[Bug 927883] Review Request: python-defusedxml - XML bomb protection for Python stdlib modules

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



https://bugzilla.redhat.com/show_bug.cgi?id=927883

Aviso <redhat@xxxxxxxx> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |redhat@xxxxxxxx



--- Comment #14 from Aviso <redhat@xxxxxxxx> ---
Looks like python-defusedxml was never added to EPEL 7. Can we get that added?


Also, I'm attaching a couple patches:


python-defusedxml-0.4.1-entity_loop.patch

It looks like in the mass rebuilds, --nocheck is used, so the tests don't
actually run, but when I rebuild manually, I noticed a few of the tests fail
with:

lxml.etree.XMLSyntaxError: Detected an entity reference loop, line 1, column 4

This is due to a security patch in libxml2. It's legitimate, but the tests are
expecting the wrong exception. I emailed the maintainer about it, but haven't
heard anything yet. This patch modifies the tests so they check for what is
expected.


python-defusedxml-0.4.1-format_strings.patch

This is from a pull request in the defusedxml repo. It fixes some string
formatting syntax so it work in Python 2.6 as well as 2.7+
https://bitbucket.org/tiran/defusedxml/pull-request/1/make-format-strings-python26-compatible/diff

-- 
You are receiving this mail because:
You are on the CC list for the bug.
You are always notified about changes to this product and component
_______________________________________________
package-review mailing list
package-review@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/package-review




[Index of Archives]     [Fedora Legacy]     [Fedora Desktop]     [Fedora SELinux]     [Yosemite News]     [KDE Users]     [Fedora Tools]