Compare commits

...
Sign in to create a new pull request.

6 commits

Author SHA1 Message Date
Jeremy Cline
2b1ec09a17
Update to v2.20.0
This fixes CVE-2018-18074.
2018-10-29 15:15:37 -04:00
Miro Hrončok
ededecf749
Remove useless shebang 2018-10-29 15:14:05 -04:00
Miro Hrončok
54d18926d3
General cleanup of the specfile
- python_sitelib was defined but never used
 - _with_python3 was True, so I removed the ifs
 - python3_pkgversion is defined on both Fedora and EPEL
 - %{py3dir} is deprecated and not needed here
 - use %pyX_build and %pyX_install macros, stop using %{__python}
 - run tests against the installed version
 - some cruft removal
2018-10-29 15:14:04 -04:00
Miro Hrončok
2e79d755e6
BR idna, or the tests fail 2018-10-29 15:14:04 -04:00
Miro Hrončok
db93b6ba25
Conditionalize the tests, useful when bootstrapping Python 2018-10-29 15:14:04 -04:00
Jeremy Cline
3f626829ac
Don't inject pyopenssl into urllib3 (rhbz 1567862)
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2018-04-16 11:34:42 -04:00
6 changed files with 86 additions and 95 deletions

3
.gitignore vendored
View file

@ -37,3 +37,6 @@
/requests-v2.18.1.tar.gz /requests-v2.18.1.tar.gz
/requests-v2.18.2.tar.gz /requests-v2.18.2.tar.gz
/requests-v2.18.4.tar.gz /requests-v2.18.4.tar.gz
/requests-v2.19.0.tar.gz
/requests-v2.19.1.tar.gz
/requests-v2.20.0.tar.gz

View file

@ -0,0 +1,38 @@
From 86b1fa39fdebdb7bc57131c1a198d4d18e104f95 Mon Sep 17 00:00:00 2001
From: Jeremy Cline <jeremy@jcline.org>
Date: Mon, 16 Apr 2018 10:35:35 -0400
Subject: [PATCH] Don't inject pyopenssl into urllib3
Fedora ships sufficiently new versions of Python 2 and 3 to make this
unnecessary (rhbz 1567862)
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
---
requests/__init__.py | 7 -------
1 file changed, 7 deletions(-)
diff --git a/requests/__init__.py b/requests/__init__.py
index a5b3c9c3..e312d314 100644
--- a/requests/__init__.py
+++ b/requests/__init__.py
@@ -90,17 +90,6 @@ except (AssertionError, ValueError):
"version!".format(urllib3.__version__, chardet.__version__),
RequestsDependencyWarning)
-# Attempt to enable urllib3's SNI support, if possible
-try:
- from urllib3.contrib import pyopenssl
- pyopenssl.inject_into_urllib3()
-
- # Check cryptography version
- from cryptography import __version__ as cryptography_version
- _check_cryptography(cryptography_version)
-except ImportError:
- pass
-
# urllib3's DependencyWarnings should be silenced.
from urllib3.exceptions import DependencyWarning
warnings.simplefilter('ignore', DependencyWarning)
--
2.17.0

View file

@ -1,29 +0,0 @@
From 75f027ac8bc55ad280f7bf72a25db1ce8c1fc76d Mon Sep 17 00:00:00 2001
From: Jeremy Cline <jeremy@jcline.org>
Date: Mon, 19 Jun 2017 16:19:53 -0400
Subject: [PATCH] Don't import OrderedDict from urllib3
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
---
requests/compat.py | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/requests/compat.py b/requests/compat.py
index 5c09ea8..61fa0c8 100644
--- a/requests/compat.py
+++ b/requests/compat.py
@@ -46,7 +46,10 @@ if is_py2:
from Cookie import Morsel
from StringIO import StringIO
- from urllib3.packages.ordered_dict import OrderedDict
+ try:
+ from collections import OrderedDict # py2.7+
+ except:
+ from ordereddict import OrderedDict # py2.6 and lower (el6, etc.
builtin_str = str
bytes = str
--
2.9.4

