{"record":{"id":"db2232eb93b38f3a","repo":"paperclipai/paperclip","slug":"sync-operation-label-path-escapes-its-confineme","errorCode":null,"errorMessage":"sync operation ${label} path escapes its confinement root: ${candidate}","messagePattern":"sync operation (.+?) path escapes its confinement root: (.+?)","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/adapter-utils/src/sandbox-managed-runtime.ts","lineNumber":311,"sourceCode":"    .filter(Boolean);\n}\n\n/**\n * Bounded backoff before each retry of a saturated Git scan: none before the\n * first attempt, 1 second before the second, 2 seconds before the third. Three\n * total attempts (the first plus these two retries) is a liveness parameter,\n * not a security control — the retry only ever fires for the scheduler's\n * typed saturation code (see {@link isWorkspaceGitScanSaturatedError}).\n */\nconst REFERENCED_SOURCE_IGNORE_SCAN_RETRY_DELAYS_MS = [1_000, 2_000] as const;\n\nasync function delay(ms: number): Promise<void> {\n  await new Promise<void>((resolve) => setTimeout(resolve, ms));\n}\n\n/**\n * True only when `error` carries the workspace Git scan scheduler's typed\n * saturation code on its `code` property. Matches the code alone, never\n * message text — a message can change wording without changing meaning, and\n * matching text would silently stop retrying (or start retrying the wrong\n * failure) the moment it did.\n */\nfunction isWorkspaceGitScanSaturatedError(error: unknown): boolean {\n  return (\n    typeof error === \"object\" &&\n    error !== null &&\n    \"code\" in error &&\n    (error as { code?: unknown }).code === WORKSPACE_GIT_SCAN_SATURATED_CODE\n  );\n}\n\n/**\n * Resolve a referenced project's Git-ignored paths ONCE, before any staging\n * site runs. Called once per project (see `execute.ts`); the sandbox lane,\n * the SSH lane, and the content-signature walk all consume this one result,\n * so they can never apply a different exclusion set to the same project.","sourceCodeStart":293,"sourceCodeEnd":329,"githubUrl":"https://github.com/paperclipai/paperclip/blob/3f1d897a7c018d76563a21c6e39c3c9b03933622/packages/adapter-utils/src/sandbox-managed-runtime.ts#L293-L329","documentation":"Host-side complete-mediation guard for native sandbox sync: the path canonicalizes fine but resolves outside every allowed orchestrator-owned root (sourceRoots/targetRoots), so the sync would touch files the orchestrator does not own and is rejected before provider handoff.","triggerScenarios":"Thrown at packages/adapter-utils/src/sandbox-managed-runtime.ts:281 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Keep the sync operation path inside its confinement root; remove traversal segments."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"3f1d897a7c018d76563a21c6e39c3c9b03933622","analyzedAt":"2026-08-18T22:49:45.177Z","contentChangedAt":"2026-08-18T22:49:45.177Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}