python / python/cpython

Wrong extract version set in local headers for files located beyond zip64 limit

Ouverte
#121,171 6 commentaires 0 réactions 0 personnes assignées Voir sur GitHub

Personne n'a encore pris cette issue.

stdlib type-bug
Langage dominant
Python
Étoiles
77.2k
Forks
35.9k
Métriques de merge des PR
Métriques de PR en attente

Description

Bug report

Bug description:

When creating a zip file which contains a file large enough to push additional files beyond the ZIP64_LIMIT, the extract version is correctly incremented to 4.5 in the Central Header, but not in the Local Header. This mismatch is usually ignored, but more picky implementations fail when validating the zip file.

When the Local Header is being generated, the extract version that is used does not account for the fact that if the header is located farther than the ZIP64_LIMIT, the ZIP64_VERSION is needed since to reference the header offset the Central Header needs to store the offset in the Extra Bits.

Repro

Create a directory with a file over the ZIP64_LIMIT and a file after it, then zip the directory:

>tree source_dir/ -h
source_dir/
├── [4.7G]  5_gig_file.dat
└── [ 229]  t
# Zip the test directory
out_file = "outputs/test.zip"
source_dir = "source_dir"

with zipfile.ZipFile(out_file, "w") as zipf:
    for root, _dirs, files in os.walk(source_dir):
        for file in files:
            file_path = os.path.join(root, file)
            arc_path = pathlib.Path(file_path).relative_to(source_dir)
            zipf.write(file_path, arcname=arc_path)

print(f"generated {out_file}")

Using zipdetails we can see the extract_version in the local header does not match the central header:

> zipdetails outputs/test.zip

...

12A05F240 LOCAL HEADER #2       04034B50
12A05F244 Extract Zip Spec      14 '2.0'
12A05F245 Extract OS            00 'MS-DOS'
12A05F246 General Purpose Flag  0000
12A05F248 Compression Method    0000 'Stored'
12A05F24A Last Mod Time         58DCB5CE 'Fri Jun 28 22:46:28 2024'
12A05F24E CRC                   BB63C172
12A05F252 Compressed Length     000000E5
12A05F256 Uncompressed Length   000000E5
12A05F25A Filename Length       0008
12A05F25C Extra Length          0000
12A05F25E Filename              'test.TXT'
...

12A05F39B CENTRAL HEADER #2     02014B50
12A05F39F Created Zip Spec      2D '4.5'
12A05F3A0 Created OS            00 'MS-DOS'
12A05F3A1 Extract Zip Spec      2D '4.5'
12A05F3A2 Extract OS            00 'MS-DOS'
12A05F3A3 General Purpose Flag  0000
12A05F3A5 Compression Method    0000 'Stored'
12A05F3A7 Last Mod Time         58DCB5CE 'Fri Jun 28 22:46:28 2024'
12A05F3AB CRC                   BB63C172
12A05F3AF Compressed Length     000000E5
12A05F3B3 Uncompressed Length   000000E5
12A05F3B7 Filename Length       0008
12A05F3B9 Extra Length          000C
12A05F3BB Comment Length        0000
12A05F3BD Disk Start            0000
12A05F3BF Int File Attributes   0000
          [Bit 0]               0 'Binary Data'
12A05F3C1 Ext File Attributes   81B60000
12A05F3C5 Local Header Offset   FFFFFFFF
12A05F3C9 Filename              'test.TXT'
12A05F3D1 Extra ID #0001        0001 'ZIP64'
12A05F3D3   Length              0008
12A05F3D5   Offset to Central   000000012A05F240
          Dir

12A05F3DD ZIP64 END CENTRAL DIR 06064B50
          RECORD
12A05F3E1 Size of record        000000000000002C
12A05F3E9 Created Zip Spec      2D '4.5'
12A05F3EA Created OS            00 'MS-DOS'
12A05F3EB Extract Zip Spec      2D '4.5'
12A05F3EC Extract OS            00 'MS-DOS'
12A05F3ED Number of this disk   00000000
12A05F3F1 Central Dir Disk no   00000000
12A05F3F5 Entries in this disk  0000000000000002
12A05F3FD Total Entries         0000000000000002
12A05F405 Size of Central Dir   0000000000000092
12A05F40D Offset to Central dir 000000012A05F34B

12A05F415 ZIP64 END CENTRAL DIR 07064B50
          LOCATOR
12A05F419 Central Dir Disk no   00000000
12A05F41D Offset to Central dir 000000012A05F3DD
12A05F425 Total no of Disks     00000001

12A05F429 END CENTRAL HEADER    06054B50
12A05F42D Number of this disk   0000
12A05F42F Central Dir Disk no   0000
12A05F431 Entries in this disk  0002
12A05F433 Total Entries         0002
12A05F435 Size of Central Dir   00000092
12A05F439 Offset to Central Dir FFFFFFFF
12A05F43D Comment Length        0000

The zip -F command also warns about the mismatch:

zip --version
Copyright (c) 1990-2008 Info-ZIP - Type 'zip "-L"' for software license.
This is Zip 3.0 (July 5th 2008), by Info-ZIP.
...
> zip -F outputs/test.zip  --out out2.zip
Fix archive (-F) - assume mostly intact archive
Zip entry offsets do not need adjusting
 copying: 5_gig_file.dat
 copying: test.TXT
        zip warning: Local Version Needed To Extract does not match CD: test.TXT
CPython versions tested on:

3.10, CPython main branch

Operating systems tested on:

Linux, Windows

Linked PRs
  • gh-121177

Guide de contribution

Ouvrir le guide de contribution

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Piste de recherche

Commencez dans le chemin d’écriture d’archives de zipfile.ZipFile et suivez la manière dont la version requise pour l’extraction est choisie pour les en-têtes local et central lorsqu’un offset d’entrée dépasse ZIP64_LIMIT. Reproduisez l’archive avec un fichier dépassant la limite, inspectez-la avec zipdetails et comparez les versions des en-têtes local et central. C’est terminé lorsque les en-têtes concordent et que l’avertissement de zip -F n’apparaît plus.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
python
Domaine
tooling
Type d'issue
Bug
Difficulté
4/5
Temps estimé
3-5 jours
Activité
À l'abandon
Clarté
Plutôt claire
Accessibilité débutants
35/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.