Skip to content

{AKS} Fix desktop archive tests for tarfile path normalization - #34172

Open
FumingZhang wants to merge 2 commits into
Azure:devfrom
FumingZhang:fix/aks-desktop-archive-normalization-test
Open

FumingZhang wants to merge 2 commits into
Azure:devfrom
FumingZhang:fix/aks-desktop-archive-normalization-test

Conversation

@FumingZhang

@FumingZhang FumingZhang commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Related command

az aks install-desktop (tests only).

Description

Fix the current Azure Linux 3.0 RPM test failure in build 357861, on both AMD64 and ARM64. Merge current dev (7e73b31a0150df02975d120ea57ffa585834ad07) and resolve the overlapping archive-test changes.

This PR originally addressed the normalization-sensitive test introduced in #34100. Since then:

Update that existing upstream test to match the current implementation:

  • Require the path-containment FileOperationError regardless of the available tarfile.data_filter behavior.
  • Verify that no normalized output file was created inside the destination.
  • Always verify that the outside sentinel is unchanged.
  • Preserve upstream's stricter dir/foo/../../../outside fixture and all other rejection checks.

The net diff against current dev is one test file: 3 insertions and 7 deletions. No production code, CLI behavior, dependency, or pipeline changes beyond those inherited from dev.

Testing Guide

From the repository root with the development dependencies installed:

PYTHONPATH=src/azure-cli:src/azure-cli-core:src/azure-cli-testsdk:src/azure-cli-telemetry \
  python -m pytest -q \
  src/azure-cli/azure/cli/command_modules/acs/tests/latest/test_custom.py \
  -k 'aks_install_desktop_archive'

Verified locally:

  • Host Python 3.12.3: 22 passed, 79 subtests passed.

  • Exact image from the current failing build (mcr.microsoft.com/azurelinux/base/core@sha256:bfd3e44899fe7c17f6fda42a6ef2a322f2178c2dafb88e69fd87675cdcac39ec) with Python 3.12.15-1.azl3: ran the actual pytest tests against the current strict CLI implementation, using the installed tarfile and then each earlier RPM's extracted module:

    Library RPM Current dev archive suite Resolved PR archive suite
    python3-libs-3.12.14-1.azl3 Passes 22 tests / 79 subtests pass
    python3-libs-3.12.14-2.azl3 Reproduces the normalized-traversal subtest failure 22 tests / 79 subtests pass
    python3-libs-3.12.15-1.azl3 (installed) Reproduces the exact failure from build 357861 22 tests / 79 subtests pass
  • Mutation check: the updated test fails if extraction silently accepts the fixture, in both filter API states.

  • Python compilation, changed-line pycodestyle, and git diff --check pass.

The local commit/push hooks reported that no activated azdev environment was configured; their wrappers still allowed the operations. No hooks were bypassed. The explicit checks above completed successfully; the full azdev hook suites were not run locally.

Pipeline validation

The full-test PR pipeline can exercise the modified unit tests on Python 3.12 and 3.14. However, the Azure Linux RPM build/test jobs in azure-pipelines.yml explicitly exclude Build.Reason=PullRequest. Ordinary PR checks therefore do not reproduce that packaging environment.

For end-to-end packaging confirmation, manually run Azure.azure-cli (definition 32) against this PR revision, including the Azure Linux 3.0 AMD64/ARM64 RPM build and test jobs. The local container validation above reproduces the current upstream failure and verifies the fix in the affected runtime; it is not a claim that the full packaging pipeline has run.

History Notes

Internal test-only change; no customer-facing history note.


  • The PR title and description follow the submitting-pull-requests guidelines.
  • I adhere to the Command Guidelines.
  • I adhere to the Error Handling Guidelines.

Accept either native rejection or safe normalized extraction for the parent-symlink fixture. Preserve the outside-sentinel check, mandatory compatibility-extractor rejection, and all other unsafe-member checks.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused test-only change correctly accommodates differing safe tarfile behavior without weakening containment validation.

Review effort: Balanced
Findings: None

What changed in this PR

Updates AKS Desktop archive tests for portable tar path normalization behavior.

Changes:

  • Separates the normalization-sensitive symlink case.
  • Accepts safe native extraction or rejection while requiring fallback rejection.
  • Verifies destination containment and sentinel integrity.
File Description
src/​azure-cli/​azure/​cli/​command_modules/​acs/​tests/​latest/​test_custom.py Adds portable containment coverage for parent-symlink archive paths.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@FumingZhang

Copy link
Copy Markdown
Member Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).

Resolve the overlapping normalization fixture while preserving the upstream compatibility extractor and stricter unsafe-member case. Require the containment error for both filter API states and verify neither inside output nor the outside sentinel is changed.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants