windows compatibility fixes

This commit is contained in:
2025-10-15 15:23:07 -05:00
committed by Jason Ross
parent 05e0366363
commit e2d8b484fc
3 changed files with 23 additions and 14 deletions
+4 -1
View File
@@ -132,8 +132,11 @@ def ensure_platform_tools_in_user_dir(version_tag: Optional[str] = "latest") ->
# Check for path traversal in zip entries
for info in zf.infolist():
# Normalize the path and ensure it doesn't escape
# Use realpath to resolve any symlinks and get absolute path
normalized = os.path.normpath(os.path.join(tmp_dir, info.filename))
if not normalized.startswith(tmp_dir):
# On Windows, tmp_dir might not have a trailing separator, so add it
tmp_dir_with_sep = tmp_dir if tmp_dir.endswith(os.sep) else tmp_dir + os.sep
if not (normalized.startswith(tmp_dir_with_sep) or normalized == tmp_dir):
raise RuntimeError(f"Zip contains path traversal: {info.filename}")
zf.extractall(tmp_dir)