pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: CVS commit: pkgsrc/security/gnupg2



Hi,

Thomas Klausner <wiz%netbsd.org@localhost> writes:

> Hi!
>
> Yes, I had already started an upstream discussion, but probably due to
> the weekend, there was no real feedback yet.
>
> I've downgraded the package for now.

I have some more information.
The following patch seems minimal patch to fix my problem.
So I think that build_mode1003_sexp() has bad bahavior.

--- g10/import.c.orig   2026-09-22 09:20:47.000000000 +0000
+++ g10/import.c
@@ -3159,12 +3159,14 @@ transfer_secret_keys (ctrl_t ctrl, struct import_stats
             }
           use_mode1003 = 1;
         }
+#if 0
       else if (!ski->is_protected)
         {
           /* The key is not protected.  Build a mode1003 format here.  */
           err = build_mode1003_sexp (pk, &tmpsexp);
           use_mode1003 = 1;
         }
+#endif
       else
         err = build_classic_transfer_sexp (pk, &tmpsexp);
 
And switch() in line 2696 of g10/import.c may have wrong value.
In my case, Ed25519 should be in case PUBKEY_ALGO_ED25519, I believe.
However it goes another case. (I have forgotten to the value, sorry.)

I am not on gnupg-dev mailing list now.
I will subscribe it.

Thank you.

>  Thomas
>
>
> On Sun, Sep 27, 2026 at 11:09:30PM +0100, Ryo ONODERA wrote:
>> Hi,
>> 
>> It seems that GnuPG 2.5.24 does not import Ed25519 keys like 2.5.22.
>> In ~/gnupg/private-keys-v1.d, S expression format keys uses OID,
>> "1.3.6.1.4.1.11591.15.1" instead of algorithm name like Ed25519.
>> I have no idea about what really intended, however this change
>> prevents `gpg --show-session-key PGPMIME.eml`
>> and configure of pkgsrc/mail/notmuch.
>> 
>> If you already have a solution, could you please revert
>> pkgsrc/security/gnupg to 2.5.22?
>> 
>> Thank you.
>> 
>> On Sat, Sep 26, 2026 at 6:47 PM Thomas Klausner <wiz%netbsd.org@localhost> wrote:
>> >
>> > Module Name:    pkgsrc
>> > Committed By:   wiz
>> > Date:           Sat Sep 26 09:47:55 UTC 2026
>> >
>> > Modified Files:
>> >         pkgsrc/security/gnupg2: Makefile distinfo
>> >
>> > Log Message:
>> > gnupg2: update to 2.5.24.
>> >
>> > Noteworthy changes in version 2.5.24 (2026-09-23)
>> > -------------------------------------------------
>> >
>> >  * Bug fixes:
>> >
>> >    - scd: Fix for regression in 2.5.23 related to the new Nitrokey
>> >      detection.  [T8331]
>> >
>> >  Release-info: https://dev.gnupg.org/T8425
>> >
>> > Noteworthy changes in version 2.5.23 (2026-09-22)
>> > -------------------------------------------------
>> >
>> >  * New and extended features:
>> >
>> >    - gpg: New option --allow-9980 to enable the processing of RFC-9980
>> >      specified data structures.  The use of this option is only
>> >      recommended if external policy requirements demand the use of
>> >      these governmental approved specification.  PGP folks requiring
>> >      some PQC resistance should keep on using the standard LibrePGP
>> >      Kyber algorithm introduced 2 years ago.  [rG6803ce215c]
>> >
>> >    - gpg: In 9980 mode support PQC encryption using ML-KEM (aka Kyber)
>> >      with X448, X25519, Brainpool, or NIST curves as specified by
>> >      RFC-9980 et al.
>> >
>> >    - gpg: In 9980 mode support ED25519 and X25519 as specified by
>> >      RFC-9580 under the names "ietf27" and "ietf27".
>> >
>> >    - gpg: Add experimental support for a --compliance=fips mode to use
>> >      GCM for bulk encryption.  [rG05c271f45a]
>> >
>> >    - scd: Add Nitrokey 3 to pcsc-shared interference detection.
>> >      [T8331]
>> >
>> >  * Bug fixes:
>> >
>> >    - gpgsm: Fix an exploitable printf bug when using the debug option
>> >      "--debug x509".  [rGe6d92ff7af]
>> >
>> >    - dirmngr: Make the LDAP upload flags also work for KS_SEARCH.
>> >      [T7866]
>> >
>> >    - dirmngr: Fix OOB read in DNS CERT record parser.  [T8464]
>> >
>> >    - scd: Fix OOB access in DO parsing of faulty cards.  [T8465]
>> >
>> >  * Other changes:
>> >
>> >    - dirmngr: Add a mitigation for badly configured web key
>> >      directories.  [rGbc7686ad7c]
>> >
>> >    - New option --debug-no-libgcrypt for gpg, gpgsm, and agent.  This
>> >      debug option is useful to avoid cluttering other debug output
>> >      with libgcrypt generated debug details.
>> >
>> >    - gpg: New --list-options "debug-show-sexp" to print a secret key
>> >      as an s-expression.  [rG1e0261fe50]
>> >
>> >  Release-info: https://dev.gnupg.org/T8425
>> >
>> >
>> > To generate a diff of this commit:
>> > cvs rdiff -u -r1.180 -r1.181 pkgsrc/security/gnupg2/Makefile
>> > cvs rdiff -u -r1.100 -r1.101 pkgsrc/security/gnupg2/distinfo
>> >
>> > Please note that diffs are not public domain; they are subject to the
>> > copyright notices on the relevant files.
>> >
>> 
>> 
>> -- 
>> Ryo ONODERA // ryo%tetera.org@localhost
>> PGP fingerprint = 82A2 DC91 76E0 A10A 8ABB  FD1B F404 27FA C7D1 15F3

-- 
Ryo ONODERA // ryo%tetera.org@localhost
PGP fingerprint = 82A2 DC91 76E0 A10A 8ABB  FD1B F404 27FA C7D1 15F3



Home | Main Index | Thread Index | Old Index