Skip to content

Commit 9338465

Browse files
committed
feat(@angular/build): allow enabling Bazel sandbox plugin with esbuild
Setting the new `ENABLE_BAZEL_SANDBOX_PLUGIN` environment variable to `true` or `1` during a build with the `esbuild` based builder will now inject a special plugin to make `esbuild` compatible with Bazel builds in the output tree. When trying to integrate the `esbuild` based builder into Bazel with `rules_js` we found that it will incorrectly follow symlinks out of the sandbox. This is because Node.js based tooling runs in the output tree to support canonical JS project directory structures. The output tree will contain symlinks outside of the sandbox. Node tooling will generally follow these symlinks, which violates the rules of Bazel sandboxing. This can manifest in a wide variety of errors. One example we encountered with Angular compilation is that the symlinked browser entry point (e.g. `main.ts`) is outside of the range of `tsconfig.json` when the compiler follows the symlink. The plugin itself was originally written in https://github.com/aspect-build/rules_esbuild. The version container in this commit is a fork of https://github.com/aspect-build/rules_esbuild/blob/e4e49d3354cbf7087c47ac9c5f2e6fe7f5e398d3/esbuild/private/plugins/bazel-sandbox.js. I've adapted the JS file to TypeScript and made no further changes.
1 parent 6b4512b commit 9338465

File tree

2 files changed

+131
-0
lines changed

2 files changed

+131
-0
lines changed

packages/angular/build/src/tools/esbuild/application-code-bundle.ts

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -34,6 +34,7 @@ import { createSourcemapIgnorelistPlugin } from './sourcemap-ignorelist-plugin';
3434
import { SERVER_GENERATED_EXTERNALS, getFeatureSupport, isZonelessApp } from './utils';
3535
import { createVirtualModulePlugin } from './virtual-module-plugin';
3636
import { createWasmPlugin } from './wasm-plugin';
37+
import { createBazelSandboxPlugin } from './sandbox-plugin-bazel';
3738

3839
export function createBrowserCodeBundleOptions(
3940
options: NormalizedApplicationBuildOptions,
@@ -606,6 +607,19 @@ function getEsBuildCommonOptions(options: NormalizedApplicationBuildOptions): Bu
606607
}
607608
}
608609

