From dced54c4ba0bb0d94e0e5f5bf58255c550a0b2ea Mon Sep 17 00:00:00 2001 From: Zoltan Kochan Date: Wed, 16 Sep 2026 01:39:23 +0200 Subject: [PATCH] test(binary-fetcher): fix symlink assertions in TS CI (#14936) The binary-fetcher symlink tests still named the removed adm-zip 0.6.0 patch and required its custom error message. Current adm-zip rejects those paths with a file-in-the-way error, so the tests failed despite preventing an outside-file overwrite. Check for that destination-path rejection and preserve the outside-file assertion, without coupling the tests to the removed patch's message. --- pnpm11/fetching/binary-fetcher/test/index.ts | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/pnpm11/fetching/binary-fetcher/test/index.ts b/pnpm11/fetching/binary-fetcher/test/index.ts index e24ba754db..d8b0acd489 100644 --- a/pnpm11/fetching/binary-fetcher/test/index.ts +++ b/pnpm11/fetching/binary-fetcher/test/index.ts @@ -462,9 +462,8 @@ describe('extractZipToTarget security', () => { // Developer Mode or elevation. const itOnNonWindows = process.platform === 'win32' ? it.skip : it -describe('adm-zip patch (__patches__/adm-zip@0.6.0.patch)', () => { - // The patch makes Utils.sanitize re-check containment against the resolved path. - // Without it adm-zip follows the link and clobbers the file outside the root. +// A symlink inside an extraction destination can redirect a ZIP entry to a file outside it. +describe('adm-zip symlink extraction', () => { function extractOverSymlink (plantSymlink: (paths: { root: string, outside: string }) => void): string { const dir = temporaryDirectory() const outside = path.join(dir, 'outside') @@ -480,7 +479,7 @@ describe('adm-zip patch (__patches__/adm-zip@0.6.0.patch)', () => { for (const entry of zip.getEntries()) { if (!entry.isDirectory) zip.extractEntryTo(entry, root, true, true) } - }).toThrow(/symbolic link/) + }).toThrow(/There is a file in the way/) return fs.readFileSync(path.join(outside, 'node'), 'utf8') }