@@ -1,4 +1,4 @@
-From 3f2df0e1fce8c7425998dade00d084f1b101a982 Mon Sep 17 00:00:00 2001
+From f0a7ea3a22726c67c9432d0a2095cf1f2efb8d41 Mon Sep 17 00:00:00 2001
From: Paulo Neves <ptsneves@gmail.com>
Date: Tue, 7 Jun 2022 16:16:41 +0200
Subject: [PATCH] Avoid shebang overflow on python-config.py
@@ -16,10 +16,10 @@ Upstream-Status: Denied [distribution]
1 file changed, 2 insertions(+)
diff --git a/Makefile.pre.in b/Makefile.pre.in
-index e946018..345ed29 100644
+index b43baf1..18a46de 100644
--- a/Makefile.pre.in
+++ b/Makefile.pre.in
-@@ -2835,6 +2835,8 @@ python-config: $(srcdir)/Misc/python-config.in Misc/python-config.sh
+@@ -2836,6 +2836,8 @@ python-config: $(srcdir)/Misc/python-config.in Misc/python-config.sh
@ # Substitution happens here, as the completely-expanded BINDIR
@ # is not available in configure
sed -e "s,@EXENAME@,$(EXENAME)," < $(srcdir)/Misc/python-config.in >python-config.py
@@ -1,4 +1,4 @@
-From 9cd44429215352eb2753e0fd8e25fef24f714006 Mon Sep 17 00:00:00 2001
+From b68b37ca8a876b0123a291366b341eeacf1db71d Mon Sep 17 00:00:00 2001
From: Alexander Kanavin <alex@linutronix.de>
Date: Thu, 16 Sep 2021 16:35:37 +0200
Subject: [PATCH] Lib/pty.py: handle stdin I/O errors same way as master I/O
@@ -1,4 +1,4 @@
-From b5aad6a9b6c5add7a85861aed8aa030c1ad3d52f Mon Sep 17 00:00:00 2001
+From 7be6f1b478c2472822d17a40ca42ad1fc19fc6f4 Mon Sep 17 00:00:00 2001
From: Alexander Kanavin <alex@linutronix.de>
Date: Fri, 17 Nov 2023 14:26:32 +0100
Subject: [PATCH] Lib/sysconfig.py: use prefix value from build configuration
@@ -1,4 +1,4 @@
-From d6f77e3a934616d1f6c083b7144c50a32e08b70a Mon Sep 17 00:00:00 2001
+From 649b09c80b5954a54d2ed2ebf6c9bf61e98db225 Mon Sep 17 00:00:00 2001
From: Alexander Kanavin <alex.kanavin@gmail.com>
Date: Wed, 30 Jan 2019 12:41:04 +0100
Subject: [PATCH] Makefile.pre: use qemu wrapper when gathering profile data
@@ -15,10 +15,10 @@ Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/Makefile.pre.in b/Makefile.pre.in
-index 526d500..a7e536d 100644
+index 7ca65dd..de72b03 100644
--- a/Makefile.pre.in
+++ b/Makefile.pre.in
-@@ -861,8 +861,7 @@ profile-run-stamp:
+@@ -862,8 +862,7 @@ profile-run-stamp:
# enabled.
$(MAKE) profile-gen-stamp
# Next, run the profile task to generate the profile information.
@@ -1,4 +1,4 @@
-From c608cb4b3c8c31f1aa25ad1264ff58733fb99769 Mon Sep 17 00:00:00 2001
+From 43f53b757f220c592d5a77d228d087099a92ea7a Mon Sep 17 00:00:00 2001
From: Wentao Zhang <wentao.zhang@windriver.com>
Date: Mon, 20 Mar 2023 13:39:52 +0800
Subject: [PATCH] Update test_sysconfig for posix_user purelib
@@ -1,7 +1,10 @@
-From 3364e7e62fa24d0e19133fb0f90b1c24ef1110c5 Mon Sep 17 00:00:00 2001
+From fb464673dbaecfb1afa6e54776b9e0eaff791e4b Mon Sep 17 00:00:00 2001
From: Victor Stinner <vstinner@python.org>
Date: Wed, 25 Mar 2026 07:44:47 +0100
Subject: [PATCH] gh-146207: Add support for OpenSSL 4.0.0 alpha1 (#146217)
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
OpenSSL 4.0.0 alpha1 removed these functions:
@@ -29,10 +32,10 @@ Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
4 files changed, 58 insertions(+), 31 deletions(-)
diff --git a/Lib/test/test_ssl.py b/Lib/test/test_ssl.py
-index dc795c6bd8a..61355927296 100644
+index d1486a4..f50888d 100644
--- a/Lib/test/test_ssl.py
+++ b/Lib/test/test_ssl.py
-@@ -395,7 +395,7 @@ def test_constants(self):
+@@ -424,7 +424,7 @@ class BasicSocketTests(unittest.TestCase):
ssl.OP_NO_COMPRESSION
self.assertEqual(ssl.HAS_SNI, True)
self.assertEqual(ssl.HAS_ECDH, True)
@@ -41,7 +44,7 @@ index dc795c6bd8a..61355927296 100644
self.assertEqual(ssl.HAS_TLSv1_3, True)
ssl.OP_NO_SSLv2
ssl.OP_NO_SSLv3
-@@ -586,11 +586,11 @@ def test_openssl_version(self):
+@@ -615,11 +615,11 @@ class BasicSocketTests(unittest.TestCase):
# Some sanity checks follow
# >= 1.1.1
self.assertGreaterEqual(n, 0x10101000)
@@ -56,7 +59,7 @@ index dc795c6bd8a..61355927296 100644
self.assertGreaterEqual(minor, 0)
self.assertLess(minor, 256)
self.assertGreaterEqual(fix, 0)
-@@ -656,12 +656,14 @@ def test_openssl111_deprecations(self):
+@@ -685,12 +685,14 @@ class BasicSocketTests(unittest.TestCase):
ssl.OP_NO_TLSv1_2,
ssl.OP_NO_TLSv1_3
]
@@ -77,7 +80,7 @@ index dc795c6bd8a..61355927296 100644
versions = [
ssl.TLSVersion.SSLv3,
ssl.TLSVersion.TLSv1,
-@@ -1205,6 +1207,7 @@ def test_min_max_version(self):
+@@ -1184,6 +1186,7 @@ class ContextTests(unittest.TestCase):
ssl.TLSVersion.TLSv1,
ssl.TLSVersion.TLSv1_1,
ssl.TLSVersion.TLSv1_2,
@@ -85,7 +88,7 @@ index dc795c6bd8a..61355927296 100644
ssl.TLSVersion.SSLv3,
}
)
-@@ -1218,7 +1221,7 @@ def test_min_max_version(self):
+@@ -1197,7 +1200,7 @@ class ContextTests(unittest.TestCase):
with self.assertRaises(ValueError):
ctx.minimum_version = 42
@@ -94,7 +97,7 @@ index dc795c6bd8a..61355927296 100644
ctx = ssl.SSLContext(ssl.PROTOCOL_TLSv1_1)
self.assertIn(
-@@ -1675,23 +1678,24 @@ def test__create_stdlib_context(self):
+@@ -1749,23 +1752,24 @@ class ContextTests(unittest.TestCase):
self.assertFalse(ctx.check_hostname)
self._assert_context_options(ctx)
@@ -130,7 +133,7 @@ index dc795c6bd8a..61355927296 100644
ctx = ssl._create_stdlib_context(purpose=ssl.Purpose.CLIENT_AUTH)
self.assertEqual(ctx.protocol, ssl.PROTOCOL_TLS_SERVER)
-@@ -3654,10 +3658,10 @@ def test_protocol_tlsv1_2(self):
+@@ -3863,10 +3867,10 @@ class ThreadedTests(unittest.TestCase):
client_options=ssl.OP_NO_TLSv1_2)
try_protocol_combo(ssl.PROTOCOL_TLS, ssl.PROTOCOL_TLSv1_2, 'TLSv1.2')
@@ -144,10 +147,10 @@ index dc795c6bd8a..61355927296 100644
try_protocol_combo(ssl.PROTOCOL_TLSv1_1, ssl.PROTOCOL_TLSv1_2, False)
diff --git a/Modules/_ssl.c b/Modules/_ssl.c
-index b45295b4c0c..6f75af86113 100644
+index 90bcb6f..b99830e 100644
--- a/Modules/_ssl.c
+++ b/Modules/_ssl.c
-@@ -164,6 +164,17 @@ static void _PySSLFixErrno(void) {
+@@ -135,6 +135,17 @@ static void _PySSLFixErrno(void) {
#error Unsupported OpenSSL version
#endif
@@ -165,7 +168,7 @@ index b45295b4c0c..6f75af86113 100644
/* OpenSSL API 1.1.0+ does not include version methods */
#ifndef OPENSSL_NO_SSL3_METHOD
extern const SSL_METHOD *SSLv3_method(void);
-@@ -1151,7 +1162,7 @@ _asn1obj2py(_sslmodulestate *state, const ASN1_OBJECT *name, int no_name)
+@@ -1134,7 +1145,7 @@ _asn1obj2py(_sslmodulestate *state, const ASN1_OBJECT *name, int no_name)
static PyObject *
_create_tuple_for_attribute(_sslmodulestate *state,
@@ -174,7 +177,7 @@ index b45295b4c0c..6f75af86113 100644
{
Py_ssize_t buflen;
PyObject *pyattr;
-@@ -1180,16 +1191,16 @@ _create_tuple_for_attribute(_sslmodulestate *state,
+@@ -1163,16 +1174,16 @@ _create_tuple_for_attribute(_sslmodulestate *state,
}
static PyObject *
@@ -195,7 +198,7 @@ index b45295b4c0c..6f75af86113 100644
int index_counter;
int rdn_level = -1;
int retcode;
-@@ -6967,9 +6978,15 @@ sslmodule_init_constants(PyObject *m)
+@@ -6529,9 +6540,15 @@ sslmodule_init_constants(PyObject *m)
ADD_INT_CONST("PROTOCOL_TLS", PY_SSL_VERSION_TLS);
ADD_INT_CONST("PROTOCOL_TLS_CLIENT", PY_SSL_VERSION_TLS_CLIENT);
ADD_INT_CONST("PROTOCOL_TLS_SERVER", PY_SSL_VERSION_TLS_SERVER);
@@ -212,7 +215,7 @@ index b45295b4c0c..6f75af86113 100644
#define ADD_OPTION(NAME, VALUE) if (sslmodule_add_option(m, NAME, (VALUE)) < 0) return -1
diff --git a/Modules/_ssl/cert.c b/Modules/_ssl/cert.c
-index f2e7be89668..061b0fb3171 100644
+index f2e7be8..061b0fb 100644
--- a/Modules/_ssl/cert.c
+++ b/Modules/_ssl/cert.c
@@ -128,7 +128,8 @@ _ssl_Certificate_get_info_impl(PySSLCertificate *self)
@@ -226,10 +229,10 @@ index f2e7be89668..061b0fb3171 100644
PyObject *res;
BIO *biobuf;
diff --git a/Tools/ssl/multissltests.py b/Tools/ssl/multissltests.py
-index 3b4507c6771..48207e5330f 100755
+index 99e2a3f..70812bc 100755
--- a/Tools/ssl/multissltests.py
+++ b/Tools/ssl/multissltests.py
-@@ -429,9 +429,11 @@ def _post_install(self):
+@@ -422,9 +422,11 @@ class BuildOpenSSL(AbstractBuilder):
def _post_install(self):
if self.version.startswith("3."):
self._post_install_3xx()
@@ -242,7 +245,7 @@ index 3b4507c6771..48207e5330f 100755
config_args += ("enable-fips",)
super()._build_src(config_args)
-@@ -447,6 +449,9 @@ def _post_install_3xx(self):
+@@ -440,6 +442,9 @@ class BuildOpenSSL(AbstractBuilder):
lib64 = self.lib_dir + "64"
os.symlink(lib64, self.lib_dir)
@@ -252,6 +255,3 @@ index 3b4507c6771..48207e5330f 100755
