lists.arthurdejong.org
RSS feed

python-pskc branch master updated. 1.4-8-g6bcd027

[Date Prev][Date Next] [Thread Prev][Thread Next]

python-pskc branch master updated. 1.4-8-g6bcd027



This is an automated email from the git hooks/post-receive script. It was
generated because a ref change was pushed to the repository containing
the project "python-pskc".

The branch, master has been updated
       via  6bcd0274db24467f7c9c410b31461228f70d6620 (commit)
       via  fb4ae2925500c4d9a68e62b4f54b6ba756207437 (commit)
       via  de54716034dcfd7c24de0c579730c423c1c53899 (commit)
       via  0ac1fbe5932a1b74caa63652fd9978284e846b66 (commit)
      from  cd4b3779be39de882998c9aa89bb82bce1aa924c (commit)

Those revisions listed above that are new to this repository have
not appeared on any other notification email; so we list those
revisions in full, below.

- Log -----------------------------------------------------------------
https://arthurdejong.org/git/python-pskc/commit/?id=6bcd0274db24467f7c9c410b31461228f70d6620

commit 6bcd0274db24467f7c9c410b31461228f70d6620
Author: Arthur de Jong <arthur@arthurdejong.org>
Date:   Sat Jul 18 17:27:47 2026 +0200

    Ensure test certificate has keyUsage attribute
    
    Newer versions of cryptography check for the presence of the X509
    extension.

diff --git a/tests/certificate/README b/tests/certificate/README
index 100826d..7f46cd4 100644
--- a/tests/certificate/README
+++ b/tests/certificate/README
@@ -23,7 +23,8 @@ openssl req \
   -new \
   -key key.pem -out request.pem \
   -subj '/C=NL/O=python-pskc/CN=Test signing' \
-  -addext 'subjectAltName = email:test-signing@example.com'
+  -addext 'subjectAltName = email:test-signing@example.com' \
+  -addext 'keyUsage = digitalSignature'
 
 openssl x509 \
   -req \
diff --git a/tests/certificate/certificate.pem 
b/tests/certificate/certificate.pem
index 7e19000..7b09cd6 100644
--- a/tests/certificate/certificate.pem
+++ b/tests/certificate/certificate.pem
@@ -1,20 +1,21 @@
 -----BEGIN CERTIFICATE-----
-MIIDUTCCAjmgAwIBAgIBKjANBgkqhkiG9w0BAQsFADA1MQswCQYDVQQGEwJOTDEU
-MBIGA1UECgwLcHl0aG9uLXBza2MxEDAOBgNVBAMMB1Rlc3QgQ0EwHhcNMjQwODI3
-MjEyODM1WhcNMzQwODI1MjEyODM1WjA6MQswCQYDVQQGEwJOTDEUMBIGA1UECgwL
+MIIDXjCCAkagAwIBAgIBKjANBgkqhkiG9w0BAQsFADA1MQswCQYDVQQGEwJOTDEU
+MBIGA1UECgwLcHl0aG9uLXBza2MxEDAOBgNVBAMMB1Rlc3QgQ0EwHhcNMjYwNzE4
+MTUyNTUwWhcNMzYwNzE1MTUyNTUwWjA6MQswCQYDVQQGEwJOTDEUMBIGA1UECgwL
 cHl0aG9uLXBza2MxFTATBgNVBAMMDFRlc3Qgc2lnbmluZzCCASIwDQYJKoZIhvcN
 AQEBBQADggEPADCCAQoCggEBAMTn3YiNxlR1mxUJyGhU65yvvzsKhl/4HpDmiVQo
 UGq7daxYLddLx9bW/OSUQmIZS9NiebcmZGJF0B1+ru3Au962+Cso69F4+mPN+xKo
 fqyQpl9gzgo5IXvFzvgjlVQYuSGjf6B5J+NoQbeuR/latqIrjT7K1QtDSYZr4WSN
 0BVI1JpEmQ3ucmIgwt9ZtC1mZg8ApznDs/yf8dfN6Y5jFYjCaRt+Qzzv/Uqx3rgK
 /tl8Kr1fJXGWaDI0afPrja7syVCkTs1VhMaZt5nXzEmX17W4PzBz3M6ElBrO06S2
-B++DDe2Hjip0wJ+qCUVmUQuDCdC9o35Oi6cf0RIy8gZReaECAwEAAaNnMGUwIwYD
-VR0RBBwwGoEYdGVzdC1zaWduaW5nQGV4YW1wbGUuY29tMB0GA1UdDgQWBBQaU4Kp
-x4G2yysRZ4du/WRn7/aBFTAfBgNVHSMEGDAWgBQT90iyrXa6/1Rj0NiHnsOe30Y8
-BzANBgkqhkiG9w0BAQsFAAOCAQEAJzt19KlSPCP2RH5wMI7OiVf+Zbt9inC1pCPb
-vRebgz2GuDRZu+WMlXQ9WXFLwZze+j7VVdx9k84MKfasLmkarUt6xc5fhxIzopMs
-Of2swbIjxKssdO9GNIhjuVnC2d3ltwPqBb/Y+mpuxRwQ2zoahS1bFxTxTnhXLxQx
-qEzWeJ66dplYdKnYsCsnB7yDv1A7KPQTy/zHzFzD9DBk9WCluyLJQ6DASjQlKr8M
-Uu42tVkfhTaBJTBfEh+HlJApSJP94xE5uY5iE2cLAlEPJwZk4BCQYM8B5JR4PpHq
-0L4dJYLcE5Id0f9xdO0D9L5/kmO4RipBXImdoNZwDoeqRx8aEw==
+B++DDe2Hjip0wJ+qCUVmUQuDCdC9o35Oi6cf0RIy8gZReaECAwEAAaN0MHIwIwYD
+VR0RBBwwGoEYdGVzdC1zaWduaW5nQGV4YW1wbGUuY29tMAsGA1UdDwQEAwIHgDAd
+BgNVHQ4EFgQUGlOCqceBtssrEWeHbv1kZ+/2gRUwHwYDVR0jBBgwFoAUE/dIsq12
+uv9UY9DYh57Dnt9GPAcwDQYJKoZIhvcNAQELBQADggEBAEx3eiwct1Hr+G+wIcCs
+PRY/xUH0DvTISEZXhIGFiJG6UTdyyEMTjhuZBYLS+WTV7ipqR2B6ZqBoQXbfnwJG
+IDbIS/J4DbpHvih3gvLz1F4tFm00gvZZ3fSvu3bSVymOKIH2KsOtcii3FWaL7uAK
+RvPDgztjPhZHKFETavOifTT5/GhVCTQccgr7kQ6+zEkmplu1jW+HZ8knL1THWGJq
+GHrLd/gh5s6CYx+lbO7layRVNynObMmyzrLRdUBDV/00e12ZMgtGpk1woUZ8fYij
+UsN4ihWq6CIYQZKhsnNJNU9dsuFvAHLKlcG6ql44yM2eVZekZBYfwqwRwur2X7hT
+hwA=
 -----END CERTIFICATE-----
diff --git a/tests/certificate/request.pem b/tests/certificate/request.pem
index 8d3f4c2..56916ef 100644
--- a/tests/certificate/request.pem
+++ b/tests/certificate/request.pem
@@ -1,17 +1,17 @@
 -----BEGIN CERTIFICATE REQUEST-----
-MIICtTCCAZ0CAQAwOjELMAkGA1UEBhMCTkwxFDASBgNVBAoMC3B5dGhvbi1wc2tj
+MIICwjCCAaoCAQAwOjELMAkGA1UEBhMCTkwxFDASBgNVBAoMC3B5dGhvbi1wc2tj
 MRUwEwYDVQQDDAxUZXN0IHNpZ25pbmcwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
 ggEKAoIBAQDE592IjcZUdZsVCchoVOucr787CoZf+B6Q5olUKFBqu3WsWC3XS8fW
 1vzklEJiGUvTYnm3JmRiRdAdfq7twLvetvgrKOvRePpjzfsSqH6skKZfYM4KOSF7
 xc74I5VUGLkho3+geSfjaEG3rkf5WraiK40+ytULQ0mGa+FkjdAVSNSaRJkN7nJi
 IMLfWbQtZmYPAKc5w7P8n/HXzemOYxWIwmkbfkM87/1Ksd64Cv7ZfCq9XyVxlmgy
 NGnz642u7MlQpE7NVYTGmbeZ18xJl9e1uD8wc9zOhJQaztOktgfvgw3th44qdMCf
-qglFZlELgwnQvaN+TounH9ESMvIGUXmhAgMBAAGgNjA0BgkqhkiG9w0BCQ4xJzAl
-MCMGA1UdEQQcMBqBGHRlc3Qtc2lnbmluZ0BleGFtcGxlLmNvbTANBgkqhkiG9w0B
-AQsFAAOCAQEAuVZnrqmn7SgQDAgzYI7dPLI2NeDwq4+1JOGOupEO4Iz9N4AEa5dt
-rj0FiFzLGRueskI0W6GgFW+FHxEiFVykGttY/oWXkjMziJWYu9QbV+JsmIHSi89y
-m4+zoSXEvZTDfmuj5D2FLTuDSLwIxbWLn+6c/3/hKsK1SdD7mJ/JA6gKcmuM+RAM
-mOOB5/ZJ5z/3heKoy68NR5kt3JdI1OJokoep0rb6hsImxf9j3gJXPFg8Rhg0spDh
-DOBzrlqTemokUc6n+2Xa3zY31rB7vaqfX47b4eLDZQ7Nj3Ap9Nu2wH0HXHQDiRI8
-G05Tf6c1fZNuIkEm42PqE072oWZcapnMfQ==
+qglFZlELgwnQvaN+TounH9ESMvIGUXmhAgMBAAGgQzBBBgkqhkiG9w0BCQ4xNDAy
+MCMGA1UdEQQcMBqBGHRlc3Qtc2lnbmluZ0BleGFtcGxlLmNvbTALBgNVHQ8EBAMC
+B4AwDQYJKoZIhvcNAQELBQADggEBAMGF7SY653d+XaU32E5+vwnCuURYF4UNGAxs
+uqZd6UwAiqj0Fdgd2j0/a2lAoEq3vwDRNVphBhjSsmRcM21tYlS3wgxmoSKzUpUc
+C47CreumM4wcXNjepYksU/Yyeob7JQgazfT1ke32FoA8/rLm65GGW6yIi0VHVrer
+sGCVqmI9oVput4ncjIdfW8uH1dlHQMo3OfL3lc/RVYHmhXKx27M3/M/9wy2vYcqG
+kk45mDNt6PCJpvQQYnz0ful9Zq8ogJ7IMHe3/F5KRDHhAAE6CSUnkHLecuL+Vs4Q
+wmZFdDdC0Si5ShMrLYFfLNCLFpTY+mGqSCRu3Wbm2YLHlyraDAo=
 -----END CERTIFICATE REQUEST-----

https://arthurdejong.org/git/python-pskc/commit/?id=fb4ae2925500c4d9a68e62b4f54b6ba756207437

commit fb4ae2925500c4d9a68e62b4f54b6ba756207437
Author: Arthur de Jong <arthur@arthurdejong.org>
Date:   Sat Jul 18 16:54:04 2026 +0200

    Be explicit about exception chaining

diff --git a/pskc/encryption.py b/pskc/encryption.py
index a35bfc5..4fff7b8 100644
--- a/pskc/encryption.py
+++ b/pskc/encryption.py
@@ -87,8 +87,8 @@ def _decrypt_cbc(
         return unpadder.update(
             decryptor.update(ciphertext) +
             decryptor.finalize()) + unpadder.finalize()
-    except ValueError:
-        raise DecryptionError('Invalid padding')
+    except ValueError as exc:
+        raise DecryptionError('Invalid padding') from exc
 
 
 def decrypt(algorithm: str | None, key: bytes | None, ciphertext: bytes, iv: 
bytes | None = None) -> bytes:
@@ -248,9 +248,9 @@ class KeyDerivation:
             return pbkdf2_hmac(
                 prf, password, self.pbkdf2_salt, self.pbkdf2_iterations,  # 
type: ignore[arg-type]
                 self.pbkdf2_key_length)
-        except ValueError:
+        except ValueError as exc:
             raise KeyDerivationError(
-                'Pseudorandom function unsupported: %r' % self.pbkdf2_prf)
+                'Pseudorandom function unsupported: %r' % self.pbkdf2_prf) 
from exc
 
     def derive(self, password: str | bytes | bytearray) -> bytes:
         """Derive a key from the password."""
diff --git a/pskc/parser.py b/pskc/parser.py
index 53458bc..3661471 100644
--- a/pskc/parser.py
+++ b/pskc/parser.py
@@ -76,8 +76,8 @@ class PSKCParser:
         """Parse the provided file and store data in the PSKC instance."""
         try:
             tree = parse(filename)
-        except Exception:
-            raise ParseError('Error parsing XML')
+        except Exception as exc:
+            raise ParseError('Error parsing XML') from exc
         # save a clean copy of the tree for signature checking
         pskc.signature.tree = copy.deepcopy(tree)
         cls.parse_document(pskc, tree.getroot())

https://arthurdejong.org/git/python-pskc/commit/?id=de54716034dcfd7c24de0c579730c423c1c53899

commit de54716034dcfd7c24de0c579730c423c1c53899
Author: Arthur de Jong <arthur@arthurdejong.org>
Date:   Sat Jul 18 16:00:20 2026 +0200

    Update to newer flake8
    
    Sadly the version of flake8 that supported a readable configuration no
    longer works on Python 3.14.
    
    This drop flake8-exact-pin because it is not compatible with Python
    3.14.

diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml
index b2c3395..8fd25d6 100644
--- a/.github/workflows/test.yml
+++ b/.github/workflows/test.yml
@@ -57,7 +57,7 @@ jobs:
       - name: Set up Python
         uses: actions/setup-python@v4
         with:
-          python-version: 3.13
+          python-version: 3.14
       - name: Install dependencies
         run: python -m pip install --upgrade pip tox
       - name: Run tox ${{ matrix.tox_job }}
diff --git a/setup.cfg b/setup.cfg
index ecd922a..36da508 100644
--- a/setup.cfg
+++ b/setup.cfg
@@ -24,11 +24,16 @@ builder = html man
 
 [flake8]
 ignore =
-  B902  # catching Exception is fine
-  D105  # Missing docstring in magic method
-  D107  # Missing docstring in __init__
-  Q001  # Use of ''' multiline strings
-  W504  # we put the binary operator on the preceding line
+  # catching Exception is fine:
+  B902
+  # Missing docstring in magic method:
+  D105
+  # Missing docstring in __init__:
+  D107
+  # Use of ''' multiline strings:
+  Q001
+  # we put the binary operator on the preceding line:
+  W504
 max-complexity = 14
 max-line-length = 120
 extend-exclude =
diff --git a/tox.ini b/tox.ini
index a388ab2..276df0b 100644
--- a/tox.ini
+++ b/tox.ini
@@ -17,7 +17,7 @@ setenv=
 
 [testenv:flake8]
 skip_install = true
-deps = flake8<6.0
+deps = flake8
        flake8-author
        flake8-blind-except
        flake8-bugbear
@@ -25,7 +25,6 @@ deps = flake8<6.0
        flake8-commas
        flake8-deprecated
        flake8-docstrings
-       flake8-exact-pin
        flake8-import-order
        flake8-print
        flake8-quotes

https://arthurdejong.org/git/python-pskc/commit/?id=0ac1fbe5932a1b74caa63652fd9978284e846b66

commit 0ac1fbe5932a1b74caa63652fd9978284e846b66
Author: Arthur de Jong <arthur@arthurdejong.org>
Date:   Sat Jul 18 15:59:31 2026 +0200

    Add lining override for attribute test

diff --git a/pskc/encryption.py b/pskc/encryption.py
index d94bbfc..a35bfc5 100644
--- a/pskc/encryption.py
+++ b/pskc/encryption.py
@@ -349,8 +349,9 @@ class Encryption:
         from pskc.exceptions import DecryptionError
         try:
             for key in self.pskc.keys:
-                key.secret, key.counter, key.time_offset
-                key.time_interval, key.time_drift
+                # Evaluate all the attributes which should trigger an exception
+                # of decryption is required
+                key.secret, key.counter, key.time_offset, key.time_interval, 
key.time_drift  # noqa: B018
         except DecryptionError:
             return True
         return False

-----------------------------------------------------------------------

Summary of changes:
 .github/workflows/test.yml        |  2 +-
 pskc/encryption.py                | 13 +++++++------
 pskc/parser.py                    |  4 ++--
 setup.cfg                         | 15 ++++++++++-----
 tests/certificate/README          |  3 ++-
 tests/certificate/certificate.pem | 25 +++++++++++++------------
 tests/certificate/request.pem     | 18 +++++++++---------
 tox.ini                           |  3 +--
 8 files changed, 45 insertions(+), 38 deletions(-)


hooks/post-receive
-- 
python-pskc