Skip to content

fix: skip stripped directory metadata on extraction cwd - #467

Open
00200200 wants to merge 1 commit into
isaacs:mainfrom
00200200:skip-stripped-cwd-dir-metadata
Open

00200200 wants to merge 1 commit into
isaacs:mainfrom
00200200:skip-stripped-cwd-dir-metadata

Conversation

@00200200

Copy link
Copy Markdown

When strip leaves a directory (or GNU dumpdir) with an empty path, unpack currently still applies that entry's owner/mode/mtime to the extraction directory. GNU tar --strip-components does not do that, and as root this can change cwd permissions and ownership (#294).

This skips those leftover directory entries after stripping, matching GNU tar. Nested files such as dir/keep.txt still extract as keep.txt.

Test plan

  • npx tap test/unpack.js --disable-coverage --grep 'strip does not chown the extraction directory' fails without the CHECKPATH skip and passes with it (async + sync)
  • existing using strip option when top level file exists still passes

Fixes #294

GNU tar --strip-components does not chown, chmod, or utimes the
destination when a directory entry strips to an empty path. Skip
those directory entries so extracting as root cannot change cwd.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] extract with strip can change permissions on existing files when running as root

1 participant