[issue35755] Remove current directory from posixpath.defpath to enhance security

Jakub Wilk report at bugs.python.org
Wed Apr 17 11:06:12 EDT 2019


Jakub Wilk <jwilk at jwilk.net> added the comment:

(Note that in msg333835 another implementation, presumably GNU which, was tested.)

My point is that "which" implementations have different behavior, so justifying anything with "which" compatibility is weird at best. You can't be compatible with all them.

Also telling users that you "mimick Unix which command behavior" is unhelpful, because vast majority of users have no idea how it behaves in this corner case.

----------

_______________________________________
Python tracker <report at bugs.python.org>
<https://bugs.python.org/issue35755>
_______________________________________


More information about the Python-bugs-list mailing list