88msgstr ""
99"Project-Id-Version : Python 3.15\n "
1010"Report-Msgid-Bugs-To : \n "
11- "POT-Creation-Date : 2026-09-13 17 :08+0000\n "
11+ "POT-Creation-Date : 2026-09-25 18 :08+0000\n "
1212"PO-Revision-Date : 2025-09-16 00:00+0000\n "
1313"Language-Team : Tamil (https://app.transifex.com/python-doc/teams/5390/ta/)\n "
1414"MIME-Version : 1.0\n "
@@ -26,8 +26,8 @@ msgid ""
2626msgstr ""
2727
2828msgid ""
29- "Most platforms require elevated privileges to attach to another Python "
30- "process ."
29+ "Attaching to another Python process may require additional permissions or "
30+ "configuration, depending on the platform ."
3131msgstr ""
3232
3333msgid "Disabling remote debugging"
@@ -51,56 +51,120 @@ msgid "Permission requirements"
5151msgstr ""
5252
5353msgid ""
54- "Attaching to a running Python process for remote debugging requires elevated "
55- "privileges on most platforms. The specific requirements and troubleshooting "
56- "steps depend on your operating system:"
54+ "Attaching to a running Python process for remote debugging requires special "
55+ "configuration on most platforms. The specific requirements and "
56+ "troubleshooting steps depend on your operating system:"
5757msgstr ""
5858
5959msgid "Linux"
6060msgstr ""
6161
6262msgid ""
63- "The tracer process must have the ``CAP_SYS_PTRACE`` capability or equivalent "
64- "privileges. You can only trace processes you own and can signal. Tracing may "
65- "fail if the process is already being traced, or if it is running with set- "
66- "user-ID or set-group-ID. Security modules like Yama may further restrict "
67- "tracing. "
63+ "In general, you can debug your own processes, but there are several common "
64+ "configurations that may disable this. Some Linux distributions enable "
65+ "**ptrace restrictions**, aka \" Yama, \" as a form of system hardening. Recent "
66+ "versions of the ``setpriv`` command (util-linux 2.41, released June 2025) "
67+ "let you loosen ptrace restrictions on a per-process basis: "
6868msgstr ""
6969
70- msgid "To temporarily relax ptrace restrictions (until reboot), run:"
70+ msgid "``setpriv --ptracer any python3``"
71+ msgstr ""
72+
73+ msgid ""
74+ "(This is configured on the process *being debugged*.) You can also turn off "
75+ "ptrace restrictions for all processes until reboot with:"
7176msgstr ""
7277
7378msgid "``echo 0 | sudo tee /proc/sys/kernel/yama/ptrace_scope``"
7479msgstr ""
7580
81+ msgid "This can also be configured persistently, usually in ``/etc/sysctl.d``."
82+ msgstr ""
83+
7684msgid ""
7785"Disabling ``ptrace_scope`` reduces system hardening and should only be done "
78- "in trusted environments."
86+ "in low-security environments."
87+ msgstr ""
88+
89+ msgid ""
90+ "It is also possible that the ``ptrace`` system call is disabled because of a "
91+ "security filter. In particular, this was common with older versions of some "
92+ "container software. Docker 19.03 or newer (released 2019) and containerd "
93+ "1.6.7 or newer (released 2022) will automatically allow usage of the "
94+ "``ptrace`` system call inside containers, when running on Linux kernel 4.8 "
95+ "or higher. If you cannot upgrade to these versions, you can create your "
96+ "container with an option like ``--security-opt seccomp=unconfined`` to "
97+ "disable the system call security filter for that container. This weakens the "
98+ "container's isolation and should only be done in low-security environments."
7999msgstr ""
80100
81101msgid ""
82- "If running inside a container, use ``--cap-add=SYS_PTRACE`` or ``--"
83- "privileged``, and run as root if needed."
102+ "If you need to trace a process that you *do not* own, you will need "
103+ "superuser access or equivalent. This also applies to processes that have "
104+ "changed their security credentials, e.g., set-user-ID or set-group-ID "
105+ "processes (though this is unusual for Python). Try running the debugging "
106+ "command with ``sudo -E``."
84107msgstr ""
85108
86- msgid "Try re-running the command with elevated privileges:"
109+ msgid ""
110+ "The ``CAP_SYS_PTRACE`` capability is equivalent to superuser access, in that "
111+ "it allows debugging *any* process, not just your own. You may see advice on "
112+ "the internet suggesting using it to work around ptrace restrictions or "
113+ "system call filters. This may work in practice, as would ``sudo``, but this "
114+ "gives the debugging process much more access than it needs and should only "
115+ "be done in low-security environments."
87116msgstr ""
88117
89- msgid "``sudo -E !!``"
118+ msgid ""
119+ "Finally, note that a process can only have one tracer at a time. If you have "
120+ "already attached to a Python process under ``strace``, ``gdb``, etc., you "
121+ "won't be able to simultaneously use remote debugging. (Superuser access "
122+ "cannot get around this restriction.)"
90123msgstr ""
91124
92125msgid "macOS"
93126msgstr ""
94127
128+ msgid "By default, macOS disables the ability to debug other processes."
129+ msgstr ""
130+
131+ msgid ""
132+ "You can modify your Python binary to opt in to being debugged by giving it "
133+ "an **ad-hoc code signature** with an **entitlement** enabling it to be "
134+ "debugged. (An ad-hoc \" signature\" is just a configuration without any "
135+ "actual cryptographic signature or a need for a certificate or anything else "
136+ "such as an Apple developer program membership.)"
137+ msgstr ""
138+
139+ msgid ""
140+ "The following commands will create a file ``get-task-allow.plist`` with the "
141+ "necessary entitlement and add it to the Python binary:"
142+ msgstr ""
143+
144+ msgid ""
145+ "echo '{\" com.apple.security.get-task-allow\" : true}' | plutil -convert xml1 -"
146+ "o get-task-allow.plist -\n"
147+ "codesign --sign - --entitlements get-task-allow.plist path/to/bin/python3"
148+ msgstr ""
149+
150+ msgid ""
151+ "where ``path/to/bin/python3`` is the path to your Python binary, which you "
152+ "can find by e.g. running ``which python3`` or evaluating ``sys."
153+ "base_executable`` at the Python REPL. (These instructions are for a non-"
154+ "framework build of Python. Framework builds may need to be configured "
155+ "differently.)"
156+ msgstr ""
157+
95158msgid ""
96- "To attach to another process, you typically need to run your debugging tool "
97- "with elevated privileges. This can be done by using ``sudo`` or running as "
98- "root."
159+ "You should then be able to debug your own Python processes started with that "
160+ "binary."
99161msgstr ""
100162
101163msgid ""
102- "Even when attaching to processes you own, macOS may block debugging unless "
103- "the debugger is run with root privileges due to system security restrictions."
164+ "Alternatively, much as with Linux, processes with superuser privileges e.g. "
165+ "``sudo`` are not subject to this check and can debug any user's process on "
166+ "the system (though there are additional checks on specific binaries, such as "
167+ "OS-provided commands, due to System Integrity Protection)."
104168msgstr ""
105169
106170msgid "Windows"
0 commit comments