{"record":{"id":"be9cb652d0896c1a","repo":"affaan-m/ECC","slug":"path-path-targets-a-system-directory","errorCode":null,"errorMessage":"Path '{path}' targets a system directory","messagePattern":"Path '(.+?)' targets a system directory","errorType":"validation","errorClass":"ValueError","httpStatus":null,"severity":"error","filePath":"skills/continuous-learning-v2/scripts/instinct-cli.py","lineNumber":168,"sourceCode":"    \"\"\"Validate and resolve a file path, guarding against path traversal.\n\n    Raises ValueError if the path is invalid or suspicious.\n    \"\"\"\n    path = Path(path_str).expanduser().resolve()\n\n    # Block paths that escape into system directories\n    # We block specific system paths but allow temp dirs (/var/folders on macOS)\n    blocked_prefixes = [\n        \"/etc\", \"/usr\", \"/bin\", \"/sbin\", \"/proc\", \"/sys\",\n        \"/var/log\", \"/var/run\", \"/var/lib\", \"/var/spool\",\n        # macOS resolves /etc → /private/etc\n        \"/private/etc\",\n        \"/private/var/log\", \"/private/var/run\", \"/private/var/db\",\n    ]\n    path_s = str(path)\n    for prefix in blocked_prefixes:\n        if path_s.startswith(prefix + \"/\") or path_s == prefix:\n            raise ValueError(f\"Path '{path}' targets a system directory\")\n\n    if must_exist and not path.exists():\n        raise ValueError(f\"Path does not exist: {path}\")\n\n    return path\n\n\ndef _validate_instinct_id(instinct_id: str) -> bool:\n    \"\"\"Validate instinct IDs before using them in filenames.\"\"\"\n    if not instinct_id or len(instinct_id) > 128:\n        return False\n    if \"/\" in instinct_id or \"\\\\\" in instinct_id:\n        return False\n    if \"..\" in instinct_id:\n        return False\n    if instinct_id.startswith(\".\"):\n        return False\n    return bool(re.match(r\"^[A-Za-z0-9][A-Za-z0-9._-]*$\", instinct_id))","sourceCodeStart":150,"sourceCodeEnd":186,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/skills/continuous-learning-v2/scripts/instinct-cli.py#L150-L186","documentation":"Raised by _validate_file_path in skills/continuous-learning-v2/scripts/instinct-cli.py when a user-supplied path string starts with (or equals) one of the blocked system prefixes such as /etc, /var/log, /private/etc. The CLI refuses file-path arguments that target protected OS directories to prevent instinct import/export from reading or clobbering system files. It is a prefix-based blocklist check performed before any filesystem access.","triggerScenarios":"Running import/export commands with --file or path arguments equal to or under blocked prefixes like /etc, /etc/passwd, /var/log, /usr, /private/var/db (macOS private paths also blocked).","commonSituations":"User typo meaning to pass a relative path but typed an absolute system path; scripted automation resolving config into /etc; attempting to export instincts into /usr/local/bin deliberately.","solutions":["Pass a path outside the blocked prefixes — use a project or user directory (e.g. ~/.config/ecc-instincts/...).","Check the path with a prefix check (path == prefix or path.startswith(prefix + '/')) before invoking the command.","If exporting, choose an output file in the working directory instead of a system location.","For genuinely intended system integration, install via a package manager rather than writing through this CLI."],"exampleFix":"# before\npython instinct-cli.py export --file /etc/instincts.yaml\n# after\npython instinct-cli.py export --file ~/.config/ecc-instincts/instincts.yaml","handlingStrategy":"validation","validationCode":"blocked = [\"/etc\", \"/var\", \"/usr\", \"/private/etc\", \"/private/var\", \"/private/usr\"]\np = str(path)\nif any(p == b or p.startswith(b + \"/\") for b in blocked):\n    raise ValueError(f\"system path not allowed: {p}\")","typeGuard":null,"tryCatchPattern":"try:\n    cli_import(file=path)\nexcept ValueError as e:\n    if \"system directory\" in str(e):\n        print(\"choose a path outside /etc, /var, /usr\")","preventionTips":["Use project-relative or ~/.config paths for instinct files","Prefix-check absolute paths against the blocklist before invoking","Never point CLI file arguments at OS directories","Validate user-supplied paths at the boundary before passing to the CLI"],"tags":["python","security","path-validation","cli"],"backgroundTag":"path-traversal-blocked","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}