Skip to content

{AKS} Fix desktop archive tests for tarfile path normalization - #34172

Open
FumingZhang wants to merge 1 commit into
Azure:devfrom
FumingZhang:fix/aks-desktop-archive-normalization-test
Open

FumingZhang wants to merge 1 commit into
Azure:devfrom
FumingZhang:fix/aks-desktop-archive-normalization-test

Conversation

@FumingZhang

@FumingZhang FumingZhang commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Related command

az aks install-desktop (tests only).

Description

Fix the Azure Linux 3.0 RPM test failure in build 357027, also reproduced in build 357207.

The archive test introduced in #34100 expects FileOperationError for a member named dir/foo/../../outside, where dir/foo is a symlink to .. Azure Linux's python3-libs-3.12.14-2.azl3 includes the CPython gh-155999 backport, which normalizes .. components before resolving symlinks. This member is now safely extracted as outside inside the destination, so mandatory rejection is no longer a portable expectation.

  • Move this normalization-sensitive fixture into a dedicated containment test.
  • Accept either rejection or safe native extraction with the expected contents inside the destination.
  • Continue requiring the compatibility extractor to reject the fixture.
  • Always verify that the outside sentinel is unchanged.
  • Leave mandatory rejection checks for the remaining unsafe members intact.

No production code, CLI behavior, dependency, or pipeline changes.

Testing Guide

From the repository root with the development dependencies installed:

PYTHONPATH=src/azure-cli:src/azure-cli-core:src/azure-cli-testsdk:src/azure-cli-telemetry \
  python -m pytest -q \
  src/azure-cli/azure/cli/command_modules/acs/tests/latest/test_custom.py \
  -k 'aks_install_desktop_archive'

Verified locally:

  • Host Python 3.12.3: 22 passed, 77 subtests passed.

  • Exact failing Azure Linux image (mcr.microsoft.com/azurelinux/base/core@sha256:1324a2cf7ed34e5f48a1022816b205782b86c7305651658e611dcd3d30756751) with Python 3.12.14-2.azl3: ran the actual pytest tests against workspace source, switching only the tarfile module extracted from each shipped RPM:

    Library RPM Original unsafe-members test Fixed archive test suite
    python3-libs-3.12.14-1.azl3 26 subtests pass 22 tests / 77 subtests pass
    python3-libs-3.12.14-2.azl3 Reproduces FileOperationError not raised in exactly the reported native subcase 22 tests / 77 subtests pass
  • Mutation check: the new test fails if an extractor overwrites the outside sentinel, and also fails if the compatibility extractor accepts the fixture.

  • Python compilation, changed-line pycodestyle, and git diff --check pass.

The local commit/push hooks reported that no activated azdev environment was configured; their wrappers still allowed the operations. No hooks were bypassed. The explicit checks above completed successfully; the full azdev hook suites were not run locally.

Pipeline validation

The full-test PR pipeline can exercise the modified unit tests on Python 3.12 and 3.14. However, the Azure Linux RPM build/test jobs in azure-pipelines.yml explicitly exclude Build.Reason=PullRequest. Ordinary PR checks therefore do not reproduce that packaging environment.

For end-to-end packaging confirmation, manually run Azure.azure-cli (definition 32) against this PR revision, including the Azure Linux 3.0 AMD64/ARM64 RPM build and test jobs. The local container validation above already reproduces the original failure and verifies the fix in the affected runtime; it is not a claim that the full packaging pipeline has run.

History Notes

Internal test-only change; no customer-facing history note.


  • The PR title and description follow the submitting-pull-requests guidelines.
  • I adhere to the Command Guidelines.
  • I adhere to the Error Handling Guidelines.

Accept either native rejection or safe normalized extraction for the parent-symlink fixture. Preserve the outside-sentinel check, mandatory compatibility-extractor rejection, and all other unsafe-member checks.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused test-only change correctly accommodates differing safe tarfile behavior without weakening containment validation.

Review effort: Balanced
Findings: None

What changed in this PR

Updates AKS Desktop archive tests for portable tar path normalization behavior.

Changes:

  • Separates the normalization-sensitive symlink case.
  • Accepts safe native extraction or rejection while requiring fallback rejection.
  • Verifies destination containment and sentinel integrity.
File Description
src/​azure-cli/​azure/​cli/​command_modules/​acs/​tests/​latest/​test_custom.py Adds portable containment coverage for parent-symlink archive paths.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@FumingZhang

Copy link
Copy Markdown
Member Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants