# \`using\` a package that uses \`OrderedCollections\` can silently add function methods?

**URL:** <https://discourse.julialang.org/t/using-a-package-that-uses-orderedcollections-can-silently-add-function-methods/60741>\
**Category:** New to Julia\
**Tags:** question, type-piracy\
**Created:** [May 7, 2021, 7:24pm UTC](https://discourse.julialang.org/t/using-a-package-that-uses-orderedcollections-can-silently-add-function-methods/60741 "2021-05-07T19:24:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tomohiro\_soejima](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tomohiro_soejima/32/8056_2.png) [@tomohiro\_soejima](https://discourse.julialang.org/u/tomohiro_soejima)\
**Post date:** [May 7, 2021, 7:24pm UTC](https://discourse.julialang.org/t/using-a-package-that-uses-orderedcollections-can-silently-add-function-methods/60741/1 "2021-05-07T19:24:31Z")

</div>

(This might not be specific to `Revise`, but I have not looked for other examples yet. Will change the title if this topic applies more generally.)

`sort` usually does not work with dictionaries, but it starts to work after `using Revise`, even though [`Revise` does not export `sort`](https://github.com/timholy/Revise.jl/search?q=export).

```julia
test_dict = Dict(1=>2, 2=>1)
sort(test_dict) # this errors
using Revise
sort(test_dict) # this does not error and prints the following

OrderedCollections.OrderedDict{Int64, Int64} with 2 entries:
  1 => 2
  2 => 1

```

`@which` tells us the function is from `OrderedCollections`, even though `OrderedCollections` itself is brought in scope.

```julia
julia> @which sort(test_dict)
sort(d::Dict; args...) in OrderedCollections at deprecated.jl:70

julia> OrderedCollections
ERROR: UndefVarError: OrderedCollections not defined

julia> Revise.OrderedCollections # this is in scope, and it gets printed without a qualifier
# which might be why @which says sort is from OrderedCollections
OrderedCollections

```

This seems to have something to do with the fact [Revise.jl uses OrderedCollections](https://github.com/timholy/Revise.jl/blob/509d1c3155f14690035000c809ad00aae556c51b/src/Revise.jl#L12), but I don’t quite understand how it works. Specifically,

1. I thought `using` only brings in exported names and the module name into scope. Why does the behavior of `sort` change?
2. Does this mean I always need to worry about the possibility that an imported package might silently add some methods to functions?

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![rdeits](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/rdeits/32/286_2.png) [@rdeits](https://discourse.julialang.org/u/rdeits)\
**Post date:** [May 7, 2021, 7:32pm UTC](https://discourse.julialang.org/t/using-a-package-that-uses-orderedcollections-can-silently-add-function-methods/60741/2 "2021-05-07T19:32:23Z")

</div>

This is a classic case of [type piracy](https://docs.julialang.org/en/v1/manual/style-guide/#Avoid-type-piracy), in this case within `OrderedCollections`. `Revise` isn’t actually relevant here except that it happens to be the first thing in your environment to use `OrderedCollections` and thus trigger the issue. This was actually already identified as a bug in OrderedCollections: [Type piracy? · Issue #25 · JuliaCollections/OrderedCollections.jl · GitHub](https://github.com/JuliaCollections/OrderedCollections.jl/issues/25) and was fixed by deprecating that method: [do not support sorting a Dict by dpo · Pull Request #26 · JuliaCollections/OrderedCollections.jl · GitHub](https://github.com/JuliaCollections/OrderedCollections.jl/pull/26) (which will hopefully be removed completely soon).

> [@tomohiro\_soejima](#):
>
> Does this mean I always need to worry about the possibility that an imported package might silently add some methods to functions?

Only if that package commits [type piracy](https://docs.julialang.org/en/v1/manual/style-guide/#Avoid-type-piracy), which is exactly why we always tell people to avoid that.

---

<div class="post-metadata">

**Author:** ![tomohiro\_soejima](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tomohiro_soejima/32/8056_2.png) [@tomohiro\_soejima](https://discourse.julialang.org/u/tomohiro_soejima)\
**Post date:** [May 7, 2021, 7:42pm UTC](https://discourse.julialang.org/t/using-a-package-that-uses-orderedcollections-can-silently-add-function-methods/60741/3 "2021-05-07T19:42:04Z")

</div>

Thanks for your quick response! That makes sense.

As a follow-up question, does this mean there is nothing users can do to protect ourselves from type piracy, other than to hope they don’t exist? I initially thought modules that are called inside a package wouldn’t be an issue because it’s separated by two `using`s (I call `Revise` which calls `OrderedCollections`), but I suppose that is not the case? In other words, not only do I need to hope a package I load is not committing type piracy, but I also need to hope all dependencies of the package did not commit type piracy?

---

<div class="post-metadata">

**Author:** ![rdeits](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/rdeits/32/286_2.png) [@rdeits](https://discourse.julialang.org/u/rdeits)\
**Post date:** [May 7, 2021, 8:04pm UTC](https://discourse.julialang.org/t/using-a-package-that-uses-orderedcollections-can-silently-add-function-methods/60741/4 "2021-05-07T20:04:15Z")

</div>

> [@tomohiro\_soejima](#):
>
> I initially thought modules that are called inside a package wouldn’t be an issue because it’s separated by two `using` s (I call `Revise` which calls `OrderedCollections` ), but I suppose that is not the case?

No, that has no effect. There is only ever one instance of a given module, so the `OrderedCollections` inside `Revise` is the same one you get everywhere else (it is possible to have two unrelated modules with the same name, but that’s unrelated to what’s going on here).

> [@tomohiro\_soejima](#):
>
> As a follow-up question, does this mean there is nothing users can do to protect ourselves from type piracy, other than to hope they don’t exist?

You might try [Pirate Hunter](https://discourse.julialang.org/t/pirate-hunter/20402) (I haven’t used it myself)

> [@tomohiro\_soejima](#):
>
> In other words, not only do I need to hope a package I load is not committing type piracy, but I also need to hope all dependencies of the package did not commit type piracy?

Basically yes. In my experience, this is rarely a problem, but it is something to be aware of.

---

<div class="post-metadata">

**Author:** ![tomohiro\_soejima](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tomohiro_soejima/32/8056_2.png) [@tomohiro\_soejima](https://discourse.julialang.org/u/tomohiro_soejima)\
**Post date:** [May 7, 2021, 9:10pm UTC](https://discourse.julialang.org/t/using-a-package-that-uses-orderedcollections-can-silently-add-function-methods/60741/5 "2021-05-07T21:10:44Z")

</div>

Great, thanks for the clarifications!
