python / python/cpython

zipapps execute symlinks as if they are code

Open
#84,705 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

3.7 (EOL) 3.8 (EOL) 3.9 (EOL) interpreter-core type-bug
Dominant language
Python
Stars
77.2k
Forks
36k
PR merge metrics
PR metrics pending

Description

BPO 40525
Nosy @asottile, @FFY00
Files
  • zipimporter-symlink.patch
  • Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

    Show more details

    GitHub fields:

    assignee = None
    closed_at = None
    created_at = <Date 2020-05-05.22:55:41.298>
    labels = ['interpreter-core', '3.8', 'type-bug', '3.7', '3.9']
    title = 'zipapps execute symlinks as if they are code'
    updated_at = <Date 2020-05-08.02:21:52.263>
    user = 'https://github.com/asottile'
    

    bugs.python.org fields:

    activity = <Date 2020-05-08.02:21:52.263>
    actor = 'FFY00'
    assignee = 'none'
    closed = False
    closed_date = None
    closer = None
    components = ['Interpreter Core']
    creation = <Date 2020-05-05.22:55:41.298>
    creator = 'Anthony Sottile'
    dependencies = []
    files = ['49140']
    hgrepos = []
    issue_num = 40525
    keywords = ['patch']
    message_count = 2.0
    messages = ['368212', '368403']
    nosy_count = 2.0
    nosy_names = ['Anthony Sottile', 'FFY00']
    pr_nums = []
    priority = 'normal'
    resolution = None
    stage = None
    status = 'open'
    superseder = None
    type = 'behavior'
    url = 'https://bugs.python.org/issue40525'
    versions = ['Python 3.7', 'Python 3.8', 'Python 3.9']
    

    Contributor guide

    Open the contributing guide

    First steps

    1. Read the whole issue, then the project's contributing guide.
    2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
    3. Fork the repository and make your change on a branch.
    4. Open a pull request that references the issue number.

    Research direction

    Start with the linked zipimporter-symlink.patch and the Interpreter Core component; reproduce the reported behavior with a zipapp containing a symlink. Confirm how the issue's existing patch addresses symlinks being executed as code, and verify that the corrected behavior holds for Python 3.7, 3.8, and 3.9.

    Written by the indexing model from the issue text.

    Assessment

    Tech stack
    python
    Domain
    operating-systems
    Issue type
    Bug
    Difficulty
    4/5
    Estimated time
    3-5 days
    Activity status
    Stale
    Clarity
    Needs clarification
    Newbie friendliness
    35/100

    Get new issues in your inbox

    A short digest of beginner-friendly GitHub issues.