NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #995 most downloaded on PyPI
An asynchronous networking framework written in Python
Last release 4 months ago
11 May 2026
Ships unpredictably
gaps range from 8 days to 11 months
Most releases are documented
notes for 41 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
21 years old
111 releases · first in 2005
Reported and fixed by Tomas Illuminati Balbin CVE-2026-42304
This is the last release with support for Python 3.9.
tls endpoint
type, which allows you to do twist web --listen=tls:.../certbot-dir/config/live pointed at a certbot live
configuration directory and have your certbot certificates automatically
discovered and served appropriately. (#9885)twisted.internet.reactor now has type annotations and will appear to be an object of an appropriate type, allowing for idiomatic common usages with correct type information. (#9909)application property from these new key types. (#12212)RuntimeWarning: TestResult has no addDuration method when running PyUnit tests. (#12229)sys.modules gracefully. Prior to the change, it could possibly raise a "dictionary changed size during iteration" error if the module list changed. (#12458)factor for initial delay, but use initialDelay directly. (#12478)twisted.internet.testing.MemoryReactor.callWhenRunning now invokes the callback immediately, if already started. (#12514)No significant changes.
No significant changes.
Bugfixes
One column per quarter.
Reported and fixed by Tomas Illuminati Balbin CVE-2026-42304
This is the last release with support for Python 3.9.
tls endpoint
type, which allows you to do twist web --listen=tls:.../certbot-dir/config/live pointed at a certbot live
configuration directory and have your certbot certificates automatically
discovered and served appropriately. (#9885)twisted.internet.reactor now has type annotations and will appear to be an object of an appropriate type, allowing for idiomatic common usages with correct type information. (#9909)application property from these new key types. (#12212)RuntimeWarning: TestResult has no addDuration method when running PyUnit tests. (#12229)sys.modules gracefully. Prior to the change, it could possibly raise a "dictionary changed size during iteration" error if the module list changed. (#12458)factor for initial delay, but use initialDelay directly. (#12478)twisted.internet.testing.MemoryReactor.callWhenRunning now invokes the callback immediately, if already started. (#12514)No significant changes.
No significant changes.
Bugfixes
twisted.internet.defer.waitForDeferred twisted.internet.defer.deferredGenerator have been removed. They have been deprecated since Twisted 15.0.0
twisted.web.server.Site can now be created with a
parsePOSTFormSubmission=False parameter to disable parsing of HTTP
request bodies. (#12412)An error in the example for using a Resource object in th documentation on Configuring and Using the Twisted Web Server has been correctd.
Furthermore, a number of references to "strings" where "bytes" where expected has been adjusted. (#12410)
No significant changes.
No significant changes.
twisted.internet.defer.waitForDeferred twisted.internet.defer.deferredGenerator have been removed. They have been deprecated since Twisted 15.0.0
twisted.web.server.Site can now be created with a
parsePOSTFormSubmission=False parameter to disable parsing of HTTP
request bodies. (#12412)An error in the example for using a Resource object in th documentation on Configuring and Using the Twisted Web Server has been correctd.
Furthermore, a number of references to "strings" where "bytes" where expected has been adjusted. (#12410)
No significant changes.
No significant changes.
twisted.python.constants, deprecated since 16.5.0, has been removed.
No changes since 24.11.0rc2.
In comparison to 24.11.0rc1, this release includes and update to do the PyPI release using the trusted publisher functionality of PyPI.
No significant changes.
No significant changes.
No significant changes.
No significant changes.
No significant changes.
twisted.python.constants, deprecated since 16.5.0, has been removed.
In comparison to 24.11.0rc1, this release includes and update to do the PyPI release using the trusted publisher functionality of PyPI.
No significant changes.
No significant changes.
No significant changes.
No significant changes.
No significant changes.
twisted.python.constants, deprecated since 16.5.0, has been removed.
No significant changes.
No significant changes.
No significant changes.
No significant changes.
No significant changes.
The Blowfish and CAST5 ciphers were removed as they were deprecated by the Python cryptography library.\\\`
No significant changes.
No significant changes.
No significant changes.
-j flag now accepts an auto keyword to spawn a number of
workers based on the available CPUs. (#5824)The Blowfish and CAST5 ciphers were removed as they were deprecated by the Python cryptography library.\\\`
No significant changes.
No significant changes.
No significant changes.
-j flag now accepts an auto keyword to spawn a number of
workers based on the available CPUs. (#5824)twisted.web.util.redirectTo now HTML-escapes the provided URL in the fallback response body it returns (GHSA-cf56-g6w6-pqq2, CVE-2024-41810).
24.7.0.rc2 fixed an unreleased regression caused by PR 12109. (#12279) No other changes since 24.7.0.rc2
REMOTE_PORT. (#12096)assert to check the type of the arguments. You should now use type checking to validate your code. These changes were done to reduce the CPU usage. (#12122)conch command-line no longer will either. (#12141)return statement. (#9930)twisted-iocpsupport is no longer a hard dependency on Windows.
The IOCP support is now installed together with the other Windows soft
dependencies via twisted[windows-platform]. (#11893)async argument, deprecated since 18.9.0, has been removed. (#12130)Bugfixes
- twisted.conch.insults.window.Widget.functionKeyReceived now dispatches functional key events to corresponding `func_KEYNAME` methods, where `KEYNAME` can be `F1`, `F2`, `HOME`, `UP_ARROW` etc. This is a regression introduced with #8214 in Twisted 16.5.0, where events changed from `const` objects to bytestrings in square brackets like `[F1]`. (#12046)
Web
---
Features
Bugfixes
- twisted.web.util.redirectTo now HTML-escapes the provided URL in the fallback response body it returns (GHSA-cf56-g6w6-pqq2, CVE-2024-41810). (#9839)
- twisted.web.http.IM_A_TEAPOT was added and returns `I'm a teapot`
as default message for the status code 418,
as defined in RFC 2324 section 2.3.2. (#12104)
- The HTTP 1.0/1.1 server provided by twisted.web is now more picky about the first line of a request, improving compliance with RFC 9112. (#12233)
- The HTTP 1.0/1.1 server provided by twisted.web now contains the characters set of HTTP header names, improving compliance with RFC 9110. (#12235)
- The HTTP 1.0 and 1.1 server provided by twisted.web could process pipelined HTTP requests out-of-order, possibly resulting in information disclosure (CVE-2024-41671/GHSA-c8m8-j448-xjx7) (#12248)
- twisted.web.util.redirectTo now HTML-escapes the provided URL in the fallback response body it returns (GHSA-cf56-g6w6-pqq2). The issue is being tracked with CVE-2024-41810. (#12263)
Improved Documentation
Deprecations and Removals
- twisted.web.util.ChildRedirector, which has never worked on Python 3, has been removed. (#9591)
- ``twisted.web.http.Request.setResponseCode()`` no longer validates the types of inputs; we encourage you to use a type checker like mypy to catch these sort of errors. The long-deprecated ``twisted.web.server.string_date_time()`` and ``twisted.web.server.date_time_string()`` APIs were removed altogether. (#12133)
- twisted.web.http.HTTPClient is now deprecated in favor of twisted.web.client.Agent (#12158)
Misc
~~~~
- #12098, #12194, #12200, #12241, #12257
Mail
----
No significant changes.
Words
-----
No significant changes.
Names
-----
No significant changes.
Trial
-----
No significant changes.
twisted.web.util.redirectTo now HTML-escapes the provided URL in the fallback response body it returns (GHSA-cf56-g6w6-pqq2, CVE-2024-41810).
REMOTE_PORT. (#12096)assert to check the type of the arguments. You should now use type checking to validate your code. These changes were done to reduce the CPU usage. (#12122)conch command-line no longer will either. (#12141)return statement. (#9930)twisted-iocpsupport is no longer a hard dependency on Windows.
The IOCP support is now installed together with the other Windows soft
dependencies via twisted[windows-platform]. (#11893)async argument, deprecated since 18.9.0, has been removed. (#12130)Bugfixes
- twisted.conch.insults.window.Widget.functionKeyReceived now dispatches functional key events to corresponding `func_KEYNAME` methods, where `KEYNAME` can be `F1`, `F2`, `HOME`, `UP_ARROW` etc. This is a regression introduced with #8214 in Twisted 16.5.0, where events changed from `const` objects to bytestrings in square brackets like `[F1]`. (#12046)
Web
---
Features
Bugfixes
- twisted.web.util.redirectTo now HTML-escapes the provided URL in the fallback response body it returns (GHSA-cf56-g6w6-pqq2, CVE-2024-41810). (#9839)
- twisted.web.http.IM_A_TEAPOT was added and returns `I'm a teapot`
as default message for the status code 418,
as defined in RFC 2324 section 2.3.2. (#12104)
- The HTTP 1.0/1.1 server provided by twisted.web is now more picky about the first line of a request, improving compliance with RFC 9112. (#12233)
- The HTTP 1.0/1.1 server provided by twisted.web now contains the characters set of HTTP header names, improving compliance with RFC 9110. (#12235)
- The HTTP 1.0 and 1.1 server provided by twisted.web could process pipelined HTTP requests out-of-order, possibly resulting in information disclosure (CVE-2024-41671/GHSA-c8m8-j448-xjx7) (#12248)
- twisted.web.util.redirectTo now HTML-escapes the provided URL in the fallback response body it returns (GHSA-cf56-g6w6-pqq2). The issue is being tracked with CVE-2024-41810. (#12263)
Improved Documentation
Deprecations and Removals
- twisted.web.util.ChildRedirector, which has never worked on Python 3, has been removed. (#9591)
- ``twisted.web.http.Request.setResponseCode()`` no longer validates the types of inputs; we encourage you to use a type checker like mypy to catch these sort of errors. The long-deprecated ``twisted.web.server.string_date_time()`` and ``twisted.web.server.date_time_string()`` APIs were removed altogether. (#12133)
- twisted.web.http.HTTPClient is now deprecated in favor of twisted.web.client.Agent (#12158)
Misc
~~~~
- #12098, #12194, #12200, #12241, #12257
Mail
----
No significant changes.
Words
-----
No significant changes.
Names
-----
No significant changes.
Trial
-----
No significant changes.
twisted.web.util.redirectTo now HTML-escapes the provided URL in the fallback response body it returns (GHSA-cf56-g6w6-pqq2, CVE-2024-41810).
REMOTE_PORT. (#12096)assert to check the type of the arguments. You should now use type checking to validate your code. These changes were done to reduce the CPU usage. (#12122)conch command-line no longer will either. (#12141)return statement. (#9930)twisted-iocpsupport is no longer a hard dependency on Windows.
The IOCP support is now installed together with the other Windows soft
dependencies via twisted[windows-platform]. (#11893)async argument, deprecated since 18.9.0, has been removed. (#12130)Bugfixes
- twisted.conch.insults.window.Widget.functionKeyReceived now dispatches functional key events to corresponding `func_KEYNAME` methods, where `KEYNAME` can be `F1`, `F2`, `HOME`, `UP_ARROW` etc. This is a regression introduced with #8214 in Twisted 16.5.0, where events changed from `const` objects to bytestrings in square brackets like `[F1]`. (#12046)
Web
---
Features
Bugfixes
- twisted.web.util.redirectTo now HTML-escapes the provided URL in the fallback response body it returns (GHSA-cf56-g6w6-pqq2, CVE-2024-41810). (#9839)
- twisted.web.http.IM_A_TEAPOT was added and returns `I'm a teapot`
as default message for the status code 418,
as defined in RFC 2324 section 2.3.2. (#12104)
- The HTTP 1.0/1.1 server provided by twisted.web is now more picky about the first line of a request, improving compliance with RFC 9112. (#12233)
- The HTTP 1.0/1.1 server provided by twisted.web now contains the characters set of HTTP header names, improving compliance with RFC 9110. (#12235)
- The HTTP 1.0 and 1.1 server provided by twisted.web could process pipelined HTTP requests out-of-order, possibly resulting in information disclosure (CVE-2024-41671/GHSA-c8m8-j448-xjx7) (#12248)
- twisted.web.util.redirectTo now HTML-escapes the provided URL in the fallback response body it returns (GHSA-cf56-g6w6-pqq2). The issue is being tracked with CVE-2024-41810. (#12263)
Improved Documentation
Deprecations and Removals
- twisted.web.util.ChildRedirector, which has never worked on Python 3, has been removed. (#9591)
- ``twisted.web.http.Request.setResponseCode()`` no longer validates the types of inputs; we encourage you to use a type checker like mypy to catch these sort of errors. The long-deprecated ``twisted.web.server.string_date_time()`` and ``twisted.web.server.date_time_string()`` APIs were removed altogether. (#12133)
- twisted.web.http.HTTPClient is now deprecated in favor of twisted.web.client.Agent (#12158)
Misc
~~~~
- #12098, #12194, #12200, #12241, #12257
Mail
----
No significant changes.
Words
-----
No significant changes.
Names
-----
No significant changes.
Trial
-----
No significant changes.
twisted.python.failure.Failure now throws exception for generators without triggering a deprecation warnings on Python 3.12. (\#12026)
This release supports PyPy v7.3.14.
reactor.spawnProcess,
now copies the parent environment when the [env=None]{.title-ref}
argument is passed on Posix systems and os.posix_spawnp is used
internally. (#12068)No significant changes.
cookielib and urllib2 standard
library modules. (#12044)No significant changes.
No significant changes.
No significant changes.
twisted.python.failure.Failure now throws exception for generators without triggering a deprecation warnings on Python 3.12.
formatEvent("here's the result of calling a method at log-format time: {obj.method()}", obj=...) (#9347)reactor.spawnProcess, now copies the parent environment when the env=None argument is passed on Posix systems and os.posix_spawnp is used internally. (#12068)@inlineCallbacks to run on new PyPY versions. (#12084)No significant changes.
cookielib and urllib2 standard library modules. (#12044)multipart/form-data using email.message_from_bytes.
The usage of cgi.parse_multipart was removed as the cgi module will be removed in Python 3.13. (#11848)No significant changes.
No significant changes.
No significant changes.
…until the previous request has fully completed. (CVE-2023-46137, GHSA-cq7q-gv5w-rwx2)
No changes since 23.10.0.rc1.
CPython, functions wrapped by twisted.internet.defer.inlineCallbacks can have their arguments and return values freed immediately after completion (due to there no longer being circular references). (#11885)No significant changes.
Bugfixes
- In Twisted 16.3.0, we changed twisted.web to stop dispatching HTTP/1.1
pipelined requests to application code. There was a bug in this change which
still allowed clients which could send multiple full HTTP requests in a single
TCP segment to trigger asynchronous processing of later requests, which could
lead to out-of-order responses. This has now been corrected and twisted.web
should never process a pipelined request over HTTP/1.1 until the previous
request has fully completed. (CVE-2023-46137, GHSA-cq7q-gv5w-rwx2) (#11976)
Deprecations and Removals
No significant changes.
No significant changes.
No significant changes.
Misc
- #10115
Deprecations and Removals ~~~~~~~~~~~~~~~~~~~~~~~~~
CPython, functions wrapped by twisted.internet.defer.inlineCallbacks can have their arguments and return values freed immediately after completion (due to there no longer being circular references). (#11885)No significant changes.
Bugfixes
- In Twisted 16.3.0, we changed twisted.web to stop dispatching HTTP/1.1
pipelined requests to application code. There was a bug in this change which
still allowed clients which could send multiple full HTTP requests in a single
TCP segment to trigger asynchronous processing of later requests, which could
lead to out-of-order responses. This has now been corrected and twisted.web
should never process a pipelined request over HTTP/1.1 until the previous
request has fully completed. (#11976)
Deprecations and Removals
No significant changes.
No significant changes.
No significant changes.
Misc
- #10115
BadZipfile (with a small f) has been deprecated since Python 3.2, use BadZipFile (big F) instead, added in 3.2.
This is the last release with support for Python 3.7.
No changes since 23.8.0.rc1.
twisted.internet.defer.race has been added as a way to get the first available result from a list of Deferreds. (#11817)IHostnameResolver.resolveHostName and IResolverSimple.getHostByName. (#10276)twist conch --auth=sshkey can now authenticate users without a traceback again, thanks to twisted.conch.unix.UnixConchUser no longer being incorrectly instantiated with bytes. In the course of this fix, some type hinting has also been applied to twisted.cred.portal. (#11626)trial -j no longer obscures tracebacks for
any errors caused by that interruption with an UnboundLocalError due to a bug
in its own implementation. Note that there are still several internal
tracebacks that will be emitted upon exiting, because tearing down the test
runner mid-suite is still not an entirely clean operation, but it should at
least be possible to see errors reported from, for example, a test that is
hanging more clearly. (#11707)twisted.web.template now avoids unnecessary copying and is faster, particularly for templates with deep nesting. (#11834)twisted.web.template now avoids some unecessary evaluation of type annotations and is faster. (#11835)conch_nacl now use hyphens rather than underscores to comply with PEP 685. The old names will be supported until the end of 2023. (#11655)Deprecations and Removals
- PyAsn1 has been removed as a conch dependency.
twisted.conch.ssh.keys.Key no longer supports loading "alternate" OpenSSH private keys.
These are some private keys that at some point were handled by OpenSSH but for which no specification exists.
For more info about these OpenSSH keys see https://github.com/twisted/twisted/issues/3008. (#11843)
- Due to changes in the way raw private key byte serialization are handled in Cryptography, and widespread support for Ed25519 in current versions of OpenSSL, we no longer support PyNaCl as a fallback for Ed25519 keys in Conch. (#11871)
Web
---
Misc
~~~~
- #11815, #11879
Mail
----
No significant changes.
Words
-----
No significant changes.
Names
-----
No significant changes.
Trial
-----
No significant changes.
BadZipfile (with a small f) has been deprecated since Python 3.2, use BadZipFile (big F) instead, added in 3.2.
This is the last release with support for Python 3.7.
reactor.spawnProcess() now uses posix_spawnp when possible, making it much more efficient (#5710)twisted.internet.defer.Deferred.fromFuture now has a more precise type annotation. (#11753)twisted.internet.defer._ConcurrencyPrimitive.__aexit__ now has a more precise type annotation. (#11795)twisted.internet.defer.race has been added as a way to get the first available result from a list of Deferreds. (#11817)IHostnameResolver.resolveHostName and IResolverSimple.getHostByName. (#10276)twist conch --auth=sshkey can now authenticate users without a traceback again, thanks to twisted.conch.unix.UnixConchUser no longer being incorrectly instantiated with bytes. In the course of this fix, some type hinting has also been applied to twisted.cred.portal. (#11626)trial -j no longer obscures tracebacks for
any errors caused by that interruption with an UnboundLocalError due to a bug
in its own implementation. Note that there are still several internal
tracebacks that will be emitted upon exiting, because tearing down the test
runner mid-suite is still not an entirely clean operation, but it should at
least be possible to see errors reported from, for example, a test that is
hanging more clearly. (#11707)twisted.web.template now avoids unnecessary copying and is faster, particularly for templates with deep nesting. (#11834)twisted.web.template now avoids some unecessary evaluation of type annotations and is faster. (#11835)conch_nacl now use hyphens rather than underscores to comply with PEP 685. The old names will be supported until the end of 2023. (#11655)Deprecations and Removals
- PyAsn1 has been removed as a conch dependency.
twisted.conch.ssh.keys.Key no longer supports loading "alternate" OpenSSH private keys.
These are some private keys that at some point were handled by OpenSSH but for which no specification exists.
For more info about these OpenSSH keys see https://github.com/twisted/twisted/issues/3008. (#11843)
- Due to changes in the way raw private key byte serialization are handled in Cryptography, and widespread support for Ed25519 in current versions of OpenSSL, we no longer support PyNaCl as a fallback for Ed25519 keys in Conch. (#11871)
Web
---
Misc
~~~~
- #11815, #11879
Mail
----
No significant changes.
Words
-----
No significant changes.
Names
-----
No significant changes.
Trial
-----
No significant changes.
This release contains a security fix for CVE-2022-39348. This is a low-severity security bug.
This release contains a security fix for CVE-2022-39348. This is a low-severity security bug.
Twisted 22.10.0rc1 release candidate was released on 2022-10-26 and there are no changes between the release candidate and the final release.
systemd: endpoint parser now supports "named" file descriptors. This is a more reliable mechanism for choosing among several inherited descriptors. (#8147)systemd endpoint parser's index parameter is now documented as leading to non-deterministic results in which descriptor is selected. The new name parameter is now documented as preferred. (#8146)Bugfixes
- twisted.conch.manhole.ManholeInterpreter now captures tracebacks even if sys.excepthook has been modified. (#11638)
Web
---
Features
Bugfixes
- twisted.web.error.Error.__str__ no longer raises an exception when the error's message attribute is None. Additionally, it validates that code is a plausible 3-digit HTTP status code. (#10271)
- The typing of the twisted.web.http_headers.Headers methods addRawHeader() and setRawHeaders() now allow mixing str and bytes, matching the runtime behavior. (#11635)
- twisted.web.vhost.NameVirtualHost no longer echoes HTML received in the Host header without escaping it (CVE-2022-39348, GHSA-vg46-2rrj-3647). (#11716)
Deprecations and Removals
Bugfixes
- emailserver.tac now runs under python3.x (#11634)
Words
-----
No significant changes.
Names
-----
No significant changes.
Trial
-----
Features
Bugfixes
- The implementation of ``trial -jN ...`` now handles test errors and failures larger than 64 kB. It also handles other internal communication errors by logging them in the worker and attempting to send them to the parent process -- instead of crashing with ``UnknownRemoteError`` and no additional details. (#10314)
- `trial -jN --logfile path` no longer hangs if *path* contains a directory separator. (#11580)
Misc
~~~~
- #11649, #11661, #11677, #11710
twisted.web.vhost.NameVirtualHost no longer echoes HTML received in the Host header without escaping it (CVE-2022-39348, GHSA-vg46-2rrj-3647).
systemd: endpoint parser now supports "named" file descriptors. This is a more reliable mechanism for choosing among several inherited descriptors. (#8147)test.yaml workflow permissions restricted. (#11631)systemd endpoint parser's index parameter is now documented as leading to non-deterministic results in which descriptor is selected. The new name parameter is now documented as preferred. (#8146)No significant changes.
No significant changes.
trial -jN ... now handles test errors and failures larger than 64 kB. It also handles other internal communication errors by logging them in the worker and attempting to send them to the parent process -- instead of crashing with UnknownRemoteError and no additional details. (#10314)trial -jN --logfile path no longer hangs if path contains a directory separator. (#11580)The release process documentation was updated to include information about doing a security release.
Twisted 22.8.0rc1 release candidate was released on 2022-08-28 and there are no changes between the release candidate and the final release.
twisted.internet.base.DelayedCall.__repr__ will no longer raise AttributeError if the DelayedCall was created before debug mode was enabled. As a side-effect, twisted.internet.base.DelayedCall.creator is now defined as None in cases where previously it was undefined. (#8306)ContextVar.reset() now works correctly inside inlineCallbacks functions and coroutines. (#10301)Bugfixes
- twisted.conch.checkers.UNIXAuthorizedKeysFiles now uses the filesystem encoding to decode usernames before looking them up in the password database, so it works on Python 3. (#10286)
- twisted.conch.ssh.SSHSession.request_env no longer gives a warning if the session does not implement ISessionSetEnv. (#10347)
- The cftp command line (and `twisted.conch.scripts.cftp.SSHSession.extReceived`) no longer raises an unhandled error when receiving data on stderr from the server. (#10351)
Misc
~~~~
- #10330
Web
---
Features
IRequest.write instead of passing them all separately. This greatly reduces the number of chunks in the response. (#10348)Misc
- #11604
Mail
----
Bugfixes
Bugfixes
- twisted.words.protocols.irc.IRCClient now splits overly long NOTICEs and NOTICEs containing \n before sending. (#10285)
Names
-----
Bugfixes
Features
- ``trial --jobs=N --exitfirst`` is now supported. (#9654)
Bugfixes
trial --jobs=N --until-failure ... now reports the correct number of tests run after each iteration. (#10311)trial -jN ... will now pass errors and failures to IReporter methods as instances of WorkerException instead of str. (#10333)Misc
- #10319, #10338, #11571
The release process documentation was updated to include information about doing a security release.
twisted.internet.base.DelayedCall.__repr__ will no longer raise AttributeError if the DelayedCall was created before debug mode was enabled. As a side-effect, twisted.internet.base.DelayedCall.creator is now defined as None in cases where previously it was undefined. (#8306)ContextVar.reset() now works correctly inside inlineCallbacks functions and coroutines. (#10301)Bugfixes
- twisted.conch.checkers.UNIXAuthorizedKeysFiles now uses the filesystem encoding to decode usernames before looking them up in the password database, so it works on Python 3. (#10286)
- twisted.conch.ssh.SSHSession.request_env no longer gives a warning if the session does not implement ISessionSetEnv. (#10347)
- The cftp command line (and `twisted.conch.scripts.cftp.SSHSession.extReceived`) no longer raises an unhandled error when receiving data on stderr from the server. (#10351)
Misc
~~~~
- #10330
Web
---
Features
IRequest.write instead of passing them all separately. This greatly reduces the number of chunks in the response. (#10348)Misc
- #11604
Mail
----
Bugfixes
Bugfixes
- twisted.words.protocols.irc.IRCClient now splits overly long NOTICEs and NOTICEs containing \n before sending. (#10285)
Names
-----
Bugfixes
Features
- ``trial --jobs=N --exitfirst`` is now supported. (#9654)
Bugfixes
trial --jobs=N --until-failure ... now reports the correct number of tests run after each iteration. (#10311)trial -jN ... will now pass errors and failures to IReporter methods as instances of WorkerException instead of str. (#10333)Misc
- #0, #10319, #10338, #11571
…from header values. These changes address CVE-2022-24801 and GHSA-c2jg-hw38-jrqq.
Features
- twisted.conch.ssh now supports using RSA keys with SHA-2 signatures (RFC 8332) when acting as a server. The rsa-sha2-512 and rsa-sha2-256 public key signature algorithms are automatically preferred over ssh-rsa if the client advertises support for them; the actual public keys do not need to change. (#9765)
- twisted.conch.ssh now has an alternative Ed25519 implementation using PyNaCl, in order to support platforms that lack OpenSSL >= 1.1.1b. The new "conch_nacl" extra has the necessary dependency. (#10208)
Misc
~~~~
- (#10313)
Web
---
Features
Bugfixes
- twisted.web.http had several several defects in HTTP request parsing that could permit HTTP request smuggling. It now disallows signed Content-Length headers, forbids illegal characters in chunked extensions, forbids a ``0x`` prefix to chunk lengths, and only strips spaces and horizontal tab characters from header values. These changes address CVE-2022-24801 and GHSA-c2jg-hw38-jrqq. (#10323)
Mail
----
Bugfixes
No significant changes.
No significant changes.
Features
- `trial --until-failure --jobs=N` now reports the number of each test pass as it begins. (#10312)
Bugfixes
trial -u .... (#10320)Misc
- #10315, #10321, #10322
…from header values. These changes address CVE-2022-24801 and GHSA-c2jg-hw38-jrqq.
Features
- twisted.conch.ssh now supports using RSA keys with SHA-2 signatures (RFC 8332) when acting as a server. The rsa-sha2-512 and rsa-sha2-256 public key signature algorithms are automatically preferred over ssh-rsa if the client advertises support for them; the actual public keys do not need to change. (#9765)
- twisted.conch.ssh now has an alternative Ed25519 implementation using PyNaCl, in order to support platforms that lack OpenSSL >= 1.1.1b. The new "conch_nacl" extra has the necessary dependency. (#10208)
Bugfixes
Features
- Twisted is now compatible with h2 4.x.x. (#10182)
Bugfixes
Bugfixes
- twisted.mail.pop3.APOPCredentials is now correctly marked as implementing twisted.cred.credentials.IUsernamHashedPassword, rather than IUsernamePassword. (#10305)
Words
-----
No significant changes.
Names
-----
No significant changes.
Trial
-----
Features
trial --until-failure --jobs=N now reports the number of each test pass as it begins. (#10312)Bugfixes
- twisted.trial.unittest.TestCase now discards cleanup functions after running them. Notably, this prevents them from being run an ever growing number of times with `trial -u ...`. (#10320)
Misc
~~~~
- #10315, #10321, #10322
…is not sent in the first 4096 bytes. (#10284, CVE-2022-21716, GHSA-rv6r-3f5q-9rgx)
min function no longer accepts None as an argument. (#9660)Misc
- #10298
Web
---
No significant changes.
Mail
----
No significant changes.
Words
-----
No significant changes.
Names
-----
No significant changes.
Trial
-----
Bugfixes
Support for Python 3.6, which is EoL as of 2021-09-04, has been deprecated.
This is the last release with support for Python 3.6.
min function no longer accepts None as an argument. (#9660)Bugfixes
- twisted.conch.ssh.transport.SSHTransportBase now disconnects the remote peer if the
SSH version string is not sent in the first 4096 bytes. (#10284)
Misc
~~~~
- #10298
Web
---
No significant changes.
Mail
----
No significant changes.
Words
-----
No significant changes.
Names
-----
No significant changes.
Trial
-----
Bugfixes
Deprecated twisted.python.threading.ThreadPool.currentThread() in favor of threading.current_thread(). Switched twisted.python.threading.ThreadPool.cu…
twisted.internet.base.DelayedCall.__repr__ and twisted.internet.task.LoopingCall.__repr__ had the changes from #10155 reverted to accept non-function callables. (#10235)twisted.python.threading.ThreadPool.currentThread() in favor of threading.current_thread().
Switched twisted.python.threading.ThreadPool.currentThread() and twisted.python.threadable.getThreadID() to use `threading.current_thread()to avoid the deprecation warnings introduced forthreading.currentThread()`` in Python 3.10. (#10273)Features
- twisted.conch.ssh now supports SSH extension negotiation (RFC 8308). (#10266)
Bugfixes
Bugfixes
- twisted.web.client.RedirectAgent and twisted.web.client.BrowserLikeRedirectAgent now properly remove sensitive headers when redirecting to a different origin. (#10294)
Improved Documentation
Deprecations and Removals
- twisted.web.client.getPage, twisted.web.client.downladPage, and the associated implementation classes (HTTPPageGetter, HTTPPageDownloader, HTTPClientFactory, HTTPDownloader) have been removed because they do not segregate cookies by domain. They were deprecated in Twisted 16.7.0 in favor of twisted.web.client.Agent. GHSA-92x2-jw7w-xvvx. (#10295)
Mail
----
No significant changes.
Words
-----
No significant changes.
Names
-----
No significant changes.
Trial
-----
Bugfixes
~~~~~~~~
- trial.runner.filenameToModule now sets the correct module.__name__ and sys.modules key (#10230)
Deprecated twisted.python.threading.ThreadPool.currentThread() in favor of threading.current_thread(). Switched twisted.python.threading.ThreadPool.cu…
DelayedCall.__repr__ and LoopingCall.__repr__ (#10235)twisted.python.threading.ThreadPool.currentThread() in favor of threading.current_thread().
Switched twisted.python.threading.ThreadPool.currentThread() and twisted.python.threadable.getThreadID() to use `threading.current_thread()to avoid the deprecation warnings introduced forthreading.currentThread()`` in Python 3.10. (#10273)Type hinting was added to twisted.internet.defer, making this is the first release of Twisted where you might reasonably be able to use mypy without y
DelayedCall.__repr__ and LoopingCall.__repr__ from
21.7.0.rc1 were reverted as the wrong assumption that __qualname__ is
available on all the supported Python versions.
(#10235)module.__name__ and sys.modules key (#10230)Misc
- #10097
Web
---
Features
Bugfixes
- The server-side HTTP/1.1 chunking implementation no longer performs quadratic work when input arrives in small chunks, preventing CPU exhaustion. (#3795)
- twisted.web.http's chunked encoding support now rejects chunk sizes that are invalid because they look like negative hexadecimal integers. (#10130)
- The type hint of twisted.web.server.Request.postpath is now correctly listed as Optional[List[bytes]]. This was incorrect in Twisted v21.2.0. (#10136)
- The server-side HTTP/1.1 chunking implementation now rejects invalid chunk boundaries, preventing unbounded buffering. (#10137)
- The server-side HTTP/1.1 chunking implementation now limits the length of the chunk size line (which includes chunk extensions) to twisted.web.http.maxChunkSizeLineLength — 1 KiB — so that it may not consume an unbounded amount of memory. (#10144)
- Calling twisted.web.server.Site now registers its expiration timeout using the reactor associated with its twisted.web.server.Site. Site now a reactor attribute via its superclass, twisted.web.http.HTTPFactory. (#10177)
Misc
~~~~
- #9659, #10100, #10154, #10186
Mail
----
No significant changes.
Words
-----
No significant changes.
Names
-----
No significant changes.
Twisted 21.7.0.rc3 (2021-07-23)
DelayedCall.__repr__ and LoopingCall.__repr__ from
21.7.0.rc1 were reverted as the wrong assumption that __qualname__ is
available on all the supported Python versions.
(#10235)Twisted 21.7.0.rc2 (2021-07-20)
module.__name__ and sys.modules key (#10230)Twisted 21.7.0.rc1 (2021-07-10)
Features
- twisted.web.template.renderElement() now accepts any IRequest implementer instead of only twisted.web.server.Request.
Add type hints to twisted.web.template. (#10184)
Bugfixes
twisted.web.util.ParentRedirect has been fixed and documented. It was broken by a security fix in Twisted 19.2.0.
Ticket numbers in this file can be looked up by visiting http://twistedmatrix.com/trac/ticket/<number>
.. towncrier release notes start
__repr__, __slots__ and other @attrs.define related changes from compatibility policy. (#9982)Features
- twisted.conch.ssh now supports Ed25519 keys (requires OpenSSL >= 1.1.1b). (#8966)
- twisted.conch.ssh.session.SSHSession can now accept environment variables sent by the client, if the SSH avatar implements the new ISessionSetEnv interface. (#9315)
- twisted.conch.ssh.keys.Key.fromString and twisted.conch.ssh.keys.Key.toString now normalize Unicode passphrases as required by NIST 800-63B. (#9736)
- twisted.conch.telnet now implements EOR (End of Record) command (RFC 885) (#9875)
Bugfixes
Improved Documentation
- construct and assign portal and checkers consistently in ssh server example (#9578)
Misc
~~~~
- #6446, #9571, #9831, #9913
Web
---
Bugfixes
~~~~~~~~
- twisted.web.http.Request.getRequestHostname now supports IPv6 literal hostnames
in HTTP host headers. (#6014)
- Fixed unexpected exception by handling subclass of TaskFinished when FileBodyProducer's task stopped twice. (#6528)
- Importing twisted.web.client no longer has the side effect of initializing the reactor. (#9774)
- Ensure that all calls to connectionLost use a Failure instance in the HTTP 2 code. (#9817)
- twisted.web.util.ParentRedirect has been fixed and documented. It was broken by a security fix in Twisted 19.2.0. (#9835)
- xmlrpc's Proxy class now verifies HTTPS certificates against the system bundle. (#9836)
- twisted.web.twcgi can now handle url parameters in python 3 (#9887)
- defer reactor import in twisted.web.xmlrpc (#9931)
- twisted.web.RedirectAgent now supports 308 redirects (#9940)
- Fixed an error where twisted.web.http.requestReceived() tries to encode a NoneType returned by cgi.parse_multipart when a multipart body does not contain a "content-disposition" definition. (#10084)
Improved Documentation
Misc
- #6446, #9758, #9801, #9831, #9834, #9841
Mail
----
Bugfixes
Misc
- #6446, #9831, #9832, #9900, #9910
Words
-----
Misc
Features
- twisted.names.hosts.Resolver and twisted.names.hosts.searchFileForAll() now ignore malformed lines in hosts files like /etc/hosts (#9752)
- New interface IEncodableRecord combines IEncodable and IRecord, which is useful when using type annotations. (#9920)
Bugfixes
Misc
- #9749
twisted.web.util.ParentRedirect has been fixed and documented. It was broken by a security fix in Twisted 19.2.0.
__repr__, __slots__ and other @attrs.define related changes from compatibility policy. (#9982)Features
- twisted.conch.ssh now supports Ed25519 keys (requires OpenSSL >= 1.1.1b). (#8966)
- twisted.conch.ssh.session.SSHSession can now accept environment variables sent by the client, if the SSH avatar implements the new ISessionSetEnv interface. (#9315)
- twisted.conch.ssh.keys.Key.fromString and twisted.conch.ssh.keys.Key.toString now normalize Unicode passphrases as required by NIST 800-63B. (#9736)
- twisted.conch.telnet now implements EOR (End of Record) command (RFC 885) (#9875)
Bugfixes
Improved Documentation
- construct and assign portal and checkers consistently in ssh server example (#9578)
Misc
~~~~
- #6446, #9571, #9831, #9913
Web
---
Bugfixes
~~~~~~~~
- twisted.web.http.Request.getRequestHostname now supports IPv6 literal hostnames
in HTTP host headers. (#6014)
- Fixed unexpected exception by handling subclass of TaskFinished when FileBodyProducer's task stopped twice. (#6528)
- Importing twisted.web.client no longer has the side effect of initializing the reactor. (#9774)
- Ensure that all calls to connectionLost use a Failure instance in the HTTP 2 code. (#9817)
- twisted.web.util.ParentRedirect has been fixed and documented. It was broken by a security fix in Twisted 19.2.0. (#9835)
- xmlrpc's Proxy class now verifies HTTPS certificates against the system bundle. (#9836)
- twisted.web.twcgi can now handle url parameters in python 3 (#9887)
- defer reactor import in twisted.web.xmlrpc (#9931)
- twisted.web.RedirectAgent now supports 308 redirects (#9940)
- Fixed an error where twisted.web.http.requestReceived() tries to encode a NoneType returned by cgi.parse_multipart when a multipart body does not contain a "content-disposition" definition. (#10084)
Improved Documentation
Misc
- #6446, #9758, #9801, #9831, #9834, #9841
Mail
----
Bugfixes
Misc
- #6446, #9831, #9832, #9900, #9910
Words
-----
Misc
Features
- twisted.names.hosts.Resolver and twisted.names.hosts.searchFileForAll() now ignore malformed lines in hosts files like /etc/hosts (#9752)
- New interface IEncodableRecord combines IEncodable and IRecord, which is useful when using type annotations. (#9920)
Bugfixes
Misc
- #9749
Requests with multiple Content-Length headers were allowed (CVE-2020-10108, thanks to Jake Miller from Bishop Fox and ZeddYu Lu for reporting this) an…
twisted.protocols.amp.BoxDispatcher.callRemote and callRemoteString will no longer return failing Deferreds for requiresAnswer=False commands when the transport they're operating on has been disconnected. (#9756)
Added a missing hyphen to a reference to the --debug option of pdb in the Trial how-to. (#9690)
The documentation of the twisted.cred.checkers module has been extended and corrected. (#9724)
twisted.news is deprecated. (#9405)
#9634, #9701, #9707, #9710, #9715, #9726, #9727, #9728, #9729, #9735, #9737, #9757
twisted.conch.ssh now supports the curve25519-sha256 key exchange algorithm (requires OpenSSL >= 1.1.0). (#6814)
twisted.conch.ssh.keys can now write private keys in the new "openssh-key-v1" format, introduced in OpenSSH 6.5 and made the default in OpenSSH 7.8. ckeygen has a corresponding new --private-key-subtype=v1 option. (#9683)
twisted.conch.keys.Key.privateBlob now returns the correct blob format for ECDSA (i.e. the same as that implemented by OpenSSH). (#9682)
#9760
Fixed return type of twisted.web.http.Request.getUser and twisted.web.http.Request.getPassword to binary if no authorization header was found or an exception was thrown (#9596)
twisted.web.http.HTTPChannel now rejects requests (with status code 400 and a drop) that have malformed headers of the form "Foo : value" or ": value". (#9646)
twisted.web.http.Request now correctly parses multipart-encoded form data submitted as a chunked request on Python 3.7+. (#9678)
twisted.web.client.BrowserLikePolicyForHTTPS is now listed in __all__, since it's a user-facing class that anyone could import and extend. (#9769)
twisted.web.http was subject to several request smuggling attacks. Requests with multiple Content-Length headers were allowed (CVE-2020-10108, thanks to Jake Miller from Bishop Fox and ZeddYu Lu for reporting this) and now fail with a 400; requests with a Content-Length header and a Transfer-Encoding header honored the first header (CVE-2020-10109, thanks to Jake Miller from Bishop Fox for reporting this) and now fail with a 400; requests whose Transfer-Encoding header had a value other than "chunked" and "identity" (thanks to ZeddYu Lu) were allowed and now fail with a 400. (#9770)
#9733
Fixed parsing of streams with Python 3.8 when there are spaces in namespaces or namespaced attributes in twisted.words.xish.domish.ExpatElementStream (#9730)
twisted.names.secondary.SecondaryAuthority now accepts str for its domain parameter, so twist dns --secondary now functions on Python 3. (#9496)
Nothing published for this version
…data without reading responses. This closes CVE-2019-9512 (Ping Flood), CVE-2019-9514 (Reset Flood), and CVE-2019-9515 (Settings Flood). Thanks to Jon…
twisted.trial.successResultOf, twisted.trial.failureResultOf, and twisted.trial.assertNoResult accept coroutines as well as Deferreds. (#9006)
Fixed circular import in twisted.trial.reporter, introduced in Twisted 16.0.0. (#8267)
The POP3 server implemented by twisted.mail.pop3 now accepts passwords that contain spaces. (#9100)
Incoming HTTP/2 connections will now not time out if they persist for longer than one minute. (#9653)
The serial extra now requires pywin32 on Windows enabling use of twisted.internet.serialport without specifying the windows_platform extra. (#9700)
#8506, #9677, #9684, #9687, #9688
twisted.conch.ssh.keys now correctly writes the "iqmp" parameter in serialized RSA private keys as q^-1 mod p rather than p^-1 mod q. (#9681)
#9689
twisted.web.server.Request will now use twisted.web.server.Site.getContentFile, if it exists, to get a file into which to write request content. If getContentFile is not provided by the site, it will fall back to the previous behavior of using io.BytesIO for small requests and tempfile.TemporaryFile for large ones. (#9655)
twisted.web.client.FileBodyProducer will now stop producing when the Deferred returned by FileBodyProducer.startProducing is cancelled. (#9547)
The HTTP/2 server implementation now enforces TCP flow control on control frame messages and times out clients that send invalid data without reading responses. This closes CVE-2019-9512 (Ping Flood), CVE-2019-9514 (Reset Flood), and CVE-2019-9515 (Settings Flood). Thanks to Jonathan Looney and Piotr Sikora. (#9694)
No significant changes.
No significant changes.
No significant changes.
Nothing published for this version
…that contain invalid characters. This mitigates CVE-2019-12387. Thanks to Alex Brasetvik for reporting this vulnerability.
The callable argument to twisted.internet.task.deferLater() is no longer required. (#9577)
Twisted's minimum Cryptography requirement is now 2.5. (#9592)
twisted.internet.utils.getProcessOutputAndValue now accepts stdinBytes to write to the child process's standard input. (#9607)
Add new twisted.logger.capturedLogs context manager for capturing observed log events in tests. (#9617)
twisted.internet.base.PluggableResolverMixin, which implements the pluggable resolver interfaces for easier re-use in other reactors, has been factored out of ReactorBase. (#9632)
The PyPI page for Twisted has been enhanced to include more information and useful links. (#9648)
twisted.internet.endpoints is now importable on Windows when pywin32 is not installed. (#6032)
twisted.conch.ssh now generates correct keys when using hmac-sha2-512 with SHA1 based KEX algorithms. (#8258)
twisted.internet.iocpreactor.abstract.FileHandle no longer duplicates/looses outgoing data when .write() is called in rapid succession with large payloads (#9446)
twisted.application.backoffPolicy will not fail on connection attempts > 1750 with default settings. (#9476)
Trial on Python 3 will now properly re-raise ImportErrors that occur during the import of a module, rather than saying the module doesn't exist. (#9628)
twisted.internet.process does not fail on import when the process has more than 1024 file descriptors opened. (#9636)
Add the stackLevel keyword argument to twisted.logger.STDLibLogObserver._findCaller to fix an incompatibility with Python 3.8. (#9668)
Fix the incorrect docstring for twisted.python.components.Componentized.addComponent which stated that the function returned a list of interfaces, even though the function doesn't actually do so. (#9637)
twisted.test.proto_helpers has moved to twisted.internet.testing. twisted.test.proto_helpers has been deprecated. (#6435)
twisted.protocols.mice, deprecated since Twisted 16.0, has been removed. (#9602)
twisted.conch.insults.client and twisted.conch.insults.colors, deprecated since Twisted 10.1, have been removed. (#9603)
The __version__ attribute of Twisted submodules that were previously packaged separately, deprecated since Twisted 16.0, has been removed. (#9604)
Python 3.4 is no longer supported. (#9613)
twisted.python.compat.OrderedDict, an alias for collections.OrderedDict and deprecated since Twisted 15.5, has been removed. (#9639)
#9217, #9445, #9454, #9605, #9614, #9615, #9619, #9625, #9633, #9640, #9674
t.c.ssh.connection.SSHConnection now fails channels that are in the process of opening when the connection is lost. (#2782)
#9610
twisted.web.tap, the module that is run by twist web, now accepts --display-tracebacks to render tracebacks on uncaught exceptions. (#9656)
twisted.web.http.Request.write after the channel is disconnected will no longer raise AttributeError. (#9410)
twisted.web.client.Agent.request() and twisted.web.client.ProxyAgent.request() now produce TypeError when the method argument is not bytes, rather than failing to generate the request. (#9643)
twisted.web.http.HTTPChannel no longer raises TypeError internally when receiving a line-folded HTTP header on Python 3. (#9644)
All HTTP clients in twisted.web.client now raise a ValueError when called with a method and/or URL that contain invalid characters. This mitigates CVE-2019-12387. Thanks to Alex Brasetvik for reporting this vulnerability. (#9647)
twisted.web.server.Site's instance variable displayTracebacks is now set to False by default. (#9656)
twisted.web.iweb.IRequest's "prepath" and "postpath" attributes, which have existed for a long time, are now documented. (#5533)
The documented type of t.w.iweb.IRequest's "method" and "uri" attributes on Python 3 has been corrected to match the implementation. (#9091)
t.w.iweb.IRequest's "args" attribute is now correctly documented to be bytes. (#9458)
The API documentation of twisted.web.iweb.IRequest and twisted.web.http.Request has been updated and extended to match the implementation. (#9593)
Passing a path argument to twisted.web.resource.Resource.putChild which is not of type bytes is now deprecated. In the future, passing a non-bytes argument to putChild will return an error. (#9135)
Passing --notracebacks/-n to twisted.web.tap, the module that is run by twist web, is now deprecated due to traceback rendering being disabled by default. (#9656)
#9597
No significant changes.
twisted.words.protocols.jabber.xmlstream.TLSInitiatingInitializer and twisted.words.protocols.jabber.client.XMPPClientFactory now take an optional configurationForTLS for customizing certificate options for StartTLS. (#9561)
twisted.words.protocols.jabber.xmlstream.TLSInitiatingInitializer now properly verifies the server's certificate against platform CAs and the stream's domain, mitigating CVE-2019-12855. (#9561)
twisted.names.client.Resolver will no longer infinite loop if it cannot bind a UDP port to use for resolving. (#9620)
Nothing published for this version
Nothing published for this version
twisted.web.http.Request.cookies, twisted.web.http.HTTPChannel.writeHeaders, and twisted.web.http_headers.Headers were all vulnerable to header inject…
This is the final release that will support Python 3.4.
twisted.internet.ssl.CertificateOptions now uses 32 random bytes instead of an MD5 hash for the ssl session identifier context. (#9463)
DeferredLock and DeferredSemaphore can be used as asynchronous context managers on Python 3.5+. (#9546)
t.i.b.BaseConnector has custom __repr__ (#9548)
twisted.internet.ssl.optionsForClientTLS now supports validating IP addresses from the certificate subjectAltName (#9585)
Twisted's minimum Cryptography requirement is now 2.5. (#9592)
twisted.web.proxy.ReverseProxyResource fixed documentation and example snippet (#9192)
twisted.python.failure.Failure.getTracebackObject now returns traceback objects whose frames can be passed into traceback.print_stack for better debugging of where the exception came from. (#9305)
twisted.internet.ssl.KeyPair.generate: No longer generate 1024-bit RSA keys by default. Anyone who generated a key with this method using the default value should move to replace it immediately. (#9453)
The message of twisted.internet.error.ConnectionAborted is no longer truncated. (#9522)
twisted.enterprise.adbapi.ConnectionPool.connect now logs only the dbapiName and not the connection arguments, which may contain credentials (#9544)
twisted.python.runtime.Platform.supportsINotify no longer considers the result of isDocker for its own result. (#9579)
The documentation for the the twisted.internet.interfaces.IConsumer, IProducer, and IPullProducer interfaces is more detailed. (#2546)
The errback example in the docstring of twisted.logger.Logger.failure has been corrected. (#9334)
The sample code in the "Twisted Web In 60 Seconds" tutorial runs on Python 3. (#9559)
#8921, #9071, #9125, #9428, #9536, #9540, #9580
twisted.conch.ssh.keys can now read private keys in the new "openssh-key-v1" format, introduced in OpenSSH 6.5 and made the default in OpenSSH 7.8. (#9515)
Conch now uses pyca/cryptography for Diffie-Hellman key generation and agreement. (#8831)
#9584
twisted.web.client.HostnameCachingHTTPSPolicy was added as a new contextFactory option. The policy caches a specified number of twisted.internet.interfaces.IOpenSSLClientConnectionCreator instances to to avoid the cost of instantiating a connection creator for multiple requests to the same host. (#9138)
twisted.web.http.Request.cookies, twisted.web.http.HTTPChannel.writeHeaders, and twisted.web.http_headers.Headers were all vulnerable to header injection attacks. They now replace linear whitespace ('r', 'n', and 'rn') with a single space. twisted.web.http.Reqeuest.cookies also replaces semicolons (';') with a single space. (#9420)
twisted.web.client.Request and twisted.web.client.HTTPClient were both vulnerable to header injection attacks. They now replace linear whitespace ('r', 'n', and 'rn') with a single space. (#9421)
No significant changes.
