Skip to content

xtask: Fail packaging if the vendor archive has PCRE2 C sources - #2529

Merged
cgwalters merged 1 commit into
bootc-dev:mainfrom
cgwalters-forge:bot/xtask-package-denylist
Oct 5, 2026
Merged

cgwalters merged 1 commit into
bootc-dev:mainfrom
cgwalters-forge:bot/xtask-package-denylist

Conversation

@cgwalters-bot

Copy link
Copy Markdown
Contributor

Follow-up to #2495, and stacked on it: the first commit here is #2495's.

exclude-crate-paths only matches a directory name, so if a pcre2-sys update moved its bundled sources the exclusion would silently stop applying. cargo xtask package now reads the generated vendor tarball and fails if it contains any .c/.h files from pcre2-sys (a small denylist, easy to extend to other -sys crates).

Testing, on a 16-core RHEL 10 devspace with stable Rust:
cargo test -p xtask (15 passed, including new table-driven tests) and the Makefile's clippy config are clean. cargo xtask package produces a vendor tarball with no pcre2-sys .c/.h files, and bootc builds from the source and vendor tarballs with cargo build --offline, linking the system libpcre2-8. With the #2495 exclusion reverted, cargo xtask package fails listing the 76 bundled files. just package builds the RPMs.

Related: #2495 (comment)

The Signed-off-by: Colin Walters <walters@verbum.org> on these commits was added on cgwalters's approval of the review draft: cgwalters-forge#17 (review)

Generated-by: https://github.com/cgwalters/#llms

The vendor tarball excludes pcre2-sys's bundled sources via
exclude-crate-paths, but that only matches a directory name. If a
pcre2-sys update moved them, the exclusion would silently stop applying
and we would be back to shipping (and possibly building) a second copy
of PCRE2. Inspect the generated archive against a small denylist
instead, so that shows up as a packaging failure.

Longer term vendor-filterer itself should support an allowlist for
C sources.

Generated-by: AI
Signed-off-by: Colin Walters <walters@verbum.org>
Comment thread crates/xtask/src/xtask.rs
/// These crates link against system libraries, so their bundled C sources are
/// excluded via `exclude-crate-paths` in the toplevel Cargo.toml; this catches
/// a crate update that moves them somewhere the exclusion no longer covers.
const VENDOR_DENYLIST: &[(&str, &[&str])] = &[("pcre2-sys", &["c", "h"])];

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's xref coreos/cargo-vendor-filterer#140 as a followup

@cgwalters
cgwalters merged commit 8bba809 into bootc-dev:main Oct 5, 2026
93 of 96 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants