#1124050 tillitis-tkey-device-signer: Please upgrade build-dep to llvm/clang 21

#1124050#5
Date:
2025-12-25 23:52:10 UTC
From:
To:
Dear Maintainer,

We would like to remove llvm-toolchain-19 from the archive.
Please update to 21.

Thanks
Sylvestre

#1124050#12
Date:
2025-12-27 23:15:46 UTC
From:
To:
Thanks, I'll have to discuss with upstream about this -- the problem for
these two (closely related) packages is that llvm/clang 21 does not (*)
produce the same code as llvm/clang 19.  For these packages, that
results in users getting a different private key from their Tillitis
hardware device.  This invalidate any public key configurations.  If
they use trixie tkey device signer app and then upgrade to a forky
version (that were built with llvm/clang 21) their private keys will be
different, and they can't (easily) get their old trixie private key,
which pretty much locks them out of everything.

I understand it is unreasonable to keep llvm/clang 19 in Debian for
these two packages, and mitigating this problem has an open upstream
request that I'm hoping will get some action before forky:

https://github.com/tillitis/tkey-ssh-agent/issues/125

Will forky ship with llvm/clang 21?  If we bump the compiler version and
expected hash checksum here, we'd rather not have to do it twice, since
this churn induce a ecosystem (and end-user) cost.  If the code
generated by llvm/clang 21 changes before forky is released, this is
also problematic.  So maybe we can prepare an change in experimental now
(to get a hash checksum for future comparison), and wait until shortly
before the forky freeze to upload it into unstable, hoping the expected
generated code stays the same.  That means dropping it from testing, I
guess, which may be an acceptable price to pay.

More thoughts on this rather odd situation is welcome, I don't care
strongly how we approach this as long as it is done carefully.

/Simon

(*) I did not confirm the produced code is different now, but I assume
it is, since it was when we decided to pin on llvm/clang 19 instead of
latest version, and I would be surprised if a later version of
llvm/clang than what was used back then somehow reverted to produce the
same code as version 19.

Sylvestre Ledru <sylvestre@debian.org> writes:

Sylvestre Ledru <sylvestre@debian.org> writes:

#1124050#19
Date:
2026-07-23 13:58:19 UTC
From:
To:
Hi

I noticed Debian now has clang 22 in testing already.

Is the intention to ship forky with clang 21 or 22?  Or both?

I'm in the process of uploading tillitis-tkey-libs and
tillitis-tkey-device-signer using clang 21, first to experimental to
allow some testing before an unstable upload.  It is problematic to bump
compiler too often as it results in different binaries (and hence
private keys for users) so I'd like to minimize the number of uploads to
sid before forky.

For future reference, if anyone is chasing this: the upstream bug report
has good discussion of compilers and hash values:
https://github.com/tillitis/tkey-device-signer/issues/27

/Simon

Simon Josefsson <simon@josefsson.org> writes:

#1124050#24
Date:
2026-07-23 16:55:33 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
tillitis-tkey-device-signer, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1124050@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon Josefsson <simon@josefsson.org> (supplier of updated tillitis-tkey-device-signer package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 23 Jul 2026 15:22:55 +0200
Source: tillitis-tkey-device-signer
Architecture: source
Version: 1.0.2-3~exp0
Distribution: experimental
Urgency: medium
Maintainer: Debian Security Tools <team+pkg-security@tracker.debian.org>
Changed-By: Simon Josefsson <simon@josefsson.org>
Closes: 1124050
Changes:
 tillitis-tkey-device-signer (1.0.2-3~exp0) experimental; urgency=medium
 .
   * Standards-Version: 4.7.4
   * Drop Priority: optional
   * Drop Rules-Requires-Root: no
   * Modernize Salsa CI
   * Use gbp debian-branch experimental
   * Use llvm/clang 21 (Closes: #1124050)
   * Bump to clang-21 tkey-libs
   * Update expected firmware hash
   * Use compat 14
   * Use watch v5
   * Bump debian/* copyright years
Checksums-Sha1:
 5aac4eaf1b46bacc14be641bbdc047c8388b6ce4 2524 tillitis-tkey-device-signer_1.0.2-3~exp0.dsc
 90a73b0b3669c1837cad29875f3fb6b6eb9e5f3c 3724 tillitis-tkey-device-signer_1.0.2-3~exp0.debian.tar.xz
 adb5f0a1cfde76fd376c5e65ab6990caece70889 28564 tillitis-tkey-device-signer_1.0.2-3~exp0.git.tar.xz
 f23ae21baa42ecc0b9865a64e2d5f3ea5c627fbb 17646 tillitis-tkey-device-signer_1.0.2-3~exp0_source.buildinfo
Checksums-Sha256:
 c3421c0908e511901a87e29b34043ecef5124173ae37b374fb83ab6211056f54 2524 tillitis-tkey-device-signer_1.0.2-3~exp0.dsc
 3815e6a5af3abadfc1e9f1b57066b4094810eba6550f059b65bc38a9a70bc78d 3724 tillitis-tkey-device-signer_1.0.2-3~exp0.debian.tar.xz
 41e013d817b1502c64dc047ae79fbcab7bd3fc3b6fcf45b475588a5ad15c59ee 28564 tillitis-tkey-device-signer_1.0.2-3~exp0.git.tar.xz
 271daece60377d4e36c14c4250b09026448a9792038bbb68e7aee651970e5aa9 17646 tillitis-tkey-device-signer_1.0.2-3~exp0_source.buildinfo
Files:
 32bb6f88bc6bde07ab701f48fb8bd511 2524 libs optional tillitis-tkey-device-signer_1.0.2-3~exp0.dsc
 32686881d734ff73666973c448e6b699 3724 libs optional tillitis-tkey-device-signer_1.0.2-3~exp0.debian.tar.xz
 04a8e10424c15313ab6a5c7b56d509f7 28564 libs None tillitis-tkey-device-signer_1.0.2-3~exp0.git.tar.xz
 3a7f75a58b23a46ac720c336e1269952 17646 libs optional tillitis-tkey-device-signer_1.0.2-3~exp0_source.buildinfo
Git-Tag-Info: tag=e838c99ccb3a0b8a59a92eb387f33ffcd9bf3450 fp=a3cc9c870b9d310abad4cf2f51722b08fe4745a2
Git-Tag-Tagger: Simon Josefsson <simon@josefsson.org>
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmpiNjMACgkQYG0ITkaD
wHlf+hAAiAwCErd2theUqdLcV/OBeySVESKX6flSkYVMmAcAHlApG1hBDz66IIm+
afvARawl7PsJ2O5Rg6T/wNUKQePeB5bOmislvlh+CYeNw3uXDRPg/dgDhU5NRFf0
cqCZoIKPyTJDuy/6n/OGT3U1dEW5kwwwA6hLWQ9uwbMBsSLqYytO3+Fg9w5jqDX5
+6TD3OeyyErtg+tqC/VlTTzdtrgwGUc2hut+9/7lJthGIAcJsVBMnJrYtDlJHF4W
qqdXR2YRECCezoi2MRTlVuQf3gmD9wl+DTjuG/ZisaDxGIL3ko+3ttNFm6+i5XuR
xMdsNqIgRss+NZ/z6qJrM+JxNJNeTzEku5EKZrmSjg7+UElEklcd8TbDscyHUIlx
BjKlgYwOCPVuoyC+VuBQSUa0bCa6fR2BNRZ0c//pUodnF71C7Adi0EX2RtaoJNbp
5C82zo9OkqLdb9sO2Ez6nh444ZwvIv+MyXBfBHPbgApqcqlxbrjZFg+b9Jn9a/kJ
sGCApLQCyqUUGOcScWedOD1ar9Z78P8Ntlt6eyBwdvlmoDD0bnQmmnFmphN0eOwv
BcWzbQbC2JZccIKo8WMYx4UNbK4o7iHxg+11rlTvc92ruHvlDFlOfXWNVtHaCMA1
yFssYt7E0zvJ744HYU96/v3+9FBSUNPC4WhhgLWC4aKoSuyVeyc=
=/QU/
-----END PGP SIGNATURE-----