slint-ui/slint · error

LICENSE symlink " " points outside the repository

Error message

LICENSE symlink "{}" points outside the repository

What it means

After canonicalization, the symlink target must be an absolute path inside the repository top directory. This bail fires when the canonicalized target escapes the repo (relative ../ chains that go above the root) or is not absolute, blocking license files from being sourced outside the repository.

Solutions

  1. Recreate the symlink with the correct number of ../ so it lands on the repo's top-level LICENSES/ directory
  2. Run `cargo xtask reuse-compliance-check --fix-symlinks` to replace offending links
  3. Never point LICENSES symlinks outside the repo; copy the license text into the top-level LICENSES/ dir first

Example fix

// before
package/a/b/LICENSES/MIT.txt -> ../../../../../usr/share/common-licenses/MIT
// after
package/a/b/LICENSES/MIT.txt -> ../../../../LICENSES/MIT.txt
Defensive patterns

Strategy: validation

Validate before calling

let canon = std::fs::canonicalize(link.parent().unwrap().join(std::fs::read_link(link)?))?;
let top = std::fs::canonicalize(".")?;
if !canon.starts_with(&top) { eprintln!("escapes repo: {}", canon.display()); }

Type guard

fn target_inside_repo(link: &std::path::Path, top: &std::path::Path) -> bool {
    link.parent().and_then(|p| std::fs::read_link(link).ok().map(|t| p.join(t))).and_then(|p| std::fs::canonicalize(p).ok()).map(|c| c.starts_with(top)).unwrap_or(false)
}

Try / catch

if let Err(e) = run_check() {
    if e.to_string().contains("points outside the repository") { /* recompute the relative path within the repo */ }
    else { return Err(e); }
}

Prevention

When it happens

Trigger: A symlink in a sub-LICENSES/ dir whose relative target contains too many `../` components and escapes the repository root, or points at an absolute path elsewhere on disk — detected when running without --fix-symlinks.

Common situations: Wrong number of ../ in a hand-made symlink; symlink pointing to a license installed on the system (e.g. /usr/share/common-licenses/GPL-3); repo checked out at a shallow depth so ../ resolves above it.

Understand the failure class

Background: Path traversal blocked: "path escapes the workspace" and "outside site root" errors when a path will not stay inside its allowed directory — this error's family across 26 libraries.

Related errors


AI-assisted analysis of slint-ui/slint@bb937076de (2026-09-16). Data as JSON: /api/errors/945aa084dbc78ab2. Report an issue: GitHub.

Appendix: source

Thrown at xtask/src/reuse_compliance_check.rs:218

            continue;
        }
        if link_target_extension != ext || link_target_file_stem != file_stem {
            if !fix_it {
                anyhow::bail!(
                    "LICENSE symlink \"{}\" renames the license.",
                    child.to_string_lossy()
                );
            } else {
                to_remove.push(child.clone());
                to_add.push(file_stem.clone());
                continue;
            }
        }

        if !validated_link_target.is_absolute() || !validated_link_target.starts_with(&top_dir) {
            if !fix_it {
                let c = child.to_string_lossy();
                anyhow::bail!("LICENSE symlink \"{}\" points outside the repository", c);
            } else {
                to_remove.push(child.clone());
                to_add.push(file_stem.clone());
                continue;
            }
        }

        if !validated_link_target.starts_with(top_dir.join("LICENSES")) {
            if !fix_it {
                let c = child.to_string_lossy();
                anyhow::bail!(
                    "LICENSE symlink \"{}\" points to a random place in the repository",
                    c
                );
            } else {
                to_remove.push(child.clone());
                to_add.push(file_stem.clone());
                continue;

View on GitHub (pinned to bb937076de)