feat: inherit PYTHONSAFEPATH env var from outer process#2076
Merged
rickeylev merged 2 commits intobazel-contrib:mainfrom Jul 19, 2024
Merged
feat: inherit PYTHONSAFEPATH env var from outer process#2076rickeylev merged 2 commits intobazel-contrib:mainfrom
rickeylev merged 2 commits intobazel-contrib:mainfrom
Conversation
7687eb7 to
f730df0
Compare
aignas
approved these changes
Jul 19, 2024
…o feat.allow.env.override
|
I will check if this solves #2060, but I have a hunch that just setting |
Collaborator
Author
|
One of the tests does exactly that and checks the interpreter flag to verify that safe path is disabled, so it should work :). Feel free to re-open the issue with a repro if you find otherwise. Actually, I'm going to re-open the issue for now. This only fixes it for --bootstrap_impl=script, not windows, and, come to think of it, certain types of zips might also still have the bug. |
Collaborator
Author
|
Doh, this introduced a bug that disable safe path by default unless it was opted in to. That'll be fixed shortly in #2073. |
github-merge-queue bot
pushed a commit
that referenced
this pull request
Jul 19, 2024
Previously, all the user import paths were put at the end of sys.path. This was done so that user import paths didn't hide stdlib modules. However, a side-effect is that user import paths came after the runtime's site-packages directory. This prevented user imports from overriding non-stdlib modules included in a runtime (e.g. pip). To fix, we look for the runtime site-packages directory, then insert the user import paths before it. A test is used to ensure that the ordering is `[stdlib, user, runtime site-packages]` Also fixes a bug introduced by #2076: safe path was being disabled by default Fixes #2064
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
By default, PYTHONSAFEPATH is enabled to help prevent imports being found where they
shouldn't be. However, this behavior can't be disabled, which makes it harder to use
a py_binary when the non-safe path behavior is explicitly desired.
To fix, the bootstrap now respects the caller environment's PYTHONSAFEPATH environment variable, if set. This allows the callers to set
PYTHONSAFEPATH=(empty string) tooverride the default behavior that enables it.
Fixes #2060