{"record":{"id":"00bdd8e6f5a6adb0","repo":"paperclipai/paperclip","slug":"networkscope-must-be-deny-or-allowlist","errorCode":null,"errorMessage":"networkScope must be \"deny\" or \"allowlist\".","messagePattern":"networkScope must be \"deny\" or \"allowlist\"\\.","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/adapter-utils/src/local-process-sandbox.ts","lineNumber":154,"sourceCode":"  if (!hostname || hostname === \"*\" || hostname.startsWith(\"*.\")) {\n    throw new Error(`networkAllowlist[${index}] must use an exact hostname; wildcards are not supported.`);\n  }\n  return { hostname, port };\n}\n\nexport function parseLocalProcessNetworkAllowlist(value: unknown): string[] {\n  if (!Array.isArray(value)) return [];\n  return value.map((entry, index) => {\n    if (typeof entry !== \"string\") throw new Error(`networkAllowlist[${index}] must be a string.`);\n    const rule = parseNetworkAllowlistEntry(entry, index);\n    return rule.port ? `${rule.hostname}:${rule.port}` : rule.hostname;\n  });\n}\n\nexport function parseLocalProcessNetworkScope(value: unknown): LocalProcessNetworkScope | null {\n  if (value == null || value === \"\") return null;\n  if (value === \"deny\" || value === \"allowlist\") return value;\n  throw new Error('networkScope must be \"deny\" or \"allowlist\".');\n}\n\nexport function parseLocalProcessFilesystemScope(value: unknown): \"workspace\" | null {\n  if (value == null || value === \"\") return null;\n  if (value === \"workspace\") return value;\n  throw new Error('filesystemScope must be \"workspace\".');\n}\n\nfunction isNetworkTargetAllowed(hostname: string, port: string, rules: NetworkAllowlistRule[]): boolean {\n  const normalizedHostname = hostname.toLowerCase().replace(/^\\[|\\]$/g, \"\");\n  return rules.some((rule) => rule.hostname === normalizedHostname && (rule.port === null || rule.port === port));\n}\n\nfunction assertUnixSocketPathLength(socketPath: string): void {\n  const pathBytes = Buffer.byteLength(socketPath);\n  if (pathBytes > UNIX_SOCKET_PATH_MAX_BYTES) {\n    throw new Error(\n      `Paperclip sandbox proxy socket path is ${pathBytes} bytes, exceeding the Linux limit of ${UNIX_SOCKET_PATH_MAX_BYTES}: ${socketPath}`,","sourceCodeStart":136,"sourceCodeEnd":172,"githubUrl":"https://github.com/paperclipai/paperclip/blob/120ae5428fa29bee300bcf806491cd4d965fbb7c/packages/adapter-utils/src/local-process-sandbox.ts#L136-L172","documentation":"parseLocalProcessNetworkScope only accepts 'deny' or 'allowlist' for the sandbox networkScope config value; anything else (or empty-with-meaning) is rejected by this enum guard.","triggerScenarios":"Thrown at packages/adapter-utils/src/local-process-sandbox.ts:154 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Set networkScope to \"deny\" or \"allowlist\"."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"120ae5428fa29bee300bcf806491cd4d965fbb7c","analyzedAt":"2026-08-18T22:49:45.177Z","contentChangedAt":"2026-08-18T22:49:45.177Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}