- Package:
- src:tillitis-tkey-device-signer
- Source:
- src:tillitis-tkey-device-signer
- Submitter:
- Sylvestre Ledru
- Date:
- 2026-07-23 17:35:06 UTC
- Severity:
- normal
- Tags:
Dear Maintainer, We would like to remove llvm-toolchain-19 from the archive. Please update to 21. Thanks Sylvestre
Thanks, I'll have to discuss with upstream about this -- the problem for these two (closely related) packages is that llvm/clang 21 does not (*) produce the same code as llvm/clang 19. For these packages, that results in users getting a different private key from their Tillitis hardware device. This invalidate any public key configurations. If they use trixie tkey device signer app and then upgrade to a forky version (that were built with llvm/clang 21) their private keys will be different, and they can't (easily) get their old trixie private key, which pretty much locks them out of everything. I understand it is unreasonable to keep llvm/clang 19 in Debian for these two packages, and mitigating this problem has an open upstream request that I'm hoping will get some action before forky: https://github.com/tillitis/tkey-ssh-agent/issues/125 Will forky ship with llvm/clang 21? If we bump the compiler version and expected hash checksum here, we'd rather not have to do it twice, since this churn induce a ecosystem (and end-user) cost. If the code generated by llvm/clang 21 changes before forky is released, this is also problematic. So maybe we can prepare an change in experimental now (to get a hash checksum for future comparison), and wait until shortly before the forky freeze to upload it into unstable, hoping the expected generated code stays the same. That means dropping it from testing, I guess, which may be an acceptable price to pay. More thoughts on this rather odd situation is welcome, I don't care strongly how we approach this as long as it is done carefully. /Simon (*) I did not confirm the produced code is different now, but I assume it is, since it was when we decided to pin on llvm/clang 19 instead of latest version, and I would be surprised if a later version of llvm/clang than what was used back then somehow reverted to produce the same code as version 19. Sylvestre Ledru <sylvestre@debian.org> writes: Sylvestre Ledru <sylvestre@debian.org> writes:
Hi I noticed Debian now has clang 22 in testing already. Is the intention to ship forky with clang 21 or 22? Or both? I'm in the process of uploading tillitis-tkey-libs and tillitis-tkey-device-signer using clang 21, first to experimental to allow some testing before an unstable upload. It is problematic to bump compiler too often as it results in different binaries (and hence private keys for users) so I'd like to minimize the number of uploads to sid before forky. For future reference, if anyone is chasing this: the upstream bug report has good discussion of compilers and hash values: https://github.com/tillitis/tkey-device-signer/issues/27 /Simon Simon Josefsson <simon@josefsson.org> writes:
