Security Considerations

This page lists some topics relevant in context of the upcoming CRA regulation in the EU.

Deployment

Getting your projects installed on other computers or people is a task most Python developers would face at some point. When trying a local copy of the Python files, you need to be certain that the source code hasn’t been tampered with or maliciously modified. For that reason, we recommend that, for the distribution of PySide projects, you always deploy them. Please check our section on Deployment, where you can find how to do this using pyside6-deploy: the deployment tool for Qt for Python or other tools.

The Python Interpreter

The CRA does not include the Python interpreter, since that would be very problematic, but there is an exception for non-commercial Open Source software. Because of that, the security scope of Qt for Python as an offering does not include the interpreter the applications are using.

Security-relevant Topics in Qt for Python

Python Object Serialization in Qt Data Streams

PySide6 can store Python objects as arguments of queued signal connections or as values written to QSettings. Internally, PySide6 serializes them using Python’s pickle module into a QDataStream byte sequence.

Only Python builtin types can be read back. Deserialization is restricted to dict, list, tuple, set, frozenset, str, int, float, bool, bytes, bytearray, and complex. Attempting to deserialize any other type raises a RuntimeError.

This restriction prevents an attacker who can supply a crafted data stream (for example via a QtRemoteObjects connection or a tampered settings file) from achieving remote code execution, while still supporting the common use cases of storing plain data structures in QSettings.

When a QDataStream containing an unsupported Python object type is read, the following happens:

Warning

Do not pass custom Python class instances to setValue() or use them as QtRemoteObjects property values. Writing such objects succeeds (serialization is unrestricted), but reading them back will raise a RuntimeError. Use only the builtin types listed above, or serialize your custom objects to a builtin representation (e.g. a dict) before storing.

Security in Qt