Resources · 117
ZIP and TAR archives: extract within a directory and resource budget
Validate paths, links and expanded data before promoting files from an archive.
· 2 min
What this guide helps achieve
- Choose an isolated destination
- Bound actual extraction work
- Promote only a complete validated result
Quick check
- Path policy and isolated working directory.
- Explicit budgets and stop on actual overrun.
- Rejection matrix and complete-promotion evidence.
Step-by-step method
- 01
Choose an isolated destination
Extract into a fresh non-public directory with minimal permissions. Reject absolute paths, traversal, links and special files unnecessary for the task. Check resolved destinations and collisions using target filesystem rules, including case. A textual path prefix alone does not establish containment.
Path policy and isolated working directory.
- 02
Bound actual extraction work
Set per-file and aggregate limits for written bytes, entry count, depth, elapsed time and process resources. Do not rely only on compressed or declared size. Reject nested archives unless needed; if allowed, share a global budget across levels. Maintain the library and its extraction filters.
Explicit budgets and stop on actual overrun.
- 03
Promote only a complete validated result
Test a ../ entry, absolute path, link, duplicate and budget overrun. Verify an interruption leaves an unpublishable batch and never replaces existing files. Check output types and contents before promotion; clean the isolated directory through a procedure that verifies its destination.
Rejection matrix and complete-promotion evidence.
Acceptance case to reproduce
Fictional example: these inputs describe no customer or observed result.
View case inputs
{
"compressed_mb": 2,
"expanded_mb": 600,
"aggregate_budget_mb": 100,
"first_files_valid": true,
"expected": "stop_on_actual_overrun_and_do_not_promote"
}Expected decision
Fictional example: a 2 MB compressed archive produces 600 MB against a 100 MB budget. Stop when actual written bytes exceed the limit and keep the batch unpublished even if its first files appear valid.
Python — tarfile extraction filters and further verification
Your acceptance workbook
Record observations against this guide’s criteria. A record is not certification.
The workbook does not save automatically. Export before leaving.
Filters do not limit exports. Actions include issues and unreviewed criteria.
Import replaces current observations after your confirmation.
Management indicators
| Indicator | What it measures | First action |
|---|---|---|
| Observed expanded bytes | Sum of bytes actually written for the batch | Compare with aggregate budget, not ZIP size |
| Rejected batches without publication | Invalid batches without promotion / invalid batches tested | Include mid-extraction failures |
Common pitfalls
Frequently asked questions
Does a small archive or extraction filter guarantee safety?
No. A small archive can expand greatly. Add resource limits, path rules and validation of extracted files to the filters.
Official references
References consulted: . The method and worksheet propose checks to adapt to your context; they do not constitute certification.






