From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4gLGT23VVmz2xxR for ; Wed, 20 May 2026 15:59:50 +0000 (UTC) Received: from mail01.ipfire.org (mail01.haj.ipfire.org [IPv6:2001:678:b28::25]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "R12" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4gLGSz0srdz2xLm for ; Wed, 20 May 2026 15:59:47 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4gLGSy3Bt9zV2; Wed, 20 May 2026 15:59:46 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1779292786; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=aErgnyMYEXarVAKUWxOxn6Pny9kanwvso/hdx+2EMjg=; b=eW0NgcEQIiGyw/daeZ9c18uPVWJgDw8jJ/U5p7fBEUJJ91MJgXwnQ+IE4OaCWohS4Shl92 uA5iC6RL0/NhSRCw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1779292786; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=aErgnyMYEXarVAKUWxOxn6Pny9kanwvso/hdx+2EMjg=; b=sIqyJfqD/Hm5CvxTDJwxw/B4Rs2duyWrmirCUrfTT/KG1DgB0W2/tuy7zabubdQILi4zFp QBlWDR/Z1Rhyjwkf4x2LAut4h1u/LwKua8gQJtxrwpWbmrN7HjgKkWNOg/fM5lb3rCPaIR bQXHmixwqKYLvHURPmQDAZ5y9eylZI0Iot2xTc8jgFO2veX7ABjA3X2sEh/gSVRRCXtHkN t385ZpVhdvq0DkD20IEJJk9un/yeyZ0O1/Q/dN9JeG+WYaBYcTah/u0JYxPqYB8PlSOy9a IYOPVeFXW4F9oEARag1tYvmLncOKmJDIZRmWfWekCPf7VSfuyewwKLK6O+J/Pw== Content-Type: text/plain; charset=utf-8 Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: Mime-Version: 1.0 Subject: Re: Problem with update of nettle to 4.0 From: Michael Tremer In-Reply-To: Date: Wed, 20 May 2026 16:59:45 +0100 Cc: "IPFire: Development-List" Content-Transfer-Encoding: quoted-printable Message-Id: <4B486B30-59F4-4879-A529-5B2605AC01C4@ipfire.org> References: <6AE8ADFC-BBFE-485D-A646-7C9705C0782C@ipfire.org> To: Adolf Belka Hello Adolf, > On 20 May 2026, at 16:57, Adolf Belka wrote: >=20 > Hi Michael, >=20 > On 20/05/2026 17:32, Michael Tremer wrote: >> Hello Adolf, >> Thanks for looking into this. >> I wasn=E2=80=99t quite aware how outdated we are on squid, so let=E2=80= =99s change that. >=20 > I think Matthias looked at updating squid from the 6.x to 7.x branch = but felt uncomfortable with how to deal with some of the changes in that = new branch. >=20 > Maybe we can both have a try and see what happens. Check if we can we = make it work as expected. I will look back at the previous email chain = on the discussion on moving to squid-7.x Yes, please. If there is a number of items that need work in our = scripting, tooling or UI, please create an umbrella ticket and create = tickets for individual tasks so that we can assign them and share the = load amongst several shoulders. >> I checked the code and there are exactly two places where nettle is = being used: >> * The base64 encoder/decoder >> = https://git.ipfire.org/?p=3Dthirdparty/squid.git;a=3Dblob;f=3Dinclude/base= 64.h;hb=3D5c1d937d2068e4861f206884cebb02d2958d3563#l13 >> * Some code to compute MD5 checksums >> = https://git.ipfire.org/?p=3Dthirdparty/squid.git;a=3Dblob;f=3Dinclude/md5.= h;hb=3D5c1d937d2068e4861f206884cebb02d2958d3563#l13 >=20 > This was the bit where the build failed as it could not find = MD5_DIGEST_SIZE. It could be that the base64 encoder/decoder might have = been next in line. >=20 >> Both have an alternative implementation, so it is absolutely safe for = us to build squid with --without-nettle. That way we won=E2=80=99t be = held back until they have agreed on a unified API. >> > Let me know if this helps. >=20 > I will try it and see. Everything before the squid build had no = problems with nettle-4.0, I just need to see if there is anything still = to come in the build tree. I will look at it when/if it comes. >=20 > Regards, >=20 > Adolf. >=20 >> All the best, >> -Michael >>> On 20 May 2026, at 13:47, Adolf Belka = wrote: >>>=20 >>> Hi all, >>>=20 >>> For information. >>>=20 >>> A new nettle version has come out. Our old version was 3.10.2 and = the new one is 4.0 >>>=20 >>> Unfortunately nettle-4.0 has a new API/ABI and several packages that = use nettle have found that it won't build for them. >>>=20 >>> Many of those packages have already issued updated versions that now = work with nettle-4.0 >>>=20 >>> That is not the case with squid. Here we have a greater problem. >>>=20 >>> Currently we are on squid-6.14 and the current release is squid-7.5. = squid-6.14 fails to build with nettle-4.0 as there are changes in = various variables/parameters. >>>=20 >>> squid-7.5 does not yet have any fix for the nettle API/ABI changes. = I did find some discussion on it in the Pull Requests section but there = seems to be some disagreement between various of the squid contributors = which seems to be blocking anything being accepted. It is also not clear = if that pull request would fix the error that I found in my build with = squid-6.14 >>>=20 >>> squid has not been updated to the 7.x branch in IPFire because there = were a lot of significant changes in it which would require some = re-write of our web proxy code. >>>=20 >>> It is probably worth noting that squid-6.14 stopped getting any = security support in July 2025. >>>=20 >>> There also seems to be questions about squid-8.x and if it will have = even more major changes to options. >>>=20 >>> squid typically is having a two year cycle on their major branch = changes and so the expectation is that squid-7.x will go EOL somewhere = around July 2027 with squid-8.x having beta status in Feb 2027 and = stable declaration in July 2027 when 7.x is EOL'd >>>=20 >>> I will try and see if any other packages we run have any linkage to = nettle. >>>=20 >>> Regards, >>>=20 >>> Adolf. >>>=20 >=20 >=20