Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

{Packaging} Bump cryptography to 41.0.1 and pyOpenSSL to 23.2.0 on Linux and MacOS #26671

Merged
merged 1 commit into from
Jun 29, 2023

Conversation

jiasli
Copy link
Member

@jiasli jiasli commented Jun 14, 2023

Description
Rework of #26596

As explained in #26596 (comment), only bumping cryptography is not enough. pyOpenSSL should be bumped at the same time.

Close #25913

@azure-client-tools-bot-prd
Copy link

azure-client-tools-bot-prd bot commented Jun 14, 2023

️✔️AzureCLI-FullTest
️✔️acr
️✔️2020-09-01-hybrid
️✔️3.10
️✔️3.9
️✔️latest
️✔️3.10
️✔️3.9
️✔️acs
️✔️2020-09-01-hybrid
️✔️3.10
️✔️3.9
️✔️latest
️✔️3.10
️✔️3.9
️✔️advisor
️✔️latest
️✔️3.10
️✔️3.9
️✔️ams
️✔️latest
️✔️3.10
️✔️3.9
️✔️apim
️✔️latest
️✔️3.10
️✔️3.9
️✔️appconfig
️✔️latest
️✔️3.10
️✔️3.9
️✔️appservice
️✔️latest
️✔️3.10
️✔️3.9
️✔️aro
️✔️latest
️✔️3.10
️✔️3.9
️✔️backup
️✔️latest
️✔️3.10
️✔️3.9
️✔️batch
️✔️latest
️✔️3.10
️✔️3.9
️✔️batchai
️✔️latest
️✔️3.10
️✔️3.9
️✔️billing
️✔️latest
️✔️3.10
️✔️3.9
️✔️botservice
️✔️latest
️✔️3.10
️✔️3.9
️✔️cdn
️✔️latest
️✔️3.10
️✔️3.9
️✔️cloud
️✔️latest
️✔️3.10
️✔️3.9
️✔️cognitiveservices
️✔️latest
️✔️3.10
️✔️3.9
️✔️config
️✔️latest
️✔️3.10
️✔️3.9
️✔️configure
️✔️latest
️✔️3.10
️✔️3.9
️✔️consumption
️✔️latest
️✔️3.10
️✔️3.9
️✔️container
️✔️latest
️✔️3.10
️✔️3.9
️✔️core
️✔️2018-03-01-hybrid
️✔️3.10
️✔️3.9
️✔️2019-03-01-hybrid
️✔️3.10
️✔️3.9
️✔️2020-09-01-hybrid
️✔️3.10
️✔️3.9
️✔️latest
️✔️3.10
️✔️3.9
️✔️cosmosdb
️✔️latest
️✔️3.10
️✔️3.9
️✔️databoxedge
️✔️2019-03-01-hybrid
️✔️3.10
️✔️3.9
️✔️2020-09-01-hybrid
️✔️3.10
️✔️3.9
️✔️latest
️✔️3.10
️✔️3.9
️✔️dla
️✔️latest
️✔️3.10
️✔️3.9
️✔️dls
️✔️latest
️✔️3.10
️✔️3.9
️✔️dms
️✔️latest
️✔️3.10
️✔️3.9
️✔️eventgrid
️✔️latest
️✔️3.10
️✔️3.9
️✔️eventhubs
️✔️latest
️✔️3.10
️✔️3.9
️✔️feedback
️✔️latest
️✔️3.10
️✔️3.9
️✔️find
️✔️latest
️✔️3.10
️✔️3.9
️✔️hdinsight
️✔️latest
️✔️3.10
️✔️3.9
️✔️identity
️✔️latest
️✔️3.10
️✔️3.9
️✔️iot
️✔️2019-03-01-hybrid
️✔️3.10
️✔️3.9
️✔️2020-09-01-hybrid
️✔️3.10
️✔️3.9
️✔️latest
️✔️3.10
️✔️3.9
️✔️keyvault
️✔️2018-03-01-hybrid
️✔️3.10
️✔️3.9
️✔️2020-09-01-hybrid
️✔️3.10
️✔️3.9
️✔️latest
️✔️3.10
️✔️3.9
️✔️kusto
️✔️latest
️✔️3.10
️✔️3.9
️✔️lab
️✔️latest
️✔️3.10
️✔️3.9
️✔️managedservices
️✔️latest
️✔️3.10
️✔️3.9
️✔️maps
️✔️latest
️✔️3.10
️✔️3.9
️✔️marketplaceordering
️✔️latest
️✔️3.10
️✔️3.9
️✔️monitor
️✔️latest
️✔️3.10
️✔️3.9
️✔️mysql
️✔️latest
️✔️3.10
️✔️3.9
️✔️netappfiles
️✔️latest
️✔️3.10
️✔️3.9
️✔️network
️✔️2018-03-01-hybrid
️✔️3.10
️✔️3.9
️✔️latest
️✔️3.10
️✔️3.9
️✔️policyinsights
️✔️latest
️✔️3.10
️✔️3.9
️✔️privatedns
️✔️latest
️✔️3.10
️✔️3.9
️✔️profile
️✔️latest
️✔️3.10
️✔️3.9
️✔️rdbms
️✔️latest
️✔️3.10
️✔️3.9
️✔️redis
️✔️latest
️✔️3.10
️✔️3.9
️✔️relay
️✔️latest
️✔️3.10
️✔️3.9
️✔️resource
️✔️2018-03-01-hybrid
️✔️3.10
️✔️3.9
️✔️2019-03-01-hybrid
️✔️3.10
️✔️3.9
️✔️latest
️✔️3.10
️✔️3.9
️✔️role
️✔️latest
️✔️3.10
️✔️3.9
️✔️search
️✔️latest
️✔️3.10
️✔️3.9
️✔️security
️✔️latest
️✔️3.10
️✔️3.9
️✔️servicebus
️✔️latest
️✔️3.10
️✔️3.9
️✔️serviceconnector
️✔️latest
️✔️3.10
️✔️3.9
️✔️servicefabric
️✔️latest
️✔️3.10
️✔️3.9
️✔️signalr
️✔️latest
️✔️3.10
️✔️3.9
️✔️sql
️✔️latest
️✔️3.10
️✔️3.9
️✔️sqlvm
️✔️latest
️✔️3.10
️✔️3.9
️✔️storage
️✔️2018-03-01-hybrid
️✔️3.10
️✔️3.9
️✔️2019-03-01-hybrid
️✔️3.10
️✔️3.9
️✔️2020-09-01-hybrid
️✔️3.10
️✔️3.9
️✔️latest
️✔️3.10
️✔️3.9
️✔️synapse
️✔️latest
️✔️3.10
️✔️3.9
️✔️telemetry
️✔️2018-03-01-hybrid
️✔️3.10
️✔️3.9
️✔️2019-03-01-hybrid
️✔️3.10
️✔️3.9
️✔️2020-09-01-hybrid
️✔️3.10
️✔️3.9
️✔️latest
️✔️3.10
️✔️3.9
️✔️util
️✔️latest
️✔️3.10
️✔️3.9
️✔️vm
️✔️2018-03-01-hybrid
️✔️3.10
️✔️3.9
️✔️2019-03-01-hybrid
️✔️3.10
️✔️3.9
️✔️2020-09-01-hybrid
️✔️3.10
️✔️3.9
️✔️latest
️✔️3.10
️✔️3.9

@azure-client-tools-bot-prd
Copy link

azure-client-tools-bot-prd bot commented Jun 14, 2023

️✔️AzureCLI-BreakingChangeTest
️✔️Non Breaking Changes

@ghost ghost requested review from wangzelin007, yonzhan and bebound June 14, 2023 09:01
@ghost ghost added the Auto-Assign Auto assign by bot label Jun 14, 2023
@ghost ghost assigned bebound Jun 14, 2023
@ghost ghost added the Packaging label Jun 14, 2023
@jiasli
Copy link
Member Author

jiasli commented Jun 14, 2023

Discussion: Should we silence the warning raised by cryptography on 32-bit Python (#25690)?

I did consider disabling the warning by calling warnings.filterwarnings or warnings.simplefilter:

import platform

if platform.system() == 'Windows' and platform.architecture()[0].startswith('32'):
    import warnings
    warnings.simplefilter("ignore", category=UserWarning)

import cryptography.hazmat.bindings.openssl.binding

but I think it is good to keep that warning to encourage people to upgrade to 64-bit Azure CLI once #26640 has been released.

Additional information
Even if we have --only-show-errors, it doesn't work here as the warning is printed by warnings module, instead of Azure CLI's logger's warning method.

bebound
bebound previously approved these changes Jun 29, 2023
@@ -1,5 +1,8 @@
pushd %~dp0..\..

Rem Upgrade pip to the latest version
python -m pip install --upgrade pip
Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Upgrading pip makes VerifyWindowsRequirements, VerifyLinuxRequirements and VerifyDarwinRequirements have the same logic as other package building jobs, such as BuildDebPackages.

It can utilize the latest pip's error message to better find dependency resolution failures.

@jiasli jiasli marked this pull request as ready for review June 29, 2023 02:25
@jiasli
Copy link
Member Author

jiasli commented Jun 29, 2023

We have decided to keep the warning, as it is printed to stderr and this is not considered a breaking change. If your pipelines have failOnStderr set to true and you encounter failure due to the warning message

UserWarning: You are using cryptography on a 32-bit Python on a 64-bit Windows Operating System. Cryptography 
will be significantly faster if you switch to using a 64-bit Python.

please set failOnStderr to false. More information can be found at #18372.

Update: We finally decided to postpone the version bump on Windows until Windows 64-bit MSI has been released (#26640).

wangzelin007
wangzelin007 previously approved these changes Jun 29, 2023
jsntcy
jsntcy previously approved these changes Jun 29, 2023
@jiasli jiasli dismissed stale reviews from jsntcy, wangzelin007, and bebound via 482f3a4 June 29, 2023 06:58
@jiasli jiasli merged commit 67ffb1b into Azure:dev Jun 29, 2023
@jiasli jiasli deleted the cryptography branch June 29, 2023 08:39
@jiasli jiasli changed the title {Packaging} Bump cryptography to 41.0.1 and pyOpenSSL to 23.2.0 {Packaging} Bump cryptography to 41.0.1 and pyOpenSSL to 23.2.0 on Linux and MacOS Jul 21, 2023
avgale pushed a commit to avgale/azure-cli that referenced this pull request Aug 24, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Auto-Assign Auto assign by bot Packaging
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Cryptography Package S360 Security Vulnerability
4 participants