{"record":{"id":"f28db4c612a1a11a","repo":"abhigyanpatwari/GitNexus","slug":"storage-path-must-not-be-a-filesystem-root","errorCode":null,"errorMessage":"Storage path must not be a filesystem root.","messagePattern":"Storage path must not be a filesystem root\\.","errorType":"validation","errorClass":"InvalidStoragePathError","httpStatus":null,"severity":"critical","filePath":"gitnexus/src/storage/storage-resolver.ts","lineNumber":254,"sourceCode":"  const canonical = canonicalRepoPath(repoPath);\n  const identity = process.platform === 'win32' ? canonical.toLowerCase() : canonical;\n  const basename = sanitizeSlotBasename(path.basename(canonical));\n  const digest = createHash('sha256')\n    .update(identity)\n    .digest('hex')\n    .slice(0, STORAGE_SLOT_HASH_LENGTH);\n  return `${basename}-${digest}`;\n};\n\nexport const defaultStoragePath = (repoPath: string): string =>\n  path.join(resolveRepoPath(repoPath), GITNEXUS_DIR);\n\nexport const validateConfiguredStoragePath = (value: string): string => {\n  const resolved = validateAbsolutePath(value, 'Storage path');\n  const parent = path.dirname(resolved);\n  const base = path.basename(resolved);\n  if (base.length === 0) {\n    throw new InvalidStoragePathError('Storage path must not be a filesystem root.');\n  }\n  // Rebuild through parent + basename and apply the path.relative idiom\n  // CodeQL's js/path-injection sanitizer recognizes. The reconstructed path\n  // is what callers pass to filesystem APIs.\n  const inspected = path.resolve(parent, base);\n  const rel = path.relative(parent, inspected);\n  if (rel.startsWith('..') || path.isAbsolute(rel)) {\n    throw new InvalidStoragePathError('Storage path escaped its parent directory.');\n  }\n  return inspected;\n};\n\n/** Resolve one repository's isolated slot under an external storage root. */\nexport const storagePathFromRoot = (rootPath: string, repoPath: string): string => {\n  const root = validateAbsolutePath(rootPath, STORAGE_ROOT_ENV);\n  const storagePath = path.resolve(root, storageSlotName(repoPath));\n  const rel = path.relative(root, storagePath);\n  if (","sourceCodeStart":236,"sourceCodeEnd":272,"githubUrl":"https://github.com/abhigyanpatwari/GitNexus/blob/ac9a4e9abd8fd3058c070b72c23402a4f887929a/gitnexus/src/storage/storage-resolver.ts#L236-L272","documentation":"validateConfiguredStoragePath rejects a storage path whose basename is empty after validation, i.e. a filesystem root like '/' or 'C:\\'. GitNexus storage must live in a named directory slot; pointing storage at a root would make deletion/ownership logic operate on the entire volume, so it fails closed.","triggerScenarios":"Setting GITNEXUS_STORAGE_PATH or GITNEXUS_STORAGE_ROOT to '/' (or a drive root), or a value like '/data/repos/' that normalizes so basename is empty; calling configuredStoragePath/registeredStoragePath/resolved/resolvedStoragePath with such a value.","commonSituations":"Env var placeholder left as '/'; config template with trailing-slash root value; someone attempting to use a mounted volume root as the storage root.","solutions":["Point storage at a dedicated subdirectory, e.g. /var/lib/gitnexus-storage instead of /.","Strip trailing slashes and ensure a real directory name is present in the configured value.","Validate config at startup and fail with a friendly message before invoking storage APIs."],"exampleFix":"// before\nexport GITNEXUS_STORAGE_PATH=/\n// after\nexport GITNEXUS_STORAGE_PATH=/var/lib/gitnexus-storage","handlingStrategy":"validation","validationCode":"const resolvedValue = path.resolve(value);\nif (path.basename(resolvedValue).length === 0) {\n  throw new Error('storage path must be a named directory, not a filesystem root');\n}","typeGuard":"const isNamedDirPath = (v: string): boolean => path.basename(path.resolve(v)).length > 0;","tryCatchPattern":"try {\n  const p = configuredStoragePath(value);\n} catch (e) {\n  if (e instanceof InvalidStoragePathError && e.message.includes('root')) {\n    throw new Error('GITNEXUS_STORAGE_PATH points at a filesystem root; use a dedicated subdirectory');\n  }\n  throw e;\n}","preventionTips":["Never configure '/' or a drive root as storage; always use a dedicated directory.","Trim trailing separators and verify basename is non-empty when building config.","Fail fast at startup with a clear message pointing at the offending env var."],"tags":["storage","filesystem-root","safety"],"backgroundTag":"invalid-config-value","analyzedSha":"ac9a4e9abd8fd3058c070b72c23402a4f887929a","analyzedAt":"2026-09-15T23:29:44.066Z","contentChangedAt":"2026-09-15T23:29:44.066Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}