Skip to content

ensurepip warning about running pip as the root user cannot be suppressed #139363

Description

@zvickery

Bug report

Bug description:

The Github Action for installing python currently invokes ensurepip before installing pip. This all works great. It even sets PIP_ROOT_USER_ACTION=ignore to suppress the warning about root (text below), which is common when using containerized environments in CI. However it seems that pip respects this environment variable while ensurepip does not. In particular, https://github.com/python/cpython/blob/main/Lib/ensurepip/__init__.py#L101 seems to guarantee that ensurepip will honor neither environment variables nor the pip configuration file for controlling this.

I have a few questions about this and didn't see a prior ticket, so here goes:

  • Is the Github action taking the correct approach to install Python? (AFAICT, yes)
  • Is ensurepip ignoring all environment and configuration correct? AFAICT this was added a long time ago to address some test suite issues
  • Is there any way I have missed to suppress the below message when the installer invokes ensurepip within a container running as root? WARNING: Running pip as the 'root' user can result in broken permissions and conflicting behaviour with the system package manager. It is recommended to use a virtual environment instead: https://pip.pypa.io/warnings/venv
  • If there is no way, should there be? IMO, yes. My proposal would be to alter the sanitization to preserve this variable. I'm happy to PR that if it is the best approach here.

CPython versions tested on:

3.13

Operating systems tested on:

Linux

Activity

  1. picnixz commented on Sep 26, 2025

    @picnixz
    Member

    I'm not sure about all this but I think this is something you should ask on the pip repository: https://github.com/pypa/pip. As for PIP_ROOT_USER_ACTION, it looks like it's actually useless when using ensurepip (which essentially installs pip itself I think?) but can be useful for the second command.

  2. added
    pendingThe issue will be closed if no feedback is provided
    on Sep 26, 2025
  3. zvickery commented on Sep 26, 2025

    @zvickery
    Author

    I'm not sure about all this but I think this is something you should ask on the pip repository: https://github.com/pypa/pip. As for PIP_ROOT_USER_ACTION, it looks like it's actually useless when using ensurepip (which essentially installs pip itself I think?) but can be useful for the second command.

    In this case, it seems like pip is doing the right thing but ensurepip (in this repo) might need adjustment. Or are you saying the pip team maintains ensurepip that lives here?

  4. picnixz commented on Sep 26, 2025

    @picnixz
    Member

    No, we maintain ensurepip, but I think there is a reason why we actually want to suppress environment variables.

    cc @pfmoore @pradyunsg

  5. pfmoore commented on Sep 26, 2025

    @pfmoore
    Member

    Pip is doing the right thing here. The PIP_ROOT_USER_ACTION variable is just a standard way of setting the --root-user-action option via an environment variable.

    Ensurepip, on the other hand, is a standard library module with its own UI and behaviour. I don't know why ensurepip chooses to hide PIP_* environment variables from the pip subprocess that it calls, but that's an ensurepip choice. I can see it being a reasonable choice to ensure that stray user configuration doesn't break ensurepip. Similarly, the fact that ensurepip doesn't have a --root-user-action option which it passes through to pip is an ensurepip choice (and an entirely reasonable one - exposing all of pip's options via ensurepip would be a bad idea).

    To answer your questions:

    • Is the Github action taking the correct approach to install Python? - I'm not sure it is. Why would it need to run ensurepip? Any correct Python installation should include pip by default. But your comments are inconsistent - you say the action "invokes ensurepip before installing pip", but now you're talking about installing Python. And I'm not sure why you invoke ensurepip before installing pip. The job of ensurepip is to install pip. I'm not an expert in Github actions, but your comments sound confused to me. I suspect that the action is doing something reasonable, but I'm not sure your understanding of it is correct.
    • Is ensurepip ignoring all environment and configuration correct? - Likely yes. It would be too easy otherwise for users to end up with a broken ensurepip because they have config settings which apply to their normal pip usage but which are inappropriate for ensurepip.
    • Is there any way I have missed to suppress the below message when the installer invokes ensurepip within a container running as root? - Barring doing something like post-processing the output to remove the message, probably not.
    • If there is no way, should there be? - Maybe. But simply exposing the underlying pip mechanism might not be the right approach. As I said, there's good reason for isolating ensurepip from global pip config. It's possible there's a case for adding something to ensurepip that sets the option when invoking pip.

    But before we go too far down this route, can you explain why you are getting this error? If you have a normal install of Python, you shouldn't need to run ensurepip, it should have been run automatically, either as part of the install, or as part of the packaging process that created the Python distribution that you installed.

    I'm also not sure how "installing in a container" is relevant here. A github actions runner shouldn't be acting like a container, it should look like a normal environment - because that's what you're trying to test, surely?

    OK, I've looked at the Github action. I don't understand it particularly, but I have a question. The script you linked seems to be run with a pre-existing Python build in the CWD. Why doesn't that pre-existing build have pip included? If it does, there would be no need to run ensurepip. If it doesn't, it's an incomplete Python build, and that's the root issue here.

    I think you need to better understand (or explain) why the Github action script needs to run ensurepip.

  6. zvickery commented on Sep 26, 2025

    @zvickery
    Author

    This is great context, thank you! For reference, I am a Github actions user trying to understand why the standard python install action prints warnings which seemingly cannot be suppressed when used as root in a container. So I'm not totally familiar with how its approach came to be. But I think you are correct that the action's invocation of ensurepip is not necessary and from its history I don't see that it was added for any specific reason. I will follow up with the action's maintainers here. Thank you again!

  7. picnixz commented on Sep 26, 2025

    @picnixz
    Member

    I will follow up with the action's maintainers here

    I'm going to close this issue here and will re-open if needs arise.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    pendingThe issue will be closed if no feedback is providedstdlibStandard Library Python modules in the Lib/ directorytopic-ensurepiptype-bugAn unexpected behavior, bug, or error

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions