From patchwork Mon Sep 14 03:12:49 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 98150 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6C3F6C88E5C for ; Mon, 14 Sep 2026 03:13:12 +0000 (UTC) Received: from mail-pf1-f182.google.com (mail-pf1-f182.google.com [209.85.210.182]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.12074.1789355589436338270 for ; Sun, 13 Sep 2026 20:13:09 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=VIIAFYwe; spf=pass (domain: gmail.com, ip: 209.85.210.182, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f182.google.com with SMTP id d2e1a72fcca58-86959a6f7f6so2166909b3a.2 for ; Sun, 13 Sep 2026 20:13:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789355589; x=1789960389; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=hdfR3hspc4XMllBn+YHDmeCYofjcWQ6JPF8DWcfxMi4=; b=VIIAFYwevAnim8l85PaGecIWxWTzFNnJwndugXmkkcalCkripDgVqTiRw1vvBfY+kN wItOyM02Vj5R2Jt2YpSCHHi+JQErF5pUzRIFE4NLfPDxkbaocUbf8EbT7i9uC5BsboFq LSE+kvgFCfZivEhvtFMxretJApI3yrRXIr1A/M/RUVh6fCWxbv0Bz3CXwUXpZI0RsqLB wgmVSRfqM2+dZPR/1r7V9wNXQX2Z0H+VVPtYBbeYe1fGaMVLMCtrK5L1i4ea2Ytkq9jL A8IKhWc2OOEA159CoM0oKar7f/rGhvO5/Nmtb8jqdIbXCz4XYkHG3+sqXqxx/rWiFyxm m9rw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789355589; x=1789960389; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=hdfR3hspc4XMllBn+YHDmeCYofjcWQ6JPF8DWcfxMi4=; b=P7KJZX1S1MefZa0or4xnQxilc2Rrhz8yPj7Ce5BDlQf9CmWu5TX0G5f7jLOvitCbSR ul9YmealMxwsit2ktqG9rUvJnihamimFAliPu++1KR4B0rFU+nzXJG86JolEQFVDGZws d0c6vpBnVbZENIJWPfxLu3DfJ1eeQffl0fvKtDSoAXJwq8P5Y433Uu9sGoWxEyxqIIG8 Bi2iy2OrJyRjkzdy0ThHdQg+B1xejG5P84o2hkqoeAyDIryNkivJRqItMLAblU6Ob4Wr qSc66gmeRThezd9mLD0GE3LNA8S6ikYv9u2GT1exw7a66U02ETtSx4jYxfv9k3h2G4Rq kveA== X-Gm-Message-State: AFuF++mzeD1Drn2Y+3Mwpn9+fBygMiJWwf9sLf9lmqpcJo7bYBSf5ojh iOYd16zr5NBYR/LjxUlU1I1JU/2/Lsq2do5WiyFmaFkJjkDbLRD84omJxqFtEt7Z X-Gm-Gg: AYBFou1twH6m4b33JxFd4hfUK1nSu9A1ymQMFXm2vCogeneLwZGkmAcj+YxFPq3D/wX SAyYa9k1Pl1I8tDSpR9BGfOHZA73siFWfjzmxPeYO7iz6G1+E5VTGiWAhaHHZTNTueGOU/FM3ml 6beGlcFkbWnDLVkePFPfgm+l8KE4RDRFpTGI8QXab6CCK8lqNDrWk8dJw8aHpuE3FW7aQan0eAC 7QKx+xxjLSinAjbKRo7N8lIYkJ96mk/k+dtAaJg+J+qI2T/j0XHUDXxwYcsxzCejzpKHrra9Hsq IgAlEOuFzOm4SQn0BnpucJ4uYzatHo9856fmMqhJ7spUyoT1NO3ATL6oFQu9mIRjcHKyyg2RvGh J9ONcC/CekDdX1gVvq5IlnMBqpunyrVVjVmC8kWBmNXAbeTXtFp+/nSZjov5Mt9ajK95aMytTY5 AU+OkxW+9petJXn9qHWuAQW+JSB+OyT8dFQO5Gc5+Re/ULjKxj4MGb682yJ+VIS1DT6rsFiJiNH zUATWMQQIJOmWwqNMb7 X-Received: by 2002:a05:6a00:950b:b0:869:8620:26d2 with SMTP id d2e1a72fcca58-86f82f51c34mr1773606b3a.1.1789355588593; Sun, 13 Sep 2026 20:13:08 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([202.170.174.3]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-86b2a2b5c72sm3712425b3a.52.2026.09.13.20.13.06 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 13 Sep 2026 20:13:08 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-python][wrynose][PATCH 1/10] python3-django: upgrade 6.0.7 -> 6.0.8 Date: Mon, 14 Sep 2026 15:12:49 +1200 Message-ID: <20260914031300.3677365-1-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 14 Sep 2026 03:13:12 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130009 From: Ankur Tyagi Also revert bump in the minimum setuptools version. Release Notes: https://docs.djangoproject.com/en/dev/releases/6.0.8/ Signed-off-by: Ankur Tyagi --- ...ped-minimum-setuptools-version-to-83.patch | 42 +++++++++++++++++++ ...jango_6.0.7.bb => python3-django_6.0.8.bb} | 3 +- 2 files changed, 44 insertions(+), 1 deletion(-) create mode 100644 meta-python/recipes-devtools/python/python3-django/0001-Revert-Bumped-minimum-setuptools-version-to-83.patch rename meta-python/recipes-devtools/python/{python3-django_6.0.7.bb => python3-django_6.0.8.bb} (62%) diff --git a/meta-python/recipes-devtools/python/python3-django/0001-Revert-Bumped-minimum-setuptools-version-to-83.patch b/meta-python/recipes-devtools/python/python3-django/0001-Revert-Bumped-minimum-setuptools-version-to-83.patch new file mode 100644 index 0000000000..5913287038 --- /dev/null +++ b/meta-python/recipes-devtools/python/python3-django/0001-Revert-Bumped-minimum-setuptools-version-to-83.patch @@ -0,0 +1,42 @@ +From 2c7d43e13909886bbb0b6b5dcd5e718c67818031 Mon Sep 17 00:00:00 2001 +From: Ankur Tyagi +Date: Mon, 14 Sep 2026 11:37:53 +1200 +Subject: [PATCH] Revert "Bumped minimum setuptools version to 83." + +This reverts commit 8362cdc7efc9c881fdba48ce19e89b9194de7c46. + +Upstream precautionarily bumped minimum setuptools version[1] +Revert the change to allow building new versions of Django. + +[1]https://github.com/django/django/pull/21691 + +Upstream-Status: Inappropriate [oe-specific] +--- + docs/intro/reusable-apps.txt | 2 +- + pyproject.toml | 2 +- + 2 files changed, 2 insertions(+), 2 deletions(-) + +diff --git a/docs/intro/reusable-apps.txt b/docs/intro/reusable-apps.txt +index 41122dff9a..bb33dc0197 100644 +--- a/docs/intro/reusable-apps.txt ++++ b/docs/intro/reusable-apps.txt +@@ -211,7 +211,7 @@ this. For a small app like polls, this process isn't too difficult. + :caption: ``django-polls/pyproject.toml`` + + [build-system] +- requires = ["setuptools>83"] ++ requires = ["setuptools>=77.0.3"] + build-backend = "setuptools.build_meta" + + [project] +diff --git a/pyproject.toml b/pyproject.toml +index 1c5f5fbbe0..2b8ddbf314 100644 +--- a/pyproject.toml ++++ b/pyproject.toml +@@ -1,5 +1,5 @@ + [build-system] +-requires = ["setuptools>=83"] ++requires = ["setuptools>=77.0.3"] + build-backend = "setuptools.build_meta" + + [project] diff --git a/meta-python/recipes-devtools/python/python3-django_6.0.7.bb b/meta-python/recipes-devtools/python/python3-django_6.0.8.bb similarity index 62% rename from meta-python/recipes-devtools/python/python3-django_6.0.7.bb rename to meta-python/recipes-devtools/python/python3-django_6.0.8.bb index 4542485154..f8a5d6962c 100644 --- a/meta-python/recipes-devtools/python/python3-django_6.0.7.bb +++ b/meta-python/recipes-devtools/python/python3-django_6.0.8.bb @@ -1,7 +1,8 @@ require python3-django.inc inherit python_setuptools_build_meta -SRC_URI[sha256sum] = "2998503fc083124fb58037084bfa00de323c7c743f05f1b4284e77bff0ab8890" +SRC_URI[sha256sum] = "cb0bd962d27fc866f3c514b20aae6a7df56ec80b488f9899da46d675cd051526" +SRC_URI += "file://0001-Revert-Bumped-minimum-setuptools-version-to-83.patch" # Set DEFAULT_PREFERENCE so that the LTS version of django is built by # default. To build the 6.x branch, From patchwork Mon Sep 14 03:12:50 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 98153 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id AD517C88E6A for ; Mon, 14 Sep 2026 03:13:22 +0000 (UTC) Received: from mail-pz2-f43.google.com (mail-pz2-f43.google.com [74.125.228.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.12075.1789355592474534565 for ; Sun, 13 Sep 2026 20:13:12 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=ZTaE0384; spf=pass (domain: gmail.com, ip: 74.125.228.43, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f43.google.com with SMTP id d2e1a72fcca58-85469b2e1d5so1705982b3a.1 for ; Sun, 13 Sep 2026 20:13:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789355592; x=1789960392; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=SLMm0+krB13BTEC558tXbJVHcCPYTmJaKSBVMWBR8rg=; b=ZTaE0384pAwemm/kheMy8+3zxDcLtxKnxlDw8PMLN1HPsAljzrAM46O4ay6JDLBCKA K7BubT3z6067NTqNgzHnl3eb3IkS32lovc/1CkFOpwiAvf5XRiNr/2Zv6p6ZdKlXDiOF gaR2yCPzeP+Z9mg2B/QGtGmwTg4fIQfnwr1oKRftTcBTe6KgJ2vihJlzaQV+YXuB3ps2 kv9CKhfxxRRv/DaaEI2DbMbaESvbQuADy1K9DKrS0hMNJgd0XOrE26bEp8+/VJDgDyKM xOTsunU+9kA+uD4XgSt6ZxDWGJBBmWjuE+yjaqmIQqAU3GO0Og3f7kCQIBud4LrsdZRs y2mA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789355592; x=1789960392; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=SLMm0+krB13BTEC558tXbJVHcCPYTmJaKSBVMWBR8rg=; b=LJQt8V6flMEeDx197HHPqf9JmRdM9YqMVdC8ClK14AQ6IpQzH5YMY7fsskBUEBWoEf w7sjoF8A/sgLTVXVGJEdZtt1egXSrOQ9wZIGrr7eK/DFKlSL1F+gke+E1bY3UEk+tE7h OsIBzLHP0qKzo5zLkERwtPdX/Z+y6VmeYvOMd36IUKs0pdTzlxCOFX2HXN2M2XambA4J 9b3RKTZjPiWla2AuQylDhNFtxvXr01ebPxvdSXtrkT5E/KH4LjKCzYRfQywhROvHkspm iZ7tX4pcTiFXi+hYKxFK2VX87X1jvq0c1aCsmSUFi7/w9YoydL/ZKvr+PlQya6KPyTv9 Wgpw== X-Gm-Message-State: AFuF++khemHspmTxhFHq2SprPqA6SeIGX2u7nj1OTsMIVzDCRkR37w9w 2+nXdmtV0WtRtjfaVmFxfndt8n60Px3s7NqS5umlSyEEfWFhOxT+t8E2RT5cEgi/ X-Gm-Gg: AYBFou04mia8BFTx8HPdYykIFx+BMIofnl5Xp+HeEvaGDme5gmC1mggoTTwlZAOmeXh 1gCg+GM65qk9csMN4nZ6v7KKLh8Myz81nQjidPK1YHRHiaXi6+Vk6hd/OUhsdnWO5GjCB+2EzDy 7zFF0qq2eaggjJChCRpg9NicrE1+2i9tS9Yior1g+GZjD6n+KYYz5K5jflJUjHt5XWwBUcg5uA9 Z0gf24xv3Rn53apF/xE7jReXBdyiP5178nEuBgQsbyrSDhjQeq8r5/59yxnQqbQdlkcWdF0kiyI WhdFDjzArQR/D6RTSW616pEmEf5CQKmSrkGiOKSXamw835DSG27U4bc2o0ncCVmPze7yy9g6q0q j/KXW3gOCP4RN50qxSlhwsF5KBv8XAEyfxZxFLpt8DFy9bzXLF0KZOVga/Wzvz34UcJyKiUy7la qvUFt0P4vYgIUZ96Ba4G53tbUy6LGQXyU0lyU2zZCH0hLBmgN8oKNv+3qKgvHPps6WnwHdxhQPR /PTdRP0bbhLmkAgimFD X-Received: by 2002:a05:6a00:ad3:b0:851:ba04:ca02 with SMTP id d2e1a72fcca58-86f854fc944mr1621900b3a.16.1789355591715; Sun, 13 Sep 2026 20:13:11 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([202.170.174.3]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-86b2a2b5c72sm3712425b3a.52.2026.09.13.20.13.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 13 Sep 2026 20:13:11 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-python][wrynose][PATCH 2/10] python3-django: upgrade 5.2.16 -> 5.2.17 Date: Mon, 14 Sep 2026 15:12:50 +1200 Message-ID: <20260914031300.3677365-2-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260914031300.3677365-1-ankur.tyagi85@gmail.com> References: <20260914031300.3677365-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 14 Sep 2026 03:13:22 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130010 From: Ankur Tyagi Also revert bump in the minimum setuptools version. Release Notes: https://docs.djangoproject.com/en/dev/releases/5.2.17/ Signed-off-by: Ankur Tyagi --- .../recipes-devtools/python/python3-django_5.2.16.bb | 5 ----- .../recipes-devtools/python/python3-django_5.2.17.bb | 7 +++++++ 2 files changed, 7 insertions(+), 5 deletions(-) delete mode 100644 meta-python/recipes-devtools/python/python3-django_5.2.16.bb create mode 100644 meta-python/recipes-devtools/python/python3-django_5.2.17.bb diff --git a/meta-python/recipes-devtools/python/python3-django_5.2.16.bb b/meta-python/recipes-devtools/python/python3-django_5.2.16.bb deleted file mode 100644 index 2629ff3714..0000000000 --- a/meta-python/recipes-devtools/python/python3-django_5.2.16.bb +++ /dev/null @@ -1,5 +0,0 @@ -require python3-django.inc -inherit python_setuptools_build_meta - -SRC_URI += "file://0001-fix-test_msgfmt_error_including_non_ascii-test.patch" -SRC_URI[sha256sum] = "59ea02020c3136fce14bef0bbece21a10a4febef5eed1c51c22ae468efa22200" diff --git a/meta-python/recipes-devtools/python/python3-django_5.2.17.bb b/meta-python/recipes-devtools/python/python3-django_5.2.17.bb new file mode 100644 index 0000000000..3f49bfcaea --- /dev/null +++ b/meta-python/recipes-devtools/python/python3-django_5.2.17.bb @@ -0,0 +1,7 @@ +require python3-django.inc +inherit python_setuptools_build_meta + +SRC_URI += "file://0001-fix-test_msgfmt_error_including_non_ascii-test.patch \ + file://0001-Revert-Bumped-minimum-setuptools-version-to-83.patch \ +" +SRC_URI[sha256sum] = "9d4d93be539a18ab80d058eb515900e10951e04c537c5a6b394fc49528d3251f" From patchwork Mon Sep 14 03:12:51 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 98154 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A3436C88E66 for ; Mon, 14 Sep 2026 03:13:22 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.12076.1789355595245282342 for ; Sun, 13 Sep 2026 20:13:15 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=DTOroTyS; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id d2e1a72fcca58-85469d249c4so1702625b3a.2 for ; Sun, 13 Sep 2026 20:13:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789355595; x=1789960395; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=F9+yL6eYQxabiIOPWJ/pAK+WBW7vdjSQk8XOWWLAcEs=; b=DTOroTyS7/PLe4JNJc33RPeliXMGsZK3pGbU4umknzpAard1SkLRCOiW4nER5hQWVB hSM61Vh6OKxLHOYsWT7DsOl0yLKm/IrcUDNzTK80U6HpeJt9KMBsK8WhS+v4jTZb2xra Q8NIGGmhqppvNCTXki6JSifT0aMUr5a55yyZiVWjShPhjpR7zqNV74cK4+19NP1GI+57 bbkdElxx5n/6cLDQvQYOdIf7M0mFPd8Z8q72O8xCYH9k6MsMNb3t+o2XGTYX3BnfwEgI I/ZeB0+EotyVjCpIRpVIeAAzcWtNLiNJ7TEVOVArCVrVm3YLM/KM39Kn9k/HWa16Ix0z +oHA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789355595; x=1789960395; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=F9+yL6eYQxabiIOPWJ/pAK+WBW7vdjSQk8XOWWLAcEs=; b=oZD6myj+S3bVta9wEPtK2Hbxa08+VfdwD+jHqR5/S2tfMBEoqIpzxLit1yUSkd4YU6 zLivCkpaMNtAZ+fDW2STA7QDjVP46hdqWkXq9nKFi4JNJq9t4AcKyWWfz5/WWI6muM8U kKVN7WSnX0dh5fIwzMw+VbK9NnkWsaOmc9ECSCGzBUPYx8MsTpYPF46mscHhjx1qAXDU JnRyC6LVccphHgVdWTRAdulJLl+39ApOEbfuhMTeDefA0/dFMrRMZzEIbbb5xssDs4tn qVE85eswz40uAnKLPI7Zne70KgwbxIayacVcY6rbtGRgjPxeGjGLFLqprkycIdhk48Ed h5Ng== X-Gm-Message-State: AFuF++nv0pOpc/0DMZkRO+nBoIxIcElkC5CQvnhL8/nrtX0nwzlFeUrK dNnlBjOy0ZP5h0WhEslXvOG+OhA2htS79tuIbY+jVG3rpdhVyQ4etodhfzeAf0+r X-Gm-Gg: AYBFou0QfLffPkURy02zZoyF3ns6m3DvclV8upF+S9TVwvzk3CVw40MbdOSU+/lJhCG ceSYWgpr74u1jyYUJbEb8EtBjMM0WQrMzbk1L3sDXodDMq1nRbSOc10zt9TsaCbrCDAX/XTBAil bJw4WNxcrFKHNQWzy8lRczKeI140VUDqViZVD+n8dexQ29EEQlldz0FH08RPb2pftReC+Z/VuMh TuKdjQMEScYja2VAG37BU470V+r5of+sgsNpi/kF4osbG3p8zuCAXpbB4QM+UbB/PSp1FoU6HnF jVEjanFjTq/F/h13JLe6AKWWqYgfcMzm2IbmZMxhJpcR+NHxhzmi1EFzM/CPO5tbnKZ/tx/h0yT gmwEKD6urMsEf8LaQg3qZyEjva4o5P+LGunkJNt6U5tOIxtYvKoenegPuO7zkWN3ME36zK1ps9N 93psXyFKsOqFUjOg67OgmitTf6sNU/zBqKGNSEuamtfNNpeEuF6HrYnTwSYcDhFxysECsA2Uq0K 0GT2PJ7cZByz9dbNVwzo9RnY2yVRQM= X-Received: by 2002:a05:6a00:1916:b0:857:726d:2e9c with SMTP id d2e1a72fcca58-86f862c49b8mr1598775b3a.25.1789355594556; Sun, 13 Sep 2026 20:13:14 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([202.170.174.3]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-86b2a2b5c72sm3712425b3a.52.2026.09.13.20.13.12 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 13 Sep 2026 20:13:14 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-python][wrynose][PATCH 3/10] python3-eventlet: mark CVE-2023-29483 fixed Date: Mon, 14 Sep 2026 15:12:51 +1200 Message-ID: <20260914031300.3677365-3-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260914031300.3677365-1-ankur.tyagi85@gmail.com> References: <20260914031300.3677365-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 14 Sep 2026 03:13:22 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130011 From: Ankur Tyagi Fix[1] for the CVE is part of the upstream version. Details: https://nvd.nist.gov/vuln/detail/cve-2023-29483 [1]https://github.com/eventlet/eventlet/commit/51e3c4928d4938beb576eff34f3bf97e6e64e6b4 Signed-off-by: Ankur Tyagi --- meta-python/recipes-devtools/python/python3-eventlet_0.41.0.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta-python/recipes-devtools/python/python3-eventlet_0.41.0.bb b/meta-python/recipes-devtools/python/python3-eventlet_0.41.0.bb index 3c27caf968..0b8cd676d9 100644 --- a/meta-python/recipes-devtools/python/python3-eventlet_0.41.0.bb +++ b/meta-python/recipes-devtools/python/python3-eventlet_0.41.0.bb @@ -18,3 +18,5 @@ RDEPENDS:${PN} += " \ python3-six \ python3-greenlet \ " + +CVE_STATUS[CVE-2023-29483] = "fixed-version: fixed since v0.35.2" From patchwork Mon Sep 14 03:12:52 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 98151 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 62BB3C88E64 for ; Mon, 14 Sep 2026 03:13:22 +0000 (UTC) Received: from mail-pz2-f43.google.com (mail-pz2-f43.google.com [74.125.228.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.12167.1789355598072692803 for ; Sun, 13 Sep 2026 20:13:18 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=PHtlEb6Z; spf=pass (domain: gmail.com, ip: 74.125.228.43, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f43.google.com with SMTP id d2e1a72fcca58-8692a856865so1917553b3a.2 for ; Sun, 13 Sep 2026 20:13:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789355597; x=1789960397; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=EJhHMu3WP5axg6wYuj8RUCpXRPX7Im5vhoWxE50p1ng=; b=PHtlEb6Z75702p9ewkIMOhrx1OD1HLxFGjrblTCl8ICwmG7gJMSCHu8NtmASutugK/ zoee1bO60UFK6GGdWpG/D8qtK/OxH7WL34KLoLsi6btFQpajr6kDHimjDLiemLeg5bXm Z9WDUfOGVI9c7OhLyWwtkCBWh2CMnzmkoolacAYx3gCRtcSClLZdygQkaESG1xcCjH+n FBut+oRpEdHRCokO96eI/yNyYDI5fk/+22Kv0AxhVdQPYxASNFgWFcCjhlF088qJ8WKm PDq9qiuTrGAmFfKtxrubBFiQbJjRYm7W7t8pyi16ZvSSJZJlHkivNpDeymgCa1W24FoL DYuQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789355597; x=1789960397; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=EJhHMu3WP5axg6wYuj8RUCpXRPX7Im5vhoWxE50p1ng=; b=ISmAmm9ocHI8AlQMMZAPLttI5jbbvTrgRSMdSCvm4L+6EFNB1Po6Jro4eGQFkqPP8M IIHrkqM042CFoW39LQApoTgjauDPFwV5bZaDtP8OhBMrVJTkePy/FbdC5+r1YFmQGj9V 2gKxb3lNv4XeSXWW8owUZL5kEqkdbwa7aH8imOZXPvarBgD8+VpErvmWiw6lOO/UoVRh rsIh2RI5YgX5GNXcAmwAfL6I6nNUoH1i3yfzo/0StVP7YDh5xaNulBou56u+eUJTaODc v/07zxWJVbY57ZSnZRERMIH3R8oLKcHG56rV26Qt/M2+69S9VOFxuK9C7dUWY+qfH4/F UMYA== X-Gm-Message-State: AFuF++lGB7i+uSxhR4v3tBQAW/ebq59j+7VHy+6uJyEJrIacHg/mLzwT OPLyo+gE9FY0RGH9TJK8ua0vTbpAiYRC3btSBz2eHCCWX3X6RqQbE7YT6x05f/7V X-Gm-Gg: AYBFou1UZTE1tVtDB/eq4KabM7gr+XW1qwRoquNlEL7NQr2ldvPLCp70O1CdvrNgICg ukixe8b+RmG5q5SPLwLmqVEdezS6j7/Ql1BU0eet+O0r+7L9nyHlpd0bpLd/xdXkq9eWid72cpa U9DdMdL/YBEzRE0TiJBx5vThfLiyH4goLTkelmNNzwMr0YMDESJq0BkMlAesXxeE5u/lVh8focg nZWJUv3gZC1VHntVZkXxTC6UdMmit0zbJv/X02KpKnUoNaS6lH8bDyLPEAF2sNJvxMhHJlfT1z/ NQrSIqD2Ds/WKe3CEJlMOIUM6hd/yyCSPKZS27eP+ek07oa90XeEYwlm+WB6E9s8UDyUdkcmXm1 dyn7FzeoNxsRcGDjcUTNRHHSr9SrIHU6xReQ7DzSCr2wZvWSVxsMiAj5I91tLCpeD+awE0MtCUz tgrVf738quTY/zLptCX/w/tCidnKUfkyfcu41JkAUywHM0U/BJv5fO/YNjWJ5C7f3A8lIJtR5/8 6ow5qCfowWKbE/A6Dhw X-Received: by 2002:a05:6a00:950b:b0:86a:b3:fc50 with SMTP id d2e1a72fcca58-86f82e5bd35mr1911280b3a.3.1789355597312; Sun, 13 Sep 2026 20:13:17 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([202.170.174.3]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-86b2a2b5c72sm3712425b3a.52.2026.09.13.20.13.15 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 13 Sep 2026 20:13:16 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-python][wrynose][PATCH 4/10] python3-h11: mark CVE-2025-43859 fixed Date: Mon, 14 Sep 2026 15:12:52 +1200 Message-ID: <20260914031300.3677365-4-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260914031300.3677365-1-ankur.tyagi85@gmail.com> References: <20260914031300.3677365-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 14 Sep 2026 03:13:22 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130012 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2025-43859 Signed-off-by: Ankur Tyagi --- meta-python/recipes-devtools/python/python3-h11_0.16.0.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta-python/recipes-devtools/python/python3-h11_0.16.0.bb b/meta-python/recipes-devtools/python/python3-h11_0.16.0.bb index ed1702ff54..0bc1cd5c41 100644 --- a/meta-python/recipes-devtools/python/python3-h11_0.16.0.bb +++ b/meta-python/recipes-devtools/python/python3-h11_0.16.0.bb @@ -10,3 +10,5 @@ SRC_URI[sha256sum] = "4e35b956cf45792e4caa5885e69fba00bdbc6ffafbfa020300e549b208 CVE_PRODUCT = "python-hyper:h11" RDEPENDS:${PN} += "python3-profile" + +CVE_STATUS[CVE-2025-43859] = "fixed-version: fixed in v0.16.0" From patchwork Mon Sep 14 03:12:53 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 98152 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 84833C88E5C for ; Mon, 14 Sep 2026 03:13:22 +0000 (UTC) Received: from mail-pf1-f176.google.com (mail-pf1-f176.google.com [209.85.210.176]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.12168.1789355600986256010 for ; Sun, 13 Sep 2026 20:13:21 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=ocE2dd9P; spf=pass (domain: gmail.com, ip: 209.85.210.176, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f176.google.com with SMTP id d2e1a72fcca58-853f8c34ba4so3793730b3a.0 for ; Sun, 13 Sep 2026 20:13:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789355600; x=1789960400; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=a2wov4LNR+9JHZ9tSqO7xI23YXIvlafWyPRq3Xw2sSw=; b=ocE2dd9P6cwkM6DEnXMxE8iodxA3JeTSWiTuvgqWaRAWhnEMqvYVBsIVG5GQh+wlFV 6qJzDLAEa/ajH/F1lTvZ06StgyA9aHVF+45miIOuHdLRLzUPz069oIKvfzuppKnBfx+D T+GZJzV5Kfz9rpK5CFcecoRyTTX11z41G+ODwv+f0CkZCHIUOgRsHGbH8Ly+NUPfW3kJ mXv71RSqGw/Sy0axic5Q7fmvYearPloP5fmCaQMxJSLbstJQJz9YVvkevl5jQD2JsrDr VsJeErH1LPAh0S6hkGiBLO9fE0WnrrYbIXN574bGIJoAylrejQrZ7/tLZnJY3yNTm61Q 0spA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789355600; x=1789960400; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=a2wov4LNR+9JHZ9tSqO7xI23YXIvlafWyPRq3Xw2sSw=; b=kiMoUMl4VruiN8RuV6OH9MHqHXGiVD1N62gOA/VbNC3PcUcxDGr5jH16sralZWLxfa Th8zFAbQgEnSmKzXTzMTyqFY77kMEH1pdWhZPB3Uf679wBgq4u7hNCfpomO4BY0hu7RT EUWQbBG+JWxlsIObIclCBBRKnucCxkmx09oZTcE35DUPoqENApvgQNX48XfaX8e8+Oas +xJGBbXQqx8vgDPRdEIplJ1oHMiPIlKZNOyDCBHz83/vz5u7lSGIECNZCReziMEXSgvC BMlbpilDMkZNVFztDTkI/9kbtU75FadXzzK8mSk/ucWabAifk7BVH2ZuATDrSccXvelZ SzPQ== X-Gm-Message-State: AFuF++kLOZidW72akXuc6+jSLKxlFkpJqNhdOEC1g0xbVZedhz2owlIq bl60CYGjCqPBZIniDU7EH8rsP4PHR/JdW2Z45hc44qR40DYTq7xygu42FZwdoT9i X-Gm-Gg: AYBFou3/rMD7MsbJvPm14Y65qgJfd0y/LoJu/gdCK9amKZ2fszUjGn9vtgWzxVtOC37 MpFJHMgUrasPSeRA1FSjtv8X+KYtpPaVTTWGPhz1YlZ5v1quf1FMCKrGDF9L52WKKHpBcTeFeS5 193Duw5gTt2gxFsRtbtqFcuGtWMLxxzX3LaVJjYU/zQt0Pw5+MSaBkIXzQG/YCtvMUV0r2e52HQ Zz2nS5aWkAIQG4T6LbBkFylO3VaFVC0QOIlJHLUXAl9B0Wxx6Uk31LLK9jAtzueD754Pkj5ClQJ T27CyUHKS+TAHgvQWhtj/iVjmNOo4t1PlIOOsTOKOuyLDqDURVPmeKAMe3hb/1AeJFE1jQ2+2MV yhL5qRoccHtOuKlxuim37UEEoGmUx0rVK6tAgUWWi8SKdUIncLpo36xOxodFLEs43WuxepFM5I3 47yVBQGQDMcy2w00+bpSaC8wLc8qoxAfJSHIYjiXZ0xm9TADoRg0EMJ47iIH7+uFZyPeIuUfXyr AcbCZKxyCXf5d0rl7G6 X-Received: by 2002:a05:6a00:438d:b0:85f:2f32:7a53 with SMTP id d2e1a72fcca58-86f85ae9d18mr1819828b3a.17.1789355600378; Sun, 13 Sep 2026 20:13:20 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([202.170.174.3]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-86b2a2b5c72sm3712425b3a.52.2026.09.13.20.13.17 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 13 Sep 2026 20:13:19 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-python][wrynose][PATCH 5/10] python3-marshmallow: mark CVE-2025-68480 fixed Date: Mon, 14 Sep 2026 15:12:53 +1200 Message-ID: <20260914031300.3677365-5-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260914031300.3677365-1-ankur.tyagi85@gmail.com> References: <20260914031300.3677365-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 14 Sep 2026 03:13:22 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130013 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2025-68480 Signed-off-by: Ankur Tyagi --- .../recipes-devtools/python/python3-marshmallow_4.3.0.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta-python/recipes-devtools/python/python3-marshmallow_4.3.0.bb b/meta-python/recipes-devtools/python/python3-marshmallow_4.3.0.bb index 169726e527..402cedf459 100644 --- a/meta-python/recipes-devtools/python/python3-marshmallow_4.3.0.bb +++ b/meta-python/recipes-devtools/python/python3-marshmallow_4.3.0.bb @@ -32,3 +32,5 @@ RDEPENDS:${PN} += " \ python3-pprint \ python3-packaging \ " + +CVE_STATUS[CVE-2025-68480] = "fixed-version: fixed since v4.1.2" From patchwork Mon Sep 14 03:12:54 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 98158 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 330ECC88E6A for ; Mon, 14 Sep 2026 03:13:33 +0000 (UTC) Received: from mail-pz2-f42.google.com (mail-pz2-f42.google.com [74.125.228.42]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.12079.1789355603962511859 for ; Sun, 13 Sep 2026 20:13:24 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=MAQUC0FJ; spf=pass (domain: gmail.com, ip: 74.125.228.42, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f42.google.com with SMTP id d2e1a72fcca58-85469b35601so643230b3a.3 for ; Sun, 13 Sep 2026 20:13:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789355603; x=1789960403; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=M98FyxSIT8OIOjyA0Vx4jQt/GdTEw9IXpHU98g0Qqgw=; b=MAQUC0FJo9s+oXyXlYlv7jeSYGc6SX/Ei4tf25eoKLPHRrmdwTtdNAqB3mOnINlt4n 8Kgo60jT0c6aNhqPyB0IoT7jG57WYN+cPcbfZPiOi/ugsyBUTLR/dwnmRFbH94vZ8uem tbTRJWL2BKDTqpjogqGlBIhJti5xLYwRFolowYdIRklcao3gWzUre19NtLbguQ93vVII 0Z1FfBBGb+EE0lY3xavYz39NWvYhhUUEI+biT9kwpFbhQSn1J31+hINSl0SwrBVM/9mO kcu+oQNJWaFT0fY1aKGtuWL1AhNPH02ubg3Tn66Z1OLkheMTztki0xlF2xpb76gGowKp E/Tw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789355603; x=1789960403; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=M98FyxSIT8OIOjyA0Vx4jQt/GdTEw9IXpHU98g0Qqgw=; b=K9z6Vefu+omqNvXvF4RATYccPxIQhlq2E96I9jtxA/68TFBgglcV/d3KnZyM12yg6Y kjGPOv4RUmIzHA2NJeNXp/Db4Qas7Q0s1aKBuV8yxE3hyjSxqM+N4KK2N0991v7PDU+D x64GLp0fmXAV3wDq6vKp+0qeTX/biyU99a5pLDynKzcOMc9DBdh60LxPla9Clz4UIpwW VFChDNiqV/UFD2r7+JTTQaxAUfKi5hXIt9xJx4WeXNF+WHBf2Hg0Ewq7PXFOX9EYS4vi LNFmK4GrpXjxzimiaExFmZT9mR2HY0DSEfR90OIs+GwPcx7Cisb/bWAa+i5af/JRJgfx dpKw== X-Gm-Message-State: AFuF++lL5J5ZUagppkL5zyXOL4Lrq3DayiqDUdKICj2+hmxe7Z/s0Q8F gMCxbi7YU2G2EVExEJio2vW/sNWA/8r0RXwnSfG9AwhlMEuaVB5Ra8OIkf7NSdws X-Gm-Gg: AYBFou1ucuILFSey1Cy3iVs1qHRZlFSRJGiCxWuapf5ie0wpOXdtLMAmeOrZI0bNaQq cBP+IEs61qdOIhT8SXW11vu1yZPMbQ5F0QzOfDcNmGqUsupc9p2ECMsgr+1ZsXncMmqn+l3UCX3 CcdAoqHxvtq37/1trnAS63S/Jm0RFbgQlPRUDzDAeDEC6UzM0J826rWgJ5x2nA2+iYq0L8dJciN CN9cjSeqWZNX2NqzvBlQrOD5feML6OcIjzK7s86HocSAOWRZfzAy4mtzcyqnQI379YC50lFDYIO E1cfxBr8A7jIvRXDvpr4V91E895dtl8hDsD3R+owup5TNA0y/p3zcvSa8zPwjUM7AKBvEv1zewo Q4W7HpL+IxKtUoX5a14wne9z/klZg/+K2ATd0vp43NIDMiyPM/lNJM7DNjo4x0UStBgmWkqTZi9 Q6ZDzOWWP4slfTCaMR2LUyWtmrk/BPBHf8KOTsd0wqwyhRuureKB6uWnxBYvj5x8Tgkec/BjO8S MCT3LiCjjdg0tpEq5yiAR2meFsVnTg= X-Received: by 2002:a05:6a00:3924:b0:86e:8deb:fbd4 with SMTP id d2e1a72fcca58-86f8374468dmr1663902b3a.11.1789355603162; Sun, 13 Sep 2026 20:13:23 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([202.170.174.3]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-86b2a2b5c72sm3712425b3a.52.2026.09.13.20.13.20 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 13 Sep 2026 20:13:22 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-python][wrynose][PATCH 6/10] python3-sqlparse: patch CVE-2026-54284 Date: Mon, 14 Sep 2026 15:12:54 +1200 Message-ID: <20260914031300.3677365-6-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260914031300.3677365-1-ankur.tyagi85@gmail.com> References: <20260914031300.3677365-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 14 Sep 2026 03:13:33 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130014 From: Ankur Tyagi Detais: https://nvd.nist.gov/vuln/detail/cve-2026-54284 Signed-off-by: Ankur Tyagi --- .../python3-sqlparse/CVE-2026-54284-1.patch | 37 +++++ .../python3-sqlparse/CVE-2026-54284-2.patch | 144 ++++++++++++++++++ .../python/python3-sqlparse_0.5.5.bb | 4 + 3 files changed, 185 insertions(+) create mode 100644 meta-python/recipes-devtools/python/python3-sqlparse/CVE-2026-54284-1.patch create mode 100644 meta-python/recipes-devtools/python/python3-sqlparse/CVE-2026-54284-2.patch diff --git a/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2026-54284-1.patch b/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2026-54284-1.patch new file mode 100644 index 0000000000..90769436aa --- /dev/null +++ b/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2026-54284-1.patch @@ -0,0 +1,37 @@ +From 1a0f6530c8f506f953d1b4ffdfa84ae7ad72f7df Mon Sep 17 00:00:00 2001 +From: alhudz +Date: Mon, 1 Jun 2026 19:05:57 +0530 +Subject: [PATCH] set group value from child tokens to avoid quadratic grouping + +(cherry picked from commit 939b129e24c0ad5d51368b1aa72fffcaca76f06f) + +CVE: CVE-2026-54284 +Upstream-Status: Backport [https://github.com/andialbrecht/sqlparse/commit/939b129e24c0ad5d51368b1aa72fffcaca76f06f] + +Signed-off-by: Ankur Tyagi +--- + sqlparse/sql.py | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/sqlparse/sql.py b/sqlparse/sql.py +index 831dfb9..0163ff1 100644 +--- a/sqlparse/sql.py ++++ b/sqlparse/sql.py +@@ -159,7 +159,7 @@ class TokenList(Token): + def __init__(self, tokens=None): + self.tokens = tokens or [] + [setattr(token, 'parent', self) for token in self.tokens] +- super().__init__(None, str(self)) ++ super().__init__(None, ''.join(token.value for token in self.tokens)) + self.is_group = True + + def __str__(self): +@@ -322,7 +322,7 @@ class TokenList(Token): + grp = start + grp.tokens.extend(subtokens) + del self.tokens[start_idx + 1:end_idx] +- grp.value = str(start) ++ grp.value += ''.join(token.value for token in subtokens) + else: + subtokens = self.tokens[start_idx:end_idx] + grp = grp_cls(subtokens) diff --git a/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2026-54284-2.patch b/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2026-54284-2.patch new file mode 100644 index 0000000000..c2d355f78a --- /dev/null +++ b/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2026-54284-2.patch @@ -0,0 +1,144 @@ +From 6416e171b41da8939f391c0492b355d3b6cb8c11 Mon Sep 17 00:00:00 2001 +From: Andi Albrecht +Date: Sat, 6 Jun 2026 07:12:43 +0200 +Subject: [PATCH] Add tests from PR, update CHANGELOG and AUTHORS. + +(cherry picked from commit f80af6a4007f11ada847218df8c29dc859238290) + +CVE: CVE-2026-54284 +Upstream-Status: Backport [https://github.com/andialbrecht/sqlparse/commit/f80af6a4007f11ada847218df8c29dc859238290] + +Dropped changes to the CHANGELOG file. + +Signed-off-by: Ankur Tyagi +--- + AUTHORS | 2 ++ + benchmarks/bench_grouping.py | 59 ++++++++++++++++++++++++++++++++++++ + tests/test_dos_prevention.py | 28 +++++++++++++++++ + 3 files changed, 89 insertions(+) + create mode 100644 benchmarks/bench_grouping.py + +diff --git a/AUTHORS b/AUTHORS +index 24ca667..872c700 100644 +--- a/AUTHORS ++++ b/AUTHORS +@@ -12,6 +12,7 @@ Alphabetical list of contributors: + * Aki Ariga + * Alexander Beedie + * Alexey Malyshev ++* alhudz + * ali-tny + * andrew deryabin + * Andrew Tipton +@@ -77,6 +78,7 @@ Alphabetical list of contributors: + * Tao Wang + * Tenghuan + * Tim Graham ++* tonghuaroot + * Victor Hahn + * Victor Uriarte + * Ville Skyttä +diff --git a/benchmarks/bench_grouping.py b/benchmarks/bench_grouping.py +new file mode 100644 +index 0000000..245ea0e +--- /dev/null ++++ b/benchmarks/bench_grouping.py +@@ -0,0 +1,59 @@ ++"""Grouping performance benchmarks. ++ ++Measures parse time for SQL patterns that stress the grouping engine: ++- Deeply nested parentheses ++- Deeply nested CASE WHEN expressions ++- Wide column lists (tests O(N) identifier grouping, fixed in PR848) ++ ++Run with: python benchmarks/bench_grouping.py ++""" ++ ++import signal ++import time ++ ++import sqlparse ++ ++ ++def _alarm_handler(signum, frame): ++ raise TimeoutError() ++ ++ ++signal.signal(signal.SIGALRM, _alarm_handler) ++ ++ ++def measure(label, sql, fn): ++ signal.alarm(30) ++ t0 = time.perf_counter() ++ status = 'OK' ++ try: ++ fn(sql) ++ except sqlparse.exceptions.SQLParseError: ++ status = 'CAP' ++ except TimeoutError: ++ status = 'TIMEOUT' ++ finally: ++ signal.alarm(0) ++ dt = (time.perf_counter() - t0) * 1000 ++ print(f' {status:8} {dt:8.1f} ms {label} ({len(sql)} B)') ++ ++ ++# Vector 1: deeply nested parentheses ++print('Nested parentheses:') ++for n in (200, 500, 1000, 2000): ++ sql = 'SELECT ' + '(' * n + '1' + ')' * n ++ measure(f'nested-paren n={n}', sql, sqlparse.parse) ++ ++# Vector 2: deeply nested CASE WHEN ++print('Nested CASE WHEN:') ++for n in (100, 200, 400): ++ case = '1' ++ for i in range(n): ++ case = f'CASE WHEN x={i} THEN {case} ELSE NULL END' ++ measure(f'CASE-nested n={n}', f'SELECT {case} FROM t', sqlparse.parse) ++ ++# Vector 3: wide column lists (O(N) grouping, regression fixed in PR848) ++print('Wide column lists:') ++for n in (500, 1000, 2000, 4000): ++ cols = ', '.join(f'col_{i}' for i in range(n)) ++ sql = f'SELECT {cols} FROM t' ++ measure(f'wide-select n={n}', sql, sqlparse.parse) +diff --git a/tests/test_dos_prevention.py b/tests/test_dos_prevention.py +index 4e826c5..1753c05 100644 +--- a/tests/test_dos_prevention.py ++++ b/tests/test_dos_prevention.py +@@ -50,6 +50,34 @@ class TestDoSPrevention: + with pytest.raises(SQLParseError, match="Maximum number of tokens exceeded"): + sqlparse.format(sql, reindent=True) + ++ def test_nested_paren_within_cap_under_1s(self): ++ """Reaching MAX_GROUPING_DEPTH must not require multi-second CPU. ++ ++ Before the TokenList.__init__ fix, a 1 KB payload of 500 nested ++ parens took ~1.3 s and a 2 KB payload of 1000 nested parens took ++ ~11 s before the depth cap raised SQLParseError, because each ++ TokenList materialised its ``value`` via ``str(self)`` which ++ recursed over the full subtree (O(n * depth)). ++ """ ++ sql = 'SELECT ' + '(' * 1000 + '1' + ')' * 1000 ++ t0 = time.perf_counter() ++ with pytest.raises(SQLParseError, match='Maximum grouping depth'): ++ sqlparse.parse(sql) ++ dt = time.perf_counter() - t0 ++ assert dt < 1.0, f'parse took {dt:.2f}s, expected sub-second' ++ ++ def test_nested_case_within_cap_under_1s(self): ++ """Same invariant as nested parentheses, exercised via CASE WHEN.""" ++ case = '1' ++ for i in range(400): ++ case = f'CASE WHEN x={i} THEN {case} ELSE NULL END' ++ sql = f'SELECT {case} FROM t' ++ t0 = time.perf_counter() ++ with pytest.raises(SQLParseError, match='Maximum grouping depth'): ++ sqlparse.parse(sql) ++ dt = time.perf_counter() - t0 ++ assert dt < 1.0, f'parse took {dt:.2f}s, expected sub-second' ++ + def test_normal_sql_still_works(self): + """Test that normal SQL still works correctly after DoS protections.""" + sql = """ diff --git a/meta-python/recipes-devtools/python/python3-sqlparse_0.5.5.bb b/meta-python/recipes-devtools/python/python3-sqlparse_0.5.5.bb index 03c032c49e..021ccfa349 100644 --- a/meta-python/recipes-devtools/python/python3-sqlparse_0.5.5.bb +++ b/meta-python/recipes-devtools/python/python3-sqlparse_0.5.5.bb @@ -6,6 +6,10 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=2b136f573f5386001ea3b7b9016222fc" SRC_URI[sha256sum] = "e20d4a9b0b8585fdf63b10d30066c7c94c5d7a7ec47c889a2d83a3caa93ff28e" +SRC_URI += "file://CVE-2026-54284-1.patch \ + file://CVE-2026-54284-2.patch \ +" + CVE_PRODUCT = "sqlparse" export BUILD_SYS From patchwork Mon Sep 14 03:12:55 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 98157 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 244E3C88E5C for ; Mon, 14 Sep 2026 03:13:33 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.12169.1789355606840516848 for ; Sun, 13 Sep 2026 20:13:26 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=r9Dxf8Mj; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id d2e1a72fcca58-85469b35611so671920b3a.0 for ; Sun, 13 Sep 2026 20:13:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789355606; x=1789960406; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=s3QyXvjbiZu+T36QqmtNtiKDGyyODoOfgKvufzNPjTk=; b=r9Dxf8Mjmvigl4gtyKpcZLQJrUyD1MFA7wyWg+L6TrsqXFs4nt8gTJbSd3cRh0Yte4 RGdTCRQg5d2phu6mD1QSGUSEZlnqzo10UnfLHmGe+yylrNumitbHw0NxyuoaQBfXwiVs 6nJcgjWD3XJJv+ri93zPJy5ubZM1XeENUQ2tmyFRASleKySJzpkRrUB/PD5KOpWV9eHl jNOGUf72Bx0z+l/JScfBHfTsqVb/XwZ+ceeZ9YKbQL63VNmvkGN68ETNLTugVW4MIb8G 17orsSNlyb/k9UBKskzOuFapBwgeVLu6o7tLLlFcV/Gr2D2mJRCv+9Md8C1b8vkEsxRD h0WA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789355606; x=1789960406; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=s3QyXvjbiZu+T36QqmtNtiKDGyyODoOfgKvufzNPjTk=; b=nlMKttzAZV7L5W/X281kES47KUmi5N2rJwRNhlAIsd1WhhWhJGZtqYqQ38PswIg+pp Bb7mK+opyd7JEQcHZiR7QUsNiPi3/2CI+0ur6k1t65B/vQG9X4aqe/39IyhJ+KtI1yr1 79qlPJNgn6VI/3427UiTyk3UPBYwYAjMjTmNe0ozJ2+TySc3cxzfh9dxkG5h/3+Nheiv YiUAliG6uL8GiEn71rZ3FS7x8kZAsO3UKwL8HCtvD20jMm1Ofs/ZXEONjo4PS6pE37LW j6aG67wRTidsnqRxYGI8qBuLQIBG2wva04v3AknuFg5HUkZSi5FhuMpKPMyNbRBTWbrH rCNA== X-Gm-Message-State: AFuF++mVgk241jVjqhUJKotuUQ5KQrP/6U/gnTs8yFbBkhdxBv5b5dGE 1qO1RV1BR4v1vbk1RuqnNo6r9d51y2vjaFiuBQFXk3d5zb9s5fpAidnul4CED+aK X-Gm-Gg: AYBFou0UHNmxu6/2yPlXWT/LBStAllZbYz3GVbOBr36i8XdomWa+od6B59kFSonIuUo Z1ks+CGoKqFVbnD58e8DGno4FQuFwBneu7QOSvv9p9IJEVK7jqtECcHgKe4TVj2DepflRDlqCUu gbi2aG4Eor7Eo0diFAfXIrUxYY1f5iu292eviwgDISQVvShvu90KC9eNXXAXyykylroSD6G33ON RrwXx9IoqPDxDvvtSRnKsG2wuRL5P7DukQM/RE1wnHRLlqCgrtiUW5ZtyJFaGZiWe+T6rPaaWTq 9rQ1EML7RNff9PX9zhn80THpkNquJudL6wXPEoYWNKZ4aye2ulLL8S70juazpn6NW3Ia9DE0uA1 z5sXFxYX3Un7dCOR/0yD2dgonp7ouHVuTNRnm1oO4PCZ2AUyOwpx5wXE8jMI+SRXz7Isdaodl9G XFsctPQMeIDkhyu2Hq3onBkmhsgCV8LCApO+9cDbdaN0r/XS7pPQ5xqTdRdES8SMrzfVZCMDAHZ HfzEEoGEhJz5BwYzUKB X-Received: by 2002:a05:6a00:94d6:b0:86b:43f6:67c4 with SMTP id d2e1a72fcca58-86f82a5f17bmr1701918b3a.1.1789355606040; Sun, 13 Sep 2026 20:13:26 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([202.170.174.3]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-86b2a2b5c72sm3712425b3a.52.2026.09.13.20.13.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 13 Sep 2026 20:13:25 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-python][wrynose][PATCH 7/10] python3-sqlparse: patch CVE-2026-59893 Date: Mon, 14 Sep 2026 15:12:55 +1200 Message-ID: <20260914031300.3677365-7-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260914031300.3677365-1-ankur.tyagi85@gmail.com> References: <20260914031300.3677365-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 14 Sep 2026 03:13:33 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130015 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-59893 Signed-off-by: Ankur Tyagi --- .../python3-sqlparse/CVE-2026-59893.patch | 293 ++++++++++++++++++ .../python/python3-sqlparse_0.5.5.bb | 1 + 2 files changed, 294 insertions(+) create mode 100644 meta-python/recipes-devtools/python/python3-sqlparse/CVE-2026-59893.patch diff --git a/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2026-59893.patch b/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2026-59893.patch new file mode 100644 index 0000000000..39dd978266 --- /dev/null +++ b/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2026-59893.patch @@ -0,0 +1,293 @@ +From 3cca1f008a24b9817137d020eeed87efa5ed68d3 Mon Sep 17 00:00:00 2001 +From: Andi Albrecht +Date: Wed, 1 Jul 2026 08:38:53 +0200 +Subject: [PATCH] Fix uncontrolled CPU consumption (ReDoS) in the lexer's + handling of dollar-quoted literals and multiline comments. + +(cherry picked from commit d1d80602741f77ec78e5a04ce4719244cf32352e) + +CVE: CVE-2026-59893 +Upstream-Status: Backport [https://github.com/andialbrecht/sqlparse/commit/d1d80602741f77ec78e5a04ce4719244cf32352e] + +Dropped changes to the CHANGELOG file. + +Signed-off-by: Ankur Tyagi +--- + benchmarks/bench_dollar_quote_redos.py | 90 ++++++++++++++++++++++++++ + sqlparse/keywords.py | 60 ++++++++++++++++- + sqlparse/lexer.py | 8 +++ + sqlparse/utils.py | 46 ++++++++++++- + 4 files changed, 200 insertions(+), 4 deletions(-) + create mode 100644 benchmarks/bench_dollar_quote_redos.py + +diff --git a/benchmarks/bench_dollar_quote_redos.py b/benchmarks/bench_dollar_quote_redos.py +new file mode 100644 +index 0000000..234d9c4 +--- /dev/null ++++ b/benchmarks/bench_dollar_quote_redos.py +@@ -0,0 +1,90 @@ ++"""Delimited-literal lexer benchmark (GHSA-prg7-hcfm-mfcr). ++ ++Measures parse time for SQL text containing many unique, unmatched ++opening delimiters for the two lexer constructs that used a lazy dot-all ++regex (`[\\s\\S]*?`) terminated by a backreference or a literal closing ++sequence: ++ ++- Dollar-quoted literals, e.g. `$a0$x $a1$x ... $aN$x` (backreference). ++- Multiline comments, e.g. `/* unique0 ... /* unique1 ...` (literal `*/`). ++ ++When no closing delimiter is present, a lazy dot-all quantifier applied at ++every text position must scan to the end of the remaining input for every ++opener, which is O(n^2) total work as the number of openers grows. ++ ++This benchmark does not assert a pass/fail threshold, since absolute timings ++and scaling ratios depend on the host machine. It exists to make the ++runtime characteristics of these code paths observable and to let it be ++re-run (e.g. after a fix) to confirm that scaling has improved. ++ ++Run with: python benchmarks/bench_dollar_quote_redos.py ++""" ++ ++import signal ++import time ++ ++import sqlparse ++from sqlparse.engine import grouping ++ ++# Disable the grouping-stage DoS guards. They fire only after lexing ++# completes and do not bound regex CPU time, so they would otherwise mask ++# the lexer's true (unbounded) timing behind a SQLParseError at larger n. ++grouping.MAX_GROUPING_DEPTH = None ++grouping.MAX_GROUPING_TOKENS = None ++ ++ ++def _alarm_handler(signum, frame): ++ raise TimeoutError() ++ ++ ++signal.signal(signal.SIGALRM, _alarm_handler) ++ ++ ++def measure(label, sql, fn): ++ signal.alarm(30) ++ t0 = time.perf_counter() ++ status = 'OK' ++ try: ++ fn(sql) ++ except sqlparse.exceptions.SQLParseError: ++ status = 'CAP' ++ except TimeoutError: ++ status = 'TIMEOUT' ++ finally: ++ signal.alarm(0) ++ dt = (time.perf_counter() - t0) * 1000 ++ print(f' {status:8} {dt:8.1f} ms {label} ({len(sql)} B)') ++ return dt ++ ++ ++def make_dollar_quote_payload(n): ++ # N unique, never-closed dollar-quote openers. Each is unique so the ++ # backreference regex cannot short-circuit on an earlier match. ++ return ' '.join(f'$a{i}$x' for i in range(n)) ++ ++ ++def make_comment_payload(n): ++ # N unique, never-closed multiline comment openers. No '*/' appears ++ # anywhere, so the closing literal can never short-circuit the scan. ++ return ' '.join(f'/* unique{i} comment never closed' for i in range(n)) ++ ++ ++def run_scaling(label, make_payload, sizes=(250, 500, 1000, 2000, 4000, 8000)): ++ print(f'{label}:') ++ timings = {} ++ for n in sizes: ++ sql = make_payload(n) ++ timings[n] = measure(f'{label} n={n}', sql, sqlparse.parse) ++ ++ print() ++ print('Scaling ratios (O(n^2) implies ~4x time per 2x input):') ++ for prev, curr in zip(sizes, sizes[1:]): ++ if timings[prev] > 0: ++ ratio = timings[curr] / timings[prev] ++ print(f' n={prev} -> n={curr} (input x{curr / prev:.1f}): ' ++ f'time ratio = {ratio:.2f}x') ++ print() ++ ++ ++run_scaling('Unmatched dollar-quote openers', make_dollar_quote_payload) ++run_scaling('Unclosed multiline comments', make_comment_payload) +diff --git a/sqlparse/keywords.py b/sqlparse/keywords.py +index 874431f..243f389 100644 +--- a/sqlparse/keywords.py ++++ b/sqlparse/keywords.py +@@ -5,7 +5,10 @@ + # This module is part of python-sqlparse and is released under + # the BSD License: https://opensource.org/licenses/BSD-3-Clause + ++import re ++ + from sqlparse import tokens ++from sqlparse.utils import _DelimiterOccurrence, resolve_paired_delimiters + + # object() only supports "is" and is useful as a marker + # use this marker to specify that the given regex in SQL_REGEX +@@ -13,12 +16,64 @@ from sqlparse import tokens + PROCESS_AS_KEYWORD = object() + + ++# Dollar-quoted literals (`$tag$...$tag$`) and multiline comments ++# (`/*...*/`, `/*+...*/`) used to be matched with per-position regexes ++# using a lazy dot-all quantifier (`[\s\S]*?`) terminated by a ++# backreference or a literal delimiter. Applied at every text position by ++# the lexer loop below, that shape is O(n^2) on adversarial input with ++# many unclosed openers, since each failed attempt re-scans to the end of ++# the remaining text (GHSA-prg7-hcfm-mfcr). They are resolved instead in ++# a single linear pass by find_delimited_spans(). ++_DOLLAR_QUOTE_DELIM = re.compile(r'\$(?:[_A-ZÀ-Ü]\w*)?\$', re.IGNORECASE | re.UNICODE) ++_DOLLAR_QUOTE_OPENER_OK = re.compile(r'(? X-Patchwork-Id: 98155 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B5E12C88E64 for ; Mon, 14 Sep 2026 03:13:32 +0000 (UTC) Received: from mail-pf1-f178.google.com (mail-pf1-f178.google.com [209.85.210.178]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.12080.1789355609516069244 for ; Sun, 13 Sep 2026 20:13:29 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=RJ/XPs4T; spf=pass (domain: gmail.com, ip: 209.85.210.178, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f178.google.com with SMTP id d2e1a72fcca58-86a25369f16so2122756b3a.3 for ; Sun, 13 Sep 2026 20:13:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789355609; x=1789960409; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=908ot6WUPZKuCm2e/SVoQqNpkxi2FPrdHUnkl8USOxM=; b=RJ/XPs4Tht861HqDD47x/hFzhQiSDjYuFXge9vvTh81eeO9FRxlca2O+qhdqd9i17+ eHu7YSKFkv1MqJ+VH1KsF2NckBw2zuAqfjxbKHM6dH+ZDZ/DB3U1b+I2SkxcH8LgbdZG r6aPYezbYh7hDJRSuwubeP5AZmt8jyWW1DdIhzqSn1mDTOeL9zCRkGIQSXZ/FVVUa6/J NfGs0JNMv6JQohHz9sGE93wqVqQ46Pueab+cu0WHWS5NuMB3lI9Wifk9eLvHAS5hTLcs QsB2lAs/llaV72yQix8B3MvDKaoAKy02fGRk1GhAOkmjqF7i8VmwSE+MJjjTfbWuzmBt +Miw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789355609; x=1789960409; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=908ot6WUPZKuCm2e/SVoQqNpkxi2FPrdHUnkl8USOxM=; b=ADm3792uJav2N+bXf6iv+uUbbBVPYD35eBIwbL+ZIyKXWwknLONeqgeeBkfKPaCMoq k91I6zTKjlqEm0panzVn+DthNUpppSr63+co9S5SdAPOZ34p+GN9hvfSRHZHXL8kmIDU 9GMXzbSzelYO+B2jhm3ihvvQZii6qZTYobBhitXwk9OngxHMaK249rSnz9rXBeXObi5m 57Q+ATB/waJ7gST6t2jUZskBmAtfsXaniJTxv5RLV+eTto8NVtWzt532qdxseFEH7/xX 4QR1XLzeREnxxi8NoYriRc/ClPw1XkvGe4J4em93Ol//n8oMaFb8I4y1M9qz8lk3sLKG kP+w== X-Gm-Message-State: AFuF++nAjwYdfGppdJ4AU0Kg+0Rb1QAvUXnnuU1fj+VI6NsAa+sou8az T/F6cyoJ1j8VwmdZUdAlGfi3dlJlabCc7RBcIYM7ROTiRgl3O48juPQym9zR4QvJ X-Gm-Gg: AYBFou1aMylven3ar2RXfvgy1/1CkWxFBgj7hl1SpXI1D1RDx+EjHzJVf5EokdulOFk Sij8tWJBmr3VQ5bLAs8YyWAefg4aRN+DblyIPhXa2Xkp+HuzxyV4ZP9+ZKaXOiCgCUcTG9AJx7x bDLf2Kfy8c+kNONunphvyejghoh4DUskBgwNy/TvxWvOCbMY20YcgcHDJh66cgf6OmCTwafqwVf MVIjQT5O/X7Kb7shUQdrs5J1Lv8RUASjOphvXvsECtVBbAEDOnkN/jqTYnH/gSZMueHiJQUVlVc SL6C5HP/kINdmfrdF8o4XQYuHpDFs4pK3yIL4Wjj/7nZ/tqEmRzPfSYY6mXTtV1kf59vutA8+Aq 3dVBTyhDEqTqp4m0xy/quDwaGDbRPcU8g8nPxFnsvbQWl/JiQZFxMUhibUYqmzPswaUEa+7iPYP zcz9Z1GZvXmTvBPDzrvRBAtt0isyEo4KCLFjnLXMAGZgzNSzudByVVEEH/Afu7KMlvkH6QgCva9 n/5IrSDgFaBqYs2lWb6 X-Received: by 2002:a05:6a00:92a0:b0:84f:77cc:63cd with SMTP id d2e1a72fcca58-86f855f5788mr1672971b3a.17.1789355608811; Sun, 13 Sep 2026 20:13:28 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([202.170.174.3]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-86b2a2b5c72sm3712425b3a.52.2026.09.13.20.13.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 13 Sep 2026 20:13:28 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-python][wrynose][PATCH 8/10] python3-sqlparse: patch CVE-2026-59894 Date: Mon, 14 Sep 2026 15:12:56 +1200 Message-ID: <20260914031300.3677365-8-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260914031300.3677365-1-ankur.tyagi85@gmail.com> References: <20260914031300.3677365-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 14 Sep 2026 03:13:32 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130016 From: Ankur Tyagi Backport commit associated with GitHub advisory. Details: https://nvd.nist.gov/vuln/detail/cve-2026-59894 Signed-off-by: Ankur Tyagi --- .../python3-sqlparse/CVE-2026-59894.patch | 79 +++++++++++++++++++ .../python/python3-sqlparse_0.5.5.bb | 1 + 2 files changed, 80 insertions(+) create mode 100644 meta-python/recipes-devtools/python/python3-sqlparse/CVE-2026-59894.patch diff --git a/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2026-59894.patch b/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2026-59894.patch new file mode 100644 index 0000000000..0bd7bbc967 --- /dev/null +++ b/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2026-59894.patch @@ -0,0 +1,79 @@ +From a1ce7931eda6262f0fe94a0b2cb25854f12d6be5 Mon Sep 17 00:00:00 2001 +From: Andi Albrecht +Date: Mon, 29 Jun 2026 08:29:32 +0200 +Subject: [PATCH] Escape backslashes in output formatters. + +(cherry picked from commit 53ff44b53e27cff78259acc1af015506fea60f63) + +CVE: CVE-2026-59894 +Upstream-Status: Backport [https://github.com/andialbrecht/sqlparse/commit/53ff44b53e27cff78259acc1af015506fea60f63] + +Dropped changes to the CHANGELOG file. + +Signed-off-by: Ankur Tyagi +--- + sqlparse/filters/output.py | 16 ++++++++++------ + tests/test_format.py | 16 ++++++++++++++++ + 2 files changed, 26 insertions(+), 6 deletions(-) + +diff --git a/sqlparse/filters/output.py b/sqlparse/filters/output.py +index 253537e..697ebc3 100644 +--- a/sqlparse/filters/output.py ++++ b/sqlparse/filters/output.py +@@ -61,9 +61,11 @@ class OutputPythonFilter(OutputFilter): + yield sql.Token(T.Whitespace, after_lb) + continue + +- # Token has escape chars +- elif "'" in token.value: +- token.value = token.value.replace("'", "\\'") ++ # Escape backslashes before quotes so a backslash preceding a ++ # quote cannot break out of the generated string literal ++ # (GHSA-3496-9g83-7v6x). ++ else: ++ token.value = token.value.replace('\\', '\\\\').replace("'", "\\'") + + # Put the token + yield sql.Token(T.Text, token.value) +@@ -110,9 +112,11 @@ class OutputPHPFilter(OutputFilter): + yield sql.Token(T.Whitespace, after_lb) + continue + +- # Token has escape chars +- elif '"' in token.value: +- token.value = token.value.replace('"', '\\"') ++ # Escape backslashes before quotes so a backslash preceding a ++ # quote cannot break out of the generated string literal ++ # (GHSA-3496-9g83-7v6x). ++ else: ++ token.value = token.value.replace('\\', '\\\\').replace('"', '\\"') + + # Put the token + yield sql.Token(T.Text, token.value) +diff --git a/tests/test_format.py b/tests/test_format.py +index 0cdbcf8..9349506 100644 +--- a/tests/test_format.py ++++ b/tests/test_format.py +@@ -689,6 +689,22 @@ class TestOutputFormat: + '$sql = "select * ";', + '$sql .= "from foo;";']) + ++ def test_python_escapes_backslashes(self): ++ # GHSA-3496-9g83-7v6x: backslashes must be escaped before quotes so ++ # crafted SQL cannot break out of the generated Python string literal. ++ # SQL select '\foo\' -> each \ doubled, each ' escaped. ++ sql = "select '\\foo\\'" ++ f = lambda sql: sqlparse.format(sql, output_format='python') ++ assert f(sql) == "sql = 'select \\'\\\\foo\\\\\\''" ++ ++ def test_php_escapes_backslashes(self): ++ # GHSA-3496-9g83-7v6x: PHP double-quoted output must escape backslashes ++ # before quotes; a backslash before a quote otherwise closes the string. ++ # SQL select '\foo\' -> each \ doubled (single quotes need no escaping). ++ sql = "select '\\foo\\'" ++ f = lambda sql: sqlparse.format(sql, output_format='php') ++ assert f(sql) == '$sql = "select \'\\\\foo\\\\\'";' ++ + def test_sql(self): + # "sql" is an allowed option but has no effect + sql = 'select * from foo;' diff --git a/meta-python/recipes-devtools/python/python3-sqlparse_0.5.5.bb b/meta-python/recipes-devtools/python/python3-sqlparse_0.5.5.bb index a1dc52db49..a23f5ec0e2 100644 --- a/meta-python/recipes-devtools/python/python3-sqlparse_0.5.5.bb +++ b/meta-python/recipes-devtools/python/python3-sqlparse_0.5.5.bb @@ -9,6 +9,7 @@ SRC_URI[sha256sum] = "e20d4a9b0b8585fdf63b10d30066c7c94c5d7a7ec47c889a2d83a3caa9 SRC_URI += "file://CVE-2026-54284-1.patch \ file://CVE-2026-54284-2.patch \ file://CVE-2026-59893.patch \ + file://CVE-2026-59894.patch \ " CVE_PRODUCT = "sqlparse" From patchwork Mon Sep 14 03:12:57 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 98156 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 16220C88E66 for ; Mon, 14 Sep 2026 03:13:33 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.12081.1789355612322366707 for ; Sun, 13 Sep 2026 20:13:32 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=fRN9uYK6; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id d2e1a72fcca58-85469e211a0so1310414b3a.1 for ; Sun, 13 Sep 2026 20:13:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789355612; x=1789960412; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=VgzXQM1CNnUP6+dXHN+dhXBQziPytOi6dtk7PN1DgTM=; b=fRN9uYK67gAkw3mrrmvAfne0BwSBvz89DYOVZfS7o14LnYAHYNmuteQv0zXU0xN+dh IXDzusO6JIews8ShLGEO5Sgpt/cvzriw0CjGDVMGtdCq53SICKPpujhRvxbNCR39TtpE eMf6yj+u3zrFrCkw7vEqSOyH5PUMty6o/icuJ7Nq6Mk21Ut8fyTAiptenu1jNnpKxWKE nWfWB4XWRd0irioXceNhMLPW+Otdf/GuyUcEluy94/PBZjwAFwtH4vjCP7tFcTvrUxoK PugH/nM6S/8Ngw4WZsM7S9rp5b3lCathPYbd+yZ2CEkz1tdQr4gCI3cdDhMig4yoO/g5 TMFA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789355612; x=1789960412; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=VgzXQM1CNnUP6+dXHN+dhXBQziPytOi6dtk7PN1DgTM=; b=r2vBZGqWqeV1Op3ohu4TVTj3ccDicE0zl3gxdBFDKHxT5Gx84EUvsxylentTOBVIFB bsg0G1AGuUJGOuHbbwl3vO1rJvTfBgWPtP7LERWVCiObu0wUQTn8uPTCgSMKSQDiCU1c h4LpRYTucIcMIucwrHNPP1FdrG5InVX4UWZPR5OOQYlP0843RCOFWOAWKpJ1pTTiqxPQ N641kXXAYV4Nyf7FcoE456JnUHIiLpt395v/EyTc8SGTjA0msj3UglzLgWPuBTA93P0W MB29NMCt8IW02wq1PKMCyD8N7TvSrRIS0c0Cn/kn4BUlf5c3vccJofe2fvKKR1fIpMli aqLw== X-Gm-Message-State: AFuF++loIxMsgcndmwelpJvY8UZvsN+BkRGC4tNcx+xKMEpies2CQ6sQ O2rPz8wCaexxsCOfyMJoSdqYcnPM2vSVkASMJ/mpjlzAxSsHZdPko+YFzmhl4azN X-Gm-Gg: AYBFou3B24huuJKWQRF2BpwjFdAcoAqnZjmuY3nqljl6C5OryYAKV3UjBTuolqQY04k pvItQZ0yY44CemMmi0Y50w7lkkeyKgLPTghzAXXMwL1l00RjuaAPDp4pCaHh6aRP3+v3y4ZT1zt R+oiRLctM84EeYeevPVFSMjVdlXHSE5tUIP5XaKyxeoUAUOHzO8ceJeOBkQ16g0kiEIjWHOfVVP mkesnQtustmnRCGzNtdPNobV3jtKDvdYenk6SZvloxBT2cnEJRMywoAnR4tiT8D3ZT9SBV/Iaaz ImRUJVlt40X36+pMjNYHmUCDI4v/AwO20pG3UYeMgPj56+HZBG2z/HQs/RZJxDRhpOIhd2jtpDk i72bMnK2x61t1HRkPXV0Uvpjxpr4iF+CCdF2qneHkwGsK+kfjShMTxXExBep64W5riRf8YYKzq/ tiJ1gQHg2y7rVGZxbZbk4yHJUdvFrYbZRFgcIOsnNtTur8mTrmJj6amkRT0YayEmZYflR5FzJcT KCKLwcgymO3lBo1TSZcGzxGtvgwnoI= X-Received: by 2002:a05:6a00:992:b0:866:abd8:f112 with SMTP id d2e1a72fcca58-86f83a3f608mr1823585b3a.8.1789355611590; Sun, 13 Sep 2026 20:13:31 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([202.170.174.3]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-86b2a2b5c72sm3712425b3a.52.2026.09.13.20.13.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 13 Sep 2026 20:13:31 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-python][wrynose][PATCH 9/10] python3-sqlparse: patch CVE-2026-71491 Date: Mon, 14 Sep 2026 15:12:57 +1200 Message-ID: <20260914031300.3677365-9-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260914031300.3677365-1-ankur.tyagi85@gmail.com> References: <20260914031300.3677365-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 14 Sep 2026 03:13:33 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130017 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-71491 Signed-off-by: Ankur Tyagi --- .../python3-sqlparse/CVE-2026-71491.patch | 147 ++++++++++++++++++ .../python/python3-sqlparse_0.5.5.bb | 1 + 2 files changed, 148 insertions(+) create mode 100644 meta-python/recipes-devtools/python/python3-sqlparse/CVE-2026-71491.patch diff --git a/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2026-71491.patch b/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2026-71491.patch new file mode 100644 index 0000000000..e0136cc4aa --- /dev/null +++ b/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2026-71491.patch @@ -0,0 +1,147 @@ +From ca01c323483883f205ee7bb44581c674fcfe6e49 Mon Sep 17 00:00:00 2001 +From: Andi Albrecht +Date: Mon, 10 Aug 2026 07:35:42 +0200 +Subject: [PATCH] Fix quadratic DoS in group_comments (GHSA-f2ff-p2ww-7p4p) + +A comment-only statement ('-- c\n' repeated) made group_comments rescan +the whole remaining token tail once per comment token, costing O(n^2). +Because group_comments runs before the MAX_GROUPING_TOKENS guard, the +cost was paid even on oversized input. + +Stop as soon as token_not_matching finds no terminator in the remaining +tokens: from that point on nothing can group, so re-scanning the tail is +wasted work. This makes the pass O(n) while preserving grouping output. + +Add benchmarks/validate_group_comments_dos.py to check the scaling. + +Reported by sanktjodel. + +Co-Authored-By: Claude Opus 4.8 + +(cherry picked from commit ef2012a5eeb491e604dea2b00d516904a3830c87) + +CVE: CVE-2026-71491 +Upstream-Status: Backport [https://github.com/andialbrecht/sqlparse/commit/ef2012a5eeb491e604dea2b00d516904a3830c87] + +Dropped changes to the CHANGELOG file. + +Signed-off-by: Ankur Tyagi +--- + benchmarks/validate_group_comments_dos.py | 85 +++++++++++++++++++++++ + sqlparse/engine/grouping.py | 11 ++- + 2 files changed, 93 insertions(+), 3 deletions(-) + create mode 100644 benchmarks/validate_group_comments_dos.py + +diff --git a/benchmarks/validate_group_comments_dos.py b/benchmarks/validate_group_comments_dos.py +new file mode 100644 +index 0000000..58b3e01 +--- /dev/null ++++ b/benchmarks/validate_group_comments_dos.py +@@ -0,0 +1,85 @@ ++"""Validate that ``group_comments`` scales linearly on comment-only input. ++ ++Regression check for the quadratic O(n^2) DoS in ``group_comments`` ++(sqlparse/engine/grouping.py), reported as GHSA-f2ff-p2ww-7p4p. ++ ++A statement made only of single-line comments (``'-- c\\n'`` repeated n times) ++lexes in O(n) but ``group_comments`` rescans the O(n) remaining tokens for every ++comment token, giving O(n^2) total work. ``group_comments`` runs first in ++``group()``, before the ``MAX_GROUPING_TOKENS`` guard, so the token cap does not ++protect this vector. The path is reachable via ``sqlparse.parse()`` and ++``sqlparse.format(sql, strip_comments=True)``. ++ ++This script measures the scaling of the vulnerable path and reports whether the ++observed growth is quadratic (vulnerable) or roughly linear (patched). ++ ++Run with: python benchmarks/validate_group_comments_dos.py ++ ++Exit code 0 => behaviour looks linear (advisory mitigated). ++Exit code 1 => behaviour looks quadratic (advisory reproduced). ++""" ++ ++import sys ++import time ++ ++import sqlparse ++ ++ ++def payload(n): ++ """A comment-only statement of n single-line comments.""" ++ return '-- c\n' * n ++ ++ ++def measure(fn, sql): ++ t0 = time.perf_counter() ++ fn(sql) ++ return (time.perf_counter() - t0) * 1000 ++ ++ ++def run(label, fn): ++ print(f'{label}:') ++ sizes = (1000, 2000, 4000, 8000) ++ timings = [] ++ for n in sizes: ++ dt = measure(fn, payload(n)) ++ timings.append(dt) ++ print(f' n={n:5d} {dt:8.1f} ms ({len(payload(n))} B)') ++ ++ # For each doubling of the input, quadratic growth ~4x, linear ~2x. ++ ratios = [b / a for a, b in zip(timings, timings[1:]) if a > 0] ++ print(f' doubling ratios: {", ".join(f"{r:.2f}x" for r in ratios)}') ++ return ratios ++ ++ ++def classify(ratios): ++ """Quadratic if the average per-doubling ratio is closer to 4x than 2x.""" ++ if not ratios: ++ return 'inconclusive', 0.0 ++ avg = sum(ratios) / len(ratios) ++ # Midpoint between linear (2x) and quadratic (4x) is 3x. ++ return ('quadratic' if avg >= 3.0 else 'linear'), avg ++ ++ ++def main(): ++ print('GHSA-f2ff-p2ww-7p4p: quadratic DoS in group_comments\n') ++ ++ all_ratios = [] ++ all_ratios += run('sqlparse.parse', sqlparse.parse) ++ print() ++ all_ratios += run( ++ 'sqlparse.format(strip_comments=True)', ++ lambda s: sqlparse.format(s, strip_comments=True), ++ ) ++ print() ++ ++ verdict, avg = classify(all_ratios) ++ print(f'Average doubling ratio: {avg:.2f}x => {verdict}') ++ if verdict == 'quadratic': ++ print('VULNERABLE: growth is quadratic, advisory reproduced.') ++ return 1 ++ print('OK: growth is roughly linear, advisory mitigated.') ++ return 0 ++ ++ ++if __name__ == '__main__': ++ sys.exit(main()) +diff --git a/sqlparse/engine/grouping.py b/sqlparse/engine/grouping.py +index 43ca5b5..7a3ca1a 100644 +--- a/sqlparse/engine/grouping.py ++++ b/sqlparse/engine/grouping.py +@@ -339,9 +339,14 @@ def group_comments(tlist): + while token: + eidx, end = tlist.token_not_matching( + lambda tk: imt(tk, t=T.Comment) or tk.is_newline, idx=tidx) +- if end is not None: +- eidx, end = tlist.token_prev(eidx, skip_ws=False) +- tlist.group_tokens(sql.Comment, tidx, eidx) ++ if end is None: ++ # From tidx onward everything is comment/newline: there is no ++ # terminator to group against, and every later start would hit ++ # the same dead end. Stop instead of re-scanning the tail once ++ # per remaining comment token (which is O(n**2)). ++ break ++ eidx, end = tlist.token_prev(eidx, skip_ws=False) ++ tlist.group_tokens(sql.Comment, tidx, eidx) + + tidx, token = tlist.token_next_by(t=T.Comment, idx=tidx) + diff --git a/meta-python/recipes-devtools/python/python3-sqlparse_0.5.5.bb b/meta-python/recipes-devtools/python/python3-sqlparse_0.5.5.bb index a23f5ec0e2..61fe759ede 100644 --- a/meta-python/recipes-devtools/python/python3-sqlparse_0.5.5.bb +++ b/meta-python/recipes-devtools/python/python3-sqlparse_0.5.5.bb @@ -10,6 +10,7 @@ SRC_URI += "file://CVE-2026-54284-1.patch \ file://CVE-2026-54284-2.patch \ file://CVE-2026-59893.patch \ file://CVE-2026-59894.patch \ + file://CVE-2026-71491.patch \ " CVE_PRODUCT = "sqlparse" From patchwork Mon Sep 14 03:12:58 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 98159 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 28C7DC88E64 for ; Mon, 14 Sep 2026 03:13:43 +0000 (UTC) Received: from mail-pf1-f178.google.com (mail-pf1-f178.google.com [209.85.210.178]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.12170.1789355615157694728 for ; Sun, 13 Sep 2026 20:13:35 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=oXHRee/X; spf=pass (domain: gmail.com, ip: 209.85.210.178, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f178.google.com with SMTP id d2e1a72fcca58-86a25369f16so2122802b3a.3 for ; Sun, 13 Sep 2026 20:13:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789355614; x=1789960414; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=IjOgd4JjdNA+wJKOj+zqr58GYYKgezXpM8JnY0qwQYM=; b=oXHRee/Xgb9+vCPcuRzIUxDEVk4CI05kuDgsmzdbIdE/3z+v1wDgB57OAkLOPT19w5 RU75SuhsLM1KhyIEcGBqigA3yuO2/+a/L6JqJmo0qf7RXpGaCIZxy9KPjVTVR4DGn6G9 qVA3AuLOOCVwgz7eD7LkvW0im0KgM47pBR/L7YzI9/HSVtLTMpAVniL28eFKngdvQlDe rOaNH0hcX7hXJFBfa1aQIzYKJrUr7JcAg1na4diCAvi0bAwktFCAOsm3w+R6axKi1i0f LEPJZh1rjIoiX4ONzyp8NfQmJPP7u4hKyeyOfFQ3htIv1/tpWEAEngLGdn0X4USqKTnl uhLA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789355614; x=1789960414; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=IjOgd4JjdNA+wJKOj+zqr58GYYKgezXpM8JnY0qwQYM=; b=fv0NxbeIOO6j3sUT5NwmHJ9wh76Cztm5U9Cw93XxbJsAj3EhHQ9qfa0zFG5IUBoI4V HjDjGnHRAUdi9WkYxwKr/gvidArotG5rYxb9jeUEXdGcztOUvccxc9CwdDqX4OAx7c2x DZJEdlupPY10K8wWe7nA1Qk3suF7kOsKmM/Ef0vK3jhYWIzG4998XFXuITCBdJDVa9Sk ytOAeU/oVLyTbw9IyIgF3K/iN7qKAUUc3FMY52aeMoMWK7FvCrPmmyrVLBRHgpDd8K21 dHxeXT8K1nWEG32BGKubYvHB7eK91a6awE73PrpsrdHbvowG1gXmjme5C6BehBpGcQBn Ibxg== X-Gm-Message-State: AFuF++lLR6iXnioGFFIltRQzousnY767ZSUs3qmDbGzOmHwNAa1N/KnJ Dx9kcYjP+tuLeG7iauhQGozQbiWux1ZFnJrCeHmT4+c71UWfZkJK1KwlOWkYHT5+ X-Gm-Gg: AYBFou1GwPVk6q7/r480qKpmu9K68atrkFAey10xt+QonJFzJ6jabdemrB9AwuyQrab 7vqO/T7hQd19JlA+CxGOc1VANLcJU8lvnKcBK7y1lGEJ1RnB27UFOZn4jx3MsL4IVb4Nlldkv9H lkLwIT01+4MDTEAjPj5tO0swlZIFRPLVLVNwpRkrH/i0OMBQditQYvsyxLjFd/UYvp9hgdGwObA sd+ZUyzvIVRRok84bFE4lPB4IsOHLx9XUN0TAR7Ue2+UcZkqxuY1QQ90U5mwO7eOTkvP7t609aI ehp6o4W1QaCvx4fxtJKhyD/6qP+NxEhfeuTmKXNj1xNB9IddSY+9LCOaiC8jLMm286ekOt5gzFe rq0vSfgXEzITU4FeZvxUcluTp4IfB8dOKrdGx1LP+3oA7azpxZFMSiCirNIyUH0tzzZ9u+DvA0/ wL1ky/8P3FfoR/cD8IXt167k3dKVnyeaRu+R6n6Z5QYtZrKyfPIVZm+OLJReSZRaC3UoT6AXw4X gTgowoiHlxaLieB8JOL X-Received: by 2002:a05:6a00:3a0d:b0:860:507d:503e with SMTP id d2e1a72fcca58-86f857f079cmr1670193b3a.20.1789355614386; Sun, 13 Sep 2026 20:13:34 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([202.170.174.3]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-86b2a2b5c72sm3712425b3a.52.2026.09.13.20.13.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 13 Sep 2026 20:13:34 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-python][wrynose][PATCH 10/10] python3-tornado: mark CVEs fixed Date: Mon, 14 Sep 2026 15:12:58 +1200 Message-ID: <20260914031300.3677365-10-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260914031300.3677365-1-ankur.tyagi85@gmail.com> References: <20260914031300.3677365-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 14 Sep 2026 03:13:43 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130018 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-49853 https://nvd.nist.gov/vuln/detail/cve-2026-49854 https://nvd.nist.gov/vuln/detail/cve-2026-49855 Signed-off-by: Ankur Tyagi --- meta-python/recipes-devtools/python/python3-tornado_6.5.7.bb | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/meta-python/recipes-devtools/python/python3-tornado_6.5.7.bb b/meta-python/recipes-devtools/python/python3-tornado_6.5.7.bb index 4dda1541b8..114822fb6c 100644 --- a/meta-python/recipes-devtools/python/python3-tornado_6.5.7.bb +++ b/meta-python/recipes-devtools/python/python3-tornado_6.5.7.bb @@ -41,3 +41,7 @@ FILES:${PN}-test = " \ CVE_PRODUCT = "tornadoweb:tornado" BBCLASSEXTEND += "native nativesdk" + +CVE_STATUS[CVE-2026-49853] = "fixed-version: fixed since v6.5.6" +CVE_STATUS[CVE-2026-49854] = "fixed-version: fixed since v6.5.6" +CVE_STATUS[CVE-2026-49855] = "fixed-version: fixed since v6.5.6"