From d2a365c76df34210b9c3b2cf0650fc0138f9e00c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tom=C3=A1=C5=A1=20Hrn=C4=8Diar?= Date: Thu, 7 Oct 2021 07:30:41 +0200 Subject: [PATCH 01/26] Enable test_frozentable test_frozentable was disabled due to error in Python 3.10.0a6. This is now fixed so test can be enabled again. --- python3.10.spec | 2 -- 1 file changed, 2 deletions(-) diff --git a/python3.10.spec b/python3.10.spec index 8f3be9b..d6f23d7 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -1058,10 +1058,8 @@ CheckPython() { # test_distutils # distutils.tests.test_bdist_rpm tests fail when bootstraping the Python # package: rpmbuild requires /usr/bin/pythonX.Y to be installed - # test_frozentable fails with Python 3.10.0a6 (https://bugs.python.org/issue43372) LD_LIBRARY_PATH=$ConfDir $ConfDir/python -m test.regrtest \ -wW --slowest -j0 --timeout=1800 \ - -i test_frozentable \ %if %{with bootstrap} -x test_distutils \ %endif From 0cd2202156d5406d58d8fb8352f29441dc6e0f61 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Mon, 11 Oct 2021 13:13:50 +0200 Subject: [PATCH 02/26] Cosmetic CI config change: Use the new tox package name --- tests/tests.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tests/tests.yml b/tests/tests.yml index 4819891..0da8e38 100644 --- a/tests/tests.yml +++ b/tests/tests.yml @@ -44,7 +44,7 @@ - python3-devel # for extension building in venv and selftest - python3-tkinter # for selftest - python3-test # for selftest - - python3-tox # for venv tests + - tox # for venv tests - glibc-all-langpacks # for locale tests - marshalparser # for testing compatibility (magic numbers) with marshalparser - rpm # for debugging From dd94826d724d3fdb90d0ffc35e8760cb3be30fd0 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Mon, 11 Oct 2021 13:14:41 +0200 Subject: [PATCH 03/26] Fedora CI: Also test virtualenv --- tests/tests.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/tests/tests.yml b/tests/tests.yml index 0da8e38..c2f2df4 100644 --- a/tests/tests.yml +++ b/tests/tests.yml @@ -21,6 +21,9 @@ - smoke: dir: python/smoke run: VERSION=3.10 ./venv.sh + - smoke_virtualenv: + dir: python/smoke + run: VERSION=3.10 METHOD=virtualenv ./venv.sh - debugsmoke: dir: python/smoke run: PYTHON=python3-debug TOX=false VERSION=3.10 ./venv.sh @@ -45,6 +48,7 @@ - python3-tkinter # for selftest - python3-test # for selftest - tox # for venv tests + - virtualenv # for virtualenv tests - glibc-all-langpacks # for locale tests - marshalparser # for testing compatibility (magic numbers) with marshalparser - rpm # for debugging From f7c55a4f2fe162602e0a04c4e7af772e458e5280 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tom=C3=A1=C5=A1=20Hrn=C4=8Diar?= Date: Tue, 7 Dec 2021 16:03:14 +0100 Subject: [PATCH 04/26] Update to 3.10.1 --- 00001-rpath.patch | 2 +- 00328-pyc-timestamp-invalidation-mode.patch | 2 +- ...or-the-main-thread-gh-28549-gh-28589.patch | 103 ++++++++++++++++++ python3.10.spec | 20 +++- sources | 4 +- 5 files changed, 124 insertions(+), 7 deletions(-) create mode 100644 00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch diff --git a/00001-rpath.patch b/00001-rpath.patch index 170908e..778c077 100644 --- a/00001-rpath.patch +++ b/00001-rpath.patch @@ -9,7 +9,7 @@ Subject: [PATCH] 00001: Fixup distutils/unixccompiler.py to remove standard 1 file changed, 9 insertions(+) diff --git a/Lib/distutils/unixccompiler.py b/Lib/distutils/unixccompiler.py -index f0792de74a..4d837936c6 100644 +index d00c48981e..0283a28c19 100644 --- a/Lib/distutils/unixccompiler.py +++ b/Lib/distutils/unixccompiler.py @@ -82,6 +82,15 @@ class UnixCCompiler(CCompiler): diff --git a/00328-pyc-timestamp-invalidation-mode.patch b/00328-pyc-timestamp-invalidation-mode.patch index 138868e..26f09f2 100644 --- a/00328-pyc-timestamp-invalidation-mode.patch +++ b/00328-pyc-timestamp-invalidation-mode.patch @@ -19,7 +19,7 @@ Ideally, we should talk to upstream and explain why we don't want this 2 files changed, 4 insertions(+), 1 deletion(-) diff --git a/Lib/py_compile.py b/Lib/py_compile.py -index 0f9b59025c..59dc3fe50b 100644 +index 388614e51b..db52725016 100644 --- a/Lib/py_compile.py +++ b/Lib/py_compile.py @@ -70,7 +70,8 @@ class PycInvalidationMode(enum.Enum): diff --git a/00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch b/00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch new file mode 100644 index 0000000..5c814ef --- /dev/null +++ b/00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch @@ -0,0 +1,103 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Tom=C3=A1=C5=A1=20Hrn=C4=8Diar?= +Date: Tue, 7 Dec 2021 14:41:59 +0100 +Subject: [PATCH] 00371: Revert "bpo-1596321: Fix threading._shutdown() for the + main thread (GH-28549) (GH-28589)" + +This reverts commit 38c67738c64304928c68d5c2bd78bbb01d979b94. It +introduced regression causing FreeIPA's tests to fail. + +For more info see: +https://bodhi.fedoraproject.org/updates/FEDORA-2021-e152ce5f31 +https://github.com/GrahamDumpleton/mod_wsgi/issues/730 +--- + Lib/test/test_threading.py | 33 --------------------------------- + Lib/threading.py | 25 ++++++++----------------- + 2 files changed, 8 insertions(+), 50 deletions(-) + +diff --git a/Lib/test/test_threading.py b/Lib/test/test_threading.py +index c54806e594..c51de6f4b8 100644 +--- a/Lib/test/test_threading.py ++++ b/Lib/test/test_threading.py +@@ -928,39 +928,6 @@ def test_debug_deprecation(self): + b'is deprecated and will be removed in Python 3.12') + self.assertIn(msg, err) + +- def test_import_from_another_thread(self): +- # bpo-1596321: If the threading module is first import from a thread +- # different than the main thread, threading._shutdown() must handle +- # this case without logging an error at Python exit. +- code = textwrap.dedent(''' +- import _thread +- import sys +- +- event = _thread.allocate_lock() +- event.acquire() +- +- def import_threading(): +- import threading +- event.release() +- +- if 'threading' in sys.modules: +- raise Exception('threading is already imported') +- +- _thread.start_new_thread(import_threading, ()) +- +- # wait until the threading module is imported +- event.acquire() +- event.release() +- +- if 'threading' not in sys.modules: +- raise Exception('threading is not imported') +- +- # don't wait until the thread completes +- ''') +- rc, out, err = assert_python_ok("-c", code) +- self.assertEqual(out, b'') +- self.assertEqual(err, b'') +- + + class ThreadJoinOnShutdown(BaseTestCase): + +diff --git a/Lib/threading.py b/Lib/threading.py +index 2d89742913..928b3f715d 100644 +--- a/Lib/threading.py ++++ b/Lib/threading.py +@@ -1523,29 +1523,20 @@ def _shutdown(): + + global _SHUTTING_DOWN + _SHUTTING_DOWN = True ++ # Main thread ++ tlock = _main_thread._tstate_lock ++ # The main thread isn't finished yet, so its thread state lock can't have ++ # been released. ++ assert tlock is not None ++ assert tlock.locked() ++ tlock.release() ++ _main_thread._stop() + + # Call registered threading atexit functions before threads are joined. + # Order is reversed, similar to atexit. + for atexit_call in reversed(_threading_atexits): + atexit_call() + +- # Main thread +- if _main_thread.ident == get_ident(): +- tlock = _main_thread._tstate_lock +- # The main thread isn't finished yet, so its thread state lock can't +- # have been released. +- assert tlock is not None +- assert tlock.locked() +- tlock.release() +- _main_thread._stop() +- else: +- # bpo-1596321: _shutdown() must be called in the main thread. +- # If the threading module was not imported by the main thread, +- # _main_thread is the thread which imported the threading module. +- # In this case, ignore _main_thread, similar behavior than for threads +- # spawned by C libraries or using _thread.start_new_thread(). +- pass +- + # Join all non-deamon threads + while True: + with _shutdown_locks_lock: diff --git a/python3.10.spec b/python3.10.spec index d6f23d7..3127ab1 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -13,7 +13,7 @@ URL: https://www.python.org/ # WARNING When rebasing to a new Python version, # remember to update the python3-docs package as well -%global general_version %{pybasever}.0 +%global general_version %{pybasever}.1 #global prerel ... %global upstream_version %{general_version}%{?prerel} Version: %{general_version}%{?prerel:~%{prerel}} @@ -68,8 +68,8 @@ License: Python # If the rpmwheels condition is disabled, we use the bundled wheel packages # from Python with the versions below. # This needs to be manually updated when we update Python. -%global pip_version 21.2.3 -%global setuptools_version 57.4.0 +%global pip_version 21.2.4 +%global setuptools_version 58.1.0 # Expensive optimizations (mainly, profile-guided optimizations) %bcond_without optimizations @@ -292,6 +292,17 @@ Patch251: 00251-change-user-install-location.patch # Ideally, we should talk to upstream and explain why we don't want this Patch328: 00328-pyc-timestamp-invalidation-mode.patch +# 00371 # c1754d9c2750f89cb702e1b63a99201f5f7cff00 +# Revert "bpo-1596321: Fix threading._shutdown() for the main thread (GH-28549) (GH-28589)" +# +# This reverts commit 38c67738c64304928c68d5c2bd78bbb01d979b94. It +# introduced regression causing FreeIPA's tests to fail. +# +# For more info see: +# https://bodhi.fedoraproject.org/updates/FEDORA-2021-e152ce5f31 +# https://github.com/GrahamDumpleton/mod_wsgi/issues/730 +Patch371: 00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch + # (New patches go here ^^^) # # When adding new patches to "python" and "python3" in Fedora, EL, etc., @@ -1581,6 +1592,9 @@ CheckPython optimized # ====================================================== %changelog +* Tue Dec 07 2021 Tomáš Hrnčiar - 3.10.1-1 +- Update to 3.10.1 + * Mon Oct 04 2021 Miro Hrončok - 3.10.0-1 - Update to 3.10.0 final diff --git a/sources b/sources index 29a970b..41d82f2 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (Python-3.10.0.tar.xz) = 82b2729afc7d72a80882f199970667dce7d971a2e5ecfe6cf84f7b68612ab2caf6ed6d7a8cb81f24ea85cb0816464bb2e8b2e6884eda62fa40742edc674193bd -SHA512 (Python-3.10.0.tar.xz.asc) = 67236e02bc49da1423717cb54216b745f613ba2fc4b372a4aa15a36ab15fe69d9b9087070382957d480df7576d13056caedcd979fb56531799a1190b822f673d +SHA512 (Python-3.10.1.tar.xz) = 1c559e33f1252e51bafb941c380de16f142c0735858363c84cb8dbed6767843de3af126889c2826ffb94bd4777d7cdfc31040301c8c74de56af52b80b1aa9e76 +SHA512 (Python-3.10.1.tar.xz.asc) = 645d5f40e6e80a590923a48763f20dea7da3f3eea5825bb79e08618d81d1b8eee0ddee2b57503321a584280536e0671e4913e5ad450568fbbb44509c01d3907d From b7b2fa452df1028f9eefd656a9a9f3f9a2835cd6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Fri, 12 Nov 2021 12:31:26 +0100 Subject: [PATCH 05/26] Fedora < 36 only: Instruct pip to use distutils Fixes https://bugzilla.redhat.com/show_bug.cgi?id=2014513 --- 00251-change-user-install-location.patch | 29 ++++++++++++++++++++++-- python3.10.spec | 14 +++++++++--- 2 files changed, 38 insertions(+), 5 deletions(-) diff --git a/00251-change-user-install-location.patch b/00251-change-user-install-location.patch index e9ea32d..53392e6 100644 --- a/00251-change-user-install-location.patch +++ b/00251-change-user-install-location.patch @@ -2,17 +2,27 @@ From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 From: Michal Cyprian Date: Mon, 26 Jun 2017 16:32:56 +0200 Subject: [PATCH] 00251: Change user install location +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit Set values of prefix and exec_prefix in distutils install command to /usr/local if executable is /usr/bin/python* and RPM build is not detected to make pip and distutils install into separate location. Fedora Change: https://fedoraproject.org/wiki/Changes/Making_sudo_pip_safe -Downstream only: Awaiting resources to work on upstream PEP +Downstream only: Reworked in Fedora 36+ to follow https://bugs.python.org/issue43976 + +Also set sysconfig._PIP_USE_SYSCONFIG = False, to force pip-upgraded-pip +to respect this patched distutils install command. +See https://bugzilla.redhat.com/show_bug.cgi?id=2014513 + +Co-authored-by: Miro Hrončok --- Lib/distutils/command/install.py | 15 +++++++++++++-- Lib/site.py | 9 ++++++++- - 2 files changed, 21 insertions(+), 3 deletions(-) + Lib/sysconfig.py | 4 ++++ + 3 files changed, 25 insertions(+), 3 deletions(-) diff --git a/Lib/distutils/command/install.py b/Lib/distutils/command/install.py index 26696cfb9d..1826cbcb38 100644 @@ -61,3 +71,18 @@ index 939893eb5e..d1316c3355 100644 for sitedir in getsitepackages(prefixes): if os.path.isdir(sitedir): addsitedir(sitedir, known_paths) +diff --git a/Lib/sysconfig.py b/Lib/sysconfig.py +index 95b48f6429..f78b374748 100644 +--- a/Lib/sysconfig.py ++++ b/Lib/sysconfig.py +@@ -58,6 +58,10 @@ + }, + } + ++# Force pip to use distutils paths instead of sysconfig ++# https://github.com/pypa/pip/issues/10647 ++_PIP_USE_SYSCONFIG = False ++ + + # NOTE: site.py has copy of this function. + # Sync it when modify this function. diff --git a/python3.10.spec b/python3.10.spec index 3127ab1..7bf3f4a 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -17,7 +17,7 @@ URL: https://www.python.org/ #global prerel ... %global upstream_version %{general_version}%{?prerel} Version: %{general_version}%{?prerel:~%{prerel}} -Release: 1%{?dist} +Release: 2%{?dist} License: Python @@ -267,7 +267,7 @@ Source11: idle3.appdata.xml # Was Patch0 in ivazquez' python3000 specfile Patch1: 00001-rpath.patch -# 00251 # 5c445123f04d96be42a35eef5119378ba1713a96 +# 00251 # f9b6509e62a9b05c96470903cb0280760c443e29 # Change user install location # # Set values of prefix and exec_prefix in distutils install command @@ -275,7 +275,11 @@ Patch1: 00001-rpath.patch # is not detected to make pip and distutils install into separate location. # # Fedora Change: https://fedoraproject.org/wiki/Changes/Making_sudo_pip_safe -# Downstream only: Awaiting resources to work on upstream PEP +# Downstream only: Reworked in Fedora 36+ to follow https://bugs.python.org/issue43976 +# +# Also set sysconfig._PIP_USE_SYSCONFIG = False, to force pip-upgraded-pip +# to respect this patched distutils install command. +# See https://bugzilla.redhat.com/show_bug.cgi?id=2014513 Patch251: 00251-change-user-install-location.patch # 00328 # 318e500c98f5e59eb1f23e0fcd32db69b9bd17e1 @@ -1592,6 +1596,10 @@ CheckPython optimized # ====================================================== %changelog +* Thu Dec 09 2021 Miro Hrončok - 3.10.1-2 +- Instruct pip to use distutils +- Fixes rhbz#2014513 + * Tue Dec 07 2021 Tomáš Hrnčiar - 3.10.1-1 - Update to 3.10.1 From 7c6eb17d2b20375b2a896eb9254feb30cba8ec95 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Wed, 24 Nov 2021 13:27:08 +0100 Subject: [PATCH 06/26] Instruct pypa/distutils to add /local/ addition to prefix --- 00251-change-user-install-location.patch | 54 +++++++++++++++--------- python3.10.spec | 5 ++- 2 files changed, 38 insertions(+), 21 deletions(-) diff --git a/00251-change-user-install-location.patch b/00251-change-user-install-location.patch index 53392e6..efa2461 100644 --- a/00251-change-user-install-location.patch +++ b/00251-change-user-install-location.patch @@ -13,40 +13,42 @@ is not detected to make pip and distutils install into separate location. Fedora Change: https://fedoraproject.org/wiki/Changes/Making_sudo_pip_safe Downstream only: Reworked in Fedora 36+ to follow https://bugs.python.org/issue43976 +pypa/distutils integration: https://github.com/pypa/distutils/pull/70 + Also set sysconfig._PIP_USE_SYSCONFIG = False, to force pip-upgraded-pip to respect this patched distutils install command. See https://bugzilla.redhat.com/show_bug.cgi?id=2014513 Co-authored-by: Miro Hrončok --- - Lib/distutils/command/install.py | 15 +++++++++++++-- + Lib/distutils/command/install.py | 8 ++++++-- Lib/site.py | 9 ++++++++- - Lib/sysconfig.py | 4 ++++ - 3 files changed, 25 insertions(+), 3 deletions(-) + Lib/sysconfig.py | 16 ++++++++++++++++ + 3 files changed, 30 insertions(+), 3 deletions(-) diff --git a/Lib/distutils/command/install.py b/Lib/distutils/command/install.py -index 26696cfb9d..1826cbcb38 100644 +index 01d5331a63..79f70f0de4 100644 --- a/Lib/distutils/command/install.py +++ b/Lib/distutils/command/install.py -@@ -441,8 +441,19 @@ def finalize_unix(self): +@@ -159,6 +159,8 @@ class install(Command): + + negative_opt = {'no-compile' : 'compile'} + ++ # Allow Fedora to add components to the prefix ++ _prefix_addition = getattr(sysconfig, '_prefix_addition', '') + + def initialize_options(self): + """Initializes options.""" +@@ -441,8 +443,10 @@ def finalize_unix(self): raise DistutilsOptionError( "must not supply exec-prefix without prefix") - self.prefix = os.path.normpath(sys.prefix) - self.exec_prefix = os.path.normpath(sys.exec_prefix) -+ # self.prefix is set to sys.prefix + /local/ -+ # if neither RPM build nor virtual environment is -+ # detected to make pip and distutils install packages -+ # into the separate location. -+ if (not (hasattr(sys, 'real_prefix') or -+ sys.prefix != sys.base_prefix) and -+ 'RPM_BUILD_ROOT' not in os.environ): -+ addition = "/local" -+ else: -+ addition = "" -+ -+ self.prefix = os.path.normpath(sys.prefix) + addition -+ self.exec_prefix = os.path.normpath(sys.exec_prefix) + addition ++ self.prefix = ( ++ os.path.normpath(sys.prefix) + self._prefix_addition) ++ self.exec_prefix = ( ++ os.path.normpath(sys.exec_prefix) + self._prefix_addition) else: if self.exec_prefix is None: @@ -72,16 +74,28 @@ index 939893eb5e..d1316c3355 100644 if os.path.isdir(sitedir): addsitedir(sitedir, known_paths) diff --git a/Lib/sysconfig.py b/Lib/sysconfig.py -index 95b48f6429..f78b374748 100644 +index daf9f00006..b88f9a9de0 100644 --- a/Lib/sysconfig.py +++ b/Lib/sysconfig.py -@@ -58,6 +58,10 @@ +@@ -58,6 +58,22 @@ }, } +# Force pip to use distutils paths instead of sysconfig +# https://github.com/pypa/pip/issues/10647 +_PIP_USE_SYSCONFIG = False ++ ++# This is used by distutils.command.install in the stdlib ++# as well as pypa/distutils (e.g. bundled in setuptools). ++# The self.prefix value is set to sys.prefix + /local/ ++# if neither RPM build nor virtual environment is ++# detected to make distutils install packages ++# into the separate location. ++# https://fedoraproject.org/wiki/Changes/Making_sudo_pip_safe ++if (not (hasattr(sys, 'real_prefix') or ++ sys.prefix != sys.base_prefix) and ++ 'RPM_BUILD_ROOT' not in os.environ): ++ _prefix_addition = "/local" + # NOTE: site.py has copy of this function. diff --git a/python3.10.spec b/python3.10.spec index 7bf3f4a..e98fecf 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -267,7 +267,7 @@ Source11: idle3.appdata.xml # Was Patch0 in ivazquez' python3000 specfile Patch1: 00001-rpath.patch -# 00251 # f9b6509e62a9b05c96470903cb0280760c443e29 +# 00251 # 08a62456431df182dfad18ad75838f769aca2d08 # Change user install location # # Set values of prefix and exec_prefix in distutils install command @@ -277,6 +277,8 @@ Patch1: 00001-rpath.patch # Fedora Change: https://fedoraproject.org/wiki/Changes/Making_sudo_pip_safe # Downstream only: Reworked in Fedora 36+ to follow https://bugs.python.org/issue43976 # +# pypa/distutils integration: https://github.com/pypa/distutils/pull/70 +# # Also set sysconfig._PIP_USE_SYSCONFIG = False, to force pip-upgraded-pip # to respect this patched distutils install command. # See https://bugzilla.redhat.com/show_bug.cgi?id=2014513 @@ -1598,6 +1600,7 @@ CheckPython optimized %changelog * Thu Dec 09 2021 Miro Hrončok - 3.10.1-2 - Instruct pip to use distutils +- Instruct pypa/distutils to add /local/ addition to prefix - Fixes rhbz#2014513 * Tue Dec 07 2021 Tomáš Hrnčiar - 3.10.1-1 From 2b285dee4e1c745450c738665c164916c50ca4c6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Mon, 10 Jan 2022 15:22:28 +0100 Subject: [PATCH 07/26] Backport fixes for two Python 3.10.1 regressions Fixes https://bugzilla.redhat.com/2030621 Fixes https://bugzilla.redhat.com/2034962 --- ...521-per-interpreter-interned-strings.patch | 302 ++++++++++++++++++ ...070-fix-asyncio-initialisation-guard.patch | 60 ++++ python3.10.spec | 35 +- 3 files changed, 396 insertions(+), 1 deletion(-) create mode 100644 00373-bpo-46006-revert-bpo-40521-per-interpreter-interned-strings.patch create mode 100644 00374-bpo-46070-fix-asyncio-initialisation-guard.patch diff --git a/00373-bpo-46006-revert-bpo-40521-per-interpreter-interned-strings.patch b/00373-bpo-46006-revert-bpo-40521-per-interpreter-interned-strings.patch new file mode 100644 index 0000000..fac1cf8 --- /dev/null +++ b/00373-bpo-46006-revert-bpo-40521-per-interpreter-interned-strings.patch @@ -0,0 +1,302 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Victor Stinner +Date: Thu, 6 Jan 2022 16:12:28 +0100 +Subject: [PATCH] 00373: bpo-46006: Revert "bpo-40521: Per-interpreter interned + strings + +This reverts commit ea251806b8dffff11b30d2182af1e589caf88acf. + +Keep "assert(interned == NULL);" in _PyUnicode_Fini(), but only for +the main interpreter. + +Keep _PyUnicode_ClearInterned() changes avoiding the creation of a +temporary Python list object. + +Leave the PyInterpreterState structure unchanged to keep the ABI +backward compatibility with Python 3.10.0: rename the "interned" +member to "unused_interned". + +Fixes https://bugzilla.redhat.com/2030621 +--- + Include/internal/pycore_interp.h | 12 +--- + .../2022-01-05-17-13-47.bpo-46006.hdH5Vn.rst | 5 ++ + Objects/typeobject.c | 22 +++++++ + Objects/unicodeobject.c | 63 ++++++++++++++----- + 4 files changed, 76 insertions(+), 26 deletions(-) + create mode 100644 Misc/NEWS.d/next/Core and Builtins/2022-01-05-17-13-47.bpo-46006.hdH5Vn.rst + +diff --git a/Include/internal/pycore_interp.h b/Include/internal/pycore_interp.h +index bfd082b588..4307b61ca3 100644 +--- a/Include/internal/pycore_interp.h ++++ b/Include/internal/pycore_interp.h +@@ -71,15 +71,9 @@ struct _Py_unicode_state { + PyObject *latin1[256]; + struct _Py_unicode_fs_codec fs_codec; + +- /* This dictionary holds all interned unicode strings. Note that references +- to strings in this dictionary are *not* counted in the string's ob_refcnt. +- When the interned string reaches a refcnt of 0 the string deallocation +- function will delete the reference from this dictionary. +- +- Another way to look at this is that to say that the actual reference +- count of a string is: s->ob_refcnt + (s->state ? 2 : 0) +- */ +- PyObject *interned; ++ // Unused member kept for ABI backward compatibility with Python 3.10.0: ++ // see bpo-46006. ++ PyObject *unused_interned; + + // Unicode identifiers (_Py_Identifier): see _PyUnicode_FromId() + struct _Py_unicode_ids ids; +diff --git a/Misc/NEWS.d/next/Core and Builtins/2022-01-05-17-13-47.bpo-46006.hdH5Vn.rst b/Misc/NEWS.d/next/Core and Builtins/2022-01-05-17-13-47.bpo-46006.hdH5Vn.rst +new file mode 100644 +index 0000000000..3acd2b0939 +--- /dev/null ++++ b/Misc/NEWS.d/next/Core and Builtins/2022-01-05-17-13-47.bpo-46006.hdH5Vn.rst +@@ -0,0 +1,5 @@ ++Fix a regression when a type method like ``__init__()`` is modified in a ++subinterpreter. Fix a regression in ``_PyUnicode_EqualToASCIIId()`` and type ++``update_slot()``. Revert the change which made the Unicode dictionary of ++interned strings compatible with subinterpreters: the internal interned ++dictionary is shared again by all interpreters. Patch by Victor Stinner. +diff --git a/Objects/typeobject.c b/Objects/typeobject.c +index 02046e5f2e..b23e36a420 100644 +--- a/Objects/typeobject.c ++++ b/Objects/typeobject.c +@@ -50,6 +50,11 @@ typedef struct PySlot_Offset { + } PySlot_Offset; + + ++/* bpo-40521: Interned strings are shared by all subinterpreters */ ++#ifndef EXPERIMENTAL_ISOLATED_SUBINTERPRETERS ++# define INTERN_NAME_STRINGS ++#endif ++ + /* alphabetical order */ + _Py_IDENTIFIER(__abstractmethods__); + _Py_IDENTIFIER(__annotations__); +@@ -3988,6 +3993,7 @@ type_setattro(PyTypeObject *type, PyObject *name, PyObject *value) + if (name == NULL) + return -1; + } ++#ifdef INTERN_NAME_STRINGS + if (!PyUnicode_CHECK_INTERNED(name)) { + PyUnicode_InternInPlace(&name); + if (!PyUnicode_CHECK_INTERNED(name)) { +@@ -3997,6 +4003,7 @@ type_setattro(PyTypeObject *type, PyObject *name, PyObject *value) + return -1; + } + } ++#endif + } + else { + /* Will fail in _PyObject_GenericSetAttrWithDict. */ +@@ -8344,10 +8351,17 @@ _PyTypes_InitSlotDefs(void) + for (slotdef *p = slotdefs; p->name; p++) { + /* Slots must be ordered by their offset in the PyHeapTypeObject. */ + assert(!p[1].name || p->offset <= p[1].offset); ++#ifdef INTERN_NAME_STRINGS + p->name_strobj = PyUnicode_InternFromString(p->name); + if (!p->name_strobj || !PyUnicode_CHECK_INTERNED(p->name_strobj)) { + return _PyStatus_NO_MEMORY(); + } ++#else ++ p->name_strobj = PyUnicode_FromString(p->name); ++ if (!p->name_strobj) { ++ return _PyStatus_NO_MEMORY(); ++ } ++#endif + } + slotdefs_initialized = 1; + return _PyStatus_OK(); +@@ -8372,16 +8386,24 @@ update_slot(PyTypeObject *type, PyObject *name) + int offset; + + assert(PyUnicode_CheckExact(name)); ++#ifdef INTERN_NAME_STRINGS + assert(PyUnicode_CHECK_INTERNED(name)); ++#endif + + assert(slotdefs_initialized); + pp = ptrs; + for (p = slotdefs; p->name; p++) { + assert(PyUnicode_CheckExact(p->name_strobj)); + assert(PyUnicode_CheckExact(name)); ++#ifdef INTERN_NAME_STRINGS + if (p->name_strobj == name) { + *pp++ = p; + } ++#else ++ if (p->name_strobj == name || _PyUnicode_EQ(p->name_strobj, name)) { ++ *pp++ = p; ++ } ++#endif + } + *pp = NULL; + for (pp = ptrs; *pp; pp++) { +diff --git a/Objects/unicodeobject.c b/Objects/unicodeobject.c +index c72871074b..077cf8d7f4 100644 +--- a/Objects/unicodeobject.c ++++ b/Objects/unicodeobject.c +@@ -211,6 +211,22 @@ extern "C" { + # define OVERALLOCATE_FACTOR 4 + #endif + ++/* bpo-40521: Interned strings are shared by all interpreters. */ ++#ifndef EXPERIMENTAL_ISOLATED_SUBINTERPRETERS ++# define INTERNED_STRINGS ++#endif ++ ++/* This dictionary holds all interned unicode strings. Note that references ++ to strings in this dictionary are *not* counted in the string's ob_refcnt. ++ When the interned string reaches a refcnt of 0 the string deallocation ++ function will delete the reference from this dictionary. ++ ++ Another way to look at this is that to say that the actual reference ++ count of a string is: s->ob_refcnt + (s->state ? 2 : 0) ++*/ ++#ifdef INTERNED_STRINGS ++static PyObject *interned = NULL; ++#endif + + static struct _Py_unicode_state* + get_unicode_state(void) +@@ -1936,7 +1952,7 @@ unicode_dealloc(PyObject *unicode) + + case SSTATE_INTERNED_MORTAL: + { +- struct _Py_unicode_state *state = get_unicode_state(); ++#ifdef INTERNED_STRINGS + /* Revive the dead object temporarily. PyDict_DelItem() removes two + references (key and value) which were ignored by + PyUnicode_InternInPlace(). Use refcnt=3 rather than refcnt=2 +@@ -1944,12 +1960,13 @@ unicode_dealloc(PyObject *unicode) + PyDict_DelItem(). */ + assert(Py_REFCNT(unicode) == 0); + Py_SET_REFCNT(unicode, 3); +- if (PyDict_DelItem(state->interned, unicode) != 0) { ++ if (PyDict_DelItem(interned, unicode) != 0) { + _PyErr_WriteUnraisableMsg("deletion of interned string failed", + NULL); + } + assert(Py_REFCNT(unicode) == 1); + Py_SET_REFCNT(unicode, 0); ++#endif + break; + } + +@@ -11600,11 +11617,13 @@ _PyUnicode_EqualToASCIIId(PyObject *left, _Py_Identifier *right) + if (PyUnicode_CHECK_INTERNED(left)) + return 0; + ++#ifdef INTERNED_STRINGS + assert(_PyUnicode_HASH(right_uni) != -1); + Py_hash_t hash = _PyUnicode_HASH(left); + if (hash != -1 && hash != _PyUnicode_HASH(right_uni)) { + return 0; + } ++#endif + + return unicode_compare_eq(left, right_uni); + } +@@ -15833,21 +15852,21 @@ PyUnicode_InternInPlace(PyObject **p) + return; + } + ++#ifdef INTERNED_STRINGS + if (PyUnicode_READY(s) == -1) { + PyErr_Clear(); + return; + } + +- struct _Py_unicode_state *state = get_unicode_state(); +- if (state->interned == NULL) { +- state->interned = PyDict_New(); +- if (state->interned == NULL) { ++ if (interned == NULL) { ++ interned = PyDict_New(); ++ if (interned == NULL) { + PyErr_Clear(); /* Don't leave an exception */ + return; + } + } + +- PyObject *t = PyDict_SetDefault(state->interned, s, s); ++ PyObject *t = PyDict_SetDefault(interned, s, s); + if (t == NULL) { + PyErr_Clear(); + return; +@@ -15864,9 +15883,13 @@ PyUnicode_InternInPlace(PyObject **p) + this. */ + Py_SET_REFCNT(s, Py_REFCNT(s) - 2); + _PyUnicode_STATE(s).interned = SSTATE_INTERNED_MORTAL; ++#else ++ // PyDict expects that interned strings have their hash ++ // (PyASCIIObject.hash) already computed. ++ (void)unicode_hash(s); ++#endif + } + +- + void + PyUnicode_InternImmortal(PyObject **p) + { +@@ -15900,11 +15923,15 @@ PyUnicode_InternFromString(const char *cp) + void + _PyUnicode_ClearInterned(PyInterpreterState *interp) + { +- struct _Py_unicode_state *state = &interp->unicode; +- if (state->interned == NULL) { ++ if (!_Py_IsMainInterpreter(interp)) { ++ // interned dict is shared by all interpreters + return; + } +- assert(PyDict_CheckExact(state->interned)); ++ ++ if (interned == NULL) { ++ return; ++ } ++ assert(PyDict_CheckExact(interned)); + + /* Interned unicode strings are not forcibly deallocated; rather, we give + them their stolen references back, and then clear and DECREF the +@@ -15912,13 +15939,13 @@ _PyUnicode_ClearInterned(PyInterpreterState *interp) + + #ifdef INTERNED_STATS + fprintf(stderr, "releasing %zd interned strings\n", +- PyDict_GET_SIZE(state->interned)); ++ PyDict_GET_SIZE(interned)); + + Py_ssize_t immortal_size = 0, mortal_size = 0; + #endif + Py_ssize_t pos = 0; + PyObject *s, *ignored_value; +- while (PyDict_Next(state->interned, &pos, &s, &ignored_value)) { ++ while (PyDict_Next(interned, &pos, &s, &ignored_value)) { + assert(PyUnicode_IS_READY(s)); + + switch (PyUnicode_CHECK_INTERNED(s)) { +@@ -15949,8 +15976,8 @@ _PyUnicode_ClearInterned(PyInterpreterState *interp) + mortal_size, immortal_size); + #endif + +- PyDict_Clear(state->interned); +- Py_CLEAR(state->interned); ++ PyDict_Clear(interned); ++ Py_CLEAR(interned); + } + + +@@ -16322,8 +16349,10 @@ _PyUnicode_Fini(PyInterpreterState *interp) + { + struct _Py_unicode_state *state = &interp->unicode; + +- // _PyUnicode_ClearInterned() must be called before +- assert(state->interned == NULL); ++ if (_Py_IsMainInterpreter(interp)) { ++ // _PyUnicode_ClearInterned() must be called before _PyUnicode_Fini() ++ assert(interned == NULL); ++ } + + _PyUnicode_FiniEncodings(&state->fs_codec); + diff --git a/00374-bpo-46070-fix-asyncio-initialisation-guard.patch b/00374-bpo-46070-fix-asyncio-initialisation-guard.patch new file mode 100644 index 0000000..cc5b32f --- /dev/null +++ b/00374-bpo-46070-fix-asyncio-initialisation-guard.patch @@ -0,0 +1,60 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: "Miss Islington (bot)" + <31488909+miss-islington@users.noreply.github.com> +Date: Fri, 7 Jan 2022 06:35:15 -0800 +Subject: [PATCH] 00374: bpo-46070: Fix asyncio initialisation guard + +If init flag is set, exit successfully immediately. +If not, only set the flag after successful initialization. +(cherry picked from commit b127e70a8a682fe869c22ce04c379bd85a00db67) + +Co-authored-by: Erlend Egeberg Aasland + +Fixes https://bugzilla.redhat.com/2034962 +--- + .../Library/2022-01-07-13-51-22.bpo-46070.-axLUW.rst | 2 ++ + Modules/_asynciomodule.c | 10 ++++------ + 2 files changed, 6 insertions(+), 6 deletions(-) + create mode 100644 Misc/NEWS.d/next/Library/2022-01-07-13-51-22.bpo-46070.-axLUW.rst + +diff --git a/Misc/NEWS.d/next/Library/2022-01-07-13-51-22.bpo-46070.-axLUW.rst b/Misc/NEWS.d/next/Library/2022-01-07-13-51-22.bpo-46070.-axLUW.rst +new file mode 100644 +index 0000000000..0fedc9dfb8 +--- /dev/null ++++ b/Misc/NEWS.d/next/Library/2022-01-07-13-51-22.bpo-46070.-axLUW.rst +@@ -0,0 +1,2 @@ ++Fix possible segfault when importing the :mod:`asyncio` module from ++different sub-interpreters in parallel. Patch by Erlend E. Aasland. +diff --git a/Modules/_asynciomodule.c b/Modules/_asynciomodule.c +index 56079b0277..befec9a834 100644 +--- a/Modules/_asynciomodule.c ++++ b/Modules/_asynciomodule.c +@@ -3309,17 +3309,14 @@ static int + module_init(void) + { + PyObject *module = NULL; ++ if (module_initialized) { ++ return 0; ++ } + + asyncio_mod = PyImport_ImportModule("asyncio"); + if (asyncio_mod == NULL) { + goto fail; + } +- if (module_initialized != 0) { +- return 0; +- } +- else { +- module_initialized = 1; +- } + + current_tasks = PyDict_New(); + if (current_tasks == NULL) { +@@ -3380,6 +3377,7 @@ module_init(void) + goto fail; + } + ++ module_initialized = 1; + Py_DECREF(module); + return 0; + diff --git a/python3.10.spec b/python3.10.spec index e98fecf..86a9914 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -17,7 +17,7 @@ URL: https://www.python.org/ #global prerel ... %global upstream_version %{general_version}%{?prerel} Version: %{general_version}%{?prerel:~%{prerel}} -Release: 2%{?dist} +Release: 3%{?dist} License: Python @@ -309,6 +309,34 @@ Patch328: 00328-pyc-timestamp-invalidation-mode.patch # https://github.com/GrahamDumpleton/mod_wsgi/issues/730 Patch371: 00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch +# 00373 # 89f7a91bcd1c7227cb639667801e77de52f67b01 +# bpo-46006: Revert "bpo-40521: Per-interpreter interned strings +# +# This reverts commit ea251806b8dffff11b30d2182af1e589caf88acf. +# +# Keep "assert(interned == NULL);" in _PyUnicode_Fini(), but only for +# the main interpreter. +# +# Keep _PyUnicode_ClearInterned() changes avoiding the creation of a +# temporary Python list object. +# +# Leave the PyInterpreterState structure unchanged to keep the ABI +# backward compatibility with Python 3.10.0: rename the "interned" +# member to "unused_interned". +# +# Fixes https://bugzilla.redhat.com/2030621 +Patch373: 00373-bpo-46006-revert-bpo-40521-per-interpreter-interned-strings.patch + +# 00374 # 2e91fe5327e83ff8fb21d343b01babb611ae2027 +# bpo-46070: Fix asyncio initialisation guard +# +# If init flag is set, exit successfully immediately. +# If not, only set the flag after successful initialization. +# +# +# Fixes https://bugzilla.redhat.com/2034962 +Patch374: 00374-bpo-46070-fix-asyncio-initialisation-guard.patch + # (New patches go here ^^^) # # When adding new patches to "python" and "python3" in Fedora, EL, etc., @@ -1598,6 +1626,11 @@ CheckPython optimized # ====================================================== %changelog +* Mon Jan 10 2022 Miro Hrončok - 3.10.1-3 +- Backport fixes for two Python 3.10.1 regressions +- Fixes: rhbz#2030621 +- Fixes: rhbz#2034962 + * Thu Dec 09 2021 Miro Hrončok - 3.10.1-2 - Instruct pip to use distutils - Instruct pypa/distutils to add /local/ addition to prefix From 41c4f95a614052dc1996fc2063487325168d55fd Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tom=C3=A1=C5=A1=20Hrn=C4=8Diar?= Date: Mon, 17 Jan 2022 08:43:27 +0100 Subject: [PATCH 08/26] Update to 3.10.2 --- ...521-per-interpreter-interned-strings.patch | 302 ------------------ ...070-fix-asyncio-initialisation-guard.patch | 60 ---- python3.10.spec | 35 +- sources | 4 +- 4 files changed, 7 insertions(+), 394 deletions(-) delete mode 100644 00373-bpo-46006-revert-bpo-40521-per-interpreter-interned-strings.patch delete mode 100644 00374-bpo-46070-fix-asyncio-initialisation-guard.patch diff --git a/00373-bpo-46006-revert-bpo-40521-per-interpreter-interned-strings.patch b/00373-bpo-46006-revert-bpo-40521-per-interpreter-interned-strings.patch deleted file mode 100644 index fac1cf8..0000000 --- a/00373-bpo-46006-revert-bpo-40521-per-interpreter-interned-strings.patch +++ /dev/null @@ -1,302 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Victor Stinner -Date: Thu, 6 Jan 2022 16:12:28 +0100 -Subject: [PATCH] 00373: bpo-46006: Revert "bpo-40521: Per-interpreter interned - strings - -This reverts commit ea251806b8dffff11b30d2182af1e589caf88acf. - -Keep "assert(interned == NULL);" in _PyUnicode_Fini(), but only for -the main interpreter. - -Keep _PyUnicode_ClearInterned() changes avoiding the creation of a -temporary Python list object. - -Leave the PyInterpreterState structure unchanged to keep the ABI -backward compatibility with Python 3.10.0: rename the "interned" -member to "unused_interned". - -Fixes https://bugzilla.redhat.com/2030621 ---- - Include/internal/pycore_interp.h | 12 +--- - .../2022-01-05-17-13-47.bpo-46006.hdH5Vn.rst | 5 ++ - Objects/typeobject.c | 22 +++++++ - Objects/unicodeobject.c | 63 ++++++++++++++----- - 4 files changed, 76 insertions(+), 26 deletions(-) - create mode 100644 Misc/NEWS.d/next/Core and Builtins/2022-01-05-17-13-47.bpo-46006.hdH5Vn.rst - -diff --git a/Include/internal/pycore_interp.h b/Include/internal/pycore_interp.h -index bfd082b588..4307b61ca3 100644 ---- a/Include/internal/pycore_interp.h -+++ b/Include/internal/pycore_interp.h -@@ -71,15 +71,9 @@ struct _Py_unicode_state { - PyObject *latin1[256]; - struct _Py_unicode_fs_codec fs_codec; - -- /* This dictionary holds all interned unicode strings. Note that references -- to strings in this dictionary are *not* counted in the string's ob_refcnt. -- When the interned string reaches a refcnt of 0 the string deallocation -- function will delete the reference from this dictionary. -- -- Another way to look at this is that to say that the actual reference -- count of a string is: s->ob_refcnt + (s->state ? 2 : 0) -- */ -- PyObject *interned; -+ // Unused member kept for ABI backward compatibility with Python 3.10.0: -+ // see bpo-46006. -+ PyObject *unused_interned; - - // Unicode identifiers (_Py_Identifier): see _PyUnicode_FromId() - struct _Py_unicode_ids ids; -diff --git a/Misc/NEWS.d/next/Core and Builtins/2022-01-05-17-13-47.bpo-46006.hdH5Vn.rst b/Misc/NEWS.d/next/Core and Builtins/2022-01-05-17-13-47.bpo-46006.hdH5Vn.rst -new file mode 100644 -index 0000000000..3acd2b0939 ---- /dev/null -+++ b/Misc/NEWS.d/next/Core and Builtins/2022-01-05-17-13-47.bpo-46006.hdH5Vn.rst -@@ -0,0 +1,5 @@ -+Fix a regression when a type method like ``__init__()`` is modified in a -+subinterpreter. Fix a regression in ``_PyUnicode_EqualToASCIIId()`` and type -+``update_slot()``. Revert the change which made the Unicode dictionary of -+interned strings compatible with subinterpreters: the internal interned -+dictionary is shared again by all interpreters. Patch by Victor Stinner. -diff --git a/Objects/typeobject.c b/Objects/typeobject.c -index 02046e5f2e..b23e36a420 100644 ---- a/Objects/typeobject.c -+++ b/Objects/typeobject.c -@@ -50,6 +50,11 @@ typedef struct PySlot_Offset { - } PySlot_Offset; - - -+/* bpo-40521: Interned strings are shared by all subinterpreters */ -+#ifndef EXPERIMENTAL_ISOLATED_SUBINTERPRETERS -+# define INTERN_NAME_STRINGS -+#endif -+ - /* alphabetical order */ - _Py_IDENTIFIER(__abstractmethods__); - _Py_IDENTIFIER(__annotations__); -@@ -3988,6 +3993,7 @@ type_setattro(PyTypeObject *type, PyObject *name, PyObject *value) - if (name == NULL) - return -1; - } -+#ifdef INTERN_NAME_STRINGS - if (!PyUnicode_CHECK_INTERNED(name)) { - PyUnicode_InternInPlace(&name); - if (!PyUnicode_CHECK_INTERNED(name)) { -@@ -3997,6 +4003,7 @@ type_setattro(PyTypeObject *type, PyObject *name, PyObject *value) - return -1; - } - } -+#endif - } - else { - /* Will fail in _PyObject_GenericSetAttrWithDict. */ -@@ -8344,10 +8351,17 @@ _PyTypes_InitSlotDefs(void) - for (slotdef *p = slotdefs; p->name; p++) { - /* Slots must be ordered by their offset in the PyHeapTypeObject. */ - assert(!p[1].name || p->offset <= p[1].offset); -+#ifdef INTERN_NAME_STRINGS - p->name_strobj = PyUnicode_InternFromString(p->name); - if (!p->name_strobj || !PyUnicode_CHECK_INTERNED(p->name_strobj)) { - return _PyStatus_NO_MEMORY(); - } -+#else -+ p->name_strobj = PyUnicode_FromString(p->name); -+ if (!p->name_strobj) { -+ return _PyStatus_NO_MEMORY(); -+ } -+#endif - } - slotdefs_initialized = 1; - return _PyStatus_OK(); -@@ -8372,16 +8386,24 @@ update_slot(PyTypeObject *type, PyObject *name) - int offset; - - assert(PyUnicode_CheckExact(name)); -+#ifdef INTERN_NAME_STRINGS - assert(PyUnicode_CHECK_INTERNED(name)); -+#endif - - assert(slotdefs_initialized); - pp = ptrs; - for (p = slotdefs; p->name; p++) { - assert(PyUnicode_CheckExact(p->name_strobj)); - assert(PyUnicode_CheckExact(name)); -+#ifdef INTERN_NAME_STRINGS - if (p->name_strobj == name) { - *pp++ = p; - } -+#else -+ if (p->name_strobj == name || _PyUnicode_EQ(p->name_strobj, name)) { -+ *pp++ = p; -+ } -+#endif - } - *pp = NULL; - for (pp = ptrs; *pp; pp++) { -diff --git a/Objects/unicodeobject.c b/Objects/unicodeobject.c -index c72871074b..077cf8d7f4 100644 ---- a/Objects/unicodeobject.c -+++ b/Objects/unicodeobject.c -@@ -211,6 +211,22 @@ extern "C" { - # define OVERALLOCATE_FACTOR 4 - #endif - -+/* bpo-40521: Interned strings are shared by all interpreters. */ -+#ifndef EXPERIMENTAL_ISOLATED_SUBINTERPRETERS -+# define INTERNED_STRINGS -+#endif -+ -+/* This dictionary holds all interned unicode strings. Note that references -+ to strings in this dictionary are *not* counted in the string's ob_refcnt. -+ When the interned string reaches a refcnt of 0 the string deallocation -+ function will delete the reference from this dictionary. -+ -+ Another way to look at this is that to say that the actual reference -+ count of a string is: s->ob_refcnt + (s->state ? 2 : 0) -+*/ -+#ifdef INTERNED_STRINGS -+static PyObject *interned = NULL; -+#endif - - static struct _Py_unicode_state* - get_unicode_state(void) -@@ -1936,7 +1952,7 @@ unicode_dealloc(PyObject *unicode) - - case SSTATE_INTERNED_MORTAL: - { -- struct _Py_unicode_state *state = get_unicode_state(); -+#ifdef INTERNED_STRINGS - /* Revive the dead object temporarily. PyDict_DelItem() removes two - references (key and value) which were ignored by - PyUnicode_InternInPlace(). Use refcnt=3 rather than refcnt=2 -@@ -1944,12 +1960,13 @@ unicode_dealloc(PyObject *unicode) - PyDict_DelItem(). */ - assert(Py_REFCNT(unicode) == 0); - Py_SET_REFCNT(unicode, 3); -- if (PyDict_DelItem(state->interned, unicode) != 0) { -+ if (PyDict_DelItem(interned, unicode) != 0) { - _PyErr_WriteUnraisableMsg("deletion of interned string failed", - NULL); - } - assert(Py_REFCNT(unicode) == 1); - Py_SET_REFCNT(unicode, 0); -+#endif - break; - } - -@@ -11600,11 +11617,13 @@ _PyUnicode_EqualToASCIIId(PyObject *left, _Py_Identifier *right) - if (PyUnicode_CHECK_INTERNED(left)) - return 0; - -+#ifdef INTERNED_STRINGS - assert(_PyUnicode_HASH(right_uni) != -1); - Py_hash_t hash = _PyUnicode_HASH(left); - if (hash != -1 && hash != _PyUnicode_HASH(right_uni)) { - return 0; - } -+#endif - - return unicode_compare_eq(left, right_uni); - } -@@ -15833,21 +15852,21 @@ PyUnicode_InternInPlace(PyObject **p) - return; - } - -+#ifdef INTERNED_STRINGS - if (PyUnicode_READY(s) == -1) { - PyErr_Clear(); - return; - } - -- struct _Py_unicode_state *state = get_unicode_state(); -- if (state->interned == NULL) { -- state->interned = PyDict_New(); -- if (state->interned == NULL) { -+ if (interned == NULL) { -+ interned = PyDict_New(); -+ if (interned == NULL) { - PyErr_Clear(); /* Don't leave an exception */ - return; - } - } - -- PyObject *t = PyDict_SetDefault(state->interned, s, s); -+ PyObject *t = PyDict_SetDefault(interned, s, s); - if (t == NULL) { - PyErr_Clear(); - return; -@@ -15864,9 +15883,13 @@ PyUnicode_InternInPlace(PyObject **p) - this. */ - Py_SET_REFCNT(s, Py_REFCNT(s) - 2); - _PyUnicode_STATE(s).interned = SSTATE_INTERNED_MORTAL; -+#else -+ // PyDict expects that interned strings have their hash -+ // (PyASCIIObject.hash) already computed. -+ (void)unicode_hash(s); -+#endif - } - -- - void - PyUnicode_InternImmortal(PyObject **p) - { -@@ -15900,11 +15923,15 @@ PyUnicode_InternFromString(const char *cp) - void - _PyUnicode_ClearInterned(PyInterpreterState *interp) - { -- struct _Py_unicode_state *state = &interp->unicode; -- if (state->interned == NULL) { -+ if (!_Py_IsMainInterpreter(interp)) { -+ // interned dict is shared by all interpreters - return; - } -- assert(PyDict_CheckExact(state->interned)); -+ -+ if (interned == NULL) { -+ return; -+ } -+ assert(PyDict_CheckExact(interned)); - - /* Interned unicode strings are not forcibly deallocated; rather, we give - them their stolen references back, and then clear and DECREF the -@@ -15912,13 +15939,13 @@ _PyUnicode_ClearInterned(PyInterpreterState *interp) - - #ifdef INTERNED_STATS - fprintf(stderr, "releasing %zd interned strings\n", -- PyDict_GET_SIZE(state->interned)); -+ PyDict_GET_SIZE(interned)); - - Py_ssize_t immortal_size = 0, mortal_size = 0; - #endif - Py_ssize_t pos = 0; - PyObject *s, *ignored_value; -- while (PyDict_Next(state->interned, &pos, &s, &ignored_value)) { -+ while (PyDict_Next(interned, &pos, &s, &ignored_value)) { - assert(PyUnicode_IS_READY(s)); - - switch (PyUnicode_CHECK_INTERNED(s)) { -@@ -15949,8 +15976,8 @@ _PyUnicode_ClearInterned(PyInterpreterState *interp) - mortal_size, immortal_size); - #endif - -- PyDict_Clear(state->interned); -- Py_CLEAR(state->interned); -+ PyDict_Clear(interned); -+ Py_CLEAR(interned); - } - - -@@ -16322,8 +16349,10 @@ _PyUnicode_Fini(PyInterpreterState *interp) - { - struct _Py_unicode_state *state = &interp->unicode; - -- // _PyUnicode_ClearInterned() must be called before -- assert(state->interned == NULL); -+ if (_Py_IsMainInterpreter(interp)) { -+ // _PyUnicode_ClearInterned() must be called before _PyUnicode_Fini() -+ assert(interned == NULL); -+ } - - _PyUnicode_FiniEncodings(&state->fs_codec); - diff --git a/00374-bpo-46070-fix-asyncio-initialisation-guard.patch b/00374-bpo-46070-fix-asyncio-initialisation-guard.patch deleted file mode 100644 index cc5b32f..0000000 --- a/00374-bpo-46070-fix-asyncio-initialisation-guard.patch +++ /dev/null @@ -1,60 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: "Miss Islington (bot)" - <31488909+miss-islington@users.noreply.github.com> -Date: Fri, 7 Jan 2022 06:35:15 -0800 -Subject: [PATCH] 00374: bpo-46070: Fix asyncio initialisation guard - -If init flag is set, exit successfully immediately. -If not, only set the flag after successful initialization. -(cherry picked from commit b127e70a8a682fe869c22ce04c379bd85a00db67) - -Co-authored-by: Erlend Egeberg Aasland - -Fixes https://bugzilla.redhat.com/2034962 ---- - .../Library/2022-01-07-13-51-22.bpo-46070.-axLUW.rst | 2 ++ - Modules/_asynciomodule.c | 10 ++++------ - 2 files changed, 6 insertions(+), 6 deletions(-) - create mode 100644 Misc/NEWS.d/next/Library/2022-01-07-13-51-22.bpo-46070.-axLUW.rst - -diff --git a/Misc/NEWS.d/next/Library/2022-01-07-13-51-22.bpo-46070.-axLUW.rst b/Misc/NEWS.d/next/Library/2022-01-07-13-51-22.bpo-46070.-axLUW.rst -new file mode 100644 -index 0000000000..0fedc9dfb8 ---- /dev/null -+++ b/Misc/NEWS.d/next/Library/2022-01-07-13-51-22.bpo-46070.-axLUW.rst -@@ -0,0 +1,2 @@ -+Fix possible segfault when importing the :mod:`asyncio` module from -+different sub-interpreters in parallel. Patch by Erlend E. Aasland. -diff --git a/Modules/_asynciomodule.c b/Modules/_asynciomodule.c -index 56079b0277..befec9a834 100644 ---- a/Modules/_asynciomodule.c -+++ b/Modules/_asynciomodule.c -@@ -3309,17 +3309,14 @@ static int - module_init(void) - { - PyObject *module = NULL; -+ if (module_initialized) { -+ return 0; -+ } - - asyncio_mod = PyImport_ImportModule("asyncio"); - if (asyncio_mod == NULL) { - goto fail; - } -- if (module_initialized != 0) { -- return 0; -- } -- else { -- module_initialized = 1; -- } - - current_tasks = PyDict_New(); - if (current_tasks == NULL) { -@@ -3380,6 +3377,7 @@ module_init(void) - goto fail; - } - -+ module_initialized = 1; - Py_DECREF(module); - return 0; - diff --git a/python3.10.spec b/python3.10.spec index 86a9914..5234c7b 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -13,11 +13,11 @@ URL: https://www.python.org/ # WARNING When rebasing to a new Python version, # remember to update the python3-docs package as well -%global general_version %{pybasever}.1 +%global general_version %{pybasever}.2 #global prerel ... %global upstream_version %{general_version}%{?prerel} Version: %{general_version}%{?prerel:~%{prerel}} -Release: 3%{?dist} +Release: 1%{?dist} License: Python @@ -309,34 +309,6 @@ Patch328: 00328-pyc-timestamp-invalidation-mode.patch # https://github.com/GrahamDumpleton/mod_wsgi/issues/730 Patch371: 00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch -# 00373 # 89f7a91bcd1c7227cb639667801e77de52f67b01 -# bpo-46006: Revert "bpo-40521: Per-interpreter interned strings -# -# This reverts commit ea251806b8dffff11b30d2182af1e589caf88acf. -# -# Keep "assert(interned == NULL);" in _PyUnicode_Fini(), but only for -# the main interpreter. -# -# Keep _PyUnicode_ClearInterned() changes avoiding the creation of a -# temporary Python list object. -# -# Leave the PyInterpreterState structure unchanged to keep the ABI -# backward compatibility with Python 3.10.0: rename the "interned" -# member to "unused_interned". -# -# Fixes https://bugzilla.redhat.com/2030621 -Patch373: 00373-bpo-46006-revert-bpo-40521-per-interpreter-interned-strings.patch - -# 00374 # 2e91fe5327e83ff8fb21d343b01babb611ae2027 -# bpo-46070: Fix asyncio initialisation guard -# -# If init flag is set, exit successfully immediately. -# If not, only set the flag after successful initialization. -# -# -# Fixes https://bugzilla.redhat.com/2034962 -Patch374: 00374-bpo-46070-fix-asyncio-initialisation-guard.patch - # (New patches go here ^^^) # # When adding new patches to "python" and "python3" in Fedora, EL, etc., @@ -1626,6 +1598,9 @@ CheckPython optimized # ====================================================== %changelog +* Mon Jan 17 2022 Tomáš Hrnčiar - 3.10.2-1 +- Update to 3.10.2 + * Mon Jan 10 2022 Miro Hrončok - 3.10.1-3 - Backport fixes for two Python 3.10.1 regressions - Fixes: rhbz#2030621 diff --git a/sources b/sources index 41d82f2..93254c3 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (Python-3.10.1.tar.xz) = 1c559e33f1252e51bafb941c380de16f142c0735858363c84cb8dbed6767843de3af126889c2826ffb94bd4777d7cdfc31040301c8c74de56af52b80b1aa9e76 -SHA512 (Python-3.10.1.tar.xz.asc) = 645d5f40e6e80a590923a48763f20dea7da3f3eea5825bb79e08618d81d1b8eee0ddee2b57503321a584280536e0671e4913e5ad450568fbbb44509c01d3907d +SHA512 (Python-3.10.2.tar.xz) = 215a7159face84788fe547c1e2689b8d0ae510275157cf01636bef2902d0ff465f844eb0328c9f39fd1cd03a1d1736d4cf258992f2788e492a801a372032c08b +SHA512 (Python-3.10.2.tar.xz.asc) = 086aeaa999d3005cc1f9057d90230c7a9e65d80f436febf16b0e8ba6f49645870ef21170ca1af50c8e2f51e6f46338cfad73a2d91320ad4a3315a2ae87eb70b4 From bc7ab932a77ea5a4b082c1d704f8e6e70200087b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tom=C3=A1=C5=A1=20Hrn=C4=8Diar?= Date: Fri, 18 Mar 2022 08:54:06 +0100 Subject: [PATCH 09/26] Update to 3.10.3 --- python3.10.spec | 7 +++++-- sources | 4 ++-- 2 files changed, 7 insertions(+), 4 deletions(-) diff --git a/python3.10.spec b/python3.10.spec index 5234c7b..90ce23c 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -13,7 +13,7 @@ URL: https://www.python.org/ # WARNING When rebasing to a new Python version, # remember to update the python3-docs package as well -%global general_version %{pybasever}.2 +%global general_version %{pybasever}.3 #global prerel ... %global upstream_version %{general_version}%{?prerel} Version: %{general_version}%{?prerel:~%{prerel}} @@ -68,7 +68,7 @@ License: Python # If the rpmwheels condition is disabled, we use the bundled wheel packages # from Python with the versions below. # This needs to be manually updated when we update Python. -%global pip_version 21.2.4 +%global pip_version 22.0.4 %global setuptools_version 58.1.0 # Expensive optimizations (mainly, profile-guided optimizations) @@ -1598,6 +1598,9 @@ CheckPython optimized # ====================================================== %changelog +* Fri Mar 18 2022 Tomáš Hrnčiar - 3.10.3-1 +- Update to 3.10.3 + * Mon Jan 17 2022 Tomáš Hrnčiar - 3.10.2-1 - Update to 3.10.2 diff --git a/sources b/sources index 93254c3..b36c6bc 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (Python-3.10.2.tar.xz) = 215a7159face84788fe547c1e2689b8d0ae510275157cf01636bef2902d0ff465f844eb0328c9f39fd1cd03a1d1736d4cf258992f2788e492a801a372032c08b -SHA512 (Python-3.10.2.tar.xz.asc) = 086aeaa999d3005cc1f9057d90230c7a9e65d80f436febf16b0e8ba6f49645870ef21170ca1af50c8e2f51e6f46338cfad73a2d91320ad4a3315a2ae87eb70b4 +SHA512 (Python-3.10.3.tar.xz) = 5020407798ebaae6002b8de29475c1064a32f1527a0e4ec6fe7fcf076b4ea3ef0ab4b4a7864a6081cc8dd01dd545123198b11cc8dd1259c670394b7d81f35a86 +SHA512 (Python-3.10.3.tar.xz.asc) = ddbe55225fcdd5d36f6be4bb802ea8fb9c5e8cf1b573b76501cc0999bcbfb2355f5bf7bbe10bf7cb209e54f37ed0789b4b936920b208b2afc18597bab33f2f51 From dfe2d475a902bd1d436bce356a7f54ac2b6f6be0 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tom=C3=A1=C5=A1=20Hrn=C4=8Diar?= Date: Fri, 25 Mar 2022 08:18:30 +0100 Subject: [PATCH 10/26] Update to 3.10.4 --- python3.10.spec | 5 ++++- sources | 4 ++-- 2 files changed, 6 insertions(+), 3 deletions(-) diff --git a/python3.10.spec b/python3.10.spec index 90ce23c..9558721 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -13,7 +13,7 @@ URL: https://www.python.org/ # WARNING When rebasing to a new Python version, # remember to update the python3-docs package as well -%global general_version %{pybasever}.3 +%global general_version %{pybasever}.4 #global prerel ... %global upstream_version %{general_version}%{?prerel} Version: %{general_version}%{?prerel:~%{prerel}} @@ -1598,6 +1598,9 @@ CheckPython optimized # ====================================================== %changelog +* Fri Mar 25 2022 Tomáš Hrnčiar - 3.10.4-1 +- Update to 3.10.4 + * Fri Mar 18 2022 Tomáš Hrnčiar - 3.10.3-1 - Update to 3.10.3 diff --git a/sources b/sources index b36c6bc..46b98a4 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (Python-3.10.3.tar.xz) = 5020407798ebaae6002b8de29475c1064a32f1527a0e4ec6fe7fcf076b4ea3ef0ab4b4a7864a6081cc8dd01dd545123198b11cc8dd1259c670394b7d81f35a86 -SHA512 (Python-3.10.3.tar.xz.asc) = ddbe55225fcdd5d36f6be4bb802ea8fb9c5e8cf1b573b76501cc0999bcbfb2355f5bf7bbe10bf7cb209e54f37ed0789b4b936920b208b2afc18597bab33f2f51 +SHA512 (Python-3.10.4.tar.xz) = 6c9aeecddc55c7896b2e8527fca131c7b2b6127d56ce1a001ccedfebf590334e0c0bb7c517ed3cf1da3c1910e002552b56aa7e03eeb672f42ff0bd8150799113 +SHA512 (Python-3.10.4.tar.xz.asc) = 699e37bf09067083af159e3734b38c952bdc75432c8abfb7a7b8cce7ca975038da37490abeb5c13befd2dacb84a5341ad30de5d0a63d35af5c512215744f4d6d From 7a9076d0e10b7d2fe2bda9a7e7da202d5a016628 Mon Sep 17 00:00:00 2001 From: Tomas Orsava Date: Sat, 14 May 2022 08:44:32 +0000 Subject: [PATCH 11/26] Build Python 3.11 with subpackages (by disabling the flatpackage bcond) No change in not providing `python(abi)` for alternative Python versions Resolves: rhbz#2063227 --- python3.10.spec | 26 ++++++++++++++++---------- 1 file changed, 16 insertions(+), 10 deletions(-) diff --git a/python3.10.spec b/python3.10.spec index 9558721..caa1e8f 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -40,13 +40,10 @@ License: Python %endif # Flat package, i.e. no separate subpackages -# Default (in Fedora): if this is a main Python, it is not a flatpackage +# Default (in Fedora): don't use the flatpackage structure for Python 3.11 and +# higher, remove the bcond from the spec in the future # Not supported: Combination of flatpackage enabled and main_python enabled -%if %{with main_python} %bcond_with flatpackage -%else -%bcond_without flatpackage -%endif # When bootstrapping python3, we need to build setuptools. # but setuptools BR python3-devel and that brings in python3-rpm-generators; @@ -327,6 +324,13 @@ Patch371: 00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-g # Descriptions, and metadata for subpackages # ========================================== +%if %{without main_python} +# We'll not provide this, on purpose +# No package in Fedora shall ever depend on a alternative Python via this +%global __requires_exclude ^python\\(abi\\) = 3\\..+ +%global __provides_exclude ^python\\(abi\\) = 3\\..+ +%endif # without main_python + # this if branch is ~300 lines long and contains subpackages' definitions %if %{without flatpackage} %if %{with main_python} @@ -371,9 +375,11 @@ Recommends: %{_bindir}/python Provides: python%{pyshortver} = %{version}-%{release} Obsoletes: python%{pyshortver} < %{version}-%{release} +%if %{with main_python} # Packages with Python modules in standard locations automatically # depend on python(abi). Provide that here. Provides: python(abi) = %{pybasever} +%endif # with main_python Requires: %{pkgname}-libs%{?_isa} = %{version}-%{release} @@ -480,7 +486,10 @@ Requires: (python3-rpm-generators if rpm-build) %endif Provides: %{pkgname}-2to3 = %{version}-%{release} + +%if %{with main_python} Provides: 2to3 = %{version}-%{release} +%endif Conflicts: %{pkgname} < %{version}-%{release} @@ -498,8 +507,10 @@ Summary: A basic graphical development environment for Python Requires: %{pkgname} = %{version}-%{release} Requires: %{pkgname}-tkinter = %{version}-%{release} +%if %{with main_python} Provides: idle3 = %{version}-%{release} Provides: idle = %{version}-%{release} +%endif Provides: %{pkgname}-tools = %{version}-%{release} Provides: %{pkgname}-tools%{?_isa} = %{version}-%{release} @@ -577,11 +588,6 @@ The debug runtime additionally supports debug builds of C-API extensions %else # with flatpackage -# We'll not provide this, on purpose -# No package in Fedora shall ever depend on flatpackage via this -%global __requires_exclude ^python\\(abi\\) = 3\\..+ -%global __provides_exclude ^python\\(abi\\) = 3\\..+ - # Python interpreter packages used to be named (or provide) name pythonXY (e.g. # python39). However, to align it with the executable names and to prepare for # Python 3.10, they were renamed to pythonX.Y (e.g. python3.9, python3.10). We From a7b4c9c13d092007926e0eb1efa87bfaff74bb57 Mon Sep 17 00:00:00 2001 From: Tomas Orsava Date: Sat, 14 May 2022 08:46:32 +0000 Subject: [PATCH 12/26] Let there *not* be flatpackage Remove the flatpackage bcond entirely --- python3.10.spec | 91 ++++--------------------------------------------- 1 file changed, 7 insertions(+), 84 deletions(-) diff --git a/python3.10.spec b/python3.10.spec index caa1e8f..b9256c1 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -31,7 +31,6 @@ License: Python # Main Python, i.e. whether this is the main Python version in the distribution # that owns /usr/bin/python3 and other unique paths # This also means the built subpackages are called python3 rather than python3X -# WARNING: This also influences the flatpackage bcond below. # By default, this is determined by the %%__default_python3_pkgversion value %if "%{?__default_python3_pkgversion}" == "%{pybasever}" %bcond_without main_python @@ -39,12 +38,6 @@ License: Python %bcond_with main_python %endif -# Flat package, i.e. no separate subpackages -# Default (in Fedora): don't use the flatpackage structure for Python 3.11 and -# higher, remove the bcond from the spec in the future -# Not supported: Combination of flatpackage enabled and main_python enabled -%bcond_with flatpackage - # When bootstrapping python3, we need to build setuptools. # but setuptools BR python3-devel and that brings in python3-rpm-generators; # python3-rpm-generators needs python3-setuptools, so we cannot have it yet. @@ -76,11 +69,7 @@ License: Python # Extra build for debugging the interpreter or C-API extensions # (the -debug subpackages) -%if %{with flatpackage} -%bcond_with debug_build -%else %bcond_without debug_build -%endif # Support for the GDB debugger %bcond_without gdb_hooks @@ -324,15 +313,7 @@ Patch371: 00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-g # Descriptions, and metadata for subpackages # ========================================== -%if %{without main_python} -# We'll not provide this, on purpose -# No package in Fedora shall ever depend on a alternative Python via this -%global __requires_exclude ^python\\(abi\\) = 3\\..+ -%global __provides_exclude ^python\\(abi\\) = 3\\..+ -%endif # without main_python -# this if branch is ~300 lines long and contains subpackages' definitions -%if %{without flatpackage} %if %{with main_python} # Description for the python3X SRPM only: %description @@ -345,7 +326,7 @@ third-party libraries. Summary: Python %{pybasever} interpreter # In order to support multiple Python interpreters for development purposes, -# packages with the naming scheme flatpackage (e.g. python3.5) exist for +# packages with fully versioned naming scheme (e.g. python3.9*) exist for # non-default versions of Python 3. # For consistency, we provide python3.X from python3 as well. Provides: python%{pybasever} = %{version}-%{release} @@ -369,9 +350,6 @@ Recommends: %{_bindir}/python # python39). However, to align it with the executable names and to prepare for # Python 3.10, they were renamed to pythonX.Y (e.g. python3.9, python3.10). We # provide and obsolete the previous names. -# - Here are the tags for the nonflat package, regardless if main_python (e.g. -# python3) or not (e.g. python39). For the flat package, the provide is -# repeated many lines later. Provides: python%{pyshortver} = %{version}-%{release} Obsoletes: python%{pyshortver} < %{version}-%{release} @@ -379,7 +357,12 @@ Obsoletes: python%{pyshortver} < %{version}-%{release} # Packages with Python modules in standard locations automatically # depend on python(abi). Provide that here. Provides: python(abi) = %{pybasever} -%endif # with main_python +%else +# We'll not provide this, on purpose +# No package in Fedora shall ever depend on a alternative Python via this +%global __requires_exclude ^python\\(abi\\) = 3\\..+ +%global __provides_exclude ^python\\(abi\\) = 3\\..+ +%endif Requires: %{pkgname}-libs%{?_isa} = %{version}-%{release} @@ -586,39 +569,6 @@ The debug runtime additionally supports debug builds of C-API extensions (with the "d" ABI flag) for debugging issues in those extensions. %endif # with debug_build -%else # with flatpackage - -# Python interpreter packages used to be named (or provide) name pythonXY (e.g. -# python39). However, to align it with the executable names and to prepare for -# Python 3.10, they were renamed to pythonX.Y (e.g. python3.9, python3.10). We -# provide and obsolete the previous names. -# - Here are the tags for the flat package. For the nonflat package, the -# provide is repeated many lines above. -Provides: python%{pyshortver} = %{version}-%{release} -Obsoletes: python%{pyshortver} < %{version}-%{release} - -%if %{with rpmwheels} -Requires: python-setuptools-wheel -Requires: python-pip-wheel -%else -Provides: bundled(python3dist(pip)) = %{pip_version} -Provides: bundled(python3dist(setuptools)) = %{setuptools_version} -%endif - -# The zoneinfo module needs tzdata -Requires: tzdata - -# The description for the flat package (SRPM and built) -%description -Python %{pybasever} package for developers. - -This package exists to allow developers to test their code against a newer -version of Python. This is not a full Python stack and if you wish to run -your applications with Python %{pybasever}, update your Fedora to a newer -version once Python %{pybasever} is stable. - -%endif # with flatpackage - # ====================================================== # The prep phase of the build: # ====================================================== @@ -1121,17 +1071,13 @@ CheckPython optimized %if %{with main_python} -%if %{without flatpackage} %files -n python-unversioned-command -%endif %{_bindir}/python %{_mandir}/*/python.1* %endif -%if %{without flatpackage} %files -n %{pkgname}-libs %doc README.rst -%endif %dir %{pylibdir} %dir %{dynload_dir} @@ -1139,9 +1085,7 @@ CheckPython optimized %license %{pylibdir}/LICENSE.txt %{pylibdir}/lib2to3 -%if %{without flatpackage} %exclude %{pylibdir}/lib2to3/tests -%endif %dir %{pylibdir}/unittest/ %dir %{pylibdir}/unittest/__pycache__/ @@ -1328,10 +1272,8 @@ CheckPython optimized %{pylibdir}/sqlite3/*.py %{pylibdir}/sqlite3/__pycache__/*%{bytecode_suffixes} -%if %{without flatpackage} %exclude %{pylibdir}/turtle.py %exclude %{pylibdir}/__pycache__/turtle*%{bytecode_suffixes} -%endif %{pylibdir}/urllib %{pylibdir}/xml @@ -1357,15 +1299,10 @@ CheckPython optimized %endif -%if %{without flatpackage} %files -n %{pkgname}-devel -%endif - %{pylibdir}/config-%{LDVERSION_optimized}-%{platform_triplet}/* -%if %{without flatpackage} %exclude %{pylibdir}/config-%{LDVERSION_optimized}-%{platform_triplet}/Makefile %exclude %{_includedir}/python%{LDVERSION_optimized}/%{_pyconfig_h} -%endif %{_includedir}/python%{LDVERSION_optimized}/*.h %{_includedir}/python%{LDVERSION_optimized}/internal/ %{_includedir}/python%{LDVERSION_optimized}/cpython/ @@ -1400,10 +1337,7 @@ CheckPython optimized %{_libdir}/pkgconfig/python-%{pybasever}-embed.pc -%if %{without flatpackage} %files -n %{pkgname}-idle -%endif - %if %{with main_python} %{_bindir}/idle* %else @@ -1418,14 +1352,9 @@ CheckPython optimized %{_datadir}/icons/hicolor/*/apps/idle3.* %endif -%if %{without flatpackage} %files -n %{pkgname}-tkinter -%endif - %{pylibdir}/tkinter -%if %{without flatpackage} %exclude %{pylibdir}/tkinter/test -%endif %{dynload_dir}/_tkinter.%{SOABI_optimized}.so %{pylibdir}/turtle.py %{pylibdir}/__pycache__/turtle*%{bytecode_suffixes} @@ -1436,10 +1365,7 @@ CheckPython optimized %{pylibdir}/turtledemo/__pycache__/*%{bytecode_suffixes} -%if %{without flatpackage} %files -n %{pkgname}-test -%endif - %{pylibdir}/ctypes/test %{pylibdir}/distutils/tests %{pylibdir}/sqlite3/test @@ -1462,10 +1388,7 @@ CheckPython optimized # all of the other subpackages %if %{with debug_build} -%if %{without flatpackage} %files -n %{pkgname}-debug -%endif - %if %{with main_python} %{_bindir}/python3-debug %{_bindir}/python-debug From 3463fb44bfab38059044a279cd80e227b57e2bd8 Mon Sep 17 00:00:00 2001 From: Tomas Orsava Date: Sat, 14 May 2022 08:47:09 +0000 Subject: [PATCH 13/26] Obsolete python3.X-foo from individual subpackages e.g. python3-devel now Obsoletes python3.X-devel We are contemplating splitting alternative Pythons into subpackages, so we need to obsolete each of them from the main Python version. Related: rhbz#2063227 --- python3.10.spec | 34 ++++++++++++++++++++++++++++------ 1 file changed, 28 insertions(+), 6 deletions(-) diff --git a/python3.10.spec b/python3.10.spec index b9256c1..39d0109 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -152,6 +152,20 @@ License: Python %{warn:Doing a main_python build with wrong %%__default_python3_pkgversion (0%{?__default_python3_pkgversion}, but this is %pyshortver)} %endif +%if %{with main_python} +# To keep the upgrade path clean, we Obsolete python3.X from the python3 +# package and python3.X-foo from individual subpackages. +# Note that using Obsoletes without package version is not standard practice. +# Here we assert that *any* version of the system's default interpreter is +# preferable to an "extra" interpreter. For example, python3-3.6.1 will +# replace python3.6-3.6.2. +%define unversioned_obsoletes_of_python3_X_if_main() %{expand:\ +Obsoletes: python%{pybasever}%{?1:-%{1}}\ +} +%else +%define unversioned_obsoletes_of_python3_X_if_main() %{nil} +%endif + # ======================= # Build-time requirements # ======================= @@ -331,12 +345,8 @@ Summary: Python %{pybasever} interpreter # For consistency, we provide python3.X from python3 as well. Provides: python%{pybasever} = %{version}-%{release} Provides: python%{pybasever}%{?_isa} = %{version}-%{release} -# To keep the upgrade path clean, we Obsolete python3.X. -# Note that using Obsoletes without package version is not standard practice. -# Here we assert that *any* version of the system's default interpreter is -# preferable to an "extra" interpreter. For example, python3-3.6.1 will -# replace python3.6-3.6.2. -Obsoletes: python%{pybasever} + +%unversioned_obsoletes_of_python3_X_if_main # https://fedoraproject.org/wiki/Changes/Move_usr_bin_python_into_separate_package # https://fedoraproject.org/wiki/Changes/Python_means_Python3 @@ -429,6 +439,8 @@ Provides: bundled(python3dist(pip)) = %{pip_version} Provides: bundled(python3dist(setuptools)) = %{setuptools_version} %endif +%unversioned_obsoletes_of_python3_X_if_main libs + # There are files in the standard library that have python shebang. # We've filtered the automatic requirement out so libs are installable without # the main package. This however makes it pulled in by default. @@ -461,6 +473,8 @@ Requires: (python-rpm-macros if rpm-build) Requires: (python3-rpm-macros if rpm-build) Requires: (pyproject-rpm-macros if rpm-build) +%unversioned_obsoletes_of_python3_X_if_main devel + # Python developers are very likely to need pip Recommends: %{pkgname}-pip @@ -490,6 +504,8 @@ Summary: A basic graphical development environment for Python Requires: %{pkgname} = %{version}-%{release} Requires: %{pkgname}-tkinter = %{version}-%{release} +%unversioned_obsoletes_of_python3_X_if_main idle + %if %{with main_python} Provides: idle3 = %{version}-%{release} Provides: idle = %{version}-%{release} @@ -516,6 +532,8 @@ configuration, browsers, and other dialogs. Summary: A GUI toolkit for Python Requires: %{pkgname} = %{version}-%{release} +%unversioned_obsoletes_of_python3_X_if_main tkinter + # The importable module "turtle" is here, so provide python3-turtle. # (We don't provide python3-turtledemo, that's not too useful when imported.) %py_provides %{pkgname}-turtle @@ -530,6 +548,8 @@ Summary: The self-test suite for the main python3 package Requires: %{pkgname} = %{version}-%{release} Requires: %{pkgname}-libs%{?_isa} = %{version}-%{release} +%unversioned_obsoletes_of_python3_X_if_main test + %description -n %{pkgname}-test The self-test suite for the Python interpreter. @@ -552,6 +572,8 @@ Requires: %{pkgname}-test%{?_isa} = %{version}-%{release} Requires: %{pkgname}-tkinter%{?_isa} = %{version}-%{release} Requires: %{pkgname}-idle%{?_isa} = %{version}-%{release} +%unversioned_obsoletes_of_python3_X_if_main debug + %description -n %{pkgname}-debug python3-debug provides a version of the Python runtime with numerous debugging features enabled, aimed at advanced Python users such as developers of Python From 9aecf247bbd877274210c600090f245b063e4759 Mon Sep 17 00:00:00 2001 From: Tomas Orsava Date: Sat, 14 May 2022 08:47:09 +0000 Subject: [PATCH 14/26] Add new bcond for python_abi_provides_for_alt_pythons By default enabled on EL, disabled on Fedora --- python3.10.spec | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) diff --git a/python3.10.spec b/python3.10.spec index 39d0109..49be7b3 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -38,6 +38,15 @@ License: Python %bcond_with main_python %endif +# If this is *not* Main Python, should it contain `Provides: python(abi) ...`? +# In Fedora no package shall depend on an alternative Python via this tag, so we do not provide it. +# In ELN/RHEL/CentOS we want to allow building against alternative stacks, so the Provide is enabled. +%if 0%{?fedora} +%bcond_with python_abi_provides_for_alt_pythons +%else +%bcond_without python_abi_provides_for_alt_pythons +%endif + # When bootstrapping python3, we need to build setuptools. # but setuptools BR python3-devel and that brings in python3-rpm-generators; # python3-rpm-generators needs python3-setuptools, so we cannot have it yet. @@ -363,13 +372,12 @@ Recommends: %{_bindir}/python Provides: python%{pyshortver} = %{version}-%{release} Obsoletes: python%{pyshortver} < %{version}-%{release} -%if %{with main_python} +%if %{with main_python} || %{with python_abi_provides_for_alt_pythons} # Packages with Python modules in standard locations automatically # depend on python(abi). Provide that here. Provides: python(abi) = %{pybasever} %else -# We'll not provide this, on purpose -# No package in Fedora shall ever depend on a alternative Python via this +# We exclude the `python(abi)` Provides %global __requires_exclude ^python\\(abi\\) = 3\\..+ %global __provides_exclude ^python\\(abi\\) = 3\\..+ %endif From 68d22172370002bcf2a9c18cd659e680548bb403 Mon Sep 17 00:00:00 2001 From: Tomas Orsava Date: Sat, 14 May 2022 08:47:56 +0000 Subject: [PATCH 15/26] Do not Recommend python*-pip if this is not the main_python Because we do not ship pip for alternative stacks (outside of `venv`). --- python3.10.spec | 2 ++ 1 file changed, 2 insertions(+) diff --git a/python3.10.spec b/python3.10.spec index 49be7b3..7014f17 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -483,8 +483,10 @@ Requires: (pyproject-rpm-macros if rpm-build) %unversioned_obsoletes_of_python3_X_if_main devel +%if %{with main_python} # Python developers are very likely to need pip Recommends: %{pkgname}-pip +%endif %if %{without bootstrap} Requires: (python3-rpm-generators if rpm-build) From 6928c91eb9509db56b1cd300f28ee7a4257c4a86 Mon Sep 17 00:00:00 2001 From: Tomas Orsava Date: Sat, 14 May 2022 08:48:54 +0000 Subject: [PATCH 16/26] Remove an rpmlintrc rule that was only relevant to flatpackages --- python3.10.rpmlintrc | 3 --- 1 file changed, 3 deletions(-) diff --git a/python3.10.rpmlintrc b/python3.10.rpmlintrc index da5ed3f..5fc9c03 100644 --- a/python3.10.rpmlintrc +++ b/python3.10.rpmlintrc @@ -19,9 +19,6 @@ addFilter(r'self-obsoletion python3\.\d+ obsoletes python3\.\d+') # intentionally hardcoded addFilter(r'hardcoded-library-path in %{_prefix}/lib/(debug/%{_libdir}|python%{pybasever})') -# intentional for our pythonXY package -addFilter(r'python3\.\d+\.[^:]+: (E|W): devel-file-in-non-devel-package') - # we have non binary stuff, python files addFilter(r'only-non-binary-in-usr-lib') From ba94183739228783441f621a0495a35441f4cd0f Mon Sep 17 00:00:00 2001 From: Tomas Orsava Date: Sat, 14 May 2022 08:51:11 +0000 Subject: [PATCH 17/26] Move _sysconfigdata_d_linux*.py to the debug subpackage --- python3.10.spec | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/python3.10.spec b/python3.10.spec index 7014f17..89fa319 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -17,7 +17,7 @@ URL: https://www.python.org/ #global prerel ... %global upstream_version %{general_version}%{?prerel} Version: %{general_version}%{?prerel:~%{prerel}} -Release: 1%{?dist} +Release: 2%{?dist} License: Python @@ -1240,6 +1240,10 @@ CheckPython optimized %dir %{pylibdir}/site-packages/ %dir %{pylibdir}/site-packages/__pycache__/ %{pylibdir}/site-packages/README.txt + +%exclude %{pylibdir}/_sysconfigdata_d_linux_%{platform_triplet}.py +%exclude %{pylibdir}/__pycache__/_sysconfigdata_d_linux_%{platform_triplet}%{bytecode_suffixes} + %{pylibdir}/*.py %dir %{pylibdir}/__pycache__/ %{pylibdir}/__pycache__/*%{bytecode_suffixes} @@ -1536,6 +1540,9 @@ CheckPython optimized %{dynload_dir}/_testinternalcapi.%{SOABI_debug}.so %{dynload_dir}/_testmultiphase.%{SOABI_debug}.so +%{pylibdir}/_sysconfigdata_d_linux_%{platform_triplet}.py +%{pylibdir}/__pycache__/_sysconfigdata_d_linux_%{platform_triplet}%{bytecode_suffixes} + %endif # with debug_build # We put the debug-gdb.py file inside /usr/lib/debug to avoid noise from ldconfig @@ -1559,6 +1566,9 @@ CheckPython optimized # ====================================================== %changelog +* Sat May 14 2022 Tomas Orsava - 3.10.4-2 +- Move _sysconfigdata_d_linux*.py to the debug subpackage + * Fri Mar 25 2022 Tomáš Hrnčiar - 3.10.4-1 - Update to 3.10.4 From fd2542f9c35d7ed6c8b457e9a48bdada21b5b4b4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Tue, 31 May 2022 19:47:45 +0000 Subject: [PATCH 18/26] Don't exclude files that don't exist When built without debug_build, RPM warns: File not found: /builddir/build/BUILDROOT/python3.11-3.11.0~b2-1.fc37.x86_64/usr/lib64/python3.11/_sysconfigdata_d_linux_x86_64-linux-gnu.py File not found: /builddir/build/BUILDROOT/python3.11-3.11.0~b2-1.fc37.x86_64/usr/lib64/python3.11/__pycache__/_sysconfigdata_d_linux_x86_64-linux-gnu.cpython-311*.pyc This might become an error in some distant future. --- python3.10.spec | 2 ++ 1 file changed, 2 insertions(+) diff --git a/python3.10.spec b/python3.10.spec index 89fa319..1768248 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -1241,8 +1241,10 @@ CheckPython optimized %dir %{pylibdir}/site-packages/__pycache__/ %{pylibdir}/site-packages/README.txt +%if %{with debug_build} %exclude %{pylibdir}/_sysconfigdata_d_linux_%{platform_triplet}.py %exclude %{pylibdir}/__pycache__/_sysconfigdata_d_linux_%{platform_triplet}%{bytecode_suffixes} +%endif %{pylibdir}/*.py %dir %{pylibdir}/__pycache__/ From 5b70ab91fe8fd11db0fe718dc7a2e88ebff04e52 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Tue, 31 May 2022 19:47:45 +0000 Subject: [PATCH 19/26] Don't hardcode %{ABIFLAGS_debug} --- python3.10.spec | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/python3.10.spec b/python3.10.spec index 1768248..a957b43 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -1242,8 +1242,8 @@ CheckPython optimized %{pylibdir}/site-packages/README.txt %if %{with debug_build} -%exclude %{pylibdir}/_sysconfigdata_d_linux_%{platform_triplet}.py -%exclude %{pylibdir}/__pycache__/_sysconfigdata_d_linux_%{platform_triplet}%{bytecode_suffixes} +%exclude %{pylibdir}/_sysconfigdata_%{ABIFLAGS_debug}_linux_%{platform_triplet}.py +%exclude %{pylibdir}/__pycache__/_sysconfigdata_%{ABIFLAGS_debug}_linux_%{platform_triplet}%{bytecode_suffixes} %endif %{pylibdir}/*.py @@ -1542,8 +1542,8 @@ CheckPython optimized %{dynload_dir}/_testinternalcapi.%{SOABI_debug}.so %{dynload_dir}/_testmultiphase.%{SOABI_debug}.so -%{pylibdir}/_sysconfigdata_d_linux_%{platform_triplet}.py -%{pylibdir}/__pycache__/_sysconfigdata_d_linux_%{platform_triplet}%{bytecode_suffixes} +%{pylibdir}/_sysconfigdata_%{ABIFLAGS_debug}_linux_%{platform_triplet}.py +%{pylibdir}/__pycache__/_sysconfigdata_%{ABIFLAGS_debug}_linux_%{platform_triplet}%{bytecode_suffixes} %endif # with debug_build From 1cba7ca6d77368bae6f8379cb5fc76ffaf6add86 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tom=C3=A1=C5=A1=20Hrn=C4=8Diar?= Date: Tue, 7 Jun 2022 13:29:54 +0200 Subject: [PATCH 20/26] Update to 3.10.5 --- ...g-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch | 4 ++-- python3.10.spec | 7 +++++-- sources | 4 ++-- 3 files changed, 9 insertions(+), 6 deletions(-) diff --git a/00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch b/00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch index 5c814ef..aad6391 100644 --- a/00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch +++ b/00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch @@ -60,10 +60,10 @@ index c54806e594..c51de6f4b8 100644 class ThreadJoinOnShutdown(BaseTestCase): diff --git a/Lib/threading.py b/Lib/threading.py -index 2d89742913..928b3f715d 100644 +index 668126523d..3e14cca8be 100644 --- a/Lib/threading.py +++ b/Lib/threading.py -@@ -1523,29 +1523,20 @@ def _shutdown(): +@@ -1530,29 +1530,20 @@ def _shutdown(): global _SHUTTING_DOWN _SHUTTING_DOWN = True diff --git a/python3.10.spec b/python3.10.spec index a957b43..8112b24 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -13,11 +13,11 @@ URL: https://www.python.org/ # WARNING When rebasing to a new Python version, # remember to update the python3-docs package as well -%global general_version %{pybasever}.4 +%global general_version %{pybasever}.5 #global prerel ... %global upstream_version %{general_version}%{?prerel} Version: %{general_version}%{?prerel:~%{prerel}} -Release: 2%{?dist} +Release: 1%{?dist} License: Python @@ -1568,6 +1568,9 @@ CheckPython optimized # ====================================================== %changelog +* Tue Jun 07 2022 Tomáš Hrnčiar - 3.10.5-1 +- Update to 3.10.5 + * Sat May 14 2022 Tomas Orsava - 3.10.4-2 - Move _sysconfigdata_d_linux*.py to the debug subpackage diff --git a/sources b/sources index 46b98a4..6266f8b 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (Python-3.10.4.tar.xz) = 6c9aeecddc55c7896b2e8527fca131c7b2b6127d56ce1a001ccedfebf590334e0c0bb7c517ed3cf1da3c1910e002552b56aa7e03eeb672f42ff0bd8150799113 -SHA512 (Python-3.10.4.tar.xz.asc) = 699e37bf09067083af159e3734b38c952bdc75432c8abfb7a7b8cce7ca975038da37490abeb5c13befd2dacb84a5341ad30de5d0a63d35af5c512215744f4d6d +SHA512 (Python-3.10.5.tar.xz) = aa7f58a9b31de9824185b3e7bfa7da0dcf64ae9e89840664eae9d98d9048a650fa012cd5b873a62ff44b65b856db86f095c4003117406ec5e9583ec5f7e78e90 +SHA512 (Python-3.10.5.tar.xz.asc) = 72d0ab09900e2a10b85ccac804efd5536251152798e7347576e0e28bff4ab4a84b08d646329b225f9949047586686f9f4e7f05652526657a0948951b739c14e0 From 479c2b397f86a2da058c9843e81d1e6e1f45c52a Mon Sep 17 00:00:00 2001 From: Charalampos Stratakis Date: Thu, 9 Jun 2022 15:46:59 +0200 Subject: [PATCH 21/26] Security fix for CVE-2015-20107 Resolves: rhbz#2075390 --- 00382-cve-2015-20107.patch | 150 +++++++++++++++++++++++++++++++++++++ python3.10.spec | 16 +++- 2 files changed, 165 insertions(+), 1 deletion(-) create mode 100644 00382-cve-2015-20107.patch diff --git a/00382-cve-2015-20107.patch b/00382-cve-2015-20107.patch new file mode 100644 index 0000000..dd7992e --- /dev/null +++ b/00382-cve-2015-20107.patch @@ -0,0 +1,150 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Petr Viktorin +Date: Fri, 3 Jun 2022 11:43:35 +0200 +Subject: [PATCH] 00382: CVE-2015-20107 + +Make mailcap refuse to match unsafe filenames/types/params (GH-91993) + +Upstream: https://github.com/python/cpython/issues/68966 + +Tracker bug: https://bugzilla.redhat.com/show_bug.cgi?id=2075390 +--- + Doc/library/mailcap.rst | 12 +++++++++ + Lib/mailcap.py | 26 +++++++++++++++++-- + Lib/test/test_mailcap.py | 8 ++++-- + ...2-04-27-18-25-30.gh-issue-68966.gjS8zs.rst | 4 +++ + 4 files changed, 46 insertions(+), 4 deletions(-) + create mode 100644 Misc/NEWS.d/next/Security/2022-04-27-18-25-30.gh-issue-68966.gjS8zs.rst + +diff --git a/Doc/library/mailcap.rst b/Doc/library/mailcap.rst +index e2e5bb3445..2bc00195cd 100644 +--- a/Doc/library/mailcap.rst ++++ b/Doc/library/mailcap.rst +@@ -60,6 +60,18 @@ standard. However, mailcap files are supported on most Unix systems. + use) to determine whether or not the mailcap line applies. :func:`findmatch` + will automatically check such conditions and skip the entry if the check fails. + ++ .. versionchanged:: 3.11 ++ ++ To prevent security issues with shell metacharacters (symbols that have ++ special effects in a shell command line), ``findmatch`` will refuse ++ to inject ASCII characters other than alphanumerics and ``@+=:,./-_`` ++ into the returned command line. ++ ++ If a disallowed character appears in *filename*, ``findmatch`` will always ++ return ``(None, None)`` as if no entry was found. ++ If such a character appears elsewhere (a value in *plist* or in *MIMEtype*), ++ ``findmatch`` will ignore all mailcap entries which use that value. ++ A :mod:`warning ` will be raised in either case. + + .. function:: getcaps() + +diff --git a/Lib/mailcap.py b/Lib/mailcap.py +index ae416a8e9f..444c6408b5 100644 +--- a/Lib/mailcap.py ++++ b/Lib/mailcap.py +@@ -2,6 +2,7 @@ + + import os + import warnings ++import re + + __all__ = ["getcaps","findmatch"] + +@@ -13,6 +14,11 @@ def lineno_sort_key(entry): + else: + return 1, 0 + ++_find_unsafe = re.compile(r'[^\xa1-\U0010FFFF\w@+=:,./-]').search ++ ++class UnsafeMailcapInput(Warning): ++ """Warning raised when refusing unsafe input""" ++ + + # Part 1: top-level interface. + +@@ -165,15 +171,22 @@ def findmatch(caps, MIMEtype, key='view', filename="/dev/null", plist=[]): + entry to use. + + """ ++ if _find_unsafe(filename): ++ msg = "Refusing to use mailcap with filename %r. Use a safe temporary filename." % (filename,) ++ warnings.warn(msg, UnsafeMailcapInput) ++ return None, None + entries = lookup(caps, MIMEtype, key) + # XXX This code should somehow check for the needsterminal flag. + for e in entries: + if 'test' in e: + test = subst(e['test'], filename, plist) ++ if test is None: ++ continue + if test and os.system(test) != 0: + continue + command = subst(e[key], MIMEtype, filename, plist) +- return command, e ++ if command is not None: ++ return command, e + return None, None + + def lookup(caps, MIMEtype, key=None): +@@ -206,6 +219,10 @@ def subst(field, MIMEtype, filename, plist=[]): + elif c == 's': + res = res + filename + elif c == 't': ++ if _find_unsafe(MIMEtype): ++ msg = "Refusing to substitute MIME type %r into a shell command." % (MIMEtype,) ++ warnings.warn(msg, UnsafeMailcapInput) ++ return None + res = res + MIMEtype + elif c == '{': + start = i +@@ -213,7 +230,12 @@ def subst(field, MIMEtype, filename, plist=[]): + i = i+1 + name = field[start:i] + i = i+1 +- res = res + findparam(name, plist) ++ param = findparam(name, plist) ++ if _find_unsafe(param): ++ msg = "Refusing to substitute parameter %r (%s) into a shell command" % (param, name) ++ warnings.warn(msg, UnsafeMailcapInput) ++ return None ++ res = res + param + # XXX To do: + # %n == number of parts if type is multipart/* + # %F == list of alternating type and filename for parts +diff --git a/Lib/test/test_mailcap.py b/Lib/test/test_mailcap.py +index ef9cad498a..32f07ab290 100644 +--- a/Lib/test/test_mailcap.py ++++ b/Lib/test/test_mailcap.py +@@ -123,7 +123,8 @@ def test_subst(self): + (["", "audio/*", "foo.txt"], ""), + (["echo foo", "audio/*", "foo.txt"], "echo foo"), + (["echo %s", "audio/*", "foo.txt"], "echo foo.txt"), +- (["echo %t", "audio/*", "foo.txt"], "echo audio/*"), ++ (["echo %t", "audio/*", "foo.txt"], None), ++ (["echo %t", "audio/wav", "foo.txt"], "echo audio/wav"), + (["echo \\%t", "audio/*", "foo.txt"], "echo %t"), + (["echo foo", "audio/*", "foo.txt", plist], "echo foo"), + (["echo %{total}", "audio/*", "foo.txt", plist], "echo 3") +@@ -207,7 +208,10 @@ def test_findmatch(self): + ('"An audio fragment"', audio_basic_entry)), + ([c, "audio/*"], + {"filename": fname}, +- ("/usr/local/bin/showaudio audio/*", audio_entry)), ++ (None, None)), ++ ([c, "audio/wav"], ++ {"filename": fname}, ++ ("/usr/local/bin/showaudio audio/wav", audio_entry)), + ([c, "message/external-body"], + {"plist": plist}, + ("showexternal /dev/null default john python.org /tmp foo bar", message_entry)) +diff --git a/Misc/NEWS.d/next/Security/2022-04-27-18-25-30.gh-issue-68966.gjS8zs.rst b/Misc/NEWS.d/next/Security/2022-04-27-18-25-30.gh-issue-68966.gjS8zs.rst +new file mode 100644 +index 0000000000..da81a1f699 +--- /dev/null ++++ b/Misc/NEWS.d/next/Security/2022-04-27-18-25-30.gh-issue-68966.gjS8zs.rst +@@ -0,0 +1,4 @@ ++The deprecated mailcap module now refuses to inject unsafe text (filenames, ++MIME types, parameters) into shell commands. Instead of using such text, it ++will warn and act as if a match was not found (or for test commands, as if ++the test failed). diff --git a/python3.10.spec b/python3.10.spec index 8112b24..078c486 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -17,7 +17,7 @@ URL: https://www.python.org/ #global prerel ... %global upstream_version %{general_version}%{?prerel} Version: %{general_version}%{?prerel:~%{prerel}} -Release: 1%{?dist} +Release: 2%{?dist} License: Python @@ -318,6 +318,16 @@ Patch328: 00328-pyc-timestamp-invalidation-mode.patch # https://github.com/GrahamDumpleton/mod_wsgi/issues/730 Patch371: 00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch +# 00382 # 9e275dcdf3934b827994ecc3247d583d5bab7985 +# CVE-2015-20107 +# +# Make mailcap refuse to match unsafe filenames/types/params (GH-91993) +# +# Upstream: https://github.com/python/cpython/issues/68966 +# +# Tracker bug: https://bugzilla.redhat.com/show_bug.cgi?id=2075390 +Patch382: 00382-cve-2015-20107.patch + # (New patches go here ^^^) # # When adding new patches to "python" and "python3" in Fedora, EL, etc., @@ -1568,6 +1578,10 @@ CheckPython optimized # ====================================================== %changelog +* Thu Jun 09 2022 Charalampos Stratakis - 3.10.5-2 +- Security fix for CVE-2015-20107 +Resolves: rhbz#2075390 + * Tue Jun 07 2022 Tomáš Hrnčiar - 3.10.5-1 - Update to 3.10.5 From 8a53c5ea64a8a2d0210826a12e6c8e4c170e621d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tom=C3=A1=C5=A1=20Hrn=C4=8Diar?= Date: Tue, 2 Aug 2022 14:38:43 +0200 Subject: [PATCH 22/26] Update to 3.10.6 --- python3.10.spec | 11 +++++++---- sources | 4 ++-- 2 files changed, 9 insertions(+), 6 deletions(-) diff --git a/python3.10.spec b/python3.10.spec index 078c486..cf28f23 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -13,11 +13,11 @@ URL: https://www.python.org/ # WARNING When rebasing to a new Python version, # remember to update the python3-docs package as well -%global general_version %{pybasever}.5 +%global general_version %{pybasever}.6 #global prerel ... %global upstream_version %{general_version}%{?prerel} Version: %{general_version}%{?prerel:~%{prerel}} -Release: 2%{?dist} +Release: 1%{?dist} License: Python @@ -67,8 +67,8 @@ License: Python # If the rpmwheels condition is disabled, we use the bundled wheel packages # from Python with the versions below. # This needs to be manually updated when we update Python. -%global pip_version 22.0.4 -%global setuptools_version 58.1.0 +%global pip_version 22.2.1 +%global setuptools_version 63.2.0 # Expensive optimizations (mainly, profile-guided optimizations) %bcond_without optimizations @@ -1578,6 +1578,9 @@ CheckPython optimized # ====================================================== %changelog +* Tue Aug 02 2022 Tomáš Hrnčiar - 3.10.6-1 +- Update to 3.10.6 + * Thu Jun 09 2022 Charalampos Stratakis - 3.10.5-2 - Security fix for CVE-2015-20107 Resolves: rhbz#2075390 diff --git a/sources b/sources index 6266f8b..0c2ea47 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (Python-3.10.5.tar.xz) = aa7f58a9b31de9824185b3e7bfa7da0dcf64ae9e89840664eae9d98d9048a650fa012cd5b873a62ff44b65b856db86f095c4003117406ec5e9583ec5f7e78e90 -SHA512 (Python-3.10.5.tar.xz.asc) = 72d0ab09900e2a10b85ccac804efd5536251152798e7347576e0e28bff4ab4a84b08d646329b225f9949047586686f9f4e7f05652526657a0948951b739c14e0 +SHA512 (Python-3.10.6.tar.xz) = f2bf424bf4f4caa524ee1248b431e8e06d0745c3fc3ba457710d75f3698e653733feb4b059cd124f1de2a9e851c30d847f567aa47abef12898c9dc8a6507b476 +SHA512 (Python-3.10.6.tar.xz.asc) = 9288e2f62f2e8c8208ad176372261545a64e675d737bb616403bcd888bc91177909257632e4cc0b5d688d612bea38a274030ec6989dc7d56c03064e32ad9903e From 511bdb75bd099554c0fb5890c7bc39b12aaea559 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Wed, 7 Sep 2022 14:00:03 +0000 Subject: [PATCH 23/26] Update to 3.10.7, with security fix for CVE-2020-10735 --- ...-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch | 2 +- python3.10.spec | 8 ++++++-- sources | 4 ++-- 3 files changed, 9 insertions(+), 5 deletions(-) diff --git a/00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch b/00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch index aad6391..7ab6c6c 100644 --- a/00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch +++ b/00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch @@ -60,7 +60,7 @@ index c54806e594..c51de6f4b8 100644 class ThreadJoinOnShutdown(BaseTestCase): diff --git a/Lib/threading.py b/Lib/threading.py -index 668126523d..3e14cca8be 100644 +index 62f49c05cd..433aa11212 100644 --- a/Lib/threading.py +++ b/Lib/threading.py @@ -1530,29 +1530,20 @@ def _shutdown(): diff --git a/python3.10.spec b/python3.10.spec index cf28f23..61735ec 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -13,7 +13,7 @@ URL: https://www.python.org/ # WARNING When rebasing to a new Python version, # remember to update the python3-docs package as well -%global general_version %{pybasever}.6 +%global general_version %{pybasever}.7 #global prerel ... %global upstream_version %{general_version}%{?prerel} Version: %{general_version}%{?prerel:~%{prerel}} @@ -67,7 +67,7 @@ License: Python # If the rpmwheels condition is disabled, we use the bundled wheel packages # from Python with the versions below. # This needs to be manually updated when we update Python. -%global pip_version 22.2.1 +%global pip_version 22.2.2 %global setuptools_version 63.2.0 # Expensive optimizations (mainly, profile-guided optimizations) @@ -1578,6 +1578,10 @@ CheckPython optimized # ====================================================== %changelog +* Wed Sep 07 2022 Miro Hrončok - 3.10.7-1 +- Update to 3.10.7 +- Contains security fix for CVE-2020-10735 + * Tue Aug 02 2022 Tomáš Hrnčiar - 3.10.6-1 - Update to 3.10.6 diff --git a/sources b/sources index 0c2ea47..9efa146 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (Python-3.10.6.tar.xz) = f2bf424bf4f4caa524ee1248b431e8e06d0745c3fc3ba457710d75f3698e653733feb4b059cd124f1de2a9e851c30d847f567aa47abef12898c9dc8a6507b476 -SHA512 (Python-3.10.6.tar.xz.asc) = 9288e2f62f2e8c8208ad176372261545a64e675d737bb616403bcd888bc91177909257632e4cc0b5d688d612bea38a274030ec6989dc7d56c03064e32ad9903e +SHA512 (Python-3.10.7.tar.xz) = dc3432d72ee7382617318c9645204876d13bb61d4caf3fbbb65e6b14897261123c743049657c95e159e5566daf4dcde613d2e393f025de758f610b44eb958313 +SHA512 (Python-3.10.7.tar.xz.asc) = a65d152d87870de763de3384a1c0ff0309068a2af0fcdfa39a6f968a52b59c56229553cf6a955ec0af1d3db5bf4641c4e91d6150764548d2e9fb0e9a01ab759d From 89d9f926970cbb959621e0adede34ec24c243f1c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Wed, 12 Oct 2022 15:44:08 +0200 Subject: [PATCH 24/26] Update to 3.10.8 Patch 382 was merged upstream. --- 00382-cve-2015-20107.patch | 150 ------------------------------------- python3.10.spec | 15 +--- sources | 4 +- 3 files changed, 6 insertions(+), 163 deletions(-) delete mode 100644 00382-cve-2015-20107.patch diff --git a/00382-cve-2015-20107.patch b/00382-cve-2015-20107.patch deleted file mode 100644 index dd7992e..0000000 --- a/00382-cve-2015-20107.patch +++ /dev/null @@ -1,150 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Petr Viktorin -Date: Fri, 3 Jun 2022 11:43:35 +0200 -Subject: [PATCH] 00382: CVE-2015-20107 - -Make mailcap refuse to match unsafe filenames/types/params (GH-91993) - -Upstream: https://github.com/python/cpython/issues/68966 - -Tracker bug: https://bugzilla.redhat.com/show_bug.cgi?id=2075390 ---- - Doc/library/mailcap.rst | 12 +++++++++ - Lib/mailcap.py | 26 +++++++++++++++++-- - Lib/test/test_mailcap.py | 8 ++++-- - ...2-04-27-18-25-30.gh-issue-68966.gjS8zs.rst | 4 +++ - 4 files changed, 46 insertions(+), 4 deletions(-) - create mode 100644 Misc/NEWS.d/next/Security/2022-04-27-18-25-30.gh-issue-68966.gjS8zs.rst - -diff --git a/Doc/library/mailcap.rst b/Doc/library/mailcap.rst -index e2e5bb3445..2bc00195cd 100644 ---- a/Doc/library/mailcap.rst -+++ b/Doc/library/mailcap.rst -@@ -60,6 +60,18 @@ standard. However, mailcap files are supported on most Unix systems. - use) to determine whether or not the mailcap line applies. :func:`findmatch` - will automatically check such conditions and skip the entry if the check fails. - -+ .. versionchanged:: 3.11 -+ -+ To prevent security issues with shell metacharacters (symbols that have -+ special effects in a shell command line), ``findmatch`` will refuse -+ to inject ASCII characters other than alphanumerics and ``@+=:,./-_`` -+ into the returned command line. -+ -+ If a disallowed character appears in *filename*, ``findmatch`` will always -+ return ``(None, None)`` as if no entry was found. -+ If such a character appears elsewhere (a value in *plist* or in *MIMEtype*), -+ ``findmatch`` will ignore all mailcap entries which use that value. -+ A :mod:`warning ` will be raised in either case. - - .. function:: getcaps() - -diff --git a/Lib/mailcap.py b/Lib/mailcap.py -index ae416a8e9f..444c6408b5 100644 ---- a/Lib/mailcap.py -+++ b/Lib/mailcap.py -@@ -2,6 +2,7 @@ - - import os - import warnings -+import re - - __all__ = ["getcaps","findmatch"] - -@@ -13,6 +14,11 @@ def lineno_sort_key(entry): - else: - return 1, 0 - -+_find_unsafe = re.compile(r'[^\xa1-\U0010FFFF\w@+=:,./-]').search -+ -+class UnsafeMailcapInput(Warning): -+ """Warning raised when refusing unsafe input""" -+ - - # Part 1: top-level interface. - -@@ -165,15 +171,22 @@ def findmatch(caps, MIMEtype, key='view', filename="/dev/null", plist=[]): - entry to use. - - """ -+ if _find_unsafe(filename): -+ msg = "Refusing to use mailcap with filename %r. Use a safe temporary filename." % (filename,) -+ warnings.warn(msg, UnsafeMailcapInput) -+ return None, None - entries = lookup(caps, MIMEtype, key) - # XXX This code should somehow check for the needsterminal flag. - for e in entries: - if 'test' in e: - test = subst(e['test'], filename, plist) -+ if test is None: -+ continue - if test and os.system(test) != 0: - continue - command = subst(e[key], MIMEtype, filename, plist) -- return command, e -+ if command is not None: -+ return command, e - return None, None - - def lookup(caps, MIMEtype, key=None): -@@ -206,6 +219,10 @@ def subst(field, MIMEtype, filename, plist=[]): - elif c == 's': - res = res + filename - elif c == 't': -+ if _find_unsafe(MIMEtype): -+ msg = "Refusing to substitute MIME type %r into a shell command." % (MIMEtype,) -+ warnings.warn(msg, UnsafeMailcapInput) -+ return None - res = res + MIMEtype - elif c == '{': - start = i -@@ -213,7 +230,12 @@ def subst(field, MIMEtype, filename, plist=[]): - i = i+1 - name = field[start:i] - i = i+1 -- res = res + findparam(name, plist) -+ param = findparam(name, plist) -+ if _find_unsafe(param): -+ msg = "Refusing to substitute parameter %r (%s) into a shell command" % (param, name) -+ warnings.warn(msg, UnsafeMailcapInput) -+ return None -+ res = res + param - # XXX To do: - # %n == number of parts if type is multipart/* - # %F == list of alternating type and filename for parts -diff --git a/Lib/test/test_mailcap.py b/Lib/test/test_mailcap.py -index ef9cad498a..32f07ab290 100644 ---- a/Lib/test/test_mailcap.py -+++ b/Lib/test/test_mailcap.py -@@ -123,7 +123,8 @@ def test_subst(self): - (["", "audio/*", "foo.txt"], ""), - (["echo foo", "audio/*", "foo.txt"], "echo foo"), - (["echo %s", "audio/*", "foo.txt"], "echo foo.txt"), -- (["echo %t", "audio/*", "foo.txt"], "echo audio/*"), -+ (["echo %t", "audio/*", "foo.txt"], None), -+ (["echo %t", "audio/wav", "foo.txt"], "echo audio/wav"), - (["echo \\%t", "audio/*", "foo.txt"], "echo %t"), - (["echo foo", "audio/*", "foo.txt", plist], "echo foo"), - (["echo %{total}", "audio/*", "foo.txt", plist], "echo 3") -@@ -207,7 +208,10 @@ def test_findmatch(self): - ('"An audio fragment"', audio_basic_entry)), - ([c, "audio/*"], - {"filename": fname}, -- ("/usr/local/bin/showaudio audio/*", audio_entry)), -+ (None, None)), -+ ([c, "audio/wav"], -+ {"filename": fname}, -+ ("/usr/local/bin/showaudio audio/wav", audio_entry)), - ([c, "message/external-body"], - {"plist": plist}, - ("showexternal /dev/null default john python.org /tmp foo bar", message_entry)) -diff --git a/Misc/NEWS.d/next/Security/2022-04-27-18-25-30.gh-issue-68966.gjS8zs.rst b/Misc/NEWS.d/next/Security/2022-04-27-18-25-30.gh-issue-68966.gjS8zs.rst -new file mode 100644 -index 0000000000..da81a1f699 ---- /dev/null -+++ b/Misc/NEWS.d/next/Security/2022-04-27-18-25-30.gh-issue-68966.gjS8zs.rst -@@ -0,0 +1,4 @@ -+The deprecated mailcap module now refuses to inject unsafe text (filenames, -+MIME types, parameters) into shell commands. Instead of using such text, it -+will warn and act as if a match was not found (or for test commands, as if -+the test failed). diff --git a/python3.10.spec b/python3.10.spec index 61735ec..29daf21 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -13,7 +13,7 @@ URL: https://www.python.org/ # WARNING When rebasing to a new Python version, # remember to update the python3-docs package as well -%global general_version %{pybasever}.7 +%global general_version %{pybasever}.8 #global prerel ... %global upstream_version %{general_version}%{?prerel} Version: %{general_version}%{?prerel:~%{prerel}} @@ -318,16 +318,6 @@ Patch328: 00328-pyc-timestamp-invalidation-mode.patch # https://github.com/GrahamDumpleton/mod_wsgi/issues/730 Patch371: 00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch -# 00382 # 9e275dcdf3934b827994ecc3247d583d5bab7985 -# CVE-2015-20107 -# -# Make mailcap refuse to match unsafe filenames/types/params (GH-91993) -# -# Upstream: https://github.com/python/cpython/issues/68966 -# -# Tracker bug: https://bugzilla.redhat.com/show_bug.cgi?id=2075390 -Patch382: 00382-cve-2015-20107.patch - # (New patches go here ^^^) # # When adding new patches to "python" and "python3" in Fedora, EL, etc., @@ -1578,6 +1568,9 @@ CheckPython optimized # ====================================================== %changelog +* Wed Oct 12 2022 Miro Hrončok - 3.10.8-1 +- Update to 3.10.8 + * Wed Sep 07 2022 Miro Hrončok - 3.10.7-1 - Update to 3.10.7 - Contains security fix for CVE-2020-10735 diff --git a/sources b/sources index 9efa146..f04c9ab 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (Python-3.10.7.tar.xz) = dc3432d72ee7382617318c9645204876d13bb61d4caf3fbbb65e6b14897261123c743049657c95e159e5566daf4dcde613d2e393f025de758f610b44eb958313 -SHA512 (Python-3.10.7.tar.xz.asc) = a65d152d87870de763de3384a1c0ff0309068a2af0fcdfa39a6f968a52b59c56229553cf6a955ec0af1d3db5bf4641c4e91d6150764548d2e9fb0e9a01ab759d +SHA512 (Python-3.10.8.tar.xz) = 40e3e77d79618c81d6fc57c5d119b99c2959dcf932f40aad6b26f2ec39c5e713e6ff298f7597b4fad2ab94680db3732483b5ca0a45e6ae58c14580b3ea44cb0f +SHA512 (Python-3.10.8.tar.xz.asc) = 0c2ef09d898257ba5e9ec7c5bb224a7e50e5ebca96843b4d9e25be6cdd2f17144772aafc92280af20c21491e3c8cedc697414688ece613c93b28ff7ecddcf93f From 99563953da0bf4659195bb86a74d150d03dc47ec Mon Sep 17 00:00:00 2001 From: Lumir Balhar Date: Wed, 9 Nov 2022 12:05:00 +0100 Subject: [PATCH 25/26] Fix CVE-2022-42919 --- ...abstract-sockets-for-multiprocessing.patch | 66 +++++++++++++++++++ python3.10.spec | 26 +++++++- 2 files changed, 91 insertions(+), 1 deletion(-) create mode 100644 00391-don-t-use-linux-abstract-sockets-for-multiprocessing.patch diff --git a/00391-don-t-use-linux-abstract-sockets-for-multiprocessing.patch b/00391-don-t-use-linux-abstract-sockets-for-multiprocessing.patch new file mode 100644 index 0000000..fb7dbad --- /dev/null +++ b/00391-don-t-use-linux-abstract-sockets-for-multiprocessing.patch @@ -0,0 +1,66 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: "Miss Islington (bot)" + <31488909+miss-islington@users.noreply.github.com> +Date: Thu, 20 Oct 2022 16:55:51 -0700 +Subject: [PATCH] 00391: Don't use Linux abstract sockets for multiprocessing + +Linux abstract sockets are insecure as they lack any form of filesystem +permissions so their use allows anyone on the system to inject code into +the process. + +This removes the default preference for abstract sockets in +multiprocessing introduced in Python 3.9+ via +https://github.com/python/cpython/pull/18866 while fixing +https://github.com/python/cpython/issues/84031. + +Explicit use of an abstract socket by a user now generates a +RuntimeWarning. If we choose to keep this warning, it should be +backported to the 3.7 and 3.8 branches. +(cherry picked from commit 49f61068f49747164988ffc5a442d2a63874fc17) + +Co-authored-by: Gregory P. Smith + +Automerge-Triggered-By: GH:gpshead +--- + Lib/multiprocessing/connection.py | 5 ----- + .../2022-09-07-10-42-00.gh-issue-97514.Yggdsl.rst | 15 +++++++++++++++ + 2 files changed, 15 insertions(+), 5 deletions(-) + create mode 100644 Misc/NEWS.d/next/Security/2022-09-07-10-42-00.gh-issue-97514.Yggdsl.rst + +diff --git a/Lib/multiprocessing/connection.py b/Lib/multiprocessing/connection.py +index 510e4b5aba..8e2facf92a 100644 +--- a/Lib/multiprocessing/connection.py ++++ b/Lib/multiprocessing/connection.py +@@ -73,11 +73,6 @@ def arbitrary_address(family): + if family == 'AF_INET': + return ('localhost', 0) + elif family == 'AF_UNIX': +- # Prefer abstract sockets if possible to avoid problems with the address +- # size. When coding portable applications, some implementations have +- # sun_path as short as 92 bytes in the sockaddr_un struct. +- if util.abstract_sockets_supported: +- return f"\0listener-{os.getpid()}-{next(_mmap_counter)}" + return tempfile.mktemp(prefix='listener-', dir=util.get_temp_dir()) + elif family == 'AF_PIPE': + return tempfile.mktemp(prefix=r'\\.\pipe\pyc-%d-%d-' % +diff --git a/Misc/NEWS.d/next/Security/2022-09-07-10-42-00.gh-issue-97514.Yggdsl.rst b/Misc/NEWS.d/next/Security/2022-09-07-10-42-00.gh-issue-97514.Yggdsl.rst +new file mode 100644 +index 0000000000..02d95b5705 +--- /dev/null ++++ b/Misc/NEWS.d/next/Security/2022-09-07-10-42-00.gh-issue-97514.Yggdsl.rst +@@ -0,0 +1,15 @@ ++On Linux the :mod:`multiprocessing` module returns to using filesystem backed ++unix domain sockets for communication with the *forkserver* process instead of ++the Linux abstract socket namespace. Only code that chooses to use the ++:ref:`"forkserver" start method ` is affected. ++ ++Abstract sockets have no permissions and could allow any user on the system in ++the same `network namespace ++`_ (often the ++whole system) to inject code into the multiprocessing *forkserver* process. ++This was a potential privilege escalation. Filesystem based socket permissions ++restrict this to the *forkserver* process user as was the default in Python 3.8 ++and earlier. ++ ++This prevents Linux `CVE-2022-42919 ++`_. diff --git a/python3.10.spec b/python3.10.spec index 29daf21..22fb30a 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -17,7 +17,7 @@ URL: https://www.python.org/ #global prerel ... %global upstream_version %{general_version}%{?prerel} Version: %{general_version}%{?prerel:~%{prerel}} -Release: 1%{?dist} +Release: 2%{?dist} License: Python @@ -318,6 +318,26 @@ Patch328: 00328-pyc-timestamp-invalidation-mode.patch # https://github.com/GrahamDumpleton/mod_wsgi/issues/730 Patch371: 00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch +# 00391 # e6d12d8fca6afad3a56dc076c220f213b723a28e +# Don't use Linux abstract sockets for multiprocessing +# +# Linux abstract sockets are insecure as they lack any form of filesystem +# permissions so their use allows anyone on the system to inject code into +# the process. +# +# This removes the default preference for abstract sockets in +# multiprocessing introduced in Python 3.9+ via +# https://github.com/python/cpython/pull/18866 while fixing +# https://github.com/python/cpython/issues/84031. +# +# Explicit use of an abstract socket by a user now generates a +# RuntimeWarning. If we choose to keep this warning, it should be +# backported to the 3.7 and 3.8 branches. +# +# +# Automerge-Triggered-By: GH:gpshead +Patch391: 00391-don-t-use-linux-abstract-sockets-for-multiprocessing.patch + # (New patches go here ^^^) # # When adding new patches to "python" and "python3" in Fedora, EL, etc., @@ -1568,6 +1588,10 @@ CheckPython optimized # ====================================================== %changelog +* Wed Nov 09 2022 Lumír Balhar - 3.10.8-2 +- Fix CVE-2022-42919 +Resolves: rhbz#2138709 + * Wed Oct 12 2022 Miro Hrončok - 3.10.8-1 - Update to 3.10.8 From e3252eefc868ce194d60f024b3eda95b9982b69c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Mon, 14 Nov 2022 16:23:15 +0100 Subject: [PATCH 26/26] Make IDLE work without python3-test installed --- 00393-idle---fix-buggy-macosx-patch.patch | 111 ++++++++++++++++++++++ python3.10.spec | 15 ++- 2 files changed, 125 insertions(+), 1 deletion(-) create mode 100644 00393-idle---fix-buggy-macosx-patch.patch diff --git a/00393-idle---fix-buggy-macosx-patch.patch b/00393-idle---fix-buggy-macosx-patch.patch new file mode 100644 index 0000000..5bb80dc --- /dev/null +++ b/00393-idle---fix-buggy-macosx-patch.patch @@ -0,0 +1,111 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: "Miss Islington (bot)" + <31488909+miss-islington@users.noreply.github.com> +Date: Sun, 16 Oct 2022 08:33:33 -0700 +Subject: [PATCH] 00393: IDLE - fix buggy macosx patch + +GH-97530 fixed IDLE tests possibly crashing on a Mac without a GUI. +But it resulted in IDLE not starting in 3.10.8, 3.12.0a1, and +Microsoft Python 3.10.2288.0 when test/* is not installed. +After this patch, test.* is only imported when testing on Mac. +(cherry picked from commit 35fa5d5e7f2b0971b39b2659dc70cb77e34a7dd6) + +Co-authored-by: Terry Jan Reedy +--- + Lib/idlelib/NEWS.txt | 5 +++ + Lib/idlelib/macosx.py | 42 ++++++++++++------- + ...2-10-15-21-20-40.gh-issue-97527.otAHJM.rst | 3 ++ + 3 files changed, 34 insertions(+), 16 deletions(-) + create mode 100644 Misc/NEWS.d/next/IDLE/2022-10-15-21-20-40.gh-issue-97527.otAHJM.rst + +diff --git a/Lib/idlelib/NEWS.txt b/Lib/idlelib/NEWS.txt +index 277fd9429a..521b1f12f9 100644 +--- a/Lib/idlelib/NEWS.txt ++++ b/Lib/idlelib/NEWS.txt +@@ -4,6 +4,11 @@ Released 2023-04-03? + ========================= + + ++gh-97527: Fix a bug in the previous bugfix that caused IDLE to not ++start when run with 3.10.8, 3.12.0a1, and at least Microsoft Python ++3.10.2288.0 installed without the Lib/test package. 3.11.0 was never ++affected. ++ + gh-65802: Document handling of extensions in Save As dialogs. + + gh-95191: Include prompts when saving Shell (interactive input/output). +diff --git a/Lib/idlelib/macosx.py b/Lib/idlelib/macosx.py +index 1085d689f6..f53bd58970 100644 +--- a/Lib/idlelib/macosx.py ++++ b/Lib/idlelib/macosx.py +@@ -4,7 +4,6 @@ + from os.path import expanduser + import plistlib + from sys import platform # Used in _init_tk_type, changed by test. +-from test.support import requires, ResourceDenied + + import tkinter + +@@ -16,27 +15,38 @@ + + def _init_tk_type(): + """ Initialize _tk_type for isXyzTk functions. ++ ++ This function is only called once, when _tk_type is still None. + """ + global _tk_type + if platform == 'darwin': +- try: +- requires('gui') +- except ResourceDenied: # Possible when testing. +- _tk_type = "cocoa" # Newest and most common. +- else: +- root = tkinter.Tk() +- ws = root.tk.call('tk', 'windowingsystem') +- if 'x11' in ws: +- _tk_type = "xquartz" +- elif 'aqua' not in ws: +- _tk_type = "other" +- elif 'AppKit' in root.tk.call('winfo', 'server', '.'): ++ ++ # When running IDLE, GUI is present, test/* may not be. ++ # When running tests, test/* is present, GUI may not be. ++ # If not, guess most common. Does not matter for testing. ++ from idlelib.__init__ import testing ++ if testing: ++ from test.support import requires, ResourceDenied ++ try: ++ requires('gui') ++ except ResourceDenied: + _tk_type = "cocoa" +- else: +- _tk_type = "carbon" +- root.destroy() ++ return ++ ++ root = tkinter.Tk() ++ ws = root.tk.call('tk', 'windowingsystem') ++ if 'x11' in ws: ++ _tk_type = "xquartz" ++ elif 'aqua' not in ws: ++ _tk_type = "other" ++ elif 'AppKit' in root.tk.call('winfo', 'server', '.'): ++ _tk_type = "cocoa" ++ else: ++ _tk_type = "carbon" ++ root.destroy() + else: + _tk_type = "other" ++ return + + def isAquaTk(): + """ +diff --git a/Misc/NEWS.d/next/IDLE/2022-10-15-21-20-40.gh-issue-97527.otAHJM.rst b/Misc/NEWS.d/next/IDLE/2022-10-15-21-20-40.gh-issue-97527.otAHJM.rst +new file mode 100644 +index 0000000000..e7fda89741 +--- /dev/null ++++ b/Misc/NEWS.d/next/IDLE/2022-10-15-21-20-40.gh-issue-97527.otAHJM.rst +@@ -0,0 +1,3 @@ ++Fix a bug in the previous bugfix that caused IDLE to not start when run with ++3.10.8, 3.12.0a1, and at least Microsoft Python 3.10.2288.0 installed ++without the Lib/test package. 3.11.0 was never affected. diff --git a/python3.10.spec b/python3.10.spec index 22fb30a..0bdc766 100644 --- a/python3.10.spec +++ b/python3.10.spec @@ -17,7 +17,7 @@ URL: https://www.python.org/ #global prerel ... %global upstream_version %{general_version}%{?prerel} Version: %{general_version}%{?prerel:~%{prerel}} -Release: 2%{?dist} +Release: 3%{?dist} License: Python @@ -338,6 +338,15 @@ Patch371: 00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-g # Automerge-Triggered-By: GH:gpshead Patch391: 00391-don-t-use-linux-abstract-sockets-for-multiprocessing.patch +# 00393 # 353b3ca7b9e0884839cd6dea28c9bafd9f878571 +# IDLE - fix buggy macosx patch +# +# GH-97530 fixed IDLE tests possibly crashing on a Mac without a GUI. +# But it resulted in IDLE not starting in 3.10.8, 3.12.0a1, and +# Microsoft Python 3.10.2288.0 when test/* is not installed. +# After this patch, test.* is only imported when testing on Mac. +Patch393: 00393-idle---fix-buggy-macosx-patch.patch + # (New patches go here ^^^) # # When adding new patches to "python" and "python3" in Fedora, EL, etc., @@ -1588,6 +1597,10 @@ CheckPython optimized # ====================================================== %changelog +* Mon Nov 14 2022 Miro Hrončok - 3.10.8-3 +- Make IDLE work without python3-test installed +- Fixes rhbz#2142602 + * Wed Nov 09 2022 Lumír Balhar - 3.10.8-2 - Fix CVE-2022-42919 Resolves: rhbz#2138709