (#​1453, #​1469)
API changes: Distributions: renames
  • Rename module rand::distributions to rand::distr (#​1470)
  • Rename distribution Standard to StandardUniform (#​1526)
  • Move distr::Slice -> distr::slice::Choose, distr::EmptySlice -> distr::slice::Empty (#​1548)
  • Rename trait distr::DistString -> distr::SampleString (#​1548)
  • Rename distr::DistIter -> distr::Iter, distr::DistMap -> distr::Map (#​1548)
API changes: Distributions
  • Relax Sized bound on Distribution<T> for &D (#​1278)
  • Remove impl of Distribution<Option<T>> for StandardUniform (#​1526)
  • Let distribution StandardUniform support all NonZero* types (#​1332)
  • Fns {Uniform, UniformSampler}::{new, new_inclusive} return a Result (instead of potentially panicking) (#​1229)
  • Distribution Uniform implements TryFrom instead of From for ranges (#​1229)
  • Add UniformUsize (#​1487)
  • Remove support for generating isize and usize values with StandardUniform, Uniform (except via UniformUsize) and Fill and usage as a WeightedAliasIndex weight (#​1487)
  • Add impl DistString for distributions Slice<char> and Uniform<char> (#​1315)
  • Add fn Slice::num_choices (#​1402)
  • Add fn p() for distribution Bernoulli to access probability (#​1481)
API changes: Weighted distributions
  • Add pub module rand::distr::weighted, moving WeightedIndex there (#​1548)
  • Add trait weighted::Weight, allowing WeightedIndex to trap overflow (#​1353)
  • Add fns weight, weights, total_weight to distribution WeightedIndex (#​1420)
  • Rename enum WeightedError to weighted::Error, revising variants (#​1382) and mark as #[non_exhaustive] (#​1480)
API changes: SIMD
  • Switch to std::simd, expand SIMD & docs (#​1239)
Reproducibility-breaking changes
  • Make ReseedingRng::reseed discard remaining data from the last block generated (#​1379)
  • Change fn SmallRng::seed_from_u64 implementation (#​1203)
  • Allow UniformFloat::new samples and UniformFloat::sample_single to yield high (#​1462)
  • Fix portability of distribution Slice (#​1469)
  • Make Uniform for usize portable via UniformUsize (#​1487)
  • Fix IndexdRandom::choose_multiple_weighted for very small seeds and optimize for large input length / low memory (#​1530)
Reproducibility-breaking optimisations
  • Optimize fn sample_floyd, affecting output of rand::seq::index::sample and rand::seq::SliceRandom::choose_multiple (#​1277)
  • New, faster algorithms for IteratorRandom::choose and choose_stable (#​1268)
  • New, faster algorithms for SliceRandom::shuffle and partial_shuffle (#​1272)
  • Optimize distribution Uniform: use Canon's method (single sampling) / Lemire's method (distribution sampling) for faster sampling (breaks value stability; #​1287)
  • Optimize fn sample_single_inclusive for floats (+~20% perf) (#​1289)
Other optimisations
  • Improve SmallRng initialization performance (#​1482)
  • Optimise SIMD widening multiply (#​1247)
Other
Documentation
  • Improve ThreadRng related docs (#​1257)
  • Docs: enable experimental --generate-link-to-definition feature (#​1327)
  • Better doc of crate features, use doc_auto_cfg (#​1411, #​1450)

v0.8.8

Compare Source

What's Changed

Full Changelog: rust-random/rand@0.8.7...0.8.8

v0.8.7

Compare Source

What's Changed

Full Changelog: rust-random/rand@0.8.6...0.8.7

v0.8.6

Compare Source

What's Changed

This release back-ports a fix from v0.10. See also #​1763.

Changes
  • Drop the experimental simd_support feature.

