Wednesday, September 30, 2026

Re: gnupg 2.5.24 vs notmuch [Re: CVS: cvs.openbsd.org: ports]

REVISION not needed but doesn't hurt. ok

-- 
  Sent from a phone, apologies for poor formatting.


On 30 September 2026 18:44:38 Jeremie Courreges-Anglas <jca@wxcvbn.org> wrote:

On Sun, Sep 27, 2026 at 08:00:31PM +0200, Jeremie Courreges-Anglas wrote:
On Sat, Sep 26, 2026 at 01:00:46PM +0100, Stuart Henderson wrote:
On 2026/09/23 13:43, Jeremie Courreges-Anglas wrote:
CVSROOT: /cvs
Module name: ports
Changes by: jca@cvs.openbsd.org 2026/09/23 13:43:54

Modified files:
security/gnupg : Makefile distinfo 

Log message:
Update to gnupg-2.5.24


This breaks a configure test in mail/notmuch which tries to extract
a session key using gmime. I've had trouble with this in the past due
to a libgcrypt issue on i386, so I have a test case handy, shell script
attached. Any ideas? Nothing from https://dev.gnupg.org/T8425.html
jumps out at me as being particularly likely to be involved.

I have reverted to 2.5.22(+EPOCH) since it's not clear how wide the
breakage is.  I'm not sure there will be a gnupg-2.5.26 bugfix release
before OpenBSD 8.0 so I'm playing it safe for now.  Issue already
reported upstream by wiz@NetBSD:

https://lists.gnupg.org/pipermail/gnupg-devel/2026-September/036466.html

I've added some input but my mail is currently blocked by greylisting.

So upstream quickly found the issue.  I propose going back to
gnupg-2.5.24 plus the fix before release.  This way it would be a
smaller diff to review if I have to push a security update to the
-stable branch.

Thoughts?  ok?


Index: Makefile
===================================================================
RCS file: /home/cvs/ports/security/gnupg/Makefile,v
diff -u -p -r1.153 Makefile
--- Makefile 27 Sep 2026 16:55:00 -0000 1.153
+++ Makefile 30 Sep 2026 10:19:35 -0000
@@ -1,7 +1,8 @@
 COMMENT = GNU privacy guard - a free PGP replacement
 
-DISTNAME = gnupg-2.5.22
+DISTNAME = gnupg-2.5.24
 EPOCH = 0
+REVISION = 0
 
 CATEGORIES = security
 
Index: distinfo
===================================================================
RCS file: /home/cvs/ports/security/gnupg/distinfo,v
diff -u -p -r1.57 distinfo
--- distinfo 27 Sep 2026 16:55:00 -0000 1.57
+++ distinfo 30 Sep 2026 10:19:41 -0000
@@ -1,2 +1,2 @@
-SHA256 (gnupg-2.5.22.tar.bz2) = luJ7AgrSZRA4jgb18H8/cKTtiRbumV8bcregJObZ2H4=
-SIZE (gnupg-2.5.22.tar.bz2) = 8363854
+SHA256 (gnupg-2.5.24.tar.bz2) = vxSdAaK5/MDkWJuK6Gl9PVxVfqSO2Vo/pV3TsRh+YDk=
+SIZE (gnupg-2.5.24.tar.bz2) = 8431157
Index: patches/patch-g10_import_c
===================================================================
RCS file: patches/patch-g10_import_c
diff -N patches/patch-g10_import_c
--- /dev/null 1 Jan 1970 00:00:00 -0000
+++ patches/patch-g10_import_c 30 Sep 2026 10:24:14 -0000
@@ -0,0 +1,19 @@
+42386bc upstream commit
+
+Index: g10/import.c
+--- g10/import.c.orig
++++ g10/import.c
+@@ -2732,11 +2732,11 @@ build_mode1003_sexp (PKT_public_key *pk, gcry_sexp_t *
+       else if (openpgp_oid_is_cv25519 (pk->pkey[0]))
+         err = gcry_sexp_build
+           (&skey,NULL,"(private-key(ecc(curve %s)(flags djb-tweak)(q%m)(d%m)))",
+-           curvename, pk->pkey[2], pk->pkey[3]);
++           curvename, pk->pkey[1], pk->pkey[3]);
+       else
+         err = gcry_sexp_build
+           (&skey,NULL,"(private-key(ecc(curve %s)(q%m)(d%m)))",
+-           curvename, pk->pkey[2], pk->pkey[3]);
++           curvename, pk->pkey[1], pk->pkey[3]);
+       break;
+ 
+     case PUBKEY_ALGO_X25519:


-- 
jca

No comments:

Post a Comment