diff --git a/package/ntp/0008-openssl4.patch b/package/ntp/0008-openssl4.patch new file mode 100644 index 0000000000..fc8ba9ef8e --- /dev/null +++ b/package/ntp/0008-openssl4.patch @@ -0,0 +1,100 @@ +Enable building with OpenSSL 4.0 + +Upstream: https://bugs.ntp.org/show_bug.cgi?id=4023 + +Signed-off-by: Bernd Kuhls + +diff -Nru a/ntpd/ntp_crypto.c b/ntpd/ntp_crypto.c +--- a/ntpd/ntp_crypto.c 2026-05-19 05:47:27 +0000 ++++ b/ntpd/ntp_crypto.c 2026-05-19 05:47:27 +0000 +@@ -2019,6 +2019,9 @@ + struct calendar *pjd /* pointer to result */ + ) + { ++ /* OpenSSL 4 makes ASN1_TIME opaque */ ++#if OPENSSL_VERSION_NUMBER < 0x40000000L ++ + size_t len; /* length of ASN1_TIME string */ + char v[24]; /* writable copy of ASN1_TIME string */ + unsigned long temp; /* result from strtoul */ +@@ -2064,7 +2067,24 @@ + pjd->year = temp; + + pjd->yearday = pjd->weekday = 0; +- return; ++ ++#else /* OpenSSL 4+ follows */ ++ ++ struct tm t; ++ int rc; ++ ++ rc = ASN1_TIME_to_tm(asn1time, &t); ++ INSIST(0 == rc); ++ ++ pjd->second = t.tm_sec; ++ pjd->minute = t.tm_min; ++ pjd->hour = t.tm_hour; ++ pjd->monthday = t.tm_mday; ++ pjd->month = t.tm_mon; ++ pjd->year = t.tm_year; ++ pjd->yearday = t.tm_yday; ++ pjd->weekday = t.tm_wday; ++#endif + } + + +@@ -3517,6 +3537,7 @@ + X509_EXTENSION *ext; + ASN1_OBJECT *obj; + int nid; ++ int datalen; + ASN1_OCTET_STRING *data; + + ext = X509_get_ext(cert, i); +@@ -3550,8 +3571,21 @@ + */ + case NID_subject_key_identifier: + data = X509_EXTENSION_get_data(ext); +- ret->grpkey = BN_bin2bn(&data->data[2], +- data->length - 2, NULL); ++#if OPENSSL_VERSION_NUMBER >= 0x40000000 ++ datalen = ASN1_STRING_length(data); ++ if (datalen > 2) { ++ ret->grpkey = ++ BN_bin2bn(ASN1_STRING_get0_data(data) + 2, ++ datalen - 2, NULL); ++ } ++#else /* OpenSSL 3.x or earlier follows */ ++ datalen = data->length; ++ if (datalen > 2) { ++ ret->grpkey = ++ BN_bin2bn(&data->data[2], ++ datalen - 2, NULL); ++ } ++#endif + /* fall through */ + default: + DPRINTF(1, ("cert_parse: %s\n", +diff -Nru a/ports/winnt/ntpd/ntservice.c b/ports/winnt/ntpd/ntservice.c +--- a/ports/winnt/ntpd/ntservice.c 2026-05-19 05:47:27 +0000 ++++ b/ports/winnt/ntpd/ntservice.c 2026-05-19 05:47:27 +0000 +@@ -87,6 +87,7 @@ + int argc_after_opts; + char ** argv_after_opts; + ++ init_lib(); /* ntp_strerror() below needs it */ + ssl_applink(); + + /* Save the command line parameters */ +diff -Nru a/util/ntp-keygen.c b/util/ntp-keygen.c +--- a/util/ntp-keygen.c 2026-05-19 05:47:27 +0000 ++++ b/util/ntp-keygen.c 2026-05-19 05:47:27 +0000 +@@ -625,7 +625,7 @@ + + /* + * Create new encrypted GQ server keys file if requested; +- * otherwise, look for an exisiting file. If found, fetch the ++ * otherwise, look for an existing file. If found, fetch the + * public key for the certificate. + */ + if (gqkey)