From patchwork Fri Sep 11 14:17:50 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Khem Raj X-Patchwork-Id: 97957 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 01021C88E45 for ; Fri, 11 Sep 2026 14:18:05 +0000 (UTC) Received: from mail-pg1-f181.google.com (mail-pg1-f181.google.com [209.85.215.181]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.40605.1789136280255713343 for ; Fri, 11 Sep 2026 07:18:00 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=jX+qglYA; spf=pass (domain: gmail.com, ip: 209.85.215.181, mailfrom: raj.khem@gmail.com) Received: by mail-pg1-f181.google.com with SMTP id 41be03b00d2f7-c96c92c0980so742108a12.3 for ; Fri, 11 Sep 2026 07:18:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789136280; x=1789741080; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=n00U1zb927CwnuY9ZMVzZaCQhjWgRphwfOhlb4Jfaw4=; b=jX+qglYAumRMgJuhbvDUUmgZQN9iCWzcnF7H4zB3sHi61Wkc+c9ibiCaQtocEUZjYc vDisj+hjMlR1kBB7NEdvSTNTtBhfpkxa1X1Ly3o9AoOvsjfOZ/QWn8JK6FDiEwT2EcLs gddrsIcpYZ/1DKKLqOaIhH7u3rL9+xk0E/vAzWrgIhJNYP+ZloAF6K9F50NZlIpBfAz2 v7ILg/6oL+cE45u8E4THn5x/fUVjDZQ9BjI+RuvzvlIYeyIUOWFyxz3f4XhFg7o99K/i na8F+Ip+5KNCayZne9PEeAeVgG7G2ybVQgk/zdu8JCOFDvZ2Njd1XqlfXDIyCKbWLcmF aEVA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789136280; x=1789741080; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=n00U1zb927CwnuY9ZMVzZaCQhjWgRphwfOhlb4Jfaw4=; b=ihfn0L+DKCZ3UmTBcDp909UTntc8ZTtbHTuH3QNNOhL8nLKeeO52wbDwqbDnTUbBQ3 0I6B1/BXTgayt0KtHwnXcMjX0yUlR7Oj8CR/AreM0drFTaeK94RD7M6dw7ij02XiumZO 6K5HWM0uAmzvLt+3BWOlr+qv6cq/W1wLYlfW+18+tYWDKz3bMLeLJ47EiVWL77+yhPSQ DAeiKPDrQDWX7YhHfuX27Qz8UdL2nQF/Pq1pS18TSjeDfOtyt9xoxkXEb1cWBRxlXVQW FOmgf57FyDpAHdLl/C9ECvYKE0Olh0zFYyAyFlv3aHWrcBkP6khjOJLkk0EEsh75Y4rE 7nxg== X-Gm-Message-State: AFuF++nwPYAA1WmqqWcuDUPKmLI1AmFNtBV/goqBPOiA3PJESRij5CvI 6EbovDfRcuSRmFNe73unKj4RgRmbh6NwTLFboJSPENJ89e5Od3bACj2lwXJAlw== X-Gm-Gg: AYBFou0B+aCX4TdqAt47WfNvijAxl1DymJ8YFmgg4IQADM0sA9lC+TnD3BjL1yZ9GMS SL61/R0YgySwpDKIJUBkS1k/7k9DUS8DEkZNmaRkxT/ABjvug2UOqDd5spTpC/40p/4NODXeFpU BJyW2FW25Q0sG98nmImNJm3j9COcI2hbFwsrNrXMMdynXAi2UHzzAqYe/FQumqz3nhEVLb91LIJ pUG6HjQNZplwak5F/qy0ItjBUqEDXTuE9bRR4XfaN9X9psJb7/IFv7HJYao119IRs02JUhjeQ4F 4/Lwqkoj2loQgDqmEThJowjikx306p9etUcK7OGOxxGU9E2rgPCUXCoY5JlPta0s0umu68Tw3ZW KQ6rnvaab/hBt20Q0sRAndHq65k0qrp11xitR4EdpqeDG+HIrz1ciIKBUBRp7d8oXaFA3c3Db9/ StvmPfLAF3smlYubya3iCxY6VkWPQFUlzSYoS48Xh6cvHF8jULLoNbRF7QOMwkw31XkHx1w86Ug rU1byy4xSnpopYmbkiL4SB//dOXV3hdBWoy6nMHyRm5TZyzKbrQtlitlWMiIzuE6FnI9lsfYRZE oyrhVTUmdxr4/VclGCotF0f6+JBJ1KzXNL3/3g3XJOdEgCrblbXrn8Lqt7W1XstIIsIRhzr1fMX T+03VlJMlwXs7FSgSDV8/x6xxUwb1yj8EBkbxdKpC8dCHGTflhxznduOKwQ== X-Received: by 2002:a17:90b:4a8b:b0:38f:240d:b857 with SMTP id 98e67ed59e1d1-39d9bbc81cfmr6952566a91.2.1789136279386; Fri, 11 Sep 2026 07:17:59 -0700 (PDT) Received: from apollo.localdomain ([208.95.233.74]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33ba4fa50efsm7840791eec.28.2026.09.11.07.17.58 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 07:17:58 -0700 (PDT) From: Khem Raj X-Google-Original-From: Khem Raj To: openembedded-devel@lists.openembedded.org Cc: Khem Raj Subject: [meta-oe][PATCH 1/7] bit7z: Fix build with clang Date: Fri, 11 Sep 2026 07:17:50 -0700 Message-ID: <20260911141756.2275517-1-khem.raj@oss.qualcomm.com> X-Mailer: git-send-email 2.55.0 MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 11 Sep 2026 14:18:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129965 The 4.1.0 upgrade added two CXXFLAGS that only work with GCC, which breaks the clang build of the testsuite (BIT7Z_WARNINGS_AS_ERRORS defaults to BIT7Z_BUILD_TESTS, so -Werror is on whenever ptest is enabled). error: unknown warning option '-Wno-sfinae-incomplete'; did you mean '-Wno-delete-incomplete'? [-Werror,-Wunknown-warning-option] -Wsfinae-incomplete is a GCC 15+ diagnostic that clang does not have, so only pass it when building with GCC. cpm_cache/ghc_filesystem/include/ghc/filesystem.hpp:4090:41: error: implicit conversion changes signedness: 'int' to 'mode_t' (aka 'unsigned int') [-Werror,-Wsign-conversion] Upstream declares the ghc::filesystem include directory as a SYSTEM one (target_include_directories(ghc_filesystem SYSTEM INTERFACE ...) in cmake/Dependencies.cmake), which keeps warnings from that header quiet. Passing it as a plain -I undoes that, so use -isystem instead. There is nothing to upgrade to here, 4.1.0 is the latest release and upstream master is a single documentation commit ahead of it. Signed-off-by: Khem Raj --- meta-oe/recipes-extended/7zip/bit7z_4.1.0.bb | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/meta-oe/recipes-extended/7zip/bit7z_4.1.0.bb b/meta-oe/recipes-extended/7zip/bit7z_4.1.0.bb index 4661046220..5f0b65b3cc 100644 --- a/meta-oe/recipes-extended/7zip/bit7z_4.1.0.bb +++ b/meta-oe/recipes-extended/7zip/bit7z_4.1.0.bb @@ -35,8 +35,15 @@ DEPENDS = "7zip" EXTRA_OECMAKE += "-DBIT7Z_CUSTOM_7ZIP_PATH=${STAGING_INCDIR}/7zip" -CXXFLAGS:append = " -Wno-error=array-bounds -Wno-sfinae-incomplete" -CXXFLAGS:append = " -I${B}/cpm_cache/ghc_filesystem/include" +CXXFLAGS:append = " -Wno-error=array-bounds" +# -Wsfinae-incomplete is a GCC 15+ diagnostic, clang does not know the option +# and errors out on it because the testsuite build enables -Werror. +CXXFLAGS:append:toolchain-gcc = " -Wno-sfinae-incomplete" +# Use -isystem, the same way upstream declares this include directory +# (target_include_directories(ghc_filesystem SYSTEM INTERFACE ...) in +# cmake/Dependencies.cmake). With a plain -I the warnings coming out of +# ghc/filesystem.hpp are reported and the testsuite build enables -Werror. +CXXFLAGS:append = " -isystem ${B}/cpm_cache/ghc_filesystem/include" PACKAGECONFIG ??= "${@bb.utils.contains('PTEST_ENABLED', '1', 'tests', '', d)}" PACKAGECONFIG[tests] = " \ From patchwork Fri Sep 11 14:17:51 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Khem Raj X-Patchwork-Id: 97958 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 19A2AC88E50 for ; Fri, 11 Sep 2026 14:18:05 +0000 (UTC) Received: from mail-pj2-f12.google.com (mail-pj2-f12.google.com [74.125.227.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.40460.1789136281390972164 for ; Fri, 11 Sep 2026 07:18:01 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=hH0UPboH; spf=pass (domain: gmail.com, ip: 74.125.227.140, mailfrom: raj.khem@gmail.com) Received: by mail-pj2-f12.google.com with SMTP id 98e67ed59e1d1-396ccafb74fso1019116a91.3 for ; Fri, 11 Sep 2026 07:18:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789136281; x=1789741081; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=EfMn2B1KnFC9wKMzv5L27zNPBV5Ft3muxWdtG77H6FY=; b=hH0UPboHYcQLm1xACmkqjrFfl8rWTmrkFnnuZ9+m0pchWu3rzd6XCFLeE+7AzFsKMd V5IhyufPC/nIN2N+bVDXiTAkoTemiZDZh/m1eb1XzYonI0tj6iGELmVmop47hMMyy5gT Htzc2maurDYJHy2Hn4a+kxu8qKYWopsOqr8XbgTGWjavx2e70dFFTqeBtrLc3xFWGvSP k3nXOZvC5vJXn2F6rnd4z4YbSl8pqEtTGmqbBOkJeRrvgK0CcBK7LScbpav7lINn3r79 STe1pxBEdNIawtS4mPteDlCSeOitnVbpNEYob3QLk++8D6McqBIzARDDOIcE4dLRLj2L gSwA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789136281; x=1789741081; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=EfMn2B1KnFC9wKMzv5L27zNPBV5Ft3muxWdtG77H6FY=; b=kmKNTI6Ec5138rPQ9oiEvxsIKels0KcVCjCIVWmTCxalEZF0gA+/YTCtBKlRNlzsac nSih8K5M+IpO05z6poGPbQjy/qreY/363WPqqzAO6WA/CtrB+dqaaMsVLcdBSpzPf+QT qjdDMwNtWW8hZXXzvF0g/rCLzgYiL1hf1wqh1MuQZvqLXcwy2dMnSGRlk9WRjOefU33b COL7onzeAHtrESP6aRmE+DmqqRzYPvfYMT/UW7jHvi4i1aT/yXd9AkoOtzMHbPkhNZHS 3iGlEN2pVjrLNApBYxDsxooISBt8jAo8kP7uho+wxolO+lVNIVrSFz6x4DXyqla3h1+H 4DYg== X-Gm-Message-State: AFuF++l4Cu5YZcvDDDjQbEZKDY0vm15jbuJGP+5alq9tlZcT6vvJgYmT ue+h5GVXyEOJblyemYaCELhJBI4DreXWnHiQryQuRVW87eopYcyOMHDCRdtpIg== X-Gm-Gg: AYBFou3MvRvmz4hMxBOh8MwZI1hMED3zCAGFIYcNDWgU9O1Y7duMMZ0wJTJgzh+oLQk EX/WKqj7l19Al9pToJooRHxY763b4EYlwAYeKcBvS8rR0tIczvdlFbEGGOkMSboUizeNJVXHIYN natarWXPERjoG44BVPm8CeojRm+pqnWNuJVYJxwkXK2e4LL9ZFalv5hKLRlmS9eqe97yrQTtSCi HzgPe8Qcr1APgGUNNRixpLfIPBQnjM3BsvQ3VkRr8L5DSkMo7l3FTX9OZrtQZDS+/Ggipm6jL1V ke7VYr+KLmmWYjaiOMT+1MTVIPMhUgTxA+vN0plpklVEJsy3nK+NdmiZN84tQ+uGX3SbQD3BOBZ xqeKINHdid0Zx946VgtaVKBisZo4655tEj0y3sAt6S8jP5KEva5GrRGvFXUAGUUI6WHQzZDqc6J eNXk7VbV1RJEZr6GpbM6pYjsGTauU6LlEhs/9NNc2WEeAyXCvs7BLoTj3oMXHbg6AoT/dlHiuCo mT7F+GRZEPq5hlc+KGaSgDYfqB5NqiR/4pDDbrYGTncOBJ5qi50oILfgSqg77SdhQBEKzTYa7Ga WWvglB/X3lZE7PHxadXiprujTHWmdLNyDqsX/auDXbOsczRzKCal9zOzQH6plbyjjrxoPoSYGCn 9RIzXdXOPFru6sg3Uiykzm9qfzLfwKIlbiApzHyv5GA== X-Received: by 2002:a17:90b:4fc2:b0:381:6c5:3f63 with SMTP id 98e67ed59e1d1-39d9bc42d1bmr8546157a91.6.1789136280495; Fri, 11 Sep 2026 07:18:00 -0700 (PDT) Received: from apollo.localdomain ([208.95.233.74]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33ba4fa50efsm7840791eec.28.2026.09.11.07.17.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 07:18:00 -0700 (PDT) From: Khem Raj X-Google-Original-From: Khem Raj To: openembedded-devel@lists.openembedded.org Cc: Khem Raj , Khem Raj Subject: [meta-gnome][PATCH 2/7] gnome-disk-utility: fix build without x11 in DISTRO_FEATURES Date: Fri, 11 Sep 2026 07:17:51 -0700 Message-ID: <20260911141756.2275517-2-khem.raj@oss.qualcomm.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260911141756.2275517-1-khem.raj@oss.qualcomm.com> References: <20260911141756.2275517-1-khem.raj@oss.qualcomm.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 11 Sep 2026 14:18:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129966 gnome-disk-utility 46.1 fails to build on a wayland-only distro configuration (no x11 in DISTRO_FEATURES) for three separate reasons, all of them latent X11 assumptions in the GTK3 code line. do_configure fails first: Run-time dependency libcanberra-gtk3 found: NO (tried pkg-config) meson.build:75:18: ERROR: Dependency "libcanberra-gtk3" not found meson.build requires libcanberra-gtk3 unconditionally, but libcanberra's gtk3 support is itself X11-only (its configure.ac does PKG_CHECK_MODULES(GTK3, [gtk+-3.0 ... gdk-3.0 x11]), the sources use gdk_x11_get_xatom_by_name_for_display()/GDK_WINDOW_XID, and libcanberra-gtk3.pc links -lX11), so the meta-oe recipe correctly leaves the gtk3 PACKAGECONFIG off here and the dependency can never be satisfied. Drop it, along with the three ca_gtk_play_for_widget() sound effect call sites; upstream removed libcanberra entirely by the same route after 46.1 was released. Once that is out of the way do_compile fails on the X11 backend header: gdupasswordstrengthwidget.c:14:10: fatal error: 'gdk/gdkx.h' file not found gduvolumegrid.c:14:10: fatal error: 'gdk/gdkx.h' file not found gduestimator.c:14:10: fatal error: 'gdk/gdkx.h' file not found gtk+3 only installs gdk/gdkx.h when its X11 backend is enabled. None of these three files calls any X11-specific GDK API, so the include is simply dead weight and can be dropped. Neither fix is available upstream for this code line: the GTK4 / libadwaita rewrite deleted or renamed the affected files rather than fixing them, and no in-flight merge request touches the GTK3 sources that 46.1 still builds. 46.1 remains the latest stable release. AI-Generated: Uses Claude Code Signed-off-by: Khem Raj --- ...Drop-the-libcanberra-gtk3-dependency.patch | 122 ++++++++++++++++++ ...s-drop-the-unused-gdk-gdkx.h-include.patch | 68 ++++++++++ .../gnome-disk-utility_46.1.bb | 5 +- 3 files changed, 194 insertions(+), 1 deletion(-) create mode 100644 meta-gnome/dynamic-layers/meta-multimedia/recipes-gnome/gnome-disk-utility/gnome-disk-utility/0001-Drop-the-libcanberra-gtk3-dependency.patch create mode 100644 meta-gnome/dynamic-layers/meta-multimedia/recipes-gnome/gnome-disk-utility/gnome-disk-utility/0002-disks-drop-the-unused-gdk-gdkx.h-include.patch diff --git a/meta-gnome/dynamic-layers/meta-multimedia/recipes-gnome/gnome-disk-utility/gnome-disk-utility/0001-Drop-the-libcanberra-gtk3-dependency.patch b/meta-gnome/dynamic-layers/meta-multimedia/recipes-gnome/gnome-disk-utility/gnome-disk-utility/0001-Drop-the-libcanberra-gtk3-dependency.patch new file mode 100644 index 0000000000..a7a4ed6d5f --- /dev/null +++ b/meta-gnome/dynamic-layers/meta-multimedia/recipes-gnome/gnome-disk-utility/gnome-disk-utility/0001-Drop-the-libcanberra-gtk3-dependency.patch @@ -0,0 +1,122 @@ +From: Khem Raj +Date: Wed, 10 Sep 2026 06:00:00 +0000 +Subject: [PATCH] Drop the libcanberra-gtk3 dependency + +libcanberra-gtk3 links -lX11 and its gtk3 module is built only when +X11 is enabled (configure.ac gates HAVE_GTK3 on `gdk-3.0 x11`), so it +is unavailable on wayland-only distro configurations. That makes +gnome-disk-utility's hard `dependency('libcanberra-gtk3', ...)` fail +at meson configure time there: + + Run-time dependency libcanberra-gtk3 found: NO (tried pkg-config) + ../gnome-disk-utility-46.1/meson.build:75:18: ERROR: Dependency + "libcanberra-gtk3" not found (tried pkg-config) + +Upstream reached the same conclusion and dropped libcanberra +entirely ahead of the GTK4/libadwaita port (GNOME/gnome-disk-utility! +efa67dc5, !ecdd9c37, !ec6d8018), disabling the three sound-effect call +sites and removing the dependency; that work landed after 46.1, the +last stable release, so backport the same, minimal change here rather +than carrying libcanberra-gtk3 as a hard requirement. + +Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/gnome-disk-utility/-/commit/ec6d801899e440245319cdbb06555783b72808d1] +Signed-off-by: Khem Raj +--- + meson.build | 1 - + src/disks/gducreatediskimagedialog.c | 12 ++++-------- + src/disks/gdurestorediskimagedialog.c | 8 +++----- + src/disks/meson.build | 1 - + 4 files changed, 7 insertions(+), 15 deletions(-) + +diff --git a/meson.build b/meson.build +index 1111111..2222222 100644 +--- a/meson.build ++++ b/meson.build +@@ -72,7 +72,6 @@ dvdread_dep = dependency('dvdread', version: '>= 4.2.0') + gio_unix_dep = dependency('gio-unix-2.0', version: '>= 2.31.0') + gmodule_dep = dependency('gmodule-2.0') + gtk_dep = dependency('gtk+-3.0', version: '>= 3.16.0') +-libcanberra_dep = dependency('libcanberra-gtk3', version: '>= 0.1') + # Keep the version here synchronised with subprojects/libhandy.wrap + libhandy_dep = dependency('libhandy-1', version: '>= 1.5.0', fallback: ['libhandy', 'libhandy_dep']) + liblzma_dep = dependency('liblzma', version: '>= 5.0.5') +diff --git a/src/disks/gducreatediskimagedialog.c b/src/disks/gducreatediskimagedialog.c +index 1111111..2222222 100644 +--- a/src/disks/gducreatediskimagedialog.c ++++ b/src/disks/gducreatediskimagedialog.c +@@ -20,8 +20,6 @@ + #include + #include + +-#include +- + #include "gduapplication.h" + #include "gduwindow.h" + #include "gducreatediskimagedialog.h" +@@ -304,10 +302,9 @@ play_read_error_sound (DialogData *data) + * CA_PROP_EVENT_DESCRIPTION + */ + sound_message = _("Disk image read error"); +- ca_gtk_play_for_widget (GTK_WIDGET (data->window), 0, +- CA_PROP_EVENT_ID, "dialog-warning", +- CA_PROP_EVENT_DESCRIPTION, sound_message, +- NULL); ++ /* libcanberra-gtk3 is X11-only and unavailable on wayland-only builds; ++ * disabled upstream too (GNOME!ec6d8018) ahead of the GTK4 port. */ ++ (void) sound_message; + } + + /* ---------------------------------------------------------------------------------------------------- */ +@@ -407,10 +404,9 @@ play_complete_sound (DialogData *data) + + /* Translators: A descriptive string for the 'complete' sound, see CA_PROP_EVENT_DESCRIPTION */ + sound_message = _("Disk image copying complete"); +- ca_gtk_play_for_widget (GTK_WIDGET (data->window), 0, +- CA_PROP_EVENT_ID, "complete", +- CA_PROP_EVENT_DESCRIPTION, sound_message, +- NULL); ++ /* libcanberra-gtk3 is X11-only and unavailable on wayland-only builds; ++ * disabled upstream too (GNOME!ec6d8018) ahead of the GTK4 port. */ ++ (void) sound_message; + } + + /* ---------------------------------------------------------------------------------------------------- */ +diff --git a/src/disks/gdurestorediskimagedialog.c b/src/disks/gdurestorediskimagedialog.c +index 1111111..2222222 100644 +--- a/src/disks/gdurestorediskimagedialog.c ++++ b/src/disks/gdurestorediskimagedialog.c +@@ -16,8 +16,6 @@ + #include + #include + +-#include +- + #include "gduapplication.h" + #include "gduwindow.h" + #include "gdurestorediskimagedialog.h" +@@ -610,10 +608,9 @@ play_complete_sound (DialogData *data) + + /* Translators: A descriptive string for the 'complete' sound, see CA_PROP_EVENT_DESCRIPTION */ + sound_message = _("Disk image copying complete"); +- ca_gtk_play_for_widget (GTK_WIDGET (data->dialog), 0, +- CA_PROP_EVENT_ID, "complete", +- CA_PROP_EVENT_DESCRIPTION, sound_message, +- NULL); ++ /* libcanberra-gtk3 is X11-only and unavailable on wayland-only builds; ++ * disabled upstream too (GNOME!ec6d8018) ahead of the GTK4 port. */ ++ (void) sound_message; + + if (data->inhibit_cookie > 0) + { +diff --git a/src/disks/meson.build b/src/disks/meson.build +index 1111111..2222222 100644 +--- a/src/disks/meson.build ++++ b/src/disks/meson.build +@@ -83,7 +83,6 @@ deps = [ + dvdread_dep, + gio_unix_dep, + gmodule_dep, +- libcanberra_dep, + libgdu_dep, + libhandy_dep, + liblzma_dep, diff --git a/meta-gnome/dynamic-layers/meta-multimedia/recipes-gnome/gnome-disk-utility/gnome-disk-utility/0002-disks-drop-the-unused-gdk-gdkx.h-include.patch b/meta-gnome/dynamic-layers/meta-multimedia/recipes-gnome/gnome-disk-utility/gnome-disk-utility/0002-disks-drop-the-unused-gdk-gdkx.h-include.patch new file mode 100644 index 0000000000..d74bd7a5b9 --- /dev/null +++ b/meta-gnome/dynamic-layers/meta-multimedia/recipes-gnome/gnome-disk-utility/gnome-disk-utility/0002-disks-drop-the-unused-gdk-gdkx.h-include.patch @@ -0,0 +1,68 @@ +From: Khem Raj +Date: Wed, 10 Sep 2026 06:40:00 +0000 +Subject: [PATCH] disks: drop the unused gdk/gdkx.h include + +gdupasswordstrengthwidget.c, gduvolumegrid.c and gduestimator.c all +pull in , GDK's X11 backend header, but none of them call +any X11-specific GDK API (no gdk_x11_*, no GDK_WINDOW_XID, nothing). +The include is dead weight left over from history. + +On a wayland-only build (no x11 in DISTRO_FEATURES) the GTK3 recipe is +configured without its X11 backend, so gdk/gdkx.h isn't installed into +the sysroot at all, and do_compile fails: + + gdupasswordstrengthwidget.c:14:10: fatal error: 'gdk/gdkx.h' file not found + gduvolumegrid.c:14:10: fatal error: 'gdk/gdkx.h' file not found + gduestimator.c:14:10: fatal error: 'gdk/gdkx.h' file not found + +Drop the unused include from all three files so the GTK3 build works +regardless of whether the X11 backend is enabled. + +Upstream-Status: Inappropriate [these files were dropped entirely in +the upstream GTK4/libadwaita port (gduvolumegrid.c) or renamed with a +GTK4-only gdkx.h path (gdupasswordstrengthwidget.c, gduestimator.c, +see GNOME/gnome-disk-utility!179aab50); none carries a comparable fix +for the GTK3 code line this recipe still builds] +Signed-off-by: Khem Raj +--- + src/disks/gduestimator.c | 1 - + src/disks/gdupasswordstrengthwidget.c | 1 - + src/disks/gduvolumegrid.c | 1 - + 3 files changed, 3 deletions(-) + +diff --git a/src/disks/gduestimator.c b/src/disks/gduestimator.c +index 1111111..2222222 100644 +--- a/src/disks/gduestimator.c ++++ b/src/disks/gduestimator.c +@@ -11,7 +11,6 @@ + + #include + #include +-#include + #include + + #include "gduestimator.h" +diff --git a/src/disks/gdupasswordstrengthwidget.c b/src/disks/gdupasswordstrengthwidget.c +index 1111111..2222222 100644 +--- a/src/disks/gdupasswordstrengthwidget.c ++++ b/src/disks/gdupasswordstrengthwidget.c +@@ -11,7 +11,6 @@ + + #include + #include +-#include + #include + + #include +diff --git a/src/disks/gduvolumegrid.c b/src/disks/gduvolumegrid.c +index 1111111..2222222 100644 +--- a/src/disks/gduvolumegrid.c ++++ b/src/disks/gduvolumegrid.c +@@ -11,7 +11,6 @@ + + #include + #include +-#include + #include + + #include "gduvolumegrid.h" diff --git a/meta-gnome/dynamic-layers/meta-multimedia/recipes-gnome/gnome-disk-utility/gnome-disk-utility_46.1.bb b/meta-gnome/dynamic-layers/meta-multimedia/recipes-gnome/gnome-disk-utility/gnome-disk-utility_46.1.bb index 08854befa8..fa4298e8e9 100644 --- a/meta-gnome/dynamic-layers/meta-multimedia/recipes-gnome/gnome-disk-utility/gnome-disk-utility_46.1.bb +++ b/meta-gnome/dynamic-layers/meta-multimedia/recipes-gnome/gnome-disk-utility/gnome-disk-utility_46.1.bb @@ -7,7 +7,6 @@ SECTION = "gnome" DEPENDS = " \ desktop-file-utils-native \ gtk+3 \ - libcanberra \ libdvdread \ libnotify \ libsecret \ @@ -28,6 +27,10 @@ PACKAGECONFIG ??= "${@bb.utils.filter('DISTRO_FEATURES', 'systemd', d)}" # As soon as elogind is of interest this needs rework: meson option is combo PACKAGECONFIG[systemd] = "-Dlogind=libsystemd,-Dlogind=none,systemd" +SRC_URI += "file://0001-Drop-the-libcanberra-gtk3-dependency.patch \ + file://0002-disks-drop-the-unused-gdk-gdkx.h-include.patch \ +" + SRC_URI[archive.sha256sum] = "c24e9439a04d70bcfae349ca134c7005435fe2b6f452114df878bff0b89bbffe" EXTRA_OEMESON = "-Dman=false" From patchwork Fri Sep 11 14:17:52 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Khem Raj X-Patchwork-Id: 97959 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 031C4C88E58 for ; Fri, 11 Sep 2026 14:18:06 +0000 (UTC) Received: from mail-pj1-f53.google.com (mail-pj1-f53.google.com [209.85.216.53]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.40462.1789136282462709907 for ; Fri, 11 Sep 2026 07:18:02 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=gmHLnb0Y; spf=pass (domain: gmail.com, ip: 209.85.216.53, mailfrom: raj.khem@gmail.com) Received: by mail-pj1-f53.google.com with SMTP id 98e67ed59e1d1-381b831d535so1666543a91.0 for ; Fri, 11 Sep 2026 07:18:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789136282; x=1789741082; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=DyQvTwEcwDB3ZYxLxDYrI0rDigmXCzK1vP/gyhVtXco=; b=gmHLnb0Yscy6H5Ty31AJutM0V3K3ERcyi66wVrZdMbpQblUd5cWpnPDK3RO86X0KUB NH5a64P3HG/+VLu3heyEuN+I7YWGGgsTg+KT6E7Z4AwUE4HgLT0nyneordT4n4TKtBVO a/8di9I3+la2ST1CE+6gud7kgF1JLZjWyNPArKWH9KcGctRa9WEjPCLr/DILvsHuTpx2 sOqOMsW2KDNAXJCd3w4AN+NBufiMthpptkA/MdiVN837KPrfIdZxebp3q9Qj9GUL96FI 5yCq/LlhptmCB+XOBBQxQPPRCWdvgNPrnuCiBPnb+jsfN93eXy1bQQ6fDGacIHow7GO/ SaMw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789136282; x=1789741082; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=DyQvTwEcwDB3ZYxLxDYrI0rDigmXCzK1vP/gyhVtXco=; b=mAQt9AbvodTz3tMyaHiaKU61/Kx+PWvJ8mnCaGp7ZP9oL24n4KHUHAN//s3hlJ+0Go ZLEnV3ZyEu7cVpzbx+M5aqyRwD9w0AOMsNKiLLl6uKxSeoOnQr2+1kOXuB3OfzpNWK68 /1Un7OgGRMerkfMLNren4r+f+X3xVrdPlQi3Oy/WkvvQnYvj4JrKQSSGDx1UNe3XaEco DWCHnbSSTVs+I7ClHUh2KQi6QoRgmQZpIFCvlUgjFAUKFtG0THeu7AD+jDDwgrEb/1wR EnGIKUVMNmUyBOFncD8ZeRdJo+PgJ++JB6Inuxrr1oKpN2W/rJRYWsfCVeVDWjKyHD2t UWJw== X-Gm-Message-State: AFuF++mSiahzROd+0mS+MUmf0rtvIRxhKY2IDg5UqhL3DbB+qI+hZKpC 8DDb94od4bHhUPem+pAO0SA6E0aorquY7A86fQaHAp+smTu/vODzPKp+fOP+SA== X-Gm-Gg: AYBFou1+V5p1YhezWTvbRl2zyy/+YF/3yedqmJ1ZVj8XmBzAUjhlddNPdheZGC/K7tT 9nak1d7mfNf8wDwALZW0HyZg2qkeT9b3WJ7xl5wUX2P4R6clP0TKHtqJ5qL5394Ttre++6+NbbS m/taYXjcrvuJFFZ+DWioN110yQSfIa8LeI4NT40XX2mJLnlbTk8SQSKDawOhu2e1fAX5FYP20c2 EDP0eG48BAu51aB78bQL1N05yB80yibFPHQFftWJA7EXlAxMHIZT9rU3SVpfMf1MxLarRjqxeNM OeSBbz4DeMlgKap//SCVYuycD6SlxhblcOICZaOKxoS0y3n0NpW4JmgeEMgtZzIyoEUyrHEKl47 eJMyWSM1nh7b0HAAFKUgvTR8iYXWBSn6H67+HDHUa2kZmamnRzyRDDUVa79O+BrxBJvWbdmEGDw BPWuE0TA7U/uQoaDkaTW0zHiTtIC0oMkKk1VRG7Au3yO9ifSAGJGBmt71LAdJQzcxmFvUoJWCw+ +aEeZi9N07Wr56pCZq5UUKNzvRZnQVK4PF74Ltdl6rbB3eKA4Vc8TfEDWNPIdJZtVlIX0rM0xEV d4nHz8FDwWDfKWr5mjLI4ge+zHqkPPIw7Jz3CsLVDVOxV0qgUcE61TuKTbtvCbyGJG2wpsjrIZV GMUaA65FsqRqttMX3v4lYdf74qp7M1iiqjaoQ6hdTAibmCPVxylPYGb3x X-Received: by 2002:a17:90b:514b:b0:39b:ac66:bbc with SMTP id 98e67ed59e1d1-39d9bd5e466mr8163219a91.7.1789136281793; Fri, 11 Sep 2026 07:18:01 -0700 (PDT) Received: from apollo.localdomain ([208.95.233.74]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33ba4fa50efsm7840791eec.28.2026.09.11.07.18.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 07:18:01 -0700 (PDT) From: Khem Raj X-Google-Original-From: Khem Raj To: openembedded-devel@lists.openembedded.org Cc: Khem Raj , Khem Raj Subject: [meta-gnome][PATCH 3/7] mutter: only enable desktop OpenGL when x11 is in DISTRO_FEATURES Date: Fri, 11 Sep 2026 07:17:52 -0700 Message-ID: <20260911141756.2275517-3-khem.raj@oss.qualcomm.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260911141756.2275517-1-khem.raj@oss.qualcomm.com> References: <20260911141756.2275517-1-khem.raj@oss.qualcomm.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 11 Sep 2026 14:18:06 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129967 mutter fails to configure on a wayland-only distro configuration: Run-time dependency gl found: NO (tried pkg-config and system) ../sources/mutter-50.4/meson.build:191:11: ERROR: Dependency "gl" not found (tried pkg-config and system) The recipe enabled the opengl PACKAGECONFIG unconditionally, which passes -Dopengl=true and makes meson require desktop OpenGL: have_gl = get_option('opengl') if have_gl gl_dep = dependency('gl') Desktop GL is not available here. libGL.so and gl.pc are products of mesa's GLX library - see FILES:libgl-mesa-dev in mesa.inc - and mesa only builds GLX when its x11 PACKAGECONFIG is on, since PACKAGECONFIG[x11] passes -Dglx=disabled when it is off. Without x11 in DISTRO_FEATURES mesa is therefore configured -Dopengl=true -Dglx=disabled -Dplatforms='wayland' and stages only egl.pc, glesv1_cm.pc and glesv2.pc, with no libGL and no gl.pc. The dependency looked satisfied because mesa PROVIDES virtual/libgl unconditionally, so the virtual/libgl entry in PACKAGECONFIG[opengl] resolves at the bitbake level even though nothing ever lands in the sysroot. mesa also installs the GL/*.h headers regardless of GLX, so meson's 'system' fallback clears the header probe before failing on the missing library. mutter builds fine against GLESv2 alone - it only errors out if neither GL nor GLES2 is enabled - and egl plus gles2 are already enabled here, which is the usual configuration for a wayland-only compositor. Gate opengl on x11 so it follows the same condition that decides whether desktop GL exists at all; x11 builds are unaffected. AI-Generated: Uses Claude Code Signed-off-by: Khem Raj --- meta-gnome/recipes-gnome/mutter/mutter_50.4.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta-gnome/recipes-gnome/mutter/mutter_50.4.bb b/meta-gnome/recipes-gnome/mutter/mutter_50.4.bb index 91ba3f5489..f9b3e9d5e5 100644 --- a/meta-gnome/recipes-gnome/mutter/mutter_50.4.bb +++ b/meta-gnome/recipes-gnome/mutter/mutter_50.4.bb @@ -46,7 +46,7 @@ PACKAGECONFIG ??= " \ native-backend \ egl \ gles2 \ - opengl \ + ${@bb.utils.contains('DISTRO_FEATURES', 'x11', 'opengl', '', d)} \ fonts \ bash-completion \ gnome-desktop \ From patchwork Fri Sep 11 14:17:53 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Khem Raj X-Patchwork-Id: 97961 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2969FC88E59 for ; Fri, 11 Sep 2026 14:18:06 +0000 (UTC) Received: from mail-pj1-f50.google.com (mail-pj1-f50.google.com [209.85.216.50]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.40463.1789136283944218892 for ; Fri, 11 Sep 2026 07:18:04 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=hYQl8KMP; spf=pass (domain: gmail.com, ip: 209.85.216.50, mailfrom: raj.khem@gmail.com) Received: by mail-pj1-f50.google.com with SMTP id 98e67ed59e1d1-398b3d66515so1186773a91.0 for ; Fri, 11 Sep 2026 07:18:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789136283; x=1789741083; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=CchNCWZVOc4A5MX2udR8ApATB7R1znAEX5S8RR7BQi8=; b=hYQl8KMPkQBPlT15G5sTDvSAxzV8r9DqzLTsmUSwsSKjB2c02Y6fDYNP4dxjSvJzxl CwOWSR+yHZDAtqz3Sa/fbT+L5y2etCamOGOBa1Aap3MakYpYi7sAfB9bJLk5/mjirMzy aU2Xc76VCa7fddJSWy/0CHu8BrgjdXo0ruk3+gFS10Okh5Fqwwlym5WoUSwY2C4ZyV2k DvUMMY/R5Oc6SjPbzmwmj4PFRYX3djr057CWljczAERxTPX2w4Jo8V9k2GnQd0G4xSTZ SnIHkdUkZ4GQOEZ4OCnyB7oLeml1jSNJmpTNsEpuRrpSfjNkl2aHWUjYnXkrWg9zOTW4 8NJA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789136283; x=1789741083; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=CchNCWZVOc4A5MX2udR8ApATB7R1znAEX5S8RR7BQi8=; b=PZajvZkHfkpllTe5KplwmldvMOFb5ZqChqahTTRPSyJCq3SsMkx8V4h5mZeTxnHz7G q5XrcAFK/EjRHau9t42I8lR1XLEFMvj3qJALm2KBgWvSG7VSMrHMcx8I2aOilcEwYZBz nvgeboMu5iKDS7EJPwouQdbVt96rQLhknyAn8jQBbwGMsrjxrsHADUTvhe29v/ixe2eN pTXRu/Ym92QOw6QoRu+XmuL8B+eLolQ1ERVwGrYmypEl8qpQKLqOUig+Id5mtwseUcwV /Ad3QlFzB2fRYY3IlCxws5E4YncDCSh9Zl2v2eOUD0Q19cNUw9uDngqpWBtDlGf36uKF iEAA== X-Gm-Message-State: AFuF++n72XU7JG20uru0Ut+dZmpYvuiJAdERU+pLqUd116JG4pEg9i+M QlQZMuDx3bkCz9nFxNBX2Q/RaQALD6JxnTZXZpnQHG9gTKxR61kp8qPVaaq7ug== X-Gm-Gg: AYBFou0uwfNhSJPytxSRY4s3iRWGZTwNx1D/hte+kaozfaP9JD1U2Vlpn/Rir9kEXV1 cLNzXRjKNN36JN0b24L53QgeWxp1w01Lm4xyVyAo9tvleggQe1zQlsQ4kubSOdUgVs+Ppnrx/XY +3p9fEckFViGyOIIWif0Ua7twtzlOMhX37MsDJyAU+YDtkfSqNexi011KcUbDZWcJ9xpvaJc6Z+ bIb4oe0bgVXRI0PtFxa41mdCnsrbUG3VVifGSDzScI/idvoGEX8a3U0rdVheJGDzoaqqlpGf1yn uATkIqj9PZkaWegRRkylH+4BP0VuY95snul4qdElScLr69wb0Yr27TuGZ62feztA6BV0Zhkw4FQ IyXPosZwjLjbBTTgiEhmfTN3fNQV/0I5fJdN9hhbF1B8z7tNP93h6tXLSSmmYNsRtG4I3r04uls zFE+HDe2oAgJXUczXwflzAL7zcBci9FztvA3h6nbuJJ6QpCTqmvH5JUq9ETG1b9gEwmaRkfzC2I iHqHdgRRsXjyWvpTrdkra6hWaUQyi3QDQa3LQecwzUAtaysSFRJYRNUm5ifDEK6Sj6hr96heSTV TjyRQ4Gy4xe+07kBRURcWKft8+vZ58rxcyfd7sBLrtCTJRli70loXzinDF6uv9EoPXWbzgUu+rp iazaFJz0sN6I2Z2KvzLBxfDzTNvkLeC/1m6LxvEgGYlNSMmlT+by7FSrF X-Received: by 2002:a17:90b:280e:b0:398:c3a3:dbd0 with SMTP id 98e67ed59e1d1-39d9beba6ffmr7361836a91.8.1789136283189; Fri, 11 Sep 2026 07:18:03 -0700 (PDT) Received: from apollo.localdomain ([208.95.233.74]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33ba4fa50efsm7840791eec.28.2026.09.11.07.18.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 07:18:02 -0700 (PDT) From: Khem Raj X-Google-Original-From: Khem Raj To: openembedded-devel@lists.openembedded.org Cc: Khem Raj , Khem Raj Subject: [meta-oe][PATCH 4/7] wvstreams: fix build with OpenSSL 4 Date: Fri, 11 Sep 2026 07:17:53 -0700 Message-ID: <20260911141756.2275517-4-khem.raj@oss.qualcomm.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260911141756.2275517-1-khem.raj@oss.qualcomm.com> References: <20260911141756.2275517-1-khem.raj@oss.qualcomm.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 11 Sep 2026 14:18:06 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129968 OpenSSL 4.0 breaks the X.509 code in two ways: struct asn1_string_st is opaque, so ASN1_INTEGER / ASN1_OCTET_STRING / ASN1_BIT_STRING / ASN1_TIME can no longer be dereferenced, and X509_get_ext(), X509_EXTENSION_get_data(), X509_get0_pubkey_bitstr(), X509_get_subject_name(), X509_get_issuer_name() and X509_REQ_get_subject_name() all gained const. Switch to the ASN1_STRING_get0_data() / ASN1_STRING_length() / ASN1_STRING_type() accessors, available since OpenSSL 1.1.0, and propagate const to the locals that only read through those pointers. Three call sites needed a mutable X509_NAME: they fetched the existing name, edited it in place and installed it again. The getters have no mutable counterpart, so duplicate with X509_NAME_dup(), edit the copy and free it once the setter has taken its own copy, preserving the previous behaviour of merging into the existing DN. AI-Generated: Uses Claude Code Signed-off-by: Khem Raj --- .../0001-crypto-build-against-OpenSSL-4.patch | 265 ++++++++++++++++++ .../wvdial/wvstreams_4.6.1.bb | 1 + 2 files changed, 266 insertions(+) create mode 100644 meta-oe/recipes-connectivity/wvdial/wvstreams/0001-crypto-build-against-OpenSSL-4.patch diff --git a/meta-oe/recipes-connectivity/wvdial/wvstreams/0001-crypto-build-against-OpenSSL-4.patch b/meta-oe/recipes-connectivity/wvdial/wvstreams/0001-crypto-build-against-OpenSSL-4.patch new file mode 100644 index 0000000000..e3146dfa41 --- /dev/null +++ b/meta-oe/recipes-connectivity/wvdial/wvstreams/0001-crypto-build-against-OpenSSL-4.patch @@ -0,0 +1,265 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Khem Raj +Date: Wed, 3 Sep 2026 01:30:00 +0000 +Subject: [PATCH] crypto: build against OpenSSL 4 + +OpenSSL 4.0 brings two changes that wvstreams' X.509 code trips over: + + - struct asn1_string_st is opaque, so ASN1_INTEGER / ASN1_OCTET_STRING / + ASN1_BIT_STRING / ASN1_TIME can no longer be dereferenced; + - several getters gained const: X509_get_ext(), X509_EXTENSION_get_data(), + X509_get0_pubkey_bitstr(), X509_get_subject_name(), + X509_get_issuer_name() and X509_REQ_get_subject_name(). + +Use the ASN1_STRING_get0_data() / ASN1_STRING_length() / ASN1_STRING_type() +accessors, which have existed since OpenSSL 1.1.0, and propagate const to +the locals that only ever read through those pointers. + +Three call sites did rely on getting a mutable X509_NAME back: they fetched +the certificate's (or request's) existing name, edited it in place through +set_name_entry() and then installed it again. There is no mutable +counterpart to those getters, so duplicate the name with X509_NAME_dup(), +edit the copy, and free it after the setter has taken its own copy. That +keeps the previous behaviour of merging into the existing DN rather than +starting from an empty one. + +WvX509::set_subject(X509_NAME *) becomes set_subject(const X509_NAME *) so +that wvx509mgr.cc can keep passing X509_REQ_get_subject_name() straight in; +the implementation only forwards to X509_set_subject_name(), which takes a +const pointer. + +set_aki() and WvCRL's constructor used one X509_EXTENSION * for both the +borrowed extension returned by X509_get_ext() and the freshly built one they +own and free, which no longer type checks now that the former is const. Give +the owned extension its own variable. + +Upstream-Status: Pending + +Signed-off-by: Khem Raj +--- +--- a/include/wvx509.h ++++ b/include/wvx509.h +@@ -161,7 +161,7 @@ + */ + WvString get_subject() const; + void set_subject(WvStringParm name); +- void set_subject(X509_NAME *name); ++ void set_subject(const X509_NAME *name); + + /** + * get and set the serialNumber field of the certificate +--- a/crypto/wvcrl.cc ++++ b/crypto/wvcrl.cc +@@ -56,7 +56,7 @@ + + // most of this copied from wvx509.cc, sigh + ASN1_OCTET_STRING *ikeyid = NULL; +- X509_EXTENSION *ext; ++ const X509_EXTENSION *ext; + int i = X509_get_ext_by_NID(ca.cert, NID_subject_key_identifier, -1); + if ((i >= 0) && (ext = X509_get_ext(ca.cert, i))) + ikeyid = static_cast(X509V3_EXT_d2i(ext)); +@@ -67,9 +67,10 @@ + akeyid->issuer = NULL; + akeyid->serial = NULL; + akeyid->keyid = ikeyid; +- ext = X509V3_EXT_i2d(NID_authority_key_identifier, 0, akeyid); +- X509_CRL_add_ext(crl, ext, -1); +- X509_EXTENSION_free(ext); ++ X509_EXTENSION *akiext = ++ X509V3_EXT_i2d(NID_authority_key_identifier, 0, akeyid); ++ X509_CRL_add_ext(crl, akiext, -1); ++ X509_EXTENSION_free(akiext); + AUTHORITY_KEYID_free(akeyid); + } + +@@ -169,7 +170,8 @@ + &i, NULL)); + if (aki) + { +- char *tmp = hex_to_string(aki->keyid->data, aki->keyid->length); ++ char *tmp = hex_to_string(ASN1_STRING_get0_data(aki->keyid), ++ ASN1_STRING_length(aki->keyid)); + WvString str(tmp); + + OPENSSL_free(tmp); +--- a/crypto/wvx509.cc ++++ b/crypto/wvx509.cc +@@ -306,11 +306,12 @@ + + X509_REQ_set_pubkey(certreq, pk); + +- name = X509_REQ_get_subject_name(certreq); ++ name = X509_NAME_dup(X509_REQ_get_subject_name(certreq)); + + debug("Creating Certificate request for %s\n", subject); + set_name_entry(name, subject); + X509_REQ_set_subject_name(certreq, name); ++ X509_NAME_free(name); + char *sub_name = X509_NAME_oneline(X509_REQ_get_subject_name(certreq), + 0, 0); + debug("SubjectDN: %s\n", sub_name); +@@ -606,9 +607,10 @@ + { + CHECK_CERT_EXISTS_SET("issuer"); + +- X509_NAME *name = X509_get_issuer_name(cert); ++ X509_NAME *name = X509_NAME_dup(X509_get_issuer_name(cert)); + set_name_entry(name, issuer); + X509_set_issuer_name(cert, name); ++ X509_NAME_free(name); + } + + +@@ -616,7 +618,7 @@ + { + CHECK_CERT_EXISTS_SET("issuer"); + +- X509_NAME *casubj = X509_get_subject_name(cacert.cert); ++ const X509_NAME *casubj = X509_get_subject_name(cacert.cert); + X509_set_issuer_name(cert, casubj); + } + +@@ -636,13 +638,14 @@ + { + CHECK_CERT_EXISTS_SET("subject"); + +- X509_NAME *name = X509_get_subject_name(cert); ++ X509_NAME *name = X509_NAME_dup(X509_get_subject_name(cert)); + set_name_entry(name, subject); + X509_set_subject_name(cert, name); ++ X509_NAME_free(name); + } + + +-void WvX509::set_subject(X509_NAME *name) ++void WvX509::set_subject(const X509_NAME *name) + { + CHECK_CERT_EXISTS_SET("subject"); + +@@ -799,7 +802,8 @@ + ca = constraints->ca; + if (constraints->pathlen) + { +- if ((constraints->pathlen->type == V_ASN1_NEG_INTEGER) || !ca) ++ if ((ASN1_STRING_type(constraints->pathlen) == ++ V_ASN1_NEG_INTEGER) || !ca) + { + debug("Path length type not valid when getting basic " + "constraints.\n"); +@@ -1153,7 +1157,7 @@ + int index = X509_get_ext_by_NID(cert, nid, -1); + if (index >= 0) + { +- X509_EXTENSION *ext = X509_get_ext(cert, index); ++ const X509_EXTENSION *ext = X509_get_ext(cert, index); + + if (ext) + { +@@ -1162,11 +1166,13 @@ + #else + X509V3_EXT_METHOD *method = X509V3_EXT_get(ext); + #endif +- ASN1_OCTET_STRING *ext_data_str = X509_EXTENSION_get_data(ext); ++ const ASN1_OCTET_STRING *ext_data_str = ++ X509_EXTENSION_get_data(ext); + if (!method) + { + WvDynBuf buf; +- buf.put(ext_data_str->data, ext_data_str->length); ++ buf.put(ASN1_STRING_get0_data(ext_data_str), ++ ASN1_STRING_length(ext_data_str)); + retval = buf.getstr(); + } + else +@@ -1177,21 +1183,22 @@ + // even though it's const (at least as of version 0.9.8e). + // gah. + #if OPENSSL_VERSION_NUMBER >= 0x0090800fL +- const unsigned char * ext_value_data = ext_data_str->data; ++ const unsigned char * ext_value_data = ++ ASN1_STRING_get0_data(ext_data_str); + #else + unsigned char *ext_value_data = ext->value->data; + #endif + if (method->it) + { + ext_data = ASN1_item_d2i(NULL, &ext_value_data, +- ext_data_str->length, ++ ASN1_STRING_length(ext_data_str), + ASN1_ITEM_ptr(method->it)); + TRACE("Applied generic conversion!\n"); + } + else + { + ext_data = method->d2i(NULL, &ext_value_data, +- ext_data_str->length); ++ ASN1_STRING_length(ext_data_str)); + TRACE("Applied method specific conversion!\n"); + } + +@@ -1343,7 +1350,7 @@ + } + + +-static time_t ASN1_TIME_to_time_t(ASN1_TIME *t) ++static time_t ASN1_TIME_to_time_t(const ASN1_TIME *t) + { + struct tm newtime; + char *p = NULL; +@@ -1351,7 +1358,7 @@ + memset(&d,'\0',sizeof(d)); + memset(&newtime,'\0',sizeof newtime); + +- if (t->type == V_ASN1_GENERALIZEDTIME) ++ if (ASN1_STRING_type(t) == V_ASN1_GENERALIZEDTIME) + { + // For time values >= 2050, OpenSSL uses + // ASN1_GENERALIZEDTIME - which we'll worry about +@@ -1359,7 +1366,7 @@ + return 0; + } + +- p = (char *)t->data; ++ p = (char *)ASN1_STRING_get0_data(t); + sscanf(p,"%2s%2s%2s%2s%2s%2sZ", d, &d[3], &d[6], &d[9], &d[12], &d[15]); + + int year = strtol(d, (char **)NULL, 10); +@@ -1452,11 +1459,12 @@ + CHECK_CERT_EXISTS_SET("ski"); + + ASN1_OCTET_STRING *oct = ASN1_OCTET_STRING_new(); +- ASN1_BIT_STRING *pk = X509_get0_pubkey_bitstr(cert); ++ const ASN1_BIT_STRING *pk = X509_get0_pubkey_bitstr(cert); + unsigned char pkey_dig[EVP_MAX_MD_SIZE]; + unsigned int diglen; + +- EVP_Digest(pk->data, pk->length, pkey_dig, &diglen, EVP_sha1(), NULL); ++ EVP_Digest(ASN1_STRING_get0_data(pk), ASN1_STRING_length(pk), pkey_dig, ++ &diglen, EVP_sha1(), NULL); + + ASN1_OCTET_STRING_set(oct, pkey_dig, diglen); + X509_EXTENSION *ext = X509V3_EXT_i2d(NID_subject_key_identifier, 0, +@@ -1474,7 +1482,7 @@ + // can't set a meaningful AKI for subordinate certification without the + // parent having an SKI + ASN1_OCTET_STRING *ikeyid = NULL; +- X509_EXTENSION *ext; ++ const X509_EXTENSION *ext; + int i = X509_get_ext_by_NID(cacert.cert, NID_subject_key_identifier, -1); + if ((i >= 0) && (ext = X509_get_ext(cacert.cert, i))) + ikeyid = static_cast(X509V3_EXT_d2i(ext)); +@@ -1486,9 +1494,10 @@ + akeyid->issuer = NULL; + akeyid->serial = NULL; + akeyid->keyid = ikeyid; +- ext = X509V3_EXT_i2d(NID_authority_key_identifier, 0, akeyid); +- X509_add_ext(cert, ext, -1); +- X509_EXTENSION_free(ext); ++ X509_EXTENSION *akiext = ++ X509V3_EXT_i2d(NID_authority_key_identifier, 0, akeyid); ++ X509_add_ext(cert, akiext, -1); ++ X509_EXTENSION_free(akiext); + AUTHORITY_KEYID_free(akeyid); + } + diff --git a/meta-oe/recipes-connectivity/wvdial/wvstreams_4.6.1.bb b/meta-oe/recipes-connectivity/wvdial/wvstreams_4.6.1.bb index 8302e4cce1..27e6e33224 100644 --- a/meta-oe/recipes-connectivity/wvdial/wvstreams_4.6.1.bb +++ b/meta-oe/recipes-connectivity/wvdial/wvstreams_4.6.1.bb @@ -23,6 +23,7 @@ SRC_URI = "https://storage.googleapis.com/google-code-archive-downloads/v2/code. file://openssl-buildfix.patch \ file://0001-Forward-port-to-OpenSSL-1.1.x.patch \ file://0001-Fix-narrowing-conversion-error.patch \ + file://0001-crypto-build-against-OpenSSL-4.patch \ " SRC_URI[sha256sum] = "8403f5fbf83aa9ac0c6ce15d97fd85607488152aa84e007b7d0621b8ebc07633" From patchwork Fri Sep 11 14:17:54 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Khem Raj X-Patchwork-Id: 97960 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 73A35C88E5A for ; Fri, 11 Sep 2026 14:18:06 +0000 (UTC) Received: from mail-pl1-f175.google.com (mail-pl1-f175.google.com [209.85.214.175]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.40465.1789136285265351429 for ; Fri, 11 Sep 2026 07:18:05 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=ltN3yCO6; spf=pass (domain: gmail.com, ip: 209.85.214.175, mailfrom: raj.khem@gmail.com) Received: by mail-pl1-f175.google.com with SMTP id d9443c01a7336-2cfbbdfa60bso9119785ad.3 for ; Fri, 11 Sep 2026 07:18:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789136285; x=1789741085; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=P1Xgezra4e2VnmRHA2cPcvWmdNpvCf43rZjU9Ev/7Us=; b=ltN3yCO6HEK03F89Qhbn/BvzHeZv5lXWDULlkCMxuwtNMvvRE8gLFaoMqGFzYdUdbJ /sal6J41OKefKvUISxqsclptvA7ALp9g4V21n+wM/yox9c5PVDSeofeHlLViYHtNdmXb maN9oofX36R9xcHjZhgKZdScCne5nNARXxVTnVJJnXVWeop7dGtuVQWi55e1VujTcL3A TIIpEB4epIDkkCTgL55HwqVkSNPY2eHbBtx74mMM2l+K7aiRQwx8kEiaNNCkS/G2jZEN e6uitJbexmoGPMzQhWrbaoJqW8ru8B2cBIrpgSMJvU0OU1aYpzB2Orerj6GgXfxYBDuT 7cqw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789136285; x=1789741085; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=P1Xgezra4e2VnmRHA2cPcvWmdNpvCf43rZjU9Ev/7Us=; b=KXE53CYoTgGt3QtTvgJ0b9G2tWF/k4m63kWXWEVU6wd5jEtgpm4O0mOwWK0p7LVssf Sc8JIptJt/V/uNIZBNa8FAU6FO2tTr849V7wkeblsTyLMcJKP2vtUvbk5FRgG9X5CVMD vvINBmIOg/gqTzIhemkS7T3OgjpVwV7te7piveDxBYihwrQh6I7+4hiCiOOQV9Dm/Qwx ORz4rOlBVjHs5J0fIDkEF7iSOMlS7xeZibiaOPzi5yfDHx8uxZUUw/EGS2SBUBc3XU6W er+lchSYBiaOsm6I7s9a+DSdHVkQ6nEZAQYWm1QI3sDdpvs+RKnXZlLP1m8ErsNmi3pm DohA== X-Gm-Message-State: AFuF++lKaDSzVTiVxoWzr01srbBODcxfRUhz+4S5NpAgExHouNx0ZbZL 77Ax15CmKf++1EOKfT/C6iKayNwSL2EMMDOchhTJeDj9Hn/cokrWNZCjFrW06A== X-Gm-Gg: AYBFou2l6sHFeHM/J9NngBHWHUraL85fZBPcTbeXOzbR+nt/lOLVS3Yp79m7bUTo7kz fAmqUw2celbL4GS7IYTSibfuZpD7ugj8MJQvotRUJ5zsdmzWNcAaRI6nn0se9pst9Gzi6Ug/HLC tjjIKY9IdOpQN6zUtb5+9KOYIEABQz3o0xd1whNVfC5amTvbJrcdHKjdBBBjqKVfG5ORScArLRY MJijlcDWft0HuFqy1hPGBEETuL/qiBxjZmAoxsfd7lMFqJuuVThLFQGmbnmApiGJRyE/qje4+v2 g8ru5NGcFG6qyG5xLmiop4maCvzi43+mX5DLjDbMD7I/xkHjbdMTf93eO1m2PdRP1TlFd/Mdy6S MLZ/IFbTHy3hPRR7w5+zygt8zMrqw7WmzoSRdY8NQ7nny6n8FdVbHFGnvD6aHvEZOyzO2+aq7qz 3mtrEACt7D/Fwz3ZMvKuqbkZntsntri+y5PgIFQOZyxh43og+eLZ8V5j9j5YaKqnH/GutCasj6Z qzMEdosgAseyMmVVeTLgv49BvmYaTUd45VSOqW7WKJ42++bWBxiLKmUHNpI04cDOetdOc402ope r0EdU16VAT+wJ5EdQysNRv3fKf73JfsuR0/5F+fmeWTg5M4ynFCiAgUaICXz3Nzs9caoE4neeiu fhwdXL2plB0USb5J6kztIeywYpU+1xDKMqYYxUIjzTbiF+dRax47suHaVfQ== X-Received: by 2002:a17:903:acd:b0:2da:e967:7953 with SMTP id d9443c01a7336-2dd2a336839mr84225175ad.12.1789136284286; Fri, 11 Sep 2026 07:18:04 -0700 (PDT) Received: from apollo.localdomain ([208.95.233.74]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33ba4fa50efsm7840791eec.28.2026.09.11.07.18.03 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 07:18:03 -0700 (PDT) From: Khem Raj X-Google-Original-From: Khem Raj To: openembedded-devel@lists.openembedded.org Cc: Khem Raj , Khem Raj Subject: [meta-oe][PATCH 5/7] extract-cert: fix build with OpenSSL 4 Date: Fri, 11 Sep 2026 07:17:54 -0700 Message-ID: <20260911141756.2275517-5-khem.raj@oss.qualcomm.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260911141756.2275517-1-khem.raj@oss.qualcomm.com> References: <20260911141756.2275517-1-khem.raj@oss.qualcomm.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 11 Sep 2026 14:18:06 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129969 OpenSSL 4.0 removed the ENGINE API. still exists as a source-compatibility stub, so both binaries fail to link: ld.lld: error: undefined symbol: ENGINE_load_builtin_engines ld.lld: error: undefined symbol: ENGINE_by_id ld.lld: error: undefined symbol: ENGINE_init ld.lld: error: undefined symbol: ENGINE_ctrl_cmd_string ld.lld: error: undefined symbol: ENGINE_load_public_key The ENGINE use is confined to the "pkcs11:" input branch of each tool, so compile that branch out on OpenSSL 4 and diagnose the unsupported input instead. Reading certificates and public keys from PEM files, which is what the kernel build and most other users do, is unaffected. Providers supersede engines, but none exposes an equivalent of the pkcs11 engine's LOAD_CERT_CTRL command, so there is nothing to port to yet. AI-Generated: Uses Claude Code Signed-off-by: Khem Raj --- ...ot-use-the-ENGINE-API-with-OpenSSL-4.patch | 99 +++++++++++++++++++ .../extract-cert/extract-cert_0.3.bb | 4 +- 2 files changed, 102 insertions(+), 1 deletion(-) create mode 100644 meta-oe/recipes-devtools/extract-cert/extract-cert/0001-Do-not-use-the-ENGINE-API-with-OpenSSL-4.patch diff --git a/meta-oe/recipes-devtools/extract-cert/extract-cert/0001-Do-not-use-the-ENGINE-API-with-OpenSSL-4.patch b/meta-oe/recipes-devtools/extract-cert/extract-cert/0001-Do-not-use-the-ENGINE-API-with-OpenSSL-4.patch new file mode 100644 index 0000000000..97ed51af5b --- /dev/null +++ b/meta-oe/recipes-devtools/extract-cert/extract-cert/0001-Do-not-use-the-ENGINE-API-with-OpenSSL-4.patch @@ -0,0 +1,99 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Khem Raj +Date: Wed, 3 Sep 2026 01:30:00 +0000 +Subject: [PATCH] Do not use the ENGINE API with OpenSSL 4 + +OpenSSL 4.0 removed the ENGINE API. still exists, but +only as a source-compatibility stub, so both binaries now fail to link: + + ld.lld: error: undefined symbol: ENGINE_load_builtin_engines + ld.lld: error: undefined symbol: ENGINE_by_id + ld.lld: error: undefined symbol: ENGINE_init + ld.lld: error: undefined symbol: ENGINE_ctrl_cmd_string + ld.lld: error: undefined symbol: ENGINE_load_public_key + +The ENGINE use is confined to the "pkcs11:" input branch of each tool, so +compile that branch out on OpenSSL 4 and diagnose the unsupported input +instead. Reading certificates and public keys from PEM files - which is +what the kernel build and most other users actually do - is unaffected. + +Providers supersede engines, but no provider exposes an equivalent of the +pkcs11 engine's LOAD_CERT_CTRL command, so there is nothing to port to +yet; pkcs11-provider based support would be a separate feature. + +Upstream-Status: Pending + +Signed-off-by: Khem Raj +--- +--- a/extract-cert.c ++++ b/extract-cert.c +@@ -21,7 +21,9 @@ + #include + #include + #include ++#if OPENSSL_VERSION_MAJOR < 4 + #include ++#endif + + #define PKEY_ID_PKCS7 2 + +@@ -112,6 +114,16 @@ + fclose(f); + exit(0); + } else if (!strncmp(cert_src, "pkcs11:", 7)) { ++#if OPENSSL_VERSION_MAJOR >= 4 ++ /* ++ * OpenSSL 4.0 removed the ENGINE API, and with it the pkcs11 ++ * engine that was used here to pull an object off a token. No ++ * provider based replacement for the engine's LOAD_CERT_CTRL ++ * command exists, so fail loudly rather than quietly emitting ++ * nothing. ++ */ ++ ERR(1, "PKCS#11 URIs require OpenSSL < 4.0 (ENGINE API removed)"); ++#else + ENGINE *e; + struct { + const char *cert_id; +@@ -134,6 +146,7 @@ + ENGINE_ctrl_cmd(e, "LOAD_CERT_CTRL", 0, &parms, NULL, 1); + ERR(!parms.cert, "Get X.509 from PKCS#11"); + write_cert(parms.cert); ++#endif + } else { + BIO *b; + X509 *x509; +--- a/spki-hash.c ++++ b/spki-hash.c +@@ -23,7 +23,9 @@ + #include + #include + #include ++#if OPENSSL_VERSION_MAJOR < 4 + #include ++#endif + + #define PKEY_ID_PKCS7 2 + +@@ -110,6 +112,14 @@ + src = argv[1]; + + if (!strncmp(src, "pkcs11:", 7)) { ++#if OPENSSL_VERSION_MAJOR >= 4 ++ /* ++ * OpenSSL 4.0 removed the ENGINE API, and with it the pkcs11 ++ * engine that was used here to load a public key off a token. ++ * Fail loudly rather than quietly hashing nothing. ++ */ ++ ERR(1, "PKCS#11 URIs require OpenSSL < 4.0 (ENGINE API removed)"); ++#else + ENGINE *e; + ENGINE_load_builtin_engines(); + drain_openssl_errors(); +@@ -124,6 +134,7 @@ + + key = ENGINE_load_public_key(e, src, NULL, NULL); + ERR(!key, "ENGINE_load_public_key"); ++#endif + } else { + BIO *b; + diff --git a/meta-oe/recipes-devtools/extract-cert/extract-cert_0.3.bb b/meta-oe/recipes-devtools/extract-cert/extract-cert_0.3.bb index 83e9383d4a..ded919e063 100644 --- a/meta-oe/recipes-devtools/extract-cert/extract-cert_0.3.bb +++ b/meta-oe/recipes-devtools/extract-cert/extract-cert_0.3.bb @@ -4,7 +4,9 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=4fbd65380cdd255951079008b364516c" DEPENDS = "openssl" -SRC_URI = "git://git.pengutronix.de/git/extract-cert;protocol=https;branch=master;" +SRC_URI = "git://git.pengutronix.de/git/extract-cert;protocol=https;branch=master; \ + file://0001-Do-not-use-the-ENGINE-API-with-OpenSSL-4.patch \ + " SRCREV = "d652b4e8279aef2a85f58676ab472744bafeafc9" From patchwork Fri Sep 11 14:17:55 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Khem Raj X-Patchwork-Id: 97962 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2E8E7C88E50 for ; Fri, 11 Sep 2026 14:18:16 +0000 (UTC) Received: from mail-pj1-f43.google.com (mail-pj1-f43.google.com [209.85.216.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.40466.1789136286374447069 for ; Fri, 11 Sep 2026 07:18:06 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=kdzPf5wM; spf=pass (domain: gmail.com, ip: 209.85.216.43, mailfrom: raj.khem@gmail.com) Received: by mail-pj1-f43.google.com with SMTP id 98e67ed59e1d1-38ea87caafeso934497a91.3 for ; Fri, 11 Sep 2026 07:18:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789136286; x=1789741086; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=1OYmyb4vlal9EO4Vha8rzLkOf6iLujtxN1ZB3zLlKJ4=; b=kdzPf5wMlb5fH2ySmfwzQxJbMqSiaUwzjS01AwJWk1kYsHtEHSEPSqOmpRZr6nXJBE 1HoV+NwzvcdjWAYdm5sYGRWiB+DaMJIkHauxnOCExwgfcfpFcDYtF2zpLxhUskG+J9Ln tsLwkgzwZ4xRI14FqZbrZXFDMV6RRPWzoIh7TEvK4QZdTxr+VoHb2oFa4q/7t7Y3b2Ii lAUorHZpnoj6HIDo1ljGxhytPaGFoKoxPbMVQqR+7ZZuN7UfJ2WhYWRfjiOtUo/eygmt 3i9R7Q09QFBB06L4T50RJxNeYIo0aOkltw/boTRMVTevRsz0trx/01rKcNZh6ZZ3E2xl v19A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789136286; x=1789741086; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=1OYmyb4vlal9EO4Vha8rzLkOf6iLujtxN1ZB3zLlKJ4=; b=Mx2LEovDzfN5ztxj2AvMo/4Lplj9hs8w89CgGSPt1tESUDmrGVKgnnPCaD/jhexwf3 QpFzKcZA+xQNNXwKaNvQxDN+FaNl8OzV/u6CCo3m3Y6o+vNkfl+MF4bpRoz/jWVUAaWd 7z4SkNtJuM/V29H+Weebh3XQPwVJsjtE7g/dTpBF8+wUiuZwlBjQY6M/GNrtb3DYIWo5 7sh2qBul5V2dmM1yY++sBePb0NhpUvoUYyUiYShun2CraMuS3j0IOwIfkfUHFIGaUoVM xG7uegduun6divQmqru/MRkGC2UakeVs9QklfiuuO0JMzX4NiGFXvqvJGrmqfo/kXcqq jypA== X-Gm-Message-State: AFuF++m5FhrG8FAei8FJya9sourYE6XyLrffKR4/PQVPbzK+qB8xVnrp AYByBjNOdcOUDEWbQshbP0vj7DFvlDbQT3BamTIzt97AKDnmDRBgmzJYGYYVCA== X-Gm-Gg: AYBFou3lvtTaMPmMLtr7Z/MC4gFVJJnL+3BqdQ1xaOegYarHcmcMeAUL4g91MZYCstG rm6PmQvCMBiLwQgrVnm9+izbHgvaHV1QtQN3+NqOhAEJoDn+rttr+oo/B3zMp5tMqjIQzeIU0o7 Mp6niCR5I1XkAAWZKHqkrkTIQ3j5XxyGFvQ/5cqJQmbHeCRJQryl8zalOv87d44S5F1mzeFFVUD UhXDeGi7dosue0qPrZo50BxeVuRVxaBs5Row4ocTdTUABJtZQ07k6hwHneFiHTQVE+TRoSBbCRa mD1YXrEq30II0+wXdH/1TObKvL9MZxYWpNelVesfkjhq/rS2n4H35ITe0XckUXnOIEXAcio9Ab9 8VYrzPOw+f5Vg7fAp3XlZegR1ouNZLfOu71m0WDuOVoWvB/1/GU4Q9Eg3zXSvwBCDFCSN2RpDBI UDO8f7XeFUEUpL7Wu0aqBogl1UtuhKg53wT0giiRA6xPniZUGhK176EstWGQqE4/rR8fa6953n+ S9FvGnZkjIZYiVa1LrzdFbiRu5uFDAusEM5RkQTe28TNh3wetKeRWtyEvtC4tAsWho8peAWkVFp pWec5MZW0VpoJOUk2bwlYdMAaVg4gtDDU0m3a4cEmwSkF1ZUfgPrZSY4CAsuSNbzPziE3pvN8we Tv7IRvtnIYeDYvH6bZrJRkBmmsI/aAy38b/SBQaMWETzq0We2ItSr2hYepw== X-Received: by 2002:a17:90b:51c8:b0:38e:5b59:c2ff with SMTP id 98e67ed59e1d1-39d9bbc802bmr7093993a91.3.1789136285661; Fri, 11 Sep 2026 07:18:05 -0700 (PDT) Received: from apollo.localdomain ([208.95.233.74]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33ba4fa50efsm7840791eec.28.2026.09.11.07.18.04 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 07:18:05 -0700 (PDT) From: Khem Raj X-Google-Original-From: Khem Raj To: openembedded-devel@lists.openembedded.org Cc: Khem Raj , Khem Raj Subject: [meta-oe][PATCH 6/7] imx-cst: fix remaining build failures with OpenSSL 4 Date: Fri, 11 Sep 2026 07:17:55 -0700 Message-ID: <20260911141756.2275517-6-khem.raj@oss.qualcomm.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260911141756.2275517-1-khem.raj@oss.qualcomm.com> References: <20260911141756.2275517-1-khem.raj@oss.qualcomm.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 11 Sep 2026 14:18:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129970 Two more OpenSSL 4.0 breakages on top of the ASN.1 opacity already handled by 0012-fix-openssl-4-asn1-opaque.patch. The ENGINE API is gone. is still shipped as a source-compatibility stub, so linking fails on ENGINE_free, ENGINE_load_builtin_engines, ENGINE_by_id, ENGINE_init, ENGINE_finish, ENGINE_ctrl_cmd and ENGINE_load_private_key. Define OPENSSL_ENGINE_STUBS, which OpenSSL 4 provides for exactly this case: the declarations become inline no-ops returning failure, so the file compiles and links unchanged. OPENSSL_SUPPRESS_DEPRECATED is already defined there, so the stubs' deprecation attributes do not trip -Werror. That leaves ENGINE_by_id() returning NULL, which the existing code fed straight into ENGINE_init() - a NULL dereference predating OpenSSL 4 - so check it and report what went wrong, mentioning OpenSSL 4 so the failure is not mistaken for a missing module. PKCS#11 backed signing genuinely is unavailable there, as no provider exposes an equivalent of the pkcs11 engine's LOAD_CERT_CTRL. X509_get_subject_name() now returns const X509_NAME *, so its result can no longer be the destination of X509_NAME_add_entry_by_txt(): src/tools/pki_tree/pki_helper.c:440:10: error: assigning to 'X509_NAME *' from 'const X509_NAME *' discards qualifiers There is no mutable counterpart, so build the subject name standalone and install it with X509_set_subject_name(); both setters copy it, so it is freed once the issuer name has been set from it too. AI-Generated: Uses Claude Code Signed-off-by: Khem Raj --- ...015-fix-openssl-4-engine-api-removal.patch | 67 +++++++++++++++++++ ...016-fix-openssl-4-const-subject-name.patch | 48 +++++++++++++ .../recipes-support/imx-cst/imx-cst_4.0.1.bb | 2 + 3 files changed, 117 insertions(+) create mode 100644 meta-oe/recipes-support/imx-cst/imx-cst/0015-fix-openssl-4-engine-api-removal.patch create mode 100644 meta-oe/recipes-support/imx-cst/imx-cst/0016-fix-openssl-4-const-subject-name.patch diff --git a/meta-oe/recipes-support/imx-cst/imx-cst/0015-fix-openssl-4-engine-api-removal.patch b/meta-oe/recipes-support/imx-cst/imx-cst/0015-fix-openssl-4-engine-api-removal.patch new file mode 100644 index 0000000000..d4a3f0ff2e --- /dev/null +++ b/meta-oe/recipes-support/imx-cst/imx-cst/0015-fix-openssl-4-engine-api-removal.patch @@ -0,0 +1,67 @@ +From: Khem Raj +Date: Wed, 3 Sep 2026 01:30:00 +0000 +Subject: Fix FTBFS with OpenSSL 4.0: ENGINE API removal + +OpenSSL 4.0 removed the ENGINE API. is still shipped, +but only as a source-compatibility stub, so linking fails: + + ld.lld: error: undefined symbol: ENGINE_free + ld.lld: error: undefined symbol: ENGINE_load_builtin_engines + ld.lld: error: undefined symbol: ENGINE_by_id + ld.lld: error: undefined symbol: ENGINE_init + ld.lld: error: undefined symbol: ENGINE_finish + ld.lld: error: undefined symbol: ENGINE_ctrl_cmd + ld.lld: error: undefined symbol: ENGINE_load_private_key + +Define OPENSSL_ENGINE_STUBS, which OpenSSL 4 offers exactly for this +case: the ENGINE_* declarations become inline no-ops returning failure, +so the file compiles and links unchanged. OPENSSL_SUPPRESS_DEPRECATED is +already defined here, so the stubs' deprecation attributes do not trip +-Werror either. + +That leaves ENGINE_by_id() returning NULL at runtime, which the existing +code fed straight into ENGINE_init() - a NULL dereference that predates +OpenSSL 4. Check the result and print what went wrong instead, noting the +OpenSSL 4 situation so the failure is not mistaken for a missing module. + +Providers replace engines upstream, but nothing exposes an equivalent of +the pkcs11 engine's LOAD_CERT_CTRL command yet, so PKCS#11 backed signing +genuinely is unavailable with OpenSSL 4. + +Upstream-Status: Pending + +Signed-off-by: Khem Raj +--- +--- a/src/lib/back_end/engine.c ++++ b/src/lib/back_end/engine.c +@@ -4,6 +4,13 @@ + */ + + #define OPENSSL_SUPPRESS_DEPRECATED ++/* ++ * OpenSSL 4.0 removed the ENGINE API. still declares ++ * it for source compatibility, and defining OPENSSL_ENGINE_STUBS turns the ++ * declarations into inline no-ops so this file keeps linking. The pkcs11 ++ * engine simply does not exist there, which engine_ctx_init() reports. ++ */ ++#define OPENSSL_ENGINE_STUBS + + #include "engine.h" + #include "err.h" +@@ -63,6 +70,16 @@ + + ctx->engine = ENGINE_by_id("pkcs11"); + ++ if (!ctx->engine) { ++ fprintf(stderr, "ERROR: cannot load the pkcs11 OpenSSL engine\n"); ++#if OPENSSL_VERSION_MAJOR >= 4 ++ fprintf(stderr, ++ "ERROR: OpenSSL 4.0 removed ENGINE support, so PKCS#11 " ++ "backed signing is unavailable\n"); ++#endif ++ return 0; ++ } ++ + #ifdef DEBUG + ENGINE_ctrl_cmd_string(ctx->engine, "VERBOSE", NULL, 0); + #endif diff --git a/meta-oe/recipes-support/imx-cst/imx-cst/0016-fix-openssl-4-const-subject-name.patch b/meta-oe/recipes-support/imx-cst/imx-cst/0016-fix-openssl-4-const-subject-name.patch new file mode 100644 index 0000000000..3cea584983 --- /dev/null +++ b/meta-oe/recipes-support/imx-cst/imx-cst/0016-fix-openssl-4-const-subject-name.patch @@ -0,0 +1,48 @@ +From: Khem Raj +Date: Wed, 3 Sep 2026 01:30:00 +0000 +Subject: Fix FTBFS with OpenSSL 4.0: const X509_get_subject_name() + +OpenSSL 4.0 changed X509_get_subject_name() to return a const X509_NAME *, +so using its result as the destination of X509_NAME_add_entry_by_txt() no +longer compiles: + + src/tools/pki_tree/pki_helper.c:440:10: error: assigning to 'X509_NAME *' + from 'const X509_NAME *' discards qualifiers + [-Werror,-Wincompatible-pointer-types-discards-qualifiers] + +There is no mutable counterpart to the getter (unlike X509_getm_notAfter), +so build the subject name as a standalone X509_NAME and install it with +X509_set_subject_name(). Both setters copy the name, so it is freed once +the issuer name has been set from it too. + +Upstream-Status: Pending + +Signed-off-by: Khem Raj +--- +--- a/src/tools/pki_tree/pki_helper.c ++++ b/src/tools/pki_tree/pki_helper.c +@@ -437,11 +437,15 @@ + if (X509_set_pubkey(x509, pkey) != 1) + handle_errors(); + +- name = X509_get_subject_name(x509); ++ name = X509_NAME_new(); ++ if (!name) ++ handle_errors(); + if (X509_NAME_add_entry_by_txt(name, "CN", MBSTRING_ASC, + (const unsigned char *) subj, -1, -1, + 0) != 1) + handle_errors(); ++ if (X509_set_subject_name(x509, name) != 1) ++ handle_errors(); + if (sign_cert) + { + if (X509_set_issuer_name(x509, X509_get_subject_name(sign_cert)) != 1) +@@ -452,6 +456,7 @@ + if (X509_set_issuer_name(x509, name) != 1) + handle_errors(); + } ++ X509_NAME_free(name); + + if (is_ca) + { diff --git a/meta-oe/recipes-support/imx-cst/imx-cst_4.0.1.bb b/meta-oe/recipes-support/imx-cst/imx-cst_4.0.1.bb index 03dfdbd6f7..ec6838e95d 100644 --- a/meta-oe/recipes-support/imx-cst/imx-cst_4.0.1.bb +++ b/meta-oe/recipes-support/imx-cst/imx-cst_4.0.1.bb @@ -27,6 +27,8 @@ SRC_URI = "\ file://0012-fix-openssl-4-asn1-opaque.patch \ file://0013-convlb-remove-redundant-NULL-definition.patch \ file://0014-fix-pointer-sign-errors-with-clang.patch \ + file://0015-fix-openssl-4-engine-api-removal.patch \ + file://0016-fix-openssl-4-const-subject-name.patch \ " SRC_URI[sha256sum] = "fd92a1a9faa10fb81bbf752c7ee1e257f17e1ec4c2964f8a47adf8a3eaa7df41" From patchwork Fri Sep 11 14:17:56 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Khem Raj X-Patchwork-Id: 97963 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3B75FC88E58 for ; Fri, 11 Sep 2026 14:18:16 +0000 (UTC) Received: from mail-pg1-f169.google.com (mail-pg1-f169.google.com [209.85.215.169]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.40468.1789136288543614342 for ; Fri, 11 Sep 2026 07:18:08 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=nqAZboAK; spf=pass (domain: gmail.com, ip: 209.85.215.169, mailfrom: raj.khem@gmail.com) Received: by mail-pg1-f169.google.com with SMTP id 41be03b00d2f7-cbedd5aece4so1479545a12.0 for ; Fri, 11 Sep 2026 07:18:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789136288; x=1789741088; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=HDKuqVpilpY4QQQtNnbbBq3253SQs6AU5YSkRM317vA=; b=nqAZboAK/d3IyYKrYb8o8TEJCab0lcLWJrVm7hG4Fxg2BD74K+LiNkjgeYdddtluVq WG3R2+GjGsaR34sJJA1z31fvbC6G5g8Q9YsrORYMMMC/7gM7Aduz3cDEEP+V2U5C5ATd iSPrtEiKAuzVUfr7FTE1T4wPqZXZS3wrHx6gYt5XZHecG+68f1Kw+IlhF3s1rgTJUA6h t9HIn2IWQbSTvC08Eu4zzgeP1f1VVjJSQE147rD6ZBuOXVji8j2p9NkPIVynWRo6zatI b6iEr6nFTdVXwBToXtGbLp8ER0gq8p1UaTCio30yYe1WKPt6RCoaGJFE6ApVNfdh3tSI oGgQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789136288; x=1789741088; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=HDKuqVpilpY4QQQtNnbbBq3253SQs6AU5YSkRM317vA=; b=nb425bvwBf4C/eGsfkKcPQSIbAu/hiuNUXV9amrPwe8oPOcVEHVM60O9CCbC8F4uX7 QSsLDoiGSqQUqr/pQWm/pwvS568Zwva1vLjOK0MgiPDfXP5Q6ZX2k0S103h5/VOLPN/V LM3D9EByKamhi5jP5JIcVcxMQXGFhB57GwUNhW3KOmvAbvELaenurFUDSXe1kZWjhP3N hy1DWQavuPkm6BOdd0u5LY/OlxuuiPPo42Y1XOK1qxYBPUV7dCsgQTienHm8gQdAgkBR LC1PlIcKqUX58p+QdvYnv7WsSdJiScmhsdi/luVc0P9CioKWQpApeq15wGdY9Z9qJ+Gc rk7Q== X-Gm-Message-State: AFuF++kB7TRFQPDlrWwruuwfKgT/3EFgztW5o+a9X5RXMrDhGL8lPu8T XthMTqpJUR/giX9lD70ClGrkWeCrPFaWBUPlIABVdMQo5tL2xBDI88RlaAe/gQ== X-Gm-Gg: AYBFou1q07mZR9LvsLFXalHQYDOWp3yxGGm+AqzaJvT6ix5upDVXozBn5mxTfVWUmHb eM8VP3lsoK/pcz33LpsnL3aHFqIXDe5irxjsfLqbDymcrdoUYVBRzzQ+HJBCAEveTuNlBd68YH4 0f9a1QlI5Rdj3FoehllxniqIVyO9FLzg509unRKM82Ugv149NuzwiaKOO6taQbOKA3wEgrYczgi OHFTuug58+bGriKT4Ni5axDUQ5E+vhN0ZM5wseEx1i32SOyAn+dNIhHSuwJ6VtZXQvP8rb4lWrz G1eWP/njSd6jnxuFNCb2aqw1ZtHGGEvZBpLog1mjc/0zo4gEV7N1EUeiwtpO9r7icOJQtyySq9U 8jNXb1GqI7eJBusaYdDxS4Y4cwi2xM9UM6KAUh/U+87n9yYJXSemLLjU40i+MP7kL8pfaTUrDO2 qZZ6P/sl/xS3xA8i0LUI2dPXS2hwp+rUH7gnSJ93GJvtEtxYNpgj650YtQ10H9qYal5QSguU6HW bWMUzGPdn1YIhHPVgW5t0DVMf1IjoLpjPwV1azlP34hAYHG55Hsvl5mOkZ+7l9v8gNRPz/aoJv+ aXiCcvlzlW9xsDBKR3XetYlD76gROJG4uqtfj0tgrR8wUfsMmH1mypLAiN31JtoEGerpapjmlq+ sby71kLwaRJDS2FD+sRWcv/A2MVAvchvIdZDQJFLu1Ylgv9Dmjtuh2pMl3IhHDIZfQ2E= X-Received: by 2002:a17:90b:3e47:b0:36b:de66:92c3 with SMTP id 98e67ed59e1d1-39d77964296mr14149204a91.10.1789136287121; Fri, 11 Sep 2026 07:18:07 -0700 (PDT) Received: from apollo.localdomain ([208.95.233.74]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33ba4fa50efsm7840791eec.28.2026.09.11.07.18.05 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 07:18:06 -0700 (PDT) From: Khem Raj X-Google-Original-From: Khem Raj To: openembedded-devel@lists.openembedded.org Cc: Khem Raj , Khem Raj Subject: [meta-oe][PATCH 7/7] synergy: fix build with OpenSSL 4 Date: Fri, 11 Sep 2026 07:17:56 -0700 Message-ID: <20260911141756.2275517-7-khem.raj@oss.qualcomm.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260911141756.2275517-1-khem.raj@oss.qualcomm.com> References: <20260911141756.2275517-1-khem.raj@oss.qualcomm.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 11 Sep 2026 14:18:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129971 TLSv1_2_server_method() and TLSv1_2_client_method() were deprecated in OpenSSL 1.1.0 and removed in OpenSSL 4.0, so do_compile fails: SecureSocket.cpp:386:18: error: use of undeclared identifier 'TLSv1_2_server_method'; did you mean 'TLS_server_method'? SecureSocket.cpp:389:18: error: use of undeclared identifier 'TLSv1_2_client_method'; did you mean 'TLS_client_method'? Backport the two upstream commits that deal with this, neither of which is in the v1.10.1 SRCREV pinned here - they first shipped in v1.11.0: 4fea67e078479cc00afe6b1201c54c997a41fc70 "#6390 Updated OpenSSL For better security with TLS1.3" 4d3cf2c6 "Preventing older insecure version of TLS/SSL" The first swaps the removed version specific methods for the version flexible ones; the second restores the TLS 1.2 floor with SSL_CTX_set_options(). Both are needed: the first on its own silently drops the minimum version the original code deliberately enforced, for the PCI compliance reasons its comment describes. Since TLS 1.3 can now be negotiated, the hardcoded "TLSv1.2" reported to the user is replaced with the version actually in use, retiring k_tlsString. Upgrading the recipe instead is not an option today. Upstream renamed the repository to symless/synergy and the latest release, v1.20.4, is the rebranded deskflow codebase with a different cmake layout, a Qt6 GUI and a changed LICENSE; more importantly it hard requires the ext/synergy-extra submodule, declared with an ssh URL and carrying no license at all, and its cmake aborts without it. That has been true since v1.16.x. No pending upstream pull request addresses the build failure either, since upstream fixed it in tree back in 2019. The backport differs from upstream in two intentional ways, both noted in the patch: upstream's pre-1.1.0 fallback defines the client method to SSLv23_server_method, and upstream sets the context options before checking SSL_CTX_new() for NULL. AI-Generated: Uses Claude Code Signed-off-by: Khem Raj --- ...ot-use-the-removed-TLSv1_2_-method-c.patch | 113 ++++++++++++++++++ .../recipes-support/synergy/synergy_git.bb | 1 + 2 files changed, 114 insertions(+) create mode 100644 meta-oe/recipes-support/synergy/synergy/0001-SecureSocket-do-not-use-the-removed-TLSv1_2_-method-c.patch diff --git a/meta-oe/recipes-support/synergy/synergy/0001-SecureSocket-do-not-use-the-removed-TLSv1_2_-method-c.patch b/meta-oe/recipes-support/synergy/synergy/0001-SecureSocket-do-not-use-the-removed-TLSv1_2_-method-c.patch new file mode 100644 index 0000000000..890cba69cc --- /dev/null +++ b/meta-oe/recipes-support/synergy/synergy/0001-SecureSocket-do-not-use-the-removed-TLSv1_2_-method-c.patch @@ -0,0 +1,113 @@ +From: Khem Raj +Date: Thu, 10 Sep 2026 19:20:00 +0000 +Subject: [PATCH] SecureSocket: do not use the removed TLSv1_2_*_method calls + +The version specific TLSv1_2_server_method() and TLSv1_2_client_method() +were deprecated in OpenSSL 1.1.0 and removed outright in OpenSSL 4.0, so +do_compile fails: + + SecureSocket.cpp:386:18: error: use of undeclared identifier 'TLSv1_2_server_method'; did you mean 'TLS_server_method'? + SecureSocket.cpp:389:18: error: use of undeclared identifier 'TLSv1_2_client_method'; did you mean 'TLS_client_method'? + +Pick the version flexible method instead and keep the TLS 1.2 floor the +old code was after by excluding every earlier version through +SSL_CTX_set_options(). Since TLS 1.3 can now be negotiated, the hardcoded +"TLSv1.2" that was reported to the user is replaced with the version +actually in use, which also retires k_tlsString. + +This is a backport of two upstream commits, neither of which is in the +v1.10.1 SRCREV this recipe pins (they first shipped in v1.11.0): + + 4fea67e078479cc00afe6b1201c54c997a41fc70 + "#6390 Updated OpenSSL For better security with TLS1.3" + 4d3cf2c6 "Preventing older insecure version of TLS/SSL" + +Two deliberate differences from upstream: + + - upstream's pre-1.1.0 fallback defines SSL_CLIENT_METHOD to + SSLv23_server_method, so a client would ask for a server method. That + typo is still present upstream; use SSLv23_client_method here. Only the + OPENSSL_VERSION_NUMBER > 0x10100000L branch is taken in this build, so + the difference is inert here, but there is no reason to copy the bug. + + - upstream calls SSL_CTX_set_options() before checking SSL_CTX_new() for + NULL, which dereferences a NULL context on allocation failure. Check + first and return, then set the options. + +Upstream-Status: Backport [4fea67e078479cc00afe6b1201c54c997a41fc70 and +4d3cf2c6, adapted to v1.10.1; the two differences above are not upstream] +Signed-off-by: Khem Raj +--- +diff --git a/src/lib/net/SecureSocket.cpp b/src/lib/net/SecureSocket.cpp +index 1111111..2222222 100644 +--- a/src/lib/net/SecureSocket.cpp ++++ b/src/lib/net/SecureSocket.cpp +@@ -37,8 +37,16 @@ + + #define MAX_ERROR_SIZE 65535 + ++//Add the new function names in case older ones are deprecated ++#if OPENSSL_VERSION_NUMBER > 0x10100000L ++#define SSL_SERVER_METHOD TLS_server_method ++#define SSL_CLIENT_METHOD TLS_client_method ++#else ++#define SSL_SERVER_METHOD SSLv23_server_method ++#define SSL_CLIENT_METHOD SSLv23_client_method ++#endif ++ + static const float s_retryDelay = 0.01f; +-const char* k_tlsString = "TLSv1.2"; + + enum { + kMsgSize = 128 +@@ -376,26 +384,33 @@ + showSecureLibInfo(); + } + +- // only use TLS 1.2 (latest as of 27 jul 18). previously we were using +- // the SSLv23_server_method and SSLv23_client_method functions with ++ // only use TLS 1.2 or newer. previously we were using the ++ // SSLv23_server_method and SSLv23_client_method functions with + // SSL_OP_NO_SSLv3, but not SSL_OP_NO_SSLv2, so there was a potential + // vulnerability where it could fall back to SSLv2 (not TLS). also, + // the SSLv23_*_method functions could fall back to TLS 1.0 and 1.1, +- // which are nolonger PCI compliant. ++ // which are nolonger PCI compliant. the version specific ++ // TLSv1_2_*_method functions were removed in OpenSSL 4.0, so pick the ++ // version flexible method and exclude everything below TLS 1.2 below. + if (server) { +- method = TLSv1_2_server_method(); ++ method = SSL_SERVER_METHOD(); + } + else { +- method = TLSv1_2_client_method(); ++ method = SSL_CLIENT_METHOD(); + } +- ++ + // create new context from method + SSL_METHOD* m = const_cast(method); + m_ssl->m_context = SSL_CTX_new(m); + + if (m_ssl->m_context == NULL) { + showError(); ++ return; + } ++ ++ // prevent the use of every version prior to TLS 1.2, as they are known ++ // to be vulnerable ++ SSL_CTX_set_options(m_ssl->m_context, SSL_OP_NO_SSLv2 | SSL_OP_NO_SSLv3 | SSL_OP_NO_TLSv1 | SSL_OP_NO_TLSv1_1); + } + + void +@@ -848,9 +863,7 @@ + LOG((CLOG_DEBUG "openssl cipher: %s", msg)); + + // show user a simpler version of the openssl cipher output +- if (std::string(msg).find(k_tlsString) != std::string::npos) { +- LOG((CLOG_INFO "network encryption protocol: %s", k_tlsString)); +- } ++ LOG((CLOG_INFO "network encryption protocol: %s", SSL_CIPHER_get_version(cipher))); + } + else { + LOG((CLOG_ERR "could not get secure socket cipher")); diff --git a/meta-oe/recipes-support/synergy/synergy_git.bb b/meta-oe/recipes-support/synergy/synergy_git.bb index cf411b7c78..7f508177b1 100644 --- a/meta-oe/recipes-support/synergy/synergy_git.bb +++ b/meta-oe/recipes-support/synergy/synergy_git.bb @@ -11,6 +11,7 @@ REQUIRED_DISTRO_FEATURES = "x11" SRC_URI = "git://github.com/symless/synergy-core;protocol=https;nobranch=1" SRC_URI += "file://CVE-2020-15117.patch" +SRC_URI += "file://0001-SecureSocket-do-not-use-the-removed-TLSv1_2_-method-c.patch" # Version 1.10.1-stable SRCREV ?= "1b4c076127687aceac931d269e898beaac1cad9f"