AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Windows Prompt-Loading Symlink Tests Fail Without Symlink Privilege

Three security regression tests in langchain-core's prompt loading tests unconditionally create symlinks, causing OSError [WinError 1314] on default Windows environments. This makes the core test suite fail for contributors without elevated privileges or Developer Mode, and the suite has no Windows CI to catch it.

mediumConfidence 95%Langchain

Origin Analysis

The tests call Path.symlink_to() without a platform guard. On Windows, creating symlinks requires Administrator privileges or Developer Mode; otherwise os.symlink raises OSError WinError 1314. The test file lacks any pytest.mark.skipif or try/except fallback, unlike other tests in the repository.
On a non-elevated Windows shell with Developer Mode off: git clone the repository, cd libs/core, uv sync --group test, uv run pytest tests/unit_tests/prompts/test_loading.py. Three tests fail with OSError: [WinError 1314] A required privilege is not held by the client.

Fixing Code Block

def _symlink_or_skip(link, target): try: link.symlink_to(target) except OSError: pytest.skip("Symlink creation not supported") # In test_symlink_txt_to_py_is_blocked, replace symlink.symlink_to(sensitive) with: _symlink_or_skip(symlink, sensitive) # In test_symlink_jinja2_rce_is_blocked, replace symlink.symlink_to(sensitive) with: _symlink_or_skip(symlink, sensitive) # In test_save_symlink_to_py_is_blocked, replace symlink.symlink_to(sensitive) with: _symlink_or_skip(symlink, sensitive)
The helper wraps symlink creation in try/except OSError and skips the test when the platform cannot create symlinks. Replacing the three unguarded calls with the helper makes the tests skip on Windows without privilege while preserving existing behavior on Linux and privileged Windows environments. This matches the pattern already used in libs/langchain_v1/tests/unit_tests/agents/middleware/implementations/test_file_search.py.

Edge Case Audit

The broad except OSError may skip the test if symlink creation fails for reasons other than lack of privilege (e.g., filesystem errors), potentially hiding real regressions in those environments. Consider narrowing to Windows-only WinError 1314 or checking os.name=='nt' and privilege. Rollback: revert this test-only patch if unexpected skips occur on Linux/macOS; no runtime code is changed. Additionally, CI remains Linux-only, so Windows coverage is still missing; adding a Windows CI job is recommended.

Ecosystem Topology