Repository navigation
import-tar: convert GNU tar PAX ACLs, exact PAX ns timestamps - #10499
Merged
Merged
Conversation
GNU tar (--format=posix --acls) writes named ACL entries without the numeric uid/gid, e.g. "user:nobody:rw-". import-tar stored the text unchanged, but borg's ACL format has the id as a 4th field, so borg extract crashed in acl_use_local_uid_gid with an IndexError. Named entries without an id now get it from a local user/group name lookup (falling back to the name, like borg create does). Comma separated entries (as star writes them) and comments are handled, too. system.posix_acl_* xattrs (GNU tar --xattrs-include='*') are skipped, like borg create does, because the ACLs are stored separately. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
export-tar wrote the atime/ctime/mtime PAX headers via str(ns / 1e9) and import-tar parsed them via float(s) * 1e9. A float has ~240 ns resolution at today's epoch, so the "ns" timestamps of --tar-format=PAX did not roundtrip exactly (e.g. ...987654321 came back as ...987654400). Write and parse them as exact decimal strings now. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #10499 +/- ##
==========================================
+ Coverage 89.08% 89.12% +0.03%
==========================================
Files 103 103
Lines 19757 19783 +26
Branches 3094 3099 +5
==========================================
+ Hits 17600 17631 +31
+ Misses 1494 1490 -4
+ Partials 663 662 -1 ☔ View full report in Codecov by Harness. |
Previously, an invalid atime/ctime/mtime PAX header made import-tar crash with a ValueError from float(). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Haiku has no "root" user, so the name lookup fell back to the name and the test expected uid 0 in vain. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ThomasWaldmann
added a commit
to ThomasWaldmann/borg
that referenced
this pull request
Oct 6, 2026
Like on master (borgbackup#10499): - test_export_tar_pax_headers: compare the imported item timestamps with exact ns precision, not via borg list (only us precision). - test_import_tar_invalid_pax_timestamp: invalid PAX timestamps get ignored, valid ones are used. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
import-tar: convert PAX ACLs to borg's ACL format
GNU tar (
tar --format=posix --acls) writes named ACL entries without a numeric id, e.g.:import-tar copied
SCHILY.acl.access/SCHILY.acl.defaultunchanged intoitem.acl_access/item.acl_default. Borg's internal ACL format has the uid/gid as a 4th field (user:nobody:rw-:65534), soborg extractcrashed inacl_use_local_uid_gid(platform/linux.pyx):Reproduced on master in a Linux container: GNU tar posix tarball →
borg import-tar→borg extractcrashed with rc 2.Fix:
tar_acl_to_borg()converts the ACL text:#comments are handled.SCHILY.xattr.system.posix_acl_*keys (GNU tar--xattrs-include='*'also stores the ACLs as raw xattrs) are skipped, like borg create does inlistxattr, because borg stores the ACLs separately.The export-tar help table now says that PAX also transfers POSIX ACLs.
export-tar/import-tar: exact ns timestamps in PAX headers
export-tar wrote the atime/ctime/mtime PAX headers via
str(ns / 1e9), and import-tar parsed them viafloat(s) * 1e9. A float has about 240 ns resolution at today's epoch, so the "ns" timestamps of--tar-format=PAXdid not roundtrip exactly (...987654321came back as...987654400). Both directions now use exact decimal strings (ns_to_pax_time/pax_time_to_nsinhelpers/time.py).Tests
test_tar_acl_to_borg(parametrized: GNU tar, star and borg formats, unknown names, comments)test_import_tar_gnu_tar_acls(Linux only): builds a PAX tarball with GNU-tar-style ACL headers, imports it, extracts it and checks the ACLs. On master it fails with the IndexError.test_roundtrip_pax_timestamps: fails with either of the old float conversions.test_ns_to_pax_time,test_pax_time_to_nsAlso checked manually on Linux: a real GNU tar
--format=posix --xattrs --xattrs-include='*' --aclstarball goes through import-tar and extract, and the ACLs and xattrs are restored correctly.🤖 Generated with Claude Code