<#22441 semgrep backend fails with `... uname ... ...
# github-notifications
c
#22441 semgrep backend fails with `... uname ... no such file or directory` if run with restricted paths Issue created by huonw Describe the bug If one is using a Python provider and then restricts the various "leaks" of
PATH
, the semgrep backend starts failing when invoking semgrep, which seems to require some system binaries:
uname
, and (on macOS)
security
. For instance, this configuration locks down all the paths: [GLOBAL] pants_version = "2.27.0" backend_packages = [ "pants.backend.experimental.tools.semgrep", "pants.backend.python.providers.experimental.python_build_standalone", ] [python] interpreter_constraints = ["==3.11.*"] [pex] executable_search_paths = [] # Workaround: set to
["/usr/bin"]
[python-bootstrap] search_path = [] [subprocess-environment] env_vars = [] Output like:
Copy code
16:31:24.99 [ERROR] Completed: Lint with Semgrep - semgrep failed (exit code 2).
Partition: .semgrep.yml
Fatal error: exception Failure("run ['uname' '-s']: No such file or directory")
Raised at Stdlib.failwith in file "<http://stdlib.ml|stdlib.ml>", line 29, characters 17-33
Called from CamlinternalLazy.force_lazy_block in file "<http://camlinternalLazy.ml|camlinternalLazy.ml>", line 31, characters 17-27
Re-raised at CamlinternalLazy.force_lazy_block in file "<http://camlinternalLazy.ml|camlinternalLazy.ml>", line 36, characters 4-11
Called from Conduit_lwt_unix.default_ctx in file "src/conduit-lwt-unix/conduit_lwt_unix.ml", line 158, characters 26-79
Called from CamlinternalLazy.force_lazy_block in file "<http://camlinternalLazy.ml|camlinternalLazy.ml>", line 31, characters 17-27
Re-raised at CamlinternalLazy.force_lazy_block in file "<http://camlinternalLazy.ml|camlinternalLazy.ml>", line 36, characters 4-11
Called from Cohttp_lwt_unix__Net.default_ctx in file "cohttp-lwt-unix/src/net.ml", line 33, characters 10-49


āœ• semgrep failed.
A workaround is to ensure that those two binaries specifically are available on the PATH. Full reproducer, including demonstration of the workaround: cd $(mktemp -d) cat > pants.toml <<EOF [GLOBAL] pants_version = "2.27.0" backend_packages = [ "pants.backend.experimental.tools.semgrep", "pants.backend.python.providers.experimental.python_build_standalone", ] [python] interpreter_constraints = ["==3.11.*"] [pex] executable_search_paths = [] [python-bootstrap] search_path = [] [subprocess-environment] env_vars = [] EOF cat > BUILD <<EOF file(name="foo", source="foo.txt") EOF echo x > foo.txt cat > .semgrep.yml <<EOF rules: - id: x patterns: - pattern: x message: found an x languages: [generic] severity: ERROR EOF # BUG: Fatal error: exception Failure("run ['uname' '-s']: No such file or directory") pants lint :: # WORKAROUND cat > pants.toml <<EOF [GLOBAL] pants_version = "2.27.0" backend_packages = [ "pants.backend.experimental.tools.semgrep", "pants.backend.python.providers.experimental.python_build_standalone", ] [python] interpreter_constraints = ["==3.11.*"] [pex] executable_search_paths = ["/usr/bin"] # CHANGED [python-bootstrap] search_path = [] [subprocess-environment] env_vars = [] EOF pants lint :: Pants version 2.27.0 OS macOS Additional info N/A pantsbuild/pants