{"record":{"id":"2e3984508ee0bf44","repo":"paperclipai/paperclip","slug":"writable-sandbox-path-normalizedextrapath-is","errorCode":null,"errorMessage":"Writable sandbox path \"${normalizedExtraPath}\" is outside synchronized workspace \"${workspaceDir}\" and has no outbound restore mapping.","messagePattern":"Writable sandbox path \"(.+?)\" is outside synchronized workspace \"(.+?)\" and has no outbound restore mapping\\.","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/adapter-utils/src/local-process-sandbox.ts","lineNumber":373,"sourceCode":"  const cwd = normalizeAbsolutePath(input.cwd, \"Sandbox cwd\");\n  if (filesystemScope === \"workspace\") {\n    const relativeCwd = path.relative(workspaceDir, cwd);\n    if (relativeCwd.startsWith(\"..\") || path.isAbsolute(relativeCwd)) {\n      throw new Error(`Sandbox cwd \"${cwd}\" must be inside workspaceDir \"${workspaceDir}\".`);\n    }\n    const outboundRestorePaths = (input.options.outboundRestorePaths ?? []).map((candidate, index) =>\n      normalizeAbsolutePath(candidate, `Sandbox outboundRestorePaths[${index}]`));\n    for (const [index, extraPath] of (input.options.extraPaths ?? []).entries()) {\n      if (extraPath.access !== \"rw\") continue;\n      const normalizedExtraPath = normalizeAbsolutePath(extraPath.path, `Sandbox extraPaths[${index}].path`);\n      const relativeToWorkspace = path.relative(workspaceDir, normalizedExtraPath);\n      const synchronized = !relativeToWorkspace.startsWith(\"..\") && !path.isAbsolute(relativeToWorkspace);\n      const restored = outboundRestorePaths.some((restorePath) => {\n        const relative = path.relative(restorePath, normalizedExtraPath);\n        return !relative.startsWith(\"..\") && !path.isAbsolute(relative);\n      });\n      if (!synchronized && !restored) {\n        throw new Error(\n          `Writable sandbox path \"${normalizedExtraPath}\" is outside synchronized workspace \"${workspaceDir}\" and has no outbound restore mapping.`,\n        );\n      }\n    }\n  }\n\n  const bwrapCommand = input.options.command?.trim() || \"bwrap\";\n  const args = [\"--die-with-parent\", \"--new-session\", \"--unshare-pid\", \"--unshare-ipc\", \"--unshare-uts\"];\n  const env: Record<string, string | undefined> = {};\n  let cleanup: (() => Promise<void>) | undefined;\n  let executable = input.executable;\n  let executableArgs = input.args;\n\n  if (filesystemScope === \"workspace\") {\n    args.push(\"--tmpfs\", \"/\", \"--proc\", \"/proc\", \"--dev\", \"/dev\", \"--tmpfs\", \"/tmp\");\n    args.push(\n      \"--symlink\", \"usr/bin\", \"/bin\",\n      \"--symlink\", \"usr/sbin\", \"/sbin\",","sourceCodeStart":355,"sourceCodeEnd":391,"githubUrl":"https://github.com/paperclipai/paperclip/blob/120ae5428fa29bee300bcf806491cd4d965fbb7c/packages/adapter-utils/src/local-process-sandbox.ts#L355-L391","documentation":"A writable (rw) extraPath lies outside the synchronized workspace and has no outboundRestorePaths mapping, so writes to it would be lost or escape the sandbox contract.","triggerScenarios":"Thrown at packages/adapter-utils/src/local-process-sandbox.ts:373 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Keep writable sandbox paths inside the synchronized workspace, or configure an outbound restore mapping."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"120ae5428fa29bee300bcf806491cd4d965fbb7c","analyzedAt":"2026-08-18T22:49:45.177Z","contentChangedAt":"2026-08-18T22:49:45.177Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}