@@ -4010,6 +4010,23 @@ def test_sneaky_hardlink_fallback_deep(self):
40104010 self .expect_file ("a/b/s" , symlink_to = os .path .join ('..' , 'escape' ))
40114011 self .expect_file ("s" , symlink_to = os .path .join ('..' , 'escape' ))
40124012
4013+ @os_helper .skip_unless_hardlink
4014+ def test_sneaky_hardlink_relocation (self ):
4015+ with ArchiveMaker () as arc :
4016+ arc .add ("a/escape" , content = "decoy" )
4017+ arc .add ("a/b/s" , symlink_to = os .path .join (".." , "escape" ))
4018+ arc .add ("s" , hardlink_to = os .path .join ("a" , "b" , "s" ))
4019+
4020+ for filter in 'data' , 'tar' :
4021+ with self .subTest (filter ), self .check_context (arc .open (), filter ):
4022+ self .expect_file ("a/escape" , content = "decoy" )
4023+ if os_helper .can_symlink ():
4024+ self .expect_file ("a/b/s" , symlink_to = os .path .join ('..' , 'escape' ))
4025+ else :
4026+ self .expect_file ("a/b/s" , content = "decoy" )
4027+ self .expect_file ("s" , content = "decoy" )
4028+ self .assertFalse ((self .destdir / "s" ).is_symlink ())
4029+
40134030 def test_exfiltration_via_symlink (self ):
40144031 # (CVE-2025-4138)
40154032 # Test changing symlinks that result in a symlink pointing outside
0 commit comments