General issue Python extractor fails in macOS App Sandbox: `PermissionError: [Errno 1] Operation not permitted` from `_multiprocessing.SemLock`
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Anfängerfreundlichkeit
- 52/100
- Issue-Typ
- Bug
- Klarheit
- Klar beschrieben
- Aktivitätsstatus
- Ruhig
- Tech-Stack
- macos, python
- Bereich
- devtools, operating-systems
Rechercherichtung
Beginnen Sie mit python/tools/python3src.zip/semmle/logging.py:84 und semmle/worker.py:115-116, reproduzieren Sie dann den Fehler mit dem sandboxed multiprocessing Queue-Befehl und codeql database create. Verfolgen Sie sowohl die Initialisierungspfade von Queue als auch von Prozessen und überprüfen Sie, dass die Erstellung der Python-Datenbank abgeschlossen wird, wenn POSIX-Semaphoren verweigert werden, einschließlich der logger- und extractor-pool-Pfade.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
Summary
The Python extractor unconditionally uses multiprocessing.Queue and multiprocessing.Process, which require POSIX semaphores (sem_open()). In macOS App Sandbox environments (Seatbelt), ipc-posix-sem is denied at the kernel level, making codeql database create --language=python impossible.
No existing issue covers this — searched for SemLock, semaphore, PermissionError macos, sandbox, multiprocessing with zero matches.
Environment
- CodeQL CLI: 2.25.6 (Homebrew cask, Apple Silicon)
- Python extractor version: 7.1.8
- macOS: Darwin 24.6.0 (Sequoia, arm64)
- Python: 3.12 and 3.14 (both fail identically)
- Sandbox: macOS Seatbelt (
sandbox-exec) — used by Claude Code, Codex, and other sandboxed developer tools
Reproduction
Run codeql database create inside any macOS App Sandbox that denies ipc-posix-sem:
# Minimal test — verify semaphores are blocked in your environment:
python3 -c "import multiprocessing; multiprocessing.get_context('spawn').Queue()"
# PermissionError: [Errno 1] Operation not permitted
# Then:
echo 'print("hello")' > /tmp/test.py
codeql database create /tmp/codeql-db --language=python --source-root=/tmp --overwrite
Fails at:
File ".../python3src.zip/semmle/logging.py", line 85, in __init__
self.queue = ctx.Queue()
...
_multiprocessing.SemLock(kind, value, maxvalue, self._make_name(), unlink_now)
PermissionError: [Errno 1] Operation not permitted
If the logger is patched to bypass this, a second identical failure occurs in semmle/worker.py:115 (ExtractorPool.__init__ → ctx.Queue(proc_count*2)).
Affected Code
-
python/tools/python3src.zip → semmle/logging.py:84—Logger.__init__unconditionally createsmultiprocessing.Queue()and spawns aProcessfor log message routing, regardless of verbosity level. -
python/tools/python3src.zip → semmle/worker.py:115-116—ExtractorPool.__init__createsmultiprocessing.Queueandmultiprocessing.Processworkers for parallel extraction.
Both use multiprocessing.get_context('spawn') on macOS, which calls sem_open().
Why This Matters
macOS Seatbelt sandboxing is increasingly common in developer tooling — Claude Code, GitHub Codex CLI, Gemini CLI, and third-party sandbox wrappers all use it. The ipc-posix-sem denial is standard in these profiles. As AI-assisted development grows, more developers will hit this when running CodeQL from sandboxed terminals.
Suggested Fix
Add a fallback to threading.Thread + queue.Queue when multiprocessing is unavailable or fails. This is the same pattern used for AWS Lambda (where /dev/shm is unavailable) and Docker containers with restricted IPC namespaces.
A minimal change: catch PermissionError/OSError in Logger.__init__ and ExtractorPool.__init__, falling back to thread-based equivalents. Single-threaded extraction already works correctly (verified with a patched extractor scanning 132 Python files).
- Vorherrschende Sprache
- CodeQL
- Sterne
- 10.1k
- Forks
- 2.1k
- Ø Merge
- 2 T. 11 Std.
- Gemergte PRs (30 T.)
- 129
Beitragsleitfaden
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus github/codeql
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
-
C#: cs/simplifiable-boolean-expression false positive on Nullable<bool> compared with a literal Offen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
-
false-positive
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 70/100
-
False positive Offenfalse-positive
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 15/100
Ähnliche Issues
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
idean3885/claude-ops-agent#521 ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
0xMiden/bridge-portal#132 ·
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
newrelic-experimental/preflight#793 · 1 Kommentar ·
-
enhancement
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 70/100
babalae/bettergi-scripts-list#3674 ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 88/100
caddyserver/caddy#8046 ·