New Contributors

Full Changelog: rust-random/rand@0.8.5...0.8.6


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@greptile-apps

greptile-apps Bot commented Mar 22, 2026

Copy link
Copy Markdown
Contributor

PR author is in the excluded authors list.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 223b6b6a25

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

ahash = "0.8"
blake3 = "1.8"
rand = { version = "0.9", optional = true }
rand = { version = "0.10", optional = true }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Preserve seed replay for the simulation harnesses

Upgrading the simulation crates from rand 0.9 to 0.10 changes the sampler behind calls like random_range/random_bool, so a ChaCha8Rng seeded with an old failing seed will no longer drive the same operation stream. That breaks the reproducibility contract documented in crates/gossip-coordination/src/sim/mod.rs:31-34 and the seed-replay workflow relied on by crates/gossip-coordination/src/sim/harness_tests.rs:577-579 and crates/gossip-coordination/src/sim/mega_sim_tests.rs:495-521: any seed captured from CI or a proptest-regressions file on the 0.9 line stops reproducing the original failure after this bump.

Useful? React with 👍 / 👎.

csv = "1.3"
memchr = "2"
rand = { version = "0.8", default-features = false, features = ["std_rng"] }
rand = { version = "0.10", default-features = false, features = ["std_rng"] }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep bootstrap CI generation on a value-stable RNG

The eval harness uses StdRng::seed_from_u64 in tools/eval-harness/src/metrics.rs:268-283,543 specifically so bootstrap confidence intervals are deterministic and comparable in CI. Moving this dependency to rand 0.10 weakens that guarantee because StdRng on the 0.10 line is explicitly non-portable, so the same BootstrapConfig { seed: 42 } can start producing different intervals after a routine dependency refresh. That will make report diffs noisy and undermine the “same input, same CI” behavior this module documents.

Useful? React with 👍 / 👎.

@renovate renovate Bot changed the title Update Rust crate rand to 0.10 chore(deps): update rust crate rand to 0.10 Mar 23, 2026
@renovate renovate Bot changed the title chore(deps): update rust crate rand to 0.10 Update Rust crate rand to 0.10 Mar 23, 2026
@renovate renovate Bot changed the title Update Rust crate rand to 0.10 chore(deps): update rust crate rand to 0.10 Mar 24, 2026
@renovate
renovate Bot force-pushed the renovate/rand-0.x branch from 223b6b6 to b163aa3 Compare March 24, 2026 16:31
@renovate renovate Bot changed the title chore(deps): update rust crate rand to 0.10 Update Rust crate rand to 0.10 Mar 25, 2026
@renovate renovate Bot changed the title Update Rust crate rand to 0.10 chore(deps): update rust crate rand to 0.10 Mar 25, 2026
@renovate renovate Bot changed the title chore(deps): update rust crate rand to 0.10 Update Rust crate rand to 0.10 Mar 25, 2026
@renovate renovate Bot changed the title Update Rust crate rand to 0.10 chore(deps): update rust crate rand to 0.10 Mar 26, 2026
@renovate renovate Bot changed the title chore(deps): update rust crate rand to 0.10 Update Rust crate rand to 0.10 Mar 26, 2026
@renovate renovate Bot changed the title Update Rust crate rand to 0.10 chore(deps): update rust crate rand to 0.10 Mar 27, 2026
@renovate renovate Bot changed the title chore(deps): update rust crate rand to 0.10 Update Rust crate rand to 0.10 Apr 1, 2026
@renovate renovate Bot changed the title Update Rust crate rand to 0.10 chore(deps): update rust crate rand to 0.10 Apr 2, 2026
@renovate renovate Bot changed the title chore(deps): update rust crate rand to 0.10 Update Rust crate rand to 0.10 Apr 3, 2026
@renovate
renovate Bot force-pushed the renovate/rand-0.x branch from b163aa3 to 017ace7 Compare April 3, 2026 03:49
blake3 = "1.8"
rand = { version = "0.9", optional = true }
rand = { version = "0.10", optional = true }
rand_chacha = { version = "0.9", optional = true }

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

CRITICAL: The RNG stack is only half-upgraded here

crates/gossip-coordination/src/sim/mod.rs and the other simulation modules still use the 0.9 rand API with rand_chacha::ChaCha8Rng. Moving only rand to 0.10 is not source-compatible: 0.10 changed the trait surface, while rand_chacha 0.9 still sits on the older rand_core line. As written, the test-support targets stop compiling until the RNG crates and imports are updated together.

tracing.workspace = true
rand = { version = "0.9", optional = true }
rand = { version = "0.10", optional = true }
rand_chacha = { version = "0.9", optional = true }

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

CRITICAL: This leaves the crate on incompatible rand APIs

crates/gossip-coordination-etcd/src/sim_etcd_kv.rs and crates/gossip-coordination-etcd/tests/concurrent_cas_contention.rs still import rand::{Rng, SeedableRng} and drive ChaCha8Rng directly. Bumping only rand to 0.10 is not source-compatible here: the 0.10 traits no longer match rand_chacha 0.9, so these simulator/test targets stop compiling until the RNG versions and imports move in lockstep.

thiserror.workspace = true
rand = { version = "0.9", optional = true }
rand = { version = "0.10", optional = true }
rand_chacha = { version = "0.9", optional = true }

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

CRITICAL: The simulator still depends on the pre-0.10 RNG API

crates/gossip-persistence-inmemory/src/sim/mod.rs and crates/gossip-persistence-inmemory/tests/differential_oracle.rs still use the 0.9 rand API with rand_chacha::ChaCha8Rng. Updating only rand to 0.10 leaves those call sites on incompatible traits, so the test-support code stops compiling until the RNG stack is upgraded together.

@kilo-code-bot

kilo-code-bot Bot commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

Code Review Summary

Status: 4 Issues Found | Recommendation: Address before merge

Overview

Severity Count
CRITICAL 4
WARNING 0
SUGGESTION 0

Fix these issues in Kilo Cloud

Issue Details (click to expand)

CRITICAL

File Line Issue
crates/gossip-coordination/Cargo.toml 21 rand 0.10 is still paired with rand_chacha 0.9, leaving simulation and test-support code on incompatible rand_core trait versions.
crates/gossip-coordination-etcd/Cargo.toml 32 The etcd simulator/tests still drive ChaCha8Rng through rand traits, so this partial RNG upgrade leaves those targets on incompatible APIs.
crates/gossip-persistence-inmemory/Cargo.toml 20 The in-memory simulator/test code still uses rand_chacha 0.9, so the rand 0.10 bump breaks the seeded RNG trait stack.
tools/eval-harness/Cargo.toml 17 The harness source still calls the pre-0.9 rng.gen_range(...) API, so moving this direct dependency to rand 0.10 leaves the standalone tool source-incompatible.
Files Reviewed (6 files)
  • Cargo.lock - generated lockfile, dependency graph reviewed
  • crates/gossip-coordination-etcd/Cargo.toml - 1 issue
  • crates/gossip-coordination/Cargo.toml - 1 issue
  • crates/gossip-persistence-inmemory/Cargo.toml - 1 issue
  • tools/eval-harness/Cargo.lock - generated lockfile, dependency graph reviewed
  • tools/eval-harness/Cargo.toml - 1 issue
Previous Review Summary (commit 6741630)

Current summary above is authoritative. Previous snapshots are kept for context only.

