paperclipai/paperclip · error
Daytona syncOut refusing tarball member that escapes the…
Error message
Daytona syncOut refusing tarball member that escapes the extraction dir: ${name} What it means
Confinement guard in assertTarballEntriesConfined: a tar member name (after stripping trailing slashes) resolves outside the extraction directory — e.g. an absolute path or '../' traversal. Because the archive comes from the untrusted sandbox, such a member would let `tar -xf` write to arbitrary host paths, so extraction is refused.
Solutions
- Remove path-traversal entries from the tarball; all members must extract inside the target dir.
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at packages/plugins/sandbox-providers/daytona/src/file-sync.ts:258 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of paperclipai/paperclip@3f1d897a7c (2026-08-18).
Data as JSON: /api/errors/638e68a04c6f3169.
Report an issue: GitHub.
Appendix: source
Thrown at packages/plugins/sandbox-providers/daytona/src/file-sync.ts:262
* escapes the tree — the latter would let a follow-up member be written through
* the link to an arbitrary host path. Legitimate in-tree relative links (targets
* that resolve back inside the archive, e.g. `shortcut -> nested/data.txt`) are
* preserved. Parses the `-tvf` verbose listing so both member names and link
* targets are inspected; any unparseable line fails closed.
*/
async function assertTarballEntriesConfined(archivePath: string): Promise<void> {
const { stdout } = await execFileAsync("tar", ["-tvf", archivePath], {
env: { ...process.env, COPYFILE_DISABLE: "1" },
maxBuffer: 32 * 1024 * 1024,
});
const lines = stdout.split("\n").filter((line) => line.trim().length > 0);
for (const line of lines) {
const parsed = parseTarVerboseListingLine(line);
if (!parsed) {
throw new Error(`Daytona syncOut refusing tarball with an unparseable entry listing: ${line}`);
}
const typeFlag = parsed.typeFlag;
let name = parsed.rest;
let linkTarget: string | null = null;
if (typeFlag === "l") {
const split = splitLinkEntryOnce(name, " -> ");
if (!split) throw new Error(`Daytona syncOut refusing unparseable or ambiguous symlink entry: ${line}`);
name = split.name;
linkTarget = split.target;
} else if (typeFlag === "h") {
const split = splitLinkEntryOnce(name, " link to ");
if (!split) throw new Error(`Daytona syncOut refusing unparseable or ambiguous hardlink entry: ${line}`);
name = split.name;
linkTarget = split.target;
}
const cleanName = name.replace(/\/+$/, "");
if (cleanName.length > 0 && posixPathEscapes(cleanName)) {
throw new Error(`Daytona syncOut refusing tarball member that escapes the extraction dir: ${name}`);
}
if (linkTarget !== null) {
const resolved = path.posix.join(path.posix.dirname(cleanName), linkTarget);View on GitHub (pinned to 3f1d897a7c)