@@ -11,7 +11,7 @@ msgid ""
1111msgstr ""
1212"Project-Id-Version : Python 3.15\n "
1313"Report-Msgid-Bugs-To : \n "
14- "POT-Creation-Date : 2026-09-11 17:24 +0000\n "
14+ "POT-Creation-Date : 2026-09-25 18:08 +0000\n "
1515"PO-Revision-Date : 2025-09-16 00:00+0000\n "
1616"Last-Translator : python-doc bot, 2025\n "
1717"Language-Team : Indonesian (https://app.transifex.com/python-doc/teams/5390/ "
@@ -31,8 +31,8 @@ msgid ""
3131msgstr ""
3232
3333msgid ""
34- "Most platforms require elevated privileges to attach to another Python "
35- "process ."
34+ "Attaching to another Python process may require additional permissions or "
35+ "configuration, depending on the platform ."
3636msgstr ""
3737
3838msgid "Disabling remote debugging"
@@ -56,56 +56,120 @@ msgid "Permission requirements"
5656msgstr ""
5757
5858msgid ""
59- "Attaching to a running Python process for remote debugging requires elevated "
60- "privileges on most platforms. The specific requirements and troubleshooting "
61- "steps depend on your operating system:"
59+ "Attaching to a running Python process for remote debugging requires special "
60+ "configuration on most platforms. The specific requirements and "
61+ "troubleshooting steps depend on your operating system:"
6262msgstr ""
6363
6464msgid "Linux"
6565msgstr ""
6666
6767msgid ""
68- "The tracer process must have the ``CAP_SYS_PTRACE`` capability or equivalent "
69- "privileges. You can only trace processes you own and can signal. Tracing may "
70- "fail if the process is already being traced, or if it is running with set- "
71- "user-ID or set-group-ID. Security modules like Yama may further restrict "
72- "tracing. "
68+ "In general, you can debug your own processes, but there are several common "
69+ "configurations that may disable this. Some Linux distributions enable "
70+ "**ptrace restrictions**, aka \" Yama, \" as a form of system hardening. Recent "
71+ "versions of the ``setpriv`` command (util-linux 2.41, released June 2025) "
72+ "let you loosen ptrace restrictions on a per-process basis: "
7373msgstr ""
7474
75- msgid "To temporarily relax ptrace restrictions (until reboot), run:"
75+ msgid "``setpriv --ptracer any python3``"
76+ msgstr ""
77+
78+ msgid ""
79+ "(This is configured on the process *being debugged*.) You can also turn off "
80+ "ptrace restrictions for all processes until reboot with:"
7681msgstr ""
7782
7883msgid "``echo 0 | sudo tee /proc/sys/kernel/yama/ptrace_scope``"
7984msgstr ""
8085
86+ msgid "This can also be configured persistently, usually in ``/etc/sysctl.d``."
87+ msgstr ""
88+
8189msgid ""
8290"Disabling ``ptrace_scope`` reduces system hardening and should only be done "
83- "in trusted environments."
91+ "in low-security environments."
92+ msgstr ""
93+
94+ msgid ""
95+ "It is also possible that the ``ptrace`` system call is disabled because of a "
96+ "security filter. In particular, this was common with older versions of some "
97+ "container software. Docker 19.03 or newer (released 2019) and containerd "
98+ "1.6.7 or newer (released 2022) will automatically allow usage of the "
99+ "``ptrace`` system call inside containers, when running on Linux kernel 4.8 "
100+ "or higher. If you cannot upgrade to these versions, you can create your "
101+ "container with an option like ``--security-opt seccomp=unconfined`` to "
102+ "disable the system call security filter for that container. This weakens the "
103+ "container's isolation and should only be done in low-security environments."
84104msgstr ""
85105
86106msgid ""
87- "If running inside a container, use ``--cap-add=SYS_PTRACE`` or ``--"
88- "privileged``, and run as root if needed."
107+ "If you need to trace a process that you *do not* own, you will need "
108+ "superuser access or equivalent. This also applies to processes that have "
109+ "changed their security credentials, e.g., set-user-ID or set-group-ID "
110+ "processes (though this is unusual for Python). Try running the debugging "
111+ "command with ``sudo -E``."
89112msgstr ""
90113
91- msgid "Try re-running the command with elevated privileges:"
114+ msgid ""
115+ "The ``CAP_SYS_PTRACE`` capability is equivalent to superuser access, in that "
116+ "it allows debugging *any* process, not just your own. You may see advice on "
117+ "the internet suggesting using it to work around ptrace restrictions or "
118+ "system call filters. This may work in practice, as would ``sudo``, but this "
119+ "gives the debugging process much more access than it needs and should only "
120+ "be done in low-security environments."
92121msgstr ""
93122
94- msgid "``sudo -E !!``"
123+ msgid ""
124+ "Finally, note that a process can only have one tracer at a time. If you have "
125+ "already attached to a Python process under ``strace``, ``gdb``, etc., you "
126+ "won't be able to simultaneously use remote debugging. (Superuser access "
127+ "cannot get around this restriction.)"
95128msgstr ""
96129
97130msgid "macOS"
98131msgstr "macOS"
99132
133+ msgid "By default, macOS disables the ability to debug other processes."
134+ msgstr ""
135+
136+ msgid ""
137+ "You can modify your Python binary to opt in to being debugged by giving it "
138+ "an **ad-hoc code signature** with an **entitlement** enabling it to be "
139+ "debugged. (An ad-hoc \" signature\" is just a configuration without any "
140+ "actual cryptographic signature or a need for a certificate or anything else "
141+ "such as an Apple developer program membership.)"
142+ msgstr ""
143+
144+ msgid ""
145+ "The following commands will create a file ``get-task-allow.plist`` with the "
146+ "necessary entitlement and add it to the Python binary:"
147+ msgstr ""
148+
149+ msgid ""
150+ "echo '{\" com.apple.security.get-task-allow\" : true}' | plutil -convert xml1 -"
151+ "o get-task-allow.plist -\n"
152+ "codesign --sign - --entitlements get-task-allow.plist path/to/bin/python3"
153+ msgstr ""
154+
155+ msgid ""
156+ "where ``path/to/bin/python3`` is the path to your Python binary, which you "
157+ "can find by e.g. running ``which python3`` or evaluating ``sys."
158+ "base_executable`` at the Python REPL. (These instructions are for a non-"
159+ "framework build of Python. Framework builds may need to be configured "
160+ "differently.)"
161+ msgstr ""
162+
100163msgid ""
101- "To attach to another process, you typically need to run your debugging tool "
102- "with elevated privileges. This can be done by using ``sudo`` or running as "
103- "root."
164+ "You should then be able to debug your own Python processes started with that "
165+ "binary."
104166msgstr ""
105167
106168msgid ""
107- "Even when attaching to processes you own, macOS may block debugging unless "
108- "the debugger is run with root privileges due to system security restrictions."
169+ "Alternatively, much as with Linux, processes with superuser privileges e.g. "
170+ "``sudo`` are not subject to this check and can debug any user's process on "
171+ "the system (though there are additional checks on specific binaries, such as "
172+ "OS-provided commands, due to System Integrity Protection)."
109173msgstr ""
110174
111175msgid "Windows"
0 commit comments