Fix usage attribution for dotdot-prefixed child paths (#3651)

* fix: attribute dotdot-prefixed usage paths

* Add usage attribution boundary tests

Co-authored-by: Orca <help@stably.ai>

---------

Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com>
Co-authored-by: Orca <help@stably.ai>
This commit is contained in:
Neil
2026-05-30 12:46:55 -07:00
committed by GitHub
co-authored by Orca Jinwoo-H
parent 7e7562bd37
commit 07b8d014bd
4 changed files with 134 additions and 3 deletions
+8 -1
View File
@@ -428,7 +428,14 @@ function isContainingPath(candidatePath: string, targetPath: string): boolean {
const isAbsoluteRelative = useWin32
? win32.isAbsolute(relativePath)
: posix.isAbsolute(relativePath)
return !isAbsoluteRelative && !relativePath.startsWith('..') && relativePath !== '.'
const parentPrefix = useWin32 ? `..${win32.sep}` : `..${posix.sep}`
// Why: `..name` is a valid child path; only `..` and `../...` escape.
return (
!isAbsoluteRelative &&
relativePath !== '..' &&
!relativePath.startsWith(parentPrefix) &&
relativePath !== '.'
)
}
async function buildWorktreesWithCanonicalPaths(