dev-lang/python: 3.4: disable getentropy() on linux
authorMike Gilbert <floppym@gentoo.org>
Wed, 1 Nov 2017 16:02:54 +0000 (12:02 -0400)
committerMike Gilbert <floppym@gentoo.org>
Wed, 1 Nov 2017 16:03:13 +0000 (12:03 -0400)
Closes: https://bugs.gentoo.org/635534
Package-Manager: Portage-2.3.13, Repoman-2.3.3_p80

dev-lang/python/files/3.4-getentropy-linux.patch [new file with mode: 0644]
dev-lang/python/python-3.4.5.ebuild
dev-lang/python/python-3.4.6.ebuild

diff --git a/dev-lang/python/files/3.4-getentropy-linux.patch b/dev-lang/python/files/3.4-getentropy-linux.patch
new file mode 100644 (file)
index 0000000..9f12389
--- /dev/null
@@ -0,0 +1,40 @@
+From 5635d44079e1bbd9c495951ede8d078e7b8d67d5 Mon Sep 17 00:00:00 2001
+From: Victor Stinner <victor.stinner@gmail.com>
+Date: Mon, 9 Jan 2017 11:10:41 +0100
+Subject: [PATCH] Don't use getentropy() on Linux
+
+Issue #29188: Support glibc 2.24 on Linux: don't use getentropy() function but
+read from /dev/urandom to get random bytes, for example in os.urandom().  On
+Linux, getentropy() is implemented which getrandom() is blocking mode, whereas
+os.urandom() should not block.
+---
+ Python/random.c | 13 ++++++++++---
+ 1 file changed, 10 insertions(+), 3 deletions(-)
+
+diff --git a/Python/random.c b/Python/random.c
+index af3d0bd0d5..dc6400d3b8 100644
+--- a/Python/random.c
++++ b/Python/random.c
+@@ -67,9 +67,16 @@ win32_urandom(unsigned char *buffer, Py_ssize_t size, int raise)
+     return 0;
+ }
+-/* Issue #25003: Don' use getentropy() on Solaris (available since
+- * Solaris 11.3), it is blocking whereas os.urandom() should not block. */
+-#elif defined(HAVE_GETENTROPY) && !defined(sun)
++/* Issue #25003: Don't use getentropy() on Solaris (available since
++   Solaris 11.3), it is blocking whereas os.urandom() should not block.
++
++   Issue #29188: Don't use getentropy() on Linux since the glibc 2.24
++   implements it with the getrandom() syscall which can fail with ENOSYS,
++   and this error is not supported in py_getentropy() and getrandom() is called
++   with flags=0 which blocks until system urandom is initialized, which is not
++   the desired behaviour to seed the Python hash secret nor for os.urandom():
++   see the PEP 524 which was only implemented in Python 3.6. */
++#elif defined(HAVE_GETENTROPY) && !defined(sun) && !defined(linux)
+ #define PY_GETENTROPY 1
+ /* Fill buffer with size pseudo-random bytes generated by getentropy().
+-- 
+2.15.0.rc2
+
index 20fadf8ea6fbc062fd4424eadf8b671f6458d40e..29991dd53ae7929ff5ce4eade4f4300c0e25558c 100644 (file)
@@ -72,6 +72,7 @@ src_prepare() {
        EPATCH_SUFFIX="patch" epatch "${WORKDIR}/patches"
        epatch "${FILESDIR}/${PN}-3.4.3-ncurses-pkg-config.patch"
        epatch "${FILESDIR}/${PN}-3.4.5-cross.patch"
+       epatch "${FILESDIR}/3.4-getentropy-linux.patch"
 
        epatch_user
 
index 80dffce2af5429a7da6074cf701e1d019f110fcc..4e06debaade723d00cb64dd0931b446526afbfde 100644 (file)
@@ -72,6 +72,7 @@ src_prepare() {
        EPATCH_SUFFIX="patch" epatch "${WORKDIR}/patches"
        epatch "${FILESDIR}/${PN}-3.4.3-ncurses-pkg-config.patch"
        epatch "${FILESDIR}/${PN}-3.4.5-cross.patch"
+       epatch "${FILESDIR}/3.4-getentropy-linux.patch"
 
        epatch_user