Repository navigation
setup-python pip upgrade triggers root user warning on self-hosted runners #1295
Description
Activity
Hi @xgboosted,
Thank you for creating this issue. We will investigate it and provide feedback as soon as we have some updates.Hi @xgboosted, thank you for the detailed report.
The warning does not originate fromsrc/find-python.ts. TheinstallPip()function infind-python.tsonly runs when the pip-version: input is explicitly set. The"Upgrading pip..."line in your log is printed by thesetup.shscript bundled inside the pre-built Python tarball fromactions/python-versions, which runs during Python installation.The warning comes from
ensurepip’s internal pip subprocess. Suppression attempts likePIP_ROOT_USER_ACTION,--root-user-action=ignore, or/etc/pip.confdo not help here becauseensurepipstripsPIP_*environment variables and ignorespip.confbefore spawning pip by design. You can see this in CPython’sensurepip/__init__.py#L98-L107.Hope this clarifies the situation.
@priyagupta108 yes, you're right about
ensurepipbeing the real cause. It took us quite a while to figure this out (NVIDIA/cuda-python#1879 (comment)).I think actions/python-versions#369 would be the correct fix (to avoid calling
ensurepipwhen possible). Could you help get it cross the finish line? 🙂Reacted by xgboosted@priyagupta108 Can the suggestion made by @leofang be prioritized?
Hello @xgboosted @leofang,
Thank you for your response. We’ve opened another PR actions/python-versions#392 with an alternative approach to address the warning from thesetup-pythonside by avoidingensurepipwhen possible.
Please take a look when you have a chance, and let us know if there’s anything we should adjust.@priyagupta108, I left a review comment in the PR, please check it out and apply the fix to merge the PR.
Reacted by Priya Gupta@xgboosted,
Thanks for the thorough review! You're absolutely right, this is a valid concern. I've addressed it in the latest commit by adding an explicit$LASTEXITCODEcheck afterensurepip, so its failure surfaces with a dedicated error message rather than being misattributed to the pip install step. Please take another look when you get a chance.@priyagupta108, please go ahead with releasing this!
Hi! 👋
This has been addressed! The fix is merged into actions/python-versions as part of PR #392. New Python version binaries going forward will include this fix, resolving the root user warning on self-hosted runners.
Closing this issue now. Please feel free to reach out if you have any questions or need further assistance.
Thanks again for the detailed report and repro steps!
Reacted by xgboosted
Problem
On root-user self-hosted runners (e.g. Hetzner Cloud),
setup-pythoninternally upgrades pip against the system Python outside any venv:This produces on every run:
The warning cannot be suppressed from the workflow side because
setup-pythonspawns the pip subprocess via a Node.js child process with a controlled environment that does not reliably inherit the job-levelPIP_ROOT_USER_ACTIONenv var or/etc/pip.conf.Proposed Fix
Add
--root-user-action=ignoreto the pip upgrade call insrc/find-python.ts:This is a non-breaking, no-op change on non-root runners.
Reproduction
Log output:
Environment
setup-pythonv6root3.12