diff --git a/00001-rpath.patch b/00001-rpath.patch index cd063e5..778c077 100644 --- a/00001-rpath.patch +++ b/00001-rpath.patch @@ -1,10 +1,9 @@ From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 From: David Malcolm Date: Wed, 13 Jan 2010 21:25:18 +0000 -Subject: 00001: Fixup distutils/unixccompiler.py to remove standard library - path from rpath +Subject: [PATCH] 00001: Fixup distutils/unixccompiler.py to remove standard + library path from rpath Was Patch0 in ivazquez' python3000 specfile -Was Patch0 in ivazquez' python3000 specfile --- Lib/distutils/unixccompiler.py | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/00251-change-user-install-location.patch b/00251-change-user-install-location.patch index 7c079b0..53096ec 100644 --- a/00251-change-user-install-location.patch +++ b/00251-change-user-install-location.patch @@ -1,7 +1,7 @@ From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Mon, 15 Feb 2021 12:19:27 +0100 -Subject: 00251: Change user install location +Subject: [PATCH] 00251: Change user install location MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit @@ -61,10 +61,10 @@ index 01d5331a63..79f70f0de4 100644 else: if self.exec_prefix is None: diff --git a/Lib/site.py b/Lib/site.py -index 2904e44cff..1c9bfa7713 100644 +index 69670d9d7f..104cb93899 100644 --- a/Lib/site.py +++ b/Lib/site.py -@@ -387,8 +387,15 @@ def getsitepackages(prefixes=None): +@@ -377,8 +377,15 @@ def getsitepackages(prefixes=None): return sitepackages def addsitepackages(known_paths, prefixes=None): @@ -160,7 +160,7 @@ index ebe3711827..55af57b335 100644 # On Windows we want to substitute 'lib' for schemes rather # than the native value (without modifying vars, in case it diff --git a/Lib/test/test_sysconfig.py b/Lib/test/test_sysconfig.py -index d3bb0d25ca..f39bbf67ea 100644 +index d96371d242..72b028435f 100644 --- a/Lib/test/test_sysconfig.py +++ b/Lib/test/test_sysconfig.py @@ -111,8 +111,19 @@ def test_get_path(self): @@ -184,7 +184,7 @@ index d3bb0d25ca..f39bbf67ea 100644 os.path.normpath(expected), ) -@@ -345,7 +356,7 @@ def test_get_config_h_filename(self): +@@ -336,7 +347,7 @@ def test_get_config_h_filename(self): self.assertTrue(os.path.isfile(config_h), config_h) def test_get_scheme_names(self): @@ -193,7 +193,7 @@ index d3bb0d25ca..f39bbf67ea 100644 if HAS_USER_BASE: wanted.extend(['nt_user', 'osx_framework_user', 'posix_user']) self.assertEqual(get_scheme_names(), tuple(sorted(wanted))) -@@ -357,6 +368,8 @@ def test_symlink(self): # Issue 7880 +@@ -348,6 +359,8 @@ def test_symlink(self): # Issue 7880 cmd = "-c", "import sysconfig; print(sysconfig.get_platform())" self.assertEqual(py.call_real(*cmd), py.call_link(*cmd)) diff --git a/00328-pyc-timestamp-invalidation-mode.patch b/00328-pyc-timestamp-invalidation-mode.patch new file mode 100644 index 0000000..d04a267 --- /dev/null +++ b/00328-pyc-timestamp-invalidation-mode.patch @@ -0,0 +1,54 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= +Date: Thu, 11 Jul 2019 13:44:13 +0200 +Subject: [PATCH] 00328: Restore pyc to TIMESTAMP invalidation mode as default + in rpmbuild + +Since Fedora 31, the $SOURCE_DATE_EPOCH is set in rpmbuild to the latest +%changelog date. This makes Python default to the CHECKED_HASH pyc +invalidation mode, bringing more reproducible builds traded for an import +performance decrease. To avoid that, we don't default to CHECKED_HASH +when $RPM_BUILD_ROOT is set (i.e. when we are building RPM packages). + +See https://src.fedoraproject.org/rpms/redhat-rpm-config/pull-request/57#comment-27426 +Downstream only: only used when building RPM packages +Ideally, we should talk to upstream and explain why we don't want this +--- + Lib/py_compile.py | 3 ++- + Lib/test/test_py_compile.py | 2 ++ + 2 files changed, 4 insertions(+), 1 deletion(-) + +diff --git a/Lib/py_compile.py b/Lib/py_compile.py +index 388614e51b..db52725016 100644 +--- a/Lib/py_compile.py ++++ b/Lib/py_compile.py +@@ -70,7 +70,8 @@ class PycInvalidationMode(enum.Enum): + + + def _get_default_invalidation_mode(): +- if os.environ.get('SOURCE_DATE_EPOCH'): ++ if (os.environ.get('SOURCE_DATE_EPOCH') and not ++ os.environ.get('RPM_BUILD_ROOT')): + return PycInvalidationMode.CHECKED_HASH + else: + return PycInvalidationMode.TIMESTAMP +diff --git a/Lib/test/test_py_compile.py b/Lib/test/test_py_compile.py +index a4a52b180d..e53f5d92aa 100644 +--- a/Lib/test/test_py_compile.py ++++ b/Lib/test/test_py_compile.py +@@ -19,6 +19,7 @@ def without_source_date_epoch(fxn): + def wrapper(*args, **kwargs): + with os_helper.EnvironmentVarGuard() as env: + env.unset('SOURCE_DATE_EPOCH') ++ env.unset('RPM_BUILD_ROOT') + return fxn(*args, **kwargs) + return wrapper + +@@ -29,6 +30,7 @@ def with_source_date_epoch(fxn): + def wrapper(*args, **kwargs): + with os_helper.EnvironmentVarGuard() as env: + env['SOURCE_DATE_EPOCH'] = '123456789' ++ env.unset('RPM_BUILD_ROOT') + return fxn(*args, **kwargs) + return wrapper + diff --git a/00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch b/00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch index 598f434..1d39233 100644 --- a/00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch +++ b/00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch @@ -1,8 +1,8 @@ From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tom=C3=A1=C5=A1=20Hrn=C4=8Diar?= Date: Tue, 7 Dec 2021 14:41:59 +0100 -Subject: 00371: Revert "bpo-1596321: Fix threading._shutdown() for the main - thread (GH-28549) (GH-28589)" +Subject: [PATCH] 00371: Revert "bpo-1596321: Fix threading._shutdown() for the + main thread (GH-28549) (GH-28589)" This reverts commit 38c67738c64304928c68d5c2bd78bbb01d979b94. It introduced regression causing FreeIPA's tests to fail. @@ -16,10 +16,10 @@ https://github.com/GrahamDumpleton/mod_wsgi/issues/730 2 files changed, 8 insertions(+), 50 deletions(-) diff --git a/Lib/test/test_threading.py b/Lib/test/test_threading.py -index ec6a319486..1dbb9d0baa 100644 +index 9c6561c099..84714c03fe 100644 --- a/Lib/test/test_threading.py +++ b/Lib/test/test_threading.py -@@ -1045,39 +1045,6 @@ def test_debug_deprecation(self): +@@ -956,39 +956,6 @@ def test_debug_deprecation(self): b'is deprecated and will be removed in Python 3.12') self.assertIn(msg, err) @@ -60,10 +60,10 @@ index ec6a319486..1dbb9d0baa 100644 class ThreadJoinOnShutdown(BaseTestCase): diff --git a/Lib/threading.py b/Lib/threading.py -index 29b8ec7465..2145f5a6dc 100644 +index 4f72938551..18c10e6489 100644 --- a/Lib/threading.py +++ b/Lib/threading.py -@@ -1553,29 +1553,20 @@ def _shutdown(): +@@ -1546,29 +1546,20 @@ def _shutdown(): global _SHUTTING_DOWN _SHUTTING_DOWN = True diff --git a/00452-properly-apply-exported-cflags-for-dtrace-systemtap-builds.patch b/00452-properly-apply-exported-cflags-for-dtrace-systemtap-builds.patch deleted file mode 100644 index 3fea025..0000000 --- a/00452-properly-apply-exported-cflags-for-dtrace-systemtap-builds.patch +++ /dev/null @@ -1,51 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: "Miss Islington (bot)" - <31488909+miss-islington@users.noreply.github.com> -Date: Mon, 31 Mar 2025 20:29:04 +0200 -Subject: 00452: Properly apply exported CFLAGS for dtrace/systemtap builds - -When using --with-dtrace the resulting object file could be missing -specific CFLAGS exported by the build system due to the systemtap -script using specific defaults. - -Exporting the CC and CFLAGS variables before the dtrace invocation -allows us to properly apply CFLAGS exported by the build system -even when cross-compiling. - -Co-authored-by: stratakis ---- - Makefile.pre.in | 4 ++-- - .../next/Build/2025-03-31-19-22-41.gh-issue-131865.PIJy7X.rst | 2 ++ - 2 files changed, 4 insertions(+), 2 deletions(-) - create mode 100644 Misc/NEWS.d/next/Build/2025-03-31-19-22-41.gh-issue-131865.PIJy7X.rst - -diff --git a/Makefile.pre.in b/Makefile.pre.in -index ad29e1a0ca..79b07194bb 100644 ---- a/Makefile.pre.in -+++ b/Makefile.pre.in -@@ -1458,7 +1458,7 @@ Python/frozen.o: $(FROZEN_FILES_OUT) - # an include guard, so we can't use a pipeline to transform its output. - Include/pydtrace_probes.h: $(srcdir)/Include/pydtrace.d - $(MKDIR_P) Include -- $(DTRACE) $(DFLAGS) -o $@ -h -s $< -+ CC="$(CC)" CFLAGS="$(CFLAGS)" $(DTRACE) $(DFLAGS) -o $@ -h -s $< - : sed in-place edit with POSIX-only tools - sed 's/PYTHON_/PyDTrace_/' $@ > $@.tmp - mv $@.tmp $@ -@@ -1468,7 +1468,7 @@ Python/import.o: $(srcdir)/Include/pydtrace.h - Modules/gcmodule.o: $(srcdir)/Include/pydtrace.h - - Python/pydtrace.o: $(srcdir)/Include/pydtrace.d $(DTRACE_DEPS) -- $(DTRACE) $(DFLAGS) -o $@ -G -s $< $(DTRACE_DEPS) -+ CC="$(CC)" CFLAGS="$(CFLAGS)" $(DTRACE) $(DFLAGS) -o $@ -G -s $< $(DTRACE_DEPS) - - Objects/typeobject.o: Objects/typeslots.inc - -diff --git a/Misc/NEWS.d/next/Build/2025-03-31-19-22-41.gh-issue-131865.PIJy7X.rst b/Misc/NEWS.d/next/Build/2025-03-31-19-22-41.gh-issue-131865.PIJy7X.rst -new file mode 100644 -index 0000000000..a287e0b228 ---- /dev/null -+++ b/Misc/NEWS.d/next/Build/2025-03-31-19-22-41.gh-issue-131865.PIJy7X.rst -@@ -0,0 +1,2 @@ -+The DTrace build now properly passes the ``CC`` and ``CFLAGS`` variables -+to the ``dtrace`` command when utilizing SystemTap on Linux. diff --git a/00462-fix-pyssl_seterror-handling-ssl_error_syscall.patch b/00462-fix-pyssl_seterror-handling-ssl_error_syscall.patch deleted file mode 100644 index e9b2851..0000000 --- a/00462-fix-pyssl_seterror-handling-ssl_error_syscall.patch +++ /dev/null @@ -1,196 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: yevgeny hong -Date: Tue, 26 Mar 2024 16:45:43 +0900 -Subject: 00462: Fix PySSL_SetError handling SSL_ERROR_SYSCALL - -Python 3.10 changed from using SSL_write() and SSL_read() to SSL_write_ex() and -SSL_read_ex(), but did not update handling of the return value. - -Change error handling so that the return value is not examined. -OSError (not EOF) is now returned when retval is 0. - -This resolves the issue of failing tests when a system is -stressed on OpenSSL 3.5. - -Co-authored-by: Serhiy Storchaka -Co-authored-by: Petr Viktorin ---- - Lib/test/test_ssl.py | 28 ++++++----- - ...-02-18-09-50-31.gh-issue-115627.HGchj0.rst | 2 + - Modules/_ssl.c | 48 +++++++------------ - 3 files changed, 35 insertions(+), 43 deletions(-) - create mode 100644 Misc/NEWS.d/next/Library/2024-02-18-09-50-31.gh-issue-115627.HGchj0.rst - -diff --git a/Lib/test/test_ssl.py b/Lib/test/test_ssl.py -index aa8ce81db6..61cde99753 100644 ---- a/Lib/test/test_ssl.py -+++ b/Lib/test/test_ssl.py -@@ -2635,16 +2635,18 @@ def run(self): - self.write(msg.lower()) - except OSError as e: - # handles SSLError and socket errors -+ if isinstance(e, ConnectionError): -+ # OpenSSL 1.1.1 sometimes raises -+ # ConnectionResetError when connection is not -+ # shut down gracefully. -+ if self.server.chatty and support.verbose: -+ print(f" Connection reset by peer: {self.addr}") -+ -+ self.close() -+ self.running = False -+ return - if self.server.chatty and support.verbose: -- if isinstance(e, ConnectionError): -- # OpenSSL 1.1.1 sometimes raises -- # ConnectionResetError when connection is not -- # shut down gracefully. -- print( -- f" Connection reset by peer: {self.addr}" -- ) -- else: -- handle_error("Test server failure:\n") -+ handle_error("Test server failure:\n") - try: - self.write(b"ERROR\n") - except OSError: -@@ -3339,8 +3341,8 @@ def test_wrong_cert_tls13(self): - suppress_ragged_eofs=False) as s: - s.connect((HOST, server.port)) - with self.assertRaisesRegex( -- ssl.SSLError, -- 'alert unknown ca|EOF occurred' -+ OSError, -+ 'alert unknown ca|EOF occurred|TLSV1_ALERT_UNKNOWN_CA|closed by the remote host|Connection reset by peer' - ): - # TLS 1.3 perform client cert exchange after handshake - s.write(b'data') -@@ -4612,8 +4614,8 @@ def msg_cb(conn, direction, version, content_type, msg_type, data): - # test sometimes fails with EOF error. Test passes as long as - # server aborts connection with an error. - with self.assertRaisesRegex( -- ssl.SSLError, -- '(certificate required|EOF occurred)' -+ OSError, -+ 'certificate required|EOF occurred|closed by the remote host|Connection reset by peer' - ): - # receive CertificateRequest - data = s.recv(1024) -diff --git a/Misc/NEWS.d/next/Library/2024-02-18-09-50-31.gh-issue-115627.HGchj0.rst b/Misc/NEWS.d/next/Library/2024-02-18-09-50-31.gh-issue-115627.HGchj0.rst -new file mode 100644 -index 0000000000..75d926ab59 ---- /dev/null -+++ b/Misc/NEWS.d/next/Library/2024-02-18-09-50-31.gh-issue-115627.HGchj0.rst -@@ -0,0 +1,2 @@ -+Fix the :mod:`ssl` module error handling of connection terminate by peer. -+It now throws an OSError with the appropriate error code instead of an EOFError. -diff --git a/Modules/_ssl.c b/Modules/_ssl.c -index 9c2e8c391d..174e5dfce5 100644 ---- a/Modules/_ssl.c -+++ b/Modules/_ssl.c -@@ -576,7 +576,7 @@ PySSL_ChainExceptions(PySSLSocket *sslsock) { - } - - static PyObject * --PySSL_SetError(PySSLSocket *sslsock, int ret, const char *filename, int lineno) -+PySSL_SetError(PySSLSocket *sslsock, const char *filename, int lineno) - { - PyObject *type; - char *errstr = NULL; -@@ -589,7 +589,6 @@ PySSL_SetError(PySSLSocket *sslsock, int ret, const char *filename, int lineno) - _sslmodulestate *state = get_state_sock(sslsock); - type = state->PySSLErrorObject; - -- assert(ret <= 0); - e = ERR_peek_last_error(); - - if (sslsock->ssl != NULL) { -@@ -622,32 +621,21 @@ PySSL_SetError(PySSLSocket *sslsock, int ret, const char *filename, int lineno) - case SSL_ERROR_SYSCALL: - { - if (e == 0) { -- PySocketSockObject *s = GET_SOCKET(sslsock); -- if (ret == 0 || (((PyObject *)s) == Py_None)) { -+ /* underlying BIO reported an I/O error */ -+ ERR_clear_error(); -+#ifdef MS_WINDOWS -+ if (err.ws) { -+ return PyErr_SetFromWindowsErr(err.ws); -+ } -+#endif -+ if (err.c) { -+ errno = err.c; -+ return PyErr_SetFromErrno(PyExc_OSError); -+ } -+ else { - p = PY_SSL_ERROR_EOF; - type = state->PySSLEOFErrorObject; - errstr = "EOF occurred in violation of protocol"; -- } else if (s && ret == -1) { -- /* underlying BIO reported an I/O error */ -- ERR_clear_error(); --#ifdef MS_WINDOWS -- if (err.ws) { -- return PyErr_SetFromWindowsErr(err.ws); -- } --#endif -- if (err.c) { -- errno = err.c; -- return PyErr_SetFromErrno(PyExc_OSError); -- } -- else { -- p = PY_SSL_ERROR_EOF; -- type = state->PySSLEOFErrorObject; -- errstr = "EOF occurred in violation of protocol"; -- } -- } else { /* possible? */ -- p = PY_SSL_ERROR_SYSCALL; -- type = state->PySSLSyscallErrorObject; -- errstr = "Some I/O error occurred"; - } - } else { - if (ERR_GET_LIB(e) == ERR_LIB_SSL && -@@ -1013,7 +1001,7 @@ _ssl__SSLSocket_do_handshake_impl(PySSLSocket *self) - err.ssl == SSL_ERROR_WANT_WRITE); - Py_XDECREF(sock); - if (ret < 1) -- return PySSL_SetError(self, ret, __FILE__, __LINE__); -+ return PySSL_SetError(self, __FILE__, __LINE__); - if (PySSL_ChainExceptions(self) < 0) - return NULL; - Py_RETURN_NONE; -@@ -2434,7 +2422,7 @@ _ssl__SSLSocket_write_impl(PySSLSocket *self, Py_buffer *b) - - Py_XDECREF(sock); - if (retval == 0) -- return PySSL_SetError(self, retval, __FILE__, __LINE__); -+ return PySSL_SetError(self, __FILE__, __LINE__); - if (PySSL_ChainExceptions(self) < 0) - return NULL; - return PyLong_FromSize_t(count); -@@ -2464,7 +2452,7 @@ _ssl__SSLSocket_pending_impl(PySSLSocket *self) - self->err = err; - - if (count < 0) -- return PySSL_SetError(self, count, __FILE__, __LINE__); -+ return PySSL_SetError(self, __FILE__, __LINE__); - else - return PyLong_FromLong(count); - } -@@ -2587,7 +2575,7 @@ _ssl__SSLSocket_read_impl(PySSLSocket *self, Py_ssize_t len, - err.ssl == SSL_ERROR_WANT_WRITE); - - if (retval == 0) { -- PySSL_SetError(self, retval, __FILE__, __LINE__); -+ PySSL_SetError(self, __FILE__, __LINE__); - goto error; - } - if (self->exc_type != NULL) -@@ -2713,7 +2701,7 @@ _ssl__SSLSocket_shutdown_impl(PySSLSocket *self) - } - if (ret < 0) { - Py_XDECREF(sock); -- PySSL_SetError(self, ret, __FILE__, __LINE__); -+ PySSL_SetError(self, __FILE__, __LINE__); - return NULL; - } - if (self->exc_type != NULL) diff --git a/00474-cve-2025-15366.patch b/00474-cve-2025-15366.patch deleted file mode 100644 index 0e474a4..0000000 --- a/00474-cve-2025-15366.patch +++ /dev/null @@ -1,61 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Seth Michael Larson -Date: Tue, 20 Jan 2026 14:45:42 -0600 -Subject: 00474: CVE-2025-15366 - -gh-143921: Reject control characters in IMAP commands - -(cherry-picked from commit 6262704b134db2a4ba12e85ecfbd968534f28b45) ---- - Lib/imaplib.py | 4 +++- - Lib/test/test_imaplib.py | 6 ++++++ - .../Security/2026-01-16-11-41-06.gh-issue-143921.AeCOor.rst | 1 + - 3 files changed, 10 insertions(+), 1 deletion(-) - create mode 100644 Misc/NEWS.d/next/Security/2026-01-16-11-41-06.gh-issue-143921.AeCOor.rst - -diff --git a/Lib/imaplib.py b/Lib/imaplib.py -index 20b86c35d3..bc7628d17a 100644 ---- a/Lib/imaplib.py -+++ b/Lib/imaplib.py -@@ -132,7 +132,7 @@ - # We compile these in _mode_xxx. - _Literal = br'.*{(?P\d+)}$' - _Untagged_status = br'\* (?P\d+) (?P[A-Z-]+)( (?P.*))?' -- -+_control_chars = re.compile(b'[\x00-\x1F\x7F]') - - - class IMAP4: -@@ -994,6 +994,8 @@ def _command(self, name, *args): - if arg is None: continue - if isinstance(arg, str): - arg = bytes(arg, self._encoding) -+ if _control_chars.search(arg): -+ raise ValueError("Control characters not allowed in commands") - data = data + b' ' + arg - - literal = self.literal -diff --git a/Lib/test/test_imaplib.py b/Lib/test/test_imaplib.py -index 7665532d01..caf0884719 100644 ---- a/Lib/test/test_imaplib.py -+++ b/Lib/test/test_imaplib.py -@@ -510,6 +510,12 @@ def test_login(self): - self.assertEqual(data[0], b'LOGIN completed') - self.assertEqual(client.state, 'AUTH') - -+ def test_control_characters(self): -+ client, _ = self._setup(SimpleIMAPHandler) -+ for c0 in support.control_characters_c0(): -+ with self.assertRaises(ValueError): -+ client.login(f'user{c0}', 'pass') -+ - def test_logout(self): - client, _ = self._setup(SimpleIMAPHandler) - typ, data = client.login('user', 'pass') -diff --git a/Misc/NEWS.d/next/Security/2026-01-16-11-41-06.gh-issue-143921.AeCOor.rst b/Misc/NEWS.d/next/Security/2026-01-16-11-41-06.gh-issue-143921.AeCOor.rst -new file mode 100644 -index 0000000000..4e13fe92bc ---- /dev/null -+++ b/Misc/NEWS.d/next/Security/2026-01-16-11-41-06.gh-issue-143921.AeCOor.rst -@@ -0,0 +1 @@ -+Reject control characters in IMAP commands. diff --git a/00475-cve-2025-15367.patch b/00475-cve-2025-15367.patch deleted file mode 100644 index eab4dec..0000000 --- a/00475-cve-2025-15367.patch +++ /dev/null @@ -1,61 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Seth Michael Larson -Date: Tue, 20 Jan 2026 14:46:32 -0600 -Subject: 00475: CVE-2025-15367 - -gh-143923: Reject control characters in POP3 commands - -(cherry-picked from commit b234a2b67539f787e191d2ef19a7cbdce32874e7) ---- - Lib/poplib.py | 2 ++ - Lib/test/test_poplib.py | 8 ++++++++ - .../2026-01-16-11-43-47.gh-issue-143923.DuytMe.rst | 1 + - 3 files changed, 11 insertions(+) - create mode 100644 Misc/NEWS.d/next/Security/2026-01-16-11-43-47.gh-issue-143923.DuytMe.rst - -diff --git a/Lib/poplib.py b/Lib/poplib.py -index 0f8587317c..f563030f7f 100644 ---- a/Lib/poplib.py -+++ b/Lib/poplib.py -@@ -122,6 +122,8 @@ def _putline(self, line): - def _putcmd(self, line): - if self._debugging: print('*cmd*', repr(line)) - line = bytes(line, self.encoding) -+ if re.search(b'[\x00-\x1F\x7F]', line): -+ raise ValueError('Control characters not allowed in commands') - self._putline(line) - - -diff --git a/Lib/test/test_poplib.py b/Lib/test/test_poplib.py -index 49ba993197..b56bc3535e 100644 ---- a/Lib/test/test_poplib.py -+++ b/Lib/test/test_poplib.py -@@ -12,6 +12,7 @@ - import unittest - from unittest import TestCase, skipUnless - from test import support as test_support -+from test.support import control_characters_c0 - from test.support import hashlib_helper - from test.support import socket_helper - from test.support import threading_helper -@@ -367,6 +368,13 @@ def test_quit(self): - self.assertIsNone(self.client.sock) - self.assertIsNone(self.client.file) - -+ def test_control_characters(self): -+ for c0 in control_characters_c0(): -+ with self.assertRaises(ValueError): -+ self.client.user(f'user{c0}') -+ with self.assertRaises(ValueError): -+ self.client.pass_(f'{c0}pass') -+ - @requires_ssl - def test_stls_capa(self): - capa = self.client.capa() -diff --git a/Misc/NEWS.d/next/Security/2026-01-16-11-43-47.gh-issue-143923.DuytMe.rst b/Misc/NEWS.d/next/Security/2026-01-16-11-43-47.gh-issue-143923.DuytMe.rst -new file mode 100644 -index 0000000000..3cde4df3e0 ---- /dev/null -+++ b/Misc/NEWS.d/next/Security/2026-01-16-11-43-47.gh-issue-143923.DuytMe.rst -@@ -0,0 +1 @@ -+Reject control characters in POP3 commands. diff --git a/00494-increase-the-timeout-of-test_large_content_length_truncated.patch b/00494-increase-the-timeout-of-test_large_content_length_truncated.patch deleted file mode 100644 index 229b73a..0000000 --- a/00494-increase-the-timeout-of-test_large_content_length_truncated.patch +++ /dev/null @@ -1,23 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Karolina Surma -Date: Fri, 14 Aug 2026 09:38:26 +0200 -Subject: 00494: Increase the timeout of test_large_content_length_truncated - -It has started to fail randomly when run on s390x architecture. ---- - Lib/test/test_httpservers.py | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/Lib/test/test_httpservers.py b/Lib/test/test_httpservers.py -index b0b09daab0..59434936b7 100644 ---- a/Lib/test/test_httpservers.py -+++ b/Lib/test/test_httpservers.py -@@ -899,7 +899,7 @@ def test_large_content_length(self): - self.assertEqual(res.read(), b'%d %d' % (size, size) + self.linesep) - - def test_large_content_length_truncated(self): -- with support.swap_attr(self.request_handler, 'timeout', 0.001): -+ with support.swap_attr(self.request_handler, 'timeout', support.LOOPBACK_TIMEOUT): - for w in range(18, 65): - size = 1 << w - headers = {'Content-Length' : str(size)} diff --git a/check-pyc-timestamps.py b/check-pyc-timestamps.py index 0497eca..91af4fd 100644 --- a/check-pyc-timestamps.py +++ b/check-pyc-timestamps.py @@ -16,12 +16,14 @@ LEVELS = (None, 1, 2) # list of globs of test and other files that we expect not to have bytecode not_compiled = [ '/usr/bin/*', - '*/test/*/bad_coding.py', - '*/test/*/bad_coding2.py', - '*/test/*/badsyntax_*.py', - '*/lib2to3/tests/data/*.py', - '*/lib2to3/tests/data/*/*.py', - '*/lib2to3/tests/data/*/*/*.py', + '*/test/bad_coding.py', + '*/test/bad_coding2.py', + '*/test/badsyntax_*.py', + '*/lib2to3/tests/data/bom.py', + '*/lib2to3/tests/data/crlf.py', + '*/lib2to3/tests/data/different_encoding.py', + '*/lib2to3/tests/data/false_encoding.py', + '*/lib2to3/tests/data/py2_test_grammar.py', '*.debug-gdb.py', ] diff --git a/plan.fmf b/plan.fmf deleted file mode 100644 index c4ea482..0000000 --- a/plan.fmf +++ /dev/null @@ -1,66 +0,0 @@ -execute: - how: tmt - -provision: - hardware: - memory: '>= 3 GB' - -environment: - pybasever: '3.11' - -discover: - - name: tests_python - how: shell - url: https://src.fedoraproject.org/tests/python.git - tests: - - name: smoke - path: /smoke - test: "VERSION=${pybasever} ./venv.sh" - - name: smoke_virtualenv - path: /smoke - test: "VERSION=${pybasever} METHOD=virtualenv ./venv.sh" - - name: debugsmoke - path: /smoke - test: "PYTHON=python${pybasever}d TOX=false VERSION=${pybasever} ./venv.sh" - - name: selftest - path: /selftest - test: "VERSION=${pybasever} X='-i test_check_probes' ./parallel.sh" - - name: debugtest - path: /selftest - test: "VERSION=${pybasever} PYTHON=python${pybasever}d X='-i test_check_probes' ./parallel.sh" - - name: debugflags - path: /flags - test: "python${pybasever}d ./assertflags.py -O0" - - name: marshalparser - path: /marshalparser - test: "VERSION=${pybasever} SAMPLE=10 ./test_marshalparser_compatibility.sh" - - name: required_symbols - path: /required-symbols - test: "VERSION=${pybasever} ./check.sh" - -prepare: - - name: Install dependencies - how: install - package: - - gcc # for extension building in venv and selftest - - gdb # for test_gdb - - gcc-c++ # for test_cppext - - "python${pybasever}" # the test subject - - "python${pybasever}-debug" # for leak testing - - "python${pybasever}-devel" # for extension building in venv and selftest - - "python${pybasever}-tkinter" # for selftest - - "python${pybasever}-test" # for selftest - - tox # for venv tests - - virtualenv # for virtualenv tests - - glibc-all-langpacks # for locale tests - - marshalparser # for testing compatibility (magic numbers) with marshalparser - - binutils # for nm (symbol inspection) - - rpm # for debugging - - dnf # for upgrade and downgrade - - name: Update packages - how: shell - script: dnf upgrade -y - - name: rpm_qa - order: 100 - how: shell - script: rpm -qa | sort | tee $TMT_PLAN_DATA/rpmqa.txt diff --git a/python3.11.spec b/python3.11.spec index a736a7b..8f48027 100644 --- a/python3.11.spec +++ b/python3.11.spec @@ -13,7 +13,7 @@ URL: https://www.python.org/ # WARNING When rebasing to a new Python version, # remember to update the python3-docs package as well -%global general_version %{pybasever}.16 +%global general_version %{pybasever}.1 #global prerel ... %global upstream_version %{general_version}%{?prerel} Version: %{general_version}%{?prerel:~%{prerel}} @@ -67,8 +67,8 @@ License: Python-2.0.1 # If the rpmwheels condition is disabled, we use the bundled wheel packages # from Python with the versions below. # This needs to be manually updated when we update Python. -%global pip_version 24.0 -%global setuptools_version 79.0.1 +%global pip_version 22.3.1 +%global setuptools_version 65.5.0 # Expensive optimizations (mainly, profile-guided optimizations) %bcond_without optimizations @@ -175,12 +175,6 @@ Obsoletes: python%{pybasever}%{?1:-%{1}}\ %define unversioned_obsoletes_of_python3_X_if_main() %{nil} %endif -# Opt-out from https://fedoraproject.org/wiki/Changes/fno-omit-frame-pointer -# Python is slower with frame pointers, but we expect to remove this in Python 3.12+ -# See https://lists.fedoraproject.org/archives/list/python-devel@lists.fedoraproject.org/thread/6TQYCHMX4FZLF27U5BCEC7IFV6XNBKJP/ -# Tracking bugzilla: https://bugzilla.redhat.com/2158729 -%undefine _include_frame_pointers - # ======================= # Build-time requirements # ======================= @@ -205,20 +199,18 @@ BuildRequires: glibc-devel BuildRequires: gmp-devel BuildRequires: gnupg2 BuildRequires: libappstream-glib -%if %{undefined rhel} BuildRequires: libb2-devel -%endif BuildRequires: libffi-devel BuildRequires: libnsl2-devel BuildRequires: libtirpc-devel BuildRequires: libGL-devel BuildRequires: libuuid-devel -BuildRequires: libxcrypt-devel BuildRequires: libX11-devel BuildRequires: make BuildRequires: mpdecimal-devel BuildRequires: ncurses-devel +BuildRequires: openssl-devel BuildRequires: pkgconfig BuildRequires: readline-devel BuildRequires: redhat-rpm-config >= 127 @@ -226,15 +218,11 @@ BuildRequires: sqlite-devel BuildRequires: gdb BuildRequires: tar -BuildRequires: tcl-devel < 1:9 +BuildRequires: tcl-devel BuildRequires: tix-devel -BuildRequires: tk-devel < 1:9 +BuildRequires: tk-devel BuildRequires: tzdata -# Support for OpenSSL 4 only landed in Python 3.15 for now -# https://github.com/python/cpython/issues/146207 -BuildRequires: (openssl-devel < 1:4 or openssl3-devel) - %if %{with valgrind} BuildRequires: valgrind-devel %endif @@ -242,7 +230,6 @@ BuildRequires: valgrind-devel BuildRequires: xz-devel BuildRequires: zlib-devel -BuildRequires: systemtap-sdt-devel BuildRequires: /usr/bin/dtrace # workaround http://bugs.python.org/issue19804 (test_uuid requires ifconfig) @@ -251,9 +238,6 @@ BuildRequires: /usr/sbin/ifconfig %if %{with rpmwheels} BuildRequires: %{python_wheel_pkg_prefix}-setuptools-wheel BuildRequires: %{python_wheel_pkg_prefix}-pip-wheel -%else -# For %%python_wheel_inject_sbom -BuildRequires: python-rpm-macros %endif %if %{without bootstrap} @@ -290,7 +274,6 @@ Source11: idle3.appdata.xml # 00001 # d06a8853cf4bae9e115f45e1d531d2dc152c5cc8 # Fixup distutils/unixccompiler.py to remove standard library path from rpath -# # Was Patch0 in ivazquez' python3000 specfile Patch1: 00001-rpath.patch @@ -315,6 +298,20 @@ Patch1: 00001-rpath.patch # pypa/distutils integration: https://github.com/pypa/distutils/pull/70 Patch251: 00251-change-user-install-location.patch +# 00328 # 318e500c98f5e59eb1f23e0fcd32db69b9bd17e1 +# Restore pyc to TIMESTAMP invalidation mode as default in rpmbuild +# +# Since Fedora 31, the $SOURCE_DATE_EPOCH is set in rpmbuild to the latest +# %%changelog date. This makes Python default to the CHECKED_HASH pyc +# invalidation mode, bringing more reproducible builds traded for an import +# performance decrease. To avoid that, we don't default to CHECKED_HASH +# when $RPM_BUILD_ROOT is set (i.e. when we are building RPM packages). +# +# See https://src.fedoraproject.org/rpms/redhat-rpm-config/pull-request/57#comment-27426 +# Downstream only: only used when building RPM packages +# Ideally, we should talk to upstream and explain why we don't want this +Patch328: 00328-pyc-timestamp-invalidation-mode.patch + # 00371 # c1754d9c2750f89cb702e1b63a99201f5f7cff00 # Revert "bpo-1596321: Fix threading._shutdown() for the main thread (GH-28549) (GH-28589)" # @@ -326,53 +323,6 @@ Patch251: 00251-change-user-install-location.patch # https://github.com/GrahamDumpleton/mod_wsgi/issues/730 Patch371: 00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch -# 00452 # eb11d070c5af7d1b5e47f4e02186152d08eaf793 -# Properly apply exported CFLAGS for dtrace/systemtap builds -# -# When using --with-dtrace the resulting object file could be missing -# specific CFLAGS exported by the build system due to the systemtap -# script using specific defaults. -# -# Exporting the CC and CFLAGS variables before the dtrace invocation -# allows us to properly apply CFLAGS exported by the build system -# even when cross-compiling. -Patch452: 00452-properly-apply-exported-cflags-for-dtrace-systemtap-builds.patch - -# 00462 # c9db492d8924b2d1a0991e36f3c2b4f9c2ec8942 -# Fix PySSL_SetError handling SSL_ERROR_SYSCALL -# -# Python 3.10 changed from using SSL_write() and SSL_read() to SSL_write_ex() and -# SSL_read_ex(), but did not update handling of the return value. -# -# Change error handling so that the return value is not examined. -# OSError (not EOF) is now returned when retval is 0. -# -# This resolves the issue of failing tests when a system is -# stressed on OpenSSL 3.5. -Patch462: 00462-fix-pyssl_seterror-handling-ssl_error_syscall.patch - -# 00474 # 837ddca0372fa87ff9cee47142200caa21e77def -# CVE-2025-15366 -# -# gh-143921: Reject control characters in IMAP commands -# -# (cherry-picked from commit 6262704b134db2a4ba12e85ecfbd968534f28b45) -Patch474: 00474-cve-2025-15366.patch - -# 00475 # 3748209a316662d4e85981ca1a7418547a1d25c6 -# CVE-2025-15367 -# -# gh-143923: Reject control characters in POP3 commands -# -# (cherry-picked from commit b234a2b67539f787e191d2ef19a7cbdce32874e7) -Patch475: 00475-cve-2025-15367.patch - -# 00494 # 430aab133397ed44cc9ee621fd311e02fee317b5 -# Increase the timeout of test_large_content_length_truncated -# -# It has started to fail randomly when run on s390x architecture. -Patch494: 00494-increase-the-timeout-of-test_large_content_length_truncated.patch - # (New patches go here ^^^) # # When adding new patches to "python" and "python3" in Fedora, EL, etc., @@ -492,8 +442,6 @@ This package contains /usr/bin/python - the "python" command that runs Python 3. %package -n %{pkgname}-libs Summary: Python runtime libraries -# Bundled libb2 is CC0, covered by grandfathering exception -License: Python-2.0.1 AND CC0-1.0 %if %{with rpmwheels} Requires: %{python_wheel_pkg_prefix}-setuptools-wheel @@ -505,10 +453,6 @@ Provides: bundled(python3dist(setuptools)) = %{setuptools_version} %unversioned_obsoletes_of_python3_X_if_main libs -# Bundled internal headers are used even when building with system libb2 -# last updated by https://github.com/python/cpython/pull/6286 -Provides: bundled(libb2) = 0.98.1 - # There are files in the standard library that have python shebang. # We've filtered the automatic requirement out so libs are installable without # the main package. This however makes it pulled in by default. @@ -523,26 +467,6 @@ Recommends: (%{pkgname}-tkinter%{?_isa} = %{version}-%{release} if tk%{?_isa}) # The zoneinfo module needs tzdata Requires: tzdata -# The requirement on libexpat is generated, but we need to version it. -# When built with a specific expat version, but installed with an older one, -# we sometimes get: -# ImportError: /usr/lib64/python3.X/lib-dynload/pyexpat.cpython-....so: -# undefined symbol: XML_... -# The pyexpat module has build-time checks for expat version to only use the -# available symbols. However, there is no runtime protection, so when the module -# is later installed with an older expat, it may error due to undefined symbols. -# This breaks many things, including python -m venv. -# We avoid this problem by requiring at least the same version of expat that -# was used during the build time. -# Other subpackages (like -debug) also need this, but they all depend on -libs. -# Since expat 2.7.4, the library has versioned symbols and this is no longer needed, -# as the generated requirement will be in the form of libexpat.so.1(LIBEXPAT_2.7.2) etc. -%global expat_version %(LANG=C rpm -q --qf '%%{version}' expat.%{_target_cpu} | sed 's/.*not installed/0/') -%if v"%{expat_version}" < v"2.7.4" -Requires: expat%{?_isa} >= %{expat_version} -%endif - - %description -n %{pkgname}-libs This package contains runtime libraries for use by Python: - the majority of the Python standard library @@ -558,11 +482,7 @@ Requires: %{pkgname}-libs%{?_isa} = %{version}-%{release} # But we want them when packages BuildRequire python3-devel Requires: (python-rpm-macros if rpm-build) Requires: (python3-rpm-macros if rpm-build) -# We omit this dependency on RHEL to avoid pulling the macros to AppStream: -# RHEL users can use the minimal implementation of %%pyproject_buildrequires -# from pyproject-srpm-macros instead. -# On Fedora, we keep this to avoid one additional round of %%generate_buildrequires. -%{!?rhel:Requires: (pyproject-rpm-macros if rpm-build)} +Requires: (pyproject-rpm-macros if rpm-build) %unversioned_obsoletes_of_python3_X_if_main devel @@ -754,15 +674,14 @@ topdir=$(pwd) # Standard library built here will still use the %%build_...flags, # Fedora packages utilizing %%py3_build will use them as well # https://fedoraproject.org/wiki/Changes/Python_Extension_Flags -# https://fedoraproject.org/wiki/Changes/Python_Extension_Flags_Reduction -export CFLAGS="%{extension_cflags}" +export CFLAGS="%{extension_cflags} -D_GNU_SOURCE -fPIC -fwrapv" export CFLAGS_NODIST="%{build_cflags} -D_GNU_SOURCE -fPIC -fwrapv" -export CXXFLAGS="%{extension_cxxflags}" +export CXXFLAGS="%{extension_cxxflags} -D_GNU_SOURCE -fPIC -fwrapv" export CPPFLAGS="$(pkg-config --cflags-only-I libffi)" -export OPT="%{extension_cflags}" +export OPT="%{extension_cflags} -D_GNU_SOURCE -fPIC -fwrapv" export LINKCC="gcc" export CFLAGS="$CFLAGS $(pkg-config --cflags openssl)" -export LDFLAGS="%{extension_ldflags} $(pkg-config --libs-only-L openssl)" +export LDFLAGS="%{extension_ldflags} -g $(pkg-config --libs-only-L openssl)" export LDFLAGS_NODIST="%{build_ldflags} -g $(pkg-config --libs-only-L openssl)" # We can build several different configurations of Python: regular and debug. @@ -1026,25 +945,15 @@ find . -name "*~" -exec rm -f {} \; # Python CMD line options: # -s - don't add user site directory to sys.path # -B - don't write .pyc files on import -# Clamp the source mtime first, see https://fedoraproject.org/wiki/Changes/ReproducibleBuildsClampMtimes -# The clamp_source_mtime module is only guaranteed to exist on Fedoras that enabled this option: -%if 0%{?clamp_mtime_to_source_date_epoch} -LD_LIBRARY_PATH="%{buildroot}%{dynload_dir}/:%{buildroot}%{_libdir}" \ -PYTHONPATH="%{_rpmconfigdir}/redhat" \ -%{buildroot}%{_bindir}/python%{pybasever} -s -B -m clamp_source_mtime %{buildroot}%{pylibdir} -%endif # compileall CMD line options: # -f - force rebuild even if timestamps are up to date # -o - optimization levels to run compilation with # -s - part of path to left-strip from path to source file (buildroot) # -p - path to add as prefix to path to source file (/ to make it absolute) # --hardlink-dupes - hardlink different optimization level pycs together if identical (saves space) -# --invalidation-mode - we prefer the timestamp invalidation mode for performance reasons -# -x - skip test modules with SyntaxErrors (taken from the Makefile) LD_LIBRARY_PATH="%{buildroot}%{dynload_dir}/:%{buildroot}%{_libdir}" \ %{buildroot}%{_bindir}/python%{pybasever} -s -B -m compileall \ --f %{_smp_mflags} -o 0 -o 1 -o 2 -s %{buildroot} -p / %{buildroot} --hardlink-dupes --invalidation-mode=timestamp \ --x 'bad_coding|badsyntax|site-packages|lib2to3/tests/data' +-f %{_smp_mflags} -o 0 -o 1 -o 2 -s %{buildroot} -p / %{buildroot} --hardlink-dupes || : # Turn this BRP off, it is done by compileall2 --hardlink-dupes above %global __brp_python_hardlink %{nil} @@ -1102,11 +1011,6 @@ for file in %{buildroot}%{pylibdir}/pydoc_data/topics.py $(grep --include='*.py' rm ${directory}/{__pycache__/${module}.cpython-%{pyshortver}.opt-?.pyc,${module}.py} done -%if %{without rpmwheels} -# Inject SBOM into the installed wheels (if the macro is available) -%{?python_wheel_inject_sbom:%python_wheel_inject_sbom %{buildroot}%{pylibdir}/ensurepip/_bundled/*.whl} -%endif - # ====================================================== # Checks for packaging issues # ====================================================== @@ -1168,25 +1072,16 @@ CheckPython() { # test_freeze_simple_script is skipped, because it fails when bundled wheels # are removed in Fedora. # upstream report: https://bugs.python.org/issue45783 - # test_check_probes is failing since it was introduced in 3.12.0rc1, - # the test is skipped until it is fixed in upstream. - # see: https://github.com/python/cpython/issues/104280#issuecomment-1669249980 - # test_sendfile_close_peer_in_the_middle_of_receiving: - # https://github.com/python/cpython/issues/120226 LD_LIBRARY_PATH=$ConfDir $ConfDir/python -m test.regrtest \ -wW --slowest -j0 --timeout=1800 \ -i test_freeze_simple_script \ - -i test_check_probes \ %if %{with bootstrap} -x test_distutils \ %endif %ifarch %{mips64} -x test_ctypes \ %endif - %ifarch ppc64le - -i test_sendfile_close_peer_in_the_middle_of_receiving \ - %endif echo FINISHED: CHECKING OF PYTHON FOR CONFIGURATION: $ConfName @@ -1426,7 +1321,6 @@ CheckPython optimized %{pylibdir}/multiprocessing %dir %{pylibdir}/re/ -%dir %{pylibdir}/re/__pycache__/ %{pylibdir}/re/*.py %{pylibdir}/re/__pycache__/*%{bytecode_suffixes} @@ -1436,7 +1330,6 @@ CheckPython optimized %{pylibdir}/sqlite3/__pycache__/*%{bytecode_suffixes} %dir %{pylibdir}/tomllib/ -%dir %{pylibdir}/tomllib/__pycache__/ %{pylibdir}/tomllib/*.py %{pylibdir}/tomllib/__pycache__/*%{bytecode_suffixes} %exclude %{pylibdir}/turtle.py @@ -1446,8 +1339,7 @@ CheckPython optimized %{pylibdir}/xml %{pylibdir}/zoneinfo -%dir %{pylibdir}/__phello__/ -%dir %{pylibdir}/__phello__/__pycache__/ +%dir %{pylibdir}/__phello__ %{pylibdir}/__phello__/__init__.py %{pylibdir}/__phello__/spam.py %{pylibdir}/__phello__/__pycache__/*%{bytecode_suffixes} @@ -1545,7 +1437,6 @@ CheckPython optimized %{dynload_dir}/_ctypes_test.%{SOABI_optimized}.so %{dynload_dir}/_testbuffer.%{SOABI_optimized}.so %{dynload_dir}/_testcapi.%{SOABI_optimized}.so -%{dynload_dir}/_testclinic.%{SOABI_optimized}.so %{dynload_dir}/_testimportmultiple.%{SOABI_optimized}.so %{dynload_dir}/_testinternalcapi.%{SOABI_optimized}.so %{dynload_dir}/_testmultiphase.%{SOABI_optimized}.so @@ -1674,7 +1565,6 @@ CheckPython optimized %{dynload_dir}/_ctypes_test.%{SOABI_debug}.so %{dynload_dir}/_testbuffer.%{SOABI_debug}.so %{dynload_dir}/_testcapi.%{SOABI_debug}.so -%{dynload_dir}/_testclinic.%{SOABI_debug}.so %{dynload_dir}/_testimportmultiple.%{SOABI_debug}.so %{dynload_dir}/_testinternalcapi.%{SOABI_debug}.so %{dynload_dir}/_testmultiphase.%{SOABI_debug}.so @@ -1705,169 +1595,6 @@ CheckPython optimized # ====================================================== %changelog -* Thu Aug 13 2026 Karolina Surma - 3.11.16-1 -- Update to Python 3.11.16 - -* Thu Jul 30 2026 Miro Hrončok - 3.11.15-7 - - Skip UDP Lite tests if it's not supported - - Fixes FTBFS on Linux kernel 7.1 and newer - -* Thu Jul 16 2026 Fedora Release Engineering - 3.11.15-6 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild - -* Thu Jul 02 2026 Miro Hrončok - 3.11.15-5 -- Fix ssl.SSLError: [ASN1: NOT_ENOUGH_DATA] not enough data with OpenSSL 3.5.7+ - -* Fri Apr 17 2026 Charalampos Stratakis - 3.11.15-4 -- Security fixes for CVE-2026-1502, CVE-2026-4786, CVE-2026-6100, CVE-2026-2297, CVE 2026-3644, CVE-2026-4224 -Resolves: rhbz#2457941, rhbz#2458221, rhbz#2458013, rhbz#2444704, rhbz#2448188, rhbz#2448204 - -* Sat Apr 11 2026 Miro Hrončok - 3.11.15-3 -- Explicitly build with OpenSSL 3 - -* Thu Mar 26 2026 Lumír Balhar - 3.11.15-2 -- Security fix for CVE-2026-4519 (rhbz#2449727) - -* Tue Mar 03 2026 Tomáš Hrnčiar - 3.11.15-1 -- Update to 3.11.15 - -* Mon Feb 09 2026 Tomáš Hrnčiar - 3.11.14-5 -- Security fixes for CVE-2026-0865, CVE-2025-15366 and CVE-2025-15367 - -* Fri Jan 16 2026 Lumír Balhar - 3.11.14-4 -- Security fix for CVE-2025-13836 - -* Thu Jan 08 2026 Lumír Balhar - 3.11.14-3 -- Security fix for CVE-2025-12084 - -* Tue Jan 06 2026 Karolina Surma - 3.11.14-2 -- Require at least the same expat version as used during the build time - -* Fri Oct 10 2025 Karolina Surma - 3.11.14-1 -- Update to 3.11.14 - -* Fri Jul 25 2025 Fedora Release Engineering - 3.11.13-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild - -* Wed Jun 04 2025 Tomáš Hrnčiar - 3.11.13-1 -- Update to 3.11.13 - -* Tue May 13 2025 Charalampos Stratakis - 3.11.12-3 -- Fix PySSL_SetError handling SSL_ERROR_SYSCALL -- This fixes random flakiness of test_ssl on stressed machines - -* Wed Apr 16 2025 Charalampos Stratakis - 3.11.12-2 -- test_ssl: Don't stop ThreadedEchoServer on OSError in ConnectionHandler -- Fixes: rhbz#2355052 - -* Wed Apr 09 2025 Miro Hrončok - 3.11.12-1 -- Update to 3.11.12 - -* Mon Mar 31 2025 Charalampos Stratakis - 3.11.11-6 -- Properly apply exported CFLAGS for dtrace/systemtap builds -- Fixes: rhbz#2356302 - -* Mon Feb 10 2025 Charalampos Stratakis - 3.11.11-5 -- Security fix for CVE-2025-0938 -- Fixes: rhbz#2343272 - -* Thu Feb 06 2025 Miro Hrončok - 3.11.11-4 -- Rebuilt with mpdecimal 4.0.0 - -* Sat Feb 01 2025 Björn Esser - 3.11.11-3 -- Add explicit BR: libxcrypt-devel - -* Sat Jan 18 2025 Fedora Release Engineering - 3.11.11-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild - -* Tue Dec 03 2024 Lumír Balhar - 3.11.11-1 -- Update to 3.11.11 -- Fixes: rhbz#2321655 - -* Mon Sep 09 2024 Tomáš Hrnčiar - 3.11.10-1 -- Update to 3.11.10 - -* Fri Aug 23 2024 Charalampos Stratakis - 3.11.9-6 -- Security fix for CVE-2024-8088 -- Fixes: rhbz#2307460 - -* Thu Aug 15 2024 Charalampos Stratakis - 3.11.9-5 -- Security fix for CVE-2024-4032 (rhbz#2293391) -- Security fix for CVE-2024-6923 (rhbz#2303158) - -* Tue Jul 23 2024 Lumír Balhar - 3.11.9-4 -- Require systemtap-sdt-devel for sys/sdt.h - -* Fri Jul 19 2024 Fedora Release Engineering - 3.11.9-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild - -* Wed Apr 17 2024 Miro Hrončok - 3.11.9-2 -- Require expat >= 2.6 to prevent errors when creating venvs with older expat - -* Tue Apr 09 2024 Tomáš Hrnčiar - 3.11.9-1 -- Update to 3.11.9 - -* Wed Feb 28 2024 Charalampos Stratakis - 3.11.8-2 -- Fix tests for XMLPullParser with Expat 2.6.0 - -* Wed Feb 07 2024 Tomáš Hrnčiar - 3.11.8-1 -- Update to 3.11.8 - -* Fri Jan 26 2024 Fedora Release Engineering - 3.11.7-4 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild - -* Mon Jan 22 2024 Fedora Release Engineering - 3.11.7-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild - -* Mon Dec 18 2023 Lumír Balhar - 3.11.7-2 -- Security fix for CVE-2023-27043 (rhbz#2196188) - -* Wed Dec 06 2023 Tomáš Hrnčiar - 3.11.7-1 -- Update to 3.11.7 -- Own stray directories in /usr/lib64/python3.11 -- Fixes: rhbz#2252144 - -* Tue Oct 03 2023 Yaakov Selkowitz - 3.11.6-2 -- Use bundled libb2 in RHEL builds - -* Tue Oct 03 2023 Tomáš Hrnčiar - 3.11.6-1 -- Update to 3.11.6 - -* Mon Aug 28 2023 Tomáš Hrnčiar - 3.11.5-1 -- Update to 3.11.5 - -* Wed Aug 02 2023 Charalampos Stratakis - 3.11.4-4 -- Remove extra distro-applied CFLAGS passed to user built C extensions -- https://fedoraproject.org/wiki/Changes/Python_Extension_Flags_Reduction - -* Fri Jul 21 2023 Fedora Release Engineering - 3.11.4-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild - -* Tue Jun 13 2023 Python Maint - 3.11.4-2 -- Rebuilt for Python 3.12 - -* Wed Jun 07 2023 Tomáš Hrnčiar - 3.11.4-1 -- Update to 3.11.4 - -* Wed May 24 2023 Lumír Balhar - 3.11.3-2 -- Fix for CVE-2023-24329 - -* Wed Apr 05 2023 Tomáš Hrnčiar - 3.11.3-1 -- Update to 3.11.3 - -* Wed Feb 08 2023 Tomáš Hrnčiar - 3.11.2-1 -- Update to 3.11.2 - -* Fri Jan 20 2023 Fedora Release Engineering - 3.11.1-4 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild - -* Fri Jan 06 2023 Miro Hrončok - 3.11.1-3 -- Fix `asyncio` subprocess losing `stderr` and `stdout` output -- Remove any deprecation warnings in asyncio.get_event_loop() - -* Mon Dec 19 2022 Miro Hrončok - 3.11.1-2 -- No longer patch the default bytecode cache invalidation policy - * Wed Dec 07 2022 Tomáš Hrnčiar - 3.11.1-1 - Update to 3.11.1 diff --git a/rpminspect.yaml b/rpminspect.yaml index 8cc18cb..83dfb5e 100644 --- a/rpminspect.yaml +++ b/rpminspect.yaml @@ -1,22 +1,22 @@ # exclude test XML data (not always valid) from XML validity check: xml: ignore: - - '/usr/lib*/python*/test/xmltestdata/*' - - '/usr/lib*/python*/test/xmltestdata/*/*' + - /usr/lib*/python*/test/xmltestdata/* + - /usr/lib*/python*/test/xmltestdata/*/* # exclude _socket from ipv4 only functions check, it has both ipv4 and ipv6 only badfuncs: allowed: - '/usr/lib*/python*/lib-dynload/_socket.*': + /usr/lib*/python*/lib-dynload/_socket.*: - inet_aton - inet_ntoa # exclude the debug build from annocheck entirely annocheck: ignore: - - '/usr/bin/python*d' - - '/usr/lib*/libpython*d.so.1.0' - - '/usr/lib*/python*/lib-dynload/*.cpython-*d-*-*-*.so' + - /usr/bin/python*d + - /usr/lib*/libpython*d.so.1.0 + - /usr/lib*/python*/lib-dynload/*.cpython-*d-*-*-*.so # don't report changed content of compiled files # that is expected with every toolchain update and not reproducible yet diff --git a/sources b/sources index 737c40b..327dc94 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (Python-3.11.16.tar.xz) = f4e168d35596c2df080663d8e8b3472f03bace987d46b49b8410f2425ba193215b9880c7d03d4653ec31c83b72209d95866fc1cb6d666799145075b092f64a48 -SHA512 (Python-3.11.16.tar.xz.asc) = b31b3205e68951478fe76f4884a124ebb4955a711b6105754d4179acb48b16a5439ec8c35383a84787cd673fa1143f2f047c6d65944909b0f1a8e3c75a0e2efe +SHA512 (Python-3.11.1.tar.xz) = 5edd70c881e083c96199c60471f18f9ebc4c97a2d45dc66f89e16d7c3638d8a5d2cbf2e84b1be3d7f1178ce9f7fa4197884385c1ee3618ff66a538f872f318ed +SHA512 (Python-3.11.1.tar.xz.asc) = 81ed05c2adf38552bdc5ac761704f2720a646d56681a919a6bfa51f1a4b42cd14edb9c84d58664dbc8e7b561cd78d82ae6b10dda423e1fae543bc7fa4bf3f78e diff --git a/.fmf/version b/tests/.fmf/version similarity index 100% rename from .fmf/version rename to tests/.fmf/version diff --git a/tests/provision.fmf b/tests/provision.fmf new file mode 100644 index 0000000..1a4f0f0 --- /dev/null +++ b/tests/provision.fmf @@ -0,0 +1,4 @@ +--- +standard-inventory-qcow2: + qemu: + m: 3G # Amount of VM memory diff --git a/tests/tests.yml b/tests/tests.yml new file mode 100644 index 0000000..3f9165b --- /dev/null +++ b/tests/tests.yml @@ -0,0 +1,56 @@ +--- +- hosts: localhost + tags: + - classic + tasks: + - dnf: + name: "*" + state: latest + +- hosts: localhost + roles: + - role: standard-test-basic + tags: + - classic + repositories: + - repo: "https://src.fedoraproject.org/tests/python.git" + dest: "python" + pybasever: "3.11" + tests: + - rpm_qa: + run: rpm -qa + - smoke: + dir: python/smoke + run: "VERSION={{ pybasever }} ./venv.sh" + - smoke_virtualenv: + dir: python/smoke + run: "VERSION={{ pybasever }} METHOD=virtualenv ./venv.sh" + - debugsmoke: + dir: python/smoke + run: "PYTHON=python{{ pybasever }}d TOX=false VERSION={{ pybasever }} ./venv.sh" + - selftest: + dir: python/selftest + run: "VERSION={{ pybasever }} X='' ./parallel.sh" + - debugtest: + dir: python/selftest + run: "VERSION={{ pybasever }} PYTHON=python{{ pybasever }}d X='' ./parallel.sh" + - debugflags: + dir: python/flags + run: "python{{ pybasever }}d ./assertflags.py -O0" + - marshalparser: + dir: python/marshalparser + run: "VERSION={{ pybasever }} SAMPLE=10 test_marshalparser_compatibility.sh" + required_packages: + - gcc # for extension building in venv and selftest + - gcc-c++ # for test_cppext + - gdb # for test_gdb + - "python{{ pybasever }}" # the test subject + - "python{{ pybasever }}-debug" # for leak testing + - "python{{ pybasever }}-devel" # for extension building in venv and selftest + - "python{{ pybasever }}-tkinter" # for selftest + - "python{{ pybasever }}-test" # for selftest + - tox # for venv tests + - virtualenv # for virtualenv tests + - glibc-all-langpacks # for locale tests + - marshalparser # for testing compatibility (magic numbers) with marshalparser + - rpm # for debugging