Add safe Octopus archive extraction with configurable limits
Summary
- Created local branch
feature/octopus-import-safe-archive-extractionfromfeature/squid-import-project. - Added
IOctopusArchiveExtractor/OctopusArchiveExtractorfor safe ZIP extraction underSquid.Core.Services.OctopusImport.Octopus. - Added configurable extraction limits for entry count, per-entry uncompressed size, and total uncompressed size.
- Added explicit extraction error codes and
OctopusArchiveExtractionExceptionfor unsafe archive rejection. - Implemented traversal prevention, duplicate normalized path rejection, nested archive rejection by extension and content magic, invalid ZIP handling, and cancellation checks.
- Added focused unit coverage in
OctopusArchiveExtractorTestsfor valid ZIP extraction, unsafe paths, unsafe directory entries, nested archives, entry-count limits, size limits, cancellation, and invalid ZIP input. - Scope intentionally stops at task 2.3; JSON/folder fallback, manifest inventory/hash checks, and normalized resource graph construction remain for later branches.
- Local ignored OpenSpec task file now shows task 2.3 complete, but
openspec/is ignored by.git/info/excludeand is not part of tracked branch changes.
Test plan
-
/usr/local/share/dotnet/dotnet test tests/Squid.UnitTests/Squid.UnitTests.csproj --filter "FullyQualifiedName~Services.OctopusImport"passed:65passed,0failed,0skipped. -
/usr/local/share/dotnet/dotnet test tests/Squid.UnitTests/Squid.UnitTests.csprojpassed:6287passed,0failed,0skipped. -
OpenSpec CLI validation was not run because openspecis not available in this environment. -
Integration tests were not run; this branch only adds the safe ZIP extraction service and unit tests.