a8e3f5da86
- use BR2_TOOLCHAIN_HAS_UCONTEXT This is used to set -DOPENSSL_NO_ASYNC if needed. - apply the CFLAGS correctly when compiling with -Os (bugfix). - use -latomic when needed This fixes the build for br-sparc-uclibc-2018.05 - don't use madvise() if no MMU Trying to do so results in undefined reference to madvise() as it is not available on uclibc without MMU. The original openssl code checks if a macro used in the madvise call is defined. The problem comes from the fact that the code in crypto/mem_sec.c also includes a kernel header defining the same macro unconditionally. Thus the check is always true in that case. Upstream: https://github.com/openssl/openssl/pull/8089 - don't compile test/fuzzers These binaries introduced with 1.1.x sometimes do not compile. This is the case with the br-arm-cortex-m4-full toolchain - don't build ocsp daemon if no MMU. Patch from Richard Levitte. - correctly enable cryptodev engine Thanks to Arnout Vandecappelle for spotting this. - remove all parallel build patches (openssl build-system changed) - rebased 0001-Dont-waste-time-building-manpages-if-we-re-not-going.patch to apply to Configurations/unix-Makefile.tmpl (Makefile template) - removed 0002-cryptodev-Fix-issue-with-signature-generation.patch (upstream applied) - rebased 0003-Reproducible-build-do-not-leak-compiler-path.patch to apply to crypto/build.info (Makefile template) - fix musl/uclibc build failure, use '-DOPENSSL_NO_ASYNC' - remove legacy enable-tlsext configure option - remove target/host libdir configure options, fixes openssl.pc installation path, fixes wget compile - change legacy INSTALL_PREFIX to DESTDIR - remove 'libraries gets installed read only, so strip fails' workaround (not needed anymore) - change engine directory from /usr/lib/engines to /usr/lib/engines-1.1 - change license file hash, no license change, only the following hint was removed: Actually both licenses are BSD-style Open Source licenses. In case of any license issues related to OpenSSL please contact openssl-core@openssl.org. Signed-off-by: Peter Seiderer <ps.report@gmx.net> Tested-by: Ryan Coe <bluemrp9@gmail.com> Signed-off-by: Vadim Kochan <vadim4j@gmail.com> Signed-off-by: Patrick Havelange <patrick.havelange@essensium.com> Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
179 lines
4.9 KiB
Makefile
179 lines
4.9 KiB
Makefile
################################################################################
|
||
#
|
||
# libopenssl
|
||
#
|
||
################################################################################
|
||
|
||
LIBOPENSSL_VERSION = 1.1.1a
|
||
LIBOPENSSL_SITE = https://www.openssl.org/source
|
||
LIBOPENSSL_SOURCE = openssl-$(LIBOPENSSL_VERSION).tar.gz
|
||
LIBOPENSSL_LICENSE = OpenSSL or SSLeay
|
||
LIBOPENSSL_LICENSE_FILES = LICENSE
|
||
LIBOPENSSL_INSTALL_STAGING = YES
|
||
LIBOPENSSL_DEPENDENCIES = zlib
|
||
HOST_LIBOPENSSL_DEPENDENCIES = host-zlib
|
||
LIBOPENSSL_TARGET_ARCH = generic32
|
||
LIBOPENSSL_CFLAGS = $(TARGET_CFLAGS)
|
||
LIBOPENSSL_PROVIDES = openssl
|
||
|
||
# relocation truncated to fit: R_68K_GOT16O
|
||
ifeq ($(BR2_m68k_cf),y)
|
||
LIBOPENSSL_CFLAGS += -mxgot
|
||
endif
|
||
|
||
ifeq ($(BR2_USE_MMU),)
|
||
LIBOPENSSL_CFLAGS += -DHAVE_FORK=0 -DOPENSSL_NO_MADVISE
|
||
endif
|
||
|
||
ifeq ($(BR2_PACKAGE_HAS_CRYPTODEV),y)
|
||
LIBOPENSSL_DEPENDENCIES += cryptodev
|
||
endif
|
||
|
||
# fixes the following build failures:
|
||
#
|
||
# - musl
|
||
# ./libcrypto.so: undefined reference to `getcontext'
|
||
# ./libcrypto.so: undefined reference to `setcontext'
|
||
# ./libcrypto.so: undefined reference to `makecontext'
|
||
#
|
||
# - uclibc:
|
||
# crypto/async/arch/../arch/async_posix.h:32:5: error: unknown type name ‘ucontext_t’
|
||
#
|
||
|
||
ifeq ($(BR2_TOOLCHAIN_USES_MUSL),y)
|
||
LIBOPENSSL_CFLAGS += -DOPENSSL_NO_ASYNC
|
||
endif
|
||
ifeq ($(BR2_TOOLCHAIN_HAS_UCONTEXT),)
|
||
LIBOPENSSL_CFLAGS += -DOPENSSL_NO_ASYNC
|
||
endif
|
||
|
||
# Some architectures are optimized in OpenSSL
|
||
# Doesn't work for thumb-only (Cortex-M?)
|
||
ifeq ($(BR2_ARM_CPU_HAS_ARM),y)
|
||
LIBOPENSSL_TARGET_ARCH = armv4
|
||
endif
|
||
ifeq ($(ARCH),aarch64)
|
||
LIBOPENSSL_TARGET_ARCH = aarch64
|
||
endif
|
||
ifeq ($(ARCH),powerpc)
|
||
# 4xx cores seem to have trouble with openssl's ASM optimizations
|
||
ifeq ($(BR2_powerpc_401)$(BR2_powerpc_403)$(BR2_powerpc_405)$(BR2_powerpc_405fp)$(BR2_powerpc_440)$(BR2_powerpc_440fp),)
|
||
LIBOPENSSL_TARGET_ARCH = ppc
|
||
endif
|
||
endif
|
||
ifeq ($(ARCH),powerpc64)
|
||
LIBOPENSSL_TARGET_ARCH = ppc64
|
||
endif
|
||
ifeq ($(ARCH),powerpc64le)
|
||
LIBOPENSSL_TARGET_ARCH = ppc64le
|
||
endif
|
||
ifeq ($(ARCH),x86_64)
|
||
LIBOPENSSL_TARGET_ARCH = x86_64
|
||
endif
|
||
|
||
define HOST_LIBOPENSSL_CONFIGURE_CMDS
|
||
(cd $(@D); \
|
||
$(HOST_CONFIGURE_OPTS) \
|
||
./config \
|
||
--prefix=$(HOST_DIR) \
|
||
--openssldir=$(HOST_DIR)/etc/ssl \
|
||
no-tests \
|
||
no-fuzz-libfuzzer \
|
||
no-fuzz-afl \
|
||
shared \
|
||
zlib-dynamic \
|
||
)
|
||
$(SED) "s#-O[0-9s]#$(HOST_CFLAGS)#" $(@D)/Makefile
|
||
endef
|
||
|
||
define LIBOPENSSL_CONFIGURE_CMDS
|
||
(cd $(@D); \
|
||
$(TARGET_CONFIGURE_ARGS) \
|
||
$(TARGET_CONFIGURE_OPTS) \
|
||
./Configure \
|
||
linux-$(LIBOPENSSL_TARGET_ARCH) \
|
||
--prefix=/usr \
|
||
--openssldir=/etc/ssl \
|
||
$(if $(BR2_TOOLCHAIN_HAS_LIBATOMIC),-latomic) \
|
||
$(if $(BR2_TOOLCHAIN_HAS_THREADS),threads,no-threads) \
|
||
$(if $(BR2_STATIC_LIBS),no-shared,shared) \
|
||
$(if $(BR2_PACKAGE_HAS_CRYPTODEV),enable-devcryptoeng) \
|
||
no-rc5 \
|
||
enable-camellia \
|
||
enable-mdc2 \
|
||
no-tests \
|
||
no-fuzz-libfuzzer \
|
||
no-fuzz-afl \
|
||
$(if $(BR2_STATIC_LIBS),zlib,zlib-dynamic) \
|
||
$(if $(BR2_STATIC_LIBS),no-dso) \
|
||
)
|
||
$(SED) "s#-march=[-a-z0-9] ##" -e "s#-mcpu=[-a-z0-9] ##g" $(@D)/Makefile
|
||
$(SED) "s#-O[0-9s]#$(LIBOPENSSL_CFLAGS)#" $(@D)/Makefile
|
||
$(SED) "s# build_tests##" $(@D)/Makefile
|
||
endef
|
||
|
||
# libdl is not available in a static build, and this is not implied by no-dso
|
||
ifeq ($(BR2_STATIC_LIBS),y)
|
||
define LIBOPENSSL_FIXUP_STATIC_MAKEFILE
|
||
$(SED) 's#-ldl##g' $(@D)/Makefile
|
||
endef
|
||
LIBOPENSSL_POST_CONFIGURE_HOOKS += LIBOPENSSL_FIXUP_STATIC_MAKEFILE
|
||
endif
|
||
|
||
define HOST_LIBOPENSSL_BUILD_CMDS
|
||
$(HOST_MAKE_ENV) $(MAKE) -C $(@D)
|
||
endef
|
||
|
||
define LIBOPENSSL_BUILD_CMDS
|
||
$(TARGET_MAKE_ENV) $(MAKE) -C $(@D)
|
||
endef
|
||
|
||
define LIBOPENSSL_INSTALL_STAGING_CMDS
|
||
$(TARGET_MAKE_ENV) $(MAKE) -C $(@D) DESTDIR=$(STAGING_DIR) install
|
||
endef
|
||
|
||
define HOST_LIBOPENSSL_INSTALL_CMDS
|
||
$(HOST_MAKE_ENV) $(MAKE) -C $(@D) install
|
||
endef
|
||
|
||
define LIBOPENSSL_INSTALL_TARGET_CMDS
|
||
$(TARGET_MAKE_ENV) $(MAKE) -C $(@D) DESTDIR=$(TARGET_DIR) install
|
||
rm -rf $(TARGET_DIR)/usr/lib/ssl
|
||
rm -f $(TARGET_DIR)/usr/bin/c_rehash
|
||
endef
|
||
|
||
# libdl has no business in a static build
|
||
ifeq ($(BR2_STATIC_LIBS),y)
|
||
define LIBOPENSSL_FIXUP_STATIC_PKGCONFIG
|
||
$(SED) 's#-ldl##' $(STAGING_DIR)/usr/lib/pkgconfig/libcrypto.pc
|
||
$(SED) 's#-ldl##' $(STAGING_DIR)/usr/lib/pkgconfig/libssl.pc
|
||
$(SED) 's#-ldl##' $(STAGING_DIR)/usr/lib/pkgconfig/openssl.pc
|
||
endef
|
||
LIBOPENSSL_POST_INSTALL_STAGING_HOOKS += LIBOPENSSL_FIXUP_STATIC_PKGCONFIG
|
||
endif
|
||
|
||
ifeq ($(BR2_PACKAGE_PERL),)
|
||
define LIBOPENSSL_REMOVE_PERL_SCRIPTS
|
||
$(RM) -f $(TARGET_DIR)/etc/ssl/misc/{CA.pl,tsget}
|
||
endef
|
||
LIBOPENSSL_POST_INSTALL_TARGET_HOOKS += LIBOPENSSL_REMOVE_PERL_SCRIPTS
|
||
endif
|
||
|
||
ifeq ($(BR2_PACKAGE_LIBOPENSSL_BIN),)
|
||
define LIBOPENSSL_REMOVE_BIN
|
||
$(RM) -f $(TARGET_DIR)/usr/bin/openssl
|
||
$(RM) -f $(TARGET_DIR)/etc/ssl/misc/{CA.*,c_*}
|
||
endef
|
||
LIBOPENSSL_POST_INSTALL_TARGET_HOOKS += LIBOPENSSL_REMOVE_BIN
|
||
endif
|
||
|
||
ifneq ($(BR2_PACKAGE_LIBOPENSSL_ENGINES),y)
|
||
define LIBOPENSSL_REMOVE_LIBOPENSSL_ENGINES
|
||
rm -rf $(TARGET_DIR)/usr/lib/engines-1.1
|
||
endef
|
||
LIBOPENSSL_POST_INSTALL_TARGET_HOOKS += LIBOPENSSL_REMOVE_LIBOPENSSL_ENGINES
|
||
endif
|
||
|
||
$(eval $(generic-package))
|
||
$(eval $(host-generic-package))
|