Race conditions in shutil.copy, shutil.copy2 and shutil.copyfile

Abierto
#59,305 6 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
25/100
Tipo de issue
Error
Claridad
Necesita aclaración
Estado de actividad
Estancado
Stack tecnológico
python
Área
backend, security

Línea de trabajo

Start with the current implementations of shutil.copy, shutil.copy2, and shutil.copyfile, then review the linked python_shutil_copyfile.diff and python_shutil_copy_with_umask.diff patches. Compare their proposed handling of race conditions and umask-related disclosure with the open issue; done means the security concerns are addressed and the relevant behavior is covered by the project's existing checks.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

3.7 (EOL) stdlib type-security
BPO 15100
Nosy @loewis, @pitrou, @giampaolo, @florentx, @hynek, @jimjjewett
Files
  • python_shutil_copyfile.diff: A patch for copyfile procedure
  • python_shutil_copy_with_umask.diff: A patch for the disclosure bug only
  • Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

    Show more details

    GitHub fields:

    assignee = None
    closed_at = None
    created_at = <Date 2012-06-18.11:57:48.316>
    labels = ['type-security', '3.7', 'library', 'expert-IO']
    title = 'Race conditions in shutil.copy, shutil.copy2 and shutil.copyfile'
    updated_at = <Date 2018-08-13.12:48:25.884>
    user = 'https://bugs.python.org/radoslawzarzynski'
    

    bugs.python.org fields:

    activity = <Date 2018-08-13.12:48:25.884>
    actor = 'Jim.Jewett'
    assignee = 'none'
    closed = False
    closed_date = None
    closer = None
    components = ['Library (Lib)', 'IO']
    creation = <Date 2012-06-18.11:57:48.316>
    creator = 'radoslaw.zarzynski'
    dependencies = []
    files = ['26042', '26043']
    hgrepos = []
    issue_num = 15100
    keywords = []
    message_count = 6.0
    messages = ['163096', '163160', '185124', '185125', '213975', '323481']
    nosy_count = 10.0
    nosy_names = ['loewis', 'pitrou', 'giampaolo.rodola', 'Arfrever', 'flox', 'neologix', 'hynek', 'Jim.Jewett', 'radoslaw.zarzynski', 'jm']
    pr_nums = []
    priority = 'high'
    resolution = None
    stage = 'needs patch'
    status = 'open'
    superseder = None
    type = 'security'
    url = 'https://bugs.python.org/issue15100'
    versions = ['Python 2.7', 'Python 3.5', 'Python 3.6', 'Python 3.7']
    

    Lenguaje dominante
    Python
    Estrellas
    77.2k
    Forks
    36k
    Merge medio
    1 d 9 h
    PR fusionados (30 d)
    558

    Guía de contribución

    Abrir la guía de contribución

    Primeros pasos

    1. Lee el issue completo y luego la guía de contribución del proyecto.
    2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
    3. Haz un fork del repositorio y trabaja en una rama.
    4. Abre un pull request que haga referencia al número del issue.

    Más de python/cpython

    Todos los issues de python/cpython

    Issues similares

    Más issues de Python

    Recibe los nuevos issues en tu correo

    Un resumen breve de issues de GitHub para principiantes.