BigPizzaV3/CodexPlusPlus · error
Reparse paths are unsupported
Error message
Reparse paths are unsupported
What it means
On Windows, plain_path additionally inspects file_attributes for the reparse-point bit (0x400). Beyond symlinks/junctions, other reparse-tag entries (mount points, OneDrive placeholder files, AppExecLink etc.) can change path resolution semantics, so any ancestor with the reparse bit is rejected.
Solutions
- Move the browser runtime/state roots to a plain local NTFS directory with no reparse points in the ancestry
- Disable OneDrive sync/placeholders for the folder or exclude it, then copy the data to a local path
- Check the attribute before configuring: (fs::symlink_metadata(p)?.file_attributes() & 0x400) == 0
- Update the configured path to a non-reparse location (e.g. C:\\codex-browser\\...)
Example fix
// before: root under OneDrive placeholder folder runtime_root = "C:\\Users\\me\\OneDrive\\browser-runtime" // after: plain local folder runtime_root = "C:\\codex-browser\\runtime"
Defensive patterns
Strategy: validation
Validate before calling
#[cfg(windows)]
fn has_reparse_ancestor(p: &Path) -> bool {
use std::os::windows::fs::MetadataExt;
p.ancestors().any(|a| fs::symlink_metadata(a).map(|m| m.file_attributes() & 0x400 != 0).unwrap_or(false))
} Try / catch
match plain_path(p) {
Err(e) if e.to_string().contains("Reparse paths") => {
eprintln!("{} is inside a reparse-point location (OneDrive/mount); relocate to plain NTFS", p.display());
}
other => other?,
} Prevention
- Keep browser roots out of OneDrive/cloud-sync and mounted-volume locations
- Prefer plain local NTFS directories (e.g. under LOCALAPPDATA or a dedicated C:\\ folder)
- Pre-check the reparse bit on all ancestors during setup
When it happens
Trigger: Any plain_path caller traverses an ancestor whose symlink_metadata has FILE_ATTRIBUTE_REPARSE_POINT set — e.g. a runtime root inside an OneDrive-synced folder, Dev Drive mount points, or store-app AppExecLink directories.
Common situations: Configuring the browser root under OneDrive/Documents/Cloud-synced folders; using directories inside mounted VHDs or DFS paths; paths under WindowsApps or other reparse-backed locations.
Understand the failure class
Background: Path traversal blocked: "path escapes the workspace" and "outside site root" errors when a path will not stay inside its allowed directory — this error's family across 26 libraries.
Related errors
- cannot terminate Windows process id
- cannot wait for Windows process id
- failed to open DevTools URL
- failed to wait for Windows process id
- Native browser compatibility is Windows-only
AI-assisted analysis of BigPizzaV3/CodexPlusPlus@b1ed92e5e4 (2026-09-19).
Data as JSON: /api/errors/5379fef8095e4150.
Report an issue: GitHub.
Appendix: source
Thrown at crates/codex-plus-core/src/native_browser.rs:120
}
fn key_valid(key: &str) -> bool {
key.len() == 16 && key.bytes().all(|b| b.is_ascii_hexdigit())
}
// Reject junctions as well as symlinks, including in parent directories.
fn plain_path(path: &Path) -> Result<()> {
ensure!(path.is_absolute(), "Expected an absolute local path");
for ancestor in path.ancestors() {
if let Ok(meta) = fs::symlink_metadata(ancestor) {
ensure!(
!meta.file_type().is_symlink(),
"Linked paths are unsupported"
);
#[cfg(windows)]
{
use std::os::windows::fs::MetadataExt;
ensure!(
meta.file_attributes() & 0x400 == 0,
"Reparse paths are unsupported"
);
}
}
}
ensure!(
!path
.components()
.any(|c| matches!(c, std::path::Component::ParentDir)),
"Parent traversal is unsupported"
);
Ok(())
}
// Deny directory deletion/renaming while a Windows transaction uses its descendants.
// Open root-first with OPEN_REPARSE_POINT so no checked parent can become a junction.
fn pin_parents(path: &Path) -> Result<Vec<File>> {View on GitHub (pinned to b1ed92e5e4)