# Path Guards और Symlinks — AI Coding-Agent Guardrails

Source: https://www.geekswithgeeks.com/hi/coding-agent-guardrails/fs-path-guard

> File tools को project folder के भीतर रखें और ../ व symlink से निकलने की चालें विफल करें।

## तुलना से पहले resolve करें

File tool को सिर्फ़ project के भीतर के paths छूने चाहिए। यह जाँचना कि path का **string** project folder से शुरू होता है काफ़ी नहीं: `../outside.txt` और project के भीतर का **symlink** जो कहीं और जाता है, दोनों बाहर निकल जाते हैं। उपाय है पहले असली path **resolve** करना (`..` हटाना और links का पीछा करना) और फिर जाँचना कि वह root के भीतर है।

## दीवारों वाला कमरा

Agent को ऐसी जगह रखें जहाँ बुरा command भी सिर्फ़ वहीं पहुँचे जो आपने उपलब्ध कराया।

![तीन दीवारें: files, process, network।](assets/figures/coding-agent-guardrails/section-3-map.svg) — चित्र 3.1 — Files, process और network।

## सरल बनाम resolved, चलाकर

मैंने यह असली symlink वाली अस्थायी directory में चलाया। सरल string जाँच तीनों paths allow करती है; resolved जाँच `..` वाला path और symlink दोनों रोकती है।

```python
import os, tempfile
from pathlib import Path

root = Path(tempfile.mkdtemp()).resolve()
work = root / "work"; work.mkdir()
(root / "outside.txt").write_text("secret")
(work / "ok.txt").write_text("hi")
os.symlink(root / "outside.txt", work / "link.txt")

def naive_path(p): return str(work / p).startswith(str(work))
def safe_path(p):
    r = (work / p).resolve()
    return r == work or work in r.parents

for p in ("ok.txt", "../outside.txt", "link.txt"):
    print(p, "naive:", naive_path(p), "safe:", safe_path(p))
```

Output:

```
ok.txt naive: True safe: True
../outside.txt naive: True safe: False
link.txt naive: True safe: False
```

## उपयोग के समय जाँचें

Check और उपयोग के बीच path बदल सकता है ("time-of-check to time-of-use" race), जैसे फ़ाइल की जगह symlink आ जाना। जाँच को फ़ाइल कर्म के जितना हो सके क़रीब करें, और असली सीमा के रूप में sandbox पर भरोसा रखें।

**Quiz:** "Path string project folder से शुरू होता है" असुरक्षित जाँच क्यों है?

- [ ] Folders के नाम नहीं हो सकते
- [ ] Strings की तुलना नहीं हो सकती
- [x] `..` और symlinks folder के बाहर इशारा कर सकते हैं
- [ ] यह बहुत धीमी है

*Answer:* `..` और symlinks folder के बाहर इशारा कर सकते हैं. सिर्फ़ resolved असली path दिखाता है कि फ़ाइल कर्म असल में कहाँ पहुँचेगा।
