Repository navigation
drop setuid/setgid/sticky bits in archive_util zip extraction - #5342
Open
sahvx655-wq wants to merge 1 commit into
Open
sahvx655-wq wants to merge 1 commit into
sahvx655-wq wants to merge 1 commit into
Conversation
Contributor
|
Tick the box to add this pull request to the merge queue (same as
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary of changes
_unpack_zipfile_objhandsinfo.external_attr >> 16straight toos.chmod, so the setuid, setgid and sticky bits an archive records for a member are applied to the extracted file. I went looking after reading #5328, which lists those bits among the tar driver's gaps, and the zip driver has the same one: a member recorded as0o7755came out ofunpack_archiveas-rwsr-sr-t, andWheel.install_as_eggproduced the same mode from a wheel, with no warning or trace logged either time. The wheel path is low severity because that wheel is about to be imported anyway, but a caller using the publicunpack_archiveas a plain extractor under root is left with a setuid-root file of the archive's choosing.Mask the mode to
0o777at thechmodcall, the same maskwheel unpackapplies to this field. That call is the only place an archive-supplied mode becomes a filesystem mode, sounpack_zipfileand the wheel path are both covered, and the read, write and execute bits from #3167 behave as before. Group and other write bits are left alone on purpose sincetest_wheel_modepins a0o777round trip, and tar is untouched because #5337 already moves it onto the data filter; the new test fails on main with mode0o7755and passes with the mask.Pull Request Checklist
newsfragments/.(See documentation for details)