Author steve.dower
Recipients brett.cannon, gregory.p.smith, jamesls, lukasz.langa, omnios, steve.dower
Date 2021-05-07.23:52:07
SpamBayes Score -1.0
Marked as misclassified Yes
Message-id <1620431527.79.0.22155657049.issue44070@roundup.psfhosted.org>
In-reply-to
Content
Yeah, you're probably right. That effect was not noticed when implementing it.

We should update the fix in 3.9 and 3.8 to limit it to .pyd's on Windows to protect against the security risks, but leave other import types loaded with relative paths.

I think it's fine to leave the resolution in 3.10, as it's closer to the intended behaviour.

I also don't think that fixing this justifies an extra maintenance release of 3.8, which is now in security-fix only mode, but I'll leave that decision to the RM.
History
Date User Action Args
2021-05-07 23:52:07steve.dowersetrecipients: + steve.dower, brett.cannon, gregory.p.smith, lukasz.langa, jamesls, omnios
2021-05-07 23:52:07steve.dowersetmessageid: <1620431527.79.0.22155657049.issue44070@roundup.psfhosted.org>
2021-05-07 23:52:07steve.dowerlinkissue44070 messages
2021-05-07 23:52:07steve.dowercreate