Skip to content

Ignore detect paths that can't be stat'ed in project detection - #14984

Open
pinin4fjords wants to merge 3 commits into
quarto-dev:mainfrom
pinin4fjords:fix/detect-denied-paths
Open

pinin4fjords wants to merge 3 commits into
quarto-dev:mainfrom
pinin4fjords:fix/detect-denied-paths

Conversation

@pinin4fjords

@pinin4fjords pinin4fjords commented Oct 3, 2026 •

Copy link
Copy Markdown

Description

Fixes #14983.

Project detection currently treats an inaccessible detect path as if it exists. This happens because safeExistsSync, which wraps @std/fs’s existsSync, returns true for PermissionDenied.

As a result, a parent directory containing content/ and an inaccessible config/ can incorrectly match Hugo’s config/_default/config.toml detect path, even when that file does not exist. quarto render may then:

  • write hugo-md output despite --output doc.html; or
  • fail while walking the directory.

This change counts a detect path only when Deno.statSync succeeds. It affects detection only; the input walk still fails on unreadable directories, as intended by #14966.

Scope. Quarto resolves documents using absolute paths, so every directory in the upward walk must be searchable. A _quarto.yml or single-segment detect path is checked in a searchable directory, so a permission error cannot cause a false match there. Among the bundled extensions, only Hugo’s multi-segment detect path (config/_default/config.toml) is affected.

Trade-off. If a Hugo site’s config/ directory cannot be searched, Quarto will no longer detect it as a Hugo site and will render the input as a single file. If only the config file itself is unreadable, the site is still detected (tested on macOS and Linux).

Tests. Added unit and smoke tests that fail without this change and pass with it, on macOS and in CI. The following also pass:

Added one sentence describing this rule to llm-docs/project-context-architecture.md.

Checklist

I have (if applicable):

  • referenced the GitHub issue this PR closes
  • updated the appropriate changelog in the PR
  • ensured the present test suite passes
  • added new tests
  • created a separate documentation PR in Quarto's website repo and linked it to this PR (not needed)
AI-assisted PR

pinin4fjords and others added 3 commits October 3, 2026 15:18
existsSync returns true on PermissionDenied, so a parent folder with
content/ and a config/ that can't be searched matched the Hugo detect
rule config/_default/config.toml although that file doesn't exist.
quarto render then wrote Hugo Markdown (even with --output doc.html)
or failed walking the folder.

Count a detect path only if Deno.statSync succeeds. Real sites are
still detected, including when the config file itself is unreadable.

Fixes quarto-dev#14983

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Make the detection unit tests table-driven and POSIX-only, add a smoke
test that renders with --output doc.html below a config/ at mode 644,
and note the stat rule in the project-context architecture doc.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@posit-snyk-bot

posit-snyk-bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Hugo project detection matches a parent folder whose config/ can't be entered, so quarto render can silently write Markdown

2 participants