You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Trigger: PR merge (dependabot bump of fastembed 5.12.1 → 5.13.0)
Workflow: CI (ci.yml)
Root Cause Analysis
The most likely root cause is an API change in fastembed 5.13.0 where TextEmbedding::embed changed from &mut self to &self. This would make two let mut model bindings in src/embedding/fastembed_impl.rs unnecessary, generating unused_mut compiler warnings. Because the CI workflow sets RUSTFLAGS: "-D warnings", these warnings are promoted to errors, causing the clippy, test, and msrv jobs to fail.
Affected code in src/embedding/fastembed_impl.rs:
// Line ~107 in embed():letmut model = model // ← `mut` is unused if embed() now takes &self.lock().map_err(...)?;
...
let result = catch_unwind(AssertUnwindSafe(|| model.embed(texts,None)));// Line ~147 in embed_batch():letmut model = model // ← `mut` is unused if embed() now takes &self.lock().map_err(...)?;
...
let result = catch_unwind(AssertUnwindSafe(|| model.embed(texts,None)));
```
## FailedJobsandErrors(Expected)Based on code analysis(actual logs unavailable at investigation time):
| Job | ExpectedError |
|-----|---------------|
| `clippy` | `error[unused_mut]: variable does not need to be mutable` at lines ~107 and ~147 |
| `test` | Compilation failure due to `-D warnings` |
| `msrv` | Compilation failure due to `-D warnings` |
| `all-checks-pass` | Fails because above jobs failed |
## AlternativeHypothesesIf the `unused_mut` theory is incorrect, consider:1.**`cargo deny` failure**: `tokenizers 0.22.2` (a transitive dep of fastembed 5.13.0) pulls in new crates that may have non-allowed licenses or outstanding RUSTSEC advisories not covered by the current `deny.toml` ignore list.2.**C++ compiler dependency**: `tokenizers 0.22.2` added `esaxx-rs` which requires a C++ compiler — this could cause build failures on restrictive CI runner configurations.3.**`ureq 3.x` / `native-tls` / `openssl`**:The dependency chain `ort-sys → ureq 3.1.4 → native-tls → openssl` may have introduced platform-specific compilation issues.The `openssl` crate is now a transitive dependency which was not present before.
## RecommendedActions
- []**Check actual CI logs**for the specific error message in run [#23531982616](https://github.com/zircote/rlm-rs/actions/runs/23531982616)
- []**Primary fix**:If `unused_mut` is the error, update `src/embedding/fastembed_impl.rs` to remove `mut` from the two `model` lock bindings:
```rust
// Change:
let mutmodel = model.lock().map_err(...)?;// To:let model = model.lock().map_err(...)?;
```
- []**If `cargo deny` failed**:Add any new advisory IDs to the `ignore` list in `deny.toml` with justification comments, or update allowed licenses if a new dep has a permissive but unlisted license.
- []**Verify locally**: `cargo clippy --all-features -- -D warnings` to reproduce
## PreventionStrategies1.**Pin fastembed more strictly** in `Cargo.toml` using `~5.12` (tilde requirement) to only allow patch updates until the API change is verified.2.**Add a Dependabot test run prerequisite**:The automerge workflow(`dependabot-automerge.yml`) should require all CI checks to pass before merging dependency bumps.3.**AddAPI change tests**:A compile-time test or doc-test that exercises the `embed()` method signature would catch interface changes at merge time.
## AITeamSelf-ImprovementForAI coding agents (add to `CLAUDE.md` or agent instructions):
```
## DependencyBumpGuidance
- When reviewing dependabot PRs that bump `fastembed`, `ort`, or `tokenizers`, always check
for `&mutself` → `&self` method signature changes in `src/embedding/fastembed_impl.rs`.
- TheCI sets RUSTFLAGS="-D warnings", so any unused `mut` binding causes a build failure.
- After merging a dependency bump, verify with `cargo clippy --all-features -- -D warnings`
before marking the PRas complete.
- Check `deny.toml` ignore list if `cargo deny` fails — new transitive deps may need
advisory suppressions with justification comments.
Historical Context
This is the first recorded CI failure from a fastembed version bump in the investigation history. The pattern (dependency minor-version bump → API change → unused mut → -D warnings failure) is common in Rust projects that aggressively deny warnings and track fast-moving ML ecosystem crates.
Investigation performed by CI Failure Doctor (run #140) on 2026-03-25. Direct log access was unavailable; findings based on code analysis of the repository at 3fa0e5d.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Summary
The CI workflow (run #23531982616) failed after merging dependabot PR #159 which bumped
fastembedfrom 5.12.1 → 5.13.0.Failure Details
3fa0e5d105b8ebfa8802002edc5fb117ebb237bfci.yml)Root Cause Analysis
The most likely root cause is an API change in fastembed 5.13.0 where
TextEmbedding::embedchanged from&mut selfto&self. This would make twolet mut modelbindings insrc/embedding/fastembed_impl.rsunnecessary, generatingunused_mutcompiler warnings. Because the CI workflow setsRUSTFLAGS: "-D warnings", these warnings are promoted to errors, causing theclippy,test, andmsrvjobs to fail.Affected code in
src/embedding/fastembed_impl.rs:Historical Context
This is the first recorded CI failure from a fastembed version bump in the investigation history. The pattern (dependency minor-version bump → API change → unused
mut→-D warningsfailure) is common in Rust projects that aggressively deny warnings and track fast-moving ML ecosystem crates.Investigation performed by CI Failure Doctor (run #140) on 2026-03-25. Direct log access was unavailable; findings based on code analysis of the repository at
3fa0e5d.All reactions