gh-101726: Update the OpenSSL version to 1.1.1t by gpshead · Pull Request #101727 · python/cpython (original) (raw)

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Conversation15 Commits5 Checks0 Files changed

Conversation

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.Learn more about bidirectional Unicode characters

[ Show hidden characters]({{ revealButtonHref }})

gpshead

@gpshead

@gpshead

@gpshead

@ned-deily

@ned-deily

ned-deily

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The macOS installer change looks good, thanks.

@ambv

@zooba

I'm working on the build, but OpenSSL introduced an ARM64 regression and consider the platform "unadopted" and so won't rerelease to fix it: openssl/openssl#20234

I'll pull the patch into our own sources and retag them.

@zooba

Binaries have been published, so I retriggered the builds

@miss-islington

Thanks @gpshead for the PR, and @zooba for merging it 🌮🎉.. I'm working now to backport this PR to: 3.7, 3.8, 3.9, 3.10, 3.11.
🐍🍒⛏🤖

@miss-islington

Sorry, @gpshead and @zooba, I could not cleanly backport this to 3.11 due to a conflict.
Please backport using cherry_picker on command line.
cherry_picker b41c47cd0606e8273aef4813e83fe2deaf9ab33b 3.11

@miss-islington

Sorry @gpshead and @zooba, I had trouble checking out the 3.10 backport branch.
Please retry by removing and re-adding the "needs backport to 3.10" label.
Alternatively, you can backport using cherry_picker on the command line.
cherry_picker b41c47cd0606e8273aef4813e83fe2deaf9ab33b 3.10

@miss-islington

Sorry, @gpshead and @zooba, I could not cleanly backport this to 3.9 due to a conflict.
Please backport using cherry_picker on command line.
cherry_picker b41c47cd0606e8273aef4813e83fe2deaf9ab33b 3.9

@miss-islington

Sorry @gpshead and @zooba, I had trouble checking out the 3.8 backport branch.
Please retry by removing and re-adding the "needs backport to 3.8" label.
Alternatively, you can backport using cherry_picker on the command line.
cherry_picker b41c47cd0606e8273aef4813e83fe2deaf9ab33b 3.8

@miss-islington

Sorry, @gpshead and @zooba, I could not cleanly backport this to 3.7 due to a conflict.
Please backport using cherry_picker on command line.
cherry_picker b41c47cd0606e8273aef4813e83fe2deaf9ab33b 3.7

@bedevere-bot

zooba pushed a commit to zooba/cpython that referenced this pull request

Feb 9, 2023

@gpshead @zooba

@bedevere-bot

@bedevere-bot

zooba pushed a commit to zooba/cpython that referenced this pull request

Feb 9, 2023

@gpshead @zooba

@bedevere-bot

zooba pushed a commit to zooba/cpython that referenced this pull request

Feb 9, 2023

@gpshead @zooba

@bedevere-bot

zooba added a commit that referenced this pull request

Feb 9, 2023

@zooba @gpshead

zooba added a commit that referenced this pull request

Feb 9, 2023

@zooba @gpshead

ned-deily added a commit that referenced this pull request

Feb 9, 2023

carljm added a commit to carljm/cpython that referenced this pull request

Feb 10, 2023

@carljm

ned-deily added a commit that referenced this pull request

Mar 7, 2023

ned-deily added a commit that referenced this pull request

Mar 7, 2023

@gpshead gpshead deleted the security/openssl-bin-1.1.1t branch

May 31, 2023 22:25

carlosroman added a commit to DataDog/cpython that referenced this pull request

Jun 22, 2023

Co-authored-by: Benjamin Peterson benjamin@python.org

Co-authored-by: Ned Deily nad@python.org

(cherry picked from commit 30a6cc4)

Co-authored-by: Ned Deily nad@python.org Co-authored-by: HARSHA VARDHAN 75431678+Thunder-007@users.noreply.github.com

(cherry picked from commit 1cf3d78) (cherry picked from commit 88fe8d7)

Co-authored-by: Jeremy Paige ucodery@gmail.com Co-authored-by: Gregory P. Smith greg@krypto.org

(cherry picked from commit c22a55c)

Co-authored-by: Hugo van Kemenade hugovk@users.noreply.github.com

(cherry picked from commit ea23271)

Co-authored-by: Owain Davies 116417456+OTheDev@users.noreply.github.com

(cherry picked from commit 4652182)

Co-authored-by: Oleg Iarygin oleg@arhadthedev.net Co-authored-by: Steve Dower steve.dower@microsoft.com

[3.8] pythongh-101981: Fix Ubuntu SSL tests with OpenSSL (3.1.0-beta1) CI issue (pythongh-102079)

[3.8] Avoid GHA CI macOS test_posix failure by using the appropriate macOS SDK.

Fixes CVE-2023-0286 (High) and a couple of Medium security issues. https://www.openssl.org/news/secadv/20230207.txt

Co-authored-by: Gregory P. Smith greg@krypto.org Co-authored-by: Ned Deily nad@python.org

(cherry picked from commit 61479d4)

Co-authored-by: Blind4Basics 32236948+Blind4Basics@users.noreply.github.com Co-authored-by: C.A.M. Gerlach CAM.Gerlach@Gerlach.CAM Co-authored-by: Hugo van Kemenade hugovk@users.noreply.github.com

(cherry picked from commit 89d9ff0)

Backport of c8c3956

(cherry picked from commit 0aeda29)

Co-authored-by: Sam Carroll 70000253+samcarroll42@users.noreply.github.com

Do not expose the local server's on-disk location from SimpleHTTPRequestHandler when generating a directory index. (unnecessary information disclosure)

(cherry picked from commit c7c3a60)

Co-authored-by: Ethan Furman ethan@stoneleaf.us Co-authored-by: Gregory P. Smith greg@krypto.org Co-authored-by: Jelle Zijlstra jelle.zijlstra@gmail.com

Co-authored-by: Tian Gao gaogaotiantian@hotmail.com

(cherry picked from commit ee26ca1)

Co-authored-by: Irit Katriel 1055913+iritkatriel@users.noreply.github.com

urllib.parse.urlsplit has already been respecting the WHATWG spec a bit pythonGH-25595.

This adds more sanitizing to respect the "Remove any leading C0 control or space from input" rule in response to CVE-2023-24329.

I simplified the docs by eliding the state of the world explanatory paragraph in this security release only backport. (people will see that in the mainline /3/ docs)

(cherry picked from commit d7f8a5f) (cherry picked from commit 2f630e1) (cherry picked from commit 610cc0a) (cherry picked from commit f48a96a)

Co-authored-by: Miss Islington (bot) 31488909+miss-islington@users.noreply.github.com Co-authored-by: Illia Volochii illia.volochii@gmail.com Co-authored-by: Gregory P. Smith [Google] greg@krypto.org

Upgrade builds to OpenSSL 1.1.1u.

Also updates _ssl_data_111.h from OpenSSL 1.1.1u, _ssl_data_300.h from 3.0.9.

Manual edits to the _ssl_data_300.h file prevent it from removing any existing definitions in case those exist in some peoples builds and were important (avoiding regressions during backporting).

(cherry picked from commit ede89af) (cherry picked from commit e15de14)

Co-authored-by: Gregory P. Smith greg@krypto.org Co-authored-by: Ned Deily nad@python.org


Co-authored-by: Łukasz Langa lukasz@langa.pl Co-authored-by: Benjamin Peterson benjamin@python.org Co-authored-by: Ned Deily nad@python.org Co-authored-by: Miss Islington (bot) 31488909+miss-islington@users.noreply.github.com Co-authored-by: HARSHA VARDHAN 75431678+Thunder-007@users.noreply.github.com Co-authored-by: Gregory P. Smith greg@krypto.org Co-authored-by: Jeremy Paige ucodery@gmail.com Co-authored-by: Hugo van Kemenade hugovk@users.noreply.github.com Co-authored-by: Steve Dower steve.dower@python.org Co-authored-by: Owain Davies 116417456+OTheDev@users.noreply.github.com Co-authored-by: Éric earaujo@caravan.coop Co-authored-by: Oleg Iarygin oleg@arhadthedev.net Co-authored-by: Steve Dower steve.dower@microsoft.com Co-authored-by: Dong-hee Na donghee.na@python.org Co-authored-by: Blind4Basics 32236948+Blind4Basics@users.noreply.github.com Co-authored-by: C.A.M. Gerlach CAM.Gerlach@Gerlach.CAM Co-authored-by: Pradyun Gedam pradyunsg@gmail.com Co-authored-by: Petr Viktorin encukou@gmail.com Co-authored-by: Sam Carroll 70000253+samcarroll42@users.noreply.github.com Co-authored-by: Ethan Furman ethan@stoneleaf.us Co-authored-by: Jelle Zijlstra jelle.zijlstra@gmail.com Co-authored-by: Tian Gao gaogaotiantian@hotmail.com Co-authored-by: Irit Katriel 1055913+iritkatriel@users.noreply.github.com Co-authored-by: stratakis cstratak@redhat.com Co-authored-by: Illia Volochii illia.volochii@gmail.com