| Summary: | python3-cryptography legacy openssl broken after update to 42.0.5 | ||
|---|---|---|---|
| Product: | [Build System, Metadata & Runtime] OE-Core | Reporter: | kweihmann |
| Component: | devtools / tool chain | Assignee: | Colin McAllister <colinmca242> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | major | ||
| Priority: | Medium | CC: | colinmca242, meta.mr.watcher, meta.watcher, randy.macleod, ross.burton, tim.orling |
| Version: | unspecified | ||
| Target Milestone: | 6.0 | ||
| Hardware: | x86 | ||
| OS: | Multiple | ||
| Whiteboard: | |||
| OS type for building Yocto: | --- | Type of Regression: | --- |
| Verified: | Documentation change: | No (bug/feature does not impact docs) | |
|
Description
kweihmann
2024-03-02 08:45:59 UTC
I currently helped myself with a bbappend containing
do_install:append() {
echo "import os" >> ${D}${PYTHON_SITEPACKAGES_DIR}/cryptography/hazmat/__init__.py
echo "os.environ['CRYPTOGRAPHY_OPENSSL_NO_LEGACY'] = '1'" >> ${D}${PYTHON_SITEPACKAGES_DIR}/cryptography/hazmat/__init__.py
}
All of the ptests have been passing, so saying python3-cryptography is broken is an exaggeration. This should most likely be a PACKAGECONFIG[legacy-openssl] where by default it would be NO LEGACY. We do not want to support old algorithms unless it is for intentional reasons (such as FIPS compliance). Sadly, it will also require a configuration/PACKAGECONFIG of OpenSSL in order for the "legacy" algorithms to work at all. Folks that need a different configuration for OpenSSL (such as FIPS) will most likely also have a requirement to use an older (e.g. 3.0.8 for FIPS) version of OpenSSL anyway. Please send a patch which sets a PACKAGECONFIG that enables NO LEGACY by default. FWIW we have some recipes that use pycryptography-native and they do this:
# python3-cryptography needs the legacy provider, so set OPENSSL_MODULES to the
# right path until this is relocated automatically.
export OPENSSL_MODULES="${STAGING_LIBDIR_NATIVE}/ossl-modules"
Bulk move of 5.1 bugs to 5.2. -- YP bug review (Randy) Bulk move of all unassigned 5.2 medium importance bugs to 5.3. As of Python cryptography 45.0.0 it appears that there's a build-time environment variable, CRYPTOGRAPHY_BUILD_OPENSSL_NO_LEGACY, that can be used to prevent the library from ever attempting to load the legacy provider. https://github.com/pyca/cryptography/commit/ddc364d28b480010f527c9838906992a27d4b55a It does seem like this commit also "fixes" the issue somewhat where this runtime exception is now downgraded to a warning. To Tim's point, could a PACKAGECONFIG option be added that enables legacy functionality, but otherwise sets this build time environment variable? It's not immediately clear to me what changes are necessary on the openssl side. I do see the openssl-ossl-module-legacy package provided by openssl. I assume the PACKAGECONFIG option would need to rdepend on this? I'm not quite sure what to do about what Ross mentioned where the OPENSSL_MODULES environment variable needs to be exported. I'm happy to pick up this bug and ensure that it gets closed out. After looking into this a bit more, I think this defect can be closed out on it's own since 45.0.0 downgraded this warning to an exception and python3-cryptography was upgraded to 45.0.7 in Whinlatter. However, I think there's still room for improvement, so I sent in a proposal last night for a PACKAGECONFIG option to enable/disable legacy-openssl support. https://lists.openembedded.org/g/openembedded-core/topic/patch_python3_cryptography/117394116 This option specifies a runtime dependency for the openssl-ossl-module-legacy module, which didn't exist and also uses the CRYPTOGRAPHY_BUILD_OPENSSL_NO_LEGACY build time environment variable to disable legacy support if the PACKAGECONFIG option is disabled. To keep forwards compatibility and not introduce any breaking changes, I left this PACKAGECONFIG option enabled, but it could also be disabled by default as that is the more secure configuration. However, that could cause breaking issues for those currently using the OpenSSL legacy module. I'm not sure about a better solution for the native openssl modules path, other than what Ross is doing with exporting OPENSSL_MODULES. If anyone thinks that's worthy of a separate bug that requires a better solution, please let me know. Fixed by: https://git.openembedded.org/openembedded-core/commit/?id=c3c612608d816eb6b40575a86e0907701cf525dc and https://git.openembedded.org/openembedded-core/commit/?id=96548d97cbad4c125cdc07aa21182390513ca2c6 As noted in my previous comments, the assert was downgraded to a warning in python3-cryptography v45.0.0. However, the second change linked above sets the build-time environment variable to explicitly disable legacy support if the legacy packageconfig option is not set. This ensures the warning will not be shown if legacy support is not intended to be used and is not included. As noted in the ML, the legacy packageconfig option is enabled by default to preserve current behavior, but will be disabled by default once OpenSSL is disables the legacy module by default. |