From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
To: openembedded-core@lists.openembedded.org
Subject: [RFC v4 1/6] openssl: upgrade 3.5.7 -> 4.0.1
Date: Sat, 22 Aug 2026 19:51:55 +0200 [thread overview]
Message-ID: <20260822175200.57534-2-jaipaul.cheernam@est.tech> (raw)
In-Reply-To: <20260822175200.57534-1-jaipaul.cheernam@est.tech>
Upgrade OpenSSL from 3.5.7 to 4.0.1. This is a major version upgrade.
Changelog: https://github.com/openssl/openssl/blob/openssl-4.0.1/CHANGES.md
New CVE fixes not already in 3.5.7:
* CVE-2026-28386: Fixed OOB read in AES-CFB-128 on x86-64 with AVX-512
* CVE-2026-35188: Fixed double-free when checking OCSP stapled response
* CVE-2026-42765: Fixed NULL deref in cert verification with OCSP
* CVE-2026-42771: Fixed OOB read in X509_VERIFY_PARAM_set1_email()
Major breaking changes in 4.0.0:
* Removed support for engines. The ENGINE API is fully removed.
* Removed support for SSLv3. SSLv3 has been deprecated since 2015.
* Removed support for the SSLv2 Client Hello.
* Removed per-version TLS method functions (SSLv3_method(),
TLSv1_method(), TLSv1_1_method(), TLSv1_2_method()).
* Removed c_rehash script tool. Use 'openssl rehash' instead.
* ASN1_STRING has been made opaque.
* Numerous API function signatures changed to include const qualifiers.
* libcrypto no longer cleans up globally allocated data via atexit().
* Added AKID verification checks when X509_V_FLAG_X509_STRICT is set.
* Support of deprecated elliptic curves in TLS disabled at compile-time
by default.
Recipe changes:
* Drop 0001-Added-handshake-history-reporting-when-test-fails.patch
(merged upstream via PR #22481).
* Refresh remaining patches against the new version.
* Remove ENGINE API artifacts: engines package, dasync.so/ossltest.so
ptest installation, ENGINESDIR references, OPENSSL_ENGINES wrapper
variable, and cryptodev-linux PACKAGECONFIG.
Tested: ptest on qemux86-64:
Files=362, Tests=4310, Result: PASS
Passed: 338, Skipped: 24 (fips, lms, rc5, tfo, compression,
sslversions, sslkeylogfile, external tests - all expected)
Failed: 0
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
---
...ke-history-reporting-when-test-fails.patch | 366 ------------------
...1-Configure-do-not-tweak-mips-cflags.patch | 6 +-
...sysroot-and-debug-prefix-map-from-co.patch | 11 +-
.../0001-extend-check_cwm-test-timeout.patch | 4 +-
.../{openssl_3.5.7.bb => openssl_4.0.1.bb} | 28 +-
5 files changed, 18 insertions(+), 397 deletions(-)
delete mode 100644 meta/recipes-connectivity/openssl/openssl/0001-Added-handshake-history-reporting-when-test-fails.patch
rename meta/recipes-connectivity/openssl/{openssl_3.5.7.bb => openssl_4.0.1.bb} (87%)
diff --git a/meta/recipes-connectivity/openssl/openssl/0001-Added-handshake-history-reporting-when-test-fails.patch b/meta/recipes-connectivity/openssl/openssl/0001-Added-handshake-history-reporting-when-test-fails.patch
deleted file mode 100644
index a74c79303f..0000000000
--- a/meta/recipes-connectivity/openssl/openssl/0001-Added-handshake-history-reporting-when-test-fails.patch
+++ /dev/null
@@ -1,366 +0,0 @@
-From 5ba65051fea0513db0d997f0ab7cafb9826ed74a Mon Sep 17 00:00:00 2001
-From: William Lyu <William.Lyu@windriver.com>
-Date: Fri, 20 Oct 2023 16:22:37 -0400
-Subject: [PATCH] Added handshake history reporting when test fails
-
-Upstream-Status: Submitted [https://github.com/openssl/openssl/pull/22481]
-
-Signed-off-by: William Lyu <William.Lyu@windriver.com>
----
- test/helpers/handshake.c | 136 ++++++++++++++++++++++++++++++---------
- test/helpers/handshake.h | 70 +++++++++++++++++++-
- test/ssl_test.c | 44 +++++++++++++
- 3 files changed, 217 insertions(+), 33 deletions(-)
-
-diff --git a/test/helpers/handshake.c b/test/helpers/handshake.c
-index f611b3a..5703b48 100644
---- a/test/helpers/handshake.c
-+++ b/test/helpers/handshake.c
-@@ -25,6 +25,102 @@
- #include <netinet/sctp.h>
- #endif
-
-+/* Shamelessly copied from test/helpers/ssl_test_ctx.c */
-+/* Maps string names to various enumeration type */
-+typedef struct {
-+ const char *name;
-+ int value;
-+} enum_name_map;
-+
-+static const enum_name_map connect_phase_names[] = {
-+ {"Handshake", HANDSHAKE},
-+ {"RenegAppData", RENEG_APPLICATION_DATA},
-+ {"RenegSetup", RENEG_SETUP},
-+ {"RenegHandshake", RENEG_HANDSHAKE},
-+ {"AppData", APPLICATION_DATA},
-+ {"Shutdown", SHUTDOWN},
-+ {"ConnectionDone", CONNECTION_DONE}
-+};
-+
-+static const enum_name_map peer_status_names[] = {
-+ {"PeerSuccess", PEER_SUCCESS},
-+ {"PeerRetry", PEER_RETRY},
-+ {"PeerError", PEER_ERROR},
-+ {"PeerWaiting", PEER_WAITING},
-+ {"PeerTestFail", PEER_TEST_FAILURE}
-+};
-+
-+static const enum_name_map handshake_status_names[] = {
-+ {"HandshakeSuccess", HANDSHAKE_SUCCESS},
-+ {"ClientError", CLIENT_ERROR},
-+ {"ServerError", SERVER_ERROR},
-+ {"InternalError", INTERNAL_ERROR},
-+ {"HandshakeRetry", HANDSHAKE_RETRY}
-+};
-+
-+/* Shamelessly copied from test/helpers/ssl_test_ctx.c */
-+static const char *enum_name(const enum_name_map *enums, size_t num_enums,
-+ int value)
-+{
-+ size_t i;
-+ for (i = 0; i < num_enums; i++) {
-+ if (enums[i].value == value) {
-+ return enums[i].name;
-+ }
-+ }
-+ return "InvalidValue";
-+}
-+
-+const char *handshake_connect_phase_name(connect_phase_t phase)
-+{
-+ return enum_name(connect_phase_names, OSSL_NELEM(connect_phase_names),
-+ (int)phase);
-+}
-+
-+const char *handshake_status_name(handshake_status_t handshake_status)
-+{
-+ return enum_name(handshake_status_names, OSSL_NELEM(handshake_status_names),
-+ (int)handshake_status);
-+}
-+
-+const char *handshake_peer_status_name(peer_status_t peer_status)
-+{
-+ return enum_name(peer_status_names, OSSL_NELEM(peer_status_names),
-+ (int)peer_status);
-+}
-+
-+static void save_loop_history(HANDSHAKE_HISTORY *history,
-+ connect_phase_t phase,
-+ handshake_status_t handshake_status,
-+ peer_status_t server_status,
-+ peer_status_t client_status,
-+ int client_turn_count,
-+ int is_client_turn)
-+{
-+ HANDSHAKE_HISTORY_ENTRY *new_entry = NULL;
-+
-+ /*
-+ * Create a new history entry for a handshake loop with statuses given in
-+ * the arguments. Potentially evicting the oldest entry when the
-+ * ring buffer is full.
-+ */
-+ ++(history->last_idx);
-+ history->last_idx &= MAX_HANDSHAKE_HISTORY_ENTRY_IDX_MASK;
-+
-+ new_entry = &((history->entries)[history->last_idx]);
-+ new_entry->phase = phase;
-+ new_entry->handshake_status = handshake_status;
-+ new_entry->server_status = server_status;
-+ new_entry->client_status = client_status;
-+ new_entry->client_turn_count = client_turn_count;
-+ new_entry->is_client_turn = is_client_turn;
-+
-+ /* Evict the oldest handshake loop entry when the ring buffer is full. */
-+ if (history->entry_count < MAX_HANDSHAKE_HISTORY_ENTRY) {
-+ ++(history->entry_count);
-+ }
-+}
-+
- HANDSHAKE_RESULT *HANDSHAKE_RESULT_new(void)
- {
- HANDSHAKE_RESULT *ret;
-@@ -724,15 +820,6 @@ static void configure_handshake_ssl(SSL *server, SSL *client,
- SSL_set_post_handshake_auth(client, 1);
- }
-
--/* The status for each connection phase. */
--typedef enum {
-- PEER_SUCCESS,
-- PEER_RETRY,
-- PEER_ERROR,
-- PEER_WAITING,
-- PEER_TEST_FAILURE
--} peer_status_t;
--
- /* An SSL object and associated read-write buffers. */
- typedef struct peer_st {
- SSL *ssl;
-@@ -1077,16 +1164,6 @@ static void do_shutdown_step(PEER *peer)
- }
- }
-
--typedef enum {
-- HANDSHAKE,
-- RENEG_APPLICATION_DATA,
-- RENEG_SETUP,
-- RENEG_HANDSHAKE,
-- APPLICATION_DATA,
-- SHUTDOWN,
-- CONNECTION_DONE
--} connect_phase_t;
--
- static int renegotiate_op(const SSL_TEST_CTX *test_ctx)
- {
- switch (test_ctx->handshake_mode) {
-@@ -1164,19 +1241,6 @@ static void do_connect_step(const SSL_TEST_CTX *test_ctx, PEER *peer,
- }
- }
-
--typedef enum {
-- /* Both parties succeeded. */
-- HANDSHAKE_SUCCESS,
-- /* Client errored. */
-- CLIENT_ERROR,
-- /* Server errored. */
-- SERVER_ERROR,
-- /* Peers are in inconsistent state. */
-- INTERNAL_ERROR,
-- /* One or both peers not done. */
-- HANDSHAKE_RETRY
--} handshake_status_t;
--
- /*
- * Determine the handshake outcome.
- * last_status: the status of the peer to have acted last.
-@@ -1541,6 +1605,10 @@ static HANDSHAKE_RESULT *do_handshake_internal(
-
- start = time(NULL);
-
-+ save_loop_history(&(ret->history),
-+ phase, status, server.status, client.status,
-+ client_turn_count, client_turn);
-+
- /*
- * Half-duplex handshake loop.
- * Client and server speak to each other synchronously in the same process.
-@@ -1562,6 +1630,10 @@ static HANDSHAKE_RESULT *do_handshake_internal(
- 0 /* server went last */);
- }
-
-+ save_loop_history(&(ret->history),
-+ phase, status, server.status, client.status,
-+ client_turn_count, client_turn);
-+
- switch (status) {
- case HANDSHAKE_SUCCESS:
- client_turn_count = 0;
-diff --git a/test/helpers/handshake.h b/test/helpers/handshake.h
-index 78b03f9..b9967c2 100644
---- a/test/helpers/handshake.h
-+++ b/test/helpers/handshake.h
-@@ -1,5 +1,5 @@
- /*
-- * Copyright 2016-2021 The OpenSSL Project Authors. All Rights Reserved.
-+ * Copyright 2016-2023 The OpenSSL Project Authors. All Rights Reserved.
- *
- * Licensed under the Apache License 2.0 (the "License"). You may not use
- * this file except in compliance with the License. You can obtain a copy
-@@ -12,6 +12,11 @@
-
- #include "ssl_test_ctx.h"
-
-+#define MAX_HANDSHAKE_HISTORY_ENTRY_BIT 4
-+#define MAX_HANDSHAKE_HISTORY_ENTRY (1 << MAX_HANDSHAKE_HISTORY_ENTRY_BIT)
-+#define MAX_HANDSHAKE_HISTORY_ENTRY_IDX_MASK \
-+ ((1 << MAX_HANDSHAKE_HISTORY_ENTRY_BIT) - 1)
-+
- typedef struct ctx_data_st {
- unsigned char *npn_protocols;
- size_t npn_protocols_len;
-@@ -22,6 +27,63 @@ typedef struct ctx_data_st {
- char *session_ticket_app_data;
- } CTX_DATA;
-
-+typedef enum {
-+ HANDSHAKE,
-+ RENEG_APPLICATION_DATA,
-+ RENEG_SETUP,
-+ RENEG_HANDSHAKE,
-+ APPLICATION_DATA,
-+ SHUTDOWN,
-+ CONNECTION_DONE
-+} connect_phase_t;
-+
-+/* The status for each connection phase. */
-+typedef enum {
-+ PEER_SUCCESS,
-+ PEER_RETRY,
-+ PEER_ERROR,
-+ PEER_WAITING,
-+ PEER_TEST_FAILURE
-+} peer_status_t;
-+
-+typedef enum {
-+ /* Both parties succeeded. */
-+ HANDSHAKE_SUCCESS,
-+ /* Client errored. */
-+ CLIENT_ERROR,
-+ /* Server errored. */
-+ SERVER_ERROR,
-+ /* Peers are in inconsistent state. */
-+ INTERNAL_ERROR,
-+ /* One or both peers not done. */
-+ HANDSHAKE_RETRY
-+} handshake_status_t;
-+
-+/* Stores the various status information in a handshake loop. */
-+typedef struct handshake_history_entry_st {
-+ connect_phase_t phase;
-+ handshake_status_t handshake_status;
-+ peer_status_t server_status;
-+ peer_status_t client_status;
-+ int client_turn_count;
-+ int is_client_turn;
-+} HANDSHAKE_HISTORY_ENTRY;
-+
-+typedef struct handshake_history_st {
-+ /* Implemented using ring buffer. */
-+ /*
-+ * The valid entries are |entries[last_idx]|, |entries[last_idx-1]|,
-+ * ..., etc., going up to |entry_count| number of entries. Note that when
-+ * the index into the array |entries| becomes < 0, we wrap around to
-+ * the end of |entries|.
-+ */
-+ HANDSHAKE_HISTORY_ENTRY entries[MAX_HANDSHAKE_HISTORY_ENTRY];
-+ /* The number of valid entries in |entries| array. */
-+ size_t entry_count;
-+ /* The index of the last valid entry in the |entries| array. */
-+ size_t last_idx;
-+} HANDSHAKE_HISTORY;
-+
- typedef struct handshake_result {
- ssl_test_result_t result;
- /* These alerts are in the 2-byte format returned by the info_callback. */
-@@ -77,6 +139,8 @@ typedef struct handshake_result {
- char *cipher;
- /* session ticket application data */
- char *result_session_ticket_app_data;
-+ /* handshake loop history */
-+ HANDSHAKE_HISTORY history;
- } HANDSHAKE_RESULT;
-
- HANDSHAKE_RESULT *HANDSHAKE_RESULT_new(void);
-@@ -95,4 +159,8 @@ int configure_handshake_ctx_for_srp(SSL_CTX *server_ctx, SSL_CTX *server2_ctx,
- CTX_DATA *server2_ctx_data,
- CTX_DATA *client_ctx_data);
-
-+const char *handshake_connect_phase_name(connect_phase_t phase);
-+const char *handshake_status_name(handshake_status_t handshake_status);
-+const char *handshake_peer_status_name(peer_status_t peer_status);
-+
- #endif /* OSSL_TEST_HANDSHAKE_HELPER_H */
-diff --git a/test/ssl_test.c b/test/ssl_test.c
-index ea60851..9d6b093 100644
---- a/test/ssl_test.c
-+++ b/test/ssl_test.c
-@@ -26,6 +26,44 @@ static OSSL_LIB_CTX *libctx = NULL;
- /* Currently the section names are of the form test-<number>, e.g. test-15. */
- #define MAX_TESTCASE_NAME_LENGTH 100
-
-+static void print_handshake_history(const HANDSHAKE_HISTORY *history)
-+{
-+ size_t first_idx;
-+ size_t i;
-+ size_t cur_idx;
-+ const HANDSHAKE_HISTORY_ENTRY *cur_entry;
-+ const char header_template[] = "|%14s|%16s|%16s|%16s|%17s|%14s|";
-+ const char body_template[] = "|%14s|%16s|%16s|%16s|%17d|%14s|";
-+
-+ TEST_info("The following is the server/client state "
-+ "in the most recent %d handshake loops.",
-+ MAX_HANDSHAKE_HISTORY_ENTRY);
-+
-+ TEST_note("=================================================="
-+ "==================================================");
-+ TEST_note(header_template,
-+ "phase", "handshake status", "server status",
-+ "client status", "client turn count", "is client turn");
-+ TEST_note("+--------------+----------------+----------------"
-+ "+----------------+-----------------+--------------+");
-+
-+ first_idx = (history->last_idx - history->entry_count + 1) &
-+ MAX_HANDSHAKE_HISTORY_ENTRY_IDX_MASK;
-+ for (i = 0; i < history->entry_count; ++i) {
-+ cur_idx = (first_idx + i) & MAX_HANDSHAKE_HISTORY_ENTRY_IDX_MASK;
-+ cur_entry = &(history->entries)[cur_idx];
-+ TEST_note(body_template,
-+ handshake_connect_phase_name(cur_entry->phase),
-+ handshake_status_name(cur_entry->handshake_status),
-+ handshake_peer_status_name(cur_entry->server_status),
-+ handshake_peer_status_name(cur_entry->client_status),
-+ cur_entry->client_turn_count,
-+ cur_entry->is_client_turn ? "true" : "false");
-+ }
-+ TEST_note("=================================================="
-+ "==================================================");
-+}
-+
- static const char *print_alert(int alert)
- {
- return alert ? SSL_alert_desc_string_long(alert) : "no alert";
-@@ -388,6 +426,12 @@ static int check_test(HANDSHAKE_RESULT *result, SSL_TEST_CTX *test_ctx)
- ret &= check_client_sign_type(result, test_ctx);
- ret &= check_client_ca_names(result, test_ctx);
- }
-+
-+ /* Print handshake loop history if any check fails. */
-+ if (!ret) {
-+ print_handshake_history(&(result->history));
-+ }
-+
- return ret;
- }
-
---
-2.25.1
-
diff --git a/meta/recipes-connectivity/openssl/openssl/0001-Configure-do-not-tweak-mips-cflags.patch b/meta/recipes-connectivity/openssl/openssl/0001-Configure-do-not-tweak-mips-cflags.patch
index cd8906df67..77bfe4e4e5 100644
--- a/meta/recipes-connectivity/openssl/openssl/0001-Configure-do-not-tweak-mips-cflags.patch
+++ b/meta/recipes-connectivity/openssl/openssl/0001-Configure-do-not-tweak-mips-cflags.patch
@@ -1,4 +1,4 @@
-From 0377f0d5b5c1079e3b9a80881f4dcc891cbe9f9a Mon Sep 17 00:00:00 2001
+From b5cee0cb0f14a78056ef7722a34b361491f1fdda Mon Sep 17 00:00:00 2001
From: Alexander Kanavin <alex@linutronix.de>
Date: Tue, 30 May 2023 09:11:27 -0700
Subject: [PATCH] Configure: do not tweak mips cflags
@@ -17,10 +17,10 @@ Signed-off-by: Tim Orling <tim.orling@konsulko.com>
1 file changed, 10 deletions(-)
diff --git a/Configure b/Configure
-index fff97bd..5ee54c1 100755
+index c05a30b..db8adee 100755
--- a/Configure
+++ b/Configure
-@@ -1557,16 +1557,6 @@ if ($target =~ /^mingw/ && `$config{CC} --target-help 2>&1` =~ m/-mno-cygwin/m)
+@@ -1575,16 +1575,6 @@ if ($target =~ /^mingw/ && `$config{CC} --target-help 2>&1` =~ m/-mno-cygwin/m)
push @{$config{shared_ldflag}}, "-mno-cygwin";
}
diff --git a/meta/recipes-connectivity/openssl/openssl/0001-buildinfo-strip-sysroot-and-debug-prefix-map-from-co.patch b/meta/recipes-connectivity/openssl/openssl/0001-buildinfo-strip-sysroot-and-debug-prefix-map-from-co.patch
index bfbfedbd67..1d9e7539f6 100644
--- a/meta/recipes-connectivity/openssl/openssl/0001-buildinfo-strip-sysroot-and-debug-prefix-map-from-co.patch
+++ b/meta/recipes-connectivity/openssl/openssl/0001-buildinfo-strip-sysroot-and-debug-prefix-map-from-co.patch
@@ -1,4 +1,4 @@
-From 5985253f2c9025d7c127443a3a9938946f80c2a1 Mon Sep 17 00:00:00 2001
+From 6df53bfebcf8ca65910a18220a6576fb110918a5 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Martin=20Hundeb=C3=B8ll?= <martin@geanix.com>
Date: Tue, 6 Nov 2018 14:50:47 +0100
Subject: [PATCH] buildinfo: strip sysroot and debug-prefix-map from compiler
@@ -28,17 +28,16 @@ Signed-off-by: Kai Kang <kai.kang@windriver.com>
Update to fix buildpaths qa issue for '-ffile-prefix-map'.
Signed-off-by: Khem Raj <raj.khem@gmail.com>
-
---
Configurations/unix-Makefile.tmpl | 16 +++++++++++++++-
crypto/build.info | 2 +-
2 files changed, 16 insertions(+), 2 deletions(-)
diff --git a/Configurations/unix-Makefile.tmpl b/Configurations/unix-Makefile.tmpl
-index 09303c4..011bda1 100644
+index eff66e5..bc48f51 100644
--- a/Configurations/unix-Makefile.tmpl
+++ b/Configurations/unix-Makefile.tmpl
-@@ -514,13 +514,27 @@ BIN_LDFLAGS={- join(' ', $target{bin_lflags} || (),
+@@ -503,13 +503,27 @@ BIN_LDFLAGS={- join(' ', $target{bin_lflags} || (),
'$(CNF_LDFLAGS)', '$(LDFLAGS)') -}
BIN_EX_LIBS=$(CNF_EX_LIBS) $(EX_LIBS)
@@ -68,10 +67,10 @@ index 09303c4..011bda1 100644
# For x86 assembler: Set PROCESSOR to 386 if you want to support
diff --git a/crypto/build.info b/crypto/build.info
-index aee5c46..95c9577 100644
+index 8e4a885..95b0902 100644
--- a/crypto/build.info
+++ b/crypto/build.info
-@@ -115,7 +115,7 @@ DEFINE[../libcrypto]=$UPLINKDEF
+@@ -114,7 +114,7 @@ DEFINE[../libcrypto]=$UPLINKDEF
DEPEND[info.o]=buildinf.h
DEPEND[cversion.o]=buildinf.h
diff --git a/meta/recipes-connectivity/openssl/openssl/0001-extend-check_cwm-test-timeout.patch b/meta/recipes-connectivity/openssl/openssl/0001-extend-check_cwm-test-timeout.patch
index f6eb28069a..76bc05d5f9 100644
--- a/meta/recipes-connectivity/openssl/openssl/0001-extend-check_cwm-test-timeout.patch
+++ b/meta/recipes-connectivity/openssl/openssl/0001-extend-check_cwm-test-timeout.patch
@@ -1,4 +1,4 @@
-From c7000672296f4c367341aa3415f26c4d9f5e4749 Mon Sep 17 00:00:00 2001
+From 14856dbd767621ce6f162680c00557b54af0effb Mon Sep 17 00:00:00 2001
From: Gyorgy Sarvari <skandigraun@gmail.com>
Date: Thu, 23 Oct 2025 11:24:36 +0200
Subject: [PATCH] extend check_cwm test timeout
@@ -15,7 +15,7 @@ Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
1 file changed, 5 insertions(+)
diff --git a/test/radix/main.c b/test/radix/main.c
-index 4a1e886a71..39f8c61ef9 100644
+index 0f3dc11..d925639 100644
--- a/test/radix/main.c
+++ b/test/radix/main.c
@@ -25,6 +25,11 @@ static int test_script(int idx)
diff --git a/meta/recipes-connectivity/openssl/openssl_3.5.7.bb b/meta/recipes-connectivity/openssl/openssl_4.0.1.bb
similarity index 87%
rename from meta/recipes-connectivity/openssl/openssl_3.5.7.bb
rename to meta/recipes-connectivity/openssl/openssl_4.0.1.bb
index b95c734f1d..a669de1b22 100644
--- a/meta/recipes-connectivity/openssl/openssl_3.5.7.bb
+++ b/meta/recipes-connectivity/openssl/openssl_4.0.1.bb
@@ -11,7 +11,6 @@ SRC_URI = "http://www.openssl.org/source/openssl-${PV}.tar.gz \
file://run-ptest \
file://0001-buildinfo-strip-sysroot-and-debug-prefix-map-from-co.patch \
file://0001-Configure-do-not-tweak-mips-cflags.patch \
- file://0001-Added-handshake-history-reporting-when-test-fails.patch \
file://0001-extend-check_cwm-test-timeout.patch \
"
@@ -19,10 +18,9 @@ SRC_URI:append:class-nativesdk = " \
file://environment.d-openssl.sh \
"
-SRC_URI[sha256sum] = "a8c0d28a529ca480f9f36cf5792e2cd21984552a3c8e4aa11a24aa31aeac98e8"
+SRC_URI[sha256sum] = "2db3f3a0d6ea4b59e1f094ace2c8cd536dffb87cdc39084c5afa1e6f7f37dd09"
-inherit lib_package multilib_header multilib_script ptest perlnative manpages
-MULTILIB_SCRIPTS = "${PN}-bin:${bindir}/c_rehash"
+inherit lib_package multilib_header ptest perlnative manpages
# OpenSSL publishes bugfix/security-only releases on its per-minor branches.
# When the tracked series reaches EOL, bump the regex manually to the next
@@ -33,7 +31,6 @@ PACKAGECONFIG ?= ""
PACKAGECONFIG:class-native = ""
PACKAGECONFIG:class-nativesdk = ""
-PACKAGECONFIG[cryptodev-linux] = "enable-devcryptoeng,disable-devcryptoeng,cryptodev-linux,,cryptodev-module"
PACKAGECONFIG[legacy] = ",no-legacy"
PACKAGECONFIG[tls1] = ",no-tls1"
PACKAGECONFIG[tls1_1] = ",no-tls1_1"
@@ -57,8 +54,8 @@ EXTRA_OECONF:append:class-native = " --with-rand-seed=os,devrandom"
EXTRA_OECONF:append:class-nativesdk = " --with-rand-seed=os,devrandom"
# Relying on hardcoded built-in paths causes openssl-native to not be relocateable from sstate.
-EXTRA_OEMAKE:append:task-compile:class-native = ' OPENSSLDIR="/not/builtin" ENGINESDIR="/not/builtin" MODULESDIR="/not/builtin"'
-EXTRA_OEMAKE:append:task-compile:class-nativesdk = ' OPENSSLDIR="/not/builtin" ENGINESDIR="/not/builtin" MODULESDIR="/not/builtin"'
+EXTRA_OEMAKE:append:task-compile:class-native = ' OPENSSLDIR="/not/builtin" MODULESDIR="/not/builtin"'
+EXTRA_OEMAKE:append:task-compile:class-nativesdk = ' OPENSSLDIR="/not/builtin" MODULESDIR="/not/builtin"'
#| threads_pthread.c:(.text+0x372): undefined reference to `__atomic_is_lock_free'
EXTRA_OECONF:append:toolchain-clang:x86 = " -latomic"
@@ -204,12 +201,10 @@ do_install:append:class-native () {
OPENSSL_CONF=\${OPENSSL_CONF:-${libdir}/ssl-3/openssl.cnf} \
SSL_CERT_DIR=\${SSL_CERT_DIR:-${libdir}/ssl-3/certs} \
SSL_CERT_FILE=\${SSL_CERT_FILE:-${libdir}/ssl-3/cert.pem} \
- OPENSSL_ENGINES=\${OPENSSL_ENGINES:-${libdir}/engines-3} \
OPENSSL_MODULES=\${OPENSSL_MODULES:-${libdir}/ossl-modules}
- # Setting ENGINESDIR and MODULESDIR to invalid paths prevents host contamination,
+ # Setting MODULESDIR to invalid paths prevents host contamination,
# but also breaks the generated libcrypto.pc file. Post-Fix it manually here.
- sed -i 's|^enginesdir=\($.libdir.\)/.*|enginesdir=\1/engines-3|' ${D}${libdir}/pkgconfig/libcrypto.pc
sed -i 's|^modulesdir=\($.libdir.\)/.*|modulesdir=\1/ossl-modules|' ${D}${libdir}/pkgconfig/libcrypto.pc
}
@@ -252,10 +247,6 @@ do_install_ptest() {
sed 's|${S}|${PTEST_PATH}|g' -i ${D}${PTEST_PATH}/configdata.pm ${D}${PTEST_PATH}/util/wrap.pl
- install -d ${D}${PTEST_PATH}/engines
- install -m755 ${B}/engines/dasync.so ${D}${PTEST_PATH}/engines/
- install -m755 ${B}/engines/ossltest.so ${D}${PTEST_PATH}/engines/
- ln -s ${libdir}/engines-3/loader_attic.so ${D}${PTEST_PATH}/engines/
ln -s ${libdir}/ossl-modules/ ${D}${PTEST_PATH}/providers
}
@@ -270,17 +261,14 @@ pkg_postinst_ontarget:${PN}-ossl-module-fips () {
# file to be installed for both the openssl-bin package and the libcrypto
# package since the openssl-bin package depends on the libcrypto package.
-PACKAGES =+ "libcrypto libssl openssl-conf ${PN}-engines ${PN}-misc ${PN}-ossl-module-legacy ${PN}-ossl-module-fips"
+PACKAGES =+ "libcrypto libssl openssl-conf ${PN}-misc ${PN}-ossl-module-legacy ${PN}-ossl-module-fips"
FILES:libcrypto = "${libdir}/libcrypto${SOLIBS}"
FILES:libssl = "${libdir}/libssl${SOLIBS}"
FILES:openssl-conf = "${sysconfdir}/ssl/openssl.cnf* \
${libdir}/ssl-3/openssl.cnf* \
"
-FILES:${PN}-engines = "${libdir}/engines-3"
-# ${prefix} comes from what we pass into --prefix at configure time (which is used for INSTALLTOP)
-FILES:${PN}-engines:append:mingw32:class-nativesdk = " ${prefix}${libdir}/engines-3"
-FILES:${PN}-misc = "${libdir}/ssl-3/misc ${bindir}/c_rehash"
+FILES:${PN}-misc = "${libdir}/ssl-3/misc"
FILES:${PN}-ossl-module-legacy = "${libdir}/ossl-modules/legacy.so"
FILES:${PN}-ossl-module-fips = "${libdir}/ossl-modules/fips.so"
FILES:${PN} =+ "${libdir}/ssl-3/* ${libdir}/ossl-modules/"
@@ -290,7 +278,7 @@ CONFFILES:openssl-conf = "${sysconfdir}/ssl/openssl.cnf"
RRECOMMENDS:libcrypto += "openssl-conf ${PN}-ossl-module-legacy"
RDEPENDS:${PN}-misc = "perl"
-RDEPENDS:${PN}-ptest += "openssl-bin perl perl-modules bash sed openssl-engines"
+RDEPENDS:${PN}-ptest += "openssl-bin perl perl-modules bash sed"
RRECOMMENDS:${PN}-ptest += "${PN}-ossl-module-legacy"
RDEPENDS:${PN}-bin += "openssl-conf"
next prev parent reply other threads:[~2026-08-22 17:52 UTC|newest]
Thread overview: 44+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-14 5:18 [RFC 0/7] openssl: upgrade to 4.0.1 and fix dependent recipes Jaipaul Cheernam
2026-08-14 5:18 ` [PATCH 1/7] openssl: upgrade 3.5.7 -> 4.0.1 Jaipaul Cheernam
2026-08-15 16:20 ` [OE-core] " Mathieu Dubois-Briand
2026-08-14 5:18 ` [PATCH 2/7] python3: backport OpenSSL 4.0 support from upstream Jaipaul Cheernam
2026-08-14 5:18 ` [PATCH 3/7] socat: fix build with OpenSSL 4.0 Jaipaul Cheernam
2026-08-14 5:18 ` [PATCH 4/7] rust: Upgrade 1.96.1 -> 1.97.1 Jaipaul Cheernam
2026-08-15 16:11 ` [OE-core] " Mathieu Dubois-Briand
2026-08-14 5:18 ` [PATCH 5/7] serf: fix build with OpenSSL 4.0 Jaipaul Cheernam
2026-08-14 5:18 ` [PATCH 6/7] u-boot-tools: " Jaipaul Cheernam
2026-08-14 11:12 ` [OE-core] " Alexander Kanavin
2026-08-21 10:44 ` Quentin Schulz
2026-08-15 16:14 ` Mathieu Dubois-Briand
2026-08-14 5:18 ` [PATCH 7/7] kea: " Jaipaul Cheernam
2026-08-14 11:14 ` [OE-core] " Alexander Kanavin
2026-08-20 18:10 ` [RFC v2 0/6] openssl: upgrade to 4.0.1 and fix dependent recipes Jaipaul Cheernam
2026-08-20 18:10 ` [RFC v2 1/6] openssl: upgrade 3.5.7 -> 4.0.1 Jaipaul Cheernam
2026-08-21 17:52 ` [OE-core] " Khem Raj
2026-08-20 18:10 ` [RFC v2 2/6] python3: backport OpenSSL 4.0 support from upstream Jaipaul Cheernam
2026-08-20 18:10 ` [RFC v2 3/6] socat: fix build with OpenSSL 4.0 Jaipaul Cheernam
2026-08-20 18:10 ` [RFC v2 4/6] serf: " Jaipaul Cheernam
2026-08-20 18:10 ` [RFC v2 5/6] u-boot: " Jaipaul Cheernam
2026-08-21 10:52 ` [OE-core] " Quentin Schulz
2026-08-22 14:02 ` Jaipaul Cheernam
2026-08-24 10:59 ` Quentin Schulz
2026-08-20 18:10 ` [RFC v2 6/6] kea: " Jaipaul Cheernam
2026-08-21 21:17 ` [OE-core] [RFC v2 0/6] openssl: upgrade to 4.0.1 and fix dependent recipes Richard Purdie
2026-08-22 14:31 ` [OE-core][RFC v3 0/6] openssl: upgrade 3.5.7 -> 4.0.1 Jaipaul Cheernam
2026-08-22 14:31 ` [OE-core][RFC v3 1/6] " Jaipaul Cheernam
2026-08-22 14:31 ` [OE-core][RFC v3 2/6] python3: backport OpenSSL 4.0 support from upstream Jaipaul Cheernam
2026-08-22 14:31 ` [OE-core][RFC v3 3/6] socat: fix build with OpenSSL 4.0 Jaipaul Cheernam
2026-08-22 14:31 ` [OE-core][RFC v3 4/6] serf: " Jaipaul Cheernam
2026-08-22 14:31 ` [OE-core][RFC v3 5/6] u-boot: " Jaipaul Cheernam
2026-08-22 14:31 ` [OE-core][RFC v3 6/6] kea: " Jaipaul Cheernam
2026-08-22 17:51 ` [RFC v4 0/6] openssl: upgrade 3.5.7 -> 4.0.1 Jaipaul Cheernam
2026-08-22 17:51 ` Jaipaul Cheernam [this message]
2026-08-23 6:56 ` [OE-core] [RFC v4 1/6] " Khem Raj
2026-08-23 6:57 ` Khem Raj
2026-08-22 17:51 ` [RFC v4 2/6] python3: backport OpenSSL 4.0 support from upstream Jaipaul Cheernam
2026-08-22 17:51 ` [RFC v4 3/6] socat: fix build with OpenSSL 4.0 Jaipaul Cheernam
2026-08-22 17:51 ` [RFC v4 4/6] serf: " Jaipaul Cheernam
2026-08-22 17:51 ` [RFC v4 5/6] u-boot: " Jaipaul Cheernam
2026-08-22 17:52 ` [RFC v4 6/6] kea: " Jaipaul Cheernam
2026-08-23 7:02 ` [OE-core] [RFC v4 0/6] openssl: upgrade 3.5.7 -> 4.0.1 Richard Purdie
2026-08-24 14:16 ` Ahmad Fatoum
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260822175200.57534-2-jaipaul.cheernam@est.tech \
--to=jaipaul.cheernam@est.tech \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.