Skip to content

fix(security-guidance): launch Python once per hook, not twice - #2

Merged
adri22235 merged 1 commit into
integration/page1-fixesfrom
fix/98929-sg-python-single-launch
Oct 2, 2026
Merged

adri22235 merged 1 commit into
integration/page1-fixesfrom
fix/98929-sg-python-single-launch

Conversation

@adri22235

Copy link
Copy Markdown
Owner

Summary

Addresses upstream issue 98929 (Windows: sg-python.sh launches py -3 twice per hook; each launch of the Python Install Manager alias starts an AppX update that leaks ~1.6 MB in AppXSvc).

sg-python.sh probed each candidate with -c and then exec'd the chosen one, so every hook cost at least two interpreter launches, more when earlier candidates (for example the Store stub) also had to be probed and failed.

  • Cache the name of the candidate that passed the probe in ~/.claude/security/python-cmd (override with SG_PYTHON_CACHE).
  • Later hooks exec it directly: one launch, no probing.
  • Only python3, python or py -3 are accepted from the cache; the file's contents are never run as-is.
  • The entry expires after a day and is ignored if the command is no longer on PATH, so a changed or removed interpreter falls back to probing.
  • A cache that cannot be read or written never blocks the hook.

Stacked on the first PR in this fork (integration/page1-fixes), because it builds on that branch's sg-python.sh change. Retarget to main once that one lands.

Not addressed: preferring real interpreter paths over %LOCALAPPDATA%\Microsoft\WindowsApps aliases (the issue's third suggestion). The cold run still launches twice, once per day at most.

Test plan

  • plugins/security-guidance/tests/test-sg-python.sh: 42 checks pass (18 new): warm run launches once, py -3 cached with its flag, unrecognised cache content ignored and never executed, missing command falls back, expired entry re-probed, unwritable cache location tolerated
  • Real interpreter, end to end: cold run caches python3, warm run works, hook stdin still reaches the interpreter
  • plugins/security-guidance/tests (37) and test_extensibility (17) still pass
  • Not tested on Windows with the Python Install Manager: needs the reporter's setup

🤖 Generated with Claude Code

https://claude.ai/code/session_01LoLAv3aLaRJocsRMcjFbpv


Generated by Claude Code

…not twice

sg-python.sh probed each candidate and then exec'd the chosen one, so every
hook cost at least two interpreter launches. On Windows with the Python
Install Manager, each launch of the WindowsApps alias starts an AppX update
that leaks ~1.6 MB in AppXSvc, which exhausted system commit in the report.

Cache the name of the candidate that passed the probe (python3, python or
py -3 only; never run arbitrary file contents) in ~/.claude/security/python-cmd.
Later hooks exec it directly with a single launch. The entry expires after a
day and is ignored when the command is no longer on PATH. Cache failures never
block the hook.

Not addressed here: preferring real interpreter paths over WindowsApps aliases.

Addresses upstream issue 98929 (Windows: py -3 launched twice per hook).

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01LoLAv3aLaRJocsRMcjFbpv
@adri22235
adri22235 marked this pull request as ready for review October 2, 2026 16:14
@adri22235
adri22235 merged commit 610f266 into integration/page1-fixes Oct 2, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants