python / python/cpython

tarfile extraction filters raise raw ValueError for Windows drive-relative paths

Aperta
#154,987 5 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

OS-windows stdlib type-bug
Lingua principale
Python
Stelle
77.2k
Fork
35.9k
Metriche di merge delle PR
Metriche PR in attesa

Descrizione

Bug report

Bug description:

tarfile extraction filters raise a raw ValueError on Windows when handling drive-relative member names or link targets such as C:bad.txt.

This looks like an inconsistency in the extraction-filter error handling path. The affected cases are rejected through a raw ValueError from Windows path handling instead of the structured tarfile filter exceptions that similar rejected paths use.

For example, with filter="data" and errorlevel = 0, I expected the invalid member to be skipped/refused and extraction to continue to later members. Instead, extraction aborts with:

ValueError: Paths don't have the same drive

Minimal reproducer:

import io
import os
import tarfile
import tempfile
from pathlib import Path


def add_file(tf, name, data=b"x"):
    info = tarfile.TarInfo(name)
    info.size = len(data)
    tf.addfile(info, io.BytesIO(data))


def build_archive_with_drive_relative_member(path):
    with tarfile.open(path, "w") as tf:
        add_file(tf, "before.txt", b"before")
        add_file(tf, "C:bad.txt", b"bad")
        add_file(tf, "after.txt", b"after")


def main():
    if os.name != "nt":
        print("This reproducer is Windows-specific.")
        return 0

    with tempfile.TemporaryDirectory() as tmp:
        tmp = Path(tmp)
        archive_path = tmp / "drive_relative.tar"
        extract_dir = tmp / "extract"
        extract_dir.mkdir()

        build_archive_with_drive_relative_member(archive_path)

        try:
            with tarfile.open(archive_path, "r") as tf:
                tf.errorlevel = 0
                tf.extractall(extract_dir, filter="data")
        except Exception as exc:
            print("exception_type:", type(exc).__name__)
            print("exception_message:", str(exc))

        print("before_exists:", (extract_dir / "before.txt").exists())
        print("after_exists:", (extract_dir / "after.txt").exists())


if __name__ == "__main__":
    raise SystemExit(main())

Observed output on Windows:

exception_type: ValueError
exception_message: Paths don't have the same drive
before_exists: True
after_exists: False

Expected behavior:

The drive-relative member should be handled through the normal tarfile extraction-filter exception path, for example OutsideDestinationError, so that errorlevel = 0 can skip/refuse that member and continue extracting later members.

Expected output would be:

before_exists: True
after_exists: True

I also observed the same raw ValueError behavior for drive-relative hardlink and symlink targets under filter="data".

Expected structured exceptions:

Drive-relative member name: OutsideDestinationError
Drive-relative hardlink target: LinkOutsideDestinationError
Drive-relative symlink target: LinkOutsideDestinationError

The issue appears to come from ntpath.commonpath() raising ValueError for incompatible drive/path semantics, and that exception escaping directly instead of being converted into the appropriate tarfile filter exception.

A possible fix would be to treat ValueError from the containment/commonpath check as an outside-destination condition and raise the appropriate structured tarfile exception.

CPython versions tested on:

CPython main branch

Operating systems tested on:

Windows

Linked PRs
  • gh-154993

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Direzione di ricerca

Iniziare dai controlli di contenimento del filtro di estrazione di tarfile e dalla gestione di ntpath.commonpath descritti nell’issue; riprodurre i casi su Windows con nomi dei membri e destinazioni dei link come C:bad.txt. Il lavoro è completato quando i casi relativi all’unità usano le eccezioni strutturate di tarfile indicate e errorlevel=0 continua l’estrazione con i membri successivi; notare che il PR collegato gh-154993 è già presente.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
python
Ambito
operating-systems
Tipo di issue
Bug
Difficoltà
3/5
Tempo stimato
1-2 giorni
Stato di attività
Ferma
Chiarezza
Specificata chiaramente
Idoneità per principianti
30/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.