Context
The wasm32-unknown-unknown target requires explicit opt-in for entropy sources. We currently carry three separate wasm32 target overrides in Cargo.toml because three different generations of RustCrypto crates each pin a different major version of getrandom:
[target.'cfg(target_arch = "wasm32")'.dependencies]
getrandom02 = { package = "getrandom", version = "0.2", features = ["js"] }
getrandom03 = { package = "getrandom", version = "0.3", features = ["wasm_js"] }
getrandom = { package = "getrandom", version = "0.4", features = ["wasm_js"] }
Each version is forced by a different part of the dep graph — they are not interchangeable (getrandom uses strict semver, each major is a distinct crate to Cargo).
Why each version exists
| getrandom |
Forced by |
Pull chain |
| 0.2 |
aes-siv 0.7, crypto_secretbox 0.1, ipcrypt-rs 0.9 |
old RustCrypto stack: aead 0.5 → rand_core 0.6 → getrandom 0.2 |
| 0.3 |
rand 0.9 (direct VRL dep) |
rand 0.9 → rand_core 0.9 → getrandom 0.3 |
| 0.4 |
aes-gcm 0.11, chacha20poly1305 0.11, aes 0.9 |
new RustCrypto stack: aead 0.6 → crypto-common 0.2 → getrandom 0.4 |
What needs to happen to consolidate
Eliminate getrandom 0.2
Requires migrating three crates from old RustCrypto (aead 0.5 / cipher 0.4 / aes 0.8) to new (aead 0.6 / cipher 0.5 / aes 0.9):
Eliminate getrandom 0.3
Requires rand to release a version that depends on getrandom 0.4. rand 0.9 is the current stable release; no 0.10 exists yet (rust-random/rand).
Goal state
Once all blockers resolve, the section collapses to a single line:
[target.'cfg(target_arch = "wasm32")'.dependencies]
getrandom = { package = "getrandom", version = "0.4", features = ["wasm_js"] }
This is a pure upstream dependency problem. No action is required in this repo until the upstream crates ship stable releases. This issue exists to track that work.
Context
The
wasm32-unknown-unknowntarget requires explicit opt-in for entropy sources. We currently carry three separate wasm32 target overrides inCargo.tomlbecause three different generations of RustCrypto crates each pin a different major version ofgetrandom:Each version is forced by a different part of the dep graph — they are not interchangeable (getrandom uses strict semver, each major is a distinct crate to Cargo).
Why each version exists
aes-siv0.7,crypto_secretbox0.1,ipcrypt-rs0.9aead 0.5→rand_core 0.6→getrandom 0.2rand0.9 (direct VRL dep)rand 0.9→rand_core 0.9→getrandom 0.3aes-gcm0.11,chacha20poly13050.11,aes0.9aead 0.6→crypto-common 0.2→getrandom 0.4What needs to happen to consolidate
Eliminate getrandom 0.2
Requires migrating three crates from old RustCrypto (aead 0.5 / cipher 0.4 / aes 0.8) to new (aead 0.6 / cipher 0.5 / aes 0.9):
aes-siv0.8.0-rc.3— pre-release (RustCrypto/AEADs)crypto_secretbox0.2.0-pre.0— pre-release onlyipcrypt-rsEliminate getrandom 0.3
Requires
randto release a version that depends ongetrandom 0.4.rand0.9 is the current stable release; no 0.10 exists yet (rust-random/rand).Goal state
Once all blockers resolve, the section collapses to a single line:
This is a pure upstream dependency problem. No action is required in this repo until the upstream crates ship stable releases. This issue exists to track that work.