Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[mbedtls] update to 3.2.1 #25703

Closed
xavier2k6 opened this issue Jul 11, 2022 · 8 comments · Fixed by #40687
Closed

[mbedtls] update to 3.2.1 #25703

xavier2k6 opened this issue Jul 11, 2022 · 8 comments · Fixed by #40687
Assignees
Labels
category:port-update The issue is with a library, which is requesting update new revision

Comments

@xavier2k6
Copy link
Contributor

xavier2k6 commented Jul 11, 2022

Library name: mbedtls

New version number: 3.2.1

Other information that may be useful (release notes, etc...)
https://github.com/Mbed-TLS/mbedtls/releases
https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/advisories/mbedtls-security-advisory-2022-07.md

@JonLiu1993 JonLiu1993 added the category:port-update The issue is with a library, which is requesting update new revision label Jul 12, 2022
@xavier2k6 xavier2k6 changed the title [mbedtls] update to 3.2.0 [mbedtls] update to 3.2.1 Jul 13, 2022
@ekilmer
Copy link
Contributor

ekilmer commented Jul 20, 2022

This has been attempted in the past #20860 and I'm also trying to update it for a new port #22957 but found that there are ports that are not compatible with the new v3 changes and so it won't be accepted until all ports are compatible with v3.

Mbed-TLS also has a v2.28 LTS branch, which means the dependent ports likely won't upgrade until v2 is retired. You can read more about Mbed-TLS releases here https://github.com/Mbed-TLS/mbedtls/blob/development/BRANCHES.md#maintained-branches

Copy link

This is an automated message. Per our repo policy, stale issues get closed if there has been no activity in the past 180 days. The issue will be automatically closed in 14 days. If you wish to keep this issue open, please add a new comment.

@EvanBalster
Copy link

It would be useful if there were an mbedtls3 feature or a separate package that could be installed. For the moment I'm having to clone, build and install the library by hand for my applications to avoid a lot of trouble related to version 2's lack of a CMake install configuration.

Copy link

This is an automated message. Per our repo policy, stale issues get closed if there has been no activity in the past 180 days. The issue will be automatically closed in 14 days. If you wish to keep this issue open, please add a new comment.

@github-actions github-actions bot added the Stale label Aug 14, 2024
@github-actions github-actions bot closed this as not planned Won't fix, can't repro, duplicate, stale Aug 28, 2024
@JonLiu1993 JonLiu1993 reopened this Aug 28, 2024
@JonLiu1993
Copy link
Member

Currently, the mbedtls update in vcpkg continues the mbedtls-2.28 branch. The update required by the issue needs to switch to the mbedtls-3.6 branch. However, some ports that depend on mbedtls are not compatible with the mbedtls-3.6 branch, so it is temporarily impossible to update to the mbedtls-3.6 branch, so this issue is temporarily closed.

@JonLiu1993 JonLiu1993 closed this as not planned Won't fix, can't repro, duplicate, stale Aug 28, 2024
@dg0yt
Copy link
Contributor

dg0yt commented Aug 28, 2024

@JonLiu1993 I really cannot understand the priorities and procedures of your crew. In particular when it comes to software which fundamental to security.

There are exactly two blocking ports, according to #40011 results: openvpn3 and oatpp-mbedtls.

So there is no acceptable reason to delay the update of mbedts.

@JonLiu1993 JonLiu1993 reopened this Aug 28, 2024
@JonLiu1993
Copy link
Member

@JonLiu1993 I really cannot understand the priorities and procedures of your crew. In particular when it comes to software which fundamental to security.

There are exactly two blocking ports, according to #40011 results: openvpn3 and oatpp-mbedtls.

So there is no acceptable reason to delay the update of mbedts.

Sorry I didn't notice your PR and @talregev's, because I tried to update this port several times, but failed, and now it is always updated on mbedtls_2.8 branch so I closed it. I reopened it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
category:port-update The issue is with a library, which is requesting update new revision
Projects
None yet
7 participants
@ekilmer @EvanBalster @dg0yt @xavier2k6 @JackBoosY @JonLiu1993 and others