vectordotdev/vector · info
just set
Error message
just set
What it means
This panic fires in `PathConfiner::verify_parent` when `base_canonical` is `None` despite the code immediately above having canonicalized the base directory and stored it via `self.base_canonical = Some(canonical)`. The expect asserts the cache was just populated, so the unwrap can never see `None`.
Solutions
- Report as a bug to Vector if observed.
- Re-run the affected topology check; transient state issues are not expected here.
- Review recent changes to src/sinks/util/path_confinement.rs if using a patched build.
Defensive patterns
Strategy: fallback
Prevention
- No user-side action required; report occurrences as bugs.
- Avoid untested patches to path_confinement.rs.
- Re-run topology checks after upgrades to confirm state handling.
When it happens
Trigger: Calling `verify_parent` on a confined path check; the panic would require the canonicalization branch to be skipped while `base_canonical` remains unset, which the surrounding control flow prevents.
Common situations: Not reachable in normal operation; would only appear from a refactoring bug in the path confinement code.
Understand the failure class
Background: "This is a bug, please report it": internal invariant violations, unreachable panics, and SNH errors explained — this error's family across 47 libraries.
Related errors
- Failed to bind to listener socket at path
- Failed to create output dir
- Failed to create output dir(s)
- Failed to get entry for dir
- Failed to get extension for
AI-assisted analysis of vectordotdev/vector@bdb87aeaa4 (2026-09-16).
Data as JSON: /api/errors/94a8ca25962343b1.
Report an issue: GitHub.
Appendix: source
Thrown at src/sinks/util/path_confinement.rs:335
/// for a symlink; closing that gap requires fd-based traversal
/// (`openat`/`cap-std`), which is Phase 1b scope.
pub async fn verify_parent(&mut self, parent: &Path) -> Result<PathBuf, ConfineError> {
if self.base_canonical.is_none() {
tokio_fs::create_dir_all(&self.base_lexical)
.await
.map_err(|source| ConfineError::BaseIo {
path: self.base_lexical.clone(),
source,
})?;
let canonical = tokio_fs::canonicalize(&self.base_lexical)
.await
.map_err(|source| ConfineError::BaseIo {
path: self.base_lexical.clone(),
source,
})?;
self.base_canonical = Some(canonical);
}
let base_canonical = self.base_canonical.as_ref().expect("just set");
let parent_canonical =
tokio_fs::canonicalize(parent)
.await
.map_err(|source| ConfineError::BaseIo {
path: parent.to_path_buf(),
source,
})?;
if !parent_canonical.starts_with(base_canonical) {
return Err(ConfineError::SymlinkEscape {
parent: parent_canonical,
base: base_canonical.clone(),
});
}
Ok(parent_canonical)
}View on GitHub (pinned to bdb87aeaa4)