Thanks, review comments from ubuntu-review-new skill/opus5

     0. debian/README.source says the package is based on 3.5.5-1ubuntu3.5 and 
that the patches should stay "identical to the Ubuntu OpenSSL 3.5 security 
source". But resolute-security      
     has since published 3.6 and 3.7, and none of those patches are in this 
package: 

     1. Leftover packaging files that nothing uses any more. Suggest removing 
them:                                                                           
                                                                    
        - openssl.install, openssl.dirs, openssl.docs, openssl.NEWS             
                                                                                
                                                                  
        - openssl.postinst and openssl.lintian-overrides                        
                                                                                
                                                                  
        - openssl-provider-legacy.install and openssl-provider-fips.install     
                                                                                
                                                                  
        - libssl-dev.*, libssl-doc.*, lib*-udeb.dirs                            
                                                                                
                                                                  
        - salsa-ci.yml                                                          
                                                                                
                                                                  
        - package=openssl in debian/rules         


     2. debian/control:                                                         
                                                                                
                                               
        - Uploaders and Vcs-* still point at Debian's openssl team and Salsa. 
This source exists only in Ubuntu, so I'd drop Uploaders and Vcs-* or point 
them at the real Ubuntu git branch.                                     
        - The Homepage field is fine.       

     3. Providers loaded at runtime: libcrypto.so.3 still loads providers from 
/usr/lib/<triplet>/ossl-modules, where openssl 4 installs its own legacy.so and 
fips.so. README.source itself says the OpenSSL 4 module can't      
        serve libcrypto.so.3. Please confirm what happens in two cases:         
                                                                                
                                                                  
        - when an OpenSSL 3 app asks for the legacy provider;                   
                                                                                
                                                                  
        - in kernel FIPS mode, where the Ubuntu FIPS patches load fips.so 
automatically.      

        It should be a clean error, not a crash. If it's a clean error,
it's worth saying so in README.debian.

     4. Shared config: /etc/ssl/openssl.cnf (and its drop-ins) is shared with 
openssl 4. It needs to keep parsing cleanly under libssl3.                      
                                                                    
     5. Helper scripts: the scripts shipped in /usr/lib/ssl3.5/misc (CA.pl, 
tsget) call openssl from PATH, so they'll actually run OpenSSL 4. That's minor, 
but either note it or drop them.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2167636

Title:
  [FFe] create an openssl3 compat package for stonking

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/2167636/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to