pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/www/py-tornado



Module Name:    pkgsrc
Committed By:   wiz
Date:           Sat Sep 26 10:40:16 UTC 2026

Modified Files:
        pkgsrc/www/py-tornado: Makefile distinfo

Log Message:
py-tornado: update to 6.5.10.

6.5.10

Bug fixes

tornado.web

    The allowed_symlink_directory argument of StaticFileHandler
    may now be a list of directories instead of just a single
    directory. This feature has been adjusted to improve compatibility
    with Jupyter, which would fail to load with Tornado 6.5.9.

6.5.9

Sep 14, 2026

Security fixes

    StaticFileHandler no longer follows symlinks outside of the
    static root directory. Applications that wish to continue the
    previous behavior may set the new argument allowed_symlink_directory
    to the directory (an ancestor of the static root) that should
    be used for symlink validation. Thanks to Yasha-ops and
    iaohkut-from-NightWolf-Team for reporting this issue.

    curl_httpclient has a new max_body_size argument (default 100MB,
    same as for simple_httpclient). This limit is enforced on all
    requests, whether or not streaming_callback is used. curl_httpclient
    now also controls its memory usage when decompressing response
    bodies. Thanks to afldl, iaohkut-from-NightWolf-Team, and
    aoto-tech for reporting this issue.

    simple_httpclient now correctly applies the max_body_size limit
    to responses using HTTP/1.0 format (no Content-Length or
    Transfer-Encoding). Previously it silently truncated such
    responses at max_buffer_size instead. Thanks to afldl for
    reporting this issue.

    simple_httpclient now rejects responses that use more than 10
    100 Continue responses, which could previously cause stack
    overflow errors. Thanks to afldl for reporting this issue.

    The limit ParseBodyConfig.urlencoded.max_argument is now applied
    to URL arguments in addition to POST bodies. Thanks to
    iaohkut-from-NightWolf-Team, afldl, and manus-pi for reporting
    this issue.

Bug fixes

tornado.iostream

    .IOStream.read_until_close now reports errors correctly when a
    stream is closed due to an error or exceeds a memory limit.
    Previously it would report a successful read of whatever was
    in the buffer. Connection resets are still treated as a normal
    close (as they are elsewhere in IOStream), since some platforms
    report a clean shutdown by the peer this way.


To generate a diff of this commit:
cvs rdiff -u -r1.50 -r1.51 pkgsrc/www/py-tornado/Makefile
cvs rdiff -u -r1.38 -r1.39 pkgsrc/www/py-tornado/distinfo

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: pkgsrc/www/py-tornado/Makefile
diff -u pkgsrc/www/py-tornado/Makefile:1.50 pkgsrc/www/py-tornado/Makefile:1.51
--- pkgsrc/www/py-tornado/Makefile:1.50 Fri Aug  7 08:28:01 2026
+++ pkgsrc/www/py-tornado/Makefile      Sat Sep 26 10:40:16 2026
@@ -1,6 +1,6 @@
-# $NetBSD: Makefile,v 1.50 2026/08/07 08:28:01 adam Exp $
+# $NetBSD: Makefile,v 1.51 2026/09/26 10:40:16 wiz Exp $
 
-DISTNAME=      tornado-6.5.8
+DISTNAME=      tornado-6.5.10
 PKGNAME=       ${PYPKGPREFIX}-${DISTNAME}
 CATEGORIES=    www python
 MASTER_SITES=  ${MASTER_SITE_PYPI:=t/tornado/}

Index: pkgsrc/www/py-tornado/distinfo
diff -u pkgsrc/www/py-tornado/distinfo:1.38 pkgsrc/www/py-tornado/distinfo:1.39
--- pkgsrc/www/py-tornado/distinfo:1.38 Fri Aug  7 08:28:01 2026
+++ pkgsrc/www/py-tornado/distinfo      Sat Sep 26 10:40:16 2026
@@ -1,5 +1,5 @@
-$NetBSD: distinfo,v 1.38 2026/08/07 08:28:01 adam Exp $
+$NetBSD: distinfo,v 1.39 2026/09/26 10:40:16 wiz Exp $
 
-BLAKE2s (tornado-6.5.8.tar.gz) = 9c09a9e07f2a8269cb8cded525642be74b1797eeac875bd9a51447c3abbfb100
-SHA512 (tornado-6.5.8.tar.gz) = 88c096ca30357644c07b6013cd514b5e64135b26a77d9ff17640951632d6f68c9a68d7fa80224743f7900fbf5ddde838088bd9838395651d87d876c8d1d1a2fe
-Size (tornado-6.5.8.tar.gz) = 520493 bytes
+BLAKE2s (tornado-6.5.10.tar.gz) = bcafa2e7ad4eddbde5f471a9975e0e4884419e89c7a4d2836611f9f8f57f5573
+SHA512 (tornado-6.5.10.tar.gz) = 0a3a38162a91d7d82f0d790d37788c5761bd9663af0356641bd6bd0ec5f6d490e5013965db1f91f28959d925127640cffbd4b661415b43ca5b50ee812841f445
+Size (tornado-6.5.10.tar.gz) = 537910 bytes



Home | Main Index | Thread Index | Old Index