Wednesday, September 30, 2026

Re: gnupg 2.5.24 vs notmuch [Re: CVS: cvs.openbsd.org: ports]

On Sun, Sep 27, 2026 at 08:00:31PM +0200, Jeremie Courreges-Anglas wrote: > On Sat, Sep 26, 2026 at 01:00:46PM +0100, Stuart Henderson wrote: > > On 2026/09/23 13:43, Jeremie Courreges-Anglas wrote: > > > CVSROOT: /cvs > > > Module name: ports > > > Changes by: jca@cvs.openbsd.org 2026/09/23 13:43:54 > > > > > > Modified files: > > > security/gnupg : Makefile distinfo > > > > > > Log message: > > > Update to gnupg-2.5.24 > > > > > > > This breaks a configure test in mail/notmuch which tries to extract > > a session key using gmime. I've had trouble with this in the past due > > to a libgcrypt issue on i386, so I have a test case handy, shell script > > attached. Any ideas? Nothing from https://dev.gnupg.org/T8425.html > > jumps out at me as being particularly likely to be involved. > > I have reverted to 2.5.22(+EPOCH) since it's not clear how wide the > breakage is. I'm not sure there will be a gnupg-2.5.26 bugfix release > before OpenBSD 8.0 so I'm playing it safe for now. Issue already > reported upstream by wiz@NetBSD: > > https://lists.gnupg.org/pipermail/gnupg-devel/2026-September/036466.html > > I've added some input but my mail is currently blocked by greylisting. So upstream quickly found the issue. I propose going back to gnupg-2.5.24 plus the fix before release. This way it would be a smaller diff to review if I have to push a security update to the -stable branch. Thoughts? ok? Index: Makefile =================================================================== RCS file: /home/cvs/ports/security/gnupg/Makefile,v diff -u -p -r1.153 Makefile --- Makefile 27 Sep 2026 16:55:00 -0000 1.153 +++ Makefile 30 Sep 2026 10:19:35 -0000 @@ -1,7 +1,8 @@ COMMENT = GNU privacy guard - a free PGP replacement -DISTNAME = gnupg-2.5.22 +DISTNAME = gnupg-2.5.24 EPOCH = 0 +REVISION = 0 CATEGORIES = security Index: distinfo =================================================================== RCS file: /home/cvs/ports/security/gnupg/distinfo,v diff -u -p -r1.57 distinfo --- distinfo 27 Sep 2026 16:55:00 -0000 1.57 +++ distinfo 30 Sep 2026 10:19:41 -0000 @@ -1,2 +1,2 @@ -SHA256 (gnupg-2.5.22.tar.bz2) = luJ7AgrSZRA4jgb18H8/cKTtiRbumV8bcregJObZ2H4= -SIZE (gnupg-2.5.22.tar.bz2) = 8363854 +SHA256 (gnupg-2.5.24.tar.bz2) = vxSdAaK5/MDkWJuK6Gl9PVxVfqSO2Vo/pV3TsRh+YDk= +SIZE (gnupg-2.5.24.tar.bz2) = 8431157 Index: patches/patch-g10_import_c =================================================================== RCS file: patches/patch-g10_import_c diff -N patches/patch-g10_import_c --- /dev/null 1 Jan 1970 00:00:00 -0000 +++ patches/patch-g10_import_c 30 Sep 2026 10:24:14 -0000 @@ -0,0 +1,19 @@ +42386bc upstream commit + +Index: g10/import.c +--- g10/import.c.orig ++++ g10/import.c +@@ -2732,11 +2732,11 @@ build_mode1003_sexp (PKT_public_key *pk, gcry_sexp_t * + else if (openpgp_oid_is_cv25519 (pk->pkey[0])) + err = gcry_sexp_build + (&skey,NULL,"(private-key(ecc(curve %s)(flags djb-tweak)(q%m)(d%m)))", +- curvename, pk->pkey[2], pk->pkey[3]); ++ curvename, pk->pkey[1], pk->pkey[3]); + else + err = gcry_sexp_build + (&skey,NULL,"(private-key(ecc(curve %s)(q%m)(d%m)))", +- curvename, pk->pkey[2], pk->pkey[3]); ++ curvename, pk->pkey[1], pk->pkey[3]); + break; + + case PUBKEY_ALGO_X25519: -- jca

No comments:

Post a Comment