jdx/mise · error
brew-cask: : unsupported glob outside staged_path
Error message
brew-cask:{}: unsupported {kind} {field} glob outside staged_path {} What it means
For permission flight paths whose base is "appdir", glob patterns are not allowed — globs are only meaningful relative to the staged_path, where the cask's extracted content lives. When a cask declares an appdir-based path containing glob characters, this error aborts parsing because matching against the /Applications directory with a wildcard is unsupported.
Solutions
- Change the path to a concrete appdir entry (no glob characters), or switch base back to "staged_path" if a glob is actually needed
- Fix the cask definition in the upstream tap
- Enumerate the specific target paths instead of using a wildcard
Example fix
// before
{ "type": "permissions", "base": "appdir", "path": "*.app" }
// after
{ "type": "permissions", "base": "staged_path", "path": "Foo.app/**" } Defensive patterns
Strategy: validation
Validate before calling
// Reject globs with appdir base before installing
let is_glob = |p: &str| p.contains('*') || p.contains('?') || p.contains('[');
if base == "appdir" && is_glob(path) {
eprintln!("appdir-based permission paths cannot use globs");
} Prevention
- Use globs only with base "staged_path"
- Enumerate concrete appdir entries instead of wildcards
- Review cask stanzas for glob characters when migrating between bases
When it happens
Trigger: parse_permissions_flight_path sees `base == FlightPathBase::AppDir` and `is_flight_glob(path)` is true — e.g. {"base": "appdir", "path": "*.app"}.
Common situations: A tap cask tries to express 'match any app in Applications' via a glob with base appdir; cask authors migrating stanzas from staged_path to appdir without removing glob syntax.
Understand the failure class
Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.
Related errors
- app target is outside an allowed Applications directory
- artifact target has changed
- binary target is not an owned Caskroom symlink
- brew-cask: : cask metadata has no sha256
- brew-cask: : git only_path must name a directory within the…
AI-assisted analysis of jdx/mise@533346cc37 (2026-09-17).
Data as JSON: /api/errors/fe66426986331b33.
Report an issue: GitHub.
Appendix: source
Thrown at src/system/packages/brew/cask/artifacts.rs:1174
"brew-cask:{}: unsupported {kind} {field} base {}",
cask.token,
base
),
None => bail!("brew-cask:{}: unsupported {kind} {field} base", cask.token),
};
let path = object
.get("path")
.and_then(Value::as_str)
.ok_or_else(|| eyre!("brew-cask:{}: unsupported {kind} {field} path", cask.token))?;
if validate_flight_relative_path(path).is_err() {
bail!(
"brew-cask:{}: invalid {kind} {field} path {}",
cask.token,
path
)
}
if base == FlightPathBase::AppDir && is_flight_glob(path) {
bail!(
"brew-cask:{}: unsupported {kind} {field} glob outside staged_path {}",
cask.token,
path
)
}
Ok(FlightPath {
base,
path: path.to_string(),
})
}
pub(super) fn collect_pkg_receipt_ids(value: &Value, pkg_ids: &mut Vec<String>) {
let Some(object) = value.as_object() else {
return;
};
let Some(metadata) = object.get("uninstall") else {
return;
};View on GitHub (pinned to 533346cc37)