Repository navigation
{AKS} Fix desktop archive tests for tarfile path normalization - #34172
Open
FumingZhang wants to merge 1 commit into
Open
FumingZhang wants to merge 1 commit into
FumingZhang wants to merge 1 commit into
Conversation
Accept either native rejection or safe normalized extraction for the parent-symlink fixture. Preserve the outside-sentinel check, mandatory compatibility-extractor rejection, and all other unsafe-member checks. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
microsoft-github-policy-service
Bot
requested review from
Yu Chen (jsntcy),
ZelinWang (wangzelin007) and
Yong Zhang (yonzhan)
October 6, 2026 03:53
FumingZhang
marked this pull request as ready for review
October 6, 2026 04:13
Contributor
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The focused test-only change correctly accommodates differing safe tarfile behavior without weakening containment validation.
Review effort: Balanced
Findings: None
What changed in this PR
Updates AKS Desktop archive tests for portable tar path normalization behavior.
Changes:
- Separates the normalization-sensitive symlink case.
- Accepts safe native extraction or rejection while requiring fallback rejection.
- Verifies destination containment and sentinel integrity.
| File | Description |
|---|---|
src/azure-cli/azure/cli/command_modules/acs/tests/latest/test_custom.py |
Adds portable containment coverage for parent-symlink archive paths. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Member
Author
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related command
az aks install-desktop(tests only).Description
Fix the Azure Linux 3.0 RPM test failure in build 357027, also reproduced in build 357207.
The archive test introduced in #34100 expects
FileOperationErrorfor a member nameddir/foo/../../outside, wheredir/foois a symlink to.. Azure Linux'spython3-libs-3.12.14-2.azl3includes the CPython gh-155999 backport, which normalizes..components before resolving symlinks. This member is now safely extracted asoutsideinside the destination, so mandatory rejection is no longer a portable expectation.No production code, CLI behavior, dependency, or pipeline changes.
Testing Guide
From the repository root with the development dependencies installed:
PYTHONPATH=src/azure-cli:src/azure-cli-core:src/azure-cli-testsdk:src/azure-cli-telemetry \ python -m pytest -q \ src/azure-cli/azure/cli/command_modules/acs/tests/latest/test_custom.py \ -k 'aks_install_desktop_archive'Verified locally:
Host Python 3.12.3: 22 passed, 77 subtests passed.
Exact failing Azure Linux image (
mcr.microsoft.com/azurelinux/base/core@sha256:1324a2cf7ed34e5f48a1022816b205782b86c7305651658e611dcd3d30756751) with Python3.12.14-2.azl3: ran the actual pytest tests against workspace source, switching only thetarfilemodule extracted from each shipped RPM:python3-libs-3.12.14-1.azl3python3-libs-3.12.14-2.azl3FileOperationError not raisedin exactly the reported native subcaseMutation check: the new test fails if an extractor overwrites the outside sentinel, and also fails if the compatibility extractor accepts the fixture.
Python compilation, changed-line pycodestyle, and
git diff --checkpass.The local commit/push hooks reported that no activated
azdevenvironment was configured; their wrappers still allowed the operations. No hooks were bypassed. The explicit checks above completed successfully; the fullazdevhook suites were not run locally.Pipeline validation
The full-test PR pipeline can exercise the modified unit tests on Python 3.12 and 3.14. However, the Azure Linux RPM build/test jobs in azure-pipelines.yml explicitly exclude
Build.Reason=PullRequest. Ordinary PR checks therefore do not reproduce that packaging environment.For end-to-end packaging confirmation, manually run
Azure.azure-cli(definition 32) against this PR revision, including the Azure Linux 3.0 AMD64/ARM64 RPM build and test jobs. The local container validation above already reproduces the original failure and verifies the fix in the affected runtime; it is not a claim that the full packaging pipeline has run.History Notes
Internal test-only change; no customer-facing history note.