Skip to content

Cargo lint extraction reads workspace files that are not declared action inputs #4290

Description

@jrandolf

Description

extract_cargo_lints declares the package manifest and optional workspace manifest as inputs. When a workspace manifest is provided, the helper completes the Cargo package from disk, which can read workspace members or inherited resources that are absent from the Bazel sandbox. Lint extraction fails even though both manifests contain everything needed to resolve the lint settings.

The helper should read the declared manifests and resolve [lints] / [workspace.lints] without requiring the rest of the Cargo workspace.

Reproduction steps

The regression in #4274 creates only two manifest files. The workspace lists a missing member and a missing README; the package inherits the README, version and lint settings. Those files stand in for valid workspace files that the extraction action has not declared as inputs.

Run the helper with the package and workspace manifests and request its lints output. It should emit --deny=unused, --forbid=unsafe_code and --warn=clippy::all without opening the member or README. Before the fix, manifest completion fails on missing workspace files.

To use the regression in the rules_rust checkout, add only cargo/tests/cargo_toml_info from the PR to the affected revision and run:

bazel test //cargo/tests/cargo_toml_info:declared_manifests_test

Additional context

Proposed fix: #4274. The helper can parse both supplied manifests with Manifest::from_str and use the existing lint-inheritance logic. The regression covers extraction for a root package and a member package.

Impact

Workspace-inherited lint configurations can fail under sandboxed builds even though the extraction rule's declared inputs are present.

Bazel and rules_rust version

Affected rules_rust revision: c708b236. The existing regression work used Bazel 9.2.0 on macOS arm64.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions