It looks like tar developers are going to enforce --one-top-level to be a relative directory:
https://github.com/praiskup/tar/commit/678dbc679a1478da58c884de509ab2844eb04cdb While this does change behaviour, I'm not sure we should deviate from upstream for the CVE-2026-5704 fix. ** CVE added: https://cve.org/CVERecord?id=CVE-2026-5704 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2160696 Title: Extraction fails when passing absolute directory to --one-top-level To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/tar/+bug/2160696/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
