Skip to content

Make the pickle decoder for .pkl/.pickle opt-in (split from #16, item 3) #29

Description

@thorwhalen

Split out of #16 (item 3). The documentation half (warnings in config2py/codecs.py that .pkl/.pickle decode with pickle.loads and must never be used on untrusted bytes) lands in the cloud-sweep PR. This issue tracks the behaviour change.

Problem

decode_by_extension("x.pkl", untrusted_bytes) executes arbitrary code. Anything that routes keys from a remote store through the extension registry is exposed.

Why this was not changed unattended

Removing or gating the decoder changes what decode_by_extension('*.pkl', ...) does for existing callers who round-trip trusted pickles. It is a security-vs-convenience call for the maintainer.

Proposed plan

  1. Keep the encoder registered. Stop registering the decoder by default.
  2. Provide config2py.codecs.enable_pickle_decoding() (registers pickle.loads for .pkl and .pickle with overwrite=True) for callers who trust their data.
  3. Make the "No decoder registered" ValueError for .pkl/.pickle point to that function.
  4. Tests: default decode of .pkl raises with the hint; after enable_pickle_decoding() it round-trips. Run the dependents gate.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions