From 688d39eb9b73bfffcca9d882e08b916105eea9e9 Mon Sep 17 00:00:00 2001 From: Xiao Yuan <47032563+yuanx749@users.noreply.github.com> Date: Tue, 8 Sep 2026 09:15:28 +0300 Subject: [PATCH] gh-127636: Fix tarfile extracting trailing slash member names (GH-152984) Fixes tarfile.TarFile.extract to accept archive member names with a trailing forward slash, including those returned by tarfile.TarFile.getnames very old style tar files may have these. new archivers likely do not do this. (cherry picked from commit 7a562c474c6885b1d6f3ac74962bb920483bfbe1) Co-authored-by: Xiao Yuan <47032563+yuanx749@users.noreply.github.com> --- Lib/tarfile.py | 4 +++- Lib/test/test_tarfile.py | 13 +++++++++++++ .../2026-07-04-00-19-23.gh-issue-127636.o_uD9U.rst | 3 +++ 3 files changed, 19 insertions(+), 1 deletion(-) create mode 100644 Misc/NEWS.d/next/Library/2026-07-04-00-19-23.gh-issue-127636.o_uD9U.rst diff --git a/Lib/tarfile.py b/Lib/tarfile.py index 3c59eac5d9a0f11..8f5573cba3cd17e 100755 --- a/Lib/tarfile.py +++ b/Lib/tarfile.py @@ -2127,7 +2127,9 @@ def getmember(self, name): than once in the archive, its last occurrence is assumed to be the most up-to-date version. """ - tarinfo = self._getmember(name.rstrip('/')) + tarinfo = self._getmember(name) + if tarinfo is None and name.endswith('/'): + tarinfo = self._getmember(name.rstrip('/')) if tarinfo is None: raise KeyError("filename %r not found" % name) return tarinfo diff --git a/Lib/test/test_tarfile.py b/Lib/test/test_tarfile.py index 86fe8efac2e3495..fbb0a3cd8fb003a 100644 --- a/Lib/test/test_tarfile.py +++ b/Lib/test/test_tarfile.py @@ -242,6 +242,19 @@ def test_add_dir_getmember(self): self.add_dir_and_getmember('bar') self.add_dir_and_getmember('a'*101) + def test_extract_name_with_trailing_slash(self): + # gh-127636: './mydir/' is deliberately a regular-file member + # (REGTYPE, not DIRTYPE) whose stored name ends in a slash. It + # extracts as a file. Do not "fix" this by setting DIRTYPE; the + # trailing-slash name on a non-directory is what is being tested. + with tarfile.open(tmpname, 'w') as tar: + tar.addfile(tarfile.TarInfo('./mydir/')) + with os_helper.temp_dir() as tmpdir, tarfile.open(tmpname) as tar: + names = tar.getnames() + self.assertEqual(names, ['./mydir/']) + tar.extract(names[0], tmpdir, filter='fully_trusted') + self.assertTrue(os.path.isfile(os.path.join(tmpdir, 'mydir'))) + @unittest.skipUnless(hasattr(os, "getuid") and hasattr(os, "getgid"), "Missing getuid or getgid implementation") def add_dir_and_getmember(self, name): diff --git a/Misc/NEWS.d/next/Library/2026-07-04-00-19-23.gh-issue-127636.o_uD9U.rst b/Misc/NEWS.d/next/Library/2026-07-04-00-19-23.gh-issue-127636.o_uD9U.rst new file mode 100644 index 000000000000000..51957a73b5603b2 --- /dev/null +++ b/Misc/NEWS.d/next/Library/2026-07-04-00-19-23.gh-issue-127636.o_uD9U.rst @@ -0,0 +1,3 @@ +Fix :meth:`tarfile.TarFile.extract` to accept archive member names with a +trailing forward slash, including those returned by +:meth:`tarfile.TarFile.getnames`. Contributed by Xiao Yuan.