使用Bazel rules_foreign_cc调用CMake无法下载外部包
问题分析:Bazel中CMake无法下载nlohmann/json依赖(状态码7)
问题背景
开发Bazel C++项目时,尝试通过rules_foreign_cc的cmake规则集成外部库databento。本地直接使用CMake构建该库正常,但通过Bazel执行时,CMake无法下载依赖nlohmann/json,报错连接服务器被拒绝(状态码7)。
相关文件内容
BUILD文件
load("@rules_cc//cc:defs.bzl", "cc_library") load("@rules_foreign_cc//foreign_cc:defs.bzl", "cmake") cmake( name = "databento", build_args = [ "-j16", ], lib_source = "@databento//:all", targets = [ "install", ], visibility = ["//visibility:public"])
WORKSPACE文件片段
load("@bazel_tools//tools/build_defs/repo:http.bzl", "http_archive") all_content = """filegroup( name = "all", srcs = glob(["**"]), visibility = ["//visibility:public"] ) """ http_archive( name = "databento", strip_prefix = "databento-cpp-0.14.1", build_file_content = all_content, urls = ["https://github.com/databento/databento-cpp/archive/refs/tags/v0.14.1.tar.gz"], # build_file = "//library-bazel-builds:databento.BUILD", ) load("@bazel_tools//tools/build_defs/repo:http.bzl", "http_archive") http_archive( name = "rules_foreign_cc", # TODO: Get the latest sha256 value from a bazel debug message or the latest # release on the releases page: https://github.com/bazelbuild/rules_foreign_cc/releases # # sha256 = "...", strip_prefix = "rules_foreign_cc-51152aac9d6d8b887802a47ec08a1a37ef2c4885", url = "https://github.com/bazelbuild/rules_foreign_cc/archive/51152aac9d6d8b887802a47ec08a1a37ef2c4885.tar.gz", ) load("@rules_foreign_cc//foreign_cc:repositories.bzl", "rules_foreign_cc_dependencies") rules_foreign_cc_dependencies()
错误日志(翻译后)
-- 正在下载... 目标路径='/private/var/tmp/_bazel_root/1beb7f234b15119b93696bf5c0611a9f/sandbox/darwin-sandbox/9/execroot/Trading_Core/bazel-out/darwin_arm64-fastbuild/bin/Databento/databento.build_tmpdir/_deps/json-subbuild/json-populate-prefix/src/json.tar.xz' 超时时间='无' 无活动超时='无' -- 使用源地址='https://github.com/nlohmann/json/releases/download/v3.11.2/json.tar.xz' -- 重试... -- 使用源地址='https://github.com/nlohmann/json/releases/download/v3.11.2/json.tar.xz' -- 5秒后重试(第2次尝试)... -- 使用源地址='https://github.com/nlohmann/json/releases/download/v3.11.2/json.tar.xz' -- 5秒后重试(第3次尝试)... -- 使用源地址='https://github.com/nlohmann/json/releases/download/v3.11.2/json.tar.xz' -- 15秒后重试(第4次尝试)... -- 使用源地址='https://github.com/nlohmann/json/releases/download/v3.11.2/json.tar.xz' -- 60秒后重试(第5次尝试)... -- 使用源地址='https://github.com/nlohmann/json/releases/download/v3.11.2/json.tar.xz' CMake错误位于json-subbuild/json-populate-prefix/src/json-populate-stamp/download-json-populate.cmake:170 (message): 所有下载尝试均失败! 错误:下载'https://github.com/nlohmann/json/releases/download/v3.11.2/json.tar.xz'失败 状态码:7 状态信息:"无法连接到服务器" 日志: --- 日志开始 --- 尝试连接140.82.112.3:443... 连接140.82.112.3立即失败:操作不被允许 关闭连接0 --- 日志结束 --- 错误:下载'https://github.com/nlohmann/json/releases/download/v3.11.2/json.tar.xz'失败 状态码:7 状态信息:"无法连接到服务器" 日志: --- 日志开始 --- 尝试连接140.82.112.3:443... 连接140.82.112.3立即失败:操作不被允许 关闭连接0
问题原因及解决方案
核心原因
Bazel的沙箱机制默认限制构建过程中的网络访问。当通过rules_foreign_cc调用CMake时,CMake在沙箱环境内尝试下载nlohmann/json,被Bazel的网络隔离策略阻止,导致连接失败(状态码7对应CURLE_COULDNT_CONNECT,日志中的操作不被允许也验证了这一点)。而本地直接用CMake构建时无沙箱限制,因此可以正常下载依赖。
解决方法
禁用单个目标的沙箱:
在cmake规则中添加sandbox = "never",允许该构建目标绕过沙箱限制,获得网络访问权限:cmake( name = "databento", build_args = [ "-j16", ], lib_source = "@databento//:all", targets = [ "install", ], sandbox = "never", # 添加该行 visibility = ["//visibility:public"])全局禁用沙箱(仅临时调试用):
执行Bazel命令时添加--sandbox_debug --nouse_sandbox参数,全局关闭沙箱,但会降低所有构建目标的隔离性,不推荐长期使用。预依赖管理(推荐方案):
通过Bazel的http_archive预先下载nlohmann/json,再修改databento的CMake配置,强制使用本地已有的依赖,避免构建过程中动态下载:- 在WORKSPACE中添加nlohmann/json的依赖声明:
http_archive( name = "nlohmann_json", strip_prefix = "json-3.11.2", urls = ["https://github.com/nlohmann/json/releases/download/v3.11.2/json.tar.xz"], ) - 编写自定义BUILD文件,传递
-DJSON_BuildTests=OFF -Dnlohmann_json_DIR=@nlohmann_json//参数给CMake,指定使用预下载的依赖。
- 在WORKSPACE中添加nlohmann/json的依赖声明:
内容的提问来源于stack exchange,提问作者ILutRf7
相关产品推荐
相关产品推荐

