{"record":{"id":"40750f304921ad98","repo":"rust-lang/cargo","slug":"invalid-inclusion-of-reserved-file-name-in-pack","errorCode":null,"errorMessage":"invalid inclusion of reserved file name {} in package source","messagePattern":"invalid inclusion of reserved file name (.+?) in package source","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/ops/cargo_package/mod.rs","lineNumber":515,"sourceCode":"#[tracing::instrument(skip_all)]\nfn build_ar_list(\n    ws: &Workspace<'_>,\n    pkg: &Package,\n    src_files: Vec<PathEntry>,\n    vcs_info: Option<vcs::VcsInfo>,\n    include_lockfile: bool,\n) -> CargoResult<Vec<ArchiveFile>> {\n    let mut result = HashMap::default();\n    let root = pkg.root();\n    for src_file in &src_files {\n        let rel_path = src_file.strip_prefix(&root)?;\n        check_filename(rel_path, &mut ws.gctx().shell())?;\n        let rel_str = rel_path.to_str().ok_or_else(|| {\n            anyhow::format_err!(\"non-utf8 path in source directory: {}\", rel_path.display())\n        })?;\n        match rel_str {\n            \"Cargo.lock\" => continue,\n            VCS_INFO_FILE | ORIGINAL_MANIFEST_FILE => anyhow::bail!(\n                \"invalid inclusion of reserved file name {} in package source\",\n                rel_str\n            ),\n            _ => {\n                result\n                    .entry(UncasedAscii::new(rel_str))\n                    .or_insert_with(Vec::new)\n                    .push(ArchiveFile {\n                        rel_path: rel_path.to_owned(),\n                        rel_str: rel_str.to_owned(),\n                        contents: FileContents::OnDisk(src_file.to_path_buf()),\n                    });\n            }\n        }\n    }\n\n    // Ensure we normalize for case insensitive filesystems (like on Windows) by removing the\n    // existing entry, regardless of case, and adding in with the correct case","sourceCodeStart":497,"sourceCodeEnd":533,"githubUrl":"https://github.com/rust-lang/cargo/blob/495c385d0875c4ba51eb72ea0448a2d4c018b8d4/src/ops/cargo_package/mod.rs#L497-L533","documentation":"During `cargo package`, cargo walks every source file to archive it. Two filenames are reserved and must NEVER come from the package's own source: `Cargo.toml.orig` (cargo writes the original manifest under this name itself) and `.cargo_vcs_info.json` (cargo generates this from VCS metadata). If either appears in the user's source tree, packaging aborts — including it would either be overwritten by cargo's generated copy (losing data) or spoof cargo's integrity metadata.","triggerScenarios":"Running `cargo package` when the package source tree contains a file literally named `Cargo.toml.orig` or `.cargo_vcs_info.json` — e.g. left over from unzipping a previously packaged `.crate`, or committed by mistake after extracting a published crate.","commonSituations":"Unpacking a downloaded `.crate` (which contains both reserved files) and then re-packaging without removing them. Copying a `target/package/` output back into source. A build script or generator that emits `Cargo.toml.orig`. Accidental commit of packaging artifacts.","solutions":["Delete the offending reserved file(s) from the source tree: `rm Cargo.toml.orig .cargo_vcs_info.json` (and add them to `.gitignore`).","Ensure no build/generation step writes these filenames into the package source.","If you extracted a published crate to study/modify it, remove the packaging metadata before re-packaging."],"exampleFix":"# before\n$ ls\nCargo.toml.orig  .cargo_vcs_info.json  Cargo.toml  src/\n$ cargo package   # error: invalid inclusion of reserved file name\n\n# after\n$ rm Cargo.toml.orig .cargo_vcs_info.json\n$ cargo package","handlingStrategy":"validation","validationCode":"use std::path::Path;\nconst RESERVED: &[&str] = &[\"Cargo.toml.orig\", \".cargo_vcs_info.json\"];\nfn contains_reserved_source_file(root: &Path) -> Vec<String> {\n    RESERVED.iter().filter(|n| root.join(n).exists()).map(|s| s.to_string()).collect()\n}\n// before `cargo package`, if !contains_reserved_source_file(&root).is_empty() { remove them }","typeGuard":"fn is_packaging_clean(root: &Path) -> bool { contains_reserved_source_file(root).is_empty() }","tryCatchPattern":null,"preventionTips":["Never commit `Cargo.toml.orig` or `.cargo_vcs_info.json` into source — they are packaging outputs.","Add both to `.gitignore`.","After extracting a published `.crate` to modify it, delete these metadata files before re-packaging.","Audit generators/build scripts to ensure none write these filenames into the source tree."],"tags":["cargo-package","reserved-files","packaging","vcs-metadata"],"backgroundTag":null,"analyzedSha":"495c385d0875c4ba51eb72ea0448a2d4c018b8d4","analyzedAt":"2026-08-11T17:42:36.556Z","contentChangedAt":"2026-08-11T17:42:36.556Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}