Skip to content

setup-python pip upgrade triggers root user warning on self-hosted runners #1295

Description

@xgboosted

Problem

On root-user self-hosted runners (e.g. Hetzner Cloud), setup-python internally upgrades pip against the system Python outside any venv:

// src/find-python.ts — installPip()
`${pythonLocation}/python -m pip install --upgrade pip --disable-pip-version-check`

This produces on every run:

WARNING: Running pip as the 'root' user can result in broken permissions...
Use the --root-user-action option if you know what you are doing.

The warning cannot be suppressed from the workflow side because setup-python spawns the pip subprocess via a Node.js child process with a controlled environment that does not reliably inherit the job-level PIP_ROOT_USER_ACTION env var or /etc/pip.conf.

Proposed Fix

Add --root-user-action=ignore to the pip upgrade call in src/find-python.ts:

await exec.exec(`${pythonLocation}/python`, [
  '-m', 'pip', 'install', '--upgrade', 'pip',
  '--root-user-action=ignore',
  '--disable-pip-version-check',
  '--no-warn-script-location'
]);

This is a non-breaking, no-op change on non-root runners.

Reproduction

jobs:
  test:
    runs-on: self-hosted  # root user (e.g. Hetzner Cloud ephemeral runner)
    steps:
      - uses: actions/setup-python@v6
        with:
          python-version: '3.12'

Log output:

Upgrading pip...
WARNING: Running pip as the 'root' user...
Successfully installed pip-26.0.1

Environment

setup-python v6
Runner OS Ubuntu 24.04
Runner user root
Python version 3.12

Activity

  1. v-mahabaleshwars commented on Mar 23, 2026

    @v-mahabaleshwars
    Contributor

    Hi @xgboosted,
    Thank you for creating this issue. We will investigate it and provide feedback as soon as we have some updates.

  2. v-priyagupta108 commented on Apr 8, 2026

    @v-priyagupta108
    Contributor

    Hi @xgboosted, thank you for the detailed report.
    The warning does not originate from src/find-python.ts. The installPip() function in find-python.ts only runs when the pip-version: input is explicitly set. The "Upgrading pip..." line in your log is printed by the setup.sh script bundled inside the pre-built Python tarball from actions/python-versions, which runs during Python installation.

    The warning comes from ensurepip’s internal pip subprocess. Suppression attempts like PIP_ROOT_USER_ACTION, --root-user-action=ignore, or /etc/pip.conf do not help here because ensurepip strips PIP_* environment variables and ignores pip.conf before spawning pip by design. You can see this in CPython’s ensurepip/__init__.py#L98-L107.

    Hope this clarifies the situation.

  3. leofang commented on Apr 8, 2026

    @leofang

    @priyagupta108 yes, you're right about ensurepip being the real cause. It took us quite a while to figure this out (NVIDIA/cuda-python#1879 (comment)).

    I think actions/python-versions#369 would be the correct fix (to avoid calling ensurepip when possible). Could you help get it cross the finish line? 🙂

  4. xgboosted commented on Apr 12, 2026

    @xgboosted
    Author

    @priyagupta108 Can the suggestion made by @leofang be prioritized?

    actions/python-versions#369

  5. v-priyagupta108 commented on May 13, 2026

    @v-priyagupta108
    Contributor

    Hello @xgboosted @leofang,
    Thank you for your response. We’ve opened another PR actions/python-versions#392 with an alternative approach to address the warning from the setup-python side by avoiding ensurepip when possible.
    Please take a look when you have a chance, and let us know if there’s anything we should adjust.

  6. xgboosted commented on May 14, 2026

    @xgboosted
    Author

    @priyagupta108, I left a review comment in the PR, please check it out and apply the fix to merge the PR.

  7. v-priyagupta108 commented on May 20, 2026

    @v-priyagupta108
    Contributor

    @xgboosted,
    Thanks for the thorough review! You're absolutely right, this is a valid concern. I've addressed it in the latest commit by adding an explicit $LASTEXITCODE check after ensurepip, so its failure surfaces with a dedicated error message rather than being misattributed to the pip install step. Please take another look when you get a chance.

  8. xgboosted commented on May 21, 2026

    @xgboosted
    Author

    @priyagupta108, please go ahead with releasing this!

  9. v-priyagupta108 commented on May 28, 2026

    @v-priyagupta108
    Contributor

    Hi! 👋

    This has been addressed! The fix is merged into actions/python-versions as part of PR #392. New Python version binaries going forward will include this fix, resolving the root user warning on self-hosted runners.

    Closing this issue now. Please feel free to reach out if you have any questions or need further assistance.

    Thanks again for the detailed report and repro steps!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

bugSomething isn't working

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions