(Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 4fqDy63VWHz41KD; Mon, 06 Apr 2026 16:17:49 +0000 (UTC) (envelope-from junchoon@dec.sakura.ne.jp) Authentication-Results: mx1.freebsd.org; dkim=pass header.d=dec.sakura.ne.jp header.s=s2405 header.b=vRI4ocZ5; dmarc=pass (policy=none) header.from=dec.sakura.ne.jp; spf=pass (mx1.freebsd.org: domain of junchoon@dec.sakura.ne.jp designates 153.125.133.21 as permitted sender) smtp.mailfrom=junchoon@dec.sakura.ne.jp Received: from delta.joker.local (124-18-6-240.area1c.commufa.jp [124.18.6.240]) (authenticated bits=0) by www121.sakura.ne.jp (8.18.1/8.17.1/[SAKURA-WEB]/20201212) with ESMTPA id 636GHjBa038729; Tue, 7 Apr 2026 01:17:46 +0900 (JST) (envelope-from junchoon@dec.sakura.ne.jp) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=dec.sakura.ne.jp; s=s2405; t=1775492266; bh=m7iq/a3YvU6iLYd02xZsjyv2TGyfrkI+kdDmROpmGI4=; h=Date:From:To:Cc:Subject; b=vRI4ocZ5XR/WKbURKmUbCerqQK2qW4NDVufvL7cxeWFlbEzDqD86ohs+J2Ez+BJV/ hsqoWLJA02HH4IMtxxwO+Xg842/flWNFrm7qYir5EBUxalXAxdDweTcTeAyE2lDHsA Bs/GhzuZ2mndNJavjCNv0eDCWL8MsNE+y8YLhM3w= Date: Tue, 7 Apr 2026 01:17:45 +0900 From: Tomoaki AOKI To: Dima Panov , Pierre Pronchery Cc: dev-commits-ports-main@freebsd.org, Daniel Engberg Subject: Re: git: 4211f99a216d - main - security/libssh: Mark BROKEN on 15+ and add backup for MASTER_SITES Message-Id: <20260407011745.1ee516a74deca884c60415a7@dec.sakura.ne.jp> Organization: Junchoon corps X-Mailer: Sylpheed 3.7.0 (GTK+ 2.24.33; amd64-portbld-freebsd15.0) List-Id: Commits to the main branch of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-ports-main@freebsd.org Sender: owner-dev-commits-ports-main@FreeBSD.org Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-Spamd-Result: default: False [0.31 / 15.00]; FAKE_REPLY(1.00)[]; SUSPICIOUS_URL_IN_SUSPICIOUS_MESSAGE(1.00)[]; NEURAL_HAM_MEDIUM(-1.00)[-1.000]; NEURAL_HAM_SHORT(-1.00)[-0.998]; NEURAL_HAM_LONG(-0.99)[-0.993]; MV_CASE(0.50)[]; URIBL_RED(0.50)[dec.sakura.ne.jp:dkim,dec.sakura.ne.jp:mid,dec.sakura.ne.jp:email]; ONCE_RECEIVED(0.20)[]; HAS_ANON_DOMAIN(0.10)[]; MIME_GOOD(-0.10)[text/plain]; BAD_REP_POLICIES(0.10)[]; DKIM_TRACE(0.00)[dec.sakura.ne.jp:+]; ARC_NA(0.00)[]; R_DKIM_ALLOW(0.00)[dec.sakura.ne.jp:s=s2405]; HAS_ORG_HEADER(0.00)[]; RCVD_TLS_LAST(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; DMARC_POLICY_ALLOW(0.00)[dec.sakura.ne.jp,none]; FROM_HAS_DN(0.00)[]; MIME_TRACE(0.00)[0:+]; MID_RHS_MATCH_FROM(0.00)[]; MLMMJ_DEST(0.00)[dev-commits-ports-main@freebsd.org]; FROM_EQ_ENVFROM(0.00)[]; RCPT_COUNT_THREE(0.00)[4]; R_SPF_ALLOW(0.00)[+ip4:153.125.133.16/28]; ASN(0.00)[asn:7684, ipnet:153.125.128.0/18, country:JP]; RCVD_VIA_SMTP_AUTH(0.00)[]; RCVD_COUNT_ONE(0.00)[1]; TO_DN_SOME(0.00)[] X-Rspamd-Queue-Id: 4fqDy63VWHz41KD X-Spamd-Bar: / Hi. Is it intentional here that didn't make ml_kem.h installed on importing at commit e7be843b4a162e68651d3911f0357ed464915629? https://cgit.freebsd.org/src/commit/?id=e7be843b4a162e68651d3911f0357ed464915629 If not, can it be made installed (possibly OSVERSION bump is wanted, though) on all affected branches (including releng/15.0 as errata -p* upgrade)? Regards. > BTW, we have missed corresponding include file in base openssl since it was merged with 3.5.x > > diff --git a/secure/lib/libcrypto/Makefile b/secure/lib/libcrypto/Makefile > index 9d484e9d48..f57f53a8c7 100644 > --- a/secure/lib/libcrypto/Makefile > +++ b/secure/lib/libcrypto/Makefile > @@ -635,7 +635,7 @@ INCS+= des.h dh.h dherr.h dsa.h > INCS+= dsaerr.h > INCS+= dtls1.h e_os2.h e_ostime.h ebcdic.h ec.h ecdh.h ecdsa.h ecerr.h encoder.h encodererr.h > INCS+= engine.h engineerr.h err.h ess.h esserr.h evp.h evperr.h fips_names.h fipskey.h hmac.h hpke.h http.h httperr.h idea.h indicator.h > -INCS+= kdf.h kdferr.h lhash.h macros.h md2.h md4.h md5.h mdc2.h modes.h obj_mac.h > +INCS+= kdf.h kdferr.h lhash.h macros.h md2.h md4.h md5.h mdc2.h ml_kem.h modes.h obj_mac.h > INCS+= objects.h objectserr.h ocsp.h ocsperr.h opensslconf.h opensslv.h > INCS+= ossl_typ.h param_build.h params.h pem.h pem2.h pemerr.h pkcs12.h pkcs12err.h pkcs7.h > INCS+= pkcs7err.h prov_ssl.h proverr.h provider.h quic.h rand.h randerr.h rc2.h rc4.h rc5.h ripemd.h > > On 06.04.2026 18:12, Dima Panov wrote: > > Hello! > > > > There is another solution -- force check for openssl 3.6 to enable ML-KEM extension > > > > > > diff --git a/security/libssh/Makefile b/security/libssh/Makefile > > index cbec0cfe7b..2f1224e3be 100644 > > --- a/security/libssh/Makefile > > +++ b/security/libssh/Makefile > > @@ -67,6 +68,10 @@ OPENSSL_CMAKE_BOOL_OFF= CMAKE_DISABLE_FIND_PACKAGE_OpenSSL > > OPENSSL_USES= ssl > > STATIC_CMAKE_BOOL= BUILD_STATIC_LIB > > > > +post-patch: > > + ${REINPLACE_CMD} -e '/OPENSSL_VERSION/s,3.5.0,3.6.0,g' \ > > + ${WRKSRC}/ConfigureChecks.cmake > > + > > post-install-STATIC-on: > > ${INSTALL_DATA} ${INSTALL_WRKSRC}/src/libssh.a ${STAGEDIR}${PREFIX}/lib/ > > > > > > On 06.04.2026 15:53, Daniel Engberg wrote: > > > The branch main has been updated by diizzy: > > > > > > URL: https://cgit.FreeBSD.org/ports/commit/?id=4211f99a216d4f440b3b804a1e6db475087e3ed2 > > > > > > commit 4211f99a216d4f440b3b804a1e6db475087e3ed2 > > > Author: Daniel Engberg > > > AuthorDate: 2026-04-06 12:45:14 +0000 > > > Commit: Daniel Engberg > > > CommitDate: 2026-04-06 12:53:21 +0000 > > > > > > security/libssh: Mark BROKEN on 15+ and add backup for MASTER_SITES > > > > > > Fails to build on 15+, > > > src/mlkem_crypto.c:31:10: fatal error: 'openssl/ml_kem.h' file not found > > > > > > Add temporary backup for MASTER_SITES to avoid build failures on other > > > versions and of consumers as main upstream site current truncates > > > downloads > > > > > > Thanks to eduardo@ for verifying build issues on -CURRENT > > > > > > PR: 294268 > > > Approved by: blanket, just fix it > > > --- > > > security/libssh/Makefile | 7 ++++++- > > > 1 file changed, 6 insertions(+), 1 deletion(-) > > > > > > diff --git a/security/libssh/Makefile b/security/libssh/Makefile > > > index cbec0cfe7b55..10ebb693d642 100644 > > > --- a/security/libssh/Makefile > > > +++ b/security/libssh/Makefile > > > @@ -1,7 +1,9 @@ > > > PORTNAME= libssh > > > PORTVERSION= 0.12.0 > > > +PORTREVISION= 1 > > > CATEGORIES= security devel > > > -MASTER_SITES= https://www.libssh.org/files/${PORTVERSION:R}/ > > > +MASTER_SITES= https://www.libssh.org/files/${PORTVERSION:R}/ \ > > > + https://ftp.openbsd.org/pub/OpenBSD/distfiles/ > > > > > > MAINTAINER= sunpoet@FreeBSD.org > > > COMMENT= Library implementing the SSH2 protocol > > > @@ -11,6 +13,9 @@ WWW= https://www.libssh.org/ \ > > > LICENSE= LGPL21 > > > LICENSE_FILE= ${WRKSRC}/COPYING > > > > > > +BROKEN_FreeBSD_15= src/mlkem_crypto.c:31:10: fatal error: 'openssl/ml_kem.h' file not found > > > +BROKEN_FreeBSD_16= src/mlkem_crypto.c:31:10: fatal error: 'openssl/ml_kem.h' file not found > > > + > > > TEST_DEPENDS= cmocka>=0:sysutils/cmocka > > > > > > USES= cmake:testing cpe tar:xz > > > > > > > -- > > Sincerely, > > Dima (fluffy@FreeBSD.org, https://t.me/FluffyBSD, @fluffy:matrix-dev.freebsd.org) > > (desktop, kde, x11, office, ports-secteam)@FreeBSD team > > > > -- > Sincerely, > Dima (fluffy@FreeBSD.org, https://t.me/FluffyBSD, @fluffy:matrix-dev.freebsd.org) > (desktop, kde, x11, office, ports-secteam)@FreeBSD team -- Tomoaki AOKI