View file

@ -1,4 +1,4 @@
From fd9ab446d8479360d2c1c8252508d97d58ed3e0e Mon Sep 17 00:00:00 2001 From a8ef690988f92a56226f8b688f1a3638346bca8e Mon Sep 17 00:00:00 2001
From: Jeremy Cline <jeremy@jcline.org> From: Jeremy Cline <jeremy@jcline.org>
Date: Mon, 19 Jun 2017 16:09:02 -0400 Date: Mon, 19 Jun 2017 16:09:02 -0400
Subject: [PATCH] Patch requests/certs.py to use the system CA bundle Subject: [PATCH] Patch requests/certs.py to use the system CA bundle
@ -10,7 +10,7 @@ Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2 files changed, 10 insertions(+), 2 deletions(-) 2 files changed, 10 insertions(+), 2 deletions(-)
diff --git a/requests/certs.py b/requests/certs.py diff --git a/requests/certs.py b/requests/certs.py
index d1a378d..7b103ba 100644 index d1a378d7..7b103baf 100644
--- a/requests/certs.py --- a/requests/certs.py
+++ b/requests/certs.py +++ b/requests/certs.py
@@ -11,8 +11,17 @@ only one — the one from the certifi package. @@ -11,8 +11,17 @@ only one — the one from the certifi package.
@ -33,17 +33,17 @@ index d1a378d..7b103ba 100644
if __name__ == '__main__': if __name__ == '__main__':
print(where()) print(where())
diff --git a/setup.py b/setup.py diff --git a/setup.py b/setup.py
index 93a8507..2db9569 100755 index 4e2ad936..60de5861 100755
--- a/setup.py --- a/setup.py
+++ b/setup.py +++ b/setup.py
@@ -45,7 +45,6 @@ requires = [ @@ -45,7 +45,6 @@ requires = [
'chardet>=3.0.2,<3.1.0', 'chardet>=3.0.2,<3.1.0',
'idna>=2.5,<2.7', 'idna>=2.5,<2.8',
'urllib3>=1.21.1,<1.23', 'urllib3>=1.21.1,<1.25',
- 'certifi>=2017.4.17' - 'certifi>=2017.4.17'
] ]
test_requirements = ['pytest-httpbin==0.0.7', 'pytest-cov', 'pytest-mock', 'pytest-xdist', 'PySocks>=1.5.6, !=1.5.7', 'pytest>=2.8.0'] test_requirements = [
-- --
2.9.4 2.19.1

