Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 2 additions & 6 deletions src/azure-cli/azure/cli/command_modules/acs/custom.py
Original file line number Diff line number Diff line change
Expand Up @@ -2658,7 +2658,7 @@ def redirect_request(self, req, fp, code, msg, headers, newurl):


def _extract_aks_desktop_archive_compat(archive, destination):
# Python 3.10.0-3.10.11 and 3.11.0-3.11.3 have no tar extraction filters.
# Keep path validation consistent across Python data-filter implementations.
root = os.path.realpath(destination)

def contained_path(path):
Expand Down Expand Up @@ -2746,11 +2746,7 @@ def _extract_aks_desktop_archive(archive_path, destination):
# Older data filters resolve these names differently from extraction (CPython gh-149486).
if (member.issym() or member.islnk()) and member.name.endswith(('/', '\\')):
raise FileOperationError('The AKS Desktop archive contains an unsafe link name.')
# Check each member against the filesystem state left by earlier members.
if getattr(tarfile, 'data_filter', None) is not None:
archive.extractall(destination, filter='data')
else:
_extract_aks_desktop_archive_compat(archive, destination)
_extract_aks_desktop_archive_compat(archive, destination)
except (OSError, tarfile.TarError) as ex:
raise FileOperationError(
'Failed to extract the AKS Desktop archive ({}).'.format(ex))
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1316,19 +1316,19 @@ def test_aks_install_desktop_digest_failure_prevents_launch(

@contextmanager
def _aks_desktop_archive_extractor(self, fallback):
if fallback:
# Match the old API: accepting filter= must fail, and an unfiltered call is never safe.
def legacy_extractall(archive, path='.', members=None, *, numeric_owner=False):
raise AssertionError('The compatibility extractor must not call extractall')
def legacy_extractall(archive, path='.', members=None, *, numeric_owner=False):
raise AssertionError('The compatibility extractor must not call extractall')

if fallback:
with mock.patch.object(tarfile, 'data_filter', None, create=True), \
mock.patch.object(tarfile.TarFile, 'extractall', legacy_extractall):
yield
else:
if not hasattr(tarfile, 'data_filter'):
self.skipTest('Native tar extraction filters unavailable')
# Exercise pre-3.14 defaults even on newer Python.
with mock.patch.object(tarfile.TarFile, 'extraction_filter',
# Exercise both filter API states; extraction always uses the strict CLI validator.
with mock.patch.object(tarfile.TarFile, 'extractall', legacy_extractall), \
mock.patch.object(tarfile.TarFile, 'extraction_filter',
staticmethod(lambda member, path: member), create=True):
yield

Expand Down
2 changes: 1 addition & 1 deletion src/azure-cli/requirements.py3.Darwin.txt
Original file line number Diff line number Diff line change
Expand Up @@ -123,7 +123,7 @@ portalocker==3.2.0
psutil==6.1.0
pycomposefile==0.0.34
PyGithub==1.55
PyJWT==2.13.0
PyJWT==2.15.0
PyNaCl==1.6.2
pyOpenSSL==26.2.0
PySocks==1.7.1
Expand Down
2 changes: 1 addition & 1 deletion src/azure-cli/requirements.py3.Linux.txt
Original file line number Diff line number Diff line change
Expand Up @@ -124,7 +124,7 @@ portalocker==3.2.0
psutil==6.1.0
pycomposefile==0.0.34
PyGithub==1.55
PyJWT==2.13.0
PyJWT==2.15.0
PyNaCl==1.6.2
pyOpenSSL==26.2.0
PySocks==1.7.1
Expand Down
2 changes: 1 addition & 1 deletion src/azure-cli/requirements.py3.windows.txt
Original file line number Diff line number Diff line change
Expand Up @@ -123,7 +123,7 @@ portalocker==3.2.0
psutil==6.1.0
pycomposefile==0.0.34
PyGithub==1.55
PyJWT==2.13.0
PyJWT==2.15.0
pymsalruntime==0.20.6
PyNaCl==1.6.2
pyOpenSSL==26.2.0
Expand Down
Loading