{"record":{"id":"1df467602b3decf6","repo":"affaan-m/ECC","slug":"label-must-be-a-regular-non-symlink-file","errorCode":null,"errorMessage":"${label} must be a regular, non-symlink file.","messagePattern":"(.+?) must be a regular, non-symlink file\\.","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"scripts/lib/memory-vault.js","lineNumber":156,"sourceCode":"  }\n  return left.dev === right.dev;\n}\n\nfunction readRegularTextFile(filePath, options = {}) {\n  const label = options.label || 'file';\n  const maxBytes = options.maxBytes || MAX_DOCUMENT_BYTES;\n  if (options.trustedRoot) {\n    assertWithinTrustedRoot(filePath, options.trustedRoot, `read ${label}`);\n  }\n\n  const flags = fs.constants.O_RDONLY\n    | (fs.constants.O_NOFOLLOW || 0)\n    | (fs.constants.O_NONBLOCK || 0);\n  const descriptor = fs.openSync(filePath, flags);\n  try {\n    const opened = fs.fstatSync(descriptor, { bigint: true });\n    if (!opened.isFile()) {\n      throw new Error(`${label} must be a regular, non-symlink file.`);\n    }\n    const after = fs.lstatSync(filePath, { bigint: true });\n    if (\n      after.isSymbolicLink()\n      || !after.isFile()\n      || !sameFileIdentity(after, opened)\n    ) {\n      throw new Error(`${label} must remain a regular, non-symlink file while it is opened.`);\n    }\n    if (options.trustedRoot) {\n      assertWithinTrustedRoot(filePath, options.trustedRoot, `read ${label}`);\n    }\n    if (opened.size > BigInt(maxBytes)) {\n      throw new Error(`${label} is too large (${opened.size} bytes).`);\n    }\n\n    const chunks = [];\n    let total = 0;","sourceCodeStart":138,"sourceCodeEnd":174,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/scripts/lib/memory-vault.js#L138-L174","documentation":"readRegularTextFile throws when the opened descriptor is not a regular file (directory, FIFO, device, or symlink target), after opening with O_NOFOLLOW/O_NONBLOCK. It hardens memory-vault reads against special-file abuse; the faulting input is the path in `label`.","triggerScenarios":"Thrown at scripts/lib/memory-vault.js:156 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Point the read at a regular file, not a directory or special file.","Remove/replace symlinks in the memory path with real files.","Check the caller for a wrong path suffix (e.g. passing a directory)."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}