]>
granicus.if.org Git - python/log
Barry Warsaw [Tue, 29 Oct 2013 14:16:34 +0000 (10:16 -0400)]
Added tag v2.6.9 for changeset
fcb3ec2842f9
Barry Warsaw [Tue, 29 Oct 2013 14:14:05 +0000 (10:14 -0400)]
version bump
Barry Warsaw [Tue, 29 Oct 2013 14:10:41 +0000 (10:10 -0400)]
updating topics
Barry Warsaw [Tue, 1 Oct 2013 15:38:38 +0000 (11:38 -0400)]
Typo caught by : Arfrever Frehtes Taifersar Arahesis.
Barry Warsaw [Tue, 1 Oct 2013 01:49:31 +0000 (21:49 -0400)]
post release bump
Barry Warsaw [Tue, 1 Oct 2013 00:37:58 +0000 (20:37 -0400)]
Added tag v2.6.9rc1 for changeset
a0025037f11a
Barry Warsaw [Tue, 1 Oct 2013 00:37:45 +0000 (20:37 -0400)]
Bump copyright years.
Barry Warsaw [Tue, 1 Oct 2013 00:34:29 +0000 (20:34 -0400)]
Bump to 2.6.9rc1
Barry Warsaw [Tue, 1 Oct 2013 00:31:56 +0000 (20:31 -0400)]
Regenerate pydoc_topics.py
Barry Warsaw [Mon, 30 Sep 2013 22:35:15 +0000 (18:35 -0400)]
- Issue #16040: CVE-2013-1752: nntplib: Limit maximum line lengths to 2048 to
prevent readline() calls from consuming too much memory. Patch by Jyrki
Pulliainen.
Barry Warsaw [Mon, 30 Sep 2013 20:45:40 +0000 (16:45 -0400)]
Fix typo in NEWS file.
Barry Warsaw [Mon, 30 Sep 2013 19:56:29 +0000 (15:56 -0400)]
- Issue #16041: CVE-2013-1752: poplib: Limit maximum line lengths to 2048 to
prevent readline() calls from consuming too much member. Patch by Jyrki
Pulliainen.
Barry Warsaw [Sun, 29 Sep 2013 17:59:06 +0000 (13:59 -0400)]
- Issue #16037: HTTPMessage.readheaders() raises an HTTPException when more
than 100 headers are read. Adapted from patch by Jyrki Pulliainen.
Barry Warsaw [Wed, 25 Sep 2013 13:36:58 +0000 (09:36 -0400)]
- Issue #16038: CVE-2013-1752: ftplib: Limit amount of data read by
limiting the call to readline(). Original patch by Michał
Jastrzębski and Giampaolo Rodola.
with test fixes by Serhiy Storchaka.
Barry Warsaw [Sun, 22 Sep 2013 20:07:09 +0000 (16:07 -0400)]
- Issue #16039: CVE-2013-1752: Change use of readline in imaplib module to
limit line length. Patch by Emil Lind.
R David Murray [Wed, 18 Sep 2013 12:49:25 +0000 (08:49 -0400)]
#14984: only import pwd on POSIX.
R David Murray [Wed, 18 Sep 2013 00:08:09 +0000 (20:08 -0400)]
Add versionchanged for #14984, remove extra blank from string.
R David Murray [Mon, 16 Sep 2013 17:48:44 +0000 (13:48 -0400)]
#14984: On POSIX, enforce permissions when reading default .netrc.
Initial patch by Bruno Piguet.
This is implemented as if a useful .netrc file could exist without passwords,
which is possible in the general case; but in fact our netrc implementation
does not support it. Fixing that issue will be an enhancement.
Andrew Kuchling [Sun, 15 Sep 2013 17:11:47 +0000 (13:11 -0400)]
#16042: CVE-2013-1752: Limit amount of data read by limiting the call to readline().
