Skip to content

Commit 029a31e

Browse files
committed
Fall back to an NTFS junction when the symlink escape test can't create a symlink
Windows only lets elevated processes, or any process once Developer Mode is on, create symlinks, so test_safe_join_rejects_symlink_escape errored with WinError 1314 on an ordinary developer machine while passing on the hosted runners (which are both elevated and have Developer Mode enabled). A junction needs no privilege and Path.resolve() follows it the same way, so the containment assertion still runs there instead of being skipped. Fixes #3408
1 parent d639cf7 commit 029a31e

1 file changed

Lines changed: 9 additions & 1 deletion

File tree

‎tests/shared/test_path_security.py‎

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
"""Tests for filesystem path safety primitives."""
22

3+
import sys
34
from pathlib import Path
45

56
import pytest
@@ -142,7 +143,14 @@ def test_safe_join_rejects_symlink_escape(tmp_path: Path):
142143
outside.mkdir()
143144
sandbox = tmp_path / "sandbox"
144145
sandbox.mkdir()
145-
(sandbox / "escape").symlink_to(outside)
146+
try:
147+
(sandbox / "escape").symlink_to(outside)
148+
except OSError as exc: # pragma: lax no cover
149+
if sys.platform != "win32" or exc.winerror != 1314: # ERROR_PRIVILEGE_NOT_HELD; a junction needs no privilege
150+
raise
151+
import _winapi
152+
153+
_winapi.CreateJunction(str(outside), str(sandbox / "escape"))
146154

147155
with pytest.raises(PathEscapeError, match="escapes base"):
148156
safe_join(sandbox, "escape", "secret.txt")

0 commit comments

Comments
 (0)