Compare commits
No commits in common. "rawhide" and "f41" have entirely different histories.
11 changed files with 127 additions and 231 deletions
|
|
@ -21,7 +21,7 @@ Co-Authored-By: Victor Stinner <vstinner@python.org>
|
||||||
5 files changed, 6 insertions(+), 6 deletions(-)
|
5 files changed, 6 insertions(+), 6 deletions(-)
|
||||||
|
|
||||||
diff --git a/Lib/test/support/__init__.py b/Lib/test/support/__init__.py
|
diff --git a/Lib/test/support/__init__.py b/Lib/test/support/__init__.py
|
||||||
index 1ee8ffc1b7..cab0f49366 100644
|
index 4c22f131e3..e49e3668a3 100644
|
||||||
--- a/Lib/test/support/__init__.py
|
--- a/Lib/test/support/__init__.py
|
||||||
+++ b/Lib/test/support/__init__.py
|
+++ b/Lib/test/support/__init__.py
|
||||||
@@ -2308,7 +2308,7 @@ def _findwheel(pkgname):
|
@@ -2308,7 +2308,7 @@ def _findwheel(pkgname):
|
||||||
|
|
|
||||||
|
|
@ -9,7 +9,7 @@ Subject: 00461: Downstream only: Install wheel in test venvs when setuptools <
|
||||||
1 file changed, 10 insertions(+), 1 deletion(-)
|
1 file changed, 10 insertions(+), 1 deletion(-)
|
||||||
|
|
||||||
diff --git a/Lib/test/support/__init__.py b/Lib/test/support/__init__.py
|
diff --git a/Lib/test/support/__init__.py b/Lib/test/support/__init__.py
|
||||||
index cab0f49366..26c0af4b13 100644
|
index e49e3668a3..4c42234ccc 100644
|
||||||
--- a/Lib/test/support/__init__.py
|
--- a/Lib/test/support/__init__.py
|
||||||
+++ b/Lib/test/support/__init__.py
|
+++ b/Lib/test/support/__init__.py
|
||||||
@@ -2329,9 +2329,18 @@ def setup_venv_with_pip_setuptools(venv_dir):
|
@@ -2329,9 +2329,18 @@ def setup_venv_with_pip_setuptools(venv_dir):
|
||||||
|
|
|
||||||
|
|
@ -84,7 +84,7 @@ index 0000000000..75d926ab59
|
||||||
+Fix the :mod:`ssl` module error handling of connection terminate by peer.
|
+Fix the :mod:`ssl` module error handling of connection terminate by peer.
|
||||||
+It now throws an OSError with the appropriate error code instead of an EOFError.
|
+It now throws an OSError with the appropriate error code instead of an EOFError.
|
||||||
diff --git a/Modules/_ssl.c b/Modules/_ssl.c
|
diff --git a/Modules/_ssl.c b/Modules/_ssl.c
|
||||||
index aae4dc323d..27dd7bbe11 100644
|
index 0b8cf0b6df..42a4c95890 100644
|
||||||
--- a/Modules/_ssl.c
|
--- a/Modules/_ssl.c
|
||||||
+++ b/Modules/_ssl.c
|
+++ b/Modules/_ssl.c
|
||||||
@@ -573,7 +573,7 @@ PySSL_ChainExceptions(PySSLSocket *sslsock) {
|
@@ -573,7 +573,7 @@ PySSL_ChainExceptions(PySSLSocket *sslsock) {
|
||||||
|
|
|
||||||
102
00464-enable-pac-and-bti-protections-for-aarch64.patch
Normal file
102
00464-enable-pac-and-bti-protections-for-aarch64.patch
Normal file
|
|
@ -0,0 +1,102 @@
|
||||||
|
From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Charalampos Stratakis <cstratak@redhat.com>
|
||||||
|
Date: Tue, 3 Jun 2025 03:02:15 +0200
|
||||||
|
Subject: 00464: Enable PAC and BTI protections for aarch64
|
||||||
|
|
||||||
|
Apply protection against ROP/JOP attacks for aarch64 on asm_trampoline.S
|
||||||
|
|
||||||
|
The BTI flag must be applied in the assembler sources for this class
|
||||||
|
of attacks to be mitigated on newer aarch64 processors.
|
||||||
|
|
||||||
|
Upstream PR: https://github.com/python/cpython/pull/130864/files
|
||||||
|
|
||||||
|
The upstream patch is incomplete but only for the case where
|
||||||
|
frame pointers are not used on 3.13+.
