From 4f7cc728657ef10cfe0cbc3f78d7a2b07d2b5845 Mon Sep 17 00:00:00 2001 From: Simone Orsi Date: Mon, 28 Sep 2026 17:09:42 +0200 Subject: [PATCH] [FIX] data_encryption: pin cryptography to odoo core version An unpinned "cryptography" in requirements.txt lets pip resolve the latest release, which removed the private cryptography.hazmat.backends.openssl.x509 module. Odoo's own pinned urllib3==1.26.5 (Python < 3.12) still imports that module through its legacy contrib.pyopenssl shim, used unconditionally by odoo/addons/base/models/ir_mail_server.py, so any install that upgrades cryptography past that point fails to boot at all: ModuleNotFoundError: No module named 'cryptography.hazmat.backends.openssl.x509' Cap it below the breaking release so the version Odoo itself pins (3.4.8 on Python < 3.12, 42.0.8 on Python >= 3.12) is still installable. --- data_encryption/__manifest__.py | 8 +++++++- requirements.txt | 3 ++- 2 files changed, 9 insertions(+), 2 deletions(-) diff --git a/data_encryption/__manifest__.py b/data_encryption/__manifest__.py index 169cf215c..067c45656 100644 --- a/data_encryption/__manifest__.py +++ b/data_encryption/__manifest__.py @@ -12,7 +12,13 @@ "license": "AGPL-3", "application": False, "installable": True, - "external_dependencies": {"python": ["cryptography"]}, + "external_dependencies": { + # Use the same pin as Odoo to avoid compatibility issues + "python": [ + "cryptography==3.4.8; python_version < '3.12'", + "cryptography==42.0.8 ; python_version >= '3.12'", + ] + }, "depends": ["base"], "data": ["security/ir.model.access.csv"], } diff --git a/requirements.txt b/requirements.txt index 368c5c28f..dd388a177 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,2 +1,3 @@ # generated from manifests external_dependencies -cryptography +cryptography==3.4.8; python_version < '3.12' +cryptography==42.0.8 ; python_version >= '3.12'