{"record":{"id":"597fe95c8b704892","repo":"affaan-m/ECC","slug":"refusing-to-trust-managed-install-state-path-er","errorCode":null,"errorMessage":"Refusing to trust managed install-state path: ${error.message}","messagePattern":"Refusing to trust managed install-state path: (.+?)","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"scripts/lib/multi-harness-setup.js","lineNumber":181,"sourceCode":"      + 'recorded root does not match the current install root.'\n    );\n  }\n  if (!pathsMatch(target.installStatePath, plan.installStatePath)) {\n    throw new Error(\n      `Refusing to trust managed install-state at ${plan.installStatePath}: `\n      + 'recorded install-state path does not match the current install-state path.'\n    );\n  }\n}\n\nfunction readOwnedDestinations(plan, dependencies) {\n  if (!plan.installStatePath) {\n    return { destinations: new Set(), stateFingerprint: { exists: false, sha256: null } };\n  }\n  try {\n    assertSafeInstallOperation(plan, { destinationPath: plan.installStatePath });\n  } catch (error) {\n    throw new Error(`Refusing to trust managed install-state path: ${error.message}`);\n  }\n  const initialFingerprint = fingerprintFile(plan.installStatePath);\n  if (!initialFingerprint.exists) {\n    return { destinations: new Set(), stateFingerprint: { exists: false, sha256: null } };\n  }\n  const readState = dependencies.readInstallState || require('./install-state').readInstallState;\n  const state = readState(plan.installStatePath);\n  const validatedFingerprint = fingerprintFile(plan.installStatePath);\n  if (\n    initialFingerprint.exists !== validatedFingerprint.exists\n    || initialFingerprint.sha256 !== validatedFingerprint.sha256\n  ) {\n    throw new Error(\n      `Refusing to trust install-state that changed during validation: ${plan.installStatePath}.`\n    );\n  }\n  assertPriorInstallStateMatchesPlan(state, plan);\n  const plannedByDestination = new Map(plan.operations.map(operation => [","sourceCodeStart":163,"sourceCodeEnd":199,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/scripts/lib/multi-harness-setup.js#L163-L199","documentation":"Before reading an install-state file, readOwnedDestinations runs assertSafeInstallOperation against the state path itself. If that safety check rejects the path (e.g. outside the trusted root, unsafe path shape, or a symlink/traversal risk), the original failure is rethrown wrapped as 'Refusing to trust managed install-state path'. The install-state location itself must be a safe, managed destination before its contents can be trusted.","triggerScenarios":"plan.installStatePath points outside the trusted target root, contains path-traversal segments, resolves through a symlink, or otherwise fails assertSafeInstallOperation; readOwnedDestinations is called via the ownership step of install/update.","commonSituations":"Custom installStatePath configured to a shared/home directory outside the target root; misconfigured adapter; state path pointing at a symlinked dotfile; attacker-influenced or hand-edited plan paths.","solutions":["Inspect the wrapped error.message to see which safety check failed (root containment, traversal, symlink).","Set plan.installStatePath inside plan.targetRoot and remove traversal segments or symlinks from the path.","If the state path was customized, revert to the adapter's default install-state location and re-run the install."],"exampleFix":"// before\nconst plan = buildPlan({ targetRoot: '/repo', installStatePath: '/shared/state.json' });\n// after\nconst plan = buildPlan({ targetRoot: '/repo' }); // state kept inside the trusted root","handlingStrategy":"validation","validationCode":"const resolved = path.resolve(plan.installStatePath);\nif (!resolved.startsWith(path.resolve(plan.targetRoot) + path.sep)) {\n  throw new Error('installStatePath must live inside targetRoot');\n}","typeGuard":"function isSafeStatePath(p, root) {\n  const resolved = path.resolve(p);\n  return resolved.startsWith(path.resolve(root) + path.sep) && !p.includes('..');\n}","tryCatchPattern":"try {\n  readOwnedDestinations(plan, deps);\n} catch (err) {\n  if (String(err.message).startsWith('Refusing to trust managed install-state path:')) {\n    console.error('Fix installStatePath (inside targetRoot, no symlinks/traversal):', err.message);\n  } else throw err;\n}","preventionTips":["Keep installStatePath inside the target root and free of symlinks.","Never accept install-state paths from untrusted input.","Use the adapter's default state path.","Run assertSafeInstallOperation yourself in tests for custom path configurations."],"tags":["install-state","path-safety","validation"],"backgroundTag":"path-traversal-blocked","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}