From 0b1caae22baf5c89e5650c1264002af71f88c3ea Mon Sep 17 00:00:00 2001 From: Bernd Kuhls Date: Sun, 27 Sep 2026 12:42:35 +0200 Subject: [PATCH] package/mtd: fix build with OpenSSL 4.0.0 Signed-off-by: Bernd Kuhls Signed-off-by: Thomas Petazzoni --- ...t-compile-engine-support-if-not-avai.patch | 62 +++++++++++++++++++ 1 file changed, 62 insertions(+) create mode 100644 package/mtd/0001-ubifs-utils-Don-t-compile-engine-support-if-not-avai.patch diff --git a/package/mtd/0001-ubifs-utils-Don-t-compile-engine-support-if-not-avai.patch b/package/mtd/0001-ubifs-utils-Don-t-compile-engine-support-if-not-avai.patch new file mode 100644 index 0000000000..21fc2ca2fd --- /dev/null +++ b/package/mtd/0001-ubifs-utils-Don-t-compile-engine-support-if-not-avai.patch @@ -0,0 +1,62 @@ +From 50136f0ec6d8c9763889d49b31ca6965189afba5 Mon Sep 17 00:00:00 2001 +From: Sebastian Andrzej Siewior +Date: Sat, 29 Aug 2026 19:25:02 +0200 +Subject: [PATCH] ubifs-utils: Don't compile engine support if not available + +OpenSSL 4.0 dropped engine support which was deprecated since 3.0. The +replacement is the "providers" API. + +Add an ifndef OPENSSL_NO_ENGINE around the engine code so it can be left +out where it is not supported. + +Signed-off-by: Sebastian Andrzej Siewior + +Upstream: https://lists.infradead.org/pipermail/linux-mtd/2026-August/114868.html + +Signed-off-by: Bernd Kuhls +--- + ubifs-utils/common/sign.c | 10 +++++++++- + 1 file changed, 9 insertions(+), 1 deletion(-) + +diff --git a/ubifs-utils/common/sign.c b/ubifs-utils/common/sign.c +index 032a6ac..5f94c0a 100644 +--- a/ubifs-utils/common/sign.c ++++ b/ubifs-utils/common/sign.c +@@ -23,11 +23,14 @@ + #include + #include + #include +-#include + #include + #include + #include + ++#ifndef OPENSSL_NO_ENGINE ++#include ++#endif ++ + #include "linux_types.h" + #include "sign.h" + #include "ubifs.h" +@@ -139,6 +142,7 @@ static EVP_PKEY *read_private_key(const char *private_key_name, X509 **cert) + *cert = NULL; + + if (!strncmp(private_key_name, "pkcs11:", 7)) { ++#ifndef OPENSSL_NO_ENGINE + ENGINE *e; + struct { + const char *url; +@@ -177,6 +181,10 @@ static EVP_PKEY *read_private_key(const char *private_key_name, X509 **cert) + } + *cert = parms.cert; + fprintf(stderr, "Using cert %p\n", *cert); ++#else ++ ssl_err_msg("PKCS#11 ENGINE support not available."); ++ return NULL; ++#endif + } else { + BIO *b; + +-- +2.47.3 +