Skip to content

drop setuid/setgid/sticky bits in archive_util zip extraction - #5342

Open
sahvx655-wq wants to merge 1 commit into
pypa:mainfrom
sahvx655-wq:zip-special-mode-bits
Open

sahvx655-wq wants to merge 1 commit into
pypa:mainfrom
sahvx655-wq:zip-special-mode-bits

Conversation

@sahvx655-wq

Copy link
Copy Markdown

Summary of changes

_unpack_zipfile_obj hands info.external_attr >> 16 straight to os.chmod, so the setuid, setgid and sticky bits an archive records for a member are applied to the extracted file. I went looking after reading #5328, which lists those bits among the tar driver's gaps, and the zip driver has the same one: a member recorded as 0o7755 came out of unpack_archive as -rwsr-sr-t, and Wheel.install_as_egg produced the same mode from a wheel, with no warning or trace logged either time. The wheel path is low severity because that wheel is about to be imported anyway, but a caller using the public unpack_archive as a plain extractor under root is left with a setuid-root file of the archive's choosing.

Mask the mode to 0o777 at the chmod call, the same mask wheel unpack applies to this field. That call is the only place an archive-supplied mode becomes a filesystem mode, so unpack_zipfile and the wheel path are both covered, and the read, write and execute bits from #3167 behave as before. Group and other write bits are left alone on purpose since test_wheel_mode pins a 0o777 round trip, and tar is untouched because #5337 already moves it onto the data filter; the new test fails on main with mode 0o7755 and passes with the mask.

Pull Request Checklist

@mergify

mergify Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Tick the box to add this pull request to the merge queue (same as @mergifyio queue).

  • Queue this pull request

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant