Conversation
mcepl
force-pushed
the
opensuse_3.6-openssl_3.2
branch
from
September 20, 2026 20:04
93882ca to
de22aa2
Compare
mcepl
force-pushed
the
opensuse_3.6-openssl_3.2
branch
5 times, most recently
from
September 25, 2026 16:55
e0d2c7a to
b24aa6c
Compare
mcepl
force-pushed
the
opensuse_3.6-openssl_3.2
branch
from
October 1, 2026 17:47
b24aa6c to
ac50dad
Compare
Backport the relevant behavior changes from bpo-45436 (4fe454c), bpo-41306 (aecf036), and the bpo-45979 correction (dbbe4d2). Retain the older Tk expectations. On Tk 8.6.11+, explicitly test empty Menu.type and ttk compound values while still rejecting invalid enum values. On Tk 8.6.10+, expect Scale.from to retain its fractional value. Validated test_tk and test_ttk_guionly with Python 3.6 and Tcl/Tk 8.6.12 on openSUSE Leap 15.6, including the affected widget classes with wantobjects disabled. Patch: tkinter-tests-tk-8.6.12.patch
Regenerate configure and pyconfig.h.in before the full build so locale coercion is enabled. Install glibc-locale-base for the UTF-32 converters required by GDB. Replace the public HTTP endpoint in test_issue16464 with a mocked transport while retaining request and Content-Length checks. Include full GDB command, status and output in failures, with regression coverage for the diagnostics.
Restore ast.Num and ast.Str handling in Argument Clinic for negative numeric defaults and legacy string converters. Use the Python 3.6 Clinic NULL convention for the Unicode escape decoder error defaults and regenerate their header and checksums. Preserve the stateful decoding security fix and final argument. Add regression tests for numeric defaults, string converters, NULL defaults, and expression validation. Verified clean regen-all output, make smelly, and the tool, codec, Unicode, and bytes tests on Leap 15.6.
Add only GITHUB_WORKSPACE to safe.directory in the Git configuration used by shell steps. The checkout action configures its own temporary HOME, leaving subsequent Git commands subject to ownership checks. Use git status and git diff --exit-code for the generated-files check so repository errors are not misreported as stale generated files.
Fixes: gh#phihag/ipaddress!60 Patch: ipaddress-update-pr60.patch
Limit the buffer size for IPv6 address parsing. Fixes: gh#python#128840 Fixes: bsc#1244401 From-PR: gh#python/cpython!128841 From-PR: gh#python/cpython!134836 Patch: gh-128840_parse-IPv6-with-emb-IPv4.patch
…in HTMLParser End-of-file errors are now handled according to the HTML5 specs -- comments and declarations are automatically closed, tags are ignored. (cherry picked from commit 6eb6c5d) Fixes: bsc#1244705 (CVE-2025-6069) Fixes: gh#python#135462 From-PR: gh#python/cpython!135464 Patch: CVE-2025-6069-quad-complex-HTMLParser.patch
The backported fixes do not contain changes for ntpath.py and related tests, because the support for symlinks and junctions were added later in Python 3.9, and it does not make sense to backport them to 3.6 here. The patch is contains the following changes: - gh#python/cpython!108274 fixes symlink handling for tarfile.data_filter - gh#python/cpython!21409 fixes handling of existing files/symlinks in tarfile - gh#python/cpython!135035 adds a new "strict" argument to realpath() - gh#python/cpython!135084 fixes mulriple CVE fixes in the tarfile module - downstream only fixes that makes the changes work and compatible with Python 3.6 Fixes: bsc#1244032 (CVE-2025-4517) Fixes: bsc#1244056 (CVE-2024-12718) Fixes: bsc#1244059 (CVE-2025-4138) Fixes: bsc#1244060 (CVE-2025-4330) Fixes: bsc#1244061 (CVE-2025-4435) From-PR: gh#python/cpython!108274 From-PR: gh#python/cpython!21409 From-PR: gh#python/cpython!135035 From-PR: gh#python/cpython!135084 From-PR: gh#fedora-python/cpython!129 Patch: CVE-2025-4435-normalize-lnk-trgts-tarfile.patch
