Skip to content

Add .7z package extraction via SharpCompress

Placeholder ppxd requested to merge feat/calamari-7z-extraction into main

Summary

  • Add a SharpCompress-backed .7z extractor to Calamari's multi-format package pipeline, replacing the prior deferral stub that failed .7z with a "convert to another format" message.
  • The .7z path reuses the shared ArchiveSafety sandbox — zip-slip rejection, per-entry + total size caps (enforced against the header-declared size before decompression, so a zip-bomb entry never hits disk), fail-closed on malformed/encrypted input.
  • Non-breaking: a .7z package that previously errored now extracts; no wire-literal changes, no frontend impact. SharpCompress is MIT-licensed, pure-managed (~1.5 MB), chosen over shelling out to a 7z CLI so it works in minimal Linux containers and keeps the uniform safety story across every format.

Test plan

  • Unit: 13 dedicated SevenZipPackageExtractorTests + updated step/registry tests, driven against real py7zr-generated 7z bytes (embedded base64; 7z has no managed writer)
    • Happy-path nested extraction (content + byte-count + dir creation) + idempotent re-extract
    • Genuine traversal archive (../../escape.txt) rejected — destination untouched
    • Zip-bomb-style oversize entry rejected pre-decompression; same fixture extracts under the default 50 MB cap
    • Malformed bytes -> structured failure (no crash); nonexistent path -> failure
  • Full Calamari suite green (532/532)
  • Full solution builds clean (0 errors)

Merge request reports

Loading