mirror of
https://github.com/rclone/rclone.git
synced 2026-10-10 06:55:45 -04:00
When the plugin restarts it reads its persisted state file and used the stored mountpoint verbatim. A state file written by an older rclone that allowed escaping volume names, or one that was tampered with, could point the mountpoint outside the base directory, so upgrading did not remediate an already-escaped volume. Re-derive the mountpoint from the base directory and the volume name on restore, confined to the base directory, rather than trusting the stored path.