Previous review (commit 6741630)

Status: 4 Issues Found | Recommendation: Address before merge

Overview

Severity Count
CRITICAL 4
WARNING 0
SUGGESTION 0

Fix these issues in Kilo Cloud

Issue Details (click to expand)

CRITICAL

File Line Issue
crates/gossip-coordination/Cargo.toml 21 rand 0.10 is still paired with rand_chacha 0.9, which leaves the simulation/test-support targets on split rand_core versions.
crates/gossip-coordination-etcd/Cargo.toml 32 This crate still drives ChaCha8Rng through rand traits, so bumping only rand to 0.10 leaves the etcd simulator/tests on incompatible RNG APIs.
crates/gossip-persistence-inmemory/Cargo.toml 20 The in-memory persistence simulator still uses rand_chacha 0.9, so this partial RNG upgrade keeps the test code on incompatible trait versions.
Other Observations (not in diff)

Issues found in unchanged code that cannot receive inline comments:

File Line Issue
tools/eval-harness/src/metrics.rs 555 The bootstrap sampling loop still calls rng.gen_range(...), so the eval harness source remains on the pre-0.9 rand API after this dependency bump.
Files Reviewed (6 files)
  • Cargo.lock - generated lockfile, no direct review findings
  • crates/gossip-coordination-etcd/Cargo.toml - 1 issue
  • crates/gossip-coordination/Cargo.toml - 1 issue
  • crates/gossip-persistence-inmemory/Cargo.toml - 1 issue
  • tools/eval-harness/Cargo.lock - generated lockfile, no direct review findings
  • tools/eval-harness/Cargo.toml - 1 related unchanged-code issue in tools/eval-harness/src/metrics.rs

Reviewed by gpt-5.5-2026-04-23 · Input: 119.8K · Output: 20.6K · Cached: 645.1K

@renovate renovate Bot changed the title Update Rust crate rand to 0.10 chore(deps): update rust crate rand to 0.10 Apr 3, 2026
@renovate renovate Bot changed the title chore(deps): update rust crate rand to 0.10 Update Rust crate rand to 0.10 Apr 4, 2026
@renovate renovate Bot changed the title Update Rust crate rand to 0.10 chore(deps): update rust crate rand to 0.10 Apr 4, 2026
@renovate
renovate Bot force-pushed the renovate/rand-0.x branch from 017ace7 to 384d8fc Compare April 4, 2026 07:16
@renovate renovate Bot changed the title chore(deps): update rust crate rand to 0.10 Update Rust crate rand to 0.10 Apr 5, 2026
@renovate renovate Bot changed the title Update Rust crate rand to 0.10 chore(deps): update rust crate rand to 0.10 Apr 6, 2026
@renovate renovate Bot changed the title chore(deps): update rust crate rand to 0.10 Update Rust crate rand to 0.10 Apr 7, 2026
@renovate renovate Bot changed the title Update Rust crate rand to 0.10 chore(deps): update rust crate rand to 0.10 Apr 8, 2026
@renovate renovate Bot changed the title chore(deps): update rust crate rand to 0.10 Update Rust crate rand to 0.10 Apr 8, 2026
@renovate renovate Bot changed the title Update Rust crate rand to 0.10 chore(deps): update rust crate rand to 0.10 Apr 8, 2026
@renovate renovate Bot changed the title chore(deps): update rust crate rand to 0.10 Update Rust crate rand to 0.10 Apr 8, 2026
@renovate
renovate Bot force-pushed the renovate/rand-0.x branch from 384d8fc to 7a51854 Compare April 11, 2026 13:44
@renovate
renovate Bot force-pushed the renovate/rand-0.x branch from 7a51854 to 045363b Compare April 11, 2026 18:20
@renovate
renovate Bot force-pushed the renovate/rand-0.x branch from 045363b to 6741630 Compare May 18, 2026 12:11
@renovate
renovate Bot force-pushed the renovate/rand-0.x branch from 6741630 to ee456d3 Compare July 2, 2026 11:59
@renovate
renovate Bot force-pushed the renovate/rand-0.x branch from ee456d3 to eebecda Compare July 21, 2026 02:04
@renovate
renovate Bot force-pushed the renovate/rand-0.x branch from eebecda to bbd8c7e Compare August 26, 2026 17:58
@renovate
renovate Bot force-pushed the renovate/rand-0.x branch from bbd8c7e to 6633230 Compare September 2, 2026 19:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants