Repository navigation
pyexpat changes in 3.10.14 broke Supervisor #117173
Description
Activity
- addedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on Mar 23, 2024 Hello!
From e2caef7:
The :mod:`xmlrpclib` module has been renamed to :mod:`xmlrpc.client` in Python 3.0.
So, there's no problem, just use axmlrpc.clientinstead ofxmlrpclib.
It was renamed long time ago, but name of supervisor issue says "Fatal error after update python from 3.10.13 to 3.10.14", I'm sure that this cannot be true,import xmlrpclibcannot work on any of 3.10 versions, probably you're missing something.Hello!
Thanks for the prompt feedback, but I don’t agree with youThe supervisor definitely works on 3.10.13 - verified.
And it stops working on 3.10.14.
It turns out that the minor version influences the supervisor.
If you look at what was done in 3.10.14, this is exactly a fix for an xml vulnerability in Python. https://github.com/python/cpython/commits/3.10/If you look at the supervisor code, they solved the problem you describe
https://github.com/Supervisor/supervisor/blob/main/supervisor/compat.py#L66try: # pragma: no cover import xmlrpc.client as xmlrpclib except ImportError: # pragma: no cover import xmlrpclib
Also, the supervisor hasn’t changed anything for a long time, and the breakdown occurred precisely after the release of Python 3.10.14
The problem is on your side
A closer look at the traceback makes it clear that the problem is probably related to version of the
pyexpatlibrary bundled in your system. I'm not expert in this kind of issues, so I'm re-open the issue.Highlighting the most relevant part of the traceback:
Traceback (most recent call last): File "/usr/lib/python3.10/site-packages/supervisor/compat.py", line 67, in <module> import xmlrpc.client as xmlrpclib File "/usr/lib/python3.10/xmlrpc/client.py", line 138, in <module> from xml.parsers import expat File "/usr/lib/python3.10/xml/parsers/expat.py", line 4, in <module> from pyexpat import * ImportError: Error relocating /usr/lib/python3.10/lib-dynload/pyexpat.cpython-310-x86_64-linux-gnu.so: XML_SetReparseDeferralEnabled: symbol not found
Diff between the releases: v3.10.13...v3.10.14
Had three expat changes:
Reacted by Alex Waygood and Kirill PodoprigoraAnd the related issues:
- test.test_xml_etree*.XMLPullParserTest.test_simple_xml fails with (system) expat 2.6.0 #115133
- Please upgrade bundled Expat to 2.6.0 (e.g. for the fix to CVE-2023-52425) #115399
- Please expose Expat >=2.6.0 API function
XML_SetReparseDeferralEnabled#115398
This last one seems most relevant, to expose
XML_SetReparseDeferralEnabled, as the traceback saysXML_SetReparseDeferralEnabled: symbol not found.We don't provide Linux installers (and don't provide any installers for 3.10 because it's in the security-only/source-code only phase).
Could it be a problem with a distro-provided Python installation?
(See also jupyterhub/repo2docker-action#113 for a similar report.)
- changed the title
[-]Release 3.10.14 broke Supervisor[/-][+]pyexpat changes in 3.10.14 broke Supervisor[/+]on Mar 23, 2024 From a quick look my understanding is that @unlike777 is using Python binaries compiled on a host that did have symbol
XML_SetReparseDeferralEnabledpresent in libexpat — through a backport or version >=2.6.0 — but the target system has installed binaries that lack these symbols. If that's what's going on, the fix is to get these two sides back in sync.Reacted by Serhiy Storchaka@unlike777 which distro is this on, which release of the distro, and how did you install CPython and libexpat and which version are they now?
Thank you very much for being included!
I use alpine:3, 3.16, 3.16.3, latest
Install the supervisor:
apk add supervisor[supervisor 1/3] RUN apk add supervisor
2.126 (1/10) Installing mpdecimal (2.5.1-r1)
2.437 (2/10) Installing python3 (3.10.14-r0)
3.440 (3/10) Installing py3-appdirs (1.4.4-r3)
3.483 (4/10) Installing py3-more-itertools (8.13.0-r0)
3.532 (5/10) Installing py3-ordered-set (4.0.2-r3)
3.575 (6/10) Installing py3-parsing (2.4.7-r3)
3.629 (7/10) Installing py3-six (1.16.0-r1)
3.672 (8/10) Installing py3-packaging (21.3-r0)
3.720 (9/10) Installing py3-setuptools (59.4.0-r0)
3.818 (10/10) Installing supervisor (4.2.4-r0)@unlike777 thanks. I cannot reproduce the issue with Alpine 3.16. This will need a robust minimal reproducer. What's a way to reliably reproduce the issue?
It's a bug in Alpine's packaging of Python 3.10.14-r0, not an upstream issue.
Reacted by unlike777, Hugo van Kemenade, Kirill Podoprigora and Shaun WalbridgeGreat — thanks @hartwork!
Reacted by Kirill Podoprigora
Bug report
Bug description:
Link for supervisor issue Supervisor/supervisor#1636
CPython versions tested on:
3.10
Operating systems tested on:
Linux