From patchwork Sat Aug 22 17:51:55 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 96055 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7621AC5DF97 for ; Sat, 22 Aug 2026 17:52:09 +0000 (UTC) Received: from DB3PR0202CU003.outbound.protection.outlook.com (DB3PR0202CU003.outbound.protection.outlook.com [52.101.84.1]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1192.1787421126431531265 for ; Sat, 22 Aug 2026 10:52:07 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=yMKqeuvr; spf=pass (domain: est.tech, ip: 52.101.84.1, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=msd16nwq8Y48tvmEJE/1IyFGl2qZnc2GUWPNhPHzODjYK8BrXoGI0CQesMQ8r/NPadA4rUYr6wlV94Cbe/0+i8k2GCs7KIB+5f6UJFb3hvHSHpcb5ApoAXfW+QsUu9sq4GyvBZ9rU9pic8JOLfQK7AgEkOiqBoGDTZHft76mkeSuDzyPR5nevUsbZ1dw4dT92LN3TYDgZ+m/NhjH+j9oKxbnZoNBsLH8Oa7v5LuO2bsx6IzYBjtF/9e3WGYqxCJK0vnR3YZXjbr4jy17bT4EjvbtJc46ngcVS8PbyrLyVa5ryWxw7ZdvCE0LsueDmjiwRP2wpVdMXTaHyvPwOnDDTA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=8r/viJchj+gBiw/qkJZgftMO2i2OWyRzuRFxE5OHB6I=; b=f8SGz0X9n2pQ1dp8Lx+rGj9dpIQSXxpBWDPnqhMcbsUMuAdoblZ4EBgtBuZbBoa/QMuxQ8B6g1k/pLL9XGVeZSghF/n8tPZQpTzwAb6yla5Ep9C1DBIg8wbPljoE9A3afmLKs9C+Lb/5jxy6FPxyzzGICRVzivAKpGONljD4uKnIlLx7IuXuYAsDI5jRnQXVEGQohZeSJ8yUzwuoBvm+itGNnKNkjeub4xpyMvXkZdacMY4PCWW0vKGoy5N0ISK/QHmzSaXmHKXPoyCLxLNjqhVuS8gY/V4jsk5x/L+8ipNoI6wtuIcJnu5cPNhFWijM7vy4O4sBXDcGL+9ct8mkhA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=8r/viJchj+gBiw/qkJZgftMO2i2OWyRzuRFxE5OHB6I=; b=yMKqeuvrdR9Q3lNq/WKGqK1O7h+y6mvDSYqgSZVOgF+PvpUZgmZ0/KOu/7k2HfkqssZGyuJqCFaQHoF+p2jUQaoaAfRp+4HLRgs5vaFbvF5i23XUt6f4FfS56WzCiZKxuL5AUDoRHa2U6+n4YiyyVpiGwcm9gx8MYqVIwzz2HGbM5xy3E4A0zQ5khxj+i+XbRb5SbFGaI6ZwyyQg69J3DeO4p7OPmTm7/ukhAiP6VVUwtW6ntF5FpNxYOBRQVp4WT2eoDRNxundmM1JwicvqUhdtfR/wXHtSncOBFn3GgTYH/rPQJbDf1eudtkXyjTsFI8XEV+iIkUYspKyS4HBlCQ== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by AM0P189MB0641.EURP189.PROD.OUTLOOK.COM (2603:10a6:208:1a2::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.5; Sat, 22 Aug 2026 17:52:02 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::7ab2:c6af:6760:5c85]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::7ab2:c6af:6760:5c85%7]) with mapi id 15.21.0360.003; Sat, 22 Aug 2026 17:52:02 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [RFC v4 1/6] openssl: upgrade 3.5.7 -> 4.0.1 Date: Sat, 22 Aug 2026 19:51:55 +0200 Message-ID: <20260822175200.57534-2-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260822175200.57534-1-jaipaul.cheernam@est.tech> References: <20260814051829.35088-1-jaipaul.cheernam@est.tech> <20260822175200.57534-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: LO6P123CA0030.GBRP123.PROD.OUTLOOK.COM (2603:10a6:600:313::10) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|AM0P189MB0641:EE_ X-MS-Office365-Filtering-Correlation-Id: 0570f98c-11ab-4cfc-3ee9-08df00761284 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|10070799003|23010399003|1800799024|376014|366016|29003799003|6133799003|3023799007|56012099006|10067099003|11063799006|4143699003|25016099003|12006099003|17002099007|22082099003|18002099003; X-Microsoft-Antispam-Message-Info: B8oRdPc9sUHWMcKrtNGWZBgjdxFn/L9EEPjeIkpmcpJoEdnlVOpq32JL/r5SyDVSE9mVHX730h2OnTsbcPIrfciCAp8MQKftAapd19w4pSr1HblxpmIx/pCwT+hu6veLhpk0Si/SLVRoCFRRoprRDI6JBbCe7lwWxvRsRhZ9rvuiPEzMhsa9rEPK1YLIa1NFSq3TxvmuDjTEjGKxDR1vvjso3IC+dzo07lSrVKU5KYQodK/AOxr63D9XqRhjn+Oq9n1Crw4oK02nX2dLHrXp410D/DmdJ8tZ+xv2xAk4mhlok79jVINnjd3bs92Kex4KOSIGZYrjvQSDGfaaz7Fc64g+U18VlmqqnjExX09k2X1uDnl6yOAVzl49dcTu3P8eA/tOb3DrsWc/gXOSW7cTF2HNCwxYC7P/yGbWxUjy7nfBIRzME4AOpFbRdNWuwx6Q3ij6HRQ388LWcLvAqrCkm48TqsytIcUP2ygLOL8buXjXJnTtJJ1vkJ1MVT+n7zDYx0iaRXg5ZygFGqwWfB1LnDlD1G630ofc7iEFzN5ZnIaizfiVov1qmvDC77YFQdEML6x8apFbnDntAxNBIhQxijwENcBIiWYF9N4sbtw7UsPNvR9DKEyzXXkFXWf3kyEL X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(10070799003)(23010399003)(1800799024)(376014)(366016)(29003799003)(6133799003)(3023799007)(56012099006)(10067099003)(11063799006)(4143699003)(25016099003)(12006099003)(17002099007)(22082099003)(18002099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 2 X-MS-Exchange-AntiSpam-MessageData-0: ITxyqpdDGnSlfdkjcl2vIK3FEt5oyvoj/2u8d+mwA75KN4Nhq2Eu+6exHvZ+VfjXucBIAn2vzrC7EOcrB5eFsBsfJvTtANtc2UZHTeMn3mBoab2ZfhCm9M3Pb1N5Gz1aYiqmKeIHKezRXrviN3vjhelXyxpgpUfOWJDDzEIdYifKA6NASwO+HrRoZRtkZy8ekMvXulqjhYHX/27o6uzuZaAlnMSTFH8mQ1KUTtFMmiOGeVYpEC1zgBXwGXOxElpxx4yisnWRj7LTM1kXsKHL4j9LwFttRLRSayne+XzF9HPUh2XIn+qnnH0gCRS0hTEdPT3NdGEIJU4ir/5p9fR7trQvUUexVTynUPbqZrA6iOhd2VpjOAKLLKYaXbSUkv7rC8NRA2xwAQyZoNAoKPY9eROEC9AhdfN685BQlPiQKpoC7AJ5f1LkV0vjw9WaUR1h3lNacd16e3Wr204BWPBdetUix5z2Qg5qv5wtb8ograYIbN2ZJvD4TqA7zcv0mx44ag/xP/vRfxL6XRixayONYzi0WtukqxuMyRSiuvlyr0DBO9OeoM5NVNp5jK/+z7oj3Q1r52dhweVTYDX3Jx7uZJA5rKZsRqgOKFvHIiV1DgdOsS4xxh1tL+5gmPtndKhVJLg2Pc39pNQldxovzsLWnVKSvHq4/NCWcJGtmLstGhyV1ebrVxTpvmm0Xy5sgeOktQ1nmTgyLpSiOkiVmzb0Zs96RYr6+CpxcvmKpWfZ8ccsz7jlfFXRow15KUigrQXRzSALR8cweBqZcLCEjcZZnWD/L1RRBibVnKJjcXuqIOvpOy6pO0EgdK+XQFDXUj15Sw8y3NyWaI+GSJJ2Em9fg8auKIWO7iRJaI83WuCkvWpLns2ITolcMmfh4+lCNW2f674Bq7bmC1u/x0l6EIrzvOYKByYHIu4LJdLdgofnHLO113tc2Yjn9OUo6DWzGR6wzRgrwTs1PlvXdp+AhGmnjzLo0uyZUfLzANRheRNVsGCrIGVMyJ+HMCdsTnfFHeqddqXoIsUt+eyL3Gs3dfAa5eMYlfyItxOvSebZDXDj5QPMDOhbAidveabzXDizyj+CM06KeKkBnDVD7pedFl7peL72ACC/zgl44Reh0Y8z8PRIxj4jOkkz2dUEtf4UrQhWYifYxH/53dLlxCDm7QaiW6I5MRFda6mxlxWWXXORJR1iZD4/hLAiRdGivPZPZspKe7+ZdWhTBz4ZGGj9D1zTVslKGuvgu3d6xOX2kB9/AtYmek81NITqSBrW7rQvsGUv23zw2cczradO0POmZ6/bSVsHJ+8WvirtVqDft4Zag1gC8y/erBE8IPk6UCUApRbwF76dMBwpAVW2b823prVfGKnnOle0W2wDiNuUdqM3CoSBXB/DzbgF/D93f4vb3huoHjgll84xTXfYzTB3JxjUmaYMbl0tAhGEi959cRcoyH5i3epc1r5efLEF0v1ncQU9Xo4mMNY/ZXAm9YhkKcvMZBmhhAfL0NUCU3wmQQ0mCNfK0LnswsgEEdIjg2706uqnR90SDta2+GGds30su1113VTzZe4xD3rqDEKVJYj9OWDTYr2CTgyL4WLrBufTOGb9p0Kyt0ER2muRq6t4DjKspAgrOM1dv6qGUB9ST1mluUXyISJifJpiDqY5CUVQBvcAVwRLsHavT+9uG6mUaUDDzb5sHxYm8X6hxrRhC5LBarx29QiNnO9wxAV/mIsJR0LkbGuzDW8Icb2nM2IwHFhemoDjLr0Z1zHa3JqdphkTuHYG6y2bIF9nx3i4D4yTXcZZjsPZEWqO X-MS-Exchange-AntiSpam-MessageData-1: P/xXfjhU3gqVAVI5aC1zFroRwAWTTAVhi3Q= X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 0570f98c-11ab-4cfc-3ee9-08df00761284 X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 22 Aug 2026 17:52:02.7927 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: QUmYdY6gqWx4h5wYulVLKKMAyeC7z39XUA7CDaL0C8AOVEehK9BhpOHNDVl+hSnVGXMzq14KEjvMn69YwlVwKzuo7ZSJsaka2q0Os7HkqkQ= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM0P189MB0641 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 22 Aug 2026 17:52:09 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/243993 Upgrade OpenSSL from 3.5.7 to 4.0.1. This is a major version upgrade. Changelog: https://github.com/openssl/openssl/blob/openssl-4.0.1/CHANGES.md New CVE fixes not already in 3.5.7: * CVE-2026-28386: Fixed OOB read in AES-CFB-128 on x86-64 with AVX-512 * CVE-2026-35188: Fixed double-free when checking OCSP stapled response * CVE-2026-42765: Fixed NULL deref in cert verification with OCSP * CVE-2026-42771: Fixed OOB read in X509_VERIFY_PARAM_set1_email() Major breaking changes in 4.0.0: * Removed support for engines. The ENGINE API is fully removed. * Removed support for SSLv3. SSLv3 has been deprecated since 2015. * Removed support for the SSLv2 Client Hello. * Removed per-version TLS method functions (SSLv3_method(), TLSv1_method(), TLSv1_1_method(), TLSv1_2_method()). * Removed c_rehash script tool. Use 'openssl rehash' instead. * ASN1_STRING has been made opaque. * Numerous API function signatures changed to include const qualifiers. * libcrypto no longer cleans up globally allocated data via atexit(). * Added AKID verification checks when X509_V_FLAG_X509_STRICT is set. * Support of deprecated elliptic curves in TLS disabled at compile-time by default. Recipe changes: * Drop 0001-Added-handshake-history-reporting-when-test-fails.patch (merged upstream via PR #22481). * Refresh remaining patches against the new version. * Remove ENGINE API artifacts: engines package, dasync.so/ossltest.so ptest installation, ENGINESDIR references, OPENSSL_ENGINES wrapper variable, and cryptodev-linux PACKAGECONFIG. Tested: ptest on qemux86-64: Files=362, Tests=4310, Result: PASS Passed: 338, Skipped: 24 (fips, lms, rc5, tfo, compression, sslversions, sslkeylogfile, external tests - all expected) Failed: 0 Signed-off-by: Jaipaul Cheernam --- ...ke-history-reporting-when-test-fails.patch | 366 ------------------ ...1-Configure-do-not-tweak-mips-cflags.patch | 6 +- ...sysroot-and-debug-prefix-map-from-co.patch | 11 +- .../0001-extend-check_cwm-test-timeout.patch | 4 +- .../{openssl_3.5.7.bb => openssl_4.0.1.bb} | 28 +- 5 files changed, 18 insertions(+), 397 deletions(-) delete mode 100644 meta/recipes-connectivity/openssl/openssl/0001-Added-handshake-history-reporting-when-test-fails.patch rename meta/recipes-connectivity/openssl/{openssl_3.5.7.bb => openssl_4.0.1.bb} (87%) diff --git a/meta/recipes-connectivity/openssl/openssl/0001-Added-handshake-history-reporting-when-test-fails.patch b/meta/recipes-connectivity/openssl/openssl/0001-Added-handshake-history-reporting-when-test-fails.patch deleted file mode 100644 index a74c79303f..0000000000 --- a/meta/recipes-connectivity/openssl/openssl/0001-Added-handshake-history-reporting-when-test-fails.patch +++ /dev/null @@ -1,366 +0,0 @@ -From 5ba65051fea0513db0d997f0ab7cafb9826ed74a Mon Sep 17 00:00:00 2001 -From: William Lyu -Date: Fri, 20 Oct 2023 16:22:37 -0400 -Subject: [PATCH] Added handshake history reporting when test fails - -Upstream-Status: Submitted [https://github.com/openssl/openssl/pull/22481] - -Signed-off-by: William Lyu ---- - test/helpers/handshake.c | 136 ++++++++++++++++++++++++++++++--------- - test/helpers/handshake.h | 70 +++++++++++++++++++- - test/ssl_test.c | 44 +++++++++++++ - 3 files changed, 217 insertions(+), 33 deletions(-) - -diff --git a/test/helpers/handshake.c b/test/helpers/handshake.c -index f611b3a..5703b48 100644 ---- a/test/helpers/handshake.c -+++ b/test/helpers/handshake.c -@@ -25,6 +25,102 @@ - #include - #endif - -+/* Shamelessly copied from test/helpers/ssl_test_ctx.c */ -+/* Maps string names to various enumeration type */ -+typedef struct { -+ const char *name; -+ int value; -+} enum_name_map; -+ -+static const enum_name_map connect_phase_names[] = { -+ {"Handshake", HANDSHAKE}, -+ {"RenegAppData", RENEG_APPLICATION_DATA}, -+ {"RenegSetup", RENEG_SETUP}, -+ {"RenegHandshake", RENEG_HANDSHAKE}, -+ {"AppData", APPLICATION_DATA}, -+ {"Shutdown", SHUTDOWN}, -+ {"ConnectionDone", CONNECTION_DONE} -+}; -+ -+static const enum_name_map peer_status_names[] = { -+ {"PeerSuccess", PEER_SUCCESS}, -+ {"PeerRetry", PEER_RETRY}, -+ {"PeerError", PEER_ERROR}, -+ {"PeerWaiting", PEER_WAITING}, -+ {"PeerTestFail", PEER_TEST_FAILURE} -+}; -+ -+static const enum_name_map handshake_status_names[] = { -+ {"HandshakeSuccess", HANDSHAKE_SUCCESS}, -+ {"ClientError", CLIENT_ERROR}, -+ {"ServerError", SERVER_ERROR}, -+ {"InternalError", INTERNAL_ERROR}, -+ {"HandshakeRetry", HANDSHAKE_RETRY} -+}; -+ -+/* Shamelessly copied from test/helpers/ssl_test_ctx.c */ -+static const char *enum_name(const enum_name_map *enums, size_t num_enums, -+ int value) -+{ -+ size_t i; -+ for (i = 0; i < num_enums; i++) { -+ if (enums[i].value == value) { -+ return enums[i].name; -+ } -+ } -+ return "InvalidValue"; -+} -+ -+const char *handshake_connect_phase_name(connect_phase_t phase) -+{ -+ return enum_name(connect_phase_names, OSSL_NELEM(connect_phase_names), -+ (int)phase); -+} -+ -+const char *handshake_status_name(handshake_status_t handshake_status) -+{ -+ return enum_name(handshake_status_names, OSSL_NELEM(handshake_status_names), -+ (int)handshake_status); -+} -+ -+const char *handshake_peer_status_name(peer_status_t peer_status) -+{ -+ return enum_name(peer_status_names, OSSL_NELEM(peer_status_names), -+ (int)peer_status); -+} -+ -+static void save_loop_history(HANDSHAKE_HISTORY *history, -+ connect_phase_t phase, -+ handshake_status_t handshake_status, -+ peer_status_t server_status, -+ peer_status_t client_status, -+ int client_turn_count, -+ int is_client_turn) -+{ -+ HANDSHAKE_HISTORY_ENTRY *new_entry = NULL; -+ -+ /* -+ * Create a new history entry for a handshake loop with statuses given in -+ * the arguments. Potentially evicting the oldest entry when the -+ * ring buffer is full. -+ */ -+ ++(history->last_idx); -+ history->last_idx &= MAX_HANDSHAKE_HISTORY_ENTRY_IDX_MASK; -+ -+ new_entry = &((history->entries)[history->last_idx]); -+ new_entry->phase = phase; -+ new_entry->handshake_status = handshake_status; -+ new_entry->server_status = server_status; -+ new_entry->client_status = client_status; -+ new_entry->client_turn_count = client_turn_count; -+ new_entry->is_client_turn = is_client_turn; -+ -+ /* Evict the oldest handshake loop entry when the ring buffer is full. */ -+ if (history->entry_count < MAX_HANDSHAKE_HISTORY_ENTRY) { -+ ++(history->entry_count); -+ } -+} -+ - HANDSHAKE_RESULT *HANDSHAKE_RESULT_new(void) - { - HANDSHAKE_RESULT *ret; -@@ -724,15 +820,6 @@ static void configure_handshake_ssl(SSL *server, SSL *client, - SSL_set_post_handshake_auth(client, 1); - } - --/* The status for each connection phase. */ --typedef enum { -- PEER_SUCCESS, -- PEER_RETRY, -- PEER_ERROR, -- PEER_WAITING, -- PEER_TEST_FAILURE --} peer_status_t; -- - /* An SSL object and associated read-write buffers. */ - typedef struct peer_st { - SSL *ssl; -@@ -1077,16 +1164,6 @@ static void do_shutdown_step(PEER *peer) - } - } - --typedef enum { -- HANDSHAKE, -- RENEG_APPLICATION_DATA, -- RENEG_SETUP, -- RENEG_HANDSHAKE, -- APPLICATION_DATA, -- SHUTDOWN, -- CONNECTION_DONE --} connect_phase_t; -- - static int renegotiate_op(const SSL_TEST_CTX *test_ctx) - { - switch (test_ctx->handshake_mode) { -@@ -1164,19 +1241,6 @@ static void do_connect_step(const SSL_TEST_CTX *test_ctx, PEER *peer, - } - } - --typedef enum { -- /* Both parties succeeded. */ -- HANDSHAKE_SUCCESS, -- /* Client errored. */ -- CLIENT_ERROR, -- /* Server errored. */ -- SERVER_ERROR, -- /* Peers are in inconsistent state. */ -- INTERNAL_ERROR, -- /* One or both peers not done. */ -- HANDSHAKE_RETRY --} handshake_status_t; -- - /* - * Determine the handshake outcome. - * last_status: the status of the peer to have acted last. -@@ -1541,6 +1605,10 @@ static HANDSHAKE_RESULT *do_handshake_internal( - - start = time(NULL); - -+ save_loop_history(&(ret->history), -+ phase, status, server.status, client.status, -+ client_turn_count, client_turn); -+ - /* - * Half-duplex handshake loop. - * Client and server speak to each other synchronously in the same process. -@@ -1562,6 +1630,10 @@ static HANDSHAKE_RESULT *do_handshake_internal( - 0 /* server went last */); - } - -+ save_loop_history(&(ret->history), -+ phase, status, server.status, client.status, -+ client_turn_count, client_turn); -+ - switch (status) { - case HANDSHAKE_SUCCESS: - client_turn_count = 0; -diff --git a/test/helpers/handshake.h b/test/helpers/handshake.h -index 78b03f9..b9967c2 100644 ---- a/test/helpers/handshake.h -+++ b/test/helpers/handshake.h -@@ -1,5 +1,5 @@ - /* -- * Copyright 2016-2021 The OpenSSL Project Authors. All Rights Reserved. -+ * Copyright 2016-2023 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy -@@ -12,6 +12,11 @@ - - #include "ssl_test_ctx.h" - -+#define MAX_HANDSHAKE_HISTORY_ENTRY_BIT 4 -+#define MAX_HANDSHAKE_HISTORY_ENTRY (1 << MAX_HANDSHAKE_HISTORY_ENTRY_BIT) -+#define MAX_HANDSHAKE_HISTORY_ENTRY_IDX_MASK \ -+ ((1 << MAX_HANDSHAKE_HISTORY_ENTRY_BIT) - 1) -+ - typedef struct ctx_data_st { - unsigned char *npn_protocols; - size_t npn_protocols_len; -@@ -22,6 +27,63 @@ typedef struct ctx_data_st { - char *session_ticket_app_data; - } CTX_DATA; - -+typedef enum { -+ HANDSHAKE, -+ RENEG_APPLICATION_DATA, -+ RENEG_SETUP, -+ RENEG_HANDSHAKE, -+ APPLICATION_DATA, -+ SHUTDOWN, -+ CONNECTION_DONE -+} connect_phase_t; -+ -+/* The status for each connection phase. */ -+typedef enum { -+ PEER_SUCCESS, -+ PEER_RETRY, -+ PEER_ERROR, -+ PEER_WAITING, -+ PEER_TEST_FAILURE -+} peer_status_t; -+ -+typedef enum { -+ /* Both parties succeeded. */ -+ HANDSHAKE_SUCCESS, -+ /* Client errored. */ -+ CLIENT_ERROR, -+ /* Server errored. */ -+ SERVER_ERROR, -+ /* Peers are in inconsistent state. */ -+ INTERNAL_ERROR, -+ /* One or both peers not done. */ -+ HANDSHAKE_RETRY -+} handshake_status_t; -+ -+/* Stores the various status information in a handshake loop. */ -+typedef struct handshake_history_entry_st { -+ connect_phase_t phase; -+ handshake_status_t handshake_status; -+ peer_status_t server_status; -+ peer_status_t client_status; -+ int client_turn_count; -+ int is_client_turn; -+} HANDSHAKE_HISTORY_ENTRY; -+ -+typedef struct handshake_history_st { -+ /* Implemented using ring buffer. */ -+ /* -+ * The valid entries are |entries[last_idx]|, |entries[last_idx-1]|, -+ * ..., etc., going up to |entry_count| number of entries. Note that when -+ * the index into the array |entries| becomes < 0, we wrap around to -+ * the end of |entries|. -+ */ -+ HANDSHAKE_HISTORY_ENTRY entries[MAX_HANDSHAKE_HISTORY_ENTRY]; -+ /* The number of valid entries in |entries| array. */ -+ size_t entry_count; -+ /* The index of the last valid entry in the |entries| array. */ -+ size_t last_idx; -+} HANDSHAKE_HISTORY; -+ - typedef struct handshake_result { - ssl_test_result_t result; - /* These alerts are in the 2-byte format returned by the info_callback. */ -@@ -77,6 +139,8 @@ typedef struct handshake_result { - char *cipher; - /* session ticket application data */ - char *result_session_ticket_app_data; -+ /* handshake loop history */ -+ HANDSHAKE_HISTORY history; - } HANDSHAKE_RESULT; - - HANDSHAKE_RESULT *HANDSHAKE_RESULT_new(void); -@@ -95,4 +159,8 @@ int configure_handshake_ctx_for_srp(SSL_CTX *server_ctx, SSL_CTX *server2_ctx, - CTX_DATA *server2_ctx_data, - CTX_DATA *client_ctx_data); - -+const char *handshake_connect_phase_name(connect_phase_t phase); -+const char *handshake_status_name(handshake_status_t handshake_status); -+const char *handshake_peer_status_name(peer_status_t peer_status); -+ - #endif /* OSSL_TEST_HANDSHAKE_HELPER_H */ -diff --git a/test/ssl_test.c b/test/ssl_test.c -index ea60851..9d6b093 100644 ---- a/test/ssl_test.c -+++ b/test/ssl_test.c -@@ -26,6 +26,44 @@ static OSSL_LIB_CTX *libctx = NULL; - /* Currently the section names are of the form test-, e.g. test-15. */ - #define MAX_TESTCASE_NAME_LENGTH 100 - -+static void print_handshake_history(const HANDSHAKE_HISTORY *history) -+{ -+ size_t first_idx; -+ size_t i; -+ size_t cur_idx; -+ const HANDSHAKE_HISTORY_ENTRY *cur_entry; -+ const char header_template[] = "|%14s|%16s|%16s|%16s|%17s|%14s|"; -+ const char body_template[] = "|%14s|%16s|%16s|%16s|%17d|%14s|"; -+ -+ TEST_info("The following is the server/client state " -+ "in the most recent %d handshake loops.", -+ MAX_HANDSHAKE_HISTORY_ENTRY); -+ -+ TEST_note("==================================================" -+ "=================================================="); -+ TEST_note(header_template, -+ "phase", "handshake status", "server status", -+ "client status", "client turn count", "is client turn"); -+ TEST_note("+--------------+----------------+----------------" -+ "+----------------+-----------------+--------------+"); -+ -+ first_idx = (history->last_idx - history->entry_count + 1) & -+ MAX_HANDSHAKE_HISTORY_ENTRY_IDX_MASK; -+ for (i = 0; i < history->entry_count; ++i) { -+ cur_idx = (first_idx + i) & MAX_HANDSHAKE_HISTORY_ENTRY_IDX_MASK; -+ cur_entry = &(history->entries)[cur_idx]; -+ TEST_note(body_template, -+ handshake_connect_phase_name(cur_entry->phase), -+ handshake_status_name(cur_entry->handshake_status), -+ handshake_peer_status_name(cur_entry->server_status), -+ handshake_peer_status_name(cur_entry->client_status), -+ cur_entry->client_turn_count, -+ cur_entry->is_client_turn ? "true" : "false"); -+ } -+ TEST_note("==================================================" -+ "=================================================="); -+} -+ - static const char *print_alert(int alert) - { - return alert ? SSL_alert_desc_string_long(alert) : "no alert"; -@@ -388,6 +426,12 @@ static int check_test(HANDSHAKE_RESULT *result, SSL_TEST_CTX *test_ctx) - ret &= check_client_sign_type(result, test_ctx); - ret &= check_client_ca_names(result, test_ctx); - } -+ -+ /* Print handshake loop history if any check fails. */ -+ if (!ret) { -+ print_handshake_history(&(result->history)); -+ } -+ - return ret; - } - --- -2.25.1 - diff --git a/meta/recipes-connectivity/openssl/openssl/0001-Configure-do-not-tweak-mips-cflags.patch b/meta/recipes-connectivity/openssl/openssl/0001-Configure-do-not-tweak-mips-cflags.patch index cd8906df67..77bfe4e4e5 100644 --- a/meta/recipes-connectivity/openssl/openssl/0001-Configure-do-not-tweak-mips-cflags.patch +++ b/meta/recipes-connectivity/openssl/openssl/0001-Configure-do-not-tweak-mips-cflags.patch @@ -1,4 +1,4 @@ -From 0377f0d5b5c1079e3b9a80881f4dcc891cbe9f9a Mon Sep 17 00:00:00 2001 +From b5cee0cb0f14a78056ef7722a34b361491f1fdda Mon Sep 17 00:00:00 2001 From: Alexander Kanavin Date: Tue, 30 May 2023 09:11:27 -0700 Subject: [PATCH] Configure: do not tweak mips cflags @@ -17,10 +17,10 @@ Signed-off-by: Tim Orling 1 file changed, 10 deletions(-) diff --git a/Configure b/Configure -index fff97bd..5ee54c1 100755 +index c05a30b..db8adee 100755 --- a/Configure +++ b/Configure -@@ -1557,16 +1557,6 @@ if ($target =~ /^mingw/ && `$config{CC} --target-help 2>&1` =~ m/-mno-cygwin/m) +@@ -1575,16 +1575,6 @@ if ($target =~ /^mingw/ && `$config{CC} --target-help 2>&1` =~ m/-mno-cygwin/m) push @{$config{shared_ldflag}}, "-mno-cygwin"; } diff --git a/meta/recipes-connectivity/openssl/openssl/0001-buildinfo-strip-sysroot-and-debug-prefix-map-from-co.patch b/meta/recipes-connectivity/openssl/openssl/0001-buildinfo-strip-sysroot-and-debug-prefix-map-from-co.patch index bfbfedbd67..1d9e7539f6 100644 --- a/meta/recipes-connectivity/openssl/openssl/0001-buildinfo-strip-sysroot-and-debug-prefix-map-from-co.patch +++ b/meta/recipes-connectivity/openssl/openssl/0001-buildinfo-strip-sysroot-and-debug-prefix-map-from-co.patch @@ -1,4 +1,4 @@ -From 5985253f2c9025d7c127443a3a9938946f80c2a1 Mon Sep 17 00:00:00 2001 +From 6df53bfebcf8ca65910a18220a6576fb110918a5 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Martin=20Hundeb=C3=B8ll?= Date: Tue, 6 Nov 2018 14:50:47 +0100 Subject: [PATCH] buildinfo: strip sysroot and debug-prefix-map from compiler @@ -28,17 +28,16 @@ Signed-off-by: Kai Kang Update to fix buildpaths qa issue for '-ffile-prefix-map'. Signed-off-by: Khem Raj - --- Configurations/unix-Makefile.tmpl | 16 +++++++++++++++- crypto/build.info | 2 +- 2 files changed, 16 insertions(+), 2 deletions(-) diff --git a/Configurations/unix-Makefile.tmpl b/Configurations/unix-Makefile.tmpl -index 09303c4..011bda1 100644 +index eff66e5..bc48f51 100644 --- a/Configurations/unix-Makefile.tmpl +++ b/Configurations/unix-Makefile.tmpl -@@ -514,13 +514,27 @@ BIN_LDFLAGS={- join(' ', $target{bin_lflags} || (), +@@ -503,13 +503,27 @@ BIN_LDFLAGS={- join(' ', $target{bin_lflags} || (), '$(CNF_LDFLAGS)', '$(LDFLAGS)') -} BIN_EX_LIBS=$(CNF_EX_LIBS) $(EX_LIBS) @@ -68,10 +67,10 @@ index 09303c4..011bda1 100644 # For x86 assembler: Set PROCESSOR to 386 if you want to support diff --git a/crypto/build.info b/crypto/build.info -index aee5c46..95c9577 100644 +index 8e4a885..95b0902 100644 --- a/crypto/build.info +++ b/crypto/build.info -@@ -115,7 +115,7 @@ DEFINE[../libcrypto]=$UPLINKDEF +@@ -114,7 +114,7 @@ DEFINE[../libcrypto]=$UPLINKDEF DEPEND[info.o]=buildinf.h DEPEND[cversion.o]=buildinf.h diff --git a/meta/recipes-connectivity/openssl/openssl/0001-extend-check_cwm-test-timeout.patch b/meta/recipes-connectivity/openssl/openssl/0001-extend-check_cwm-test-timeout.patch index f6eb28069a..76bc05d5f9 100644 --- a/meta/recipes-connectivity/openssl/openssl/0001-extend-check_cwm-test-timeout.patch +++ b/meta/recipes-connectivity/openssl/openssl/0001-extend-check_cwm-test-timeout.patch @@ -1,4 +1,4 @@ -From c7000672296f4c367341aa3415f26c4d9f5e4749 Mon Sep 17 00:00:00 2001 +From 14856dbd767621ce6f162680c00557b54af0effb Mon Sep 17 00:00:00 2001 From: Gyorgy Sarvari Date: Thu, 23 Oct 2025 11:24:36 +0200 Subject: [PATCH] extend check_cwm test timeout @@ -15,7 +15,7 @@ Signed-off-by: Gyorgy Sarvari 1 file changed, 5 insertions(+) diff --git a/test/radix/main.c b/test/radix/main.c -index 4a1e886a71..39f8c61ef9 100644 +index 0f3dc11..d925639 100644 --- a/test/radix/main.c +++ b/test/radix/main.c @@ -25,6 +25,11 @@ static int test_script(int idx) diff --git a/meta/recipes-connectivity/openssl/openssl_3.5.7.bb b/meta/recipes-connectivity/openssl/openssl_4.0.1.bb similarity index 87% rename from meta/recipes-connectivity/openssl/openssl_3.5.7.bb rename to meta/recipes-connectivity/openssl/openssl_4.0.1.bb index b95c734f1d..a669de1b22 100644 --- a/meta/recipes-connectivity/openssl/openssl_3.5.7.bb +++ b/meta/recipes-connectivity/openssl/openssl_4.0.1.bb @@ -11,7 +11,6 @@ SRC_URI = "http://www.openssl.org/source/openssl-${PV}.tar.gz \ file://run-ptest \ file://0001-buildinfo-strip-sysroot-and-debug-prefix-map-from-co.patch \ file://0001-Configure-do-not-tweak-mips-cflags.patch \ - file://0001-Added-handshake-history-reporting-when-test-fails.patch \ file://0001-extend-check_cwm-test-timeout.patch \ " @@ -19,10 +18,9 @@ SRC_URI:append:class-nativesdk = " \ file://environment.d-openssl.sh \ " -SRC_URI[sha256sum] = "a8c0d28a529ca480f9f36cf5792e2cd21984552a3c8e4aa11a24aa31aeac98e8" +SRC_URI[sha256sum] = "2db3f3a0d6ea4b59e1f094ace2c8cd536dffb87cdc39084c5afa1e6f7f37dd09" -inherit lib_package multilib_header multilib_script ptest perlnative manpages -MULTILIB_SCRIPTS = "${PN}-bin:${bindir}/c_rehash" +inherit lib_package multilib_header ptest perlnative manpages # OpenSSL publishes bugfix/security-only releases on its per-minor branches. # When the tracked series reaches EOL, bump the regex manually to the next @@ -33,7 +31,6 @@ PACKAGECONFIG ?= "" PACKAGECONFIG:class-native = "" PACKAGECONFIG:class-nativesdk = "" -PACKAGECONFIG[cryptodev-linux] = "enable-devcryptoeng,disable-devcryptoeng,cryptodev-linux,,cryptodev-module" PACKAGECONFIG[legacy] = ",no-legacy" PACKAGECONFIG[tls1] = ",no-tls1" PACKAGECONFIG[tls1_1] = ",no-tls1_1" @@ -57,8 +54,8 @@ EXTRA_OECONF:append:class-native = " --with-rand-seed=os,devrandom" EXTRA_OECONF:append:class-nativesdk = " --with-rand-seed=os,devrandom" # Relying on hardcoded built-in paths causes openssl-native to not be relocateable from sstate. -EXTRA_OEMAKE:append:task-compile:class-native = ' OPENSSLDIR="/not/builtin" ENGINESDIR="/not/builtin" MODULESDIR="/not/builtin"' -EXTRA_OEMAKE:append:task-compile:class-nativesdk = ' OPENSSLDIR="/not/builtin" ENGINESDIR="/not/builtin" MODULESDIR="/not/builtin"' +EXTRA_OEMAKE:append:task-compile:class-native = ' OPENSSLDIR="/not/builtin" MODULESDIR="/not/builtin"' +EXTRA_OEMAKE:append:task-compile:class-nativesdk = ' OPENSSLDIR="/not/builtin" MODULESDIR="/not/builtin"' #| threads_pthread.c:(.text+0x372): undefined reference to `__atomic_is_lock_free' EXTRA_OECONF:append:toolchain-clang:x86 = " -latomic" @@ -204,12 +201,10 @@ do_install:append:class-native () { OPENSSL_CONF=\${OPENSSL_CONF:-${libdir}/ssl-3/openssl.cnf} \ SSL_CERT_DIR=\${SSL_CERT_DIR:-${libdir}/ssl-3/certs} \ SSL_CERT_FILE=\${SSL_CERT_FILE:-${libdir}/ssl-3/cert.pem} \ - OPENSSL_ENGINES=\${OPENSSL_ENGINES:-${libdir}/engines-3} \ OPENSSL_MODULES=\${OPENSSL_MODULES:-${libdir}/ossl-modules} - # Setting ENGINESDIR and MODULESDIR to invalid paths prevents host contamination, + # Setting MODULESDIR to invalid paths prevents host contamination, # but also breaks the generated libcrypto.pc file. Post-Fix it manually here. - sed -i 's|^enginesdir=\($.libdir.\)/.*|enginesdir=\1/engines-3|' ${D}${libdir}/pkgconfig/libcrypto.pc sed -i 's|^modulesdir=\($.libdir.\)/.*|modulesdir=\1/ossl-modules|' ${D}${libdir}/pkgconfig/libcrypto.pc } @@ -252,10 +247,6 @@ do_install_ptest() { sed 's|${S}|${PTEST_PATH}|g' -i ${D}${PTEST_PATH}/configdata.pm ${D}${PTEST_PATH}/util/wrap.pl - install -d ${D}${PTEST_PATH}/engines - install -m755 ${B}/engines/dasync.so ${D}${PTEST_PATH}/engines/ - install -m755 ${B}/engines/ossltest.so ${D}${PTEST_PATH}/engines/ - ln -s ${libdir}/engines-3/loader_attic.so ${D}${PTEST_PATH}/engines/ ln -s ${libdir}/ossl-modules/ ${D}${PTEST_PATH}/providers } @@ -270,17 +261,14 @@ pkg_postinst_ontarget:${PN}-ossl-module-fips () { # file to be installed for both the openssl-bin package and the libcrypto # package since the openssl-bin package depends on the libcrypto package. -PACKAGES =+ "libcrypto libssl openssl-conf ${PN}-engines ${PN}-misc ${PN}-ossl-module-legacy ${PN}-ossl-module-fips" +PACKAGES =+ "libcrypto libssl openssl-conf ${PN}-misc ${PN}-ossl-module-legacy ${PN}-ossl-module-fips" FILES:libcrypto = "${libdir}/libcrypto${SOLIBS}" FILES:libssl = "${libdir}/libssl${SOLIBS}" FILES:openssl-conf = "${sysconfdir}/ssl/openssl.cnf* \ ${libdir}/ssl-3/openssl.cnf* \ " -FILES:${PN}-engines = "${libdir}/engines-3" -# ${prefix} comes from what we pass into --prefix at configure time (which is used for INSTALLTOP) -FILES:${PN}-engines:append:mingw32:class-nativesdk = " ${prefix}${libdir}/engines-3" -FILES:${PN}-misc = "${libdir}/ssl-3/misc ${bindir}/c_rehash" +FILES:${PN}-misc = "${libdir}/ssl-3/misc" FILES:${PN}-ossl-module-legacy = "${libdir}/ossl-modules/legacy.so" FILES:${PN}-ossl-module-fips = "${libdir}/ossl-modules/fips.so" FILES:${PN} =+ "${libdir}/ssl-3/* ${libdir}/ossl-modules/" @@ -290,7 +278,7 @@ CONFFILES:openssl-conf = "${sysconfdir}/ssl/openssl.cnf" RRECOMMENDS:libcrypto += "openssl-conf ${PN}-ossl-module-legacy" RDEPENDS:${PN}-misc = "perl" -RDEPENDS:${PN}-ptest += "openssl-bin perl perl-modules bash sed openssl-engines" +RDEPENDS:${PN}-ptest += "openssl-bin perl perl-modules bash sed" RRECOMMENDS:${PN}-ptest += "${PN}-ossl-module-legacy" RDEPENDS:${PN}-bin += "openssl-conf" From patchwork Sat Aug 22 17:51:56 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 96054 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 879F6C5DF8C for ; Sat, 22 Aug 2026 17:52:09 +0000 (UTC) Received: from DB3PR0202CU003.outbound.protection.outlook.com (DB3PR0202CU003.outbound.protection.outlook.com [52.101.84.1]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1192.1787421126431531265 for ; Sat, 22 Aug 2026 10:52:08 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=Zcr/Z+CS; spf=pass (domain: est.tech, ip: 52.101.84.1, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=PyoGzAxk85Ii8GqprTHFw3PWZGZF0s2B5iXJGLq4d1N6MHjY/aX28ztD7fduo175Lktj8FO2zGKs/GY3hbhwzrnSI3XduKaN5rXSR4DHu2y+gPlHa0/ZMvHkR1GksOBYxCwIhxHsVjp3kvCxBzajqUyTQ8ovo6RR7DKYqgLjNz6u3J/sg6hcyr05LOz5MERz/MwEOs6RzEe4JIvlEta4mkKhEE7bGioBBFXHzlp/LJ6RDvSijpKj3grbeUnHnE0iEZle5doP0OuSB4T20EauJa+ysIqMrgW0nuQWJ/ZhcfwTTM9A+JjZxbjtiwfNtHuKtow3hpF70XGrR68cKiUsFQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=x8obRpt5bZC0XGtiklXI2aRsfhAiDJp+JXpX2O9ZL50=; b=vRmVVByAYeaDMNxYqPyibJwb9iXXTzhijgTQij4T/2Mm3oplisU4TElxFB3OTC8m8nzrNjG1TER6S58M+OZ9Afj3cP9fOt+ph/fR/u75ymadAr8bY0mXzNz5iwlBvehmyA7tuvOGc2FxZwbiBxeT6wyU9wYHwTgD5fVp9UHqWb0V3hUb/s8xja8IWojKC+kPOMc6hlGWjcV7YWllGr/Lg7JuRtDMIanPmI72gDpXVjXVkNAP8QNaC1/p5jD/mmRmiQfsAfsu+ALGslaE38pYO/FccZdOXbMJ5C448TmQ2vWlYfVAWWOjxSbvj7Ykkkz2PE0JDg10rTQ29Rtdv9bb3A== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=x8obRpt5bZC0XGtiklXI2aRsfhAiDJp+JXpX2O9ZL50=; b=Zcr/Z+CSDOTrk4oOdAWh44a0ZXXIvZ9Aq4CUhjxwcNEm2SfeQcbPVnL5H5GlfLcjPHhU2GnRxyOCsE1CDSrcxFo6CWaGl9Y3Mp1xNuHzLyPIaJKv4us7Nsa0zHWY7D41HeeXf83g7cy9fAkHwJ8KYz9RfBg75H2kJlkaUxBh6c3h6E/MRac5feLU1IMEK6eHvK898lAbsoj0LHtZA7/OkTCeLbG/Nip9R1hpIJy38ItVmkqhFvt9Arqm4ExPDaoSSU0zPsboqa9UkYnKwUZ9wgGG4EgBP4Bmi1COXrzQFQAKzhCi4Uy/wReA4ocubv87x1/xzwgPpYQcQelVBnPg5g== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by AM0P189MB0641.EURP189.PROD.OUTLOOK.COM (2603:10a6:208:1a2::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.5; Sat, 22 Aug 2026 17:52:04 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::7ab2:c6af:6760:5c85]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::7ab2:c6af:6760:5c85%7]) with mapi id 15.21.0360.003; Sat, 22 Aug 2026 17:52:04 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [RFC v4 2/6] python3: backport OpenSSL 4.0 support from upstream Date: Sat, 22 Aug 2026 19:51:56 +0200 Message-ID: <20260822175200.57534-3-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260822175200.57534-1-jaipaul.cheernam@est.tech> References: <20260814051829.35088-1-jaipaul.cheernam@est.tech> <20260822175200.57534-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: LO4P123CA0217.GBRP123.PROD.OUTLOOK.COM (2603:10a6:600:1a6::6) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|AM0P189MB0641:EE_ X-MS-Office365-Filtering-Correlation-Id: d64b71c6-bac0-4ac2-cc5b-08df0076133b X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|10070799003|23010399003|1800799024|376014|366016|13003099007|6133799003|3023799007|56012099006|10067099003|11063799006|4143699003|12006099003|22082099003|18002099003; X-Microsoft-Antispam-Message-Info: saxgXzXFp7yuJor6We+zfxOAYJwurTofZnlBeFWxCcP+bNRkDv0Jz6kV58NBo7iE8n6XcHy0NGfOxaLF/orR25TYQyNQtWRZ8XDPKRDn3U3naFfrd2fKv8h22XQBpBNLRPF37W+mX/259wI6FKooYlvdbyzguE39NPqXSVEsV3o5U9GF3MDbZQNovu+Q+kSqQ9wls8O0V4Sz6VB4YWyDdes6a8Oh0mPFUXtd7ruMm0E/E+eS+OLAspdU/CqoGIa/nTki8oqBUposSwGF1Hq/9JeACTGxz2+kErx/yFgRqEMLjzYjDS8GjpJE+74ehixXCjrGUHBmCsnCJboD4WkdJFwjuQf4iYKejCvXixWVZB6+mMDyx2//ZrGHpjjp9vCf2QN87JR93aHfR7vqettjFThcNu+KpKenbdVcGOHC+NSQ7avDNwLREmKuPfvPwMTp1ddGQkbWRTkJh07d/gblXiYyeq2BC81HQ1CFr9eKn9YIQh+l/bZOFYGT+7X8LBlD9epy/jpolWu6ouujLnOtDzazpydBnRxziLnql+SBkX5X+K8s2k1RmesQzRDf5fohtaCAvFq2ZeLVtUAw1LUWpMZ5miGWiyDgIfe1PuxkaHY2E/eXHdyiC2a7Dh7h0XB8vXWnrdfg9ylQgi4uy25OcF7MBJOF+stQoGEY7Y01he0= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(10070799003)(23010399003)(1800799024)(376014)(366016)(13003099007)(6133799003)(3023799007)(56012099006)(10067099003)(11063799006)(4143699003)(12006099003)(22082099003)(18002099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 2 X-MS-Exchange-AntiSpam-MessageData-0: e9dmrnYW3C9U4kb8TGhM1qBt+0uWk3I2Zh/C9YPfGC9cbmx1K4F82t2TsMzAXqJ6UYGYIZ4BBTRwwNTiMHB7fgP72I3SDonsvh1WA6S2qHSv0MSTB4xJyYgHfm4YReiT91NnZtdyHBKyksnnEmmrTs/eey4Atno56vf56LTN3bZ/mAKg1nr11Z0H9JaZmF8gjMu9e52yGE8gLYxR/wPjk3mxARB65cGrj6WHawYMY0ztdsnU8qj4ObUyKO+Y14VZTxWXio7ecsZ6POIyPppLmbRdj3TqHAtoc4DR9Vx6gSb0Oon/G3fdvgzplSWw5vLPd9tAGmmdhXhEf7FlNwu6XZr6sCIVHn289wND2rW4z1VXZEC3++1mh+2CTrELOgyDZMqcIUMXVm7DD1+1TKbiG853Y23+1IwHdVnUJwcOX98+nOQTJ1f1cdj1TavG2xepNAV3yBo+oUFFhSq59eBnxouKSPyK7ow/hU2+uX/YY4drSK1Tovr67peGlGz9FaAGyH00uiBavit9dFlU3HbTv7ZoGpytIq8Gla4l5GvAtJQrhlsF/78QmCzl4nqFvopCxBu+90c2prZZK/OWDozUK64YNXRfqVVhQdDZWdkiA340RnVmuu93aymaZNKnno/n0ks/h2CStLt8qrjY8gVJrPKQpnytHn6lj9fp7Ui3zi2gJMR/eCjvmXVrVnGJds0qlzYAESW7G1DKElRsGoREGCRvkPJVZKdokl5NVx2tH2AARaXtHGaRIRN7csBAFvPQGMCG5rAWMjHqRS+WRJ8cWeoD8Cx1KWmIV62rE78sZdnXFSDHiwW/f1Gr84GF652xzE9uYLKiVGaD0FgCW8abZfdKVtbjouGL2ouZlrMTImzYE+iGbfjdOs8aWyp6XvXzui43NB4Y40n5EEcrVkr/2LdQ21uh8ZTV4ZTX1jJ6i4CuigqJgmmXRR9tHZpionyeyZSTb0DNs0q6Ce/Vs/UfZb7tvBwrWZQtLvYEMCQusV7M0pnL2ijTWoinUBoBq9e6pyk+p31cxAP2XVdqQ1YzlZDZkf+q7G59c5tMjQE/1L2hCHsS2CSzfkWec/hA/tIIzkCnvU6P6AeSaOJ3SoxjeBIrLULFt7LLiFoObh1dSBX+OG6acvoKJYv8gVYpgSRnd4S1axVTt/TuT5+LUytAXOGzeGrPJ2culkwOIBsvpaFEdLhCACFbyIBsTu7G27z0KIujCYn+ibwi8TYwr9KgOKaS03MTos/6YGGuHDemCuCdp41dh40ouAT05EmL/XuZiDOKk19OqvrRcOhlGWjIK6Gdr+/kI9SAUV9sU9fQdg54a5sh9oD4XdzsYVD5/LxiiumVtU9qPSdC54zGV/VpcTbFKW1TwKjcLulzw188Vve6jxxywSMW+fZkmOHynQXmFosWz/FEgBXDmq23doCZamLdH1mIxwMh38UNwBGJqFBBuS5hmi8Ce4031AEb9c58/Z4XUyN8frZPvUijeOiEyjOcOBGup0TQ3SNR5vQ7tMuxI8GXd1DD9wZMGlhTwa+dYDLBwF1hjbcsIfhSxMjsi8bfS8VEbpWeqtAdls2t0zn3nmidt31OfF0HyCdlEO+c93yLgXzKCnSjxe1HRSHv+P5A/MWzTAU3TBy87TKV+9Rk1996gSA9khz/JUNUraxWxcye1WRqDqVIuGUlXwVrHVkaPc+p8sh7FAxpmUw0TEpOHasx92LCQWIrWxoicZDtAMhIGoqLqWgNFc/O/X71PgjS8IHI8At702p74U6J6DKPIgDtj5rrZZbZY+Gm6gMviQoELSn8 X-MS-Exchange-AntiSpam-MessageData-1: uDDIiSKzplwpY2OmIo7Ay7ZSt6dvcIhoqLw= X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: d64b71c6-bac0-4ac2-cc5b-08df0076133b X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 22 Aug 2026 17:52:03.9801 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: bEhBqDFd/mNVw1gnjLJJzmS1I09PjLyGIEt695Ff0SjcQTscjVdJdzZvNVsIYbSIVuKNScWM6f551RNnoXurs8UDLPhx8aIbC4+E4BxVRvY= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM0P189MB0641 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 22 Aug 2026 17:52:09 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/243994 Backport CPython commit 3364e7e62fa24d0e19133fb0f90b1c24ef1110c5: gh-146207: Add support for OpenSSL 4.0.0 alpha1 (#146217) OpenSSL 4.0.0 alpha1 removed these functions: * SSLv3_method() * TLSv1_method() * TLSv1_1_method() * TLSv1_2_method() Other changes: * Update test_openssl_version(). * Update multissltests.py for OpenSSL 4. * Add const qualifier to fix compiler warnings. Co-authored-by: Bénédikt Tran <10796600+picnixz@users.noreply.github.com> Upstream-Status: Backport [https://github.com/python/cpython/commit/3364e7e62fa24d0e19133fb0f90b1c24ef1110c5] Signed-off-by: Jaipaul Cheernam --- ...146207-Add-support-for-OpenSSL-4.0.0.patch | 257 ++++++++++++++++++ ...Update-_ssl._SSLSocket-for-OpenSSL-4.patch | 234 ++++++++++++++++ ...utdown-test-in-test_ssl.test_got_eof.patch | 41 +++ .../recipes-devtools/python/python3_3.14.7.bb | 3 + 4 files changed, 535 insertions(+) create mode 100644 meta/recipes-devtools/python/python3/0001-gh-146207-Add-support-for-OpenSSL-4.0.0.patch create mode 100644 meta/recipes-devtools/python/python3/0002-gh-148292-Update-_ssl._SSLSocket-for-OpenSSL-4.patch create mode 100644 meta/recipes-devtools/python/python3/0003-gh-148292-Remove-shutdown-test-in-test_ssl.test_got_eof.patch diff --git a/meta/recipes-devtools/python/python3/0001-gh-146207-Add-support-for-OpenSSL-4.0.0.patch b/meta/recipes-devtools/python/python3/0001-gh-146207-Add-support-for-OpenSSL-4.0.0.patch new file mode 100644 index 0000000000..bef6044358 --- /dev/null +++ b/meta/recipes-devtools/python/python3/0001-gh-146207-Add-support-for-OpenSSL-4.0.0.patch @@ -0,0 +1,257 @@ +From 3364e7e62fa24d0e19133fb0f90b1c24ef1110c5 Mon Sep 17 00:00:00 2001 +From: Victor Stinner +Date: Wed, 25 Mar 2026 07:44:47 +0100 +Subject: [PATCH] gh-146207: Add support for OpenSSL 4.0.0 alpha1 (#146217) + +OpenSSL 4.0.0 alpha1 removed these functions: + +* SSLv3_method() +* TLSv1_method() +* TLSv1_1_method() +* TLSv1_2_method() + +Other changes: + +* Update test_openssl_version(). +* Update multissltests.py for OpenSSL 4. +* Add const qualifier to fix compiler warnings. + +Co-authored-by: Bénédikt Tran <10796600+picnixz@users.noreply.github.com> +Signed-off-by: Victor Stinner + +Upstream-Status: Backport [https://github.com/python/cpython/commit/3364e7e62fa24d0e19133fb0f90b1c24ef1110c5] +Signed-off-by: Jaipaul Cheernam +--- + Lib/test/test_ssl.py | 52 ++++++++++++++++++++------------------ + Modules/_ssl.c | 27 ++++++++++++++++---- + Modules/_ssl/cert.c | 3 ++- + Tools/ssl/multissltests.py | 7 ++++- + 4 files changed, 58 insertions(+), 31 deletions(-) + +diff --git a/Lib/test/test_ssl.py b/Lib/test/test_ssl.py +index dc795c6bd8a..61355927296 100644 +--- a/Lib/test/test_ssl.py ++++ b/Lib/test/test_ssl.py +@@ -395,7 +395,7 @@ def test_constants(self): + ssl.OP_NO_COMPRESSION + self.assertEqual(ssl.HAS_SNI, True) + self.assertEqual(ssl.HAS_ECDH, True) +- self.assertEqual(ssl.HAS_TLSv1_2, True) ++ self.assertIsInstance(ssl.HAS_TLSv1_2, bool) + self.assertEqual(ssl.HAS_TLSv1_3, True) + ssl.OP_NO_SSLv2 + ssl.OP_NO_SSLv3 +@@ -586,11 +586,11 @@ def test_openssl_version(self): + # Some sanity checks follow + # >= 1.1.1 + self.assertGreaterEqual(n, 0x10101000) +- # < 4.0 +- self.assertLess(n, 0x40000000) ++ # < 5.0 ++ self.assertLess(n, 0x50000000) + major, minor, fix, patch, status = t + self.assertGreaterEqual(major, 1) +- self.assertLess(major, 4) ++ self.assertLess(major, 5) + self.assertGreaterEqual(minor, 0) + self.assertLess(minor, 256) + self.assertGreaterEqual(fix, 0) +@@ -656,12 +656,14 @@ def test_openssl111_deprecations(self): + ssl.OP_NO_TLSv1_2, + ssl.OP_NO_TLSv1_3 + ] +- protocols = [ +- ssl.PROTOCOL_TLSv1, +- ssl.PROTOCOL_TLSv1_1, +- ssl.PROTOCOL_TLSv1_2, +- ssl.PROTOCOL_TLS +- ] ++ protocols = [] ++ if hasattr(ssl, 'PROTOCOL_TLSv1'): ++ protocols.append(ssl.PROTOCOL_TLSv1) ++ if hasattr(ssl, 'PROTOCOL_TLSv1_1'): ++ protocols.append(ssl.PROTOCOL_TLSv1_1) ++ if hasattr(ssl, 'PROTOCOL_TLSv1_2'): ++ protocols.append(ssl.PROTOCOL_TLSv1_2) ++ protocols.append(ssl.PROTOCOL_TLS) + versions = [ + ssl.TLSVersion.SSLv3, + ssl.TLSVersion.TLSv1, +@@ -1205,6 +1207,7 @@ def test_min_max_version(self): + ssl.TLSVersion.TLSv1, + ssl.TLSVersion.TLSv1_1, + ssl.TLSVersion.TLSv1_2, ++ ssl.TLSVersion.TLSv1_3, + ssl.TLSVersion.SSLv3, + } + ) +@@ -1218,7 +1221,7 @@ def test_min_max_version(self): + with self.assertRaises(ValueError): + ctx.minimum_version = 42 + +- if has_tls_protocol(ssl.PROTOCOL_TLSv1_1): ++ if has_tls_protocol('PROTOCOL_TLSv1_1'): + ctx = ssl.SSLContext(ssl.PROTOCOL_TLSv1_1) + + self.assertIn( +@@ -1675,23 +1678,24 @@ def test__create_stdlib_context(self): + self.assertFalse(ctx.check_hostname) + self._assert_context_options(ctx) + +- if has_tls_protocol(ssl.PROTOCOL_TLSv1): ++ if has_tls_protocol('PROTOCOL_TLSv1'): + with warnings_helper.check_warnings(): + ctx = ssl._create_stdlib_context(ssl.PROTOCOL_TLSv1) + self.assertEqual(ctx.protocol, ssl.PROTOCOL_TLSv1) + self.assertEqual(ctx.verify_mode, ssl.CERT_NONE) + self._assert_context_options(ctx) + +- with warnings_helper.check_warnings(): +- ctx = ssl._create_stdlib_context( +- ssl.PROTOCOL_TLSv1_2, +- cert_reqs=ssl.CERT_REQUIRED, +- check_hostname=True +- ) +- self.assertEqual(ctx.protocol, ssl.PROTOCOL_TLSv1_2) +- self.assertEqual(ctx.verify_mode, ssl.CERT_REQUIRED) +- self.assertTrue(ctx.check_hostname) +- self._assert_context_options(ctx) ++ if has_tls_protocol('PROTOCOL_TLSv1_2'): ++ with warnings_helper.check_warnings(): ++ ctx = ssl._create_stdlib_context( ++ ssl.PROTOCOL_TLSv1_2, ++ cert_reqs=ssl.CERT_REQUIRED, ++ check_hostname=True ++ ) ++ self.assertEqual(ctx.protocol, ssl.PROTOCOL_TLSv1_2) ++ self.assertEqual(ctx.verify_mode, ssl.CERT_REQUIRED) ++ self.assertTrue(ctx.check_hostname) ++ self._assert_context_options(ctx) + + ctx = ssl._create_stdlib_context(purpose=ssl.Purpose.CLIENT_AUTH) + self.assertEqual(ctx.protocol, ssl.PROTOCOL_TLS_SERVER) +@@ -3654,10 +3658,10 @@ def test_protocol_tlsv1_2(self): + client_options=ssl.OP_NO_TLSv1_2) + + try_protocol_combo(ssl.PROTOCOL_TLS, ssl.PROTOCOL_TLSv1_2, 'TLSv1.2') +- if has_tls_protocol(ssl.PROTOCOL_TLSv1): ++ if has_tls_protocol('PROTOCOL_TLSv1'): + try_protocol_combo(ssl.PROTOCOL_TLSv1_2, ssl.PROTOCOL_TLSv1, False) + try_protocol_combo(ssl.PROTOCOL_TLSv1, ssl.PROTOCOL_TLSv1_2, False) +- if has_tls_protocol(ssl.PROTOCOL_TLSv1_1): ++ if has_tls_protocol('PROTOCOL_TLSv1_1'): + try_protocol_combo(ssl.PROTOCOL_TLSv1_2, ssl.PROTOCOL_TLSv1_1, False) + try_protocol_combo(ssl.PROTOCOL_TLSv1_1, ssl.PROTOCOL_TLSv1_2, False) + +diff --git a/Modules/_ssl.c b/Modules/_ssl.c +index b45295b4c0c..6f75af86113 100644 +--- a/Modules/_ssl.c ++++ b/Modules/_ssl.c +@@ -164,6 +164,17 @@ static void _PySSLFixErrno(void) { + #error Unsupported OpenSSL version + #endif + ++#if (OPENSSL_VERSION_NUMBER >= 0x40000000L) ++# define OPENSSL_NO_SSL3 ++# define OPENSSL_NO_TLS1 ++# define OPENSSL_NO_TLS1_1 ++# define OPENSSL_NO_TLS1_2 ++# define OPENSSL_NO_SSL3_METHOD ++# define OPENSSL_NO_TLS1_METHOD ++# define OPENSSL_NO_TLS1_1_METHOD ++# define OPENSSL_NO_TLS1_2_METHOD ++#endif ++ + /* OpenSSL API 1.1.0+ does not include version methods */ + #ifndef OPENSSL_NO_SSL3_METHOD + extern const SSL_METHOD *SSLv3_method(void); +@@ -1151,7 +1162,7 @@ _asn1obj2py(_sslmodulestate *state, const ASN1_OBJECT *name, int no_name) + + static PyObject * + _create_tuple_for_attribute(_sslmodulestate *state, +- ASN1_OBJECT *name, ASN1_STRING *value) ++ const ASN1_OBJECT *name, const ASN1_STRING *value) + { + Py_ssize_t buflen; + PyObject *pyattr; +@@ -1180,16 +1191,16 @@ _create_tuple_for_attribute(_sslmodulestate *state, + } + + static PyObject * +-_create_tuple_for_X509_NAME (_sslmodulestate *state, X509_NAME *xname) ++_create_tuple_for_X509_NAME(_sslmodulestate *state, const X509_NAME *xname) + { + PyObject *dn = NULL; /* tuple which represents the "distinguished name" */ + PyObject *rdn = NULL; /* tuple to hold a "relative distinguished name" */ + PyObject *rdnt; + PyObject *attr = NULL; /* tuple to hold an attribute */ + int entry_count = X509_NAME_entry_count(xname); +- X509_NAME_ENTRY *entry; +- ASN1_OBJECT *name; +- ASN1_STRING *value; ++ const X509_NAME_ENTRY *entry; ++ const ASN1_OBJECT *name; ++ const ASN1_STRING *value; + int index_counter; + int rdn_level = -1; + int retcode; +@@ -6967,9 +6978,15 @@ sslmodule_init_constants(PyObject *m) + ADD_INT_CONST("PROTOCOL_TLS", PY_SSL_VERSION_TLS); + ADD_INT_CONST("PROTOCOL_TLS_CLIENT", PY_SSL_VERSION_TLS_CLIENT); + ADD_INT_CONST("PROTOCOL_TLS_SERVER", PY_SSL_VERSION_TLS_SERVER); ++#ifndef OPENSSL_NO_TLS1 + ADD_INT_CONST("PROTOCOL_TLSv1", PY_SSL_VERSION_TLS1); ++#endif ++#ifndef OPENSSL_NO_TLS1_1 + ADD_INT_CONST("PROTOCOL_TLSv1_1", PY_SSL_VERSION_TLS1_1); ++#endif ++#ifndef OPENSSL_NO_TLS1_2 + ADD_INT_CONST("PROTOCOL_TLSv1_2", PY_SSL_VERSION_TLS1_2); ++#endif + + #define ADD_OPTION(NAME, VALUE) if (sslmodule_add_option(m, NAME, (VALUE)) < 0) return -1 + +diff --git a/Modules/_ssl/cert.c b/Modules/_ssl/cert.c +index f2e7be89668..061b0fb3171 100644 +--- a/Modules/_ssl/cert.c ++++ b/Modules/_ssl/cert.c +@@ -128,7 +128,8 @@ _ssl_Certificate_get_info_impl(PySSLCertificate *self) + } + + static PyObject* +-_x509name_print(_sslmodulestate *state, X509_NAME *name, int indent, unsigned long flags) ++_x509name_print(_sslmodulestate *state, const X509_NAME *name, ++ int indent, unsigned long flags) + { + PyObject *res; + BIO *biobuf; +diff --git a/Tools/ssl/multissltests.py b/Tools/ssl/multissltests.py +index 3b4507c6771..48207e5330f 100755 +--- a/Tools/ssl/multissltests.py ++++ b/Tools/ssl/multissltests.py +@@ -429,9 +429,11 @@ def _post_install(self): + def _post_install(self): + if self.version.startswith("3."): + self._post_install_3xx() ++ elif self.version.startswith("4."): ++ self._post_install_4xx() + + def _build_src(self, config_args=()): +- if self.version.startswith("3."): ++ if self.version.startswith(("3.", "4.")): + config_args += ("enable-fips",) + super()._build_src(config_args) + +@@ -447,6 +449,9 @@ def _post_install_3xx(self): + lib64 = self.lib_dir + "64" + os.symlink(lib64, self.lib_dir) + ++ def _post_install_4xx(self): ++ self._post_install_3xx() ++ + @property + def short_version(self): + """Short version for OpenSSL download URL""" +-- +2.25.1 + diff --git a/meta/recipes-devtools/python/python3/0002-gh-148292-Update-_ssl._SSLSocket-for-OpenSSL-4.patch b/meta/recipes-devtools/python/python3/0002-gh-148292-Update-_ssl._SSLSocket-for-OpenSSL-4.patch new file mode 100644 index 0000000000..587f141dd4 --- /dev/null +++ b/meta/recipes-devtools/python/python3/0002-gh-148292-Update-_ssl._SSLSocket-for-OpenSSL-4.patch @@ -0,0 +1,234 @@ +From 3c2a3014af7d73cc34f2498f60fdf863d9bc7c6c Mon Sep 17 00:00:00 2001 +From: Victor Stinner +Date: Mon, 4 May 2026 13:52:57 +0200 +Subject: [PATCH] gh-148292: Update _ssl._SSLSocket for OpenSSL 4 (#149102) + +The _SSLSocket object now remembers if it gets an EOF error. In this +case, read(), sendfile(), write() and do_handshake method calls fail +with SSLEOFError without calling the underlying OpenSSL function. + +Co-authored-by: Gregory P. Smith +(cherry picked from commit 7b7fa3f9bf3d7cdf3eb669d02b386e05b39c402a) + +Upstream-Status: Backport [https://github.com/python/cpython/commit/3c2a3014af7d] + +Note: This is from the unmerged CPython PR #149783 which backports +OpenSSL 4.0 support to the 3.14 branch. Upstream deferred merging +until after Python 3.15.1 is released. + +Signed-off-by: Jaipaul Cheernam +--- + Lib/test/test_ssl.py | 82 +++++++++++++++++++ + ...-04-28-17-47-55.gh-issue-148292.oIq3ml.rst | 7 ++ + Modules/_ssl.c | 42 ++++++++++ + 3 files changed, 131 insertions(+) + create mode 100644 Misc/NEWS.d/next/Library/2026-04-28-17-47-55.gh-issue-148292.oIq3ml.rst + +diff --git a/Lib/test/test_ssl.py b/Lib/test/test_ssl.py +index 965dbc36f096499..03d9e3f9e5e96b5 100644 +--- a/Lib/test/test_ssl.py ++++ b/Lib/test/test_ssl.py +@@ -2711,6 +2711,36 @@ def close(self): + def stop(self): + self.active = False + ++class TestEOFServer(threading.Thread): ++ def __init__(self): ++ super().__init__() ++ self.listening = threading.Event() ++ self.address = None ++ ++ def run(self): ++ context = ssl.create_default_context(ssl.Purpose.CLIENT_AUTH) ++ context.load_cert_chain(CERTFILE) ++ server_sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM) ++ with server_sock: ++ server_sock.settimeout(support.SHORT_TIMEOUT) ++ server_sock.bind((HOST, 0)) ++ server_sock.listen(5) ++ ++ self.address = server_sock.getsockname() ++ self.listening.set() ++ ++ sock, addr = server_sock.accept() ++ sslconn = context.wrap_socket(sock, server_side=True) ++ with sslconn: ++ request = b'' ++ while chunk := sslconn.recv(1024): ++ request += chunk ++ if b'\n' in chunk: ++ break ++ ++ sslconn.sendall(b'server\n') ++ sslconn.shutdown(socket.SHUT_WR) ++ + class AsyncoreEchoServer(threading.Thread): + + # this one's based on asyncore.dispatcher +@@ -4747,6 +4777,58 @@ def background(sock): + if cm.exc_value is not None: + raise cm.exc_value + ++ def test_got_eof(self): ++ # gh-148292: Test that _ssl._SSLSocket behaves the same on all OpenSSL ++ # versions on calling methods after EOF (after the first SSLEOFError). ++ ++ server = TestEOFServer() ++ server.start() ++ if not server.listening.wait(support.SHORT_TIMEOUT): ++ raise RuntimeError("server took too long") ++ self.addCleanup(server.join) ++ ++ context = ssl.create_default_context(cafile=CERTFILE) ++ sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM) ++ sock.settimeout(support.SHORT_TIMEOUT) ++ sock.connect(server.address) ++ sslsock = context.wrap_socket(sock, server_hostname='localhost') ++ with sslsock: ++ sslsock.sendall(b'client\n') ++ # test the _ssl._SSLSocket object, not ssl.SSLSocket ++ sslobj = sslsock._sslobj ++ ++ data = sslobj.read(1024) ++ self.assertEqual(data, b'server\n') ++ ++ # The second read gets EOF error and sets got_eof_error to 1 ++ with self.assertRaises(ssl.SSLEOFError): ++ sslobj.read(1024) ++ ++ # Following read(), sendfile(), write() and do_handshake() calls ++ # must raise SSLEOFError ++ with self.assertRaises(ssl.SSLEOFError): ++ # The _SSLSocket remembers the previous EOF error ++ # and raises again SSLEOFError ++ sslobj.read(1024) ++ if hasattr(sslobj, 'sendfile'): ++ with open(__file__, "rb") as fp: ++ with self.assertRaises(ssl.SSLEOFError): ++ sslobj.sendfile(fp.fileno(), 0, 1) ++ with self.assertRaises(ssl.SSLEOFError): ++ sslobj.write(b'client2\n') ++ with self.assertRaises(ssl.SSLEOFError): ++ sslsock.do_handshake() ++ ++ self.assertEqual(sslsock.pending(), 0) ++ try: ++ sslsock.shutdown(socket.SHUT_WR) ++ except OSError as exc: ++ self.assertEqual(exc.errno, errno.ENOTCONN) ++ else: ++ # On Windows and on OpenSSL 1.1.1, shutdown() doesn't ++ # raise an error ++ pass ++ + + @unittest.skipUnless(has_tls_version('TLSv1_3') and ssl.HAS_PHA, + "Test needs TLS 1.3 PHA") +diff --git a/Misc/NEWS.d/next/Library/2026-04-28-17-47-55.gh-issue-148292.oIq3ml.rst b/Misc/NEWS.d/next/Library/2026-04-28-17-47-55.gh-issue-148292.oIq3ml.rst +new file mode 100644 +index 000000000000000..e1f308df5a678e6 +--- /dev/null ++++ b/Misc/NEWS.d/next/Library/2026-04-28-17-47-55.gh-issue-148292.oIq3ml.rst +@@ -0,0 +1,7 @@ ++:mod:`ssl`: Update :class:`ssl.SSLSocket` and :class:`ssl.SSLObject` for ++OpenSSL 4. The classes now remember if they get a :exc:`ssl.SSLEOFError`. In this ++case, following :meth:`~ssl.SSLSocket.read`, :meth:`!sendfile`, ++:meth:`~ssl.SSLSocket.write`, and :meth:`~ssl.SSLSocket.do_handshake` calls ++raise :exc:`ssl.SSLEOFError` without calling the underlying OpenSSL function. ++Thanks to that, :class:`ssl.SSLSocket` behaves the same on all OpenSSL versions ++on EOF. Patch by Victor Stinner. +diff --git a/Modules/_ssl.c b/Modules/_ssl.c +index 1603d0ffd559559..376df32b7cb4bd6 100644 +--- a/Modules/_ssl.c ++++ b/Modules/_ssl.c +@@ -352,6 +352,16 @@ typedef struct { + * and shutdown methods check for chained exceptions. + */ + PyObject *exc; ++ // gh-148292: If non-zero, read(), sendfile(), write() and do_handshake() ++ // methods raise SSLEOFError without calling the underlying OpenSSL ++ // function. Set to 1 on PY_SSL_ERROR_EOF error. ++ // ++ // On OpenSSL 4, if SSL_read_ex() fails with ++ // SSL_R_UNEXPECTED_EOF_WHILE_READING, the following SSL_read_ex() call ++ // fails with a generic protocol error (ERR_peek_last_error() returns 0). ++ // Use got_eof_error to have the same behavior on OpenSSL 4 and newer and ++ // on OpenSSL 3 and older. ++ int got_eof_error; + } PySSLSocket; + + #define PySSLSocket_CAST(op) ((PySSLSocket *)(op)) +@@ -499,6 +509,10 @@ fill_and_set_sslerror(_sslmodulestate *state, + PyObject *init_value, *msg, *key; + PyUnicodeWriter *writer = NULL; + ++ if (ssl_errno == PY_SSL_ERROR_EOF && sslsock != NULL) { ++ sslsock->got_eof_error = 1; ++ } ++ + if (errcode != 0) { + int lib, reason; + +@@ -654,6 +668,18 @@ PySSL_ChainExceptions(PySSLSocket *sslsock) { + return -1; + } + ++ ++static void ++set_eof_error(PySSLSocket *sslsock) ++{ ++ _sslmodulestate *state = get_state_sock(sslsock); ++ fill_and_set_sslerror(state, sslsock, state->PySSLEOFErrorObject, ++ PY_SSL_ERROR_EOF, ++ "EOF occurred in violation of protocol", ++ __LINE__, 0); ++} ++ ++ + static PyObject * + PySSL_SetError(PySSLSocket *sslsock, const char *filename, int lineno) + { +@@ -901,6 +927,7 @@ newPySSLSocket(PySSLContext *sslctx, PySocketSockObject *sock, + self->server_hostname = NULL; + self->err = err; + self->exc = NULL; ++ self->got_eof_error = 0; + + /* Make sure the SSL error state is initialized */ + ERR_clear_error(); +@@ -1041,6 +1068,11 @@ _ssl__SSLSocket_do_handshake_impl(PySSLSocket *self) + BIO_set_nbio(SSL_get_wbio(self->ssl), nonblocking); + } + ++ if (self->got_eof_error) { ++ set_eof_error(self); ++ goto error; ++ } ++ + timeout = GET_SOCKET_TIMEOUT(sock); + has_timeout = (timeout > 0); + if (has_timeout) { +@@ -2504,6 +2536,11 @@ _ssl__SSLSocket_write_impl(PySSLSocket *self, Py_buffer *b) + BIO_set_nbio(SSL_get_wbio(self->ssl), nonblocking); + } + ++ if (self->got_eof_error) { ++ set_eof_error(self); ++ goto error; ++ } ++ + timeout = GET_SOCKET_TIMEOUT(sock); + has_timeout = (timeout > 0); + if (has_timeout) { +@@ -2644,6 +2681,11 @@ _ssl__SSLSocket_read_impl(PySSLSocket *self, Py_ssize_t len, + Py_INCREF(sock); + } + ++ if (self->got_eof_error) { ++ set_eof_error(self); ++ goto error; ++ } ++ + if (!group_right_1) { + dest = PyBytes_FromStringAndSize(NULL, len); + if (dest == NULL) diff --git a/meta/recipes-devtools/python/python3/0003-gh-148292-Remove-shutdown-test-in-test_ssl.test_got_eof.patch b/meta/recipes-devtools/python/python3/0003-gh-148292-Remove-shutdown-test-in-test_ssl.test_got_eof.patch new file mode 100644 index 0000000000..af067f549c --- /dev/null +++ b/meta/recipes-devtools/python/python3/0003-gh-148292-Remove-shutdown-test-in-test_ssl.test_got_eof.patch @@ -0,0 +1,41 @@ +From 81911909bc439d6de8ce6a173b0691b3c58e9e1a Mon Sep 17 00:00:00 2001 +From: Victor Stinner +Date: Mon, 4 May 2026 16:20:25 +0200 +Subject: [PATCH] gh-148292: Remove shutdown() test in test_ssl.test_got_eof() + (#149366) + +The shutdown() behavior depends too much on the operating system and +it's unrelated to the got_eof_error change. + +(cherry picked from commit 1e21cf6fee3830012e458c0fe5dbc6fcd45ace92) + +Upstream-Status: Backport [https://github.com/python/cpython/commit/81911909bc43] + +Note: This is from the unmerged CPython PR #149783 which backports +OpenSSL 4.0 support to the 3.14 branch. Upstream deferred merging +until after Python 3.15.1 is released. + +Signed-off-by: Jaipaul Cheernam +--- + Lib/test/test_ssl.py | 8 -------- + 1 file changed, 8 deletions(-) + +diff --git a/Lib/test/test_ssl.py b/Lib/test/test_ssl.py +index 03d9e3f9e5e96b5..6445f122b4272be 100644 +--- a/Lib/test/test_ssl.py ++++ b/Lib/test/test_ssl.py +@@ -4820,14 +4820,6 @@ def test_got_eof(self): + sslsock.do_handshake() + + self.assertEqual(sslsock.pending(), 0) +- try: +- sslsock.shutdown(socket.SHUT_WR) +- except OSError as exc: +- self.assertEqual(exc.errno, errno.ENOTCONN) +- else: +- # On Windows and on OpenSSL 1.1.1, shutdown() doesn't +- # raise an error +- pass + + + @unittest.skipUnless(has_tls_version('TLSv1_3') and ssl.HAS_PHA, diff --git a/meta/recipes-devtools/python/python3_3.14.7.bb b/meta/recipes-devtools/python/python3_3.14.7.bb index 568e632278..18373e5b5e 100644 --- a/meta/recipes-devtools/python/python3_3.14.7.bb +++ b/meta/recipes-devtools/python/python3_3.14.7.bb @@ -22,6 +22,9 @@ SRC_URI = "http://www.python.org/ftp/python/${PV}/Python-${PV}.tar.xz \ file://0001-Avoid-shebang-overflow-on-python-config.py.patch \ file://0001-Update-test_sysconfig-for-posix_user-purelib.patch \ file://0001-prefer-valid-entrypoints.patch \ + file://0001-gh-146207-Add-support-for-OpenSSL-4.0.0.patch \ + file://0002-gh-148292-Update-_ssl._SSLSocket-for-OpenSSL-4.patch \ + file://0003-gh-148292-Remove-shutdown-test-in-test_ssl.test_got_eof.patch \ " SRC_URI:append:class-native = " \ file://0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch \ From patchwork Sat Aug 22 17:51:57 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 96058 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C3E3DC5DF9D for ; Sat, 22 Aug 2026 17:52:19 +0000 (UTC) Received: from DB3PR0202CU003.outbound.protection.outlook.com (DB3PR0202CU003.outbound.protection.outlook.com [52.101.84.1]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1192.1787421126431531265 for ; Sat, 22 Aug 2026 10:52:09 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=s6uYyR6u; spf=pass (domain: est.tech, ip: 52.101.84.1, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=IBNYjpqHHmcV3jqylVRNPmDMaGsWYUZNyEiS6wJD/AES/sNgJMTPjzzsZ8QMxjTa5IDbG7p/BeLjbwR7VK2pRBGLfjfSmWSqZcSoJooK93w/lzsHOtjZOQb5rEq2Q/KFkX4A48Uzj6WbXV4LlCgXl5VPa1W2QDopHx9vdeHh0K104b3lM1aLvByyqeafXX5IsaRaU3J295pQ7hbOGlSPK0oDBz/qrZL9EneYoqrzlTHwEVnaiuno2iHFpl1NcAUmaiq8ueL1e6opEe2wM3+5WySyPyOL54flWxQXRTojlHbROv5S3q+W8sKCsbzdGXz+iPW4ek4jMCy3dYjXUyf4zg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=Onvm+2HAwGnVCooubyR2xkNHb2NYahWb0ZNHGt/iZuo=; b=IhJIxIV+c3+r4OiXFvbX9llpI4inLJwGI7ZhcJcF5tRrYc/aA/OHQa31qcfl4cHAEoFbNuSancDHosswCJpWfF4+pjrbqI83EsuL8KRr94+zp0SKs8GdQv5wzSdL4knmxoNRPwfL6aCZL9rv/nwjMxK/slhKnyii6d5DyF2GhEheyaJ9WmAau+RK7I50oK6GrKfAA0GYsBjsZoncRtg1rSfeX4oQu4C5L/ebqj4xLytca/OCETYO95jPE4SEuq43Ip6t4hagN9w8UWSyWdRetlXxbNl6X6703AIjPf9e7rYU6buYlknhcDK4ECmbngXJRPGsHhyga+CZX6Unre1uDg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Onvm+2HAwGnVCooubyR2xkNHb2NYahWb0ZNHGt/iZuo=; b=s6uYyR6uHdFhSKl49cSE//5hiWvxK6yVjzYfOHYN+KKFNcOZG1q3HdcK9HkIOBtsz8eh4V3NCK4xLwBvCGcYyb/Da8D86ldBi3VF0QIXD692sFx6kgQpc43ZA4C6qLPgp3wQm8FruiyHvVK4PX0zhcr+hdDEZRS1ZCrIdqAO1nKhtqoP3aV99iWRJadgn8JJxYzKjPAkLqjqmBgv4ZGyhI/vZkeWyatBgGoHyeGh8xtCXyHLftdY/fEHr7knaaqKQhWH/itYK1yNRPoOGRUyerrLHY0pWepAB5e+ZrdsIAvOzzuQcoYL/oPyCleJYFdZ32acHGA1xOoKZgpYKD1m2g== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by AM0P189MB0641.EURP189.PROD.OUTLOOK.COM (2603:10a6:208:1a2::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.5; Sat, 22 Aug 2026 17:52:05 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::7ab2:c6af:6760:5c85]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::7ab2:c6af:6760:5c85%7]) with mapi id 15.21.0360.003; Sat, 22 Aug 2026 17:52:05 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [RFC v4 3/6] socat: fix build with OpenSSL 4.0 Date: Sat, 22 Aug 2026 19:51:57 +0200 Message-ID: <20260822175200.57534-4-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260822175200.57534-1-jaipaul.cheernam@est.tech> References: <20260814051829.35088-1-jaipaul.cheernam@est.tech> <20260822175200.57534-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: LO2P123CA0092.GBRP123.PROD.OUTLOOK.COM (2603:10a6:600:139::7) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|AM0P189MB0641:EE_ X-MS-Office365-Filtering-Correlation-Id: 84456ad7-4864-49ba-63e1-08df007613fd X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|10070799003|23010399003|1800799024|376014|366016|6133799003|56012099006|10067099003|11063799006|4143699003|12006099003|22082099003|18002099003; X-Microsoft-Antispam-Message-Info: wu0Gox4+jEGqBLETkinPd0ljIEY0Y9MtBj4h+SiK2hr0Sy5b4DQUNGrBBtsG44QffA5AMCoSnavenDQ1pHtL1nrYbe0LZdBCfcuhcJl8nJS+hrZgmJBXpY1xmjGiBtocipg1p1c6OmLcCXSvzVa9a26rM7QwA0lx/Z66cARP5j+rdSoVEATOIAlFOkWbLMdY69Y69cB5A6Rs3UJ+8m+8Sq1LzEjPWPliyT5sG+wRvyyon/rIX2X0Bwikhl9pK0vV54qb28T63AB6IeVG7fAgykIgGrl4gM7w0iMCRDrzzZy37GA2fzmxqp0O3UwFQvtvtE/gH/fXtILGtf8yKK2zttepm1dvS9cOsljRztvWcPEMH/xmliIMWFcNQ9Az0kWQ+nsYQJDqTo0TDjY/Lj0gd/CcGI/tebeztPf/VuFM5lQDpoQaxMsn9P2OmGy6tb8UAnwx57RkahQriLXvgpaRu4nqqrESpwF//LSN+UbkPSNBGsuCmZHe81k79cNvElCagm4xT6AGbrhhtImzeg3cSsYCjYcF8zMZzuqqbYrVL78ZTDGzwxbiYBm3wEQ6JARi6jxrzrYGpP0xkppR8hx6DLtqrqQfA4jDaZxbvNfmyxKJY+f7kwm6BF+i06aZ1OJifunF6WMEYAJp1GckwfJNz6yzS1meiO6+yWZ8mEoLe5M= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(10070799003)(23010399003)(1800799024)(376014)(366016)(6133799003)(56012099006)(10067099003)(11063799006)(4143699003)(12006099003)(22082099003)(18002099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 2 X-MS-Exchange-AntiSpam-MessageData-0: 1B/1Z68p4ZJoEChjO/3dzAYZvPTGRpj+syx1c8n9MyEVgZbQ88B38tWhjEUWCxEHsxy5tr9ZP6JyBd/VX7+QMS9y31eJAF7qzMSNTXtZVo70OdMXG2avWQujhj/28raaSmHe7KNccqVvUGpkPFj3YOyCcWNHGLNM40eTkYyNGE3SRw0/KjyWMchyum8PYoA0K5yPFRhiOZpMSEt2dOP4X4vqBa4n7BLTNk/98sYZI1RYXC85RKLyItOU8bCSyCwlo6tnimYZYlnFxDp6KGYsYMS72YyaTARjBpxFb3fssFv/Ir3nGIMbtkkI1KdBTKhIWP8X5y1aouuUanqo+ViSbUX6ZeenH9rVkBtNyRFh+woVMlcWvK3F+m/joB8fvS/Sab/WcDpAxMEkHrCUZAGvXwTm2SICgZvfChQociWT3ZkEyHvz5PcqrxR5vUr+vamIqv7SHyRUp36Wm5yLwd8z25a7ShdjYgNiiZmN2jBcjnBZ8zmRwIYAmDVgacgQZXZVowIFTpdIDFvAEGovUC1EFxYDE+PokWcCwZXfAbqjSmyyQF0S5ZjfAXuL8OT+37CZMX5OzpV1Blipt3ksFtQFhM0w7KDBZkraMUHfYXbNC7bgRw4jo+w9J7j5oRhITvlNbvQzgU6edKMI5Akoj6MNYC180ZIy6qTLlfC2/2RAiKKIDSIMwNUUynwE41wpF29JgbvN1z0oELH3IJyk04tc2zgUT/kjMQBIoTCRlCcksf7dQwX7AKarFY+N/WjVuojiDCgBTYAQt2xFJaXdpLcDLHMujChToLOfE326RLGzFlYiDwbN28Qunwr6Lg4rjLW2OfEsIcz92NMo1LBySy7bpZ5Jj3tGWxYztvqrvwEYcbWegXI4pAunuzztqg0b4U65S6C7VwGB1rpTAQ0mI1JZZkdwZTY9X/bUIwXW/VXcpMYhwsfMXFGu8ZnU3Vj/J9y9QdkW0PtPPXEiT7/qfdPxTX2Y6tZrumggpULPkXmhZUtbjmRnFzncBp/+L28dUmAmlE5GLbP8WlpqLg6sBh25/517T6CILJVge9uOS+rpKGTGkNO7WO9+3ozJZPxKTrugjRQyumPCn0mddPiUlKq9ueBpwSfB3NjdUlIl8wkWpGf0LLUNniT3OWgp1X7litfldsrIE4Ei8qcDicX1u638q2P2c1Cuul13r0G8uqQ85CvHFPPgFlJK8c/IpjQTr95d5wGagVf7fo8nQ/tShpqiyQmZiivgvqTWWQ0YZaP2rqdv0dWWVR82MxQqIZf43DN3VwxIpeuL1bni17pZCV33UHGH6J5aa9ydeoJtOObRH0sg1CvLGxVHtQxayxyMD9XKIreE24VpjfKNvSgrfMqy6/FxrehsZ8TYSFsSKjzbRfsd94HPgUpZVGyCoBwqSTSu8ynQEicshfT2SR3DPs3E5JtQddqJ6TDjpBH5MlEAipFFA+rbEwg39qXPZrhEZiVkHTrQ4SD47aNgzxshYXUg1F6fgNqjj6gd+powKJdPFMe99wrCVbNrDAd12dcaegOVRcuU8FTSyHNFaQ0z0v9z6jlhX5u22z23CyVRR5+uYlydz8sd30UpnWfli35FQVxBIE5tptPsfGB0YJ0m1huMtGEmE+AH4rCso2vKcmWX6KLWUk2cMWaVkEVF2GMa+6GvlE+AsG9MpOCm589ExdkeddXmntqfo7Q5JutSsqEmjOp1ve6vPbfwGllLjO+WnFIu7qEtMVsClSlKIJz1j/Y6G0ceVAzNw7OXGlU0Og+h+GX2zj8IUlTdvRVRylDfgWd8rC5Akvkp X-MS-Exchange-AntiSpam-MessageData-1: iH++bCY9O9pmLffRN7x+du3qSsZTlNe9nzA= X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 84456ad7-4864-49ba-63e1-08df007613fd X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 22 Aug 2026 17:52:05.2544 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: JCEeJM2BCFaOYgEaz/CJDfiefUsFx51f+G74ajsgkpFtyF1pVzlZyZdTnzP0DY0Rb2nPTjCsb52wLeX3XthlLrBmnN/pJfmdoCcPnnp8zzE= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM0P189MB0641 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 22 Aug 2026 17:52:19 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/243995 OpenSSL 4.0 made ASN1_STRING opaque. socat directly accesses pName->d.iPAddress->data and pName->d.iPAddress->length which is no longer allowed. Use ASN1_STRING_get0_data() and ASN1_STRING_length() accessor functions instead. These have been available since OpenSSL 1.1.0 so this is backward compatible. Upstream-Status: Submitted [socat@dest-unreach.org] Signed-off-by: Jaipaul Cheernam --- ...penSSL-4.0-use-ASN1_STRING-accessors.patch | 31 +++++++++++++++++++ .../socat/socat_1.8.1.3.bb | 1 + 2 files changed, 32 insertions(+) create mode 100644 meta/recipes-connectivity/socat/files/0001-Fix-build-with-OpenSSL-4.0-use-ASN1_STRING-accessors.patch diff --git a/meta/recipes-connectivity/socat/files/0001-Fix-build-with-OpenSSL-4.0-use-ASN1_STRING-accessors.patch b/meta/recipes-connectivity/socat/files/0001-Fix-build-with-OpenSSL-4.0-use-ASN1_STRING-accessors.patch new file mode 100644 index 0000000000..5e021d66c5 --- /dev/null +++ b/meta/recipes-connectivity/socat/files/0001-Fix-build-with-OpenSSL-4.0-use-ASN1_STRING-accessors.patch @@ -0,0 +1,31 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Jaipaul Cheernam +Date: Thu, 13 Aug 2026 07:00:00 +0000 +Subject: [PATCH] Fix build with OpenSSL 4.0: use ASN1_STRING accessors + +OpenSSL 4.0 made ASN1_STRING opaque. Direct access to struct members +(->data, ->length) is no longer possible. Use the accessor functions +ASN1_STRING_get0_data() and ASN1_STRING_length() instead. + +These accessors have been available since OpenSSL 1.1.0, so this change +is backward compatible. + +Upstream-Status: Submitted [socat@dest-unreach.org] +Signed-off-by: Jaipaul Cheernam +--- + xio-openssl.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +--- a/xio-openssl.c ++++ b/xio-openssl.c +@@ -1898,8 +1898,8 @@ + case GEN_IPADD: + { + /* binary address format */ +- const unsigned char *data = pName->d.iPAddress->data; +- size_t len = pName->d.iPAddress->length; ++ const unsigned char *data = ASN1_STRING_get0_data(pName->d.iPAddress); ++ size_t len = ASN1_STRING_length(pName->d.iPAddress); + char aBuffer[INET6_ADDRSTRLEN]; /* canonical peername */ + struct in6_addr ip6bin; + diff --git a/meta/recipes-connectivity/socat/socat_1.8.1.3.bb b/meta/recipes-connectivity/socat/socat_1.8.1.3.bb index e485c7d28d..025b478392 100644 --- a/meta/recipes-connectivity/socat/socat_1.8.1.3.bb +++ b/meta/recipes-connectivity/socat/socat_1.8.1.3.bb @@ -12,6 +12,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263 \ SRC_URI = "http://www.dest-unreach.org/socat/download/socat-${PV}.tar.bz2 \ file://0001-fix-compile-procan.c-failed.patch \ + file://0001-Fix-build-with-OpenSSL-4.0-use-ASN1_STRING-accessors.patch \ " SRC_URI[sha256sum] = "25bc6476292b2e614220989c77b0b6fca87bb2525d9747b31a6639b1fb602418" From patchwork Sat Aug 22 17:51:58 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 96056 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 98138C5DF8C for ; Sat, 22 Aug 2026 17:52:19 +0000 (UTC) Received: from DB3PR0202CU003.outbound.protection.outlook.com (DB3PR0202CU003.outbound.protection.outlook.com [52.101.84.1]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1192.1787421126431531265 for ; Sat, 22 Aug 2026 10:52:10 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=fRtbqOq3; spf=pass (domain: est.tech, ip: 52.101.84.1, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=uS7hGrRDnV0lY2f6qrhUC0ImHMUB7IV4TlFWC3zwVNAOFMz7TFTk/yRauQneJpok4ySnm77sENCx/1Y3gJj/koWopQ5027Da2yMwRigCFSpGzktWEdGYWgQwCXDSJ5+B8ABFCpHVT/udOOMo2MB76yAnpow1rhj3MiOVuXClTUhXlYkeAJhjNJWADpgW6dOe9E9zLeh6n0ORhxL/vEcKcuaHnbq8y6NbnOG8s6CJWyi6cZReS4rs3SeKHAhBEPCEvJteaqR1KMnNBKhFbaCiCGfKkAmsh6x2f0ECx5VdeXanI7QSGVOaVmqDgg049/ne5B2ZuXFh7ltcCFBJNgENMw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=VnpQqhiTijQD2viIb0eklZ9CPeDOsOv5Wm0kLohqvzY=; b=jeuoqvfkfcgysyS20B24Ql3UYofWsLgnXweRKnFK20Zx3kDmT+aLGY1GA4l1jNjGFlfgpmJxjQCc7ldOUxDOd84aza8HQF3C4dzg4b+30qBg/obwAITIAHxJ9sIw6rrKMKZxnyPlk+3yPLKETXJVuGgjMjeNpOAKCi68MDLXv8H9HGlGhwnye7v6saEuD6z1cD6e9QURMQkKaaLGQo231qheTAtu2lQSGWeu6VPiHIUknVzRGvHisJxiUktPyipv2lyhp0p8upuQ/wU6Ro+Y+RD8FlQupAXfqiNdgbtrSTAjX8TG9tHTP0qKsiR4+rA7gLTAfQrhMSEw2BSPJVaO4w== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=VnpQqhiTijQD2viIb0eklZ9CPeDOsOv5Wm0kLohqvzY=; b=fRtbqOq3H0XNDqrSSy4lfp00HxTKnJ3RnAKnAB2mQ2N3VpIlP1E+1MQqmB4zKXGi4DJh33rjEtvf5z1l/TYNZNKgmDMy9PZcgeooJeakI8wxyoGkyBc5xuB25CuTN47EppvRoyLB/wz/1lzjhywptgG/w+iPnrzDcUZw/5+kqkw0c1PFgcQlKKs9RWPU3lGVzzgKUxWTSy8bEBqeLq0OkBjhFVgU2uHEsADlHjCavGXUj++hKnb3GC1V6vpWeYm/hsuAYCzJOnFHWnAsE+Bd/4OUQXJkm5bYRJJZdGoVwWx7mG+EPTeczeUMJTxHmxEVs7ESbdkutK53/k3JDOvVPQ== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by AM0P189MB0641.EURP189.PROD.OUTLOOK.COM (2603:10a6:208:1a2::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.5; Sat, 22 Aug 2026 17:52:06 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::7ab2:c6af:6760:5c85]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::7ab2:c6af:6760:5c85%7]) with mapi id 15.21.0360.003; Sat, 22 Aug 2026 17:52:06 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [RFC v4 4/6] serf: fix build with OpenSSL 4.0 Date: Sat, 22 Aug 2026 19:51:58 +0200 Message-ID: <20260822175200.57534-5-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260822175200.57534-1-jaipaul.cheernam@est.tech> References: <20260814051829.35088-1-jaipaul.cheernam@est.tech> <20260822175200.57534-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: LO4P123CA0062.GBRP123.PROD.OUTLOOK.COM (2603:10a6:600:153::13) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|AM0P189MB0641:EE_ X-MS-Office365-Filtering-Correlation-Id: 18666f4d-8c18-4a14-0f9a-08df007614b5 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|10070799003|23010399003|1800799024|376014|366016|13003099007|6133799003|56012099006|10067099003|11063799006|4143699003|22082099003|18002099003; X-Microsoft-Antispam-Message-Info: Tpxp2TvhwCUJYOehlV2tRTIC7x4tk/+71ZwtaaMsVOmDCUVZt583VPB8hCkIR4yo3b8t9zPcZ+weSA6fji4PcYx2BcH/kpDn81T0S6kZoUYZuVIDDOkJ3JAj+05k9aPhgqXRFdYFi0ZiZuwH/fuHZSrCLNu6P/eLtFx5UgWw0i89RpxH2dLlh3240jEMMksGPvVNFVB+Qy0ugR+Cu9eTo0kpRJiqoi7mh0SWGnm+8CnAKt/ibZzVaWHS9rFp8Shs9t5MieUiNEI0Ocbz6an5ckpXSCLlc/dqFHmQ/8dPTxQjdONDVRq3/w/PSiPLtaki6hFT/HU/jCzEtFmrlaMZKN1zlUcmscjw2+ZrohEkZM/HbEpaQ6jYe1rq5kWXAP9ZNoq2bFG4X7bYrWQpLnGAaK9qpIamGuCPTFloOMTV9MgwtF9J2Yz4uBCDJrD+E6CywGQzxd3mPH5ffhzkEATLm9jmoG8iMOAPNGv0y7INvV0hFL6GhBWlznpFLq/4CkyWZSe3tS7m3HMC4qW7aCkx/Ed+ll6tV0lEpYymX/DDTbHhmJOBSCr3Ag5NU+Uvgqvn0B46svjVI8/iDAji2BuaNE+PwynEtzvfO8rZvj2XPUwXQ4bJEJRb2ysZ7ThFc85HGn82tXV3nBhJyCxI9fOb+SBsCUX8taL4y+ww1xd+fVM= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(10070799003)(23010399003)(1800799024)(376014)(366016)(13003099007)(6133799003)(56012099006)(10067099003)(11063799006)(4143699003)(22082099003)(18002099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 2 X-MS-Exchange-AntiSpam-MessageData-0: IWNtWKKRdLAUqDHz1xekFhyIkW5qCObOHHCYBTzSNuDbg4lKD+wFl5m0vGtZSl0DBbZiboG0bBFj1+hBu7EwMU2X6FKRjBNBTqax2Pxx3xePygJc2QSBsrNGT8RgZD3g+ekrAISTgBF/v+INaTcB4mLD0/I+57+FscNQJdFhFS8Oz3t3DkjFHPriR4t0FsPKegdwv0+zDn1o5uwk+qk7V3QQEFx2aqlpaCESSMCKr9CyvSfSMF+OU/mCjo4dJGnX92ovNgJC0Oga5YHXrWShVDbeLVU+JAOmzMxT+yISFZll3ep4UeRycLvYcWsyyk96ub9SUYcsEeWgDieClf6LrWcPQfDJb/ogsUgYA+rgUnHJb/Nvb5QQc75PTwLbH4wrM8fN6gEyxzPRgf4N8ruB1KIZi2NUV1FcOi7uQdS3a1Uoe0rZ65XbsGID5/y1t1PWQTeqkAUwkYwtrS1HsDCEfrRxTZmxV1u1zPvKvtE3YI9wylXXNU5mXstPIKY7Kx6yXM5TUeJfu9BqmLvaP/+Ugbmw4uaVY+NgDHprKg5shXM4TQw2tmWLsUWJZUd5AVrLCrKshuibP5UOFg/U8YJT8jtetacs6FkVCoyJaTHFdApjum5ERefhuw7ASM/SNu5eVqFUWhU4qG7ZKdcBDlCvorm+uYEggaeD+1nGJvjTc3O9b3az3JDJ4hcvYo2vtULR+gpYVzuwUhVlVelwk0hr5wh9geRrdJfgFxpAE3cmEtunZaBTGziAyU2iXr8ydzEXeWHcFw00hgNBpWcYrE7paGBMlH0cEqRplt20TZy7wTB9j4PnGpwdWrsR2nqo4UePWGjwP78XqSs2pMZpofd6EG1HNx4C0v1awoVK2O3fI28aZbjTjOmQI7NeW+hhf8q0k6eA/7g+n8aV1b9Yf3WBcvgQe+R0Pi3WwvIBFpkkxJy8XRyTlcjH/kO+OP7nAVYL9SHdGYv5u+ZpaX8A+7Srmv97guw2DnNDa7S7dGDSyDigI8ML3wIhkPj1X5/lMKa3t0MZdowglwU7WUAyc+4jto3lNDCfg75DjmXm0eY3Sjx8q6fCEeFxJLPGaS/JGLyj35c1gGyOpjTfSbLEmR6GOc2u3IwaypDLU/pTMqNG1OLedjfj+N4QtTo5SmMGxBFS8rN+2mburfgUqtmVn0dy3tGQEnm54rKmFwN7Cd/ZQHLXbUsfEVK0QLnzTDJtRo/dmlRq4EUxG2X18lqBuCiQoRL2E/+yRGCqLyiuJkFmHsNYB5Sa4mzvaJ4WLaO67LeZus7LevV43kD9dKQ0+MoaOW8EaGPSgJJyzJ1uuM3kj05GE/9byN8KFF6xiueIupUsEicXP7drz46KaGHpnQG7rpLbbp5vRNdPA3iYRfgo4Z9NxKXRbF1C4svpnKzuI3RC6JuvjCJAahKqabxA3HRUGNXRd8qmEI/w9Cyk9I+EF8rqFpnAwgX5T6mgZyIQQZJnT/du3IiMj7GFlei1MF9tcG8FLVCJjdIxssctmGBo5fjacUObySd4Y6C/2LX4h8C70bEudh7yfUD+bjzkRQnmrFEsKg/SGeuR9K0vqA7d2hmeafKX8BcETvHFa3p8CkkxanPEKhhhfuUMS2iy7dJe6qrdlpt2O+UckoVoEn2khrQZKh8eQOqC474PTgK7N8aySiMSU+Wr5ri20sobRJ7I3i/supw88dEUzgLqgbDFu9/lm1GTxL9X0O5QGOHk9iCws6NwA0f5LDCj5WrCO3GeQCdBEYkqTmNsoeWGKl/0wmYZ4ZIHMksHujLD6lJMYtUb8wPl8xfi X-MS-Exchange-AntiSpam-MessageData-1: FO8SKCyb/fcmqLwAc6iBaBXvQqUyoVlXR64= X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 18666f4d-8c18-4a14-0f9a-08df007614b5 X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 22 Aug 2026 17:52:06.4735 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: F+528EJfGG6E9JfbuQopAz8sEApKMTYjOl+vcbkz7+3eGPSi4acIlzVsS40KU45QXSHvXSZTq4fWmkkNTHinC/bU+rq7oDNFpR1fgSByhOs= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM0P189MB0641 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 22 Aug 2026 17:52:19 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/243996 OpenSSL 4.0 made ASN1_STRING opaque. serf directly accesses nm->d.ia5->data and nm->d.ia5->length which is no longer allowed. Use ASN1_STRING_get0_data() and ASN1_STRING_length() accessor functions instead. These have been available since OpenSSL 1.1.0 so this is backward compatible. The fix is already in serf trunk (r1935023) but no new release has been made. Upstream-Status: Backport [https://svn.apache.org/repos/asf/serf/trunk r1935023] Signed-off-by: Jaipaul Cheernam --- ...penSSL-4.0-use-ASN1_STRING-accessors.patch | 35 +++++++++++++++++++ meta/recipes-support/serf/serf_1.3.10.bb | 1 + 2 files changed, 36 insertions(+) create mode 100644 meta/recipes-support/serf/serf/0001-Fix-build-with-OpenSSL-4.0-use-ASN1_STRING-accessors.patch diff --git a/meta/recipes-support/serf/serf/0001-Fix-build-with-OpenSSL-4.0-use-ASN1_STRING-accessors.patch b/meta/recipes-support/serf/serf/0001-Fix-build-with-OpenSSL-4.0-use-ASN1_STRING-accessors.patch new file mode 100644 index 0000000000..2392cf1dca --- /dev/null +++ b/meta/recipes-support/serf/serf/0001-Fix-build-with-OpenSSL-4.0-use-ASN1_STRING-accessors.patch @@ -0,0 +1,35 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Jaipaul Cheernam +Date: Thu, 13 Aug 2026 11:52:00 +0000 +Subject: [PATCH] Fix build with OpenSSL 4.0: use ASN1_STRING accessors + +OpenSSL 4.0 made ASN1_STRING opaque. Direct access to struct members +(->data, ->length) is no longer possible. Use the accessor functions +ASN1_STRING_get0_data() and ASN1_STRING_length() instead. + +These accessors have been available since OpenSSL 1.1.0, so this change +is backward compatible. + +Upstream-Status: Backport [https://svn.apache.org/repos/asf/serf/trunk r1935023] +Signed-off-by: Jaipaul Cheernam +--- + buckets/ssl_buckets.c | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +--- a/buckets/ssl_buckets.c ++++ b/buckets/ssl_buckets.c +@@ -567,11 +567,11 @@ + switch (nm->type) { + case GEN_DNS: + if (copy_action == ErrorOnNul && +- strlen(nm->d.ia5->data) != nm->d.ia5->length) ++ strlen((const char *)ASN1_STRING_get0_data(nm->d.ia5)) != (size_t)ASN1_STRING_length(nm->d.ia5)) + return SERF_ERROR_SSL_CERT_FAILED; + if (san_arr && *san_arr) +- p = pstrdup_escape_nul_bytes((const char *)nm->d.ia5->data, +- nm->d.ia5->length, ++ p = pstrdup_escape_nul_bytes((const char *)ASN1_STRING_get0_data(nm->d.ia5), ++ ASN1_STRING_length(nm->d.ia5), + pool); + break; + default: diff --git a/meta/recipes-support/serf/serf_1.3.10.bb b/meta/recipes-support/serf/serf_1.3.10.bb index c6b51452aa..fd3560876b 100644 --- a/meta/recipes-support/serf/serf_1.3.10.bb +++ b/meta/recipes-support/serf/serf_1.3.10.bb @@ -10,6 +10,7 @@ SRC_URI = "${APACHE_MIRROR}/${BPN}/${BPN}-${PV}.tar.bz2 \ file://0002-SConstruct-Fix-path-quoting-for-.def-generator.patch \ file://0003-gen_def.patch \ file://SConstruct.stop.creating.directories.without.sandbox-install.prefix.patch \ + file://0001-Fix-build-with-OpenSSL-4.0-use-ASN1_STRING-accessors.patch \ " SRC_URI[sha256sum] = "be81ef08baa2516ecda76a77adf7def7bc3227eeb578b9a33b45f7b41dc064e6" From patchwork Sat Aug 22 17:51:59 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 96057 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A9C0BC5DF97 for ; Sat, 22 Aug 2026 17:52:19 +0000 (UTC) Received: from DB3PR0202CU003.outbound.protection.outlook.com (DB3PR0202CU003.outbound.protection.outlook.com [52.101.84.1]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1192.1787421126431531265 for ; Sat, 22 Aug 2026 10:52:10 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=yWlMqlgE; spf=pass (domain: est.tech, ip: 52.101.84.1, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=Zb3QxApBx81UJ4DFCI1OWZ37g9N8ohzGw4NVnabL8AOOE/yN2YAUcjEWydYp6bUndUtp46qFRkg5h5vKfhJaJpVc9QJqmTOlBB8E5qh6D0XDHhJpV9rxHVA9UVhTqBm1kmZQqfa0CSux1vQ9OQUwHJ0/JJdOH+In2mpDThDoLP/t/kz1CAX5DxdmnNFH4/7ydk+c8FoU/YDyAZz1K8+JEGHDrAQUkXXdcebWR5yP6h6wAW6coQ48C/HK76Tq0iea3pfvgIvmTHrfZ/AwEtg74xgU88c1m5z/lDbm96WYA1HgAaULkwQGehWDYNFyZpfxvoTZ5RvU4daMsnVovPRacA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=rM8g/I3zMrwx6Qs9f0f97J6CzZtP7ajQdNI3kOIaRBE=; b=DimQTPSDVz277pKLfgb/uLJaa3NftQF376dnLoTx1lntlOZU8MMeNrUjffuP0qYOcvOIXfeAXMDuYYwoAim7q7JWU8TgIOf1s/QOhIr2ldjKL4sQftTNNIjBhTCHZGrlZgjEYm09oguVQm++sIdksm+eYvoqmArDpQys63NaIA2bE0LTh40GOA5psV49awJgR88jBuQ3kuj9N8Rqm8JR8JdfkOUXFJk6gBzcwkfcM40k8BeNwgfizaJEM7rgUpuo1iLg1vxxVUv19phlHYhyz0nwvVjF9Vj3BfWiphntIV3BfmOqvXaTDBlk4Em35HfYuTz19W2E8Xtt5JBEveN38A== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=rM8g/I3zMrwx6Qs9f0f97J6CzZtP7ajQdNI3kOIaRBE=; b=yWlMqlgEs+VlD973lVjesuaVl/f8HwZiIgO9CXPC3fXKy7nXjEzPjo7gCe/0o5pfDpUVgTAEZ8O1P6vxu1uCtS0nAeCIiPD8nndcAyJg3v7rcyUuYV1soDfHTe56p10lxdWYguwGs1i1UHW9+ycYK4P/occuakpf5KGII/dXIUeIIDdCmgg43RmOtDgywc4zsVnw1UQ5hfPVKBEcY9jd7KDNZaer9Fs4TL4cs1OmIuIWekVWcjk7gNAEY9Osq3DZALXhLlB4cV6JiYCPperZXXMWFy9dHhmfmWbhcBJ4AmLifUFQVU9Mlln/m8KyHE3ngy3tVuJmmKK2+Ed0+DAxhA== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by AM0P189MB0641.EURP189.PROD.OUTLOOK.COM (2603:10a6:208:1a2::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.5; Sat, 22 Aug 2026 17:52:08 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::7ab2:c6af:6760:5c85]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::7ab2:c6af:6760:5c85%7]) with mapi id 15.21.0360.003; Sat, 22 Aug 