Skip to content

Generate unique paths for duplicate multipart filenames - #6990

Merged
tim-smart merged 3 commits into
mainfrom
audit/repro-unstable-http-multipart-filename-collision
Aug 4, 2026
Merged

Generate unique paths for duplicate multipart filenames#6990
tim-smart merged 3 commits into
mainfrom
audit/repro-unstable-http-multipart-filename-collision

Conversation

@fubhy

@fubhy fubhy commented Aug 4, 2026

Copy link
Copy Markdown
Member

Summary

Two ordinary file parts named same.txt receive the same persisted path, so the later write replaces the bytes referenced by both returned PersistedFile values and silently loses one file.

Important

This PR starts with focused failing reproduction tests. Add the implementation fix to this same branch; CI is expected to fail until that fix is included.

Equal multipart filenames overwrite each other during persistence

Module: Multipart
Audit ID: unstable-http-multipart-filename-collision
Severity / confidence: medium / high

What happens

Two ordinary file parts named same.txt receive the same persisted path, so the later write replaces the bytes referenced by both returned PersistedFile values and silently loses one file.

Why it happens

Each file path is derived only as join(tempDir, basename(file.name).slice(-128)). Parts with equal filenames are written sequentially to one path, and both returned values point to the final write.

Expected behavior

toPersisted must preserve every valid multipart file part and return a path containing that part's bytes for the scope lifetime.

Relevant implementation

These links and excerpts are pinned to audit base c9b56ab507f224426ee8388dc450da447ec4715f.

View problematic code at packages/effect/src/unstable/http/Multipart.ts:672-708
export const toPersisted = (
  stream: Stream.Stream<Part, MultipartError>,
  writeFile = defaultWriteFile
): Effect.Effect<Persisted, MultipartError, FileSystem.FileSystem | Path.Path | Scope.Scope> =>
  Effect.gen(function*() {
    const fs = yield* FileSystem.FileSystem
    const path_ = yield* Path.Path
    const dir = yield* fs.makeTempDirectoryScoped()
    const persisted: Record<string, Array<PersistedFile> | Array<string> | string> = Object.create(null)
    yield* Stream.runForEach(stream, (part) => {
      if (part._tag === "Field") {
        if (!(part.key in persisted)) {
          persisted[part.key] = part.value
        } else if (typeof persisted[part.key] === "string") {
          persisted[part.key] = [persisted[part.key] as string, part.value]
        } else {
          ;(persisted[part.key] as Array<string>).push(part.value)
        }
        return Effect.void
      } else if (part.name === "") {
        return Effect.void
      }
      const file = part
      const path = path_.join(dir, path_.basename(file.name).slice(-128))
      const filePart = new PersistedFileImpl(
        file.key,
        file.name,
        file.contentType,
        path
      )
      if (Array.isArray(persisted[part.key])) {
        ;(persisted[part.key] as Array<PersistedFile>).push(filePart)
      } else {
        persisted[part.key] = [filePart]
      }
      return writeFile(path, file)
    })

View exact lines on GitHub

View problematic code at packages/effect/src/unstable/http/Multipart.ts:695
      const path = path_.join(dir, path_.basename(file.name).slice(-128))

View exact lines on GitHub

Reproduction

pnpm test --run packages/effect/test/unstable/http/Multipart.test.ts

Observed failure: Failed as intended because both writes used /tmp/audit/same.txt and the returned paths were equal.

Implementation handoff

The initial reproduction tests on this branch are the regression specification for the implementation fix that should follow in this PR.

  1. Start with the pinned implementation excerpts and the Why it happens analysis above.
  2. Change the implementation so it satisfies the stated Expected behavior; do not weaken or remove the reproduction assertions.
  3. Run the focused reproduction command(s) and confirm the observed failures become passing tests:
pnpm test --run packages/effect/test/unstable/http/Multipart.test.ts
  1. Run the affected package's existing tests, then the repository lint and type checks before requesting review.

Audit provenance

  • Audit base: c9b56ab507f224426ee8388dc450da447ec4715f
  • Reproduction base: c9b56ab507f224426ee8388dc450da447ec4715f
  • Findings: unstable-http-multipart-filename-collision
  • Initial patch: focused reproduction tests; implementation fix pending

Closes EFF-427

@fubhy fubhy added the audit Findings originating from the Effect runtime correctness audit label Aug 4, 2026
@changeset-bot

changeset-bot Bot commented Aug 4, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 9cf5760

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 30 packages
Name Type
effect Patch
@effect/opentelemetry Patch
@effect/platform-browser Patch
@effect/platform-bun Patch
@effect/platform-deno Patch
@effect/platform-node-shared Patch
@effect/platform-node Patch
@effect/vitest Patch
@effect/ai-anthropic Patch
@effect/ai-openai-compat Patch
@effect/ai-openai Patch
@effect/ai-openrouter Patch
@effect/atom-react Patch
@effect/atom-solid Patch
@effect/atom-vue Patch
@effect/sql-clickhouse Patch
@effect/sql-d1 Patch
@effect/sql-libsql Patch
@effect/sql-mssql Patch
@effect/sql-mysql2 Patch
@effect/sql-pg Patch
@effect/sql-pglite Patch
@effect/sql-sqlite-bun Patch
@effect/sql-sqlite-do Patch
@effect/sql-sqlite-node Patch
@effect/sql-sqlite-react-native Patch
@effect/sql-sqlite-wasm Patch
@effect/docgen Patch
@effect/doctest Patch
@effect/openapi-generator Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@effect-slopcop effect-slopcop Bot added 4.0 bug Something isn't working labels Aug 4, 2026

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Important

The reproduction test is valid and pinpoints the bug, but as the PR body states, CI is expected to fail until the implementation fix lands on this branch. I do not recommend merging in the current state.

