exporter: sanitize platform IDs in path components - #7022
Open
crazy-max wants to merge 3 commits into
Open
Conversation
tonistiigi
reviewed
Aug 10, 2026
| const platformDir = ".._buildkit-outside" | ||
| payloadPath := "" | ||
| for name, item := range m { | ||
| if item.Header.Typeflag != tar.TypeReg { |
Member
There was a problem hiding this comment.
These skips at least need comments describing what cases they are handling and why we have files in the tar that we can't strictly verify.
tonistiigi
reviewed
Aug 10, 2026
tonistiigi
left a comment
Member
There was a problem hiding this comment.
Doesn't seem to be passing
=== FAIL: client TestIntegration/slice=1-4/TestExportTarPlatformIDSanitized/worker=containerd (1.00s)
client_export_local_test.go:541:
Replace Windows path separators and drive separators when platform IDs are used as local and tar exporter path components. Add a regression test for tar exporter output generated from frontend-controlled platform metadata. Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
Member
Author
Seems to be an fsutil issue actually. The tar exporter passes a I moved the fix to fsutil so root walks work consistently there: tonistiigi/fsutil#275 |
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
crazy-max
force-pushed
the
platform-id-path-sanitize-followup
branch
from
August 11, 2026 09:08
bae2e3f to
7c575a2
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
needs tonistiigi/fsutil#275
This restores the platform ID path sanitization from #6910 after it was reverted in #6935.
The first commit cherry-picks original sanitizer onto the current tree, with the integration test moved into the split client exporter test file. The second commit fixes the regression test by checking that the payload exists under the sanitized platform directory instead of requiring one exact Windows rootfs path.