Skip to content

Add safe Octopus archive extraction with configurable limits

Summary

  • Created local branch feature/octopus-import-safe-archive-extraction from feature/squid-import-project.
  • Added IOctopusArchiveExtractor / OctopusArchiveExtractor for safe ZIP extraction under Squid.Core.Services.OctopusImport.Octopus.
  • Added configurable extraction limits for entry count, per-entry uncompressed size, and total uncompressed size.
  • Added explicit extraction error codes and OctopusArchiveExtractionException for unsafe archive rejection.
  • Implemented traversal prevention, duplicate normalized path rejection, nested archive rejection by extension and content magic, invalid ZIP handling, and cancellation checks.
  • Added focused unit coverage in OctopusArchiveExtractorTests for valid ZIP extraction, unsafe paths, unsafe directory entries, nested archives, entry-count limits, size limits, cancellation, and invalid ZIP input.
  • Scope intentionally stops at task 2.3; JSON/folder fallback, manifest inventory/hash checks, and normalized resource graph construction remain for later branches.
  • Local ignored OpenSpec task file now shows task 2.3 complete, but openspec/ is ignored by .git/info/exclude and is not part of tracked branch changes.

Test plan

  • /usr/local/share/dotnet/dotnet test tests/Squid.UnitTests/Squid.UnitTests.csproj --filter "FullyQualifiedName~Services.OctopusImport" passed: 65 passed, 0 failed, 0 skipped.
  • /usr/local/share/dotnet/dotnet test tests/Squid.UnitTests/Squid.UnitTests.csproj passed: 6287 passed, 0 failed, 0 skipped.
  • OpenSpec CLI validation was not run because openspec is not available in this environment.
  • Integration tests were not run; this branch only adds the safe ZIP extraction service and unit tests.

Merge request reports

Loading