The SSLFakeFile.readline() method needs to support limiting readline() as
well. It's not a full emulation of readline()'s signature, but this class
is only used by smtplib's code, so it doesn't have to be.
Modified version of original patch by Christian Heimes.
Christian Heimes [Thu, 5 Sep 2013 14:04:35 +0000 (16:04 +0200)]
Issue #18709: GCC 4.6 complains that 'v' may be used uninitialized in GEN_EMAIL/GEN_URI/GEN_DNS case
Christian Heimes [Tue, 3 Sep 2013 12:47:00 +0000 (14:47 +0200)]
Python 2.6's ssl module has neither OPENSSL_VERSION_INFO nor _OPENSSL_API_VERSION
Christian Heimes [Sun, 25 Aug 2013 12:12:41 +0000 (14:12 +0200)]
Issue #18709: Fix issue with IPv6 address in subjectAltName on Mac OS X Tiger
Barry Warsaw [Fri, 23 Aug 2013 17:26:49 +0000 (13:26 -0400)]
- Issue #18709: Fix CVE-2013-4238. The SSL module now handles NULL bytes
inside subjectAltName correctly. Formerly the module has used OpenSSL's
GENERAL_NAME_print() function to get the string represention of ASN.1
strings for `rfc822Name` (email), `dNSName` (DNS) and
`uniformResourceIdentifier` (URI).
Barry Warsaw [Wed, 21 Aug 2013 00:35:20 +0000 (20:35 -0400)]
Fix UnboundLocalError regression due to previous incorrect fix for
issue 16248.
Barry Warsaw [Wed, 20 Feb 2013 23:19:55 +0000 (18:19 -0500)]
- Issue #16248: Disable code execution from the user's home directory by
tkinter when the -E flag is passed to Python. Patch by Zachary Ware.
Georg Brandl [Sun, 28 Oct 2012 07:04:38 +0000 (08:04 +0100)]
#8040: port versionswitcher patch to 2.6.
Barry Warsaw [Tue, 10 Apr 2012 18:50:39 +0000 (14:50 -0400)]
Post release twiddle.
Barry Warsaw [Tue, 10 Apr 2012 15:18:47 +0000 (11:18 -0400)]
Added tag v2.6.8 for changeset
c9910fd022fc
Barry Warsaw [Tue, 10 Apr 2012 14:59:35 +0000 (10:59 -0400)]
Bump to 2.6.8
Barry Warsaw [Tue, 10 Apr 2012 14:56:26 +0000 (10:56 -0400)]
update docs
Georg Brandl [Sun, 18 Mar 2012 06:31:17 +0000 (07:31 +0100)]
Remove duplicate hgtags entries for 2.6.8rc{1,2}.
Barry Warsaw [Sat, 17 Mar 2012 22:34:05 +0000 (18:34 -0400)]
Added tag v2.6.8rc2 for changeset
bd9e1a02e3e3
Barry Warsaw [Sat, 17 Mar 2012 22:19:42 +0000 (18:19 -0400)]
Added tag v2.6.8rc2 for changeset
1d1b7b9fad48
Barry Warsaw [Sat, 17 Mar 2012 22:19:15 +0000 (18:19 -0400)]
Bump to 2.6.8rc2
Barry Warsaw [Sat, 17 Mar 2012 22:16:58 +0000 (18:16 -0400)]
Update Docs and NEWS for 2.6.8rc2.
Barry Warsaw [Thu, 15 Mar 2012 00:10:41 +0000 (17:10 -0700)]
- Issue #14234: CVE-2012-0876: Randomize hashes of xml attributes in the hash
table internal to the pyexpat module's copy of the expat library to avoid a
denial of service due to hash collisions. Patch by David Malcolm with some
modifications by the expat project.
Barry Warsaw [Thu, 23 Feb 2012 16:10:31 +0000 (11:10 -0500)]
Added tag v2.6.8rc1 for changeset
5356b6c7fd66
Barry Warsaw [Thu, 23 Feb 2012 15:59:50 +0000 (10:59 -0500)]
Added tag v2.6.8rc1 for changeset
caab08cd2b3e
Barry Warsaw [Thu, 23 Feb 2012 15:59:38 +0000 (10:59 -0500)]
Bump some more copyright years (as per PEP 101), since this is the first
release of 2.6 for 2012.
Barry Warsaw [Thu, 23 Feb 2012 15:55:57 +0000 (10:55 -0500)]
Bump to version 2.6.8rc1.
Barry Warsaw [Wed, 22 Feb 2012 22:26:50 +0000 (17:26 -0500)]
Back port from 2.7:
http://hg.python.org/cpython/rev/
48705250232c
changeset: 75187:
48705250232c
branch: 2.7
parent: 75184:
9a1d902714ae
user: Antoine Pitrou <solipsis@pitrou.net>
date: Wed Feb 22 22:16:25 2012 +0100
Barry Warsaw [Wed, 22 Feb 2012 18:50:04 +0000 (13:50 -0500)]
Backport from 2.7:
changeset: 75153:
9b7c6dd19e25
branch: 2.7
parent: 75151:
b1a02c17b327
user: Antoine Pitrou <solipsis@pitrou.net>
date: Tue Feb 21 22:02:04 2012 +0100
files: Lib/test/test_os.py
Barry Warsaw [Wed, 22 Feb 2012 18:34:18 +0000 (13:34 -0500)]
Backport from 2.7 branch.
changeset: 75165:
780008020c40
user: Antoine Pitrou <solipsis@pitrou.net>
date: Wed Feb 22 03:33:56 2012 +0100
summary: Fix (presumably) test_hash under big-endian systems (PPC).
Georg Brandl [Tue, 21 Feb 2012 21:36:27 +0000 (22:36 +0100)]
Remove reST markup from --help output. Also: O(n**2) is dict construction, not single insertion.
Benjamin Peterson [Tue, 21 Feb 2012 20:08:51 +0000 (15:08 -0500)]
don't need this hack anymore
Antoine Pitrou [Tue, 21 Feb 2012 19:42:48 +0000 (20:42 +0100)]
Fix crash at startup with -W options.
Benjamin Peterson [Tue, 21 Feb 2012 16:23:21 +0000 (11:23 -0500)]
merge heads
Barry Warsaw [Tue, 21 Feb 2012 16:16:06 +0000 (11:16 -0500)]
Backport fix from default branch for ./python -R -Wd where hash('d') would not
have gotten randomized.
Benjamin Peterson [Tue, 21 Feb 2012 16:08:50 +0000 (11:08 -0500)]
ensure no one tries to hash things before the random seed is found
Barry Warsaw [Tue, 21 Feb 2012 15:22:34 +0000 (10:22 -0500)]
Let's sort the keys so that this test passes even with random hashes.
Barry Warsaw [Tue, 21 Feb 2012 01:44:15 +0000 (20:44 -0500)]
Whitespace normalization
Barry Warsaw [Tue, 21 Feb 2012 01:42:21 +0000 (20:42 -0500)]
- Issue #13703: oCERT-2011-003: add -R command-line option and PYTHONHASHSEED
environment variable, to provide an opt-in way to protect against denial of
service attacks due to hash collisions within the dict and set types. Patch
by David Malcolm, based on work by Victor Stinner.
Barry Warsaw [Mon, 20 Feb 2012 19:43:22 +0000 (14:43 -0500)]
Back port Python 2.7 fix for test_invalid_redirect() in test_urllib.py.
Charles-François Natali [Sat, 18 Feb 2012 13:15:38 +0000 (14:15 +0100)]
Issue #14001: CVE-2012-0845: xmlrpc: Fix an endless loop in SimpleXMLRPCServer
upon malformed POST request.
Antoine Pitrou [Fri, 27 Jan 2012 08:42:45 +0000 (09:42 +0100)]
Issue #13885: CVE-2011-3389: the _ssl module would always disable the CBC IV attack countermeasure.
