Skip to content

Commit 9091021

Browse files
prashant1221tapakund
authored andcommitted
python3-requests: Fix functionality break introduced by CVE-2024-35195
CVE-2024-35195 fix in python3-requests breaks docker-py This patch addresses the issue Upstream discussion: requests: psf/requests#6710 docker: docker/docker-py#3256 Fix in python3-pip as it uses vulnerable requests Change-Id: I4a39f6f178b6212c08f08030a22112093763f6fb Reviewed-on: http://photon-gerrit.lvn.broadcom.net/c/photon/+/25188 Reviewed-by: Shreenidhi Shedi <[email protected]> Reviewed-by: Tapas Kundu <[email protected]> Tested-by: gerrit-photon <[email protected]>
1 parent 9eeda20 commit 9091021

File tree

11 files changed

+792
-15
lines changed

11 files changed

+792
-15
lines changed

SPECS/asciidoc3/asciidoc3.spec

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
Summary: AsciiDoc is a human readable text document format
44
Name: asciidoc3
55
Version: 3.2.0
6-
Release: 3%{?dist}
6+
Release: 4%{?dist}
77
License: GPLv2+
88
URL: https://gitlab.com/asciidoc3/asciidoc3
99
Group: System Environment/Development
@@ -50,6 +50,8 @@ mv %{buildroot}/asciidoc3 %{buildroot}%{python3_sitelib}
5050
%{_bindir}/*
5151

5252
%changelog
53+
* Thu Feb 06 2025 Prashant S Chauhan <[email protected]> 3.2.0-4
54+
- Bump up release as part of python3-pip upgrade
5355
* Tue Jan 09 2024 Prashant S Chauhan <[email protected]> 3.2.0-3
5456
- Add python3-pip as runtime Requires
5557
* Mon Nov 15 2021 Prashant S Chauhan <[email protected]> 3.2.0-2

SPECS/docker-py/docker-py.spec

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
Name: docker-py3
22
Version: 6.0.0
3-
Release: 1%{?dist}
3+
Release: 2%{?dist}
44
Summary: Python API for docker
55
License: ASL2.0
66
Group: Development/Languages/Python
@@ -11,6 +11,8 @@ URL: https://github.com/docker/docker-py
1111
Source0: https://github.com/docker/docker-py/releases/download/%{version}/docker-%{version}.tar.gz
1212
%define sha512 docker=09edf7b058d38d34d0fe0432b336d6fc494648c0e41cf4ae7f7bbf3db158143ca8fbea87e51d3b354c5f40bd7f1481e003e4b55f879ef562e91f19b62143c271
1313

14+
Patch0: fix-for-requests.patch
15+
1416
BuildRequires: python3-devel
1517
BuildRequires: python3-ipaddress
1618
BuildRequires: python3-pip
@@ -30,7 +32,7 @@ Requires: python3
3032
Requires: docker-pycreds3
3133
Requires: python3-backports.ssl_match_hostname
3234
Requires: python3-ipaddress
33-
Requires: python3-requests
35+
Requires: python3-requests >= 2.26.0-5
3436
Requires: python3-six
3537
Requires: python3-websocket-client
3638

@@ -61,6 +63,8 @@ rm -rf %{buildroot}/*
6163
%{python3_sitelib}/*
6264

6365
%changelog
66+
* Wed Jan 15 2025 Prashant S Chauhan <[email protected]> 6.0.0-2
67+
- Fix functionality break introduced by CVE-2024-35195 in python3-requests
6468
* Mon Oct 24 2022 Shreenidhi Shedi <[email protected]> 6.0.0-1
6569
- Upgrade to v6.0.0
6670
* Thu Dec 09 2021 Prashant S Chauhan <[email protected]> 4.3.1-2
Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
From e33e0a437ecd895158c8cb4322a0cdad79312636 Mon Sep 17 00:00:00 2001
2+
From: Felix Fontein <[email protected]>
3+
Date: Mon, 20 May 2024 21:13:41 +0200
4+
Subject: Hotfix for requests 2.32.2+.
5+
6+
diff --git a/docker/transport/basehttpadapter.py b/docker/transport/basehttpadapter.py
7+
index dfbb193..2301b6b 100644
8+
--- a/docker/transport/basehttpadapter.py
9+
+++ b/docker/transport/basehttpadapter.py
10+
@@ -6,3 +6,8 @@ class BaseHTTPAdapter(requests.adapters.HTTPAdapter):
11+
super().close()
12+
if hasattr(self, 'pools'):
13+
self.pools.clear()
14+
+
15+
+ # Fix for requests 2.32.2+:
16+
+ # https://github.com/psf/requests/commit/c98e4d133ef29c46a9b68cd783087218a8075e05
17+
+ def get_connection_with_tls_context(self, request, verify, proxies=None, cert=None):
18+
+ return self.get_connection(request.url, proxies)

SPECS/python-pyudev/python-pyudev.spec

Lines changed: 9 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,12 @@
11
Summary: Python binding for libudev
22
Name: python3-pyudev
33
Version: 0.22.0
4-
Release: 2%{?dist}
4+
Release: 3%{?dist}
55
License: GNU Library or Lesser General Public License (LGPL) (LGPL 2.1+)
66
Group: Development/Languages/Python
77
URL: https://pypi.org/project/pyudev
88
Source0: pyudev-%{version}.tar.gz
9-
%define sha1 pyudev=1826db6e768153548df20bfd0a3149f5db9f80e7
9+
%define sha512 pyudev=a09ed479a54a1772a6af68cb975fef792068c2de3655e20223905bc3f574fd32bd3dbe6b97062eee3ab5f08a8b041ad3ea86dfb68c839ea44e29d65ec1686670
1010
Vendor: VMware, Inc.
1111
Distribution: Photon
1212
BuildArch: noarch
@@ -17,9 +17,8 @@ BuildRequires: python3-xml
1717
BuildRequires: systemd-devel
1818
Requires: systemd
1919
Requires: python3
20-
Requires: python3-pip
2120
Requires: python3-six
22-
%if %{with_check}
21+
%if 0%{?with_check}
2322
BuildRequires: python3-pip
2423
BuildRequires: curl-devel
2524
BuildRequires: python3-six
@@ -58,7 +57,9 @@ python3 setup.py test
5857
%{python3_sitelib}/*
5958

6059
%changelog
61-
* Thu Dec 09 2021 Prashant S Chauhan <[email protected]> 0.22.0-2
62-
- Bump up to compile with python 3.10
63-
* Thu Mar 19 2020 Tapas Kundu <[email protected]> 0.22.0-1
64-
- Initial release.
60+
* Tue Feb 04 2025 Prashant S Chauhan <[email protected]> 0.22.0-3
61+
- Remove pip from Requires
62+
* Thu Dec 09 2021 Prashant S Chauhan <[email protected]> 0.22.0-2
63+
- Bump up to compile with python 3.10
64+
* Thu Mar 19 2020 Tapas Kundu <[email protected]> 0.22.0-1
65+
- Initial release.
Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
From 8b02ed531d8def03b4cf767e8a925be09db43dff Mon Sep 17 00:00:00 2001
2+
From: Simon Deziel <[email protected]>
3+
Date: Wed, 22 May 2024 12:02:20 -0400
4+
Subject: [PATCH] adapters: fix for requests 2.32.2+
5+
6+
Signed-off-by: Simon Deziel <[email protected]>
7+
---
8+
requests_unixsocket/adapters.py | 4 ++++
9+
1 file changed, 4 insertions(+)
10+
11+
diff --git a/requests_unixsocket/adapters.py b/requests_unixsocket/adapters.py
12+
index 83e1400..c3c73cc 100644
13+
--- a/requests_unixsocket/adapters.py
14+
+++ b/requests_unixsocket/adapters.py
15+
@@ -63,6 +63,10 @@ def __init__(self, timeout=60, pool_connections=25, *args, **kwargs):
16+
pool_connections, dispose_func=lambda p: p.close()
17+
)
18+
19+
+ # Fix for requests 2.32.2+: https://github.com/psf/requests/pull/6710
20+
+ def get_connection_with_tls_context(self, request, verify, proxies=None, cert=None):
21+
+ return self.get_connection(request.url, proxies)
22+
+
23+
def get_connection(self, url, proxies=None):
24+
proxies = proxies or {}
25+
proxy = proxies.get(urlparse(url.lower()).scheme)

SPECS/python-requests-unixsocket/python-requests-unixsocket.spec

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22

33
Name: python3-requests-unixsocket
44
Version: 0.3.0
5-
Release: 1%{?dist}
5+
Release: 2%{?dist}
66
Summary: Use requests to talk HTTP via a UNIX domain socket
77
License: Apache-2
88
Url: https://pypi.org/project/requests-unixsocket
@@ -13,6 +13,8 @@ Distribution: Photon
1313
Source0: https://files.pythonhosted.org/packages/c3/ea/0fb87f844d8a35ff0dcc8b941e1a9ffc9eb46588ac9e4267b9d9804354eb/%{srcname}-%{version}.tar.gz
1414
%define sha512 %{srcname}=21c887b0c3fa526a2debb3960e0ea4dc3b3015cdd517459b6484501176321408d1b4c87dd2840c7d8b71d08fa9114f655ae03f8bc9ff1fca33c914900ef82f5b
1515

16+
Patch0: fix-for-requests.patch
17+
1618
BuildRequires: python3-devel
1719
BuildRequires: python3-setuptools
1820
BuildRequires: python3-requests
@@ -23,6 +25,7 @@ BuildRequires: python3-pytest
2325
%endif
2426

2527
Requires: python3
28+
Requires: python3-requests >= 2.26.0-5
2629

2730
BuildArch: noarch
2831

@@ -53,5 +56,7 @@ rm -rf %{buildroot}/*
5356
%{python3_sitelib}/*
5457

5558
%changelog
59+
* Tue Jan 28 2025 Prashant S Chauhan <[email protected]> 0.3.0-2
60+
- Fix functionality break introduced by CVE-2024-35195 in python3-requests
5661
* Thu Aug 11 2022 Tapas Kundu <[email protected]> 0.3.0-1
5762
- Initial addition

0 commit comments

Comments
 (0)