Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

bpo-9216: hashlib usedforsecurity fixes#20258

Merged
miss-islington merged 1 commit into
python:masterpython/cpython:masterfrom
tiran:bpo9216-fixtiran/cpython:bpo9216-fixCopy head branch name to clipboard
May 22, 2020
Merged

bpo-9216: hashlib usedforsecurity fixes#20258
miss-islington merged 1 commit into
python:masterpython/cpython:masterfrom
tiran:bpo9216-fixtiran/cpython:bpo9216-fixCopy head branch name to clipboard

Conversation

@tiran

@tiran tiran commented May 20, 2020

Copy link
Copy Markdown
Member

func:hashlib.new passed usedforsecurity to OpenSSL EVP constructor
_hashlib.new(). test_hashlib and test_smtplib handle strict security
policy better.

Signed-off-by: Christian Heimes christian@python.org

https://bugs.python.org/issue9216

Automerge-Triggered-By: @tiran

@tiran tiran requested review from gpshead and vstinner May 20, 2020 10:58
@tiran tiran requested a review from a team as a code owner May 20, 2020 10:58
@tiran tiran force-pushed the bpo9216-fix branch 2 times, most recently from 71887fe to 0838bd5 Compare May 22, 2020 10:23
func:`hashlib.new` passed ``usedforsecurity`` to OpenSSL EVP constructor
``_hashlib.new()``. test_hashlib and test_smtplib handle strict security
policy better.

Signed-off-by: Christian Heimes <christian@python.org>
@@ -0,0 +1,3 @@
func:`hashlib.new` passed ``usedforsecurity`` to OpenSSL EVP constructor

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A user reading this shouldn't need to be aware of the internal implementation details behind the Python hashlib "usedforsecurity" construct. I'd just simplify this news entry:

func:`hashlib.new` now passes the ``usedforsecurity`` flag to the internal OpenSSL hash constructors.

and probably omit the final "test_hashlib and test_smtplib handle strict security policy better." part entirely as we don't need a NEWS entry to mention updates to our internal test suite. (though it is harmless to do so)

@miss-islington

Copy link
Copy Markdown
Contributor

Thanks @tiran for the PR 🌮🎉.. I'm working now to backport this PR to: 3.9.
🐍🍒⛏🤖

@bedevere-bot

Copy link
Copy Markdown

GH-20320 is a backport of this pull request to the 3.9 branch.

miss-islington pushed a commit to miss-islington/cpython that referenced this pull request May 22, 2020
func:`hashlib.new` passed ``usedforsecurity`` to OpenSSL EVP constructor
``_hashlib.new()``. test_hashlib and test_smtplib handle strict security
policy better.

Signed-off-by: Christian Heimes <christian@python.org>

Automerge-Triggered-By: @tiran
(cherry picked from commit 909b571)

Co-authored-by: Christian Heimes <christian@python.org>
miss-islington added a commit that referenced this pull request May 22, 2020
func:`hashlib.new` passed ``usedforsecurity`` to OpenSSL EVP constructor
``_hashlib.new()``. test_hashlib and test_smtplib handle strict security
policy better.

Signed-off-by: Christian Heimes <christian@python.org>

Automerge-Triggered-By: @tiran
(cherry picked from commit 909b571)

Co-authored-by: Christian Heimes <christian@python.org>
arturoescaip pushed a commit to arturoescaip/cpython that referenced this pull request May 24, 2020
func:`hashlib.new` passed ``usedforsecurity`` to OpenSSL EVP constructor
``_hashlib.new()``. test_hashlib and test_smtplib handle strict security
policy better.

Signed-off-by: Christian Heimes <christian@python.org>

Automerge-Triggered-By: @tiran
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

Morty Proxy This is a proxified and sanitized view of the page, visit original site.