From 94aa7f40b5b132b255314f6402d4c2bf50928c75 Mon Sep 17 00:00:00 2001 From: Peter Korsgaard Date: Thu, 27 Aug 2026 18:55:31 +0200 Subject: [PATCH] package/haproxy: needs signed overflow handling haproxy has a runtime test to verify that it is built with -fwrapv: haproxy FATAL ERROR: invalid code detected -- cannot go further, please recompile! The source code was miscompiled by the compiler, which usually indicates that some of the CFLAGS needed to work around overzealous compiler optimizations were overwritten at build time. Please do not force CFLAGS, and read Makefile and INSTALL files to decide on the best way to pass your local build options. Build options : TARGET = custom CPU = generic CC = /home/peko/source/buildroot/output-haproxy/host/bin/arm-linux-gcc CFLAGS = -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -O2 -g0 -D_FORTIFY_SOURCE=1 -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -O2 -g0 -D_FORTIFY_SOURCE=1 OPTIONS = USE_THREAD=1 USE_DL=1 DEBUG = -DDEBUG_STRICT -DDEBUG_MEMORY_POOLS Which comes from: https://github.com/haproxy/haproxy/blob/v2.6.0/src/haproxy.c#L3008-L3037 So build it with -fwrapv to fix that. Notice that this message also embeds the build path (through CC), breaking reproducible builds. Signed-off-by: Peter Korsgaard Signed-off-by: Julien Olivain --- package/haproxy/haproxy.mk | 2 ++ 1 file changed, 2 insertions(+) diff --git a/package/haproxy/haproxy.mk b/package/haproxy/haproxy.mk index 970347d3ed..f75f18e031 100644 --- a/package/haproxy/haproxy.mk +++ b/package/haproxy/haproxy.mk @@ -15,8 +15,10 @@ HAPROXY_CPE_ID_VENDOR = haproxy # https://git.haproxy.org/?p=haproxy-2.6.git;a=commit;h=832b672eee54866c7a42a1d46078cc9ae0d544d9 HAPROXY_IGNORE_CVES += CVE-2023-45539 +# haproxy relies on signed overflow, so MUST be built with -fwrapv HAPROXY_MAKE_OPTS = \ LD=$(TARGET_CC) \ + CFLAGS="$(TARGET_CFLAGS) -fwrapv" \ PREFIX=/usr \ TARGET=custom