Skip to content

Unblock security dependency updates and retire Bullseye - #5

Open
ibrahim halatci (ihalatci) wants to merge 6 commits into
mainfrom
automation/relax-msgpack-tornado-caps
Open

Unblock security dependency updates and retire Bullseye#5
ibrahim halatci (ihalatci) wants to merge 6 commits into
mainfrom
automation/relax-msgpack-tornado-caps

Conversation

@ihalatci

@ihalatci ibrahim halatci (ihalatci) commented Jul 1, 2026

Copy link
Copy Markdown

Summary

Unblock Citus's dependency-security-sync while preserving the fork's TCP-kill behavior and the existing msgpack cap relaxation.

Dependency Previous upper bound New upper bound
msgpack 1.1.2 1.2.1
tornado 6.5.5 6.5.8
h2 4.3.0 4.4.1
cryptography 48.1 50.0.0

The cryptography, h2 and tornado bounds match current upstream support. Synchronize the corresponding uv.lock dependency metadata without changing unrelated resolved versions or importing upstream wholesale.

Cryptography 50 uses OpenSSL 4, which can reject SSL3 during protocol configuration rather than the handshake. Extend the existing narrow SSL.Error handling in is_supported_version to cover that configuration step, preserving the unsupported-version=false contract. Add deterministic regression coverage for both protocol setters; context construction and cipher configuration remain outside the catch.

Replace both Linux standalone-build containers (x86_64 and ARM64) from Debian 11/Bullseye to Debian 12/Bookworm. This removes the expired Bullseye repository failure without bypassing apt freshness or signature checks. The changelog records the supported standalone-binary glibc baseline moving from 2.31 to 2.36. Release Docker images already use Trixie and are unchanged.

Coordinated downstream updates

Citus consumes runtime-fix commit a16444362cc0393ccf7329f50fc909b711729de7. The later Bookworm commit changes only CI/changelog, so no further runtime-pin churn is needed. Merge the the-process requirements PR before the generated Citus dependency PR so the post-merge workflow can advance Citus to the release-image tag. No PRs have been merged by this work.

Validation

  • WSL Ubuntu-22.04, Python 3.12; focused TCP/TCP-kill, TLS, HTTP/2, certificate and Tornado/web suites: 199 passed, 1 platform skip on both the original locked environment and an environment using cryptography 50.0.0, h2 4.4.1 and tornado 6.5.8.
  • Lock consistency and dependency checks pass in both environments; patched mitmdump starts with OpenSSL 4.0.1.
  • Actual security-sync workflow addressed all three packages across both dependency trees and generated both downstream PRs.
  • Bookworm push CI completed successfully: https://github.com/citusdata/mitmproxy/actions/runs/34461400099

Co-authored-by: Copilot App 223556219+Copilot@users.noreply.github.com

Raise the upper bounds on msgpack (<=1.1.2 -> <=1.2.1) and tornado
(<=6.5.5 -> <=6.5.7) so downstream consumers (citus regress tests) can
pick up security-relevant patch releases while still pinning mitmproxy
to a controlled range. Consistent with the fork's existing relaxations
of urwid and cryptography.

Verified: a real `pipenv lock` of the citus src/test/regress/Pipfile
with mitmproxy pointed at this change resolves msgpack==1.2.1 and
tornado==6.5.7 while preserving the cryptography==46.0.7 pin.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@autofix-troubleshooter

Copy link
Copy Markdown

Hi! I'm the autofix logoautofix.ci troubleshooter bot.

It looks like you correctly set up a CI job that uses the autofix.ci GitHub Action, but the autofix.ci GitHub App has not been installed for this repository. This means that autofix.ci unfortunately does not have the permissions to fix this pull request. If you are the repository owner, please install the app and then restart the CI workflow! 😃

cap experiment and others added 3 commits July 1, 2026 17:13
Regenerate uv.lock so uv sync --locked matches the pyproject.toml cap

relaxation (msgpack<=1.2.1, tornado<=6.5.7). Only the requires-dist

specifiers change; no resolved versions move (1.1.2/6.5.5 still satisfy

the widened caps), keeping the fork diff minimal.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@ihalatci ibrahim halatci (ihalatci) changed the title Relax msgpack and tornado dependency caps Relax security dependency caps and support OpenSSL 4 Sep 10, 2026
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@ihalatci ibrahim halatci (ihalatci) changed the title Relax security dependency caps and support OpenSSL 4 Unblock security dependency updates and retire Bullseye Sep 10, 2026
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants