Sitelet https://github.com/flutter/flutter/pull/193161
Skip to content

[flutter_tools] Revert PR: Extract Windows archives using native tar with PowerShell fallback - #193161

Merged
auto-submit[bot] merged 1 commit into
flutter:masterfrom
elliette:issue-193156
Sep 23, 2026
Merged

auto-submit[bot] merged 1 commit into
flutter:masterfrom
elliette:issue-193156

Conversation

@elliette

Copy link
Copy Markdown
Member

Fixes #193156

This PR reverts commit b138043, which was causing the Flutter -> Packages and Flutter -> DevTools rolls to fail.

Pre-launch Checklist

Text exemption: Revert.

If you need help, consider asking for advice on the #hackers-new channel on Discord.

If this change needs to override an active code freeze, provide a comment explaining why. The code freeze workflow can be overridden by code reviewers. See pinned issues for any active code freezes with guidance.

Note: The Flutter team is currently trialing the use of Gemini Code Assist for GitHub. Comments from the gemini-code-assist bot should not be taken as authoritative feedback from the Flutter team. If you find its comments useful you can update your code accordingly, but if you are unsure or disagree with the feedback, please feel free to wait for a Flutter team member's review for guidance on which automated comments should be addressed.

@elliette
elliette requested a review from a team as a code owner September 22, 2026 16:49
@flutter-dashboard flutter-dashboard Bot added the CICD Run CI/CD label Sep 22, 2026
@elliette
elliette requested review from bkonyi and removed request for a team September 22, 2026 16:49

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request replaces external process calls to tar and PowerShell with the Dart archive package for extracting zip and tar archives on Windows, and introduces path validation to prevent Zip Slip vulnerabilities. Feedback on the changes highlights a regression in application_package.dart, where narrowing the caught exception from Exception to ArchiveException will fail to handle file system and format exceptions, potentially causing the tool to crash.

Comment on lines +48 to 51
} on ArchiveException {
globals.printError('Invalid prebuilt Windows app. Unable to extract from archive.');
return null;
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

Changing the caught exception type from Exception to ArchiveException introduces a regression:\n\n1. globals.os.unzip reads the file using file.readAsBytesSync(), which throws a FileSystemException (an IOException/Exception, not an ArchiveException) if the file is missing or unreadable.\n2. ZipDecoder().decodeBytes() can throw other standard exceptions like FormatException or TypeError on corrupted archives.\n\nBecause of this change, the unit test 'Bad zipped app, unzip throws exception' in application_package_test.dart had to be deleted because it would now crash the tool instead of failing gracefully.\n\nWe should catch Exception instead of ArchiveException to handle all potential I/O and decoding failures gracefully, and restore the deleted unit test.

Suggested change
} on ArchiveException {
globals.printError('Invalid prebuilt Windows app. Unable to extract from archive.');
return null;
}
} on Exception {
globals.printError('Invalid prebuilt Windows app. Unable to extract from archive.');
return null;
}

@Piinks Piinks left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@github-actions github-actions Bot added tool Affects the "flutter" command-line tool. See also t: labels. platform-windows Building on or for Windows specifically a: desktop Running on desktop team-windows Owned by the Windows platform team labels Sep 22, 2026
@elliette elliette added the autosubmit Merge PR when tree becomes green via auto submit App label Sep 22, 2026
@auto-submit auto-submit Bot removed the autosubmit Merge PR when tree becomes green via auto submit App label Sep 22, 2026
@auto-submit

auto-submit Bot commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

autosubmit label was removed for flutter/flutter/193161, because - The status or check suite Google testing has failed. Please fix the issues identified (or deflake) before re-applying this label.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

a: desktop Running on desktop CICD Run CI/CD platform-windows Building on or for Windows specifically team-windows Owned by the Windows platform team tool Affects the "flutter" command-line tool. See also t: labels.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Flutter into Packages roller is failing

2 participants