Skip to main content

validate_path

Function validate_path 

Source
pub fn validate_path(
    path: &str,
    root: &Path,
    allowlist: Option<&[PathBuf]>,
    blocklist: Option<&[PathBuf]>,
) -> GuardResult
Expand description

Check that path is allowed by the project root, allowlist, and blocklist.

The path is first normalized (./.. resolved). The root is also normalized so both sides are compared on equal footing.

Besides the project root and the explicit allowlist, paths under the harness scratch directory (<OS temp>/cosh, where truncated tool-output logs live) are allowed: the OS temp dir is ephemeral scratch by definition, and blocking it would break the agent’s ability to read its own logs back. The blocklist always takes priority, so even scratch paths can be denied.

Returns Allowed(normalized_path) when the path passes all checks, Denied(reason) when it is blocked, and Mismatch(msg) when the path appears in both the allowlist and blocklist simultaneously.