Skip to content

trace.__main__ does not use io.open_code #103935

Activity

  1. Agent-Hellboy commented on Apr 27, 2023

    @Agent-Hellboy
    Contributor

    Hi @zooba
    I was exploring this and in the mean time i got this error
    ▶ ./python -m trace --trace Lib/calendar.py

      File "Lib/calendar.py", line 155, in monthrange
        ndays = mdays[month] + (month == FEBRUARY and isleap(year))
                                         ^^^^^^^^
    NameError: name 'FEBRUARY' is not defined
    

    FEBRUARY is a global attribute for this module which is made using the global_enum decorator over an enum but trace is throwing an exception that FEBRUARY is not defined

    several std libs are throwing one or the other error

    Btw, is the issue just about changing the open to io.open_code?

  2. gaogaotiantian commented on Apr 27, 2023

    @gaogaotiantian
    Member

    Could you explain why this is a security issue? A similar PR was done for pdb a couple of days ago #103581.

  3. zooba commented on Apr 27, 2023

    @zooba
    MemberAuthor

    Because we made a promise that files being opened for execution would go through open_code, and execution is a sensitive path. Plus it's something that anyone building their own security releases would want to backport, so we can save them all the work.

    The pdb change should be backported as well.

    (I removed 3.7 because this was all added in 3.8.)

  4. zooba commented on Apr 27, 2023

    @zooba
    MemberAuthor

    I stand corrected - pdb was fine in 3.8-3.10, someone regressed it in 3.11, which has now been fixed.

  5. gaogaotiantian commented on Apr 27, 2023

    @gaogaotiantian
    Member

    Thank you for the explanation! In that case, do you want me to submit a PR to fix profile and cProfile which also use raw open for executable code?

  6. zooba commented on Apr 27, 2023

    @zooba
    MemberAuthor

    Sure, go ahead. They can all go in the same PR

  7. zooba commented on Apr 27, 2023

    @zooba
    MemberAuthor

    Incidentally, I checked out the other open() calls in trace and they're all fine. It's just the one that I point out in the first message.

  8. gaogaotiantian commented on Apr 27, 2023

    @gaogaotiantian
    Member

    I also did a quick scan for other similar usages, but did not find any Lib code that loads an executable file.

  9. 1 remaining item

  10. added 5 commits that reference this issue on Apr 27, 2023
  11. added 2 commits that reference this issue on May 22, 2023
  12. added a commit that references this issue on Jun 22, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions