create: overwrite follows target symlinks and deletes linked contents
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
Research direction
Review the vp create overwrite flow and the draft fix in #2418, then reproduce the symlink case from this issue on macOS or another local filesystem. Done means confirming that “Remove existing files and continue” does not delete contents outside the symlink entry and that the prompt or behavior makes any resolved target explicit.
Written by the indexing model from the issue text.
Description
Summary
When vp create targets a non-empty directory symbolic link, choosing “Remove existing files and continue” deletes files inside the linked directory instead of removing or rejecting the link itself.
The confirmation prompt only displays the target path. It does not indicate that deletion will occur in the directory referenced by that path.
Reproduction
-
Create a directory containing a sentinel file:
mkdir linked-directory printf 'keep\n' > linked-directory/keep.txt -
Create a target directory symlink:
ln -s "$PWD/linked-directory" new-project -
Start any
vp createflow withnew-projectas its target directory. -
When prompted, select “Remove existing files and continue”.
-
Check the linked directory:
test -e linked-directory/keep.txt
Actual behavior
linked-directory/keep.txt is deleted. Other entries in the linked directory are also removed recursively, except for the existing .git preservation behavior.
Expected behavior
The overwrite flow should not implicitly traverse the final target symlink and delete its destination contents.
It should treat the symbolic link as a distinct filesystem entry, or otherwise make the resolved deletion target explicit before performing a destructive operation.
Impact
This can cause irreversible local data loss outside the symbolic-link entry shown by the prompt.
The trigger is limited: the create target must be a symbolic link and the user must confirm removal. This is therefore a low-frequency but high-impact local data-loss issue, not a remote security vulnerability.
Environment
- Reproduced on macOS arm64
- Node.js v25.9.0
- Vite+ revision:
295c8d6069605a249ed39e8c5e4d4d3d79e4be3e
A draft fix is available in #2418.
- Dominant language
- Rust
- Stars
- 6k
- Forks
- 271
- Avg merge
- 19h 51m
- Merged PRs (30d)
- 140
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from voidzero-dev/vite-plus
-
`vite-plus/test/browser-playwright` types import `playwright`, which vite-plus does not declare, so provider options go unchecked under pnpmPossibly taken @liangmiQwQ claimed this 1 day ago. Openpending triage
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
voidzero-dev/vite-plus#2854 · 1 assignee ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
voidzero-dev/vite-plus#2849 ·
Maintainers usually reply within 1 day
-
pending triage
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
voidzero-dev/vite-plus#2801 · 1 reaction ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
voidzero-dev/vite-plus#2097 · 10 comments · 2 reactions ·
Maintainers usually reply within 1 day
-
pending triage
Difficulty 3/5 1-2 days Newbie friendliness 72/100
voidzero-dev/vite-plus#2873 · 2 reactions ·
Maintainers usually reply within 1 day
All issues in voidzero-dev/vite-plus
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
component:sight
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
agentic-os-org/ANOLISA#4622 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
HigherOrderCO/Bend#1294 ·
-
chore P0
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
LibChecker/LibChecker-Rules#1406 ·
Maintainers usually reply within 1 day