voidzero-dev / voidzero-dev/vite-plus
create: overwrite follows target symlinks and deletes linked contents
- Langage dominant
- Rust
- Étoiles
- 5.8k
- Forks
- 262
- Merge moyen
- 23 h 18 min
- PR mergées (30 j)
- 139
Description
## Summary
When `vp create` targets a non-empty directory symbolic link, choosing “Remove existing files and continue” deletes files inside the linked directory instead of removing or rejecting the link itself.
The confirmation prompt only displays the target path. It does not indicate that deletion will occur in the directory referenced by that path.
## Reproduction
1. Create a directory containing a sentinel file:
```sh
mkdir linked-directory
printf 'keep\n' > linked-directory/keep.txt
```
2. Create a target directory symlink:
```sh
ln -s "$PWD/linked-directory" new-project
```
3. Start any `vp create` flow with `new-project` as its target directory.
4. When prompted, select “Remove existing files and continue”.
5. Check the linked directory:
```sh
test -e linked-directory/keep.txt
```
## Actual behavior
`linked-directory/keep.txt` is deleted. Other entries in the linked directory are also removed recursively, except for the existing `.git` preservation behavior.
## Expected behavior
The overwrite flow should not implicitly traverse the final target symlink and delete its destination contents.
It should treat the symbolic link as a distinct filesystem entry, or otherwise make the resolved deletion target explicit before performing a destructive operation.
## Impact
This can cause irreversible local data loss outside the symbolic-link entry shown by the prompt.
The trigger is limited: the create target must be a symbolic link and the user must confirm removal. This is therefore a low-frequency but high-impact local data-loss issue, not a remote security vulnerability.
## Environment
- Reproduced on macOS arm64
- Node.js v25.9.0
- Vite+ revision: `295c8d6069605a249ed39e8c5e4d4d3d79e4be3e`
A draft fix is available in #2418.
Guide de contribution
Ouvrir le guide de contribution
Piste de recherche
Examinez le flux d’écrasement de `vp create` et l’ébauche de correction dans #2418, puis reproduisez le cas de symlink de cette issue sur macOS ou sur un autre système de fichiers local. C’est terminé lorsque vous avez confirmé que « Supprimer les fichiers existants et continuer » ne supprime pas de contenu en dehors de l’entrée du symlink et que le prompt ou le comportement rend explicitement visible toute cible résolue.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- rust
- Domaine
- cli
- Type d'issue
- Bug
- Difficulté
- 4/5
- Temps estimé
- 3-5 jours
- Activité
- À l'abandon
- Clarté
- Clairement spécifiée
- Accessibilité débutants
- 35/100