Repository navigation
gh-70331: Protect IDLE's imports from user files in the current directory - #157643
Conversation
… directory Start the user process with -P, so that the current directory is not on sys.path while idlelib.run and its dependencies are imported. sys.path is set later by transfer_path(). "python -m idlelib" now removes the current directory from sys.path.
terryjreedy
left a comment
There was a problem hiding this comment.
I once did some research on on what sys.path looks like after various methods of starting python without IDLE. Probably on some other issue. I should repeat and save somewhere in idlelib.
|
When you're done making the requested changes, leave the comment: |
|
Done for
Measured I have made the requested changes; please review again |
|
Thanks for making the requested changes! @terryjreedy: please review the changes made to this pull request. |
|
I included pyshell with idle(w) because it is also an entry point. I vaguely remember seeing is documented as such (though not sure if 'officially'). The lines Both were part of the initial commit. Should it not get the same treatment? |
|
Thanks @serhiy-storchaka for the PR, and @terryjreedy for merging it 🌮🎉.. I'm working now to backport this PR to: 3.13, 3.14, 3.15. |
|
GH-158034 is a backport of this pull request to the 3.15 branch. |
|
GH-158035 is a backport of this pull request to the 3.14 branch. |
|
GH-158036 is a backport of this pull request to the 3.13 branch. |
…t directory (GH-157643) (#158036) gh-70331: Protect IDLE's imports from user files in the current directory (GH-157643) Start the user process with -P, so that the current directory is not on sys.path while idlelib.run and its dependencies are imported. sys.path is set later by transfer_path(). Protect __main__, idle, and pyshell entry points. (cherry picked from commit 6893326) Co-authored-by: Serhiy Storchaka <storchaka@gmail.com>
…t directory (GH-157643) (#158035) gh-70331: Protect IDLE's imports from user files in the current directory (GH-157643) Start the user process with -P, so that the current directory is not on sys.path while idlelib.run and its dependencies are imported. sys.path is set later by transfer_path(). Protect __main__, idle, and pyshell entry points. (cherry picked from commit 6893326) Co-authored-by: Serhiy Storchaka <storchaka@gmail.com>
…t directory (GH-157643) (#158034) gh-70331: Protect IDLE's imports from user files in the current directory (GH-157643) Start the user process with -P, so that the current directory is not on sys.path while idlelib.run and its dependencies are imported. sys.path is set later by transfer_path(). Protect __main__, idle, and pyshell entry points. (cherry picked from commit 6893326) Co-authored-by: Serhiy Storchaka <storchaka@gmail.com>
A user file such as
random.py,threading.pyortkinter.pyin the directory from which IDLE was started (on Windows, "Edit with IDLE" starts it in the file's directory; on macOS, IDLE.app starts in~/Documents) shadowed the stdlib modules imported by IDLE, in the IDLE process (python -m idlelib) or in the user process (started withpython -c), and IDLE failed to start.Now the user process is started with
-P, so the current directory is not onsys.pathwhileidlelib.runand its dependencies are imported.sys.pathof the user process is set bytransfer_path()later anyway, so user code sees the samesys.pathas before.python -m idlelibremoves the current directory fromsys.pathbefore importingidlelib.pyshell, which imports almost all of IDLE.pyshell.main()still adds the current directory or the directories of the files to be edited tosys.pathof the IDLE process, so the few modules imported later (pydoc) can still be shadowed. Changing this would changesys.pathseen by user code, so it is left for a separate change.🤖 Generated with Claude Code