Files
buildroot/package/openscap/0001-Fix-build-without-crypto-support.patch
Alexis Lothoré 680074eeb1 package/openscap: allow building when crypto backend is not gcrypt
When enabling the openscap package and the libnss library _but not_
libgcrypt, the build can fail on the following error:

  ../src/libopenscap.so.33.1.3: undefined reference to `crapi_init'

The issue is due to the fact that the corresponding Makefile
systematically forces -DWITH_CRYPTO=gcrypt: openscap CMake
instrumentation then searches only this backend, fails to find it,
assumes that no crypto backend is available, and so does not include the
crapi_object in the final link step.

Commit 7c85f3adf4 ("package/openscap: new package") took into account
the fact that openscap isn't currently able to build if no crypto backend
is provided (see [0]), and so made sure to force libgcrypt inclusion if
libnss is not included. Since then, two fixes ([1] and [2]) have been
integrated upstream to allow building openscap with any backend.

Do not systematically enforce libgcrypt anymore through WITH_CRYPTO:
rather than testing nss presence, and falling back to libgcrypt, allow
both to be absent, and so relax the libgcrypt dependency to make it
optional as well. Bring the two upstream patches allowing openscap build
without any crypto backend.  Those patches can be dropped once openscap
v1.4.5 is released.

[0] https://github.com/OpenSCAP/openscap/issues/2310
[1] d12d820a94
[2] 5b858d1786

Fixes: https://autobuild.buildroot.org/results/4c905c1b0ee384149c3d85e8f2ebf0af3a12c2ad/
Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit c24ae7f2f1)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:34:04 +02:00

58 lines
1.8 KiB
Diff

From d12d820a9493b0a0ee1ad4b0aeaa87da28aa0080 Mon Sep 17 00:00:00 2001
From: Eljees <yurytumanov.r@yandex.ru>
Date: Mon, 27 Jul 2026 06:57:38 +0300
Subject: [PATCH] Fix build without crypto support
Upstream: https://github.com/OpenSCAP/openscap/commit/d12d820a9493b0a0ee1ad4b0aeaa87da28aa0080
Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com>
---
src/CMakeLists.txt | 2 +-
src/OVAL/probes/CMakeLists.txt | 2 +-
src/OVAL/probes/crapi/CMakeLists.txt | 7 ++++++-
3 files changed, 8 insertions(+), 3 deletions(-)
diff --git a/src/CMakeLists.txt b/src/CMakeLists.txt
index 5d59bf3f036f..f31ce8040e0a 100644
--- a/src/CMakeLists.txt
+++ b/src/CMakeLists.txt
@@ -59,7 +59,7 @@ if (ENABLE_PROBES)
)
endif()
endif()
-if (HAVE_MMAN_H AND (GCRYPT_FOUND OR NSS_FOUND))
+if (HAVE_MMAN_H)
list(APPEND OBJECTS_TO_LINK_AGAINST
$<TARGET_OBJECTS:crapi_object>
)
diff --git a/src/OVAL/probes/CMakeLists.txt b/src/OVAL/probes/CMakeLists.txt
index e505908f5842..25e3ca56a0c3 100644
--- a/src/OVAL/probes/CMakeLists.txt
+++ b/src/OVAL/probes/CMakeLists.txt
@@ -1,7 +1,7 @@
add_subdirectory("SEAP")
add_subdirectory("probe")
-if (HAVE_MMAN_H AND CRYPTO_FOUND)
+if (HAVE_MMAN_H)
add_subdirectory("crapi")
endif()
diff --git a/src/OVAL/probes/crapi/CMakeLists.txt b/src/OVAL/probes/crapi/CMakeLists.txt
index 1f3e5a963bbf..3fb6f123c8d6 100644
--- a/src/OVAL/probes/crapi/CMakeLists.txt
+++ b/src/OVAL/probes/crapi/CMakeLists.txt
@@ -1,4 +1,9 @@
-file(GLOB_RECURSE CRAPI_SOURCES "*.c")
+if (CRYPTO_FOUND)
+ file(GLOB_RECURSE CRAPI_SOURCES "*.c")
+else()
+ # crapi_init has a no-op implementation for builds without a digest backend.
+ set(CRAPI_SOURCES "crapi.c")
+endif()
file(GLOB_RECURSE CRAPI_HEADERS "*.h")
add_library(crapi_object OBJECT ${CRAPI_SOURCES} ${CRAPI_HEADERS})
--
2.55.0