fix(storage): harden portable path diagnostics

This commit is contained in:
2026-07-11 21:25:03 +02:00
parent eacb139e22
commit 7f3f6f7ce7
4 changed files with 100 additions and 6 deletions
+5 -1
View File
@@ -39,7 +39,11 @@ def resolve_workspace_paths(
Relative roots are sandboxed to the logical workspace. Absolute roots are a
compatibility bridge for existing installations and are never rewritten.
"""
workspace = (data_root / "workspaces" / config_path.stem).resolve()
canonical_data_root = data_root.resolve()
workspaces_root = canonical_data_root / "workspaces"
workspace = (workspaces_root / config_path.stem).resolve()
if not workspace.is_relative_to(workspaces_root):
raise ConfigError("workspace resolves outside workspaces root")
roots = cfg.roots
return ResolvedPaths(
workspace=workspace,