Hi Yoann, Thanks for the review. I added python3-shell because the backported click.edit() fix imports shlex to split the editor command, and OE packages shlex.py in python3-shell. Without that runtime dependency, the fixed path can fail on a minimal image.
Click also imports shlex in master (8.5.0) and Wrynose (8.3.3). I’ve sent separate dependency patches for master [1] and Wrynose [2]. [1] https://lists.openembedded.org/g/openembedded-core/message/247148 [2] https://lists.openembedded.org/g/openembedded-core/message/247149 Best Regards, Darsh On Fri, Oct 2, 2026 at 02:37 PM, Yoann Congal wrote: > > On Wed Sep 23, 2026 at 8:36 AM CEST, Darsh Kelaiya -X (dkelaiya - E > INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote: > >> From: Darsh Kelaiya <[email protected]> >> >> This backports the click.edit() hardening identified as the fix in >> the public advisory [2], using upstream commit [1]. >> >> Upstream follow-up commit [3] adds regression-test coverage for editor >> command parsing and clarifies the related source comments. It does not >> change runtime behavior or provide an additional security fix. Carry it >> as a separate patch to preserve the upstream commit boundaries. >> >> [1] >> https://github.com/pallets/click/commit/b96c2601af4e01341b4d2c0db494ebee4aef8f42 >> >> [2] >> https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw >> >> [3] >> https://github.com/pallets/click/commit/b55294797ef32e22eb41e7d9657edb8faefa4976 >> >> >> Signed-off-by: Darsh Kelaiya <[email protected]> >> --- >> .../CVE-2026-7246-regression.patch | 124 +++++++++++ >> .../python/python3-click/CVE-2026-7246.patch | 201 ++++++++++++++++++ >> .../python/python3-click_8.1.7.bb | 6 +- >> 3 files changed, 330 insertions(+), 1 deletion(-) >> create mode 100644 >> meta/recipes-devtools/python/python3-click/CVE-2026-7246-regression.patch >> create mode 100644 >> meta/recipes-devtools/python/python3-click/CVE-2026-7246.patch >> >> [...] >> diff --git a/meta/recipes-devtools/python/python3-click_8.1.7.bb >> b/meta/recipes-devtools/python/python3-click_8.1.7.bb >> index b75d9108893..8a077f48c7c 100644 >> --- a/meta/recipes-devtools/python/python3-click_8.1.7.bb >> +++ b/meta/recipes-devtools/python/python3-click_8.1.7.bb >> @@ -12,7 +12,10 @@ SRC_URI[sha256sum] = >> "ca9853ad459e787e2192211578cc907e7594e294c7ccc834310722b41b >> >> inherit pypi setuptools3 ptest >> >> -SRC_URI += "file://run-ptest" >> +SRC_URI += "file://run-ptest \ >> + file://CVE-2026-7246.patch \ >> + file://CVE-2026-7246-regression.patch \ >> + " >> >> CVE_PRODUCT = "palletsprojects:click" >> >> @@ -36,6 +39,7 @@ CLEANBROKEN = "1" >> RDEPENDS:${PN} += "\ >> python3-io \ >> python3-threading \ > > Hello, > > >> + python3-shell \ > > Why was this added? master does not have this RDEPENDS. If that is an > issue to fix, then it should go through master (and other stables) > first. > > >> " >> >> BBCLASSEXTEND = "native nativesdk" > > FYI, the rest of the patch looks good to me. I've not found convincing > reason to ignore the CVE. So the fix is the way forward. > > Regards, > -- > Yoann Congal > Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#247150): https://lists.openembedded.org/g/openembedded-core/message/247150 Mute This Topic: https://lists.openembedded.org/mt/121388818/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
