astroid 4.1.2 (the version this distro packages) changed how it
resolves the enclosing scope/parent name and end_lineno for decorated
functions, singledispatch registrations, positional-only-arg checks
and a few other node kinds. These functional tests were pinned against
an older astroid's output and fail with plain output-text mismatches
(not logic errors) once run against 4.1.2. Regenerated the expected
.txt fixtures against astroid==4.1.2, mirroring the existing
0001-Adjust-test-expectations-for-ptest.patch approach for this
recipe.
tests/functional/u/undefined/undefined_variable.314.txt is pylint's
own Python-3.14-specific override of undefined_variable.txt (see
FunctionalTestFile.expected_output, which prefers a
"<base>.<ver>.txt" file over the plain one when it matches the
running interpreter). The distro's target Python is 3.14.7, so this
file - not the plain .txt - is what actually gets read during ptest,
and it still carried the pre-4.1.2 astroid values for the same two
lines. Applied the identical fix there too.
AI-Generated: Uses Claude Code
Signed-off-by: Khem Raj <raj.khem@gmail.com>
Guard each shell test case with a dbus-launch availability check and
emit SKIP instead of hard-failing when it isn't installed.
AI-Generated: Uses Claude Code
Signed-off-by: Khem Raj <raj.khem@gmail.com>
test_docs.py lint-checks every doc/docstring code example through
ruff (via pytest-examples). The installed ruff's rule set is not
version-locked to what pydantic's examples were written for, so ~130
style rules (import sorting, future-annotations, datetime-tz, etc.)
get flagged as failures that are not runtime bugs. Disable only the
lint step in test_docs.py; the examples are still executed.
test_deprecated_fields.py uses pytest.warns(Warning, callable,
match=...); newer pytest forwards match= to the callable instead of
consuming it, so these raise "unexpected keyword argument 'match'".
pytest API version skew; deselect via the existing -k mechanism.
test_internal.py's test_representation_integrations needs asttokens
(via executing/devtools.debug); add python3-asttokens to
RDEPENDS:${PN}-ptest.
AI-Generated: Uses Claude Code
Signed-off-by: Khem Raj <raj.khem@gmail.com>
test_dict_empty round-trips a 4096x4096 nested structure through JSON,
materializing ~16.7M real dict objects on loads() (~900MB+ RSS), which
gets OOM-killed on the memory-constrained qemu ptest target.
test_fake.py instantiates Faker with 9 locales at once, pulling in a
similarly large amount of locale provider data, for what is a
Unicode-robustness smoke test rather than core JSON logic.
AI-Generated: Uses Claude Code
Signed-off-by: Khem Raj <raj.khem@gmail.com>
tests/test_cli.py and tests/conftest.py use pytest's monkeypatch
"not set" sentinel, renamed from lowercase 'notset' to 'NOTSET' in
pytest 9.1; rewrite the references in the installed ptest copy.
werkzeug 3.1.x's get_host() no longer raises SecurityError for a Host
header with invalid/non-printable characters when no trusted_hosts is
configured (flask's default) - it silently returns "" and the request
routes to a 404 instead of the 400 test_bad_environ_raises_bad_request
expects against older werkzeug. Version-skew, not a flask bug; skip
the test.
AI-Generated: Uses Claude Code
Signed-off-by: Khem Raj <raj.khem@gmail.com>
tests/ imports itself as "tests.*" and pulls in "capabilities" from
the sibling tasks/ dir; upstream's pyproject.toml sets
[tool.pytest] pythonpath = [".", "tasks"] to make both resolve, so
ship tasks/ and pyproject.toml into the ptest install too.
Also disable pytest's cache plugin: the non-root "tester" user ptest
runs as can't write a cache dir under the read-only-to-them
/usr/lib/python3-filelock/ptest install path.
Add python3-pytest-timeout, used by the test suite.
AI-Generated: Uses Claude Code
Signed-off-by: Khem Raj <raj.khem@gmail.com>
The PyPI sdist ships no tests/ directory at all, so ptest had nothing
to run from it (pytest exits 5, "no tests collected"). Fetch the
matching git tag instead, which does include tests/, mirroring
python3-pydantic's fetch pattern.
Also set asyncio_mode=auto via a ptest-local pytest.ini:
tests/test_adapter_deprecation.py has plain "async def" tests with no
@pytest.mark.asyncio marker; they rely on upstream's pyproject.toml
setting asyncio_mode=auto, which isn't shipped into the ptest package.
AI-Generated: Uses Claude Code
Signed-off-by: Khem Raj <raj.khem@gmail.com>
The product-only "twisted" value emits a wildcard-vendor identity
instead of the active identity assigned to the packaged Twisted source.
Use "twisted:twisted" for its NVD dictionary CPE, NVD configuration,
and CNA affected-data identities. With sbom-cve-check 1.3.3 and the
pinned database snapshots, the generated product identity changes; the
current CVE report is unchanged.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
The current inherited "python:ujson" mapping does not match the UltraJSON identities used by NVD and CVE List V5, so source-aligned CVEs are missed.
Use "ultrajson:ultrajson" for the CNA affected-data identity and "ultrajson_project:ultrajson" for the NVD dictionary CPE and configuration identity.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
The product-only "tweepy" value emits a wildcard-vendor identity and
hides the distinct NVD identities assigned to the packaged Tweepy source.
Use "josh_roesslein:tweepy" for its NVD dictionary CPE and
"tweepy:tweepy" for the NVD configuration-only identity. With
sbom-cve-check 1.3.3 and the pinned database snapshots, the generated
product identity changes; the current CVE report is unchanged.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
The current "flask-user" mapping emits the wildcard-vendor
*:flask-user CPE instead of the exact NVD identity for the packaged
lingthio/Flask-User source.
Use "flask-user_project:flask-user", which is both an NVD dictionary
CPE and an NVD configuration identity. CNA affected data uses
"n/a:Flask-User" and remains covered by scanner aliases. With
sbom-cve-check 1.3.3 and the pinned 2026-08-12 data, the generated
identity changes but CVE-2021-23401 remains reported as affected.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
The current "flask" mapping emits the wildcard-vendor *:flask CPE
instead of the exact NVD identity for the packaged pallets/flask
source.
Use "palletsprojects:flask", which is both an NVD dictionary CPE and
an NVD configuration identity. CNA affected data uses "pallets:flask"
and "The Pallets Project:Flask", which remain covered by scanner
aliases. With sbom-cve-check 1.3.3 and the pinned 2026-08-12 data, the
generated identity changes but the current CVE report does not.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
The current "aiohttp" mapping emits the wildcard-vendor *:aiohttp CPE
instead of the exact NVD identity for the packaged aio-libs/aiohttp
source.
Use "aiohttp:aiohttp", which is both an NVD dictionary CPE and an NVD
configuration identity. CNA affected data uses "aio-libs:aiohttp" and
remains covered by scanner aliases. With sbom-cve-check 1.3.3 and the
pinned 2026-08-12 data, the generated identity changes but the current
CVE report does not.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
The current product-only "waitress" mapping emits a wildcard-vendor identity instead of the exact identities assigned to the packaged Pylons source.
Use "pylons:waitress" for the CNA affected-data identity and "agendaless:waitress" for the NVD dictionary CPE and configuration identity. This changes the generated product identity, but sbom-cve-check 1.3.3 with the pinned databases leaves the current CVE report unchanged.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
The current product-only "werkzeug" mapping emits a wildcard-vendor identity instead of the exact identities assigned to the packaged Pallets source.
Use "pallets:werkzeug" for the CNA affected-data identity and "palletsprojects:werkzeug" for the NVD dictionary CPE and configuration identity. This changes the generated product identity, but sbom-cve-check 1.3.3 with the pinned databases leaves the current CVE report unchanged.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
The product-only "pymongo" value emits a wildcard-vendor identity and
omits the second authoritative name for the packaged MongoDB Python
driver.
Use "mongodb:python_driver" for its NVD dictionary CPE family and
"mongodb:pymongo" for its NVD dictionary CPE and configuration identity.
With sbom-cve-check 1.3.3 and the pinned database snapshots, the
generated product identity changes; the current CVE report is unchanged.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
The current product-only "m2crypto" mapping generates a wildcard-vendor
identity instead of the two vendors used for the packaged source.
Use "heikkitoivonen:m2crypto" and "m2crypto_project:m2crypto" for their
exact NVD dictionary CPE and NVD configuration identities. This changes
the generated CPE set, but sbom-cve-check 1.3.3 with the pinned NVD
snapshot has no current CVE report delta.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
The product-only "py" mapping generates a wildcard-vendor identity
instead of the exact NVD identity for the packaged pytest-dev py
source. Use "pytest:py" for its NVD dictionary CPE and configuration
matches.
This changes the generated product identity. With sbom-cve-check 1.3.3,
the current CVE report is unchanged using the pinned database snapshots;
both mappings report CVE-2020-29651 and CVE-2022-42969.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
The current inherited "python:simpleeval" mapping is wrong for the
packaged danthedeckie SimpleEval source and misses its vulnerability
record.
Use "danthedeckie:simpleeval" for the source-aligned NVD dictionary
CPE, NVD configuration identity, and CNA affected-data identity.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
The inherited python:filelock mapping does not identify the tox-dev source packaged by this recipe, so filelock CVEs are missed.
Use tox-dev:filelock to match the source identity used by NVD and CNA.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Fast serialization and validation library for JSON, MessagePack, YAML and
TOML. Added as a runtime dependency of the forthcoming python3-max recipe,
but useful on its own.
Signed-off-by: Khem Raj <raj.khem@gmail.com>
The current product-only "httplib2" mapping generates a wildcard-vendor
product identity instead of the vendor assigned to the packaged project.
Use "httplib2_project:httplib2" for its exact NVD dictionary CPE and NVD
configuration identity. This changes the generated CPE, but sbom-cve-check
1.3.3 with the pinned NVD database snapshot has no current CVE report delta.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
The current inherited "python:web3" mapping does not match the web3.py identities used by NVD and CVE List V5, so its source-aligned CVE is missed.
Use "ethereum:web3.py" for the CNA affected-data identity and "apeworx:web3.py" for the NVD dictionary CPE and configuration identity.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
The product-only cbor2 mapping uses a wildcard vendor. Use
agronholm:cbor2, the NVD identity for the packaged source.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
License-Update: Copyright year updated to 2026
Changelog:
===========
- Breaking change: Drop support for Python 3.8, require Python >= 3.9
- Breaking change: Remove deprecated xxhash.VERSION_TUPLE
- Breaking change: The input keyword argument is renamed to data in
constructors and one-shot functions. update() additionally gains a data
keyword argument (it accepted no keyword arguments before).
- Breaking change: str input is no longer accepted and raises TypeError:
Strings must be encoded before hashing; encode to bytes before hashing
- Upgrade xxHash from v0.8.2 to v0.8.3. Note: on GCC/Clang source builds that
target AVX2 (e.g. -march=x86-64-v3), upstream v0.8.3 autovectorizes
XXH64_update() and makes the xxh64 streaming path about 2x slower. The shipped
wheels are built for baseline x86-64 and are unaffected. Source builds can work
around it by adding -fno-tree-vectorize to the compiler flags.
- Add per-object locking for thread safety, with sub-interpreter and
free-threaded (no-GIL) Python support. The GIL is now released only while
hashing inputs larger than 64 KiB; previously update() released it
unconditionally and one-shot functions always held it.
- Speed up hash constructors by switching them to tp_vectorcall.
- Build pyodide wasm32 wheels
- Add s390x big-endian test job
- Add Python 3.15 classifier
- CI: shard the PyPI upload into parallel groups and create the GitHub Release
automatically
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Changelog:
===========
- fix(type): cast set value in _render_options
- docs: fix typo 'set the the' -> 'set then the' in config reference
- ci: pin coverage to the ctrace core
- chore: remove the misc changelog category
- test: seed the virtualenv wheel image up front
- feat(plugin): type the plugin and internal API surfaces
- test: raise timeout for missing-interpreter discovery tests
- docs: mark the INI configuration format as deprecated
- docs: publish llms.txt from the docs build
- Provision before loading env_list
- docs: repoint nine dead source links in the onboarding guide
- Add {home} and {tox_root_name} substitutions
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Changelog:
===========
- Form-encoded ''POST'' bodies are now subject to a limit of 1000 arguments by default. This
prevents a CPU and memory denial of service attack. This limit can be overridden via the
'.set_parse_body_config' function.
- Multipart parsing now rejects requests with an excessive number of parts earlier in the parsing
process, limiting memory consumption.
- The deprecated mixed-case arguments to '.RequestHandler.set_cookie' now enforce the same
restrictions on invalid characters that were introduced in Tornado 6.5.5 for the standard
lowercase arguments.
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>