diff --git a/00459-apply-intel-control-flow-technology-for-x86-64.patch b/00459-apply-intel-control-flow-technology-for-x86-64.patch new file mode 100644 index 0000000..380856c --- /dev/null +++ b/00459-apply-intel-control-flow-technology-for-x86-64.patch @@ -0,0 +1,51 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Charalampos Stratakis +Date: Wed, 8 Jan 2025 04:58:22 +0100 +Subject: 00459: Apply Intel Control-flow Technology for x86-64 + +Required for mitigation against return-oriented programming (ROP) and Call or Jump Oriented Programming (COP/JOP) attacks + +Proposed upstream: https://github.com/python/cpython/pull/128606 + +See also: https://sourceware.org/annobin/annobin.html/Test-cf-protection.html +--- + Python/asm_trampoline.S | 22 ++++++++++++++++++++++ + 1 file changed, 22 insertions(+) + +diff --git a/Python/asm_trampoline.S b/Python/asm_trampoline.S +index 460707717d..341d0bbe51 100644 +--- a/Python/asm_trampoline.S ++++ b/Python/asm_trampoline.S +@@ -9,6 +9,9 @@ + # } + _Py_trampoline_func_start: + #ifdef __x86_64__ ++#if defined(__CET__) && (__CET__ & 1) ++ endbr64 ++#endif + sub $8, %rsp + call *%rcx + add $8, %rsp +@@ -26,3 +29,22 @@ _Py_trampoline_func_start: + .globl _Py_trampoline_func_end + _Py_trampoline_func_end: + .section .note.GNU-stack,"",@progbits ++# Note for indicating the assembly code supports CET ++#if defined(__x86_64__) && defined(__CET__) && (__CET__ & 1) ++ .section .note.gnu.property,"a" ++ .align 8 ++ .long 1f - 0f ++ .long 4f - 1f ++ .long 5 ++0: ++ .string "GNU" ++1: ++ .align 8 ++ .long 0xc0000002 ++ .long 3f - 2f ++2: ++ .long 0x3 ++3: ++ .align 8 ++4: ++#endif // __x86_64__ diff --git a/00460-gh-132415-update-vendored-setuptools-in-lib-test-wheeldata.patch b/00460-gh-132415-update-vendored-setuptools-in-lib-test-wheeldata.patch index d6c067b..03d769e 100644 --- a/00460-gh-132415-update-vendored-setuptools-in-lib-test-wheeldata.patch +++ b/00460-gh-132415-update-vendored-setuptools-in-lib-test-wheeldata.patch @@ -13,33 +13,47 @@ gh-127906: Add missing sys import to test_cppext Co-Authored-By: Victor Stinner --- - Lib/test/support/__init__.py | 5 ++--- - Lib/test/test_cext/__init__.py | 2 +- - Lib/test/test_cppext/__init__.py | 2 +- - Lib/test/test_cppext/setup.py | 1 + - Lib/test/test_peg_generator/test_c_parser.py | 2 +- - 5 files changed, 6 insertions(+), 6 deletions(-) + Lib/test/support/__init__.py | 11 +++++------ + Lib/test/test_cext/__init__.py | 2 +- + Lib/test/test_cppext/__init__.py | 2 +- + Lib/test/test_cppext/setup.py | 1 + + Lib/test/test_peg_generator/test_c_parser.py | 2 +- + 5 files changed, 9 insertions(+), 9 deletions(-) diff --git a/Lib/test/support/__init__.py b/Lib/test/support/__init__.py -index 1ee8ffc1b7..cab0f49366 100644 +index c899347624..223787244f 100644 --- a/Lib/test/support/__init__.py +++ b/Lib/test/support/__init__.py -@@ -2308,7 +2308,7 @@ def _findwheel(pkgname): - # Context manager that creates a virtual environment, install setuptools in it, - # and returns the paths to the venv directory and the python executable +@@ -2260,7 +2260,7 @@ def _findwheel(pkgname): + filenames = os.listdir(wheel_dir) + filenames = sorted(filenames, reverse=True) # approximate "newest" first + for filename in filenames: +- # filename is like 'setuptools-67.6.1-py3-none-any.whl' ++ # filename is like 'setuptools-{version}-py3-none-any.whl' + if not filename.endswith(".whl"): + continue + prefix = pkgname + '-' +@@ -2269,10 +2269,10 @@ def _findwheel(pkgname): + raise FileNotFoundError(f"No wheel for {pkgname} found in {wheel_dir}") + + +-# Context manager that creates a virtual environment, install setuptools and wheel in it +-# and returns the path to the venv directory and the path to the python executable ++# Context manager that creates a virtual environment, install setuptools in it, ++# and returns the paths to the venv directory and the python executable @contextlib.contextmanager -def setup_venv_with_pip_setuptools_wheel(venv_dir): +def setup_venv_with_pip_setuptools(venv_dir): import subprocess from .os_helper import temp_cwd -@@ -2331,8 +2331,7 @@ def setup_venv_with_pip_setuptools_wheel(venv_dir): +@@ -2295,8 +2295,7 @@ def setup_venv_with_pip_setuptools_wheel(venv_dir): - cmd = (python, '-X', 'dev', + cmd = [python, '-X', 'dev', '-m', 'pip', 'install', - _findwheel('setuptools'), -- _findwheel('wheel')) -+ _findwheel('setuptools')) +- _findwheel('wheel')] ++ _findwheel('setuptools')] if verbose: print() print('Run:', ' '.join(cmd)) diff --git a/00461-downstream-only-install-wheel-in-test-venvs-when-setuptools-71.patch b/00461-downstream-only-install-wheel-in-test-venvs-when-setuptools-71.patch index 5d1416c..06cb28a 100644 --- a/00461-downstream-only-install-wheel-in-test-venvs-when-setuptools-71.patch +++ b/00461-downstream-only-install-wheel-in-test-venvs-when-setuptools-71.patch @@ -9,10 +9,10 @@ Subject: 00461: Downstream only: Install wheel in test venvs when setuptools < 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/Lib/test/support/__init__.py b/Lib/test/support/__init__.py -index cab0f49366..26c0af4b13 100644 +index 223787244f..94f55ccaf0 100644 --- a/Lib/test/support/__init__.py +++ b/Lib/test/support/__init__.py -@@ -2329,9 +2329,18 @@ def setup_venv_with_pip_setuptools(venv_dir): +@@ -2293,9 +2293,18 @@ def setup_venv_with_pip_setuptools(venv_dir): else: python = os.path.join(venv, 'bin', python_exe) @@ -24,11 +24,11 @@ index cab0f49366..26c0af4b13 100644 + else: + wheels = (setuptools_whl, _findwheel('wheel')) + - cmd = (python, '-X', 'dev', + cmd = [python, '-X', 'dev', '-m', 'pip', 'install', -- _findwheel('setuptools')) +- _findwheel('setuptools')] + *wheels, -+ ) ++ ] if verbose: print() print('Run:', ' '.join(cmd)) diff --git a/00462-fix-pyssl_seterror-handling-ssl_error_syscall.patch b/00462-fix-pyssl_seterror-handling-ssl_error_syscall.patch deleted file mode 100644 index 93984f2..0000000 --- a/00462-fix-pyssl_seterror-handling-ssl_error_syscall.patch +++ /dev/null @@ -1,196 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: yevgeny hong -Date: Tue, 26 Mar 2024 16:45:43 +0900 -Subject: 00462: Fix PySSL_SetError handling SSL_ERROR_SYSCALL - -Python 3.10 changed from using SSL_write() and SSL_read() to SSL_write_ex() and -SSL_read_ex(), but did not update handling of the return value. - -Change error handling so that the return value is not examined. -OSError (not EOF) is now returned when retval is 0. - -This resolves the issue of failing tests when a system is -stressed on OpenSSL 3.5. - -Co-authored-by: Serhiy Storchaka -Co-authored-by: Petr Viktorin ---- - Lib/test/test_ssl.py | 28 ++++++----- - ...-02-18-09-50-31.gh-issue-115627.HGchj0.rst | 2 + - Modules/_ssl.c | 48 +++++++------------ - 3 files changed, 35 insertions(+), 43 deletions(-) - create mode 100644 Misc/NEWS.d/next/Library/2024-02-18-09-50-31.gh-issue-115627.HGchj0.rst - -diff --git a/Lib/test/test_ssl.py b/Lib/test/test_ssl.py -index b13e37d0cd..daeb8cba74 100644 ---- a/Lib/test/test_ssl.py -+++ b/Lib/test/test_ssl.py -@@ -2427,16 +2427,18 @@ def run(self): - self.write(msg.lower()) - except OSError as e: - # handles SSLError and socket errors -+ if isinstance(e, ConnectionError): -+ # OpenSSL 1.1.1 sometimes raises -+ # ConnectionResetError when connection is not -+ # shut down gracefully. -+ if self.server.chatty and support.verbose: -+ print(f" Connection reset by peer: {self.addr}") -+ -+ self.close() -+ self.running = False -+ return - if self.server.chatty and support.verbose: -- if isinstance(e, ConnectionError): -- # OpenSSL 1.1.1 sometimes raises -- # ConnectionResetError when connection is not -- # shut down gracefully. -- print( -- f" Connection reset by peer: {self.addr}" -- ) -- else: -- handle_error("Test server failure:\n") -+ handle_error("Test server failure:\n") - try: - self.write(b"ERROR\n") - except OSError: -@@ -3148,8 +3150,8 @@ def test_wrong_cert_tls13(self): - suppress_ragged_eofs=False) as s: - s.connect((HOST, server.port)) - with self.assertRaisesRegex( -- ssl.SSLError, -- 'alert unknown ca|EOF occurred|TLSV1_ALERT_UNKNOWN_CA' -+ OSError, -+ 'alert unknown ca|EOF occurred|TLSV1_ALERT_UNKNOWN_CA|closed by the remote host|Connection reset by peer' - ): - # TLS 1.3 perform client cert exchange after handshake - s.write(b'data') -@@ -4422,8 +4424,8 @@ def msg_cb(conn, direction, version, content_type, msg_type, data): - # test sometimes fails with EOF error. Test passes as long as - # server aborts connection with an error. - with self.assertRaisesRegex( -- ssl.SSLError, -- '(certificate required|EOF occurred)' -+ OSError, -+ 'certificate required|EOF occurred|closed by the remote host|Connection reset by peer' - ): - # receive CertificateRequest - data = s.recv(1024) -diff --git a/Misc/NEWS.d/next/Library/2024-02-18-09-50-31.gh-issue-115627.HGchj0.rst b/Misc/NEWS.d/next/Library/2024-02-18-09-50-31.gh-issue-115627.HGchj0.rst -new file mode 100644 -index 0000000000..75d926ab59 ---- /dev/null -+++ b/Misc/NEWS.d/next/Library/2024-02-18-09-50-31.gh-issue-115627.HGchj0.rst -@@ -0,0 +1,2 @@ -+Fix the :mod:`ssl` module error handling of connection terminate by peer. -+It now throws an OSError with the appropriate error code instead of an EOFError. -diff --git a/Modules/_ssl.c b/Modules/_ssl.c -index aae4dc323d..27dd7bbe11 100644 ---- a/Modules/_ssl.c -+++ b/Modules/_ssl.c -@@ -573,7 +573,7 @@ PySSL_ChainExceptions(PySSLSocket *sslsock) { - } - - static PyObject * --PySSL_SetError(PySSLSocket *sslsock, int ret, const char *filename, int lineno) -+PySSL_SetError(PySSLSocket *sslsock, const char *filename, int lineno) - { - PyObject *type; - char *errstr = NULL; -@@ -586,7 +586,6 @@ PySSL_SetError(PySSLSocket *sslsock, int ret, const char *filename, int lineno) - _sslmodulestate *state = get_state_sock(sslsock); - type = state->PySSLErrorObject; - -- assert(ret <= 0); - e = ERR_peek_last_error(); - - if (sslsock->ssl != NULL) { -@@ -619,32 +618,21 @@ PySSL_SetError(PySSLSocket *sslsock, int ret, const char *filename, int lineno) - case SSL_ERROR_SYSCALL: - { - if (e == 0) { -- PySocketSockObject *s = GET_SOCKET(sslsock); -- if (ret == 0 || (((PyObject *)s) == Py_None)) { -+ /* underlying BIO reported an I/O error */ -+ ERR_clear_error(); -+#ifdef MS_WINDOWS -+ if (err.ws) { -+ return PyErr_SetFromWindowsErr(err.ws); -+ } -+#endif -+ if (err.c) { -+ errno = err.c; -+ return PyErr_SetFromErrno(PyExc_OSError); -+ } -+ else { - p = PY_SSL_ERROR_EOF; - type = state->PySSLEOFErrorObject; - errstr = "EOF occurred in violation of protocol"; -- } else if (s && ret == -1) { -- /* underlying BIO reported an I/O error */ -- ERR_clear_error(); --#ifdef MS_WINDOWS -- if (err.ws) { -- return PyErr_SetFromWindowsErr(err.ws); -- } --#endif -- if (err.c) { -- errno = err.c; -- return PyErr_SetFromErrno(PyExc_OSError); -- } -- else { -- p = PY_SSL_ERROR_EOF; -- type = state->PySSLEOFErrorObject; -- errstr = "EOF occurred in violation of protocol"; -- } -- } else { /* possible? */ -- p = PY_SSL_ERROR_SYSCALL; -- type = state->PySSLSyscallErrorObject; -- errstr = "Some I/O error occurred"; - } - } else { - if (ERR_GET_LIB(e) == ERR_LIB_SSL && -@@ -1007,7 +995,7 @@ _ssl__SSLSocket_do_handshake_impl(PySSLSocket *self) - err.ssl == SSL_ERROR_WANT_WRITE); - Py_XDECREF(sock); - if (ret < 1) -- return PySSL_SetError(self, ret, __FILE__, __LINE__); -+ return PySSL_SetError(self, __FILE__, __LINE__); - if (PySSL_ChainExceptions(self) < 0) - return NULL; - Py_RETURN_NONE; -@@ -2424,7 +2412,7 @@ _ssl__SSLSocket_write_impl(PySSLSocket *self, Py_buffer *b) - - Py_XDECREF(sock); - if (retval == 0) -- return PySSL_SetError(self, retval, __FILE__, __LINE__); -+ return PySSL_SetError(self, __FILE__, __LINE__); - if (PySSL_ChainExceptions(self) < 0) - return NULL; - return PyLong_FromSize_t(count); -@@ -2454,7 +2442,7 @@ _ssl__SSLSocket_pending_impl(PySSLSocket *self) - self->err = err; - - if (count < 0) -- return PySSL_SetError(self, count, __FILE__, __LINE__); -+ return PySSL_SetError(self, __FILE__, __LINE__); - else - return PyLong_FromLong(count); - } -@@ -2577,7 +2565,7 @@ _ssl__SSLSocket_read_impl(PySSLSocket *self, Py_ssize_t len, - err.ssl == SSL_ERROR_WANT_WRITE); - - if (retval == 0) { -- PySSL_SetError(self, retval, __FILE__, __LINE__); -+ PySSL_SetError(self, __FILE__, __LINE__); - goto error; - } - if (self->exc != NULL) -@@ -2703,7 +2691,7 @@ _ssl__SSLSocket_shutdown_impl(PySSLSocket *self) - } - if (ret < 0) { - Py_XDECREF(sock); -- PySSL_SetError(self, ret, __FILE__, __LINE__); -+ PySSL_SetError(self, __FILE__, __LINE__); - return NULL; - } - if (self->exc != NULL) diff --git a/00474-cve-2025-15366.patch b/00474-cve-2025-15366.patch deleted file mode 100644 index 50f62d9..0000000 --- a/00474-cve-2025-15366.patch +++ /dev/null @@ -1,61 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Seth Michael Larson -Date: Tue, 20 Jan 2026 14:45:42 -0600 -Subject: 00474: CVE-2025-15366 - -gh-143921: Reject control characters in IMAP commands - -(cherry-picked from commit 6262704b134db2a4ba12e85ecfbd968534f28b45) ---- - Lib/imaplib.py | 4 +++- - Lib/test/test_imaplib.py | 6 ++++++ - .../Security/2026-01-16-11-41-06.gh-issue-143921.AeCOor.rst | 1 + - 3 files changed, 10 insertions(+), 1 deletion(-) - create mode 100644 Misc/NEWS.d/next/Security/2026-01-16-11-41-06.gh-issue-143921.AeCOor.rst - -diff --git a/Lib/imaplib.py b/Lib/imaplib.py -index e337fe6471..c7f44f05b1 100644 ---- a/Lib/imaplib.py -+++ b/Lib/imaplib.py -@@ -132,7 +132,7 @@ - # We compile these in _mode_xxx. - _Literal = br'.*{(?P\d+)}$' - _Untagged_status = br'\* (?P\d+) (?P[A-Z-]+)( (?P.*))?' -- -+_control_chars = re.compile(b'[\x00-\x1F\x7F]') - - - class IMAP4: -@@ -994,6 +994,8 @@ def _command(self, name, *args): - if arg is None: continue - if isinstance(arg, str): - arg = bytes(arg, self._encoding) -+ if _control_chars.search(arg): -+ raise ValueError("Control characters not allowed in commands") - data = data + b' ' + arg - - literal = self.literal -diff --git a/Lib/test/test_imaplib.py b/Lib/test/test_imaplib.py -index 4429a90050..73c25bc733 100644 ---- a/Lib/test/test_imaplib.py -+++ b/Lib/test/test_imaplib.py -@@ -504,6 +504,12 @@ def test_login(self): - self.assertEqual(data[0], b'LOGIN completed') - self.assertEqual(client.state, 'AUTH') - -+ def test_control_characters(self): -+ client, _ = self._setup(SimpleIMAPHandler) -+ for c0 in support.control_characters_c0(): -+ with self.assertRaises(ValueError): -+ client.login(f'user{c0}', 'pass') -+ - def test_logout(self): - client, _ = self._setup(SimpleIMAPHandler) - typ, data = client.login('user', 'pass') -diff --git a/Misc/NEWS.d/next/Security/2026-01-16-11-41-06.gh-issue-143921.AeCOor.rst b/Misc/NEWS.d/next/Security/2026-01-16-11-41-06.gh-issue-143921.AeCOor.rst -new file mode 100644 -index 0000000000..4e13fe92bc ---- /dev/null -+++ b/Misc/NEWS.d/next/Security/2026-01-16-11-41-06.gh-issue-143921.AeCOor.rst -@@ -0,0 +1 @@ -+Reject control characters in IMAP commands. diff --git a/00475-cve-2025-15367.patch b/00475-cve-2025-15367.patch deleted file mode 100644 index 12b945f..0000000 --- a/00475-cve-2025-15367.patch +++ /dev/null @@ -1,61 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Seth Michael Larson -Date: Tue, 20 Jan 2026 14:46:32 -0600 -Subject: 00475: CVE-2025-15367 - -gh-143923: Reject control characters in POP3 commands - -(cherry-picked from commit b234a2b67539f787e191d2ef19a7cbdce32874e7) ---- - Lib/poplib.py | 2 ++ - Lib/test/test_poplib.py | 8 ++++++++ - .../2026-01-16-11-43-47.gh-issue-143923.DuytMe.rst | 1 + - 3 files changed, 11 insertions(+) - create mode 100644 Misc/NEWS.d/next/Security/2026-01-16-11-43-47.gh-issue-143923.DuytMe.rst - -diff --git a/Lib/poplib.py b/Lib/poplib.py -index 9eb662d000..5c83522504 100644 ---- a/Lib/poplib.py -+++ b/Lib/poplib.py -@@ -122,6 +122,8 @@ def _putline(self, line): - def _putcmd(self, line): - if self._debugging: print('*cmd*', repr(line)) - line = bytes(line, self.encoding) -+ if re.search(b'[\x00-\x1F\x7F]', line): -+ raise ValueError('Control characters not allowed in commands') - self._putline(line) - - -diff --git a/Lib/test/test_poplib.py b/Lib/test/test_poplib.py -index f1ebbeafe0..50d8c255d6 100644 ---- a/Lib/test/test_poplib.py -+++ b/Lib/test/test_poplib.py -@@ -12,6 +12,7 @@ - import unittest - from unittest import TestCase, skipUnless - from test import support as test_support -+from test.support import control_characters_c0 - from test.support import hashlib_helper - from test.support import socket_helper - from test.support import threading_helper -@@ -395,6 +396,13 @@ def test_quit(self): - self.assertIsNone(self.client.sock) - self.assertIsNone(self.client.file) - -+ def test_control_characters(self): -+ for c0 in control_characters_c0(): -+ with self.assertRaises(ValueError): -+ self.client.user(f'user{c0}') -+ with self.assertRaises(ValueError): -+ self.client.pass_(f'{c0}pass') -+ - @requires_ssl - def test_stls_capa(self): - capa = self.client.capa() -diff --git a/Misc/NEWS.d/next/Security/2026-01-16-11-43-47.gh-issue-143923.DuytMe.rst b/Misc/NEWS.d/next/Security/2026-01-16-11-43-47.gh-issue-143923.DuytMe.rst -new file mode 100644 -index 0000000000..3cde4df3e0 ---- /dev/null -+++ b/Misc/NEWS.d/next/Security/2026-01-16-11-43-47.gh-issue-143923.DuytMe.rst -@@ -0,0 +1 @@ -+Reject control characters in POP3 commands. diff --git a/00494-increase-the-timeout-of-test_large_content_length_truncated.patch b/00494-increase-the-timeout-of-test_large_content_length_truncated.patch deleted file mode 100644 index 9d0ef51..0000000 --- a/00494-increase-the-timeout-of-test_large_content_length_truncated.patch +++ /dev/null @@ -1,23 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Karolina Surma -Date: Fri, 14 Aug 2026 09:38:26 +0200 -Subject: 00494: Increase the timeout of test_large_content_length_truncated - -It has started to fail randomly when run on s390x architecture. ---- - Lib/test/test_httpservers.py | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/Lib/test/test_httpservers.py b/Lib/test/test_httpservers.py -index 96fc9ca574..6a3f5731a4 100644 ---- a/Lib/test/test_httpservers.py -+++ b/Lib/test/test_httpservers.py -@@ -907,7 +907,7 @@ def test_large_content_length(self): - self.assertEqual(res.read(), b'%d %d' % (size, size) + self.linesep) - - def test_large_content_length_truncated(self): -- with support.swap_attr(self.request_handler, 'timeout', 0.001): -+ with support.swap_attr(self.request_handler, 'timeout', support.LOOPBACK_TIMEOUT): - for w in range(18, 65): - size = 1 << w - headers = {'Content-Length' : str(size)} diff --git a/plan.fmf b/plan.fmf deleted file mode 100644 index bb48d32..0000000 --- a/plan.fmf +++ /dev/null @@ -1,67 +0,0 @@ -execute: - how: tmt - -provision: - hardware: - memory: '>= 3 GB' - -environment: - pybasever: '3.12' - -discover: - - name: tests_python - how: shell - url: https://src.fedoraproject.org/tests/python.git - tests: - - name: smoke - path: /smoke - test: "VERSION=${pybasever} ./venv.sh" - - name: smoke_virtualenv - path: /smoke - test: "VERSION=${pybasever} METHOD=virtualenv ./venv.sh" - - name: debugsmoke - path: /smoke - test: "PYTHON=python${pybasever}d TOX=false VERSION=${pybasever} ./venv.sh" - - name: selftest - path: /selftest - test: "VERSION=${pybasever} X='-i test_check_probes' ./parallel.sh" - - name: debugtest - path: /selftest - test: "VERSION=${pybasever} PYTHON=python${pybasever}d X='-i test_check_probes' ./parallel.sh" - - name: debugflags - path: /flags - test: "python${pybasever}d ./assertflags.py -O0" - - name: marshalparser - path: /marshalparser - test: "VERSION=${pybasever} SAMPLE=10 ./test_marshalparser_compatibility.sh" - - name: required_symbols - path: /required-symbols - test: "VERSION=${pybasever} ./check.sh" - -prepare: - - name: Install dependencies - how: install - package: - - gcc # for extension building in venv and selftest - - gcc-c++ # for test_cppext - - gdb # for test_gdb - - "python${pybasever}" # the test subject - - "python${pybasever}-debug" # for leak testing - - "python${pybasever}-devel" # for extension building in venv and selftest - - "python${pybasever}-tkinter" # for selftest - - "python${pybasever}-test" # for selftest - - tox # for venv tests - - virtualenv # for virtualenv tests - - glibc-all-langpacks # for locale tests - - marshalparser # for testing compatibility (magic numbers) with marshalparser - - binutils # for nm (symbol inspection) - - rpm # for debugging - - dnf # for upgrade and downgrade - - perf # for test_perf_profiler - - name: Update packages - how: shell - script: dnf upgrade -y - - name: rpm_qa - order: 100 - how: shell - script: rpm -qa | sort | tee $TMT_PLAN_DATA/rpmqa.txt diff --git a/python3.12.spec b/python3.12.spec index 0c61ac1..dcb0cc8 100644 --- a/python3.12.spec +++ b/python3.12.spec @@ -13,11 +13,11 @@ URL: https://www.python.org/ # WARNING When rebasing to a new Python version, # remember to update the python3-docs package as well -%global general_version %{pybasever}.14 +%global general_version %{pybasever}.10 #global prerel ... %global upstream_version %{general_version}%{?prerel} Version: %{general_version}%{?prerel:~%{prerel}} -Release: 1%{?dist} +Release: 3%{?dist} License: Python-2.0.1 @@ -72,7 +72,7 @@ License: Python-2.0.1 # from Python with the versions below. # This needs to be manually updated when we update Python. %global pip_version 25.0.1 -%global setuptools_version 79.0.1 +%global setuptools_version 67.6.1 %global wheel_version 0.40.0 # All of those also include a list of indirect bundled libs: # pip @@ -98,25 +98,22 @@ Provides: bundled(python3dist(typing-extensions)) = 4.12.2 Provides: bundled(python3dist(urllib3)) = 1.26.20 } # setuptools -# vendor.txt not in .whl -# %%{_rpmconfigdir}/pythonbundles.py <(unzip -l Lib/test/wheeldata/setuptools-*.whl | grep -E '_vendor/.+dist-info/RECORD' | sed -E 's@^.*/([^-]+)-([^-]+)\.dist-info/.*$@\1==\2@') +# vendor.txt files not in .whl +# $ %%{_rpmconfigdir}/pythonbundles.py \ +# <(curl -L https://github.com/pypa/setuptools/raw/v%%{setuptools_version}/setuptools/_vendor/vendored.txt) \ +# <(curl -L https://github.com/pypa/setuptools/raw/v%%{setuptools_version}/pkg_resources/_vendor/vendored.txt) %global setuptools_bundled_provides %{expand: -Provides: bundled(python3dist(autocommand)) = 2.2.2 -Provides: bundled(python3dist(backports-tarfile)) = 1.2 -Provides: bundled(python3dist(importlib-metadata)) = 8 -Provides: bundled(python3dist(inflect)) = 7.3.1 -Provides: bundled(python3dist(jaraco-collections)) = 5.1 -Provides: bundled(python3dist(jaraco-context)) = 5.3 -Provides: bundled(python3dist(jaraco-functools)) = 4.0.1 -Provides: bundled(python3dist(jaraco-text)) = 3.12.1 -Provides: bundled(python3dist(more-itertools)) = 10.3 -Provides: bundled(python3dist(packaging)) = 24.2 -Provides: bundled(python3dist(platformdirs)) = 4.2.2 +Provides: bundled(python3dist(importlib-metadata)) = 6 +Provides: bundled(python3dist(importlib-resources)) = 5.10.2 +Provides: bundled(python3dist(jaraco-text)) = 3.7 +Provides: bundled(python3dist(more-itertools)) = 8.8 +Provides: bundled(python3dist(ordered-set)) = 3.1.1 +Provides: bundled(python3dist(packaging)) = 23 +Provides: bundled(python3dist(platformdirs)) = 2.6.2 Provides: bundled(python3dist(tomli)) = 2.0.1 -Provides: bundled(python3dist(typeguard)) = 4.3 -Provides: bundled(python3dist(typing-extensions)) = 4.12.2 -Provides: bundled(python3dist(wheel)) = 0.45.1 -Provides: bundled(python3dist(zipp)) = 3.19.2 +Provides: bundled(python3dist(typing-extensions)) = 4.0.1 +Provides: bundled(python3dist(typing-extensions)) = 4.4 +Provides: bundled(python3dist(zipp)) = 3.7 } # wheel # $ %%{_rpmconfigdir}/pythonbundles.py <(unzip -p Lib/test/wheeldata/wheel-*.whl wheel/vendored/vendor.txt) @@ -240,7 +237,8 @@ BuildRequires: bluez-libs-devel BuildRequires: bzip2 BuildRequires: bzip2-devel BuildRequires: desktop-file-utils -BuildRequires: expat-devel +# See the runtime requirement in the -libs subpackage +BuildRequires: expat-devel >= 2.6 BuildRequires: findutils BuildRequires: gcc-c++ @@ -267,6 +265,7 @@ BuildRequires: make BuildRequires: mpdecimal-devel BuildRequires: ncurses-devel +BuildRequires: openssl-devel BuildRequires: pkgconfig BuildRequires: python-rpm-macros BuildRequires: readline-devel @@ -280,15 +279,6 @@ BuildRequires: tix-devel BuildRequires: tk-devel < 1:9 BuildRequires: tzdata -# Support for OpenSSL 4 only landed in Python 3.15 for now -# https://github.com/python/cpython/issues/146207 -BuildRequires: (openssl-devel < 1:4 or openssl3-devel) - -# Perf support is only available on x86_64 and aarch64 right now -%ifarch x86_64 aarch64 -BuildRequires: perf -%endif - %if %{with valgrind} BuildRequires: valgrind-devel %endif @@ -375,7 +365,17 @@ Patch251: 00251-change-user-install-location.patch # https://github.com/GrahamDumpleton/mod_wsgi/issues/730 Patch371: 00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-gh-28549-gh-28589.patch -# 00460 # 1da89114f7ee7e7f392128a9861d9c2b41c0ddeb +# 00459 # 906f6692bd85034012c9554f2434627ccfc04c67 +# Apply Intel Control-flow Technology for x86-64 +# +# Required for mitigation against return-oriented programming (ROP) and Call or Jump Oriented Programming (COP/JOP) attacks +# +# Proposed upstream: https://github.com/python/cpython/pull/128606 +# +# See also: https://sourceware.org/annobin/annobin.html/Test-cf-protection.html +Patch459: 00459-apply-intel-control-flow-technology-for-x86-64.patch + +# 00460 # f399a428258bbb149de1a9b8a62583bf77742eb0 # gh-132415: Update vendored setuptools in ``Lib/test/wheeldata`` # # (actual changes in .whl files removed to make this patch smaller) @@ -383,45 +383,10 @@ Patch371: 00371-revert-bpo-1596321-fix-threading-_shutdown-for-the-main-thread-g # gh-127906: Add missing sys import to test_cppext Patch460: 00460-gh-132415-update-vendored-setuptools-in-lib-test-wheeldata.patch -# 00461 # f7bc103c7bcc6e48789b225e06daf835793e1086 +# 00461 # 47f50dd1f049470c33edb114754529777ab2332f # Downstream only: Install wheel in test venvs when setuptools < 71 Patch461: 00461-downstream-only-install-wheel-in-test-venvs-when-setuptools-71.patch -# 00462 # 5324dc5f57e0068f7e4f7b2f20006e88ff5f4e47 -# Fix PySSL_SetError handling SSL_ERROR_SYSCALL -# -# Python 3.10 changed from using SSL_write() and SSL_read() to SSL_write_ex() and -# SSL_read_ex(), but did not update handling of the return value. -# -# Change error handling so that the return value is not examined. -# OSError (not EOF) is now returned when retval is 0. -# -# This resolves the issue of failing tests when a system is -# stressed on OpenSSL 3.5. -Patch462: 00462-fix-pyssl_seterror-handling-ssl_error_syscall.patch - -# 00474 # 837ddca0372fa87ff9cee47142200caa21e77def -# CVE-2025-15366 -# -# gh-143921: Reject control characters in IMAP commands -# -# (cherry-picked from commit 6262704b134db2a4ba12e85ecfbd968534f28b45) -Patch474: 00474-cve-2025-15366.patch - -# 00475 # 3748209a316662d4e85981ca1a7418547a1d25c6 -# CVE-2025-15367 -# -# gh-143923: Reject control characters in POP3 commands -# -# (cherry-picked from commit b234a2b67539f787e191d2ef19a7cbdce32874e7) -Patch475: 00475-cve-2025-15367.patch - -# 00494 # 430aab133397ed44cc9ee621fd311e02fee317b5 -# Increase the timeout of test_large_content_length_truncated -# -# It has started to fail randomly when run on s390x architecture. -Patch494: 00494-increase-the-timeout-of-test_large_content_length_truncated.patch - # (New patches go here ^^^) # # When adding new patches to "python" and "python3" in Fedora, EL, etc., @@ -574,24 +539,12 @@ Recommends: (%{pkgname}-tkinter%{?_isa} = %{version}-%{release} if tk%{?_isa}) Requires: tzdata # The requirement on libexpat is generated, but we need to version it. -# When built with a specific expat version, but installed with an older one, -# we sometimes get: +# When built with expat >= 2.6, but installed with older expat, we get: # ImportError: /usr/lib64/python3.X/lib-dynload/pyexpat.cpython-....so: -# undefined symbol: XML_... -# The pyexpat module has build-time checks for expat version to only use the -# available symbols. However, there is no runtime protection, so when the module -# is later installed with an older expat, it may error due to undefined symbols. +# undefined symbol: XML_SetReparseDeferralEnabled # This breaks many things, including python -m venv. -# We avoid this problem by requiring at least the same version of expat that -# was used during the build time. # Other subpackages (like -debug) also need this, but they all depend on -libs. -# Since expat 2.7.4, the library has versioned symbols and this is no longer needed, -# as the generated requirement will be in the form of libexpat.so.1(LIBEXPAT_2.7.2) etc. -%global expat_version %(LANG=C rpm -q --qf '%%{version}' expat.%{_target_cpu} | sed 's/.*not installed/0/') -%if v"%{expat_version}" < v"2.7.4" -Requires: expat%{?_isa} >= %{expat_version} -%endif - +Requires: expat >= 2.6 %description -n %{pkgname}-libs This package contains runtime libraries for use by Python: @@ -764,7 +717,6 @@ The debug runtime additionally supports debug builds of C-API extensions if [ -f %{_rpmconfigdir}/pythonbundles.py ]; then %{_rpmconfigdir}/pythonbundles.py <(unzip -p Lib/ensurepip/_bundled/pip-*.whl pip/_vendor/vendor.txt) --compare-with '%pip_bundled_provides' %{_rpmconfigdir}/pythonbundles.py <(unzip -p Lib/test/wheeldata/wheel-*.whl wheel/vendored/vendor.txt) --compare-with '%wheel_bundled_provides' - %{_rpmconfigdir}/pythonbundles.py <(unzip -l Lib/test/wheeldata/setuptools-*.whl | grep -E '_vendor/.+dist-info/RECORD' | sed -E 's@^.*/([^-]+)-([^-]+)\.dist-info/.*$@\1==\2@') --compare-with '%setuptools_bundled_provides' fi %if %{with rpmwheels} @@ -1169,11 +1121,6 @@ for file in %{buildroot}%{pylibdir}/pydoc_data/topics.py $(grep --include='*.py' rm ${directory}/{__pycache__/${module}.cpython-%{pyshortver}.opt-?.pyc,${module}.py} done -%if %{without rpmwheels} -# Inject SBOM into the installed wheels (if the macro is available) -%{?python_wheel_inject_sbom:%python_wheel_inject_sbom %{buildroot}%{pylibdir}/ensurepip/_bundled/*.whl} -%endif - # ====================================================== # Checks for packaging issues # ====================================================== @@ -1758,56 +1705,6 @@ CheckPython optimized # ====================================================== %changelog -* Thu Aug 13 2026 Karolina Surma - 3.12.14-1 -- Update to Python 3.12.14 - -* Tue Jul 28 2026 Lukáš Zachar - 3.12.13-6 -- Security fix for CVE-2026-15308 -Resolves: rhbz#2498688 - -* Tue Jul 28 2026 Miro Hrončok - 3.12.13-5 -- Skip UDP Lite tests if it's not supported -- Fixes FTBFS on Linux kernel 7.1 and newer - -* Thu Jul 16 2026 Fedora Release Engineering - 3.12.13-4 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild - -* Thu Apr 16 2026 Charalampos Stratakis - 3.12.13-3 -- Security fixes for CVE-2026-1502, CVE-2026-4786, CVE-2026-6100, CVE-2026-2297, CVE-2026-3644, CVE-2026-4224 -Resolves: rhbz#2444705, rhbz#2448189, rhbz#2448205, rhbz#2457942, rhbz#2458014, rhbz#2458222 - -* Thu Mar 26 2026 Lumír Balhar - 3.12.13-2 -- Security fix for CVE-2026-4519 (rhbz#2449728) - -* Tue Mar 03 2026 Tomáš Hrnčiar - 3.12.13-1 -- Update to 3.12.13 - -* Fri Feb 06 2026 Tomáš Hrnčiar - 3.12.12-4 -- Security fixes for CVE-2026-0865, CVE-2025-15366 and CVE-2025-15367 - -* Fri Jan 16 2026 Lumír Balhar - 3.12.12-3 -- Security fix for CVE-2025-13836 - -* Tue Jan 06 2026 Lumír Balhar - 3.12.12-2 -- Security fix for CVE-2025-12084 -- Require at least the same expat version as used during the build time - -* Fri Oct 10 2025 Karolina Surma - 3.12.12-1 -- Update to 3.12.12 - -* Fri Jul 25 2025 Fedora Release Engineering - 3.12.11-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild - -* Thu Jun 12 2025 Charalampos Stratakis - 3.12.11-2 -- Enable PAC and BTI hardware protections for aarch64 - -* Wed Jun 04 2025 Tomáš Hrnčiar - 3.12.11-1 -- Update to 3.12.11 - -* Fri May 09 2025 Charalampos Stratakis - 3.12.10-4 -- Fix PySSL_SetError handling SSL_ERROR_SYSCALL -- This fixes random flakiness of test_ssl on stressed machines - * Tue May 06 2025 Miro Hrončok - 3.12.10-3 - Drop requirement on python-wheel-wheel with setuptools >= 71 diff --git a/rpminspect.yaml b/rpminspect.yaml index 8cc18cb..83dfb5e 100644 --- a/rpminspect.yaml +++ b/rpminspect.yaml @@ -1,22 +1,22 @@ # exclude test XML data (not always valid) from XML validity check: xml: ignore: - - '/usr/lib*/python*/test/xmltestdata/*' - - '/usr/lib*/python*/test/xmltestdata/*/*' + - /usr/lib*/python*/test/xmltestdata/* + - /usr/lib*/python*/test/xmltestdata/*/* # exclude _socket from ipv4 only functions check, it has both ipv4 and ipv6 only badfuncs: allowed: - '/usr/lib*/python*/lib-dynload/_socket.*': + /usr/lib*/python*/lib-dynload/_socket.*: - inet_aton - inet_ntoa # exclude the debug build from annocheck entirely annocheck: ignore: - - '/usr/bin/python*d' - - '/usr/lib*/libpython*d.so.1.0' - - '/usr/lib*/python*/lib-dynload/*.cpython-*d-*-*-*.so' + - /usr/bin/python*d + - /usr/lib*/libpython*d.so.1.0 + - /usr/lib*/python*/lib-dynload/*.cpython-*d-*-*-*.so # don't report changed content of compiled files # that is expected with every toolchain update and not reproducible yet diff --git a/sources b/sources index f116187..da3276e 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (Python-3.12.14.tar.xz) = 9007399ffdd3a493c91a98cd7a6cb93acfb8de80f3be2f5480cda36f134d49b5043a60bc6b5c62ed18cc6a2e4e3c81cb7556ac5f337e2cd58ff3449a8099ed22 -SHA512 (Python-3.12.14.tar.xz.asc) = 69cc4757f5d79ea46f9b632d5b34f9f16855cb1f767f77c827ad65546ba8f77b68e75a661ebc4e4f453edd7a98a73d916491597f67d4fed9c891aa599a869324 +SHA512 (Python-3.12.10.tar.xz) = 520c30e3958d0be3c127e5dbb1c52bb3bfc404b5b3c7eb56525e25b9b59af9b21b53bee192f323f470e1df806f6cb2dd3411eb90cbc1c4b7d9b6b0777c29e644 +SHA512 (Python-3.12.10.tar.xz.asc) = 7edfa6fd816cf2a052abdb775d464e2f389105ed3e782cacf90805613aaca54bf71308504a5336ee1204e872e7db28df32413fb10b057056b0d5cb3c7a20a9f1 diff --git a/.fmf/version b/tests/.fmf/version similarity index 100% rename from .fmf/version rename to tests/.fmf/version diff --git a/tests/provision.fmf b/tests/provision.fmf new file mode 100644 index 0000000..1a4f0f0 --- /dev/null +++ b/tests/provision.fmf @@ -0,0 +1,4 @@ +--- +standard-inventory-qcow2: + qemu: + m: 3G # Amount of VM memory diff --git a/tests/tests.yml b/tests/tests.yml new file mode 100644 index 0000000..cc1e061 --- /dev/null +++ b/tests/tests.yml @@ -0,0 +1,56 @@ +--- +- hosts: localhost + tags: + - classic + tasks: + - dnf: + name: "*" + state: latest + +- hosts: localhost + roles: + - role: standard-test-basic + tags: + - classic + repositories: + - repo: "https://src.fedoraproject.org/tests/python.git" + dest: "python" + pybasever: "3.12" + tests: + - rpm_qa: + run: rpm -qa + - smoke: + dir: python/smoke + run: "VERSION={{ pybasever }} ./venv.sh" + - smoke_virtualenv: + dir: python/smoke + run: "VERSION={{ pybasever }} METHOD=virtualenv ./venv.sh" + - debugsmoke: + dir: python/smoke + run: "PYTHON=python{{ pybasever }}d TOX=false VERSION={{ pybasever }} ./venv.sh" + - selftest: + dir: python/selftest + run: "VERSION={{ pybasever }} X='-i test_check_probes' ./parallel.sh" + - debugtest: + dir: python/selftest + run: "VERSION={{ pybasever }} PYTHON=python{{ pybasever }}d X='-i test_check_probes' ./parallel.sh" + - debugflags: + dir: python/flags + run: "python{{ pybasever }}d ./assertflags.py -O0" + - marshalparser: + dir: python/marshalparser + run: "VERSION={{ pybasever }} SAMPLE=10 test_marshalparser_compatibility.sh" + required_packages: + - gcc # for extension building in venv and selftest + - gcc-c++ # for test_cppext + - gdb # for test_gdb + - "python{{ pybasever }}" # the test subject + - "python{{ pybasever }}-debug" # for leak testing + - "python{{ pybasever }}-devel" # for extension building in venv and selftest + - "python{{ pybasever }}-tkinter" # for selftest + - "python{{ pybasever }}-test" # for selftest + - tox # for venv tests + - virtualenv # for virtualenv tests + - glibc-all-langpacks # for locale tests + - marshalparser # for testing compatibility (magic numbers) with marshalparser + - rpm # for debugging