Repository navigation
fix(security-guidance): launch Python once per hook, not twice - #2
Merged
adri22235 merged 1 commit intoOct 2, 2026
Merged
Conversation
…not twice sg-python.sh probed each candidate and then exec'd the chosen one, so every hook cost at least two interpreter launches. On Windows with the Python Install Manager, each launch of the WindowsApps alias starts an AppX update that leaks ~1.6 MB in AppXSvc, which exhausted system commit in the report. Cache the name of the candidate that passed the probe (python3, python or py -3 only; never run arbitrary file contents) in ~/.claude/security/python-cmd. Later hooks exec it directly with a single launch. The entry expires after a day and is ignored when the command is no longer on PATH. Cache failures never block the hook. Not addressed here: preferring real interpreter paths over WindowsApps aliases. Addresses upstream issue 98929 (Windows: py -3 launched twice per hook). Co-Authored-By: Claude Sonnet 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01LoLAv3aLaRJocsRMcjFbpv
adri22235
marked this pull request as ready for review
October 2, 2026 16:14
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Addresses upstream issue 98929 (Windows:
sg-python.shlaunchespy -3twice per hook; each launch of the Python Install Manager alias starts an AppX update that leaks ~1.6 MB in AppXSvc).sg-python.shprobed each candidate with-cand thenexec'd the chosen one, so every hook cost at least two interpreter launches, more when earlier candidates (for example the Store stub) also had to be probed and failed.~/.claude/security/python-cmd(override withSG_PYTHON_CACHE).execit directly: one launch, no probing.python3,pythonorpy -3are accepted from the cache; the file's contents are never run as-is.PATH, so a changed or removed interpreter falls back to probing.Stacked on the first PR in this fork (
integration/page1-fixes), because it builds on that branch'ssg-python.shchange. Retarget tomainonce that one lands.Not addressed: preferring real interpreter paths over
%LOCALAPPDATA%\Microsoft\WindowsAppsaliases (the issue's third suggestion). The cold run still launches twice, once per day at most.Test plan
plugins/security-guidance/tests/test-sg-python.sh: 42 checks pass (18 new): warm run launches once,py -3cached with its flag, unrecognised cache content ignored and never executed, missing command falls back, expired entry re-probed, unwritable cache location toleratedpython3, warm run works, hook stdin still reaches the interpreterplugins/security-guidance/tests(37) andtest_extensibility(17) still pass🤖 Generated with Claude Code
https://claude.ai/code/session_01LoLAv3aLaRJocsRMcjFbpv
Generated by Claude Code