Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

Bug: Windows upload helper should quote URL-derived remote paths

Aberta Para iniciantes
#401 0 comentários 0 reações 0 responsáveis Ver no GitHub

Mantenedores costumam responder em até 1 dia

@e-q já está trabalhando nisso.

Desde 2/6/2026.

  • #402 de @e-q — aberto

Avaliação

Dificuldade
2/5
Tempo estimado
1-3 horas
Facilidade para iniciantes
78/100
Tipo de issue
Bug
Clareza
Claramente especificada
Status de atividade
Pouca atividade
Stack de tecnologia
python
Domínio
release

Direção de pesquisa

Comece por windows-release/merge-and-upload.py, especialmente por url2path, call_ssh, upload_ssh e pelo loop de upload que prepara diretórios e atualiza modos. Execute o reproducer fornecido e inspecione cada comando SSH e SCP capturado. O trabalho estará concluído quando os caminhos remotos derivados de URLs forem tratados como dados de caminho nos comandos de diretório, upload, grupo e modo, com cobertura de regressão para o caso do ponto e vírgula.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

windows-release/merge-and-upload.py converts installer metadata URLs from
__install__.json into remote filesystem paths. The resulting paths are then
used in SSH and SCP command arguments for directory creation, upload, group, and
mode updates.

The metadata is normally produced by the release process, but the URL-derived
path should still be treated as path data and quoted before it is passed through
remote command strings.

Reproducer

Run this from the repository root on the current base tree. It mocks the
subprocess boundary and does not contact the upload host:

import importlib.util
from pathlib import Path

script = Path("windows-release/merge-and-upload.py")
spec = importlib.util.spec_from_file_location("merge_and_upload_repro", script)
module = importlib.util.module_from_spec(spec)

try:
    spec.loader.exec_module(module)
except SystemExit:
    # The script exits when no local __install__.json files are present. The
    # upload helper functions are already defined by that point.
    pass

calls = []


def fake_run(*args, single_cmd=False):
    calls.append(args)
    return ""


module._run = fake_run
module.PLINK = "plink.exe"
module.PSCP = "pscp.exe"
module.UPLOAD_HOST = "downloads.example.org"
module.UPLOAD_USER = "release-manager"
module.NO_UPLOAD = False
module.LOCAL_INDEX = False

dest = module.url2path(
    "https://www.python.org/ftp/python/3.14.0;touch marker/"
    "python-3.14.0-amd64.exe"
)

# This matches the directory preparation code in the base upload loop.
destdir = dest.rpartition("/")[0]
module.call_ssh(f"mkdir {destdir} && chgrp downloads {destdir} && chmod a+rx {destdir}")
module.upload_ssh("python-3.14.0-amd64.exe", dest)

for call in calls:
    print(call)

The captured commands include the URL-derived path without shell quoting:

('plink.exe', '-batch', '[email protected]', 'mkdir /srv/www.python.org/ftp/python/3.14.0;touch marker && chgrp downloads /srv/www.python.org/ftp/python/3.14.0;touch marker && chmod a+rx /srv/www.python.org/ftp/python/3.14.0;touch marker')
('pscp.exe', '-batch', 'python-3.14.0-amd64.exe', '[email protected]:/srv/www.python.org/ftp/python/3.14.0;touch marker/python-3.14.0-amd64.exe')
('plink.exe', '-batch', '[email protected]', 'chgrp downloads /srv/www.python.org/ftp/python/3.14.0;touch marker/python-3.14.0-amd64.exe && chmod g-x,o+r /srv/www.python.org/ftp/python/3.14.0;touch marker/python-3.14.0-amd64.exe')

The semicolon from the metadata URL remains shell syntax in the generated
directory, upload, group, and mode commands.

Expected behavior

Remote paths derived from installer metadata URLs should be quoted as path data
before they are used in SSH command strings or SCP remote path arguments.

Linguagem predominante
Python
Estrelas
61
Forks
48
Merge médio
5h 50min
PRs com merge (30d)
6

Preparar o ambiente

Este projeto não oferece contêiner de desenvolvimento, Dockerfile nem guia de contribuição, então a configuração fica por sua conta: comece pelo README e veja nosso guia da primeira contribuição para os passos gerais.

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de python/release-tools

Todas as issues de python/release-tools

Issues semelhantes

Mais issues de Python

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.