• Bug#1064264: openssl: NMU diff for 64-bit time_t transition

    From Steve Langasek@21:1/5 to All on Mon Feb 19 08:40:01 2024
    This is a multi-part MIME message sent by reportbug.


    Source: openssl
    Version: 3.1.5-1
    Severity: important
    Tags: patch pending sid trixie
    User: debian-arm@lists.debian.org
    Usertags: time-t

    NOTICE: these changes must not be uploaded to unstable yet!

    Dear maintainer,

    As part of the 64-bit time_t transition required to support 32-bit architectures in 2038 and beyond (https://wiki.debian.org/ReleaseGoals/64bit-time), we have identified
    openssl as a source package shipping runtime libraries whose ABI
    either is affected by the change in size of time_t, or could not be
    analyzed via abi-compliance-checker (and therefore to be on the safe
    side we assume is affected).

    To ensure that inconsistent combinations of libraries with their reverse-dependencies are never installed together, it is necessary to
    have a library transition, which is most easily done by renaming the
    runtime library package.

    Since turning on 64-bit time_t is being handled centrally through a change
    to the default dpkg-buildflags (https://bugs.debian.org/1037136), it is important that libraries affected by this ABI change all be uploaded close together in time. Therefore I have prepared a 0-day NMU for openssl
    which will initially be uploaded to experimental if possible, then to
    unstable after packages have cleared binary NEW.

    Please find the patch for this NMU attached.

    If you have any concerns about this patch, please reach out ASAP. Although this package will be uploaded to experimental immediately, there will be a period of several days before we begin uploads to unstable; so if information becomes available that your package should not be included in the transition, there is time for us to amend the planned uploads.



    -- System Information:
    Debian Release: trixie/sid
    APT prefers unstable
    APT policy: (500, 'unstable')
    Architecture: amd64 (x86_64)

    Kernel: Linux 6.5.0-14-generic (SMP w/12 CPU threads; PREEMPT)
    Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE
    Locale: LANG=C, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE not set
    Shell: /bin/sh linked to /usr/bin/dash
    Init: systemd (via /run/systemd/system)

    diff -Nru openssl-3.1.5/debian/changelog openssl-3.1.5/debian/changelog
    --- openssl-3.1.5/debian/changelog 2024-02-03 16:11:24.000000000 +0000
    +++ openssl-3.1.5/debian/changelog 2024-02-19 07:06:24.000000000 +0000
    @@ -1,3 +1,10 @@
    +openssl (3.1.5-1.1) experimental; urgency=medium
    +
    + * Non-maintainer upload.
    + * Rename libraries for 64-bit time_t transition.
    +
    + -- Steve Langasek <vorlon@debian.org> Mon, 19 Feb 2024 07:06:24 +0000
    +
    openssl (3.1.5-1) unstable; urgency=medium

    * Import 3.1.5
    diff -Nru openssl-3.1.5/debian/control openssl-3.1.5/debian/control
    --- openssl-3.1.5/debian/control 2024-02-03 16:00:20.000000000 +0000
    +++ openssl-3.1.5/debian/control 2024-02-19 07:06:24.000000000 +0000
    @@ -29,11 +29,13 @@
    * testing SSL/TLS clients and servers;
    * handling S/MIME signed or encrypted mail.

    -Package: libssl3
    +Package: libssl3t64
    +Provides: ${t64:Provides}
    +Replaces: libssl3
    Section: libs
    Architecture: any
    Multi-Arch: same
    -Breaks: openssh-client (<< 1:9.4p1), openssh-server (<< 1:9.4p1), python3-m2crypto (<< 0.38.0-4)
    +Breaks: libss
  • From Benjamin Drung@21:1/5 to All on Thu Feb 29 14:10:01 2024
    This is a multi-part MIME message sent by reportbug.


    Source: openssl
    Dear maintainer,

    Please find attached a final version of this patch for the time_t
    transition. This patch is being uploaded to unstable.

    Note that this adds a versioned build-dependency on dpkg-dev, to guard
    against accidental backports with a wrong ABI.

    Thanks!


    -- System Information:
    Debian Release: trixie/sid
    APT prefers unstable
    APT policy: (500, 'unstable'), (1, 'experimental')
    Architecture: amd64 (x86_64)

    Kernel: Linux 6.5.0-21-generic (SMP w/16 CPU threads; PREEMPT)
    Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE, TAINT_UNSIGNED_MODULE
    Locale: LANG=C, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE not set
    Shell: /bin/sh linked to /usr/bin/dash
    Init: unable to detect

    diff -Nru openssl-3.1.5/debian/changelog openssl-3.1.5/debian/changelog
    --- openssl-3.1.5/debian/changelog 2024-02-03 16:11:24.000000000 +0000
    +++ openssl-3.1.5/debian/changelog 2024-02-29 12:55:38.000000000 +0000
    @@ -1,3 +1,10 @@
    +openssl (3.1.5-1.1) unstable; urgency=medium
    +
    + * Non-maintainer upload.
    + * Rename libraries for 64-bit time_t transition. Closes: #1064264
    +
    + -- Benjamin Drung <bdrung@debian.org> Thu, 29 Feb 2024 12:55:38 +0000
    +
    openssl (3.1.5-1) unstable; urgency=medium

    * Import 3.1.5
    diff -Nru openssl-3.1.5/debian/control openssl-3.1.5/debian/control
    --- openssl-3.1.5/debian/control 2024-02-03 16:00:20.000000000 +0000
    +++ openssl-3.1.5/debian/control 2024-02-29 12:55:38.000000000 +0000
    @@ -1,5 +1,5 @@
    Source: openssl
    -Build-Depends: debhelper-compat (= 13), dpkg-dev (>= 1.15.7)
    +Build-Depends: dpkg-dev (>= 1.22.5), debhelper-compat (= 13), dpkg-dev (>= 1.15.7)
    Section: utils
    Priority: optional
    Maintainer: Debian OpenSSL Team <pkg-openssl-devel@alioth-lists.debian.net>
    @@ -29,11 +29,13 @@
    * testing SSL/TLS clients and serv