{"record":{"id":"3ca28f2688881cd7","repo":"paperclipai/paperclip","slug":"post-upload-command-cwd-escapes-the-operation-s-ta","errorCode":null,"errorMessage":"post-upload command cwd escapes the operation's target root: ${raw}","messagePattern":"post-upload command cwd escapes the operation's target root: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"packages/adapter-utils/src/command-managed-runtime.ts","lineNumber":245,"sourceCode":" * provider ever sees it. `cwd` (when present) MUST be an absolute POSIX path with\n * no `..` segment, confined to (equal to or under) one of the operation's own\n * file-mapping target paths. Commands with no `cwd` are unconstrained here and\n * default to the runtime's stable command cwd at exec time.\n */\nexport function assertPostUploadCommandsConfined(operations: readonly SandboxSyncOperation[]): void {\n  for (const operation of operations) {\n    const commands = operation.postUploadCommands ?? [];\n    if (commands.length === 0) continue;\n    const targetRoots = operation.files.map((mapping) => path.posix.normalize(mapping.targetPath));\n    for (const command of commands) {\n      if (command.cwd == null) continue;\n      const raw = command.cwd;\n      if (!path.posix.isAbsolute(raw) || raw.split(\"/\").includes(\"..\")) {\n        throw new Error(`post-upload command cwd is not a confined absolute POSIX path: ${raw}`);\n      }\n      const normalized = path.posix.normalize(raw);\n      const within = targetRoots.some(\n        (root) => normalized === root || normalized.startsWith(`${root}/`),\n      );\n      if (!within) {\n        throw new Error(`post-upload command cwd escapes the operation's target root: ${raw}`);\n      }\n    }\n  }\n}\n\nexport function createCommandManagedRuntimeClient(input: {\n  runner: CommandManagedRuntimeRunner;\n  commandCwd: string;\n  timeoutMs: number;\n  shellCommand?: \"bash\" | \"sh\" | null;\n}): SandboxManagedRuntimeClient {\n  const shellCommand = preferredShellForSandbox(input.shellCommand);\n  const runShell = async (\n    script: string,\n    opts: {","sourceCodeStart":227,"sourceCodeEnd":263,"githubUrl":"https://github.com/paperclipai/paperclip/blob/3f1d897a7c018d76563a21c6e39c3c9b03933622/packages/adapter-utils/src/command-managed-runtime.ts#L227-L263","documentation":"Confinement guard (Security Condition C2): the post-upload command `cwd`, while absolute and traversal-free, does not lie within any of the operation's own file-mapping target paths, so it would run outside the synced root and is rejected before handoff.","triggerScenarios":"Thrown at packages/adapter-utils/src/command-managed-runtime.ts:194 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Set the post-upload command cwd to a path inside the operation's target root."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"3f1d897a7c018d76563a21c6e39c3c9b03933622","analyzedAt":"2026-08-18T22:49:45.177Z","contentChangedAt":"2026-08-18T22:49:45.177Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}