python / python/cpython

ProcessPoolExecutor fails to construct when os.sysconf("SC_SEM_NSEMS_MAX") raises PermissionError

未关闭
#155,912 5 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

OS-mac stdlib topic-multiprocessing type-bug
主要语言
Python
星标
77.2k
派生
35.9k
PR 合并指标
PR 指标待抓取

描述

Bug report

Bug description:

concurrent.futures.ProcessPoolExecutor cannot be constructed on macOS under
any sandbox profile that denies sysctl reads, even though every primitive it
depends on is fully functional in that environment.

_check_system_limits() in Lib/concurrent/futures/process.py reads the
semaphore limit like this:

try:
    nsems_max = os.sysconf("SC_SEM_NSEMS_MAX")
except (AttributeError, ValueError):
    # sysconf not available or setting not available
    return

The handler catches AttributeError and ValueError. It does not catch
OSError. On macOS, SC_SEM_NSEMS_MAX is backed by a sysctl, so a sandbox that
denies sysctl reads makes this call raise PermissionError (an OSError
subclass). The exception propagates out of ProcessPoolExecutor.__init__ before
any worker is created.

The inconsistency is with the function's own stated intent. The existing
except clause already treats "the limit cannot be determined" as benign and
returns — as does the nsems_max == -1 branch immediately below, commented
"indetermined limit, assume that limit is determined by available memory only".
A denied read is the same condition as an unavailable one, arriving as a
different exception type, but it is handled as a fatal error instead.

The practical result is that ProcessPoolExecutor becomes unavailable while
multiprocessing.Pool — same platform, same named semaphores, same spawn
machinery — works correctly. multiprocessing.Pool differs only in that it
never calls _check_system_limits.

This is a robustness bug, not a security issue. The sandbox behaves correctly by
denying the sysctl; the reproduction below denies it explicitly.

Reproduction

repro.py (attached) is standalone, has no third-party dependencies, and does
no monkeypatching. deny_sysctl.sb is a minimal profile that allows everything
except sysctl reads, so the outcome cannot be attributed to any other
restriction:

(version 1)
(allow default)
(deny sysctl-read)
$ python3 repro.py                                   # baseline
$ sandbox-exec -f deny_sysctl.sb python3 repro.py    # one capability denied

Actual behaviour

Under (deny sysctl-read) on macOS 26.5.2 (Darwin 25.5.0), CPython 3.13.12:

introspection (queries about a capability)
  os.sysconf(SC_SEM_NSEMS_MAX)     FAIL    PermissionError: [Errno 1] Operation not permitted (errno=1)
  _check_system_limits()           FAIL    PermissionError: [Errno 1] Operation not permitted (errno=1)

direct (exercises the capability)
  multiprocessing.Semaphore        OK      acquire/release
  multiprocessing.Process(spawn)   OK      spawn/join exit=0
  multiprocessing.Pool(spawn)      OK      [1, 4, 9, 16]
  concurrent.futures.ProcessPool   FAIL    PermissionError: [Errno 1] Operation not permitted (errno=1)

Traceback:

  File "concurrent/futures/process.py", line ..., in __init__
    _check_system_limits()
  File "concurrent/futures/process.py", line ..., in _check_system_limits
    nsems_max = os.sysconf("SC_SEM_NSEMS_MAX")
PermissionError: [Errno 1] Operation not permitted

Baseline run with no sandbox: all six checks pass.

Expected behaviour

ProcessPoolExecutor should construct and run. An unreadable semaphore limit is
already treated as benign when the read fails for other reasons; a denied read
should be treated the same way.

Suggested fix

Add OSError to the caught exceptions:

try:
    nsems_max = os.sysconf("SC_SEM_NSEMS_MAX")
except (AttributeError, ValueError, OSError):
    # sysconf not available, setting not available, or the read was denied
    # (e.g. a sandbox profile that denies sysctl reads on macOS)
    return

This preserves the genuine "too few semaphores" check, which raises
NotImplementedError with an explanatory message and is unaffected. It only
extends the existing "limit cannot be determined" path to cover denial.

If the narrower change is preferred, catching PermissionError alone fixes the
observed case, though any denied sysconf read raises some OSError and the
broader catch matches the comment's intent.

A regression test could patch os.sysconf to raise PermissionError and assert
that ProcessPoolExecutor still constructs — no sandbox required in CI.

Environment

  • macOS 26.5.2 (Darwin 25.5.0), arm64

Verified on three interpreters on the same host, all with identical results —
sysconf denied, ProcessPoolExecutor unconstructible, multiprocessing.Pool
working:

Interpreter Result
CPython 3.9.6 (/usr/bin/python3, Apple system Python) reproduces
CPython 3.12.13 reproduces
CPython 3.13.12 (python.org framework build) reproduces

The handler predates all three, so this is longstanding rather than a
regression. Note that the version shipped with macOS is affected.

CPython versions tested on:

3.12, 3.13

Operating systems tested on:

macOS

Linked PRs
  • gh-155955
  • gh-156303

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

从 Lib/concurrent/futures/process.py 和 _check_system_limits() 开始,然后检查现有的 concurrent.futures 进程测试。当被拒绝的 sysconf 读取不再阻止构造 ProcessPoolExecutor,并且为 PermissionError 提供回归测试覆盖时,即表示完成;关联的 PR gh-155955 和 gh-156303 表明这项工作已经在进行中。

由索引模型根据 Issue 内容生成。

评估

技术栈
python
领域
operating-systems
Issue 类型
缺陷
难度
2/5
预计耗时
1-3 小时
活跃度
停滞
描述清晰度
描述清楚
新手友好度
25/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。