head	1.16;
access;
symbols
	pkgsrc-2026Q2:1.15.0.2
	pkgsrc-2026Q2-base:1.15
	pkgsrc-2026Q1:1.12.0.2
	pkgsrc-2026Q1-base:1.12
	pkgsrc-2025Q4:1.9.0.2
	pkgsrc-2025Q4-base:1.9;
locks; strict;
comment	@# @;


1.16
date	2026.08.05.15.56.03;	author adam;	state Exp;
branches;
next	1.15;
commitid	gQNKTBzU5pbuSsQG;

1.15
date	2026.06.11.12.13.39;	author adam;	state Exp;
branches;
next	1.14;
commitid	wtZiQRh8lR0TpnJG;

1.14
date	2026.05.18.21.23.27;	author wiz;	state Exp;
branches;
next	1.13;
commitid	p7FOG3l5AdRlelGG;

1.13
date	2026.03.25.22.52.08;	author wiz;	state Exp;
branches;
next	1.12;
commitid	5KmfLoNsNAElspzG;

1.12
date	2026.03.20.14.01.10;	author adam;	state Exp;
branches;
next	1.11;
commitid	NhVxHvTfr0PlGIyG;

1.11
date	2026.02.03.20.30.46;	author adam;	state Exp;
branches;
next	1.10;
commitid	B9AWSoqw04svhYsG;

1.10
date	2026.01.07.08.47.41;	author wiz;	state Exp;
branches;
next	1.9;
commitid	1wQ3ICD8eebefrpG;

1.9
date	2025.12.04.15.21.11;	author adam;	state Exp;
branches;
next	1.8;
commitid	6Q6M8ruWUXk3x6lG;

1.8
date	2025.12.02.21.34.37;	author adam;	state Exp;
branches;
next	1.7;
commitid	hj2qqD2t47lIESkG;

1.7
date	2025.11.05.22.20.05;	author wiz;	state Exp;
branches;
next	1.6;
commitid	OMqLF6Y0ijosMphG;

1.6
date	2025.10.22.13.46.55;	author jperkin;	state Exp;
branches;
next	1.5;
commitid	vv2IFREwo6uXnzfG;

1.5
date	2025.10.11.12.47.19;	author wiz;	state Exp;
branches;
next	1.4;
commitid	nh17cNTd0wRQp9eG;

1.4
date	2025.10.11.10.14.06;	author wiz;	state Exp;
branches;
next	1.3;
commitid	lcChe0GHoELcz8eG;

1.3
date	2025.10.10.13.57.52;	author wiz;	state Exp;
branches;
next	1.2;
commitid	4HCq0pb4z9q2Q1eG;

1.2
date	2025.10.09.19.52.16;	author wiz;	state Exp;
branches;
next	1.1;
commitid	l3juCkZRyrxvPVdG;

1.1
date	2025.10.08.07.13.07;	author adam;	state Exp;
branches;
next	;
commitid	PH62V3eT27S1FJdG;


desc
@@


1.16
log
@python314 py314-html-docs: updated to 3.14.7

Python 3.14.7 final

Security
gh-153030: Fixed quadratic complexity in incremental parsing of long unterminated constructs (such as tags or comments) in html.parser.HTMLParser, which could be exploited for a denial of service.
gh-152674: The xml.etree.ElementTree.Element methods findall(), iterfind() and find() avoid quadratic behavior when using XPath index predicates ([1], [last()], [last()-N]) on XML documents with many same-tag siblings.
gh-152216: Update bundled libexpat to version 2.8.2.
gh-151987: The tarfile.TarFile.extract() method now applies the given filter when it extracts a link target from the archive as a fallback.
gh-151981: In tarfile, seeking a stream now stops when end of the stream is reached.
gh-151544: Modules/Setup.local is no longer used as a landmark to discover whether Python is running in a source tree, as it could potentially affect actual installs. The pybuilddir.txt file is now the sole indicator of running in a source tree.
gh-151558: Fixed an vulnerability in the tarfile data and tar extraction filters where crafted archives could create a symlink pointing outside the destination directory. This was a bypass of CVE 2025-4330.
gh-150743: http.client now limits the number of chunked-response trailer lines it will read to 100, and the number of interim (1xx) responses it will skip to 100. A malicious or broken server could previously stream trailer lines or 100 Continue responses forever, hanging the client even when a socket timeout was in use. Reported by @@YLChen-007 via GHSA-w4q2-g22w-6fr4.
gh-143927: Normalize all line endings (CR, CRLF, and LF) to LF+TAB when writing multi-line configparser values.
gh-143921: Reject NUL, CR and LF characters in IMAP commands. Other control characters are allowed and sent quoted.
Core and Builtins
gh-133931: Fix data races when setting attributes of function objects on the free threaded build.

gh-154709: Fix an out-of-bounds access in reverse dictionary iterators when the underlying dictionary is cleared and modified after the iterator is created.

gh-154695: Fix asyncio.Task raising AttributeError when created with eager_start=True and no explicit loop argument.

gh-153809: Fix interpreter crash while deallocating objects of asyncio.Task on free-threaded builds. Contributed by Sergey Miryanov.

gh-154275: Fix a crash when getting deeply nested __parameters__ from a types.GenericAlias objects.

gh-153932: Fix thread safety issue in the __reduce__ method of enumerate.

gh-153298: Fixes a data race in types.GenericAlias __parameters__ initialization on free-threading builds.

gh-153205: Fix a potential SystemError during vector calls when memory allocation fails. A MemoryError is now raised instead.

gh-152682: Fix NULL pointer dereference in compile() when a reserved name (e.g. __classdict__) is used as a type parameter name and memory allocation fails while formatting the error message.

gh-152635: Fix a crash caused when running out of memory creating a _interpchannels channel. Now a MemoryError is correctly raised.

gh-152375: Fix undefined behaviour when a sys.monitoring callback raised an exception while the program was following a branch or loop.

gh-152235: Defer GC tracking of set.intersection(), set.difference(), set.symmetric_difference(), set.union() and set.__sub__. Patch by Donghee Na.

gh-152235: Defer GC tracking of a set or frozenset to the end of its construction from iterable. Patch by Donghee Na.

gh-152228: Fix an assertion failure when python is built in a debug mode that happened in str.replace() under a limited memory situation.

gh-151763: Fixes possible crash on types.CodeType deallocation.

gh-152020: On the free-threaded build, asyncio.all_tasks() no longer loses eager-started tasks when called from a thread other than the one running the event loop.

gh-151763: Fix a potential crash in compile(), exec(), eval() and ast.parse() when an allocation fails: the parser or compiler could return without setting an exception.

gh-151912: Fixed a crash in type() when selecting a metaclass whose tp_new slot is NULL. Such metaclasses are now rejected with TypeError instead of causing a NULL pointer dereference.

gh-151905: Fix OOM error handling in PyFrame_GetBack() to propagate exceptions instead of masking them as None.

gh-151773: Fix a crash in contextvars.ContextVar.set() when memory allocation fails.

gh-151126: Fix a crash when sharing memoryview objects between interpreters fails due to running out of memory. It now raises a proper MemoryError.

gh-151644: Fix a data race in sys.setdlopenflags() and sys.getdlopenflags() when called concurrently in the free-threaded build. The underlying _PyImport_GetDLOpenFlags and _PyImport_SetDLOpenFlags functions now use atomic load/store operations.

gh-151126: Avoid possible crash in _winapi.c where a device has no memory left. Now it properly raises a MemoryError. Patch by Ivy Xu.

gh-151546: Fix the stack limit check if Python is linked to musl (ex: Alpine Linux). Use the stack size set by the linker to compute the stack limits. Patch by Victor Stinner.

gh-151461: Fix direct execution of files with invalid source encodings to report the underlying codec lookup or decoding error instead of the generic SyntaxError: encoding problem message. Patch by Bartosz Sławecki.

gh-151218: PyConfig_Set() and sys.set_int_max_str_digits() now replace sys.flags (create a new object), instead of modifying sys.flags in-place. Patch by Victor Stinner.

gh-151253: If import encodings (first import) fails at Python startup, dump the Python path configuration to help users debugging their configuration. Patch by Victor Stinner.

gh-151238: Fix a crash when compiling a concatenated f-string or t-string if an error occurs when processing one of it’s parts.

gh-151126: Fix a crash, when there’s no memory left on a device, which happened in _interpchannels module.

Now it raises proper MemoryError errors.

gh-150902: Apply an existing optimization of PyCriticalSection (single mutex) to PyCriticalSection2: avoid acquiring the same locks that the current CS has already acquired.

gh-151065: Fix memory leak when using the mimalloc memory allocator.

gh-151029: On Linux, fix sys.remote_exec() unable to find remote writable memory when libpython replaced on disk.

gh-150988: Fix a reference leak in OSError when attributes are set before super().__init__().

gh-144774: Fix data race in BaseException when an exception is copied while being mutated.

gh-150411: Fix a data race in the free-threaded build when gc.get_count() reads the young generation allocation count while another thread updates it.

gh-149689: Fix missing error propagation in parser action helpers when memory allocation fails. Patch by Thomas Kowalski.

gh-149162: Fix a potential deadlock in PyUnicode_InternFromString() and other interning functions in the free-threaded build when called from C++ static local initializers.
Library
gh-155009: Fix argparse.ArgumentParser to preserve the program name from sys.argv[0] when a named module is executed as the main program without replacing sys.argv[0].

gh-155063: Bump the version of pip bundled in ensurepip to version 26.2.1

gh-155063: Bump the version of pip bundled in ensurepip to version 26.2

gh-154936: Fix the pure Python json decoder to report the correct position for invalid literal control characters in JSON strings.

gh-154892: Fix a bug in the C accelerator for zoneinfo where datetime.datetime subclasses returning -1 for hour, minute, or second could incorrectly raise a SystemError.

gh-154848: The pickle C accelerator now enforces frame boundaries when unpickling, as the pure Python implementation already did. An argument that straddles a frame boundary, or a frame that begins before the previous one has ended, now raises pickle.UnpicklingError instead of being silently read across the boundary. This prevents the loaded data from diverging from the pickletools disassembly of the same pickle.

gh-109638: Fix exponential time in csv.Sniffer.sniff() for a sample which contains many quote characters. A doubled quote character is now also detected in a field which contains the delimiter or a line break.

gh-98820: Fix quadratic time in csv.Sniffer.sniff() for a sample which contains quoted fields, in particular for a single column of quoted fields.

gh-154738: Fix ExternalEntityParserCreate() not propagating the reparse-deferral setting to the subparser, which left GetReparseDeferralEnabled() returning an uninitialized value. Patch by tonghuaroot.

gh-93251: Fix UnicodeDecodeError in socket functions (such as getaddrinfo() and gethostbyaddr()) when the localized error message of the C library is not UTF-8: decode it from the locale encoding.

gh-154551: Fix ctypes.util.find_library() returning None in non-UTF-8 locales.

gh-79366: Fixed a race condition in logging: if a handler was removed while a record was being emitted, the following handlers of the same logger could be skipped.

gh-73458: Fix logging.config.listen(): it left the caller waiting for the ready event forever if the server could not be started, for example if the port was invalid or already in use. It now also binds to an IPv6 address if the host has no IPv4 address, for example if localhost is only aliased to ::1.

gh-154460: Fix time.strftime() and datetime.datetime.strftime() returning a wrong ISO 8601 week number (%V) on OpenBSD.

gh-154435: Fix os.posix_fadvise() and os.posix_fallocate() on DragonFly BSD: they raised OSError with a meaningless error code, because these functions return -1 and set errno there.

gh-154399: Fix venv activation in a non-interactive csh: activate.csh no longer fails when the prompt variable is not set.

gh-154389: Fix uuid.uuid1() on OpenBSD: it returned a version 4 UUID, because uuid_create() generates random UUIDs on this platform.

gh-154324: Fix os.sendfile() on illumos: it no longer reports a successful transfer when the underlying system call failed without writing any data.

gh-154307: Fix tempfile.TemporaryDirectory.cleanup() on DragonFly BSD, where removing a file with the UF_NOUNLINK flag failed with EISDIR instead of EPERM.

gh-154291: Fix socket.has_dualstack_ipv6() to return False on platforms such as DragonFly BSD where setting IPV6_V6ONLY to 0 silently has no effect.

gh-154283: On DragonFly BSD, threading.get_native_id() now returns a value that is unique across processes, matching the other platforms.

gh-154258: Fix a crash in mmap.mmap.resize() on NetBSD when growing a shared anonymous mapping. resize() now raises ValueError in this case, as it already did on Linux.

gh-131565: ctypes.util.dllist() now works on NetBSD. It is implemented in the _ctypes extension module so that dl_iterate_phdr() reports all loaded shared libraries: on NetBSD it only reports the link-map group of the calling object, which excluded them when called through ctypes.

gh-154225: Fix os.openpty() on Solaris and illumos: it no longer leaves the pseudo-terminal as the controlling terminal of the calling process.

gh-154227: Fix os.posix_openpt() on OpenBSD, where it rejected the O_CLOEXEC flag.

