{"record":{"id":"99eac738bd3f5179","repo":"paperclipai/paperclip","slug":"sandbox-cwd-cwd-must-be-inside-workspacedir","errorCode":null,"errorMessage":"Sandbox cwd \"${cwd}\" must be inside workspaceDir \"${workspaceDir}\".","messagePattern":"Sandbox cwd \"(.+?)\" must be inside workspaceDir \"(.+?)\"\\.","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/adapter-utils/src/local-process-sandbox.ts","lineNumber":359,"sourceCode":"export async function buildLocalProcessSandboxSpawnTarget(input: {\n  executable: string;\n  args: string[];\n  cwd: string;\n  options: LocalProcessSandboxOptions;\n}): Promise<LocalProcessSandboxSpawnTarget> {\n  if (process.platform !== \"linux\") {\n    throw new Error(\"Local process filesystem and network scopes are currently supported only on Linux.\");\n  }\n  const filesystemScope = input.options.filesystemScope ?? null;\n  const networkScope = input.options.networkScope ?? null;\n  if (!filesystemScope && !networkScope) throw new Error(\"Local process sandbox requires a filesystem or network scope.\");\n\n  const workspaceDir = normalizeAbsolutePath(input.options.workspaceDir, \"Sandbox workspaceDir\");\n  const cwd = normalizeAbsolutePath(input.cwd, \"Sandbox cwd\");\n  if (filesystemScope === \"workspace\") {\n    const relativeCwd = path.relative(workspaceDir, cwd);\n    if (relativeCwd.startsWith(\"..\") || path.isAbsolute(relativeCwd)) {\n      throw new Error(`Sandbox cwd \"${cwd}\" must be inside workspaceDir \"${workspaceDir}\".`);\n    }\n    const outboundRestorePaths = (input.options.outboundRestorePaths ?? []).map((candidate, index) =>\n      normalizeAbsolutePath(candidate, `Sandbox outboundRestorePaths[${index}]`));\n    for (const [index, extraPath] of (input.options.extraPaths ?? []).entries()) {\n      if (extraPath.access !== \"rw\") continue;\n      const normalizedExtraPath = normalizeAbsolutePath(extraPath.path, `Sandbox extraPaths[${index}].path`);\n      const relativeToWorkspace = path.relative(workspaceDir, normalizedExtraPath);\n      const synchronized = !relativeToWorkspace.startsWith(\"..\") && !path.isAbsolute(relativeToWorkspace);\n      const restored = outboundRestorePaths.some((restorePath) => {\n        const relative = path.relative(restorePath, normalizedExtraPath);\n        return !relative.startsWith(\"..\") && !path.isAbsolute(relative);\n      });\n      if (!synchronized && !restored) {\n        throw new Error(\n          `Writable sandbox path \"${normalizedExtraPath}\" is outside synchronized workspace \"${workspaceDir}\" and has no outbound restore mapping.`,\n        );\n      }\n    }","sourceCodeStart":341,"sourceCodeEnd":377,"githubUrl":"https://github.com/paperclipai/paperclip/blob/120ae5428fa29bee300bcf806491cd4d965fbb7c/packages/adapter-utils/src/local-process-sandbox.ts#L341-L377","documentation":"With filesystemScope=workspace, the requested process cwd resolves outside the workspace dir (path.relative escapes), so the sandboxed process would start outside its confined workspace.","triggerScenarios":"Thrown at packages/adapter-utils/src/local-process-sandbox.ts:359 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Set the sandbox cwd to a path inside workspaceDir."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"120ae5428fa29bee300bcf806491cd4d965fbb7c","analyzedAt":"2026-08-18T22:49:45.177Z","contentChangedAt":"2026-08-18T22:49:45.177Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}