Skip to content

[3.14] gh-157265: tarfile: Honor None result of filter for link fallbacks (GH-157266) - #157307

Merged
StanFromIreland merged 3 commits into
python:3.14from
miss-islington:backport-fb2f0bb-3.14
Oct 1, 2026
Merged

StanFromIreland merged 3 commits into
python:3.14from
miss-islington:backport-fb2f0bb-3.14

Conversation

@miss-islington

@miss-islington miss-islington commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

(cherry picked from commit fb2f0bb)

Co-authored-by: Petr Viktorin encukou@gmail.com
Co-authored-by: Stan Ulbrych stan@python.org

…cks (pythonGH-157266)

(cherry picked from commit fb2f0bb)

Co-authored-by: Petr Viktorin <encukou@gmail.com>
Co-authored-by: Stan Ulbrych <stan@python.org>
pythongh-157266: Adjust test for Windows

On Windows (no symlinks, no hardlinks), the behaviour is
the same as without the fix in pythonGH-157266:
- a/t/dummy is extracted
- b/ is extracted
- c/ is *not* created (the target, a/t, is not in the archive)
- c/escape: c/ is created; escape is skipped (target,
   c/../../link_here, is not in archive)
- c is not recreated as a directory
- boom is not created (target is c/escape, which falls back to
  ..\..\link_here, which does not exist in archive)
@encukou
encukou marked this pull request as ready for review September 15, 2026 12:43
LearningCircuit added a commit to LearningCircuit/local-deep-research that referenced this pull request Sep 25, 2026
- Dockerfile: correct the tarfile CVE comment — the upstream fix is merged
  on CPython main (python/cpython#157266, fb2f0bbc), not the 3.14
  maintenance branch; the 3.14 backport (python/cpython#157307) is open.
- test_cpython_tarfile_backport.py: skip the behavioral test based on
  whether the ambient tarfile actually carries the patch markers, not a
  version check plus two strings every 3.14.x contains; fix the module
  docstring's stale wording.
- test_cpython_tarfile_backport.py: make the source-level test reject the
  variant that captures the first filter result but overwrites it before
  the None check, by asserting on the exact upstream hunk structure
  instead of marker presence plus a call count.
- patch_cpython_tarfile_cve_2026_87910.py: print a clear notice (exit 0)
  when the target's tarfile already contains the fix; extend
  verify_runtime to exercise the accepted fallback-copy path, which the
  existing benign check never enters.
@StanFromIreland
StanFromIreland merged commit a491993 into python:3.14 Oct 1, 2026
49 of 52 checks passed
@miss-islington
miss-islington deleted the backport-fb2f0bb-3.14 branch October 1, 2026 09:39
cvince pushed a commit to capysc/pkgs that referenced this pull request Oct 2, 2026
… fallback) (gominimal#765)

Backport CPython gh-157265 (PSF-2026-40) to 3.14.7 as
0002-gh-157265-tarfile-honor-filter-none-link-fallback.patch. When a hard
link falls back to extracting a copy of its target, makelink_with_filter
called the filter with the link's name and discarded the result, so a
custom filter that rejects a member by returning None was ignored.

Taken from the 3.14 backport PR python/cpython#157307 (cherry-pick of
main fb2f0bbc + the Windows test tweak from #157334); code change is
identical to the merged main commit and 3.13 backport 9c17bace90f8. No
released 3.14.x has it -- drop the patch on the 3.14.8 bump.

Adds a standalone regression test that fails with the fix reverted.

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
jkreileder added a commit to jkreileder/cf-ips-to-hcloud-fw that referenced this pull request Oct 2, 2026
Python 3.14.8 carries the 3.14 backports for nine of the ten CPython CVEs
ignored for 3.14.7, so drop those entries.

Keep CVE-2025-15367: the poplib fix landed only on main (3.15) and was
never backported to 3.14, so its removal condition changes from 3.14.8
to a move to 3.15 or a future 3.14.x backport.

Add CVE-2026-87910 (tarfile link-fallback filter): grype now lists fixes
in 3.12.15, 3.13.16 and 3.15.0, so only-fixed no longer hides it, but the
3.14 backport (python/cpython#157307) merged after v3.14.8 was tagged.
Remove it once the base reaches 3.14.9.

Refs #1412

Signed-off-by: Jürgen Kreileder <jk@blackdown.de>
renovate Bot added a commit to jkreileder/cf-ips-to-hcloud-fw that referenced this pull request Oct 2, 2026
…1517)

* chore(deps): update docker.io/library/python docker tag to v3.14.8

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* ci(grype): update CPython ignores for the 3.14.8 base

Python 3.14.8 carries the 3.14 backports for nine of the ten CPython CVEs
ignored for 3.14.7, so drop those entries.

Keep CVE-2025-15367: the poplib fix landed only on main (3.15) and was
never backported to 3.14, so its removal condition changes from 3.14.8
to a move to 3.15 or a future 3.14.x backport.

Add CVE-2026-87910 (tarfile link-fallback filter): grype now lists fixes
in 3.12.15, 3.13.16 and 3.15.0, so only-fixed no longer hides it, but the
3.14 backport (python/cpython#157307) merged after v3.14.8 was tagged.
Remove it once the base reaches 3.14.9.

Refs #1412

Signed-off-by: Jürgen Kreileder <jk@blackdown.de>

---------

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Signed-off-by: Jürgen Kreileder <jk@blackdown.de>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Jürgen Kreileder <jk@blackdown.de>
benbrasso added a commit to HHS/simpler-grants-pdf-builder that referenced this pull request Oct 2, 2026
## Summary

PR #1014 fails Anchore on the sole remaining finding: `CVE-2026-87910`
in CPython 3.14.8 (`/usr/local/lib/libpython3.14.so.1.0`). Add a
documented temporary safelist entry, following the existing policy for
Python vulnerabilities whose fix is unavailable on the supported runtime
line. This suppresses the finding; it does **not** patch the
vulnerability.

The [3.14 backport](python/cpython#157307)
merged on October 1 after the 3.14.8 release. The [PSF CVE
record](https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/87xxx/CVE-2026-87910.json)
still marks the 3.14 series affected, and the [release
announcement](https://blog.python.org/2026/10/python-31022-31117/) lists
this fix for 3.10–3.13 only. Remove the exception once
`python:3.14-slim` contains the backport and Grype recognizes the fixed
release.


[HHS/simpler-grants-gov#12615](HHS/simpler-grants-gov#12615)
updates urllib3, Amazon Linux packages and frontend dependencies; none
addresses this CPython finding in the Debian-based NOFO image. No
dependency or image changes are needed for this temporary scan-policy
change.

After this PR merges, rebase #1014 onto main to pick up the exception.
The deployment repository maintains a separate `.grype.yml`; its NOFO
deployment scan will need the same exception while the runtime fix
remains unreleased. This PR changes only the PDF Builder repository.

## Test plan

- Reviewed the failed Anchore job on #1014; confirmed this is its only
reported match.
- Grype 0.119.0 successfully loaded `.grype.yml` and recognized the new
ignore entry.
- Pre-commit checks passed, including YAML validation; `git diff
--check` passed.
- Application tests are unchanged and were not run locally for this
scan-configuration-only change. GitHub CI will build and scan the actual
image; no local Docker runtime is available.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants