From 151c6f8e8c62745ad6e9922494bf14de20242c16 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 1 Oct 2026 01:45:53 +0000 Subject: [PATCH 1/2] Bump pyjwt from 2.13.0 to 2.15.0 in /src/azure-cli Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.15.0. - [Release notes](https://github.com/jpadilla/pyjwt/releases) - [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst) - [Commits](https://github.com/jpadilla/pyjwt/compare/2.13.0...2.15.0) --- updated-dependencies: - dependency-name: pyjwt dependency-version: 2.15.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] --- src/azure-cli/requirements.py3.Darwin.txt | 2 +- src/azure-cli/requirements.py3.Linux.txt | 2 +- src/azure-cli/requirements.py3.windows.txt | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/src/azure-cli/requirements.py3.Darwin.txt b/src/azure-cli/requirements.py3.Darwin.txt index ab8c676c17a..804c4e95a28 100644 --- a/src/azure-cli/requirements.py3.Darwin.txt +++ b/src/azure-cli/requirements.py3.Darwin.txt @@ -123,7 +123,7 @@ portalocker==3.2.0 psutil==6.1.0 pycomposefile==0.0.34 PyGithub==1.55 -PyJWT==2.13.0 +PyJWT==2.15.0 PyNaCl==1.6.2 pyOpenSSL==26.2.0 PySocks==1.7.1 diff --git a/src/azure-cli/requirements.py3.Linux.txt b/src/azure-cli/requirements.py3.Linux.txt index 9c0d9958690..520c238c110 100644 --- a/src/azure-cli/requirements.py3.Linux.txt +++ b/src/azure-cli/requirements.py3.Linux.txt @@ -124,7 +124,7 @@ portalocker==3.2.0 psutil==6.1.0 pycomposefile==0.0.34 PyGithub==1.55 -PyJWT==2.13.0 +PyJWT==2.15.0 PyNaCl==1.6.2 pyOpenSSL==26.2.0 PySocks==1.7.1 diff --git a/src/azure-cli/requirements.py3.windows.txt b/src/azure-cli/requirements.py3.windows.txt index b600e67c8ce..091888b2881 100644 --- a/src/azure-cli/requirements.py3.windows.txt +++ b/src/azure-cli/requirements.py3.windows.txt @@ -123,7 +123,7 @@ portalocker==3.2.0 psutil==6.1.0 pycomposefile==0.0.34 PyGithub==1.55 -PyJWT==2.13.0 +PyJWT==2.15.0 pymsalruntime==0.20.6 PyNaCl==1.6.2 pyOpenSSL==26.2.0 From c01d609d633b1847af291d7a7155d176c1315f04 Mon Sep 17 00:00:00 2001 From: Mansoor Sarfraz Date: Tue, 6 Oct 2026 16:10:41 +1100 Subject: [PATCH 2/2] fixed AZL3 failure --- .../azure/cli/command_modules/acs/custom.py | 8 ++------ .../command_modules/acs/tests/latest/test_custom.py | 12 ++++++------ 2 files changed, 8 insertions(+), 12 deletions(-) diff --git a/src/azure-cli/azure/cli/command_modules/acs/custom.py b/src/azure-cli/azure/cli/command_modules/acs/custom.py index 1b00dd20b6d..3f89130acfc 100644 --- a/src/azure-cli/azure/cli/command_modules/acs/custom.py +++ b/src/azure-cli/azure/cli/command_modules/acs/custom.py @@ -2658,7 +2658,7 @@ def redirect_request(self, req, fp, code, msg, headers, newurl): def _extract_aks_desktop_archive_compat(archive, destination): - # Python 3.10.0-3.10.11 and 3.11.0-3.11.3 have no tar extraction filters. + # Keep path validation consistent across Python data-filter implementations. root = os.path.realpath(destination) def contained_path(path): @@ -2746,11 +2746,7 @@ def _extract_aks_desktop_archive(archive_path, destination): # Older data filters resolve these names differently from extraction (CPython gh-149486). if (member.issym() or member.islnk()) and member.name.endswith(('/', '\\')): raise FileOperationError('The AKS Desktop archive contains an unsafe link name.') - # Check each member against the filesystem state left by earlier members. - if getattr(tarfile, 'data_filter', None) is not None: - archive.extractall(destination, filter='data') - else: - _extract_aks_desktop_archive_compat(archive, destination) + _extract_aks_desktop_archive_compat(archive, destination) except (OSError, tarfile.TarError) as ex: raise FileOperationError( 'Failed to extract the AKS Desktop archive ({}).'.format(ex)) diff --git a/src/azure-cli/azure/cli/command_modules/acs/tests/latest/test_custom.py b/src/azure-cli/azure/cli/command_modules/acs/tests/latest/test_custom.py index dc9c0656458..7eeeefc9eec 100644 --- a/src/azure-cli/azure/cli/command_modules/acs/tests/latest/test_custom.py +++ b/src/azure-cli/azure/cli/command_modules/acs/tests/latest/test_custom.py @@ -1316,19 +1316,19 @@ def test_aks_install_desktop_digest_failure_prevents_launch( @contextmanager def _aks_desktop_archive_extractor(self, fallback): - if fallback: - # Match the old API: accepting filter= must fail, and an unfiltered call is never safe. - def legacy_extractall(archive, path='.', members=None, *, numeric_owner=False): - raise AssertionError('The compatibility extractor must not call extractall') + def legacy_extractall(archive, path='.', members=None, *, numeric_owner=False): + raise AssertionError('The compatibility extractor must not call extractall') + if fallback: with mock.patch.object(tarfile, 'data_filter', None, create=True), \ mock.patch.object(tarfile.TarFile, 'extractall', legacy_extractall): yield else: if not hasattr(tarfile, 'data_filter'): self.skipTest('Native tar extraction filters unavailable') - # Exercise pre-3.14 defaults even on newer Python. - with mock.patch.object(tarfile.TarFile, 'extraction_filter', + # Exercise both filter API states; extraction always uses the strict CLI validator. + with mock.patch.object(tarfile.TarFile, 'extractall', legacy_extractall), \ + mock.patch.object(tarfile.TarFile, 'extraction_filter', staticmethod(lambda member, path: member), create=True): yield