All of lore.kernel.org
 help / color / mirror / Atom feed
* [Buildroot] [PATCH 1/1] package/monit: fix openssl static build
@ 2023-10-15 21:01 Fabrice Fontaine
  2023-11-01 22:44 ` Thomas Petazzoni via buildroot
  0 siblings, 1 reply; 4+ messages in thread
From: Fabrice Fontaine @ 2023-10-15 21:01 UTC (permalink / raw)
  To: buildroot; +Cc: Fabrice Fontaine, Thomas Petazzoni

Fix the following openssl static build failure raised since bump to
version 5.33.0 in commit 8cedb39764f70f9d467bf0cc1acc99a8bbb963d6:

configure: error: Could not find SSL library, please use --with-ssl-lib-dir option or disabled the SSL support using --without-ssl

Fixes:
 - http://autobuild.buildroot.org/results/b2fe4ecd1d84c3cf7d0eb8f606b20bc6638d6d65

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
---
 package/monit/monit.mk | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/package/monit/monit.mk b/package/monit/monit.mk
index ce0f5f0e92..f9d6617a54 100644
--- a/package/monit/monit.mk
+++ b/package/monit/monit.mk
@@ -25,8 +25,9 @@ MONIT_CONF_OPTS += \
 	--with-largefiles
 
 ifeq ($(BR2_PACKAGE_OPENSSL),y)
+MONIT_CONF_ENV += LIBS=`$(PKG_CONFIG_HOST_BINARY) --libs openssl`
 MONIT_CONF_OPTS += --with-ssl --with-ssl-dir=$(STAGING_DIR)/usr
-MONIT_DEPENDENCIES += openssl
+MONIT_DEPENDENCIES += host-pkgconf openssl
 else
 MONIT_CONF_OPTS += --without-ssl
 endif
-- 
2.42.0

_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [Buildroot] [PATCH 1/1] package/monit: fix openssl static build
  2023-10-15 21:01 [Buildroot] [PATCH 1/1] package/monit: fix openssl static build Fabrice Fontaine
@ 2023-11-01 22:44 ` Thomas Petazzoni via buildroot
  0 siblings, 0 replies; 4+ messages in thread
From: Thomas Petazzoni via buildroot @ 2023-11-01 22:44 UTC (permalink / raw)
  To: Fabrice Fontaine; +Cc: buildroot

On Sun, 15 Oct 2023 23:01:25 +0200
Fabrice Fontaine <fontaine.fabrice@gmail.com> wrote:

> Fix the following openssl static build failure raised since bump to
> version 5.33.0 in commit 8cedb39764f70f9d467bf0cc1acc99a8bbb963d6:
> 
> configure: error: Could not find SSL library, please use --with-ssl-lib-dir option or disabled the SSL support using --without-ssl
> 
> Fixes:
>  - http://autobuild.buildroot.org/results/b2fe4ecd1d84c3cf7d0eb8f606b20bc6638d6d65
> 
> Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
> ---
>  package/monit/monit.mk | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)

Applied to master, thanks. It would be nice if the monit configure.ac
script could use pkg-config directly, though.

Thomas
-- 
Thomas Petazzoni, CTO, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply	[flat|nested] 4+ messages in thread

* [Buildroot] [PATCH 1/1] package/monit: fix openssl static build
@ 2023-11-30 22:11 Fabrice Fontaine
  2023-12-01 16:07 ` Yann E. MORIN
  0 siblings, 1 reply; 4+ messages in thread
From: Fabrice Fontaine @ 2023-11-30 22:11 UTC (permalink / raw)
  To: buildroot; +Cc: Fabrice Fontaine, Thomas Petazzoni

--with-ssl-dir will exclusively search for dynamic library so use
--with-ssl-static to fix the following openssl static build failure
raised since bump to version 5.33.0 in commit
8cedb39764f70f9d467bf0cc1acc99a8bbb963d6:

checking for static SSL support... disabled
checking for SSL support... enabled
checking for SSL include directory... /home/buildroot/autobuild/instance-2/output-1/host/mipsel-buildroot-linux-uclibc/sysroot/usr/include
checking for SSL library directory... /lib64

[...]