|
||||||
|
|
||||||
|
Since on Fedora we always compile with frame pointers the BTI/PAC
|
||||||
|
hardware protections can be enabled without losing Perf unwinding.
|
||||||
|
---
|
||||||
|
Python/asm_trampoline.S | 4 +++
|
||||||
|
Python/asm_trampoline_aarch64.h | 50 +++++++++++++++++++++++++++++++++
|
||||||
|
2 files changed, 54 insertions(+)
|
||||||
|
create mode 100644 Python/asm_trampoline_aarch64.h
|
||||||
|
|
||||||
|
diff --git a/Python/asm_trampoline.S b/Python/asm_trampoline.S
|
||||||
|
index 341d0bbe51..ae882660b5 100644
|
||||||
|
--- a/Python/asm_trampoline.S
|
||||||
|
+++ b/Python/asm_trampoline.S
|
||||||
|
@@ -1,3 +1,5 @@
|
||||||
|
+#include "asm_trampoline_aarch64.h"
|
||||||
|
+
|
||||||
|
.text
|
||||||
|
.globl _Py_trampoline_func_start
|
||||||
|
# The following assembly is equivalent to:
|
||||||
|
@@ -20,10 +22,12 @@ _Py_trampoline_func_start:
|
||||||
|
#if defined(__aarch64__) && defined(__AARCH64EL__) && !defined(__ILP32__)
|
||||||
|
// ARM64 little endian, 64bit ABI
|
||||||
|
// generate with aarch64-linux-gnu-gcc 12.1
|
||||||
|
+ SIGN_LR
|
||||||
|
stp x29, x30, [sp, -16]!
|
||||||
|
mov x29, sp
|
||||||
|
blr x3
|
||||||
|
ldp x29, x30, [sp], 16
|
||||||
|
+ VERIFY_LR
|
||||||
|
ret
|
||||||
|
#endif
|
||||||
|
.globl _Py_trampoline_func_end
|
||||||
|
diff --git a/Python/asm_trampoline_aarch64.h b/Python/asm_trampoline_aarch64.h
|
||||||
|
new file mode 100644
|
||||||
|
index 0000000000..4b0ec4a7dc
|
||||||
|
--- /dev/null
|
||||||
|
+++ b/Python/asm_trampoline_aarch64.h
|
||||||
|
@@ -0,0 +1,50 @@
|
||||||
|
+#ifndef ASM_TRAMPOLINE_AARCH_64_H_
|
||||||
|
+#define ASM_TRAMPOLINE_AARCH_64_H_
|
||||||
|
+
|
||||||
|
+/*
|
||||||
|
+ * References:
|
||||||
|
+ * - https://developer.arm.com/documentation/101028/0012/5--Feature-test-macros
|
||||||
|
+ * - https://github.com/ARM-software/abi-aa/blob/main/aaelf64/aaelf64.rst
|
||||||
|
+ */
|
||||||
|
+
|
||||||
|
+#if defined(__ARM_FEATURE_BTI_DEFAULT) && __ARM_FEATURE_BTI_DEFAULT == 1
|
||||||
|
+ #define BTI_J hint 36 /* bti j: for jumps, IE br instructions */
|
||||||
|
+ #define BTI_C hint 34 /* bti c: for calls, IE bl instructions */
|
||||||
|
+ #define GNU_PROPERTY_AARCH64_BTI 1 /* bit 0 GNU Notes is for BTI support */
|
||||||
|
+#else
|
||||||
|
+ #define BTI_J
|
||||||
|
+ #define BTI_C
|
||||||
|
+ #define GNU_PROPERTY_AARCH64_BTI 0
|
||||||
|
+#endif
|
||||||
|
+
|
||||||
|
+#if defined(__ARM_FEATURE_PAC_DEFAULT)
|
||||||
|
+ #if __ARM_FEATURE_PAC_DEFAULT & 1
|
||||||
|
+ #define SIGN_LR hint 25 /* paciasp: sign with the A key */
|
||||||
|
+ #define VERIFY_LR hint 29 /* autiasp: verify with the A key */
|
||||||
|
+ #elif __ARM_FEATURE_PAC_DEFAULT & 2
|
||||||
|
+ #define SIGN_LR hint 27 /* pacibsp: sign with the b key */
|
||||||
|
+ #define VERIFY_LR hint 31 /* autibsp: verify with the b key */
|
||||||
|
+ #endif
|
||||||
|
+ #define GNU_PROPERTY_AARCH64_POINTER_AUTH 2 /* bit 1 GNU Notes is for PAC support */
|
||||||
|
+#else
|
||||||
|
+ #define SIGN_LR BTI_C
|
||||||
|
+ #define VERIFY_LR
|
||||||
|
+ #define GNU_PROPERTY_AARCH64_POINTER_AUTH 0
|
||||||
|
+#endif
|
||||||
|
+
|
||||||
|
+/* Add the BTI and PAC support to GNU Notes section */
|
||||||
|
+#if GNU_PROPERTY_AARCH64_BTI != 0 || GNU_PROPERTY_AARCH64_POINTER_AUTH != 0
|
||||||
|
+ .pushsection .note.gnu.property, "a"; /* Start a new allocatable section */
|
||||||
|
+ .balign 8; /* align it on a byte boundry */
|
||||||
|
+ .long 4; /* size of "GNU\0" */
|
||||||
|
+ .long 0x10; /* size of descriptor */
|
||||||
|
+ .long 0x5; /* NT_GNU_PROPERTY_TYPE_0 */
|
||||||
|
+ .asciz "GNU";
|
||||||
|
+ .long 0xc0000000; /* GNU_PROPERTY_AARCH64_FEATURE_1_AND */
|
||||||
|
+ .long 4; /* Four bytes of data */
|
||||||
|
+ .long (GNU_PROPERTY_AARCH64_BTI|GNU_PROPERTY_AARCH64_POINTER_AUTH); /* BTI or PAC is enabled */
|
||||||
|
+ .long 0; /* padding for 8 byte alignment */
|
||||||
|
+ .popsection; /* end the section */
|
||||||
|
+#endif
|
||||||
|
+
|
||||||
|
+#endif
|
||||||
|
|
@ -1,61 +0,0 @@
|
||||||
From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Seth Michael Larson <seth@python.org>
|
|
||||||
Date: Tue, 20 Jan 2026 14:45:42 -0600
|
|
||||||
Subject: 00474: CVE-2025-15366
|
|
||||||
|
|
||||||
gh-143921: Reject control characters in IMAP commands
|
|
||||||
|
|
||||||
(cherry-picked from commit 6262704b134db2a4ba12e85ecfbd968534f28b45)
|
|
||||||
---
|
|
||||||
Lib/imaplib.py | 4 +++-
|
|
||||||
Lib/test/test_imaplib.py | 6 ++++++
|
|
||||||
.../Security/2026-01-16-11-41-06.gh-issue-143921.AeCOor.rst | 1 +
|
|
||||||
3 files changed, 10 insertions(+), 1 deletion(-)
|
|
||||||
create mode 100644 Misc/NEWS.d/next/Security/2026-01-16-11-41-06.gh-issue-143921.AeCOor.rst
|
|
||||||
|
|
||||||
diff --git a/Lib/imaplib.py b/Lib/imaplib.py
|
|
||||||
index e337fe6471..c7f44f05b1 100644
|
|
||||||
--- a/Lib/imaplib.py
|
|
||||||
+++ b/Lib/imaplib.py
|
|
||||||
@@ -132,7 +132,7 @@
|
|
||||||
# We compile these in _mode_xxx.
|
|
||||||
_Literal = br'.*{(?P<size>\d+)}$'
|
|
||||||
_Untagged_status = br'\* (?P<data>\d+) (?P<type>[A-Z-]+)( (?P<data2>.*))?'
|
|
||||||
-
|
|
||||||
+_control_chars = re.compile(b'[\x00-\x1F\x7F]')
|
|
||||||
|
|
||||||
|
|
||||||
class IMAP4:
|
|
||||||
@@ -994,6 +994,8 @@ def _command(self, name, *args):
|
|
||||||
if arg is None: continue
|
|
||||||
if isinstance(arg, str):
|
|
||||||
arg = bytes(arg, self._encoding)
|
|
||||||
+ if _control_chars.search(arg):
|
|
||||||
+ raise ValueError("Control characters not allowed in commands")
|
|
||||||
data = data + b' ' + arg
|
|
||||||
|
|
||||||
literal = self.literal
|
|
||||||
diff --git a/Lib/test/test_imaplib.py b/Lib/test/test_imaplib.py
|
|
||||||
index 4429a90050..73c25bc733 100644
|
|
||||||
--- a/Lib/test/test_imaplib.py
|
|
||||||
+++ b/Lib/test/test_imaplib.py
|
|
||||||
@@ -504,6 +504,12 @@ def test_login(self):
|
|
||||||
self.assertEqual(data[0], b'LOGIN completed')
|
|
||||||
self.assertEqual(client.state, 'AUTH')
|
|
||||||
|
|
||||||
+ def test_control_characters(self):
|
|
||||||
+ client, _ = self._setup(SimpleIMAPHandler)
|
|
||||||
+ for c0 in support.control_characters_c0():
|
|
||||||
+ with self.assertRaises(ValueError):
|
|
||||||
+ client.login(f'user{c0}', 'pass')
|
|
||||||
+
|
|
||||||
def test_logout(self):
|
|
||||||
client, _ = self._setup(SimpleIMAPHandler)
|
|
||||||
typ, data = client.login('user', 'pass')
|
|
||||||
diff --git a/Misc/NEWS.d/next/Security/2026-01-16-11-41-06.gh-issue-143921.AeCOor.rst b/Misc/NEWS.d/next/Security/2026-01-16-11-41-06.gh-issue-143921.AeCOor.rst
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..4e13fe92bc
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/Misc/NEWS.d/next/Security/2026-01-16-11-41-06.gh-issue-143921.AeCOor.rst
|
|
||||||
@@ -0,0 +1 @@
|
|
||||||
+Reject control characters in IMAP commands.
|
|
||||||
|
|
@ -1,61 +0,0 @@
|
||||||
From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Seth Michael Larson <seth@python.org>
|
|
||||||
Date: Tue, 20 Jan 2026 14:46:32 -0600
|
|
||||||
Subject: 00475: CVE-2025-15367
|
|
||||||
|
|
||||||
gh-143923: Reject control characters in POP3 commands
|
|
||||||
|
|
||||||
(cherry-picked from commit b234a2b67539f787e191d2ef19a7cbdce32874e7)
|
|
||||||
---
|
|
||||||
Lib/poplib.py | 2 ++
|
|
||||||
Lib/test/test_poplib.py | 8 ++++++++
|
|
||||||
.../2026-01-16-11-43-47.gh-issue-143923.DuytMe.rst | 1 +
|
|
||||||
3 files changed, 11 insertions(+)
|
|
||||||
create mode 100644 Misc/NEWS.d/next/Security/2026-01-16-11-43-47.gh-issue-143923.DuytMe.rst
|
|
||||||
|
|
||||||
diff --git a/Lib/poplib.py b/Lib/poplib.py
|
|
||||||
index 9eb662d000..5c83522504 100644
|
|
||||||
--- a/Lib/poplib.py
|
|
||||||
+++ b/Lib/poplib.py
|
|
||||||
@@ -122,6 +122,8 @@ def _putline(self, line):
|
|
||||||
def _putcmd(self, line):
|
|
||||||
if self._debugging: print('*cmd*', repr(line))
|
|
||||||
line = bytes(line, self.encoding)
|
|
||||||
+ if re.search(b'[\x00-\x1F\x7F]', line):
|
|
||||||
+ raise ValueError('Control characters not allowed in commands')
|
|
||||||
self._putline(line)
|
|
||||||
|
|
||||||
|
|
||||||
diff --git a/Lib/test/test_poplib.py b/Lib/test/test_poplib.py
|
|
||||||
index f1ebbeafe0..50d8c255d6 100644
|
|
||||||
--- a/Lib/test/test_poplib.py
|
|
||||||
+++ b/Lib/test/test_poplib.py
|
|
||||||
@@ -12,6 +12,7 @@
|
|
||||||
import unittest
|
|
||||||
from unittest import TestCase, skipUnless
|
|
||||||
from test import support as test_support
|
|
||||||
+from test.support import control_characters_c0
|
|
||||||
from test.support import hashlib_helper
|
|
||||||
from test.support import socket_helper
|
|
||||||
from test.support import threading_helper
|
|
||||||
@@ -395,6 +396,13 @@ def test_quit(self):
|
|
||||||
self.assertIsNone(self.client.sock)
|
|
||||||
self.assertIsNone(self.client.file)
|
|
||||||
|
|
||||||
+ def test_control_characters(self):
|
|
||||||
+ for c0 in control_characters_c0():
|
|
||||||
+ with self.assertRaises(ValueError):
|
|
||||||
+ self.client.user(f'user{c0}')
|
|
||||||
+ with self.assertRaises(ValueError):
|
|
||||||
+ self.client.pass_(f'{c0}pass')
|
|
||||||
+
|
|
||||||
@requires_ssl
|
|
||||||
def test_stls_capa(self):
|
|
||||||
capa = self.client.capa()
|
|
||||||
diff --git a/Misc/NEWS.d/next/Security/2026-01-16-11-43-47.gh-issue-143923.DuytMe.rst b/Misc/NEWS.d/next/Security/2026-01-16-11-43-47.gh-issue-143923.DuytMe.rst
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..3cde4df3e0
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/Misc/NEWS.d/next/Security/2026-01-16-11-43-47.gh-issue-143923.DuytMe.rst
|
|
||||||
@@ -0,0 +1 @@
|
|
||||||
+Reject control characters in POP3 commands.
|
|
||||||
|
|
@ -1,23 +0,0 @@
|
||||||
From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Karolina Surma <ksurma@redhat.com>
|
|
||||||
Date: Fri, 14 Aug 2026 09:38:26 +0200
|
|
||||||
Subject: 00494: Increase the timeout of test_large_content_length_truncated
|
|
||||||
|
|
||||||
It has started to fail randomly when run on s390x architecture.
|
|
||||||
---
|
|
||||||
Lib/test/test_httpservers.py | 2 +-
|
|
||||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
|
||||||
|
|
||||||
diff --git a/Lib/test/test_httpservers.py b/Lib/test/test_httpservers.py
|
|
||||||
index 96fc9ca574..6a3f5731a4 100644
|
|
||||||
--- a/Lib/test/test_httpservers.py
|
|
||||||
+++ b/Lib/test/test_httpservers.py
|
|
||||||
@@ -907,7 +907,7 @@ def test_large_content_length(self):
|
|
||||||
self.assertEqual(res.read(), b'%d %d' % (size, size) + self.linesep)
|
|
||||||
|
|
||||||
def test_large_content_length_truncated(self):
|
|
||||||
- with support.swap_attr(self.request_handler, 'timeout', 0.001):
|
|
||||||
+ with support.swap_attr(self.request_handler, 'timeout', support.LOOPBACK_TIMEOUT):
|
|
||||||
for w in range(18, 65):
|
|
||||||
size = 1 << w
|
|
||||||
headers = {'Content-Length' : str(size)}
|
|
||||||
6
plan.fmf
6
plan.fmf
|
|
@ -34,9 +34,6 @@ discover:
|
||||||
- name: marshalparser
|
- name: marshalparser
|
||||||
path: /marshalparser
|
path: /marshalparser
|
||||||
test: "VERSION=${pybasever} SAMPLE=10 ./test_marshalparser_compatibility.sh"
|
test: "VERSION=${pybasever} SAMPLE=10 ./test_marshalparser_compatibility.sh"
|
||||||
- name: required_symbols
|
|
||||||
path: /required-symbols
|
|
||||||
test: "VERSION=${pybasever} ./check.sh"
|
|
||||||
|
|
||||||
prepare:
|
prepare:
|
||||||
- name: Install dependencies
|
- name: Install dependencies
|
||||||
|
|
@ -54,9 +51,8 @@ prepare:
|
||||||
- virtualenv # for virtualenv tests
|
- virtualenv # for virtualenv tests
|
||||||
- glibc-all-langpacks # for locale tests
|
- glibc-all-langpacks # for locale tests
|
||||||
- marshalparser # for testing compatibility (magic numbers) with marshalparser
|
- marshalparser # for testing compatibility (magic numbers) with marshalparser
|
||||||
- binutils # for nm (symbol inspection)
|
|
||||||
- rpm # for debugging
|
- rpm # for debugging
|
||||||
- dnf # for upgrade and downgrade
|
- dnf # for upgrade
|
||||||
- perf # for test_perf_profiler
|
- perf # for test_perf_profiler
|
||||||
- name: Update packages
|
- name: Update packages
|
||||||
how: shell
|
how: shell
|
||||||
|
|
|
||||||
|
|
@ -13,7 +13,7 @@ URL: https://www.python.org/
|
||||||
|
|
||||||
# WARNING When rebasing to a new Python version,
|
# WARNING When rebasing to a new Python version,
|
||||||
# remember to update the python3-docs package as well
|
# remember to update the python3-docs package as well
|
||||||
%global general_version %{pybasever}.14
|
%global general_version %{pybasever}.12
|
||||||
#global prerel ...
|
#global prerel ...
|
||||||
%global upstream_version %{general_version}%{?prerel}
|
%global upstream_version %{general_version}%{?prerel}
|
||||||
Version: %{general_version}%{?prerel:~%{prerel}}
|
Version: %{general_version}%{?prerel:~%{prerel}}
|
||||||
|
|
@ -240,7 +240,8 @@ BuildRequires: bluez-libs-devel
|
||||||
BuildRequires: bzip2
|
BuildRequires: bzip2
|
||||||
BuildRequires: bzip2-devel
|
BuildRequires: bzip2-devel
|
||||||
BuildRequires: desktop-file-utils
|
BuildRequires: desktop-file-utils
|
||||||
BuildRequires: expat-devel
|
# See the runtime requirement in the -libs subpackage
|
||||||
|
BuildRequires: expat-devel >= 2.6
|
||||||
|
|
||||||
BuildRequires: findutils
|
BuildRequires: findutils
|
||||||
BuildRequires: gcc-c++
|
BuildRequires: gcc-c++
|
||||||
|
|
@ -267,6 +268,7 @@ BuildRequires: make
|
||||||
BuildRequires: mpdecimal-devel
|
BuildRequires: mpdecimal-devel
|
||||||
BuildRequires: ncurses-devel
|
BuildRequires: ncurses-devel
|
||||||
|
|
||||||
|
BuildRequires: openssl-devel
|
||||||
BuildRequires: pkgconfig
|
BuildRequires: pkgconfig
|
||||||
BuildRequires: python-rpm-macros
|
BuildRequires: python-rpm-macros
|
||||||
BuildRequires: readline-devel
|
BuildRequires: readline-devel
|
||||||
|
|
@ -280,10 +282,6 @@ BuildRequires: tix-devel
|
||||||
BuildRequires: tk-devel < 1:9
|
BuildRequires: tk-devel < 1:9
|
||||||
BuildRequires: tzdata
|
BuildRequires: tzdata
|
||||||
|
|
||||||
# Support for OpenSSL 4 only landed in Python 3.15 for now
|
|
||||||
# https://github.com/python/cpython/issues/146207
|
|
||||||
BuildRequires: (openssl-devel < 1:4 or openssl3-devel)
|
|
||||||
|
|
||||||
# Perf support is only available on x86_64 and aarch64 right now
|
# Perf support is only available on x86_64 and aarch64 right now
|
||||||
%ifarch x86_64 aarch64
|
%ifarch x86_64 aarch64
|
||||||
BuildRequires: perf
|
BuildRequires: perf
|
||||||
|
|
@ -400,27 +398,22 @@ Patch461: 00461-downstream-only-install-wheel-in-test-venvs-when-setuptools-71.p
|
||||||
# stressed on OpenSSL 3.5.
|
# stressed on OpenSSL 3.5.
|
||||||
Patch462: 00462-fix-pyssl_seterror-handling-ssl_error_syscall.patch
|
Patch462: 00462-fix-pyssl_seterror-handling-ssl_error_syscall.patch
|
||||||
|
|
||||||
# 00474 # 837ddca0372fa87ff9cee47142200caa21e77def
|
# 00464 # 1c713e02a26bf8865bb6421749d19d0766cac178
|
||||||
# CVE-2025-15366
|
# Enable PAC and BTI protections for aarch64
|
||||||
#
|
#
|
||||||
# gh-143921: Reject control characters in IMAP commands
|
# Apply protection against ROP/JOP attacks for aarch64 on asm_trampoline.S
|
||||||
#
|
#
|
||||||
# (cherry-picked from commit 6262704b134db2a4ba12e85ecfbd968534f28b45)
|
# The BTI flag must be applied in the assembler sources for this class
|
||||||
Patch474: 00474-cve-2025-15366.patch
|
# of attacks to be mitigated on newer aarch64 processors.
|
||||||
|
|
||||||
# 00475 # 3748209a316662d4e85981ca1a7418547a1d25c6
|
|
||||||
# CVE-2025-15367
|
|
||||||
#
|
#
|
||||||
# gh-143923: Reject control characters in POP3 commands
|
# Upstream PR: https://github.com/python/cpython/pull/130864/files
|
||||||
#
|
#
|
||||||
# (cherry-picked from commit b234a2b67539f787e191d2ef19a7cbdce32874e7)
|
# The upstream patch is incomplete but only for the case where
|
||||||
Patch475: 00475-cve-2025-15367.patch
|
# frame pointers are not used on 3.13+.
|
||||||
|
|
||||||
# 00494 # 430aab133397ed44cc9ee621fd311e02fee317b5
|
|
||||||
# Increase the timeout of test_large_content_length_truncated
|
|
||||||
#
|
#
|
||||||
# It has started to fail randomly when run on s390x architecture.
|
# Since on Fedora we always compile with frame pointers the BTI/PAC
|
||||||
Patch494: 00494-increase-the-timeout-of-test_large_content_length_truncated.patch
|
# hardware protections can be enabled without losing Perf unwinding.
|
||||||
|
Patch464: 00464-enable-pac-and-bti-protections-for-aarch64.patch
|
||||||
|
|
||||||
# (New patches go here ^^^)
|
# (New patches go here ^^^)
|
||||||
#
|
#
|
||||||
|
|
@ -574,24 +567,12 @@ Recommends: (%{pkgname}-tkinter%{?_isa} = %{version}-%{release} if tk%{?_isa})
|
||||||
Requires: tzdata
|
Requires: tzdata
|
||||||
|
|
||||||
# The requirement on libexpat is generated, but we need to version it.
|
# The requirement on libexpat is generated, but we need to version it.
|
||||||
# When built with a specific expat version, but installed with an older one,
|
# When built with expat >= 2.6, but installed with older expat, we get:
|
||||||
# we sometimes get:
|
|
||||||
# ImportError: /usr/lib64/python3.X/lib-dynload/pyexpat.cpython-....so:
|
# ImportError: /usr/lib64/python3.X/lib-dynload/pyexpat.cpython-....so:
|
||||||
# undefined symbol: XML_...
|
# undefined symbol: XML_SetReparseDeferralEnabled
|
||||||
# The pyexpat module has build-time checks for expat version to only use the
|
|
||||||
# available symbols. However, there is no runtime protection, so when the module
|
|
||||||
# is later installed with an older expat, it may error due to undefined symbols.
|
|
||||||
# This breaks many things, including python -m venv.
|
# This breaks many things, including python -m venv.
|
||||||
# We avoid this problem by requiring at least the same version of expat that
|
|
||||||
# was used during the build time.
|
|
||||||
# Other subpackages (like -debug) also need this, but they all depend on -libs.
|
# Other subpackages (like -debug) also need this, but they all depend on -libs.
|
||||||
# Since expat 2.7.4, the library has versioned symbols and this is no longer needed,
|
Requires: expat >= 2.6
|
||||||
# as the generated requirement will be in the form of libexpat.so.1(LIBEXPAT_2.7.2) etc.
|
|
||||||
%global expat_version %(LANG=C rpm -q --qf '%%{version}' expat.%{_target_cpu} | sed 's/.*not installed/0/')
|
|
||||||
%if v"%{expat_version}" < v"2.7.4"
|
|
||||||
Requires: expat%{?_isa} >= %{expat_version}
|
|
||||||
%endif
|
|
||||||
|
|
||||||
|
|
||||||
%description -n %{pkgname}-libs
|
%description -n %{pkgname}-libs
|
||||||
This package contains runtime libraries for use by Python:
|
