Bug#1130568: non-source generated code in OpenSSH should be rebuilt from source

Simon Josefsson <[email protected]> Fri, 13 Mar 2026 08:39:29 +0100
Newsgroups gmane.linux.debian.devel.ssh
Message-ID <87a4wc18lq.fsf__40093.6631065392$1773387713$gmane$org@josefsson.org>
Package: openssh
Version: 1:10.2p1-5

Hi!

The Debian OpenSSH package contains the following files which are
generated from external sources, and are not re-built during build:

https://sources.debian.org/src/openssh/1%3A10.2p1-5/ed25519.c
https://sources.debian.org/src/openssh/1%3A10.2p1-5/libcrux_mlkem768_sha3.h
https://sources.debian.org/src/openssh/1%3A10.2p1-5/sntrup761.c

The process to re-generate the files are detailed by upstream in:

https://sources.debian.org/src/openssh/1%3A10.2p1-5/ed25519.sh
https://sources.debian.org/src/openssh/1%3A10.2p1-5/mlkem768.sh
https://sources.debian.org/src/openssh/1%3A10.2p1-5/sntrup761.sh

These scripts are well-written and I have confirmed that they work, but
they require some external source code files that somehow would have to
be included in Debian.

It would be nice if we only rely on generated files after rebuilding
them from the actual real source code.

I suppose upstream OpenSSH will react on security vulnerabilities in
these generated files, but if someone release a fix for some
vulnerability in any of the upstream source code (or the tools used to
generate the files), we could issue a security fix more quickly.

/Simon
signature.asc (application/pgp-signature, 1.2 KB)
-----BEGIN PGP SIGNATURE-----

iQNoBAEWCgMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmmzvzEUHHNpbW9uQGpv
c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f
V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z
ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh
BLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XQkBQkNZGbwAAoJENc89jjFPAa+BtIA
/iR73CfBurG9y8pASh3cbGOMHpDZfMAtosu6jbpO69GHAP4p7l57d+iVty2VQMsx
+3TCSAvZkpr4P/FuTzZ8JZe8BrgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx
I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0
+MTXPPY4xTwGvgUCZ9F0SgUJDWRmSQCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R
cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE
8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J
ENc89jjFPAa+wUUBAO64fbZek6FPlRK0DrlWsrjCXuLi6PUxyzCAY6lG2nhUAQC6
qobB9mkZlZ0qihy1x4JRtflqFcqqT9n7iUZkCDIiDbg4BFySz2oSCisGAQQBl1UB
BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA
JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XTSBQkNZGboAAoJENc89jjF
PAa+0M0BAPPRq73kLnHYNDMniVBOzUdi2XeF32idjEWWfjvyIJUOAP4wZ+ALxIeh
is3Uw2BzGZE6ttXQ2Q+DeCJO3TPpIqaXDAAKCRBRcisI/kdFokY2AP9TyVOYY8Bw
xhmrpatUVUAv2rzc7Qq1ou1K8D5EBve6HQD/QLFlM/pcX1kG3TzGFmqVatm0Sook
xvKZJPqIPecR8QM=
=xh0S
-----END PGP SIGNATURE-----