Repository navigation
ensurepip warning about running pip as the root user cannot be suppressed #139363
Description
Activity
- addedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on Sep 26, 2025 - addedstdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directory
on Sep 26, 2025 I'm not sure about all this but I think this is something you should ask on the
piprepository: https://github.com/pypa/pip. As forPIP_ROOT_USER_ACTION, it looks like it's actually useless when usingensurepip(which essentially installspipitself I think?) but can be useful for the second command.- addedpendingThe issue will be closed if no feedback is providedThe issue will be closed if no feedback is provided
on Sep 26, 2025 I'm not sure about all this but I think this is something you should ask on the
piprepository: https://github.com/pypa/pip. As forPIP_ROOT_USER_ACTION, it looks like it's actually useless when usingensurepip(which essentially installspipitself I think?) but can be useful for the second command.In this case, it seems like
pipis doing the right thing butensurepip(in this repo) might need adjustment. Or are you saying thepipteam maintainsensurepipthat lives here?No, we maintain
ensurepip, but I think there is a reason why we actually want to suppress environment variables.Pip is doing the right thing here. The
PIP_ROOT_USER_ACTIONvariable is just a standard way of setting the--root-user-actionoption via an environment variable.Ensurepip, on the other hand, is a standard library module with its own UI and behaviour. I don't know why ensurepip chooses to hide
PIP_*environment variables from the pip subprocess that it calls, but that's an ensurepip choice. I can see it being a reasonable choice to ensure that stray user configuration doesn't break ensurepip. Similarly, the fact that ensurepip doesn't have a--root-user-actionoption which it passes through to pip is an ensurepip choice (and an entirely reasonable one - exposing all of pip's options via ensurepip would be a bad idea).To answer your questions:
- Is the Github action taking the correct approach to install Python? - I'm not sure it is. Why would it need to run
ensurepip? Any correct Python installation should include pip by default. But your comments are inconsistent - you say the action "invokesensurepipbefore installing pip", but now you're talking about installing Python. And I'm not sure why you invokeensurepipbefore installing pip. The job ofensurepipis to install pip. I'm not an expert in Github actions, but your comments sound confused to me. I suspect that the action is doing something reasonable, but I'm not sure your understanding of it is correct. - Is
ensurepipignoring all environment and configuration correct? - Likely yes. It would be too easy otherwise for users to end up with a brokenensurepipbecause they have config settings which apply to their normal pip usage but which are inappropriate forensurepip. - Is there any way I have missed to suppress the below message when the installer invokes
ensurepipwithin a container running as root? - Barring doing something like post-processing the output to remove the message, probably not. - If there is no way, should there be? - Maybe. But simply exposing the underlying pip mechanism might not be the right approach. As I said, there's good reason for isolating
ensurepipfrom global pip config. It's possible there's a case for adding something toensurepipthat sets the option when invoking pip.
But before we go too far down this route, can you explain why you are getting this error? If you have a normal install of Python, you shouldn't need to run
ensurepip, it should have been run automatically, either as part of the install, or as part of the packaging process that created the Python distribution that you installed.I'm also not sure how "installing in a container" is relevant here. A github actions runner shouldn't be acting like a container, it should look like a normal environment - because that's what you're trying to test, surely?
OK, I've looked at the Github action. I don't understand it particularly, but I have a question. The script you linked seems to be run with a pre-existing Python build in the CWD. Why doesn't that pre-existing build have pip included? If it does, there would be no need to run
ensurepip. If it doesn't, it's an incomplete Python build, and that's the root issue here.I think you need to better understand (or explain) why the Github action script needs to run
ensurepip.- Is the Github action taking the correct approach to install Python? - I'm not sure it is. Why would it need to run
This is great context, thank you! For reference, I am a Github actions user trying to understand why the standard python install action prints warnings which seemingly cannot be suppressed when used as root in a container. So I'm not totally familiar with how its approach came to be. But I think you are correct that the action's invocation of
ensurepipis not necessary and from its history I don't see that it was added for any specific reason. I will follow up with the action's maintainers here. Thank you again!I will follow up with the action's maintainers here
I'm going to close this issue here and will re-open if needs arise.
Bug report
Bug description:
The Github Action for installing python currently invokes
ensurepipbefore installing pip. This all works great. It even setsPIP_ROOT_USER_ACTION=ignoreto suppress the warning about root (text below), which is common when using containerized environments in CI. However it seems thatpiprespects this environment variable whileensurepipdoes not. In particular, https://github.com/python/cpython/blob/main/Lib/ensurepip/__init__.py#L101 seems to guarantee thatensurepipwill honor neither environment variables nor the pip configuration file for controlling this.I have a few questions about this and didn't see a prior ticket, so here goes:
ensurepipignoring all environment and configuration correct? AFAICT this was added a long time ago to address some test suite issuesensurepipwithin a container running as root?WARNING: Running pip as the 'root' user can result in broken permissions and conflicting behaviour with the system package manager. It is recommended to use a virtual environment instead: https://pip.pypa.io/warnings/venvCPython versions tested on:
3.13
Operating systems tested on:
Linux