mipsel-buildroot-linux-uclibc-gcc: ERROR: unsafe header/library path used in cross-compilation: '-L/lib64'

Fixes:
 - http://autobuild.buildroot.org/results/4189decbafb5d28c11d89ddac792b4610abeaff1

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
---
 package/monit/monit.mk | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/package/monit/monit.mk b/package/monit/monit.mk
index 4766ce3d9e..f3e16a3e4f 100644
--- a/package/monit/monit.mk
+++ b/package/monit/monit.mk
@@ -27,7 +27,12 @@ MONIT_CONF_OPTS += \
 
 ifeq ($(BR2_PACKAGE_OPENSSL),y)
 MONIT_CONF_ENV += LIBS=`$(PKG_CONFIG_HOST_BINARY) --libs openssl`
-MONIT_CONF_OPTS += --with-ssl --with-ssl-dir=$(STAGING_DIR)/usr
+MONIT_CONF_OPTS += --with-ssl
+ifeq ($(BR2_STATIC_LIBS),y)
+MONIT_CONF_OPTS += --with-ssl-static=$(STAGING_DIR)/usr
+else
+MONIT_CONF_OPTS += --with-ssl-dir=$(STAGING_DIR)/usr
+endif
 MONIT_DEPENDENCIES += host-pkgconf openssl
 else
 MONIT_CONF_OPTS += --without-ssl
-- 
2.42.0

_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [Buildroot] [PATCH 1/1] package/monit: fix openssl static build
  2023-11-30 22:11 Fabrice Fontaine
@ 2023-12-01 16:07 ` Yann E. MORIN
  0 siblings, 0 replies; 4+ messages in thread
From: Yann E. MORIN @ 2023-12-01 16:07 UTC (permalink / raw)
  To: Fabrice Fontaine; +Cc: Thomas Petazzoni, buildroot

Fabrice, All,

On 2023-11-30 23:11 +0100, Fabrice Fontaine spake thusly:
> --with-ssl-dir will exclusively search for dynamic library so use
> --with-ssl-static to fix the following openssl static build failure
> raised since bump to version 5.33.0 in commit
> 8cedb39764f70f9d467bf0cc1acc99a8bbb963d6:
> 
> checking for static SSL support... disabled
> checking for SSL support... enabled
> checking for SSL include directory... /home/buildroot/autobuild/instance-2/output-1/host/mipsel-buildroot-linux-uclibc/sysroot/usr/include
> checking for SSL library directory... /lib64
> 
> [...]
> 
> mipsel-buildroot-linux-uclibc-gcc: ERROR: unsafe header/library path used in cross-compilation: '-L/lib64'
> 
> Fixes:
>  - http://autobuild.buildroot.org/results/4189decbafb5d28c11d89ddac792b4610abeaff1
> 
> Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
> ---
>  package/monit/monit.mk | 7 ++++++-
>  1 file changed, 6 insertions(+), 1 deletion(-)
> 
> diff --git a/package/monit/monit.mk b/package/monit/monit.mk
> index 4766ce3d9e..f3e16a3e4f 100644
> --- a/package/monit/monit.mk
> +++ b/package/monit/monit.mk
> @@ -27,7 +27,12 @@ MONIT_CONF_OPTS += \
>  
>  ifeq ($(BR2_PACKAGE_OPENSSL),y)
>  MONIT_CONF_ENV += LIBS=`$(PKG_CONFIG_HOST_BINARY) --libs openssl`
> -MONIT_CONF_OPTS += --with-ssl --with-ssl-dir=$(STAGING_DIR)/usr
> +MONIT_CONF_OPTS += --with-ssl
> +ifeq ($(BR2_STATIC_LIBS),y)
> +MONIT_CONF_OPTS += --with-ssl-static=$(STAGING_DIR)/usr
> +else
> +MONIT_CONF_OPTS += --with-ssl-dir=$(STAGING_DIR)/usr
> +endif

The situation is a bit more complex than that, in fact.

What prompted me to investigate a bit further, is that I wanted to
checked if we could force --without-ssl-static or --without-ssl-dir.