Martin v. Löwis [Mon, 31 Oct 2011 11:39:25 +0000 (12:39 +0100)]
merge closing of 2.5 branch
Martin v. Löwis [Mon, 31 Oct 2011 11:38:50 +0000 (12:38 +0100)]
2.5 is no longer maintained
Éric Araujo [Thu, 28 Jul 2011 20:27:28 +0000 (22:27 +0200)]
Remove mentions of previous license in profile module (#12417 followup)
Benjamin Peterson [Wed, 29 Jun 2011 02:57:21 +0000 (21:57 -0500)]
fix ws
Benjamin Peterson [Mon, 27 Jun 2011 14:14:34 +0000 (09:14 -0500)]
update profile license (closes #12417)
Barry Warsaw [Sat, 4 Jun 2011 00:05:48 +0000 (20:05 -0400)]
Replay svn r88852.
Barry Warsaw [Sat, 4 Jun 2011 00:02:47 +0000 (20:02 -0400)]
Replay svn r88850.
Martin v. Löwis [Sat, 28 May 2011 12:13:32 +0000 (14:13 +0200)]
Nearly null-merge 2.5.6
Martin v. Löwis [Sat, 28 May 2011 12:06:55 +0000 (14:06 +0200)]
merge 2.5.6c1 tag
Martin v. Löwis [Sat, 28 May 2011 12:05:31 +0000 (14:05 +0200)]
Added tag v2.5.6c1 for changeset
a87c7b96672b
Martin v. Löwis [Sat, 28 May 2011 12:00:37 +0000 (14:00 +0200)]
Added tag v2.5.6 for changeset
de34c7b097e8
Martin v. Löwis [Sat, 28 May 2011 11:58:36 +0000 (13:58 +0200)]
r88840: Prepare for 2.5.6.
Martin v. Löwis [Sat, 28 May 2011 11:57:28 +0000 (13:57 +0200)]
r88828: Fix year.
Martin v. Löwis [Sat, 28 May 2011 11:56:22 +0000 (13:56 +0200)]
r88824: Prepare for 2.5.6c1.
Barry Warsaw [Mon, 23 May 2011 19:27:52 +0000 (15:27 -0400)]
Replay changeset 70249:
b571c7a8cf2e from fubar branch. Original commit
message:
Merging post 2.6.7rc2 changes from Subversion.
Barry Warsaw [Mon, 23 May 2011 19:26:11 +0000 (15:26 -0400)]
Replay changeset 70248:
c714e2f92f63 from fubar branch. Original commit
message:
Cross-port changes for 2.6.7rc2 from the Subversion branch.
Barry Warsaw [Mon, 23 May 2011 19:22:56 +0000 (15:22 -0400)]
Replay changeset 70238:
03e488b5c009 from fubar branch. Original commit
message:
Reconcile with the 2.6svn branch. The 2.6.7 release will be made from
Subversion, but there were differences, so this brings them in sync. These
changes should *not* propagate to any newer versions.
Barry Warsaw [Mon, 23 May 2011 01:16:55 +0000 (21:16 -0400)]
These files have Windows line endings in 2.6.
Łukasz Langa [Thu, 28 Apr 2011 15:27:59 +0000 (17:27 +0200)]
Closes #11786: ConfigParser.[Raw]ConfigParser optionxform().
Martin v. Löwis [Sun, 17 Apr 2011 20:56:19 +0000 (22:56 +0200)]
merge 11442 NEWS
Martin v. Löwis [Sun, 17 Apr 2011 20:29:40 +0000 (22:29 +0200)]
Issue 11442: Add NEWS entry for
e9724d7abbc2
Guido van Rossum [Tue, 29 Mar 2011 20:03:10 +0000 (13:03 -0700)]
Merge cleanup.
Guido van Rossum [Tue, 29 Mar 2011 19:51:16 +0000 (12:51 -0700)]
Merge issue 11662 from 2.5.
guido@google.com [Tue, 29 Mar 2011 17:48:23 +0000 (10:48 -0700)]
Merge urllib/urllib2 security fix from 2.5 branch.
guido@google.com [Tue, 29 Mar 2011 16:53:33 +0000 (09:53 -0700)]
Adding .hgignore (copied from default branch).
Vinay Sajip [Tue, 29 Mar 2011 00:07:50 +0000 (01:07 +0100)]
Issue #11639: Configuration function documentation referred to logging.XXX rather than logging.config.XXX.
guido@google.com [Mon, 28 Mar 2011 20:53:40 +0000 (13:53 -0700)]
Add CVE number to urllib/urllib2 news item.
guido@google.com [Mon, 28 Mar 2011 20:47:01 +0000 (13:47 -0700)]
Add tests for the urllib[2] vulnerability. Change to raise exceptions.
guido@google.com [Thu, 24 Mar 2011 17:44:17 +0000 (10:44 -0700)]
Add FTP to the allowed url schemes. Add Misc/NEWS.
guido@google.com [Thu, 24 Mar 2011 15:07:45 +0000 (08:07 -0700)]
Issue 22663: fix redirect vulnerability in urllib/urllib2.
Martin v. Löwis [Mon, 21 Mar 2011 09:31:44 +0000 (10:31 +0100)]
null merge
Martin v. Löwis [Mon, 21 Mar 2011 09:30:07 +0000 (10:30 +0100)]
Set subversion version identification to empty strings if this is not a subversion
checkout (but a mercurial one). Closes #11579. Closes #11421.
Patch by Senthil Kumaran.
Guido van Rossum [Sat, 19 Mar 2011 23:20:39 +0000 (16:20 -0700)]
Whoops. The copyright should be two lines (merge from 2.5).
Guido van Rossum [Sat, 19 Mar 2011 23:20:06 +0000 (16:20 -0700)]
Whoops. The copyright should be two lines.
Guido van Rossum [Sat, 19 Mar 2011 23:17:14 +0000 (16:17 -0700)]
Test commit. Add 2011 to copyright line (merge from 2.5).
Guido van Rossum [Sat, 19 Mar 2011 23:14:44 +0000 (16:14 -0700)]
Test commit. Add 2011 to copyright line.
Senthil Kumaran [Thu, 17 Mar 2011 06:23:24 +0000 (14:23 +0800)]
merge from 2.5 branch.
Senthil Kumaran [Thu, 17 Mar 2011 04:34:18 +0000 (12:34 +0800)]
Fix issue11442 - Add a charset parameter to the Content-type to avoid XSS attacks.
Patch by Tom N. (Backported from py3k codeline).
Vinay Sajip [Fri, 11 Mar 2011 18:44:10 +0000 (18:44 +0000)]
Reverted bug fixes for #11444 (
fc4d045e3170 ) and #11424 (
b9d76846bb1c ), which should not have been made in this branch.
Vinay Sajip [Tue, 8 Mar 2011 22:39:55 +0000 (22:39 +0000)]
Issue #11444: Lock handlers while flushing/closing during shutdown.
Vinay Sajip [Mon, 7 Mar 2011 15:02:11 +0000 (15:02 +0000)]
Issue #11424: Fix bug in determining child loggers.
Georg Brandl [Sat, 5 Mar 2011 19:40:50 +0000 (20:40 +0100)]
Merge tags from 2.5.
Georg Brandl [Sat, 5 Mar 2011 19:38:24 +0000 (20:38 +0100)]
Add tags from the closed branches.
Georg Brandl [Sat, 5 Mar 2011 14:13:50 +0000 (15:13 +0100)]
Dummy-merge 2.5 branch into 2.6 branch.
Georg Brandl [Sat, 5 Mar 2011 14:04:01 +0000 (15:04 +0100)]
Add .hgeol file and fix newlines in the 2.6 branch.