{"record":{"id":"0f7f60951cf9ff5a","repo":"pypa/pip","slug":"can-not-open-an-editor-for-a-file-name-containing","errorCode":null,"errorMessage":"Can not open an editor for a file name containing \"\n{fname}","messagePattern":"Can not open an editor for a file name containing \"\n(.+?)","errorType":"exception","errorClass":"PipError","httpStatus":null,"severity":"error","filePath":"src/pip/_internal/commands/configuration.py","lineNumber":243,"sourceCode":"\n    def print_env_var_values(self) -> None:\n        \"\"\"Get key-values pairs present as environment variables\"\"\"\n        write_output(\"%s:\", \"env_var\")\n        with indent_log():\n            for key, value in sorted(self.configuration.get_environ_vars()):\n                env_var = f\"PIP_{key.upper()}\"\n                write_output(\"%s=%r\", env_var, value)\n\n    def open_in_editor(self, options: Values, args: list[str]) -> None:\n        editor = self._determine_editor(options)\n\n        fname = self.configuration.get_file_to_edit()\n        if fname is None:\n            raise PipError(\"Could not determine appropriate file.\")\n        elif '\"' in fname:\n            # This shouldn't happen, unless we see a username like that.\n            # If that happens, we'd appreciate a pull request fixing this.\n            raise PipError(\n                f'Can not open an editor for a file name containing \"\\n{fname}'\n            )\n\n        try:\n            subprocess.check_call(f'{editor} \"{fname}\"', shell=True)\n        except FileNotFoundError as e:\n            if not e.filename:\n                e.filename = editor\n            raise\n        except subprocess.CalledProcessError as e:\n            raise PipError(f\"Editor Subprocess exited with exit code {e.returncode}\")\n\n    def _get_n_args(self, args: list[str], example: str, n: int) -> Any:\n        \"\"\"Helper to make sure the command got the right number of arguments\"\"\"\n        if len(args) != n:\n            msg = (\n                f\"Got unexpected number of arguments, expected {n}. \"\n                f'(example: \"{get_prog()} config {example}\")'","sourceCodeStart":225,"sourceCodeEnd":261,"githubUrl":"https://github.com/pypa/pip/blob/f399c3718970b1b0e2478dac5296eb62679a9b86/src/pip/_internal/commands/configuration.py#L225-L261","documentation":"Raised by `pip config edit` when the resolved configuration file path contains a double-quote character (\"). open_in_editor at configuration.py:240 guards against this because it builds the shell command `f'{editor} \"{fname}\"'` (configuration.py:248); a quote in the path would break or inject into the shell command. The code comments this should not normally happen unless a username contains one.","triggerScenarios":"The OS username (and thus the user config path, e.g. ~/.config/pip/pip.conf or %APPDATA%\\pip\\pip.ini) contains a \" character, and pip config edit resolves that path.","commonSituations":"An unusual account name containing special characters. This is an edge-case safety guard, not a typical user mistake. The code explicitly invites a pull request to fix the underlying quoting.","solutions":["Use a username without a double-quote character, or create a separate user account for the install.","Set PIP_CONFIG_FILE to a safe path without quotes: `export PIP_CONFIG_FILE=/safe/path/pip.conf`.","Edit the config file manually with a path-safe editor instead of `pip config edit`.","Avoid `pip config edit`; use `pip config set/get/unset` which do not shell out."],"exampleFix":"// before\npip config edit   # username contains \" char\n// after\nexport PIP_CONFIG_FILE=/tmp/pip.conf\npip config edit","handlingStrategy":"validation","validationCode":"# Reject config paths containing a double-quote before editing\nimport os\n\ndef safe_config_edit_path():\n    from pip._internal.configuration import Configuration\n    fname = Configuration(get_file_to_edit_via_pip()).get_file_to_edit()\n    if fname is None:\n        raise RuntimeError(\"No config file to edit\")\n    if '\"' in fname:\n        raise ValueError(\"Config path contains a double-quote; refusing to shell out: %s\" % fname)\n    return fname\n","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Avoid usernames containing double-quote characters.","Set PIP_CONFIG_FILE to a quote-free path.","Prefer `pip config set/get/unset` over `pip config edit` to avoid shell-out entirely."],"tags":["cli","pip-config","security","shell-injection-guard","edge-case"],"backgroundTag":null,"analyzedSha":"f399c3718970b1b0e2478dac5296eb62679a9b86","analyzedAt":"2026-08-08T23:01:42.227Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}