vectordotdev/vector · info

just set

Error message

just set

What it means

This panic fires in `PathConfiner::verify_parent` when `base_canonical` is `None` despite the code immediately above having canonicalized the base directory and stored it via `self.base_canonical = Some(canonical)`. The expect asserts the cache was just populated, so the unwrap can never see `None`.

Solutions

  1. Report as a bug to Vector if observed.
  2. Re-run the affected topology check; transient state issues are not expected here.
  3. Review recent changes to src/sinks/util/path_confinement.rs if using a patched build.
Defensive patterns

Strategy: fallback

Prevention

When it happens

Trigger: Calling `verify_parent` on a confined path check; the panic would require the canonicalization branch to be skipped while `base_canonical` remains unset, which the surrounding control flow prevents.

Common situations: Not reachable in normal operation; would only appear from a refactoring bug in the path confinement code.

Understand the failure class

Background: "This is a bug, please report it": internal invariant violations, unreachable panics, and SNH errors explained — this error's family across 47 libraries.

Related errors


AI-assisted analysis of vectordotdev/vector@bdb87aeaa4 (2026-09-16). Data as JSON: /api/errors/94a8ca25962343b1. Report an issue: GitHub.

Appendix: source

Thrown at src/sinks/util/path_confinement.rs:335

    /// for a symlink; closing that gap requires fd-based traversal
    /// (`openat`/`cap-std`), which is Phase 1b scope.
    pub async fn verify_parent(&mut self, parent: &Path) -> Result<PathBuf, ConfineError> {
        if self.base_canonical.is_none() {
            tokio_fs::create_dir_all(&self.base_lexical)
                .await
                .map_err(|source| ConfineError::BaseIo {
                    path: self.base_lexical.clone(),
                    source,
                })?;
            let canonical = tokio_fs::canonicalize(&self.base_lexical)
                .await
                .map_err(|source| ConfineError::BaseIo {
                    path: self.base_lexical.clone(),
                    source,
                })?;
            self.base_canonical = Some(canonical);
        }
        let base_canonical = self.base_canonical.as_ref().expect("just set");

        let parent_canonical =
            tokio_fs::canonicalize(parent)
                .await
                .map_err(|source| ConfineError::BaseIo {
                    path: parent.to_path_buf(),
                    source,
                })?;

        if !parent_canonical.starts_with(base_canonical) {
            return Err(ConfineError::SymlinkEscape {
                parent: parent_canonical,
                base: base_canonical.clone(),
            });
        }

        Ok(parent_canonical)
    }

View on GitHub (pinned to bdb87aeaa4)