fix(datasets): reject link and traversal members before tar extraction - #9593
fix(datasets): reject link and traversal members before tar extraction#9593erensh27 wants to merge 1 commit into
Conversation
tar.extractall() follows symlink/hardlink members and honors '..' segments, so a malicious archive extracted via download_and_extract_ archive() / extract_archive() could write outside the destination directory (see pytorch#9517). _extract_tar now rejects, before extracting, any member that is a symlink, hardlink, or device file, has an absolute path, or contains a '..' segment. The safe-subset validation mirrors tarfile.data_filter (PEP 706) but stays portable across supported Python versions. Adds regression tests for link, traversal, and absolute-path members.
🔗 Helpful Links🧪 See artifacts and rendered test results at hud.pytorch.org/pr/pytorch/vision/9593
Note: Links to docs will display an error until the docs builds have been completed. This comment was automatically generated by Dr. CI and updates every 15 minutes. |
|
Hi @erensh27! Thank you for your pull request and welcome to our community. Action RequiredIn order to merge any pull request (code, docs, etc.), we require contributors to sign our Contributor License Agreement, and we don't seem to have one on file for you. ProcessIn order for us to review and merge your suggested changes, please sign at https://code.facebook.com/cla. If you are contributing on behalf of someone else (eg your employer), the individual CLA may not be sufficient and your employer may need to sign the corporate CLA. Once the CLA is signed, our tooling will perform checks and validations. Afterwards, the pull request will be tagged with If you have received this in error or have any questions, please contact us at cla@meta.com. Thanks! |
|
Thank you for signing our Contributor License Agreement. We can now accept your code for this (and any) Meta Open Source project. Thanks! |
Security fix for #9517:
extract_archive/download_and_extract_archiveexposed untrusted tar archives totar.extractall, which follows symlink/hardlink members and allows..traversal to escape the destination.torchvision/datasets/utils.py—_extract_tarnow validates every member before extraction and raisesRuntimeErrorfor:..segmentThe safe-subset validation mirrors
tarfile.data_filter(PEP 706) but remains portable to all supported Python versions.zip.extractallis left unchanged: zipfile has built-in traversal sanitization on all supported Pythons.Tests —
test/test_datasets_utils.py: crafted archives with a symlink member, a../escape.txtmember, and a/absolute.txtmember are rejected, and nothing is written outside the destination. Logged-can't-run note: tests require a full torch env; the test module compiles.