From c58fb5f97b7cc6177c1ac675467f0ec43de44b8e Mon Sep 17 00:00:00 2001 From: Florian Larysch Date: Fri, 29 May 2026 21:12:37 +0200 Subject: [PATCH] package/sigsum-c: new package Add the sigsum-c library, which is a more lightweight alternative to sigsum-go when only proof verification is needed or needs to be embedded in some other program. Signed-off-by: Florian Larysch Signed-off-by: Peter Korsgaard --- DEVELOPERS | 1 + package/Config.in | 1 + ...001-Make-command-line-tools-optional.patch | 71 +++++++++++++++++++ package/sigsum-c/Config.in | 17 +++++ package/sigsum-c/sigsum-c.hash | 3 + package/sigsum-c/sigsum-c.mk | 21 ++++++ 6 files changed, 114 insertions(+) create mode 100644 package/sigsum-c/0001-Make-command-line-tools-optional.patch create mode 100644 package/sigsum-c/Config.in create mode 100644 package/sigsum-c/sigsum-c.hash create mode 100644 package/sigsum-c/sigsum-c.mk diff --git a/DEVELOPERS b/DEVELOPERS index beabe134b9..c71640b6b5 100644 --- a/DEVELOPERS +++ b/DEVELOPERS @@ -1146,6 +1146,7 @@ F: package/cpulimit/ N: Florian Larysch F: package/casync-nano/ +F: package/sigsum-c/ F: package/sigsum-go/ N: Floris Bos diff --git a/package/Config.in b/package/Config.in index ed003562da..166b666ad8 100644 --- a/package/Config.in +++ b/package/Config.in @@ -1661,6 +1661,7 @@ menu "Crypto" source "package/parsec-tool/Config.in" source "package/pkcs11-helper/Config.in" source "package/rhash/Config.in" + source "package/sigsum-c/Config.in" source "package/tinydtls/Config.in" source "package/tpm2-openssl/Config.in" source "package/tpm2-pkcs11/Config.in" diff --git a/package/sigsum-c/0001-Make-command-line-tools-optional.patch b/package/sigsum-c/0001-Make-command-line-tools-optional.patch new file mode 100644 index 0000000000..3ce986b8bd --- /dev/null +++ b/package/sigsum-c/0001-Make-command-line-tools-optional.patch @@ -0,0 +1,71 @@ +From 5c74c6d0dd2dd1707b178083815f3a165e3e7dc3 Mon Sep 17 00:00:00 2001 +From: Florian Larysch +Date: Fri, 22 May 2026 14:36:02 +0200 +Subject: [PATCH] Make command line tools optional + +When only using the sigsum-c library in another program, the +dedicated sigsum-c-verify tool might be redundant. + +Allow disabling it to save space/avoid littering /bin. + +Upstream: https://git.glasklar.is/sigsum/core/sigsum-c/-/commit/5c74c6d0dd2dd1707b178083815f3a165e3e7dc3 +Signed-off-by: Florian Larysch +--- + Makefile.in | 4 ++-- + configure.ac | 11 +++++++++++ + 2 files changed, 13 insertions(+), 2 deletions(-) + +diff --git a/Makefile.in b/Makefile.in +index 0648adb..771551a 100644 +--- a/Makefile.in ++++ b/Makefile.in +@@ -12,7 +12,7 @@ lib: + tools: lib + cd tools && $(MAKE) all + +-all: lib @IF_PARSERS@ tools ++all: lib @IF_TOOLS@ tools + + clean distclean: + cd lib && $(MAKE) $@ +@@ -34,7 +34,7 @@ install-lib: lib + install-tools: tools + cd tools && $(MAKE) install + +-install: install-lib @IF_PARSERS@ install-tools ++install: install-lib @IF_TOOLS@ install-tools + + # Remake configure-generated files. + # From the autoconf manual (4.8.5 Automatic Remaking) +diff --git a/configure.ac b/configure.ac +index 37a18b7..8305789 100644 +--- a/configure.ac ++++ b/configure.ac +@@ -19,6 +19,16 @@ else + IF_PARSERS='#' + fi + ++AC_ARG_ENABLE(tools, ++ AS_HELP_STRING([--disable-tools], [Do not build or install command-line tools.]),, ++ [enable_tools="$enable_parsers"]) ++ ++if test "$enable_tools" = yes ; then ++ IF_TOOLS='' ++else ++ IF_TOOLS='#' ++fi ++ + AC_ARG_ENABLE(static, + AS_HELP_STRING([--disable-static], [Do not build any static library]),, + [enable_static=yes]) +@@ -47,6 +57,7 @@ if test -z "$PIC_CFLAGS" ; then + fi + + AC_SUBST(IF_PARSERS) ++AC_SUBST(IF_TOOLS) + AC_SUBST(IF_STATIC) + AC_SUBST(IF_SHARED) + AC_SUBST(IF_NOT_SHARED) +-- +2.54.0 + diff --git a/package/sigsum-c/Config.in b/package/sigsum-c/Config.in new file mode 100644 index 0000000000..afc5942e83 --- /dev/null +++ b/package/sigsum-c/Config.in @@ -0,0 +1,17 @@ +config BR2_PACKAGE_SIGSUM_C + bool "sigsum-c" + select BR2_PACKAGE_NETTLE + help + C library and command-line utility for verifying Sigsum + proofs. + + https://git.glasklar.is/sigsum/core/sigsum-c/ + +if BR2_PACKAGE_SIGSUM_C + +config BR2_PACKAGE_SIGSUM_C_TOOLS + bool "Enable tools" + help + Build CLI tools like sigsum-c-verify. + +endif diff --git a/package/sigsum-c/sigsum-c.hash b/package/sigsum-c/sigsum-c.hash new file mode 100644 index 0000000000..5941eafc5d --- /dev/null +++ b/package/sigsum-c/sigsum-c.hash @@ -0,0 +1,3 @@ +# Locally calculated +sha256 147ab839b22c5584aa9982c912bdb629cc717dcd978528233889789544e5fe51 sigsum-c-v1.0.0-git4.tar.gz +sha256 f592312f5d5756846c43becd06fc1d826eafe05b1b45f88e95af460d59d24ad0 LICENSE diff --git a/package/sigsum-c/sigsum-c.mk b/package/sigsum-c/sigsum-c.mk new file mode 100644 index 0000000000..a6021f0587 --- /dev/null +++ b/package/sigsum-c/sigsum-c.mk @@ -0,0 +1,21 @@ +################################################################################ +# +# sigsum-c +# +################################################################################ + +SIGSUM_C_VERSION = v1.0.0 +SIGSUM_C_SITE = https://git.glasklar.is/sigsum/core/sigsum-c +SIGSUM_C_SITE_METHOD = git +SIGSUM_C_LICENSE = BSD-2-Clause +SIGSUM_C_LICENSE_FILES = LICENSE +SIGSUM_C_INSTALL_STAGING = YES +SIGSUM_C_DEPENDENCIES = nettle + +SIGSUM_C_AUTORECONF = YES + +ifneq ($(BR2_PACKAGE_SIGSUM_C_TOOLS),y) +SIGSUM_C_CONF_OPTS += --disable-tools +endif + +$(eval $(autotools-package))