Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

gh-131423: Update OpenSSL data to 3.4.1 on Linux#131618

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Merged
picnixz merged 15 commits intopython:mainfrompicnixz:ci/update/ssl-versions-131423
Apr 25, 2025

Conversation

picnixz
Copy link
Member

@picnixzpicnixz commentedMar 23, 2025
edited
Loading

I've also updated themake_ssl_data.py script that@encukou has recently updated as well. I completed with instructions that I thought usefull for future maintainers.


📚 Documentation preview 📚:https://cpython-previews--131618.org.readthedocs.build/

Since mnemonics from 3.4.1 are different (renumbered) from 3.4.0.To ease future updates, we assume the following:`_ssl_data_<MAJOR><PATCH>.h` contains the latest OpenSSL data. If theprevious `_ssl_data_<MAJOR><PATCH>.h` file is incompatible with thenewest one (e.g., because some mnemonics were renamed or removed), theold one is renamed to `_ssl_data_<MAJOR><MINOR><PATCH>.h` where <PATCH>is the patch number it was based upon.In this commit, OpenSSL 3.4.1 mnemonics are not compatible with OpenSSL3.4.0 mnemonics as they were renumbered. Therefore, `_ssl_data_34.h` isrenamed to `_ssl_data_340.h` and `_ssl_data_34x.h` now contains OpenSSL3.4.1 mnemonics.We also refined the mnemonics that are selected, discarding those thatare mnemonics-like but should not be used as such (e.g., ERR_LIB_MASKand ERR_LIB_OFFSET for OpenSSL 1.1.1).
@picnixzpicnixzforce-pushed theci/update/ssl-versions-131423 branch from05ee142 to5bbc702CompareMarch 23, 2025 10:53
@picnixzpicnixz marked this pull request as ready for reviewMarch 24, 2025 14:56
@picnixzpicnixz marked this pull request as draftMarch 24, 2025 17:49
@picnixz
Copy link
MemberAuthor

arf, I'm not on my Linux so I can't regen :< I'm leaving tomorrow morning so I'm not really sure I'll be able to commit before leaving, but otherwise, just take over the PR and regen the data!

Copy link
Member

@ned-deilyned-deily left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

The macOS build-installer.py changes LGTM, thanks!

@picnixzpicnixz marked this pull request as ready for reviewMarch 28, 2025 22:50
@picnixzpicnixz requested a review fromencukouMarch 28, 2025 22:50
@picnixzpicnixz requested a review fromgpshead as acode ownerApril 5, 2025 10:52
@picnixzpicnixz changed the titlegh-131423: Update OpenSSL to 3.0.16 (macOS, Windows) and 3.4.1 (Linux)gh-131423: Update OpenSSL to 3.0.16 (macOS) and 3.4.1 (Linux)Apr 5, 2025
@picnixzpicnixz added the 🔨 test-with-buildbotsTest PR w/ buildbots; report in status section labelApr 5, 2025
@bedevere-bot
Copy link

🤖 New build scheduled with the buildbot fleet by@picnixz for commit905f1a5 🤖

Results will be shown at:

https://buildbot.python.org/all/#/grid?branch=refs%2Fpull%2F131618%2Fmerge

If you want to schedule another build, you need to add the🔨 test-with-buildbots label again.

@bedevere-botbedevere-bot removed the 🔨 test-with-buildbotsTest PR w/ buildbots; report in status section labelApr 5, 2025
@picnixz
Copy link
MemberAuthor

To avoid surprises, I'm running the build bots. If they pass, I'll merge this one so that we can close the other issue. I think the Windows-related failures were recently solved as well

@picnixz
Copy link
MemberAuthor

picnixz commentedApr 5, 2025
edited by hugovk
Loading

The iOS failure is known (PR#132050)

@picnixz
Copy link
MemberAuthor

I want to think about something. Mnenmonics were updated in 3.4.1 compared to 3.4.0, but that's only because Iknew that they were changed. However, we're actually having a

#if (OPENSSL_VERSION_NUMBER >=0x30100000L)#include"_ssl_data_34.h"

So I think I'll need a way to check first that when OpenSSL mnemonics changed so that we regenerate the correct files per version.

@ned-deily
Copy link
Member

@picnixz, with the 3.14.a7, 3.13.3, and 3.12.10 releases approaching in two days, I plan to update the macOS installers for those releases to use 3.0.16. If you don't expect to be able to merge this PR before then, I can pull out the build-installer.py change into a separate PR since it has no relation to any of the other changes in this PR. (And that's why I prefer to keep changes like this separate.)

@picnixz
Copy link
MemberAuthor

If you don't expect to be able to merge this PR before then

To be on the safe side, please do so. I don't want to block the macOS side with my interrogations. Hopefully I'll be able to merge this before the release.

ned-deily reacted with thumbs up emoji

@picnixz
Copy link
MemberAuthor

picnixz commentedApr 7, 2025
edited
Loading

Note: 3.4.1 includes CVE patchesbut since we're still in alpha, we can say that those security patches are not really necessarynow (in addition, they affect components that are not directly exposed by Python IIRC). So, I'll postpone this until after the release (I don't want to have surprises where a mnemonic change would be actually annoying for a user)

@picnixzpicnixz changed the titlegh-131423: Update OpenSSL to 3.0.16 (macOS) and 3.4.1 (Linux)gh-131423: Update OpenSSL to 3.4.1 on LinuxApr 7, 2025
@picnixzpicnixz changed the titlegh-131423: Update OpenSSL to 3.4.1 on Linuxgh-131423: Update OpenSSL data to 3.4.1 on LinuxApr 8, 2025
@picnixz
Copy link
MemberAuthor

I'll merge this one and work on#132745.

@picnixzpicnixz merged commit6a9bfee intopython:mainApr 25, 2025
45 checks passed
@picnixzpicnixz deleted the ci/update/ssl-versions-131423 branchApril 25, 2025 08:27
@picnixz
Copy link
MemberAuthor

Rationale for not backporting:#131423 (comment).

Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment
Reviewers

@zoobazoobazooba left review comments

@ned-deilyned-deilyned-deily left review comments

@gpsheadgpsheadgpshead approved these changes

@erlend-aaslanderlend-aaslandAwaiting requested review from erlend-aaslanderlend-aasland is a code owner

@corona10corona10Awaiting requested review from corona10corona10 is a code owner

@ezio-melottiezio-melottiAwaiting requested review from ezio-melottiezio-melotti is a code owner

@hugovkhugovkAwaiting requested review from hugovkhugovk is a code owner

@AA-TurnerAA-TurnerAwaiting requested review from AA-TurnerAA-Turner is a code owner

@encukouencukouAwaiting requested review from encukou

Assignees
No one assigned
Labels
None yet
Projects
None yet
Milestone
No milestone
Development

Successfully merging this pull request may close these issues.

6 participants
@picnixz@bedevere-bot@ned-deily@gpshead@encukou@zooba

[8]ページ先頭

©2009-2025 Movatter.jp