Regression: ImportError for `HeaderWriteError` in long-running process post-Python update for CVE-2024-6923
還沒有人認領這個 Issue。
- 主要語言
- Python
- 星號
- 77.2k
- 分支
- 35.9k
- PR 合併指標
- PR 指標待擷取
描述
Bug report
Bug description:
Pull request #122233 introduced a new class HeaderWriteError in commit 097633981879b3c9de9a1dd120d3aa585ecc2384 and imports that from email.generator.
This breaks running applications that have imported other parts of email before the update, and then try to import the generator past the update.
Now this is a bit silly, but it is what email.message.Message.as_string() does, it imports email.generator inside the function - which may happen at any point of the program run-time rather than at startup.
For example, the following pseudo-code will fail, assuming it has not generated another email earlier or manually imported the email.generator module.
import email.message
<do something for a long time, such as wait for a web form, Python is being upgraded here>
msg = <prepare a message>
msg.as_string()
A particular instance of the issue is the unattended-upgrades package in Ubuntu and Debian, which will install the security update and then may send an email and fail there due to the ImportError, see https://bugs.launchpad.net/ubuntu/+source/python3.8/+bug/2080940.
I'm wondering if it's feasible to add a workaround to the stable branches:
Cchange the email.generator module import:
from email.errors import HeaderWriteError
to graciously support the previous version email.errors:
try:
from email.errors import HeaderWriteError
except ImportError:
from email.errors import MessageError as HeaderWriteError
This is a safe change, existing applications, where the import fails can't be having except HeaderWriteError statements anyway.
Thanks.
CPython versions tested on:
3.12
Operating systems tested on:
No response
貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
研究方向
從 Lib/email/generator.py 開始,檢查 HeaderWriteError 的匯入,以及 email.errors 和 Message.as_string()。重現報告中描述的長時間執行程序情境,然後驗證相容性匯入能夠阻止 ImportError,同時保留現有行為。
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- python
- 領域
- backend
- Issue 類型
- 缺陷
- 難度
- 2/5
- 預估耗時
- 1-3 小時
- 活躍度
- 停滯
- 描述清晰度
- 描述清楚
- 新手友好度
- 35/100