Repository navigation
ensurepip bootstrap breaks out of isolated environment #90355
Description
Activity
A change in behavior was made to the
ensurepipmodule in Python 3.8.7 that causes bootstrapping to break out of an isolated environment. This is relevant to the assumption made in thevenvmodule, which ran ensurepip as a sub-process with the-Iflag environment isolation to force installation in the virtual environment directory.In Python <= 3.8.6, ensurepip ran the bootstrap within the current interpreter, so the environment remained isolated. But in Python >= 3.8.7 it creates a second subprocess without the
-Iflag, and the un-isolated environment appears to be restored for pip. This would then allow a search of any additional paths, and prevent installation of pip and setuptools from being installed in the venv environment directory if they are found somewhere else.- added3.8 (EOL)end of lifeend of life3.9 (EOL)end of lifeend of life3.10 (EOL)end of lifeend of life3.11only security fixesonly security fixestype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on Dec 29, 2021 Thanks for the report and PR.
The workflow would be to merge a fix to the main branch for 3.11, then there’s a bot that makes backports for active branches (3.10 and 3.9).
More info: https://devguide.python.org/
@kcdodd Pleas follow instructions here.
As stated in the issue, this should be rebased onto main and once accepted and merged there it can be backported. Probably a new PR is easiest.
Should the pull request be to "main", or to "3.11"?
Also, the "cpython-cla-bot" now marks that the CLA is not signed again. I have signed it and previously "the-knights-who-say-ni" had marked it as signed.
It should be main (that comment was written when 3.11==main, but now 3.11b1 was released and 3.12==main until next year). I'll look into the CLA bot.
- added a commit that references this issue
on Jul 5, 2022 - added 6 commits that reference this issue
on Jul 5, 2022 This is now fixed in 3.8 - 3.12. Thanks, Carter! ✨ 🍰 ✨
Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
bugs.python.org fields: