Skip to content

feat: validate bundle stays within output dir#8441

Merged
graphite-app[bot] merged 1 commit intomainfrom
02-24-feat_validate_bundle_stays_within_output_dir
Feb 24, 2026
Merged

feat: validate bundle stays within output dir#8441
graphite-app[bot] merged 1 commit intomainfrom
02-24-feat_validate_bundle_stays_within_output_dir

Conversation

@sapphi-red
Copy link
Member

@sapphi-red sapphi-red commented Feb 24, 2026

Adds the error added in rollup/rollup#6275

Copy link
Member Author


How to use the Graphite Merge Queue

Add the label graphite: merge-when-ready to this PR to add it to the merge queue.

You must have a Graphite account in order to use the merge queue. Sign up using this link.

An organization admin has enabled the Graphite Merge Queue in this repository.

Please do not merge from GitHub as this will restart CI on PRs being processed by the merge queue.

This stack of pull requests is managed by Graphite. Learn more about stacking.

@netlify
Copy link

netlify bot commented Feb 24, 2026

Deploy Preview for rolldown-rs ready!

Name Link
🔨 Latest commit 69c2083
🔍 Latest deploy log https://app.netlify.com/projects/rolldown-rs/deploys/699da47374af280008201198
😎 Deploy Preview https://deploy-preview-8441--rolldown-rs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@sapphi-red sapphi-red force-pushed the 02-24-feat_validate_bundle_stays_within_output_dir branch 2 times, most recently from 7fd112b to 63fced6 Compare February 24, 2026 10:18
@sapphi-red sapphi-red marked this pull request as ready for review February 24, 2026 11:30
Copilot AI review requested due to automatic review settings February 24, 2026 11:30
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds validation to ensure that all bundle output files stay within the output directory, matching Rollup's behavior from PR #6275. It prevents path traversal attacks and accidental file writes outside the intended output location.

Changes:

  • Added FilenameOutsideOutputDirectoryError event type to detect files that would escape the output directory
  • Implemented path validation logic that rejects absolute paths, Windows drive-letter paths, and paths with ".." traversal
  • Updated test status to reflect 8 tests moved to ignored (due to bundle assignment API differences) and 2 tests now passing

Reviewed changes

Copilot reviewed 9 out of 10 changed files in this pull request and generated no comments.

Show a summary per file
File Description
packages/rollup-tests/src/status.md Updated test counts: 10 fewer skipFailed, 8 more ignored, 2 more passed
packages/rollup-tests/src/status.json Same test count updates in JSON format
packages/rollup-tests/src/ignored-tests.js Added 8 tests to ignored list with explanation that bundle assignment API is not supported
packages/rollup-tests/src/failed-tests.json Removed 10 tests that are now either passing or properly ignored
crates/rolldown_error/src/types/event_kind.rs Added FilenameOutsideOutputDirectoryError variant and Display implementation
crates/rolldown_error/src/generated/event_kind_switcher.rs Added corresponding bitflag for the new error type
crates/rolldown_error/src/build_diagnostic/events/mod.rs Added module declaration for the new error event
crates/rolldown_error/src/build_diagnostic/events/filename_outside_output_directory.rs Implemented the new error event with clear error message
crates/rolldown_error/src/build_diagnostic/constructors.rs Added constructor function for the new error type
crates/rolldown/src/bundle/bundle.rs Added validation loop and helper function to check all output filenames

@github-actions
Copy link
Contributor

Benchmarks Rust

  • target: main(6faf02f)
  • pr: 02-24-feat_validate_bundle_stays_within_output_dir(63fced6)
group                                                        pr                                     target
-----                                                        --                                     ------
bundle/bundle@multi-duplicated-top-level-symbol              1.00     67.3±2.18ms        ? ?/sec    1.00     67.3±1.85ms        ? ?/sec
bundle/bundle@multi-duplicated-top-level-symbol-sourcemap    1.00     71.9±2.15ms        ? ?/sec    1.01     72.6±2.48ms        ? ?/sec
bundle/bundle@rome_ts                                        1.00     98.5±5.65ms        ? ?/sec    1.01     99.5±2.63ms        ? ?/sec
bundle/bundle@rome_ts-sourcemap                              1.00    106.6±1.91ms        ? ?/sec    1.02    109.1±2.46ms        ? ?/sec
bundle/bundle@threejs                                        1.00     35.1±0.73ms        ? ?/sec    1.03     36.1±2.25ms        ? ?/sec
bundle/bundle@threejs-sourcemap                              1.00     39.9±1.21ms        ? ?/sec    1.00     39.8±0.89ms        ? ?/sec
bundle/bundle@threejs10x                                     1.00    363.3±6.89ms        ? ?/sec    1.02    370.9±7.40ms        ? ?/sec
bundle/bundle@threejs10x-sourcemap                           1.00    417.8±6.50ms        ? ?/sec    1.02    426.6±5.47ms        ? ?/sec
scan/scan@rome_ts                                            1.00     78.1±2.03ms        ? ?/sec    1.00     77.8±1.63ms        ? ?/sec
scan/scan@threejs                                            1.00     27.4±1.77ms        ? ?/sec    1.02     28.0±1.61ms        ? ?/sec
scan/scan@threejs10x                                         1.00    278.0±7.46ms        ? ?/sec    1.01    282.2±6.27ms        ? ?/sec

Copy link
Member Author

sapphi-red commented Feb 24, 2026

Merge activity

  • Feb 24, 11:48 AM UTC: The merge label 'graphite: merge-when-ready' was detected. This PR will be added to the Graphite merge queue once it meets the requirements.
  • Feb 24, 1:14 PM UTC: sapphi-red added this pull request to the Graphite merge queue.
  • Feb 24, 1:27 PM UTC: Merged by the Graphite merge queue.

@sapphi-red sapphi-red force-pushed the 02-24-feat_validate_bundle_stays_within_output_dir branch from 63fced6 to 20a2084 Compare February 24, 2026 12:15
Copilot AI review requested due to automatic review settings February 24, 2026 12:16
@sapphi-red sapphi-red force-pushed the 02-24-feat_validate_bundle_stays_within_output_dir branch from 20a2084 to 1bf5632 Compare February 24, 2026 12:16
@sapphi-red sapphi-red requested a review from hyf0 February 24, 2026 12:17
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 10 changed files in this pull request and generated 2 comments.

@sapphi-red sapphi-red force-pushed the 02-24-feat_validate_bundle_stays_within_output_dir branch from 1bf5632 to 1e4ded4 Compare February 24, 2026 12:32
@graphite-app graphite-app bot force-pushed the 02-24-feat_validate_bundle_stays_within_output_dir branch from 1e4ded4 to 69c2083 Compare February 24, 2026 13:15
@graphite-app graphite-app bot merged commit 69c2083 into main Feb 24, 2026
34 checks passed
@graphite-app graphite-app bot deleted the 02-24-feat_validate_bundle_stays_within_output_dir branch February 24, 2026 13:27
shulaoda added a commit that referenced this pull request Feb 26, 2026
## [1.0.0-rc.6] - 2026-02-26

### 💥 BREAKING CHANGES

- css: remove `css_entry_filenames` , `css_chunk_filenames` and related code (#8402) by @hyf0
- css: drop builtin CSS bundling to explore alternative solutions (#8399) by @hyf0

### 🚀 Features

- rust/data-url: use hash as id for data url modules to prevent long string overhead (#8420) by @hyf0
- validate bundle stays within output dir (#8441) by @sapphi-red
- rust: support `PluginOrder::PinPost` (#8417) by @hyf0
- support `ModuleType:Copy` (#8407) by @hyf0
- expose `ESTree` types from `rolldown/utils` (#8400) by @sapphi-red

### 🐛 Bug Fixes

- incorrect sourcemap when postBanner/postFooter is used with shebang (#8459) by @Copilot
- resolver: disable node_path option to align ESM resolver behavior (#8472) by @sapphi-red
- parse `.js` within `"type": "commonjs"` as ESM for now (#8470) by @sapphi-red
- case-insensitive filename conflict detection for chunk deduplication (#8458) by @Copilot
- prevent inlining CJS exports that are mutated by importers (#8456) by @IWANABETHATGUY
- parse `.cjs` / `.cts` / `.js` within `"type": "commonjs"` as CommonJS (#8455) by @sapphi-red
- plugin/copy-module: correct hooks' priority (#8423) by @hyf0
- plugin/chunk-import-map: ensure `render_chunk_meta` run after users plugin (#8422) by @hyf0
- rust: correct hooks order of `DataUriPlugin` (#8418) by @hyf0
- `jsx.preserve` should also considering tsconfig json preserve (#8324) by @IWANABETHATGUY
- `deferred_scan_data.rs "Should have resolved id: NotFound"` error (#8379) by @sapphi-red
- cli: require value for `--dir`/`-d` and `--file`/`-o` (#8378) by @Copilot
- dev: avoid mutex deadlock caused by inconsistent lock order (#8370) by @sapphi-red

### 🚜 Refactor

- watch: rename TaskStart/TaskEnd to BundleStart/BundleEnd (#8463) by @hyf0
- rust: rename `rolldown_plugin_data_uri` to `rolldown_plugin_data_url` (#8421) by @hyf0
- bindingify-build-hook: extract helper for PluginContextImpl (#8438) by @ShroXd
- give source loading a proper name (#8436) by @IWANABETHATGUY
- ban holding DashMap refs across awaits (#8362) by @sapphi-red

### 📚 Documentation

- add glob pattern usage example to input option (#8469) by @IWANABETHATGUY
- remove `https://rolldown.rs` from links in reference docs (#8454) by @sapphi-red
- mention execution order issue in `output.codeSplitting` docs (#8452) by @sapphi-red
- clarify `output.comments` behavior a bit (#8451) by @sapphi-red
- replace npmjs package links with npmx.dev (#8439) by @Boshen
- reference: add `Exported from` for values / types exported from subpath exports (#8394) by @sapphi-red
- add JSDocs for APIs exposed from subpath exports (#8393) by @sapphi-red
- reference: generate reference pages for APIs exposed from subpath exports (#8392) by @sapphi-red
- avoid pipe character in codeSplitting example to fix broken rendering (#8391) by @IWANABETHATGUY

### ⚡ Performance

- avoid redundant PathBuf allocations in resolve paths (#8435) by @Brooooooklyn
- bump to `sugar_path@2` (#8432) by @hyf0
- use flag-based convergence detection in include_statements (#8412) by @Brooooooklyn

### 🧪 Testing

- execute `_test.mjs` even if `executeOutput` is false (#8398) by @sapphi-red
- add retry to tree-shake/module-side-effects-proxy4 as it is flaky (#8397) by @sapphi-red
- avoid `expect.assertions()` as it is not concurrent test friendly (#8383) by @sapphi-red
- disable `mockReset` option (#8382) by @sapphi-red
- fix flaky failure caused by concurrent resolveId calls (#8381) by @sapphi-red

### ⚙️ Miscellaneous Tasks

- deps: update dependency rollup to v4.59.0 [security] (#8471) by @renovate[bot]
- ai/design: add design doc about watch mode (#8453) by @hyf0
- deps: update oxc resolver to v11.19.0 (#8461) by @renovate[bot]
- ai: introduce progressive spec-driven development pattern (#8446) by @hyf0
- deprecate output.legalComments (#8450) by @sapphi-red
- deps: update dependency oxlint-tsgolint to v0.15.0 (#8448) by @renovate[bot]
- ai: make CLAUDE.md a symlink of AGENTS.md (#8445) by @hyf0
- deps: update rollup submodule for tests to v4.59.0 (#8433) by @sapphi-red
- deps: update test262 submodule for tests (#8434) by @sapphi-red
- deps: update oxc to v0.115.0 (#8430) by @renovate[bot]
- deps: update oxc apps (#8429) by @renovate[bot]
- deps: update npm packages (#8426) by @renovate[bot]
- deps: update rust crate owo-colors to v4.3.0 (#8428) by @renovate[bot]
- deps: update github-actions (#8424) by @renovate[bot]
- deps: update rust crates (#8425) by @renovate[bot]
- deps: update oxc resolver to v11.18.0 (#8406) by @renovate[bot]
- deps: update dependency oxlint-tsgolint to v0.14.2 (#8405) by @renovate[bot]
- ban `expect.assertions` in all fixture tests (#8395) by @sapphi-red
- deps: update oxc apps (#8389) by @renovate[bot]
- ban `expect.assertions` in fixture tests (#8387) by @sapphi-red
- enable lint for `_config.ts` files (#8386) by @sapphi-red
- deps: update dependency oxlint-tsgolint to v0.14.1 (#8385) by @renovate[bot]

Co-authored-by: shulaoda <165626830+shulaoda@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants