( cwd: string, inputPath: string, label: string, scope: WorkspacePathScope, )
| 391 | } |
| 392 | |
| 393 | async function resolveExistingPathInScope( |
| 394 | cwd: string, |
| 395 | inputPath: string, |
| 396 | label: string, |
| 397 | scope: WorkspacePathScope, |
| 398 | ): Promise<string> { |
| 399 | const { root, path: candidate } = await canonicalPathInScope(cwd, inputPath, label, scope); |
| 400 | if (scope === 'host') return await fs.realpath(candidate); |
| 401 | // The read/search callers depend on the target existing; surface that here |
| 402 | // rather than as a downstream open/spawn failure. |
| 403 | // |
| 404 | // Do not drop the second assertion: it closes the window between the two |
| 405 | // awaits, where a segment that was missing during canonicalisation can become |
| 406 | // a symlink out of the cwd before the realpath runs. It is deliberately |
| 407 | // defence-in-depth and no deterministic test can drive that race, so nothing |
| 408 | // will fail if it is removed. |
| 409 | return assertInsideCwd(root, await fs.realpath(candidate), inputPath, label); |
| 410 | } |
| 411 | |
| 412 | async function resolveDirectoryEntryPathInScope( |
| 413 | cwd: string, |
no test coverage detected