Skip to content

fix(security-guidance): preserve Python probe errors - #86746

Open
aayush598 wants to merge 1 commit into
anthropics:mainfrom
aayush598:fix/86709-sg-python-stderr
Open

aayush598 wants to merge 1 commit into
anthropics:mainfrom
aayush598:fix/86709-sg-python-stderr

Conversation

@aayush598

Copy link
Copy Markdown

What this does

Fixes #86709 by preserving stderr from Python interpreter probes and reporting the diagnostics when all candidate interpreters fail.

Previously, sg-python.sh redirected probe stderr to /dev/null. When python3, python, and py -3 all failed, users only saw the generic "no working Python 3 interpreter found" message, which made failures such as broken pyenv shims, Microsoft Store stubs, or transient process errors difficult to diagnose.

Changes

  • Capture probe stderr in a temporary file while checking each Python candidate.
  • Report the captured probe errors when no working Python 3 interpreter is found.
  • Keep probe stderr suppressed when a later candidate succeeds, preserving the existing fallback behavior.
  • Make diagnostic capture best-effort so failure to create the temporary log does not change the existing interpreter-selection behavior.
  • Clean up the temporary diagnostic file after interpreter selection.

Test plan

  • Reproduced the reported failure with broken python3 and python shims and verified their stderr is now included in the final error.
  • Verified that a failing python3 candidate can still fall through to a working python candidate without exposing the failed probe's stderr.
  • Verified the existing py -3 fallback remains functional.
  • Verified the shell script with bash -n.
  • Added a regression test covering the all-candidates-failed diagnostic path and fallback behavior.

Fixes #86709

@CanReader CanReader left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ran the new test: 24 passed on this branch, and with main's sg-python.sh 4 fail (the "probe errors:" ones), so it catches the bug. Also tried it by hand with no python on PATH, now I get the errors for python3, python and py instead of the generic message. With no mktemp it falls back to the old output without crashing, and the temp file is gone after success, failure and a SIGTERM.

Small things, all optional:

  • If errlog defaults to /dev/null when mktemp fails, probe can always use 2>>"$errlog" and you don't need the two branches with the same python line.
  • errlog="" before the mktemp line isn't needed, it's already empty when mktemp fails.
  • For a missing interpreter the output now includes bash's own message with the shim's line number (sg-python.sh: line 38: python3: command not found). Still useful, just a bit noisy.
  • Nothing in CI runs plugins/security-guidance/tests/ right now, so it only helps when someone runs it by hand.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

security-guidance: sg-python.sh discards probe stderr, misreporting any failing interpreter as 'no working Python 3'

2 participants