The engine runs on the host for OSS Docker scans, where /workspace does
not exist: include cloned_repo_path, local-code target_path and the
workspace mount as roots so re-anchoring works outside the sandbox.
Skip locations whose file fails path validation before any read so
absolute paths (e.g. /dev/zero) can never hang reporting, resolve
candidates and require they stay inside the root (symlink escapes), and
cap buffered files at 4 MiB.
Require the anchor to resolve to one position across every root instead
of picking the globally-nearest hit, which could store another repo's
range in a multi-target scan; apply the single-line uniqueness rule to
exact matches too so a lone repeated line keeps the reported range.
Agents report start_line/end_line from memory and routinely land tens of
lines off while copying the vulnerable code verbatim. Since fix_before
(falling back to snippet) is a byte-faithful copy, locate that block in
the checked-out file under /workspace and correct the range before the
locations are validated and stored. Locations whose anchor is not found
keep their reported numbers. Applies on both create_vulnerability_report
and update_vulnerability_report.