This package contains runtime libraries for use by Python:
|
||||||
|
|
@ -1169,11 +1150,6 @@ for file in %{buildroot}%{pylibdir}/pydoc_data/topics.py $(grep --include='*.py'
|
||||||
rm ${directory}/{__pycache__/${module}.cpython-%{pyshortver}.opt-?.pyc,${module}.py}
|
rm ${directory}/{__pycache__/${module}.cpython-%{pyshortver}.opt-?.pyc,${module}.py}
|
||||||
done
|
done
|
||||||
|
|
||||||
%if %{without rpmwheels}
|
|
||||||
# Inject SBOM into the installed wheels (if the macro is available)
|
|
||||||
%{?python_wheel_inject_sbom:%python_wheel_inject_sbom %{buildroot}%{pylibdir}/ensurepip/_bundled/*.whl}
|
|
||||||
%endif
|
|
||||||
|
|
||||||
# ======================================================
|
# ======================================================
|
||||||
# Checks for packaging issues
|
# Checks for packaging issues
|
||||||
# ======================================================
|
# ======================================================
|
||||||
|
|
@ -1758,40 +1734,6 @@ CheckPython optimized
|
||||||
# ======================================================
|
# ======================================================
|
||||||
|
|
||||||
%changelog
|
%changelog
|
||||||
* Thu Aug 13 2026 Karolina Surma <ksurma@redhat.com> - 3.12.14-1
|
|
||||||
- Update to Python 3.12.14
|
|
||||||
|
|
||||||
* Tue Jul 28 2026 Lukáš Zachar <lzachar@redhat.com> - 3.12.13-6
|
|
||||||
- Security fix for CVE-2026-15308
|
|
||||||
Resolves: rhbz#2498688
|
|
||||||
|
|
||||||
* Tue Jul 28 2026 Miro Hrončok <mhroncok@redhat.com> - 3.12.13-5
|
|
||||||
- Skip UDP Lite tests if it's not supported
|
|
||||||
- Fixes FTBFS on Linux kernel 7.1 and newer
|
|
||||||
|
|
||||||
* Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 3.12.13-4
|
|
||||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
|
|
||||||
|
|
||||||
* Thu Apr 16 2026 Charalampos Stratakis <cstratak@redhat.com> - 3.12.13-3
|
|
||||||
- Security fixes for CVE-2026-1502, CVE-2026-4786, CVE-2026-6100, CVE-2026-2297, CVE-2026-3644, CVE-2026-4224
|
|
||||||
Resolves: rhbz#2444705, rhbz#2448189, rhbz#2448205, rhbz#2457942, rhbz#2458014, rhbz#2458222
|
|
||||||
|
|
||||||
* Thu Mar 26 2026 Lumír Balhar <lbalhar@redhat.com> - 3.12.13-2
|
|
||||||
- Security fix for CVE-2026-4519 (rhbz#2449728)
|
|
||||||
|
|
||||||
* Tue Mar 03 2026 Tomáš Hrnčiar <thrnciar@redhat.com> - 3.12.13-1
|
|
||||||
- Update to 3.12.13
|
|
||||||
|
|
||||||
* Fri Feb 06 2026 Tomáš Hrnčiar <thrnciar@redhat.com> - 3.12.12-4
|
|
||||||
- Security fixes for CVE-2026-0865, CVE-2025-15366 and CVE-2025-15367
|
|
||||||
|
|
||||||
* Fri Jan 16 2026 Lumír Balhar <lbalhar@redhat.com> - 3.12.12-3
|
|
||||||
- Security fix for CVE-2025-13836
|
|
||||||
|
|
||||||
* Tue Jan 06 2026 Lumír Balhar <lbalhar@redhat.com> - 3.12.12-2
|
|
||||||
- Security fix for CVE-2025-12084
|
|
||||||
- Require at least the same expat version as used during the build time
|
|
||||||
|
|
||||||
* Fri Oct 10 2025 Karolina Surma <ksurma@redhat.com> - 3.12.12-1
|
* Fri Oct 10 2025 Karolina Surma <ksurma@redhat.com> - 3.12.12-1
|
||||||
- Update to 3.12.12
|
- Update to 3.12.12
|
||||||
|
|
||||||
|
|
|
||||||
4
sources
4
sources
|
|
@ -1,2 +1,2 @@
|
||||||
SHA512 (Python-3.12.14.tar.xz) = 9007399ffdd3a493c91a98cd7a6cb93acfb8de80f3be2f5480cda36f134d49b5043a60bc6b5c62ed18cc6a2e4e3c81cb7556ac5f337e2cd58ff3449a8099ed22
|
SHA512 (Python-3.12.12.tar.xz) = 4b99d240dd96a6e154909dcffe87f8bb38193d634cd80a1c3d9e819b7a63af2afa46d5e6423e81f00dd388840dc29a4a71580f6aa1ce9a12e559c1d63f65a205
|
||||||
SHA512 (Python-3.12.14.tar.xz.asc) = 69cc4757f5d79ea46f9b632d5b34f9f16855cb1f767f77c827ad65546ba8f77b68e75a661ebc4e4f453edd7a98a73d916491597f67d4fed9c891aa599a869324
|
SHA512 (Python-3.12.12.tar.xz.asc) = 32c10fd427c6f9f11595493d1b4d4c3cade85bffd439fe11e8b0b2c619e06734097b6aaedfdb4fe035b7fdd7196714dba77cdc806923e4454d5bcf60056991a0
|
||||||
|
|
|
||||||
1
tests/.fmf/version
Normal file
1
tests/.fmf/version
Normal file
|
|
@ -0,0 +1 @@
|
||||||
|
1
|
||||||
Loading…
Add table
Add a link
Reference in a new issue