Repository navigation
trace.__main__ does not use io.open_code #103935
Description
Activity
- addedtype-securityA security issueA security issueneeds backport to 3.10only security fixesonly security fixesneeds backport to 3.11only security fixesonly security fixes
on Apr 27, 2023 Hi @zooba
I was exploring this and in the mean time i got this error
▶ ./python -m trace --trace Lib/calendar.pyFile "Lib/calendar.py", line 155, in monthrange ndays = mdays[month] + (month == FEBRUARY and isleap(year)) ^^^^^^^^ NameError: name 'FEBRUARY' is not definedFEBRUARYis a global attribute for this module which is made using theglobal_enumdecorator over an enum but trace is throwing an exception thatFEBRUARYis not definedseveral std libs are throwing one or the other error
Btw, is the issue just about changing the
opentoio.open_code?Could you explain why this is a security issue? A similar PR was done for
pdba couple of days ago #103581.Because we made a promise that files being opened for execution would go through
open_code, and execution is a sensitive path. Plus it's something that anyone building their own security releases would want to backport, so we can save them all the work.The
pdbchange should be backported as well.(I removed 3.7 because this was all added in 3.8.)
I stand corrected -
pdbwas fine in 3.8-3.10, someone regressed it in 3.11, which has now been fixed.Thank you for the explanation! In that case, do you want me to submit a PR to fix profile and cProfile which also use raw
openfor executable code?Sure, go ahead. They can all go in the same PR
Incidentally, I checked out the other
open()calls in trace and they're all fine. It's just the one that I point out in the first message.I also did a quick scan for other similar usages, but did not find any Lib code that loads an executable file.
Reacted by Steve Dower1 remaining item
- added 5 commits that reference this issue
on Apr 27, 2023 - added3.11only security fixesonly security fixes3.10 (EOL)end of lifeend of life3.9 (EOL)end of lifeend of lifeand removedneeds backport to 3.10only security fixesonly security fixesneeds backport to 3.11only security fixesonly security fixes
on Feb 17, 2025
When used as an entry point, the
tracemodule opens code files without usingio.open_code:https://github.com/python/cpython/blob/main/Lib/trace.py#L719
This should use the
io.open_codemethod instead ofopen(..., 'rb').Linked PRs
io.open_code()to open executable file #103947io.open_code()when executing code in trace and profile modules (GH-103947) #103950io.open_code()when executing code in trace and profile modules (GH-103947) #103952io.open_code()when executing code in trace and profile modules (GH-103947) #103953io.open_code()when executing code in trace and profile modules (GH-103947) #103954