[3.14] gh-157265: tarfile: Honor None result of filter for link fallbacks (GH-157266) - #157307
Merged
StanFromIreland merged 3 commits intoOct 1, 2026
Merged
Conversation
…cks (pythonGH-157266) (cherry picked from commit fb2f0bb) Co-authored-by: Petr Viktorin <encukou@gmail.com> Co-authored-by: Stan Ulbrych <stan@python.org>
pythongh-157266: Adjust test for Windows On Windows (no symlinks, no hardlinks), the behaviour is the same as without the fix in pythonGH-157266: - a/t/dummy is extracted - b/ is extracted - c/ is *not* created (the target, a/t, is not in the archive) - c/escape: c/ is created; escape is skipped (target, c/../../link_here, is not in archive) - c is not recreated as a directory - boom is not created (target is c/escape, which falls back to ..\..\link_here, which does not exist in archive)
encukou
marked this pull request as ready for review
September 15, 2026 12:43
LearningCircuit
added a commit
to LearningCircuit/local-deep-research
that referenced
this pull request
Sep 25, 2026
- Dockerfile: correct the tarfile CVE comment — the upstream fix is merged on CPython main (python/cpython#157266, fb2f0bbc), not the 3.14 maintenance branch; the 3.14 backport (python/cpython#157307) is open. - test_cpython_tarfile_backport.py: skip the behavioral test based on whether the ambient tarfile actually carries the patch markers, not a version check plus two strings every 3.14.x contains; fix the module docstring's stale wording. - test_cpython_tarfile_backport.py: make the source-level test reject the variant that captures the first filter result but overwrites it before the None check, by asserting on the exact upstream hunk structure instead of marker presence plus a call count. - patch_cpython_tarfile_cve_2026_87910.py: print a clear notice (exit 0) when the target's tarfile already contains the fix; extend verify_runtime to exercise the accepted fallback-copy path, which the existing benign check never enters.
This was referenced Oct 1, 2026
Draft
cvince
pushed a commit
to capysc/pkgs
that referenced
this pull request
Oct 2, 2026
… fallback) (gominimal#765) Backport CPython gh-157265 (PSF-2026-40) to 3.14.7 as 0002-gh-157265-tarfile-honor-filter-none-link-fallback.patch. When a hard link falls back to extracting a copy of its target, makelink_with_filter called the filter with the link's name and discarded the result, so a custom filter that rejects a member by returning None was ignored. Taken from the 3.14 backport PR python/cpython#157307 (cherry-pick of main fb2f0bbc + the Windows test tweak from #157334); code change is identical to the merged main commit and 3.13 backport 9c17bace90f8. No released 3.14.x has it -- drop the patch on the 3.14.8 bump. Adds a standalone regression test that fails with the fix reverted. Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
jkreileder
added a commit
to jkreileder/cf-ips-to-hcloud-fw
that referenced
this pull request
Oct 2, 2026
Python 3.14.8 carries the 3.14 backports for nine of the ten CPython CVEs ignored for 3.14.7, so drop those entries. Keep CVE-2025-15367: the poplib fix landed only on main (3.15) and was never backported to 3.14, so its removal condition changes from 3.14.8 to a move to 3.15 or a future 3.14.x backport. Add CVE-2026-87910 (tarfile link-fallback filter): grype now lists fixes in 3.12.15, 3.13.16 and 3.15.0, so only-fixed no longer hides it, but the 3.14 backport (python/cpython#157307) merged after v3.14.8 was tagged. Remove it once the base reaches 3.14.9. Refs #1412 Signed-off-by: Jürgen Kreileder <jk@blackdown.de>
renovate Bot
added a commit
to jkreileder/cf-ips-to-hcloud-fw
that referenced
this pull request
Oct 2, 2026
…1517) * chore(deps): update docker.io/library/python docker tag to v3.14.8 Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> * ci(grype): update CPython ignores for the 3.14.8 base Python 3.14.8 carries the 3.14 backports for nine of the ten CPython CVEs ignored for 3.14.7, so drop those entries. Keep CVE-2025-15367: the poplib fix landed only on main (3.15) and was never backported to 3.14, so its removal condition changes from 3.14.8 to a move to 3.15 or a future 3.14.x backport. Add CVE-2026-87910 (tarfile link-fallback filter): grype now lists fixes in 3.12.15, 3.13.16 and 3.15.0, so only-fixed no longer hides it, but the 3.14 backport (python/cpython#157307) merged after v3.14.8 was tagged. Remove it once the base reaches 3.14.9. Refs #1412 Signed-off-by: Jürgen Kreileder <jk@blackdown.de> --------- Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Signed-off-by: Jürgen Kreileder <jk@blackdown.de> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: Jürgen Kreileder <jk@blackdown.de>
benbrasso
added a commit
to HHS/simpler-grants-pdf-builder
that referenced
this pull request
Oct 2, 2026
## Summary PR #1014 fails Anchore on the sole remaining finding: `CVE-2026-87910` in CPython 3.14.8 (`/usr/local/lib/libpython3.14.so.1.0`). Add a documented temporary safelist entry, following the existing policy for Python vulnerabilities whose fix is unavailable on the supported runtime line. This suppresses the finding; it does **not** patch the vulnerability. The [3.14 backport](python/cpython#157307) merged on October 1 after the 3.14.8 release. The [PSF CVE record](https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/87xxx/CVE-2026-87910.json) still marks the 3.14 series affected, and the [release announcement](https://blog.python.org/2026/10/python-31022-31117/) lists this fix for 3.10–3.13 only. Remove the exception once `python:3.14-slim` contains the backport and Grype recognizes the fixed release. [HHS/simpler-grants-gov#12615](HHS/simpler-grants-gov#12615) updates urllib3, Amazon Linux packages and frontend dependencies; none addresses this CPython finding in the Debian-based NOFO image. No dependency or image changes are needed for this temporary scan-policy change. After this PR merges, rebase #1014 onto main to pick up the exception. The deployment repository maintains a separate `.grype.yml`; its NOFO deployment scan will need the same exception while the runtime fix remains unreleased. This PR changes only the PDF Builder repository. ## Test plan - Reviewed the failed Anchore job on #1014; confirmed this is its only reported match. - Grype 0.119.0 successfully loaded `.grype.yml` and recognized the new ignore entry. - Pre-commit checks passed, including YAML validation; `git diff --check` passed. - Application tests are unchanged and were not run locally for this scan-configuration-only change. GitHub CI will build and scan the actual image; no local Docker runtime is available.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
(cherry picked from commit fb2f0bb)
Co-authored-by: Petr Viktorin encukou@gmail.com
Co-authored-by: Stan Ulbrych stan@python.org