diff --git a/00452-properly-apply-exported-cflags-for-dtrace-systemtap-builds.patch b/00452-properly-apply-exported-cflags-for-dtrace-systemtap-builds.patch index 3fea025..1417bdb 100644 --- a/00452-properly-apply-exported-cflags-for-dtrace-systemtap-builds.patch +++ b/00452-properly-apply-exported-cflags-for-dtrace-systemtap-builds.patch @@ -20,10 +20,10 @@ Co-authored-by: stratakis create mode 100644 Misc/NEWS.d/next/Build/2025-03-31-19-22-41.gh-issue-131865.PIJy7X.rst diff --git a/Makefile.pre.in b/Makefile.pre.in -index ad29e1a0ca..79b07194bb 100644 +index 81d4d50f82..0bd3447638 100644 --- a/Makefile.pre.in +++ b/Makefile.pre.in -@@ -1458,7 +1458,7 @@ Python/frozen.o: $(FROZEN_FILES_OUT) +@@ -1453,7 +1453,7 @@ Python/frozen.o: $(FROZEN_FILES_OUT) # an include guard, so we can't use a pipeline to transform its output. Include/pydtrace_probes.h: $(srcdir)/Include/pydtrace.d $(MKDIR_P) Include @@ -32,7 +32,7 @@ index ad29e1a0ca..79b07194bb 100644 : sed in-place edit with POSIX-only tools sed 's/PYTHON_/PyDTrace_/' $@ > $@.tmp mv $@.tmp $@ -@@ -1468,7 +1468,7 @@ Python/import.o: $(srcdir)/Include/pydtrace.h +@@ -1463,7 +1463,7 @@ Python/import.o: $(srcdir)/Include/pydtrace.h Modules/gcmodule.o: $(srcdir)/Include/pydtrace.h Python/pydtrace.o: $(srcdir)/Include/pydtrace.d $(DTRACE_DEPS) diff --git a/00462-fix-pyssl_seterror-handling-ssl_error_syscall.patch b/00462-fix-pyssl_seterror-handling-ssl_error_syscall.patch index e9b2851..43182ad 100644 --- a/00462-fix-pyssl_seterror-handling-ssl_error_syscall.patch +++ b/00462-fix-pyssl_seterror-handling-ssl_error_syscall.patch @@ -22,10 +22,10 @@ Co-authored-by: Petr Viktorin create mode 100644 Misc/NEWS.d/next/Library/2024-02-18-09-50-31.gh-issue-115627.HGchj0.rst diff --git a/Lib/test/test_ssl.py b/Lib/test/test_ssl.py -index aa8ce81db6..61cde99753 100644 +index 0b169c37d5..921c41bd0d 100644 --- a/Lib/test/test_ssl.py +++ b/Lib/test/test_ssl.py -@@ -2635,16 +2635,18 @@ def run(self): +@@ -2633,16 +2633,18 @@ def run(self): self.write(msg.lower()) except OSError as e: # handles SSLError and socket errors @@ -53,7 +53,7 @@ index aa8ce81db6..61cde99753 100644 try: self.write(b"ERROR\n") except OSError: -@@ -3339,8 +3341,8 @@ def test_wrong_cert_tls13(self): +@@ -3337,8 +3339,8 @@ def test_wrong_cert_tls13(self): suppress_ragged_eofs=False) as s: s.connect((HOST, server.port)) with self.assertRaisesRegex( @@ -64,7 +64,7 @@ index aa8ce81db6..61cde99753 100644 ): # TLS 1.3 perform client cert exchange after handshake s.write(b'data') -@@ -4612,8 +4614,8 @@ def msg_cb(conn, direction, version, content_type, msg_type, data): +@@ -4610,8 +4612,8 @@ def msg_cb(conn, direction, version, content_type, msg_type, data): # test sometimes fails with EOF error. Test passes as long as # server aborts connection with an error. with self.assertRaisesRegex( @@ -84,7 +84,7 @@ index 0000000000..75d926ab59 +Fix the :mod:`ssl` module error handling of connection terminate by peer. +It now throws an OSError with the appropriate error code instead of an EOFError. diff --git a/Modules/_ssl.c b/Modules/_ssl.c -index 9c2e8c391d..174e5dfce5 100644 +index 09207abde1..787c241133 100644 --- a/Modules/_ssl.c +++ b/Modules/_ssl.c @@ -576,7 +576,7 @@ PySSL_ChainExceptions(PySSLSocket *sslsock) { diff --git a/00474-cve-2025-15366.patch b/00474-cve-2025-15366.patch deleted file mode 100644 index 0e474a4..0000000 --- a/00474-cve-2025-15366.patch +++ /dev/null @@ -1,61 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Seth Michael Larson -Date: Tue, 20 Jan 2026 14:45:42 -0600 -Subject: 00474: CVE-2025-15366 - -gh-143921: Reject control characters in IMAP commands - -(cherry-picked from commit 6262704b134db2a4ba12e85ecfbd968534f28b45) ---- - Lib/imaplib.py | 4 +++- - Lib/test/test_imaplib.py | 6 ++++++ - .../Security/2026-01-16-11-41-06.gh-issue-143921.AeCOor.rst | 1 + - 3 files changed, 10 insertions(+), 1 deletion(-) - create mode 100644 Misc/NEWS.d/next/Security/2026-01-16-11-41-06.gh-issue-143921.AeCOor.rst - -diff --git a/Lib/imaplib.py b/Lib/imaplib.py -index 20b86c35d3..bc7628d17a 100644 ---- a/Lib/imaplib.py -+++ b/Lib/imaplib.py -@@ -132,7 +132,7 @@ - # We compile these in _mode_xxx. - _Literal = br'.*{(?P\d+)}$' - _Untagged_status = br'\* (?P\d+) (?P[A-Z-]+)( (?P.*))?' -- -+_control_chars = re.compile(b'[\x00-\x1F\x7F]') - - - class IMAP4: -@@ -994,6 +994,8 @@ def _command(self, name, *args): - if arg is None: continue - if isinstance(arg, str): - arg = bytes(arg, self._encoding) -+ if _control_chars.search(arg): -+ raise ValueError("Control characters not allowed in commands") - data = data + b' ' + arg - - literal = self.literal -diff --git a/Lib/test/test_imaplib.py b/Lib/test/test_imaplib.py -index 7665532d01..caf0884719 100644 ---- a/Lib/test/test_imaplib.py -+++ b/Lib/test/test_imaplib.py -@@ -510,6 +510,12 @@ def test_login(self): - self.assertEqual(data[0], b'LOGIN completed') - self.assertEqual(client.state, 'AUTH') - -+ def test_control_characters(self): -+ client, _ = self._setup(SimpleIMAPHandler) -+ for c0 in support.control_characters_c0(): -+ with self.assertRaises(ValueError): -+ client.login(f'user{c0}', 'pass') -+ - def test_logout(self): - client, _ = self._setup(SimpleIMAPHandler) - typ, data = client.login('user', 'pass') -diff --git a/Misc/NEWS.d/next/Security/2026-01-16-11-41-06.gh-issue-143921.AeCOor.rst b/Misc/NEWS.d/next/Security/2026-01-16-11-41-06.gh-issue-143921.AeCOor.rst -new file mode 100644 -index 0000000000..4e13fe92bc ---- /dev/null -+++ b/Misc/NEWS.d/next/Security/2026-01-16-11-41-06.gh-issue-143921.AeCOor.rst -@@ -0,0 +1 @@ -+Reject control characters in IMAP commands. diff --git a/00475-cve-2025-15367.patch b/00475-cve-2025-15367.patch deleted file mode 100644 index eab4dec..0000000 --- a/00475-cve-2025-15367.patch +++ /dev/null @@ -1,61 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Seth Michael Larson -Date: Tue, 20 Jan 2026 14:46:32 -0600 -Subject: 00475: CVE-2025-15367 - -gh-143923: Reject control characters in POP3 commands - -(cherry-picked from commit b234a2b67539f787e191d2ef19a7cbdce32874e7) ---- - Lib/poplib.py | 2 ++ - Lib/test/test_poplib.py | 8 ++++++++ - .../2026-01-16-11-43-47.gh-issue-143923.DuytMe.rst | 1 + - 3 files changed, 11 insertions(+) - create mode 100644 Misc/NEWS.d/next/Security/2026-01-16-11-43-47.gh-issue-143923.DuytMe.rst - -diff --git a/Lib/poplib.py b/Lib/poplib.py -index 0f8587317c..f563030f7f 100644 ---- a/Lib/poplib.py -+++ b/Lib/poplib.py -@@ -122,6 +122,8 @@ def _putline(self, line): - def _putcmd(self, line): - if self._debugging: print('*cmd*', repr(line)) - line = bytes(line, self.encoding) -+ if re.search(b'[\x00-\x1F\x7F]', line): -+ raise ValueError('Control characters not allowed in commands') - self._putline(line) - - -diff --git a/Lib/test/test_poplib.py b/Lib/test/test_poplib.py -index 49ba993197..b56bc3535e 100644 ---- a/Lib/test/test_poplib.py -+++ b/Lib/test/test_poplib.py -@@ -12,6 +12,7 @@ - import unittest - from unittest import TestCase, skipUnless - from test import support as test_support -+from test.support import control_characters_c0 - from test.support import hashlib_helper - from test.support import socket_helper - from test.support import threading_helper -@@ -367,6 +368,13 @@ def test_quit(self): - self.assertIsNone(self.client.sock) - self.assertIsNone(self.client.file) - -+ def test_control_characters(self): -+ for c0 in control_characters_c0(): -+ with self.assertRaises(ValueError): -+ self.client.user(f'user{c0}') -+ with self.assertRaises(ValueError): -+ self.client.pass_(f'{c0}pass') -+ - @requires_ssl - def test_stls_capa(self): - capa = self.client.capa() -diff --git a/Misc/NEWS.d/next/Security/2026-01-16-11-43-47.gh-issue-143923.DuytMe.rst b/Misc/NEWS.d/next/Security/2026-01-16-11-43-47.gh-issue-143923.DuytMe.rst -new file mode 100644 -index 0000000000..3cde4df3e0 ---- /dev/null -+++ b/Misc/NEWS.d/next/Security/2026-01-16-11-43-47.gh-issue-143923.DuytMe.rst -@@ -0,0 +1 @@ -+Reject control characters in POP3 commands. diff --git a/00494-increase-the-timeout-of-test_large_content_length_truncated.patch b/00494-increase-the-timeout-of-test_large_content_length_truncated.patch deleted file mode 100644 index 229b73a..0000000 --- a/00494-increase-the-timeout-of-test_large_content_length_truncated.patch +++ /dev/null @@ -1,23 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Karolina Surma -Date: Fri, 14 Aug 2026 09:38:26 +0200 -Subject: 00494: Increase the timeout of test_large_content_length_truncated - -It has started to fail randomly when run on s390x architecture. ---- - Lib/test/test_httpservers.py | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/Lib/test/test_httpservers.py b/Lib/test/test_httpservers.py -index b0b09daab0..59434936b7 100644 ---- a/Lib/test/test_httpservers.py -+++ b/Lib/test/test_httpservers.py -@@ -899,7 +899,7 @@ def test_large_content_length(self): - self.assertEqual(res.read(), b'%d %d' % (size, size) + self.linesep) - - def test_large_content_length_truncated(self): -- with support.swap_attr(self.request_handler, 'timeout', 0.001): -+ with support.swap_attr(self.request_handler, 'timeout', support.LOOPBACK_TIMEOUT): - for w in range(18, 65): - size = 1 << w - headers = {'Content-Length' : str(size)} diff --git a/plan.fmf b/plan.fmf index c4ea482..028bf63 100644 --- a/plan.fmf +++ b/plan.fmf @@ -34,9 +34,6 @@ discover: - name: marshalparser path: /marshalparser test: "VERSION=${pybasever} SAMPLE=10 ./test_marshalparser_compatibility.sh" - - name: required_symbols - path: /required-symbols - test: "VERSION=${pybasever} ./check.sh" prepare: - name: Install dependencies @@ -54,9 +51,8 @@ prepare: - virtualenv # for virtualenv tests - glibc-all-langpacks # for locale tests - marshalparser # for testing compatibility (magic numbers) with marshalparser - - binutils # for nm (symbol inspection) - rpm # for debugging - - dnf # for upgrade and downgrade + - dnf # for upgrade - name: Update packages how: shell script: dnf upgrade -y diff --git a/python3.11.spec b/python3.11.spec index a736a7b..838231b 100644 --- a/python3.11.spec +++ b/python3.11.spec @@ -13,7 +13,7 @@ URL: https://www.python.org/ # WARNING When rebasing to a new Python version, # remember to update the python3-docs package as well -%global general_version %{pybasever}.16 +%global general_version %{pybasever}.14 #global prerel ... %global upstream_version %{general_version}%{?prerel} Version: %{general_version}%{?prerel:~%{prerel}} @@ -192,7 +192,8 @@ BuildRequires: bluez-libs-devel BuildRequires: bzip2 BuildRequires: bzip2-devel BuildRequires: desktop-file-utils -BuildRequires: expat-devel +# See the runtime requirement in the -libs subpackage +BuildRequires: expat-devel >= 2.6 BuildRequires: findutils BuildRequires: gcc-c++ @@ -219,6 +220,7 @@ BuildRequires: make BuildRequires: mpdecimal-devel BuildRequires: ncurses-devel +BuildRequires: openssl-devel BuildRequires: pkgconfig BuildRequires: readline-devel BuildRequires: redhat-rpm-config >= 127 @@ -231,10 +233,6 @@ BuildRequires: tix-devel BuildRequires: tk-devel < 1:9 BuildRequires: tzdata -# Support for OpenSSL 4 only landed in Python 3.15 for now -# https://github.com/python/cpython/issues/146207 -BuildRequires: (openssl-devel < 1:4 or openssl3-devel) - %if %{with valgrind} BuildRequires: valgrind-devel %endif @@ -251,9 +249,6 @@ BuildRequires: /usr/sbin/ifconfig %if %{with rpmwheels} BuildRequires: %{python_wheel_pkg_prefix}-setuptools-wheel BuildRequires: %{python_wheel_pkg_prefix}-pip-wheel -%else -# For %%python_wheel_inject_sbom -BuildRequires: python-rpm-macros %endif %if %{without bootstrap} @@ -351,28 +346,6 @@ Patch452: 00452-properly-apply-exported-cflags-for-dtrace-systemtap-builds.patch # stressed on OpenSSL 3.5. Patch462: 00462-fix-pyssl_seterror-handling-ssl_error_syscall.patch -# 00474 # 837ddca0372fa87ff9cee47142200caa21e77def -# CVE-2025-15366 -# -# gh-143921: Reject control characters in IMAP commands -# -# (cherry-picked from commit 6262704b134db2a4ba12e85ecfbd968534f28b45) -Patch474: 00474-cve-2025-15366.patch - -# 00475 # 3748209a316662d4e85981ca1a7418547a1d25c6 -# CVE-2025-15367 -# -# gh-143923: Reject control characters in POP3 commands -# -# (cherry-picked from commit b234a2b67539f787e191d2ef19a7cbdce32874e7) -Patch475: 00475-cve-2025-15367.patch - -# 00494 # 430aab133397ed44cc9ee621fd311e02fee317b5 -# Increase the timeout of test_large_content_length_truncated -# -# It has started to fail randomly when run on s390x architecture. -Patch494: 00494-increase-the-timeout-of-test_large_content_length_truncated.patch - # (New patches go here ^^^) # # When adding new patches to "python" and "python3" in Fedora, EL, etc., @@ -524,24 +497,12 @@ Recommends: (%{pkgname}-tkinter%{?_isa} = %{version}-%{release} if tk%{?_isa}) Requires: tzdata # The requirement on libexpat is generated, but we need to version it. -# When built with a specific expat version, but installed with an older one, -# we sometimes get: +# When built with expat >= 2.6, but installed with older expat, we get: # ImportError: /usr/lib64/python3.X/lib-dynload/pyexpat.cpython-....so: -# undefined symbol: XML_... -# The pyexpat module has build-time checks for expat version to only use the -# available symbols. However, there is no runtime protection, so when the module -# is later installed with an older expat, it may error due to undefined symbols. +# undefined symbol: XML_SetReparseDeferralEnabled # This breaks many things, including python -m venv. -# We avoid this problem by requiring at least the same version of expat that -# was used during the build time. # Other subpackages (like -debug) also need this, but they all depend on -libs. -# Since expat 2.7.4, the library has versioned symbols and this is no longer needed, -# as the generated requirement will be in the form of libexpat.so.1(LIBEXPAT_2.7.2) etc. -%global expat_version %(LANG=C rpm -q --qf '%%{version}' expat.%{_target_cpu} | sed 's/.*not installed/0/') -%if v"%{expat_version}" < v"2.7.4" -Requires: expat%{?_isa} >= %{expat_version} -%endif - +Requires: expat >= 2.6 %description -n %{pkgname}-libs This package contains runtime libraries for use by Python: @@ -1102,11 +1063,6 @@ for file in %{buildroot}%{pylibdir}/pydoc_data/topics.py $(grep --include='*.py' rm ${directory}/{__pycache__/${module}.cpython-%{pyshortver}.opt-?.pyc,${module}.py} done -%if %{without rpmwheels} -# Inject SBOM into the installed wheels (if the macro is available) -%{?python_wheel_inject_sbom:%python_wheel_inject_sbom %{buildroot}%{pylibdir}/ensurepip/_bundled/*.whl} -%endif - # ====================================================== # Checks for packaging issues # ====================================================== @@ -1705,44 +1661,6 @@ CheckPython optimized # ====================================================== %changelog -* Thu Aug 13 2026 Karolina Surma - 3.11.16-1 -- Update to Python 3.11.16 - -* Thu Jul 30 2026 Miro Hrončok - 3.11.15-7 - - Skip UDP Lite tests if it's not supported - - Fixes FTBFS on Linux kernel 7.1 and newer - -* Thu Jul 16 2026 Fedora Release Engineering - 3.11.15-6 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild - -* Thu Jul 02 2026 Miro Hrončok - 3.11.15-5 -- Fix ssl.SSLError: [ASN1: NOT_ENOUGH_DATA] not enough data with OpenSSL 3.5.7+ - -* Fri Apr 17 2026 Charalampos Stratakis - 3.11.15-4 -- Security fixes for CVE-2026-1502, CVE-2026-4786, CVE-2026-6100, CVE-2026-2297, CVE 2026-3644, CVE-2026-4224 -Resolves: rhbz#2457941, rhbz#2458221, rhbz#2458013, rhbz#2444704, rhbz#2448188, rhbz#2448204 - -* Sat Apr 11 2026 Miro Hrončok - 3.11.15-3 -- Explicitly build with OpenSSL 3 - -* Thu Mar 26 2026 Lumír Balhar - 3.11.15-2 -- Security fix for CVE-2026-4519 (rhbz#2449727) - -* Tue Mar 03 2026 Tomáš Hrnčiar - 3.11.15-1 -- Update to 3.11.15 - -* Mon Feb 09 2026 Tomáš Hrnčiar - 3.11.14-5 -- Security fixes for CVE-2026-0865, CVE-2025-15366 and CVE-2025-15367 - -* Fri Jan 16 2026 Lumír Balhar - 3.11.14-4 -- Security fix for CVE-2025-13836 - -* Thu Jan 08 2026 Lumír Balhar - 3.11.14-3 -- Security fix for CVE-2025-12084 - -* Tue Jan 06 2026 Karolina Surma - 3.11.14-2 -- Require at least the same expat version as used during the build time - * Fri Oct 10 2025 Karolina Surma - 3.11.14-1 - Update to 3.11.14 diff --git a/sources b/sources index 737c40b..d418a33 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (Python-3.11.16.tar.xz) = f4e168d35596c2df080663d8e8b3472f03bace987d46b49b8410f2425ba193215b9880c7d03d4653ec31c83b72209d95866fc1cb6d666799145075b092f64a48 -SHA512 (Python-3.11.16.tar.xz.asc) = b31b3205e68951478fe76f4884a124ebb4955a711b6105754d4179acb48b16a5439ec8c35383a84787cd673fa1143f2f047c6d65944909b0f1a8e3c75a0e2efe +SHA512 (Python-3.11.14.tar.xz) = 8b5aa917fe67dbaa3c306239ed56c16cd7a3b4b701fab0b3dc0d342d60176c75440713bcab0c59a3289ac4a0f06103bd31140c492556e1937fcdbd990675f9e5 +SHA512 (Python-3.11.14.tar.xz.asc) = d0049fd6f6d06ae5d86b3587080be060d522dd52e7e56270125541d5617582ea3977b75c7e585da005694665cfc5657e39033a730187c506edc252965f4df769