vectordotdev/vector · error

must resolve below the repository root

Error message

{description} must resolve below the repository root: {}

What it means

Symlink-escape guard in resolve_repo_relative_path: the joined path is canonicalized and checked against the canonical repository root, and this bail fires when the resolved location is not below the root — typically because a symlink inside the tree points outside it, or the path traverses such a link. The {description} identifies the offending user input.

Solutions

  1. Replace the symlink with a real file/directory inside the repository
  2. Point the argument at the actual target location inside the repo rather than through the link
  3. Remove dangling symlinks from the working tree
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at vdev/src/utils/paths.rs:89 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of vectordotdev/vector@0d4ab78a4f (2026-09-16). Data as JSON: /api/errors/e71a79fd69525a44. Report an issue: GitHub.

Appendix: source

Thrown at vdev/src/utils/paths.rs:90

    let output = repo_root.join(relative);
    let canonical_root = repo_root.canonicalize().with_context(|| {
        format!(
            "Could not canonicalize repository root {}",
            repo_root.display()
        )
    })?;
    let existing_ancestor = output
        .ancestors()
        .find(|ancestor| ancestor.exists())
        .expect("repository root must be an existing output ancestor");
    let canonical_ancestor = existing_ancestor.canonicalize().with_context(|| {
        format!(
            "Could not canonicalize output ancestor {}",
            existing_ancestor.display()
        )
    })?;
    if !canonical_ancestor.starts_with(&canonical_root) {
        bail!(
            "{description} must resolve below the repository root: {}",
            path.display()
        );
    }

    Ok(output)
}

/// Find an npm tool installed by `scripts/environment/prepare.sh`.
pub fn npm_tool_path(repo_root: &Path, tool: &str) -> Result<PathBuf> {
    let path = repo_root
        .join("scripts/environment/npm-tools/node_modules/.bin")
        .join(tool);
    if path.is_file() {
        return Ok(path);
    }

    bail!(

View on GitHub (pinned to 0d4ab78a4f)