Bug 15439

Summary: python-cryptodomex has inconsistent internal imports causing ImportError
Product: [Build System, Metadata & Runtime] OE-Core Reporter: eroderic
Component: devtools / tool chainAssignee: Steve Sakoman <steve>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Medium+ CC: meta.mr.watcher, meta.watcher, randy.macleod, tim.orling
Version: unspecified   
Target Milestone: 4.0.21   
Hardware: x86   
OS: x86_64   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)

Description eroderic 2024-03-10 23:29:40 UTC
python-cryptodomex is a Python package that adds crypto based operations and is imported as `Cryptodome`. It is similar to python-cryptodome, (exactly the same functionality/codebase) which is imported as `Crytpo` for compatibility. 

A recent patch to Yocto, adds a patch file for both of these Python packages, however it uses 'Crypto' imports for both packages. This means that the python-cryptodomex package, which uses the `Cryptodome` import, will have an import error when attempting to import cryptographic functions.

The patch in particular is 'python3-pycryptodome: Fix CVE-2023-52323', https://git.yoctoproject.org/poky/commit/?h=kirkstone&id=e17cf6a549c53c48629d9454ec744fd2c824a83f

Amending the patch to pycryptodomex to use the correct imports seems to fix the issue.
Comment 1 Randy MacLeod 2024-03-14 14:39:19 UTC
Can you send a patch to the list please?
There seems to be some test code, you could add a ptest wrapper?
 -- YP bug review.
Comment 2 Randy MacLeod 2024-05-23 15:15:13 UTC
Did this get sent to the list and/or merged
Comment 3 Randy MacLeod 2024-08-08 15:07:39 UTC
On master, fixed by? 

06b4475c5e   2024-07-23   python3-pycryptodome(x): use python_setuptools_build_meta build class


Steve please check on the stable releases.