summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorPetr Viktorin <encukou@gmail.com>2023-08-23 18:00:07 (GMT)
committerGitHub <noreply@github.com>2023-08-23 18:00:07 (GMT)
commit5d1871576500adc4ebaa7f59b8559605a57ad36b (patch)
tree29abab9a38d23e0f27e520f9319c2d1c18a8bfed
parent72119d16a5f658939809febef29dadeca02cf34d (diff)
downloadcpython-5d1871576500adc4ebaa7f59b8559605a57ad36b.zip
cpython-5d1871576500adc4ebaa7f59b8559605a57ad36b.tar.gz
cpython-5d1871576500adc4ebaa7f59b8559605a57ad36b.tar.bz2
gh-107811: tarfile: treat overflow in UID/GID as failure to set it (#108369)
-rwxr-xr-xLib/tarfile.py3
-rw-r--r--Misc/NEWS.d/next/Library/2023-08-23-17-34-39.gh-issue-107811.3Fng72.rst3
2 files changed, 5 insertions, 1 deletions
diff --git a/Lib/tarfile.py b/Lib/tarfile.py
index a835d00..726f9f5 100755
--- a/Lib/tarfile.py
+++ b/Lib/tarfile.py
@@ -2557,7 +2557,8 @@ class TarFile(object):
os.lchown(targetpath, u, g)
else:
os.chown(targetpath, u, g)
- except OSError as e:
+ except (OSError, OverflowError) as e:
+ # OverflowError can be raised if an ID doesn't fit in `id_t`
raise ExtractError("could not change owner") from e
def chmod(self, tarinfo, targetpath):
diff --git a/Misc/NEWS.d/next/Library/2023-08-23-17-34-39.gh-issue-107811.3Fng72.rst b/Misc/NEWS.d/next/Library/2023-08-23-17-34-39.gh-issue-107811.3Fng72.rst
new file mode 100644
index 0000000..ffca413
--- /dev/null
+++ b/Misc/NEWS.d/next/Library/2023-08-23-17-34-39.gh-issue-107811.3Fng72.rst
@@ -0,0 +1,3 @@
+:mod:`tarfile`: extraction of members with overly large UID or GID (e.g. on
+an OS with 32-bit :c:type:`!id_t`) now fails in the same way as failing to
+set the ID.