-
-
Notifications
You must be signed in to change notification settings - Fork 32k
gh-97514: Authenticate the forkserver control socket. #99309
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
gpshead
merged 16 commits into
python:main
from
gpshead:security/multiprocessing-forkserver-authkey
Nov 20, 2024
Merged
Changes from all commits
Commits
Show all changes
16 commits
Select commit
Hold shift + click to select a range
d82afc8
Authenticate the forkserver control socket.
gpshead 72f3843
improve some error handling and add a test.
gpshead c83193d
NEWS entry.
gpshead 14f6f4d
Fix refleaks in the test.
gpshead 8c5f7f4
minor news wording tweak.
gpshead ca47b6f
fix the hang on macOS by removing part of the test.
gpshead 6f8e22f
clear up some comments and an assert
gpshead 3bbbda7
Merge branch 'main' into security/multiprocessing-forkserver-authkey
gpshead 0119b6a
Merge branch 'main' into security/multiprocessing-forkserver-authkey
gpshead ab9f93d
Add a comment about the fd recv acks.
gpshead 7d41b16
Merge branch 'main' into security/multiprocessing-forkserver-authkey
gpshead 6bb9db4
Address review comments: simplify & comment.
gpshead 9c22c06
Add a whatsnew entry.
gpshead 07c01d4
missing : sphinx-lint
gpshead a53c01f
Minor edits per @.picnixz code review comments.
gpshead db29006
Merge branch 'main' into security/multiprocessing-forkserver-authkey
gpshead File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
10 changes: 10 additions & 0 deletions
10
Misc/NEWS.d/next/Library/2022-11-10-17-16-45.gh-issue-97514.kzA0zl.rst
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,10 @@ | ||
Authentication was added to the :mod:`multiprocessing` forkserver start | ||
method control socket so that only processes with the authentication key | ||
generated by the process that spawned the forkserver can control it. This | ||
is an enhancement over the other :gh:`97514` fixes so that access is no | ||
longer limited only by filesystem permissions. | ||
|
||
The file descriptor exchange of control pipes with the forked worker process | ||
now requires an explicit acknowledgement byte to be sent over the socket after | ||
the exchange on all forkserver supporting platforms. That makes testing the | ||
above much easier. |
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.