Reviewed changes

  • packages/effect/test/unstable/http/Multipart.test.ts: added a regression test that asserts two multipart file parts with the identical client filename (same.txt) are written to distinct persisted paths.
  • Confirmed the new test currently fails against the existing Multipart.toPersisted implementation, matching the reported audit finding.

⚠️ Implementation fix is still missing

The PR description says this branch starts with focused failing reproduction tests and that the implementation fix should be added to the same branch. The diff only touches the test file, so the underlying bug in packages/effect/src/unstable/http/Multipart.ts (toPersisted derives the destination path only from the basename) is still present.

ℹ️ Nitpicks

  • The new test's writeFile callback records only the paths it was asked to write to. Consider also asserting that the two returned PersistedFile values have different path values, not just that writeFile received different paths — that mirrors the actual user-visible bug more closely.
  • The FileSystem service stub is cast as any; while this is only test code, providing at least makeTempDirectoryScoped is enough for this path but will become brittle if toPersisted ever touches another FileSystem method. That's acceptable for a focused regression test.
  • The test name is clear, but it could be strengthened to mention that the collision happens in the persisted path returned to the caller (e.g., "returns distinct PersistedFile.path values for files with the same client filename").

Pullfrog  | ⚠️ this action is pinned to a commit SHA, which freezes the cleanup step — switch to @v0 or keep the SHA fresh with Dependabot | Fix it ➔View workflow run | Using Kimi K2 (free via Pullfrog for OSS) | 𝕏

@@ -692,7 +693,7 @@ export const toPersisted = (
return Effect.void
}
const file = part
const path = path_.join(dir, path_.basename(file.name).slice(-128))
const path = path_.join(dir, `${fileIndex++}-${path_.basename(file.name).slice(-128)}`)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it should only add the prefix when the name is already taken

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes

  • packages/effect/src/unstable/http/Multipart.ts: implemented unique path generation for duplicate multipart filenames by tracking used paths in a scoped Set and appending an incrementing numeric prefix (0-, 1-, ...) to subsequent collisions.
  • packages/effect/test/unstable/http/Multipart.test.ts: updated the regression test to use FileSystem.makeNoop for the service stub and to assert distinct PersistedFile.path values as well as the exact sequence of writeFile calls.
  • .changeset/tender-points-sleep.md: added a patch-level changeset describing the fix.

Pullfrog  | ⚠️ this action is pinned to a commit SHA, which freezes the cleanup step — switch to @v0 or keep the SHA fresh with Dependabot | View workflow run | Using Kimi K2 (free via Pullfrog for OSS) | 𝕏

@tim-smart
tim-smart enabled auto-merge (squash) August 4, 2026 23:22
@tim-smart
tim-smart merged commit ba2c3aa into main Aug 4, 2026
18 of 19 checks passed
@tim-smart
tim-smart deleted the audit/repro-unstable-http-multipart-filename-collision branch August 4, 2026 23:46
@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Bundle Size Analysis

Generated from PR build output; treat the content below as untrusted.

File Name Current Size Previous Size Difference
basic.ts 7.06 KB 7.06 KB 0.00 KB (0.00%)
batching.ts 9.86 KB 9.86 KB 0.00 KB (0.00%)
brand.ts 6.34 KB 6.34 KB 0.00 KB (0.00%)
cache.ts 10.71 KB 10.71 KB 0.00 KB (0.00%)
config.ts 20.60 KB 20.60 KB 0.00 KB (0.00%)
differ.ts 20.20 KB 20.20 KB 0.00 KB (0.00%)
http-client.ts 21.58 KB 21.54 KB +0.04 KB (+0.18%)
logger.ts 10.84 KB 10.84 KB 0.00 KB (0.00%)
metric.ts 8.98 KB 8.98 KB 0.00 KB (0.00%)
optic.ts 7.18 KB 7.18 KB 0.00 KB (0.00%)
pubsub.ts 14.99 KB 14.99 KB 0.00 KB (0.00%)
queue.ts 11.66 KB 11.66 KB 0.00 KB (0.00%)
schedule.ts 10.83 KB 10.83 KB 0.00 KB (0.00%)
schema-class.ts 19.14 KB 19.14 KB 0.00 KB (0.00%)
schema-fromJsonSchemaDocument.ts 28.96 KB 28.96 KB 0.00 KB (0.00%)
schema-representation-roundtrip.ts 25.29 KB 25.29 KB 0.00 KB (0.00%)
schema-string-transformation.ts 13.38 KB 13.38 KB 0.00 KB (0.00%)
schema-string.ts 10.94 KB 10.94 KB 0.00 KB (0.00%)
schema-template-literal.ts 15.17 KB 15.17 KB 0.00 KB (0.00%)
schema-toArbitraryLazy.ts 21.94 KB 21.94 KB 0.00 KB (0.00%)
schema-toCodeDocument.ts 24.34 KB 24.34 KB 0.00 KB (0.00%)
schema-toCodecJson.ts 19.18 KB 19.18 KB 0.00 KB (0.00%)
schema-toEquivalence.ts 19.01 KB 19.01 KB 0.00 KB (0.00%)
schema-toFormatter.ts 18.87 KB 18.87 KB 0.00 KB (0.00%)
schema-toJsonSchemaDocument.ts 22.60 KB 22.60 KB 0.00 KB (0.00%)
schema-toRepresentation.ts 19.52 KB 19.52 KB 0.00 KB (0.00%)
schema.ts 18.41 KB 18.41 KB 0.00 KB (0.00%)
stm.ts 12.63 KB 12.63 KB 0.00 KB (0.00%)
stream.ts 9.80 KB 9.80 KB 0.00 KB (0.00%)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

4.0 audit Findings originating from the Effect runtime correctness audit bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants