{"record":{"id":"a0cb49fdf02131ac","repo":"paperclipai/paperclip","slug":"refusing-to-activate-payload-outside-paths-insta","errorCode":null,"errorMessage":"Refusing to activate payload outside ${paths.installsRoot}.","messagePattern":"Refusing to activate payload outside (.+?)\\.","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"cli/src/install-store.ts","lineNumber":250,"sourceCode":"\nexport function writeInstallManifestAtomic(\n  manifest: InstallManifest,\n  paths = resolveInstallStorePaths(),\n): void {\n  ensurePrivateDirectory(paths.cliRoot);\n  const temporaryPath = `${paths.manifestPath}.tmp-${process.pid}-${Date.now()}`;\n  try {\n    fs.writeFileSync(temporaryPath, `${JSON.stringify(manifest, null, 2)}\\n`, { mode: 0o600 });\n    fs.renameSync(temporaryPath, paths.manifestPath);\n  } finally {\n    fs.rmSync(temporaryPath, { force: true });\n  }\n}\n\nfunction assertPayloadPath(payloadPath: string, paths: InstallStorePaths): void {\n  const relative = path.relative(paths.installsRoot, path.resolve(payloadPath));\n  if (!relative || relative.startsWith(\"..\") || path.isAbsolute(relative)) {\n    throw new Error(`Refusing to activate payload outside ${paths.installsRoot}.`);\n  }\n  const stat = fs.lstatSync(payloadPath);\n  if (!stat.isDirectory() || stat.isSymbolicLink()) {\n    throw new Error(`Refusing to activate non-directory payload ${payloadPath}.`);\n  }\n  const installsRealPath = fs.realpathSync(paths.installsRoot);\n  const payloadRealPath = fs.realpathSync(payloadPath);\n  if (!payloadRealPath.startsWith(`${installsRealPath}${path.sep}`)) {\n    throw new Error(`Refusing to activate payload that resolves outside ${paths.installsRoot}.`);\n  }\n}\n\nexport function flipCurrentAtomic(\n  payloadPath: string,\n  paths = resolveInstallStorePaths(),\n  hooks: { beforeRename?: () => void } = {},\n): void {\n  assertPayloadPath(payloadPath, paths);","sourceCodeStart":232,"sourceCodeEnd":268,"githubUrl":"https://github.com/paperclipai/paperclip/blob/01ad8584922b5d85292b1723cae71fa0d9b07a19/cli/src/install-store.ts#L232-L268","documentation":"assertPayloadPath computed path.relative from the installs root to the payload and got an escaping relative path, so activating it would point 'current' outside the store.","triggerScenarios":"Thrown at cli/src/install-store.ts:250 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Activate only payloads located inside ${paths.installsRoot}."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"01ad8584922b5d85292b1723cae71fa0d9b07a19","analyzedAt":"2026-08-18T22:49:45.177Z","contentChangedAt":"2026-08-18T22:49:45.177Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}