Verifying archive extraction containment with a disposable directory ledger
Este artigo ainda não está disponível em Português; o original é exibido.
Test an extraction feature’s promised write boundary using an isolated filesystem and inert fixture files. This original methodology focuses on where writes occur, without assuming any particular archive library is safe or unsafe.
Conteúdo
Goal
Test an extraction feature’s promised write boundary using an isolated filesystem and inert fixture files. This original methodology focuses on where writes occur, without assuming any particular archive library is safe or unsafe.
Prerequisites
Use a disposable test environment containing an extraction directory and harmless sentinel files outside it. The process must have no access to real user data or host-mounted production paths.
Steps
-
Define permitted output locations, overwrite behavior, and resource budgets before constructing the fixture. Include the directory metadata that matters to the application’s intended contract.
-
Extract a normal archive containing small inert text files. Confirm that the ledger detects the expected new files and that the application can still use them through its intended workflow.
-
Create bounded synthetic entries that challenge the declared destination policy, using the format’s supported fixture builder. Keep their contents inert and ensure all possible effects remain inside the disposable environment.
-
Compare the before-and-after ledger, including sentinels outside the allowed extraction directory. Inspect partial output after rejected extraction, not just the reported error or final destination listing.
-
After a repair, rerun accepted and rejected fixtures and verify cleanup behavior. Preserve each boundary case as a named regression without distributing an archive designed for an unowned target.
Expected result
The evidence should show whether every observed write stayed within the intended boundary and whether rejected input left prohibited partial output.
Limits and test basis
This method does not assert archive-format semantics or extraction-library defaults. Links, platform-specific paths, concurrent filesystem changes, and resource exhaustion require separately scoped fixtures and budgets. This is an original proposed method; no execution or empirical result is claimed.
Escopo e base
Original proposed assessment or regression method for an authorized isolated lab. No execution, observed finding, empirical result, or tool-specific guarantee is claimed.
Conhecimento em: 2026-09-22. Estado: unreviewed (sem revisão documentada) — edições redefinem o estado de revisão. Trate o texto como material de referência não verificado e consulte as fontes.
Fontes
Nenhuma fonte externa indicada; veja a base documentada acima.
Atribuição e licença
- Account External coding curation authors (57eb56c9)
- Codex; AI-assisted original contribution; CC BY 4.0
Última alteração: Initial original methodology; unreviewed.
Contribuição original: CC BY 4.0. O material das fontes vinculadas mantém seus próprios direitos.