voidzero-dev / voidzero-dev/vite-plus

create: overwrite follows target symlinks and deletes linked contents

Open
#2,419 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Rust
Stars
5.8k
Forks
261
Avg merge
1d 34m
Merged PRs (30d)
135

Description

## Summary

When `vp create` targets a non-empty directory symbolic link, choosing “Remove existing files and continue” deletes files inside the linked directory instead of removing or rejecting the link itself.

The confirmation prompt only displays the target path. It does not indicate that deletion will occur in the directory referenced by that path.

## Reproduction

1. Create a directory containing a sentinel file:

```sh
mkdir linked-directory
printf 'keep\n' > linked-directory/keep.txt
```

2. Create a target directory symlink:

```sh
ln -s "$PWD/linked-directory" new-project
```

3. Start any `vp create` flow with `new-project` as its target directory.

4. When prompted, select “Remove existing files and continue”.

5. Check the linked directory:

```sh
test -e linked-directory/keep.txt
```

## Actual behavior

`linked-directory/keep.txt` is deleted. Other entries in the linked directory are also removed recursively, except for the existing `.git` preservation behavior.

## Expected behavior

The overwrite flow should not implicitly traverse the final target symlink and delete its destination contents.

It should treat the symbolic link as a distinct filesystem entry, or otherwise make the resolved deletion target explicit before performing a destructive operation.

## Impact

This can cause irreversible local data loss outside the symbolic-link entry shown by the prompt.

The trigger is limited: the create target must be a symbolic link and the user must confirm removal. This is therefore a low-frequency but high-impact local data-loss issue, not a remote security vulnerability.

## Environment

- Reproduced on macOS arm64
- Node.js v25.9.0
- Vite+ revision: `295c8d6069605a249ed39e8c5e4d4d3d79e4be3e`

A draft fix is available in #2418.

Contributor guide

Open the contributing guide

Research direction

Review the `vp create` overwrite flow and the draft fix in #2418, then reproduce the symlink case from this issue on macOS or another local filesystem. Done means confirming that “Remove existing files and continue” does not delete contents outside the symlink entry and that the prompt or behavior makes any resolved target explicit.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
cli
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.