From 28f9f29b5e4b79e9a7061066b3d22656bfd9bbc3 Mon Sep 17 00:00:00 2001 From: Quentin Schulz Date: Tue, 7 Apr 2026 19:37:09 +0200 Subject: [PATCH] package/ca-certificates: enable host package variant The host ca-certificates is needed to download the SPDX schema on CycloneDX's GitHub when using Buildroot's host Python, see urllib.request.urlretrieve(SPDX_SCHEMA_URL, SPDX_SCHEMA_PATH) in utils/generate-cyclonedx. Note that unlike the target package which uses a _TARGET_FINALIZE_HOOKS since commit 2bc8e72bafed ("package/ca-certificates: create the bundle as target-finalize hook"), the host package doesn't have this option as there's no such hook for host packages. Therefore, the target's CA_CERTIFICATES_INSTALL_TARGET_CMDS and CA_CERTIFICATES_GEN_BUNDLE are merged and adapted into HOST_CA_CERTIFICATES_INSTALL_CMDS. This of course has the same shortcomings as the target package had before commit 2bc8e72bafed ("package/ca-certificates: create the bundle as target-finalize hook"). The adaptations were: - replaced $(TARGET_MAKE_ENV) with $(HOST_MAKE_ENV) - replaced $(TARGET_DIR) to $(HOST_DIR) - replaced $(HOST_DIR)/usr with $(HOST_DIR) - replaced find usr/share/ca-certificates with find share/ca-certificates (since it's done from within $(HOST_DIR) Signed-off-by: Quentin Schulz Signed-off-by: Arnout Vandecappelle --- package/Config.in.host | 1 + package/ca-certificates/Config.in.host | 12 +++++++++ package/ca-certificates/ca-certificates.mk | 30 ++++++++++++++++++++++ 3 files changed, 43 insertions(+) create mode 100644 package/ca-certificates/Config.in.host diff --git a/package/Config.in.host b/package/Config.in.host index bb6732a639..df57cc0c17 100644 --- a/package/Config.in.host +++ b/package/Config.in.host @@ -14,6 +14,7 @@ menu "Host utilities" source "package/bmap-writer/Config.in.host" source "package/bootgen/Config.in.host" source "package/btrfs-progs/Config.in.host" + source "package/ca-certificates/Config.in.host" source "package/casync-nano/Config.in.host" source "package/cbootimage/Config.in.host" source "package/checkpolicy/Config.in.host" diff --git a/package/ca-certificates/Config.in.host b/package/ca-certificates/Config.in.host new file mode 100644 index 0000000000..950f5854dc --- /dev/null +++ b/package/ca-certificates/Config.in.host @@ -0,0 +1,12 @@ +config BR2_PACKAGE_HOST_CA_CERTIFICATES + bool "Host CA Certificates" + help + This package includes PEM files of CA certificates to allow + SSL-based applications to check for the authenticity of SSL + connections on the host. + + It includes, among others, certificate authorities used by the + Debian infrastructure and those shipped with Mozilla's + browsers. + + https://salsa.debian.org/debian/ca-certificates diff --git a/package/ca-certificates/ca-certificates.mk b/package/ca-certificates/ca-certificates.mk index 1f3f192d4a..f5675b754d 100644 --- a/package/ca-certificates/ca-certificates.mk +++ b/package/ca-certificates/ca-certificates.mk @@ -8,6 +8,7 @@ CA_CERTIFICATES_VERSION = 20260223 CA_CERTIFICATES_SOURCE = ca-certificates_$(CA_CERTIFICATES_VERSION).tar.xz CA_CERTIFICATES_SITE = https://snapshot.debian.org/archive/debian/20260223T202245Z/pool/main/c/ca-certificates CA_CERTIFICATES_DEPENDENCIES = host-openssl host-python3 +HOST_CA_CERTIFICATES_DEPENDENCIES = host-openssl host-python3 CA_CERTIFICATES_LICENSE = GPL-2.0+ (script), MPL-2.0 (data) CA_CERTIFICATES_LICENSE_FILES = debian/copyright @@ -43,4 +44,33 @@ define CA_CERTIFICATES_GEN_BUNDLE endef CA_CERTIFICATES_TARGET_FINALIZE_HOOKS += CA_CERTIFICATES_GEN_BUNDLE +define HOST_CA_CERTIFICATES_BUILD_CMDS + $(HOST_MAKE_ENV) $(MAKE) -C $(@D) clean all +endef + +define HOST_CA_CERTIFICATES_INSTALL_CMDS + $(INSTALL) -d -m 0755 $(HOST_DIR)/share/ca-certificates + $(INSTALL) -d -m 0755 $(HOST_DIR)/etc/ssl/certs + $(HOST_MAKE_ENV) $(MAKE) -C $(@D) install DESTDIR=$(HOST_DIR) + rm -f $(HOST_DIR)/sbin/update-ca-certificates + # Remove any existing certificates under /etc/ssl/certs + rm -f $(HOST_DIR)/etc/ssl/certs/* + + # Create symlinks to certificates under /etc/ssl/certs + # and generate the bundle + cd $(HOST_DIR) ;\ + for i in `find share/ca-certificates -name "*.crt" | LC_COLLATE=C sort` ; do \ + ln -sf ../../../$$i etc/ssl/certs/`basename $${i} .crt`.pem ;\ + cat $$i ;\ + done >$(BUILD_DIR)/ca-certificates.crt + + # Create symlinks to the certificates by their hash values + $(HOST_DIR)/bin/c_rehash $(HOST_DIR)/etc/ssl/certs + + # Install the certificates bundle + $(INSTALL) -D -m 644 $(BUILD_DIR)/ca-certificates.crt \ + $(HOST_DIR)/etc/ssl/certs/ca-certificates.crt +endef + $(eval $(generic-package)) +$(eval $(host-generic-package))