Skip to content

ensurepip bootstrap breaks out of isolated environment #90355

Description

@kcdodd
mannequin
BPO 46197
Nosy @gvanrossum, @ncoghlan, @merwok, @ericsnowcurrently, @dstufft, @pradyunsg, @cdce8p, @kcdodd
PRs
  • [3.10] bpo-46197: Add isolated flag if currently isolated #30307
  • Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

    Show more details

    GitHub fields:

    assignee = None
    closed_at = None
    created_at = <Date 2021-12-29.23:24:11.769>
    labels = ['type-bug', '3.8', '3.9', '3.10', '3.11']
    title = 'ensurepip bootstrap breaks out of isolated environment'
    updated_at = <Date 2022-03-29.20:57:30.348>
    user = 'https://github.com/kcdodd'

    bugs.python.org fields:

    activity = <Date 2022-03-29.20:57:30.348>
    actor = 'gvanrossum'
    assignee = 'none'
    closed = False
    closed_date = None
    closer = None
    components = []
    creation = <Date 2021-12-29.23:24:11.769>
    creator = 'kcdodd'
    dependencies = []
    files = []
    hgrepos = []
    issue_num = 46197
    keywords = ['patch']
    message_count = 2.0
    messages = ['409334', '412408']
    nosy_count = 8.0
    nosy_names = ['gvanrossum', 'ncoghlan', 'eric.araujo', 'eric.snow', 'dstufft', 'pradyunsg', 'cdce8p', 'kcdodd']
    pr_nums = ['30307']
    priority = 'normal'
    resolution = None
    stage = 'patch review'
    status = 'open'
    superseder = None
    type = 'behavior'
    url = 'https://bugs.python.org/issue46197'
    versions = ['Python 3.8', 'Python 3.9', 'Python 3.10', 'Python 3.11']

    Activity

    1. kcdodd commented on Dec 29, 2021

      kcdoddmannequin
      MannequinAuthor

      A change in behavior was made to the ensurepip module in Python 3.8.7 that causes bootstrapping to break out of an isolated environment. This is relevant to the assumption made in the venv module, which ran ensurepip as a sub-process with the -I flag environment isolation to force installation in the virtual environment directory.

      In Python <= 3.8.6, ensurepip ran the bootstrap within the current interpreter, so the environment remained isolated. But in Python >= 3.8.7 it creates a second subprocess without the -I flag, and the un-isolated environment appears to be restored for pip. This would then allow a search of any additional paths, and prevent installation of pip and setuptools from being installed in the venv environment directory if they are found somewhere else.

    2. added
      3.11only security fixes
      type-bugAn unexpected behavior, bug, or error
      on Dec 29, 2021
    3. merwok commented on Feb 3, 2022

      @merwok
      Member

      Thanks for the report and PR.

      The workflow would be to merge a fix to the main branch for 3.11, then there’s a bot that makes backports for active branches (3.10 and 3.9).

      More info: https://devguide.python.org/

    4. transferred this issue fromon Apr 10, 2022
    5. gvanrossum commented on May 16, 2022

      @gvanrossum
      Member

      @kcdodd Pleas follow instructions here.

    6. kcdodd commented on May 16, 2022

      @kcdodd
      ContributorAuthor

      @gvanrossum

      As stated in the issue, this should be rebased onto main and once accepted and merged there it can be backported. Probably a new PR is easiest.

      Should the pull request be to "main", or to "3.11"?

      Also, the "cpython-cla-bot" now marks that the CLA is not signed again. I have signed it and previously "the-knights-who-say-ni" had marked it as signed.

    7. gvanrossum commented on May 16, 2022

      @gvanrossum
      Member

      It should be main (that comment was written when 3.11==main, but now 3.11b1 was released and 3.12==main until next year). I'll look into the CLA bot.

    8. added a commit that references this issue on Jul 5, 2022
    9. added a commit that references this issue on Jul 5, 2022
    10. added a commit that references this issue on Jul 5, 2022
    11. added 6 commits that reference this issue on Jul 5, 2022
    12. ambv commented on Jul 5, 2022

      @ambv
      Contributor

      This is now fixed in 3.8 - 3.12. Thanks, Carter! ✨ 🍰 ✨

    Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

    Metadata

    Metadata

    Assignees

    No one assigned

      Labels

      3.10 (EOL)end of life3.11only security fixes3.8 (EOL)end of life3.9 (EOL)end of lifetype-bugAn unexpected behavior, bug, or error

      Projects

      No projects

        Milestone

        No milestone

        Relationships

        None yet

        Development

        No branches or pull requests

        Issue actions