Skip to content

Handle TAR uid/gid values larger than int.MaxValue - #134850

Merged
rzikm merged 5 commits into
dotnet:mainfrom
am11:bug/fix-tar-gnu-uid-overflow
Oct 5, 2026
Merged

rzikm merged 5 commits into
dotnet:mainfrom
am11:bug/fix-tar-gnu-uid-overflow

Conversation

@am11

@am11 am11 commented Sep 29, 2026

Copy link
Copy Markdown
Member

Unix uid_t/gid_t are unsigned. Reading a GNU base-256 or PAX uid/gid
above Int32.MaxValue threw OverflowException. Reinterpret such values
as int without an overflow check, matching what TarWriter already does
for file system ids, and write negative ids back as unsigned in the GNU
header field and PAX extended attributes so they roundtrip.

Fixes #127006

@am11
am11 requested a review from rzikm September 29, 2026 10:34
@dotnet-policy-service dotnet-policy-service Bot added the community-contribution Indicates that the PR has been added by a community member label Sep 29, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @dotnet/area-system-formats-tar
See info in area-owners.md if you want to be subscribed.

@rzikm

rzikm commented Sep 29, 2026

Copy link
Copy Markdown
Member

What happens if id is bigger than uint? is it still okay to truncate it? I am wondering if it would not be better to introduce long variants for the properties

@am11

am11 commented Sep 29, 2026

Copy link
Copy Markdown
Member Author

@rzikm, good point. uid_t/gid_t are 32-bit unsigned on our Unix targets, so anything that doesn't fit in 32 bits can't be a real id. It now throws InvalidDataException instead of truncating.

I'd rather not add long properties here: the real range is uint, so they wouldn't carry more information, and they'd need API review. Happy to open a separate proposal if you think it's worth it.

@rzikm

rzikm commented Sep 29, 2026

Copy link
Copy Markdown
Member

I'd rather not add long properties here: the real range is uint, so they wouldn't carry more information, and they'd need API review. Happy to open a separate proposal if you think it's worth it.

no, if the valid range is 32 bits only, then allowing negative numbers seems like a good compromise.

@am11

am11 commented Sep 30, 2026

Copy link
Copy Markdown
Member Author

SslStream failure is unrelated.

@rzikm rzikm left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks

@rzikm

rzikm commented Sep 30, 2026

Copy link
Copy Markdown
Member

/ba-g SslStream failure is #134925

@tskala-gordic

Copy link
Copy Markdown

Would you consider backporting this fix to .NET 10?

@rzikm

rzikm commented Oct 7, 2026

Copy link
Copy Markdown
Member

Would you consider backporting this fix to .NET 10?

Sure, can you briefly explain your scenario and what impact the issue has for you? Are there some workarounds that you can use?

Having some justification will make it easier to get the backport approved.

@tskala-gordic

Copy link
Copy Markdown

Our CI/CD tooling explores component packages from nuget/npm/github for metainfo/licenses updates. And it fails on one of them

https://registry.npmjs.org/d3-timelines/-/d3-timelines-1.3.1.tgz

It's entry PaxHeader/package/README.md, has a GNU base-256 UID field containing 80 00 00 00 A8 19 40 05 (2,820,227,077). TarReader.GetNextEntry() throws OverflowException while parsing that field into Int32 on .NET 10.0.12. Windows tar (libarchive) successfully reads the archive.

As hotfix we processed it manually and filled it as static information (it's old so it won't change anyway). Hoping future packages won't fail the same way. Using new/alternative tar (NET) unzippers is problematic. We would use external unzipper if necessary. It's not critical but this fix seems to solve it within native NET libraries.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-System.Formats.Tar community-contribution Indicates that the PR has been added by a community member

Projects

None yet

Development

Successfully merging this pull request may close these issues.

System.Formats.Tar — OverflowException on GNU binary-encoded UID/GID

3 participants