Bug 2154347 - Review Request: mbedtls3 - Light-weight cryptographic and SSL/TLS library
Summary: Review Request: mbedtls3 - Light-weight cryptographic and SSL/TLS library
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: Package Review
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Nobody's working on this, feel free to take it
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-12-16 16:08 UTC by Benson Muite
Modified: 2024-02-26 00:45 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Benson Muite 2022-12-16 16:08:43 UTC
spec: https://download.copr.fedorainfracloud.org/results/fed500/mbedtls3/fedora-rawhide-x86_64/05149739-mbedtls3/mbedtls3.spec
srpm: https://download.copr.fedorainfracloud.org/results/fed500/mbedtls3/fedora-rawhide-x86_64/05149739-mbedtls3/mbedtls3-3.3.0-1.fc38.src.rpm

Description: 
Mbed TLS is a light-weight open source cryptographic and SSL/TLS
library written in C. Mbed TLS makes it easy for developers to include
cryptographic and SSL/TLS capabilities in their (embedded)
applications with as little hassle as possible.

Fedora Account System Username: fed500

This package is for version 3 of mbedtls, version 2 is already packaged. They currently conflict, which needs to be resolved

HTML documentation is causing some errors. May remove this.

Comment 1 Neal Gompa 2022-12-17 11:02:27 UTC
Why are we doing this instead of upgrading the main one? Did you try to see if this is necessary?

Comment 2 Benson Muite 2022-12-22 05:33:49 UTC
The two versions seem to be currently maintained and updated:
https://github.com/Mbed-TLS/mbedtls/releases
It is unclear how many packages would break if only version 3 is available.

Comment 4 Neal Gompa 2022-12-22 13:14:17 UTC
Well, we should try in a COPR then, right?

There aren't a lot of packages that link to mbedtls in Fedora:

[root@94bd36f45bc2 /]# dnf repoquery --whatrequires mbedtls --qf "%{SOURCERPM}"
Last metadata expiration check: 0:08:48 ago on Thu Dec 22 13:03:39 2022.
dislocker-0.7.3-8.fc37.src.rpm
dolphin-emu-5.0.16380-7.fc38.src.rpm
freeopcua-0-36.20220717.bd13aee.fc38.src.rpm
gauche-0.9.11-3.fc37.src.rpm
godot-3.4.5-1.fc37.src.rpm
haxe-4.2.5-3.fc37.src.rpm
imhex-1.25.0-1.fc38.src.rpm
julia-1.8.2-2.fc38.src.rpm
lighttpd-1.4.67-1.fc38.src.rpm
mbedtls-2.28.1-1.fc38.src.rpm
nekovm-2.3.0-10.fc38.src.rpm
openrgb-0.8-2.fc38.src.rpm
retroarch-1.14.0-1.fc38.src.rpm
secvarctl-0.3-4.fc37.src.rpm

Comment 5 Benson Muite 2022-12-22 15:19:41 UTC
Ok. Version 2.28 is an LTS and there are very many breaking changes going to version 3:
https://github.com/Mbed-TLS/mbedtls/blob/development/docs/3.0-migration-guide.md

Comment 6 Package Review 2024-01-27 00:45:23 UTC
This is an automatic check from review-stats script.

This review request ticket hasn't been updated for some time, but it seems
that the review is still being working out by you. If this is right, please
respond to this comment clearing the NEEDINFO flag and try to reach out the
submitter to proceed with the review.

If you're not interested in reviewing this ticket anymore, please clear the
fedora-review flag and reset the assignee, so that a new reviewer can take
this ticket.

Without any reply, this request will shortly be resetted.

Comment 7 Package Review 2024-02-26 00:45:29 UTC
This is an automatic action taken by review-stats script.

The ticket reviewer failed to clear the NEEDINFO flag in a month.
As per https://fedoraproject.org/wiki/Policy_for_stalled_package_reviews
we reset the status and the assignee of this ticket.


Note You need to log in before you can comment on or make changes to this bug.