No significant changes.
twisted.names.dns now has IRecord implementations for the SSHFP and TSIG record types. (#9373)
Nothing published for this version
Nothing published for this version
async keyword argument is deprecated in twisted.conch.manhole (ManholeInterpreter.write and Manhole.add) and in twisted.main.imap4.IMAP4Server.sendUnt…
twisted.internet._sslverify.ClientTLSOptions no longer raises IDNAError when given an IPv6 address as a hostname in a HTTPS URL. (#9433)
The repr() of a twisted.internet.base.DelayedCall now encodes the same information as its str(), exposing details of its scheduling and target callable. (#9481)
Python 3.7 is now supported. (#9502)
twisted.logger.LogBeginner's default critical observer now prints tracebacks for new and legacy log system events through the use of the new eventAsText API. This API also does not raise an error for non-ascii encoded data in Python2, it attempts as well as possible to format the traceback. (#7927)
Syntax error under Python 3.7 fixed for twisted.conch.manhole and twisted.main.imap4. (#9384)
trial -j reports tracebacks on test failures under Python 3. (#9436)
Properly format multi-byte and non-ascii encoded data in a traceback. (#9456)
twisted.python.rebuild now functions on Python 3.7. (#9492)
HTTP/2 server connections will no longer time out active downloads that take too long. (#9529)
Several minor formatting problems in the API documentation have been corrected. (#9461)
The documentation of twisted.internet.defer.Deferred.fromFuture() has been updated to reflect upstream changes. (#9539)
async keyword argument is deprecated in twisted.conch.manhole (ManholeInterpreter.write and Manhole.add) and in twisted.main.imap4.IMAP4Server.sendUntaggedResponse, isAsync keyword argument is introduced instead. (#9384)
#9379, #9485, #9489, #9499, #9501, #9511, #9514, #9523, #9524, #9525, #9538
twisted.conch.keys.Key.public returns the same twisted.conch.keys.Key instance when it is already a public key instead of failing with an exception. (#9441)
RSA private keys are no longer corrupted during loading, allowing OpenSSL's fast-path to operate for RSA signing. (#9518)
The documentation for IConchUser.gotGlobalRequest() is more accurate. (#9413)
twisted.conch.ssh.filetransfer.ClientDirectory's use as an iterator has been deprecated. (#9527)
twisted.web.server.Request.getSession now returns a new session if the previous session has expired. (#9288)
#9479, #9480, #9482, #9491
No significant changes.
No significant changes.
No significant changes.
Nothing published for this version
Deprecate direct introspection of ProcMon's processes: processes should not be directly accessed or pickled.
Cancelling a Deferred returned by twisted.internet.defer.inlineCallbacks now cancels the Deferred it is waiting on. (#4632)
twisted.application.internet.ClientService now accepts a function to initialize or validate a connection before it is returned by the whenConnected method as the prepareConnection argument. (#8375)
Traceback generated for twisted.internet.defer.inlineCallbacks now includes the full stack of inlineCallbacks generators between catcher and raiser (before it only contained raiser's stack). (#9176)
Add optional cwd argument to twisted.runner.procmon.ProcMon.addProcess (#9287)
twisted.python.failure.Failure tracebacks generated by coroutines scheduled with twisted.internet.defer.ensureDeferred - i.e. any Deferred-awaiting coroutine - now contain fewer extraneous frames from the trampoline implementation, and correctly indicate the source of exceptions raised in other call stacks - i.e. the function that raised the exception. In other words: if you 'await' a function that raises an exception, you'll be able to see where the error came from. (#9459)
On UNIX-like platforms, Twisted attempts to recover from EMFILE when accepting connections on TCP and UNIX ports by shedding incoming clients. (#5368)
The documentation of IReactorTime.getDelayedCalls() has been corrected to indicate that the method returns a list, not a tuple. (#9418)
"python -m twisted web --help" now refers to "--listen" instead of the non-existing "--http" (#9434)
twisted.python.htmlizer.TokenPrinter now explicitly works on bytestrings. (#9442)
twisted.enterprise.adbapi.ConnectionPool.runWithConnection and runInteraction now use the reactor that is passed to ConnectionPool's constructor. (#9467)
The Twisted Coding Standard now contains examples of how to mark up a feature as added in the next Twisted release. (#9460)
Deprecate direct introspection of ProcMon's processes: processes should not be directly accessed or pickled. (#9287)
twisted.internet.address.IPv4Address._bwHack and twisted.internet.address.UNIXAddress._bwHack, as well as the parameters to the constructors, deprecated since Twisted 11.0, have been removed. (#9450)
#7495, #9399, #9406, #9411, #9425, #9439, #9449, #9450, #9452
twisted.conch.ssh.transport.SSHTransportBase now includes Twisted's version in the software version string it sends to the server, allowing servers to apply compatibility workarounds for bugs in particular client versions. (#9424)
If the command run by twisted.conch.endpoints.SSHCommandClientEndpoint exits because of a delivered signal, the client protocol's connectionLost is now called with a ProcessTerminated exception instead of a ConnectionDone exception. (#9412)
twisted.conch.ssh.transport.SSHTransportBase now correctly handles MSG_DEBUG with a false alwaysDisplay field on Python 2 (broken since 8.0.0). (#9422)
twisted.conch.manhole.lastColorizedLine now does not throw a UnicodeDecodeError on non-ASCII input. (#9442)
Added support for SameSite cookies in http.Request.addCookie. (#9387)
twisted.web.server.GzipEncoderFactory would sometimes fail to gzip requests if the Accept-Encoding header contained whitespace between the comma-separated acceptable encodings. It now trims whitespace before checking if gzip is an acceptable encoding. (#9086)
twisted.web.static.File renders directory listings on Python 2, including those with text paths. (#9438)
twisted.python.http.Request now correcly parses multipart bodies on Python 3.7. (#9448)
twisted.web.http.combinedLogFormatter (used by t.w.http.Server and t.w.server.Site) no longer produces DeprecationWarning about Request.getClientIP. (#9470)
#9432, #9466, #9479, #9480
No significant changes.
No significant changes.
#9398
Nothing published for this version
Nothing published for this version
The --port/--https arguments to web plugin are now deprecated, in favor of --listen. The --listen argument can be given multiple times to listen on mu…
The --port/--https arguments to web plugin are now deprecated, in favor of --listen. The --listen argument can be given multiple times to listen on multiple ports. (#6670)
Twisted now requires zope.interface 4.4.2 or higher across all platforms and Python versions. (#8149)
The osx_platform setuptools extra has been renamed to macos_platform, with the former name being a compatibility alias. (#8848)
Zsh completions are now provided for the twist command. (#9338)
twisted.internet.endpoints.HostnameEndpoint now has a __repr__ method which includes the host and port to which the endpoint connects. (#9341)
twistd now uses the UID's default GID to initialize groups when --uid is given but --gid is not. This prevents an unhandled TypeError from being raised when os.initgroups() is called. (#4442)
twisted.protocols.basic.LineReceiver checks received lines' lengths against its MAX_LENGTH only after receiving a complete delimiter. A line ending in a multi-byte delimiter like 'rn' might be split by the network, with the first part arriving before the rest; previously, LineReceiver erroneously disconnected if the first part, e.g. 'zzzz....r' exceeded MAX_LENGTH. LineReceiver now checks received data against MAX_LENGTH plus the delimiter's length, allowing short reads to complete a line. (#6556)
twisted.protocols.basic.LineOnlyReceiver disconnects the transport after receiving a line that exceeds MAX_LENGTH, like LineReceiver. (#6557)
twisted.web.http.Request.getClientIP now returns the host part of the client's address when connected over IPv6. (#7704)
twisted.application.service.IService is now documented as requiring the 'running', 'name' and 'parent' attributes (the documentation previously implied they were required, but was unclear). (#7922)
twisted.web.wsgi.WSGIResource no longer raises an exception when a client connects over IPv6. (#8241)
When using TLS enable automatic ECDH curve selection on OpenSSL 1.0.2+ instead of only supporting P-256 (#9210)
twisted.trial._dist.worker and twisted.trial._dist.workertrial consistently pass bytes, not unicode to AMP. This fixes "trial -j" on Python 3. (#9264)
twisted.trial.runner now uses the 'importlib' module instead of the 'imp' module on Python 3+. This eliminates DeprecationWarnings caused by importing 'imp' on Python 3. (#9275)
twisted.web.client.HTTP11ClientProtocol now closes the connection when the server is sending a header line which is longer than he line limit of twisted.protocols.basic.LineReceiver.MAX_LENGTH. (#9295)
twisted.python.failure now handles long stacktraces better; in particular it will log tracebacks for stack overflow errors. (#9301)
The "--_shell-completion" argument to twistd now works on Python 3. (#9303)
twisted.python.failure.Failure now raises the wrapped exception in Python3, and self (Failure) n Python2 when trap() is called without a matching exception (#9307)
Writing large amounts of data no longer implies repeated, expensive copying under Python 3. Python 3's write speeds are now as fast as Python 2's. (#9324)
twisted.protocols.postfix now properly encodes errors which are unicode strings to bytes. (#9335)
twisted.protocols.policies.ProtocolWrapper and twisted.protocols.tls.TLSMemoryBIOProtocol no longer create circular references that keep protocol instances in memory after connection is closed. (#9374)
twisted.conch.ssh.transport.SSHTransportBase no longer strips trailing spaces from the SSH version string of the connected peer. (#9377)
trial -j no longer crashes on Python 2 on test failure messages containing non-ASCII bytes. (#9378)
RSA keys replaced with 2048bit ones in twisted.conch.test.keydata in order to be compatible with OpenSSH 7.6. (#9388)
AsyncioSelectorReactor uses the global policy's event loop. asyncio libraries that retrieve the running event loop with get_event_loop() will now receive the one used by AsyncioSelectorReactor. (#9390)
public attributes of twisted.logger.Logger are now documented as attributes. (#8157)
List indentation formatting errors have been corrected throughout the documentation. (#9256)
twisted.protocols.basic.LineOnlyReceiver.lineLengthExceeded no longer returns twisted.internet.error.ConnectionLost. It instead directly disconnects the transport and returns None. (#6557)
twisted.python.win32.getProgramsMenuPath and twisted.python.win32.getProgramFilesPath were deprecated in Twisted 15.3.0 and have now been removed. (#9312)
Python 3.3 is no longer supported. (#9352)
#7033, #8887, #9204, #9289, #9291, #9292, #9293, #9302, #9336, #9355, #9356, #9364, #9375, #9381, #9382, #9389, #9391, #9393, #9394, #9396
twisted.plugins.cred_unix now properly converts a username and password from bytes to str on Python 3. In addition, passwords which are encrypted with SHA512 and SH256 are properly verified. This fixes running a conch server with: "twistd -n conch -d /etc/ssh/ --auth=unix". (#9130)
In twisted.conch.scripts.conch, on Python 3 do not write bytes directly to sys.stderr. On Python 3, this fixes remote SSH execution of a command which fails. (#9344)
twisted.conch.ssh.filetransfer.FileTransferClient.wasAFile attribute has been removed as it serves no purpose. (#9362)
Removed deprecated support for PyCrypto key objects in conch (#9368)
The new twisted.iweb.IRequest.getClientAddress returns the IAddress provider representing the client's address. Callers should check the type of the returned value before using it. (#7707)
Eliminate use of twisted.python.log in twisted.web modules. (#9280)
Scripts ending with .rpy, .epy, and .cgi now execute properly in Twisted Web on Python 3. (#9271)
twisted.web.http.Request and twisted.web.server.Request are once again hashable on Python 2, fixing a regression introduced in Twisted 17.5.0. (#9314)
Correct reactor docstrings for twisted.web.client.Agent and twisted.web.client._StandardEndpointFactory to communicate interface requirements since 17.1. (#9274)
The examples for the "Twisted Web in 60 Seconds" tutorial have been fixed to work on Python 3. (#9285)
twisted.iweb.IRequest.getClientIP is deprecated. Use twisted.iweb.IRequest.getClientAddress instead (see #7707). (#7705)
twisted.web.iweb.IRequest.getClient and its implementations (deprecated in #2552) have been removed. (#9395)
twistd.mail.scripts.mailmail has been ported to Python 3. (#8487)
twisted.mail.bounce now works on Python 3. (#9260)
twisted.mail.pop3 and twisted.mail.pop3client now work on Python 3. (#9269)
SMTP authentication in twisted.mail.smtp now works better on Python 3, due to improved improved bytes vs unicode handling. (#9299)
#9310
No significant changes.
No significant changes.
Nothing published for this version
twisted.protocols.dict is deprecated.
This is the last Twisted release where Python 3.3 is supported, on any platform.
twisted.python.failure.Failure is now a new-style class which subclasses BaseException. (#5519)
twisted.internet.posixbase.PosixReactorBase.adoptStreamPort and twisted.internet.posixbase.PosixReactorBase.adoptStreamConnection now support AF_UNIX SOCK_STREAM sockets. (#5573)
(#8940)
t.protocol.policies.TimeoutMixin.setTimeout and t.protocol.policies.TimeoutProtocol.cancelTimeout (used in t.protocol.policies.TimeoutFactory) no longer raise a t.internet.error.AlreadyCancelled exception when calling them for an already cancelled timeout. (#9131)
twisted.web.template.flatten now supports coroutines that yield Deferreds. (#9199)
twisted.web.client.HTTPConnectionPool passes the repr() of the endpoint to the client protocol factory, and the protocol factory adds that to its own repr(). This makes logs more useful. (#9235)
Python 3.6 is now supported (#9240)
twisted.python.logfile.BaseLogFile and subclasses now always open the file in binary mode, and will process text as UTF-8. (#6938)
The ssl: endpoint now accepts certKey PEM files without trailing newlines. (#7530)
Logger.__init__ sets the namespace to "<unknown>" instead of raising KeyError when unable to determine the namespace from the calling context. (#7930)
twisted.internet._win32serialport updated to support pySerial 3.x and dropped pySerial 2.x support. (#8159)
twisted.python.rebuild now works on Python 3. (#8213)
twisted.web.server.Request.notifyFinish will now once again promptly notify applications of client disconnection (assuming that the client doesn't send a large amount of pipelined request data) rather than waiting for the timeout; this fixes a bug introduced in Twisted 16.3.0. (#8692)
twisted.web.guard.HTTPAuthSessionWrapper configured with DigestCredentialFactory now works on both Python 2 and 3. (#9127)
Detect when we’re being run using “-m twisted” or “-m twisted.trial” and use it to build an accurate usage message. (#9133)
twisted.protocols.tls.TLSMemoryBIOProtocol now allows unregisterProducer to be called when no producer is registered, bringing it in line with other transports. (#9156)
twisted.web web servers no longer print tracebacks when they timeout clients that do not respond to TLS CLOSE_NOTIFY messages. (#9157)
twisted.mail.imap4 now works on Python 3. (#9161)
twisted.python.shortcut now works on Python 3 in Windows. (#9170)
Fix traceback forwarding with inlineCallbacks on python 3. (#9175)
twisted.mail.imap4.MessageSet now treats * as larger than every message ID, leading to more consistent and robust behavior. (#9177)
The following plugins can now be used on Python 3 with twistd: dns, inetd, portforward, procmon, socks, and words. (#9184)
twisted.internet._win32serialport now uses serial.serialutil.to_bytes() to provide bytes in Python 3. (#9186)
twisted.internet.reactor.spawnProcess() now does not fail on Python 3 in Windows if passed a bytes-encoded path argument. (#9200)
twisted.protocols.ident now works on Python 3. (#9221)
Ignore PyPy's implementation differences in base object class. (#9225)
twisted.python.test.test_setup now passes with setuptools 36.2.1 (#9231)
twisted.internet._win32serialport SerialPort._clearCommError() no longer raises AttributeError (#9252)
twisted.trial.unittest.SynchronousTestCase and twisted.trial.unittest.TestCase now always run their tearDown methods, even when a test method fails with an exception. They also flush all errors logged by a test method before running another, ensuring the logged errors are associated with their originating test method. (#9267)
Trial's documentation now directly mentions the preferred way of running Trial, via "python -m twisted.trial". (#9052)
twisted.internet.endpoints.HostnameEndpoint and twisted.internet.endpoints.TCP4Client endpoint documentation updated to correctly reflect that the timeout argument takes a float as well as an int. (#9151)
Badges at top of README now correctly render as links to respective result pages on GitHub. (#9216)
The example code for the trial tutorial is now compatible with Python3 and the current version of Twisted. (#9223)
twisted.protocols.dict is deprecated. (#9141)
gpsfix.py has been removed from the examples. It uses twisted.protocols.gps which was removed in Twisted 16.5.0. (#9253)
oscardemo.py, which illustrates the use of twisted.words.protocols.oscar, as been removed. twisted.words.protocols.oscar was removed in Twisted 17.5.0. (#9255)
#5949, #8566, #8650, #8944, #9159, #9160, #9162, #9196, #9219, #9228, #9229, #9230, #9247, #9248, #9249, #9251, #9254, #9262, #9276, #9308
twisted.conch.ssh.userauth.SSHUserAuthServer now gracefully handles unsupported authentication key types. (#9139)
twisted.conch.client.default verifyHostKey now opens /dev/tty with no buffer to be compatible with Python 3. This lets the conch cli work with Python 3. (#9265)
twisted.conch.ssh._cryptography_backports has been removed in favor of using int_to_bytes() and int_from_bytes() from cryptography.utils. (#9263)
#9158, #9272
twisted.web.static.File.contentTypes is now documented. (#5739)
twisted.web.server.Request and any Twisted web server using it now support automatic fast responses to HTTP/1.1 and HTTP/2 OPTIONS * requests, and reject any other verb using the * URL form. (#9190)
--add-header "HeaderName: Value" can be passed to twist web in order to set extra headers on all responses (#9241)
twisted.web.client.HTTPClientFactory(...).gotHeaders(...) now handles a wrong Set-Cookie header without a traceback. (#9136)
twisted.python.web.http.HTTPFactory now always opens logFile in binary mode and writes access logs in UTF-8, to avoid encoding issues and newline differences on Windows. (#9143)
The code examples in "Using the Twisted Web Client" now work on Python 3. (#9172)
twisted.web.server.Request and all web servers that use it now no longer send a default Content-Type header on responses that do not have a body (i.e. that set Content-Length: 0 or that send a 204 status code). (#9191)
twisted.web.http.Request and all subclasses now correctly fire Deferreds returned from notifyFinish with errbacks when errors are encountered in HTTP/2 streams. (#9208)
twisted.web.microdom, twisted.web.domhelpers, and twisted.web.sux now work on Python 3. (#9222)
Sending a list of recipients with twisted.smtp.SenderFactory has been fixed. This fixes a problem found when running buildbot. (#9180)
twisted.mail.imap4.IMAP4Server parses empty string literals even when they are the last argument to a command, such as LOGIN. (#9207)
twisted.words.tap has been ported to Python 3 (#9169)
#9246
Queries for unknown record types no longer incorrectly result in a server error. (#9095)
Failed TCP connections for AFXR queries no longer raise an AttributeError. (#9174)
Nothing published for this version
The transition to the hyperlink package adds IPv6 support to twisted.python.url.URL. This is now deprecated and new code should use hyperlink directly…
spawnProcess no longer opens an unwanted console on Windows (#5726)
The transition to the hyperlink package adds IPv6 support to twisted.python.url.URL. This is now deprecated and new code should use hyperlink directly (see #9126). (#8069)
twisted.logger now buffers only 200 events by default (reduced from 65536) while waiting for observers to be configured. (#8164)
The transition of twisted.python.url to using the hyperlink package enables a URL.click() with no arguments (or 0-length string argument) to resolve dot segments in the path. (#8184)
twisted.protocols.finger now works on Python 3. (#8230)
TLS-related tests now pass when run with OpenSSL 1.1.0. This makes tests pass again on macOS and Windows, as cryptography 1.8 and later include OpenSSL 1.1.0. (#8898)
UNIX socket endpoints now process all messages from recvmsg's ancillary data via twisted.internet.unix.Server.doRead/twisted.internet.unix.Client.doRead, while discarding and logging ones that don't contain file descriptors. (#8912)
twisted.internet.endpoints.HostnameEndpoint and twisted.web.client.Agent work again with reactors that do not provide IReactorPluggableNameResolver. This undoes the changes that broke downstream users such as treq.testing. Note that passing reactors that do not provide IReactorPluggableNameResolver to either is deprecated. (#9032)
A Python 3 Perspective Broker server which receives a remote call with keyword arguments from a Python 2 client will now decode any keys which are binary to strings instead of crashing. This fixes interoperability between Python 2 Buildbot clients and Python 3 Buildbot servers. (#9047)
twisted.internet._threadedselect now works on both Python 2 and 3. (#9053)
twisted.internet.interfaces.IResolverSimple implementers will now always be passed bytes, properly IDNA encoded if required, on Python 2. On Python 3, they will now be passed correctly IDNA-encoded Unicode forms of the domain, taking advantage of the idna library from PyPI if possible. This is to avoid Python's standard library (which has an out of date idna module) from mis- encoding domain names when non-ASCII Unicode is passed to it. (#9137)
