package/mender: fix build with OpenSSL 4.0.0

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
This commit is contained in:
Bernd Kuhls
2026-09-27 12:42:33 +02:00
committed by Thomas Petazzoni
parent 3caf39eb79
commit 061a33b36a

View File

@@ -0,0 +1,191 @@
Description: Fix build compatibility with OpenSSL 4.0
Include <openssl/x509v3.h> in hostname.c and hostname.go before checking
#ifndef X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT, preventing fallback to
legacy OpenSSL < 1.0.2 code that attempts to directly access opaque
ASN1_STRING fields.
Also add preprocessor guards around deprecated protocol methods
(SSLv3_method, TLSv1_method, TLSv1_1_method, TLSv1_2_method) in shim.c
and ENGINE functions (ENGINE_by_id, ENGINE_init, ENGINE_free,
ENGINE_finish, ENGINE_load_private_key, ENGINE_load_builtin_engines)
in shim.c, shim.h, engine.go, key.go to prevent implicit declaration
and undefined reference errors when building against OpenSSL 4.0.
Author: Frank Heimes <frank.heimes@canonical.com>
Downloaded from Ubuntu:
https://git.launchpad.net/ubuntu/+source/golang-github-mendersoftware-openssl/tree/debian/patches/0004-openssl-v4-update.patch?h=applied/ubuntu/stonking-devel
Upstream: not applicable, upstream moved to c++ in newer versions
[Bernd: rebased for vendored download by buildroot infra]
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
diff -uNr mender-3.5.3.orig/vendor/github.com/mendersoftware/openssl/engine.go mender-3.5.3/vendor/github.com/mendersoftware/openssl/engine.go
--- mender-3.5.3.orig/vendor/github.com/mendersoftware/openssl/engine.go 2024-05-24 12:07:27.000000000 +0200
+++ mender-3.5.3/vendor/github.com/mendersoftware/openssl/engine.go 2026-09-20 18:37:50.270612314 +0200
@@ -15,6 +15,7 @@
package openssl
/*
+#include "shim.h"
#include "openssl/engine.h"
*/
import "C"
@@ -33,18 +34,18 @@
cname := C.CString(name)
defer C.free(unsafe.Pointer(cname))
e := &Engine{
- e: C.ENGINE_by_id(cname),
+ e: C.X_ENGINE_by_id(cname),
}
if e.e == nil {
return nil, fmt.Errorf("engine %s missing", name)
}
- if C.ENGINE_init(e.e) == 0 {
- C.ENGINE_free(e.e)
+ if C.X_ENGINE_init(e.e) == 0 {
+ C.X_ENGINE_free(e.e)
return nil, fmt.Errorf("engine %s not initialized", name)
}
runtime.SetFinalizer(e, func(e *Engine) {
- C.ENGINE_finish(e.e)
- C.ENGINE_free(e.e)
+ C.X_ENGINE_finish(e.e)
+ C.X_ENGINE_free(e.e)
})
return e, nil
}
diff -uNr mender-3.5.3.orig/vendor/github.com/mendersoftware/openssl/hostname.c mender-3.5.3/vendor/github.com/mendersoftware/openssl/hostname.c
--- mender-3.5.3.orig/vendor/github.com/mendersoftware/openssl/hostname.c 2024-05-24 12:07:27.000000000 +0200
+++ mender-3.5.3/vendor/github.com/mendersoftware/openssl/hostname.c 2026-09-20 18:32:37.854514981 +0200
@@ -6,6 +6,7 @@
*/
#include <openssl/x509.h>
+#include <openssl/x509v3.h>
#ifndef X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT
diff -uNr mender-3.5.3.orig/vendor/github.com/mendersoftware/openssl/key.go mender-3.5.3/vendor/github.com/mendersoftware/openssl/key.go
--- mender-3.5.3.orig/vendor/github.com/mendersoftware/openssl/key.go 2024-05-24 12:07:27.000000000 +0200
+++ mender-3.5.3/vendor/github.com/mendersoftware/openssl/key.go 2026-09-20 18:38:13.462370202 +0200
@@ -303,7 +303,7 @@
keyID := C.CString(id)
defer C.free(unsafe.Pointer(keyID))
- key := C.ENGINE_load_private_key(e.e, keyID, nil, nil)
+ key := C.X_ENGINE_load_private_key(e.e, keyID, nil, nil)
if key == nil {
return nil, errors.New("cannot load private key, ENGINE_load_private_key error")
}
diff -uNr mender-3.5.3.orig/vendor/github.com/mendersoftware/openssl/shim.c mender-3.5.3/vendor/github.com/mendersoftware/openssl/shim.c
--- mender-3.5.3.orig/vendor/github.com/mendersoftware/openssl/shim.c 2024-05-24 12:07:27.000000000 +0200
+++ mender-3.5.3/vendor/github.com/mendersoftware/openssl/shim.c 2026-09-20 18:36:02.855038372 +0200
@@ -382,7 +382,9 @@
int rc = 0;
OPENSSL_config(NULL);
+#if OPENSSL_VERSION_NUMBER < 0x40000000L && !defined(OPENSSL_NO_ENGINE)
ENGINE_load_builtin_engines();
+#endif
SSL_load_error_strings();
SSL_library_init();
OpenSSL_add_all_algorithms();
@@ -403,6 +405,46 @@
return 0;
}
+ENGINE *X_ENGINE_by_id(const char *id) {
+#if OPENSSL_VERSION_NUMBER < 0x40000000L && !defined(OPENSSL_NO_ENGINE)
+ return ENGINE_by_id(id);
+#else
+ return NULL;
+#endif
+}
+
+int X_ENGINE_init(ENGINE *e) {
+#if OPENSSL_VERSION_NUMBER < 0x40000000L && !defined(OPENSSL_NO_ENGINE)
+ return ENGINE_init(e);
+#else
+ return 0;
+#endif
+}
+
+int X_ENGINE_free(ENGINE *e) {
+#if OPENSSL_VERSION_NUMBER < 0x40000000L && !defined(OPENSSL_NO_ENGINE)
+ return ENGINE_free(e);
+#else
+ return 0;
+#endif
+}
+
+int X_ENGINE_finish(ENGINE *e) {
+#if OPENSSL_VERSION_NUMBER < 0x40000000L && !defined(OPENSSL_NO_ENGINE)
+ return ENGINE_finish(e);
+#else
+ return 0;
+#endif
+}
+
+EVP_PKEY *X_ENGINE_load_private_key(ENGINE *e, const char *key_id, UI_METHOD *ui_method, void *callback_data) {
+#if OPENSSL_VERSION_NUMBER < 0x40000000L && !defined(OPENSSL_NO_ENGINE)
+ return ENGINE_load_private_key(e, key_id, ui_method, callback_data);
+#else
+ return NULL;
+#endif
+}
+
void * X_OPENSSL_malloc(size_t size) {
return OPENSSL_malloc(size);
}
@@ -480,7 +522,7 @@
}
const SSL_METHOD *X_SSLv3_method() {
-#ifndef OPENSSL_NO_SSL3_METHOD
+#if OPENSSL_VERSION_NUMBER < 0x40000000L && !defined(OPENSSL_NO_SSL3_METHOD) && !defined(OPENSSL_NO_DEPRECATED_1_1_0) && !defined(OPENSSL_NO_DEPRECATED_3_0)
return SSLv3_method();
#else
return NULL;
@@ -488,11 +530,15 @@
}
const SSL_METHOD *X_TLSv1_method() {
+#if OPENSSL_VERSION_NUMBER < 0x40000000L && !defined(OPENSSL_NO_TLS1_METHOD) && !defined(OPENSSL_NO_DEPRECATED_1_1_0) && !defined(OPENSSL_NO_DEPRECATED_3_0)
return TLSv1_method();
+#else
+ return NULL;
+#endif
}
const SSL_METHOD *X_TLSv1_1_method() {
-#if defined(TLS1_1_VERSION) && !defined(OPENSSL_SYSNAME_MACOSX)
+#if OPENSSL_VERSION_NUMBER < 0x40000000L && defined(TLS1_1_VERSION) && !defined(OPENSSL_SYSNAME_MACOSX) && !defined(OPENSSL_NO_TLS1_1_METHOD) && !defined(OPENSSL_NO_DEPRECATED_1_1_0) && !defined(OPENSSL_NO_DEPRECATED_3_0)
return TLSv1_1_method();
#else
return NULL;
@@ -500,7 +546,7 @@
}
const SSL_METHOD *X_TLSv1_2_method() {
-#if defined(TLS1_2_VERSION) && !defined(OPENSSL_SYSNAME_MACOSX)
+#if OPENSSL_VERSION_NUMBER < 0x40000000L && defined(TLS1_2_VERSION) && !defined(OPENSSL_SYSNAME_MACOSX) && !defined(OPENSSL_NO_TLS1_2_METHOD) && !defined(OPENSSL_NO_DEPRECATED_1_1_0) && !defined(OPENSSL_NO_DEPRECATED_3_0)
return TLSv1_2_method();
#else
return NULL;
diff -uNr mender-3.5.3.orig/vendor/github.com/mendersoftware/openssl/shim.h mender-3.5.3/vendor/github.com/mendersoftware/openssl/shim.h
--- mender-3.5.3.orig/vendor/github.com/mendersoftware/openssl/shim.h 2024-05-24 12:07:27.000000000 +0200
+++ mender-3.5.3/vendor/github.com/mendersoftware/openssl/shim.h 2026-09-20 18:38:33.117854985 +0200
@@ -40,6 +40,13 @@
/* shim methods */
extern int X_shim_init();
+/* Engine methods */
+extern ENGINE *X_ENGINE_by_id(const char *id);
+extern int X_ENGINE_init(ENGINE *e);
+extern int X_ENGINE_free(ENGINE *e);
+extern int X_ENGINE_finish(ENGINE *e);
+extern EVP_PKEY *X_ENGINE_load_private_key(ENGINE *e, const char *key_id, UI_METHOD *ui_method, void *callback_data);
+
/* Library methods */
extern void X_OPENSSL_free(void *ref);
extern void *X_OPENSSL_malloc(size_t size);