Re: time for a new release

Michał Górny <[email protected]>
Newsgroups gmane.comp.python.pypy
Organization Gentoo
Message-ID <[email protected]>
On Thu, 2020-09-10 at 13:37 +0300, Matti Picus wrote:
> On 9/10/20 12:40 PM, Michał Górny wrote:
> > I've filed two MRs for a start:
> > https://foss.heptapod.net/pypy/pypy/-/merge_requests/752
> > https://foss.heptapod.net/pypy/pypy/-/merge_requests/753
> > 
> > Could you please let me know if that approach is ok?  If so, I'll tackle
> > the remaining vulnerabilities (around 6 patches FWICS).
> > 
> 
> Thanks.
> 
> Could you add comments in each patched chunk of each PR that will allow 
> us to track how the code diverged? Something like "added manually to 
> resolve bpo xxx".

I don't see a problem with doing that.

> 
> 
> I am concerned this will make an eventual update to the stdlib 
> difficult. MR753 is quite invasive. Are all the other patches against 
> the same single file? Maybe a different strategy would be to adopt the 
> file and tests as-is from the HEAD of the CPython branch, as long as no 
> user-facing APIs change.

I suppose I can try doing that.  I presumed you'll want to keep
the changes to bare minimum possible but it might turn out not much
different once I iterate over all the CVEs.

> It would be nice to make similar PRs against default (python2.7) in 
> lib-python/2.7 on that branch.

The primary problem with that is that CPython 2.7 is abandoned
and contrary to all the big talk about random people willing to maintain
it post-EOL, I am yet to see anyone taking its security seriously.

So far I and the Fedora maintainer were able to independently backport
one vulnerability that clearly applied (the tarfile one) but we weren't
able to get a clear match of any other Python 3.x fixes to 2.7 codebase.
 Well, until today when thanks to you I've noticed that http.request
code has a vulnerable match in httplib.

But this all is lots of work, and I'm really supposed to be doing
something else right now.  I'm trying my best but I'm not sure if I can
manage to fix several months of negligence in two days.

-- 
Best regards,
Michał Górny

_______________________________________________
pypy-dev mailing list
[email protected]
https://mail.python.org/mailman/listinfo/pypy-dev
signature.asc (application/pgp-signature, 618 B)
-----BEGIN PGP SIGNATURE-----

iQGTBAABCgB9FiEEx2qEUJQJjSjMiybFY5ra4jKeJA4FAl9aA9hfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEM3
NkE4NDUwOTQwOThEMjhDQzhCMjZDNTYzOUFEQUUyMzI5RTI0MEUACgkQY5ra4jKe
JA7iGQf+MyznTe3tCXPaH5oU1Oip76HhsAg41/e8hqAY2l0OEkoTU0NQuqqbMT1a
3y/M9q3zMOjqYdhQu+/0yaIeUcjLbpXIG4Co3e6wGwJJWZOWXk7KrBSLGc0wQoIp
NRK7CGRUo4tIOBPAZFMIX74F2e/u4i/O56OCK2tzWHVHXBA+BDZpn/mIpD+Zm6At
OY0RCXlyIx9l4zyHzuu96YpmdCtPMx8jLcXDq8pr/SqhrKaIVHSrL5reFfiOIjAj
0mO758ENrT3Q1aNUDxVrbKZcpYVbxG99LQNc6dWAY5SklU8n4yBo0SR9Afyg62fS
qEahZvIHDi4PqYGLvvbtgLTw4bZpag==
=LMQF
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.