{"record":{"id":"9d38630e6db9f49b","repo":"paperclipai/paperclip","slug":"daytona-sync-label-path-is-not-a-confined-absol","errorCode":null,"errorMessage":"Daytona sync ${label} path is not a confined absolute path: ${candidate}","messagePattern":"Daytona sync (.+?) path is not a confined absolute path: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"packages/plugins/sandbox-providers/daytona/src/file-sync.ts","lineNumber":121,"sourceCode":" * path handed to `sandbox.process.executeCommand` (tar extract / `mv -f` rename)\n * MUST pass through this so a path containing shell metacharacters is transferred\n * literally, never interpreted.\n */\nfunction shellQuote(value: string): string {\n  return `'${value.replace(/'/g, `'\"'\"'`)}'`;\n}\n\n/**\n * Convert a POSIX numeric mode (e.g. `0o600`) to the octal string the Daytona\n * SDK's `setFilePermissions` expects (e.g. `\"600\"`), masked to the permission\n * bits so an accidental type flag never widens the mode.\n */\nfunction toOctalModeString(mode: number): string {\n  return (mode & 0o7777).toString(8).padStart(3, \"0\");\n}\n\n/**\n * Host-side complete-mediation guard applied as defense-in-depth below the\n * orchestrator's own confinement. Every sandbox-side path (the sync target for\n * inbound, the sync source for outbound) MUST canonicalize inside the workspace\n * remote dir; absolute escapes and `..` traversal are rejected fail-closed before\n * any bytes move. Sandbox paths on the server are POSIX.\n */\nexport function assertConfinedSandboxPath(remoteDir: string, candidate: string, label: string): void {\n  const normalizedRoot = path.posix.normalize(remoteDir);\n  const normalized = path.posix.normalize(candidate);\n  if (\n    !path.posix.isAbsolute(normalized) ||\n    normalized === \"..\" ||\n    normalized.includes(\"/../\") ||\n    normalized.endsWith(\"/..\")\n  ) {\n    throw new Error(`Daytona sync ${label} path is not a confined absolute path: ${candidate}`);\n  }\n  const prefix = normalizedRoot.endsWith(\"/\") ? normalizedRoot : `${normalizedRoot}/`;\n  if (normalized !== normalizedRoot && !normalized.startsWith(prefix)) {","sourceCodeStart":103,"sourceCodeEnd":139,"githubUrl":"https://github.com/paperclipai/paperclip/blob/3f1d897a7c018d76563a21c6e39c3c9b03933622/packages/plugins/sandbox-providers/daytona/src/file-sync.ts#L103-L139","documentation":"Defense-in-depth confinement guard in assertConfinedSandboxPath: a Daytona file-sync path (sync target for inbound, sync source for outbound) did not canonicalize to a POSIX absolute path inside the workspace remote dir — it was relative, empty, or a bare '..'. The guard fails closed before any bytes move so sync can never address a path outside the sandbox workspace root.","triggerScenarios":"Thrown at packages/plugins/sandbox-providers/daytona/src/file-sync.ts:117 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Use an absolute path confined to the allowed root for the sync path."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"3f1d897a7c018d76563a21c6e39c3c9b03933622","analyzedAt":"2026-08-18T22:49:45.177Z","contentChangedAt":"2026-08-18T22:49:45.177Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}