On Tue, 10 May 2016 at 01:18 Martin Panter <vadmium...@gmail.com> wrote:

> I am working on <https://bugs.python.org/issue22636>, to fix shell
> injection problems with ctypes.util.find_library(). The proposal for
> Python 3 is to change os.popen(shell-script) calls to use
> subprocess.Popen().
>
> However the Python 2.7 version of the module has a comment which says
> “This file should be kept compatible with Python 2.3, see PEP 291.”
> Looking at <https://www.python.org/dev/peps/pep-0291/>, it is not
> clear why we have to maintain this compatibility. My best guess is
> that there may be an external ctypes package that people want(ed) to
> keep compatible with 2.3, and also keep synchronized with 2.7.
>

That's correct and the maintainer is/was Thomas Heller who I have cc'ed to
see if he's okay with lifting the restriction.

-Brett
_______________________________________________
Python-Dev mailing list
Python-Dev@python.org
https://mail.python.org/mailman/listinfo/python-dev
Unsubscribe: 
https://mail.python.org/mailman/options/python-dev/archive%40mail-archive.com

Reply via email to