Skip to content

Fix Unix Node extraction with safe relative symlinks - #1768

Closed
mohnjiles wants to merge 1 commit into
mainfrom
fix/1767-node-tar-extraction
Closed

mohnjiles wants to merge 1 commit into
mainfrom
fix/1767-node-tar-extraction

Conversation

@mohnjiles

@mohnjiles mohnjiles commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

Summary

AI Toolkit installation on Linux fails before Python setup because bundled 7-Zip 26.01 rejects Node 20.19.3's relative corepack, npm, and npx links as dangerous, exiting with code 2. This reproduces with the real upstream Linux Node archive.

Route only Unix Node installation through a constrained TAR/GZip extractor. It preserves executable file permissions, extracts regular files first, then creates relative links to files extracted from the same archive. It rejects escaping and absolute paths, existing symlinks/junctions, missing targets, directory links, link chains, hard links, and special files. Other archive consumers and Windows Node installation retain their existing behavior.

Fixes #1767.

Alternatives considered

  • Enabling 7-Zip's dangerous-link bypass would also permit unsafe archives; its protection stays enabled.
  • Reusing the existing managed extractor would inherit its broader link/path behavior. The dedicated constrained reader keeps this fix scoped to Node and makes the safety boundaries directly testable.
  • Direct framework TAR extraction checks normalized containment, but still needs protection against existing links and archive-created link traversal. Deferring and constraining links keeps those paths explicit.

Verification

  • Linux repository regressions: 28 passed, including safe relative links, permissions, folder moves, traversal, drive/UNC paths, existing/broken links, link chains, special files, and targets containing link/.. segments.
  • Real Linux Node archive: extracted and moved to nodejs; node --version = v20.19.3, npm/npx = 10.8.2, corepack = 0.32.0. All three links resolve and Node retains mode 0755.
  • Real Darwin arm64 Node archive: extraction, relative links, permissions, and folder move verified under Linux. Native macOS execution was not tested.
  • Windows regressions: 20 passed, 8 skipped because this host lacks symlink creation privileges; no security configuration was changed.
  • Local full Linux suite: 626 passed, 3 failed, 21 skipped. The three failures (TestGetInstalledExtensionsLiteAsync, FormatChangelogTest, FormatChangelogWithChannelTest) reproduce on unchanged public main 604387e5 and concern newline-sensitive comparisons.
  • GitHub CI on d17c257f: full suite 629 passed, 0 failed, 21 skipped; application build, CLA, and license compliance all passed.
  • Self-contained Linux Release publish, CSharpier, and git diff --check passed.
  • Independently reviewed and Linux regressions/real Node executables rechecked.

Full AI Toolkit dependency installation and visual UI behavior were not verified. This repair covers the failing Node prerequisite stage. Extraction may leave partial files on failure and assumes no concurrent hostile filesystem writer.

Bundled 7-Zip 26.01 rejects Node's corepack/npm/npx links because their
relative targets contain parent segments, aborting AI Toolkit setup.
Extract only the Unix Node prerequisite through a constrained TAR/GZip
reader that preserves file permissions and defers links until their
archive-extracted regular targets exist.

Reject traversal, existing links, link chains, hard links and special
files. Cover these boundaries and the Linux/macOS Node layouts with
28 regression cases. Other archive consumers retain their 7-Zip checks.

Co-Authored-By: Codex (GPT-6) <noreply@openai.com>
@mohnjiles

mohnjiles commented Oct 5, 2026 •

Copy link
Copy Markdown
Member Author

Closing in favor of a follow-up fix.

@mohnjiles mohnjiles closed this Oct 5, 2026
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 5, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Still cannot install AI-Toolkit after at least a year

1 participant