head 1.17;
access;
symbols
pkgsrc-2026Q3:1.17.0.2
pkgsrc-2026Q3-base:1.17
pkgsrc-2026Q2:1.16.0.4
pkgsrc-2026Q2-base:1.16
pkgsrc-2026Q1:1.16.0.2
pkgsrc-2026Q1-base:1.16
pkgsrc-2025Q4:1.15.0.2
pkgsrc-2025Q4-base:1.15
pkgsrc-2025Q3:1.14.0.4
pkgsrc-2025Q3-base:1.14
pkgsrc-2025Q2:1.14.0.2
pkgsrc-2025Q2-base:1.14
pkgsrc-2025Q1:1.12.0.4
pkgsrc-2025Q1-base:1.12
pkgsrc-2024Q4:1.12.0.2
pkgsrc-2024Q4-base:1.12
pkgsrc-2024Q3:1.11.0.2
pkgsrc-2024Q3-base:1.11
pkgsrc-2024Q2:1.10.0.2
pkgsrc-2024Q2-base:1.10
pkgsrc-2024Q1:1.9.0.2
pkgsrc-2024Q1-base:1.9
pkgsrc-2023Q4:1.8.0.2
pkgsrc-2023Q4-base:1.8
pkgsrc-2023Q3:1.6.0.2
pkgsrc-2023Q3-base:1.6
pkgsrc-2023Q2:1.5.0.2
pkgsrc-2023Q2-base:1.5
pkgsrc-2023Q1:1.3.0.2
pkgsrc-2023Q1-base:1.3
pkgsrc-2022Q4:1.2.0.2
pkgsrc-2022Q4-base:1.2;
locks; strict;
comment @# @;
1.17
date 2026.08.13.12.26.36; author adam; state Exp;
branches;
next 1.16;
commitid uK5mcbH3OK1PstRG;
1.16
date 2026.03.04.06.51.45; author adam; state Exp;
branches;
next 1.15;
commitid YGZczgUfr9NLOCwG;
1.15
date 2025.10.10.12.57.12; author adam; state Exp;
branches;
next 1.14;
commitid nJ7VhcBRGcs4v1eG;
1.14
date 2025.06.04.14.14.17; author adam; state Exp;
branches;
next 1.13;
commitid QGsnv8s0FZxH2AXF;
1.13
date 2025.04.09.14.47.58; author adam; state Exp;
branches;
next 1.12;
commitid 0IRavEVzlaBB1oQF;
1.12
date 2024.12.05.07.51.12; author adam; state Exp;
branches;
next 1.11;
commitid aVLjViiPBheYJhAF;
1.11
date 2024.09.09.15.50.30; author adam; state Exp;
branches;
next 1.10;
commitid pNKjnwfx6xQHb9pF;
1.10
date 2024.04.08.12.49.33; author adam; state Exp;
branches;
next 1.9;
commitid 81Mu3aXP9tch8l5F;
1.9
date 2024.02.07.08.02.11; author adam; state Exp;
branches;
next 1.8;
commitid xBoC3o5ZZmjuvtXE;
1.8
date 2023.12.11.10.23.43; author adam; state Exp;
branches;
next 1.7;
commitid sjBbPNM5hn6B92QE;
1.7
date 2023.10.02.19.59.04; author adam; state Exp;
branches;
next 1.6;
commitid i3hUMTWH7gatA5HE;
1.6
date 2023.08.25.08.28.22; author adam; state Exp;
branches;
next 1.5;
commitid mw3wi7aDwRq4Z8CE;
1.5
date 2023.06.08.10.04.26; author adam; state Exp;
branches;
next 1.4;
commitid JBWxLUIUyv9V18sE;
1.4
date 2023.04.06.11.30.37; author adam; state Exp;
branches;
next 1.3;
commitid R8CnuF9kkk6Mw2kE;
1.3
date 2023.02.09.10.48.15; author adam; state Exp;
branches;
next 1.2;
commitid 7KlrD9YLEJvN5QcE;
1.2
date 2022.12.07.11.55.37; author adam; state Exp;
branches;
next 1.1;
commitid FjXv9wnktKcgwC4E;
1.1
date 2022.10.31.09.50.40; author adam; state Exp;
branches;
next ;
commitid dJ2usVQFvHvi1RZD;
desc
@@
1.17
log
@python311 py311-html-docs: updated to 3.11.16
3.11.16
macOS
gh-137586: Invoke osascript with absolute path in webbrowser and turtledemo.
Tests
gh-149776: Fix test_socket on Linux kernel 7.1 and newer: skip UDP Lite tests if it’s not supported. Patch by Victor Stinner.
Security
gh-155558: Update bundled libexpat to version 2.8.3 for the fix to CVE-2026-72522.
gh-153030: Fixed quadratic complexity in incremental parsing of long unterminated constructs (such as tags or comments) in html.parser.HTMLParser, which could be exploited for a denial of service.
gh-152674: The xml.etree.ElementTree.Element methods findall(), iterfind() and find() avoid quadratic behavior when using XPath index predicates ([1], [last()], [last()-N]) on XML documents with many same-tag siblings.
gh-152216: Update bundled libexpat to version 2.8.2.
gh-151987: The tarfile.TarFile.extract() method now applies the given filter when it extracts a link target from the archive as a fallback.
gh-151981: In tarfile, seeking a stream now stops when end of the stream is reached.
gh-151544: Modules/Setup.local is no longer used as a landmark to discover whether Python is running in a source tree, as it could potentially affect actual installs. The pybuilddir.txt file is now the sole indicator of running in a source tree.
gh-151558: Fixed an vulnerability in the tarfile data and tar extraction filters where crafted archives could create a symlink pointing outside the destination directory. This was a bypass of CVE-2025-4330.
gh-150599: Fix a possible stack buffer overflow in bz2 when a bz2.BZ2Decompressor is reused after a decompression error. The decompressor now becomes unusable after libbz2 reports an error.
gh-150743: http.client now limits the number of chunked-response trailer lines it will read to 100, and the number of interim (1xx) responses it will skip to 100. A malicious or broken server could previously stream trailer lines or 100 Continue responses forever, hanging the client even when a socket timeout was in use. Reported by @@YLChen-007 via GHSA-w4q2-g22w-6fr4.
gh-149698: Update bundled libexpat to version 2.8.1 for the fix for CVE-2026-45186.
gh-87451: The ftplib module’s undocumented ftpcp function no longer trusts the IPv4 address value returned from the source server in response to the PASV command by default, completing the fix for CVE-2021-4189. As with ftplib.FTP, the former behavior can be re-enabled by setting the trust_server_pasv_ipv4_address attribute on the source ftplib.FTP instance to True. Thanks to Qi Deng at Aurascape AI for the report.
gh-149486: tarfile.data_filter() now validates link targets using the same normalised value that is written to disk, strips trailing separators from the member name when resolving a symlink’s directory, and rejects link members that would replace the destination directory itself. This closes several path-traversal bypasses of the data extraction filter.
gh-149079: Fix a potential denial of service in unicodedata.normalize(). The canonical ordering step of Unicode normalization used a quadratic-time insertion sort for reordering combining characters, which could be exploited with crafted input containing many combining characters in non-canonical order. Replaced with a linear-time counting sort for long runs.
gh-149018: Improved protection against XML hash-flooding attacks in xml.parsers.expat and xml.etree.ElementTree when Python is compiled with libExpat 2.8.0 or later.
gh-149017: Update bundled libexpat to version 2.8.0.
gh-148808: Added buffer boundary check when using nbytes parameter with asyncio.AbstractEventLoop.sock_recvfrom_into(). Only relevant for Windows and the asyncio.ProactorEventLoop.
gh-148395: Fix a dangling input pointer in lzma.LZMADecompressor, and bz2.BZ2Decompressor when memory allocation fails with MemoryError, which could let a subsequent decompress() call read or write through a stale pointer to the already-released caller buffer.
gh-148169: A bypass in webbrowser allowed URLs prefixed with %action to pass the dash-prefix safety check.
