diff --git a/src/azure-cli/azure/cli/command_modules/acs/custom.py b/src/azure-cli/azure/cli/command_modules/acs/custom.py index 1b00dd20b6d..3f89130acfc 100644 --- a/src/azure-cli/azure/cli/command_modules/acs/custom.py +++ b/src/azure-cli/azure/cli/command_modules/acs/custom.py @@ -2658,7 +2658,7 @@ def redirect_request(self, req, fp, code, msg, headers, newurl): def _extract_aks_desktop_archive_compat(archive, destination): - # Python 3.10.0-3.10.11 and 3.11.0-3.11.3 have no tar extraction filters. + # Keep path validation consistent across Python data-filter implementations. root = os.path.realpath(destination) def contained_path(path): @@ -2746,11 +2746,7 @@ def _extract_aks_desktop_archive(archive_path, destination): # Older data filters resolve these names differently from extraction (CPython gh-149486). if (member.issym() or member.islnk()) and member.name.endswith(('/', '\\')): raise FileOperationError('The AKS Desktop archive contains an unsafe link name.') - # Check each member against the filesystem state left by earlier members. - if getattr(tarfile, 'data_filter', None) is not None: - archive.extractall(destination, filter='data') - else: - _extract_aks_desktop_archive_compat(archive, destination) + _extract_aks_desktop_archive_compat(archive, destination) except (OSError, tarfile.TarError) as ex: raise FileOperationError( 'Failed to extract the AKS Desktop archive ({}).'.format(ex)) diff --git a/src/azure-cli/azure/cli/command_modules/acs/tests/latest/test_custom.py b/src/azure-cli/azure/cli/command_modules/acs/tests/latest/test_custom.py index dc9c0656458..7eeeefc9eec 100644 --- a/src/azure-cli/azure/cli/command_modules/acs/tests/latest/test_custom.py +++ b/src/azure-cli/azure/cli/command_modules/acs/tests/latest/test_custom.py @@ -1316,19 +1316,19 @@ def test_aks_install_desktop_digest_failure_prevents_launch( @contextmanager def _aks_desktop_archive_extractor(self, fallback): - if fallback: - # Match the old API: accepting filter= must fail, and an unfiltered call is never safe. - def legacy_extractall(archive, path='.', members=None, *, numeric_owner=False): - raise AssertionError('The compatibility extractor must not call extractall') + def legacy_extractall(archive, path='.', members=None, *, numeric_owner=False): + raise AssertionError('The compatibility extractor must not call extractall') + if fallback: with mock.patch.object(tarfile, 'data_filter', None, create=True), \ mock.patch.object(tarfile.TarFile, 'extractall', legacy_extractall): yield else: if not hasattr(tarfile, 'data_filter'): self.skipTest('Native tar extraction filters unavailable') - # Exercise pre-3.14 defaults even on newer Python. - with mock.patch.object(tarfile.TarFile, 'extraction_filter', + # Exercise both filter API states; extraction always uses the strict CLI validator. + with mock.patch.object(tarfile.TarFile, 'extractall', legacy_extractall), \ + mock.patch.object(tarfile.TarFile, 'extraction_filter', staticmethod(lambda member, path: member), create=True): yield diff --git a/src/azure-cli/requirements.py3.Darwin.txt b/src/azure-cli/requirements.py3.Darwin.txt index ab8c676c17a..804c4e95a28 100644 --- a/src/azure-cli/requirements.py3.Darwin.txt +++ b/src/azure-cli/requirements.py3.Darwin.txt @@ -123,7 +123,7 @@ portalocker==3.2.0 psutil==6.1.0 pycomposefile==0.0.34 PyGithub==1.55 -PyJWT==2.13.0 +PyJWT==2.15.0 PyNaCl==1.6.2 pyOpenSSL==26.2.0 PySocks==1.7.1 diff --git a/src/azure-cli/requirements.py3.Linux.txt b/src/azure-cli/requirements.py3.Linux.txt index 9c0d9958690..520c238c110 100644 --- a/src/azure-cli/requirements.py3.Linux.txt +++ b/src/azure-cli/requirements.py3.Linux.txt @@ -124,7 +124,7 @@ portalocker==3.2.0 psutil==6.1.0 pycomposefile==0.0.34 PyGithub==1.55 -PyJWT==2.13.0 +PyJWT==2.15.0 PyNaCl==1.6.2 pyOpenSSL==26.2.0 PySocks==1.7.1 diff --git a/src/azure-cli/requirements.py3.windows.txt b/src/azure-cli/requirements.py3.windows.txt index b600e67c8ce..091888b2881 100644 --- a/src/azure-cli/requirements.py3.windows.txt +++ b/src/azure-cli/requirements.py3.windows.txt @@ -123,7 +123,7 @@ portalocker==3.2.0 psutil==6.1.0 pycomposefile==0.0.34 PyGithub==1.55 -PyJWT==2.13.0 +PyJWT==2.15.0 pymsalruntime==0.20.6 PyNaCl==1.6.2 pyOpenSSL==26.2.0