python rebuild python3 ver.bum
This commit is contained in:
+166
@@ -0,0 +1,166 @@
|
||||
From d2b1b144b75974db6c16087398bccdd5117908e3 Mon Sep 17 00:00:00 2001
|
||||
From: "Miss Islington (bot)"
|
||||
<31488909+miss-islington@users.noreply.github.com>
|
||||
Date: Sun, 2 May 2021 06:49:03 -0700
|
||||
Subject: [PATCH 14/17] bpo-36384: Leading zeros in IPv4 addresses are no
|
||||
longer tolerated (GH-25099) (GH-25815)
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Reverts commit e653d4d8e820a7a004ad399530af0135b45db27a and makes
|
||||
parsing even more strict. Like socket.inet_pton() any leading zero
|
||||
is now treated as invalid input.
|
||||
|
||||
Signed-off-by: Christian Heimes <christian@python.org>
|
||||
|
||||
Co-authored-by: Łukasz Langa <lukasz@langa.pl>
|
||||
(cherry picked from commit 60ce8f0be6354ad565393ab449d8de5d713f35bc)
|
||||
---
|
||||
Doc/library/ipaddress.rst | 19 +++++++++++++++--
|
||||
Doc/tools/susp-ignored.csv | 8 +++++--
|
||||
Doc/whatsnew/3.8.rst | 8 +++++++
|
||||
Lib/ipaddress.py | 5 +++++
|
||||
Lib/test/test_ipaddress.py | 21 +++++++++++++++----
|
||||
.../2021-03-30-16-29-51.bpo-36384.sCAmLs.rst | 6 ++++++
|
||||
6 files changed, 59 insertions(+), 8 deletions(-)
|
||||
create mode 100644 Misc/NEWS.d/next/Security/2021-03-30-16-29-51.bpo-36384.sCAmLs.rst
|
||||
|
||||
diff --git a/Doc/library/ipaddress.rst b/Doc/library/ipaddress.rst
|
||||
index 2cdfddb02e..a6833dae57 100644
|
||||
--- a/Doc/library/ipaddress.rst
|
||||
+++ b/Doc/library/ipaddress.rst
|
||||
@@ -104,8 +104,7 @@ write code that handles both IP versions correctly. Address objects are
|
||||
1. A string in decimal-dot notation, consisting of four decimal integers in
|
||||
the inclusive range 0--255, separated by dots (e.g. ``192.168.0.1``). Each
|
||||
integer represents an octet (byte) in the address. Leading zeroes are
|
||||
- tolerated only for values less than 8 (as there is no ambiguity
|
||||
- between the decimal and octal interpretations of such strings).
|
||||
+ not tolerated to prevent confusion with octal notation.
|
||||
2. An integer that fits into 32 bits.
|
||||
3. An integer packed into a :class:`bytes` object of length 4 (most
|
||||
significant octet first).
|
||||
@@ -117,6 +116,22 @@ write code that handles both IP versions correctly. Address objects are
|
||||
>>> ipaddress.IPv4Address(b'\xC0\xA8\x00\x01')
|
||||
IPv4Address('192.168.0.1')
|
||||
|
||||
+ .. versionchanged:: 3.8
|
||||
+
|
||||
+ Leading zeros are tolerated, even in ambiguous cases that look like
|
||||
+ octal notation.
|
||||
+
|
||||
+ .. versionchanged:: 3.10
|
||||
+
|
||||
+ Leading zeros are no longer tolerated and are treated as an error.
|
||||
+ IPv4 address strings are now parsed as strict as glibc
|
||||
+ :func:`~socket.inet_pton`.
|
||||
+
|
||||
+ .. versionchanged:: 3.9.5
|
||||
+
|
||||
+ The above change was also included in Python 3.9 starting with
|
||||
+ version 3.9.5.
|
||||
+
|
||||
.. attribute:: version
|
||||
|
||||
The appropriate version number: ``4`` for IPv4, ``6`` for IPv6.
|
||||
diff --git a/Doc/tools/susp-ignored.csv b/Doc/tools/susp-ignored.csv
|
||||
index dd6aa38d72..1d7ebefe25 100644
|
||||
--- a/Doc/tools/susp-ignored.csv
|
||||
+++ b/Doc/tools/susp-ignored.csv
|
||||
@@ -142,8 +142,12 @@ library/ipaddress,,:db8,IPv6Address('2001:db8::')
|
||||
library/ipaddress,,::,IPv6Address('2001:db8::')
|
||||
library/ipaddress,,:db8,>>> ipaddress.IPv6Address('2001:db8::1000')
|
||||
library/ipaddress,,::,>>> ipaddress.IPv6Address('2001:db8::1000')
|
||||
-library/ipaddress,,:db8,IPv6Address('2001:db8::1000')
|
||||
-library/ipaddress,,::,IPv6Address('2001:db8::1000')
|
||||
+library/ipaddress,,:db8,'2001:db8::1000'
|
||||
+library/ipaddress,,::,'2001:db8::1000'
|
||||
+library/ipaddress,,:db8,">>> f'{ipaddress.IPv6Address(""2001:db8::1000""):s}'"
|
||||
+library/ipaddress,,::,">>> f'{ipaddress.IPv6Address(""2001:db8::1000""):s}'"
|
||||
+library/ipaddress,,::,IPv6Address('ff02::5678%1')
|
||||
+library/ipaddress,,::,fe80::1234
|
||||
library/ipaddress,,:db8,">>> ipaddress.ip_address(""2001:db8::1"").reverse_pointer"
|
||||
library/ipaddress,,::,">>> ipaddress.ip_address(""2001:db8::1"").reverse_pointer"
|
||||
library/ipaddress,,::,"""::abc:7:def"""
|
||||
diff --git a/Doc/whatsnew/3.8.rst b/Doc/whatsnew/3.8.rst
|
||||
index 109a06e92e..95ab18d15b 100644
|
||||
--- a/Doc/whatsnew/3.8.rst
|
||||
+++ b/Doc/whatsnew/3.8.rst
|
||||
@@ -950,6 +950,14 @@ notebook.
|
||||
reviewed by Vinay Sajip in :issue:`33897`.)
|
||||
|
||||
|
||||
+ipaddress
|
||||
+---------
|
||||
+
|
||||
+Starting with Python 3.8.9_p1 (Gentoo) the :mod:`ipaddress` module no longer
|
||||
+accepts any leading zeros in IPv4 address strings.
|
||||
+(Contributed by Christian Heimes in :issue:`36384`).
|
||||
+
|
||||
+
|
||||
math
|
||||
----
|
||||
|
||||
diff --git a/Lib/ipaddress.py b/Lib/ipaddress.py
|
||||
index 28b7b6159a..d351f07a5b 100644
|
||||
--- a/Lib/ipaddress.py
|
||||
+++ b/Lib/ipaddress.py
|
||||
@@ -1173,6 +1173,11 @@ class _BaseV4:
|
||||
if len(octet_str) > 3:
|
||||
msg = "At most 3 characters permitted in %r"
|
||||
raise ValueError(msg % octet_str)
|
||||
+ # Handle leading zeros as strict as glibc's inet_pton()
|
||||
+ # See security bug bpo-36384
|
||||
+ if octet_str != '0' and octet_str[0] == '0':
|
||||
+ msg = "Leading zeros are not permitted in %r"
|
||||
+ raise ValueError(msg % octet_str)
|
||||
# Convert to integer (we know digits are legal)
|
||||
octet_int = int(octet_str, 10)
|
||||
if octet_int > 255:
|
||||
diff --git a/Lib/test/test_ipaddress.py b/Lib/test/test_ipaddress.py
|
||||
index 2f1c5b6b6f..1297b8371d 100644
|
||||
--- a/Lib/test/test_ipaddress.py
|
||||
+++ b/Lib/test/test_ipaddress.py
|
||||
@@ -97,10 +97,23 @@ class CommonTestMixin:
|
||||
class CommonTestMixin_v4(CommonTestMixin):
|
||||
|
||||
def test_leading_zeros(self):
|
||||
- self.assertInstancesEqual("000.000.000.000", "0.0.0.0")
|
||||
- self.assertInstancesEqual("192.168.000.001", "192.168.0.1")
|
||||
- self.assertInstancesEqual("016.016.016.016", "16.16.16.16")
|
||||
- self.assertInstancesEqual("001.000.008.016", "1.0.8.16")
|
||||
+ # bpo-36384: no leading zeros to avoid ambiguity with octal notation
|
||||
+ msg = "Leading zeros are not permitted in '\d+'"
|
||||
+ addresses = [
|
||||
+ "000.000.000.000",
|
||||
+ "192.168.000.001",
|
||||
+ "016.016.016.016",
|
||||
+ "192.168.000.001",
|
||||
+ "001.000.008.016",
|
||||
+ "01.2.3.40",
|
||||
+ "1.02.3.40",
|
||||
+ "1.2.03.40",
|
||||
+ "1.2.3.040",
|
||||
+ ]
|
||||
+ for address in addresses:
|
||||
+ with self.subTest(address=address):
|
||||
+ with self.assertAddressError(msg):
|
||||
+ self.factory(address)
|
||||
|
||||
def test_int(self):
|
||||
self.assertInstancesEqual(0, "0.0.0.0")
|
||||
diff --git a/Misc/NEWS.d/next/Security/2021-03-30-16-29-51.bpo-36384.sCAmLs.rst b/Misc/NEWS.d/next/Security/2021-03-30-16-29-51.bpo-36384.sCAmLs.rst
|
||||
new file mode 100644
|
||||
index 0000000000..f956cde948
|
||||
--- /dev/null
|
||||
+++ b/Misc/NEWS.d/next/Security/2021-03-30-16-29-51.bpo-36384.sCAmLs.rst
|
||||
@@ -0,0 +1,6 @@
|
||||
+:mod:`ipaddress` module no longer accepts any leading zeros in IPv4 address
|
||||
+strings. Leading zeros are ambiguous and interpreted as octal notation by
|
||||
+some libraries. For example the legacy function :func:`socket.inet_aton`
|
||||
+treats leading zeros as octal notatation. glibc implementation of modern
|
||||
+:func:`~socket.inet_pton` does not accept any leading zeros. For a while
|
||||
+the :mod:`ipaddress` module used to accept ambiguous leading zeros.
|
||||
--
|
||||
2.32.0
|
||||
|
||||
+61
@@ -0,0 +1,61 @@
|
||||
From 5a5335aba36f6c4204ba65faa8b2e67025c1bd4a Mon Sep 17 00:00:00 2001
|
||||
From: "Miss Islington (bot)"
|
||||
<31488909+miss-islington@users.noreply.github.com>
|
||||
Date: Mon, 17 May 2021 10:34:39 -0700
|
||||
Subject: [PATCH 16/17] bpo-43650: Fix MemoryError on zip.read in
|
||||
shutil._unpack_zipfile for large files (GH-25058)
|
||||
|
||||
`shutil.unpack_archive()` tries to read the whole file into memory, making no use of any kind of smaller buffer. Process crashes for really large files: I.e. archive: ~1.7G, unpacked: ~10G. Before the crash it can easily take away all available RAM on smaller systems. Had to pull the code form `zipfile.Zipfile.extractall()` to fix this
|
||||
|
||||
Automerge-Triggered-By: GH:gpshead
|
||||
(cherry picked from commit f32c7950e0077b6d9a8e217c2796fc582f18ca08)
|
||||
|
||||
Co-authored-by: Igor Bolshakov <ibolsch@gmail.com>
|
||||
---
|
||||
Lib/shutil.py | 16 ++++++----------
|
||||
.../2021-03-29-00-23-30.bpo-43650.v01tic.rst | 2 ++
|
||||
2 files changed, 8 insertions(+), 10 deletions(-)
|
||||
create mode 100644 Misc/NEWS.d/next/Library/2021-03-29-00-23-30.bpo-43650.v01tic.rst
|
||||
|
||||
diff --git a/Lib/shutil.py b/Lib/shutil.py
|
||||
index fdadb83800..aaf76c651b 100644
|
||||
--- a/Lib/shutil.py
|
||||
+++ b/Lib/shutil.py
|
||||
@@ -1144,20 +1144,16 @@ def _unpack_zipfile(filename, extract_dir):
|
||||
if name.startswith('/') or '..' in name:
|
||||
continue
|
||||
|
||||
- target = os.path.join(extract_dir, *name.split('/'))
|
||||
- if not target:
|
||||
+ targetpath = os.path.join(extract_dir, *name.split('/'))
|
||||
+ if not targetpath:
|
||||
continue
|
||||
|
||||
- _ensure_directory(target)
|
||||
+ _ensure_directory(targetpath)
|
||||
if not name.endswith('/'):
|
||||
# file
|
||||
- data = zip.read(info.filename)
|
||||
- f = open(target, 'wb')
|
||||
- try:
|
||||
- f.write(data)
|
||||
- finally:
|
||||
- f.close()
|
||||
- del data
|
||||
+ with zip.open(name, 'r') as source, \
|
||||
+ open(targetpath, 'wb') as target:
|
||||
+ copyfileobj(source, target)
|
||||
finally:
|
||||
zip.close()
|
||||
|
||||
diff --git a/Misc/NEWS.d/next/Library/2021-03-29-00-23-30.bpo-43650.v01tic.rst b/Misc/NEWS.d/next/Library/2021-03-29-00-23-30.bpo-43650.v01tic.rst
|
||||
new file mode 100644
|
||||
index 0000000000..a2ea4a4800
|
||||
--- /dev/null
|
||||
+++ b/Misc/NEWS.d/next/Library/2021-03-29-00-23-30.bpo-43650.v01tic.rst
|
||||
@@ -0,0 +1,2 @@
|
||||
+Fix :exc:`MemoryError` in :func:`shutil.unpack_archive` which fails inside
|
||||
+:func:`shutil._unpack_zipfile` on large files. Patch by Igor Bolshakov.
|
||||
--
|
||||
2.32.0
|
||||
|
||||
+214
@@ -0,0 +1,214 @@
|
||||
From 5b42865796c6bf768d4d11e3c93dc0994d46f783 Mon Sep 17 00:00:00 2001
|
||||
From: Christian Heimes <christian@python.org>
|
||||
Date: Sat, 1 May 2021 20:53:10 +0200
|
||||
Subject: [PATCH 17/17] bpo-43998: Default to TLS 1.2 and increase cipher suite
|
||||
security (GH-25778)
|
||||
|
||||
The ssl module now has more secure default settings. Ciphers without forward
|
||||
secrecy or SHA-1 MAC are disabled by default. Security level 2 prohibits
|
||||
weak RSA, DH, and ECC keys with less than 112 bits of security.
|
||||
:class:`~ssl.SSLContext` defaults to minimum protocol version TLS 1.2.
|
||||
Settings are based on Hynek Schlawack's research.
|
||||
|
||||
```
|
||||
$ openssl version
|
||||
OpenSSL 1.1.1k FIPS 25 Mar 2021
|
||||
$ openssl ciphers -v '@SECLEVEL=2:ECDH+AESGCM:ECDH+CHACHA20:ECDH+AES:DHE+AES:!aNULL:!eNULL:!aDSS:!SHA1:!AESCCM'
|
||||
TLS_AES_256_GCM_SHA384 TLSv1.3 Kx=any Au=any Enc=AESGCM(256) Mac=AEAD
|
||||
TLS_CHACHA20_POLY1305_SHA256 TLSv1.3 Kx=any Au=any Enc=CHACHA20/POLY1305(256) Mac=AEAD
|
||||
TLS_AES_128_GCM_SHA256 TLSv1.3 Kx=any Au=any Enc=AESGCM(128) Mac=AEAD
|
||||
TLS_AES_128_CCM_SHA256 TLSv1.3 Kx=any Au=any Enc=AESCCM(128) Mac=AEAD
|
||||
ECDHE-ECDSA-AES256-GCM-SHA384 TLSv1.2 Kx=ECDH Au=ECDSA Enc=AESGCM(256) Mac=AEAD
|
||||
ECDHE-RSA-AES256-GCM-SHA384 TLSv1.2 Kx=ECDH Au=RSA Enc=AESGCM(256) Mac=AEAD
|
||||
ECDHE-ECDSA-AES128-GCM-SHA256 TLSv1.2 Kx=ECDH Au=ECDSA Enc=AESGCM(128) Mac=AEAD
|
||||
ECDHE-RSA-AES128-GCM-SHA256 TLSv1.2 Kx=ECDH Au=RSA Enc=AESGCM(128) Mac=AEAD
|
||||
ECDHE-ECDSA-CHACHA20-POLY1305 TLSv1.2 Kx=ECDH Au=ECDSA Enc=CHACHA20/POLY1305(256) Mac=AEAD
|
||||
ECDHE-RSA-CHACHA20-POLY1305 TLSv1.2 Kx=ECDH Au=RSA Enc=CHACHA20/POLY1305(256) Mac=AEAD
|
||||
ECDHE-ECDSA-AES256-SHA384 TLSv1.2 Kx=ECDH Au=ECDSA Enc=AES(256) Mac=SHA384
|
||||
ECDHE-RSA-AES256-SHA384 TLSv1.2 Kx=ECDH Au=RSA Enc=AES(256) Mac=SHA384
|
||||
ECDHE-ECDSA-AES128-SHA256 TLSv1.2 Kx=ECDH Au=ECDSA Enc=AES(128) Mac=SHA256
|
||||
ECDHE-RSA-AES128-SHA256 TLSv1.2 Kx=ECDH Au=RSA Enc=AES(128) Mac=SHA256
|
||||
DHE-RSA-AES256-GCM-SHA384 TLSv1.2 Kx=DH Au=RSA Enc=AESGCM(256) Mac=AEAD
|
||||
DHE-RSA-AES128-GCM-SHA256 TLSv1.2 Kx=DH Au=RSA Enc=AESGCM(128) Mac=AEAD
|
||||
DHE-RSA-AES256-SHA256 TLSv1.2 Kx=DH Au=RSA Enc=AES(256) Mac=SHA256
|
||||
DHE-RSA-AES128-SHA256 TLSv1.2 Kx=DH Au=RSA Enc=AES(128) Mac=SHA256
|
||||
```
|
||||
|
||||
Signed-off-by: Christian Heimes <christian@python.org>
|
||||
---
|
||||
Doc/library/ssl.rst | 8 ++++
|
||||
Lib/test/test_nntplib.py | 24 +++++++++--
|
||||
.../2021-05-01-13-13-40.bpo-43998.xhmWD7.rst | 5 +++
|
||||
Modules/_ssl.c | 43 ++++++++++++++++---
|
||||
4 files changed, 72 insertions(+), 8 deletions(-)
|
||||
create mode 100644 Misc/NEWS.d/next/Security/2021-05-01-13-13-40.bpo-43998.xhmWD7.rst
|
||||
|
||||
diff --git a/Doc/library/ssl.rst b/Doc/library/ssl.rst
|
||||
index a58717c3ab..f1c43ee3d8 100644
|
||||
--- a/Doc/library/ssl.rst
|
||||
+++ b/Doc/library/ssl.rst
|
||||
@@ -1471,6 +1471,14 @@ to speed up repeated connections from the same clients.
|
||||
ciphers, no ``NULL`` ciphers and no ``MD5`` ciphers (except for
|
||||
:data:`PROTOCOL_SSLv2`).
|
||||
|
||||
+ .. versionchanged:: 3.9.5_p2 (Gentoo)
|
||||
+
|
||||
+ The default cipher suites now include only secure AES and ChaCha20
|
||||
+ ciphers with forward secrecy and security level 2. RSA and DH keys with
|
||||
+ less than 2048 bits and ECC keys with less than 224 bits are prohibited.
|
||||
+ :data:`PROTOCOL_TLS`, :data:`PROTOCOL_TLS_CLIENT`, and
|
||||
+ :data:`PROTOCOL_TLS_SERVER` use TLS 1.2 as minimum TLS version.