…ts are non-negative Fixes: bsc#1247249 (CVE-2025-8194) Fixes: gh#python#130577 From-PR: gh#python/cpython!137027 Patch: CVE-2025-8194-tarfile-no-neg-offsets.patch
…ry record Support records with "zip64 extensible data" if there are no bytes prepended to the ZIP file. Fixes: gh#python#139700 Fixes: bsc#1251305 (CVE-2025-8291) From-PR: gh#python/cpython!139702 Patch: CVE-2025-8291-consistency-zip64.patch
Replaces the hand-rolled, character-by-character scanning loops in posixpath.expandvars() and ntpath.expandvars() with a single re.sub() pass over lazily compiled regular expressions (compiled once and cached in the module-level _varsub/_varsubb globals). Fixes: bsc#1252974 (CVE-2025-6075) Fixes: gh#python#136065 From-PR: gh#python/cpython!134952 Patch: CVE-2025-6075-expandvars-perf-degrad.patch
Reading the whole body of the HTTP response could cause OOM if the Content-Length value is too large even if the server does not send a large amount of data. Now the HTTP client reads large data by chunks, therefore the amount of consumed memory is proportional to the amount of sent data. Fixes: bsc#1254400 (CVE-2025-13836) Fixes: gh#python#119451 From-PR: gh#python/cpython!119454 Patch: CVE-2025-13836-http-resp-cont-len.patch
* Remove quadratic behavior in node ID cache clearing * Add news fragment Fixes: bsc#1254997 (CVE-2025-12084) Fixes: gh#python#142145 From-PR: gh#python/cpython!142213 Patch: CVE-2025-12084-minidom-quad-search.patch
Reading a specially prepared small Plist file could cause OOM because file's read(n) preallocates a bytes object for reading the specified amount of data. Now plistlib reads large data by chunks, therefore the upper limit of consumed memory is proportional to the size of the input file. Fixes: bsc#1254401 (CVE-2025-13837) Fixes: gh#python#119342 From-PR: gh#python/cpython!119343 Patch: CVE-2025-13837-plistlib-mailicious-length.patch
Fix a bug in the folding of comments when flattening an email message using a modern email policy. Comments consisting of a very long sequence of non-foldable characters could trigger a forced line wrap that omitted the required leading space on the continuation line, causing the remainder of the comment to be interpreted as a new header field. This enabled header injection with carefully crafted inputs. Issue: Fix folding of long comments of unfoldable characters in email headers python#143935 Signed-off-by: Edgar Ramírez Mondragón <edgarrm358@gmail.com> Fixes: bsc#1257029 (CVE-2025-11468) Fixes: gh#python#143935 From-PR: gh#python/cpython!143936 Patch: CVE-2025-11468-email-hdr-fold-comment.patch
Hardens Python's `http.cookies` module by rejecting control characters in cookie values during parsing, preventing malformed or potentially unsafe cookie data from being accepted. Fixes: bsc#1257031 (CVE-2026-0672) Fixes: gh#python#143919 From-PR: gh#python/cpython!143920 Patch: CVE-2026-0672-http-hdr-inject-cookie-Morsel.patch
Add 'test.support' fixture for C0 control characters Fixes: bsc#1257042 (CVE-2026-0865) Fixes: gh#python#143916 From-PR: gh#python/cpython!143917 From-PR: gh#python/cpython!144118 Patch: CVE-2026-0865-wsgiref-ctrl-chars.patch
This is a security fix to `imaplib` that makes the client raise an error when IMAP commands (such as those built from untrusted header or data values) contain ASCII control characters, preventing injection of stray control sequences/commands into the IMAP protocol stream. Fixes: bsc#1257044 (CVE-2025-15366) From-PR: gh#python/cpython!143922 Patch: CVE-2025-15366-imap-ctrl-chars.patch
This modifies Python's `urllib` handling of `data:` URLs to reject control characters in the mediatype portion, preventing malformed data URLs with control characters in their media types from being parsed. Fixes: bsc#1257046 (CVE-2025-15282) Fixes: gh#python#143925 From-PR: gh#python/cpython!143926 Patch: CVE-2025-15282-urllib-ctrl-chars.patch
This is a security fix to `poplib` that makes the client raise an error when POP3 commands (such as those built from untrusted header or data values) contain ASCII control characters, preventing injection of stray control sequences/commands into the POP3 protocol stream. Fixes: bsc#1257041 (CVE-2025-15367) Fixes: gh#python#143923 From-PR: gh#python/cpython!143924 Patch: CVE-2025-15367-poplib-ctrl-chars.patch
This patch fixes a CRLF injection vulnerability in http.client by enforcing that carriage return and line feed characters are rejected in proxy tunnel headers and host fields to prevent HTTP response splitting and header injection. Fixes: bsc#1261969 (CVE-2026-1502) Fixes: gh#python#146211 From-PR: gh#python/cpython!146212 Patch: CVE-2026-1502-reject-CRLF-HTTP-tunnel.patch
This patch fixes a cross-site scripting (XSS) vulnerability in http.cookies.Morsel.js_output() by base64-encoding cookie values embedded in generated JavaScript snippets to prevent HTML string-context escaping. Fixes: bsc#1262654 (CVE-2026-6019) Fixes: gh#python#90309 From-PR: gh#python/cpython!148848 Patch: CVE-2026-6019-Morsel-js_output.patch
… fallback Fixes: bsc#1268977 (CVE-2026-11940) Fixes: gh#python#151558 From-PR: gh#python#151559 Patch: CVE-2026-11940-tarfile-escape.patch
ftpcp() called parse227() directly and passed the source server's self-reported PASV IPv4 address to the target server's PORT command, bypassing the CVE-2021-4189 fix that was applied only to FTP.makepasv(). A malicious source FTP server could use this to redirect the target server's data connection to an arbitrary host:port (SSRF). ftpcp() now uses the source server's actual peer address, honoring the existing trust_server_pasv_ipv4_address opt-out, the same as makepasv(). Fixes: bsc#1265268 (CVE-2026-8328) Fixes: gh#python#87451 From-PR: gh#python/cpython!149648 Patch: CVE-2026-8328-ftplib-no-trust-PASV-resp.patch
This patch mitigates an insufficient entropy vulnerability by updating pyexpat and xml.etree.ElementTree to use Expat 2.8.0's XML_SetHashSalt16Bytes API, passing 16 bytes of salt to prevent XML hash-flooding attacks. Fixes: bsc#1264962 (CVE-2026-7210) Fixes: gh#python#149018 From-PR: gh#python/cpython!149023 Patch: CVE-2026-7210-pyexpat-entropy-hash-flooding.patch
…TMLParser When an unterminated construct (e.g. a tag or comment) spanned many feed() calls, rescanning the growing buffer and concatenating new data onto it were both quadratic. New data is now accumulated in a list and only joined and parsed once enough has piled up. Fixes: bsc#1271192 (CVE-2026-15308) Fixes: gh#python#153030 From-PR: gh#python/cpython!153031 Patch: CVE-2026-15308-HTMLParser-CPU-exhaust.patch
… .extract() This patch ensures TarFile.extract() properly passes the filter parameter to _extract_one() when fallback extraction occurs for missing hardlink targets. Fixes: bsc#1269959 (CVE-2026-4360) Fixes: gh#python#151987 From-PR: gh#python/cpython!151988 Patch: CVE-2026-4360-filter_function-TarFile-extractone.patch
The patch updates tarfile test suites and validations to ensure strict checks on hardlink extraction fallback scenarios against path traversal and filter violations. Fixes: bsc#1269788 (CVE-2026-11972) Fixes: gh#python#151981 From-PR: gh#python/cpython!151982 Patch: CVE-2026-11972-tarfile-Stream-seek-EOF.patch
The data filter rewrote linknames with normpath() but ran the containment check against the un-normalised value, and computed a symlink's directory before stripping trailing slashes. Both let a crafted archive create links pointing outside the destination. Also reject link members that resolve to the destination directory itself, which could otherwise replace it with a symlink and redirect all subsequent members. Fixes: bsc#1267821 (CVE-2026-7774) Fixes: gh#python#149486 From-PR: gh#python/cpython!149487 Patch: CVE-2026-7774-tarfile-data_filter-symlink.patch
…igparser This normalizes all line endings (CR, CRLF, and LF) to multiline continuation format (LF+TAB), preventing configuration injection vulnerabilities across mixed platform environments. Fixes: bsc#1269066 (CVE-2026-0864) Fixes: gh#python#143927 From-PR: gh#python/cpython!143929 Patch: CVE-2026-0864-normalize-LFTAB-configparser.patch
…rt in js_output() Replace the base64/atob round-trip in Morsel.js_output() with urllib.parse.quote() and decodeURIComponent(). atob() produced a binary string, so cookie values containing non-ASCII characters were corrupted when assigned to document.cookie. Fixes: bsc#1263083 (follow-up to CVE-2026-6019) Fixes: gh#python#149144 For-PR: gh#python/cpython!149157 Patch: bsc1263083-http-cookies-atob-utf8.patch
Replace the insertion sort used for canonical ordering of combining characters with a hybrid approach: insertion sort for short runs (< 20) and counting sort for longer runs, reducing worst-case complexity from O(n^2) to O(n). This prevents denial of service via crafted Unicode strings with many combining characters in alternating CCC order. Fixes: bsc#1267581 (CVE-2026-3276) Fixes: gh#python#149079 From-PR: gh#python/cpython!149080 Patch: CVE-2026-3276-On2-unicodedata-normalize.patch
The patch fixes a quadratic time complexity Denial of Service vulnerability in csv.Sniffer.sniff() when processing samples with quoted fields. Fixes: bsc#1274683 (CVE-2026-18503) Fixes: gh#python#98820 From-PR: gh#python/cpython!154867 Patch: CVE-2026-18503-csv-sniffer-quadratic-time.patch
The patch prevents a stack buffer overflow by disallowing the reuse of BZ2Decompressor objects after an error occurs. Fixes: bsc#1267974 (CVE-2026-9669) Fixes: gh#python#150599 From-PR: gh#python/cpython!151054 Patch: CVE-2026-9669-no-reuse-bz2-decompress.patch
Credentials stored for an https:// URI were also matched against the corresponding http:// URI, since `reduce_uri()` discards the scheme. `HTTPPasswordMgr` and `HTTPPasswordMgrWithPriorAuth` now compare the scheme too; URIs registered without a scheme still match any scheme. Fixes: bsc#1276223 (CVE-2026-15806) Fixes: gh#python#155694 From-PR: gh#python/cpython!155696 Patch: CVE-2026-15806-HTTPPasswordMgr-scheme.patch
…RFC 3454 Due to a bug, some Unicode codepoint attributes were considered for characters not yet defined in Unicode 3.2.0 or attributes which changed in later Unicode versions. RFC 3454 (StringPrep) requires using Unicode 3.2.0 strictly. Fixes: bsc#1276226 (CVE-2026-17084) Fixes: gh#python#155292 From-PR: gh#python/cpython!155293 Patch: CVE-2026-17084-stringprep-rfc3454.patch
Py_EnterRecursiveCall() only tracks the Python recursion limit, which Python code can raise, so it by itself does not bound C stack usage. Add an independent hard limit on the content-model nesting depth so a crafted DTD cannot overflow the C stack. Fixes: bsc#1259735 (CVE-2026-4224) Patch: CVE-2026-4224-expat-recursion-depth.patch
The committed clinic output was stale after the a2b_base64() signature change, which made the "Check generated files" job fail. Regenerate it with Tools/clinic/clinic.py. Fixes: bsc#1261970 (CVE-2026-3446) Patch: CVE-2026-3446-base64-padding-clinic.patch
The documentation still claimed that get_data() can follow parent directories and absolute paths, which contradicts the validation added for CVE-2026-3479. Also register the `cve` Sphinx role used by the NEWS entry for this CVE. Fixes: bsc#1259989 (CVE-2026-3479) Patch: CVE-2026-3479-pkgutil_get_data-docs.patch
mcepl
force-pushed
the
opensuse_3.6-openssl_3.2
branch
from
October 1, 2026 20:20
ac50dad to
4aab025
Compare
Backports the upstream CPython changes porting _ssl and _hashlib to OpenSSL 1.1.1/3.x: - Modules/_ssl.c and Modules/_hashopenssl.c changes - version-specific error tables _ssl_data_111.h / _ssl_data_300.h - rewritten Tools/ssl/make_ssl_data.py, Tools/ssl/multissltests.py - OP_IGNORE_UNEXPECTED_EOF, ERR_func_error_string deprecation guard, load_verify_locations fixes, OpenSSL 3.0 password-callback fix - test and documentation updates plus the accompanying Misc/NEWS.d fragments Patch: python36-OpenSSL-32.patch
Newer compilers (GCC 14, Clang 16) reject implicit function declarations and implicit int by default, which makes some configure run tests fail and silently change the detected configuration: - PTHREAD_SCOPE_SYSTEM check: declare "int main()" (pythongh-99086). - broken nice() check: include <stdlib.h> and <unistd.h>. Patch: python36-OpenSSL-32-no-implicit.patch
Introduce Modules/_ssl_compat.h, included by both _ssl.c and _hashopenssl.c, as the single place for OpenSSL/LibreSSL version detection and API shims. - Define PY_OPENSSL_3_API, PY_OPENSSL_1_1_API, PY_OPENSSL_1_1, PY_OPENSSL_1_1_1, PY_OPENSSL_3_3 and PY_OPENSSL_PRE_1_1, and refuse to build against OpenSSL older than 1.0.2. - Provide modern (1.1.0/3.0) names as shims over the old API only when building against older libraries (OpenSSL_version*, EVP_MD_CTX_new/free, ASN1_STRING_get0_data, X509_get0_notBefore/After, SSL_get1_peer_certificate, TLS_*method). With OpenSSL 3 nothing maps onto deprecated functions. - Move the pre-1.1 struct accessor shims out of _ssl.c into the header. - Replace OPENSSL_VERSION_1_1/OPENSSL_VERSION_3_3 in _ssl.c with the new macros. - Fix _hashopenssl.c: its init guard tested OPENSSL_VERSION_1_1, which was never defined there, so OPENSSL_add_all_algorithms_noconf() and ERR_load_crypto_strings() ran even with OpenSSL 3. They now only run for pre-1.1 libraries. - Only silence -Wdeprecated-declarations in _ssl.c for pre-3.0 builds, so remaining uses of deprecated API are visible with OpenSSL 3. Patch: python36-OpenSSL-32-ssl-compat-h.patch
