[8.8.0] Compare paths as fragments in `AbstractActionInputPrefetcher` (#30690)

This is required because `execRoot` might be located on an action file
system overlaying the host file system where downloads are written (see
the changes in
https://github.com/bazelbuild/bazel/commit/b8589c3b278e3f5cee6ef85b0dcabb1cdcd69839
for context).

Without this fix, a directory that is temporarily made writable during
the materialization of a tree artifact isn't recognized as living under
the exec root, so it is silently left with its output permissions and
files can't be moved into place. This has been observed as a tree
artifact whose top-level directory was writable while a subdirectory was
left read-only, surfacing as a spurious missing CAS blob error since all
materialization errors are converted into that.

PiperOrigin-RevId: 830480221
Change-Id: I217b81a81da80f2050c4ec9082ef5f18cb9a0bc9
(cherry picked from commit 1e9d843fa6362b88d5ca1b6cc04b38f69823fb76)

8.8.0 adaptation: on this branch `setWritable` additionally
short-circuits on external repository paths under the output base and
obtains the exec root lazily via `execRoot()`, so the fragment
comparison is applied to the existing `execRoot()` check rather than
replacing the condition wholesale.

This supersedes #30680, which applies the original patch verbatim and
thereby drops the external repository check as well as referencing
`execRoot` as a field, which doesn't exist on this branch.

Co-authored-by: Tiago Quelhas <tjgq@google.com>
1 file changed
tree: 9a12e140ebef8e3f526e8635be3c0e86fae230df
  1. .bazelci/
  2. .github/
  3. examples/
  4. scripts/
  5. site/
  6. src/
  7. third_party/
  8. tools/
  9. .bazelrc
  10. .bazelversion
  11. .gitattributes
  12. .gitignore
  13. AUTHORS
  14. bazel_downloader.cfg
  15. BUILD
  16. CHANGELOG.md
  17. CODE_OF_CONDUCT.md
  18. CODEOWNERS
  19. combine_distfiles.py
  20. combine_distfiles_to_tar.sh
  21. compile.sh
  22. CONTRIBUTING.md
  23. CONTRIBUTORS
  24. distdir.bzl
  25. extensions.bzl
  26. LICENSE
  27. maven_install.json
  28. MODULE.bazel
  29. MODULE.bazel.lock
  30. README.md
  31. repositories.bzl
  32. requirements.txt
  33. SECURITY.md
  34. workspace_deps.bzl
README.md

Bazel

{Fast, Correct} - Choose two

Build and test software of any size, quickly and reliably.

  • Speed up your builds and tests: Bazel rebuilds only what is necessary. With advanced local and distributed caching, optimized dependency analysis and parallel execution, you get fast and incremental builds.

  • One tool, multiple languages: Build and test Java, C++, Android, iOS, Go, and a wide variety of other language platforms. Bazel runs on Windows, macOS, and Linux.

  • Scalable: Bazel helps you scale your organization, codebase, and continuous integration solution. It handles codebases of any size, in multiple repositories or a huge monorepo.

  • Extensible to your needs: Easily add support for new languages and platforms with Bazel's familiar extension language. Share and re-use language rules written by the growing Bazel community.

Getting Started

Documentation

Reporting a Vulnerability

To report a security issue, please email security@bazel.build with a description of the issue, the steps you took to create the issue, affected versions, and, if known, mitigations for the issue. Our vulnerability management team will respond within 3 working days of your email. If the issue is confirmed as a vulnerability, we will open a Security Advisory. This project follows a 90 day disclosure timeline.

Contributing to Bazel

See CONTRIBUTING.md

Build status