However, both of those options only accept a path, not a yes/no answer

    https://bitbucket.org/tildeslash/monit/src/master/configure.ac#lines-766

    AC_ARG_WITH(ssl-static,
        [  --with-ssl-static=DIR       location of SSL installation],
        [
            dnl Check the specified location only
            for dir in "$withval" "$withval/include"; do
                checksslincldir "$dir"
            done
            for dir in "$withval" "$withval/lib"; do
                checkssllibdirstatic "$dir" && break
            done
            ....
        ],
        [
        with_sslstatic=0
            AC_MSG_RESULT([disabled])
        ]
    )

(similarly for --with-ssl-dir, see below)

So we can't specify --without-ssl-dir/static when the other is being
used.

But then I also noticed that the --with-ssl case is only tested if
--with-ssl-static was *not* used at all:

    https://bitbucket.org/tildeslash/monit/src/master/configure.ac#lines-794

    if test $with_sslstatic -eq 0
    then
        AC_MSG_CHECKING([for SSL support])

        AC_ARG_WITH(ssl,
            [  --without-ssl           disable the use of ssl (default: enabled)],
            [
                dnl Check the withvalue
                if test "x$withval" = "xno" ; then
                    with_ssl=0
                    AC_MSG_RESULT([disabled])
                fi
                if test "x$withval" = "xyes" ; then
                    with_ssl=1
                    AC_MSG_RESULT([enabled])
                fi
            ],
            [
                    # Note inverse test. On by default
                    with_ssl=1
                    AC_MSG_RESULT([enabled])
            ]
        )


        # Check for SSL directory
        if test $with_ssl -eq 1; then

            AC_ARG_WITH(ssl-dir,
                [  --with-ssl-dir=DIR       location of SSL installation],
                [
                    dnl Check the specified location only
                    for dir in "$withval" "$withval/include"; do
                        checksslincldir "$dir"
                    done
                    for dir in "$withval" "$withval/lib"; do
                        checkssllibdirdynamic "$dir" && break
                    done
                ]
            )

So, basically what makes sense is either one of (--with-ssl is the
default, but let's be explicit here, as we can be):

  * --with-ssl-static=/path/to/dir

  * --with-ssl --with-ssl-dir=/path/to/dir

  * --without-ssl

Can you please double-check that this is correct and works, and resubmit
a patch, please?

As an aside, there is a lurking bug later on in that configure.ac
script:

    https://bitbucket.org/tildeslash/monit/src/master/configure.ac#lines-931

        elif test -f "/usr/kerberos/include/krb5.h"; then
             # Redhat 9 compilation fix:
             CFLAGS="$CFLAGS -I$sslincldir -I/usr/kerberos/include"
             LIBS="$LIBS -L$ssllibdir -lssl -lcrypto"

So, if the user happens to have native development files for kerberos,
an unsafe path is forcibly shoehorned into the CFLAGS. It's been there
for as long as the repository has existed, so not a hugely critical
issue either. Still worth fixing, I'd say...

Regards,
Yann E. MORIN.

>  MONIT_DEPENDENCIES += host-pkgconf openssl
>  else
>  MONIT_CONF_OPTS += --without-ssl
> -- 
> 2.42.0
> 
> _______________________________________________
> buildroot mailing list
> buildroot@buildroot.org
> https://lists.buildroot.org/mailman/listinfo/buildroot

-- 
.-----------------.--------------------.------------------.--------------------.
|  Yann E. MORIN  | Real-Time Embedded | /"\ ASCII RIBBON | Erics' conspiracy: |
| +33 662 376 056 | Software  Designer | \ / CAMPAIGN     |  ___               |
| +33 561 099 427 `------------.-------:  X  AGAINST      |  \e/  There is no  |
| http://ymorin.is-a-geek.org/ | _/*\_ | / \ HTML MAIL    |   v   conspiracy.  |
'------------------------------^-------^------------------^--------------------'
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2023-12-01 16:07 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-10-15 21:01 [Buildroot] [PATCH 1/1] package/monit: fix openssl static build Fabrice Fontaine
2023-11-01 22:44 ` Thomas Petazzoni via buildroot
  -- strict thread matches above, loose matches on Subject: below --
2023-11-30 22:11 Fabrice Fontaine
2023-12-01 16:07 ` Yann E. MORIN

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.