Repository navigation
shutil.unpack_archive skips false negatives containing '..' #111791
Description
Activity
- changed the title
[-]Don't skip files containing '..'[/-][+]shutil.unpack_archive skips false positives containing '..'[/+]on Nov 6, 2023 - addedstdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directory
on Nov 6, 2023 - changed the title
[-]shutil.unpack_archive skips false positives containing '..'[/-][+]shutil.unpack_archive skips false negatives containing '..'[/+]on Nov 7, 2023 - added a commit that references this issue
on Nov 7, 2023 Hi @sepastian, I actually just ran into this bug today. Do you know if it only affects zip files? As a workaround, could I create a .gztar?
Reacted by Sebastian GassnerHi @d-walkama, I don't know, if using a tar file would fix the issue. Just give it a try.
I have submitted a PR today, which fixes the issue. You could also wait for that to get merged.
Or you could just use zipfile.extractll() instead and for the time being, which works as expected.
This is a bug in the standard library and it has been sitting here for a year now. What are the next steps, anything I can do to move this forward? Maybe @AlexWaygood knows what to do next?
This is my first contribution to CPython, so I have no idea if there's anything I can do to make progress here. If there's anything, please let me know, I'm happy to contribute (more)...
I humorously managed to run into this bug with a file that was not misspelled. This soundtrack contains a track titled "66-6 St.", and when the soundtrack is downloaded in its entirety, you then get a .zip archive where one of the files is called "07 - 66-6 St..flac". (For this use case though, it's easy enough to just use zipfile instead.)
Thanks @someguynamedjosh !
Any chance this can get merged into Python @AlexWaygood? This is a bug and the PR has been sitting around for years. Anything I can do to make it happen?
I'm afraid I don't really know anything about the internals of the shutil module and haven't got much spare time for CPython development these days!
You might find this page of the devguide helpful: https://devguide.python.org/getting-started/pull-request-lifecycle/#pull-request-lifecycle. You can also consider posting something on Discourse similar to this: https://discuss.python.org/t/request-for-merge-fix-http-cookies-module-to-support-obsolete-rfc-850-date-format/73944
- addedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on Aug 8, 2025 I can see how
..inside the name is actually wrongly interpreted. However, considering this may changes an existing (wrong) behavior, I think it's better if we:- fix handling of
..in shutil.unpack_archive: we would still skip files that are absolute or relative (so with.startswith(('/', '../')), but we would not delegate tozipfile. - in a separate issue and only for the
mainbranch, we could tozipfile. But before that, we will need a separate discussion, likely a DPO one.
- fix handling of
This was fixed in #146591.
Metadata
Metadata
Assignees
Labels
Projects
- StatusShow more project fieldsDone
I tried to extract a ZIP archive which contains a file named
somefile..ipynbusingshutil.unpack_archive.This is right, one file inside the archive is named
somefile..ipynb, with two dots, likely misspelled.This leads to a problem, because
unpack_archivewill skip extracting this file here, because it assumes that the file contains relative path components. The file is missing quietly in the extracted archive.While skipping the file is different from standard behavior, the assumption that a file with a path containing two dots would be a relative path is also wrong. A relative path component is identified by "../" instead.
I
canam going to submit a PR.Linked PRs