{"record":{"id":"94a8ca25962343b1","repo":"vectordotdev/vector","slug":"just-set","errorCode":null,"errorMessage":"just set","messagePattern":"just set","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"info","filePath":"src/sinks/util/path_confinement.rs","lineNumber":335,"sourceCode":"    /// for a symlink; closing that gap requires fd-based traversal\n    /// (`openat`/`cap-std`), which is Phase 1b scope.\n    pub async fn verify_parent(&mut self, parent: &Path) -> Result<PathBuf, ConfineError> {\n        if self.base_canonical.is_none() {\n            tokio_fs::create_dir_all(&self.base_lexical)\n                .await\n                .map_err(|source| ConfineError::BaseIo {\n                    path: self.base_lexical.clone(),\n                    source,\n                })?;\n            let canonical = tokio_fs::canonicalize(&self.base_lexical)\n                .await\n                .map_err(|source| ConfineError::BaseIo {\n                    path: self.base_lexical.clone(),\n                    source,\n                })?;\n            self.base_canonical = Some(canonical);\n        }\n        let base_canonical = self.base_canonical.as_ref().expect(\"just set\");\n\n        let parent_canonical =\n            tokio_fs::canonicalize(parent)\n                .await\n                .map_err(|source| ConfineError::BaseIo {\n                    path: parent.to_path_buf(),\n                    source,\n                })?;\n\n        if !parent_canonical.starts_with(base_canonical) {\n            return Err(ConfineError::SymlinkEscape {\n                parent: parent_canonical,\n                base: base_canonical.clone(),\n            });\n        }\n\n        Ok(parent_canonical)\n    }","sourceCodeStart":317,"sourceCodeEnd":353,"githubUrl":"https://github.com/vectordotdev/vector/blob/bdb87aeaa4c4ff27c0ba643c1c77b21bf2ef4013/src/sinks/util/path_confinement.rs#L317-L353","documentation":"This panic fires in `PathConfiner::verify_parent` when `base_canonical` is `None` despite the code immediately above having canonicalized the base directory and stored it via `self.base_canonical = Some(canonical)`. The expect asserts the cache was just populated, so the unwrap can never see `None`.","triggerScenarios":"Calling `verify_parent` on a confined path check; the panic would require the canonicalization branch to be skipped while `base_canonical` remains unset, which the surrounding control flow prevents.","commonSituations":"Not reachable in normal operation; would only appear from a refactoring bug in the path confinement code.","solutions":["Report as a bug to Vector if observed.","Re-run the affected topology check; transient state issues are not expected here.","Review recent changes to src/sinks/util/path_confinement.rs if using a patched build."],"exampleFix":null,"handlingStrategy":"fallback","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":["No user-side action required; report occurrences as bugs.","Avoid untested patches to path_confinement.rs.","Re-run topology checks after upgrades to confirm state handling."],"tags":["rust","filesystem","path-confinement","panic"],"backgroundTag":"internal-invariant-violation","analyzedSha":"bdb87aeaa4c4ff27c0ba643c1c77b21bf2ef4013","analyzedAt":"2026-09-16T02:53:35.741Z","contentChangedAt":"2026-09-16T02:53:35.741Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}