Hello,

this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe(s) 
*python3-cryptography,python3-cryptography-vectors* to *50.0.0,50.0.0* has 
Failed (devtool error).

Detailed error information:

Running 'devtool upgrade' for recipe python3-cryptography failed.
NOTE: Reconnecting to bitbake server...
Loading cache...done.
Loaded 0 entries from dependency cache.
Parsing recipes...done.
Parsing of 956 .bb files complete (0 cached, 956 parsed). 1988 targets, 40 
skipped, 0 masked, 0 errors.
NOTE: Resolving any missing task queue dependencies

Build Configuration:
BB_VERSION           = "2.19.0"
BUILD_SYS            = "x86_64-linux"
NATIVELSBSTRING      = "universal"
TARGET_SYS           = "x86_64-poky-linux"
MACHINE              = "qemux86-64"
SDKMACHINE           = "x86_64"
DISTRO               = "poky"
DISTRO_VERSION       = 
"6.0.99+snapshot-69cf2fedb5a550366ccaafff994d3c98b0f18034"
TUNE_FEATURES        = "m64 x86-64-v3"
meta                 = 
"tmp-auh-upgrades:69cf2fedb5a550366ccaafff994d3c98b0f18034"
meta-yocto-bsp       
meta-poky            = "master:9c6cf36c3511b94957aba04002d98bec665e9f1e"
workspace            = "<unknown>:<unknown>"

Initialising tasks...NOTE: The /proc/pressure files can't be read. Continuing 
build without monitoring pressure
Sstate summary: Wanted 10 Local 10 Mirrors 0 Missed 0 Current 20 (100% match, 
100% complete)
done.
NOTE: Executing Tasks
NOTE: Tasks Summary: Attempted 103 tasks of which 100 didn't need to be rerun 
and all succeeded.
NOTE: Writing buildhistory
NOTE: Writing buildhistory took: 1 seconds
Loading cache...done.
Loaded 0 entries from dependency cache.
Parsing recipes...WARNING: 
/srv/pokybuild/yocto-worker/auh/build/build/workspace/recipes/recipetool/tmp-recipetool-p8ezf6lk.bb:
 tmp-recipetool-p8ezf6lk: LICENSE is using "CLOSED", which is deprecated. 
Convert to using a license ref pointing to an actual license file, e.g.
LICENSE = "LicenseRef-tmp-recipetool-p8ezf6lk-CLOSED"
done.
Parsing of 957 .bb files complete (0 cached, 957 parsed). 1989 targets, 40 
skipped, 0 masked, 0 errors.

Summary: There was 1 WARNING message.
NOTE: Resolving any missing task queue dependencies

Build Configuration:
BB_VERSION           = "2.19.0"
BUILD_SYS            = "x86_64-linux"
NATIVELSBSTRING      = "universal"
TARGET_SYS           = "x86_64-poky-linux"
MACHINE              = "qemux86-64"
SDKMACHINE           = "x86_64"
DISTRO               = "poky"
DISTRO_VERSION       = 
"6.0.99+snapshot-69cf2fedb5a550366ccaafff994d3c98b0f18034"
TUNE_FEATURES        = "m64 x86-64-v3"
meta                 = 
"tmp-auh-upgrades:69cf2fedb5a550366ccaafff994d3c98b0f18034"
meta-yocto-bsp       
meta-poky            = "master:9c6cf36c3511b94957aba04002d98bec665e9f1e"
workspace            = "<unknown>:<unknown>"

Initialising tasks...NOTE: The /proc/pressure files can't be read. Continuing 
build without monitoring pressure
Sstate summary: Wanted 1 Local 0 Mirrors 0 Missed 1 Current 0 (0% match, 0% 
complete)
done.
NOTE: Executing Tasks
WARNING: tmp-recipetool-p8ezf6lk: LICENSE is using "CLOSED", which is 
deprecated. Convert to using a license ref pointing to an actual license file, 
e.g.
LICENSE = "LicenseRef-tmp-recipetool-p8ezf6lk-CLOSED"
WARNING: tmp-recipetool-p8ezf6lk: LICENSE is using "CLOSED", which is 
deprecated. Convert to using a license ref pointing to an actual license file, 
e.g.
LICENSE = "LicenseRef-tmp-recipetool-p8ezf6lk-CLOSED"
WARNING: tmp-recipetool-p8ezf6lk: LICENSE is using "CLOSED", which is 
deprecated. Convert to using a license ref pointing to an actual license file, 
e.g.
LICENSE = "LicenseRef-tmp-recipetool-p8ezf6lk-CLOSED"
NOTE: Tasks Summary: Attempted 3 tasks of which 0 didn't need to be rerun and 
all succeeded.
NOTE: Writing buildhistory
NOTE: Writing buildhistory took: 1 seconds
WARNING: tmp-recipetool-p8ezf6lk: LICENSE is using "CLOSED", which is 
deprecated. Convert to using a license ref pointing to an actual license file, 
e.g.
LICENSE = "LicenseRef-tmp-recipetool-p8ezf6lk-CLOSED"
Adding changed files:   0% |                                   | ETA:  --:--:--
Adding changed files:   0% |                                   | ETA:  --:--:--
Adding changed files:  58% |#####################               | ETA:  0:00:00
Adding changed files: 100% |####################################| Time: 0:00:00
Removing 1 recipes from the x86-64-v3 sysroot...done.
NOTE: Resolving any missing task queue dependencies

Build Configuration:
BB_VERSION           = "2.19.0"
BUILD_SYS            = "x86_64-linux"
NATIVELSBSTRING      = "universal"
TARGET_SYS           = "x86_64-poky-linux"
MACHINE              = "qemux86-64"
SDKMACHINE           = "x86_64"
DISTRO               = "poky"
DISTRO_VERSION       = 
"6.0.99+snapshot-69cf2fedb5a550366ccaafff994d3c98b0f18034"
TUNE_FEATURES        = "m64 x86-64-v3"
meta                 = 
"tmp-auh-upgrades:69cf2fedb5a550366ccaafff994d3c98b0f18034"
meta-yocto-bsp       
meta-poky            = "master:9c6cf36c3511b94957aba04002d98bec665e9f1e"
workspace            = "<unknown>:<unknown>"

Initialising tasks...NOTE: The /proc/pressure files can't be read. Continuing 
build without monitoring pressure
Sstate summary: Wanted 29 Local 29 Mirrors 0 Missed 0 Current 58 (100% match, 
100% complete)
done.
NOTE: Executing Tasks
NOTE: Tasks Summary: Attempted 292 tasks of which 291 didn't need to be rerun 
and all succeeded.
NOTE: Writing buildhistory
NOTE: Writing buildhistory took: 1 seconds
INFO: Extracting current version source...
INFO: Extracting upgraded version source...
INFO: Fetching 
https://files.pythonhosted.org/packages/source/c/cryptography/cryptography-50.0.0.tar.gz;downloadfilename=cryptography-50.0.0.tar.gz...
INFO: Rebasing devtool onto 883a837fd2addb1a32394e499fdfb053e2da8691
WARNING: Command 'git rebase 883a837fd2addb1a32394e499fdfb053e2da8691' failed:
Auto-merging pyproject.toml
CONFLICT (content): Merge conflict in pyproject.toml

You will need to resolve conflicts in order to complete the upgrade.
INFO: Running extra recipe upgrade task: do_update_crates
ERROR: When reparsing 
/srv/pokybuild/yocto-worker/auh/build/build/workspace/recipes/python3-cryptography/python3-cryptography.bb:do_update_crates,
 the basehash value changed from 
fef8ca18792992c562db4247a5a95cc4fe145d2306d5ddb176f238d1809d4747 to 
b5ec6dcd10f171e3b81f748cd6dc8aa22e8a52fca539714ea303420f16a4dec0. The metadata 
is not deterministic and this needs to be fixed.
ERROR: The following commands may help:
ERROR: $ bitbake python3-cryptography -cdo_update_crates -Snone
ERROR: Then:
ERROR: $ bitbake python3-cryptography -cdo_update_crates -Sprintdiff

ERROR: Taskhash mismatch 
dab261c4583f88d59aa8bffe348b3ba4274b92654b31dd63f936c626ef7ff2a1 versus 
c712e08ac8e7b361b840b901bd1a42d39624b0bdc35310c509af4687bef3cadf for 
/srv/pokybuild/yocto-worker/auh/build/build/workspace/recipes/python3-cryptography/python3-cryptography.bb:do_update_crates
INFO: Upgraded source extracted to 
/srv/pokybuild/yocto-worker/auh/build/build/workspace/sources/python3-cryptography
INFO: New recipe is 
/srv/pokybuild/yocto-worker/auh/build/build/workspace/recipes/python3-cryptography/python3-cryptography.bb
INFO: Changelog extracted to 
/srv/pokybuild/yocto-worker/auh/build/build/workspace/changelogs/python3-cryptography.txt



Please review the attached files for further information and build/update 
failures.
Any problem please file a bug at 
https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler

Regards,
The Upgrade Helper
Changelog for python3-cryptography: 49.0.0 -> 50.0.0
Source: CHANGELOG.rst

50.0.0 - 2026-07-31
~~~~~~~~~~~~~~~~~~~

* **SECURITY ISSUE**:
  :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`
  and its PEM and S/MIME variants no longer expose distinguishable errors or
  timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which could
  act as a Bleichenbacher oracle for callers that decrypt untrusted messages.
  A random key is now substituted on failure, as described in :rfc:`3218`.
  Credit to **@X1AOxiang** for reporting the issue
* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).
  Everything FFDH is deprecated, including the types in
  ``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys or
  parameters with the key loading APIs. Users should migrate to a more
  modern key exchange algorithm.
* Added ``xof()`` class methods to
  :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and
  :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing
  algorithm instances configured for use with
  :class:`~cryptography.hazmat.primitives.hashes.XOFHash`.
* The :mod:`X.509 verification <cryptography.x509.verification>` APIs are now
  considered stable and are subject to our API stability policy.
* Added the :doc:`/cobblestone` recipe, an implementation of the
  Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP
  chunked-encryption specification
  <https://c2sp.org/chunked-encryption>`_ for streaming authenticated
  encryption of large messages.
* Parsing a Signed Certificate Timestamp list now rejects encodings that
  carry trailing bytes after the list or after an individual SCT, instead of
  silently ignoring them.
* Added support for using :class:`~cryptography.x509.Name` as a field type in
  the :doc:`/hazmat/asn1/index` module.
* Loading a public key or an EC private key now rejects DER where the
  ``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a non-zero
  number of unused bits, instead of silently ignoring it.
* Parsing a CRL entry's ``InvalidityDate`` extension now rejects a
  ``GeneralizedTime`` that carries fractional seconds or another non-DER form,
  matching the strict encoding already required for every other X.509 time
  field.
* :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and
  :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request
  or response whose ``version`` field is not ``v1``, the only version defined
  by RFC 6960, matching the version validation already performed when loading
  certificates, CSRs and CRLs.
* :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported
  when building against AWS-LC.
* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when
  building against AWS-LC.
* Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported
  when building against AWS-LC.
* :func:`~cryptography.hazmat.primitives.serialization.load_der_public_key` and
  :func:`~cryptography.hazmat.primitives.serialization.load_pem_public_key` now
  reject Diffie-Hellman public keys whose modulus is smaller than 512 bits,
  matching the minimum already enforced when loading DH private keys and when
  constructing 
:class:`~cryptography.hazmat.primitives.asymmetric.dh.DHParameterNumbers`.
* Added
  :class:`~cryptography.hazmat.primitives.asymmetric.mldsa.MLDSAMuHasher` for
  incrementally computing the ML-DSA ``mu`` (message representative) used by
  the external-mu signing and verification APIs.
* The builtin :class:`~cryptography.hazmat.primitives.hashes.HashAlgorithm`
  classes and the classes in
  :mod:`~cryptography.hazmat.primitives.asymmetric.padding` can now be
  compared with ``==``.
* :class:`~cryptography.x509.CertificateBuilder` now supports creating unsigned
  certificates (:rfc:`9925`) with the ``create_unsigned`` method.
* The :mod:`X.509 verification <cryptography.x509.verification>` APIs now
  permit ML-DSA-44, ML-DSA-65, and ML-DSA-87 (:rfc:`9881`) public keys and
  signatures by default.
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#242459): 
https://lists.openembedded.org/g/openembedded-core/message/242459
Mute This Topic: https://lists.openembedded.org/mt/120546125/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • [OE-core] [AUH] python3-cry... Auto Upgrade Helper via lists.openembedded.org

Reply via email to