All crates fail building with EXDEV under `setpriv --landlock-access fs:make-block,make-char` sandbox
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 119k
- Forks
- 16.1k
- PR merge metrics
- PR metrics pending
Description
I tried this code:
cargo add memchr # or anything
setpriv --landlock-access fs:make-block,make-char cargo build
I expected to see this happen: The build should complete successfully. uutils mv tolerates EXDEV and falls back to a file copy.
Instead, this happened: It gave up with Invalid cross-device link (os error 18)
Meta
rustc --version --verbose:
rustc 1.98.0-nightly (23a3312d9 2026-05-23)
binary: rustc
commit-hash: 23a3312d92a1c4ba0373f1e25277be20ba8bb28c
commit-date: 2026-05-23
host: x86_64-unknown-linux-gnu
release: 1.98.0-nightly
LLVM version: 22.1.6
Backtrace
home@daniel-desktop3:~/CLionProjects$ cargo new hello
Creating binary (application) `hello` package
note: see more `Cargo.toml` keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html
home@daniel-desktop3:~/CLionProjects$ cd hello
home@daniel-desktop3:~/CLionProjects/hello$ cargo add memchr
Updating crates.io index
Adding memchr v2.8.0 to dependencies
Features:
+ alloc
+ std
- core
- libc
- logging
- rustc-dep-of-std
- use_std
Updating crates.io index
Locking 1 package to latest Rust 1.98.0-nightly compatible version
home@daniel-desktop3:~/CLionProjects/hello$ RUST_BACKTRACE=1 setpriv --landlock-access fs:make-block,make-char cargo build
Compiling memchr v2.8.0
error: failed to write /home/home/CLionProjects/hello/target/debug/deps/libmemchr-6107e8755c89e2eb.rmeta: Invalid cross-device link (os error 18)
error: could not compile `memchr` (lib) due to 1 previous error
home@daniel-desktop3:~/CLionProjects/hello$ RUST_BACKTRACE=1 setpriv --landlock-access fs:make-block,make-char strace -ff cargo build
[...]
[pid 21676] statx(AT_FDCWD, "/home/home/CLionProjects/hello/target/debug/deps/libmemchr-6107e8755c89e2eb.rmeta", AT_STATX_SYNC_AS_STAT, STATX_ALL, 0x708070b75770) = -1 ENOENT (No such file or directory)
[pid 21676] mkdir("/home/home/CLionProjects/hello/target/debug/deps/rmetabcqPKm", 0777) = 0
[pid 21676] openat(AT_FDCWD, "/home/home/CLionProjects/hello/target/debug/deps/rmetabcqPKm/full.rmeta", O_RDWR|O_CREAT|O_TRUNC|O_CLOEXEC, 0666) = 7
[pid 21676] write(7, "rust\0\0\0\n\0\0\0\0\0\0\0\0+rustc 1.98.0-ni"..., 65534) = 65534
[pid 21676] write(7, "\305\22\22\0\2\0\0\1i\3\1\2\24\330\22\22\0\2\0\0\1P\3\1\2\24\353\22\22\0\2\0"..., 65528) = 65528
[pid 21676] write(7, "\255\373\1\27'\33\0\267\313\7\27\330\32\0\364\354\1\27/\32\0\267\313\7\27\f\32\0\364\354\1\27"..., 65529) = 65529
[pid 21676] write(7, "\0\17\223L\0\1%\0\4\17\36\0\3\17\200\17\0J\0\t\0\217\300\7\2\1K\0\1L\0\0"..., 65531) = 65531
[pid 21676] write(7, "\1\0\0\0\1\17\243\0\0\4\0\1\374\212\24i\f\0\0\0\0\0\0\2\0\0\0\0\1\4\321\25"..., 65532) = 65532
[pid 21676] madvise(0x708065ebb000, 20480, MADV_DONTNEED) = 0
[pid 21676] write(7, "\1\1\357\370\23\0\24\0\0\0\374\215<I\1\1\216\371\23\0\24\0\0\0\\\333<\1\1\340\371\23"..., 65531) = 65531
[pid 21676] mmap(NULL, 12582912, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS|MAP_NORESERVE, -1, 0) = 0x708065000000
[pid 21676] write(7, "\0160\2\1\2\315\16\37\2662\2\1\2\212\6\37\2632\2\34\313\372\1\n\0\0\0\0\0\0\0\0"..., 65533) = 65533
[pid 21676] write(7, "\0\324\6\1\1\0\325\6\0\17_mm_cmpgt_epi64\301}\205\253\1\35\1"..., 65527) = 65527
[pid 21676] write(7, "\31_mm256_maskz_cvttps_epi32\301\315\343\2545+"..., 65533) = 65533
[pid 21676] write(7, "\265\321y+\1\0\v\1\316\253\1\1\0\324\6\1\1\0\325\6\0\16_mm_rsqrt1"..., 65532) = 65532
[pid 21676] write(7, "\1\1\0\325\6\0\25_mm_maskz_cvtepi64_pd\301\255\276\321"..., 65522) = 65522
[pid 21676] write(7, "_mm512_cvtph_epi32\301\225\351\347+=\1\0\v\1\326\316\1\1"..., 65530) = 65530
[pid 21676] write(7, "\343\323\3\0\v\1\315\240\1\1\0\344\6\1\1\0\345\6\1\354\327 \37\314\323\3\0\v\1\317\240\1"..., 65532) = 65532
[pid 21676] write(7, "\0\344\6\1\1\0\345\6\1\375\303(\37\256\335\2\0\v\1\316\276\1\1\0\344\6\1\1\0\345\6\1"..., 65534) = 65534
[pid 21676] write(7, "\n\0\0\0\0\0\2\1\273\17\0\205\n\0\0\0\1\304\17\0\206\n\1\0\0\2\0\205\n\0\0\206"..., 65523) = 65523
[pid 21676] write(7, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., 65529) = 65529
[pid 21676] write(7, "\227A\5YB\5\0\0\0\233B\5\342B\5\0\0\0\0\0\0\231F\5\23H\5\235J\5\360M"..., 65530) = 65530
[pid 21676] madvise(0x70806524e000, 36864, MADV_DONTNEED) = 0
[pid 21676] madvise(0x70806624b000, 20480, MADV_DONTNEED) = 0
[pid 21676] write(7, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., 65530) = 65530
[pid 21676] write(7, "\3\0\6\2\5\3\0\0\0107\0\0\0\0\0\0\0\2\5\3\0\0\10\2\0\0\0\0\0\0\0\1"..., 35813) = 35813
[pid 21676] write(7, "ODHT\1\10\4 \250\10\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0\0\0\2\267\336\0\0"..., 64727) = 64727
[pid 21676] madvise(0x70806687e000, 20480, MADV_DONTNEED) = 0
[pid 21676] madvise(0x7080653ab000, 36864, MADV_DONTNEED) = 0
[pid 21676] madvise(0x70806810b000, 20480, MADV_DONTNEED) = 0
[pid 21676] madvise(0x7080665c1000, 20480, MADV_DONTNEED) = 0
[pid 21676] write(7, "\25\1-\1:\4PN1\4:OM\26\4\16\4J\4\10\30\4+1\10\n>I&\r@+"..., 10423) = 10423
[pid 21676] statx(7, "", AT_STATX_SYNC_AS_STAT|AT_EMPTY_PATH, STATX_ALL, {stx_mask=STATX_ALL|STATX_MNT_ID, stx_attributes=0, stx_mode=S_IFREG|0664, stx_size=1290503, ...}) = 0
[pid 21676] write(7, "rust-end-file", 13) = 13
[pid 21676] lseek(7, 0, SEEK_CUR) = 1290516
[pid 21676] lseek(7, 8, SEEK_SET) = 8
[pid 21676] write(7, "\30\257\23\0\0\0\0\0", 8) = 8
[pid 21676] lseek(7, 1290516, SEEK_SET) = 1290516
[pid 21676] close(7) = 0
[pid 21676] unlink("/home/home/CLionProjects/hello/target/debug/deps/libmemchr-6107e8755c89e2eb.rmeta") = -1 ENOENT (No such file or directory)
[pid 21676] rename("/home/home/CLionProjects/hello/target/debug/deps/rmetabcqPKm/full.rmeta", "/home/home/CLionProjects/hello/target/debug/deps/libmemchr-6107e8755c89e2eb.rmeta") = -1 EXDEV (Invalid cross-device link)
[pid 21676] ioctl(2, TCGETS2, 0x708070b743a0) = -1 ENOTTY (Inappropriate ioctl for device)
[pid 21676] write(2, "{\"$message_type\":\"diagnostic\",\"m"..., 444) = 444
[pid 21673] <... poll resumed>) = 1 ([{fd=13, revents=POLLIN}])
[pid 21676] futex(0x70808491c230, FUTEX_WAKE_PRIVATE, 2147483647 <unfinished ...>
[pid 21673] read(13 <unfinished ...>
[pid 21676] <... futex resumed>) = 0
[pid 21673] <... read resumed>, "{\"$message_type\":\"diagnostic\",\"m"..., 256) = 256
[pid 21673] read(13, "u001b[91merror\\u001b[0m\\u001b[1m", 32) = 32
[pid 21673] read(13, ": failed to write /home/home/CLi"..., 224) = 156
[pid 21676] statx(AT_FDCWD, "/home/home/CLionProjects/hello/target/debug/deps/rmetabcqPKm", AT_STATX_SYNC_AS_STAT|AT_SYMLINK_NOFOLLOW, STATX_ALL <unfinished ...>
[pid 21673] read(13 <unfinished ...>
[pid 21676] <... statx resumed>, {stx_mask=STATX_ALL|STATX_MNT_ID, stx_attributes=0, stx_mode=S_IFDIR|0775, stx_size=60, ...}) = 0
[pid 21673] <... read resumed>, 0x78f0080014dc, 68) = -1 EAGAIN (Resource temporarily unavailable)
[pid 21676] openat(AT_FDCWD, "/home/home/CLionProjects/hello/target/debug/deps/rmetabcqPKm", O_RDONLY|O_NOFOLLOW|O_CLOEXEC|O_DIRECTORY) = 7
[pid 21673] futex(0x59b293c6a8e0, FUTEX_WAKE_PRIVATE, 1 <unfinished ...>
[pid 21676] fstat(7 <unfinished ...>
[pid 21673] <... futex resumed>) = 1
[pid 21670] <... futex resumed>) = 0
[pid 21676] <... fstat resumed>, {st_mode=S_IFDIR|0775, st_size=60, ...}) = 0
[pid 21673] openat(AT_FDCWD, "/home/home/CLionProjects/hello/target/debug/.fingerprint/memchr-6107e8755c89e2eb/output-lib-memchr", O_WRONLY|O_CREAT|O_TRUNC|O_CLOEXEC, 0666 <unfinished ...>
[pid 21670] futex(0x59b293c6a8e4, FUTEX_WAKE_PRIVATE, 1 <unfinished ...>
[pid 21676] fcntl(7, F_GETFL <unfinished ...>
[pid 21670] <... futex resumed>) = 0
[pid 21676] <... fcntl resumed>) = 0x38000 (flags O_RDONLY|O_LARGEFILE|O_NOFOLLOW|O_DIRECTORY)
[pid 21670] write(2, "\33[K", 3 <unfinished ...>
[pid 21676] fcntl(7, F_SETFD, FD_CLOEXEC <unfinished ...>
[pid 21673] <... openat resumed>) = 10
[pid 21670] <... write resumed>) = 3
[pid 21676] <... fcntl resumed>) = 0
[pid 21670] write(2, "\33[1m\33[91merror\33[0m\33[1m: failed t"..., 167 <unfinished ...>
error: failed to write /home/home/CLionProjects/hello/target/debug/deps/libmemchr-6107e8755c89e2eb.rmeta: Invalid cross-device link (os error 18)
[pid 21673] write(10, "{\"$message_type\":\"diagnostic\",\"m"..., 443 <unfinished ...>
[pid 21670] <... write resumed>) = 167
[pid 21676] getdents64(7 <unfinished ...>
[pid 21670] write(2, "\n", 1
<unfinished ...>
[pid 21676] <... getdents64 resumed>, 0x7080663910f0 /* 3 entries */, 32768) = 80
[pid 21673] <... write resumed>) = 443
[pid 21670] <... write resumed>) = 1
[pid 21676] unlinkat(7, "full.rmeta", 0 <unfinished ...>
[...]
Workaround
Relax the sandbox to allow rename(2):
setpriv --landlock-access fs:make-block,make-char,refer \
--landlock-rule path-beneath:refer:"$PWD" cargo build
Analysis
The workaround does not add compatibility with sandbox environments that continue to restrict LANDLOCK_ACCESS_FS_REFER. When rename(2) fails, please add a fallback to copy_file_range(2), like uutils mv(1).
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Reproduce the failure with the provided setpriv and cargo build commands, then use the shown strace sequence to trace the temporary artifact rename. Investigate the rename(2) failure under restricted LANDLOCK_ACCESS_FS_REFER and compare the requested copy_file_range(2) fallback with the stated workaround. Done means the build succeeds without granting refer access.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- linux, rust
- Domain
- build-system, operating-systems
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100