Skip to content

fix: skip unreadable .env files during discovery and load - #712

Open
00200200 wants to merge 3 commits into
theskumar:mainfrom
00200200:fix/skip-unreadable-dotenv-files
Open

00200200 wants to merge 3 commits into
theskumar:mainfrom
00200200:fix/skip-unreadable-dotenv-files

Conversation

@00200200

Copy link
Copy Markdown

Summary

Fixes #576.

When a .env file exists but is not readable (e.g. firejail or chmod 000), find_dotenv() previously returned that path and load_dotenv() / dotenv_values() raised PermissionError. Discovery and load now treat unreadable paths as absent: find_dotenv() continues walking parent directories, and an explicit unreadable path yields an empty result instead of crashing.

Test plan

  • test_find_dotenv_skips_unreadable_and_continues fails on main, passes with this change
  • test_load_dotenv_unreadable_file_does_not_raise fails on main, passes with this change
  • Full suite: pytest — 260 passed
  • ruff check / ruff format --check clean on touched files

Permission-denied .env paths no longer abort find_dotenv/load_dotenv;
discovery continues to parent directories instead (issue theskumar#576).
Comment thread src/dotenv/main.py Outdated
if os.access(self.dotenv_path, os.R_OK):
try:
with open(self.dotenv_path, encoding=self.encoding) as stream:
yield stream

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yielding again here after except catches a thrown exception raises RuntimeError: generator didn't stop after throw(), not that original error from reading a stream.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in f6f09d6: the PermissionError handler now covers only open(), so exceptions from reading the yielded stream propagate unchanged. Added regression tests for open failure and read failure; the read test fails on the previous head with the RuntimeError you identified. Full suite: 262 passed; Ruff check passed.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Manage Permission denied

2 participants