gh-145030: Fix asyncio write pipe transports for named FIFOs on macOS and Solaris. Unread data sitting in the FIFO made the transport misinterpret a poll event as the reader disconnecting, wrongly closing the transport.

gh-154001: Fix random.binomialvariate() raising ZeroDivisionError when random.random() returns zero.

gh-153908: Fix data race when calling repr() on itertools.count under the free-threaded build.

gh-153896: Deduplicate unhashable args in typing.Literal.

gh-153864: On a wide curses build, curses.window.insch() now inserts a non-ASCII byte as the character it encodes in the window’s encoding, consistently with addch(), instead of its code point.

gh-153862: On a wide curses build, curses.window.inch() now returns the locale-encoded byte of a non-ASCII character, matching instr(), instead of the low byte of its code point.

gh-146011: Fix a heap-use-after-free in the C implementation of decimal when calling repr() after deleting the Context.

gh-153761: Fix cancelling asyncio.loop.sock_accept() dropping a pending connection.

gh-153695: Hashing a sqlite3.Row that contains an unhashable value now raises TypeError instead of SystemError. Patch by tonghuaroot.

gh-127049: Fix a race condition in asyncio on Unix where asyncio.subprocess.Process.send_signal(), terminate() or kill() could signal an unrelated process that was recycled onto the PID of the already-reaped child when ThreadedChildWatcher is used. Patch by Kumar Aditya.

gh-153658: Fix sqlite3.Connection.iterdump() raising sqlite3.OperationalError when a table name contains a single quote. Patch by tonghuaroot.

gh-85943: Fix struct functions raising BytesWarning under the -bb command line option when a str format is used after an equal bytes format (or vice versa). The internal format cache no longer mixes str and bytes keys.

gh-153404: urllib.robotparser.RobotFileParser now silently ignores a Crawl-delay or Request-rate value written with non-decimal digits (such as U+00B2 SUPERSCRIPT TWO) instead of raising ValueError and aborting the parse of the whole robots.txt file.

gh-153417: Error messages from imaplib.IMAP4.select() and imaplib.IMAP4.uid() no longer raise BytesWarning under -bb when the mailbox or command argument is bytes.

gh-153406: email.utils.parsedate_to_datetime() now raises ValueError instead of OverflowError when the parsed year or timezone offset is out of range, matching its documented behavior.

gh-153083: Defer GC tracking of an array.array to the end of its construction. Patch by Donghee Na.

gh-153292: Fix data race in repr of threading.RLock in free-threading build.

gh-143990: A tkinter.font.Font created from a named font, including by copy(), now copies its configured options rather than the options resolved by Tcl’s font actual, preserving a size specified in pixels (a negative size).

gh-148286: Fix undefined behavior in compression.zstd.ZstdDecompressor.unused_data when a complete frame was decompressed in a single call.

gh-153210: Fix crash on array import under a memory pressure.

gh-153200: Fix math.isqrt() returning an incorrect result for arguments not less than 2**64 that are instances of an int subclass with an overridden comparison operator.

gh-153068: Fix cProfile.Profile.enable() to no longer overwrite errors from sys.monitoring.

gh-153062: Fix a crash when concurrently iterating an itertools.tee() iterator on the free-threaded build.

gh-153056: Fix string.Template raising a spurious ValueError when the pattern attribute is a compiled regular expression object, which the documentation allows. On the free-threaded build this also occurred as a data race on the first concurrent use.

gh-153037: Fix ZstdFile raising AttributeError instead of io.UnsupportedOperation when iterating over a file that is not open for reading.

gh-135661: Fix html.parser.HTMLParser: an abruptly closed empty comment (<!--> or <!--->) no longer extends up to a later --> in the same feed() call.

gh-152851: Prevent a crash when allocation fails while copying a BLAKE-2s/2b object. Patch by Bénédikt Tran.

gh-54930: Error responses of http.server.BaseHTTPRequestHandler to malformed request lines now include a status line and headers instead of being sent in the bare HTTP/0.9 style. Only a valid HTTP/0.9 request (a two-word GET request line) now receives an HTTP/0.9 style response.

gh-119592: Fix concurrent.futures.ProcessPoolExecutor stranding submitted work forever when a worker process exited upon reaching its max_tasks_per_child limit after shutdown() was called with wait=False: a replacement worker is now spawned and the remaining work executed as documented. If the executor has instead been garbage collected without shutdown() (gh-152967), or a replacement worker cannot be started, the remaining futures now fail with BrokenProcessPool instead of never resolving. A worker exit racing shutdown(wait=False) can also no longer crash the executor management thread.

gh-152951: collections.deque prevent rare crash when calling extend under high memory pressure conditions.

gh-150880: Normalize non-extended Windows paths before appending the wildcard used by os.listdir() and os.scandir(), making paths with trailing spaces behave consistently with other filesystem APIs.

gh-152849: Out-of-range float and integer timestamps now raise OverflowError with the same message. Patch by tonghuaroot.

gh-152847: Reject a POSIX TZ transition rule with non-digit characters in the day-of-year field in the pure-Python zoneinfo parser. Patch by tonghuaroot.

gh-108280: Connecting imaplib to a server that does not send a valid IMAP4 greeting (for example a POP3 server answering on the IMAP port) now raises an error reporting the server’s response instead of imaplib.IMAP4.error: None.

gh-63121: imaplib now refreshes the cached capability list after a successful login() or authenticate(), using the CAPABILITY response sent by the server or, if none was sent, by querying it, so that capabilities that become available only after authentication (such as ENABLE on Gmail) are recognized. Capabilities advertised in the server greeting are now also used, avoiding a redundant CAPABILITY command.

gh-88574: imaplib no longer fails when a server sends a spurious blank line after the counted data of a literal, including after a literal that terminates a response (such as a mailbox name returned by LIST). Such blank lines are now skipped without swallowing the following line.

gh-152502: Detect the curses mouse interface (getmouse(), the BUTTON* constants, and others) with a configure capability probe or library macros instead of gating it on ncurses-specific macros. It is now also available with other curses implementations that provide it, such as NetBSD curses and PDCurses (the latter underpins windows-curses).

gh-151842: Fix a crash in _interpreters.capture_exception() when MemoryError happens. Patch by Amrutha Modela.

gh-40038: imaplib now again quotes command arguments when necessary, for example mailbox names containing a space. Such quoting was inadvertently disabled when the module was ported to Python 3, and the arguments are now quoted according to the RFC 3501 grammar. For backward compatibility, an argument already enclosed in double quotes is left unchanged, so code that quotes arguments itself keeps working.

gh-50966: Fix unbounded recursion in turtle when a mouse event handler that moves the turtle is reentered while the screen is being redrawn, for example with screen.ondrag(turtle.goto). This could previously crash the interpreter.

gh-152569: Fix asyncio.wait() leaking waiting tasks via the await-graph when racing a future that never resolves. The waiting task is now discarded from every future’s awaited_by set once wait() returns, even for pending futures.

gh-78335: Update the docstrings of tkinter and tkinter.ttk widget classes to list all supported widget options, including options added in Tk 9.0 and 9.1. tkinter.Menubutton and tkinter.Message previously had no option list at all.

gh-152431: Fix asyncio.StreamWriter.start_tls() to keep the linked StreamReader transport in sync with the upgraded transport.

gh-151126: Fix two crashes in tkinter and socket modules initialization under a memory pressure. Sets missing MemoryError.

gh-133031: curses.textpad.Textbox now enters and reads back the non-ASCII characters of an 8-bit locale encoding, instead of mangling them with a 7-bit mask.

gh-71880: curses.textpad.Textbox now lets the lower-right cell of the window be edited. Writing it with addch() would move the cursor past the end of the window, raising an error and scrolling a scrollable window, so it is now written with insch(), which keeps the cursor in place.

gh-83274: Deallocating a tkinter application from a thread other than the one it was created in no longer crashes the interpreter. The underlying Tcl interpreter is leaked instead, and a RuntimeWarning is reported.

gh-152305: Fix the pure-Python datetime.time.strftime() implementation raising AttributeError for the year directives. Patch by tonghuaroot.

gh-88758: tkinter.Misc.focus_get(), focus_displayof(), focus_lastfor() and winfo_containing() now return None instead of raising KeyError when the widget was not created by tkinter (for example a torn-off menu).

gh-38464: tkinter.Misc.nametowidget() now resolves the auto-generated names of cloned menus (a menu used as a menubar or a cascade) back to the original widget.

gh-152248: Make the C and pure-Python zoneinfo parsers validate POSIX TZ abbreviations consistently, rejecting unquoted abbreviations with non-letter characters and empty quoted abbreviations. Patch by tonghuaroot.

gh-80937: Fix a memory leak in tkinter when a Tcl command created with createcommand was not explicitly removed before the interpreter was deleted. The command no longer keeps the interpreter alive through a reference cycle.

gh-152246: Fix the pure-Python zoneinfo parser accepting an invalid POSIX TZ transition rule with a non-period separator. Patch by tonghuaroot.

gh-139816: Fix a hang in tkinter on interactive Python built without readline. An exception raised in a callback no longer causes the event loop to stop and wait for the user to press Enter; pending callbacks now keep running until input is actually available on stdin.

gh-139145: Fix a busy loop in tkinter on interactive Python. When a Tcl command running its own event loop (such as vwait or wait_variable()) was active and input arrived on stdin, the event loop kept spinning at 100% CPU. The stdin file handler is now removed as soon as input is available. Based on a patch by Michiel de Hoon.

gh-152212: Fix the pure-Python zoneinfo parser accepting a POSIX TZ string with a std abbreviation but no offset. This is invalid per POSIX and now raises ValueError, matching the C accelerator. Patch by tonghuaroot.

gh-152156: Fix a possible crash in concurrent.interpreters.create() under limited memory conditions.

gh-152157: The C implementations of fromisoformat() and fromisoformat() now reject a decimal separator that is not followed by any fractional digit before a timezone designator.

gh-151763: Fix crash in _interpqueues.create() whe MemoryError happens on queue creation.

gh-105895: Add match and case to the list of supported topics by help().

gh-152079: Fix datetime.datetime.fromisoformat() in the C implementation dropping the sub-second part of a UTC offset whose whole-second part is zero, matching the pure-Python implementation.

gh-152052: The json C accelerator now correctly reports an unterminated string for a \uXXXX escape at the end of the input.

gh-152060: Fix datetime.datetime.fromisoformat() raising AssertionError instead of ValueError for some malformed strings in the pure-Python implementation, matching the C implementation.

gh-126219: Fixed a crash in tkinter.Tk when className contains a non-BMP character and tkinter is built against Tcl/Tk 8.x. Such a name is now rejected with a ValueError.

gh-86165: Fix imaplib.Time2Internaldate() to use the local timezone offset for time.struct_time values with tm_gmtoff set to None, as returned by datetime.datetime.timetuple(). Contributed by Xiao Yuan.

gh-151814: Fix unbounded memory growth in io.TextIOWrapper when repeatedly writing an empty string.

gh-151770: Fix datetime.datetime.fromisoformat() raising AssertionError instead of ValueError for an out-of-range month combined with a 24:00 time.

gh-151665: inspect.signature() now works on the lazy evaluators of type aliases and type parameters instead of raising ValueError.

gh-151695: Fix a use-after-free in the curses module. The encoding of the initial screen, used by curses.unctrl() and curses.ungetch() to encode non-ASCII characters, is now kept as a private copy instead of a borrowed pointer to a window object that may be deallocated.

gh-151596: Add missing size positional argument to the pure-Python implementation of io.TextIOBase.readline().

gh-151640: Fix a data race in io.BytesIO in free-threaded builds when whole-buffer reads or peeks, or getvalue(), share the internal buffer with concurrent writes.

gh-148660: Fix a crash in collections.OrderedDict.copy() when a key’s __eq__ or a subclass method mutates the dict during the copy. Now raises RuntimeError instead, as iteration does.

gh-151497: Opening a tarfile archive no longer attempts to pre-allocate a huge buffer when a crafted or truncated member claims an oversized extended header (a GNU long name/link or a pax header). The extended header is now read in bounded chunks, so its size field can no longer trigger memory exhaustion.

gh-151403: Fixed a crash in subprocess.Popen (and _posixsubprocess.fork_exec) when an argv item’s __fspath__() concurrently mutates the args sequence being converted.

gh-151390: Colorize match in the REPL when followed by a unary + or - operator. Patch by Bartosz Sławecki.

gh-151126: Fix crash on unset MemoryError on allocation failure in ctypes.get_errno().

gh-151416: Fix a crash in os.spawnv() and os.spawnve() when an argv item’s __fspath__() method mutates the argv list during argument conversion. os.spawnv() argument conversion errors other than TypeError, such as the ValueError for an embedded null, are no longer replaced with a generic TypeError.

gh-151337: Avoid possible memory leak in tkinter.c on Windows.

gh-151126: Fix a crash when MemoryError in os._path_splitroot() was not set properly.

gh-151126: Fix a crash, when there’s no memory left on a device, which happened in _interpchannels module.

Now it raises proper MemoryError errors.

gh-119710: Fix asyncio subprocess wait() hanging when the process has exited but one of its pipes is kept open by an inherited child process (so the pipe never reaches EOF). wait() now returns as soon as the process exits, regardless of the pipes’ state.

gh-151295: Fixed a crash (use-after-free) in bytes.join() and bytearray.join() that could occur if an item’s __buffer__() concurrently mutates the sequence being joined. The mutation is now reported as a RuntimeError instead.

gh-109940: Fix Windows venv activation in cmd.exe to respect VIRTUAL_ENV_DISABLE_PROMPT.

gh-117807: Fix mimetypes initialization from MIME map files containing invalid UTF-8 bytes.

gh-150583: Correctly set the default compression level in compression.zstd when passing a digested dictionary during compression.

gh-150641: Fix bug where typing.evaluate_forward_ref() with the STRING format could leak internal names used by the annotation machinery.

gh-150484: Fix unittest.mock.mock_open() __exit__ raising TypeError when used with contextlib.ExitStack.

gh-149816: Fix a potential use after free condition in pickle.dumps() in free-threaded mode when serializing lists.

gh-149319: The asyncio REPL now ignores PYTHONSTARTUP and PYTHON_BASIC_REPL when -E or -I is used. Patch by Jonathan Dung.

gh-47005: Fix urllib.request.AbstractHTTPHandler.do_open() to give regular headers set via add_header() priority over unredirected headers, consistent with get_header() and header_items().

gh-123471: Make concurrent iteration over itertools.zip_longest safe under free-threading.

gh-123720: asyncio: Fix asyncio.Server.serve_forever() shutdown regression. Since 3.12, cancelling serve_forever() could hang waiting for a handler blocked on a read from a client that never closed (effectively requiring two interrupts to stop); the shutdown sequence now ensures client streams are closed so serve_forever() exits promptly and handlers observe EOF.

gh-123471: Make concurrent iteration over itertools.accumulate safe under free-threading.

gh-123471: Make concurrent iteration over itertools.combinations_with_replacement and itertools.permutations safe under free-threading.

gh-143988: Fixed crashes in socket.socket.sendmsg() and socket.socket.recvmsg_into() that could occur if buffer sequences are concurrently mutated.

gh-130796: Undeprecate the locale.getdefaultlocale() function. Patch by Victor Stinner.

gh-115634: Fix a deadlock in concurrent.futures.ProcessPoolExecutor when using max_tasks_per_child, present since the feature was introduced in Python 3.11. The executor stopped scheduling queued tasks after a worker process exited upon reaching its task limit. Based on a fix proposed by Tabrez Mohammed.

gh-140326: Fix the asyncio REPL namespace so that relative imports no longer resolve against the asyncio package and __file__ is no longer set.

gh-79638: Disallow all access in urllib.robotparser if the robots.txt file is unreachable due to server or network errors.

gh-123471: Make concurrent iterations over itertools.chain safe under free threading.

gh-123471: Make concurrent iterations over itertools.combinations and itertools.product safe under free-threading.

gh-123471: Make concurrent iterations over itertools.cycle safe under free-threading.

gh-120665: Fixed an issue where unittest loaders would load and instantiate unittest.TestCase-derived subclasses that are also abstract base classes, which can’t be instantiated.

gh-105708: Accept an uppercase V prefix in IPvFuture addresses in urllib.parse.urlsplit().

gh-103925: Fix csv.Sniffer.sniff() for a sample with \r\n line endings in which a quoted field ends a line: a letter could be detected as the delimiter.

gh-101267: When a worker process terminates unexpectedly, concurrent.futures.ProcessPoolExecutor now sets a separate BrokenProcessPool exception on each pending future instead of sharing a single instance among them all. Sharing one exception produced malformed tracebacks: each Future.result() call re-raised the same object, appending another copy of the traceback to it.
Documentation
gh-118150: Clarify in the difflib documentation what junk actually does, its drawbacks, and how to control it.
gh-86726: Greatly expand the tkinter documentation to cover the full public API of the package and its submodules. The descriptions are oriented towards Python rather than Tcl/Tk, with corrected return types and versionadded/versionchanged information.
Tests
gh-155109: Add test.support.run_with_limited_c_stack() and use it in tests that exhaust the C stack with a fixed number of recursive calls, so that their outcome no longer depends on the C stack size.
gh-76595: Add C API tests for PyCapsule_Import().
gh-154211: Add test.support.skip_if_huge_c_stack() and use it to skip tests that exhaust the C stack if the stack limit is very large (e.g. on DragonFly BSD or with ulimit -s unlimited).
gh-154167: The test runner (regrtest) now restores the default SIGINT handler if it was inherited as ignored, so the test suite no longer hangs when run as a shell background job.
gh-154144: Fix building the _testcapi module on NetBSD.
gh-152548: Add the test.support.isolation.runInSubprocess() decorator to run a test method or TestCase subclass in a fresh interpreter subprocess, isolated from the rest of the test run.
gh-151626: Fix several tests in test.test_inspect, test.test_import, test.test_importlib, test.test_py_compile and test.test_compileall that failed when the test suite was run with PYTHONPYCACHEPREFIX set. These tests now neutralize the pycache prefix where they assume the default __pycache__ bytecode layout.
gh-151096: Fix test_embed failing when CPython is configured with a split exec prefix (--exec-prefix differing from --prefix).
gh-148853: Fix tests failing on FreeBSD in test.support’s in_systemd_nspawn_sync_suppressed() due to unreadable /run directory.
Build
gh-154070: Build the curses module against a wide-character capable ncurses even when it is not named ncursesw – for example the pkgsrc ncurses on NetBSD and illumos, or the system ncurses on macOS. Such a library previously produced a narrow build.
gh-126877: Fix the configure check for Tcl/Tk which could wrongly succeed with optimizing compilers when the libraries are missing.
gh-153438: Update Windows build and installer tooling and documentation to use the current download URL for nuget.exe.
gh-152502: The curses module now detects set_escdelay(), set_tabsize() and the ESCDELAY and TABSIZE variables with configure capability probes instead of the ncurses-specific NCURSES_EXT_FUNCS macro, so they are exposed when building against other curses implementations such as NetBSD curses that provide them.
gh-148260: On Linux when Python is linked to the musl C library, use a thread stack size of at least 1 MiB instead of musl default which is 128 kiB. Patch by Victor Stinner.
gh-138800: Fix library name in python3.pc on Android.
Windows
gh-124111: Updated Windows builds to use Tcl/Tk 9.0.4.
gh-150836: Make installed tkinter work with Tcl/Tk 9 builds that embed the Tk script library in the Tk DLL on Windows.
gh-140146: Prevent tkinter from hanging on Windows if stdin is redirected to a pipe in an interactive session. This is helpful for testing interactive usage of tkinter from a script, for example as part of the cpython test suite.
macOS
gh-153711: On macOS, do not attempt to use the dup3(2) and pipe2(2) system calls introduced in macOS 27 to prevent problems when running on older systems.
gh-124111: Update macOS installer to use Tcl/Tk 9.0.4.
IDLE
gh-82183: When the shell is busy running code, using “Run… Customized” with “Restart shell” unchecked now reports that the shell is executing instead of restarting it anyway.
gh-83653: Blanking an integer entry in IDLE’s Settings dialog, such as “Auto squeeze min lines”, no longer saves an empty string as an invalid configuration value.
gh-65339: Saving the IDLE Shell or an Output window now defaults to a .txt extension and lists text files before Python files, since their content is not Python source.
gh-80504: The “In files:” field of IDLE’s Find in Files dialog now always contains a full directory path, even for an unsaved editor or the Shell. This shows in the grep output which directory was searched.
gh-134300: Do not add the idlelib directory to the path of the IDLE user process. User code run in IDLE can no longer import idlelib submodules as top-level modules, such as import help.
gh-89360: Fix a rare crash in the IDLE editor when the completion window is closed: deleting a key binding for a sequence that is not bound to the virtual event is now ignored instead of raising a ValueError.
gh-71956: Fix Replace All in the IDLE editor’s Replace dialog when the search direction is “Up” and “Wrap around” is off: it now replaces all matches above the current position instead of only the first one.
gh-152728: Move functions run.fix_scaling, editor.fixwordbreaks (as fix_word_breaks) and pyshell.fix_x11_paste to idlelib.util.
gh-66331: Set the WM_CLASS window property of IDLE’s windows to Idle on X11, so that window managers group and label them correctly instead of using the default Toplevel.
gh-85320: IDLE now reads and writes its configuration files and the breakpoints file using UTF-8 instead of the locale encoding. This keeps non-ASCII data (such as non-ASCII paths) from being corrupted and makes the files portable between environments.
gh-94523: Detect file if modified at local disk and prompt to ask refresh. Patch by Shixian Li.
gh-139551: Support rendering BaseExceptionGroup in IDLE.
gh-89520: Make IDLE extension configuration look at user config files, allowing user-installed extensions to have settings and key bindings defined in ~/.idlerc.
Tools/Demos
gh-155218: Fix Argument Clinic generating the flags of the optional groups in different order on 32-bit and 64-bit platforms.
gh-155207: Argument Clinic now supports the --dry-run and --diff options. They list the files which would be changed, or write a unified diff of the changes to the standard output, without modifying any file.
gh-154580: Fix python-gdb.py raising UnicodeEncodeError when pretty-printing a non-ASCII str in a locale whose host charset cannot encode it, such as any non-ASCII string in the C locale.
C API
gh-152132: Fix Py_RunMain() to return an exit code, rather than calling Py_Exit(), when running a script, a command, or the REPL. Patch by Victor Stinner.
gh-153300: PyConfig_Set() now also set global configuration variables. For example, PyConfig_Set("inspect", value) now also sets Py_InspectFlag. Patch by Victor Stinner.
gh-123619: PyUnstable_Object_EnableDeferredRefcount() now returns 0 if the object is not tracked by the garbage collector: if gc.is_tracked() is false. Patch by Victor Stinner.
@
text
@# $NetBSD: Makefile,v 1.15 2026/06/11 12:13:39 adam Exp $

.include "dist.mk"

PKGNAME=	python314-${PY_DISTVERSION}
CATEGORIES=	lang python

MAINTAINER=	pkgsrc-users@@NetBSD.org
HOMEPAGE=	https://www.python.org/
COMMENT=	Interpreted, interactive, object-oriented programming language
LICENSE=	python-software-foundation

CONFLICTS+=	python-[0-9]*

PLIST_AWK=		-f ${PKGSRCDIR}/lang/python/plist-python.awk
PLIST_AWK_ENV+=		PYVERS=314
PRINT_PLIST_AWK+=	/^[^@@]/ && /[^\/]+\.pyc$$/ {
PRINT_PLIST_AWK+=	sub(/__pycache__\//, "")
PRINT_PLIST_AWK+=	sub(/\.cpython-314/, "")}
PRINT_PLIST_AWK+=	/^[^@@]/ && /[^\/]+\.opt-1.pyc$$/ {
PRINT_PLIST_AWK+=	sub(/.opt-[12].pyc$$/, ".pyo")}

USE_CC_FEATURES=	c11
USE_LANGUAGES=		c c++
USE_TOOLS+=		gmake pkg-config
GNU_CONFIGURE=		yes
CONFIGURE_ARGS+=	--enable-shared
CONFIGURE_ARGS+=	--with-openssl=${BUILDLINK_PREFIX.openssl}
CONFIGURE_ARGS+=	--with-system-expat
CONFIGURE_ARGS+=	--without-ensurepip
CONFIGURE_ENV+=		OPT=${CFLAGS:M*:Q}
CONFIGURE_ENV+=		ac_cv_path_mkdir=${TOOLS_PATH.mkdir}
CONFIGURE_ENV+=		py_cv_module__gdbm="n/a"
# example module
CONFIGURE_ENV+=		py_cv_module_xxlimited="n/a"
PKGCONFIG_OVERRIDE+=	Misc/python.pc.in Misc/python-embed.pc.in

PTHREAD_OPTS+=	require
.include "../../mk/pthread.buildlink3.mk"

.include "../../mk/bsd.prefs.mk"

# NetBSD-8 curses has enough support for py-curses
USE_CURSES=		getsyx update_panels wide
# But we build as ncurses still to get the full feature set easily
.if ${OPSYS} == "NetBSD"
FAKE_NCURSES=		yes
## Force use of libuuid
CONFIGURE_ARGS+=	ac_cv_header_uuid_h=false
.endif

.if ${USE_CROSS_COMPILE:tl} == yes
TOOL_DEPENDS+=		${PKGNAME}:../../${PKGPATH}
CONFIGURE_ARGS+=	\
	--with-build-python=${TOOLBASE:Q}/bin/python${PY_VER_SUFFIX}
CONFIGURE_ARGS+=	MACHDEP=${PY_PLATNAME}
CONFIGURE_ARGS+=	\
	_PYTHON_HOST_PLATFORM=${LOWER_OPSYS}-${MACHINE_GNU_ARCH}
CONFIGURE_ARGS+=	ac_sys_system=${OPSYS}
.  if ${OPSYS} == "OSF1"
CONFIGURE_ARGS+=	ac_cv_buggy_getaddrinfo=true
.  else
CONFIGURE_ARGS+=	ac_cv_buggy_getaddrinfo=false
.  endif
CONFIGURE_ARGS.NetBSD+=	ac_cv_file__dev_ptmx=yes
CONFIGURE_ARGS.NetBSD+=	ac_cv_file__dev_ptc=no
.endif

# http://bugs.python.org/issue13241
.if ${MACHINE_PLATFORM:MDarwin-1[12].*}
PKGSRC_COMPILER=	clang
PKG_CC=			clang
PKG_CXX=		clang++
.endif

# Used in socketmodule.c to determine if a sethostname declaration is required
CFLAGS.SunOS+=		-DPKGSRC_OPSYS_VERSION=${OPSYS_VERSION}
LIBS.SunOS+=		-lrt	# fdatasync()

LIBS.DragonFly+=	-lcrypt
LIBS.NetBSD+=		-lcrypt

PY_VER_SUFFIX=		3.14

.include "platname.mk"
PLIST_SUBST+=	PY_PLATNAME=${PY_PLATNAME:Q}

# For Xcode 5 and up, we need to search the SDK path for headers, otherwise
# certain modules will not be built.
.if ${OPSYS} == "Darwin" && exists(${OSX_SDK_PATH:Q}/usr/include)
CFLAGS+=	-I${OSX_SDK_PATH:Q}/usr/include
.endif

LDFLAGS.SunOS+=	-lresolv

.for incdir in ${_OPSYS_INCLUDE_DIRS}
.  if exists(${incdir}/rpc/rpc.h)
HAVE_RPC_H=	yes
.  elif exists(${incdir}/tirpc/rpc/rpc.h)
CPPFLAGS+=	-I${incdir}/tirpc
HAVE_RPC_H=	yes
.  endif
.  if exists(${incdir}/rpcsvc/yp_prot.h)
HAVE_YP_PROT_H=	yes
.  elif exists(${incdir}/nsl/rpcsvc/yp_prot.h)
CPPFLAGS+=	-I${incdir}/nsl
HAVE_YP_PROT_H=	yes
.  endif
.endfor

PLIST_SUBST+=	PY_VER_SUFFIX=${PY_VER_SUFFIX:Q}

PRINT_PLIST_AWK+=	{ gsub(/${PY_PLATNAME}/, "$${PY_PLATNAME}") }
PRINT_PLIST_AWK+=	{ gsub(/python${PY_VER_SUFFIX}/, \
				"python$${PY_VER_SUFFIX}") }

TEST_TARGET=	test
INSTALL_TARGET=	altinstall

REPLACE_INTERPRETER+=	python
REPLACE.python.old=	.*python[^ ]*
REPLACE.python.new=	${PREFIX}/bin/python${PY_VER_SUFFIX}
REPLACE_FILES.python+=	Lib/base64.py
REPLACE_FILES.python+=	Lib/cProfile.py
REPLACE_FILES.python+=	Lib/encodings/rot_13.py
REPLACE_FILES.python+=	Lib/idlelib/pyshell.py
REPLACE_FILES.python+=	Lib/pdb.py
REPLACE_FILES.python+=	Lib/platform.py
REPLACE_FILES.python+=	Lib/profile.py
REPLACE_FILES.python+=	Lib/pydoc.py
REPLACE_FILES.python+=	Lib/quopri.py
REPLACE_FILES.python+=	Lib/smtplib.py
REPLACE_FILES.python+=	Lib/tabnanny.py
REPLACE_FILES.python+=	Lib/tarfile.py
REPLACE_FILES.python+=	Lib/test/bisect_cmd.py
REPLACE_FILES.python+=	Lib/test/crashers/recursive_call.py
REPLACE_FILES.python+=	Lib/test/curses_tests.py
REPLACE_FILES.python+=	Lib/test/re_tests.py
REPLACE_FILES.python+=	Lib/test/regrtest.py
REPLACE_FILES.python+=	Lib/test/support/smtpd.py
REPLACE_FILES.python+=	Lib/timeit.py
REPLACE_FILES.python+=	Lib/trace.py
REPLACE_FILES.python+=	Lib/turtledemo/__main__.py
REPLACE_FILES.python+=	Lib/turtledemo/bytedesign.py
REPLACE_FILES.python+=	Lib/turtledemo/clock.py
REPLACE_FILES.python+=	Lib/turtledemo/forest.py
REPLACE_FILES.python+=	Lib/turtledemo/fractalcurves.py
REPLACE_FILES.python+=	Lib/turtledemo/lindenmayer.py
REPLACE_FILES.python+=	Lib/turtledemo/minimal_hanoi.py
REPLACE_FILES.python+=	Lib/turtledemo/paint.py
REPLACE_FILES.python+=	Lib/turtledemo/peace.py
REPLACE_FILES.python+=	Lib/turtledemo/penrose.py
REPLACE_FILES.python+=	Lib/turtledemo/planet_and_moon.py
REPLACE_FILES.python+=	Lib/turtledemo/sorting_animate.py
REPLACE_FILES.python+=	Lib/turtledemo/tree.py
REPLACE_FILES.python+=	Lib/turtledemo/yinyang.py
REPLACE_FILES.python+=	Lib/webbrowser.py

# XXX: It might be needed to add manually more paths like ${PREFIX}/qt5/lib
# Test: python -c 'from ctypes.util import find_library; print(find_library("ffi"));'
SUBST_CLASSES+=		findlib
SUBST_MESSAGE.findlib=	Fixing find_library().
SUBST_STAGE.findlib=	pre-configure
SUBST_FILES.findlib=	Lib/ctypes/macholib/dyld.py
SUBST_FILES.findlib+=	Lib/ctypes/util.py
SUBST_SED.findlib=	-e 's,/usr/local,${PREFIX},'
SUBST_SED.findlib+=	-e "s!\('-Wl,-t'\)!'${COMPILER_RPATH_FLAG}${PREFIX}/lib', '-L${PREFIX}/lib', \1!"
SUBST_NOOP_OK.findlib=	yes

.include "options.mk"

CHECK_INTERPRETER_SKIP+=	lib/python${PY_VER_SUFFIX}/test/archivetestdata/exe_with_z64
CHECK_INTERPRETER_SKIP+=	lib/python${PY_VER_SUFFIX}/test/archivetestdata/exe_with_zip
CHECK_INTERPRETER_SKIP+=	lib/python${PY_VER_SUFFIX}/test/archivetestdata/header.sh
CHECK_INTERPRETER_SKIP+=	lib/python${PY_VER_SUFFIX}/test/ziptestdata/exe_with_z64
CHECK_INTERPRETER_SKIP+=	lib/python${PY_VER_SUFFIX}/test/ziptestdata/exe_with_zip
CHECK_INTERPRETER_SKIP+=	lib/python${PY_VER_SUFFIX}/test/ziptestdata/header.sh
CHECK_INTERPRETER_SKIP+=	lib/python${PY_VER_SUFFIX}/venv/scripts/posix/pydoc

# contain CONFIGURE_ARGS and CONFIGURE_ENV
CHECK_WRKREF_SKIP+=	lib/python${PY_VER_SUFFIX}/_sysconfig*
CHECK_WRKREF_SKIP+=	lib/python${PY_VER_SUFFIX}/__pycache__/_sysconfigdata*
CHECK_WRKREF_SKIP+=	lib/python${PY_VER_SUFFIX}/config-${PY_VER_SUFFIX}/Makefile

INSTALLATION_DIRS+=	lib/python${PY_VER_SUFFIX}/site-packages

pre-install: setuptools-preinstall
.PHONY: setuptools-preinstall
setuptools-preinstall:
	${INSTALL_DATA} ${.CURDIR}/../../devel/py-setuptools/files/_distutils_system_mod \
		${DESTDIR}${PREFIX}/lib/python${PY_VER_SUFFIX}/site-packages/_distutils_system_mod.py

# for testing
ALLOW_NETWORK_ACCESS=	yes
# test status as of 3.14.0
# Total test files: run=499/491 failed=10 skipped=31 resource_denied=2 rerun=10

.if ${OPSYS} == "Linux"
.include "../../databases/gdbm_compat/buildlink3.mk"
.endif
.include "../../archivers/bzip2/buildlink3.mk"
.include "../../archivers/xz/buildlink3.mk"
.include "../../archivers/zstd/buildlink3.mk"
.include "../../databases/sqlite3/buildlink3.mk"
.include "../../devel/gettext-lib/buildlink3.mk"
.if ${USE_BUILTIN.gettext:U:tl} == no
CONFIGURE_ENV+=		ac_cv_lib_intl_textdomain=yes
.endif
.include "../../devel/libffi/buildlink3.mk"
.include "../../devel/libuuid/buildlink3.mk"
.include "../../devel/zlib/buildlink3.mk"
.include "../../security/openssl/buildlink3.mk"
.include "../../math/mpdecimal/buildlink3.mk"
.if ${OPSYS} == NetBSD && ${OPSYS_VERSION} < 119905
PREFER.expat=	pkgsrc # needs expat_config.h
.endif
.include "../../textproc/expat/buildlink3.mk"
.include "../../mk/atomic64.mk"
.include "../../mk/bdb.buildlink3.mk"
.include "../../mk/curses.buildlink3.mk"
.include "../../mk/dlopen.buildlink3.mk"
.include "../../mk/oss.buildlink3.mk"
.include "../../mk/bsd.pkg.mk"
@


1.15
log
@python314 py314-html-docs: updated to 3.14.6

Python 3.14.6

Security
gh-151159: Update Android and iOS installers to use OpenSSL 3.5.7.
gh-150599: Fix a possible stack buffer overflow in bz2 when a bz2.BZ2Decompressor is reused after a decompression error. The decompressor now becomes unusable after libbz2 reports an error.
gh-149835: shutil.move() now resolves symlinks via os.path.realpath() when checking whether the destination is inside the source directory, preventing a symlink-based bypass of that guard.
gh-149698: Update bundled libexpat to version 2.8.1 for the fix for CVE 2026-45186.
gh-87451: The ftplib module’s undocumented ftpcp function no longer trusts the IPv4 address value returned from the source server in response to the PASV command by default, completing the fix for CVE-2021-4189. As with ftplib.FTP, the former behavior can be re-enabled by setting the trust_server_pasv_ipv4_address attribute on the source ftplib.FTP instance to True. Thanks to Qi Deng at Aurascape AI for the report.
gh-149486: tarfile.data_filter() now validates link targets using the same normalised value that is written to disk, strips trailing separators from the member name when resolving a symlink’s directory, and rejects link members that would replace the destination directory itself. This closes several path-traversal bypasses of the data extraction filter.
gh-149079: Fix a potential denial of service in unicodedata.normalize(). The canonical ordering step of Unicode normalization used a quadratic-time insertion sort for reordering combining characters, which could be exploited with crafted input containing many combining characters in non-canonical order. Replaced with a linear-time counting sort for long runs.
gh-149018: Improved protection against XML hash-flooding attacks in xml.parsers.expat and xml.etree.ElementTree when Python is compiled with libExpat 2.8.0 or later.
Core and Builtins
gh-151112: Fix a crash in the compiler that could occur when running out of memory.

gh-151126: Fix a crash, when there’s no memory left on a device, which happened in:

code compilation - _winapi.CreateProcess()
Now these places raise proper MemoryError errors.

gh-150700: Fix a SystemError when compiling a class-scope comprehension containing a lambda that references __class__, __classdict__, or __conditional_annotations__. Patch by Bartosz Sławecki.

gh-150633: Fix the frozen importer accepting module names with embedded null bytes, which caused it to bypass the sys.modules cache and create duplicate module objects.

gh-148613: Fix a data race in the free-threaded build between gc.set_threshold() and garbage collection scheduling during object allocation.

gh-149156: Fix an intermittent crash after os.fork() when perf trampoline profiling is enabled and the child returns through trampoline frames inherited from the parent process.

gh-149449: Fix a use-after-free crash when the unicodedata module was removed from sys.modules and garbage-collected between calls that decode \N{...} escapes or use the namereplace codec error handler.

gh-150207: Fix a crash when a memory allocation fails during tokenizer initialization. A proper MemoryError is now raised instead.

gh-150107: asyncio: sendfile() and sock_sendfile() event loop methods now call file.seek(offset) if file has a seek() method, even if offset is 0 (default value).

gh-150146: Fix a crash on a complex type variable substitution.

from typing import TypeVar; memoryview[TypeVar("")][*typing.Mapping[..., ...]] used to fail due to missing NULL check on _unpack_args C function call.

gh-149590: Fix crash when faulthandler is imported more than once.

gh-149816: Fix a race condition in _PyBytes_FromList in free-threading mode.

gh-149816: Fix a race condition in memoryview with free-threading.

gh-149805: Fix a SystemError when compiling a compiling __classdict__ class annotation.

gh-149738: sqlite3: Disallow removing row_factory and text_factory attributes of a connection to prevent a crash on a query.

gh-139808: Add branch protections for AArch64 (BTI/PAC) in assembly code used by -X perf_jit (Linux perf profiler integration).

gh-148450: Fix abc.register() so it invalidates type version tags for registered classes.
Library
gh-151039: Fix a crash when static datetime types outlive the _datetime module.
gh-150913: Fix sqlite3.Blob slice assignment to raise TypeError and IndexError for type and size mismatches respectively, even when the target slice is empty.
gh-143008: Fix race conditions when re-initializing a io.TextIOWrapper object.
gh-150750: Fix a race condition in collections.deque.index() with free-threading.
gh-150685: Update bundled pip to 26.1.2
gh-150406: Fix a possible crash occurring during socket module initialization when the system is out of memory on platforms without a reentrant gethostbyname.
gh-150372: readline: Fix a potential crash during tab completion caused by an out-of-memory error during module initialization.
gh-150157: Fix a crash in free-threaded builds that occurs when pickling by name objects without a __module__ attribute while sys.modules is concurrently being modified.
gh-150175: Fix race condition in unittest.mock.ThreadingMock where concurrent calls could lose increments to call_count and other attributes due to a missing lock in _increment_mock_call.
gh-84353: Preserve non-UTF-8 encoded filenames when appending to a zipfile.ZipFile. Previously, non-ASCII names stored in a legacy encoding (without the UTF-8 flag bit set) could be corrupted when the central directory was rewritten: they were decoded as cp437 and then re-stored as UTF-8.
gh-149816: Fix race condition in ssl.SSLContext.sni_callback
gh-149995: Update various docstrings in typing.
gh-88726: The email package now uses standard MIME charset names “gb2312” and “big5” instead of non-standard names “eucgb2312_cn” and “big5_tw”.
gh-149571: Fix the C implementation of xml.etree.ElementTree.Element.itertext(): it no longer emits text for comments and processing instructions.
gh-149921: Fix reference leaks in error paths of the _interpchannels and _interpqueues extension modules.
gh-149816: Fix a race condition in _random.Random.__init__ method in free-threading mode.
gh-149801: Add IANA registered names and aliases with leading zeros before number (like IBM00858, CP00858, IBM01140, CP01140) for corresponding codecs.
gh-149701: Fix bad return code from Lib/venv/bin/activate if hashing is disabled
gh-112821: In the REPL, autocompletion might run arbitrary code in the getter of a descriptor. If that getter raised an exception, autocompletion would fail to present any options for the entire object. Autocompletion now works as expected for these objects.
gh-149489: Fix ElementTree serialization to HTML. The content of elements “xmp”, “iframe”, “noembed”, “noframes”, and “plaintext” is no longer escaped. The “plaintext” element no longer have the closing tag.
gh-149231: In tomllib, the number of parts in TOML keys is now limited.
gh-149046: io: Fix io.StringIO serialization: no longer call str(obj) on str subclasses. Patch by Thomas Kowalski.
gh-148954: Fix XML injection vulnerability in xmlrpc.client.dumps() where the methodname was not being escaped before interpolation into the XML body.
gh-148441: xml.parsers.expat: prevent a crash in CharacterDataHandler() when the character data size exceeds the parser’s buffer size.
gh-146452: Fix segfault in pickle when pickling a dictionary concurrently mutated by another thread in the free-threaded build.
gh-142831: Fix a crash in the json module where a use-after-free could occur if the object being encoded is modified during serialization.
gh-90949: Add SetBillionLaughsAttackProtectionActivationThreshold() and SetBillionLaughsAttackProtectionMaximumAmplification() to xmlparser objects to tune protections against billion laughs attacks. Patch by Bénédikt Tran.
gh-134261: zip: On reproducible builds, ZipFile uses UTC instead of the local time when writing file datetimes to avoid underflows.
gh-128110: Fix bug in the parsing of email address headers that could result in extraneous spaces in the decoded text when using a modern email policy. Space between pairs of adjacent RFC 2047 encoded-words is now ignored, per section 6.2 (and consistent with existing parsing of unstructured headers like Subject).
gh-107398: Fix tarfile stream mode exception when process the file with the gzip extra field.
gh-123853: Update the table of Windows language code identifiers (LCIDs) used by locale.getdefaultlocale() on Windows to protocol version 16.0 (2024-04-23).
gh-91099: imaplib.IMAP4.login() now raises exceptions with str instead of bytes. Patch by Florian Best.
Documentation
gh-150319: Generic builtin and standard library types now document the meaning of their type parameters.
gh-109503: Fix documentation for shutil.move() on usage of os.rename() since nonatomic move might be used even if the files are on the same filesystem. Patch by Fang Li
Tests
gh-151130: Add more tests for PyWeakref_* C API.
gh-149776: Fix test_socket on Linux kernel 7.1 and newer: skip UDP Lite tests if it’s not supported. Patch by Victor Stinner.
Build
gh-148294: Corrected the use of AC_PATH_TOOL in configure.ac to allow a C++ compiler to be found on PATH.
Windows
gh-151159: Updated bundled version of OpenSSL to 3.5.7.
macOS
gh-151159: Update macOS installer to use OpenSSL 3.5.7.
gh-150644: When system logging is enabled (with config.use_system_logger, messages are now tagged as public. This allows the macOS 26 system logger to view messages without special configuration.
gh-115119: Update macOS installer to use libmpdecimal 4.0.1.
IDLE
bpo-6699: Warn the user if a file will be overwritten when saving.
C API
gh-150907: Fix dynamic_annotations.h header file when built with C++ and Valgrind: add extern "C++" scope for the C++ template. Patch by Victor Stinner.
gh-145235: Made PyDict_AddWatcher(), PyDict_ClearWatcher(), PyDict_Watch(), and PyDict_Unwatch() thread-safe on the free threaded build.
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.14 2026/05/18 21:23:27 wiz Exp $
d23 1
d25 1
a25 2
USE_TOOLS+=		pkg-config
USE_CC_FEATURES+=	c11
a84 4
.if ${OPSYS} == "Darwin" || ${OPSYS} == "SunOS"
USE_TOOLS+=	gmake
.endif

@


1.14
log
@python314: fix terminfo support in REPL

Bump PKGREVISION.
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.13 2026/03/25 22:52:08 wiz Exp $
a5 1
PKGREVISION=	1
@


1.13
log
@python*: restrict expat workaround to NetBSD<11.99.5

that version installs expat_config.h

Pullups for 10, 11 have been filed, the pattern can be improved
when they are merged.
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.12 2026/03/20 14:01:10 adam Exp $
d6 1
@


1.12
log
@python31*: force use expat from pkgsrc to fix builds across platforms
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.11 2026/02/03 20:30:46 adam Exp $
d218 1
d220 1
@


1.11
log
@python314 py314-html-docs: updated to 3.14.3

Python 3.14.3

Windows
gh-128067: Fix a bug in PyREPL on Windows where output without a trailing newline was overwritten by the next prompt.
Tools/Demos
gh-142095: Make gdb ‘py-bt’ command use frame from thread local state when available. Patch by Sam Gross and Victor Stinner.
Tests
gh-144415: The Android testbed now distinguishes between stdout/stderr messages which were triggered by a newline, and those triggered by a manual call to flush. This fixes logging of progress indicators and similar content.
gh-143460: Skip tests relying on infinite recusion if stack size is unlimited.
gh-65784: Add support for parametrized resource wantobjects in regrtests, which allows to run Tkinter tests with the specified value of tkinter.wantobjects, for example -u wantobjects=0.
gh-143553: Add support for parametrized resources, such as -u xpickle=2.7.
gh-142836: Accommodated Solaris in test_pdb.test_script_target_anonymous_pipe.
bpo-31391: Forward-port test_xpickle from Python 2 to Python 3 and add the resource back to test’s command line.
Security
gh-144125: BytesGenerator will now refuse to serialize (write) headers that are unsafely folded or delimited; see verify_generated_headers. (Contributed by Bas Bloemsaat and Petr Viktorin in gh-121650).
gh-143935: Fixed a bug in the folding of comments when flattening an email message using a modern email policy. Comments consisting of a very long sequence of non-foldable characters could trigger a forced line wrap that omitted the required leading space on the continuation line, causing the remainder of the comment to be interpreted as a new header field. This enabled header injection with carefully crafted inputs.
gh-143925: Reject control characters in data: URL media types.
gh-143919: Reject control characters in http.cookies.Morsel fields and values.
gh-143916: Reject C0 control characters within wsgiref.headers.Headers fields, values, and parameters.
Library
gh-144380: Improve performance of io.BufferedReader line iteration by ~49%.
gh-144169: Fix three crashes when non-string keyword arguments are supplied to objects in the ast module.
gh-144100: Fixed a crash in ctypes when using a deprecated POINTER(str) type in argtypes. Instead of aborting, ctypes now raises a proper Python exception when the pointer target type is unresolved.
gh-144050: Fix stat.filemode() in the pure-Python implementation to avoid misclassifying invalid mode values as block devices.
gh-144023: Fixed validation of file descriptor 0 in posix functions when used with follow_symlinks parameter.
gh-143999: Fix an issue where inspect.getgeneratorstate() and inspect.getcoroutinestate() could fail for generators wrapped by types.coroutine() in the suspended state.
gh-143831: annotationlib.ForwardRef objects are now hashable when created from annotation scopes with closures. Previously, hashing such objects would throw an exception. Patch by Bartosz Sławecki.
gh-143874: Fixed a bug in pdb where expression results were not sent back to remote client.
gh-143880: Fix data race in functools.partial() in the free threading build.
gh-143706: Fix multiprocessing forkserver so that sys.argv is correctly set before __main__ is preloaded. Previously, sys.argv was empty during main module import in forkserver child processes. This fixes a regression introduced in 3.13.8 and 3.14.1. Root caused by Aaron Wieczorek, test provided by Thomas Watson, thanks!
gh-143638: Forbid reentrant calls of the pickle.Pickler and pickle.Unpickler methods for the C implementation. Previously, this could cause crash or data corruption, now concurrent calls of methods of the same object raise RuntimeError.
gh-78724: Raise RuntimeError’s when user attempts to call methods on half-initialized Struct objects, For example, created by Struct.__new__(Struct). Patch by Sergey B Kirpichev.
gh-143196: Fix crash when the internal encoder object returned by undocumented function json.encoder.c_make_encoder() was called with non-zero second (_current_indent_level) argument.
gh-143191: _thread.stack_size() now raises ValueError if the stack size is too small. Patch by Victor Stinner.
gh-143602: Fix a inconsistency issue in write() that leads to unexpected buffer overwrite by deduplicating the buffer exports.
gh-143547: Fix sys.unraisablehook() when the hook raises an exception and changes sys.unraisablehook(): hold a strong reference to the old hook. Patch by Victor Stinner.
gh-143517: annotationlib.get_annotations() no longer raises a SyntaxError when evaluating a stringified starred annotation that starts with one or more whitespace characters followed by a *. Patch by Bartosz Sławecki.
gh-143378: Fix use-after-free crashes when a BytesIO object is concurrently mutated during write() or writelines().
gh-143346: Fix incorrect wrapping of the Base64 data in plistlib._PlistWriter when the indent contains a mix of tabs and spaces.
gh-143310: tkinter: fix a crash when a Python list is mutated during the conversion to a Tcl object (e.g., when setting a Tcl variable). Patch by Bénédikt Tran.
gh-143309: Fix a crash in os.execve() on non-Windows platforms when given a custom environment mapping which is then mutated during parsing. Patch by Bénédikt Tran.
gh-143308: pickle: fix use-after-free crashes when a PickleBuffer is concurrently mutated by a custom buffer callback during pickling. Patch by Bénédikt Tran and Aaron Wieczorek.
gh-143237: Fix support of named pipes in the rotating logging handlers.
gh-143249: Fix possible buffer leaks in Windows overlapped I/O on error handling.
gh-143241: zoneinfo: fix infinite loop in ZoneInfo.from_file when parsing a malformed TZif file. Patch by Fatih Celik.
gh-142830: sqlite3: fix use-after-free crashes when the connection’s callbacks are mutated during a callback execution. Patch by Bénédikt Tran.
gh-143200: xml.etree.ElementTree: fix use-after-free crashes in __getitem__() and __setitem__() methods of Element when the element is concurrently mutated. Patch by Bénédikt Tran.
gh-142195: Updated timeout evaluation logic in subprocess to be compatible with deterministic environments like Shadow where time moves exactly as requested.
gh-142164: Fix the ctypes bitfield overflow error message to report the correct offset and size calculation.
gh-143145: Fixed a possible reference leak in ctypes when constructing results with multiple output parameters on error.
gh-122431: Corrected the error message in readline.append_history_file() to state that nelements must be non-negative instead of positive.
gh-143004: Fix a potential use-after-free in collections.Counter.update() when user code mutates the Counter during an update.
gh-143046: The asyncio REPL no longer prints copyright and version messages in the quiet mode (-q). Patch by Bartosz Sławecki.
gh-140648: The asyncio REPL now respects the -I flag (isolated mode). Previously, it would load and execute PYTHONSTARTUP even if the flag was set. Contributed by Bartosz Sławecki.
gh-142991: Fixed socket operations such as recvfrom() and sendto() for FreeBSD divert(4) socket.
gh-143010: Fixed a bug in mailbox where the precise timing of an external event could result in the library opening an existing file instead of a file it expected to create.
gh-142881: Fix concurrent and reentrant call of atexit.unregister().
gh-112127: Fix possible use-after-free in atexit.unregister() when the callback is unregistered during comparison.
gh-142783: Fix zoneinfo use-after-free with descriptor _weak_cache. a descriptor as _weak_cache could cause crashes during object creation. The fix ensures proper reference counting for descriptor-provided objects.
gh-142754: Add the ownerDocument attribute to xml.dom.minidom elements and attributes created by directly instantiating the Element or Attr class. Note that this way of creating nodes is not supported; creator functions like xml.dom.Document.documentElement() should be used instead.
gh-142784: The asyncio REPL now properly closes the loop upon the end of interactive session. Previously, it could cause surprising warnings. Contributed by Bartosz Sławecki.
gh-142555: array: fix a crash in a[i] = v when converting i to an index via i.__index__ or i.__float__ mutates the array.
gh-142594: Fix crash in TextIOWrapper.close() when the underlying buffer’s closed property calls detach().
gh-142451: hmac: Ensure that the HMAC.block_size attribute is correctly copied by HMAC.copy. Patch by Bénédikt Tran.
gh-142495: collections.defaultdict now prioritizes __setitem__() when inserting default values from default_factory. This prevents race conditions where a default value would overwrite a value set before default_factory returns.
gh-142651: unittest.mock: fix a thread safety issue where Mock.call_count may return inaccurate values when the mock is called concurrently from multiple threads.
gh-142595: Added type check during initialization of the decimal module to prevent a crash in case of broken stdlib. Patch by Sergey B Kirpichev.
gh-142556: Fix crash when a task gets re-registered during finalization in asyncio. Patch by Kumar Aditya.
gh-123241: Avoid reference count operations in garbage collection of ctypes objects.
gh-142517: The non-compat32 email policies now correctly handle refolding encoded words that contain bytes that can not be decoded in their specified character set. Previously this resulted in an encoding exception during folding.
gh-112527: The help text for required options in argparse no longer extended with “ (default: None)”.
gh-142346: Fix usage formatting for mutually exclusive groups in argparse when they are preceded by positional arguments or followed or intermixed with other optional arguments.
gh-142315: Pdb can now run scripts from anonymous pipes used in process substitution. Patch by Bartosz Sławecki.
gh-142332: Fix usage formatting for positional arguments in mutually exclusive groups in argparse. in argparse.
gh-142282: Fix winreg.QueryValueEx() to not accidentally read garbage buffer under race condition.
gh-75949: Fix argparse to preserve | separators in mutually exclusive groups when the usage line wraps due to length.
gh-142267: Improve argparse performance by caching the formatter used for argument validation.
gh-68552: MisplacedEnvelopeHeaderDefect and Missing header name defects are now correctly passed to the handle_defect method of policy in FeedParser.
gh-142006: Fix a bug in the email.policy.default folding algorithm which incorrectly resulted in a doubled newline when a line ending at exactly max_line_length was followed by an unfoldable token.
gh-105836: Fix asyncio.run_coroutine_threadsafe() leaving underlying cancelled asyncio task running.
gh-139971: pydoc: Ensure that the link to the online documentation of a stdlib module is correct.
gh-139262: Some keystrokes can be swallowed in the new PyREPL on Windows, especially when used together with the ALT key. Fix by Chris Eibl.
gh-138897: Improved license/copyright/credits display in the REPL: now uses a pager.
gh-79986: Add parsing for References and In-Reply-To headers to the email library that parses the header content as lists of message id tokens. This prevents them from being folded incorrectly.
gh-136282: Add support for UNNAMED_SECTION when creating a section via the mapping protocol access
gh-109263: Starting a process from spawn context in multiprocessing no longer sets the start method globally.
gh-133253: Fix thread-safety issues in linecache.
gh-132715: Skip writing objects during marshalling once a failure has occurred.
IDLE
gh-143774: Better explain the operation of Format / Format Paragraph.
Documentation
gh-140806: Add documentation for enum.bin().
Core and Builtins
gh-144307: Prevent a reference leak in module teardown at interpreter finalization.
gh-144194: Fix error handling in perf jitdump initialization on memory allocation failure.
gh-144012: Check if the result is NULL in BINARY_OP_EXTENT opcode.
gh-141805: Fix crash in set when objects with the same hash are concurrently added to the set after removing an element with the same hash while the set still contains elements with the same hash.
gh-143670: Fixes a crash in ga_repr_items_list function.
gh-143377: Fix a crash in _interpreters.capture_exception() when the exception is incorrectly formatted. Patch by Bénédikt Tran.
gh-136924: The interactive help mode in the REPL no longer incorrectly syntax highlights text input as Python code. Contributed by Olga Matoula.
gh-143189: Fix crash when inserting a non-str key into a split table dictionary when the key matches an existing key in the split table but has no corresponding value in the dict.
gh-143228: Fix use-after-free in perf trampoline when toggling profiling while threads are running or during interpreter finalization with daemon threads active. The fix uses reference counting to ensure trampolines are not freed while any code object could still reference them. Pach by Pablo Galindo
gh-142664: Fix a use-after-free crash in memoryview.__hash__ when the __hash__ method of the referenced object mutates that object or the view. Patch by Bénédikt Tran.
gh-142557: Fix a use-after-free crash in bytearray.__mod__ when the bytearray is mutated while formatting the %-style arguments. Patch by Bénédikt Tran.
gh-143195: Fix use-after-free crashes in bytearray.hex() and memoryview.hex() when the separator’s __len__() mutates the original object. Patch by Bénédikt Tran.
gh-142975: Fix crash after unfreezing all objects tracked by the garbage collector on the free threaded build.
gh-143135: Set sys.flags.inspect to 1 when PYTHONINSPECT is 0. Previously, it was set to 0 in this case.
gh-143003: Fix an overflow of the shared empty buffer in bytearray.extend() when __length_hint__() returns 0 for non-empty iterator.
gh-143006: Fix a possible assertion error when comparing negative non-integer float and int with the same number of bits in the integer part.
gh-143057: Avoid locking in PyTraceMalloc_Track() and PyTraceMalloc_Untrack() when tracemalloc is not enabled.
gh-142776: Fix a file descriptor leak in import.c
gh-142829: Fix a use-after-free crash in contextvars.Context comparison when a custom __eq__ method modifies the context via set().
gh-142766: Clear the frame of a generator when generator.close() is called.
gh-142737: Tracebacks will be displayed in fallback mode even if io.open() is lost. Previously, this would crash the interpreter. Patch by Bartosz Sławecki.
gh-142554: Fix a crash in divmod() when _pylong.int_divmod() does not return a tuple of length two exactly. Patch by Bénédikt Tran.
gh-142560: Fix use-after-free in bytearray search-like methods (find(), count(), index(), rindex(), and rfind()) by marking the storage as exported which causes reallocation attempts to raise BufferError. For contains(), split(), and rsplit() the buffer protocol is used for this.
gh-142531: Fix a free-threaded GC performance regression. If there are many untracked tuples, the GC will run too often, resulting in poor performance. The fix is to include untracked tuples in the “long lived” object count. The number of frozen objects is also now included since the free-threaded GC must scan those too.
gh-142402: Fix reference counting when adjacent literal parts are merged while constructing string.templatelib.Template, preventing the displaced string object from leaking.
gh-133932: Fix crash in the free threading build when clearing frames that hold tagged integers.
gh-142343: Fix SIGILL crash on m68k due to incorrect assembly constraint.
gh-100964: Fix reference cycle in exhausted generator frames. Patch by Savannah Ostrowski.
gh-69605: Fix edge-cases around already imported modules in the REPL auto-completion of imports.
gh-138568: Adjusted the built-in help() function so that empty inputs are ignored in interactive mode.
gh-137007: Fix a bug during JIT compilation failure which caused garbage collection debug assertions to fail.
C API
gh-142589: Fix PyUnstable_Object_IsUniqueReferencedTemporary() handling of tagged ints on the interpreter stack.
gh-142571: PyUnstable_CopyPerfMapFile() now checks that opening the file succeeded before flushing.
Build
gh-142454: When calculating the digest of the JIT stencils input, sort the hashed files by filenames before adding their content to the hasher. This ensures deterministic hash input and hence deterministic hash, independent on filesystem order.
gh-141808: When running make clean-retain-profile, keep the generated JIT stencils. That way, the stencils are not generated twice when Profile-guided optimization (PGO) is used. It also allows distributors to supply their own pre-built JIT stencils.
gh-138061: Ensure reproducible builds by making JIT stencil header generation deterministic.
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.10 2026/01/07 08:47:41 wiz Exp $
d29 1
a30 1
CONFIGURE_ARGS+=	--without-system-expat # requires expat_config.h
d218 2
@


1.10
log
@*: recursive bump for icu 78.1
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.9 2025/12/04 15:21:11 adam Exp $
a2 1
PKGREVISION= 1
@


1.9
log
@python314: do not use system expat - it is not portable anymore
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.8 2025/12/02 21:34:37 adam Exp $
d3 1
@


1.8
log
@python314 py314-html-docs: updated to 3.14.1

Python 3.14.1

Windows

gh-139810: Installing with py install 3[.x]-dev will now select final versions as well as prereleases.

Tools/Demos

gh-141692: Each slice of an iOS XCframework now contains a lib folder that contains a symlink to the libpython dylib. This allows binary modules to be compiled for iOS using dynamic libreary linking, rather than Framework linking.
gh-141442: The iOS testbed now correctly handles test arguments that contain spaces.
gh-140702: The iOS testbed app will now expose the GITHUB_ACTIONS environment variable to iOS apps being tested.
gh-137484: Have Tools/wasm/wasi put the build Python into a directory named after the build triple instead of “build”.
gh-137248: Add a --logdir option to Tools/wasm/wasi for specifying where to write log files.
gh-137243: Have Tools/wasm/wasi detect a WASI SDK install in /opt when it was directly extracted from a release tarball.
Tests
gh-140482: Preserve and restore the state of stty echo as part of the test environment.
gh-140082: Update python -m test to set FORCE_COLOR=1 when being run with color enabled so that unittest which is run by it with redirected output will output in color.
gh-139208: Fix regrtest --fast-ci --verbose: don’t ignore the --verbose option anymore. Patch by Victor Stinner.
gh-136442: Use exitcode 1 instead of 5 if unittest.TestCase.setUpClass() raises an exception
Security
gh-139700: Check consistency of the zip64 end of central directory record. Support records with “zip64 extensible data” if there are no bytes prepended to the ZIP file.
gh-139283: sqlite3: correctly handle maximum number of rows to fetch in Cursor.fetchmany and reject negative values for Cursor.arraysize. Patch by Bénédikt Tran.
gh-137836: Add support of the “plaintext” element, RAWTEXT elements “xmp”, “iframe”, “noembed” and “noframes”, and optionally RAWTEXT element “noscript” in html.parser.HTMLParser.
gh-136063: email.message: ensure linear complexity for legacy HTTP parameters parsing. Patch by Bénédikt Tran.
gh-136065: Fix quadratic complexity in os.path.expandvars().
gh-119451: Fix a potential memory denial of service in the http.client module. When connecting to a malicious server, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.
gh-119342: Fix a potential memory denial of service in the plistlib module. When reading a Plist file received from untrusted source, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.

Library

gh-74389: When the stdin being used by a subprocess.Popen instance is closed, this is now ignored in subprocess.Popen.communicate() instead of leaving the class in an inconsistent state.

gh-87512: Fix subprocess.Popen.communicate() timeout handling on Windows when writing large input. Previously, the timeout was ignored during stdin writing, causing the method to block indefinitely if the child process did not consume input quickly. The stdin write is now performed in a background thread, allowing the timeout to be properly enforced.

gh-141473: When subprocess.Popen.communicate() was called with input and a timeout and is called for a second time after a TimeoutExpired exception before the process has died, it should no longer hang.

gh-59000: Fix pdb breakpoint resolution for class methods when the module defining the class is not imported.

gh-141570: Support file-like object raising OSError from fileno() in color detection (_colorize.can_colorize()). This can occur when sys.stdout is redirected.

gh-141659: Fix bad file descriptor errors from _posixsubprocess on AIX.

gh-141600: Fix musl version detection on Void Linux.

gh-141497: ipaddress: ensure that the methods IPv4Network.hosts() and IPv6Network.hosts() always return an iterator.

gh-140938: The statistics.stdev() and statistics.pstdev() functions now raise a ValueError when the input contains an infinity or a NaN.

gh-124111: Updated Tcl threading configuration in _tkinter to assume that threads are always available in Tcl 9 and later.

gh-137109: The os.fork and related forking APIs will no longer warn in the common case where Linux or macOS platform APIs return the number of threads in a process and find the answer to be 1 even when a os.register_at_fork() after_in_parent= callback (re)starts a thread.

gh-141314: Fix assertion failure in io.TextIOWrapper.tell() when reading files with standalone carriage return (\r) line endings.

gh-141311: Fix assertion failure in io.BytesIO.readinto() and undefined behavior arising when read position is above capcity in io.BytesIO.

gh-141141: Fix a thread safety issue with base64.b85decode(). Contributed by Benel Tayar.

gh-137969: Fix annotationlib.ForwardRef.evaluate() returning ForwardRef objects which don’t update with new globals.

gh-140911: collections: Ensure that the methods UserString.rindex() and UserString.index() accept collections.UserString instances as the sub argument.

gh-140797: The undocumented re.Scanner class now forbids regular expressions containing capturing groups in its lexicon patterns. Patterns using capturing groups could previously lead to crashes with segmentation fault. Use non-capturing groups (?:…) instead.

gh-125115: Refactor the pdb parsing issue so positional arguments can pass through intuitively.

gh-140815: faulthandler now detects if a frame or a code object is invalid or freed. Patch by Victor Stinner.

gh-100218: Correctly set errno when socket.if_nametoindex() or socket.if_indextoname() raise an OSError. Patch by Bénédikt Tran.

gh-140875: Fix handling of unclosed character references (named and numerical) followed by the end of file in html.parser.HTMLParser with convert_charrefs=False.

gh-140734: multiprocessing: fix off-by-one error when checking the length of a temporary socket file path. Patch by Bénédikt Tran.

gh-140874: Bump the version of pip bundled in ensurepip to version 25.3

gh-140691: In urllib.request, when opening a FTP URL fails because a data connection cannot be made, the control connection’s socket is now closed to avoid a ResourceWarning.

gh-103847: Fix hang when cancelling process created by asyncio.create_subprocess_exec() or asyncio.create_subprocess_shell(). Patch by Kumar Aditya.

gh-120057: Add os.reload_environ() to os.__all__.

gh-140228: Avoid making unnecessary filesystem calls for frozen modules in linecache when the global module cache is not present.

gh-140590: Fix arguments checking for the functools.partial.__setstate__() that may lead to internal state corruption and crash. Patch by Sergey Miryanov.

gh-125434: Display thread name in faulthandler on Windows. Patch by Victor Stinner.

gh-140634: Fix a reference counting bug in os.sched_param.__reduce__().

gh-140633: Ignore AttributeError when setting a module’s __file__ attribute when loading an extension module packaged as Apple Framework.

gh-140593: xml.parsers.expat: Fix a memory leak that could affect users with ElementDeclHandler() set to a custom element declaration handler. Patch by Sebastian Pipping.

gh-140607: Inside io.RawIOBase.read(), validate that the count of bytes returned by io.RawIOBase.readinto() is valid (inside the provided buffer).

gh-138162: Fix logging.LoggerAdapter with merge_extra=True and without the extra argument.

gh-138774: ast.unparse() now generates full source code when handling ast.Interpolation nodes that do not have a specified source.

gh-140474: Fix memory leak in array.array when creating arrays from an empty str and the u type code.

gh-137530: dataclasses Fix annotations for generated __init__ methods by replacing the annotations that were in-line in the generated source code with __annotate__ functions attached to the methods.

gh-140348: Fix regression in Python 3.14.0 where using the | operator on a typing.Union object combined with an object that is not a type would raise an error.

gh-140272: Fix memory leak in the clear() method of the dbm.gnu database.

gh-140041: Fix import of ctypes on Android and Cygwin when ABI flags are present.

gh-140120: Fixed a memory leak in hmac when it was using the hacl-star backend. Discovered by @@ashm-dev using AddressSanitizer.

gh-139905: Add suggestion to error message for typing.Generic subclasses when cls.__parameters__ is missing due to a parent class failing to call super().__init_subclass__() in its __init_subclass__.

gh-139894: Fix incorrect sharing of current task with the child process while forking in asyncio. Patch by Kumar Aditya.

gh-139845: Fix to not print KeyboardInterrupt twice in default asyncio REPL.

gh-139783: Fix inspect.getsourcelines() for the case when a decorator is followed by a comment or an empty line.

gh-139809: Prevent premature colorization of subparser prog in argparse.ArgumentParser.add_subparsers() to respect color environment variable changes after parser creation.

gh-139736: Fix excessive indentation in the default argparse HelpFormatter. Patch by Alexander Edland.

gh-70765: http.server: fix default handling of HTTP/0.9 requests in BaseHTTPRequestHandler. Previously, BaseHTTPRequestHandler.parse_request() incorrectly waited for headers in the request although those are not supported in HTTP/0.9. Patch by Bénédikt Tran.

gh-63161: Fix tokenize.detect_encoding(). Support non-UTF-8 shebang and comments if non-UTF-8 encoding is specified. Detect decoding error for non-UTF-8 encoding. Detect null bytes in source code.

gh-139391: Fix an issue when, on non-Windows platforms, it was not possible to gracefully exit a python -m asyncio process suspended by Ctrl+Z and later resumed by fg other than with kill.

gh-101828: Fix 'shift_jisx0213', 'shift_jis_2004', 'euc_jisx0213' and 'euc_jis_2004' codecs truncating null chars as they were treated as part of multi-character sequences.

gh-139289: Do a real lazy-import on rlcompleter in pdb and restore the existing completer after importing rlcompleter.

gh-139246: fix: paste zero-width in default repl width is wrong.

gh-90949: Add SetAllocTrackerActivationThreshold() and SetAllocTrackerMaximumAmplification() to xmlparser objects to prevent use of disproportional amounts of dynamic memory from within an Expat parser. Patch by Bénédikt Tran.

gh-139210: Fix use-after-free when reporting unknown event in xml.etree.ElementTree.iterparse(). Patch by Ken Jin.

gh-138860: Lazy import rlcompleter in pdb to avoid deadlock in subprocess.

gh-112729: Fix crash when calling concurrent.interpreters.create() when the process is out of memory.

gh-135729: Fix unraisable exception during finalization when using concurrent.interpreters in the REPL.

gh-139076: Fix a bug in the pydoc module that was hiding functions in a Python module if they were implemented in an extension module and the module did not have __all__.

gh-139065: Fix trailing space before a wrapped long word if the line length is exactly width in textwrap.

gh-139001: Fix race condition in pathlib.Path on the internal _raw_paths field.

gh-138813: multiprocessing.BaseProcess defaults kwargs to None instead of a shared dictionary.

gh-138993: Dedent credits text.

gh-138891: Fix SyntaxError when inspect.get_annotations(f, eval_str=True) is called on a function annotated with a PEP 646 star_expression

gh-130567: Fix possible crash in locale.strxfrm() due to a platform bug on macOS.

gh-138859: Fix generic type parameterization raising a TypeError when omitting a ParamSpec that has a default which is not a list of types.

gh-138764: Prevent annotationlib.call_annotate_function() from calling __annotate__ functions that don’t support VALUE_WITH_FAKE_GLOBALS in a fake globals namespace with empty globals.

Make FORWARDREF and STRING annotations fall back to using VALUE annotations in the case that neither their own format, nor VALUE_WITH_FAKE_GLOBALS are supported.

gh-138775: Use of python -m with base64 has been fixed to detect input from a terminal so that it properly notices EOF.

gh-138779: Support device numbers larger than 2**63-1 for the st_rdev field of the os.stat_result structure.

gh-137706: Fix the partial evaluation of annotations that use typing.Annotated[T, x] where T is a forward reference.

gh-88375: Fix normalization of the robots.txt rules and URLs in the urllib.robotparser module. No longer ignore trailing ?. Distinguish raw special characters ?, = and & from the percent-encoded ones.

gh-111788: Fix parsing errors in the urllib.robotparser module. Don’t fail trying to parse weird paths. Don’t fail trying to decode non-UTF-8 robots.txt files.

gh-98896: Fix a failure in multiprocessing resource_tracker when SharedMemory names contain colons. Patch by Rani Pinchuk.

gh-138425: Fix partial evaluation of annotationlib.ForwardRef objects which rely on names defined as globals.

gh-138432: zoneinfo.reset_tzpath() will now convert any os.PathLike objects it receives into strings before adding them to TZPATH. It will raise TypeError if anything other than a string is found after this conversion. If given an os.PathLike object that represents a relative path, it will now raise ValueError instead of TypeError, and present a more informative error message.

gh-138008: Fix segmentation faults in the ctypes module due to invalid argtypes. Patch by Dung Nguyen.

gh-60462: Fix locale.strxfrm() on Solaris (and possibly other platforms).

gh-138239: The REPL now highlights type as a soft keyword in type statements.

gh-138204: Forbid expansion of shared anonymous memory maps on Linux, which caused a bus error.

gh-138010: Fix an issue where defining a class with an @@warnings.deprecated-decorated base class may not invoke the correct __init_subclass__() method in cases involving multiple inheritance. Patch by Brian Schubert.

gh-138151: In annotationlib, improve evaluation of forward references to nonlocal variables that are not yet defined when the annotations are initially evaluated.

gh-137317: inspect.signature() now correctly handles classes that use a descriptor on a wrapped __init__() or __new__() method. Contributed by Yongyu Yan.

gh-137754: Fix import of the zoneinfo module if the C implementation of the datetime module is not available.

gh-137490: Handle ECANCELED in the same way as EINTR in signal.sigwaitinfo() on NetBSD.

gh-137477: Fix inspect.getblock(), inspect.getsourcelines() and inspect.getsource() for generator expressions.

gh-137044: Return large limit values as positive integers instead of negative integers in resource.getrlimit(). Accept large values and reject negative values (except RLIM_INFINITY) for limits in resource.setrlimit().

gh-75989: tarfile.TarFile.extractall() and tarfile.TarFile.extract() now overwrite symlinks when extracting hardlinks. (Contributed by Alexander Enrique Urieles Nieto in gh-75989.)

gh-137017: Fix threading.Thread.is_alive to remain True until the underlying OS thread is fully cleaned up. This avoids false negatives in edge cases involving thread monitoring or premature threading.Thread.is_alive calls.

gh-137273: Fix debug assertion failure in locale.setlocale() on Windows.

gh-137239: heapq: Update heapq.__all__ with *_max functions.

gh-81325: tarfile.TarFile now accepts a path-like when working on a tar archive. (Contributed by Alexander Enrique Urieles Nieto in gh-81325.)

gh-137185: Fix a potential async-signal-safety issue in faulthandler when printing C stack traces.

gh-136914: Fix retrieval of doctest.DocTest.lineno for objects decorated with functools.cache() or functools.cached_property.

gh-136912: hmac.digest() now properly handles large keys and messages by falling back to the pure Python implementation when necessary. Patch by Bénédikt Tran.

gh-83424: Allows creating a ctypes.CDLL without name when passing a handle as an argument.

gh-136234: Fix asyncio.WriteTransport.writelines() to be robust to connection failure, by using the same behavior as write().

gh-136507: Fix mimetypes CLI to handle multiple file parameters.

gh-136057: Fixed the bug in pdb and bdb where next and step can’t go over the line if a loop exists in the line.

gh-135386: Fix opening a dbm.sqlite3 database for reading from read-only file or directory.

gh-135444: Fix asyncio.DatagramTransport.sendto() to account for datagram header size when data cannot be sent.

gh-126631: Fix multiprocessing forkserver bug which prevented __main__ from being preloaded.

gh-135307: email: Fix exception in set_content() when encoding text and max_line_length is set to 0 or None (unlimited).

gh-134453: Fixed subprocess.Popen.communicate() input= handling of memoryview instances that were non-byte shaped on POSIX platforms. Those are now properly cast to a byte shaped view instead of truncating the input. Windows platforms did not have this bug.

gh-134698: Fix a crash when calling methods of ssl.SSLContext or ssl.SSLSocket across multiple threads.

gh-125996: Fix thread safety of collections.OrderedDict. Patch by Kumar Aditya.

gh-133789: Fix unpickling of pathlib objects that were pickled in Python 3.13.

gh-127081: Fix libc thread safety issues with dbm by performing stateful operations in critical sections.

gh-132551: Make io.BytesIO safe in free-threaded build.

gh-131788: Make ResourceTracker.send from multiprocessing re-entrant safe

gh-118981: Fix potential hang in multiprocessing.popen_spawn_posix that can happen when the child proc dies early by closing the child fds right away.

gh-102431: Clarify constraints for “logical” arguments in methods of decimal.Context.

gh-78319: UTF8 support for the IMAP APPEND command has been made RFC compliant.

bpo-38735: Fix failure when importing a module from the root directory on unix-like platforms with sys.pycache_prefix set.

bpo-41839: Allow negative priority values from os.sched_get_priority_min() and os.sched_get_priority_max() functions.

IDLE

gh-96491: Deduplicate version number in IDLE shell title bar after saving to a file.
gh-139742: Colorize t-string prefixes for template strings in IDLE, as done for f-string prefixes.
Documentation
gh-141994: xml.sax.handler: Make Documentation of xml.sax.handler.feature_external_ges warn of opening up to external entity attacks. Patch by Sebastian Pipping.
gh-140578: Remove outdated sencence in the documentation for multiprocessing, that implied that concurrent.futures.ThreadPoolExecutor did not exist.

Core and Builtins

gh-142048: Fix quadratically increasing garbage collection delays in free-threaded build.
gh-116738: Fix thread safety issue with re scanner objects in free-threaded builds.
gh-141930: When importing a module, use Python’s regular file object to ensure that writes to .pyc files are complete or an appropriate error is raised.
gh-120158: Fix inconsistent state when enabling or disabling monitoring events too many times.
gh-139653: Only raise a RecursionError or trigger a fatal error if the stack pointer is both below the limit pointer and above the stack base. If outside of these bounds assume that it is OK. This prevents false positives when user-space threads swap stacks.
gh-139103: Improve multithreaded scaling of dataclasses on the free-threaded build.
gh-141579: Fix sys.activate_stack_trampoline() to properly support the perf_jit backend. Patch by Pablo Galindo.
gh-114203: Skip locking if object is already locked by two-mutex critical section.
gh-141528: Suggest using concurrent.interpreters.Interpreter.close() instead of the private _interpreters.destroy function when warning about remaining subinterpreters. Patch by Sergey Miryanov.
gh-141312: Fix the assertion failure in the __setstate__ method of the range iterator when a non-integer argument is passed. Patch by Sergey Miryanov.
gh-116738: Make csv module thread-safe on the free threaded build.
gh-140939: Fix memory leak when bytearray or bytes is formated with the %*b format with a large width that results in a MemoryError.
gh-140260: Fix struct data race in endian table initialization with subinterpreters. Patch by Shamil Abdulaev.
gh-140530: Fix a reference leak when raise exc from cause fails. Patch by Bénédikt Tran.
gh-140373: Correctly emit PY_UNWIND event when generator object is closed. Patch by Mikhail Efimov.
gh-140576: Fixed crash in tokenize.generate_tokens() in case of specific incorrect input. Patch by Mikhail Efimov.
gh-140551: Fixed crash in dict if dict.clear() is called at the lookup stage. Patch by Mikhail Efimov and Inada Naoki.
gh-140517: Fixed a reference leak when iterating over the result of map() with strict=True when the input iterables have different lengths. Patch by Mikhail Efimov.
gh-140471: Fix potential buffer overflow in ast.AST node initialization when encountering malformed _fields containing non-str.
gh-140431: Fix a crash in Python’s garbage collector due to partially initialized coroutine objects when coroutine origin tracking depth is enabled (sys.set_coroutine_origin_tracking_depth()).
gh-140398: Fix memory leaks in readline functions read_init_file(), read_history_file(), write_history_file(), and append_history_file() when PySys_Audit() fails.
gh-140406: Fix memory leak when an object’s __hash__() method returns an object that isn’t an int.
gh-140358: Restore elapsed time and unreachable object count in GC debug output. These were inadvertently removed during a refactor of gc.c. The debug log now again reports elapsed collection time and the number of unreachable objects. Contributed by Pål Grønås Drange.
gh-140306: Fix memory leaks in cross-interpreter channel operations and shared namespace handling.
gh-140301: Fix memory leak of PyConfig in subinterpreters.
gh-140257: Fix data race between interpreter_clear() and take_gil() on eval_breaker during finalization with daemon threads.
gh-139951: Fixes a regression in GC performance for a growing heap composed mostly of small tuples.
Counts number of actually tracked objects, instead of trackable objects. This ensures that untracking tuples has the desired effect of reducing GC overhead.
Does not track most untrackable tuples during creation. This prevents large numbers of small tuples causing excessive GCs.
gh-140104: Fix a bug with exception handling in the JIT. Patch by Ken Jin. Bug reported by Daniel Diniz.
gh-140061: Fixing the checking of whether an object is uniquely referenced to ensure free-threaded compatibility. Patch by Sergey Miryanov.
gh-140067: Fix memory leak in sub-interpreter creation.
gh-140000: Fix potential memory leak when a reference cycle exists between an instance of typing.TypeAliasType, typing.TypeVar, typing.ParamSpec, or typing.TypeVarTuple and its __name__ attribute. Patch by Mikhail Efimov.
gh-139914: Restore support for HP PA-RISC, which has an upwards-growing stack.
gh-139988: Fix a memory leak when failing to create a Union type. Patch by Bénédikt Tran.
gh-139748: Fix reference leaks in error branches of functions accepting path strings or bytes such as compile() and os.system(). Patch by Bénédikt Tran.
gh-139516: Fix lambda colon erroneously start format spec in f-string in tokenizer.
gh-139640: ast.parse() no longer emits syntax warnings for return/break/continue in finally (see PEP 765) – they are only emitted during compilation.
gh-139640: Fix swallowing some syntax warnings in different modules if they accidentally have the same message and are emitted from the same line. Fix duplicated warnings in the finally block.
gh-63161: Support non-UTF-8 shebang and comments in Python source files if non-UTF-8 encoding is specified. Detect decoding error in comments for default (UTF-8) encoding. Show the line and position of decoding error for default encoding in a traceback. Show the line containing the coding cookie when it conflicts with the BOM in a traceback.
gh-116738: Make mmap thread-safe on the free threaded build.
gh-138558: Fix handling of unusual t-string annotations in annotationlib. Patch by Dave Peck.
gh-134466: Don’t run PyREPL in a degraded environment where setting termios attributes is not allowed.
gh-138944: Fix SyntaxError message when invalid syntax appears on the same line as a valid import ... as ... or from ... import ... as ... statement. Patch by Brian Schubert.
gh-105487: Remove non-existent __copy__(), __deepcopy__(), and __bases__ from the __dir__() entries of types.GenericAlias.
gh-69605: Fix some standard library submodules missing from the REPL auto-completion of imports.
gh-116738: Make cProfile thread-safe on the free threaded build.
gh-138004: On Solaris/Illumos platforms, thread names are now encoded as ASCII to avoid errors on systems (e.g. OpenIndiana) that don’t support non-ASCII names.
gh-137433: Fix a potential deadlock in the free threading build when daemon threads enable or disable profiling or tracing while the main thread is shutting down the interpreter.
gh-137400: Fix a crash in the free threading build when disabling profiling or tracing across all threads with PyEval_SetProfileAllThreads() or PyEval_SetTraceAllThreads() or their Python equivalents threading.settrace_all_threads() and threading.setprofile_all_threads().
gh-58124: Fix name of the Python encoding in Unicode errors of the code page codec: use “cp65000” and “cp65001” instead of “CP_UTF7” and “CP_UTF8” which are not valid Python code names. Patch by Victor Stinner.
gh-132657: Improve performance of frozenset by removing locks in the free-threading build.
gh-133400: Fixed Ctrl+D (^D) behavior in _pyrepl module to match old pre-3.13 REPL behavior.
gh-128640: Fix a crash when using threads inside of a subinterpreter.

C API

gh-137422: Fix free threading race condition in PyImport_AddModuleRef(). It was previously possible for two calls to the function return two different objects, only one of which was stored in sys.modules.
gh-140042: Removed the sqlite3_shutdown call that could cause closing connections for sqlite when used with multiple sub interpreters.
gh-141042: Make qNaN in PyFloat_Pack2() and PyFloat_Pack4(), if while conversion to a narrower precision floating-point format — the remaining after truncation payload will be zero. Patch by Sergey B Kirpichev.
gh-140487: Fix Py_RETURN_NOTIMPLEMENTED in limited C API 3.11 and older: don’t treat Py_NotImplemented as immortal. Patch by Victor Stinner.
gh-140153: Fix Py_REFCNT() definition on limited C API 3.11-3.13. Patch by Victor Stinner.
gh-139653: Add PyUnstable_ThreadState_SetStackProtection() and PyUnstable_ThreadState_ResetStackProtection() functions to set the stack protection base address and stack protection size of a Python thread state. Patch by Victor Stinner.

Build

gh-141808: Do not generate the jit stencils twice in case of PGO builds on Windows.

gh-141784: Fix _remote_debugging_module.c compilation on 32-bit Linux. Include Python.h before system headers to make sure that _remote_debugging_module.c uses the same types (ABI) than Python. Patch by Victor Stinner.

gh-140768: Warn when the WASI SDK version doesn’t match what’s supported.

gh-140513: Generate a clear compilation error when _Py_TAIL_CALL_INTERP is enabled but either preserve_none or musttail is not supported.

gh-140189: iOS builds were added to CI.

gh-138489: When cross-compiling for WASI by build_wasm or build_emscripten, the build-details.json step is now included in the build process, just like with native builds.

This fixes the libinstall task which requires the build-details.json file during the process.

gh-137618: PYTHON_FOR_REGEN now requires Python 3.10 to Python 3.15. Patch by Adam Turner.

gh-123681: Check the strftime() behavior at runtime instead of at the compile time to support cross-compiling. Remove the internal macro _Py_NORMALIZE_CENTURY.
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.7 2025/11/05 22:20:05 wiz Exp $
a28 1
CONFIGURE_ARGS+=	--with-system-expat
d30 1
a217 1
.include "../../textproc/expat/buildlink3.mk"
@


1.7
log
@python314: apply upstream patch fixing CVE-2025-6075

Bump PKGREVISION.
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.6 2025/10/22 13:46:55 jperkin Exp $
a5 1
PKGREVISION=	3
@


1.6
log
@python314: Use gmake on SunOS too.

It's unclear why the python builds try to avoid gmake as the Makefiles use
incompatible $< vs $> in a few places and bmake breaks the dtrace build, but
try to appease everyone.
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.5 2025/10/11 12:47:19 wiz Exp $
d6 1
a6 1
PKGREVISION=	2
@


1.5
log
@python314: really bump PKGREVISION.
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.4 2025/10/11 10:14:06 wiz Exp $
d86 1
a86 1
.if ${OPSYS} == "Darwin"
@


1.4
log
@python314: fix zip vulnerability using upstream patch

Bump PKGREVISION.

While here, fix option name and some pkglint.
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.3 2025/10/10 13:57:52 wiz Exp $
d6 1
a6 1
PKGREVISION=	1
@


1.3
log
@python314: bump PKGREVISION for ALTERNATIVES fix
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.2 2025/10/09 19:52:16 wiz Exp $
d45 1
a45 1
USE_CURSES=	getsyx update_panels wide
d48 1
a48 1
FAKE_NCURSES=	yes
d200 2
@


1.2
log
@python314: remove some unnecessary copy'n'pasted stuff

The referenced packages never existed.
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.1 2025/10/08 07:13:07 adam Exp $
d6 1
@


1.1
log
@python314 py314-html-docs: added version 3.14.0

Major new features of the 3.14 series, compared to 3.13
Some of the major new features and changes in Python 3.14 are:

New features

PEP 779: Free-threaded Python is officially supported
PEP 649: The evaluation of annotations is now deferred, improving the semantics of using annotations.
PEP 750: Template string literals (t-strings) for custom string processing, using the familiar syntax of f-strings.
PEP 734: Multiple interpreters in the stdlib.
PEP 784: A new module compression.zstd providing support for the Zstandard compression algorithm.
PEP 758: except and except* expressions may now omit the brackets.
Syntax highlighting in PyREPL, and support for color in unittest, argparse, json and calendar CLIs.
PEP 768: A zero-overhead external debugger interface for CPython.
UUID versions 6-8 are now supported by the uuid module, and generation of versions 3-5 are up to 40% faster.
PEP 765: Disallow return/break/continue that exit a finally block.
PEP 741: An improved C API for configuring Python.
A new type of interpreter. For certain newer compilers, this interpreter provides significantly better performance. Opt-in for now, requires building from source.
Improved error messages.
Builtin implementation of HMAC with formally verified code from the HACL* project.
A new command-line interface to inspect running Python processes using asynchronous tasks.
The pdb module now supports remote attaching to a running Python process.
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.24 2025/08/15 06:44:41 adam Exp $
a13 12
CONFLICTS+=	py314-cElementTree-[0-9]*
CONFLICTS+=	py314-curses-[0-9]*
CONFLICTS+=	py314-cursespanel-[0-9]*
CONFLICTS+=	py314-expat-[0-9]*
CONFLICTS+=	py314-readline-[0-9]*
CONFLICTS+=	py314-sqlite3-[0-9]*
SUPERSEDES+=	py314-cElementTree-[0-9]*
SUPERSEDES+=	py314-curses-[0-9]*
SUPERSEDES+=	py314-cursespanel-[0-9]*
SUPERSEDES+=	py314-expat-[0-9]*
SUPERSEDES+=	py314-readline-[0-9]*
SUPERSEDES+=	py314-sqlite3-[0-9]*
@