|
||||
+
|
||||
|
||||
:class:`SSLContext` objects have the following methods and attributes:
|
||||
|
||||
diff --git a/Lib/test/test_nntplib.py b/Lib/test/test_nntplib.py
|
||||
index 89a2004dfb..d27e4abae8 100644
|
||||
--- a/Lib/test/test_nntplib.py
|
||||
+++ b/Lib/test/test_nntplib.py
|
||||
@@ -37,6 +37,8 @@ else:
|
||||
|
||||
class NetworkedNNTPTestsMixin:
|
||||
|
||||
+ ssl_context = None
|
||||
+
|
||||
def test_welcome(self):
|
||||
welcome = self.server.getwelcome()
|
||||
self.assertEqual(str, type(welcome))
|
||||
@@ -269,6 +271,13 @@ class NetworkedNNTPTestsMixin:
|
||||
return False
|
||||
return True
|
||||
|
||||
+ kwargs = dict(
|
||||
+ timeout=support.INTERNET_TIMEOUT,
|
||||
+ usenetrc=False
|
||||
+ )
|
||||
+ if self.ssl_context is not None:
|
||||
+ kwargs["ssl_context"] = self.ssl_context
|
||||
+
|
||||
try:
|
||||
with self.NNTP_CLASS(self.NNTP_HOST, timeout=TIMEOUT, usenetrc=False) as server:
|
||||
self.assertTrue(is_connected())
|
||||
@@ -306,15 +315,21 @@ class NetworkedNNTPTests(NetworkedNNTPTestsMixin, unittest.TestCase):
|
||||
@classmethod
|
||||
def setUpClass(cls):
|
||||
support.requires("network")
|
||||
- with support.transient_internet(cls.NNTP_HOST):
|
||||
+ kwargs = dict(
|
||||
+ timeout=support.INTERNET_TIMEOUT,
|
||||
+ usenetrc=False
|
||||
+ )
|
||||
+ if cls.ssl_context is not None:
|
||||
+ kwargs["ssl_context"] = cls.ssl_context
|
||||
+ with socket_helper.transient_internet(cls.NNTP_HOST):
|
||||
try:
|
||||
- cls.server = cls.NNTP_CLASS(cls.NNTP_HOST, timeout=TIMEOUT,
|
||||
- usenetrc=False)
|
||||
+ cls.server = cls.NNTP_CLASS(cls.NNTP_HOST, **kwargs)
|
||||
except SSLError as ssl_err:
|
||||
# matches "[SSL: DH_KEY_TOO_SMALL] dh key too small"
|
||||
if re.search(r'(?i)KEY.TOO.SMALL', ssl_err.reason):
|
||||
raise unittest.SkipTest(f"{cls} got {ssl_err} connecting "
|
||||
f"to {cls.NNTP_HOST!r}")
|
||||
+ print(cls.NNTP_HOST)
|
||||
raise
|
||||
except EOF_ERRORS:
|
||||
raise unittest.SkipTest(f"{cls} got EOF error on connecting "
|
||||
@@ -347,6 +362,9 @@ class NetworkedNNTP_SSLTests(NetworkedNNTPTests):
|
||||
# Disabled as the connection will already be encrypted.
|
||||
test_starttls = None
|
||||
|
||||
+ ssl_context = ssl._create_unverified_context()
|
||||
+ ssl_context.set_ciphers("DEFAULT")
|
||||
+ ssl_context.maximum_version = ssl.TLSVersion.TLSv1_2
|
||||
|
||||
#
|
||||
# Non-networked tests using a local server (or something mocking it).
|
||||
diff --git a/Misc/NEWS.d/next/Security/2021-05-01-13-13-40.bpo-43998.xhmWD7.rst b/Misc/NEWS.d/next/Security/2021-05-01-13-13-40.bpo-43998.xhmWD7.rst
|
||||
new file mode 100644
|
||||
index 0000000000..6a40346128
|
||||
--- /dev/null
|
||||
+++ b/Misc/NEWS.d/next/Security/2021-05-01-13-13-40.bpo-43998.xhmWD7.rst
|
||||
@@ -0,0 +1,5 @@
|
||||
+The :mod:`ssl` module sets more secure cipher suites defaults. Ciphers
|
||||
+without forward secrecy and with SHA-1 MAC are disabled by default. Security
|
||||
+level 2 prohibits weak RSA, DH, and ECC keys with less than 112 bits of
|
||||
+security. :class:`~ssl.SSLContext` defaults to minimum protocol version TLS
|
||||
+1.2. Settings are based on Hynek Schlawack's research.
|
||||
diff --git a/Modules/_ssl.c b/Modules/_ssl.c
|
||||
index bc665db0d5..01a2067596 100644
|
||||
--- a/Modules/_ssl.c
|
||||
+++ b/Modules/_ssl.c
|
||||
@@ -300,15 +300,27 @@ SSL_SESSION_get_ticket_lifetime_hint(const SSL_SESSION *s)
|
||||
#ifndef PY_SSL_DEFAULT_CIPHER_STRING
|
||||
#error "Py_SSL_DEFAULT_CIPHERS 0 needs Py_SSL_DEFAULT_CIPHER_STRING"
|
||||
#endif
|
||||
+ #ifndef PY_SSL_MIN_PROTOCOL
|
||||
+ #define PY_SSL_MIN_PROTOCOL TLS1_2_VERSION
|
||||
+ #endif
|
||||
#elif PY_SSL_DEFAULT_CIPHERS == 1
|
||||
/* Python custom selection of sensible cipher suites
|
||||
- * DEFAULT: OpenSSL's default cipher list. Since 1.0.2 the list is in sensible order.
|
||||
+ * @SECLEVEL=2: security level 2 with 112 bits minimum security (e.g. 2048 bits RSA key)
|
||||
+ * ECDH+*: enable ephemeral elliptic curve Diffie-Hellman
|
||||
+ * DHE+*: fallback to ephemeral finite field Diffie-Hellman
|
||||
+ * encryption order: AES AEAD (GCM), ChaCha AEAD, AES CBC
|
||||
* !aNULL:!eNULL: really no NULL ciphers
|
||||
- * !MD5:!3DES:!DES:!RC4:!IDEA:!SEED: no weak or broken algorithms on old OpenSSL versions.
|
||||
* !aDSS: no authentication with discrete logarithm DSA algorithm
|
||||
- * !SRP:!PSK: no secure remote password or pre-shared key authentication
|
||||
+ * !SHA1: no weak SHA1 MAC
|
||||
+ * !AESCCM: no CCM mode, it's uncommon and slow
|
||||
+ *
|
||||
+ * Based on Hynek's excellent blog post (update 2021-02-11)
|
||||
+ * https://hynek.me/articles/hardening-your-web-servers-ssl-ciphers/
|
||||
*/
|
||||
- #define PY_SSL_DEFAULT_CIPHER_STRING "DEFAULT:!aNULL:!eNULL:!MD5:!3DES:!DES:!RC4:!IDEA:!SEED:!aDSS:!SRP:!PSK"
|
||||
+ #define PY_SSL_DEFAULT_CIPHER_STRING "@SECLEVEL=2:ECDH+AESGCM:ECDH+CHACHA20:ECDH+AES:DHE+AES:!aNULL:!eNULL:!aDSS:!SHA1:!AESCCM"
|
||||
+ #ifndef PY_SSL_MIN_PROTOCOL
|
||||
+ #define PY_SSL_MIN_PROTOCOL TLS1_2_VERSION
|
||||
+ #endif
|
||||
#elif PY_SSL_DEFAULT_CIPHERS == 2
|
||||
/* Ignored in SSLContext constructor, only used to as _ssl.DEFAULT_CIPHER_STRING */
|
||||
#define PY_SSL_DEFAULT_CIPHER_STRING SSL_DEFAULT_CIPHER_LIST
|
||||
@@ -3249,8 +3261,25 @@ _ssl__SSLContext_impl(PyTypeObject *type, int proto_version)
|
||||
ERR_clear_error();
|
||||
PyErr_SetString(PySSLErrorObject,
|
||||
"No cipher can be selected.");
|
||||
- return NULL;
|
||||
+ goto error;
|
||||
+ }
|
||||
+#ifdef PY_SSL_MIN_PROTOCOL
|
||||
+ switch(proto_version) {
|
||||
+ case PY_SSL_VERSION_TLS:
|
||||
+ case PY_SSL_VERSION_TLS_CLIENT:
|
||||
+ case PY_SSL_VERSION_TLS_SERVER:
|
||||
+ result = SSL_CTX_set_min_proto_version(ctx, PY_SSL_MIN_PROTOCOL);
|
||||
+ if (result == 0) {
|
||||
+ PyErr_Format(PyExc_ValueError,
|
||||
+ "Failed to set minimum protocol 0x%x",
|
||||
+ PY_SSL_MIN_PROTOCOL);
|
||||
+ goto error;
|
||||
+ }
|
||||
+ break;
|
||||
+ default:
|
||||
+ break;
|
||||
}
|
||||
+#endif
|
||||
|
||||
#if defined(SSL_MODE_RELEASE_BUFFERS)
|
||||
/* Set SSL_MODE_RELEASE_BUFFERS. This potentially greatly reduces memory
|
||||
@@ -3303,6 +3332,10 @@ _ssl__SSLContext_impl(PyTypeObject *type, int proto_version)
|
||||
#endif
|
||||
|
||||
return (PyObject *)self;
|
||||
+ error:
|
||||
+ Py_XDECREF(self);
|
||||
+ ERR_clear_error();
|
||||
+ return NULL;
|
||||
}
|
||||
|
||||
static int
|
||||
--
|
||||
2.32.0
|
||||
|
||||
Reference in New Issue
Block a user