cv2 import appends a trailing ":" to LD_LIBRARY_PATH — empty entry resolves to CWD and breaks child processes
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 70/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- linux, python
Línea de trabajo
Ejecuta la reproducción mínima, inspecciona después la rama POSIX de cv2/init.py alrededor de las líneas 146-147 y sigue cómo se usa BINARIES_PATHS. Se considera terminado cuando importar cv2 ya no crea una entrada vacía en LD_LIBRARY_PATH ni hace que procesos hijo no relacionados hereden una ruta insegura; añade cobertura de regresión si el repositorio proporciona una ubicación de pruebas adecuada.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Environment
- opencv-python: reproduced on 4.11.0.86, 4.12.0.88, 4.13.0.92, 4.14.0.94 and 5.0.0.93 (PyPI manylinux x86_64 wheels; earliest tested 4.11.0.86, Jan 2025)
- Python 3.13.15 / 3.14.7, Linux x86_64 (glibc; CachyOS/Arch, kernel 6.x)
Minimal reproduction
python -m venv venv && venv/bin/pip install opencv-python==5.0.0.93
venv/bin/python - <<'EOF'
import os, subprocess
print("before import:", repr(os.environ.get("LD_LIBRARY_PATH")))
import cv2
print("cv2", cv2.__version__, "after import:", repr(os.environ.get("LD_LIBRARY_PATH")))
print("child sees:", subprocess.run(["sh", "-c", "printf '%s' \"$LD_LIBRARY_PATH\""],
capture_output=True, text=True).stdout)
EOF
Observed
before import: None
cv2 5.0.0 after import: '/…/site-packages/cv2/../../lib64:'
child sees: '/…/site-packages/cv2/../../lib64:'
cv2/__init__.py (POSIX branch, cv2/__init__.py:146-147 in current wheels):
# amending of LD_LIBRARY_PATH works for sub-processes only
os.environ['LD_LIBRARY_PATH'] = ':'.join(l_vars['BINARIES_PATHS']) + ':' + os.environ.get('LD_LIBRARY_PATH', '')
Three problems in one line:
- Unconditional trailing
:— whenLD_LIBRARY_PATHwas previously unset the
variable is created with a dangling separator. Perld.so(8)semantics an empty
entry resolves to the current working directory of every child process. - Global environment mutation — the comment itself notes this "works for
sub-processes only", yet the write persists inos.environfor the whole
process lifetime, so everysubprocess/os.system/webbrowsercall made by
the host application inherits the modified path. This is invisible side-channel
state an importer cannot reasonably expect fromimport cv2. - The injected directory typically does not exist — with standard manylinux
wheel layouts the bundled libraries live inopencv_python.libs/(located via
$ORIGINRPATH), and<site-packages>/cv2/../../lib64is absent in venv,
project, and standalone-packaged layouts, so the write buys nothing while
adding the hazard.
Real-world impact
We ship a Nuitka-standalone application whose launcher cds into the release
folder. With cv2 imported, LD_LIBRARY_PATH ends with : → the release folder
(the CWD) enters the child loader path → children that load system OpenSSL
(xdg-open → kde-open, i.e. "open a URL in the default browser") resolve the
bundled, older libssl.so.3/libcrypto.so.3 instead of the system ones and die
with:
kde-open: libssl.so.3: version `OPENSSL_3.2.0' not found (required by /usr/lib/libcurl.so.4)
Any application that imports cv2 and then spawns helper processes from a
directory containing same-named libraries is affected the same way.
Suggested fix
-
Do not append a dangling separator; only write the variable when there is
something to add and prepend/append with proper joining:paths = l_vars['BINARIES_PATHS'] if paths: old = os.environ.get('LD_LIBRARY_PATH') os.environ['LD_LIBRARY_PATH'] = ':'.join(paths) + (':' + old if old else '') -
Longer term, prefer not mutating the global environment at all: the bundled
libraries are already found through$ORIGINRPATH; if an env-based fallback
is really needed, consider documenting it and cleaning up after import, or
exposing an opt-in.
Happy to send a PR to opencv-python/opencv-python (the loader __init__.py)
if you agree with the direction.
- Lenguaje dominante
- Python
- Estrellas
- 5.4k
- Forks
- 1k
- Merge medio
- 22 h 17 min
- PR fusionados (30 d)
- 3
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de opencv/opencv-python
-
[DOC] README file Abierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 85/100
opencv/opencv-python#1217 · 3 comentarios ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
opencv/opencv-python#1165 · 2 comentarios · 1 reacción ·
-
Dificultad 5/5 Más de una semana Aptitud para principiantes 25/100
opencv/opencv-python#1273 · 1 comentario ·
-
FFMPEG v8.1.1 vulnerabilities Abierto
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
opencv/opencv-python#1272 · 1 comentario ·
-
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
opencv/opencv-python#1267 ·
Todos los issues de opencv/opencv-python
Issues similares
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
zostera/django-bootstrap4#894 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
use-agent-os/agent-os#3276 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
zephyrproject-rtos/zephyr#119726 ·
-
area/auth bug comp/agent P3 platform/discord type/security
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
NousResearch/hermes-agent#117848 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
zilliztech/memsearch#759 ·