A TypeError is thrown when an AST node is passed to `literal_eval`
because a string is expected and the object has no len().
Check the type of the expression and make sure it's a string before
calling len() on it.
closesodoo/odoo#126874
X-original-commit: 28b5cbb33a99cdca00daa35e5ae598cc8d4b2dae
Signed-off-by: Vranckx Florian (flvr) <flvr@odoo.com>
When passing a very large expression to `literal_eval`, the odoo server crashes.
To avoid this behavior, a limit needs to be set by using the env varaible `ODOO_LIMIT_LITEVAL_BUFFER`.
If the variable is not set, it defaults to 100Kib.
closesodoo/odoo#121882
X-original-commit: 0e4f3ac464b80573b3dab8761dfba54771da0128
Signed-off-by: Vranckx Florian (flvr) <flvr@odoo.com>
Signed-off-by: Dalcq Jordan (joda) <joda@odoo.com>
Despite being part of the requirement.txt, xlrd apparently was still
optional-ish, and absent from some environments like the iotbox.
Restore this by only monkeypatching xlrd if it's actually present.
closesodoo/odoo#63045
X-original-commit: c36aa16c2cc431a1e3b3bb7047dbae4fcac13946
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
Only updates outdated requirements which actively cause issues:
* freezegun broken in 3.8 (removal of time.clock)
* xlrd broken in 3.8 (removal of time.clock)
* also monkeypatches xlrd.xlsx for 3.9 (removal of
Element.getiterator, breaks because of defusedxml)
* jinja triggers DeprecationWarning in 3.8
* pillow triggers warning in 3.9
* lxml, greenlet don't compile in 3.9
* reportlab doesn't work in 3.9
New versions try to match those of Debian Bullseye.
Also adds a script to more easily compare dependency versions between
the requirements files and what's in various distributions (currently
supports checking against debian and ubuntu).
Furthermore updates warnings filtering:
* removes xlrd (mischeck was monkeypatched as noted above)
* removes setuptools (was for older versions, one would hope this
isn't an issue anymore)
* adds babel: python-babel/babel#684 fixes the deprecation warning but
is not part of any release yet
* ignores error related to `random.sample` on a set, this is a
diagnostics bug because recordsets implement both Sequence and Set,
and the stdlib checks for Set first (bpo-42470)
See #59980Closes#61103closesodoo/odoo#62510
X-original-commit: 648635deca67df09417ae55c6eb181c98524b74d
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>