Skip to content

fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs - #345

Closed
mcexit wants to merge 1 commit into
python:mainfrom
mcexit:patch-1
Closed

fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs#345
mcexit wants to merge 1 commit into
python:mainfrom
mcexit:patch-1

Conversation

@mcexit

Copy link
Copy Markdown

Description

This PR resolves a critical issue where scripts utilizing absolute or explicit relative shebangs (such as those generated by modern virtual environment managers like uv) are incorrectly intercepted, truncated, or routed to the wrong interpreter.

🐛 The Bugs

The original logic in _find_shebang_command heavily relied on pathlib.PurePath.match(). Because match() performs a loose right-aligned suffix match, PurePath("C:/uv/python.exe").match("python.exe") evaluates to True. This caused a chain reaction of unintended behaviors:

  1. The is_default Trap: Absolute paths like C:\...\python.exe incorrectly triggered the is_default check, discarding the user's isolated environment and defaulting to the system-wide global Python.
  2. The Wildcard Slicing Bug: The fallback check for python*.exe would intercept executables like C:\...\python_uv_test.exe and blindly slice the name ([6:-4]), causing the system to search for a phantom runtime tag (e.g., [ERROR] No runtime installed that matches _uv_test) and crash.
  3. Relative Execution Trap:sh_cmd.match(i["executable"]) could falsely intercept absolute shebangs if a registered runtime was using a relative executable name.

🛠️ The Fix

  • is_name_only Check: Introduced a check for path separators (/ or \) to properly distinguish between "bare names" (like py.exe or python3.14.exe) and explicit paths (C:\...\python.exe or ./python.exe).

    NOTE: This is significantly safer than checking len(sh_cmd.parts) == 1, which breaks explicit normalized relative paths (like #!./python.exe) by stripping the ./ and incorrectly flagging them as bare names.

  • Gated Fallbacks: Virtual alias lookup, the is_default override, and the tag extraction wildcards are now safely gated behind is_name_only.
  • Absolute vs Relative Validation: Added a condition (not PurePath(i["executable"]).is_absolute()) to prevent absolute shebangs from falsely matching relative executable registries.

🧪 Impact

With these changes, absolute paths are safely bypassed in the virtual lookup traps, allowing them to cleanly fall through to the LookupError at the end of the block. This exception is caught gracefully by _parse_shebang, which delegates the absolute path to shutil.which() under _find_on_path().

This restores 100% interoperability with tools like uv and explicit local paths (./python.exe), without breaking any existing PEP 397/PEP 486 behaviors for standard bare names.

…bare name rules
`PurePath.match()` performs right-aligned suffix matching, which caused absolute shebang paths (e.g., `C:\uv\python.exe`) to inadvertently evaluate true for bare names like `python.exe` or `python*.exe`.
This resulted in two critical bugs:
1. Virtual environment paths were hijacked by the `is_default` trap, falling back to the global default Python runtime instead of the specified one.
2. Custom executables (like `python_uv_test.exe`) were intercepted by the fallback wildcard search, resulting in arbitrary slicing and lookup errors for phantom version tags (e.g., `_uv_test`).
This commit introduces an `is_name_only` check (validating the absence of directory separators `/` and `\`) to safely distinguish bare commands from explicit paths. Gating the `is_default`, virtual alias, and wildcard extraction logic behind this check ensures explicit paths correctly fall through to `_find_on_path()`.
@python-cla-bot

python-cla-botBot commented May 22, 2026

Copy link
Copy Markdown

All commit authors signed the Contributor License Agreement.

CLA signed

@zooba

Copy link
Copy Markdown
Member

Please file an issue first, and leave out the cheesy headings and just focus on the problem you're observing and the context it appears in.

@zoobazooba closed this May 22, 2026
@zooba

Copy link
Copy Markdown
Member

Also, if an issue is "critical", please submit it as a security report using the Github Security Advisory feature. Otherwise, please refrain from assessing the severity of an issue - we can handle that, taking into account more than one single user.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@mcexit@zooba
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs by mcexit · Pull Request #345 · python/pymanager · GitHub
Skip to content

fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs - #345

Closed
mcexit wants to merge 1 commit into
python:mainfrom
mcexit:patch-1
Closed

fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs#345
mcexit wants to merge 1 commit into
python:mainfrom
mcexit:patch-1

Conversation

@mcexit

Copy link
Copy Markdown

Description

This PR resolves a critical issue where scripts utilizing absolute or explicit relative shebangs (such as those generated by modern virtual environment managers like uv) are incorrectly intercepted, truncated, or routed to the wrong interpreter.

🐛 The Bugs

The original logic in _find_shebang_command heavily relied on pathlib.PurePath.match(). Because match() performs a loose right-aligned suffix match, PurePath("C:/uv/python.exe").match("python.exe") evaluates to True. This caused a chain reaction of unintended behaviors:

  1. The is_default Trap: Absolute paths like C:\...\python.exe incorrectly triggered the is_default check, discarding the user's isolated environment and defaulting to the system-wide global Python.
  2. The Wildcard Slicing Bug: The fallback check for python*.exe would intercept executables like C:\...\python_uv_test.exe and blindly slice the name ([6:-4]), causing the system to search for a phantom runtime tag (e.g., [ERROR] No runtime installed that matches _uv_test) and crash.
  3. Relative Execution Trap:sh_cmd.match(i["executable"]) could falsely intercept absolute shebangs if a registered runtime was using a relative executable name.

🛠️ The Fix

  • is_name_only Check: Introduced a check for path separators (/ or \) to properly distinguish between "bare names" (like py.exe or python3.14.exe) and explicit paths (C:\...\python.exe or ./python.exe).

    NOTE: This is significantly safer than checking len(sh_cmd.parts) == 1, which breaks explicit normalized relative paths (like #!./python.exe) by stripping the ./ and incorrectly flagging them as bare names.

  • Gated Fallbacks: Virtual alias lookup, the is_default override, and the tag extraction wildcards are now safely gated behind is_name_only.
  • Absolute vs Relative Validation: Added a condition (not PurePath(i["executable"]).is_absolute()) to prevent absolute shebangs from falsely matching relative executable registries.

🧪 Impact

With these changes, absolute paths are safely bypassed in the virtual lookup traps, allowing them to cleanly fall through to the LookupError at the end of the block. This exception is caught gracefully by _parse_shebang, which delegates the absolute path to shutil.which() under _find_on_path().

This restores 100% interoperability with tools like uv and explicit local paths (./python.exe), without breaking any existing PEP 397/PEP 486 behaviors for standard bare names.

…bare name rules
`PurePath.match()` performs right-aligned suffix matching, which caused absolute shebang paths (e.g., `C:\uv\python.exe`) to inadvertently evaluate true for bare names like `python.exe` or `python*.exe`.
This resulted in two critical bugs:
1. Virtual environment paths were hijacked by the `is_default` trap, falling back to the global default Python runtime instead of the specified one.
2. Custom executables (like `python_uv_test.exe`) were intercepted by the fallback wildcard search, resulting in arbitrary slicing and lookup errors for phantom version tags (e.g., `_uv_test`).
This commit introduces an `is_name_only` check (validating the absence of directory separators `/` and `\`) to safely distinguish bare commands from explicit paths. Gating the `is_default`, virtual alias, and wildcard extraction logic behind this check ensures explicit paths correctly fall through to `_find_on_path()`.
@python-cla-bot

python-cla-botBot commented May 22, 2026

Copy link
Copy Markdown

All commit authors signed the Contributor License Agreement.

CLA signed

@zooba

Copy link
Copy Markdown
Member

Please file an issue first, and leave out the cheesy headings and just focus on the problem you're observing and the context it appears in.

@zoobazooba closed this May 22, 2026
@zooba

Copy link
Copy Markdown
Member

Also, if an issue is "critical", please submit it as a security report using the Github Security Advisory feature. Otherwise, please refrain from assessing the severity of an issue - we can handle that, taking into account more than one single user.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@mcexit@zooba
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs by mcexit · Pull Request #345 · python/pymanager · GitHub
Skip to content

fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs - #345

Closed
mcexit wants to merge 1 commit into
python:mainfrom
mcexit:patch-1
Closed

fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs#345
mcexit wants to merge 1 commit into
python:mainfrom
mcexit:patch-1

Conversation

@mcexit

Copy link
Copy Markdown

Description

This PR resolves a critical issue where scripts utilizing absolute or explicit relative shebangs (such as those generated by modern virtual environment managers like uv) are incorrectly intercepted, truncated, or routed to the wrong interpreter.

🐛 The Bugs

The original logic in _find_shebang_command heavily relied on pathlib.PurePath.match(). Because match() performs a loose right-aligned suffix match, PurePath("C:/uv/python.exe").match("python.exe") evaluates to True. This caused a chain reaction of unintended behaviors:

  1. The is_default Trap: Absolute paths like C:\...\python.exe incorrectly triggered the is_default check, discarding the user's isolated environment and defaulting to the system-wide global Python.
  2. The Wildcard Slicing Bug: The fallback check for python*.exe would intercept executables like C:\...\python_uv_test.exe and blindly slice the name ([6:-4]), causing the system to search for a phantom runtime tag (e.g., [ERROR] No runtime installed that matches _uv_test) and crash.
  3. Relative Execution Trap:sh_cmd.match(i["executable"]) could falsely intercept absolute shebangs if a registered runtime was using a relative executable name.

🛠️ The Fix

  • is_name_only Check: Introduced a check for path separators (/ or \) to properly distinguish between "bare names" (like py.exe or python3.14.exe) and explicit paths (C:\...\python.exe or ./python.exe).

    NOTE: This is significantly safer than checking len(sh_cmd.parts) == 1, which breaks explicit normalized relative paths (like #!./python.exe) by stripping the ./ and incorrectly flagging them as bare names.

  • Gated Fallbacks: Virtual alias lookup, the is_default override, and the tag extraction wildcards are now safely gated behind is_name_only.
  • Absolute vs Relative Validation: Added a condition (not PurePath(i["executable"]).is_absolute()) to prevent absolute shebangs from falsely matching relative executable registries.

🧪 Impact

With these changes, absolute paths are safely bypassed in the virtual lookup traps, allowing them to cleanly fall through to the LookupError at the end of the block. This exception is caught gracefully by _parse_shebang, which delegates the absolute path to shutil.which() under _find_on_path().

This restores 100% interoperability with tools like uv and explicit local paths (./python.exe), without breaking any existing PEP 397/PEP 486 behaviors for standard bare names.

…bare name rules
`PurePath.match()` performs right-aligned suffix matching, which caused absolute shebang paths (e.g., `C:\uv\python.exe`) to inadvertently evaluate true for bare names like `python.exe` or `python*.exe`.
This resulted in two critical bugs:
1. Virtual environment paths were hijacked by the `is_default` trap, falling back to the global default Python runtime instead of the specified one.
2. Custom executables (like `python_uv_test.exe`) were intercepted by the fallback wildcard search, resulting in arbitrary slicing and lookup errors for phantom version tags (e.g., `_uv_test`).
This commit introduces an `is_name_only` check (validating the absence of directory separators `/` and `\`) to safely distinguish bare commands from explicit paths. Gating the `is_default`, virtual alias, and wildcard extraction logic behind this check ensures explicit paths correctly fall through to `_find_on_path()`.
@python-cla-bot

python-cla-botBot commented May 22, 2026

Copy link
Copy Markdown

All commit authors signed the Contributor License Agreement.

CLA signed

@zooba

Copy link
Copy Markdown
Member

Please file an issue first, and leave out the cheesy headings and just focus on the problem you're observing and the context it appears in.

@zoobazooba closed this May 22, 2026
@zooba

Copy link
Copy Markdown
Member

Also, if an issue is "critical", please submit it as a security report using the Github Security Advisory feature. Otherwise, please refrain from assessing the severity of an issue - we can handle that, taking into account more than one single user.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@mcexit@zooba
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs by mcexit · Pull Request #345 · python/pymanager · GitHub
Skip to content

fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs - #345

Closed
mcexit wants to merge 1 commit into
python:mainfrom
mcexit:patch-1
Closed

fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs#345
mcexit wants to merge 1 commit into
python:mainfrom
mcexit:patch-1

Conversation

@mcexit

Copy link
Copy Markdown

Description

This PR resolves a critical issue where scripts utilizing absolute or explicit relative shebangs (such as those generated by modern virtual environment managers like uv) are incorrectly intercepted, truncated, or routed to the wrong interpreter.

🐛 The Bugs

The original logic in _find_shebang_command heavily relied on pathlib.PurePath.match(). Because match() performs a loose right-aligned suffix match, PurePath("C:/uv/python.exe").match("python.exe") evaluates to True. This caused a chain reaction of unintended behaviors:

  1. The is_default Trap: Absolute paths like C:\...\python.exe incorrectly triggered the is_default check, discarding the user's isolated environment and defaulting to the system-wide global Python.
  2. The Wildcard Slicing Bug: The fallback check for python*.exe would intercept executables like C:\...\python_uv_test.exe and blindly slice the name ([6:-4]), causing the system to search for a phantom runtime tag (e.g., [ERROR] No runtime installed that matches _uv_test) and crash.
  3. Relative Execution Trap:sh_cmd.match(i["executable"]) could falsely intercept absolute shebangs if a registered runtime was using a relative executable name.

🛠️ The Fix

  • is_name_only Check: Introduced a check for path separators (/ or \) to properly distinguish between "bare names" (like py.exe or python3.14.exe) and explicit paths (C:\...\python.exe or ./python.exe).

    NOTE: This is significantly safer than checking len(sh_cmd.parts) == 1, which breaks explicit normalized relative paths (like #!./python.exe) by stripping the ./ and incorrectly flagging them as bare names.

  • Gated Fallbacks: Virtual alias lookup, the is_default override, and the tag extraction wildcards are now safely gated behind is_name_only.
  • Absolute vs Relative Validation: Added a condition (not PurePath(i["executable"]).is_absolute()) to prevent absolute shebangs from falsely matching relative executable registries.

🧪 Impact

With these changes, absolute paths are safely bypassed in the virtual lookup traps, allowing them to cleanly fall through to the LookupError at the end of the block. This exception is caught gracefully by _parse_shebang, which delegates the absolute path to shutil.which() under _find_on_path().

This restores 100% interoperability with tools like uv and explicit local paths (./python.exe), without breaking any existing PEP 397/PEP 486 behaviors for standard bare names.

…bare name rules
`PurePath.match()` performs right-aligned suffix matching, which caused absolute shebang paths (e.g., `C:\uv\python.exe`) to inadvertently evaluate true for bare names like `python.exe` or `python*.exe`.
This resulted in two critical bugs:
1. Virtual environment paths were hijacked by the `is_default` trap, falling back to the global default Python runtime instead of the specified one.
2. Custom executables (like `python_uv_test.exe`) were intercepted by the fallback wildcard search, resulting in arbitrary slicing and lookup errors for phantom version tags (e.g., `_uv_test`).
This commit introduces an `is_name_only` check (validating the absence of directory separators `/` and `\`) to safely distinguish bare commands from explicit paths. Gating the `is_default`, virtual alias, and wildcard extraction logic behind this check ensures explicit paths correctly fall through to `_find_on_path()`.
@python-cla-bot

python-cla-botBot commented May 22, 2026

Copy link
Copy Markdown

All commit authors signed the Contributor License Agreement.

CLA signed

@zooba

Copy link
Copy Markdown
Member

Please file an issue first, and leave out the cheesy headings and just focus on the problem you're observing and the context it appears in.

@zoobazooba closed this May 22, 2026
@zooba

Copy link
Copy Markdown
Member

Also, if an issue is "critical", please submit it as a security report using the Github Security Advisory feature. Otherwise, please refrain from assessing the severity of an issue - we can handle that, taking into account more than one single user.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@mcexit@zooba
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs by mcexit · Pull Request #345 · python/pymanager · GitHub
Skip to content

fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs - #345

Closed
mcexit wants to merge 1 commit into
python:mainfrom
mcexit:patch-1
Closed

fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs#345
mcexit wants to merge 1 commit into
python:mainfrom
mcexit:patch-1

Conversation

@mcexit

Copy link
Copy Markdown

Description

This PR resolves a critical issue where scripts utilizing absolute or explicit relative shebangs (such as those generated by modern virtual environment managers like uv) are incorrectly intercepted, truncated, or routed to the wrong interpreter.

🐛 The Bugs

The original logic in _find_shebang_command heavily relied on pathlib.PurePath.match(). Because match() performs a loose right-aligned suffix match, PurePath("C:/uv/python.exe").match("python.exe") evaluates to True. This caused a chain reaction of unintended behaviors:

  1. The is_default Trap: Absolute paths like C:\...\python.exe incorrectly triggered the is_default check, discarding the user's isolated environment and defaulting to the system-wide global Python.
  2. The Wildcard Slicing Bug: The fallback check for python*.exe would intercept executables like C:\...\python_uv_test.exe and blindly slice the name ([6:-4]), causing the system to search for a phantom runtime tag (e.g., [ERROR] No runtime installed that matches _uv_test) and crash.
  3. Relative Execution Trap:sh_cmd.match(i["executable"]) could falsely intercept absolute shebangs if a registered runtime was using a relative executable name.

🛠️ The Fix

  • is_name_only Check: Introduced a check for path separators (/ or \) to properly distinguish between "bare names" (like py.exe or python3.14.exe) and explicit paths (C:\...\python.exe or ./python.exe).

    NOTE: This is significantly safer than checking len(sh_cmd.parts) == 1, which breaks explicit normalized relative paths (like #!./python.exe) by stripping the ./ and incorrectly flagging them as bare names.

  • Gated Fallbacks: Virtual alias lookup, the is_default override, and the tag extraction wildcards are now safely gated behind is_name_only.
  • Absolute vs Relative Validation: Added a condition (not PurePath(i["executable"]).is_absolute()) to prevent absolute shebangs from falsely matching relative executable registries.

🧪 Impact

With these changes, absolute paths are safely bypassed in the virtual lookup traps, allowing them to cleanly fall through to the LookupError at the end of the block. This exception is caught gracefully by _parse_shebang, which delegates the absolute path to shutil.which() under _find_on_path().

This restores 100% interoperability with tools like uv and explicit local paths (./python.exe), without breaking any existing PEP 397/PEP 486 behaviors for standard bare names.

…bare name rules
`PurePath.match()` performs right-aligned suffix matching, which caused absolute shebang paths (e.g., `C:\uv\python.exe`) to inadvertently evaluate true for bare names like `python.exe` or `python*.exe`.
This resulted in two critical bugs:
1. Virtual environment paths were hijacked by the `is_default` trap, falling back to the global default Python runtime instead of the specified one.
2. Custom executables (like `python_uv_test.exe`) were intercepted by the fallback wildcard search, resulting in arbitrary slicing and lookup errors for phantom version tags (e.g., `_uv_test`).
This commit introduces an `is_name_only` check (validating the absence of directory separators `/` and `\`) to safely distinguish bare commands from explicit paths. Gating the `is_default`, virtual alias, and wildcard extraction logic behind this check ensures explicit paths correctly fall through to `_find_on_path()`.
@python-cla-bot

python-cla-botBot commented May 22, 2026

Copy link
Copy Markdown

All commit authors signed the Contributor License Agreement.

CLA signed

@zooba

Copy link
Copy Markdown
Member

Please file an issue first, and leave out the cheesy headings and just focus on the problem you're observing and the context it appears in.

@zoobazooba closed this May 22, 2026
@zooba

Copy link
Copy Markdown
Member

Also, if an issue is "critical", please submit it as a security report using the Github Security Advisory feature. Otherwise, please refrain from assessing the severity of an issue - we can handle that, taking into account more than one single user.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@mcexit@zooba
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs by mcexit · Pull Request #345 · python/pymanager · GitHub
Skip to content

fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs - #345

Closed
mcexit wants to merge 1 commit into
python:mainfrom
mcexit:patch-1
Closed

fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs#345
mcexit wants to merge 1 commit into
python:mainfrom
mcexit:patch-1

Conversation

@mcexit

Copy link
Copy Markdown

Description

This PR resolves a critical issue where scripts utilizing absolute or explicit relative shebangs (such as those generated by modern virtual environment managers like uv) are incorrectly intercepted, truncated, or routed to the wrong interpreter.

🐛 The Bugs

The original logic in _find_shebang_command heavily relied on pathlib.PurePath.match(). Because match() performs a loose right-aligned suffix match, PurePath("C:/uv/python.exe").match("python.exe") evaluates to True. This caused a chain reaction of unintended behaviors:

  1. The is_default Trap: Absolute paths like C:\...\python.exe incorrectly triggered the is_default check, discarding the user's isolated environment and defaulting to the system-wide global Python.
  2. The Wildcard Slicing Bug: The fallback check for python*.exe would intercept executables like C:\...\python_uv_test.exe and blindly slice the name ([6:-4]), causing the system to search for a phantom runtime tag (e.g., [ERROR] No runtime installed that matches _uv_test) and crash.
  3. Relative Execution Trap:sh_cmd.match(i["executable"]) could falsely intercept absolute shebangs if a registered runtime was using a relative executable name.

🛠️ The Fix

  • is_name_only Check: Introduced a check for path separators (/ or \) to properly distinguish between "bare names" (like py.exe or python3.14.exe) and explicit paths (C:\...\python.exe or ./python.exe).

    NOTE: This is significantly safer than checking len(sh_cmd.parts) == 1, which breaks explicit normalized relative paths (like #!./python.exe) by stripping the ./ and incorrectly flagging them as bare names.

  • Gated Fallbacks: Virtual alias lookup, the is_default override, and the tag extraction wildcards are now safely gated behind is_name_only.
  • Absolute vs Relative Validation: Added a condition (not PurePath(i["executable"]).is_absolute()) to prevent absolute shebangs from falsely matching relative executable registries.

🧪 Impact

With these changes, absolute paths are safely bypassed in the virtual lookup traps, allowing them to cleanly fall through to the LookupError at the end of the block. This exception is caught gracefully by _parse_shebang, which delegates the absolute path to shutil.which() under _find_on_path().

This restores 100% interoperability with tools like uv and explicit local paths (./python.exe), without breaking any existing PEP 397/PEP 486 behaviors for standard bare names.

…bare name rules
`PurePath.match()` performs right-aligned suffix matching, which caused absolute shebang paths (e.g., `C:\uv\python.exe`) to inadvertently evaluate true for bare names like `python.exe` or `python*.exe`.
This resulted in two critical bugs:
1. Virtual environment paths were hijacked by the `is_default` trap, falling back to the global default Python runtime instead of the specified one.
2. Custom executables (like `python_uv_test.exe`) were intercepted by the fallback wildcard search, resulting in arbitrary slicing and lookup errors for phantom version tags (e.g., `_uv_test`).
This commit introduces an `is_name_only` check (validating the absence of directory separators `/` and `\`) to safely distinguish bare commands from explicit paths. Gating the `is_default`, virtual alias, and wildcard extraction logic behind this check ensures explicit paths correctly fall through to `_find_on_path()`.
@python-cla-bot

python-cla-botBot commented May 22, 2026

Copy link
Copy Markdown

All commit authors signed the Contributor License Agreement.

CLA signed

@zooba

Copy link
Copy Markdown
Member

Please file an issue first, and leave out the cheesy headings and just focus on the problem you're observing and the context it appears in.

@zoobazooba closed this May 22, 2026
@zooba

Copy link
Copy Markdown
Member

Also, if an issue is "critical", please submit it as a security report using the Github Security Advisory feature. Otherwise, please refrain from assessing the severity of an issue - we can handle that, taking into account more than one single user.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@mcexit@zooba
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs by mcexit · Pull Request #345 · python/pymanager · GitHub
Skip to content

fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs - #345

Closed
mcexit wants to merge 1 commit into
python:mainfrom
mcexit:patch-1
Closed

fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs#345
mcexit wants to merge 1 commit into
python:mainfrom
mcexit:patch-1

Conversation

@mcexit

Copy link
Copy Markdown

Description

This PR resolves a critical issue where scripts utilizing absolute or explicit relative shebangs (such as those generated by modern virtual environment managers like uv) are incorrectly intercepted, truncated, or routed to the wrong interpreter.

🐛 The Bugs

The original logic in _find_shebang_command heavily relied on pathlib.PurePath.match(). Because match() performs a loose right-aligned suffix match, PurePath("C:/uv/python.exe").match("python.exe") evaluates to True. This caused a chain reaction of unintended behaviors:

  1. The is_default Trap: Absolute paths like C:\...\python.exe incorrectly triggered the is_default check, discarding the user's isolated environment and defaulting to the system-wide global Python.
  2. The Wildcard Slicing Bug: The fallback check for python*.exe would intercept executables like C:\...\python_uv_test.exe and blindly slice the name ([6:-4]), causing the system to search for a phantom runtime tag (e.g., [ERROR] No runtime installed that matches _uv_test) and crash.
  3. Relative Execution Trap:sh_cmd.match(i["executable"]) could falsely intercept absolute shebangs if a registered runtime was using a relative executable name.

🛠️ The Fix

  • is_name_only Check: Introduced a check for path separators (/ or \) to properly distinguish between "bare names" (like py.exe or python3.14.exe) and explicit paths (C:\...\python.exe or ./python.exe).

    NOTE: This is significantly safer than checking len(sh_cmd.parts) == 1, which breaks explicit normalized relative paths (like #!./python.exe) by stripping the ./ and incorrectly flagging them as bare names.

  • Gated Fallbacks: Virtual alias lookup, the is_default override, and the tag extraction wildcards are now safely gated behind is_name_only.
  • Absolute vs Relative Validation: Added a condition (not PurePath(i["executable"]).is_absolute()) to prevent absolute shebangs from falsely matching relative executable registries.

🧪 Impact

With these changes, absolute paths are safely bypassed in the virtual lookup traps, allowing them to cleanly fall through to the LookupError at the end of the block. This exception is caught gracefully by _parse_shebang, which delegates the absolute path to shutil.which() under _find_on_path().

This restores 100% interoperability with tools like uv and explicit local paths (./python.exe), without breaking any existing PEP 397/PEP 486 behaviors for standard bare names.

…bare name rules
`PurePath.match()` performs right-aligned suffix matching, which caused absolute shebang paths (e.g., `C:\uv\python.exe`) to inadvertently evaluate true for bare names like `python.exe` or `python*.exe`.
This resulted in two critical bugs:
1. Virtual environment paths were hijacked by the `is_default` trap, falling back to the global default Python runtime instead of the specified one.
2. Custom executables (like `python_uv_test.exe`) were intercepted by the fallback wildcard search, resulting in arbitrary slicing and lookup errors for phantom version tags (e.g., `_uv_test`).
This commit introduces an `is_name_only` check (validating the absence of directory separators `/` and `\`) to safely distinguish bare commands from explicit paths. Gating the `is_default`, virtual alias, and wildcard extraction logic behind this check ensures explicit paths correctly fall through to `_find_on_path()`.
@python-cla-bot

python-cla-botBot commented May 22, 2026

Copy link
Copy Markdown

All commit authors signed the Contributor License Agreement.

CLA signed

@zooba

Copy link
Copy Markdown
Member

Please file an issue first, and leave out the cheesy headings and just focus on the problem you're observing and the context it appears in.

@zoobazooba closed this May 22, 2026
@zooba

Copy link
Copy Markdown
Member

Also, if an issue is "critical", please submit it as a security report using the Github Security Advisory feature. Otherwise, please refrain from assessing the severity of an issue - we can handle that, taking into account more than one single user.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@mcexit@zooba
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs by mcexit · Pull Request #345 · python/pymanager · GitHub
Skip to content

fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs - #345

Closed
mcexit wants to merge 1 commit into
python:mainfrom
mcexit:patch-1
Closed

fix(scriptutils): fix path resolution and wildcard extraction for absolute shebangs#345
mcexit wants to merge 1 commit into
python:mainfrom
mcexit:patch-1

Conversation

@mcexit

Copy link
Copy Markdown

Description

This PR resolves a critical issue where scripts utilizing absolute or explicit relative shebangs (such as those generated by modern virtual environment managers like uv) are incorrectly intercepted, truncated, or routed to the wrong interpreter.

🐛 The Bugs

The original logic in _find_shebang_command heavily relied on pathlib.PurePath.match(). Because match() performs a loose right-aligned suffix match, PurePath("C:/uv/python.exe").match("python.exe") evaluates to True. This caused a chain reaction of unintended behaviors:

  1. The is_default Trap: Absolute paths like C:\...\python.exe incorrectly triggered the is_default check, discarding the user's isolated environment and defaulting to the system-wide global Python.
  2. The Wildcard Slicing Bug: The fallback check for python*.exe would intercept executables like C:\...\python_uv_test.exe and blindly slice the name ([6:-4]), causing the system to search for a phantom runtime tag (e.g., [ERROR] No runtime installed that matches _uv_test) and crash.
  3. Relative Execution Trap:sh_cmd.match(i["executable"]) could falsely intercept absolute shebangs if a registered runtime was using a relative executable name.

🛠️ The Fix

  • is_name_only Check: Introduced a check for path separators (/ or \) to properly distinguish between "bare names" (like py.exe or python3.14.exe) and explicit paths (C:\...\python.exe or ./python.exe).

    NOTE: This is significantly safer than checking len(sh_cmd.parts) == 1, which breaks explicit normalized relative paths (like #!./python.exe) by stripping the ./ and incorrectly flagging them as bare names.

  • Gated Fallbacks: Virtual alias lookup, the is_default override, and the tag extraction wildcards are now safely gated behind is_name_only.
  • Absolute vs Relative Validation: Added a condition (not PurePath(i["executable"]).is_absolute()) to prevent absolute shebangs from falsely matching relative executable registries.

🧪 Impact

With these changes, absolute paths are safely bypassed in the virtual lookup traps, allowing them to cleanly fall through to the LookupError at the end of the block. This exception is caught gracefully by _parse_shebang, which delegates the absolute path to shutil.which() under _find_on_path().

This restores 100% interoperability with tools like uv and explicit local paths (./python.exe), without breaking any existing PEP 397/PEP 486 behaviors for standard bare names.

…bare name rules
`PurePath.match()` performs right-aligned suffix matching, which caused absolute shebang paths (e.g., `C:\uv\python.exe`) to inadvertently evaluate true for bare names like `python.exe` or `python*.exe`.
This resulted in two critical bugs:
1. Virtual environment paths were hijacked by the `is_default` trap, falling back to the global default Python runtime instead of the specified one.
2. Custom executables (like `python_uv_test.exe`) were intercepted by the fallback wildcard search, resulting in arbitrary slicing and lookup errors for phantom version tags (e.g., `_uv_test`).
This commit introduces an `is_name_only` check (validating the absence of directory separators `/` and `\`) to safely distinguish bare commands from explicit paths. Gating the `is_default`, virtual alias, and wildcard extraction logic behind this check ensures explicit paths correctly fall through to `_find_on_path()`.
@python-cla-bot

python-cla-botBot commented May 22, 2026

Copy link
Copy Markdown

All commit authors signed the Contributor License Agreement.

CLA signed

@zooba

Copy link
Copy Markdown
Member

Please file an issue first, and leave out the cheesy headings and just focus on the problem you're observing and the context it appears in.

@zoobazooba closed this May 22, 2026
@zooba

Copy link
Copy Markdown
Member

Also, if an issue is "critical", please submit it as a security report using the Github Security Advisory feature. Otherwise, please refrain from assessing the severity of an issue - we can handle that, taking into account more than one single user.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@mcexit@zooba