Merge pull request #201257 from mweinelt/22.05/twisted

[22.05] python3Packages.twisted: Resolve host header injection vulnerability
This commit is contained in:
Robert Scott
2022-11-22 20:43:39 +00:00
committed by GitHub
2 changed files with 1507 additions and 0 deletions

File diff suppressed because it is too large Load Diff

View File

@@ -24,6 +24,19 @@
, h2
, priority
, contextvars
# for passthru.tests
, cassandra-driver
, klein
, magic-wormhole
, scrapy
, treq
, txaio
, txamqp
, txrequests
, txtorcon
, thrift
, nixosTests
}:
buildPythonPackage rec {
pname = "Twisted";
@@ -50,6 +63,11 @@ buildPythonPackage rec {
contextvars = lib.optionals (pythonOlder "3.7") [ contextvars ];
};
patches = [
# https://github.com/twisted/twisted/commit/f2f5e81c03f14e253e85fe457e646130780db40b
./CVE-2022-39348.patch
];
# Patch t.p._inotify to point to libc. Without this,
# twisted.python.runtime.platform.supportsINotify() == False
postPatch = lib.optionalString stdenv.isLinux ''
@@ -71,6 +89,21 @@ buildPythonPackage rec {
# Tests require network
doCheck = false;
passthru.tests = {
inherit
cassandra-driver
klein
magic-wormhole
scrapy
treq
txaio
txamqp
txrequests
txtorcon
thrift;
inherit (nixosTests) buildbot matrix-synapse;
};
meta = with lib; {
homepage = "https://github.com/twisted/twisted";
description = "Twisted, an event-driven networking engine written in Python";