Add .7z package extraction via SharpCompress
Summary
- Add a SharpCompress-backed
.7zextractor to Calamari's multi-format package pipeline, replacing the prior deferral stub that failed.7zwith a "convert to another format" message. - The
.7zpath reuses the sharedArchiveSafetysandbox — zip-slip rejection, per-entry + total size caps (enforced against the header-declared size before decompression, so a zip-bomb entry never hits disk), fail-closed on malformed/encrypted input. - Non-breaking: a
.7zpackage that previously errored now extracts; no wire-literal changes, no frontend impact. SharpCompress is MIT-licensed, pure-managed (~1.5 MB), chosen over shelling out to a7zCLI so it works in minimal Linux containers and keeps the uniform safety story across every format.
Test plan
-
Unit: 13 dedicated SevenZipPackageExtractorTests+ updated step/registry tests, driven against real py7zr-generated 7z bytes (embedded base64; 7z has no managed writer)-
Happy-path nested extraction (content + byte-count + dir creation) + idempotent re-extract -
Genuine traversal archive ( ../../escape.txt) rejected — destination untouched -
Zip-bomb-style oversize entry rejected pre-decompression; same fixture extracts under the default 50 MB cap -
Malformed bytes -> structured failure (no crash); nonexistent path -> failure
-
-
Full Calamari suite green (532/532) -
Full solution builds clean (0 errors)