gh-146581: Fix vulnerability in shutil.unpack_archive() for ZIP files on Windows which allowed to write files outside of the destination tree if the patch in the archive contains a Windows drive prefix. Now such invalid paths will be skipped. Files containing “..” in the name (like “foo..bar”) are no longer skipped.
gh-146333: Fix quadratic backtracking in configparser.RawConfigParser option parsing regexes (OPTCRE and OPTCRE_NV). A crafted configuration line with many whitespace characters could cause excessive CPU usage.
gh-146211: Reject CR/LF characters in tunnel request headers for the HTTPConnection.set_tunnel() method.
gh-145986: xml.parsers.expat: Fixed a crash caused by unbounded C recursion when converting deeply nested XML content models with ElementDeclHandler(). This addresses CVE-2026-4224.
gh-145599: Reject control characters in http.cookies.Morsel update() and js_output(). This addresses CVE-2026-3644.
gh-145506: Fixes CVE-2026-2297 by ensuring that SourcelessFileLoader uses io.open_code() when opening .pyc files.
gh-144370: Disallow usage of control characters in status in wsgiref.handlers to prevent HTTP header injections. Patch by Benedikt Johannes.
gh-143930: Reject leading dashes in URLs passed to webbrowser.open().
gh-143927: Normalize all line endings (CR, CRLF, and LF) to LF+TAB when writing multi-line configparser values.
Library
gh-109638: Fix exponential time in csv.Sniffer.sniff() for a sample which contains many quote characters. A doubled quote character is now also detected in a field which contains the delimiter or a line break.
gh-98820: Fix quadratic time in csv.Sniffer.sniff() for a sample which contains quoted fields, in particular for a single column of quoted fields.
gh-149231: In tomllib, the number of parts in TOML keys is now limited.
gh-146083: Update bundled libexpat to version 2.7.5.
gh-141707: Don’t change tarfile.TarInfo type from AREGTYPE to DIRTYPE when parsing GNU long name or link headers.
gh-90949: Add SetBillionLaughsAttackProtectionActivationThreshold() and SetBillionLaughsAttackProtectionMaximumAmplification() to xmlparser objects to tune protections against billion laughs attacks. Patch by Bénédikt Tran.
gh-100372: ssl.SSLContext.load_verify_locations() no longer incorrectly accepts some cases of trailing data when parsing DER.
Build
gh-153438: Update Windows build and installer tooling and documentation to use the current download URL for nuget.exe.
@
text
@# $NetBSD: Makefile,v 1.16 2026/03/04 06:51:45 adam Exp $
VERS= 3.11.16
DISTNAME= python-${VERS}-docs-html
PKGNAME= py311-html-docs-${VERS}
CATEGORIES= lang python
MASTER_SITES= https://www.python.org/ftp/python/doc/${VERS}/
EXTRACT_SUFX= .tar.bz2
MAINTAINER= leot@@NetBSD.org
HOMEPAGE= https://www.python.org/doc/
COMMENT= HTML documentation for Python 3.11
LICENSE= python-software-foundation
USE_TOOLS+= pax
NO_CONFIGURE= yes
NO_BUILD= yes
HTMLDIR= share/doc/python3.11
INSTALLATION_DIRS= ${HTMLDIR}
do-install:
cd ${WRKSRC} && ${PAX} -rw -pp . ${DESTDIR}${PREFIX}/${HTMLDIR}
.include "../../mk/bsd.pkg.mk"
@
1.16
log
@python311 py311-html-docs: updated to 3.11.15
Python 3.11.15
Security
gh-144125: BytesGenerator will now refuse to serialize (write) headers that are unsafely folded or delimited; see verify_generated_headers. (Contributed by Bas Bloemsaat and Petr Viktorin in gh-121650).
gh-143935: Fixed a bug in the folding of comments when flattening an email message using a modern email policy. Comments consisting of a very long sequence of non-foldable characters could trigger a forced line wrap that omitted the required leading space on the continuation line, causing the remainder of the comment to be interpreted as a new header field. This enabled header injection with carefully crafted inputs.
gh-143925: Reject control characters in data: URL media types.
gh-143919: Reject control characters in http.cookies.Morsel fields and values.
gh-143916: Reject C0 control characters within wsgiref.headers.Headers fields, values, and parameters.
gh-142145: Remove quadratic behavior in xml.minidom node ID cache clearing. In order to do this without breaking existing users, we also add the ownerDocument attribute to xml.dom.minidom elements and attributes created by directly instantiating the Element or Attr class. Note that this way of creating nodes is not supported; creator functions like xml.dom.Document.documentElement() should be used instead.
gh-137836: Add support of the “plaintext” element, RAWTEXT elements “xmp”, “iframe”, “noembed” and “noframes”, and optionally RAWTEXT element “noscript” in html.parser.HTMLParser.
gh-136063: email.message: ensure linear complexity for legacy HTTP parameters parsing. Patch by Bénédikt Tran.
gh-136065: Fix quadratic complexity in os.path.expandvars().
gh-119451: Fix a potential memory denial of service in the http.client module. When connecting to a malicious server, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.
gh-119452: Fix a potential memory denial of service in the http.server module. When a malicious user is connected to the CGI server on Windows, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.
gh-119342: Fix a potential memory denial of service in the plistlib module. When reading a Plist file received from untrusted source, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.
Library
gh-144833: Fixed a use-after-free in ssl when SSL_new() returns NULL in newPySSLSocket(). The error was reported via a dangling pointer after the object had already been freed.
gh-144363: Update bundled libexpat to 2.7.4
gh-90949: Add SetAllocTrackerActivationThreshold() and SetAllocTrackerMaximumAmplification() to xmlparser objects to prevent use of disproportional amounts of dynamic memory from within an Expat parser. Patch by Bénédikt Tran.
Core and Builtins
gh-120384: Fix an array out of bounds crash in list_ass_subscript, which could be invoked via some specificly tailored input: including concurrent modification of a list object, where one thread assigns a slice and another clears it.
gh-120298: Fix use-after free in list_richcompare_impl which can be invoked via some specificly tailored evil input.
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.15 2025/10/10 12:57:12 adam Exp $
d3 1
a3 1
VERS= 3.11.15
@
1.15
log
@python311 py311-html-docs: updated to 3.11.14
Python 3.11.14
Security
gh-139700: Check consistency of the zip64 end of central directory record. Support records with “zip64 extensible data” if there are no bytes prepended to the ZIP file.
gh-139400: xml.parsers.expat: Make sure that parent Expat parsers are only garbage-collected once they are no longer referenced by subparsers created by ExternalEntityParserCreate(). Patch by Sebastian Pipping.
gh-135661: Fix parsing start and end tags in html.parser.HTMLParser according to the HTML5 standard.
Whitespaces no longer accepted between and the tag name. E.g. script> does not end the script section.
Vertical tabulation (\v) and non-ASCII whitespaces no longer recognized as whitespaces. The only whitespaces are \t\n\r\f and space.
Null character (U+0000) no longer ends the tag name.
Attributes and slashes after the tag name in end tags are now ignored, instead of terminating after the first > in quoted attribute value. E.g. "/>.
Multiple slashes and whitespaces between the last attribute and closing > are now ignored in both start and end tags. E.g. .
Multiple = between attribute name and value are no longer collapsed. E.g. produces attribute “foo” with value “=bar”.
gh-135661: Fix CDATA section parsing in html.parser.HTMLParser according to the HTML5 standard: ] ]> and ]] > no longer end the CDATA section. Add private method _set_support_cdata() which can be used to specify how to parse <[CDATA[ — as a CDATA section in foreign content (SVG or MathML) or as a bogus comment in the HTML namespace.
gh-102555: Fix comment parsing in html.parser.HTMLParser according to the HTML5 standard. --!> now ends the comment. -- > no longer ends the comment. Support abnormally ended empty comments <--> and <--->.
gh-135462: Fix quadratic complexity in processing specially crafted input in html.parser.HTMLParser. End-of-file errors are now handled according to the HTML5 specs – comments and declarations are automatically closed, tags are ignored.
gh-118350: Fix support of escapable raw text mode (elements “textarea” and “title”) in html.parser.HTMLParser.
gh-86155: html.parser.HTMLParser.close() no longer loses data when the