Sitelet https://github.com/python/cpython/issues/152216
Skip to content

Upgrade bundled Expat to 2.8.2 (e.g. for the fix to CVE-2026-56132 and 12 others) #152216

Activity

  1. zainnadeem786 commented on Jun 25, 2026

    @zainnadeem786
    Contributor

    Hi @hartwork @StanFromIreland

    I can take a look at this and prepare a focused PR if no one else is already working on it.

    I checked the previous Expat 2.8.1 update pattern from gh-149698 / gh-149699 and started comparing the bundled 2.8.1 copy with upstream 2.8.2.

    From the initial investigation, this looks like a focused vendoring update involving the refreshed Expat sources, the new upstream files mentioned here, SBOM metadata, and a Security NEWS entry while preserving CPython’s local Expat configuration and symbol namespacing.

    I’ll validate the update with the focused XML/pyexpat test suite before opening a PR.

  2. StanFromIreland commented on Jun 25, 2026

    @StanFromIreland
    Member

    I've assigned myself this, please check such things in the future.

  3. changed the title [-][security] Please upgrade bundled Expat to 2.8.2 (e.g. for the fix to CVE-2026-56132 and 12 others)[/-] [+]Upgrade bundled Expat to 2.8.2 (e.g. for the fix to CVE-2026-56132 and 12 others)[/+] on Jun 25, 2026
  4. added
    3.11only security fixes
    3.12only security fixes
    3.13only security fixes
    3.14bugs and security fixes
    3.15pre-release feature fixes, bugs and security fixes
    on Jun 25, 2026
  5. 13 remaining items

  6. neek78 commented on Jul 13, 2026

    @neek78
    Contributor

    Ok, it's because cpython's non-debug build turns on -Wunreachable-code - this results in warnings from both AppleClang and clang. It would be possible to disable -Wunreachable-code-fallthrough specifically.

  7. cdce8p commented on Jul 13, 2026

    @cdce8p
    Contributor

    Ok, it's because cpython's non-debug build turns on -Wunreachable-code - this results in warnings from both AppleClang and clang. It would be possible to disable -Wunreachable-code-fallthrough specifically.

    Should this be added to xmltok_impl.c upstream then?

    #ifdef __clang__
    #pragma clang diagnostic ignored "-Wunreachable-code-fallthrough"
    #endif
  8. hartwork commented on Jul 13, 2026

    @hartwork
    ContributorAuthor

    @cdce8p I have no interest in adding things like that to the Expat code base.

  9. neek78 commented on Jul 13, 2026

    @neek78
    Contributor

    @cdce8p I have no interest in adding things like that to the Expat code base.

    i tend to agree. Libexpat has its own buildsystem(s), which set appropriate flags for the code; Cpython takes the code, but builds it itself. I would suggest making the change in Cpython's build system for building expat somewhere.

    Out of interest, are these warnings showing up in CI ?

  10. cdce8p commented on Jul 13, 2026

    @cdce8p
    Contributor

    I have no interest in adding things like that to the Expat code base.

    In that case another option might be to add -Wno-unreachable-code-fallthrough here:

    cpython/Makefile.pre.in

    Lines 1451 to 1452 in 1fece44

    Modules/expat/xmltok.o: $(srcdir)/Modules/expat/xmltok.c $(LIBEXPAT_HEADERS) $(PYTHON_HEADERS)
    $(CC) -c $(LIBEXPAT_CFLAGS) -o $@ $(srcdir)/Modules/expat/xmltok.c

    @StanFromIreland Would that be acceptable?

  11. StanFromIreland commented on Jul 13, 2026

    @StanFromIreland
    Member

    I don't think we should be ignoring warnings, we also shouldn't be fixing them, they should be resolved upstream instead. Previously, there were several warnings which this update allowed us to remove from our ignore list.

  12. hartwork commented on Jul 13, 2026

    @hartwork
    ContributorAuthor

    I would like to note that Expat CI is using -Wall -Wextra -pedantic with -Werror and that -Wunreachable-code-fallthrough is beyond that. The goal of libexpat is to fix bugs, not to address warnings beyond -Wextra that do not expose actual bugs. If there is a bug to fix related to this warning, an in-depth analysis is welcome upstream.

  13. cdce8p commented on Jul 13, 2026

    @cdce8p
    Contributor

    I would like to note that Expat CI is using -Wall -Wextra -pedantic with -Werror and that -Wunreachable-code-fallthrough is beyond that.

    To be fair, AFAIK CPython only enables -Wunreachable-code explicitly. While I do share the desire to get these kind of changes upstream, I can also understand the position not to include it. Anyway, I opened #153671 in case silencing it during the build is ok. There at least seems to be some precedent to doing that for other warning types.

    cpython/Makefile.pre.in

    Lines 1518 to 1519 in 701a7c5

    Modules/_hacl/Hacl_Streaming_HMAC.o: $(srcdir)/Modules/_hacl/Hacl_Streaming_HMAC.c $(LIBHACL_HMAC_HEADERS)
    $(CC) -Wno-unused-variable -c $(LIBHACL_CFLAGS) -o $@ $(srcdir)/Modules/_hacl/Hacl_Streaming_HMAC.c

  14. added a commit that references this issue on Jul 27, 2026
  15. added a commit that references this issue on Aug 11, 2026
  16. added 2 commits that reference this issue on Aug 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions