{"record":{"id":"9106e77d78272f22","repo":"siyuan-note/siyuan","slug":"path-contains-invalid-character-s","errorCode":null,"errorMessage":"path contains invalid character [%s]","messagePattern":"path contains invalid character \\[(.+?)\\]","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"kernel/model/elevator_windows.go","lineNumber":136,"sourceCode":"\tutil.PushMsg(Conf.language(252), 0)\n}\n\nfunc isUsingMicrosoftDefender() bool {\n\tif !gulu.OS.IsWindows() {\n\t\treturn false\n\t}\n\n\tcmd := exec.Command(\"powershell\", \"-Command\", \"Get-MpPreference\")\n\tgulu.CmdAttr(cmd)\n\treturn cmd.Run() == nil\n}\n\n// validateExclusionPath 校验用于添加到 Windows Defender 排除项的路径，\n// 拒绝包含 cmd.exe 或 PowerShell 元字符的路径，防止通过未转义的路径字符串实现命令注入\nfunc validateExclusionPath(path string) error {\n\tfor _, c := range path {\n\t\tif strings.ContainsRune(\"&|<>^%!\\\"'$`\", c) {\n\t\t\treturn fmt.Errorf(\"path contains invalid character [%s]\", string(c))\n\t\t}\n\t}\n\treturn nil\n}\n\nfunc getElevatorBin() string {\n\televator := filepath.Join(util.WorkingDir, \"kernel\", \"elevator.exe\")\n\tif \"dev\" == util.Mode || !gulu.File.IsExist(elevator) {\n\t\televator = filepath.Join(util.WorkingDir, \"elevator\", \"elevator-\"+runtime.GOARCH+\".exe\")\n\t}\n\treturn elevator\n}\n","sourceCodeStart":118,"sourceCodeEnd":149,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/8641553a1f07374001902d3ce773285db1292b2d/kernel/model/elevator_windows.go#L118-L149","documentation":"`validateExclusionPath` rejects a path destined for a Windows Defender exclusion because it contains a character that is a cmd.exe or PowerShell metacharacter (`&|<>^%!\"'$` + backtick). This prevents command injection when the path is passed to an elevated shell command.","triggerScenarios":"Calling AddMicrosoftDefenderExclusion when either the install path (filepath.Dir(util.WorkingDir)) or the user-configured workspace path contains one of the rejected characters.","commonSituations":"Users installing SiYuan into directories like `C:\\apps&tools\\` or under paths with `%VAR%`, `$`, quotes, or carets; unusual but legal Windows folder names.","solutions":["Move/rename the SiYuan install directory or workspace so the path contains no shell metacharacters (letters, digits, spaces, hyphens, underscores only).","Identify the offending character from the error message and rename just that path segment.","Add the Defender exclusion manually via Windows Security settings instead of the in-app flow.","Keep installs under simple paths like C:\\SiYuan or %LOCALAPPDATA%\\SiYuan to avoid recurrence."],"exampleFix":"// before\n// workspace at C:\\tools&apps\\SiYuan -> error: path contains invalid character [&]\n// after\n// move workspace to C:\\toolsapps\\SiYuan (or add exclusion manually in Windows Security)","handlingStrategy":"validation","validationCode":"// Go: pre-check a candidate install/workspace path for shell metacharacters\nfunc safePath(p string) bool {\n    return !strings.ContainsAny(p, \"&|<>^%!\\\"'$`\")\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Install SiYuan and place workspaces in paths without shell metacharacters.","Avoid folder names containing &, %, $, quotes, or carets on Windows.","If a path cannot be renamed, add the Defender exclusion via Windows Security UI."],"tags":["go","windows","security","path-validation"],"backgroundTag":"invalid-argument-value","analyzedSha":"8641553a1f07374001902d3ce773285db1292b2d","analyzedAt":"2026-09-11T16:08:28.414Z","contentChangedAt":"2026-09-11T16:08:28.414Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}