paperclipai/paperclip · error · Error

Refusing to remove unsafe install-store path

Error message

Refusing to remove unsafe install-store path ${paths.cliRoot}.

What it means

assertManagedInstallStore lstat'ed the install-store root before removal and found it is not a plain directory (symlink or other); the guard refuses unsafe rm targets.

Solutions

  1. Do not remove unsafe paths; verify ${paths.cliRoot} is a genuine install store first.
  2. Choose a different, verified install-store path to remove.
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at cli/src/install-store.ts:119 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of paperclipai/paperclip@01ad858492 (2026-08-18). Data as JSON: /api/errors/6138b0623f9e0fe0. Report an issue: GitHub.

Appendix: source

Thrown at cli/src/install-store.ts:119

  } catch (error) {
    if ((error as NodeJS.ErrnoException).code !== "ENOENT") throw error;
    try {
      fs.writeFileSync(paths.markerPath, MANAGED_STORE_MARKER, { mode: 0o600, flag: "wx" });
    } catch (writeError) {
      if (
        (writeError as NodeJS.ErrnoException).code !== "EEXIST" ||
        fs.readFileSync(paths.markerPath, "utf8") !== MANAGED_STORE_MARKER
      ) {
        throw writeError;
      }
    }
  }
}

export function assertManagedInstallStore(paths = resolveInstallStorePaths()): InstallManifest {
  const cliStat = fs.lstatSync(paths.cliRoot);
  if (!cliStat.isDirectory() || cliStat.isSymbolicLink()) {
    throw new Error(`Refusing to remove unsafe install-store path ${paths.cliRoot}.`);
  }
  assertOwnedByCurrentUser(cliStat, paths.cliRoot);
  let markerStat: fs.Stats;
  try {
    markerStat = fs.lstatSync(paths.markerPath);
  } catch (error) {
    if ((error as NodeJS.ErrnoException).code === "ENOENT") {
      throw new Error(`Refusing to remove unverified install store ${paths.cliRoot}.`);
    }
    throw error;
  }
  if (!markerStat.isFile() || markerStat.isSymbolicLink() || markerStat.nlink > 1) {
    throw new Error(`Refusing to remove unverified install store ${paths.cliRoot}.`);
  }
  assertOwnedByCurrentUser(markerStat, paths.markerPath);
  if (fs.readFileSync(paths.markerPath, "utf8") !== MANAGED_STORE_MARKER) {
    throw new Error(`Refusing to remove unverified install store ${paths.cliRoot}.`);
  }

View on GitHub (pinned to 01ad858492)