Replace deprecated calls on the OpenSSL 3 build path, keeping the old code for pre-1.1/pre-3.0 builds behind version checks: - ERR_get_state() is only called for pre-1.1 (error state is initialised automatically since 1.1.0). - ASN1_STRING_data -> ASN1_STRING_get0_data, X509_get_notBefore/After -> X509_get0_notBefore/After, SSL_get_peer_certificate -> SSL_get1_peer_certificate (shims in _ssl_compat.h for old libraries). - SSLeay()/SSLeay_version() -> OpenSSL_version_num()/OpenSSL_version(). Drop the runtime CVE-2014-0198 check around SSL_MODE_RELEASE_BUFFERS: all affected versions are below the supported minimum (1.0.2). - PROTOCOL_TLSv1/TLSv1_1/TLSv1_2/SSLv3: with the 1.1 API use TLS_method() and pin min/max protocol version instead of the deprecated version-specific methods. - load_dh_params(): with OpenSSL 3 read parameters through PEM_read_bio_Parameters_ex() and install them with SSL_CTX_set0_tmp_dh_pkey(); reject non-DH files. Also fix both code paths returning None with an exception set when setting the parameters failed, and leaking nothing on error. - set_ecdh_curve(): with OpenSSL 3 use SSL_CTX_set1_groups() instead of EC_KEY + SSL_CTX_set_tmp_ecdh(). - RAND_pseudo_bytes(): use RAND_bytes() with the 1.1 API. - SSLSession.time: use Y2038-safe SSL_SESSION_get_time_ex() on 3.3+. _ssl.c and _hashopenssl.c now compile against OpenSSL 3.5 with -DOPENSSL_API_COMPAT=0x30000000L -DOPENSSL_NO_DEPRECATED -Werror=deprecated-declarations. Patch: python36-OpenSSL-32-3-only.patch
- Add py_digest_by_name()/PY_EVP_MD_free(). With OpenSSL 3 digests are obtained with EVP_MD_fetch() from the default library context, so provider properties (e.g. FIPS) apply and no legacy EVP_MD objects are used. Legacy aliases such as "RSA-SHA256", which are still reported in openssl_md_meth_names, are resolved to their canonical name before fetching. Older libraries keep using EVP_get_digestbyname(). Fetched digests are released after EVP_DigestInit()/PKCS5_PBKDF2_HMAC(), the context holds its own reference. - Check the EVP_MD_CTX_new() result in the named constructors (openssl_md5() & co.) and do the digest lookup only once. - Check the EVP_MD_CTX_copy() result in EVPnew(). - INIT_CONSTRUCTOR_CONSTANTS: fail module init if the name object cannot be created, and drop the stray semicolon after while (0). test_ssl: with OpenSSL 3 load_dh_params() now reads parameters through the OSSL_DECODER API, which reports errors from that library instead of PEM/NO_START_LINE; adjust test_lib_reason accordingly. Patch: python36-OpenSSL-32-3-digests.patch
Version checks:
- All checks for OpenSSL < 1.0.2 are now always true (1.0.2 is the
enforced minimum), so resolve them: TLSv1.1/1.2 support,
SSL_CTX_clear_options(), cipher_to_dict()/get_ciphers(),
CRYPTO_THREADID, and the PBKDF2 availability check.
- The SNI/IP address check tested 0x10200000L, a version that never
existed (meant 1.0.2), so OpenSSL 1.0.2 and 1.1.x silently used the
inet_pton() fallback. a2i_IPADDRESS() is available in every supported
version; use it unconditionally.
- Select the error-code table and the scrypt/ERR_func_error_string code
with the _ssl_compat.h macros; LibreSSL explicitly uses _ssl_data.h.
- Regenerate the Argument Clinic output accordingly.
Error handling:
- Remove the no-op SSL_R_CERTIFICATE_VERIFY_FAILED block from the
SSL_ERROR_SYSCALL branch of PySSL_SetError(): type already defaults to
SSLError and verification failures are reported as SSL_ERROR_SSL.
Instead, in the SSL_ERROR_SSL branch append the X509 verification
reason ("certificate verify failed: unable to get local issuer
certificate"), the same message format as Python 3.7+.
- _add_ca_certs(), _setSSLError(): keep OpenSSL error codes in unsigned
long. With OpenSSL 3 system errors have bit 31 set and were mangled by
the conversion to int before being decoded.
Patch: python36-OpenSSL-32-obsolete-version-check.patch
- Fix the OpenSSL minimum version check. The regex could not parse OpenSSL 3's opensslv.h, where OPENSSL_VERSION_NUMBER is an expression of OPENSSL_VERSION_MAJOR/MINOR/PATCH, so _hashlib was considered too old. The new _detect_openssl_version() understands both formats (and LibreSSL). The minimum is now 1.0.2, matching Modules/_ssl_compat.h, and it applies to both _ssl and _hashlib (previously _ssl was built with any OpenSSL). - Add _ssl_compat.h and the _ssl_data*.h error tables to the depends lists of _ssl and _hashlib. - pyexpat: fall back to the system libexpat when the bundled Modules/expat directory has been removed from the tree. Patch: python36-OpenSSL-32-setup-py-version-detection.patch
test_hashlib: - Restore test_refleaks_in_hash___init__ and the pbkdf2_hmac argument validation assertions, which had been deleted, and go back to the original c_hashlib/py_hashlib module names. - Drop the imports of HASHXOF and get_fips_mode from _hashlib (they do not exist in 3.6, so the ImportError fallback always won and FIPS mode was never detected) and the PY_BUILTIN_HASHLIB_HASHES config variable (also 3.9+ only). Detect FIPS mode from /proc/sys/crypto/fips_enabled instead. - The "unsupported hash type" message is stable again, as _hashlib no longer leaks OpenSSL 3 fetch errors into it. test_ssl: - Replace the unconditional "OpenSSL 3 effectively disables TLS < 1.2" skip, and the removal of TLSv1/TLSv1.1 from test_echo, with seclevel_workaround() (as in 3.10): with OpenSSL 3, lower the security level to 0 for connections involving TLS < 1.2. With OPENSSL_CONF=/dev/null all legacy protocol tests now run and pass. - skip_if_openssl_cnf_minprotocol_gt_tls11 now follows .include directives and recognises "TLS.MinProtocol", as used by system-wide crypto policies (openSUSE, Fedora). - clean_OpenSSL30_san(): decide by the runtime library version. - Fix the OPENSSL_VERSION_NUMBER upper bound comment/value (< 4.0) and drop the unused PY_SSL_DEFAULT_CIPHERS/sysconfig import. test_ftplib: disable TLS 1.3 on the dummy TLS server (bpo-32947, as in 3.7). With TLS 1.3 test_check_hostname hung, because the server only learns about the client rejecting the certificate after the handshake. test.support.hashlib_helper: drop the unused usedforsecurity parameter. Patch: python36-OpenSSL-32-tests.patch
- Describe the supported OpenSSL range (1.0.2 - 3.x) and the behaviour differences with OpenSSL 3: TLS 1.0/1.1 need a lowered security level, version-pinned PROTOCOL_TLSv1* contexts (and that, as before, they override a system-wide MinProtocol), OP_IGNORE_UNEXPECTED_EOF being on by default, and load_dh_params() errors coming from OSSL_DECODER. - OP_IGNORE_UNEXPECTED_EOF: say that it is enabled by default, explain the truncation risk and how to turn it off, and fix the "versionadded:: 3.10" which is wrong for this backport. - Add a NEWS entry summarising the OpenSSL 3 API port. - ignore false-positive :ALL markup warning in susp-ignored.csv Patch: python36-OpenSSL-32-documentation.patch
mcepl
force-pushed
the
opensuse_3.6-openssl_3.2
branch
from
October 1, 2026 22:21
4aab025 to
8d3f96a
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Backport SSL and hashlib compatibility changes for OpenSSL 3, together with supporting CPython runtime fixes and build updates.
Changes
Validation
The following suites passed on Linux x86-64 with GCC 16.2.0 and OpenSSL 3.5.3:
Testing used a clean archive of the branch. A temporary rename of the existing sinpi helper was necessary to avoid a conflict with the host C library. That workaround is not part of this branch.
OpenSSL 3.2, FIPS configurations, Windows builds, and the full CPython test suite have not been validated.
Outstanding review findings