pypa/pip · warning · ValueError
Use of .. or absolute path in a resource path is not…
Error message
Use of .. or absolute path in a resource path is not allowed.
What it means
Raised (or warned) by NullProvider._validate_resource_path() when a resource name contains '..' (parent traversal) or is an absolute path. For Windows absolute/UNC paths it raises ValueError immediately; for POSIX '..' or absolute paths it currently issues a DeprecationWarning (the message says it 'will raise exceptions in a future release'). This is a security guard against path traversal in resource access.
Solutions
- Sanitize resource names: reject any path containing '..' or starting with '/' or a drive letter.
- Use only simple relative names (e.g. 'data/config.json') and let the provider join them under the package root.
- On Windows, never pass UNC or drive-absolute paths as resource names.
Example fix
// before
data = resource_string('mypkg', '../../../etc/passwd') # traversal blocked
// after
data = resource_string('mypkg', 'config/passwd') # relative, inside package Defensive patterns
Strategy: validation
Validate before calling
import os, posixpath, ntpath
INVALID = (os.path.pardir in resource_name.split(posixpath.sep)
or posixpath.isabs(resource_name)
or resource_name.startswith('\\\\'))
if INVALID:
raise ValueError('resource name must be relative without ..') Type guard
def is_safe_resource_name(name: str) -> bool:
import posixpath, ntpath, os
return not (os.path.pardir in name.split(posixpath.sep)
or posixpath.isabs(name) or ntpath.isabs(name)
or name.startswith('\\')) Try / catch
try:
resource_string('pkg', name)
except ValueError:
# path traversal attempt; reject Prevention
- Never build resource names from untrusted input without sanitizing.
- Use only simple relative paths inside the package root.
When it happens
Trigger: Passing a resource name like '../secret.txt', '/etc/passwd', or '\\server\share' to resource_string/resource_filename/etc. The check splits on posixpath.sep and tests for os.path.pardir, posixpath.isabs, ntpath.isabs, or a leading backslash.
Common situations: Constructing resource paths from user input without sanitization; building a path with os.path.join that introduces '..'; cross-platform bugs where a Windows absolute path is passed on any OS.
Related errors
- `base` parameter in `_fn` is `None`. Either override this…
- Can't change extraction path, files already extracted
- Can't perform this operation for loaders without…
- Can't perform this operation for unregistered loader type
- Invalid member in the tar file
AI-assisted analysis of pypa/pip@f399c37189 (2026-08-08).
Data as JSON: /api/errors/d55801d64dd7969f.
Report an issue: GitHub.
Appendix: source
Thrown at src/pip/_vendor/pkg_resources/__init__.py:1818
>>> vrp(None)
Traceback (most recent call last):
...
AttributeError: ...
"""
invalid = (
os.path.pardir in path.split(posixpath.sep)
or posixpath.isabs(path)
or ntpath.isabs(path)
or path.startswith("\\")
)
if not invalid:
return
msg = "Use of .. or absolute path in a resource path is not allowed."
# Aggressively disallow Windows absolute paths
if (path.startswith("\\") or ntpath.isabs(path)) and not posixpath.isabs(path):
raise ValueError(msg)
# for compatibility, warn; in future
# raise ValueError(msg)
issue_warning(
msg[:-1] + " and will raise exceptions in a future release.",
DeprecationWarning,
)
def _get(self, path) -> bytes:
if hasattr(self.loader, 'get_data') and self.loader:
# Already checked get_data exists
return self.loader.get_data(path) # type: ignore[attr-defined]
raise NotImplementedError(
"Can't perform this operation for loaders without 'get_data()'"
)
register_loader_type(object, NullProvider)View on GitHub (pinned to f399c37189)