610+
// Inject the Bazel sandbox plugin only when specifically enabled to be fully backward compatible.
611+
// Most users will never need this and as such should not have it influence their builds.
612+
if (
613+
process.env.ENABLE_BAZEL_SANDBOX_PLUGIN === 'true' ||
614+
process.env.ENABLE_BAZEL_SANDBOX_PLUGIN === '1'
615+
) {
616+
const bindir = process.env.BAZEL_BINDIR;
617+
const execroot = process.env.JS_BINARY__EXECROOT;
618+
if (bindir && execroot) {
619+
plugins.push(createBazelSandboxPlugin({ bindir, execroot }));
620+
}
621+
}
622+
609623
return {
610624
absWorkingDir: workspaceRoot,
611625
format: 'esm',
Lines changed: 117 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,117 @@
1+
/**
2+
* @license
3+
* Copyright Google LLC All Rights Reserved.
4+
*
5+
* Use of this source code is governed by an MIT-style license that can be
6+
* found in the LICENSE file at https://angular.dev/license
7+
*/
8+
9+
/**
10+
* Forked from https://github.com/aspect-build/rules_esbuild/blob/e4e49d3354cbf7087c47ac9c5f2e6fe7f5e398d3/esbuild/private/plugins/bazel-sandbox.js
11+
*/
12+
13+
import { join } from 'node:path';
14+
import { stat } from 'node:fs/promises';
15+
import type { OnResolveResult, Plugin, PluginBuild, ResolveOptions } from 'esbuild';
16+
17+
export interface CreateBazelSandboxPluginOptions {
18+
bindir: string;
19+
execroot: string;
20+
}
21+
22+
// Under Bazel, esbuild will follow symlinks out of the sandbox when the sandbox is enabled. See https://github.com/aspect-build/rules_esbuild/issues/58.
23+
// This plugin using a separate resolver to detect if the the resolution has left the execroot (which is the root of the sandbox
24+
// when sandboxing is enabled) and patches the resolution back into the sandbox.
25+
export function createBazelSandboxPlugin({
26+
bindir,
27+
execroot,
28+
}: CreateBazelSandboxPluginOptions): Plugin {
29+
return {
30+
name: 'bazel-sandbox',
31+
setup(build) {
32+
build.onResolve({ filter: /./ }, async ({ path: importPath, ...otherOptions }) => {
33+
// NB: these lines are to prevent infinite recursion when we call `build.resolve`.
34+
if (otherOptions.pluginData) {
35+
if (otherOptions.pluginData.executedSandboxPlugin) {
36+
return;
37+
}
38+
} else {
39+
otherOptions.pluginData = {};
40+
}
41+
otherOptions.pluginData.executedSandboxPlugin = true;
42+
43+
return await resolveInExecroot({ build, bindir, execroot, importPath, otherOptions });
44+
});
45+
},
46+
};
47+
}
48+
49+
interface ResolveInExecrootOptions {
50+
build: PluginBuild;
51+
bindir: string;
52+
execroot: string;
53+
importPath: string;
54+
otherOptions: ResolveOptions;
55+
}
56+
57+
async function resolveInExecroot({
58+
build,
59+
bindir,
60+
execroot,
61+
importPath,
62+
otherOptions,
63+
}: ResolveInExecrootOptions): Promise<OnResolveResult> {
64+
const result = await build.resolve(importPath, otherOptions);
65+
66+
if (result.errors && result.errors.length) {
67+
// There was an error resolving, just return the error as-is.
68+
return result;
69+
}
70+
71+
if (
72+
!result.path.startsWith('.') &&
73+
!result.path.startsWith('/') &&
74+
!result.path.startsWith('\\')
75+
) {
76+
// Not a relative or absolute path. Likely a module resolution that is marked "external"
77+
return result;
78+
}
79+
80+
// If esbuild attempts to leave the execroot, map the path back into the execroot.
81+
if (!result.path.startsWith(execroot)) {
82+
// If it tried to leave bazel-bin, return early.
83+
if (!result.path.includes(bindir)) {
84+
return result;
85+
}
86+
// Otherwise remap the bindir-relative path
87+
const correctedPath = join(execroot, result.path.substring(result.path.indexOf(bindir)));
88+
if (!!process.env.JS_BINARY__LOG_DEBUG) {
89+
console.error(
90+
`DEBUG: [bazel-sandbox] correcting resolution ${result.path} that left the sandbox to ${correctedPath}.`,
91+
);
92+
}
93+
result.path = correctedPath;
94+
95+
// Fall back to `.js` file if resolved `.ts` file does not exist in the changed path.
96+
//
97+
// It's possible that a `.ts` file exists outside the sandbox and esbuild resolves it. It's not
98+
// guaranteed that the sandbox also contains the same file. One example might be that the build
99+
// depend on a compiled version of the file and the sandbox will only contain the corresponding
100+
// `.js` and `.d.ts` files.
101+
if (result.path.endsWith('.ts')) {
102+
try {
103+
await stat(result.path);
104+
} catch (e: unknown) {
105+
const jsPath = result.path.slice(0, -3) + '.js';
106+
if (!!process.env.JS_BINARY__LOG_DEBUG) {
107+
console.error(
108+
`DEBUG: [bazel-sandbox] corrected resolution ${result.path} does not exist in the sandbox, trying ${jsPath}.`,
109+
);
110+
}
111+
result.path = jsPath;
112+
}
113+
}
114+
}
115+
116+
return result;
117+
}

0 commit comments

Comments
 (0)