Skip to content

Fix OUT_DIR sanitization in cargo_build_script - #4050

Merged
UebelAndre merged 2 commits into
bazelbuild:mainfrom
UebelAndre:path_mapping
May 21, 2026
Merged

Fix OUT_DIR sanitization in cargo_build_script#4050
UebelAndre merged 2 commits into
bazelbuild:mainfrom
UebelAndre:path_mapping

Conversation

@UebelAndre

Copy link
Copy Markdown
Collaborator

closes #4045

@UebelAndre
UebelAndre marked this pull request as ready for review May 19, 2026 18:34
@UebelAndre
UebelAndre requested a review from slackito May 19, 2026 18:35
_transitive_out_dir_subst_test = analysistest.make(
_transitive_out_dir_subst_test_impl,
doc = """\
Test that `--subst` values were used passed which is used to dereference command line

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm having trouble parsing this first line, around "values were used passed". Is there a typo somewhere?

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wow yeah, I totally lost my way in this sentence. Fixed docs!

@UebelAndre
UebelAndre enabled auto-merge May 21, 2026 13:56
@UebelAndre
UebelAndre added this pull request to the merge queue May 21, 2026
Merged via the queue into bazelbuild:main with commit a2d98d6 May 21, 2026
3 checks passed
github-merge-queue Bot pushed a commit that referenced this pull request Jul 5, 2026
### The bug

Since the `OUT_DIR` sanitization work (#4050 / #4011, first released in
0.71.x), `outputs_to_dep_env` redacts the producer's `out_dir` to the
generic `${out_dir}` substitution token, the same way `outputs_to_env`
does.

That redaction is only correct for `_bs.env` files, which are consumed
by the target that directly owns the build script (where
`process_wrapper`'s `--out-dir` resolves the token to the right
directory). Dep env (`DEP_*`) files, however, are consumed by
*downstream* crates' build scripts: their runner only substitutes
`${pwd}`, and their own `out_dir` points to a different directory. The
token is therefore left unresolved, or would resolve to the wrong
directory.

Real-world failure: `libssh2-sys`'s build script fails to find `zlib.h`
because `libz-sys`'s `DEP_Z_INCLUDE` contains a literal `${out_dir}`
path component. Found while upgrading `rules_rust` to 0.71.3 in
dfinity/ic (see dfinity/ic#10632, where this fix is currently carried as
a patch).

### The fix

Only substitute the exec root in dep env files and keep the real
`out_dir` path. That path is valid for consumers: the producer's
`out_dir` is a declared input of downstream build script actions.

### Tests

* Unit test
`out_dir_in_dep_env_value_is_not_redacted_to_substitution_token` in
`cargo/private/cargo_build_script_runner/lib.rs`.
* End-to-end regression test `//cargo/tests/dep_env:build_read_out_dir`
mirroring the libz-sys → libssh2-sys scenario: a producer build script
advertises `cargo:include=$OUT_DIR/include` and the consumer build
script asserts `DEP_Z_INCLUDE` points at an existing directory. Fails
without the fix, passes with it.

---

Assisted-by: GitHub Copilot
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants