Showing content from http://mail.python.org/pipermail/python-dev/attachments/20180820/8f19e58a/attachment.html below:
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<p><br>
</p>
If they're really all wontfix, maybe we should mark them as wontfix,
thus giving 3.4 a sendoff worthy of its heroic stature.<br>
<br>
Godspeed, and may a flight of angels sing thee to thy rest,<br>
<br>
<br>
<i>/arry</i><br>
<br>
<div class="moz-cite-prefix">On 08/20/2018 05:52 AM, Victor Stinner
wrote:<br>
</div>
<blockquote type="cite"
cite="mid:CA+3bQGH0AbaWGyCNRHZ3E_TOS_mXGxWi0+SmT6-irZEAuaTqUg@mail.gmail.com">
<meta http-equiv="content-type" content="text/html; charset=utf-8">
> "shutil copy* unsafe on POSIX - they preserve setuid/setgit
bits"<br>
> <a href="https://bugs.python.org/issue17180"
moz-do-not-send="true">https://bugs.python.org/issue17180</a><br>
<br>
There is no fix. A fix may break the backward compatibility. Is it
really worth it for the last 3.4 release?<br>
<br>
> "XML vulnerabilities in Python"<br>
> <a href="https://bugs.python.org/issue17239"
moz-do-not-send="true">https://bugs.python.org/issue17239</a><br>
<br>
Bug inactive since 2015. I don't expect that anyone will step in
next weeks with a wonderful solution to all XML issues. I suggest
to ignore this one as well, this issue is as old as XML support in
Python and I am not aware of any victim of these issues.<br>
<br>
Obviously, it would be "nice" to see a fix for these issues but it
seems like core devs are more interested to work on other topics
and other security issues.<br>
<br>
<br>
> "fflush called on pointer to potentially closed file"
(Windows only)<br>
> <a href="https://bugs.python.org/issue19050"
moz-do-not-send="true">https://bugs.python.org/issue19050</a><br>
<br>
It seems like two core devs are opposed to fix this issue.<br>
<br>
--<br>
<br>
There are open security issues on the HTTP server and urllib. I am
more concerned by these issues, but it's hard to fix them, there
is a risk of introducing regressions.<br>
<br>
Victor
</blockquote>
<br>
</body>
</html>
RetroSearch is an open source project built by @garambo
| Open a GitHub Issue
Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo
HTML:
3.2
| Encoding:
UTF-8
| Version:
0.7.4