Race conditions in shutil.copy, shutil.copy2 and shutil.copyfile

Offen
#59,305 6 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Anfängerfreundlichkeit
25/100
Issue-Typ
Bug
Klarheit
Muss geklärt werden
Aktivitätsstatus
Veraltet
Tech-Stack
python
Bereich
backend, security

Rechercherichtung

Start with the current implementations of shutil.copy, shutil.copy2, and shutil.copyfile, then review the linked python_shutil_copyfile.diff and python_shutil_copy_with_umask.diff patches. Compare their proposed handling of race conditions and umask-related disclosure with the open issue; done means the security concerns are addressed and the relevant behavior is covered by the project's existing checks.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

3.7 (EOL) stdlib type-security
BPO 15100
Nosy @loewis, @pitrou, @giampaolo, @florentx, @hynek, @jimjjewett
Files
  • python_shutil_copyfile.diff: A patch for copyfile procedure
  • python_shutil_copy_with_umask.diff: A patch for the disclosure bug only
  • Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

    Show more details

    GitHub fields:

    assignee = None
    closed_at = None
    created_at = <Date 2012-06-18.11:57:48.316>
    labels = ['type-security', '3.7', 'library', 'expert-IO']
    title = 'Race conditions in shutil.copy, shutil.copy2 and shutil.copyfile'
    updated_at = <Date 2018-08-13.12:48:25.884>
    user = 'https://bugs.python.org/radoslawzarzynski'
    

    bugs.python.org fields:

    activity = <Date 2018-08-13.12:48:25.884>
    actor = 'Jim.Jewett'
    assignee = 'none'
    closed = False
    closed_date = None
    closer = None
    components = ['Library (Lib)', 'IO']
    creation = <Date 2012-06-18.11:57:48.316>
    creator = 'radoslaw.zarzynski'
    dependencies = []
    files = ['26042', '26043']
    hgrepos = []
    issue_num = 15100
    keywords = []
    message_count = 6.0
    messages = ['163096', '163160', '185124', '185125', '213975', '323481']
    nosy_count = 10.0
    nosy_names = ['loewis', 'pitrou', 'giampaolo.rodola', 'Arfrever', 'flox', 'neologix', 'hynek', 'Jim.Jewett', 'radoslaw.zarzynski', 'jm']
    pr_nums = []
    priority = 'high'
    resolution = None
    stage = 'needs patch'
    status = 'open'
    superseder = None
    type = 'security'
    url = 'https://bugs.python.org/issue15100'
    versions = ['Python 2.7', 'Python 3.5', 'Python 3.6', 'Python 3.7']
    

    Vorherrschende Sprache
    Python
    Sterne
    77.2k
    Forks
    36k
    Ø Merge
    1 T. 9 Std.
    Gemergte PRs (30 T.)
    558

    Beitragsleitfaden

    Beitragsleitfaden öffnen

    Erste Schritte

    1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
    2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
    3. Forken Sie das Repository und arbeiten Sie in einem Branch.
    4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

    Mehr aus python/cpython

    Alle Issues in python/cpython

    Ähnliche Issues

    Weitere Issues zu Python

    Neue Issues direkt in Ihr Postfach

    Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.