Skip to content

fix(storage): guard recursive deletion and relocation (refs #351) - #370

Open
JayceeB1 wants to merge 2 commits into
lightningpixel:devfrom
JayceeB1:fix/storage-destructive-operations
Open

JayceeB1 wants to merge 2 commits into
lightningpixel:devfrom
JayceeB1:fix/storage-destructive-operations

Conversation

@JayceeB1

@JayceeB1 JayceeB1 commented Oct 9, 2026

Copy link
Copy Markdown

Safety hotfix (review/staging PR)

This is the same branch intended for a draft PR to lightningpixel/modly:dev. The linked GitHub integration does not currently have permission to create a PR in that upstream repository (403). Opening the draft here preserves a reviewable diff while waiting for a normal cross-fork submission.

Why

See upstream #351 (reported catastrophic data loss, not independently reproduced). Source inspection confirmed unguarded copy → recursive delete during moves and unsafe raw startsWith deletion allow-list.

Patch

  • Centralize both fs:moveDirectory and fs:deleteDirectory into fail-closed main-process guards.
  • Reject volume/filesystem roots, relative/shallow/unsupported paths, dangerous home/app/config ancestors, symlink/junction ancestry, and storage path overlap.
  • Require a separate empty move destination; refuse overwrite if a file appears during copy; recheck before source deletion.
  • Keep legitimate workspace tmp cleanup and enable workflow storage deletion.
  • Add 12 regression tests for Windows path semantics and isolated real filesystem fixtures.

Verification

  • Focused 12 tests passed locally under Node 22/Linux, with simulated Windows paths.
  • Full project CI, Windows runtime/junction tests, and security review.
  • Consider directory ownership markers/inventory: path guards cannot prove that all files in a user-selected directory belong to Modly.

No upstream code is changed by this PR. Please do not merge without the remaining validation.

Upstream #351: #351
Intended upstream PR comparison: dev...JayceeB1:modly:fix/storage-destructive-operations

@JayceeB1
JayceeB1 marked this pull request as ready for review October 9, 2026 21:09
JayceeB1 added a commit to JayceeB1/modly that referenced this pull request Oct 9, 2026
…mental preview)

Source: lightningpixel#370; preserves released Modly 0.4.3.
Confirmed by combined CI regression. Remove only an empty target with rmdir; never remove source on copy failure.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant