tarfile extraction filters raise raw ValueError for Windows drive-relative paths
Nessuno ha ancora preso questa issue.
- Lingua principale
- Python
- Stelle
- 77.2k
- Fork
- 35.9k
- Metriche di merge delle PR
- Metriche PR in attesa
Descrizione
Bug report
Bug description:
tarfile extraction filters raise a raw ValueError on Windows when handling drive-relative member names or link targets such as C:bad.txt.
This looks like an inconsistency in the extraction-filter error handling path. The affected cases are rejected through a raw ValueError from Windows path handling instead of the structured tarfile filter exceptions that similar rejected paths use.
For example, with filter="data" and errorlevel = 0, I expected the invalid member to be skipped/refused and extraction to continue to later members. Instead, extraction aborts with:
ValueError: Paths don't have the same drive
Minimal reproducer:
import io
import os
import tarfile
import tempfile
from pathlib import Path
def add_file(tf, name, data=b"x"):
info = tarfile.TarInfo(name)
info.size = len(data)
tf.addfile(info, io.BytesIO(data))
def build_archive_with_drive_relative_member(path):
with tarfile.open(path, "w") as tf:
add_file(tf, "before.txt", b"before")
add_file(tf, "C:bad.txt", b"bad")
add_file(tf, "after.txt", b"after")
def main():
if os.name != "nt":
print("This reproducer is Windows-specific.")
return 0
with tempfile.TemporaryDirectory() as tmp:
tmp = Path(tmp)
archive_path = tmp / "drive_relative.tar"
extract_dir = tmp / "extract"
extract_dir.mkdir()
build_archive_with_drive_relative_member(archive_path)
try:
with tarfile.open(archive_path, "r") as tf:
tf.errorlevel = 0
tf.extractall(extract_dir, filter="data")
except Exception as exc:
print("exception_type:", type(exc).__name__)
print("exception_message:", str(exc))
print("before_exists:", (extract_dir / "before.txt").exists())
print("after_exists:", (extract_dir / "after.txt").exists())
if __name__ == "__main__":
raise SystemExit(main())
Observed output on Windows:
exception_type: ValueError
exception_message: Paths don't have the same drive
before_exists: True
after_exists: False
Expected behavior:
The drive-relative member should be handled through the normal tarfile extraction-filter exception path, for example OutsideDestinationError, so that errorlevel = 0 can skip/refuse that member and continue extracting later members.
Expected output would be:
before_exists: True
after_exists: True
I also observed the same raw ValueError behavior for drive-relative hardlink and symlink targets under filter="data".
Expected structured exceptions:
Drive-relative member name: OutsideDestinationError
Drive-relative hardlink target: LinkOutsideDestinationError
Drive-relative symlink target: LinkOutsideDestinationError
The issue appears to come from ntpath.commonpath() raising ValueError for incompatible drive/path semantics, and that exception escaping directly instead of being converted into the appropriate tarfile filter exception.
A possible fix would be to treat ValueError from the containment/commonpath check as an outside-destination condition and raise the appropriate structured tarfile exception.
CPython versions tested on:
CPython main branch
Operating systems tested on:
Windows
Linked PRs
- gh-154993
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Direzione di ricerca
Iniziare dai controlli di contenimento del filtro di estrazione di tarfile e dalla gestione di ntpath.commonpath descritti nell’issue; riprodurre i casi su Windows con nomi dei membri e destinazioni dei link come C:bad.txt. Il lavoro è completato quando i casi relativi all’unità usano le eccezioni strutturate di tarfile indicate e errorlevel=0 continua l’estrazione con i membri successivi; notare che il PR collegato gh-154993 è già presente.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- python
- Ambito
- operating-systems
- Tipo di issue
- Bug
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Stato di attività
- Ferma
- Chiarezza
- Specificata chiaramente
- Idoneità per principianti
- 30/100