Race conditions in shutil.copy, shutil.copy2 and shutil.copyfile
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 25/100
Research direction
Start with the current implementations of shutil.copy, shutil.copy2, and shutil.copyfile, then review the linked python_shutil_copyfile.diff and python_shutil_copy_with_umask.diff patches. Compare their proposed handling of race conditions and umask-related disclosure with the open issue; done means the security concerns are addressed and the relevant behavior is covered by the project's existing checks.
Written by the indexing model from the issue text.
Description
| BPO | 15100 |
|---|---|
| Nosy | @loewis, @pitrou, @giampaolo, @florentx, @hynek, @jimjjewett |
| Files |
Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
assignee = None
closed_at = None
created_at = <Date 2012-06-18.11:57:48.316>
labels = ['type-security', '3.7', 'library', 'expert-IO']
title = 'Race conditions in shutil.copy, shutil.copy2 and shutil.copyfile'
updated_at = <Date 2018-08-13.12:48:25.884>
user = 'https://bugs.python.org/radoslawzarzynski'
bugs.python.org fields:
activity = <Date 2018-08-13.12:48:25.884>
actor = 'Jim.Jewett'
assignee = 'none'
closed = False
closed_date = None
closer = None
components = ['Library (Lib)', 'IO']
creation = <Date 2012-06-18.11:57:48.316>
creator = 'radoslaw.zarzynski'
dependencies = []
files = ['26042', '26043']
hgrepos = []
issue_num = 15100
keywords = []
message_count = 6.0
messages = ['163096', '163160', '185124', '185125', '213975', '323481']
nosy_count = 10.0
nosy_names = ['loewis', 'pitrou', 'giampaolo.rodola', 'Arfrever', 'flox', 'neologix', 'hynek', 'Jim.Jewett', 'radoslaw.zarzynski', 'jm']
pr_nums = []
priority = 'high'
resolution = None
stage = 'needs patch'
status = 'open'
superseder = None
type = 'security'
url = 'https://bugs.python.org/issue15100'
versions = ['Python 2.7', 'Python 3.5', 'Python 3.6', 'Python 3.7']
- Dominant language
- Python
- Stars
- 77.2k
- Forks
- 36k
- Avg merge
- 1d 9h
- Merged PRs (30d)
- 558
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from python/cpython
-
docs pending
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
stdlib type-feature
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
stdlib type-feature
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
build type-bug
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
stdlib topic-email type-feature
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
bancolombia/sentinel#23 ·
-
test md OpenCI
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
-
integration:quickjs org:external priority:backlog topic:code-interpreter topic:middleware type:feature
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
langchain-ai/deepagents#6450 ·
-
bug client
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100