Debian Patches

Status for openssl/3.2.1-3

Patch Description Author Forwarded Bugs Origin Last update
debian-targets.patch debian-targets Debian OpenSSL Team <pkg-openssl-devel@lists.alioth.debian.org> no 2017-11-05
man-section.patch man-section Debian OpenSSL Team <pkg-openssl-devel@lists.alioth.debian.org> no 2017-11-05
no-symbolic.patch no-symbolic Debian OpenSSL Team <pkg-openssl-devel@lists.alioth.debian.org> no 2017-11-05
pic.patch pic Debian OpenSSL Team <pkg-openssl-devel@lists.alioth.debian.org> no 2017-11-05
c_rehash-compat.patch also create old hash for compatibility Ludwig Nussel <ludwig.nussel@suse.de> no 2010-04-21
Always-call-OPENSSL_cleanup-prior-to-exit.patch Always call OPENSSL_cleanup prior to exit
If an engine is loaded during the course of operations, and if that
engine is written in C++, the data in that library will be deleted using
an atexit handler prior to the execution of openssl's atexit handler,
causing memory corruption/segfaults/unpredictable behavior. The only
way to avoid that is to release any reference we have to that data prior
to exit, which means calling OPENSSL_cleanup prior to exit. This patch
enforces that behavior for all openssl utilities

Fixes #22508
Neil Horman <nhorman@openssl.org> no 2023-10-27
Update-to-upstream-HEAD.patch Update to upstream HEAD
As of commit 226cadf9f4b2b ("chachap10-ppc.pl: Fix truncated relocation").
Sebastian Andrzej Siewior <sebastian@breakpoint.cc> no 2024-02-22
Configure-allow-to-enable-ktls-if-target-does-not-start-w.patch Configure: allow to enable ktls if target does not start with Linux
The Debian build system uses a `debian' target which sets CFLAGS and
then we have for instance debian-amd64 which inherits from
linux-x86_64 and debian. So far so good.

Since the target name does not start with `linux', the build system does not
enable ktls. So in order to get enabled, I
added a
`enable => [ "ktls" ],'
to the generic linux config which sets it explicit). Having this set, we can
check for it instead matching the target name.

This commit is based on changes for afalgeng in commit
9e381e8a01859 ("Configure: allow to enable afalgeng if target does not start with Linux")
Sebastian Andrzej Siewior <sebastian@breakpoint.cc> no 2021-04-01
Remove-the-provider-section.patch Remove the provider section.
The provider section breaks libssl1.1 users. Remove it for now.
Sebastian Andrzej Siewior <sebastian@breakpoint.cc> no 2022-06-08
conf-Serialize-allocation-free-of-ssl_names.patch conf: Serialize allocation/free of ssl_names.
The access to `ssl_names' is not fully serialized. With multiple threads
it is possible that more than one thread starts to clean up `ssl_names'.
This leads to occasional segfaults if more than one terminates and
performs the clean up.
Sebastian Andrzej Siewior <sebastian@breakpoint.cc> no 2022-09-19

All known versions for source package 'openssl'

Links