voidzero-dev / voidzero-dev/vite-plus

create: overwrite follows target symlinks and deletes linked contents

Offen
#2,419 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
Rust
Sterne
5.8k
Forks
261
Ø Merge
1 T. 34 Min.
Gemergte PRs (30 T.)
135

Beschreibung

## Summary

When `vp create` targets a non-empty directory symbolic link, choosing “Remove existing files and continue” deletes files inside the linked directory instead of removing or rejecting the link itself.

The confirmation prompt only displays the target path. It does not indicate that deletion will occur in the directory referenced by that path.

## Reproduction

1. Create a directory containing a sentinel file:

```sh
mkdir linked-directory
printf 'keep\n' > linked-directory/keep.txt
```

2. Create a target directory symlink:

```sh
ln -s "$PWD/linked-directory" new-project
```

3. Start any `vp create` flow with `new-project` as its target directory.

4. When prompted, select “Remove existing files and continue”.

5. Check the linked directory:

```sh
test -e linked-directory/keep.txt
```

## Actual behavior

`linked-directory/keep.txt` is deleted. Other entries in the linked directory are also removed recursively, except for the existing `.git` preservation behavior.

## Expected behavior

The overwrite flow should not implicitly traverse the final target symlink and delete its destination contents.

It should treat the symbolic link as a distinct filesystem entry, or otherwise make the resolved deletion target explicit before performing a destructive operation.

## Impact

This can cause irreversible local data loss outside the symbolic-link entry shown by the prompt.

The trigger is limited: the create target must be a symbolic link and the user must confirm removal. This is therefore a low-frequency but high-impact local data-loss issue, not a remote security vulnerability.

## Environment

- Reproduced on macOS arm64
- Node.js v25.9.0
- Vite+ revision: `295c8d6069605a249ed39e8c5e4d4d3d79e4be3e`

A draft fix is available in #2418.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Review the `vp create` overwrite flow and the draft fix in #2418, then reproduce the symlink case from this issue on macOS or another local filesystem. Done means confirming that “Remove existing files and continue” does not delete contents outside the symlink entry and that the prompt or behavior makes any resolved target explicit.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
rust
Bereich
cli
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Klar beschrieben
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.