MagicStack / MagicStack/asyncpg

Exception when attempting to fetch SSL info

Open
#884 1 comment 3 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
8.1k
Forks
468
PR merge metrics
No merged PRs in 30d

Description

Thanks for creating asyncpg! It's dramatically improved the performance of my [open-source web application](https://github.com/RunestoneInteractive) ([Runestone Academy](https://runestone.academy/), a free interactive e-book).

To reproduce this bug, simply start asyncpg as a non-root user (one without permission to access `/root`).

* **asyncpg version**: 0.25
* **PostgreSQL version**: 12.7
* **Do you use a PostgreSQL SaaS? If so, which? Can you reproduce
the issue with a local PostgreSQL install?**: I use AWS RDS; haven't tested locally
* **Python version**: 3.9.1
* **Platform**: Debian GNU/Linux 11 (bullseye)
* **Do you use pgbouncer?**: No
* **Did you install asyncpg with pip?**: Yes
* **If you built asyncpg locally, which version of Cython did you use?**: N/A
* **Can the issue be reproduced under both asyncio and
[uvloop](https://github.com/magicstack/uvloop)?**: I only use asyncio

I run asyncpg as a non-root user for improved security; this user lacks root access. During startup in asyncpg v. 0.25, I see the error like this:

```
File "/srv/web2py/applications/runestone/.venv/lib/python3.9/site-packages/asyncpg/connection.py", line 2085, in connect
return await connect_utils._connect(
File "/srv/web2py/applications/runestone/.venv/lib/python3.9/site-packages/asyncpg/connect_utils.py", line 874, in _connect
addrs, params, config = _parse_connect_arguments(timeout=timeout, **kwargs)
File "/srv/web2py/applications/runestone/.venv/lib/python3.9/site-packages/asyncpg/connect_utils.py", line 640, in _parse_connect_arguments
addrs, params = _parse_connect_dsn_and_args(
File "/srv/web2py/applications/runestone/.venv/lib/python3.9/site-packages/asyncpg/connect_utils.py", line 543, in _parse_connect_dsn_and_args
if not sslkey.exists():
File "/usr/local/lib/python3.9/pathlib.py", line 1424, in exists
self.stat()
File "/usr/local/lib/python3.9/pathlib.py", line 1232, in stat
return self._accessor.stat(self)
PermissionError: [Errno 13] Permission denied
```

In [connect_utils.py line 543](https://github.com/MagicStack/asyncpg/commit/383c711eb68bc6a042c121e1fddfde0cdefb8068#diff-fe0ec192392fe4131382e009b40723ba9469e62ab4760fed681a438d1d352bc3R529), asyncpg checks if a root-owned file exists. Unfortunately, a non-root user gets a permission denied exception instead of a False return value from `exists()`. It looks like wrapping this in a try/except would fix this bug. (It looks like [a later exception](https://github.com/MagicStack/asyncpg/commit/383c711eb68bc6a042c121e1fddfde0cdefb8068#diff-fe0ec192392fe4131382e009b40723ba9469e62ab4760fed681a438d1d352bc3R529) needs PermissionError added to it.)

For me, reverting to asyncpg v. 0.24 causes my code to run without problems.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in connect_utils.py around line 543, where SSL key existence is checked during connection argument parsing. Reproduce the connection as a non-root user without access to /root, then verify that the SSL lookup no longer raises PermissionError and the connection proceeds as it did with asyncpg 0.24.

Written by the indexing model from the issue text.

Assessment

Tech stack
postgresql, python
Domain
database
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.