From 3a83d6ce5d289434a11516e18c5cee8dd0873449 Mon Sep 17 00:00:00 2001 From: Karolina Surma Date: Thu, 7 Aug 2025 15:40:40 +0200 Subject: [PATCH 1/9] Update to 25.2 (rhbz#2385294) Drop nowarn-pip._internal.main.patch as the warning is no longer emitted via ensurepip in Fedora Pythons. --- downstream-remove-pytest-subket.patch | 54 +++++++++++++ dummy-certifi.patch | 49 +++--------- nowarn-pip._internal.main.patch | 79 ------------------- python-pip.spec | 43 +++++----- python3.14-file-urls.patch | 67 ---------------- ...existing-dist-only-if-path-conflicts.patch | 30 +++---- sources | 2 +- 7 files changed, 100 insertions(+), 224 deletions(-) create mode 100644 downstream-remove-pytest-subket.patch delete mode 100644 nowarn-pip._internal.main.patch delete mode 100644 python3.14-file-urls.patch diff --git a/downstream-remove-pytest-subket.patch b/downstream-remove-pytest-subket.patch new file mode 100644 index 0000000..564794c --- /dev/null +++ b/downstream-remove-pytest-subket.patch @@ -0,0 +1,54 @@ +From 35378ae02912d704d466e4809070e17a8d13ad0a Mon Sep 17 00:00:00 2001 +From: Karolina Surma +Date: Thu, 7 Aug 2025 15:05:34 +0200 +Subject: [PATCH] Downstream-Only: Remove pytest-subket from tests + +--- + tests/conftest.py | 17 ----------------- + 1 file changed, 17 deletions(-) + +diff --git a/tests/conftest.py b/tests/conftest.py +index c98b871..ada7a7e 100644 +--- a/tests/conftest.py ++++ b/tests/conftest.py +@@ -451,18 +451,6 @@ def coverage_install( + return _common_wheel_editable_install(tmpdir_factory, common_wheels, "coverage") + + +-@pytest.fixture(scope="session") +-def socket_install(tmpdir_factory: pytest.TempPathFactory, common_wheels: Path) -> Path: +- lib_dir = _common_wheel_editable_install( +- tmpdir_factory, common_wheels, "pytest_subket" +- ) +- # pytest-subket is only included so it can intercept and block unexpected +- # network requests. It should NOT be visible to the pip under test. +- dist_info = next(lib_dir.glob("*.dist-info")) +- shutil.rmtree(dist_info) +- return lib_dir +- +- + def install_pth_link( + venv: VirtualEnvironment, project_name: str, lib_dir: Path + ) -> None: +@@ -480,7 +468,6 @@ def virtualenv_template( + setuptools_install: Path, + wheel_install: Path, + coverage_install: Path, +- socket_install: Path, + ) -> VirtualEnvironment: + venv_type: VirtualEnvironmentType + if request.config.getoption("--use-venv"): +@@ -495,10 +482,6 @@ def virtualenv_template( + # Install setuptools, wheel, pytest-subket, and pip. + install_pth_link(venv, "setuptools", setuptools_install) + install_pth_link(venv, "wheel", wheel_install) +- install_pth_link(venv, "pytest_subket", socket_install) +- # Also copy pytest-subket's .pth file so it can intercept socket calls. +- with open(venv.site / "pytest_socket.pth", "w") as f: +- f.write(socket_install.joinpath("pytest_socket.pth").read_text()) + + pth, dist_info = pip_editable_parts + +-- +2.50.1 + diff --git a/dummy-certifi.patch b/dummy-certifi.patch index 01e8756..ce34415 100644 --- a/dummy-certifi.patch +++ b/dummy-certifi.patch @@ -1,17 +1,17 @@ -From 0741e5a665308184ddbd20900f92e4417204092f Mon Sep 17 00:00:00 2001 +From 7b5fbac83944e3a0dd975ff17b69358791b68721 Mon Sep 17 00:00:00 2001 From: Karolina Surma Date: Thu, 27 Jun 2024 10:38:53 +0200 Subject: [PATCH] Dummy certifi patch --- - src/pip/_vendor/certifi/core.py | 110 ++------------------------------ - 1 file changed, 6 insertions(+), 104 deletions(-) + src/pip/_vendor/certifi/core.py | 80 +++------------------------------ + 1 file changed, 6 insertions(+), 74 deletions(-) diff --git a/src/pip/_vendor/certifi/core.py b/src/pip/_vendor/certifi/core.py -index 70e0c3b..eaf4210 100644 +index 2f2f7e0..bec6595 100644 --- a/src/pip/_vendor/certifi/core.py +++ b/src/pip/_vendor/certifi/core.py -@@ -4,111 +4,13 @@ certifi.py +@@ -4,80 +4,12 @@ certifi.py This module returns the installation location of cacert.pem or its contents. """ @@ -20,13 +20,13 @@ index 70e0c3b..eaf4210 100644 -def exit_cacert_ctx() -> None: - _CACERT_CTX.__exit__(None, None, None) # type: ignore[union-attr] - +# The RPM-packaged certifi always uses the system certificates +def where() -> str: + return '/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem' --if sys.version_info >= (3, 11): +-if sys.version_info >= (3, 11): +- - from importlib.resources import as_file, files - - _CACERT_CTX = None @@ -60,7 +60,7 @@ index 70e0c3b..eaf4210 100644 - def contents() -> str: - return files("pip._vendor.certifi").joinpath("cacert.pem").read_text(encoding="ascii") - --elif sys.version_info >= (3, 7): +-else: - - from importlib.resources import path as get_path, read_text - @@ -95,40 +95,9 @@ index 70e0c3b..eaf4210 100644 - - def contents() -> str: - return read_text("pip._vendor.certifi", "cacert.pem", encoding="ascii") -- --else: -- import os -- import types -- from typing import Union -- -- Package = Union[types.ModuleType, str] -- Resource = Union[str, "os.PathLike"] -- -- # This fallback will work for Python versions prior to 3.7 that lack the -- # importlib.resources module but relies on the existing `where` function -- # so won't address issues with environments like PyOxidizer that don't set -- # __file__ on modules. -- def read_text( -- package: Package, -- resource: Resource, -- encoding: str = 'utf-8', -- errors: str = 'strict' -- ) -> str: -- with open(where(), encoding=encoding) as data: -- return data.read() -- -- # If we don't have importlib.resources, then we will just do the old logic -- # of assuming we're on the filesystem and munge the path directly. -- def where() -> str: -- f = os.path.dirname(__file__) -- -- return os.path.join(f, "cacert.pem") -- -- def contents() -> str: -- return read_text("pip._vendor.certifi", "cacert.pem", encoding="ascii") +def contents() -> str: + with open(where(), encoding='utf=8') as data: + return data.read() -- -2.45.1 +2.50.1 diff --git a/nowarn-pip._internal.main.patch b/nowarn-pip._internal.main.patch deleted file mode 100644 index c8c98ed..0000000 --- a/nowarn-pip._internal.main.patch +++ /dev/null @@ -1,79 +0,0 @@ -From 9d1e0a0e91cad143702b3a2d8c54bd765a5d9eb2 Mon Sep 17 00:00:00 2001 -From: Karolina Surma -Date: Thu, 27 Jun 2024 10:48:03 +0200 -Subject: [PATCH] Don't warn the user about pip._internal.main() entrypoint - -In Fedora, we use that in ensurepip and users cannot do anything about it, -this warning is juts moot. Also, the warning breaks CPython test suite. - -Co-Authored-By: =?UTF-8?q?Miro=20Hron=C4=8Dok?= ---- - src/pip/_internal/__init__.py | 2 +- - src/pip/_internal/utils/entrypoints.py | 19 ++++++++++--------- - tests/functional/test_cli.py | 3 ++- - 3 files changed, 13 insertions(+), 11 deletions(-) - -diff --git a/src/pip/_internal/__init__.py b/src/pip/_internal/__init__.py -index 1a5b7f8..682b9e4 100755 ---- a/src/pip/_internal/__init__.py -+++ b/src/pip/_internal/__init__.py -@@ -15,4 +15,4 @@ def main(args: Optional[List[str]] = None) -> int: - """ - from pip._internal.utils.entrypoints import _wrapper - -- return _wrapper(args) -+ return _wrapper(args, _nowarn=True) -diff --git a/src/pip/_internal/utils/entrypoints.py b/src/pip/_internal/utils/entrypoints.py -index 1501369..70034eb 100644 ---- a/src/pip/_internal/utils/entrypoints.py -+++ b/src/pip/_internal/utils/entrypoints.py -@@ -20,7 +20,7 @@ if WINDOWS: - ] - - --def _wrapper(args: Optional[List[str]] = None) -> int: -+def _wrapper(args: Optional[List[str]] = None, _nowarn: bool = False) -> int: - """Central wrapper for all old entrypoints. - - Historically pip has had several entrypoints defined. Because of issues -@@ -32,14 +32,15 @@ def _wrapper(args: Optional[List[str]] = None) -> int: - directing them to an appropriate place for help, we now define all of - our old entrypoints as wrappers for the current one. - """ -- sys.stderr.write( -- "WARNING: pip is being invoked by an old script wrapper. This will " -- "fail in a future version of pip.\n" -- "Please see https://github.com/pypa/pip/issues/5599 for advice on " -- "fixing the underlying issue.\n" -- "To avoid this problem you can invoke Python with '-m pip' instead of " -- "running pip directly.\n" -- ) -+ if not _nowarn: -+ sys.stderr.write( -+ "WARNING: pip is being invoked by an old script wrapper. This will " -+ "fail in a future version of pip.\n" -+ "Please see https://github.com/pypa/pip/issues/5599 for advice on " -+ "fixing the underlying issue.\n" -+ "To avoid this problem you can invoke Python with '-m pip' instead of " -+ "running pip directly.\n" -+ ) - return main(args) - - -diff --git a/tests/functional/test_cli.py b/tests/functional/test_cli.py -index e1ccf04..30b8f74 100644 ---- a/tests/functional/test_cli.py -+++ b/tests/functional/test_cli.py -@@ -49,7 +49,8 @@ def test_entrypoints_work(entrypoint: str, script: PipTestEnvironment) -> None: - result = script.pip("-V") - result2 = script.run("fake_pip", "-V", allow_stderr_warning=True) - assert result.stdout == result2.stdout -- assert "old script wrapper" in result2.stderr -+ if entrypoint[0] != "fake_pip = pip._internal:main": -+ assert "old script wrapper" in result2.stderr - - - @pytest.mark.parametrize( --- -2.45.1 - diff --git a/python-pip.spec b/python-pip.spec index cc3f013..fdea020 100644 --- a/python-pip.spec +++ b/python-pip.spec @@ -6,7 +6,7 @@ %bcond man 1 %global srcname pip -%global base_version 25.1.1 +%global base_version 25.2 %global upstream_version %{base_version}%{?prerel} %global python_wheel_name %{srcname}-%{upstream_version}-py3-none-any.whl @@ -36,7 +36,6 @@ Summary: A tool for installing and managing Python packages # truststore: MIT # tomli: MIT # tomli-w: MIT -# typing-extensions: Python-2.0.1 # urllib3: MIT License: MIT AND Python-2.0.1 AND Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause AND ISC AND MPL-2.0 AND (Apache-2.0 OR BSD-2-Clause) @@ -94,19 +93,15 @@ Patch: remove-existing-dist-only-if-path-conflicts.patch # The same patch is a part of the RPM-packaged python-certifi Patch: dummy-certifi.patch -# Don't warn the user about pip._internal.main() entrypoint -# In Fedora, we use that in ensurepip and users cannot do anything about it, -# this warning is juts moot. Also, the warning breaks CPython test suite. -Patch: nowarn-pip._internal.main.patch - -# Adjust path_to_url et al. to produce the same results on Python 3.14+ -# https://github.com/pypa/pip/pull/13423 -Patch: python3.14-file-urls.patch - # https://fedoraproject.org/wiki/Changes/dropingOfCertPemFile # https://github.com/sethmlarson/truststore/pull/183 Patch: truststore-pem-path.patch +# pytest-subket has been introduced to intercept network calls +# https://github.com/pypa/pip/commit/a4b40f62332ccb3228b12cc5ae1493c75177247a +# We don't need a layer to check that, as we're by default in an offline environment +Patch: downstream-remove-pytest-subket.patch + # Remove -s from Python shebang - ensure that packages installed with pip # to user locations are seen by pip itself %undefine _py3_shebang_s @@ -123,25 +118,24 @@ Packages" or "Pip Installs Python". # You can generate it with: # %%{_rpmconfigdir}/pythonbundles.py --namespace 'python%%{1}dist' src/pip/_vendor/vendor.txt %global bundled() %{expand: -Provides: bundled(python%{1}dist(cachecontrol)) = 0.14.2 -Provides: bundled(python%{1}dist(certifi)) = 2025.1.31 +Provides: bundled(python%{1}dist(cachecontrol)) = 0.14.3 +Provides: bundled(python%{1}dist(certifi)) = 2025.7.14 Provides: bundled(python%{1}dist(dependency-groups)) = 1.3.1 -Provides: bundled(python%{1}dist(distlib)) = 0.3.9 +Provides: bundled(python%{1}dist(distlib)) = 0.4 Provides: bundled(python%{1}dist(distro)) = 1.9 Provides: bundled(python%{1}dist(idna)) = 3.10 -Provides: bundled(python%{1}dist(msgpack)) = 1.1 +Provides: bundled(python%{1}dist(msgpack)) = 1.1.1 Provides: bundled(python%{1}dist(packaging)) = 25 -Provides: bundled(python%{1}dist(platformdirs)) = 4.3.7 -Provides: bundled(python%{1}dist(pygments)) = 2.19.1 +Provides: bundled(python%{1}dist(platformdirs)) = 4.3.8 +Provides: bundled(python%{1}dist(pygments)) = 2.19.2 Provides: bundled(python%{1}dist(pyproject-hooks)) = 1.2 -Provides: bundled(python%{1}dist(requests)) = 2.32.3 -Provides: bundled(python%{1}dist(resolvelib)) = 1.1 -Provides: bundled(python%{1}dist(rich)) = 14 +Provides: bundled(python%{1}dist(requests)) = 2.32.4 +Provides: bundled(python%{1}dist(resolvelib)) = 1.2 +Provides: bundled(python%{1}dist(rich)) = 14.1 Provides: bundled(python%{1}dist(setuptools)) = 70.3 Provides: bundled(python%{1}dist(tomli)) = 2.2.1 Provides: bundled(python%{1}dist(tomli-w)) = 1.2 Provides: bundled(python%{1}dist(truststore)) = 0.10.1 -Provides: bundled(python%{1}dist(typing-extensions)) = 4.13.2 Provides: bundled(python%{1}dist(urllib3)) = 1.26.20 } @@ -222,7 +216,10 @@ rm -v src/pip/_vendor/distlib/*.exe sed -i '/\.exe/d' pyproject.toml # Remove unused test requirements -sed -Ei '/(pytest-(cov|xdist|rerunfailures)|proxy\.py)/d' tests/requirements.txt +sed -Ei '/(pytest-(cov|xdist|rerunfailures|subket)|proxy\.py)/d' pyproject.toml + +# Remove unused pytest-subket options +sed -Ei '/(--disable-socket|--allow-unix-socket|--allow-hosts=localhost)/d' pyproject.toml %if %{with tests} # tests expect wheels in here @@ -235,7 +232,7 @@ cp -a %{SOURCE1} %{SOURCE2} %{SOURCE3} tests/data/common_wheels %generate_buildrequires # we only use this to generate test requires # the "pyproject" part is explicitly disabled as it generates a requirement on pip -%pyproject_buildrequires -N tests/requirements.txt +%pyproject_buildrequires -N -g test %endif diff --git a/python3.14-file-urls.patch b/python3.14-file-urls.patch deleted file mode 100644 index 77e89de..0000000 --- a/python3.14-file-urls.patch +++ /dev/null @@ -1,67 +0,0 @@ -From 03b4b94a0338d80d1f45697a5ea083a5e5c937db Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= -Date: Thu, 12 Jun 2025 23:36:24 +0200 -Subject: [PATCH] Adjust path_to_url et al. to produce the same results on - Python 3.14+ - -See https://github.com/python/cpython/issues/125974 -and https://github.com/pypa/pip/pull/13138#issuecomment-2567715303 ---- - src/pip/_internal/models/link.py | 6 +++++- - src/pip/_internal/utils/urls.py | 2 +- - tests/unit/test_urls.py | 2 +- - 3 files changed, 7 insertions(+), 3 deletions(-) - -diff --git a/src/pip/_internal/models/link.py b/src/pip/_internal/models/link.py -index f0560f6..38423d1 100644 ---- a/src/pip/_internal/models/link.py -+++ b/src/pip/_internal/models/link.py -@@ -4,6 +4,7 @@ import logging - import os - import posixpath - import re -+import sys - import urllib.parse - from dataclasses import dataclass - from typing import ( -@@ -134,7 +135,10 @@ def _clean_file_url_path(part: str) -> str: - # should not be quoted. On Linux where drive letters do not - # exist, the colon should be quoted. We rely on urllib.request - # to do the right thing here. -- return urllib.request.pathname2url(urllib.request.url2pathname(part)) -+ ret = urllib.request.pathname2url(urllib.request.url2pathname(part)) -+ if sys.version_info >= (3, 14): -+ ret = ret.removeprefix("//") -+ return ret - - - # percent-encoded: / -diff --git a/src/pip/_internal/utils/urls.py b/src/pip/_internal/utils/urls.py -index 9f34f88..e951a5e 100644 ---- a/src/pip/_internal/utils/urls.py -+++ b/src/pip/_internal/utils/urls.py -@@ -12,7 +12,7 @@ def path_to_url(path: str) -> str: - quoted path parts. - """ - path = os.path.normpath(os.path.abspath(path)) -- url = urllib.parse.urljoin("file:", urllib.request.pathname2url(path)) -+ url = urllib.parse.urljoin("file://", urllib.request.pathname2url(path)) - return url - - -diff --git a/tests/unit/test_urls.py b/tests/unit/test_urls.py -index 0c14525..2a56e45 100644 ---- a/tests/unit/test_urls.py -+++ b/tests/unit/test_urls.py -@@ -11,7 +11,7 @@ from pip._internal.utils.urls import path_to_url, url_to_path - def test_path_to_url_unix() -> None: - assert path_to_url("/tmp/file") == "file:///tmp/file" - path = os.path.join(os.getcwd(), "file") -- assert path_to_url("file") == "file://" + urllib.request.pathname2url(path) -+ assert path_to_url("file") == "file://" + path - - - @pytest.mark.skipif("sys.platform != 'win32'") --- -2.49.0 - diff --git a/remove-existing-dist-only-if-path-conflicts.patch b/remove-existing-dist-only-if-path-conflicts.patch index 20e5f28..d280f34 100644 --- a/remove-existing-dist-only-if-path-conflicts.patch +++ b/remove-existing-dist-only-if-path-conflicts.patch @@ -1,8 +1,11 @@ -From 9020f56e88a7dbaef688c147c281909f95b4e1d1 Mon Sep 17 00:00:00 2001 +From d5cb806a14bb50a96484bca6536e81f2ac316b9d Mon Sep 17 00:00:00 2001 From: Karolina Surma Date: Wed, 16 Feb 2022 08:36:21 +0100 Subject: [PATCH] Prevent removing of the system packages installed under /usr/lib when pip install --upgrade is executed. +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit Resolves: rhbz#1550368 @@ -12,7 +15,6 @@ Co-Authored-By: Petr Viktorin Co-Authored-By: Lumir Balhar Co-Authored-By: Miro HronĨok Co-Authored-By: Karolina Surma - --- src/pip/_internal/metadata/base.py | 12 +++++++++++- src/pip/_internal/req/req_install.py | 2 +- @@ -21,10 +23,10 @@ Co-Authored-By: Karolina Surma 4 files changed, 27 insertions(+), 3 deletions(-) diff --git a/src/pip/_internal/metadata/base.py b/src/pip/_internal/metadata/base.py -index 9eabcdb..9816691 100644 +index 230e114..8bd5d31 100644 --- a/src/pip/_internal/metadata/base.py +++ b/src/pip/_internal/metadata/base.py -@@ -28,7 +28,7 @@ from pip._vendor.packaging.utils import NormalizedName, canonicalize_name +@@ -23,7 +23,7 @@ from pip._vendor.packaging.utils import NormalizedName, canonicalize_name from pip._vendor.packaging.version import Version from pip._internal.exceptions import NoneMetadataError @@ -33,7 +35,7 @@ index 9eabcdb..9816691 100644 from pip._internal.models.direct_url import ( DIRECT_URL_METADATA_NAME, DirectUrl, -@@ -578,6 +578,16 @@ class BaseDistribution(Protocol): +@@ -575,6 +575,16 @@ class BaseDistribution(Protocol): for extra in self._iter_egg_info_extras(): metadata["Provides-Extra"] = extra @@ -51,10 +53,10 @@ index 9eabcdb..9816691 100644 class BaseEnvironment: """An environment containing distributions to introspect.""" diff --git a/src/pip/_internal/req/req_install.py b/src/pip/_internal/req/req_install.py -index 2132785..0340890 100644 +index c9f6bff..c101826 100644 --- a/src/pip/_internal/req/req_install.py +++ b/src/pip/_internal/req/req_install.py -@@ -449,7 +449,7 @@ class InstallRequirement: +@@ -453,7 +453,7 @@ class InstallRequirement: f"lack sys.path precedence to {existing_dist.raw_name} " f"in {existing_dist.location}" ) @@ -64,10 +66,10 @@ index 2132785..0340890 100644 else: if self.editable: diff --git a/src/pip/_internal/resolution/legacy/resolver.py b/src/pip/_internal/resolution/legacy/resolver.py -index 1dd0d70..414bdbe 100644 +index 33a4fdc..1fe886e 100644 --- a/src/pip/_internal/resolution/legacy/resolver.py +++ b/src/pip/_internal/resolution/legacy/resolver.py -@@ -319,7 +319,9 @@ class Resolver(BaseResolver): +@@ -322,7 +322,9 @@ class Resolver(BaseResolver): # Don't uninstall the conflict if doing a user install and the # conflict is not a user install. assert req.satisfied_by is not None @@ -79,19 +81,19 @@ index 1dd0d70..414bdbe 100644 req.satisfied_by = None diff --git a/src/pip/_internal/resolution/resolvelib/factory.py b/src/pip/_internal/resolution/resolvelib/factory.py -index 1f31d83..3804774 100644 +index f23e4cd..1bada79 100644 --- a/src/pip/_internal/resolution/resolvelib/factory.py +++ b/src/pip/_internal/resolution/resolvelib/factory.py -@@ -1,6 +1,8 @@ +@@ -3,6 +3,8 @@ from __future__ import annotations import contextlib import functools import logging +import sys +import sysconfig + from collections.abc import Iterable, Iterator, Mapping, Sequence from typing import ( TYPE_CHECKING, - Callable, -@@ -617,6 +619,16 @@ class Factory: +@@ -615,6 +617,16 @@ class Factory: if dist is None: # Not installed, no uninstallation required. return None @@ -109,5 +111,5 @@ index 1f31d83..3804774 100644 # be uninstalled, no matter it's in global or user site, because the # user site installation has precedence over global. -- -2.45.1 +2.50.1 diff --git a/sources b/sources index 4c3846d..7230ff9 100644 --- a/sources +++ b/sources @@ -1,4 +1,4 @@ -SHA512 (pip-25.1.1.tar.gz) = ce61c9861265139b3c5ea9be9dc246097cd75c21687cf8301f80a377d02420c4524f0d6307d2ca0232ff8715b1105343bcfdb9cac6b69503780ab2c4645558dc +SHA512 (pip-25.2.tar.gz) = 5cc65c9091fdda7905e26ce32ddaa3a1c2fd287d69fd3da67c814ba7e8e5be59301d8327c06cdca78c1b95f4a5b5f75c87f36a549022408cc0e8f9411c0db11e SHA512 (setuptools-79.0.1-py3-none-any.whl) = fef6cfc6f95a5bb7320f1680e1c665cb8d9a4e4227cde4d8aab8a50bed4bcf04320085b9d7d5343359f887008db5c5a861e57f3d08b7b0b2311a28adaeee6b4a SHA512 (wheel-0.45.1-py3-none-any.whl) = 86c16248ec804ee0ac95d43b03d47351dceb534d0cdc4025ca1eb073e39e539de44c870b9261f0373144e1537f0e42675a759a318a8d5d346bbd9efcb704061d SHA512 (coverage-0-py3-none-any.whl) = e734192565347010efe68f8ba600254259c9b647f3c553fd4e5d87b1d7f955cb15d6f7d807716f4a6415d239beed945fbec7210feaf502e9cc849c332845926e From e2a1a1a9947c6f5b6ceff1148f2e32fe57249ee9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Wed, 27 Aug 2025 16:52:27 +0200 Subject: [PATCH 2/9] Include SBOM in the .whl file in python-pip-wheel --- python-pip.spec | 2 ++ 1 file changed, 2 insertions(+) diff --git a/python-pip.spec b/python-pip.spec index fdea020..91369d3 100644 --- a/python-pip.spec +++ b/python-pip.spec @@ -287,8 +287,10 @@ sed -i -e "s/^\\(complete.*\\) pip%{python3_version}\$/\\1 pip%{python3_version} -e s/_pip_completion/_pip%{python3_version_nodots}_completion/ \ %{buildroot}%{bash_completions_dir}/pip%{python3_version} +# Install the built wheel and inject SBOM into it (if the macro is available) mkdir -p %{buildroot}%{python_wheel_dir} install -p %{_pyproject_wheeldir}/%{python_wheel_name} -t %{buildroot}%{python_wheel_dir} +%{?python_wheel_inject_sbom:%python_wheel_inject_sbom %{buildroot}%{python_wheel_dir}/%{python_wheel_name}} %check From 8ddd39d6cd1ba1ee38a8ee0e8a31a511807b2b80 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Wed, 10 Sep 2025 19:11:16 +0200 Subject: [PATCH 3/9] Security fix for the bundled urllib3 for CVE-2025-50181 --- python-pip.spec | 5 ++++ urllib3-CVE-2025-50181.patch | 51 ++++++++++++++++++++++++++++++++++++ 2 files changed, 56 insertions(+) create mode 100644 urllib3-CVE-2025-50181.patch diff --git a/python-pip.spec b/python-pip.spec index 91369d3..de7e8db 100644 --- a/python-pip.spec +++ b/python-pip.spec @@ -102,6 +102,11 @@ Patch: truststore-pem-path.patch # We don't need a layer to check that, as we're by default in an offline environment Patch: downstream-remove-pytest-subket.patch +# Patch for the bundled urllib3 for CVE-2025-50181 +# Redirects are not disabled when retries are disabled on PoolManager instantiation +# Upstream fix: https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857 +Patch: urllib3-CVE-2025-50181.patch + # Remove -s from Python shebang - ensure that packages installed with pip # to user locations are seen by pip itself %undefine _py3_shebang_s diff --git a/urllib3-CVE-2025-50181.patch b/urllib3-CVE-2025-50181.patch new file mode 100644 index 0000000..05e6353 --- /dev/null +++ b/urllib3-CVE-2025-50181.patch @@ -0,0 +1,51 @@ +From b3d543d7e16af844394316360ef1bf0b9d10f1b1 Mon Sep 17 00:00:00 2001 +From: Illia Volochii +Date: Wed, 18 Jun 2025 16:25:01 +0300 +Subject: [PATCH] Security fix for CVE-2025-50181 + +Co-authored-by: Seth Michael Larson +Co-authored-by: Quentin Pradet +Co-authored-by: Seth Michael Larson +--- + src/pip/_vendor/urllib3/poolmanager.py | 18 +++++++++++++++++- + 1 file changed, 17 insertions(+), 1 deletion(-) + +diff --git a/src/pip/_vendor/urllib3/poolmanager.py b/src/pip/_vendor/urllib3/poolmanager.py +index fb51bf7..a8de7c6 100644 +--- a/src/pip/_vendor/urllib3/poolmanager.py ++++ b/src/pip/_vendor/urllib3/poolmanager.py +@@ -170,6 +170,22 @@ class PoolManager(RequestMethods): + + def __init__(self, num_pools=10, headers=None, **connection_pool_kw): + RequestMethods.__init__(self, headers) ++ if "retries" in connection_pool_kw: ++ retries = connection_pool_kw["retries"] ++ if not isinstance(retries, Retry): ++ # When Retry is initialized, raise_on_redirect is based ++ # on a redirect boolean value. ++ # But requests made via a pool manager always set ++ # redirect to False, and raise_on_redirect always ends ++ # up being False consequently. ++ # Here we fix the issue by setting raise_on_redirect to ++ # a value needed by the pool manager without considering ++ # the redirect boolean. ++ raise_on_redirect = retries is not False ++ retries = Retry.from_int(retries, redirect=False) ++ retries.raise_on_redirect = raise_on_redirect ++ connection_pool_kw = connection_pool_kw.copy() ++ connection_pool_kw["retries"] = retries + self.connection_pool_kw = connection_pool_kw + self.pools = RecentlyUsedContainer(num_pools) + +@@ -389,7 +405,7 @@ class PoolManager(RequestMethods): + kw["body"] = None + kw["headers"] = HTTPHeaderDict(kw["headers"])._prepare_for_method_change() + +- retries = kw.get("retries") ++ retries = kw.get("retries", response.retries) + if not isinstance(retries, Retry): + retries = Retry.from_int(retries, redirect=redirect) + +-- +2.51.0 + From 32b5b38cb0a6f0fc6fe586fb7844a4594cb25c49 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Wed, 10 Sep 2025 19:11:16 +0200 Subject: [PATCH 4/9] Security fix for the bundled urllib3 for CVE-2025-50181 --- python-pip.spec | 5 ++++ urllib3-CVE-2025-50181.patch | 51 ++++++++++++++++++++++++++++++++++++ 2 files changed, 56 insertions(+) create mode 100644 urllib3-CVE-2025-50181.patch diff --git a/python-pip.spec b/python-pip.spec index cc3f013..ca0366f 100644 --- a/python-pip.spec +++ b/python-pip.spec @@ -107,6 +107,11 @@ Patch: python3.14-file-urls.patch # https://github.com/sethmlarson/truststore/pull/183 Patch: truststore-pem-path.patch +# Patch for the bundled urllib3 for CVE-2025-50181 +# Redirects are not disabled when retries are disabled on PoolManager instantiation +# Upstream fix: https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857 +Patch: urllib3-CVE-2025-50181.patch + # Remove -s from Python shebang - ensure that packages installed with pip # to user locations are seen by pip itself %undefine _py3_shebang_s diff --git a/urllib3-CVE-2025-50181.patch b/urllib3-CVE-2025-50181.patch new file mode 100644 index 0000000..05e6353 --- /dev/null +++ b/urllib3-CVE-2025-50181.patch @@ -0,0 +1,51 @@ +From b3d543d7e16af844394316360ef1bf0b9d10f1b1 Mon Sep 17 00:00:00 2001 +From: Illia Volochii +Date: Wed, 18 Jun 2025 16:25:01 +0300 +Subject: [PATCH] Security fix for CVE-2025-50181 + +Co-authored-by: Seth Michael Larson +Co-authored-by: Quentin Pradet +Co-authored-by: Seth Michael Larson +--- + src/pip/_vendor/urllib3/poolmanager.py | 18 +++++++++++++++++- + 1 file changed, 17 insertions(+), 1 deletion(-) + +diff --git a/src/pip/_vendor/urllib3/poolmanager.py b/src/pip/_vendor/urllib3/poolmanager.py +index fb51bf7..a8de7c6 100644 +--- a/src/pip/_vendor/urllib3/poolmanager.py ++++ b/src/pip/_vendor/urllib3/poolmanager.py +@@ -170,6 +170,22 @@ class PoolManager(RequestMethods): + + def __init__(self, num_pools=10, headers=None, **connection_pool_kw): + RequestMethods.__init__(self, headers) ++ if "retries" in connection_pool_kw: ++ retries = connection_pool_kw["retries"] ++ if not isinstance(retries, Retry): ++ # When Retry is initialized, raise_on_redirect is based ++ # on a redirect boolean value. ++ # But requests made via a pool manager always set ++ # redirect to False, and raise_on_redirect always ends ++ # up being False consequently. ++ # Here we fix the issue by setting raise_on_redirect to ++ # a value needed by the pool manager without considering ++ # the redirect boolean. ++ raise_on_redirect = retries is not False ++ retries = Retry.from_int(retries, redirect=False) ++ retries.raise_on_redirect = raise_on_redirect ++ connection_pool_kw = connection_pool_kw.copy() ++ connection_pool_kw["retries"] = retries + self.connection_pool_kw = connection_pool_kw + self.pools = RecentlyUsedContainer(num_pools) + +@@ -389,7 +405,7 @@ class PoolManager(RequestMethods): + kw["body"] = None + kw["headers"] = HTTPHeaderDict(kw["headers"])._prepare_for_method_change() + +- retries = kw.get("retries") ++ retries = kw.get("retries", response.retries) + if not isinstance(retries, Retry): + retries = Retry.from_int(retries, redirect=redirect) + +-- +2.51.0 + From 566ed62a196ae263b08efb11f1389b83153876c6 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Fri, 19 Sep 2025 13:59:29 +0200 Subject: [PATCH 5/9] Rebuilt for Python 3.14.0rc3 bytecode From 1ba8f96abd7e8711a938ed93531ea482ede3bb29 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Fri, 19 Sep 2025 16:00:20 +0200 Subject: [PATCH 6/9] Rebuilt for Python 3.14.0rc3 bytecode From 584939ebdd94304d085e21460ecb06063212713d Mon Sep 17 00:00:00 2001 From: Karolina Surma Date: Thu, 23 Oct 2025 15:14:18 +0200 Subject: [PATCH 7/9] CI: Run tests with Python 3.15 [skip changelog] --- plan.fmf | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/plan.fmf b/plan.fmf index 79f9d9c..b336d72 100644 --- a/plan.fmf +++ b/plan.fmf @@ -27,6 +27,9 @@ discover: - name: smoke314 path: /smoke test: VERSION=3.14 ./venv.sh + - name: smoke315 + path: /smoke + test: VERSION=3.15 ./venv.sh - name: smoke39_virtualenv path: /smoke test: VERSION=3.9 METHOD=virtualenv ./venv.sh @@ -45,6 +48,9 @@ discover: - name: smoke314_virtualenv path: /smoke test: VERSION=3.14 METHOD=virtualenv ./venv.sh + - name: smoke315_virtualenv + path: /smoke + test: VERSION=3.15 METHOD=virtualenv ./venv.sh - name: rpms_pyproject-rpm-macros how: shell url: https://src.fedoraproject.org/rpms/pyproject-rpm-macros.git @@ -89,6 +95,7 @@ prepare: - python3.12-devel - python3.13-devel - python3.14-devel + - python3.15-devel - python3-devel - python3-tox - mock From 1f462a281f772282d8ade483860056f5175138c5 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Sun, 30 Nov 2025 10:13:45 +0100 Subject: [PATCH 8/9] CI: Ensure the devel subpackages for 3.6 and 3.9 are available See https://src.fedoraproject.org/rpms/python3.9/pull-request/213 and https://src.fedoraproject.org/rpms/python3.6/pull-request/153 [skip changelog] --- plan.fmf | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/plan.fmf b/plan.fmf index b336d72..72ad07b 100644 --- a/plan.fmf +++ b/plan.fmf @@ -88,8 +88,8 @@ prepare: package: - gcc - virtualenv - - python3.6 - - python3.9 + - python3.6-devel + - python3.9-devel - python3.10-devel - python3.11-devel - python3.12-devel From 2b2a030e77e9665b23c9b6d0e415556ec1b73a2b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Fri, 28 Nov 2025 12:16:06 +0100 Subject: [PATCH 9/9] Update to 25.3 - Fixes: rhbz#2406299 --- python-pip.spec | 32 ++++++++++++++++---------------- sources | 3 ++- truststore-pem-path.patch | 26 -------------------------- 3 files changed, 18 insertions(+), 43 deletions(-) delete mode 100644 truststore-pem-path.patch diff --git a/python-pip.spec b/python-pip.spec index de7e8db..8dc0aff 100644 --- a/python-pip.spec +++ b/python-pip.spec @@ -6,7 +6,7 @@ %bcond man 1 %global srcname pip -%global base_version 25.2 +%global base_version 25.3 %global upstream_version %{base_version}%{?prerel} %global python_wheel_name %{srcname}-%{upstream_version}-py3-none-any.whl @@ -57,12 +57,16 @@ Source1: https://files.pythonhosted.org/packages/0d/6d/b4752b044bf94cb802 # See https://github.com/pypa/pip/pull/13382 as an attempt to drop the requirement from pip tests. Source2: https://files.pythonhosted.org/packages/0b/2c/87f3254fd8ffd29e4c02732eee68a83a1d3c346ae39bc6822dcbcb697f2b/wheel-0.45.1-py3-none-any.whl +# flit_core.whl +# This is not built as RPM-packaged wheel in Fedora at all. +Source3: https://files.pythonhosted.org/packages/f2/65/b6ba90634c984a4fcc02c7e3afe523fef500c4980fec67cc27536ee50acf/flit_core-3.12.0-py3-none-any.whl + # coverage.whl # There is no RPM-packaged python-coverage-wheel, the package is archful. # Upstream uses this to measure coverage, which we don't. # This is a dummy placeholder package that only contains empty coverage.process_startup(). # That way, we don't need to patch the usage out of conftest.py. -Source3: coverage-0-py3-none-any.whl +Source4: coverage-0-py3-none-any.whl BuildArch: noarch @@ -93,10 +97,6 @@ Patch: remove-existing-dist-only-if-path-conflicts.patch # The same patch is a part of the RPM-packaged python-certifi Patch: dummy-certifi.patch -# https://fedoraproject.org/wiki/Changes/dropingOfCertPemFile -# https://github.com/sethmlarson/truststore/pull/183 -Patch: truststore-pem-path.patch - # pytest-subket has been introduced to intercept network calls # https://github.com/pypa/pip/commit/a4b40f62332ccb3228b12cc5ae1493c75177247a # We don't need a layer to check that, as we're by default in an offline environment @@ -124,23 +124,23 @@ Packages" or "Pip Installs Python". # %%{_rpmconfigdir}/pythonbundles.py --namespace 'python%%{1}dist' src/pip/_vendor/vendor.txt %global bundled() %{expand: Provides: bundled(python%{1}dist(cachecontrol)) = 0.14.3 -Provides: bundled(python%{1}dist(certifi)) = 2025.7.14 +Provides: bundled(python%{1}dist(certifi)) = 2025.10.5 Provides: bundled(python%{1}dist(dependency-groups)) = 1.3.1 Provides: bundled(python%{1}dist(distlib)) = 0.4 Provides: bundled(python%{1}dist(distro)) = 1.9 Provides: bundled(python%{1}dist(idna)) = 3.10 -Provides: bundled(python%{1}dist(msgpack)) = 1.1.1 +Provides: bundled(python%{1}dist(msgpack)) = 1.1.2 Provides: bundled(python%{1}dist(packaging)) = 25 -Provides: bundled(python%{1}dist(platformdirs)) = 4.3.8 +Provides: bundled(python%{1}dist(platformdirs)) = 4.5 Provides: bundled(python%{1}dist(pygments)) = 2.19.2 Provides: bundled(python%{1}dist(pyproject-hooks)) = 1.2 -Provides: bundled(python%{1}dist(requests)) = 2.32.4 -Provides: bundled(python%{1}dist(resolvelib)) = 1.2 -Provides: bundled(python%{1}dist(rich)) = 14.1 +Provides: bundled(python%{1}dist(requests)) = 2.32.5 +Provides: bundled(python%{1}dist(resolvelib)) = 1.2.1 +Provides: bundled(python%{1}dist(rich)) = 14.2 Provides: bundled(python%{1}dist(setuptools)) = 70.3 -Provides: bundled(python%{1}dist(tomli)) = 2.2.1 +Provides: bundled(python%{1}dist(tomli)) = 2.3 Provides: bundled(python%{1}dist(tomli-w)) = 1.2 -Provides: bundled(python%{1}dist(truststore)) = 0.10.1 +Provides: bundled(python%{1}dist(truststore)) = 0.10.4 Provides: bundled(python%{1}dist(urllib3)) = 1.26.20 } @@ -175,7 +175,7 @@ BuildRequires: python%{python3_pkgversion}-devel # The minimal version is for bundled provides verification script BuildRequires: python3-rpm-generators >= 11-8 BuildRequires: pyproject-rpm-macros -BuildRequires: python%{python3_pkgversion}-setuptools +BuildRequires: python%{python3_pkgversion}-flit-core BuildRequires: bash-completion BuildRequires: ca-certificates Requires: ca-certificates @@ -229,7 +229,7 @@ sed -Ei '/(--disable-socket|--allow-unix-socket|--allow-hosts=localhost)/d' pypr %if %{with tests} # tests expect wheels in here mkdir tests/data/common_wheels -cp -a %{SOURCE1} %{SOURCE2} %{SOURCE3} tests/data/common_wheels +cp -a %{SOURCE1} %{SOURCE2} %{SOURCE3} %{SOURCE4} tests/data/common_wheels %endif diff --git a/sources b/sources index 7230ff9..48867fb 100644 --- a/sources +++ b/sources @@ -1,4 +1,5 @@ -SHA512 (pip-25.2.tar.gz) = 5cc65c9091fdda7905e26ce32ddaa3a1c2fd287d69fd3da67c814ba7e8e5be59301d8327c06cdca78c1b95f4a5b5f75c87f36a549022408cc0e8f9411c0db11e +SHA512 (pip-25.3.tar.gz) = f50db092213ec3bb819d3da5669f73d119b5ec7f7ac5e8a587a17c27eafa32bc17a057df09389c526a3769ef3577f5553187d54ceffa89aed63f4b4498ff044e SHA512 (setuptools-79.0.1-py3-none-any.whl) = fef6cfc6f95a5bb7320f1680e1c665cb8d9a4e4227cde4d8aab8a50bed4bcf04320085b9d7d5343359f887008db5c5a861e57f3d08b7b0b2311a28adaeee6b4a SHA512 (wheel-0.45.1-py3-none-any.whl) = 86c16248ec804ee0ac95d43b03d47351dceb534d0cdc4025ca1eb073e39e539de44c870b9261f0373144e1537f0e42675a759a318a8d5d346bbd9efcb704061d +SHA512 (flit_core-3.12.0-py3-none-any.whl) = 790c12b1f43201e365fb3f8f2f0a54e1a578876799dfdf8bfeea679a25ea096bf62946d006618c1458ae6e37ce6d00998f37e9aba426d5ab80d32ef2d75da4e0 SHA512 (coverage-0-py3-none-any.whl) = e734192565347010efe68f8ba600254259c9b647f3c553fd4e5d87b1d7f955cb15d6f7d807716f4a6415d239beed945fbec7210feaf502e9cc849c332845926e diff --git a/truststore-pem-path.patch b/truststore-pem-path.patch deleted file mode 100644 index f771a33..0000000 --- a/truststore-pem-path.patch +++ /dev/null @@ -1,26 +0,0 @@ -From 2c8231f03987daaf9524f9568884a7b296480b32 Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= -Date: Thu, 17 Jul 2025 09:50:35 +0200 -Subject: [PATCH] Fedora 43 removes some symbolic links - -See https://fedoraproject.org/wiki/Changes/dropingOfCertPemFile ---- - src/pip/_vendor/truststore/_openssl.py | 4 +++- - 1 file changed, 3 insertions(+), 1 deletion(-) - -diff --git a/src/pip/_vendor/truststore/_openssl.py b/src/pip/_vendor/truststore/_openssl.py -index 9951cf7..3e25a56 100644 ---- a/src/pip/_vendor/truststore/_openssl.py -+++ b/src/pip/_vendor/truststore/_openssl.py -@@ -6,8 +6,10 @@ - - # candidates based on https://github.com/tiran/certifi-system-store by Christian Heimes - _CA_FILE_CANDIDATES = [ -- # Alpine, Arch, Fedora 34+, OpenWRT, RHEL 9+, BSD -+ # Alpine, Arch, Fedora 34-42, OpenWRT, RHEL 9-10, BSD - "/etc/ssl/cert.pem", -+ # Fedora 43+, RHEL 11+ -+ "/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem", - # Fedora <= 34, RHEL <= 9, CentOS <= 9 - "/etc/pki/tls/cert.pem", - # Debian, Ubuntu (requires ca-certificates)