[From nobody Mon Aug 31 21:39:08 2026
Received: (at submit) by bugs.debian.org; 29 Sep 2020 14:08:21 +0000
X-Spam-Checker-Version: SpamAssassin 3.4.2-bugs.debian.org_2005_01_02
 (2018-09-13) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-11.7 required=4.0 tests=BAYES_00,SPF_HELO_NONE,
 SPF_NONE,TXREP,X_DEBBUGS_CC autolearn=ham autolearn_force=no
 version=3.4.2-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 9; hammy, 137; neutral, 37; spammy, 0.
 spammytokens: hammytokens:0.000-+--HX-Debbugs-Cc:sk:debian-,
 0.000-+--H*F:U*helmut, 0.000-+--H*F:D*subdivi.de,
 0.000-+--H*RU:sk:helmut@, 0.000-+--H*rp:U*helmut
Return-path: &lt;helmut@subdivi.de&gt;
Received: from isilmar-4.linta.de ([136.243.71.142]:51298)
 by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.92) (envelope-from &lt;helmut@subdivi.de&gt;) id 1kNGIn-00045i-1M
 for submit@bugs.debian.org; Tue, 29 Sep 2020 14:08:21 +0000
Received: from isilmar-4.linta.de (isilmar.linta [10.0.0.1])
 by isilmar-4.linta.de (Postfix) with ESMTP id 1183E200ED2
 for &lt;submit@bugs.debian.org&gt;; Tue, 29 Sep 2020 14:08:16 +0000 (UTC)
Date: Tue, 29 Sep 2020 14:57:48 +0200
From: Helmut Grohne &lt;helmut@subdivi.de&gt;
To: Debian Bug Tracking System &lt;submit@bugs.debian.org&gt;
Subject: mariadb-10.5 should not embed wolfssl
Message-ID: &lt;20200929125748.GA8104@alf.mars&gt;
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
X-Reportbug-Version: 7.7.0
X-Debbugs-Cc: debian-security@lists.debian.org
Delivered-To: submit@bugs.debian.org

Source: mariadb-10.5
Version: 1:10.5.5-1
Tags: security
Severity: serious
Justification: unsupportable by the Debian security team

Hi Otto,

I've hinted that the situation about an embedded ssl library might be
suboptimal earlier. Since then, I've checked (using the buildd logs)
that indeed mariadb does build an embedded copy of wolfssl. I've also
checked with the Debian security team (Moritz Muehlenhoff in
particular). Such an embedding is unsupportable by the security team.
For that reason, I'm filing this as a release critical bug. It expresses
a veto of the security team for including the package in a stable
release as is.

On a technical level, this seems easy to solve. You currently pass
-DWITH_SSL=bundled. The build system supports -DWITH_SSL=system in
principle. What I'm less sure about is whether doing so breaks any
functionality and whether the involved licenses are actually compatible.

I do hope that you can sort this out. Thanks for your hard work in
managing this complex package and otherwise integrating it into Debain.

Helmut
]