The examples in Twisted howto "Using the Twisted Application Framework", section "Customizing twistd logging" have been updated to use latest logging modules and syntax (#9084)
twisted.internet.defer.Deferred.asFuture and twisted.internet.defer.Deferred.fromFuture were added, allowing for easy transitions between asyncio coroutines (which await Futures) and twisted coroutines (which await Deferreds). (#8748)
twisted.application.internet.ClientService.whenConnected now accepts an argument "failAfterFailures". If you set this to 1, the Deferred returned by whenConnected will errback when the connection attempt fails, rather than retrying forever. This lets you react (probably by stopping the ClientService) to connection errors that are likely to be persistent, such as using the wrong hostname, or not being connected to the internet at all. (#9116)
twisted.protocols.tls.TLSMemoryBIOProtocol and anything that uses it indirectly including the TLS client and server endpoints now enables TLS 1.3 cipher suites. (#9128)
#8133, #8995, #8997, #9003, #9015, #9021, #9026, #9027, #9049, #9057, #9062, #9065, #9069, #9070, #9072, #9074, #9075, #9111, #9117, #9140, #9144, #9145
twisted.runner.inetdconf.InvalidRPCServicesConfError, twisted.runner.inetdconf.RPCServicesConf, twisted.runner.inetdtap.RPCServer, and twisted.runner.portmap, deprecated since 16.2.0, have been removed. (#8464)
twisted.python.url and twisted.python._url were modified to rely on hyperlink, a new package based on the Twisted URL implementation. Hyperlink adds support for IPv6 (fixing #8069), correct username/password encoding, better scheme/netloc inference, improved URL.click() behavior (fixing #8184), and more. For full docs see hyperlink.readthedocs.io and the CHANGELOG in the hyperlink GitHub repo. (#9126)
History-aware terminal protocols like twisted.conch.manhole.Manhole no longer raise a TypeError when a user visits a partial line they added to the command line history by pressing up arrow before return. (#9031)
The telnet_echo.tac example had conflicting port callouts between runtime and documentation. File was altered to run on documented port, 6023. (#9055)
Remove diffie-hellman-group1-sha1 from twisted.conch. See https://weakdh.org/ (#9019)
Removed small and obscure elliptic curves from conch. The only curves conch supports now are the ones also supported by OpenSSH. (#9088)
twisted.mail.smtp has been ported to Python 3. (#8770)
RRHeader now converts its ttl argument to an integer, raising a TypeError if it cannot. (#8340)
twisted.web.cgi now works on Python 3 (#8009)
twisted.web.distrib now works on Python 3 (#8010)
twisted.web.http.HTTPFactory now propagates its reactor's callLater method to the HTTPChannel object, rather than having callLater grab the global reactor. This prevents the possibility of HTTPFactory logging using one reactor, but HTTPChannel running timeouts on another. (#8904)
twisted.web.template.flattenString docstring now correctly references io.BytesIO (rather than NativeStringIO). (#9028)
twisted.web.client now exposes the RequestGenerationFailed exception type. (#5310)
twisted.web.client.Agent will now parse responses that begin with a status line that is missing a phrase. (#7673)
twisted.web.http.HTTPChannel and twisted.web._http2.H2Connection have been enhanced so that after they time out they wait a small amount of time to allow the connection to close gracefully and, if it does not, they forcibly close it to avoid allowing malicious clients to forcibly keep the connection open. (#8902)
#8981, #9018, #9067, #9090, #9092, #9093, #9096
twisted.words.protocols.oscar, which is client code for Oscar/ICQ, was deprecated in 16.2.0 and has now been removed. (#9024)
twisted.internet.reactor.spawnProcess now does not emit a deprecation warning on Unicode arguments. It will encode Unicode arguments down to bytes usi…
Added a new interface, twisted.internet.interfaces.IHostnameResolver, which is an improvement to twisted.internet.interfaces.IResolverSimple that supports resolving multiple addresses as well as resolving IPv6 addresses. This is a native, asynchronous, Twisted analogue to getaddrinfo. (#4362)
twisted.web.client.Agent now uses HostnameEndpoint internally; as a consequence, it now supports IPv6, as well as making connections faster and more reliably to hosts that have more than one DNS name. (#6712)
twisted.internet.ssl.CertificateOptions now has the new constructor argument 'raiseMinimumTo', allowing you to increase the minimum TLS version to this version or Twisted's default, whichever is higher. The additional new constructor arguments 'lowerMaximumSecurityTo' and 'insecurelyLowerMinimumTo' allow finer grained control over negotiated versions that don't honour Twisted's defaults, for working around broken peers, at the cost of reducing the security of the TLS it will negotiate. (#6800)
twisted.internet.ssl.CertificateOptions now sets the OpenSSL context's mode to MODE_RELEASE_BUFFERS, which will free the read/write buffers on idle TLS connections to save memory. (#8247)
trial --help-reactors will only list reactors which can be imported. (#8745)
twisted.internet.endpoints.HostnameEndpoint now uses the passed reactor's implementation of twisted.internet.interfaces.IReactorPluggableResolver to resolve hostnames rather than its own deferToThread/getaddrinfo wrapper; this makes its hostname resolution pluggable via a public API. (#8922)
twisted.internet.reactor.spawnProcess now does not emit a deprecation warning on Unicode arguments. It will encode Unicode arguments down to bytes using the filesystem encoding on UNIX and Python 2 on Windows, and pass Unicode through unchanged on Python 3 on Windows. (#8941)
twisted.trial._dist.test.test_distreporter now works on Python 3. (#8943)
trial --help-reactors will now display iocp and win32er reactors with Python 3. (#8745)
twisted.logger._flatten.flattenEvent now handles log_format being None instead of assuming the value is always a string. (#8860)
twisted.protocol.ftp is now Python 3 compatible (#8865)
twisted.names.client.Resolver can now resolve names with IPv6 DNS servers. (#8877)
twisted.application.internet.ClientService now waits for existing connections to disconnect before trying to connect again when restarting. (#8899)
twisted.internet.unix.Server.doRead and twisted.internet.unix.Client.doRead no longer fail if recvmsg's ancillary data contains more than one file descriptor. (#8911)
twist on Python 3 now correctly prints the help text when given no plugin to run. (#8918)
twisted.python.sendmsg.sendmsg no longer segfaults on Linux + Python 2. (#8969)
IHandshakeListener providers connected via SSL4ClientEndpoint will now have their handshakeCompleted methods called. (#8973)
The twist script now respects the --reactor option. (#8983)
Fix crash when using SynchronousTestCase with Warning object which does not store a string as its first argument (like libmysqlclient). (#9005)
twisted.python.compat.execfile() does not open files with the deprecated 'U' flag on Python 3. (#9012)
twisted.internet.ssl.CertificateOption's 'method' constructor argument is now deprecated, in favour of the new 'raiseMinimumTo', 'lowerMaximumSecurityTo', and 'insecurelyLowerMinimumTo' arguments. (#6800)
twisted.protocols.telnet (not to be confused with the supported twisted.conch.telnet), deprecated since Twisted 2.5, has been removed. (#8925)
twisted.application.strports.parse, as well as the deprecated default arguments in strports.service/listen, deprecated since Twisted 10.2, has been removed. (#8926)
twisted.web.client.getPage and twisted.web.client.downloadPage have been deprecated in favour of https://pypi.org/project/treq and twisted.web.client.Agent. (#8960)
twisted.internet.defer.timeout is deprecated in favor of twisted.internet.defer.Deferred.addTimeout (#8971)
#7879, #8583, #8764, #8809, #8859, #8906, #8910, #8913, #8916, #8934, #8945, #8949, #8950, #8952, #8953, #8959, #8962, #8963, #8967, #8975, #8976, #8993, #9013
Nothing published for this version
Nothing published for this version
Nothing published for this version
The twist script can now be run by invoking python -m twisted.
The twist script can now be run by invoking python -m twisted. (#8657)
twisted.protocols.sip has been ported to Python 3. (#8669)
twisted.persisted.dirdbm has been ported to Python 3. (#8888)
twisted.internet.defer.Deferred now implements send, not __send__, which means that it is now a conforming generator. (#8861)
The IOCP reactor no longer transmits the contents of uninitialized memory when writing large amounts of data. (#8870)
Deferreds awaited/yielded from in a twisted.internet.defer.ensureDeferred wrapped coroutine will now properly raise exceptions. Additionally, it more closely models asyncio.ensure_future and will pass through Deferreds. (#8878)
Deferreds that are paused or chained on other Deferreds will now return a result when yielded/awaited in a twisted.internet.defer .ensureDeferred-wrapped coroutine, instead of returning the Deferred it was chained to. (#8890)
twisted.test.proto_helpers is now explicitly covered by the compatibility policy. (#8857)
#8281, #8823, #8862
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →