<html aria-label="message body">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="overflow-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;">
Oh sorry, I dunno the etiquette around these things, everything’s perfect now.
<div><br>
</div>
<div>Cheers,</div>
<div><br>
</div>
<div>Camden<br id="lineBreakAtBeginningOfMessage">
<div><br>
<blockquote type="cite">
<div>On Sep 17, 2026, at 11:13 PM, Debian Bug Tracking System <owner@bugs.debian.org> wrote:</div>
<br class="Apple-interchange-newline">
<div>This is an automatic notification regarding your Bug report<br>
which was filed against the nginx-dev package:<br>
<br>
#1147527: nginx-dev: Missing header file in nginx-dev after backport<br>
<br>
It has been closed by Jan Mojžíš <noreply@salsa.debian.org> (reply to 1147527@bugs.debian.org, Jan Mojžíš <janmojzis@debian.org>).<br>
<br>
Their explanation is attached below along with your original report.<br>
If this explanation is unsatisfactory and you have not received a<br>
better one in a separate message then please contact Jan Mojžíš <noreply@salsa.debian.org> (reply to 1147527@bugs.debian.org, Jan Mojžíš <janmojzis@debian.org>) by<br>
replying to this email.<br>
<br>
<br>
-- <br>
1147527: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1147527<br>
Debian Bug Tracking System<br>
Contact owner@bugs.debian.org with problems<br>
<br>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;">
<span style="font-family: -webkit-system-font, Helvetica Neue, Helvetica, sans-serif; color:rgba(127, 127, 127, 1.0);"><b>From:
</b></span><span style="font-family: -webkit-system-font, Helvetica Neue, Helvetica, sans-serif;">Jan Mojžíš <noreply@salsa.debian.org><br>
</span></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;">
<span style="font-family: -webkit-system-font, Helvetica Neue, Helvetica, sans-serif; color:rgba(127, 127, 127, 1.0);"><b>Subject:
</b></span><span style="font-family: -webkit-system-font, Helvetica Neue, Helvetica, sans-serif;"><b>Bug#1147527 fixed in nginx</b><br>
</span></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;">
<span style="font-family: -webkit-system-font, Helvetica Neue, Helvetica, sans-serif; color:rgba(127, 127, 127, 1.0);"><b>Date:
</b></span><span style="font-family: -webkit-system-font, Helvetica Neue, Helvetica, sans-serif;">September 17, 2026 at 11:09:56 PM MDT<br>
</span></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;">
<span style="font-family: -webkit-system-font, Helvetica Neue, Helvetica, sans-serif; color:rgba(127, 127, 127, 1.0);"><b>To:
</b></span><span style="font-family: -webkit-system-font, Helvetica Neue, Helvetica, sans-serif;">1147527-done@bugs.debian.org<br>
</span></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;">
<span style="font-family: -webkit-system-font, Helvetica Neue, Helvetica, sans-serif; color:rgba(127, 127, 127, 1.0);"><b>Reply-To:
</b></span><span style="font-family: -webkit-system-font, Helvetica Neue, Helvetica, sans-serif;">1147527@bugs.debian.org, Jan Mojžíš <janmojzis@debian.org><br>
</span></div>
<br>
<br>
Hello,<br>
<br>
Bug #1147527 in nginx reported by you has been fixed in the Git repository.<br>
You can see the commit message below and you can check the diff of the fix at:<br>
<br>
https://salsa.debian.org/nginx-team/nginx/-/commit/540580b6fe456a2033602e85f2bb631a4bd4f7f2<br>
<br>
------------------------------------------------------------------------<br>
Import Debian changes 1.26.3-3+deb13u9<br>
<br>
nginx (1.26.3-3+deb13u9) trixie-security; urgency=medium<br>
.<br>
* d/p/CVE-2026-42533.patch update: keep private script headers out of<br>
auto/modules' ngx_module_deps so third-party modules can be built<br>
against nginx-dev. (Closes: #1147527)<br>
* d/t/nginx-dev-test.sh add, verify that nginx-dev can build and load<br>
a minimal third-party dynamic HTTP module.<br>
------------------------------------------------------------------------<br>
<br>
(this message was generated automatically)<br>
-- <br>
Greetings<br>
<br>
https://bugs.debian.org/1147527<br>
<br>
<br>
<br>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;">
<span style="font-family: -webkit-system-font, Helvetica Neue, Helvetica, sans-serif; color:rgba(127, 127, 127, 1.0);"><b>From:
</b></span><span style="font-family: -webkit-system-font, Helvetica Neue, Helvetica, sans-serif;">Camden Narzt <camden.narzt@hotmail.com><br>
</span></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;">
<span style="font-family: -webkit-system-font, Helvetica Neue, Helvetica, sans-serif; color:rgba(127, 127, 127, 1.0);"><b>Subject:
</b></span><span style="font-family: -webkit-system-font, Helvetica Neue, Helvetica, sans-serif;"><b>nginx-dev: Missing header file in nginx-dev after backport</b><br>
</span></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;">
<span style="font-family: -webkit-system-font, Helvetica Neue, Helvetica, sans-serif; color:rgba(127, 127, 127, 1.0);"><b>Date:
</b></span><span style="font-family: -webkit-system-font, Helvetica Neue, Helvetica, sans-serif;">September 12, 2026 at 11:26:47 AM MDT<br>
</span></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;">
<span style="font-family: -webkit-system-font, Helvetica Neue, Helvetica, sans-serif; color:rgba(127, 127, 127, 1.0);"><b>To:
</b></span><span style="font-family: -webkit-system-font, Helvetica Neue, Helvetica, sans-serif;">Debian Bug Tracking System <submit@bugs.debian.org><br>
</span></div>
<br>
<br>
Package: nginx-dev<br>
Version: 1.26.3-3+deb13u8<br>
Severity: important<br>
X-Debbugs-Cc: camden.narzt@hotmail.com, team@security.debian.org<br>
<br>
Dear Maintainer,<br>
<br>
* What led up to the situation?<br>
<br>
Debian backported a fix for CVE-2026-42533 and released 1.26.3-3+deb13u8.<br>
<br>
* What exactly did you do (or not do) that was effective (or ineffective)?<br>
<br>
I tried to build my nginx-dynamic-module package against the new nginx-dev package version.<br>
<br>
* What was the outcome of this action?<br>
<br>
Make throws the error: make[2]: *** No rule to make target 'src/http/ngx_http_script.hh', needed by 'objs/addon/nginx_module/ngx_http_passenger_module.o'. Stop.<br>
<br>
* What outcome did you expect instead?<br>
<br>
Make succeeds.<br>
<br>
<br>
* Investigation<br>
# on debian 13:<br>
apt update && apt install -y nginx-dev<br>
# snipped output from apt<br>
dpkg -L nginx-dev | grep -F 'ngx_http_script.hh'<br>
find /usr/share/nginx/src -name 'ngx_http_script.hh' -o -name 'ngx_stream_script.hh'<br>
ls -l /usr/share/nginx/src/src/http/ngx_http_script.hh<br>
ls: cannot access '/usr/share/nginx/src/src/http/ngx_http_script.hh': No such file or directory<br>
<br>
<br>
auto/modules was patched to include src/http/ngx_http_script.hh and that file is added to the source tree: https://mail-archive.com/debian-bugs-dist%40lists.debian.org/msg2120411.html?utm_source=chatgpt.com<br>
<br>
but that file isn't present in the nginx-dev package.<br>
<br>
<br>
<br>
<br>
-- System Information:<br>
Debian Release: 13.6<br>
APT prefers stable-updates<br>
APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable')<br>
Architecture: arm64 (aarch64)<br>
<br>
Kernel: Linux 6.8.0-117-generic (SMP w/2 CPU threads; PREEMPT)<br>
Locale: LANG=C, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE not set<br>
Shell: /bin/sh linked to /usr/bin/dash<br>
Init: unable to detect<br>
<br>
Versions of packages nginx-dev depends on:<br>
ii debhelper [debhelper-compat] 13.24.2<br>
ii libexpat1-dev [libexpat-dev] 2.8.3-1~deb13u1<br>
ii libgd-dev 2.3.3-14~deb13u1<br>
ii libgeoip-dev 1.6.12-11.2~deb13u1<br>
ii libpcre2-dev 10.46-1~deb13u2<br>
ii libperl-dev 5.40.1-6+deb13u1<br>
ii libssl-dev 3.5.7-1~deb13u2<br>
ii libxslt1-dev 1.1.35-1.2+deb13u3<br>
ii nginx [nginx-abi-1.26.3-1] 1.26.3-3+deb13u8<br>
ii po-debconf 1.0.21+nmu1<br>
ii zlib1g-dev 1:1.3.dfsg+really1.3.1-1+b1<br>
<br>
nginx-dev recommends no packages.<br>
<br>
nginx-dev suggests no packages.<br>
<br>
-- no debconf information<br>
<br>
<br>
</div>
</blockquote>
</div>
<br>
</div>
</body>
</html>