{"record":{"id":"b7bd28e972ec3dc7","repo":"paperclipai/paperclip","slug":"sandbox-path-alias-aliaspath-must-target-the","errorCode":null,"errorMessage":"Sandbox path alias \"${aliasPath}\" must target the synchronized workspace \"${workspaceDir}\".","messagePattern":"Sandbox path alias \"(.+?)\" must target the synchronized workspace \"(.+?)\"\\.","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/adapter-utils/src/local-process-sandbox.ts","lineNumber":418,"sourceCode":"      addParentDirectories(args, created, normalized);\n      args.push(access === \"rw\" ? \"--bind\" : \"--ro-bind\", normalized, normalized);\n      mounted.add(normalized);\n      created.add(normalized);\n    };\n    for (const systemPath of SYSTEM_READ_PATHS) await mount(systemPath, \"ro\");\n    for (const executablePath of await executableReadPaths(input.executable)) await mount(executablePath, \"ro\");\n    if (networkScope === \"allowlist\") {\n      for (const nodePath of await executableReadPaths(process.execPath)) await mount(nodePath, \"ro\");\n    }\n    for (const managedPath of input.options.managedPaths ?? []) await mount(managedPath.path, managedPath.access);\n    for (const extraPath of input.options.extraPaths ?? []) await mount(extraPath.path, extraPath.access);\n    await mount(workspaceDir, \"rw\");\n    for (const [index, alias] of (input.options.pathAliases ?? []).entries()) {\n      const aliasPath = normalizeAbsolutePath(alias.path, `Sandbox pathAliases[${index}].path`);\n      const aliasTarget = normalizeAbsolutePath(alias.target, `Sandbox pathAliases[${index}].target`);\n      const relativeTarget = path.relative(workspaceDir, aliasTarget);\n      if (relativeTarget.startsWith(\"..\") || path.isAbsolute(relativeTarget)) {\n        throw new Error(\n          `Sandbox path alias \"${aliasPath}\" must target the synchronized workspace \"${workspaceDir}\".`,\n        );\n      }\n      if (!(await pathExists(aliasTarget))) {\n        throw new Error(`Sandbox path alias target \"${aliasTarget}\" does not exist.`);\n      }\n      addParentDirectories(args, created, aliasPath);\n      args.push(\"--bind\", aliasTarget, aliasPath);\n      created.add(aliasPath);\n    }\n\n    if (networkScope === \"allowlist\") {\n      const tempDir = await createNetworkProxyTempDir();\n      const socketPath = path.join(tempDir, \"proxy.sock\");\n      const bridgePath = path.join(tempDir, \"bridge.cjs\");\n      await fs.writeFile(bridgePath, await createNetworkProxyBridge(), { mode: 0o500 });\n      const proxy = await startNetworkAllowlistProxy(\n        input.options.networkAllowlist ?? [],","sourceCodeStart":400,"sourceCodeEnd":436,"githubUrl":"https://github.com/paperclipai/paperclip/blob/120ae5428fa29bee300bcf806491cd4d965fbb7c/packages/adapter-utils/src/local-process-sandbox.ts#L400-L436","documentation":"A sandbox path alias does not resolve to the synchronized workspace directory, so aliasing it would bind something other than the managed workspace into the sandbox.","triggerScenarios":"Thrown at packages/adapter-utils/src/local-process-sandbox.ts:418 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Point the path alias at the synchronized workspace \"${workspaceDir}\"."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"120ae5428fa29bee300bcf806491cd4d965fbb7c","analyzedAt":"2026-08-18T22:49:45.177Z","contentChangedAt":"2026-08-18T22:49:45.177Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}