{"record":{"id":"92457c0421c4f111","repo":"paperclipai/paperclip","slug":"provision-stagefile-name-must-be-a-simple-basename","errorCode":null,"errorMessage":"provision stageFile.name must be a simple basename, got: ${safeName}","messagePattern":"provision stageFile\\.name must be a simple basename, got: (.+?)","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/adapter-utils/src/sandbox-managed-runtime.ts","lineNumber":1199,"sourceCode":"      )))\n    : null;\n\n  // Every inbound staging step delegates to the provider through `client.syncIn`:\n  // the orchestrator no longer inlines `writeFile`+`run` or chooses a transport,\n  // and there is no `usesCustomProvision` native-diversion gate. `syncIn` is\n  // ALWAYS present in production — the command-managed client exposes a native\n  // transport (Daytona/Kubernetes `uploadFiles` + provider-executed post-upload\n  // commands) or a byte-identical base64-tar fallback that reproduces the prior\n  // `writeFile`+`run` sequence. Require it explicitly so a misconfigured client\n  // fails loud rather than silently skipping staging. `syncOut` stays optional\n  // (native-only) with a tar fallback on the restore path below.\n  const syncIn = input.client.syncIn;\n  if (typeof syncIn !== \"function\") {\n    throw new Error(\n      \"prepareSandboxManagedRuntime requires a client that exposes syncIn \" +\n        \"(createCommandManagedRuntimeClient provides a native-or-fallback implementation).\",\n    );\n  }\n  const nativeSyncOut = typeof input.client.syncOut === \"function\";\n  let syncOperationSeq = 0;\n  // Opaque, ordered, non-sensitive operation tokens — never a caller/asset id.\n  const nextSyncOperationId = () => `sync-op-${++syncOperationSeq}`;\n\n  // Remote directory of each additional (referenced) project that stages\n  // successfully, keyed by projectId. A project that fails to stage is absent.\n  const additionalSourceDirs: Record<string, string> = {};\n  // Each additional (referenced) project whose staging failed, paired with the\n  // failure message. Per-project failure isolation keeps the run and the other\n  // projects going; this list makes each failure a first-class, reported outcome.\n  const additionalSourceFailures: AdditionalSourceStagingFailure[] = [];\n  // Additional projects stage as plain trees. Drop the heavy build/cache dirs a\n  // reference tree does not need, and `.git` — additional sources never carry\n  // git-history semantics (anchor-only). Each project also drops its OWN\n  // resolved Git-ignored paths (or keeps this fixed set as-is for a non-Git\n  // source) — see `resolveReferencedSourceIgnore` and the per-project merge\n  // below.","sourceCodeStart":1181,"sourceCodeEnd":1217,"githubUrl":"https://github.com/paperclipai/paperclip/blob/3f1d897a7c018d76563a21c6e39c3c9b03933622/packages/adapter-utils/src/sandbox-managed-runtime.ts#L1181-L1217","documentation":"Sandbox provisioning validated a stage file name that is not a simple basename (contains path separators or traversal); staged files must be copied to the sandbox root by name only, so path-shaped names are rejected.","triggerScenarios":"Thrown at packages/adapter-utils/src/sandbox-managed-runtime.ts:983 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Use a simple basename (no path separators) for stageFile.name."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"3f1d897a7c018d76563a21c6e39c3c9b03933622","analyzedAt":"2026-08-21T17:58:32.592Z","contentChangedAt":"2026-08-21T17:58:32.592Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}