@property
def short_version(self):
"""Short version for OpenSSL download URL"""
-2.25.1
-
@@ -1,4 +1,4 @@
-From 8d7fcf04c6513841c7985e64b746b1ef5de0c426 Mon Sep 17 00:00:00 2001
+From b0fd65529c925d4f972088c5d87b85de69c4570f Mon Sep 17 00:00:00 2001
From: Ross Burton <ross.burton@arm.com>
Date: Fri, 17 Apr 2026 16:53:42 +0100
Subject: [PATCH] prefer valid entrypoints
@@ -1,4 +1,4 @@
-From c10d1b295a9fb93836830cce441da3f22e5c7cd7 Mon Sep 17 00:00:00 2001
+From c7d69dd13f84777ea31d3c086052e2bcef709141 Mon Sep 17 00:00:00 2001
From: Alexander Kanavin <alex@linutronix.de>
Date: Sun, 12 Sep 2021 21:44:36 +0200
Subject: [PATCH] sysconfig.py: use platlibdir also for purelib
@@ -1,4 +1,4 @@
-From f0ac5b479b99bfb7f5e937a941b31a596f4caafc Mon Sep 17 00:00:00 2001
+From 7dcb9be72f60b3bc1a5bb15a3e3684137f6ed300 Mon Sep 17 00:00:00 2001
From: Mingli Yu <mingli.yu@windriver.com>
Date: Mon, 5 Aug 2019 15:57:39 +0800
Subject: [PATCH] test_locale.py: correct the test output format
@@ -1,4 +1,4 @@
-From 3c2a3014af7d73cc34f2498f60fdf863d9bc7c6c Mon Sep 17 00:00:00 2001
+From 24629aaf608733c17ba3c0fd5202301078924af9 Mon Sep 17 00:00:00 2001
From: Victor Stinner <vstinner@python.org>
Date: Mon, 4 May 2026 13:52:57 +0200
Subject: [PATCH] gh-148292: Update _ssl._SSLSocket for OpenSSL 4 (#149102)
@@ -25,10 +25,10 @@ Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
create mode 100644 Misc/NEWS.d/next/Library/2026-04-28-17-47-55.gh-issue-148292.oIq3ml.rst
diff --git a/Lib/test/test_ssl.py b/Lib/test/test_ssl.py
-index 965dbc36f096499..03d9e3f9e5e96b5 100644
+index f50888d..375f905 100644
--- a/Lib/test/test_ssl.py
+++ b/Lib/test/test_ssl.py
-@@ -2711,6 +2711,36 @@ def close(self):
+@@ -2994,6 +2994,36 @@ class ThreadedEchoServer(threading.Thread):
def stop(self):
self.active = False
@@ -65,7 +65,7 @@ index 965dbc36f096499..03d9e3f9e5e96b5 100644
class AsyncoreEchoServer(threading.Thread):
# this one's based on asyncore.dispatcher
-@@ -4747,6 +4777,58 @@ def background(sock):
+@@ -5035,6 +5065,58 @@ class ThreadedTests(unittest.TestCase):
if cm.exc_value is not None:
raise cm.exc_value
@@ -126,7 +126,7 @@ index 965dbc36f096499..03d9e3f9e5e96b5 100644
"Test needs TLS 1.3 PHA")
diff --git a/Misc/NEWS.d/next/Library/2026-04-28-17-47-55.gh-issue-148292.oIq3ml.rst b/Misc/NEWS.d/next/Library/2026-04-28-17-47-55.gh-issue-148292.oIq3ml.rst
new file mode 100644
-index 000000000000000..e1f308df5a678e6
+index 0000000..e1f308d
--- /dev/null
+++ b/Misc/NEWS.d/next/Library/2026-04-28-17-47-55.gh-issue-148292.oIq3ml.rst
@@ -0,0 +1,7 @@
@@ -138,10 +138,10 @@ index 000000000000000..e1f308df5a678e6
+Thanks to that, :class:`ssl.SSLSocket` behaves the same on all OpenSSL versions
+on EOF. Patch by Victor Stinner.
diff --git a/Modules/_ssl.c b/Modules/_ssl.c
-index 1603d0ffd559559..376df32b7cb4bd6 100644
+index b99830e..c352de6 100644
--- a/Modules/_ssl.c
+++ b/Modules/_ssl.c
-@@ -352,6 +352,16 @@ typedef struct {
+@@ -351,6 +351,16 @@ typedef struct {
* and shutdown methods check for chained exceptions.
*/
PyObject *exc;
@@ -158,7 +158,7 @@ index 1603d0ffd559559..376df32b7cb4bd6 100644
} PySSLSocket;
#define PySSLSocket_CAST(op) ((PySSLSocket *)(op))
-@@ -499,6 +509,10 @@ fill_and_set_sslerror(_sslmodulestate *state,
+@@ -498,6 +508,10 @@ fill_and_set_sslerror(_sslmodulestate *state,
PyObject *init_value, *msg, *key;
PyUnicodeWriter *writer = NULL;
@@ -169,7 +169,7 @@ index 1603d0ffd559559..376df32b7cb4bd6 100644
if (errcode != 0) {
int lib, reason;
-@@ -654,6 +668,18 @@ PySSL_ChainExceptions(PySSLSocket *sslsock) {
+@@ -653,6 +667,18 @@ PySSL_ChainExceptions(PySSLSocket *sslsock) {
return -1;
}
@@ -188,7 +188,7 @@ index 1603d0ffd559559..376df32b7cb4bd6 100644
static PyObject *
PySSL_SetError(PySSLSocket *sslsock, const char *filename, int lineno)
{
-@@ -901,6 +927,7 @@ newPySSLSocket(PySSLContext *sslctx, PySocketSockObject *sock,
+@@ -900,6 +926,7 @@ newPySSLSocket(PySSLContext *sslctx, PySocketSockObject *sock,
self->server_hostname = NULL;
self->err = err;
self->exc = NULL;
@@ -196,7 +196,7 @@ index 1603d0ffd559559..376df32b7cb4bd6 100644
/* Make sure the SSL error state is initialized */
ERR_clear_error();
-@@ -1041,6 +1068,11 @@ _ssl__SSLSocket_do_handshake_impl(PySSLSocket *self)
+@@ -1040,6 +1067,11 @@ _ssl__SSLSocket_do_handshake_impl(PySSLSocket *self)
BIO_set_nbio(SSL_get_wbio(self->ssl), nonblocking);
}
@@ -1,4 +1,4 @@
-From 81911909bc439d6de8ce6a173b0691b3c58e9e1a Mon Sep 17 00:00:00 2001
+From 6d037e6ae517ce3179225044a73f2a518ce73d6c Mon Sep 17 00:00:00 2001
From: Victor Stinner <vstinner@python.org>
Date: Mon, 4 May 2026 16:20:25 +0200
Subject: [PATCH] gh-148292: Remove shutdown() test in test_ssl.test_got_eof()
@@ -21,10 +21,10 @@ Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
1 file changed, 8 deletions(-)
diff --git a/Lib/test/test_ssl.py b/Lib/test/test_ssl.py
-index 03d9e3f9e5e96b5..6445f122b4272be 100644
+index 375f905..efdd293 100644
--- a/Lib/test/test_ssl.py
+++ b/Lib/test/test_ssl.py
-@@ -4820,14 +4820,6 @@ def test_got_eof(self):
+@@ -5108,14 +5108,6 @@ class ThreadedTests(unittest.TestCase):
sslsock.do_handshake()
self.assertEqual(sslsock.pending(), 0)
@@ -1,4 +1,4 @@
-From b41557f570ff4451c477669d6ca5bfacabe21c66 Mon Sep 17 00:00:00 2001
+From 4a290494e1b83662c526ac371db139f721916385 Mon Sep 17 00:00:00 2001
From: Richard Purdie <richard.purdie@linuxfoundation.org>
Date: Tue, 13 Jul 2021 23:19:29 +0100
Subject: [PATCH] python3: Fix make race
@@ -17,10 +17,10 @@ Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/Makefile.pre.in b/Makefile.pre.in
-index a7e536d..e946018 100644
+index de72b03..b43baf1 100644
--- a/Makefile.pre.in
+++ b/Makefile.pre.in
-@@ -2741,7 +2741,7 @@ COMPILEALL_OPTS=-j0
+@@ -2742,7 +2742,7 @@ COMPILEALL_OPTS=-j0
TEST_MODULES=@TEST_MODULES@
.PHONY: libinstall
@@ -1,4 +1,4 @@
-From 66874ce1a9f21b4b00dc85919734d58e6243ca29 Mon Sep 17 00:00:00 2001
+From 874d907f7ab58b3c240671a1abed35ead6c30152 Mon Sep 17 00:00:00 2001
From: "Jason R. Coombs" <jaraco@jaraco.com>
Date: Tue, 23 Jul 2024 08:36:16 -0400
Subject: [PATCH] Prioritize valid dists to invalid dists when retrieving by
similarity index 99%
rename from meta/recipes-devtools/python/python3_3.14.7.bb
rename to meta/recipes-devtools/python/python3_3.14.8.bb
@@ -30,7 +30,7 @@ SRC_URI:append:class-native = " \
file://0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch \
"
-SRC_URI[sha256sum] = "3b48dac8fb59f62eaa67ac83c1eb12bda1b7a08406dd286e252c11a66be27f81"
+SRC_URI[sha256sum] = "c2215904f02b175596dc49351585104f4bc20341e1c47378b26a2c274360ce73"
