{"record":{"id":"e71a79fd69525a44","repo":"vectordotdev/vector","slug":"description-must-resolve-below-the-repository-root","errorCode":null,"errorMessage":"{description} must resolve below the repository root: {}","messagePattern":"(.+?) must resolve below the repository root: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"vdev/src/utils/paths.rs","lineNumber":90,"sourceCode":"    let output = repo_root.join(relative);\n    let canonical_root = repo_root.canonicalize().with_context(|| {\n        format!(\n            \"Could not canonicalize repository root {}\",\n            repo_root.display()\n        )\n    })?;\n    let existing_ancestor = output\n        .ancestors()\n        .find(|ancestor| ancestor.exists())\n        .expect(\"repository root must be an existing output ancestor\");\n    let canonical_ancestor = existing_ancestor.canonicalize().with_context(|| {\n        format!(\n            \"Could not canonicalize output ancestor {}\",\n            existing_ancestor.display()\n        )\n    })?;\n    if !canonical_ancestor.starts_with(&canonical_root) {\n        bail!(\n            \"{description} must resolve below the repository root: {}\",\n            path.display()\n        );\n    }\n\n    Ok(output)\n}\n\n/// Find an npm tool installed by `scripts/environment/prepare.sh`.\npub fn npm_tool_path(repo_root: &Path, tool: &str) -> Result<PathBuf> {\n    let path = repo_root\n        .join(\"scripts/environment/npm-tools/node_modules/.bin\")\n        .join(tool);\n    if path.is_file() {\n        return Ok(path);\n    }\n\n    bail!(","sourceCodeStart":72,"sourceCodeEnd":108,"githubUrl":"https://github.com/vectordotdev/vector/blob/0d4ab78a4f0d9c9e5d03a50108a2ae4d2f4b2460/vdev/src/utils/paths.rs#L72-L108","documentation":"Symlink-escape guard in resolve_repo_relative_path: the joined path is canonicalized and checked against the canonical repository root, and this bail fires when the resolved location is not below the root — typically because a symlink inside the tree points outside it, or the path traverses such a link. The {description} identifies the offending user input.","triggerScenarios":"Thrown at vdev/src/utils/paths.rs:89 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Replace the symlink with a real file/directory inside the repository","Point the argument at the actual target location inside the repo rather than through the link","Remove dangling symlinks from the working tree"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"0d4ab78a4f0d9c9e5d03a50108a2ae4d2f4b2460","analyzedAt":"2026-09-16T02:53:35.741Z","contentChangedAt":"2026-09-16T02:53:35.741Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}