shutil copy* unsafe on POSIX - they preserve setuid/setgit bits

Open
#61,382 22 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
25/100
Issue type
Bug
Clarity
Needs clarification
Activity status
Stale
Tech stack
python

Research direction

Start by reviewing the linked 17180.patch, 17180_preserve_sbits.patch, and 17180_preserve_sbits2.patch to understand the proposed handling of POSIX setuid and setgid bits in shutil copy*. Compare the alternatives and verify that the selected behavior prevents unsafe preservation on POSIX.

Written by the indexing model from the issue text.

Description

stdlib type-security
BPO 17180
Nosy @birkenfeld, @terryjreedy, @ronaldoussoren, @pitrou, @larryhastings, @giampaolo, @tiran, @benjaminp, @tarekziade, @hynek, @jimjjewett, @serhiy-storchaka, @aixtools
Files
  • 17180.patch
  • 17180_preserve_sbits.patch
  • 17180_preserve_sbits2.patch
  • pEpkey.asc
  • Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

    Show more details

    GitHub fields:

    assignee = None
    closed_at = None
    created_at = <Date 2013-02-11.09:10:56.497>
    labels = ['type-security', 'library']
    title = 'shutil copy* unsafe on POSIX - they preserve setuid/setgit bits'
    updated_at = <Date 2018-08-16.19:33:06.896>
    user = 'https://bugs.python.org/milkokrachounov'
    

    bugs.python.org fields:

    activity = <Date 2018-08-16.19:33:06.896>
    actor = 'Michael.Felt'
    assignee = 'none'
    closed = False
    closed_date = None
    closer = None
    components = ['Library (Lib)']
    creation = <Date 2013-02-11.09:10:56.497>
    creator = 'milko.krachounov'
    dependencies = []
    files = ['29057', '29058', '30647', '47752']
    hgrepos = []
    issue_num = 17180
    keywords = ['patch']
    message_count = 22.0
    messages = ['181885', '182020', '182021', '182022', '182023', '182024', '182025', '182029', '182031', '182062', '182690', '185057', '191482', '225803', '321296', '321298', '323482', '323561', '323562', '323598', '323604', '323614']
    nosy_count = 16.0
    nosy_names = ['georg.brandl', 'terry.reedy', 'ronaldoussoren', 'pitrou', 'larry', 'giampaolo.rodola', 'christian.heimes', 'benjamin.peterson', 'tarek', 'Arfrever', 'milko.krachounov', 'neologix', 'hynek', 'Jim.Jewett', 'serhiy.storchaka', 'Michael.Felt']
    pr_nums = []
    priority = 'critical'
    resolution = None
    stage = 'patch review'
    status = 'open'
    superseder = None
    type = 'security'
    url = 'https://bugs.python.org/issue17180'
    versions = ['Python 2.7', 'Python 3.4', 'Python 3.5']
    

    Dominant language
    Python
    Stars
    77.2k
    Forks
    36k
    Avg merge
    1d 9h
    Merged PRs (30d)
    558

    Contributor guide

    Open the contributing guide

    First steps

    1. Read the whole issue, then the project's contributing guide.
    2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
    3. Fork the repository and make your change on a branch.
    4. Open a pull request that references the issue number.

    More from python/cpython

    All issues in python/cpython

    Similar issues

    More Python issues

    Get new issues in your inbox

    A short digest of beginner-friendly GitHub issues.