{"record":{"id":"9524bf3ed1f09258","repo":"apache/seatunnel","slug":"python-source-executable-is-not-listed-in-serve","errorCode":null,"errorMessage":"Python source executable {} is not listed in server property {}={}","messagePattern":"Python source executable (.+?) is not listed in server property (.+?)=(.+?)","errorType":"exception","errorClass":"IllegalStateException","httpStatus":null,"severity":"error","filePath":"seatunnel-connectors-v2/connector-python/src/main/java/org/apache/seatunnel/connectors/seatunnel/python/source/PythonSourceExecutionPolicy.java","lineNumber":51,"sourceCode":"final class PythonSourceExecutionPolicy {\n\n    static final String PYTHON_SOURCE_ENABLED_PROPERTY = \"seatunnel.source.python.enabled\";\n    static final String PYTHON_ALLOWED_EXECUTABLES_PROPERTY =\n            \"seatunnel.source.python.allowed-executables\";\n\n    private PythonSourceExecutionPolicy() {}\n\n    /** Resolves the job-selected command and verifies it against the server-side allowlist. */\n    static Path resolveExecutable(String configuredExecutable) throws IOException {\n        ensureEnabled();\n        List<Path> allowedExecutables = parseAllowedExecutables();\n        Path resolvedExecutable = resolveConfiguredExecutable(configuredExecutable);\n        for (Path allowedExecutable : allowedExecutables) {\n            if (sameExecutablePath(resolvedExecutable, allowedExecutable)) {\n                return resolvedExecutable;\n            }\n        }\n        throw new IllegalStateException(\n                \"Python source executable \"\n                        + resolvedExecutable\n                        + \" is not listed in server property \"\n                        + PYTHON_ALLOWED_EXECUTABLES_PROPERTY\n                        + \"=\"\n                        + allowedExecutables);\n    }\n\n    private static void ensureEnabled() {\n        if (Boolean.parseBoolean(\n                System.getProperty(PYTHON_SOURCE_ENABLED_PROPERTY, Boolean.FALSE.toString()))) {\n            return;\n        }\n        throw new IllegalStateException(\n                \"Python source is disabled by the server-side security policy. Set -D\"\n                        + PYTHON_SOURCE_ENABLED_PROPERTY\n                        + \"=true and configure -D\"\n                        + PYTHON_ALLOWED_EXECUTABLES_PROPERTY","sourceCodeStart":33,"sourceCodeEnd":69,"githubUrl":"https://github.com/apache/seatunnel/blob/cf67b549a7a6c35fa0beb12d83c62892427ea919/seatunnel-connectors-v2/connector-python/src/main/java/org/apache/seatunnel/connectors/seatunnel/python/source/PythonSourceExecutionPolicy.java#L33-L69","documentation":"PythonSourceExecutionPolicy.resolveExecutable throws this IllegalStateException when the configured python.executable, after path resolution, is not an exact (path-equal) member of the server's allowed-executables list from the PYTHON_ALLOWED_EXECUTABLES_PROPERTY system property. This server-side allowlist prevents arbitrary interpreter execution, so any unlisted binary is rejected.","triggerScenarios":"Calling resolveExecutable when resolveConfiguredExecutable(configuredExecutable) yields a path not matching any entry in allowedExecutables — e.g. python.executable = \"python3\" (relative, resolved to a different location) while the property lists only \"/usr/bin/python3\".","commonSituations":"Config uses 'python3' but the allowlist lists an absolute path; worker nodes have different interpreter locations than the master; symlinked or versioned interpreters (/usr/bin/python3.10 vs /usr/bin/python3) that do not compare equal; property set on some nodes but not others.","solutions":["Set python.executable to the exact absolute path listed in the -Dpython.allowed.executables property.","On every worker, start with -Dpython.allowed.executables=/usr/bin/python3 (comma-separated absolute paths).","Compare resolved paths in the error message with the allowlist to catch symlink/version differences and add the correct entry.","Ensure consistency: the same property and same interpreter paths on all worker nodes."],"exampleFix":"// before\n./bin/seatunnel.sh --config job.conf  # python.executable = \"python3\"\n// after\n./bin/seatunnel.sh -Dpython.source.enabled=true \\\n  -Dpython.allowed.executables=/usr/bin/python3 \\\n  --config job.conf                    # python.executable = \"/usr/bin/python3\"","handlingStrategy":"validation","validationCode":"// Java: pre-check the configured executable against the allowlist\nString[] allowed = System.getProperty(\"python.allowed.executables\", \"\").split(\",\");\nString exe = configMap.get(\"python.executable\");\nboolean ok = java.util.Arrays.stream(allowed)\n    .anyMatch(a -> a.equals(exe));\nif (!ok) {\n    throw new IllegalArgumentException(\n        \"python.executable \" + exe + \" must be one of: \" + Arrays.toString(allowed));\n}","typeGuard":null,"tryCatchPattern":"try { Path exe = policy.resolveExecutable(cfg.getPythonExecutable()); } catch (IllegalStateException e) { LOG.error(\"Interpreter not in server allowlist: {}\", e.getMessage()); }","preventionTips":["Use the exact absolute path from the allowlist in python.executable","Keep -Dpython.allowed.executables identical on all worker nodes","Watch for symlink/versioned interpreters that resolve differently","Add new interpreter paths to the allowlist before switching the config"],"tags":["python","security-policy","allowlist","system-property"],"backgroundTag":"invalid-argument-value","analyzedSha":"cf67b549a7a6c35fa0beb12d83c62892427ea919","analyzedAt":"2026-09-10T21:44:55.265Z","contentChangedAt":"2026-09-10T21:44:55.265Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}