We believe that the bug you reported is fixed in the latest version of tillitis-tkey-device-signer, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1124050@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Simon Josefsson <simon@josefsson.org> (supplier of updated tillitis-tkey-device-signer package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Thu, 23 Jul 2026 15:22:55 +0200 Source: tillitis-tkey-device-signer Architecture: source Version: 1.0.2-3~exp0 Distribution: experimental Urgency: medium Maintainer: Debian Security Tools <team+pkg-security@tracker.debian.org> Changed-By: Simon Josefsson <simon@josefsson.org> Closes: 1124050 Changes: tillitis-tkey-device-signer (1.0.2-3~exp0) experimental; urgency=medium . * Standards-Version: 4.7.4 * Drop Priority: optional * Drop Rules-Requires-Root: no * Modernize Salsa CI * Use gbp debian-branch experimental * Use llvm/clang 21 (Closes: #1124050) * Bump to clang-21 tkey-libs * Update expected firmware hash * Use compat 14 * Use watch v5 * Bump debian/* copyright years Checksums-Sha1: 5aac4eaf1b46bacc14be641bbdc047c8388b6ce4 2524 tillitis-tkey-device-signer_1.0.2-3~exp0.dsc 90a73b0b3669c1837cad29875f3fb6b6eb9e5f3c 3724 tillitis-tkey-device-signer_1.0.2-3~exp0.debian.tar.xz adb5f0a1cfde76fd376c5e65ab6990caece70889 28564 tillitis-tkey-device-signer_1.0.2-3~exp0.git.tar.xz f23ae21baa42ecc0b9865a64e2d5f3ea5c627fbb 17646 tillitis-tkey-device-signer_1.0.2-3~exp0_source.buildinfo Checksums-Sha256: c3421c0908e511901a87e29b34043ecef5124173ae37b374fb83ab6211056f54 2524 tillitis-tkey-device-signer_1.0.2-3~exp0.dsc 3815e6a5af3abadfc1e9f1b57066b4094810eba6550f059b65bc38a9a70bc78d 3724 tillitis-tkey-device-signer_1.0.2-3~exp0.debian.tar.xz 41e013d817b1502c64dc047ae79fbcab7bd3fc3b6fcf45b475588a5ad15c59ee 28564 tillitis-tkey-device-signer_1.0.2-3~exp0.git.tar.xz 271daece60377d4e36c14c4250b09026448a9792038bbb68e7aee651970e5aa9 17646 tillitis-tkey-device-signer_1.0.2-3~exp0_source.buildinfo Files: 32bb6f88bc6bde07ab701f48fb8bd511 2524 libs optional tillitis-tkey-device-signer_1.0.2-3~exp0.dsc 32686881d734ff73666973c448e6b699 3724 libs optional tillitis-tkey-device-signer_1.0.2-3~exp0.debian.tar.xz 04a8e10424c15313ab6a5c7b56d509f7 28564 libs None tillitis-tkey-device-signer_1.0.2-3~exp0.git.tar.xz 3a7f75a58b23a46ac720c336e1269952 17646 libs optional tillitis-tkey-device-signer_1.0.2-3~exp0_source.buildinfo Git-Tag-Info: tag=e838c99ccb3a0b8a59a92eb387f33ffcd9bf3450 fp=a3cc9c870b9d310abad4cf2f51722b08fe4745a2 Git-Tag-Tagger: Simon Josefsson <simon@josefsson.org> -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmpiNjMACgkQYG0ITkaD wHlf+hAAiAwCErd2theUqdLcV/OBeySVESKX6flSkYVMmAcAHlApG1hBDz66IIm+ afvARawl7PsJ2O5Rg6T/wNUKQePeB5bOmislvlh+CYeNw3uXDRPg/dgDhU5NRFf0 cqCZoIKPyTJDuy/6n/OGT3U1dEW5kwwwA6hLWQ9uwbMBsSLqYytO3+Fg9w5jqDX5 +6TD3OeyyErtg+tqC/VlTTzdtrgwGUc2hut+9/7lJthGIAcJsVBMnJrYtDlJHF4W qqdXR2YRECCezoi2MRTlVuQf3gmD9wl+DTjuG/ZisaDxGIL3ko+3ttNFm6+i5XuR xMdsNqIgRss+NZ/z6qJrM+JxNJNeTzEku5EKZrmSjg7+UElEklcd8TbDscyHUIlx BjKlgYwOCPVuoyC+VuBQSUa0bCa6fR2BNRZ0c//pUodnF71C7Adi0EX2RtaoJNbp 5C82zo9OkqLdb9sO2Ez6nh444ZwvIv+MyXBfBHPbgApqcqlxbrjZFg+b9Jn9a/kJ sGCApLQCyqUUGOcScWedOD1ar9Z78P8Ntlt6eyBwdvlmoDD0bnQmmnFmphN0eOwv BcWzbQbC2JZccIKo8WMYx4UNbK4o7iHxg+11rlTvc92ruHvlDFlOfXWNVtHaCMA1 yFssYt7E0zvJ744HYU96/v3+9FBSUNPC4WhhgLWC4aKoSuyVeyc= =/QU/ -----END PGP SIGNATURE-----