Re: [python-committers] Gratuitous? incompatibilities in the fix only releases

2015-07-29 Thread Robert Collins
On 30 July 2015 at 04:50, Guido van Rossum gu...@python.org wrote: I believe that in this particular case, the bug was fixed (by tightening the requirements for headers) because the bug can lead to security vulnerabilities. I think you can find more by Googling for keywords like http header

Re: [python-committers] Gratuitous? incompatibilities in the fix only releases

2015-07-29 Thread Guido van Rossum
I believe that in this particular case, the bug was fixed (by tightening the requirements for headers) because the bug can lead to security vulnerabilities. I think you can find more by Googling for keywords like http header injection. The more recent Python 2.7 bugfix releases have specific

Re: [python-committers] Gratuitous? incompatibilities in the fix only releases

2015-07-29 Thread Eric Snow
On Jul 29, 2015 11:08 AM, Robert Collins robe...@robertcollins.net wrote: On 30 July 2015 at 04:50, Guido van Rossum gu...@python.org wrote: The more recent Python 2.7 bugfix releases have specific exemptions from the backwards compatibility requirements for security fixes -- because their

Re: [python-committers] Gratuitous? incompatibilities in the fix only releases

2015-07-29 Thread Jesus Cea
On 29/07/15 18:50, Guido van Rossum wrote: I believe that in this particular case, the bug was fixed (by tightening the requirements for headers) because the bug can lead to security vulnerabilities. I think you can find more by Googling for keywords like http header injection. The more recent

Re: [python-committers] Gratuitous? incompatibilities in the fix only releases

2015-07-29 Thread Jason R. Coombs
For reference, a similar bug fix also introduced incompatibilities with the Chishop service: http://bugs.python.org/issue23899 On Jul 29, 2015, at 12:06, Jesus Cea j...@jcea.esmailto:j...@jcea.es wrote: Yesterday I upgraded one of my computer to 2.7.10 and a program working for years failed.

Re: [python-committers] Gratuitous? incompatibilities in the fix only releases

2015-07-29 Thread Robert Collins
On 30 July 2015 at 05:20, Eric Snow ericsnowcurren...@gmail.com wrote: On Jul 29, 2015 11:08 AM, Robert Collins robe...@robertcollins.net wrote: On 30 July 2015 at 04:50, Guido van Rossum gu...@python.org wrote: The more recent Python 2.7 bugfix releases have specific exemptions from the

Re: [python-committers] Gratuitous? incompatibilities in the fix only releases

2015-07-29 Thread Terry Reedy
On 7/29/2015 1:01 PM, Robert Collins wrote: On 30 July 2015 at 04:50, Guido van Rossum gu...@python.org wrote: I believe that in this particular case, the bug was fixed (by tightening the requirements for headers) because the bug can lead to security vulnerabilities. I think you can find more

Re: [python-committers] Gratuitous? incompatibilities in the fix only releases

2015-07-29 Thread Guido van Rossum
When in doubt, such discussions should be escalated to python-dev. I don't know if this one was, though I vaguely recall seeing it discussed somewhere. Anyway, since it's been released, it should stay in. On Wed, Jul 29, 2015 at 7:31 PM, Robert Collins robe...@robertcollins.net wrote: On 30

Re: [python-committers] Gratuitous? incompatibilities in the fix only releases

2015-07-29 Thread R. David Murray
On Wed, 29 Jul 2015 13:41:09 -0400, Terry Reedy tjre...@udel.edu wrote: On 7/29/2015 1:01 PM, Robert Collins wrote: On 30 July 2015 at 04:50, Guido van Rossum gu...@python.org wrote: I believe that in this particular case, the bug was fixed (by tightening the requirements for headers)

Re: [python-committers] Gratuitous? incompatibilities in the fix only releases

2015-07-29 Thread R. David Murray
On Thu, 30 Jul 2015 00:11:53 +0200, Jesus Cea j...@jcea.es wrote: On 29/07/15 18:50, Guido van Rossum wrote: I believe that in this particular case, the bug was fixed (by tightening the requirements for headers) because the bug can lead to security vulnerabilities. I think you can find more