diff --git a/.gitignore b/.gitignore index dfe185d..8d7ae02 100644 --- a/.gitignore +++ b/.gitignore @@ -8,7 +8,8 @@ /orjson-3.9.10.tar.gz /orjson-3.9.12.tar.gz /orjson-3.9.13.tar.gz -/orjson-3.9.15.tar.gz +/orjson-3.10.1.tar.gz +/orjson-3.10.3.tar.gz /orjson-3.10.6.tar.gz /orjson-3.10.7.tar.gz /orjson-3.10.10.tar.gz @@ -17,3 +18,10 @@ /orjson-3.10.13.tar.gz /orjson-3.10.14.tar.gz /orjson-3.10.16.tar.gz +/orjson-3.10.18.tar.gz +/orjson-3.11.0.tar.gz +/orjson-3.11.0-filtered.tar.xz +/orjson-3.11.1-filtered.tar.xz +/orjson-3.11.2-filtered.tar.xz +/orjson-3.11.3-filtered.tar.xz +/orjson-3.11.4-filtered.tar.xz diff --git a/changelog b/changelog index 6ef650e..a07230a 100644 --- a/changelog +++ b/changelog @@ -1,9 +1,21 @@ -* Tue Jun 04 2024 Benjamin A. Beasley - 3.9.15-1 -- Update to 3.9.15. +* Mon Jul 22 2024 Benjamin A. Beasley - 3.10.6-1 +- Update to 3.10.6. Fixes rhbz#2291190. -* Fri May 24 2024 Benjamin A. Beasley - 3.9.13-2 +* Fri Jul 19 2024 Fedora Release Engineering - 3.10.3-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + +* Sat Jun 08 2024 Python Maint - 3.10.3-2 +- Rebuilt for Python 3.13 + +* Sat Jun 01 2024 Benjamin A. Beasley - 3.10.3-1 +- Update to 3.10.3. Fixes rhbz#2278078. + +* Fri May 24 2024 Benjamin A. Beasley - 3.10.1-2 - Rebuild with Rust 1.78 to fix incomplete debuginfo and backtraces +* Mon Apr 15 2024 Maxwell G - 3.10.1-1 +- Update to 3.10.1. Fixes rhbz#2264126. + * Tue Feb 6 2024 Maxwell G - 3.9.13-1 - Update to 3.9.13. Fixes rhbz#2262570. diff --git a/get_source b/get_source new file mode 100755 index 0000000..5067989 --- /dev/null +++ b/get_source @@ -0,0 +1,49 @@ +#!/bin/sh +set -o errexit +set -o nounset + +if [ "$#" != '1' ] +then + cat 1>&2 < Downloading: ${URL}" 1>&2 +curl -L -O "${URL}" + +ARCHIVE="$(find . -mindepth 1 -maxdepth 1 -type f -name '*.tar.gz' -print -quit)" +echo "--> Extracting: $(basename "${ARCHIVE}")" 1>&2 +tar -xzf "${ARCHIVE}" +echo '--> Removing data/ due to licensing issues' 1>&2 +TARDIR="$(basename "${ARCHIVE}" '.tar.gz')" +MTIME="$(stat -c '%Y' "${TARDIR}")" +rm -rvf "${TARDIR}/data/" +# Make sure the original mtime is preserved even though we modified the base +# directory by removing something at the top level. +touch -d @"${MTIME}" "${TARDIR}" +FILTERED="$(basename "${ARCHIVE}" .tar.gz)-filtered.tar.xz" +echo "--> Re-archiving: ${FILTERED}" 1>&2 +# https://www.gnu.org/software/tar/manual/html_section/Reproducibility.html +TZ=UTC LC_ALL=C tar \ + --create --verbose \ + --sort=name \ + --format=posix \ + --numeric-owner --owner=0 --group=0 \ + --mode=go+u,go-w \ + --pax-option='delete=atime,delete=ctime' \ + "${TARDIR}/" | + xz -9e > "${FILTERED}" +mv -v "${FILTERED}" "${OUTDIR}" +echo 'Done.' 1>&2 diff --git a/python-orjson.spec b/python-orjson.spec index c48f102..33e673e 100644 --- a/python-orjson.spec +++ b/python-orjson.spec @@ -10,13 +10,39 @@ %bcond pendulum %{undefined el10} Name: python-orjson -Version: 3.10.16 +Version: 3.11.4 Release: %autorelease Summary: Fast, correct Python JSON library -License: Apache-2.0 OR MIT +# The entire source is (Apache-2.0 OR MIT), except: +# +# MIT: +# - include/yyjson/yyjson.c +# - include/yyjson/yyjson.h +# +# Apache-2.0: +# - src/serialize/writer/str/mod.rs +# - src/serialize/writer/str/sse2.rs +License: (Apache-2.0 OR MIT) AND Apache-2.0 AND MIT URL: https://github.com/ijl/orjson -Source: %{pypi_source orjson} +# We must be careful about the source archive. +# +# The PyPI releases have a vendored Rust dependency bundle in include/cargo/, +# which we would remove in %%prep, but which we must still check to make sure +# everything has a license acceptable for distribution in Fedora before +# uploading to the lookaside cache. +# Source: %%{pypi_source orjson} +# The GitHub archives from +# %%{url}/archive/%%{version}/orjson-%%{version}.tar.gz do not have the +# vendored crates, but they contain benchmark data in data/, some of which is +# lacking its license text (e.g. data/blns.txt.xz, which is from +# https://github.com/minimaxir/big-list-of-naughty-strings and should carry the +# corresponding MIT license text), and some of which looks like it might have +# at best unclear license status. Since the benchmark data is potentially +# problematic, we would need to filter the GitHub archives with a script. +Source0: orjson-%{version}-filtered.tar.xz +# ./get_source ${COMMIT} (or ${TAG}) +Source1: get_source BuildRequires: tomcli BuildRequires: python3-devel @@ -45,34 +71,40 @@ datetimes, and numpy} %package -n python3-orjson Summary: %{summary} +# Output of %%{cargo_license_summary}: +# # (Apache-2.0 OR MIT) AND BSD-3-Clause # Apache-2.0 OR BSL-1.0 # Apache-2.0 OR MIT +# BSD-2-Clause OR Apache-2.0 OR MIT # BSL-1.0 # MIT -# MIT OR Apache-2.0 (duplicate) +# MIT OR Apache-2.0 # Unlicense OR MIT # -# Bundled PyO3 crates in include/pyo3/ are also (Apache-2.0 OR MIT). +# Note that this must include the terms of the base package License expression. License: %{shrink: (Apache-2.0 OR MIT) AND - BSD-3-Clause AND + Apache-2.0 AND (Apache-2.0 OR BSL-1.0) AND + (Apache-2.0 OR BSD-2-Clause OR MIT) AND + BSD-3-Clause AND BSL-1.0 AND MIT AND (Unlicense OR MIT) } -# Path to using published versions of pyo3-ffi/pyo3-build-config again? -# https://github.com/ijl/orjson/issues/524 +# Version from YYJSON_VERSION_STRING in include/yyjson/yyjson.h # -# “You are welcome to work to upstream the diff if you find the vendoring -# unsuitable for your organization's own preferences.” -# -# Note that these crates are actually forked, not only bundled/vendored; see -# https://github.com/ijl/orjson/issues/524#issuecomment-2424170405 for details. -Provides: bundled(crate(pyo3-build-config)) = 0.23.3 -Provides: bundled(crate(pyo3-ffi)) = 0.23.3 +# Since version 3.11.4, orjson unconditionally uses a bundled copy of the C +# library yyjson, https://github.com/ibireme/yyjson, as the JSON +# deserialization backend. It is forked (customized) and compiled with a +# particular set of options via preprocessor defines (see build.rs), so it is +# not a candidate for unbundling. (Prior to version 3.11.4, this could be +# disabled, and the json crate from the Rust standard library, +# https://docs.rs/json, would be used instead, but this is no longer +# supported.) +Provides: bundled(yyjson) = 0.9.0 %description -n python3-orjson %{_description} @@ -81,22 +113,10 @@ Provides: bundled(crate(pyo3-ffi)) = 0.23.3 %autosetup -p1 -n orjson-%{version} %cargo_prep -# Remove unstable features that require rust nightly; the avx512 feature also -# requires the x86_64 architecture -tomcli-set Cargo.toml del 'features.unstable-simd' -tomcli-set Cargo.toml del 'features.avx512' # Remove unwind feature, which is not useful here: the comment above it says # “Avoid bundling libgcc on musl.” tomcli-set Cargo.toml del 'features.unwind' tomcli-set Cargo.toml del 'dependencies.unwinding' -# Remove bundled rust crates -rm -r include/cargo -# Remove bundled yyjson. -rm -rv include/yyjson/ - -# Collect licenses for remaining vendored crates -mkdir -p LICENSES.vendored/pyo3 -cp -vp include/pyo3/LICENSE* LICENSES.vendored/pyo3/ %if %{without pendulum} sed -i '/^pendulum\b/d' test/requirements.txt @@ -111,23 +131,12 @@ sed -i '/pytest-random-order/d' test/requirements.txt %generate_buildrequires %pyproject_buildrequires %{?with_tests:test/requirements.txt} %cargo_generate_buildrequires -for dir in include/pyo3/*/ -do - pushd "${dir}" >/dev/null - %cargo_generate_buildrequires - popd >/dev/null -done %build export RUSTFLAGS='%{build_rustflags}' %cargo_license_summary %{cargo_license} > LICENSES.dependencies -# Fedora's pyo3 is patched to not check Python version when building RPM packages. -# However, this uses a bundled version without the patch. -# Rather than patching it, we set the environment variable, -# which allows us to test this package with development Python versions. -export UNSAFE_PYO3_SKIP_VERSION_CHECK=1 %pyproject_wheel @@ -146,7 +155,6 @@ export UNSAFE_PYO3_SKIP_VERSION_CHECK=1 %files -n python3-orjson -f %{pyproject_files} -%license LICENSES.vendored/ %doc README.md diff --git a/sources b/sources index e553587..18ca5d3 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (orjson-3.10.16.tar.gz) = ea71aa463206feae1a96bb604366af2f17ddb083a1a4b7cc87c1b8ad1f01b54bd5c4ef148e9472fed8d8308de37b2a4e4fe0b4a4290d19eaf4fc3ae5777791f9 +SHA512 (orjson-3.11.4-filtered.tar.xz) = 1a457a91dfa1918341acfebcdb86ddf92b5776f166be9dbd16a4253f55140ae0bc90f911ceb3a9b33abd963be22f089aa2764b25e1701691298c0e8840c8225a