Skip to content

python-pkcs11: Add version 0.9.5 - #2657

Open
luhenry wants to merge 3 commits into
mainfrom
python-pkcs11
Open

luhenry wants to merge 3 commits into
mainfrom
python-pkcs11

Conversation

@luhenry

@luhenry luhenry commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

Compiles the pkcs11._pkcs11 Cython extension, which loads the PKCS#11 module with dlopen at runtime. Upstream publishes no riscv64 wheel.

Mirrors upstream's release.yml, with tests from tests.yml.

Differs from upstream

  • SoftHSMv2 is built from a pinned main commit, not unpinned main
  • dnf installs autotools, openssl-devel and crypto-policies-scripts for the test token

Matrix: cp312, cp313, cp314. Upstream's [tool.cibuildwheel] skips free-threaded builds.

Testing

  • opencryptoki and multilib legs dropped (SoftHSM only)
  • Rocky crypto policy set to LEGACY, because DEFAULT refuses the SHA-1 signatures the RSA tests use
  • test_ecc.py::ECCTests::test_derive_key deselected, because Rocky's OpenSSL drops P-192
  • cryptography comes from pypi.riseproject.dev

License: OK

luhenry added a commit that referenced this pull request Oct 3, 2026
@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor
PR Preview Action v1.8.1

QR code for preview link

🚀 View preview at
https://riseproject-dev.github.io/python-wheels/pr-preview/pr-2657/

Built to branch gh-pages at 2026-10-03 09:02 UTC.
Preview will be ready when the GitHub Pages deployment is complete.

Rocky 10's softhsm 2.6.1 RPM aborts the test process on the first
empty-plaintext AES-GCM test vector. Upstream's tests.yml builds
SoftHSMv2 from main with --enable-mldsa; do the same, pinned to a commit.
Rocky 10's OpenSSL drops the P-192 curve (CentOS Stream 10 patch
0009-RH-Drop-weak-curve-definitions) and its DEFAULT crypto policy
refuses SHA-1 signatures; neither is riscv64-specific.
@luhenry
luhenry marked this pull request as ready for review October 3, 2026 11:34

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant