{"record":{"id":"76ec12e7f02df424","repo":"rust-lang/cargo","slug":"source-directory-was-modified-by-build-rs-during-c","errorCode":null,"errorMessage":"Source directory was modified by build.rs during cargo publish. Build scripts should not modify anything outside of OUT_DIR.\n {}\n\nTo proceed despite this, pass the `--no-verify` flag.","messagePattern":"Source directory was modified by build\\.rs during cargo publish\\. Build scripts should not modify anything outside of OUT_DIR\\.\n (.+?)\n\nTo proceed despite this, pass the `--no-verify` flag\\.","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/ops/cargo_package/verify.rs","lineNumber":123,"sourceCode":"            cli_features: opts.cli_features.clone(),\n            spec: ops::Packages::Packages(Vec::new()),\n            filter: ops::CompileFilter::Default {\n                required_features_filterable: true,\n            },\n            target_rustdoc_args: None,\n            target_rustc_args: rustc_args,\n            target_rustc_crate_types: None,\n            rustdoc_document_private_items: false,\n            honor_rust_version: None,\n        },\n        &exec,\n    )?;\n\n    // Check that `build.rs` didn't modify any files in the `src` directory.\n    let ws_fingerprint = hash_all(&dst)?;\n    if pkg_fingerprint != ws_fingerprint {\n        let changes = report_hash_difference(&pkg_fingerprint, &ws_fingerprint);\n        anyhow::bail!(\n            \"Source directory was modified by build.rs during cargo publish. \\\n             Build scripts should not modify anything outside of OUT_DIR.\\n\\\n             {}\\n\\n\\\n             To proceed despite this, pass the `--no-verify` flag.\",\n            changes\n        )\n    }\n\n    Ok(())\n}\n\n/// Hashes everything under a given directory.\n///\n/// This is for checking if any source file inside a `.crate` file has changed\n/// durint the compilation. It is usually caused by bad build scripts or proc\n/// macros trying to modify source files. Cargo disallows that.\nfn hash_all(path: &Path) -> CargoResult<HashMap<PathBuf, u64>> {\n    fn wrap(path: &Path) -> CargoResult<HashMap<PathBuf, u64>> {","sourceCodeStart":105,"sourceCodeEnd":141,"githubUrl":"https://github.com/rust-lang/cargo/blob/eb98b54bc9f3c74519f43d066cb3fd02ebc88df0/src/ops/cargo_package/verify.rs#L105-L141","documentation":"Thrown during the verification step of `cargo publish` when a build script (`build.rs`) modifies files inside the `src` directory. Cargo fingerprints the source tree before and after compilation; a hash mismatch means the build script wrote outside its designated `OUT_DIR`, which could corrupt the published crate. The `--no-verify` flag skips this check.","triggerScenarios":"Running `cargo publish` (without `--no-verify`) on a crate whose `build.rs` or a proc-macro invoked during compilation writes to, creates, or deletes files under `src/`. The `hash_all(&dst)` comparison detects any change.","commonSituations":"Build scripts that generate code into `src/` instead of `OUT_DIR`; proc macros that emit files next to source; buggy or malicious build scripts; code generators writing to tracked source paths.","solutions":["Fix the build script to write generated files exclusively to `$OUT_DIR` (the directory passed to build scripts).","Fix proc macros to not emit files into the source tree.","Pass `--no-verify` to bypass the check if the modification is intentional and safe: `cargo publish --no-verify`."],"exampleFix":"// build.rs (before — writes to src/)\nfn main() {\n    std::fs::write(\"src/generated.rs\", \"// ...\").unwrap();\n}\n\n// build.rs (after — writes to OUT_DIR)\nfn main() {\n    let out_dir = std::env::var(\"OUT_DIR\").unwrap();\n    std::fs::write(\n        std::path::Path::new(&out_dir).join(\"generated.rs\"),\n        \"// ...\",\n    ).unwrap();\n}","handlingStrategy":"validation","validationCode":"// Verify build script only writes to OUT_DIR\n// In build.rs, always use:\nfn main() {\n    let out_dir = std::env::var(\"OUT_DIR\").expect(\"OUT_DIR not set\");\n    // Only write under out_dir\n    let path = std::path::Path::new(&out_dir).join(\"generated.rs\");\n    std::fs::write(&path, \"// generated\").unwrap();\n    println!(\"cargo:rerun-if-changed=some_input.txt\");\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Never write to `src/` or any path outside `OUT_DIR` in build scripts.","Audit proc macros for file-writing side effects.","Run `cargo publish --dry-run` locally which triggers the verification step."],"tags":["cargo-publish","build-script","verification","source-modification","out-dir"],"backgroundTag":null,"analyzedSha":"eb98b54bc9f3c74519f43d066cb3fd02ebc88df0","analyzedAt":"2026-08-11T17:42:36.556Z","contentChangedAt":"2026-08-11T17:42:36.556Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}