Hi Yoann,

Thanks for the review. I added python3-shell because the backported 
click.edit() fix imports shlex to split the editor command, and OE packages 
shlex.py in python3-shell.
Without that runtime dependency, the fixed path can fail on a minimal image.

Click also imports shlex in master (8.5.0) and Wrynose (8.3.3). I’ve sent 
separate dependency patches for master [1] and Wrynose [2].

[1] https://lists.openembedded.org/g/openembedded-core/message/247148
[2] https://lists.openembedded.org/g/openembedded-core/message/247149

Best Regards,
Darsh

On Fri, Oct 2, 2026 at 02:37 PM, Yoann Congal wrote:

> 
> On Wed Sep 23, 2026 at 8:36 AM CEST, Darsh Kelaiya -X (dkelaiya - E
> INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> 
>> From: Darsh Kelaiya <[email protected]>
>> 
>> This backports the click.edit() hardening identified as the fix in
>> the public advisory [2], using upstream commit [1].
>> 
>> Upstream follow-up commit [3] adds regression-test coverage for editor
>> command parsing and clarifies the related source comments. It does not
>> change runtime behavior or provide an additional security fix. Carry it
>> as a separate patch to preserve the upstream commit boundaries.
>> 
>> [1] 
>> https://github.com/pallets/click/commit/b96c2601af4e01341b4d2c0db494ebee4aef8f42
>> 
>> [2] 
>> https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw
>> 
>> [3] 
>> https://github.com/pallets/click/commit/b55294797ef32e22eb41e7d9657edb8faefa4976
>> 
>> 
>> Signed-off-by: Darsh Kelaiya <[email protected]>
>> ---
>> .../CVE-2026-7246-regression.patch | 124 +++++++++++
>> .../python/python3-click/CVE-2026-7246.patch | 201 ++++++++++++++++++
>> .../python/python3-click_8.1.7.bb | 6 +-
>> 3 files changed, 330 insertions(+), 1 deletion(-)
>> create mode 100644
>> meta/recipes-devtools/python/python3-click/CVE-2026-7246-regression.patch
>> create mode 100644
>> meta/recipes-devtools/python/python3-click/CVE-2026-7246.patch
>> 
>> [...]
>> diff --git a/meta/recipes-devtools/python/python3-click_8.1.7.bb
>> b/meta/recipes-devtools/python/python3-click_8.1.7.bb
>> index b75d9108893..8a077f48c7c 100644
>> --- a/meta/recipes-devtools/python/python3-click_8.1.7.bb
>> +++ b/meta/recipes-devtools/python/python3-click_8.1.7.bb
>> @@ -12,7 +12,10 @@ SRC_URI[sha256sum] =
>> "ca9853ad459e787e2192211578cc907e7594e294c7ccc834310722b41b
>> 
>> inherit pypi setuptools3 ptest
>> 
>> -SRC_URI += "file://run-ptest"
>> +SRC_URI += "file://run-ptest \
>> + file://CVE-2026-7246.patch \
>> + file://CVE-2026-7246-regression.patch \
>> + "
>> 
>> CVE_PRODUCT = "palletsprojects:click"
>> 
>> @@ -36,6 +39,7 @@ CLEANBROKEN = "1"
>> RDEPENDS:${PN} += "\
>> python3-io \
>> python3-threading \
> 
> Hello,
> 
> 
>> + python3-shell \
> 
> Why was this added? master does not have this RDEPENDS. If that is an
> issue to fix, then it should go through master (and other stables)
> first.
> 
> 
>> "
>> 
>> BBCLASSEXTEND = "native nativesdk"
> 
> FYI, the rest of the patch looks good to me. I've not found convincing
> reason to ignore the CVE. So the fix is the way forward.
> 
> Regards,
> --
> Yoann Congal
> Smile ECS
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#247150): 
https://lists.openembedded.org/g/openembedded-core/message/247150
Mute This Topic: https://lists.openembedded.org/mt/121388818/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • ... Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Yoann Congal via lists.openembedded.org
      • ... Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org

Reply via email to