{"record":{"id":"50c9f1f02424a622","repo":"paperclipai/paperclip","slug":"post-upload-command-cwd-is-not-a-confined-absolute","errorCode":null,"errorMessage":"post-upload command cwd is not a confined absolute POSIX path: ${raw}","messagePattern":"post-upload command cwd is not a confined absolute POSIX path: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"packages/adapter-utils/src/command-managed-runtime.ts","lineNumber":238,"sourceCode":"  await client.remove(remotePath).catch(() => undefined);\n}\n\n/**\n * Host-side confinement guard for a sync operation's post-upload command `cwd`\n * (Security Condition C2). Runs BEFORE any handoff — native delegation OR the\n * generic fallback — so an out-of-root `cwd` is rejected fail-closed before a\n * provider ever sees it. `cwd` (when present) MUST be an absolute POSIX path with\n * no `..` segment, confined to (equal to or under) one of the operation's own\n * file-mapping target paths. Commands with no `cwd` are unconstrained here and\n * default to the runtime's stable command cwd at exec time.\n */\nexport function assertPostUploadCommandsConfined(operations: readonly SandboxSyncOperation[]): void {\n  for (const operation of operations) {\n    const commands = operation.postUploadCommands ?? [];\n    if (commands.length === 0) continue;\n    const targetRoots = operation.files.map((mapping) => path.posix.normalize(mapping.targetPath));\n    for (const command of commands) {\n      if (command.cwd == null) continue;\n      const raw = command.cwd;\n      if (!path.posix.isAbsolute(raw) || raw.split(\"/\").includes(\"..\")) {\n        throw new Error(`post-upload command cwd is not a confined absolute POSIX path: ${raw}`);\n      }\n      const normalized = path.posix.normalize(raw);\n      const within = targetRoots.some(\n        (root) => normalized === root || normalized.startsWith(`${root}/`),\n      );\n      if (!within) {\n        throw new Error(`post-upload command cwd escapes the operation's target root: ${raw}`);\n      }\n    }\n  }\n}\n\nexport function createCommandManagedRuntimeClient(input: {\n  runner: CommandManagedRuntimeRunner;\n  commandCwd: string;","sourceCodeStart":220,"sourceCodeEnd":256,"githubUrl":"https://github.com/paperclipai/paperclip/blob/3f1d897a7c018d76563a21c6e39c3c9b03933622/packages/adapter-utils/src/command-managed-runtime.ts#L220-L256","documentation":"Host-side confinement guard (Security Condition C2) checked before any sandbox handoff: a sync operation's post-upload command `cwd` is either not an absolute POSIX path or contains a '..' segment, so it is rejected fail-closed before a provider ever executes it.","triggerScenarios":"Thrown at packages/adapter-utils/src/command-managed-runtime.ts:187 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Use a confined absolute POSIX path (under the operation's target root) for the post-upload command cwd."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"3f1d897a7c018d76563a21c6e39c3c9b03933622","analyzedAt":"2026-08-18T22:49:45.177Z","contentChangedAt":"2026-08-18T22:49:45.177Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}