tar.py: Always use extraction filter - #2192
Merged
Merged
Conversation
The `tarfile` extraction filter support from Python 3.12 was backported to older Python releases. However, distro packages of Python < 3.12 may not include that backport. Import the latest upstream version to be able to use extraction filters on all Python versions.
This was introduced in Python 3.14. While it was also backported to older versions, the backport may not be available everywhere.
This aligns the behavior across Python versions, offering some protection from unusual and possibly malicious tar files. On Python versions lower than 3.12, this uses the imported copy of `tarfile.py`.
The `tar` filter catches attempts to extract files outside the destination directory but does not catch hardlink targets outside the destination directory. The `data` filter catches both but doesn't preserve symlinks, which may break, e.g., rootfs tarball extraction. Define a custom extraction filter that uses the `data` filter except for symlinks where the `tar` filter is used. This filter replaces the incomplete checks of `_assert_safe()`, which was invoked before extraction, which meant that the checks may already have been outdated during actual extraction.
Reported-by: Gjoko Krstic <gjoko@zeroscience.mk>
juergbi
requested review from
BenjaminSchubert,
abderrahim,
cs-shadow and
gtristan
as code owners
September 15, 2026 11:18
abderrahim
approved these changes
Sep 15, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Extraction in the tar plugin currently has two code paths. Using extraction filters on Python 3.12+ and relying on custom safety checks on older Python versions. This PR switches to using an extraction filter on all supported Python versions by importing a copy of Python's
tarfile.pyfor use on older Python versions. This allows replacing the custom safety checks with a combination of upstream Python filters that are more widely tested.