diff mbox series

[blacksail,meta-gnome,1/4] apache2: fix build with OpenSSL 4

Message ID 20261010075022.1738748-1-f_l_k@t-online.de
State New
Headers show
Series [blacksail,meta-gnome,1/4] apache2: fix build with OpenSSL 4 | expand

Commit Message

Markus Volk Oct. 10, 2026, 7:50 a.m. UTC
ASN1_STRING is opaque in OpenSSL 4, so mod_md fails to compile in
md_ocsp.c. Backport the httpd 2.4.x commit that switches to the getter
functions. The fix is part of httpd 2.4.69, which master gets through the
upgrade.

Upstream-Status: Backport [https://github.com/apache/httpd/commit/6cd9ea8dcb5bf68a195e90578c7f05e12eba5468]

AI-Generated: Uses Claude Code (Claude Opus 5.5)
Signed-off-by: Markus Volk <f_l_k@t-online.de>
---
 ...mod_md-Add-OpenSSL-4.0-compatibility.patch | 47 +++++++++++++++++++
 .../recipes-httpd/apache2/apache2_2.4.68.bb   |  1 +
 2 files changed, 48 insertions(+)
 create mode 100644 meta-webserver/recipes-httpd/apache2/apache2/0011-mod_md-Add-OpenSSL-4.0-compatibility.patch

Comments

Markus Volk Oct. 10, 2026, 7:52 a.m. UTC | #1
These three GNOME updates need to be reverted in meta-gnome so that 
GNOME can be compiled with oe-core 'blacksail'

