Skip to content

fix(core): resolve symlinks for non-existent paths during validation#21486

Closed
Adib234 wants to merge 16 commits intomainfrom
fix/symlink-path-validation
Closed

fix(core): resolve symlinks for non-existent paths during validation#21486
Adib234 wants to merge 16 commits intomainfrom
fix/symlink-path-validation

Conversation

@Adib234
Copy link
Copy Markdown
Contributor

@Adib234 Adib234 commented Mar 6, 2026

Summary

Fixes a path validation bug where attempting to write a new file to a directory that is a symbolic link would fail with a "Path not in workspace" error. fs.realpathSync fails on non-existent paths, which caused it to fall back to an unresolved path that mismatched with the fully resolved project temporary directory during the isSubpath check.

Details

Updates resolveToRealPath in packages/core/src/utils/paths.ts to robustly resolve parent directories recursively if fs.realpathSync throws an ENOENT error. Updates Config.isPathAllowed to use this improved helper. Added unit tests to verify that symlinked parent paths are correctly resolved for non-existent children, and updated storage.test.ts to reflect the fixed resolveToRealPath behavior.

Related Issues

Fixes #1

How to Validate

  1. Run the unit tests: npm test -w @google/gemini-cli-core
  2. Create a symlink to a directory.
  3. Use that symlink as your .gemini directory or temporary project path.
  4. Try to write a new file (e.g. creating a plan). It should now succeed.

Pre-Merge Checklist

  • Updated relevant documentation and README (if needed)
  • Added/updated tests (if needed)
  • Noted breaking changes (if any)
  • Validated on required platforms/methods:
    • MacOS
      • npm run
      • npx
      • Docker
      • Podman
      • Seatbelt
    • Windows
      • npm run
      • npx
      • Docker
    • Linux
      • npm run
      • npx
      • Docker

Adib234 added 16 commits March 5, 2026 23:02
The path validation logic in Config.isPathAllowed failed when attempting
to write a new file to a directory that is a symbolic link. This happened
because fs.realpathSync fails on non-existent paths, falling back to an
unresolved path which then mismatches with the resolved project temporary
directory during the isSubpath check.

This commit updates resolveToRealPath to robustly resolve parent
directories even if the leaf file does not exist, and updates
isPathAllowed to use this improved helper.
@Adib234 Adib234 requested a review from a team as a code owner March 6, 2026 23:31
@gemini-cli
Copy link
Copy Markdown
Contributor

gemini-cli bot commented Mar 6, 2026

Hi @Adib234, thank you so much for your contribution to Gemini CLI! We really appreciate the time and effort you've put into this.

We're making some updates to our contribution process to improve how we track and review changes. Please take a moment to review our recent discussion post: Improving Our Contribution Process & Introducing New Guidelines.

Key Update: Starting January 26, 2026, the Gemini CLI project will require all pull requests to be associated with an existing issue. Any pull requests not linked to an issue by that date will be automatically closed.

Thank you for your understanding and for being a part of our community!

@Adib234 Adib234 self-assigned this Mar 6, 2026
@gemini-code-assist
Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request addresses a critical path validation issue that occurred when attempting to write new files to directories that were symbolic links. Previously, the system would incorrectly report a 'Path not in workspace' error because fs.realpathSync failed on non-existent paths, leading to a mismatch in path resolution. The core change involves enhancing the resolveToRealPath utility to intelligently resolve symlinks for parent directories, even if the final child path does not exist. This ensures that paths within symlinked structures are correctly identified and validated, improving the system's robustness and preventing unexpected file operation failures. Additionally, minor UI adjustments were made to allow certain questions to utilize more vertical screen space.

Highlights

  • Path Validation Fix: Resolved a bug where path validation failed for non-existent files within symlinked directories, preventing 'Path not in workspace' errors.
  • Improved Symlink Resolution: Enhanced the resolveToRealPath utility to robustly handle symbolic links, recursively resolving parent directories even when the target path does not yet exist.
  • Configuration Update: Updated the Config.isPathAllowed method to leverage the improved resolveToRealPath for more accurate path validation.
  • UI Question Height Adjustment: Introduced an unconstrainedHeight option for UI questions, allowing them to consume more vertical space when needed.
  • Test Coverage: Added new unit tests to verify the correct behavior of symlink resolution for non-existent child paths and updated existing storage tests to reflect the fixed path resolution.
Changelog
  • packages/cli/src/ui/components/AskUserDialog.tsx
    • Adjusted question height calculation logic in ChoiceQuestionView to support the new unconstrainedHeight property.
  • packages/cli/src/ui/components/ExitPlanModeDialog.tsx
    • Set unconstrainedHeight: true for the feedback question in ExitPlanModeDialog.
  • packages/cli/src/ui/components/ToolConfirmationQueue.test.tsx
    • Updated comments in the test file to reflect the revised question height allocation logic.
  • packages/core/src/config/config.ts
    • Removed the os module import as it is no longer directly used in this file.
    • Modified isPathAllowed to utilize the new resolveToRealPath function for consistent and robust path resolution.
  • packages/core/src/config/storage.test.ts
    • Imported resolveToRealPath to update expected error messages, ensuring they reflect the resolved paths correctly.
  • packages/core/src/confirmation-bus/types.ts
    • Added an optional unconstrainedHeight boolean property to the Question interface.
  • packages/core/src/utils/paths.test.ts
    • Added a new test case to resolveToRealPath to verify its ability to recursively resolve symlinks for non-existent child paths.
  • packages/core/src/utils/paths.ts
    • Refactored resolveToRealPath to delegate to a new robustRealpath helper function.
    • Implemented robustRealpath to recursively resolve parent directories when fs.realpathSync encounters an ENOENT error, ensuring correct symlink resolution for non-existent paths.
Activity
  • Added/updated tests to cover the new symlink resolution logic.
  • Validated changes on MacOS.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

@Adib234 Adib234 closed this Mar 6, 2026
Copy link
Copy Markdown
Contributor

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request correctly fixes a bug in path validation by recursively resolving symbolic links for non-existent paths, which prevents 'Path not in workspace' errors. The implementation in robustRealpath is sound and the associated tests are well-written.

However, this pull request also includes an unrelated UI feature for unconstrainedHeight in dialogs. This change, while functional, is not mentioned in the pull request description and mixes concerns. The repository's development conventions state that pull requests should be small and focused. Bundling unrelated changes makes the pull request harder to review and track. In the future, please submit separate pull requests for distinct features or fixes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant