Skip to content

Stop the Python extension from writing files into the app bundle - #16581

Open
juliasilge wants to merge 1 commit into
mainfrom
python-no-writes-in-app-bundle
Open

juliasilge wants to merge 1 commit into
mainfrom
python-no-writes-in-app-bundle

Conversation

@juliasilge

Copy link
Copy Markdown
Member

Fixes #12281

What used to happen

The issue was first reported on 2026.03.0, quite a while ago. After the first launch, codesign --verify --deep --strict on Positron.app failed with "a sealed resource is missing or invalid". At that time, the extra files came from the Copilot extension. It copied rg, pty.node, and spawn-helper into its node_modules folder at runtime.

An upstream change removed the Copilot part. Built-in installs now ship a shims.txt placeholder, and Copilot does not copy these files when that placeholder is present. On 2026.11.0-17, the Copilot files no longer appear.

However, the signature was still not valid on 2026.11.0-17, because the Python extension wrote 26 files into the bundle:

  • python_files/deactivate/zsh/envVars.txt: the terminal deactivate service wrote this file on each launch. The service starts a hidden terminal and writes the shell environment (PATH, PS1) to a file next to the deactivate script. That script is in the extension folder, inside the app bundle.
  • 25 .pyc files in python_files/lib/python/{packaging,tomli,importlib_metadata}/__pycache__: installed_check.py imports these libraries when you open a requirements.txt or pyproject.toml file. Python wrote their bytecode next to the source files.

I believe that a changed bundle can cause problems on managed Macs that check the signature again. On read-only installs (a root-owned /Applications, Linux packages, Windows system installs), the envVars.txt write failed. Then the deactivate command in venv terminals did not work, and the service waited 30 seconds for the file.

I also started a Python console, ran code, and quit. The kernel did not add files to the bundle.

How this PR fixes it

  • The deactivate service now uses globalStorageUri/deactivate/<shell> instead of the extension folder. Before it writes envVars.txt, it copies the shipped deactivate (or deactivate.ps1) script to that folder. The scripts read envVars.txt from their own folder, so they did not need changes. The folder that the service adds to the terminal PATH is now the storage folder.
  • installed_check.py now runs with PYTHONDONTWRITEBYTECODE=1.

Both files are upstream vscode-python files, so the changes are inside Positron fences.

Release Notes

New Features

  • N/A

Bug Fixes

Validation Steps

@:interpreter @:win

Unit tests cover the new storage location and the environment variable for installed_check.py.

To do a manual test on macOS with a release build:

  1. Install the build in /Applications. Make sure that codesign --verify --deep --strict --verbose=2 /Applications/Positron.app shows no errors.
  2. Open Positron and start a Python console.
  3. Open a requirements.txt or pyproject.toml file.
  4. Activate a venv as the interpreter, open a terminal, and run deactivate. The command must work as before.
  5. Quit Positron and do the codesign command again. It must not show "file added" lines.

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown

E2E Tests 🚀
This PR will run tests tagged with: @:critical @:interpreter @:win @:console

Why these tags?
Tag Source
@:critical Always runs (required)
@:interpreter PR description
@:win PR description
@:console Changed files

More on automatic tags from changed files.

readme  valid tags

@juliasilge

Copy link
Copy Markdown
Member Author

Here are some macOS builds to check: https://github.com/posit-dev/positron-builds/actions/runs/37990650712

@juliasilge
juliasilge marked this pull request as ready for review October 9, 2026 21:47
@juliasilge
juliasilge requested a review from seeM October 9, 2026 21:47
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown

Tip

This PR moves the Python terminal deactivate scripts to global storage and stops bytecode writes, so deactivate in venv terminals across shells and requirements.txt checks could break in ways the diff doesn't show.

Comment /explore to run an exploratory test. Results will be posted in this thread.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

New files written on launching Positron.app on MacOS

1 participant