On Sat, Oct 10 2026 at 09:50:22 +02:00:00, Markus Volk via 
lists.openembedded.org <f_l_k=t-online.de@lists.openembedded.org> wrote:
> This reverts commit 6f735ce8ac29f1e57dc463bac8c34f3c439a7fb7.
> 
> mutter 51.0 needs gsettings-desktop-schemas >= 51.rc, but oe-core
> blacksail has 50.1. Tested by building gnome-image against oe-core
> blacksail.
> 
> AI-Generated: Uses Claude Code (Claude Opus 5.5)
> ---
>  .../mutter/{mutter_51.0.bb => mutter_50.4.bb}   | 17 
> +++++++++--------
>  1 file changed, 9 insertions(+), 8 deletions(-)
>  rename meta-gnome/recipes-gnome/mutter/{mutter_51.0.bb => 
> mutter_50.4.bb} (85%)
> 
> diff --git a/meta-gnome/recipes-gnome/mutter/mutter_51.0.bb 
> b/meta-gnome/recipes-gnome/mutter/mutter_50.4.bb
> similarity index 85%
> rename from meta-gnome/recipes-gnome/mutter/mutter_51.0.bb
> rename to meta-gnome/recipes-gnome/mutter/mutter_50.4.bb
> index 6604865f67..f9b3e9d5e5 100644
> --- a/meta-gnome/recipes-gnome/mutter/mutter_51.0.bb
> +++ b/meta-gnome/recipes-gnome/mutter/mutter_50.4.bb
> @@ -17,17 +17,12 @@ DEPENDS = " \
>      libdisplay-info \
>      libdrm \
>      libei \
> -    libgudev \
> -    libinput \
> -    libxcvt-native \
>      libxkbcommon \
>      pango \
>      pixman \
>      python3-argcomplete-native \
>      python3-docutils-native \
> -    udev \
>      virtual/egl \
> -    virtual/libgbm \
>      virtual/libgles2 \
>      wayland \
>      wayland-native \
> @@ -37,7 +32,7 @@ DEPENDS = " \
>  inherit gnomebase gsettings gobject-introspection gettext 
> features_check
> 
>  SRC_URI += "file://0001-Dont-use-system-sysprof-dbus-folder.patch" 
> <file://0001-dont-use-system-sysprof-dbus-folder.patch/>
> -SRC_URI[archive.sha256sum] = 
> "5d28f3ae225692428fcafb96500d673f34328b698b86960c9c1460d0b1d983b3"
> +SRC_URI[archive.sha256sum] = 
> "273d33c875abcb4b6cbea3f4ec045d18155fbc510c3521fc7e47926371310988"
> 
>  REQUIRED_DISTRO_FEATURES = "wayland polkit"
>  ANY_OF_DISTRO_FEATURES = "opengl vulkan"
> @@ -45,10 +40,10 @@ ANY_OF_DISTRO_FEATURES = "opengl vulkan"
>  # systemd can be replaced by libelogind (not available atow - make 
> systemd
>  # mandatory distro feature)
>  LOGIND ?= "systemd"
> -DEPENDS += "${LOGIND}"
>  REQUIRED_DISTRO_FEATURES += "systemd"
> 
>  PACKAGECONFIG ??= " \
> +    native-backend \
>      egl \
>      gles2 \
>      ${@bb.utils.contains 
> <mailto:${@bb.utils.contains>('DISTRO_FEATURES', 'x11', 'opengl', '', 
> d)} \
> @@ -56,11 +51,17 @@ PACKAGECONFIG ??= " \
>      bash-completion \
>      gnome-desktop \
>      ${@bb.utils.contains 
> <mailto:${@bb.utils.contains>('DISTRO_FEATURES', 'x11', 'xwayland', 
> '', d)} \
> +    ${@bb.utils.contains 
> <mailto:${@bb.utils.contains>('DISTRO_FEATURES', 'systemd', 'logind 
> udev', '', d)} \
>  "
> 
> +PACKAGECONFIG[native-backend] = "-Dnative_backend=true -Dudev=true, 
> -Dnative_backend=false -Dudev=false, libdrm virtual/libgbm libinput 
> ${LOGIND} virtual/egl virtual/libgles2 udev libxcvt-native"
>  PACKAGECONFIG[opengl] = "-Dopengl=true, -Dopengl=false, 
> virtual/libgl"
>  PACKAGECONFIG[gles2] = "-Dgles2=true, -Dgles2=false, 
> virtual/libgles2"
>  PACKAGECONFIG[egl] = "-Degl=true, -Degl=false, virtual/egl"
> +PACKAGECONFIG[egl-device] = "-Degl_device=true, -Degl_device=false"
> +PACKAGECONFIG[wayland-eglstream] = "-Dwayland_eglstream=true, 
> -Dwayland_eglstream=false, wayland-eglstream-protocols"
> +PACKAGECONFIG[udev] = "-Dudev=true, -Dudev=false, udev"
> +PACKAGECONFIG[logind] = "-Dlogind=true, -Dlogind=false, systemd"
>  PACKAGECONFIG[libwacom] = "-Dlibwacom=true, -Dlibwacom=false, 
> libwacom"
>  PACKAGECONFIG[remote-desktop] = "-Dremote_desktop=true, 
> -Dremote_desktop=false, pipewire"
>  PACKAGECONFIG[gnome-desktop] = "-Dlibgnome_desktop=true, 
> -Dlibgnome_desktop=false, gnome-desktop gnome-settings-daemon"
> @@ -87,7 +88,7 @@ EXTRA_OEMESON += " \
>      -Dverbose=true \
>  "
> 
> -MUTTER_API_NAME = "mutter-${@oe.utils.trim 
> <mailto:mutter-${@oe.utils.trim>_version('${PV}', 1)}"
> +MUTTER_API_NAME = "mutter-18"
> 
>  do_install:prepend() {
>      sed -i -e 's|${B}/||g' ${B}/cogl/cogl/cogl-enum-types.c
> --
> 2.55.0
> 
> 
> -=-=-=-=-=-=-=-=-=-=-=-
> Links: You receive all messages sent to this group.
> View/Reply Online (#130717): 
> <https://lists.openembedded.org/g/openembedded-devel/message/130717>
> Mute This Topic: <https://lists.openembedded.org/mt/121684077/3618223>
> Group Owner: openembedded-devel+owner@lists.openembedded.org 
> <mailto:openembedded-devel+owner@lists.openembedded.org>
> Unsubscribe: 
> <https://lists.openembedded.org/g/openembedded-devel/unsub> 
> [f_l_k@t-online.de <mailto:f_l_k@t-online.de>]
> -=-=-=-=-=-=-=-=-=-=-=-
>
diff mbox series

Patch

diff --git a/meta-webserver/recipes-httpd/apache2/apache2/0011-mod_md-Add-OpenSSL-4.0-compatibility.patch b/meta-webserver/recipes-httpd/apache2/apache2/0011-mod_md-Add-OpenSSL-4.0-compatibility.patch
new file mode 100644
index 0000000000..ee127681ec
--- /dev/null
+++ b/meta-webserver/recipes-httpd/apache2/apache2/0011-mod_md-Add-OpenSSL-4.0-compatibility.patch
@@ -0,0 +1,47 @@ 
+From 6cd9ea8dcb5bf68a195e90578c7f05e12eba5468 Mon Sep 17 00:00:00 2001
+From: Rainer Jung <rjung@apache.org>
+Date: Wed, 17 Jun 2026 09:48:52 +0000
+Subject: [PATCH] mod_md: Add OpenSSL 4.0 compatibility
+
+* Use getters instead of direct member access.
+
+* Struct was made opaque in OpenSSL 4. Getters exist since OpenSSL 1.1.0.
+
+* Keep OpenSSL 1.0.2 compatibility.
+
+Merge from icing/md:
+https://github.com/icing/mod_md/commit/9fd90380db0722f0ccc14ff1c4da0ca21d4da75c
+
+Backport of r1935161 from trunk, [mod_md CTR]
+
+
+Upstream-Status: Backport [https://github.com/apache/httpd/commit/6cd9ea8dcb5bf68a195e90578c7f05e12eba5468]
+---
+diff --git a/modules/md/md_ocsp.c b/modules/md/md_ocsp.c
+index aee799a7b39..2e7f14dff31 100644
+--- a/modules/md/md_ocsp.c
++++ b/modules/md/md_ocsp.c
+@@ -533,13 +533,23 @@ static const char *certid_summary(const OCSP_CERTID *certid, apr_pool_t *p)
+     serial = issuer = key = "???";
+     OCSP_id_get0_info(&aname_hash, &amd_nid, &akey_hash, &aserial, (OCSP_CERTID*)certid);
+     if (aname_hash) {
++#if OPENSSL_VERSION_NUMBER < 0x10100000L
+         data.len = (apr_size_t)aname_hash->length;
+         data.data = (const char*)aname_hash->data;
++#else
++        data.len = (apr_size_t)ASN1_STRING_length(aname_hash);
++        data.data = (const char*)ASN1_STRING_get0_data(aname_hash);
++#endif
+         md_data_to_hex(&issuer, 0, p, &data);
+     }
+     if (akey_hash) {
++#if OPENSSL_VERSION_NUMBER < 0x10100000L
+         data.len = (apr_size_t)akey_hash->length;
+         data.data = (const char*)akey_hash->data;
++#else
++        data.len = (apr_size_t)ASN1_STRING_length(akey_hash);
++        data.data = (const char*)ASN1_STRING_get0_data(akey_hash);
++#endif
+         md_data_to_hex(&key, 0, p, &data);
+     }
+     if (aserial) {
diff --git a/meta-webserver/recipes-httpd/apache2/apache2_2.4.68.bb b/meta-webserver/recipes-httpd/apache2/apache2_2.4.68.bb
index dc8c0df12d..f178007ab7 100644
--- a/meta-webserver/recipes-httpd/apache2/apache2_2.4.68.bb
+++ b/meta-webserver/recipes-httpd/apache2/apache2_2.4.68.bb
@@ -16,6 +16,7 @@  SRC_URI = "${APACHE_MIRROR}/httpd/httpd-${PV}.tar.bz2 \
            file://0008-Fix-perl-install-directory-to-usr-bin.patch \
            file://0009-support-apxs.in-force-destdir-to-be-empty-string.patch \
            file://0001-make_exports.awk-not-expose-the-path.patch \
+           file://0011-mod_md-Add-OpenSSL-4.0-compatibility.patch \
           "
 
 SRC_URI:append:class-target = " \