View file

@ -1,14 +1,15 @@
%global _with_python3 1 %if 0%{?_module_build}
%{!?python_sitelib: %global python_sitelib %(%{__python} -c "from distutils.sysconfig import get_python_lib; print (get_python_lib())")} # Don't run tests on module-build for now
# See: https://bugzilla.redhat.com/show_bug.cgi?id=1450608
%if 0%{?fedora} %bcond_with tests
%{!?python3_pkgversion: %global python3_pkgversion 3}
%else %else
%{!?python3_pkgversion: %global python3_pkgversion 34} # When bootstrapping Python, we cannot test this yet
%bcond_without tests
%endif %endif
Name: python-requests Name: python-requests
Version: 2.18.4 Version: 2.20.0
Release: 1%{?dist} Release: 1%{?dist}
Summary: HTTP library, written in Python, for human beings Summary: HTTP library, written in Python, for human beings
@ -19,14 +20,6 @@ Source0: https://github.com/requests/requests/archive/v%{version}/request
# https://bugzilla.redhat.com/show_bug.cgi?id=904614 # https://bugzilla.redhat.com/show_bug.cgi?id=904614
Patch0: patch-requests-certs.py-to-use-the-system-CA-bundle.patch Patch0: patch-requests-certs.py-to-use-the-system-CA-bundle.patch
# Remove an unnecessary reference to a bundled compat lib in urllib3
# Some discussion with upstream:
# - https://twitter.com/sigmavirus24/status/529816751651819520
# - https://github.com/kennethreitz/requests/issues/1811
# - https://github.com/kennethreitz/requests/pull/1812
Patch1: dont-import-OrderedDict-from-urllib3.patch
# https://bugzilla.redhat.com/show_bug.cgi?id=1450608 # https://bugzilla.redhat.com/show_bug.cgi?id=1450608
Patch2: Remove-tests-that-use-the-tarpit.patch Patch2: Remove-tests-that-use-the-tarpit.patch
@ -37,6 +30,9 @@ Patch2: Remove-tests-that-use-the-tarpit.patch
# a pretty odd one so this is a niche requirement. # a pretty odd one so this is a niche requirement.
Patch3: requests-2.12.4-tests_nonet.patch Patch3: requests-2.12.4-tests_nonet.patch
# https://bugzilla.redhat.com/show_bug.cgi?id=1567862
Patch4: Don-t-inject-pyopenssl-into-urllib3.patch
BuildArch: noarch BuildArch: noarch
%description %description
@ -52,11 +48,13 @@ Summary: HTTP library, written in Python, for human beings
BuildRequires: python2-devel BuildRequires: python2-devel
BuildRequires: python-chardet BuildRequires: python-chardet
BuildRequires: python2-urllib3 BuildRequires: python2-urllib3
# For tests BuildRequires: python2-idna
%if %{with tests}
BuildRequires: python2-pytest BuildRequires: python2-pytest
BuildRequires: python2-pytest-cov BuildRequires: python2-pytest-cov
BuildRequires: python2-pytest-httpbin BuildRequires: python2-pytest-httpbin
BuildRequires: python2-pytest-mock BuildRequires: python2-pytest-mock
%endif
Requires: ca-certificates Requires: ca-certificates
@ -75,7 +73,6 @@ cumbersome. Pythons built-in urllib2 module provides most of the HTTP
capabilities you should need, but the API is thoroughly broken. This library is capabilities you should need, but the API is thoroughly broken. This library is
designed to make HTTP requests easy for developers. designed to make HTTP requests easy for developers.
%if 0%{?_with_python3}
%package -n python%{python3_pkgversion}-requests %package -n python%{python3_pkgversion}-requests
Summary: HTTP library, written in Python, for human beings Summary: HTTP library, written in Python, for human beings
@ -84,11 +81,13 @@ Summary: HTTP library, written in Python, for human beings
BuildRequires: python%{python3_pkgversion}-devel BuildRequires: python%{python3_pkgversion}-devel
BuildRequires: python%{python3_pkgversion}-chardet BuildRequires: python%{python3_pkgversion}-chardet
BuildRequires: python%{python3_pkgversion}-urllib3 BuildRequires: python%{python3_pkgversion}-urllib3
# For tests BuildRequires: python%{python3_pkgversion}-idna
%if %{with tests}
BuildRequires: python%{python3_pkgversion}-pytest BuildRequires: python%{python3_pkgversion}-pytest
BuildRequires: python%{python3_pkgversion}-pytest-cov BuildRequires: python%{python3_pkgversion}-pytest-cov
BuildRequires: python%{python3_pkgversion}-pytest-httpbin BuildRequires: python%{python3_pkgversion}-pytest-httpbin
BuildRequires: python%{python3_pkgversion}-pytest-mock BuildRequires: python%{python3_pkgversion}-pytest-mock
%endif
Requires: python%{python3_pkgversion}-chardet Requires: python%{python3_pkgversion}-chardet
Requires: python%{python3_pkgversion}-urllib3 Requires: python%{python3_pkgversion}-urllib3
@ -99,7 +98,6 @@ Most existing Python modules for sending HTTP requests are extremely verbose and
cumbersome. Pythons built-in urllib2 module provides most of the HTTP cumbersome. Pythons built-in urllib2 module provides most of the HTTP
capabilities you should need, but the API is thoroughly broken. This library is capabilities you should need, but the API is thoroughly broken. This library is
designed to make HTTP requests easy for developers. designed to make HTTP requests easy for developers.
%endif
%prep %prep
%autosetup -p1 -n requests-%{version} %autosetup -p1 -n requests-%{version}
@ -107,65 +105,46 @@ designed to make HTTP requests easy for developers.
# Unbundle the certificate bundle from mozilla. # Unbundle the certificate bundle from mozilla.
rm -rf requests/cacert.pem rm -rf requests/cacert.pem
%if 0%{?_with_python3} # env shebang in nonexecutable file
rm -rf %{py3dir} sed -i '/#!\/usr\/.*python/d' requests/certs.py
cp -a . %{py3dir}
%endif # with_python3
%build %build
%if 0%{?_with_python3} %py2_build
pushd %{py3dir} %py3_build
%{__python3} setup.py build
popd
%endif
%{__python} setup.py build
%install %install
rm -rf $RPM_BUILD_ROOT %py2_install
%if 0%{?_with_python3} %py3_install
pushd %{py3dir}
%{__python3} setup.py install --skip-build --root $RPM_BUILD_ROOT
popd
%endif
%{__python} setup.py install --skip-build --root $RPM_BUILD_ROOT
%if %{with tests}
%check %check
PYTHONPATH=%{buildroot}%{python2_sitelib} %{__python2} -m pytest -v
%if ! 0%{?_module_build} PYTHONPATH=%{buildroot}%{python3_sitelib} %{__python3} -m pytest -v
# Don't run tests on module-build for now %endif # tests
# See: https://bugzilla.redhat.com/show_bug.cgi?id=1450608
PYTHONPATH=./ py.test
%if 0%{?_with_python3}
pushd %{py3dir}
PYTHONPATH=./ py.test-%{python3_pkgversion}
popd
%endif
%endif #_module_build
%files -n python2-requests %files -n python2-requests
%defattr(-,root,root,-)
%{!?_licensedir:%global license %%doc}
%license LICENSE %license LICENSE
%doc README.rst HISTORY.rst %doc README.md HISTORY.md
%{python2_sitelib}/*.egg-info %{python2_sitelib}/*.egg-info
%dir %{python2_sitelib}/requests %{python2_sitelib}/requests/
%{python2_sitelib}/requests/*
%if 0%{?_with_python3}
%files -n python%{python3_pkgversion}-requests %files -n python%{python3_pkgversion}-requests
%{!?_licensedir:%global license %%doc}
%license LICENSE %license LICENSE
%doc README.rst HISTORY.rst %doc README.md HISTORY.md
%{python3_sitelib}/*.egg-info %{python3_sitelib}/*.egg-info
%{python3_sitelib}/requests/ %{python3_sitelib}/requests/
%endif
%changelog %changelog
* Mon Oct 29 2018 Jeremy Cline <jeremy@jcline.org> - 2.20.0-1
- Update to v2.20.0
* Mon Apr 16 2018 Jeremy Cline <jeremy@jcline.org> - 2.18.4-2
- Stop injecting PyOpenSSL (rhbz 1567862)
* Fri Aug 18 2017 Jeremy Cline <jeremy@jcline.org> - 2.18.4-1 * Fri Aug 18 2017 Jeremy Cline <jeremy@jcline.org> - 2.18.4-1
- Update to 2.18.4 - Update to 2.18.4

View file

@ -1 +1 @@
SHA512 (requests-v2.18.4.tar.gz) = 8ca20fe18d13b8c62977be0c51617f2ae8618d3d002ad4dc554362828855db7359274efbff0cd13e8c5699508913e91205cffcf306221a70321e74ac10b2d4d7 SHA512 (requests-v2.20.0.tar.gz) = 766c69d1778e7286232fcd750842e89cd9bb6637076e80fe95fb67f3ccb14049bf74a533de91ef9451ac6f397ad0a6d148eb444009f501178138cdeffc5ee7c4