fix: tolerate malformed bundled entry names when listing tarball contents - #10074
Open
ManoharPaturi wants to merge 1 commit into
Open
ManoharPaturi wants to merge 1 commit into
ManoharPaturi wants to merge 1 commit into
Conversation
…ents getContents matched every package/node_modules/ entry against a bundled name regex and indexed the match without checking it, so a tarball entry with a doubled separator under package/node_modules crashed pack, publish and stage download with a TypeError before any output. Registry and staged tarballs are not built by npm, so their entry names cannot be assumed to match the shapes npm generates. Skip entries whose bundled name does not match instead of crashing; the entry is still counted and listed in the file output.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
getContentsinlib/utils/tar.jsinspects every tar entry underpackage/node_modules/to collect bundled dependency names:The match is indexed without a null check. An entry such as
package/node_modules//evil(a doubled separator, so nothing follows the prefix that the name group can consume) fails the match and the whole listing dies with:getContentsruns fornpm pack <pkg>,npm publishandnpm stage download, so a single crafted entry in a registry tarball takes down all three commands before any output. Tarballs fetched from a registry or the staging endpoint are not built by npm, so their entry names cannot be assumed to match the shapes npm generates. The existing tests only feedgetContentstarballs produced by libnpmpack, which always normalize entry paths, so the crash never showed up in the suite.Solution
Check the match before using it. An entry whose bundled name cannot be parsed is skipped for the bundled set while still being counted and listed in the file output, matching how the rest of the function treats unexpected entries.
Test Evidence
Added a test in
test/lib/utils/tar.jsthat feedsgetContentsa hand assembled tarball (raw ustar headers, because both the filesystem and the tar package collapse doubled separators in entry paths) containingpackage/node_modules//evil. It asserts the command completes, the malformed entry contributes no bundled name, and both entries are still counted and listed. On the previous code the test fails with the TypeError above; with this change the full file is green:npx tap test/lib/utils/tar.js.References