# exclude pre-releases for both python 2.x and 3.x
UPSTREAM_CHECK_REGEX = "[Pp]ython-(?P<pver>\d+(\.\d+)+).tar"
Hello, this email is a notification from the Auto Upgrade Helper that the automatic attempt to upgrade the recipe(s) *python3* to *3.14.8* has Succeeded. Next steps: - apply the patch: git am 0001-python3-upgrade-3.14.7-3.14.8.patch - check the changes to upstream patches and summarize them in the commit message, - compile an image that contains the package - perform some basic sanity tests - amend the patch and sign it off: git commit -s --reset-author --amend - send it to the appropriate mailing list Alternatively, if you believe the recipe should not be upgraded at this time, you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that automatic upgrades would no longer be attempted. Please review the attached files for further information and build/update failures. Any problem please file a bug at https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler Regards, The Upgrade Helper -- >8 -- From 77b83de4ac0e05ce4922f563b4d339cd1c5bdca4 Mon Sep 17 00:00:00 2001 From: Upgrade Helper <auh@yoctoproject.org> Date: Thu, 1 Oct 2026 05:43:36 +0000 Subject: [PATCH] python3: upgrade 3.14.7 -> 3.14.8 What's New in Python 3.14.8 final? ================================== *Release date: 2026-09-30* Security -------- - gh-158446: Fix a crash or incorrect output that could occur when formatting a :class:`float` or :class:`complex` with a precision close to the platform's ``INT_MAX``. :c:func:`PyOS_double_to_string` now raises :exc:`ValueError` for any precision of that magnitude, regardless of presentation type or value, as the format string parsers already did for precisions above ``INT_MAX``. - gh-156793: :mod:`asyncio`: :meth:`loop.start_tls() <asyncio.loop.start_tls>` and :meth:`loop.create_connection() <asyncio.loop.create_connection>` now validate the *server_hostname* argument if an :class:`ssl.SSLContext` is passed with *check_hostname* set to ``True``. - gh-156793: :meth:`ssl.SSLContext.wrap_bio` now validates its *server_side*, *server_hostname* and *session* arguments similar to :meth:`ssl.SSLContext.wrap_socket`. In particular, a context with :attr:`~ssl.SSLContext.check_hostname` enabled and no *server_hostname* passed to :meth:`!wrap_bio` now raises :exc:`ValueError` instead of completing a handshake that verified the certificate chain without verifying the peer's identity, with no indication that the check had been skipped. - gh-157953: Update bundled `libexpat <https://libexpat.github.io/>`_ to version 2.8.5. - gh-156002: Bound the amount of data :mod:`zipfile` decompresses per read for members compressed with bzip2, LZMA, or Zstandard, matching the existing limit for deflate. A small archive member could previously expand into an unbounded allocation even when read in small chunks. - gh-155999: Fix the :mod:`tarfile` ``tar`` and ``data`` extraction filters creating directories outside the destination for members whose name leaves the destination and returns to it, such as ``../evil/../dest/sub/file``. The containment check used the resolved path, but intermediate directories were created from the name as given. - gh-156293: Fix a crash in :mod:`ssl` when an :attr:`~ssl.SSLContext.sni_callback` switches a connection to another :class:`~ssl.SSLContext` and the context that carries the callback is no longer referenced by the application. Servers that keep their ``sni_callback`` context alive (the usual case when it wraps the listening socket or is stored on the server object) were not affected. This addresses :cve:`2026-19445`. - gh-155292: Change the :mod:`stringprep` module and :mod:`encodings.idna` codec to not consider Unicode codepoint attributes beyond those defined in :rfc:`3454`. - gh-155694: Fix :cve:`2026-15806` by scoping :class:`~urllib.request.HTTPPasswordMgr` credentials to the URL scheme, preventing credentials stored for an HTTPS URL from being used for a matching HTTP URL, while URIs without a scheme continue to match any scheme. Core and Builtins ----------------- - gh-158364: Fix crash when :func:`sys._current_frames` or :func:`sys._current_exceptions` is called while another interpreter is running. - gh-158254: Reverse iterators over a :class:`dict` and its views now raise :exc:`RuntimeError` if the dictionary's keys change during iteration, like forward iterators, instead of yielding entries for the new keys. - gh-157838: Merge biased reference counts on behalf of threads that are detached instead of waiting for them to attach again, in the free-threaded build. - gh-157378: Fix ``SyntaxError.offset`` and ``SyntaxError.end_offset`` for the "Non-UTF-8 code starting with ..." error when a non-ASCII character precedes the invalid byte on the same line. Patch by Shamil Abdulaev. - gh-156762: Fix undefined behaviour in :class:`operator.methodcaller`: its :c:member:`~PyTypeObject.tp_clear` slot function returned ``void`` instead of ``int``, so the garbage collector called it through an incompatible function type. Patched by Shamil Abdulaev. - gh-157377: Fix :func:`gc.get_count` on the free-threaded build resetting the thread-local allocation counter that schedules automatic garbage collection. A thread that called it while allocating could prevent cyclic garbage from ever being collected. - gh-156091: Fix a crash when compiling deeply nested inlined list, set, or dict comprehensions. A :exc:`SyntaxError` is now raised when the nesting exceeds the compiler's static block limit. - gh-156894: Fix the position of syntax errors which cover a range if the line contains non-ASCII characters before the error. - gh-155525: Fix quadratic-time tokenization of modules containing many f-strings or t-strings. - gh-156689: Fix an out-of-bounds read in :func:`compile` and :func:`ast.parse` when an AST object is passed with ``mode='func_type'``. - gh-156371: Fix missing ``PyRefTracer_DESTROY`` events for trashcan deferred objects. Patch by Donghee Na. - gh-156114: Fix a crash in the perf trampoline when a code object has a name or filename that cannot be encod [Changelog truncated as it exceeds 5000 characters; the full changelog can be found in an attachment to the AUH email] --- ...shebang-overflow-on-python-config.py.patch | 6 +-- ...e-stdin-I-O-errors-same-way-as-maste.patch | 2 +- ...-use-prefix-value-from-build-configu.patch | 2 +- ...-qemu-wrapper-when-gathering-profile.patch | 6 +-- ...est_sysconfig-for-posix_user-purelib.patch | 2 +- ...146207-Add-support-for-OpenSSL-4.0.0.patch | 42 +++++++++---------- .../0001-prefer-valid-entrypoints.patch | 2 +- ...g.py-use-platlibdir-also-for-purelib.patch | 2 +- ...le.py-correct-the-test-output-format.patch | 2 +- ...Update-_ssl._SSLSocket-for-OpenSSL-4.patch | 22 +++++----- ...utdown-test-in-test_ssl.test_got_eof.patch | 6 +-- .../python/python3/makerace.patch | 6 +-- .../python/python3/valid-dists.patch | 2 +- .../{python3_3.14.7.bb => python3_3.14.8.bb} | 2 +- 14 files changed, 52 insertions(+), 52 deletions(-) rename meta/recipes-devtools/python/{python3_3.14.7.bb => python3_3.14.8.bb} (99%)