Closed digitalisx closed 2 years ago
Thanks for the detailed bug report - pointing out the source line, TODO comment and required fix really helps us to fix this.
The TODO comment mentions AppVeyor as reason preventing the upgrade, which is a service we no longer use. If you have some time and want to contribute to GRR, please send a pull requests that upgrades the cryptography library to "cryptography==3.3.2"
specifically.
The library is pinned in the file you linked grr/api_client/python/setup.py
as core/setup.py
. Please update both and feel free to remove the AppVeyor TODO comment.
If you don't have the time or the update breaks tests or has other complications, I'll look into it next week.
Hello, @max-vogler š Thank you for reviewing my issue!
As you said, I will submit the PR related to the version upgrade within this week.
I'd appreciate it if you could pay attention until the problem is solved. And Feel free to leave a thread if there are other ways to solve this issue!
A release for PyPi is required for normal application and use of the patch in other DFIR projects. When I looked at the Release and Github Actions, Merge does not mean Release, so We need to review it.
@Digitalisx - we'll update the PyPi grr-api-client packages as part of the current GRR release. Can't give you a precise ETA, but should happen within 2 weeks or so.
Thank you for your comments @mbushkov, I think the release time is purely up to Maintainers' authority and decision! I was just recording the things that I needed to check to solve this problem correctly. Please do it whenever you have time :)
Environment
Describe the issue
Hello, everyone in the community. š The issue is derived from the dftimewolf project associated with the GRR project. To enable and debug dftimewolf, you must install
grr_api_client
for dependencies.Referring to the code below,
grr_api_client
is forcing the version of cryptography you use (2.9.2) (The comments in the code also state TODO that you need to upgrade.)https://github.com/google/grr/blob/7c9ac0c9cc793cdd696a612ccad938ccf57baa02/api_client/python/setup.py#L69
However, in an Apple Silicon M1 environment, that version is experiencing errors, and this requires that the
cryptography
version be kept at least3.3.1
or higher.Since the
grr_api_client
forced the cryptographic version, it is difficult to resolve the error in "dftimewolf". If possible, we need to upgrade the version or allow the version above it.Error logs
Additional context If there is any other reason or solution for this error, please feel free to leave a thread. I'll try to solve it.