From 061a33b36a5887f3e1101de687b2b77ac6cbb198 Mon Sep 17 00:00:00 2001 From: Bernd Kuhls Date: Sun, 27 Sep 2026 12:42:33 +0200 Subject: [PATCH] package/mender: fix build with OpenSSL 4.0.0 Signed-off-by: Bernd Kuhls Signed-off-by: Thomas Petazzoni --- package/mender/0001-openssl-v4-update.patch | 191 ++++++++++++++++++++ 1 file changed, 191 insertions(+) create mode 100644 package/mender/0001-openssl-v4-update.patch diff --git a/package/mender/0001-openssl-v4-update.patch b/package/mender/0001-openssl-v4-update.patch new file mode 100644 index 0000000000..65443614d5 --- /dev/null +++ b/package/mender/0001-openssl-v4-update.patch @@ -0,0 +1,191 @@ +Description: Fix build compatibility with OpenSSL 4.0 + Include in hostname.c and hostname.go before checking + #ifndef X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT, preventing fallback to + legacy OpenSSL < 1.0.2 code that attempts to directly access opaque + ASN1_STRING fields. + Also add preprocessor guards around deprecated protocol methods + (SSLv3_method, TLSv1_method, TLSv1_1_method, TLSv1_2_method) in shim.c + and ENGINE functions (ENGINE_by_id, ENGINE_init, ENGINE_free, + ENGINE_finish, ENGINE_load_private_key, ENGINE_load_builtin_engines) + in shim.c, shim.h, engine.go, key.go to prevent implicit declaration + and undefined reference errors when building against OpenSSL 4.0. +Author: Frank Heimes + +Downloaded from Ubuntu: +https://git.launchpad.net/ubuntu/+source/golang-github-mendersoftware-openssl/tree/debian/patches/0004-openssl-v4-update.patch?h=applied/ubuntu/stonking-devel + +Upstream: not applicable, upstream moved to c++ in newer versions + +[Bernd: rebased for vendored download by buildroot infra] +Signed-off-by: Bernd Kuhls + +diff -uNr mender-3.5.3.orig/vendor/github.com/mendersoftware/openssl/engine.go mender-3.5.3/vendor/github.com/mendersoftware/openssl/engine.go +--- mender-3.5.3.orig/vendor/github.com/mendersoftware/openssl/engine.go 2024-05-24 12:07:27.000000000 +0200 ++++ mender-3.5.3/vendor/github.com/mendersoftware/openssl/engine.go 2026-09-20 18:37:50.270612314 +0200 +@@ -15,6 +15,7 @@ + package openssl + + /* ++#include "shim.h" + #include "openssl/engine.h" + */ + import "C" +@@ -33,18 +34,18 @@ + cname := C.CString(name) + defer C.free(unsafe.Pointer(cname)) + e := &Engine{ +- e: C.ENGINE_by_id(cname), ++ e: C.X_ENGINE_by_id(cname), + } + if e.e == nil { + return nil, fmt.Errorf("engine %s missing", name) + } +- if C.ENGINE_init(e.e) == 0 { +- C.ENGINE_free(e.e) ++ if C.X_ENGINE_init(e.e) == 0 { ++ C.X_ENGINE_free(e.e) + return nil, fmt.Errorf("engine %s not initialized", name) + } + runtime.SetFinalizer(e, func(e *Engine) { +- C.ENGINE_finish(e.e) +- C.ENGINE_free(e.e) ++ C.X_ENGINE_finish(e.e) ++ C.X_ENGINE_free(e.e) + }) + return e, nil + } +diff -uNr mender-3.5.3.orig/vendor/github.com/mendersoftware/openssl/hostname.c mender-3.5.3/vendor/github.com/mendersoftware/openssl/hostname.c +--- mender-3.5.3.orig/vendor/github.com/mendersoftware/openssl/hostname.c 2024-05-24 12:07:27.000000000 +0200 ++++ mender-3.5.3/vendor/github.com/mendersoftware/openssl/hostname.c 2026-09-20 18:32:37.854514981 +0200 +@@ -6,6 +6,7 @@ + */ + + #include ++#include + + #ifndef X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT + +diff -uNr mender-3.5.3.orig/vendor/github.com/mendersoftware/openssl/key.go mender-3.5.3/vendor/github.com/mendersoftware/openssl/key.go +--- mender-3.5.3.orig/vendor/github.com/mendersoftware/openssl/key.go 2024-05-24 12:07:27.000000000 +0200 ++++ mender-3.5.3/vendor/github.com/mendersoftware/openssl/key.go 2026-09-20 18:38:13.462370202 +0200 +@@ -303,7 +303,7 @@ + keyID := C.CString(id) + defer C.free(unsafe.Pointer(keyID)) + +- key := C.ENGINE_load_private_key(e.e, keyID, nil, nil) ++ key := C.X_ENGINE_load_private_key(e.e, keyID, nil, nil) + if key == nil { + return nil, errors.New("cannot load private key, ENGINE_load_private_key error") + } +diff -uNr mender-3.5.3.orig/vendor/github.com/mendersoftware/openssl/shim.c mender-3.5.3/vendor/github.com/mendersoftware/openssl/shim.c +--- mender-3.5.3.orig/vendor/github.com/mendersoftware/openssl/shim.c 2024-05-24 12:07:27.000000000 +0200 ++++ mender-3.5.3/vendor/github.com/mendersoftware/openssl/shim.c 2026-09-20 18:36:02.855038372 +0200 +@@ -382,7 +382,9 @@ + int rc = 0; + + OPENSSL_config(NULL); ++#if OPENSSL_VERSION_NUMBER < 0x40000000L && !defined(OPENSSL_NO_ENGINE) + ENGINE_load_builtin_engines(); ++#endif + SSL_load_error_strings(); + SSL_library_init(); + OpenSSL_add_all_algorithms(); +@@ -403,6 +405,46 @@ + return 0; + } + ++ENGINE *X_ENGINE_by_id(const char *id) { ++#if OPENSSL_VERSION_NUMBER < 0x40000000L && !defined(OPENSSL_NO_ENGINE) ++ return ENGINE_by_id(id); ++#else ++ return NULL; ++#endif ++} ++ ++int X_ENGINE_init(ENGINE *e) { ++#if OPENSSL_VERSION_NUMBER < 0x40000000L && !defined(OPENSSL_NO_ENGINE) ++ return ENGINE_init(e); ++#else ++ return 0; ++#endif ++} ++ ++int X_ENGINE_free(ENGINE *e) { ++#if OPENSSL_VERSION_NUMBER < 0x40000000L && !defined(OPENSSL_NO_ENGINE) ++ return ENGINE_free(e); ++#else ++ return 0; ++#endif ++} ++ ++int X_ENGINE_finish(ENGINE *e) { ++#if OPENSSL_VERSION_NUMBER < 0x40000000L && !defined(OPENSSL_NO_ENGINE) ++ return ENGINE_finish(e); ++#else ++ return 0; ++#endif ++} ++ ++EVP_PKEY *X_ENGINE_load_private_key(ENGINE *e, const char *key_id, UI_METHOD *ui_method, void *callback_data) { ++#if OPENSSL_VERSION_NUMBER < 0x40000000L && !defined(OPENSSL_NO_ENGINE) ++ return ENGINE_load_private_key(e, key_id, ui_method, callback_data); ++#else ++ return NULL; ++#endif ++} ++ + void * X_OPENSSL_malloc(size_t size) { + return OPENSSL_malloc(size); + } +@@ -480,7 +522,7 @@ + } + + const SSL_METHOD *X_SSLv3_method() { +-#ifndef OPENSSL_NO_SSL3_METHOD ++#if OPENSSL_VERSION_NUMBER < 0x40000000L && !defined(OPENSSL_NO_SSL3_METHOD) && !defined(OPENSSL_NO_DEPRECATED_1_1_0) && !defined(OPENSSL_NO_DEPRECATED_3_0) + return SSLv3_method(); + #else + return NULL; +@@ -488,11 +530,15 @@ + } + + const SSL_METHOD *X_TLSv1_method() { ++#if OPENSSL_VERSION_NUMBER < 0x40000000L && !defined(OPENSSL_NO_TLS1_METHOD) && !defined(OPENSSL_NO_DEPRECATED_1_1_0) && !defined(OPENSSL_NO_DEPRECATED_3_0) + return TLSv1_method(); ++#else ++ return NULL; ++#endif + } + + const SSL_METHOD *X_TLSv1_1_method() { +-#if defined(TLS1_1_VERSION) && !defined(OPENSSL_SYSNAME_MACOSX) ++#if OPENSSL_VERSION_NUMBER < 0x40000000L && defined(TLS1_1_VERSION) && !defined(OPENSSL_SYSNAME_MACOSX) && !defined(OPENSSL_NO_TLS1_1_METHOD) && !defined(OPENSSL_NO_DEPRECATED_1_1_0) && !defined(OPENSSL_NO_DEPRECATED_3_0) + return TLSv1_1_method(); + #else + return NULL; +@@ -500,7 +546,7 @@ + } + + const SSL_METHOD *X_TLSv1_2_method() { +-#if defined(TLS1_2_VERSION) && !defined(OPENSSL_SYSNAME_MACOSX) ++#if OPENSSL_VERSION_NUMBER < 0x40000000L && defined(TLS1_2_VERSION) && !defined(OPENSSL_SYSNAME_MACOSX) && !defined(OPENSSL_NO_TLS1_2_METHOD) && !defined(OPENSSL_NO_DEPRECATED_1_1_0) && !defined(OPENSSL_NO_DEPRECATED_3_0) + return TLSv1_2_method(); + #else + return NULL; +diff -uNr mender-3.5.3.orig/vendor/github.com/mendersoftware/openssl/shim.h mender-3.5.3/vendor/github.com/mendersoftware/openssl/shim.h +--- mender-3.5.3.orig/vendor/github.com/mendersoftware/openssl/shim.h 2024-05-24 12:07:27.000000000 +0200 ++++ mender-3.5.3/vendor/github.com/mendersoftware/openssl/shim.h 2026-09-20 18:38:33.117854985 +0200 +@@ -40,6 +40,13 @@ + /* shim methods */ + extern int X_shim_init(); + ++/* Engine methods */ ++extern ENGINE *X_ENGINE_by_id(const char *id); ++extern int X_ENGINE_init(ENGINE *e); ++extern int X_ENGINE_free(ENGINE *e); ++extern int X_ENGINE_finish(ENGINE *e); ++extern EVP_PKEY *X_ENGINE_load_private_key(ENGINE *e, const char *key_id, UI_METHOD *ui_method, void *callback_data); ++ + /* Library methods */ + extern void X_OPENSSL_free(void *ref); + extern void *X_OPENSSL_malloc(size_t size);