2026 17:52:07 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [RFC v4 5/6] u-boot: fix build with OpenSSL 4.0 Date: Sat, 22 Aug 2026 19:51:59 +0200 Message-ID: <20260822175200.57534-6-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260822175200.57534-1-jaipaul.cheernam@est.tech> References: <20260814051829.35088-1-jaipaul.cheernam@est.tech> <20260822175200.57534-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: LO6P123CA0026.GBRP123.PROD.OUTLOOK.COM (2603:10a6:600:313::17) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|AM0P189MB0641:EE_ X-MS-Office365-Filtering-Correlation-Id: b96c0988-ff80-4814-cb03-08df00761561 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|10070799003|23010399003|1800799024|376014|366016|13003099007|6133799003|3023799007|56012099006|10067099003|11063799006|4143699003|22082099003|18002099003; X-Microsoft-Antispam-Message-Info: RiIaUc7OqImqCboS2PQzAx0Fd/NWmR6IqzOD0GKjZlPrJI7yyEKUPEOiEsBD2WDHZ8zWAhi6lZg3vaapJp2r35rO563MLUiGVaWfzPH53HQ/aGsa9vO006qpRApYsKgRt2HYaAUb8hqEt4rAM5XeW6WPS7EkOJAGK+PRbX7ur4A8O7XO6rVLyVW54qoqsqOcdsXzV+lo/ZCK0Rkyeh99WziiOSXfqlBCObNHfm8PT4yHDS+exfUwkmZ61NrBkevuT6k/K839mydZUtAcFGCkLK13eqFVUVfYtkY0idSA+jnF9HXsN0Xn3SOjLrWvuBmbhYYICuNRBlxoYhW7brq5uquCSlcyprvqOJamrgmI274T4EzXrczh3f6ugvfdU/Ub/H9vJxNp9A264KMTDOdUbrD8+jG1IM4av5NMyapgEqkx8GiZU4f9AzAy2KjqFiPd4yD1koWN1eswSAMBULXQyAT4yIy5Oukjdq6UVcKL/by3SWVjjtO7S/60SfUEQuJMQ3REfZ8H6IK3Zpt4B7wJ3Sp6OHVQpvWuWlbaeMlj6XPYEw5EroCfO+KIFd8EtedmHqXAAGAcTU79DPlhx8o9MmpMSWS7SqQ15Wh4bjjQQTEsmINILhRYfIXzv9+5sP9jh2voDZ+rxdtTILS5kF8YAUolUtekNALymsrDdpAWdkI= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(10070799003)(23010399003)(1800799024)(376014)(366016)(13003099007)(6133799003)(3023799007)(56012099006)(10067099003)(11063799006)(4143699003)(22082099003)(18002099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 2 X-MS-Exchange-AntiSpam-MessageData-0: TgcqNU/MPD4X2lA4Cc4NUrciq17dqd/PxKIZn5Pkhwt66JPwMpCk67oagm636A/DPAEEEsbSpw+s5h3L4r93zm9CNse+muCbjj5qcMSXpRqgYOB1dlPwMiA9PRCn7xmfKy7ZNYcutUg6wnPdmiBjjTJmgN1E+7R8KvEZXIJJnJ1PY0KprYwYWirKhCn0EUjHz5k8sarcF+ndIusjeYLTe4Q5s+V8OPHWjqM9MQMHHK1fcGrBRX/C4OW4CLZQeTeLF9l1QVtG8le6/1F/Tq7atkH7EFgnqo8qtQtWzhmDcQ6gCe25v3OsImo4Wg5kXUsqnK9ZS7KTUPf+1qYJIpVLTJ9CbJxKw1PWlye/w1w4IR9mE4jxucalQv0ai5Ymd7tw7hwNlCTFIOc1jAkc0XoavpkE/O9DEF82kB4h1WU4NiwIEnRaob7MQAYBpQJCz2mOOPfeHlGaoHyijF7sqP7aECuNtHZCzC9SDEsYykT8Qgakhcl/OfUUNOVHpg8piNWI9gNhSulVwtkViFc74FTly968P1EO/8t5oL3kIz+Vl8D1rbcFmzQPTV88Ykf6ad1ZhuJvNUNV4GFGCkM5Sfqo8c7Dcl4cTPq3aEpu771cgojJjP2LFCUAAs8Zx4RX4gxLQwZewAr5lBmLm2h8T4EFTeamkDYU4bKDnAvDFt3kq65dwYeJSsQPSOkwhHbSZqyrljrFPGanI4gu4LC3AHdOlnjB50UFmVYcLNAAw/B09IwpNlaC30CwvBJVhi/xxztWkyEQq4Mh+l0MAyTSnYtMyJPftpz518J2iQya2W9E63ogqfXMX2Uc+kgTvm8SDBLQueLAQtKpaCpcUWlLCCvZRpex/ZRVtB5cKjCtcEnPQ2Ko8EBX+IAUov0ZCYy6t2y8GRy3f0EpSA466zGt32t5xFJwnt43DpqkOevaZ4FJ8B+/8mUqk+qqsEUzsrYJEQqUXGcJredODqA5q1v1ncJkctuxEFf6gvMwnI5WyEVhzLNOHt1DVK9KArUBNe4g6EpSfBL7cg3ngzcd2ky6LgatkCKGVIA/gzqAmFXW3FWONe/bNxFGOhmGDKUrzxt2oNuCrLcjIvWeJkuTqJmT8PNlMsIOtpqZRFigBK9gD3Xy7ASswy9I7oHF/9I+pHa5Fo4PMBlmW6bb9CNADFtrOWjcPnbn+tlcy29LtDf8+YrrjgCZ7NvcbZe2rinL7h00Bnr+qlVjPEAdHzyELYnO/wAKOMX0rf0CRUz3eYY6vEsT7ILOOU07gDJIl6iauSXuoA+xEiVmQfqeuaTiteegTZKrcwgZ3gg09ceiDafgAXFWQpv10pYK3UPhDa+62hY9cAfPPAwSulqicJLWGMphDApVD4c16OVCEdr44FE2v6eE/M5Vmep5hoQ19qyQKWiQ5LJYb46EFh+Fe3NcNr4p7xexUiS/tO016unsC0Gdinhc0vD5/L2VfjVaSOWp9BqGDMPPbmsCTUGxs8UgGi5dHZ0MK/phiuqWZX7kTPteqtZmpRWLGnRR/8OU7pmt9MaZv6TqpT2h6qscyqyCIIMPhNHIBXMN20PDRy2CPR4w6csg29OL5R2K/mCaYfF8WUOZE8Jl/E29gPo0oBvE484P0XZtv4rC/HHeL5lENfLjG2IoJSfK6sJMhfsZpG0FrZkLbp93lxn3q8NtYAH1bZntVbOAeAUigXJf5lcfSEJ5N8pKgktqOVBAj2Rm1GRPOHQqJIPmJCTNvV3Wn05EF+l1uOhCIi3yxzewl8pWiLQh9CbzV+AddtX4+EFQNfsoKnOt/bsAaWNFeHmU X-MS-Exchange-AntiSpam-MessageData-1: IqXychWUVy+VYfwwpxp40Lq3tBkR51Y/xrg= X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: b96c0988-ff80-4814-cb03-08df00761561 X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 22 Aug 2026 17:52:07.5641 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: AdnwkBpruXuczoCnOH0BBJ4yuYM98eQoOKdxKDTQiVzeHxE9whiFHWEO9zY2EQiuC17CZrlJj4kvWkgR+K7rSrsiLTj2up/wvXPKY+57aBo= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM0P189MB0641 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 22 Aug 2026 17:52:19 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/243997 OpenSSL 4.0 removed the ENGINE API entirely. u-boot uses ENGINE_get_id, ENGINE_load_public_key, ENGINE_finish, ENGINE_free in lib/rsa/rsa-sign.c which causes link failures on all platforms that build u-boot (including riscv64). Backport the Provider API support patch from upstream u-boot which adds OpenSSL Provider support while maintaining backward compatibility with older OpenSSL versions that still have ENGINE. Add the patch to u-boot-common.inc so it applies to both u-boot and u-boot-tools recipes. Upstream-Status: Submitted [https://lore.kernel.org/u-boot/20260429180247.83091-1-ekovsky@redhat.com/] Signed-off-by: Jaipaul Cheernam --- ...Add-support-for-OpenSSL-Provider-API.patch | 340 ++++++++++++++++++ meta/recipes-bsp/u-boot/u-boot-common.inc | 1 + 2 files changed, 341 insertions(+) create mode 100644 meta/recipes-bsp/u-boot/files/0001-Add-support-for-OpenSSL-Provider-API.patch diff --git a/meta/recipes-bsp/u-boot/files/0001-Add-support-for-OpenSSL-Provider-API.patch b/meta/recipes-bsp/u-boot/files/0001-Add-support-for-OpenSSL-Provider-API.patch new file mode 100644 index 0000000000..346d0584d5 --- /dev/null +++ b/meta/recipes-bsp/u-boot/files/0001-Add-support-for-OpenSSL-Provider-API.patch @@ -0,0 +1,340 @@ +From a81cb0932dce109af44d7245d47489fe54ae390f Mon Sep 17 00:00:00 2001 +From: Eddie Kovsky +Date: Mon, 23 Feb 2026 09:43:22 -0700 +Subject: [PATCH] Add support for OpenSSL Provider API + +The Engine API has been deprecated since the release of OpenSSL 3.0. End +users have been advised to migrate to the new Provider interface. +Several distributions have already removed support for engines, which is +preventing U-Boot from being compiled in those environments. + +Add support for the Provider API while continuing to support the existing +Engine API on distros shipping older releases of OpenSSL. + +This is based on similar work contributed by Jan Stancek updating Linux +to use the Provider interface. + + commit 558bdc45dfb2669e1741384a0c80be9c82fa052c + Author: Jan Stancek + Date: Fri Sep 20 19:52:48 2024 +0300 + + sign-file,extract-cert: use pkcs11 provider for OPENSSL MAJOR >= 3 + +The changes have been tested with the FIT signature verification vboot +tests on Fedora 42 and Debian 13. All 30 tests pass with both the legacy +Engine library installed and with the Provider API. + +Signed-off-by: Eddie Kovsky + +Upstream-Status: Submitted [https://lore.kernel.org/u-boot/20260429180247.83091-1-ekovsky@redhat.com/] + +Note: Modified to make pkcs11 provider loading optional. The upstream +patch unconditionally requires the pkcs11 provider, which is not +available in the OE build environment. File-based key signing only needs +the default provider; pkcs11 is only required for pkcs11: URI keys. +Changes from upstream: + - Load default provider first (was pkcs11 first) + - Make pkcs11 provider load failure non-fatal (ERR_clear_error instead + of ERR(1, ...) which calls errx/abort) + +Signed-off-by: Jaipaul Cheernam +--- + doc/build/gcc.rst | 4 +- + lib/aes/aes-encrypt.c | 4 +- + lib/rsa/rsa-sign.c | 102 +++++++++++++++++++++++++++++++++++++++--- + tools/docker/Dockerfile | 1 + + 4 files changed, 103 insertions(+), 8 deletions(-) + +diff --git a/doc/build/gcc.rst b/doc/build/gcc.rst +index 1fef718ceecb..29a6a632e7e3 100644 +--- a/doc/build/gcc.rst ++++ b/doc/build/gcc.rst +@@ -25,8 +25,8 @@ Depending on the build targets further packages maybe needed + + sudo apt-get install bc bison build-essential coccinelle \ + device-tree-compiler dfu-util efitools flex gdisk graphviz imagemagick \ +- libgnutls28-dev libguestfs-tools libncurses-dev \ +- libpython3-dev libsdl2-dev libssl-dev lz4 lzma lzma-alone openssl \ ++ libgnutls28-dev libguestfs-tools libncurses-dev libpython3-dev \ ++ libsdl2-dev libssl-dev lz4 lzma lzma-alone openssl pkcs11-provider \ + pkg-config python3 python3-asteval python3-coverage python3-filelock \ + python3-pkg-resources python3-pycryptodome python3-pyelftools \ + python3-pytest python3-pytest-xdist python3-sphinxcontrib.apidoc \ +diff --git a/lib/aes/aes-encrypt.c b/lib/aes/aes-encrypt.c +index 90e1407b4f09..4fc4ce232478 100644 +--- a/lib/aes/aes-encrypt.c ++++ b/lib/aes/aes-encrypt.c +@@ -16,7 +16,9 @@ + #include + #include + #include +-#include ++#if !defined(OPENSSL_NO_ENGINE) && !defined(OPENSSL_NO_DEPRECATED_3_0) ++# include ++#endif + #include + + #if OPENSSL_VERSION_NUMBER >= 0x10000000L +diff --git a/lib/rsa/rsa-sign.c b/lib/rsa/rsa-sign.c +index 0e38c9e802fd..f456f3c58e65 100644 +--- a/lib/rsa/rsa-sign.c ++++ b/lib/rsa/rsa-sign.c +@@ -19,7 +19,47 @@ + #include + #include + #include +-#include ++#if OPENSSL_VERSION_MAJOR >= 3 ++# define USE_PKCS11_PROVIDER ++# include ++# include ++# include ++#else ++# if !defined(OPENSSL_NO_ENGINE) && !defined(OPENSSL_NO_DEPRECATED_3_0) ++# define USE_PKCS11_ENGINE ++# include ++# endif ++#endif ++ ++#ifdef USE_PKCS11_PROVIDER ++#define ERR(cond, fmt, ...) \ ++ do { \ ++ bool __cond = (cond); \ ++ drain_openssl_errors(__LINE__, 0); \ ++ if (__cond) { \ ++ errx(1, fmt, ## __VA_ARGS__); \ ++ } \ ++ } while (0) ++ ++static void drain_openssl_errors(int l, int silent) ++{ ++ const char *file; ++ char buf[120]; ++ int e, line; ++ ++ if (ERR_peek_error() == 0) ++ return; ++ if (!silent) ++ fprintf(stderr, "At main.c:%d:\n", l); ++ ++ while ((e = ERR_peek_error_line(&file, &line))) { ++ ERR_error_string(e, buf); ++ if (!silent) ++ fprintf(stderr, "- SSL %s: %s:%d\n", buf, file, line); ++ ERR_get_error(); ++ } ++} ++#endif + + static int rsa_err(const char *msg) + { +@@ -94,10 +134,11 @@ static int rsa_pem_get_pub_key(const char *keydir, const char *name, EVP_PKEY ** + * + * @keydir: Key prefix + * @name Name of key +- * @engine Engine to use ++ * @engine Engine to use or NULL when using pkcs11 provider + * @evpp Returns EVP_PKEY object, or NULL on failure + * Return: 0 if ok, -ve on error (in which case *evpp will be set to NULL) + */ ++#ifdef USE_PKCS11_ENGINE + static int rsa_engine_get_pub_key(const char *keydir, const char *name, + ENGINE *engine, EVP_PKEY **evpp) + { +@@ -157,21 +198,24 @@ static int rsa_engine_get_pub_key(const char *keydir, const char *name, + + return 0; + } ++#endif + + /** + * rsa_get_pub_key() - read a public key + * + * @keydir: Directory containing the key (PEM file) or key prefix (engine) + * @name Name of key file (will have a .crt extension) +- * @engine Engine to use ++ * @engine Engine to use or NULL when using pkcs11 provider + * @evpp Returns EVP_PKEY object, or NULL on failure + * Return: 0 if ok, -ve on error (in which case *evpp will be set to NULL) + */ + static int rsa_get_pub_key(const char *keydir, const char *name, + ENGINE *engine, EVP_PKEY **evpp) + { ++#ifdef USE_PKCS11_ENGINE + if (engine) + return rsa_engine_get_pub_key(keydir, name, engine, evpp); ++#endif + return rsa_pem_get_pub_key(keydir, name, evpp); + } + +@@ -207,13 +251,45 @@ static int rsa_pem_get_priv_key(const char *keydir, const char *name, + return -ENOENT; + } + ++#ifdef USE_PKCS11_PROVIDER ++ EVP_PKEY *private_key = NULL; ++ OSSL_STORE_CTX *store; ++ ++ if (!OSSL_PROVIDER_try_load(NULL, "default", true)) ++ ERR(1, "OSSL_PROVIDER_try_load(default)"); ++ /* pkcs11 provider is optional; only needed for pkcs11: URIs */ ++ if (!OSSL_PROVIDER_try_load(NULL, "pkcs11", true)) ++ ERR_clear_error(); ++ ++ store = OSSL_STORE_open(path, NULL, NULL, NULL, NULL); ++ ERR(!store, "OSSL_STORE_open"); ++ ++ while (!OSSL_STORE_eof(store)) { ++ OSSL_STORE_INFO *info = OSSL_STORE_load(store); ++ ++ if (!info) { ++ drain_openssl_errors(__LINE__, 0); ++ continue; ++ } ++ if (OSSL_STORE_INFO_get_type(info) == OSSL_STORE_INFO_PKEY) { ++ private_key = OSSL_STORE_INFO_get1_PKEY(info); ++ ERR(!private_key, "OSSL_STORE_INFO_get1_PKEY"); ++ } ++ OSSL_STORE_INFO_free(info); ++ if (private_key) ++ break; ++ } ++ OSSL_STORE_close(store); ++ ++ *evpp = private_key; ++#else + if (!PEM_read_PrivateKey(f, evpp, NULL, path)) { + rsa_err("Failure reading private key"); + fclose(f); + return -EPROTO; + } + fclose(f); +- ++#endif + return 0; + } + +@@ -226,6 +301,7 @@ static int rsa_pem_get_priv_key(const char *keydir, const char *name, + * @evpp Returns EVP_PKEY object, or NULL on failure + * Return: 0 if ok, -ve on error (in which case *evpp will be set to NULL) + */ ++#ifdef USE_PKCS11_ENGINE + static int rsa_engine_get_priv_key(const char *keydir, const char *name, + const char *keyfile, + ENGINE *engine, EVP_PKEY **evpp) +@@ -293,22 +369,25 @@ static int rsa_engine_get_priv_key(const char *keydir, const char *name, + + return 0; + } ++#endif + + /** + * rsa_get_priv_key() - read a private key + * + * @keydir: Directory containing the key (PEM file) or key prefix (engine) + * @name Name of key +- * @engine Engine to use for signing ++ * @engine Engine to use or NULL when using pkcs11 provider + * @evpp Returns EVP_PKEY object, or NULL on failure + * Return: 0 if ok, -ve on error (in which case *evpp will be set to NULL) + */ + static int rsa_get_priv_key(const char *keydir, const char *name, + const char *keyfile, ENGINE *engine, EVP_PKEY **evpp) + { ++#ifdef USE_PKCS11_ENGINE + if (engine) + return rsa_engine_get_priv_key(keydir, name, keyfile, engine, + evpp); ++#endif + return rsa_pem_get_priv_key(keydir, name, keyfile, evpp); + } + +@@ -325,6 +404,7 @@ static int rsa_init(void) + return 0; + } + ++#ifdef USE_PKCS11_ENGINE + static int rsa_engine_init(const char *engine_id, ENGINE **pe) + { + const char *key_pass; +@@ -380,6 +460,7 @@ static void rsa_engine_remove(ENGINE *e) + ENGINE_free(e); + } + } ++#endif + + static int rsa_sign_with_key(EVP_PKEY *pkey, struct padding_algo *padding_algo, + struct checksum_algo *checksum_algo, +@@ -480,11 +561,13 @@ int rsa_sign(struct image_sign_info *info, + if (ret) + return ret; + ++#ifdef USE_PKCS11_ENGINE + if (info->engine_id) { + ret = rsa_engine_init(info->engine_id, &e); + if (ret) + return ret; + } ++#endif + + ret = rsa_get_priv_key(info->keydir, info->keyname, info->keyfile, + e, &pkey); +@@ -496,16 +579,21 @@ int rsa_sign(struct image_sign_info *info, + goto err_sign; + + EVP_PKEY_free(pkey); ++ ++#ifdef USE_PKCS11_ENGINE + if (info->engine_id) + rsa_engine_remove(e); ++#endif + + return ret; + + err_sign: + EVP_PKEY_free(pkey); + err_priv: ++#ifdef USE_PKCS11_ENGINE + if (info->engine_id) + rsa_engine_remove(e); ++#endif + return ret; + } + +@@ -645,11 +733,13 @@ int rsa_add_verify_data(struct image_sign_info *info, void *keydest) + ENGINE *e = NULL; + + debug("%s: Getting verification data\n", __func__); ++#ifdef USE_PKCS11_ENGINE + if (info->engine_id) { + ret = rsa_engine_init(info->engine_id, &e); + if (ret) + return ret; + } ++#endif + ret = rsa_get_pub_key(info->keydir, info->keyname, e, &pkey); + if (ret) + goto err_get_pub_key; +@@ -726,8 +816,10 @@ int rsa_add_verify_data(struct image_sign_info *info, void *keydest) + err_get_params: + EVP_PKEY_free(pkey); + err_get_pub_key: ++#ifdef USE_PKCS11_ENGINE + if (info->engine_id) + rsa_engine_remove(e); ++#endif + + if (ret) + return ret; +diff --git a/tools/docker/Dockerfile b/tools/docker/Dockerfile +index 73bf6cdd2c52..50e98e83dc20 100644 +--- a/tools/docker/Dockerfile ++++ b/tools/docker/Dockerfile +@@ -122,6 +122,7 @@ RUN --mount=type=cache,target=/var/cache/apt,sharing=locked \ + openssl \ + picocom \ + parted \ ++ pkcs11-provider \ + pkg-config \ + python-is-python3 \ + python3 \ diff --git a/meta/recipes-bsp/u-boot/u-boot-common.inc b/meta/recipes-bsp/u-boot/u-boot-common.inc index d82d42cbce..7fce65191b 100644 --- a/meta/recipes-bsp/u-boot/u-boot-common.inc +++ b/meta/recipes-bsp/u-boot/u-boot-common.inc @@ -16,6 +16,7 @@ SRCREV = "ece349ade2973e220f524ce59e59711cc919263f" SRC_URI = "git://git.u-boot-project.org/u-boot/u-boot.git;protocol=https;branch=main;tag=v${PV} \ file://0001-pylibfdt-Replace-removed-SWIG-Python-2-compatibility.patch \ + file://0001-Add-support-for-OpenSSL-Provider-API.patch \ " B = "${WORKDIR}/build" From patchwork Sat Aug 22 17:52:00 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 96059 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B6240C5DF98 for ; Sat, 22 Aug 2026 17:52:19 +0000 (UTC) Received: from DB3PR0202CU003.outbound.protection.outlook.com (DB3PR0202CU003.outbound.protection.outlook.com [52.101.84.1]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1192.1787421126431531265 for ; Sat, 22 Aug 2026 10:52:11 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=ah/lme0n; spf=pass (domain: est.tech, ip: 52.101.84.1, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=tJge165T/f4HSg5mv/fxTrrWjIiq92LKY9X4sfllfwh/Ln5jc/Zak26di3hGVVaD6ac9xudHRrIavbutFhc1bzHmDtdG2QeXjgv7S7HzBqF/4zq2lIOEuyNzP0we1L+fN+9Pp4F2WUgK1PDXVfdW8cq9YPluz+gOwRVCGHYWi9SX0PgSIo/SA1pBln9qxMd8wig1Z1Sa9GkF64PGQp8dLbHvOuAEMYRSVH0xhhYan3VHxBTlsI5dOYB8xDTviGbp9ZJTExsEfqJaz6FvFNcmcGvvwcqnyVKW8R4OG5twy7R/rfkHRigAbHD56oDIm6xRA7CeGYlZX7l6QYRE/QOepA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=zplzsuv2OUODJV5kcEAHxIxK2x7+1plMsrQxxCndatg=; b=jZ23xCfA6NT6ZWEM0sKd3UC9pTqH0V0SZRt4qJh1CVupDG9aY23E6sPZ9lFBjrhWDqRjGA4ynaeWC81fXh9I/yyLryLb04xINuKoDEptaG+fFti8YFT/xu7XGWUGf+1coTX1u3qiGeRQq3TpXvNgnSs1Fvk1n9TTCxzoIQ+mV0gf8OS/kiRvCiGKJcto8rrvwcR6omQZYdRwAH2jJ6hVC/8190TXcN7HqWzCP+4BPrbpFUR89uLsn7Ucw1+eFoyNCgY9/UUKiuWtjzDTn1ef45gk6PmfTkmqpgDB8TDhW2SIuFwh/3NaIDeSHRqvR3mZ4ib1TSMsiYzF8K/eWILj4A== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=zplzsuv2OUODJV5kcEAHxIxK2x7+1plMsrQxxCndatg=; b=ah/lme0nlW4mXVtWEYfqEzRoQTJL0vP0TAenlLjLcOWIowRCTzl4TrvKEUAtXYN1iWiqlmtsLWRmdDm3xgiUv2b+92dCzcwikYgjrux9yMkCoUwF7g2tz6hANAMqo7Z9MdRCibBUtMfFkZcbNN0LAswPUs2rXUjaWpqPwLU/0QEhaaH2xQlpRtRzdtSeF0PJOOdJdx3J4QGlXxFBEgDrPVryBpNFKiJcW4JaOC8ynb1j/A8oTY/IhWmBIZGV1sD1+TEMu7nIsNN5ltPd+TwWUap1XQlDXBM2Ho/9L42P4LLrmwaGp8K7VTlZ8y8c0rvL5s8mitHcr6wL++j4qwLMUw== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by AM0P189MB0641.EURP189.PROD.OUTLOOK.COM (2603:10a6:208:1a2::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.5; Sat, 22 Aug 2026 17:52:08 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::7ab2:c6af:6760:5c85]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::7ab2:c6af:6760:5c85%7]) with mapi id 15.21.0360.003; Sat, 22 Aug 2026 17:52:08 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [RFC v4 6/6] kea: fix build with OpenSSL 4.0 Date: Sat, 22 Aug 2026 19:52:00 +0200 Message-ID: <20260822175200.57534-7-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260822175200.57534-1-jaipaul.cheernam@est.tech> References: <20260814051829.35088-1-jaipaul.cheernam@est.tech> <20260822175200.57534-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: LO6P123CA0017.GBRP123.PROD.OUTLOOK.COM (2603:10a6:600:313::7) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|AM0P189MB0641:EE_ X-MS-Office365-Filtering-Correlation-Id: b2d9ede6-cf0a-4c2f-ee4c-08df0076160e X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|10070799003|23010399003|1800799024|376014|366016|13003099007|6133799003|56012099006|10067099003|11063799006|4143699003|12006099003|22082099003|18002099003; X-Microsoft-Antispam-Message-Info: 3Kqp+e3qhjj5WmPjCaKkGqp3mpCdqp8ZvWvl/zhMEJu+xyAmHW015KrP3uxYOdgMVUwiM74XonsJWd3iEQZ7ISlJGxIPFVN+2UYpJqvUE644PSeR7xpstKEycARYt0ak02blt6pjKZ29k5p6zoWVTEH2wt8425lAk20T9X6Do5ShK6vi4Z/VYcyGKmcwjiTFiWpm9YQp00xZHHIkasz02gDxMpnowbtplFNEGmTSCeIwLLCcB5mmEmV/Q3X4i3B9OXWIVIaXFcS0FEiGRh1KyL27O0dnnfdr1F7C9jskKnmjzPIxMIuKCU0lIpZcOu3BKmGTKIuoh6+MAZpELzT7A4HM8NGAEnr9KKa5JOTS0as6n0v9x4IKQ2xmyU2wJwDpct+YuPvTA/OC4ztO6p02MU/Eu9ynGyy9AFC7nVfvQsxN9bhe2zmtvFSXzzaN7vN357DUarCq3Z78loi+BeZMjyR8XC01UJZTKXFqhUi6ZhG9N2px+9oAqjeX0b3NMrbDy0IVIEp4G2XHIOrcWTXsCAsyw63ThFfRj4ssvHfb7V7vSa+gx4f0e6JfRGtxLb/NE9qFk6KLa0p2Sok/AW+mC31YmTnzIvV5Wu4mqRfUMKiwN1U8Fd4Mmsc3T/ioUaqs X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(10070799003)(23010399003)(1800799024)(376014)(366016)(13003099007)(6133799003)(56012099006)(10067099003)(11063799006)(4143699003)(12006099003)(22082099003)(18002099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 2 X-MS-Exchange-AntiSpam-MessageData-0: xnTJTqF7M7D9CNfoi1wScx4oLboJaGLjShYhsFrnGykuXTEvv0Ql73NqjP37BIerSWVUoBIZrRn4yd3wzbXKd3pDZM8CGBc8IhwO1b7SnlzuRScH8JY8N2AQRsEDnukuOmqVnBVtjesNFJmwQPlp50o+Vr1SR4FLQu0nf/9EomaT64y8VlsS8DK0lRnPHGInCPXlO46wX7neQIQ27UUv7uUfnvoeiMQYHSM2KG1GB3lXXM3dWDz2JAG5VGIMPlwCx1sf7CE156GceP0Lf8gIy61FWMeubnZe4G77H7ct2WazOl2Hq/wZDcjxeR/S6c7s7Ksd3r7f7rF72mi+uMDh9X/EDZKPLTzU9tfKQ6KJKKZ/wTqiAdznKIZ7sLV3kmawOxQxE16Xad6iZlFrOqrs8eAMOuvQ4dCDEsmhWeMOWRq7AsrH36/3DXnBjrbYD80k3LFTwrE1zdINr/Ofl6f2osNGQXDVv3mdGZPCh6rF1HBamXoRZw10pywfltcjHIN0bme3EQwsFqNHi5LNRKsp3yO4TvoU5YWykCyFnYzDqAE3N+Vr7lDRFFwzVyAhjVMNb4C8hSpzN3KD8eFtPf4OzD5ifhH+mI8/mrw7Il4KHCxzO4ljqsMzXVPdwUiI5vjKFIGmuBlXmGL9yfvOjFnFJ9rYLUxpwh3pNcoEYtuDZrm+5aTEytgNoHuznl8eGo4sATlngnBEvubxjyBVe2qvcxbBwa1wYT/OYEo2fBUc0O57bdqU8N9ZBCgRihJvYASqJEkevjKkGrdO27QFfIqb0ITpqviVQnvT3WRP16Y0wiOsipVDUwy8jMUucOGMq8FM96H40SAuyfZYkfKmK3XTpR6xHlXAqk2gjyLCIl/cKxvdQKy3amU5V2V3qSJvQ3M+kTRSsrNFmxlVTc3xCtBlHTFhm9oDFMliI0HPX1heI7Ql9NfbcYv1Ul7XVxiQPMmvHGa/2iLCFzJfm9RhlT/3KbahVG5N8KxW2tUnf3S7xJmOSYeOzdeNAbzKi+fJfBf3yoxv3um45bH8l3IbXd6+PAXPDovdbpy8kB5lFNBRNzqiMIiCjPIDS4aL2zdm5BFuRqmPLJkhNqfs2MMKsE4t4oqi7y+rWtaJDBBfEVhixYsIUMd8pV30WS6S1iNTGixWzPkTXZBXtCjl3t9xibM0fx5FtJHzDyYdjrizz3pRayLTXtIuoV4DvypO+GDP2bHbsU66IubBgArKT8jr/MGpPsInLTZLuvyKZQRRbXub92n2rinL4sa00ioAgDI/94HhuOyqEMfEdn5pFC9fU/2N6SrwH9ALTyb7MBWFgKEkBd+3YlobH5ybNd0ZBTxVmomXjF7HkogR0rCf4N637X+dp65Z2xR6YwLYaoHW3jOZN7pRSYm3k19ITGHYcMwcjtLHbycyQ3BYtd9pOSMb8RYiGYsV0YN0BBgoHpeEsfBCL+YV7RLs/P3W5a3mmFt/q1xTZqUrjId9/60oubzfz5R+tRjaoi+we203GTa98xfSNSJjX2k/CC7W+4eUSg/9Xk9jTIIphVBtbky2HHKkWdfdgwJN+X7VuIlml9yhZk1+ZqL7lY6F+A/a8svQEsAUf1AbHAK2lweBaxbhC6Ie0xYPjUoxtCqlahpxVufKclO+KEI1GHMO0nYptJzFXCt0jgAM6V8S7IiB5EayiwetmhKa4Sju6rio+fri3QDLK9v6YHiGSwM1kqnHSZXO3dj5itBfDwuHpL4cBHr9oBUhJGVHKQCeUSu/BxzMPlVBDBAgdhs79nlDhHyx1fzdq5HqmLRWclcAeKY/ X-MS-Exchange-AntiSpam-MessageData-1: izgfVbHXDJ2vAoLxbssa1fnTZL9CpWTn6GI= X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: b2d9ede6-cf0a-4c2f-ee4c-08df0076160e X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 22 Aug 2026 17:52:08.7098 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: 8PhGtT8XxkZgiEz5u7A/FBH1rylpHvw+oYD0ygvei88cGe24yqVfk2QpsHtQOBHQmY8QaZ/b+Ya4oJ6FlWMQKjlGdfFm5O2Tqn9xOkXXRaY= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM0P189MB0641 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 22 Aug 2026 17:52:19 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/243998 OpenSSL 4.0 adds const qualifiers to the return type of X509_get_issuer_name() and X509_get_subject_name(). This causes compilation failures in Kea's TLS code which assigns these to non-const pointers. Add patch to use const-qualified pointers matching the new OpenSSL 4.0 API. Upstream-Status: Submitted [https://gitlab.isc.org/isc-projects/kea/-/issues/4673] Signed-off-by: Jaipaul Cheernam --- ...-qualifiers-to-OpenSSL-X509-pointers.patch | 49 +++++++++++++++++++ meta/recipes-connectivity/kea/kea_3.2.0.bb | 1 + 2 files changed, 50 insertions(+) create mode 100644 meta/recipes-connectivity/kea/files/0001-Add-const-qualifiers-to-OpenSSL-X509-pointers.patch diff --git a/meta/recipes-connectivity/kea/files/0001-Add-const-qualifiers-to-OpenSSL-X509-pointers.patch b/meta/recipes-connectivity/kea/files/0001-Add-const-qualifiers-to-OpenSSL-X509-pointers.patch new file mode 100644 index 0000000000..987890f4ff --- /dev/null +++ b/meta/recipes-connectivity/kea/files/0001-Add-const-qualifiers-to-OpenSSL-X509-pointers.patch @@ -0,0 +1,49 @@ +From 82d28b1be73bbc00e73e59d0c59c51a1e76519a5 Mon Sep 17 00:00:00 2001 +From: Simo Sorce +Date: Mon, 27 Apr 2026 17:49:56 -0400 +Subject: [PATCH] Add const qualifiers to OpenSSL X509 pointers + +Added const qualifiers to the X509_NAME and X509_NAME_ENTRY pointers when +retrieving subject and issuer names from TLS certificates. This ensures const- +correctness and maintains compatibility with newer OpenSSL versions, which +return const pointers from these getter functions. + +Signed-off-by: Simo Sorce + +Upstream-Status: Submitted [https://gitlab.isc.org/isc-projects/kea/-/issues/4673] +Signed-off-by: Jaipaul Cheernam +--- + src/lib/asiolink/openssl_tls.h | 8 ++++---- + 1 file changed, 4 insertions(+), 4 deletions(-) + +diff --git a/src/lib/asiolink/openssl_tls.h b/src/lib/asiolink/openssl_tls.h +index 57c3323..52a969b 100644 +--- a/src/lib/asiolink/openssl_tls.h ++++ b/src/lib/asiolink/openssl_tls.h +@@ -175,9 +175,9 @@ public: + if (!cert) { + return (""); + } +- ::X509_NAME *name = ::X509_get_subject_name(cert); ++ const ::X509_NAME *name = ::X509_get_subject_name(cert); + int loc = ::X509_NAME_get_index_by_NID(name, NID_commonName, -1); +- ::X509_NAME_ENTRY* ne = ::X509_NAME_get_entry(name, loc); ++ const ::X509_NAME_ENTRY* ne = ::X509_NAME_get_entry(name, loc); + if (!ne) { + ::X509_free(cert); + return (""); +@@ -209,9 +209,9 @@ public: + if (!cert) { + return (""); + } +- ::X509_NAME *name = ::X509_get_issuer_name(cert); ++ const ::X509_NAME *name = ::X509_get_issuer_name(cert); + int loc = ::X509_NAME_get_index_by_NID(name, NID_commonName, -1); +- ::X509_NAME_ENTRY* ne = ::X509_NAME_get_entry(name, loc); ++ const ::X509_NAME_ENTRY* ne = ::X509_NAME_get_entry(name, loc); + if (!ne) { + ::X509_free(cert); + return (""); +-- +2.53.0 + diff --git a/meta/recipes-connectivity/kea/kea_3.2.0.bb b/meta/recipes-connectivity/kea/kea_3.2.0.bb index feeacc8883..38b24eed1f 100644 --- a/meta/recipes-connectivity/kea/kea_3.2.0.bb +++ b/meta/recipes-connectivity/kea/kea_3.2.0.bb @@ -19,6 +19,7 @@ SRC_URI = "http://ftp.isc.org/isc/kea/${PV}/${BP}.tar.xz \ file://0001-src-lib-log-logger_unittest_support.cc-do-not-write-.patch \ file://0001-meson-use-a-runtime-safe-interpreter-string.patch \ file://0001-mk_cfgrpt.sh-strip-prefixes.patch \ + file://0001-Add-const-qualifiers-to-OpenSSL-X509-pointers.patch \ " SRC_URI[sha256sum] = "14bf695d37b65b9b1bf550fea5d0adaf9806c50e5419ef2a176a4b8e9aade3df"