Skip to content

[Bug]: Aside integration refuses a symlinked ~/.aside ("configured root is missing or is not a safe directory") #5648

Description

@Tygb99

Client or integration

Aside

Area

Integrations / client config export

Summary

On a machine where ~/.aside is a symlink to a relocated directory (e.g. an external volume after a home-folder migration), the Aside integration tab can't load profiles:

Aside 프로필을 불러오지 못했습니다. ... Aside profile: the configured root is missing or is not a safe directory.

asideHomeDir() (src/clients/config-export.ts) always returns join(home, ".aside") and ignores its _env parameter, so there is no way to point opencodex at the real location. readProfiles() (src/clients/aside-profiles.ts) then lstats that path and refuses it because it is a symbolic link.

Aside itself works normally through the symlink. The account manifest, u/0/ and models.json under the real directory are all regular files and directories.

Expected: a user-created alias above the Aside root is accepted. The comment in boundary() already says "Aliases ABOVE the chosen root (notably macOS /var) are valid". Only links at or below the root should be refused.

Reproduction

  1. mv ~/.aside /Volumes/ext/.aside && ln -s /Volumes/ext/.aside ~/.aside
  2. Launch Aside (works fine).
  3. Open the dashboard → Integrations → Aside.
  4. The error above appears and "Sync all profiles" / "Sync now" are disabled (0 of 0 applied).

Suggested fix

Either of these would work:

  • Resolve only the top-level ~/.aside alias in asideHomeDir() when it is a symlink to a directory, and keep all existing link/identity checks for u/, u/<id> and models.json. I verified this locally:
    export function asideHomeDir(_env = process.env, home = homedir()): string {
      const root = join(home, ".aside");
      try {
        if (lstatSync(root).isSymbolicLink() && statSync(root).isDirectory()) return realpathSync.native(root);
      } catch { /* fall through */ }
      return root;
    }
    With this patch, listAsideProfiles() returns the current account, and the dashboard lists the profile and can sync it.
  • Or honor an explicit override (e.g. ASIDE_HOME / an asideRoot config key) via the currently unused _env parameter.

Version

@bitkyc08/opencodex 2.63.0

Operating system

macOS 26.6.2 (Apple Silicon)

Logs or error output

Aside profile: the configured root is missing or is not a safe directory.

Checks

  • I searched existing issues and documentation.
  • I removed secrets, tokens, account details, request credentials, and personal data.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions