From 89e46163b4f409425db78ab1861234214e0fa10e Mon Sep 17 00:00:00 2001 From: Lumir Balhar Date: Wed, 19 Jun 2024 14:12:29 +0200 Subject: [PATCH] Update to 2.32.3 (rhbz#2281881) and fix CVE-2024-35195 (rhbz#2282205) --- .gitignore | 1 + bf24b7.patch | 22 ----------- python-requests.spec | 20 +++++----- sources | 2 +- support_IPv6_CIDR_in_no_proxy.patch | 45 +++++++++++---------- system-certs.patch | 61 +++++++++++++++-------------- 6 files changed, 67 insertions(+), 84 deletions(-) delete mode 100644 bf24b7.patch diff --git a/.gitignore b/.gitignore index 67de33d..7c27bec 100644 --- a/.gitignore +++ b/.gitignore @@ -52,3 +52,4 @@ /requests-v2.28.1.tar.gz /requests-v2.28.2.tar.gz /requests-v2.31.0.tar.gz +/requests-v2.32.3.tar.gz diff --git a/bf24b7.patch b/bf24b7.patch deleted file mode 100644 index 7b5e21d..0000000 --- a/bf24b7.patch +++ /dev/null @@ -1,22 +0,0 @@ -From bf24b7d8d17da34be720c19e5978b2d3bf94a53b Mon Sep 17 00:00:00 2001 -From: franekmagiera -Date: Sun, 12 May 2024 22:08:24 +0200 -Subject: [PATCH] Use an invalid URI that will not cause httpbin to throw 500 - ---- - tests/test_requests.py | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/tests/test_requests.py b/tests/test_requests.py -index d05febeef5..b4e9fe92ae 100644 ---- a/tests/test_requests.py -+++ b/tests/test_requests.py -@@ -2721,7 +2721,7 @@ def test_preparing_bad_url(self, url): - with pytest.raises(requests.exceptions.InvalidURL): - r.prepare() - -- @pytest.mark.parametrize("url, exception", (("http://localhost:-1", InvalidURL),)) -+ @pytest.mark.parametrize("url, exception", (("http://:1", InvalidURL),)) - def test_redirecting_to_bad_url(self, httpbin, url, exception): - with pytest.raises(exception): - requests.get(httpbin("redirect-to"), params={"url": url}) diff --git a/python-requests.spec b/python-requests.spec index ebc7e28..5006660 100644 --- a/python-requests.spec +++ b/python-requests.spec @@ -5,8 +5,8 @@ %bcond extras %{undefined rhel} Name: python-requests -Version: 2.31.0 -Release: 7%{?dist} +Version: 2.32.3 +Release: 1%{?dist} Summary: HTTP library, written in Python, for human beings License: Apache-2.0 @@ -24,9 +24,6 @@ Patch: system-certs.patch # This change is backported also into RHEL 9.4 (via CS) Patch: support_IPv6_CIDR_in_no_proxy.patch -# Fix FTBFS (test_redirecting_to_bad_url) -Patch: https://github.com/psf/requests/commit/bf24b7.patch - BuildArch: noarch BuildRequires: python%{python3_pkgversion}-devel %if %{with tests} @@ -66,17 +63,13 @@ designed to make HTTP requests easy for developers. %autosetup -p1 -n requests-%{version} # env shebang in nonexecutable file -sed -i '/#!\/usr\/.*python/d' requests/certs.py +sed -i '/#!\/usr\/.*python/d' src/requests/certs.py # Some doctests use the internet and fail to pass in Koji. Since doctests don't have names, I don't # know a way to skip them. We also don't want to patch them out, because patching them out will # change the docs. Thus, we set pytest not to run doctests at all. sed -i 's/ --doctest-modules//' pyproject.toml -# Fix compatibility with pytest 8 -# Upstream report: https://github.com/psf/requests/issues/6679 -sed -i "/pytest.warns/s/None//" tests/test_requests.py - %build %pyproject_wheel @@ -90,8 +83,9 @@ sed -i "/pytest.warns/s/None//" tests/test_requests.py %check %pyproject_check_import %if %{with tests} +# test_unicode_header_name - reported: https://github.com/psf/requests/issues/6734 # test_use_proxy_from_environment needs pysocks -%pytest -v tests %{!?with_extras:-k "not test_use_proxy_from_environment"} +%pytest -v tests -k "not test_unicode_header_name %{!?with_extras:and not test_use_proxy_from_environment}" %endif @@ -101,6 +95,10 @@ sed -i "/pytest.warns/s/None//" tests/test_requests.py %changelog +* Wed Jun 19 2024 Lumír Balhar - 2.32.3-1 +- Update to 2.32.3 (rhbz#2281881) +- Fix for CVE-2024-35195 (rhbz#2282205) + * Sun Jun 09 2024 Python Maint - 2.31.0-7 - Rebuilt for Python 3.13 diff --git a/sources b/sources index 3e4fef8..2c91835 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (requests-v2.31.0.tar.gz) = 43f536bdb2360fcceb24ef98e995ffa66cdefc2c502629f17a5722445bfa9ad8489201958c846c2aaef37e427f95a4d56e321a91095c69754680abfd83b39150 +SHA512 (requests-v2.32.3.tar.gz) = ea3e85e035efed0fe22bf8640491ffb20c2ac50359bb1e11c9147ed850cac5e4a6a36ab58a48fc6c6d6a44df2b511e8a5d902444c034da6baa6adc5f9417697f diff --git a/support_IPv6_CIDR_in_no_proxy.patch b/support_IPv6_CIDR_in_no_proxy.patch index f8b7285..93bcff9 100644 --- a/support_IPv6_CIDR_in_no_proxy.patch +++ b/support_IPv6_CIDR_in_no_proxy.patch @@ -1,21 +1,23 @@ -From 4f89a66430e4f701b11fdeb9e253af87e29e6f0b Mon Sep 17 00:00:00 2001 +From 91526670ad66e83e799459cb23b031b88bb680b4 Mon Sep 17 00:00:00 2001 From: Derek Higgins -Date: Fri, 8 Oct 2021 11:12:27 +0100 -Subject: [PATCH] Add ipv6 support to should_bypass_proxies +Date: Thu, 30 May 2024 11:15:18 +0200 +Subject: [PATCH 2/2] Add ipv6 support to should_bypass_proxies Add support to should_bypass_proxies to support IPv6 ipaddresses and CIDRs in no_proxy. Includes adding IPv6 support to various other helper functions. + +Co-authored-by: Lumir Balhar --- - requests/utils.py | 83 ++++++++++++++++++++++++++++++++++++------- + src/requests/utils.py | 83 ++++++++++++++++++++++++++++++++++++------- tests/test_utils.py | 66 +++++++++++++++++++++++++++++++--- 2 files changed, 132 insertions(+), 17 deletions(-) diff --git a/src/requests/utils.py b/src/requests/utils.py -index 1ae77d68ff..6a026e2d32 100644 ---- a/requests/utils.py -+++ b/requests/utils.py -@@ -674,18 +674,46 @@ def requote_uri(uri): +index ae6c42f..0363698 100644 +--- a/src/requests/utils.py ++++ b/src/requests/utils.py +@@ -679,18 +679,46 @@ def requote_uri(uri): return quote(uri, safe=safe_without_percent) @@ -65,7 +67,7 @@ index 1ae77d68ff..6a026e2d32 100644 return (ipaddr & netmask) == (network & netmask) -@@ -705,12 +733,39 @@ def is_ipv4_address(string_ip): +@@ -710,12 +738,39 @@ def is_ipv4_address(string_ip): :rtype: bool """ try: @@ -106,7 +108,7 @@ index 1ae77d68ff..6a026e2d32 100644 def is_valid_cidr(string_network): """ Very simple check of the cidr format in no_proxy variable. -@@ -718,17 +773,19 @@ def is_valid_cidr(string_network): +@@ -723,17 +778,19 @@ def is_valid_cidr(string_network): :rtype: bool """ if string_network.count("/") == 1: @@ -133,7 +135,7 @@ index 1ae77d68ff..6a026e2d32 100644 return False else: return False -@@ -785,12 +842,12 @@ def get_proxy(key): +@@ -790,12 +847,12 @@ def should_bypass_proxies(url, no_proxy): # the end of the hostname, both with and without the port. no_proxy = (host for host in no_proxy.replace(" ", "").split(",") if host) @@ -149,10 +151,10 @@ index 1ae77d68ff..6a026e2d32 100644 # matches the IP of the index return True diff --git a/tests/test_utils.py b/tests/test_utils.py -index 8988eaf69c..44a3b790d2 100644 +index 5e9b56e..befbb46 100644 --- a/tests/test_utils.py +++ b/tests/test_utils.py -@@ -14,9 +14,11 @@ +@@ -14,9 +14,11 @@ from requests._internal_utils import unicode_is_ascii from requests.cookies import RequestsCookieJar from requests.structures import CaseInsensitiveDict from requests.utils import ( @@ -164,7 +166,7 @@ index 8988eaf69c..44a3b790d2 100644 dotted_netmask, extract_zipped_paths, get_auth_from_url, -@@ -263,8 +265,15 @@ def test_invalid(self, value): +@@ -263,8 +265,15 @@ class TestIsIPv4Address: class TestIsValidCIDR: @@ -182,7 +184,7 @@ index 8988eaf69c..44a3b790d2 100644 @pytest.mark.parametrize( "value", -@@ -274,6 +283,11 @@ def test_valid(self): +@@ -274,6 +283,11 @@ class TestIsValidCIDR: "192.168.1.0/128", "192.168.1.0/-1", "192.168.1.999/24", @@ -194,7 +196,7 @@ index 8988eaf69c..44a3b790d2 100644 ), ) def test_invalid(self, value): -@@ -287,6 +301,12 @@ def test_valid(self): +@@ -287,6 +301,12 @@ class TestAddressInNetwork: def test_invalid(self): assert not address_in_network("172.16.0.1", "192.168.1.0/24") @@ -233,10 +235,10 @@ index 8988eaf69c..44a3b790d2 100644 ) assert should_bypass_proxies(url, no_proxy=None) == expected -@@ -924,3 +949,36 @@ def test_set_environ_raises_exception(): - raise Exception("Expected exception") - - assert "Expected exception" in str(exception.value) +@@ -956,3 +981,36 @@ def test_should_bypass_proxies_win_registry_ProxyOverride_value(monkeypatch): + monkeypatch.setattr(winreg, "OpenKey", OpenKey) + monkeypatch.setattr(winreg, "QueryValueEx", QueryValueEx) + assert should_bypass_proxies("http://example.com/", None) is False + + +@pytest.mark.parametrize( @@ -270,3 +272,6 @@ index 8988eaf69c..44a3b790d2 100644 +) +def test_compare_ips(a, b, expected): + assert compare_ips(a, b) == expected +-- +2.45.1 + diff --git a/system-certs.patch b/system-certs.patch index 0e323f8..efc0010 100644 --- a/system-certs.patch +++ b/system-certs.patch @@ -1,36 +1,17 @@ -From fbe9d1e38da72d8caac365841794b06614523ac9 Mon Sep 17 00:00:00 2001 +From bb733473e91e71b812ada46bc110f607630f9327 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tom=C3=A1=C5=A1=20Hrn=C4=8Diar?= -Date: Tue, 17 Oct 2023 10:44:42 +0200 -Subject: [PATCH] system certs +Date: Thu, 30 May 2024 11:10:29 +0200 +Subject: [PATCH 1/2] system certs Co-authored-by: Lumir Balhar --- - requests/certs.py | 7 ++++++- - setup.cfg | 1 - - setup.py | 1 - - 3 files changed, 6 insertions(+), 3 deletions(-) + setup.cfg | 1 - + setup.py | 1 - + src/requests/certs.py | 8 +++++++- + 3 files changed, 7 insertions(+), 3 deletions(-) -diff --git a/requests/certs.py b/requests/certs.py -index 1f30a45..9224f62 100644 ---- a/requests/certs.py -+++ b/requests/certs.py -@@ -9,8 +9,13 @@ only one — the one from the certifi package. - If you are packaging Requests, e.g., for a Linux distribution or a managed - environment, you can change the definition of where() to return a separately - packaged CA bundle. -+ -+This Fedora-patched package returns "/etc/pki/tls/certs/ca-bundle.crt" provided -+by the ca-certificates RPM package. - """ --from certifi import where -+def where(): -+ """Return the absolute path to the system CA bundle.""" -+ return '/etc/pki/tls/certs/ca-bundle.crt' - - if __name__ == "__main__": - print(where()) diff --git a/setup.cfg b/setup.cfg -index bf21c81..906c0f1 100644 +index 8d44e0e..fa10a53 100644 --- a/setup.cfg +++ b/setup.cfg @@ -4,7 +4,6 @@ provides-extra = @@ -40,9 +21,9 @@ index bf21c81..906c0f1 100644 - certifi>=2017.4.17 charset_normalizer>=2,<4 idna>=2.5,<4 - urllib3>=1.21.1,<1.27 + urllib3>=1.21.1,<3 diff --git a/setup.py b/setup.py -index 0123545..ec3fd1d 100755 +index 1b0eb37..03d19b0 100755 --- a/setup.py +++ b/setup.py @@ -62,7 +62,6 @@ requires = [ @@ -53,6 +34,26 @@ index 0123545..ec3fd1d 100755 ] test_requirements = [ "pytest-httpbin==2.0.0", +diff --git a/src/requests/certs.py b/src/requests/certs.py +index be422c3..9aee713 100644 +--- a/src/requests/certs.py ++++ b/src/requests/certs.py +@@ -10,8 +10,14 @@ only one — the one from the certifi package. + If you are packaging Requests, e.g., for a Linux distribution or a managed + environment, you can change the definition of where() to return a separately + packaged CA bundle. ++ ++This Fedora-patched package returns "/etc/pki/tls/certs/ca-bundle.crt" provided ++by the ca-certificates RPM package. + """ +-from certifi import where ++ ++def where(): ++ """Return the absolute path to the system CA bundle.""" ++ return '/etc/pki/tls/certs/ca-bundle.crt' + + if __name__ == "__main__": + print(where()) -- -2.41.0 +2.45.1