From 03aa2d09418eda47f7be6aef6deea8d75f4ba197 Mon Sep 17 00:00:00 2001 From: Anthony Shew Date: Sat, 26 Sep 2026 15:06:34 -0600 Subject: [PATCH] fix: Validate scope selector glob bases --- crates/turborepo-scope/src/filter.rs | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/crates/turborepo-scope/src/filter.rs b/crates/turborepo-scope/src/filter.rs index 4d3ee6c90fbc1..ecf14d602eca3 100644 --- a/crates/turborepo-scope/src/filter.rs +++ b/crates/turborepo-scope/src/filter.rs @@ -675,16 +675,14 @@ impl<'a, T: GitChangeDetector> FilterResolver<'a, T> { if let Some(globber) = parent_dir_globber.clone() { let (base, _) = globber.partition(); - // wax takes a unix-like glob, but partition will return a system path - // TODO: it would be more proper to use - // `AnchoredSystemPathBuf::from_system_path` but that function - // doesn't allow leading `.` or `..`. + // wax takes a unix-like glob, but partition will return a system path. + // Keep leading `.` and `..` components while rejecting absolute paths. let base = base.to_str().ok_or_else(|| { ResolutionError::InvalidSelector(InvalidSelectorError::InvalidAnchoredPath( base.to_string_lossy().into_owned(), )) })?; - let base = AnchoredSystemPathBuf::from_raw(base).map_err(|_| { + let base = AnchoredSystemPathBuf::try_from(base).map_err(|_| { ResolutionError::InvalidSelector(InvalidSelectorError::InvalidAnchoredPath( base.to_string(), ))