Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

python38-devel-3.8.19-3.1 RPM for ppc64le

From OpenSuSE Ports Tumbleweed for ppc64le

Name: python38-devel Distribution: openSUSE Tumbleweed
Version: 3.8.19 Vendor: openSUSE
Release: 3.1 Build date: Fri Jun 21 11:44:24 2024
Group: Unspecified Build host: reproducible
Size: 895407 Source RPM: python38-core-3.8.19-3.1.src.rpm
Summary: Include Files and Libraries Mandatory for Building Python Modules
The Python programming language's interpreter can be extended with
dynamically loaded extensions and can be embedded in other programs.

This package contains header files, a static library, and development
tools for building Python modules, extending the Python interpreter or
embedding Python in applications.

This also includes the Python distutils, which were in the Python
package up to version 2.2.2.






* Fri Jun 21 2024 Matej Cepl <>
  - Add CVE-2024-0397-memrace_ssl.SSLContext_cert_store.patch
    fixing bsc#1226447 (CVE-2024-0397) by removing memory race
    condition in ssl.SSLContext certificate store methods.
* Sun Mar 24 2024 Matej Cepl <>
  - Add old-libexpat.patch making the test suite work with
    libexpat < 2.6.0 (gh#python/cpython#117187).
* Thu Mar 21 2024 Matej Cepl <>
  - Update to 3.8.19:
    - Security
    - gh-115398: Allow controlling Expat >=2.6.0 reparse deferral
      (CVE-2023-52425, bsc#1219559) by adding five new methods:
    - gh-115399: Update bundled libexpat to 2.6.0
    - gh-113659: Skip .pth files with names starting with a dot
      or hidden file attribute.
    - Core and Builtins
    - gh-102388: Fix a bug where iso2022_jp_3 and iso2022_jp_2004
      codecs read out of bounds
    - Library
    - gh-115197: urllib.request no longer resolves the hostname
      before checking it against the system’s proxy bypass list
      on macOS and Windows.
    - gh-115133: Fix tests for XMLPullParser with Expat 2.6.0.
    - gh-81194: Fix a crash in socket.if_indextoname() with
      specific value (UINT_MAX). Fix an integer overflow in
      socket.if_indextoname() on 64-bit non-Windows platforms.
    - gh-109858: Protect zipfile from “quoted-overlap”
      zipbomb. It now raises BadZipFile when try to read an entry
      that overlaps with other entry or central directory
      (CVE-2024-0450, bsc#1221854).
    - gh-107077: Seems that in some conditions, OpenSSL will
      return SSL_ERROR_SYSCALL instead of SSL_ERROR_SSL
      when a certification verification has failed, but
      the error parameters will still contain ERR_LIB_SSL
      detecting this situation and raising the appropiate
      ssl.SSLCertVerificationError. Patch by Pablo Galindo
    - gh-91133: Fix a bug in tempfile.TemporaryDirectory cleanup,
      which now no longer dereferences symlinks when working
      around file system permission errors (CVE-2023-6597,
    - Documentation
    - gh-115399: Document CVE-2023-52425 of Expat <2.6.0 under
      “XML vulnerabilities”.
    - Tests
    - gh-108310: SSL tests for pre-handshake close were
      previously not enabled on Python 3.8 due to an incorrect
      backport. This is now fixed. Patch by Lumír Balhar.
  - Remove upstreamed patches:
    - CVE-2023-6597-TempDir-cleaning-symlink.patch
    - libexpat260.patch
  - Refreshed patches:
    - CVE-2019-5010-null-defer-x509-cert-DOS.patch
    - F00102-lib64.patch
    - F00251-change-user-install-location.patch
    - python-3.3.0b1-localpath.patch
    - skip_random_failing_tests.patch
    - SUSE-FEDORA-multilib.patch
* Wed Mar 06 2024 Pedro Monreal <>
  - Use the system-wide crypto-policies [bsc#1211301]
    * Use the system default cipher list instead of hardcoded values
    * Add the --with-ssl-default-suites=openssl configure option
* Fri Feb 23 2024 Matej Cepl <>
  - (bsc#1219666, CVE-2023-6597) Add
    CVE-2023-6597-TempDir-cleaning-symlink.patch (patch from
    gh#python/cpython!99930) fixing symlink bug in cleanup of
* Tue Feb 20 2024 Matej Cepl <>
  - Remove double definition of /usr/bin/idle%%{version} in
* Thu Feb 15 2024 Daniel Garcia <>
  - Add upstream patch libexpat260.patch, Fix tests for XMLPullParser
    with Expat 2.6.0, gh#python/cpython#115289
* Mon Dec 18 2023 Matej Cepl <>
  - Refresh CVE-2023-27043-email-parsing-errors.patch to
    gh#python/cpython!111116, fixing bsc#1210638 (CVE-2023-27043).
  - Thus we can remove Revert-gh105127-left-tests.patch, which is
    now useless.
* Wed Sep 06 2023 Daniel Garcia <>
  - Update to 3.8.18 (bsc#1214692):
    - gh-108310: Fixed an issue where instances of ssl.SSLSocket were
      vulnerable to a bypass of the TLS handshake and included
      protections (like certificate verification) and treating sent
      unencrypted data as if it were post-handshake TLS encrypted data.
      Security issue reported as CVE-2023-40217 by Aapo Oksman. Patch by
      Gregory P. Smith.
    - gh-107845: tarfile.data_filter() now takes the location of
      symlinks into account when determining their target, so it will no
      longer reject some valid tarballs with
    - gh-107565: Update multissltests and GitHub CI workflows to use
      OpenSSL 1.1.1v, 3.0.10, and 3.1.2.
* Thu Aug 03 2023 Matej Cepl <>
  - Add Revert-gh105127-left-tests.patch (gh#python/cpython!106941)
    partially reverting CVE-2023-27043-email-parsing-errors.patch,
    because of the regression in gh#python/cpython#106669.
  - (bsc#1210638, CVE-2023-27043) Add
    CVE-2023-27043-email-parsing-errors.patch, which detects email
    address parsing errors and returns empty tuple to indicate the
    parsing error (old API). (The patch is faulty,
    gh#python/cpython#106669, but upstream decided not to just
    revert it).
* Wed Jun 28 2023 Matej Cepl <>
  - Update to 3.8.17:
    - gh-103142: The version of OpenSSL used in Windows and
      Mac installers has been upgraded to 1.1.1u to address
      CVE-2023-2650, CVE-2023-0465, CVE-2023-0466, CVE-2023-0464,
      as well as CVE-2023-0286, CVE-2022-4303, and CVE-2022-4303
      fixed previously in 1.1.1t (gh-101727).
    - gh-102153: urllib.parse.urlsplit() now strips leading C0
      control and space characters following the specification for
      URLs defined by WHATWG in response to CVE-2023-24329
    - gh-99889: Fixed a security in flaw in uu.decode() that could
      allow for directory traversal based on the input if no
      out_file was specified.
    - gh-104049: Do not expose the local on-disk
      location in directory indexes produced by
    - gh-103935: trace.__main__ now uses io.open_code() for files
      to be executed instead of raw open().
    - gh-102953: The extraction methods in tarfile, and
      shutil.unpack_archive(), have a new filter argument that
      allows limiting tar features than may be surprising or
      dangerous, such as creating files outside the destination
      directory. See Extraction filters for details (fixing
      CVE-2007-4559, bsc#1203750).
  - Remove upstreamed patches:
    - CVE-2023-24329-blank-URL-bypass.patch
    - CVE-2007-4559-filter-tarfile_extractall.patch
* Sat May 06 2023 Matej Cepl <>
  - Add 99366-patch.dict-can-decorate-async.patch fixing
    gh#python/cpython#98086 (backport from Python 3.10 patch in
    gh#python/cpython!99366), fixing bsc#1211158.
* Wed May 03 2023 Matej Cepl <>
  - Add CVE-2007-4559-filter-tarfile_extractall.patch to fix
    CVE-2007-4559 (bsc#1203750) by adding the filter for
    tarfile.extractall (PEP 706).
* Tue Apr 18 2023 Steve Kowalik <>
  - Use python3 modules to build the documentation.
* Wed Mar 01 2023 Matej Cepl <>
  - Add CVE-2023-24329-blank-URL-bypass.patch (CVE-2023-24329,
    bsc#1208471) blocklists bypass via the urllib.parse component
    when supplying a URL that starts with blank characters
* Tue Feb 21 2023 Matej Cepl <>
  - Add provides for readline and sqlite3 to the main Python
* Fri Jan 27 2023 Thorsten Kukuk <>
  - Disable NIS for new products, it's deprecated and gets removed
* Fri Jan 13 2023 Martin Liška <>
  - Suppress warnings for Sphinx 6.0+.
* Thu Dec 08 2022 Matej Cepl <>
  - Update to 3.8.16:
    - python -m http.server no longer allows terminal
      control characters sent within a garbage request to be
      printed to the stderr server log.
      This is done by changing the http.server
      BaseHTTPRequestHandler .log_message method to replace control
      characters with a \xHH hex escape before printing.
    - Avoid publishing list of active per-interpreter
      audit hooks via the gc module
    - The IDNA codec decoder used on DNS hostnames by
      socket or asyncio related name resolution functions no
      longer involves a quadratic algorithm. This prevents a
      potential CPU denial of service if an out-of-spec excessive
      length hostname involving bidirectional characters were
      decoded. Some protocols such as urllib http 3xx redirects
      potentially allow for an attacker to supply such a
      name (CVE-2022-45061).
    - Update bundled libexpat to 2.5.0
    - Port XKCP’s fix for the buffer overflows in SHA-3
    - The deprecated mailcap module now refuses to inject
      unsafe text (filenames, MIME types, parameters) into shell
      commands. Instead of using such text, it will warn and act
      as if a match was not found (or for test commands, as if the
      test failed).
  - Removed upstream patches:
    - CVE-2022-37454-sha3-buffer-overflow.patch
    - CVE-2022-45061-DoS-by-IDNA-decode.patch
* Wed Nov 09 2022 Matej Cepl <>
  - Add CVE-2022-45061-DoS-by-IDNA-decode.patch to avoid
    CVE-2022-45061 (bsc#1205244) allowing DoS by IDNA decoding
    extremely long domain names.
* Fri Oct 28 2022 Matej Cepl <>
  - Add CVE-2022-37454-sha3-buffer-overflow.patch to fix
    bsc#1204577 (CVE-2022-37454, gh#python/cpython#98517) buffer
    overflow in hashlib.sha3_* implementations (originally from the
    XKCP library).
* Fri Oct 21 2022 Matej Cepl <>
  - Add 98437-sphinx.locale._-as-gettext-in-pyspecific.patch to
    allow building of documentation with the latest Sphinx 5.3.0
* Thu Oct 20 2022 Daniel Garcia <>
  - Add platlibdir-in-sys.patch to provide sys.platlibdir attribute. This is used
    by python-setuptools in distutils.sysconfig.get_python_lib bsc#1204395
* Wed Oct 19 2022 Matej Cepl <>
  - Update to 3.8.15:
    - Fix multiplying a list by an integer (list *= int): detect
      the integer overflow when the new allocated length is close
      to the maximum size.
    - Fix a shell code injection vulnerability in the example script. The script no
      longer uses a shell to run openssl commands. (originally
      filed as CVE-2022-37460, later withdrawn)
    - Fix command line parsing: reject -X int_max_str_digits option
      with no value (invalid) when the PYTHONINTMAXSTRDIGITS
      environment variable is set to a valid limit.
    - When ValueError is raised if an integer is larger than the
      limit, mention the sys.set_int_max_str_digits() function in
      the error message.
    - Update bundled libexpat to 2.4.9
    - Fixes a potential buffer overrun in msilib.
* Sun Sep 11 2022 Matej Cepl <>
  - Update to 3.8.14:
    - (CVE-2020-10735, bsc#1203125). Converting between int
      and str in bases other than 2 (binary), 4, 8 (octal), 16
      (hexadecimal), or 32 such as base 10 (decimal) now raises a
      ValueError if the number of digits in string form is above a
      limit to avoid potential denial of service attacks due to the
      algorithmic complexity.
      This new limit can be configured or disabled by environment
      variable, command line flag, or sys APIs. See the integer
      string conversion length limitation documentation. The
      default limit is 4300 digits in string form.
    - (CVE-2021-28861, bsc#1202624) http.server: Fix an open
      redirection vulnerability in the HTTP server when an URI path
      starts with //. Vulnerability discovered, and initial fix
      proposed, by Hamza Avvan.
    - Also other bugfixes:
    - Fix contextvars HAMT implementation to handle iteration
      over deep trees. The bug was discovered and fixed by Eli
      Libman. See MagicStack/immutables#84 for more details.
    - Fix ensurepip environment isolation for subprocess running
    - Raise ProgrammingError instead of segfaulting on recursive
      usage of cursors in sqlite3 converters. Patch by Sergey
    - Add a new gh role to the documentation to link to GitHub
    - Pin Jinja to a version compatible with Sphinx version
    - test_ssl is now checking for supported TLS version and
      protocols in more tests.
    - Fix test case for OpenSSL 3.0.1 version. OpenSSL 3.0 uses
  - Removed upstreamed patches:
    - CVE-2021-28861-double-slash-path.patch
  - Readjusted patches:
    - bpo-31046_ensurepip_honours_prefix.patch
    - sphinx-update-removed-function.patch
* Sat Sep 03 2022 Matej Cepl <>
  - (bsc#1196784, CVE-2022-25236) Add patch
    support-expat-CVE-2022-25236-patched.patch to allow working
    with different versions of libexpat.
* Thu Sep 01 2022 Steve Kowalik <>
  - Add patch CVE-2021-28861-double-slash-path.patch:
    * http.server: Fix an open redirection vulnerability in the HTTP server
      when an URI path starts with //. (bsc#1202624, CVE-2021-28861)
* Wed Aug 31 2022 Matej Cepl <>
  - Add bpo34990-2038-problem-compileall.patch making
    compliant with year 2038 (bsc#1202666, gh#python/cpython#79171),
    backport of fix to Python 3.8.
  - Add conditional for requiring rpm-build-python, so we should be
    compilable on SLE/Leap.
* Thu Jul 21 2022 Matej Cepl <>
  - Switch from %primary_interpreter to prjconf-defined
    %primary_python (gh#openSUSE/python-rpm-macros#127).
* Thu May 05 2022 Matej Cepl <>
  - Switch primary_interpreter from python38 to python310
* Sat Mar 26 2022 Matej Cepl <>
  - Update to 3.8.13:
    Core and Builtins
      bpo-46794: Bump up the libexpat version into 2.4.6
      bpo-46985: Upgrade pip wheel bundled with ensurepip (pip 22.0.4)
      bpo-46932: Update bundled libexpat to 2.4.7
      bpo-46811: Make test suite support Expat >=2.4.5
      bpo-46784: Fix libexpat symbols collisions with user
      dynamically loaded or statically linked libexpat in embedded
      bpo-46400: expat: Update libexpat from 2.4.1 to 2.4.4
      bpo-46474: In importlib.metadata.EntryPoint.pattern, avoid
      potential REDoS by limiting ambiguity in consecutive
      bpo-44849: Fix the os.set_inheritable() function on FreeBSD
      14 for file descriptor opened with the O_PATH flag: ignore
      the EBADF error on ioctl(), fallback on the fcntl()
      bpo-41028: Language and version switchers, previously
      maintained in every cpython branches, are now handled by
      bpo-45195: Fix test_readline.test_nonascii(): sometimes, the
      newline character is not written at the end, so don’t
      expect it in the output.
      bpo-44949: Fix auto history tests of test_readline:
      sometimes, the newline character is not written at the end,
      so don’t expect it in the output.
      bpo-45405: Prevent internal configure error when running
      configure with recent versions of clang.
  - Remove upstreamed patches:
    - support-expat-245.patch
* Tue Feb 22 2022 Steve Kowalik <>
  - Add patch support-expat-245.patch:
    * Support Expat >= 2.4.5
* Mon Nov 29 2021 Matej Cepl <>
  - Remove shebangs from from python-base libraries in _libdir
  - Readjust patches:
    - bpo-31046_ensurepip_honours_prefix.patch
    - decimal.patch
    - python-3.3.0b1-fix_date_time_compiler.patch
* Tue Oct 12 2021 Dominique Leuenberger <>
  - BuildRequire rpm-build-python: The provider to inject python(abi)
    has been moved there. rpm-build pulls rpm-build-python
    automatically in when building anything against python3-base, but
    this implies that the initial build of python3-base does not
    trigger the automatic installation.
* Tue Aug 31 2021 Fusion Future <>
  - Update to 3.8.12
    * Complete list of changes is available at
    * Security
    - bpo-42278: Replaced usage of tempfile.mktemp() with
      TemporaryDirectory to avoid a potential race condition.
    - bpo-44394: Update the vendored copy of libexpat to 2.4.1
      (from 2.2.8) to get the fix for the CVE-2013-0340 “Billion
      Laughs” vulnerability. This copy is most used on Windows and
    - bpo-43124: Made the internal putcmd function in smtplib
      sanitize input for presence of \r and \n characters to avoid
      (unlikely) command injection.
    - bpo-36384: ipaddress module no longer accepts any leading
      zeros in IPv4 address strings. Leading zeros are ambiguous
      and interpreted as octal notation by some libraries. For
      example the legacy function socket.inet_aton() treats leading
      zeros as octal notation. glibc implementation of modern
      inet_pton() does not accept any leading zeros. For a while
      the ipaddress module used to accept ambiguous leading zeros.
  - Refreshed patch:
    * decimal-3.8.patch
* Fri Aug 27 2021 Matej Cepl <>
  - Add decimal-3.8.patch to add building with --with-system-libmpdec
    option (bsc#1189356).
* Thu Aug 26 2021 Andreas Schwab <>
  - test_faulthandler is still problematic under qemu linux-user emulation,
    disable it there
  - Reenable profileopt with qemu emulation, test_faulthandler is no longer
    run during profiling
* Tue Aug 10 2021 Fusion Future <>
  - Update to 3.8.11
    * Security
    - bpo-44022 (boo#1189241): mod:http.client now avoids
      infinitely reading potential HTTP headers after a 100
      Continue status response from the server.
    - bpo-43882: The presence of newline or tab characters in parts
      of a URL could allow some forms of attacks.
      Following the controlling specification for URLs defined by
      WHATWG urllib.parse() now removes ASCII newlines and tabs
      from URLs, preventing such attacks.
    - bpo-42800: Audit hooks are now fired for frame.f_code,
      traceback.tb_frame, and generator code/frame attribute
    * Core and Builtins
    - bpo-44070: No longer eagerly makes import filenames absolute,
      except for extension modules, which was introduced in 3.8.10.
    * Library
    - bpo-44061: Fix regression in previous release when calling
      pkgutil.iter_modules() with a list of pathlib.Path objects
* Mon Aug 02 2021 Matej Cepl <>
  - Use versioned python-Sphinx to avoid dependency on other
    version of Python (bsc#1183858).
* Fri Jun 18 2021 Matej Cepl <>
  - Add bpo44426-complex-keyword-sphinx.patch allowing generating
    documentation with Sphinx 4 (bpo#44426).
* Tue Jun 08 2021 Dirk Müller <>
  - allow building against sphinx 3.x+
* Fri May 21 2021 Matej Cepl <>
  - Stop providing "python" symbol (bsc#1185588), which means
    python2 currently.
* Wed May 05 2021 Matej Cepl <>
  - Update to 3.8.10:
    - Security
    - bpo-43434: Creating a sqlite3.Connection object now also
      produces a sqlite3.connect auditing event. Previously this
      event was only produced by sqlite3.connect() calls. Patch
      by Erlend E. Aasland.
    - bpo-43472: Ensures interpreter-level audit hooks receive
      the cpython.PyInterpreterState_New event when called
      through the _xxsubinterpreters module.
    - bpo-43075: Fix Regular Expression Denial of Service (ReDoS)
      vulnerability in urllib.request.AbstractBasicAuthHandler.
      The ReDoS-vulnerable regex has quadratic worst-case
      complexity and it allows cause a denial of service when
      identifying crafted invalid RFCs. This ReDoS issue is on
      the client side and needs remote attackers to control the
      HTTP server.
    - Core and Builtins
    - bpo-43105: Importlib now resolves relative paths when
      creating module spec objects from file locations.
    - bpo-42924: Fix bytearray repetition incorrectly copying
      data from the start of the buffer, even if the data is
      offset within the buffer (e.g. after reassigning a slice at
      the start of the bytearray to a shorter byte string).
    - Library
    - bpo-43993: Update bundled pip to 21.1.1.
    - bpo-43937: Fixed the turtle module working with non-default
      root window.
    - bpo-43930: Update bundled pip to 21.1 and setuptools to
    - bpo-43920: OpenSSL 3.0.0: load_verify_locations() now
      returns a consistent error message when cadata contains no
      valid certificate.
    - bpo-43607: urllib can now convert Windows paths with \\?\
      prefixes into URL paths.
    - bpo-43284: platform.win32_ver derives the windows version
      from sys.getwindowsversion().platform_version which in turn
      derives the version from kernel32.dll (which can be of
      a different version than Windows itself). Therefore change
      the platform.win32_ver to determine the version using the
      platform module’s _syscmd_ver private function to return an
      accurate version.
    - bpo-42248: [Enum] ensure exceptions raised in _missing__
      are released
    - bpo-43799: OpenSSL 3.0.0: define OPENSSL_API_COMPAT 1.1.1
      to suppress deprecation warnings. Python requires OpenSSL
      1.1.1 APIs.
    - bpo-43794: Add ssl.OP_IGNORE_UNEXPECTED_EOF constants
      (OpenSSL 3.0.0)
    - bpo-43789: OpenSSL 3.0.0: Don’t call the password callback
      function a second time when first call has signaled an
      error condition.
    - bpo-43788: The header files for ssl error codes are now
      OpenSSL version-specific. Exceptions will now show correct
      reason and library codes. The script has
      been rewritten to use OpenSSL’s text file with error codes.
    - bpo-43655: tkinter dialog windows are now recognized as
      dialogs by window managers on macOS and X Window.
    - bpo-43534: turtle.textinput() and turtle.numinput() create
      now a transient window working on behalf of the canvas
    - bpo-43522: Fix problem with hostname_checks_common_name.
      OpenSSL does not copy hostflags from struct SSL_CTX to
      struct SSL.
    - bpo-42967: Allow bytes separator argument in
      urllib.parse.parse_qs and urllib.parse.parse_qsl when
      parsing str query strings. Previously, this raised
      a TypeError.
    - bpo-43176: Fixed processing of a dataclass that inherits
      from a frozen dataclass with no fields. It is now correctly
      detected as an error.
    - bpo-34463: Fixed discrepancy between traceback and the
      interpreter in formatting of SyntaxError with lineno not
      set (traceback was changed to match interpreter).
    - bpo-41735: Fix thread locks in zlib module may go wrong in
      rare case. Patch by Ma Lin.
    - bpo-26053: Fixed bug where the pdb interactive run command
      echoed the args from the shell command line, even if those
      have been overridden at the pdb prompt.
    - bpo-36470: Fix dataclasses with InitVars and replace().
      Patch by Claudiu Popa.
    - bpo-28577: The hosts method on 32-bit prefix length
      IPv4Networks and 128-bit prefix IPv6Networks now returns
      a list containing the single Address instead of an empty
    - bpo-32745: Fix a regression in the handling of ctypes’
      ctypes.c_wchar_p type: embedded null characters would cause
      a ValueError to be raised. Patch by Zackery Spytz.
    - Documentation
    - bpo-43959: The documentation on the PyContextVar C-API was
    - bpo-43938: Update dataclasses documentation to express that
      FrozenInstanceError is derived from AttributeError.
    - bpo-43739: Fixing the example code in
      Doc/extending/extending.rst to declare and initialize the
      pmodule variable to be of the right type.
    - Tests
    - bpo-43842: Fix a race condition in the SMTP test of
      test_logging. Don’t close a file descriptor (socket) from
      a different thread while asyncore.loop() is polling the
      file descriptor. Patch by Victor Stinner.
    - bpo-43811: Tests multiple OpenSSL versions on GitHub
      Actions. Use ccache to speed up testing.
    - bpo-43791: OpenSSL 3.0.0: Disable testing of legacy
      protocols TLS 1.0 and 1.1. Tests are failing with
    - IDLE
    - bpo-43655: IDLE dialog windows are now recognized as
      dialogs by window managers on macOS and X Window.
    - C API
    - bpo-43962: _PyInterpreterState_IDIncref() now calls
      _PyInterpreterState_IDInitref() and always increments
      id_refcount. Previously, calling
      _xxsubinterpreters.get_current() could create an
      id_refcount inconsistency when
      a _xxsubinterpreters.InterpreterID object was deallocated.
      Patch by Victor Stinner.
  - Reapplied patches:
    - CVE-2019-5010-null-defer-x509-cert-DOS.patch
    - F00102-lib64.patch
    - SUSE-FEDORA-multilib.patch
    - bpo-31046_ensurepip_honours_prefix.patch
    - python-3.3.0b1-fix_date_time_compiler.patch
* Sun May 02 2021 Ben Greiner <>
  - Make sure to close the file after the exception
    has been raised in order to avoid ResourceWarnings when the
    failing import is part of a try...except block.
* Wed Apr 28 2021 Matej Cepl <>
  - Update to 3.8.9:
    - bpo#42988 (bsc#1183374) CVE-2021-3426: Remove the getfile
      feature of the pydoc module which could be abused to read
      arbitrary files on the disk (directory traversal
      vulnerability). Moreover, even source code of Python modules
      can contain sensitive data like passwords. Vulnerability
      reported by David Schwörer.
    - bpo-43285: ftplib no longer trusts the IP address value
      returned from the server in response to the PASV command by
      default. This prevents a malicious FTP server from using the
      response to probe IPv4 address and port combinations on the
      client network.
    - Code that requires the former vulnerable behavior may set
      a trust_server_pasv_ipv4_address attribute on their
      ftplib.FTP instances to True to re-enable it.
    - bpo-43439: Add audit hooks for gc.get_objects(),
      gc.get_referrers() and gc.get_referents(). Patch by Pablo
    - bpo-43660: Fix crash that happens when replacing sys.stderr
      with a callable that can remove the object while an exception
      is being printed. Patch by Pablo Galindo.
    - bpo-35883: Python no longer fails at startup with a fatal
      error if a command line argument contains an invalid Unicode
      character. The Py_DecodeLocale() function now escapes byte
      sequences which would be decoded as Unicode characters
      outside the [U+0000; U+10ffff] range.
    - bpo-43406: Fix a possible race condition where
      PyErr_CheckSignals tries to execute a non-Python signal
    - bpo-35930: Raising an exception raised in a “future” instance
      will create reference cycles.
    - bpo-43577: Fix deadlock when using ssl.SSLContext debug
      callback with ssl.SSLContext.sni_callback().
    - bpo-43423: subprocess.communicate() no longer raises an
      IndexError when there is an empty stdout or stderr IO buffer
      during a timeout on Windows.
    - bpo-27820: Fixed long-standing bug of smtplib.SMTP where
      doing AUTH LOGIN with initial_response_ok=False will fail.
      The cause is that SMTP.auth_login _always_ returns a password
      if provided with a challenge string, thus non-compliant with
      the standard for AUTH LOGIN. Also fixes bug with the test for
    - bpo-43399: Fix ElementTree.extend not working on iterators
      when using the Python implementation
    - bpo-43316: The python -m gzip command line application now
      properly fails when detecting an unsupported extension. It
      exits with a non-zero exit code and prints an error message
      to stderr.
    - bpo-43260: Fix TextIOWrapper can not flush internal buffer
      forever after very large text is written.
    - bpo-42782: Fail fast in shutil.move() to avoid creating
      destination directories on failure.
    - bpo-37193: Fixed memory leak in socketserver.ThreadingMixIn
      introduced in Python 3.7.
    - bpo-43199: Answer “Why is there no goto?” in the Design and
      History FAQ.
    - bpo-43407: Clarified that a result from time.monotonic(),
      time.perf_counter(), time.process_time(), or
      time.thread_time() can be compared with the result from any
      following call to the same function - not just the next
      immediate call.
    - bpo-27646: Clarify that ‘yield from <expr>’ works with any
      iterable, not just iterators.
    - bpo-36346: Update some deprecated unicode APIs which are
      documented as “will be removed in 4.0” to “3.12”. See PEP 623
      for detail.
    - bpo-37945: Fix test_getsetlocale_issue1813() of test_locale:
      skip the test if setlocale() fails. Patch by Victor Stinner.
    - bpo-41561: Add workaround for Ubuntu’s custom OpenSSL
      security level policy.
    - bpo-43631: Update macOS, Windows, and CI to OpenSSL 1.1.1k.
    - bpo-43617: Improve Check for presence of
      autoconf-archive package and remove our copies of M4 macros.
    - bpo-41837: Update macOS installer build to use OpenSSL
    - bpo-42225: Document that IDLE can fail on Unix either from
      misconfigured IP masquerage rules or failure displaying
      complex colored (non-ascii) characters.
    - bpo-43283: Document why printing to IDLE’s Shell is often
      slower than printing to a system terminal and that it can be
      made faster by pre-formatting a single string before
* Fri Feb 19 2021 Matej Cepl <>
  - Update to 3.8.8:
    - bpo#42938 (bsc#1181126): Avoid static buffers when computing
      the repr of ctypes.c_double and ctypes.c_longdouble
      values. This issue was assigned CVE-2021-3177.
    - bpo#42967 (bsc#1182379): Fix web cache poisoning
      vulnerability by defaulting the query args separator to &,
      and allowing the user to choose a custom separator. This
      issue was assigned CVE-2021-23336.
  - Remove bsc1167501-invalid-alignment.patch and
    CVE-2021-3177-buf_ovrfl_PyCArg_repr.patch, which were included
    into the upstream tarball.
* Tue Feb 09 2021 Steve Kowalik <>
  - Add Obsoletes for python3-base when primary interpreter is set to
    properly replace it during upgrades. (bsc#1181324)
* Fri Feb 05 2021 Ben Greiner <>
  - Provide %have_<flavor> for all python flavors
  - Add %python3_default and %default_python3 for the primary python3
* Fri Jan 29 2021 Matej Cepl <>
  - Add CVE-2021-3177-buf_ovrfl_PyCArg_repr.patch fixing
    bsc#1181126 (CVE-2021-3177) buffer overflow in PyCArg_repr in
    _ctypes/callproc.c, which may lead to remote code execution.
* Tue Jan 05 2021 Matej Cepl <>
  - (bsc#1180125) We really don't Require python-rpm-macros package.
    Unnecessary dependency.



Generated by rpm2html 1.8.1

Fabrice Bellet, Tue Jul 9 10:39:13 2024