Sitelet https://github.com/python/cpython/issues/111791
Skip to content

shutil.unpack_archive skips false negatives containing '..' #111791

Description

@sepastian

I tried to extract a ZIP archive which contains a file named somefile..ipynb using shutil.unpack_archive.

This is right, one file inside the archive is named somefile..ipynb, with two dots, likely misspelled.

This leads to a problem, because unpack_archive will skip extracting this file here, because it assumes that the file contains relative path components. The file is missing quietly in the extracted archive.

While skipping the file is different from standard behavior, the assumption that a file with a path containing two dots would be a relative path is also wrong. A relative path component is identified by "../" instead.

I can am going to submit a PR.

Linked PRs

Activity

  1. changed the title [-]Don't skip files containing '..'[/-] [+]shutil.unpack_archive skips false positives containing '..'[/+] on Nov 6, 2023
  2. added
    stdlibStandard Library Python modules in the Lib/ directory
    on Nov 6, 2023
  3. changed the title [-]shutil.unpack_archive skips false positives containing '..'[/-] [+]shutil.unpack_archive skips false negatives containing '..'[/+] on Nov 7, 2023
  4. added a commit that references this issue on Nov 7, 2023
  5. d-walkama commented on Nov 7, 2023

    @d-walkama

    Hi @sepastian, I actually just ran into this bug today. Do you know if it only affects zip files? As a workaround, could I create a .gztar?

  6. sepastian commented on Nov 7, 2023

    @sepastian
    ContributorAuthor

    Hi @d-walkama, I don't know, if using a tar file would fix the issue. Just give it a try.

    I have submitted a PR today, which fixes the issue. You could also wait for that to get merged.

    Or you could just use zipfile.extractll() instead and for the time being, which works as expected.

  7. sepastian commented on Dec 9, 2024

    @sepastian
    ContributorAuthor

    This is a bug in the standard library and it has been sitting here for a year now. What are the next steps, anything I can do to move this forward? Maybe @AlexWaygood knows what to do next?

    This is my first contribution to CPython, so I have no idea if there's anything I can do to make progress here. If there's anything, please let me know, I'm happy to contribute (more)...

  8. someguynamedjosh commented on Aug 8, 2025

    @someguynamedjosh

    I humorously managed to run into this bug with a file that was not misspelled. This soundtrack contains a track titled "66-6 St.", and when the soundtrack is downloaded in its entirety, you then get a .zip archive where one of the files is called "07 - 66-6 St..flac". (For this use case though, it's easy enough to just use zipfile instead.)

  9. sepastian commented on Aug 8, 2025

    @sepastian
    ContributorAuthor

    Thanks @someguynamedjosh !

    Any chance this can get merged into Python @AlexWaygood? This is a bug and the PR has been sitting around for years. Anything I can do to make it happen?

  10. AlexWaygood commented on Aug 8, 2025

    @AlexWaygood
    Member

    I'm afraid I don't really know anything about the internals of the shutil module and haven't got much spare time for CPython development these days!

    You might find this page of the devguide helpful: https://devguide.python.org/getting-started/pull-request-lifecycle/#pull-request-lifecycle. You can also consider posting something on Discourse similar to this: https://discuss.python.org/t/request-for-merge-fix-http-cookies-module-to-support-obsolete-rfc-850-date-format/73944

  11. added
    type-bugAn unexpected behavior, bug, or error
    on Aug 8, 2025
  12. picnixz commented on Aug 8, 2025

    @picnixz
    Member

    I can see how .. inside the name is actually wrongly interpreted. However, considering this may changes an existing (wrong) behavior, I think it's better if we:

    • fix handling of .. in shutil.unpack_archive: we would still skip files that are absolute or relative (so with .startswith(('/', '../')), but we would not delegate to zipfile.
    • in a separate issue and only for the main branch, we could to zipfile. But before that, we will need a separate discussion, likely a DPO one.
  13. serhiy-storchaka commented on May 18, 2026

    @serhiy-storchaka
    Member

    This was fixed in #146591.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    stdlibStandard Library Python modules in the Lib/ directorytype-bugAn unexpected behavior, bug, or error

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions