Skip to content

fix: redact exec root before = in build script env output - #84

Open
pawelchcki wants to merge 1 commit into
hermeticbuild:mainfrom
pawelchcki:fix/redact-exec-root-before-equals
Open

pawelchcki wants to merge 1 commit into
hermeticbuild:mainfrom
pawelchcki:fix/redact-exec-root-before-equals

Conversation

@pawelchcki

Copy link
Copy Markdown

Summary

  • redact_exec_root now also rewrites the exec root when = follows it, as well as / and \.
  • Adds a regression test covering --remap-path-prefix=<exec_root>=.. The test also checks that a sibling path sharing the prefix (/abs/exec_root2/...) is left untouched.

Problem

cargo_build_script gives build scripts

CARGO_ENCODED_RUSTFLAGS=--sysroot=${pwd}/<sysroot>\x1f--remap-path-prefix=${pwd}=.

and the runner expands ${pwd} to the absolute exec root before it runs the script. Some build scripts echo that variable back as cargo:rustc-env, for example rav1e 0.8 and av-scenechange 0.14. On the way back, redact_exec_root turns --sysroot=<exec_root>/... into ${pwd}/.... It leaves --remap-path-prefix=<exec_root>=. alone, because only <exec_root>/ and <exec_root>\ are matched. As a result, _bs.env ends up containing something like:

CARGO_ENCODED_RUSTFLAGS=--sysroot=${pwd}/bazel-out/.../rust_toolchain\x1f--remap-path-prefix=/home/u/.cache/bazel/_bazel_u/<hash>/sandbox/linux-sandbox/2574/execroot/_main=.\x1f--cap-lints=allow

The sandbox directory number changes on every execution. So the crate's Rustc action gets a new key every time and can't be served from a remote or disk cache on any fresh output base, on CI or on another machine. Upstream bazelbuild/rules_rust replaces every occurrence of the exec root and doesn't have this problem. It appeared when the replacement was narrowed to avoid matching sibling paths that share the prefix. Matching on a trailing = keeps that protection.

How it was found

I built the same tree from clean twice, in two checkouts with different output bases, then diffed the two --execution_log_json_file logs. The only actions with the same key but different outputs were the CargoBuildScriptRun actions for rav1e and av-scenechange, and the only difference was the line above. With this change applied as a patch through rules_rs's rules_rust.patch(...), every spawn's action key and outputs matched between the two builds.

Testing

  • The new exec_root_followed_by_equals_is_redacted test fails without the fix (--remap-path-prefix=/abs/exec_root=. stays in the output) and passes with it.
  • All 12 tests in cargo_build_script_runner pass, with TEST_TMPDIR set for cargo_manifest_dir::tests::replace_symlinks_in_out_dir.
  • rustfmt --check is clean.

Build scripts receive CARGO_ENCODED_RUSTFLAGS containing
`--remap-path-prefix=${pwd}=.`, and some (rav1e, av-scenechange) echo it
back as `cargo:rustc-env`. redact_exec_root only rewrote the exec root when
followed by `/` or `\`, so the absolute per-action sandbox path survived
into _bs.env, giving the crate's Rustc action a different key on every
execution and defeating remote/disk caching on fresh output bases.

Also redact when the exec root is followed by `=`, which keeps the existing
protection against matching sibling paths that share the prefix.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant