You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
az storage copy, az storage remove, az storage blob sync, and az storage fs directory copy
Description
Resolve PATH-discovered AzCopy executables to a validated absolute path before version probing or command execution. Executables resolved from the current working directory are rejected, while trusted system installations remain supported and managed installation remains the fallback.
The managed AzCopy location is also normalized to an absolute path. Expected probe, decoding, malformed-output, and invalid-version failures fall back safely to managed installation.
Focused unit tests cover current-directory rejection, absolute system-path reuse, managed-path normalization, operation execution with the selected absolute path, and probe-failure fallback.
Testing Guide
Focused unit tests: 6 passed, 3 subtests passed
Flake8 on changed files: passed
Pylint on changed files: 10.00/10
Pylance syntax validation: passed
git diff --check: passed
History Notes
None. This is internal security hardening with no command-surface change.
Resolve AzCopy to a validated absolute path before probing or running it, reject executables discovered in the current working directory, and add focused regression coverage.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Treat working-directory and path-canonicalization failures as unsafe so AzCopy resolution falls back to the managed installation.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This test exercises only the OSError probe path. The newly added fallback behavior for decode errors, malformed/no-match output, and invalid version strings is untested, even though these are distinct paths in check_version() and _is_supported_version(). Please add cases confirming each result triggers managed installation and is never reused; this is important regression coverage for the security hardening.
Add regression coverage for decoding failures, malformed output, and invalid system AzCopy versions falling back to managed installation.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Addressed the latest Copilot review feedback in 5d35d3a. Added distinct regression cases for UTF-8 decode failure, malformed/no-match output, and invalid version text, each confirming fallback to the managed AzCopy executable. Focused validation now passes 6 tests and 3 subtests; Flake8, Pylint, and diff checks also pass.
The CWD test only exercises the direct resolved path. The new validation also relies on realpath to reject an executable found outside CWD whose symlink target is inside CWD; without coverage, removing that security-critical check would still leave this suite green. Please add a regression case for that bypass scenario, as the analogous ACR validation does in acr/tests/latest/test_acr_docker_path_validation.py:152-165.
This branch has not been deployed
No deployments
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related command
az storage copy,az storage remove,az storage blob sync, andaz storage fs directory copyDescription
Resolve PATH-discovered AzCopy executables to a validated absolute path before version probing or command execution. Executables resolved from the current working directory are rejected, while trusted system installations remain supported and managed installation remains the fallback.
The managed AzCopy location is also normalized to an absolute path. Expected probe, decoding, malformed-output, and invalid-version failures fall back safely to managed installation.
Focused unit tests cover current-directory rejection, absolute system-path reuse, managed-path normalization, operation execution with the selected absolute path, and probe-failure fallback.
Testing Guide
6 passed, 3 subtests passed10.00/10git diff --check: passedHistory Notes
None. This is internal security hardening with no command-surface change.