ZipInfo filename is mangled when os.sep is not '/'

未關閉
#94,529 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

還沒有人認領這個 Issue。

評估

難度
3/5
預估耗時
1-2 天
新手友好度
45/100
Issue 類型
缺陷
描述清晰度
基本清楚
活躍度
停滯
技術堆疊
python
領域
backend

研究方向

從 Lib/zipfile.py 中第 378-382 行附近所引用的 ZipInfo 檔名轉換開始,並重現回報的 os.sep='.' 範例。完成的標準是:ZipInfo 保留使用 '/' 分隔符的封存檔檔名,不在分隔符不是 '/' 或 '\' 的系統上替換 '.';該內容未指定測試檔名。

由索引模型根據 Issue 內容生成。

描述

OS-unsupported stdlib type-bug

Bug report

The ZipInfo object within ZipFile performs an explicit translation of the filename.

https://github.com/python/cpython/blob/7db1d2eaf367a1073191c80c7baeee41ae1f2f21/Lib/zipfile.py#L378-L382

I believe this is intended to make it easy to use on Windows where you might pass an explicit pathname to the ZipInfo object creation. On Windows the filesystem separator is commonly \ (although it supports / in many cases), so that this foces the the filename attribute to contain a filename in the unix form.
This logic is used whether the ZipInfo object is created manually (usually to add a new file), or when the filename has been taken from an archive that is being extracted.

However, the logic is broken on systems where the os.sep is anything else other than \ or /. On systems where the os.sep is . this means that if you try to create an archive with a file containing a . extension the filename in the archive will be mangled. On such a system, extracting an archive will also mangle the filename.

To demonstrate this, it is possible to do a very simple command line example:

>>> import zipfile
>>> import os
>>> os.sep = '.'
>>> zipfile.ZipInfo('hello.txt')
<ZipInfo filename='hello/txt' file_size=0>

In the real world, this breaks any possibility of using this module on RISC OS where the filesystem separator in os.sep is .. In the current Python 3 on RISC OS, the ZipFile module will always mangle filenames that have standard extensions.

I believe that the intention of the object is that:

  • the filename initialiser on the object and attribute is in unicode format (this has been enforced since Python 3 by the explicit decodes in the archive member reading code).
  • the filename attribute is formed as would be stored in the archive, using / as a directory separator (stated by documentation filename should be the full name of the archive member).
  • the filename initialiser on the object is allowed to be supplied a path name on unix and windows systems, as a convenience (the referenced code will have been relied on by existing software).

As such, I believe the referenced code is broken, and to retain the above assumptions and to allow the handling of zip archives on systems where os.sep is not / or \, the code should instead read:

        if os.sep == "\\" and os.sep in filename:
            filename = filename.replace(os.sep, "/")

This removes the overzealous replacement of os.sep in the creation of the ZipInfo object.

Further problems exist with the from_file method which I shall raise separately.

There are some issues which might be related to this (but this change does not preclude them): https://github.com/python/cpython/issues/90139 and https://github.com/python/cpython/issues/92184.

Your environment

  • CPython versions tested on: Python 3.9, 3.10
  • Operating system and architecture: On OS X, simulating the problem seen on RISC OS.
主要語言
Python
星號
77.2k
分支
36k
平均合併
1 天 9 小時
30 天內合併 PR
558

貢獻指南

開啟貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

python/cpython 的其他 Issue

查看 python/cpython 的全部 Issue

相似的 Issue

更多 Python Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。