On this page
Protect & operate
Keep discovery inside a useful root.
Prevent broad scans from turning a project task into a home-directory crawl.
Root guard and PathJail do different jobs
Root guard protects project discovery and indexing from overly broad or sensitive roots. PathJail validates file access against the effective allowed boundaries.
A root accepted for indexing is not authorization to read everything on the machine.
Start in the project
Launch the host and LeanCTX from the repository or intended workspace. Check that the detected root matches your task before building an index.
On a monorepo, choose the appropriate project root and use include/exclude settings to narrow indexing. Do not solve a refused broad scan by disabling the entire access boundary.
Diagnose a refusal
Read the exact refused path and compare it with the working directory, configured project root and allowed roots. Resolve symlinks and shared directories deliberately.
lean-ctx status
lean-ctx doctor
lean-ctx config path
If a legitimate task needs another repository, use a documented multi-root or provider path and grant only the required access.
Keep resource use bounded
A narrow root improves relevance and limits index work. Pair it with the file and thread limits in performance tuning.
Sources & versions
- pathutil.rsrust/src/core/pathutil.rsReviewed checkout
- 10-customization-and-governance.mddocs/reference/10-customization-and-governance.mdGitHub
- Core checkout
0ce2207ee4- Installed runtime
- 3.10.2
- SDK release
- 1.1.0
Separate baselines for source, CLI/configuration and SDK contracts. Review does not certify every platform or integration.
Versions & compatibility