fix(ls-posts): keep cargo out of $HOME so the build is pure unsandboxed #1

Merged
hutao merged 1 commit from fix/cargo-home-purity into main 2026-09-25 08:23:35 +00:00
Owner

nixpkgs' cargoSetupHook sets no CARGO_HOME, so cargo falls back to its
default of $HOME/.cargo and creates it on any invocation, cargo metadata included. Sandboxed that is invisible. Unsandboxed, as on the
Forgejo runner, $HOME is /homeless-shelter and Nix never creates it, so
cargo makes it for real on the job container's root and Nix refuses to
start every later builder in that job:

error: home directory "/homeless-shelter" exists; please remove it to assure purity of builds without sandboxing

The error names the innocent build, not this one. .#default is a
symlinkJoin over ls-posts, i.e. a second builder in the same command, so
it tripped on every run.

Setting CARGO_HOME under $NIX_BUILD_TOP fixes it at the cause rather than
mopping up after it, and needs no sandbox: the Forgejo runner's job
containers cannot sandbox at all -- measured on the box, Nix reports "this
system does not support the kernel namespaces that are required for
sandboxing", and neither seccomp=unconfined nor a capability short of
SYS_ADMIN changes that.

So .forgejo/workflows/ci.yml drops its rm -rf /homeless-shelter dance and
its split build, and is now a plain twin of the GitHub one.

nixpkgs' cargoSetupHook sets no `CARGO_HOME`, so cargo falls back to its default of `$HOME/.cargo` and creates it on any invocation, `cargo metadata` included. Sandboxed that is invisible. Unsandboxed, as on the Forgejo runner, `$HOME` is `/homeless-shelter` and Nix never creates it, so cargo makes it for real on the job container's root and Nix refuses to start every later builder in that job: `error: home directory "/homeless-shelter" exists; please remove it to assure purity of builds without sandboxing` The error names the innocent build, not this one. `.#default` is a symlinkJoin over ls-posts, i.e. a second builder in the same command, so it tripped on every run. Setting `CARGO_HOME` under `$NIX_BUILD_TOP` fixes it at the cause rather than mopping up after it, and needs no sandbox: the Forgejo runner's job containers cannot sandbox at all -- measured on the box, Nix reports "this system does not support the kernel namespaces that are required for sandboxing", and neither `seccomp=unconfined` nor a capability short of `SYS_ADMIN` changes that. So `.forgejo/workflows/ci.yml` drops its `rm -rf /homeless-shelter` dance and its split build, and is now a plain twin of the GitHub one.
fix(ls-posts): keep cargo out of $HOME so the build is pure unsandboxed
All checks were successful
CI / Format, lint and build (pull_request) Successful in 2m3s
3371eafe57
nixpkgs' cargoSetupHook sets no CARGO_HOME, so cargo falls back to its
default of $HOME/.cargo and creates it -- on any invocation, `cargo
metadata` included. Sandboxed that is invisible. Unsandboxed, as on the
Forgejo runner, $HOME is /homeless-shelter and Nix never creates it, so
cargo makes it for real on the job container's root and Nix refuses to
start every later builder in that job:

  error: home directory "/homeless-shelter" exists; please remove it to
  assure purity of builds without sandboxing

The error names the innocent build, not this one. `.#default` is a
symlinkJoin over ls-posts, i.e. a second builder in the same command, so
it tripped on every run.

Setting CARGO_HOME under $NIX_BUILD_TOP fixes it at the cause rather than
mopping up after it, and needs no sandbox: the Forgejo runner's job
containers cannot sandbox at all -- measured on the box, Nix reports "this
system does not support the kernel namespaces that are required for
sandboxing", and neither seccomp=unconfined nor a capability short of
SYS_ADMIN changes that.

So .forgejo/workflows/ci.yml drops its `rm -rf /homeless-shelter` dance and
its split build, and is now a plain twin of the GitHub one.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
hutao merged commit 36975336f3 into main 2026-09-25 08:23:35 +00:00
hutao deleted branch fix/cargo-home-purity 2026-09-25 08:23:35 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
hutao/cli-utils!1
No description provided.