Skip to content

Fix deleteQuietly handling for symlinked directories - #873

Open
Sn0wyDay wants to merge 3 commits into
apache:masterfrom
Sn0wyDay:fix-deletequietly-symlink-directory
Open

Sn0wyDay wants to merge 3 commits into
apache:masterfrom
Sn0wyDay:fix-deletequietly-symlink-directory

Conversation

@Sn0wyDay

@Sn0wyDay Sn0wyDay commented Aug 24, 2026

Copy link
Copy Markdown

Thanks for your contribution to Apache Commons! Your help is appreciated!

Before you push a pull request, review this list:

  • Read the contribution guidelines for this project.
  • Read the ASF Generative Tooling Guidance if you use Artificial Intelligence (AI).
  • I used AI to create any part of, or all of, this pull request. Which AI tool was used to create this pull request, and to what extent did it contribute?
  • Run a successful build using the default Maven goal with mvn; that's mvn on the command line by itself.
  • Write unit tests that match behavioral changes, where the tests fail if the changes to the runtime are not applied. This may not always be possible, but it is a best practice.
  • Write a pull request description that is detailed enough to understand what the pull request does, how, and why.
  • Each commit in the pull request should have a meaningful subject line and body. Note that a maintainer may squash commits during the merge process.

Summary

This PR updates FileUtils.deleteQuietly(File) so that it does not clean the target contents when the input is a symbolic link to a directory.

Previously, deleteQuietly() checked file.isDirectory() and then called cleanDirectory(file) before deleting the file. On platforms where a symbolic link to a directory is treated as a directory, this could remove the contents of the symlink target before deleting the symlink itself.

deleteDirectory() already avoids this behavior by checking !isSymlink(directory) before cleaning directory contents. This PR applies the same safety check to deleteQuietly() for consistency.

Change

Before:

if (file.isDirectory()) {
    cleanDirectory(file);
}

After:

if (file.isDirectory() && !isSymlink(file)) {
    cleanDirectory(file);
}

Tests

Added a regression test that verifies all of the following:

  • the symbolic-link directory entry itself is removed;
  • the target directory still exists;
  • the file inside the target directory is preserved.

The link assertion uses Files.exists(path, LinkOption.NOFOLLOW_LINKS) so it checks the link entry rather than following the link to its target.

Validation completed with Eclipse Temurin JDK 25:

mvn -Dtest=FileUtilsCleanSymlinksTest test
mvn

The default Maven build passed with 6,616 tests run, 0 failures, and 0 errors. Checkstyle, SpotBugs, PMD, license, coverage, and Javadoc checks also passed.

AI tooling disclosure

An OpenAI coding assistant helped identify the candidate, refine the regression-test assertion, investigate the CI failure, and draft the initial explanation. The final code and tests were manually reviewed and validated with the commands listed above.

안민기 added 3 commits August 24, 2026 22:16
Check the directory entry with NOFOLLOW_LINKS so the test verifies that deleteQuietly removes the symlink itself while preserving its target.
@Sn0wyDay

Copy link
Copy Markdown
Author

This PR is ready for review. The remaining GitHub Actions workflows are awaiting maintainer approval; could a maintainer please approve them when convenient? Thank you.

@garydgregory

Copy link
Copy Markdown
Member

This is in my queue, I should be able to get to it this week.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants