voidzero-dev / voidzero-dev/vite-plus

create: overwrite follows target symlinks and deletes linked contents

Aperta
#2,419 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
Rust
Stelle
5.8k
Fork
261
Merge medio
1g 34m
PR unite (30g)
135

Descrizione

## Summary

When `vp create` targets a non-empty directory symbolic link, choosing “Remove existing files and continue” deletes files inside the linked directory instead of removing or rejecting the link itself.

The confirmation prompt only displays the target path. It does not indicate that deletion will occur in the directory referenced by that path.

## Reproduction

1. Create a directory containing a sentinel file:

```sh
mkdir linked-directory
printf 'keep\n' > linked-directory/keep.txt
```

2. Create a target directory symlink:

```sh
ln -s "$PWD/linked-directory" new-project
```

3. Start any `vp create` flow with `new-project` as its target directory.

4. When prompted, select “Remove existing files and continue”.

5. Check the linked directory:

```sh
test -e linked-directory/keep.txt
```

## Actual behavior

`linked-directory/keep.txt` is deleted. Other entries in the linked directory are also removed recursively, except for the existing `.git` preservation behavior.

## Expected behavior

The overwrite flow should not implicitly traverse the final target symlink and delete its destination contents.

It should treat the symbolic link as a distinct filesystem entry, or otherwise make the resolved deletion target explicit before performing a destructive operation.

## Impact

This can cause irreversible local data loss outside the symbolic-link entry shown by the prompt.

The trigger is limited: the create target must be a symbolic link and the user must confirm removal. This is therefore a low-frequency but high-impact local data-loss issue, not a remote security vulnerability.

## Environment

- Reproduced on macOS arm64
- Node.js v25.9.0
- Vite+ revision: `295c8d6069605a249ed39e8c5e4d4d3d79e4be3e`

A draft fix is available in #2418.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Review the `vp create` overwrite flow and the draft fix in #2418, then reproduce the symlink case from this issue on macOS or another local filesystem. Done means confirming that “Remove existing files and continue” does not delete contents outside the symlink entry and that the prompt or behavior makes any resolved target explicit.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
rust
Ambito
cli
Tipo di issue
Bug
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Ferma
Chiarezza
Specificata chiaramente
Idoneità per principianti
35/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.