@@ -11,7 +11,7 @@ msgid ""
1111msgstr ""
1212"Project-Id-Version : Python 3.15\n "
1313"Report-Msgid-Bugs-To : \n "
14- "POT-Creation-Date : 2026-09-09 17:24 +0000\n "
14+ "POT-Creation-Date : 2026-09-25 18:08 +0000\n "
1515"PO-Revision-Date : 2025-09-16 00:00+0000\n "
1616"Last-Translator : python-doc bot, 2025\n "
1717"Language-Team : Polish (https://app.transifex.com/python-doc/teams/5390/pl/)\n "
@@ -32,8 +32,8 @@ msgid ""
3232msgstr ""
3333
3434msgid ""
35- "Most platforms require elevated privileges to attach to another Python "
36- "process ."
35+ "Attaching to another Python process may require additional permissions or "
36+ "configuration, depending on the platform ."
3737msgstr ""
3838
3939msgid "Disabling remote debugging"
@@ -57,56 +57,120 @@ msgid "Permission requirements"
5757msgstr ""
5858
5959msgid ""
60- "Attaching to a running Python process for remote debugging requires elevated "
61- "privileges on most platforms. The specific requirements and troubleshooting "
62- "steps depend on your operating system:"
60+ "Attaching to a running Python process for remote debugging requires special "
61+ "configuration on most platforms. The specific requirements and "
62+ "troubleshooting steps depend on your operating system:"
6363msgstr ""
6464
6565msgid "Linux"
6666msgstr ""
6767
6868msgid ""
69- "The tracer process must have the ``CAP_SYS_PTRACE`` capability or equivalent "
70- "privileges. You can only trace processes you own and can signal. Tracing may "
71- "fail if the process is already being traced, or if it is running with set- "
72- "user-ID or set-group-ID. Security modules like Yama may further restrict "
73- "tracing. "
69+ "In general, you can debug your own processes, but there are several common "
70+ "configurations that may disable this. Some Linux distributions enable "
71+ "**ptrace restrictions**, aka \" Yama, \" as a form of system hardening. Recent "
72+ "versions of the ``setpriv`` command (util-linux 2.41, released June 2025) "
73+ "let you loosen ptrace restrictions on a per-process basis: "
7474msgstr ""
7575
76- msgid "To temporarily relax ptrace restrictions (until reboot), run:"
76+ msgid "``setpriv --ptracer any python3``"
77+ msgstr ""
78+
79+ msgid ""
80+ "(This is configured on the process *being debugged*.) You can also turn off "
81+ "ptrace restrictions for all processes until reboot with:"
7782msgstr ""
7883
7984msgid "``echo 0 | sudo tee /proc/sys/kernel/yama/ptrace_scope``"
8085msgstr ""
8186
87+ msgid "This can also be configured persistently, usually in ``/etc/sysctl.d``."
88+ msgstr ""
89+
8290msgid ""
8391"Disabling ``ptrace_scope`` reduces system hardening and should only be done "
84- "in trusted environments."
92+ "in low-security environments."
93+ msgstr ""
94+
95+ msgid ""
96+ "It is also possible that the ``ptrace`` system call is disabled because of a "
97+ "security filter. In particular, this was common with older versions of some "
98+ "container software. Docker 19.03 or newer (released 2019) and containerd "
99+ "1.6.7 or newer (released 2022) will automatically allow usage of the "
100+ "``ptrace`` system call inside containers, when running on Linux kernel 4.8 "
101+ "or higher. If you cannot upgrade to these versions, you can create your "
102+ "container with an option like ``--security-opt seccomp=unconfined`` to "
103+ "disable the system call security filter for that container. This weakens the "
104+ "container's isolation and should only be done in low-security environments."
85105msgstr ""
86106
87107msgid ""
88- "If running inside a container, use ``--cap-add=SYS_PTRACE`` or ``--"
89- "privileged``, and run as root if needed."
108+ "If you need to trace a process that you *do not* own, you will need "
109+ "superuser access or equivalent. This also applies to processes that have "
110+ "changed their security credentials, e.g., set-user-ID or set-group-ID "
111+ "processes (though this is unusual for Python). Try running the debugging "
112+ "command with ``sudo -E``."
90113msgstr ""
91114
92- msgid "Try re-running the command with elevated privileges:"
115+ msgid ""
116+ "The ``CAP_SYS_PTRACE`` capability is equivalent to superuser access, in that "
117+ "it allows debugging *any* process, not just your own. You may see advice on "
118+ "the internet suggesting using it to work around ptrace restrictions or "
119+ "system call filters. This may work in practice, as would ``sudo``, but this "
120+ "gives the debugging process much more access than it needs and should only "
121+ "be done in low-security environments."
93122msgstr ""
94123
95- msgid "``sudo -E !!``"
124+ msgid ""
125+ "Finally, note that a process can only have one tracer at a time. If you have "
126+ "already attached to a Python process under ``strace``, ``gdb``, etc., you "
127+ "won't be able to simultaneously use remote debugging. (Superuser access "
128+ "cannot get around this restriction.)"
96129msgstr ""
97130
98131msgid "macOS"
99132msgstr "macOS"
100133
134+ msgid "By default, macOS disables the ability to debug other processes."
135+ msgstr ""
136+
137+ msgid ""
138+ "You can modify your Python binary to opt in to being debugged by giving it "
139+ "an **ad-hoc code signature** with an **entitlement** enabling it to be "
140+ "debugged. (An ad-hoc \" signature\" is just a configuration without any "
141+ "actual cryptographic signature or a need for a certificate or anything else "
142+ "such as an Apple developer program membership.)"
143+ msgstr ""
144+
145+ msgid ""
146+ "The following commands will create a file ``get-task-allow.plist`` with the "
147+ "necessary entitlement and add it to the Python binary:"
148+ msgstr ""
149+
150+ msgid ""
151+ "echo '{\" com.apple.security.get-task-allow\" : true}' | plutil -convert xml1 -"
152+ "o get-task-allow.plist -\n"
153+ "codesign --sign - --entitlements get-task-allow.plist path/to/bin/python3"
154+ msgstr ""
155+
156+ msgid ""
157+ "where ``path/to/bin/python3`` is the path to your Python binary, which you "
158+ "can find by e.g. running ``which python3`` or evaluating ``sys."
159+ "base_executable`` at the Python REPL. (These instructions are for a non-"
160+ "framework build of Python. Framework builds may need to be configured "
161+ "differently.)"
162+ msgstr ""
163+
101164msgid ""
102- "To attach to another process, you typically need to run your debugging tool "
103- "with elevated privileges. This can be done by using ``sudo`` or running as "
104- "root."
165+ "You should then be able to debug your own Python processes started with that "
166+ "binary."
105167msgstr ""
106168
107169msgid ""
108- "Even when attaching to processes you own, macOS may block debugging unless "
109- "the debugger is run with root privileges due to system security restrictions."
170+ "Alternatively, much as with Linux, processes with superuser privileges e.g. "
171+ "``sudo`` are not subject to this check and can debug any user's process on "
172+ "the system (though there are additional checks on specific binaries, such as "
173+ "OS-provided commands, due to System Integrity Protection)."
110174msgstr ""
111175
112176msgid "Windows"
0 commit comments