Skip to content

keep wheel namespace package dirs inside the egg directory - #5340

Open
sahvx655-wq wants to merge 1 commit into
pypa:mainfrom
sahvx655-wq:wheel-nspkg-contain
Open

sahvx655-wq wants to merge 1 commit into
pypa:mainfrom
sahvx655-wq:wheel-nspkg-contain

Conversation

@sahvx655-wq

Copy link
Copy Markdown

Summary of changes

Wheel._fix_namespace_packages reads namespace_packages.txt out of the wheel being installed and builds each directory with os.path.join(destination_eggdir, *mod.split('.')). Nothing checks the entry first, so an absolute name throws away the egg directory, and a drive-qualified one does the same on Windows. I traced it from install_as_egg, which fetch_build_eggs calls for setup_requires. A wheel whose entry was an absolute path under a scratch directory got a directory and an __init__.py created outside the egg on main, with no warning or trace logged. The member names were already contained by GHSA-grgh-hr87-3jpw, but this path comes from metadata and never went through that check. Left as is, an untrusted wheel can drop a file anywhere the installing user can write.

Routing the entry through archive_util._resolve_dest gives it the same absolute, drive, UNC and realpath containment that archive members already get, and it raises UnsafeMember the same way. Doing it where the path is built covers the one caller that matters and keeps dotted names like foo.bar mapping exactly as before. The new test fails on main with DID NOT RAISE UnsafeMember and passes here. The full suite passes when run serially, and ruff is clean.

Pull Request Checklist

Entries in a wheel's namespace_packages.txt were joined onto the egg directory unchecked, so an absolute or drive-qualified entry made install_as_egg create a directory and write __init__.py elsewhere on disk. Resolve each entry through _resolve_dest, which archive members already go through, so such entries raise UnsafeMember.
@mergify

mergify Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Tick the box to add this pull request to the merge queue (same as @mergifyio queue).

  • Queue this pull request

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant