package/openscap: allow building when crypto backend is not gcrypt

When enabling the openscap package and the libnss library _but not_
libgcrypt, the build can fail on the following error:

  ../src/libopenscap.so.33.1.3: undefined reference to `crapi_init'

The issue is due to the fact that the corresponding Makefile
systematically forces -DWITH_CRYPTO=gcrypt: openscap CMake
instrumentation then searches only this backend, fails to find it,
assumes that no crypto backend is available, and so does not include the
crapi_object in the final link step.

Commit 7c85f3adf4 ("package/openscap: new package") took into account
the fact that openscap isn't currently able to build if no crypto backend
is provided (see [0]), and so made sure to force libgcrypt inclusion if
libnss is not included. Since then, two fixes ([1] and [2]) have been
integrated upstream to allow building openscap with any backend.

Do not systematically enforce libgcrypt anymore through WITH_CRYPTO:
rather than testing nss presence, and falling back to libgcrypt, allow
both to be absent, and so relax the libgcrypt dependency to make it
optional as well. Bring the two upstream patches allowing openscap build
without any crypto backend.  Those patches can be dropped once openscap
v1.4.5 is released.

[0] https://github.com/OpenSCAP/openscap/issues/2310
[1] d12d820a94
[2] 5b858d1786

Fixes: https://autobuild.buildroot.org/results/4c905c1b0ee384149c3d85e8f2ebf0af3a12c2ad/
Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit c24ae7f2f1)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
This commit is contained in:
Alexis Lothoré
2026-09-07 15:47:36 +02:00
committed by Raphaël Mélotte
parent c05c6ca99a
commit 680074eeb1
4 changed files with 110 additions and 11 deletions

View File

@@ -0,0 +1,57 @@
From d12d820a9493b0a0ee1ad4b0aeaa87da28aa0080 Mon Sep 17 00:00:00 2001
From: Eljees <yurytumanov.r@yandex.ru>
Date: Mon, 27 Jul 2026 06:57:38 +0300
Subject: [PATCH] Fix build without crypto support
Upstream: https://github.com/OpenSCAP/openscap/commit/d12d820a9493b0a0ee1ad4b0aeaa87da28aa0080
Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com>
---
src/CMakeLists.txt | 2 +-
src/OVAL/probes/CMakeLists.txt | 2 +-
src/OVAL/probes/crapi/CMakeLists.txt | 7 ++++++-
3 files changed, 8 insertions(+), 3 deletions(-)
diff --git a/src/CMakeLists.txt b/src/CMakeLists.txt
index 5d59bf3f036f..f31ce8040e0a 100644
--- a/src/CMakeLists.txt
+++ b/src/CMakeLists.txt
@@ -59,7 +59,7 @@ if (ENABLE_PROBES)
)
endif()
endif()
-if (HAVE_MMAN_H AND (GCRYPT_FOUND OR NSS_FOUND))
+if (HAVE_MMAN_H)
list(APPEND OBJECTS_TO_LINK_AGAINST
$<TARGET_OBJECTS:crapi_object>
)
diff --git a/src/OVAL/probes/CMakeLists.txt b/src/OVAL/probes/CMakeLists.txt
index e505908f5842..25e3ca56a0c3 100644
--- a/src/OVAL/probes/CMakeLists.txt
+++ b/src/OVAL/probes/CMakeLists.txt
@@ -1,7 +1,7 @@
add_subdirectory("SEAP")
add_subdirectory("probe")
-if (HAVE_MMAN_H AND CRYPTO_FOUND)
+if (HAVE_MMAN_H)
add_subdirectory("crapi")
endif()
diff --git a/src/OVAL/probes/crapi/CMakeLists.txt b/src/OVAL/probes/crapi/CMakeLists.txt
index 1f3e5a963bbf..3fb6f123c8d6 100644
--- a/src/OVAL/probes/crapi/CMakeLists.txt
+++ b/src/OVAL/probes/crapi/CMakeLists.txt
@@ -1,4 +1,9 @@
-file(GLOB_RECURSE CRAPI_SOURCES "*.c")
+if (CRYPTO_FOUND)
+ file(GLOB_RECURSE CRAPI_SOURCES "*.c")
+else()
+ # crapi_init has a no-op implementation for builds without a digest backend.
+ set(CRAPI_SOURCES "crapi.c")
+endif()
file(GLOB_RECURSE CRAPI_HEADERS "*.h")
add_library(crapi_object OBJECT ${CRAPI_SOURCES} ${CRAPI_HEADERS})
--
2.55.0

View File

@@ -0,0 +1,50 @@
From 5b858d1786c025cbd50dfc284b252c3ee6dd99dc Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Alexis=20Lothor=C3=A9?= <alexis.lothore@bootlin.com>
Date: Tue, 18 Aug 2026 09:38:05 +0200
Subject: [PATCH] Do not use gcrypt cmake variables if gcrypt is not found
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Commit d12d820a9493 ("Fix build without crypto support") enabled
building the crapi library without a crypto backend, but left the
target_include_directories and target_compile_definitions calls
unguarded. When no crypto library is available, the GCrypt find module
leaves GCRYPT_INCLUDE_DIRS unset, so CMake fails at the generate step
with:
CMake Error: The following variables are used in this project, but
they are set to NOTFOUND: GCRYPT_INCLUDE_DIR
The test command provided at this time made the build successful because
it provided -DCMAKE_DISABLE_FIND_PACKAGE_GCrypt=TRUE, but if no crypto
backend is provided, it does not make sense to provide those cmake
configuration options preventing dependency search manually.
Guard both calls with a CRYPTO_FOUND check so they are only applied when
an actual digest backend is present, even without providing
-DCMAKE_DISABLE_FIND_PACKAGE_foo
Upstream: https://github.com/OpenSCAP/openscap/commit/5b858d1786c025cbd50dfc284b252c3ee6dd99dc
Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com>
---
src/OVAL/probes/crapi/CMakeLists.txt | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/src/OVAL/probes/crapi/CMakeLists.txt b/src/OVAL/probes/crapi/CMakeLists.txt
index 3fb6f123c8d6..88cb916b6d96 100644
--- a/src/OVAL/probes/crapi/CMakeLists.txt
+++ b/src/OVAL/probes/crapi/CMakeLists.txt
@@ -8,5 +8,7 @@ file(GLOB_RECURSE CRAPI_HEADERS "*.h")
add_library(crapi_object OBJECT ${CRAPI_SOURCES} ${CRAPI_HEADERS})
set_oscap_generic_properties(crapi_object)
-target_include_directories(crapi_object PUBLIC ${NSS_INCLUDE_DIRS} ${GCRYPT_INCLUDE_DIRS})
-target_compile_definitions(crapi_object PUBLIC ${GCRYPT_DEFINITIONS})
+if (CRYPTO_FOUND)
+ target_include_directories(crapi_object PUBLIC ${NSS_INCLUDE_DIRS} ${GCRYPT_INCLUDE_DIRS})
+ target_compile_definitions(crapi_object PUBLIC ${GCRYPT_DEFINITIONS})
+endif()
--
2.55.0

View File

@@ -1,14 +1,10 @@
config BR2_PACKAGE_OPENSCAP config BR2_PACKAGE_OPENSCAP
bool "openscap" bool "openscap"
depends on BR2_PACKAGE_LIBGPG_ERROR_ARCH_SUPPORTS # libgcrypt
depends on !BR2_STATIC_LIBS # dlfcn.h depends on !BR2_STATIC_LIBS # dlfcn.h
depends on BR2_TOOLCHAIN_HAS_THREADS_NPTL depends on BR2_TOOLCHAIN_HAS_THREADS_NPTL
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_7 # libxmlsec1 depends on BR2_TOOLCHAIN_GCC_AT_LEAST_7 # libxmlsec1
depends on BR2_TOOLCHAIN_HAS_ATOMIC # libxmlsec1 depends on BR2_TOOLCHAIN_HAS_ATOMIC # libxmlsec1
select BR2_PACKAGE_LIBCURL select BR2_PACKAGE_LIBCURL
# In theory should build without crypto, but in practice it
# doesn't: https://github.com/OpenSCAP/openscap/issues/2310
select BR2_PACKAGE_LIBGCRYPT if !BR2_PACKAGE_LIBNSS
select BR2_PACKAGE_LIBXML2 select BR2_PACKAGE_LIBXML2
select BR2_PACKAGE_LIBXSLT select BR2_PACKAGE_LIBXSLT
select BR2_PACKAGE_LIBXMLSEC1 select BR2_PACKAGE_LIBXMLSEC1
@@ -22,7 +18,6 @@ config BR2_PACKAGE_OPENSCAP
https://github.com/OpenSCAP/openscap https://github.com/OpenSCAP/openscap
comment "openscap needs a toolchain w/ dynamic library, NPTL, gcc >= 7" comment "openscap needs a toolchain w/ dynamic library, NPTL, gcc >= 7"
depends on BR2_PACKAGE_LIBGPG_ERROR_ARCH_SUPPORTS
depends on BR2_TOOLCHAIN_HAS_ATOMIC depends on BR2_TOOLCHAIN_HAS_ATOMIC
depends on BR2_STATIC_LIBS || !BR2_TOOLCHAIN_HAS_THREADS_NPTL || \ depends on BR2_STATIC_LIBS || !BR2_TOOLCHAIN_HAS_THREADS_NPTL || \
!BR2_TOOLCHAIN_GCC_AT_LEAST_7 !BR2_TOOLCHAIN_GCC_AT_LEAST_7

View File

@@ -22,7 +22,6 @@ OPENSCAP_DEPENDENCIES = \
HOST_OPENSCAP_DEPENDENCIES = \ HOST_OPENSCAP_DEPENDENCIES = \
host-pkgconf \ host-pkgconf \
host-libcurl \ host-libcurl \
host-libgcrypt \
host-libxml2 \ host-libxml2 \
host-libxmlsec1 \ host-libxmlsec1 \
host-libxslt \ host-libxslt \
@@ -36,7 +35,6 @@ OPENSCAP_CONF_OPTS = \
-DENABLE_OSCAP_UTIL_VM=OFF \ -DENABLE_OSCAP_UTIL_VM=OFF \
-DENABLE_PROBES_WINDOWS=OFF \ -DENABLE_PROBES_WINDOWS=OFF \
-DENABLE_TESTS=OFF \ -DENABLE_TESTS=OFF \
-DWITH_CRYPTO=gcrypt \
-DENABLE_PYTHON3=OFF -DENABLE_PYTHON3=OFF
HOST_OPENSCAP_CONF_OPTS = \ HOST_OPENSCAP_CONF_OPTS = \
@@ -47,7 +45,6 @@ HOST_OPENSCAP_CONF_OPTS = \
-DENABLE_OSCAP_UTIL_VM=OFF \ -DENABLE_OSCAP_UTIL_VM=OFF \
-DENABLE_PROBES_WINDOWS=OFF \ -DENABLE_PROBES_WINDOWS=OFF \
-DENABLE_TESTS=OFF \ -DENABLE_TESTS=OFF \
-DWITH_CRYPTO=gcrypt \
-DENABLE_PYTHON3=OFF -DENABLE_PYTHON3=OFF
ifeq ($(BR2_PACKAGE_ACL),y) ifeq ($(BR2_PACKAGE_ACL),y)
@@ -60,10 +57,10 @@ endif
ifeq ($(BR2_PACKAGE_LIBGCRYPT),y) ifeq ($(BR2_PACKAGE_LIBGCRYPT),y)
OPENSCAP_DEPENDENCIES += libgcrypt OPENSCAP_DEPENDENCIES += libgcrypt
endif OPENSCAP_CONF_OPTS += -DWITH_CRYPTO=gcrypt
else ifeq ($(BR2_PACKAGE_LIBNSS),y)
ifeq ($(BR2_PACKAGE_LIBNSS),y)
OPENSCAP_DEPENDENCIES += libnss OPENSCAP_DEPENDENCIES += libnss
OPENSCAP_CONF_OPTS += -DWITH_CRYPTO=nss
endif endif
ifneq ($(BR2_TOOLCHAIN_USES_GLIBC),y) ifneq ($(BR2_TOOLCHAIN_USES_GLIBC),y)