From: jaeyoon.jung@lge.com
To: openembedded-core@lists.openembedded.org
Cc: Jaeyoon Jung <jaeyoon.jung@lge.com>
Subject: [PATCH v2] openssl: use nonarch_libdir for openssldir
Date: Wed, 2 Sep 2026 19:00:13 +0900 [thread overview]
Message-ID: <20260902100013.2136263-1-jaeyoon.jung@lge.com> (raw)
From: Jaeyoon Jung <jaeyoon.jung@lge.com>
Set openssldir to ${nonarch_libdir}/ssl-3 instead of ${libdir}/ssl-3
as the contents of this directory do not vary between non-multilib and
multilib builds.
Signed-off-by: Jaeyoon Jung <jaeyoon.jung@lge.com>
---
.../openssl/openssl_3.5.8.bb | 30 +++++++++----------
1 file changed, 15 insertions(+), 15 deletions(-)
diff --git a/meta/recipes-connectivity/openssl/openssl_3.5.8.bb b/meta/recipes-connectivity/openssl/openssl_3.5.8.bb
index 71446e62e3..7e9f32770a 100644
--- a/meta/recipes-connectivity/openssl/openssl_3.5.8.bb
+++ b/meta/recipes-connectivity/openssl/openssl_3.5.8.bb
@@ -153,7 +153,7 @@ do_configure () {
PERLEXTERNAL="$(realpath ${S}/external/perl/Text-Template-*/lib)"
test -d "$PERLEXTERNAL" || bberror "PERLEXTERNAL '$PERLEXTERNAL' not found!"
HASHBANGPERL="/usr/bin/env perl" PERL=perl PERL5LIB="$PERLEXTERNAL" \
- perl ${S}/Configure ${EXTRA_OECONF} ${PACKAGECONFIG_CONFARGS} ${DEPRECATED_CRYPTO_FLAGS} --prefix=${prefix} --openssldir=${libdir}/ssl-3 --libdir=${baselib} $target
+ perl ${S}/Configure ${EXTRA_OECONF} ${PACKAGECONFIG_CONFARGS} ${DEPRECATED_CRYPTO_FLAGS} --prefix=${prefix} --openssldir=${nonarch_libdir}/ssl-3 --libdir=${baselib} $target
perl ${B}/configdata.pm --dump
}
@@ -175,20 +175,20 @@ do_install () {
# Create SSL structure for packages such as ca-certificates which
# contain hard-coded paths to /etc/ssl. Debian does the same.
install -d ${D}${sysconfdir}/ssl
- mv ${D}${libdir}/ssl-3/certs \
- ${D}${libdir}/ssl-3/private \
- ${D}${libdir}/ssl-3/openssl.cnf \
+ mv ${D}${nonarch_libdir}/ssl-3/certs \
+ ${D}${nonarch_libdir}/ssl-3/private \
+ ${D}${nonarch_libdir}/ssl-3/openssl.cnf \
${D}${sysconfdir}/ssl/
# Although absolute symlinks would be OK for the target, they become
# invalid if native or nativesdk are relocated from sstate.
- ln -sf ${@oe.path.relative('${libdir}/ssl-3', '${sysconfdir}/ssl/certs')} ${D}${libdir}/ssl-3/certs
- ln -sf ${@oe.path.relative('${libdir}/ssl-3', '${sysconfdir}/ssl/private')} ${D}${libdir}/ssl-3/private
- ln -sf ${@oe.path.relative('${libdir}/ssl-3', '${sysconfdir}/ssl/openssl.cnf')} ${D}${libdir}/ssl-3/openssl.cnf
+ ln -sf ${@oe.path.relative('${nonarch_libdir}/ssl-3', '${sysconfdir}/ssl/certs')} ${D}${nonarch_libdir}/ssl-3/certs
+ ln -sf ${@oe.path.relative('${nonarch_libdir}/ssl-3', '${sysconfdir}/ssl/private')} ${D}${nonarch_libdir}/ssl-3/private
+ ln -sf ${@oe.path.relative('${nonarch_libdir}/ssl-3', '${sysconfdir}/ssl/openssl.cnf')} ${D}${nonarch_libdir}/ssl-3/openssl.cnf
# Generate fipsmodule.cnf in pkg_postinst_ontarget
if ${@bb.utils.contains('PACKAGECONFIG', 'fips', 'true', 'false', d)}; then
- rm -f ${D}${libdir}/ssl-3/fipsmodule.cnf
+ rm -f ${D}${nonarch_libdir}/ssl-3/fipsmodule.cnf
fi
}
@@ -201,9 +201,9 @@ do_install:append:class-target () {
do_install:append:class-native () {
create_wrapper ${D}${bindir}/openssl \
- OPENSSL_CONF=\${OPENSSL_CONF:-${libdir}/ssl-3/openssl.cnf} \
- SSL_CERT_DIR=\${SSL_CERT_DIR:-${libdir}/ssl-3/certs} \
- SSL_CERT_FILE=\${SSL_CERT_FILE:-${libdir}/ssl-3/cert.pem} \
+ OPENSSL_CONF=\${OPENSSL_CONF:-${nonarch_libdir}/ssl-3/openssl.cnf} \
+ SSL_CERT_DIR=\${SSL_CERT_DIR:-${nonarch_libdir}/ssl-3/certs} \
+ SSL_CERT_FILE=\${SSL_CERT_FILE:-${nonarch_libdir}/ssl-3/cert.pem} \
OPENSSL_ENGINES=\${OPENSSL_ENGINES:-${libdir}/engines-3} \
OPENSSL_MODULES=\${OPENSSL_MODULES:-${libdir}/ossl-modules}
@@ -261,7 +261,7 @@ do_install_ptest() {
pkg_postinst_ontarget:${PN}-ossl-module-fips () {
if test -f ${libdir}/ossl-modules/fips.so; then
- ${bindir}/openssl fipsinstall -out ${libdir}/ssl-3/fipsmodule.cnf -module ${libdir}/ossl-modules/fips.so
+ ${bindir}/openssl fipsinstall -out ${nonarch_libdir}/ssl-3/fipsmodule.cnf -module ${libdir}/ossl-modules/fips.so
fi
}
@@ -275,15 +275,15 @@ PACKAGES =+ "libcrypto libssl openssl-conf ${PN}-engines ${PN}-misc ${PN}-ossl-m
FILES:libcrypto = "${libdir}/libcrypto${SOLIBS}"
FILES:libssl = "${libdir}/libssl${SOLIBS}"
FILES:openssl-conf = "${sysconfdir}/ssl/openssl.cnf* \
- ${libdir}/ssl-3/openssl.cnf* \
+ ${nonarch_libdir}/ssl-3/openssl.cnf* \
"
FILES:${PN}-engines = "${libdir}/engines-3"
# ${prefix} comes from what we pass into --prefix at configure time (which is used for INSTALLTOP)
FILES:${PN}-engines:append:mingw32:class-nativesdk = " ${prefix}${libdir}/engines-3"
-FILES:${PN}-misc = "${libdir}/ssl-3/misc ${bindir}/c_rehash"
+FILES:${PN}-misc = "${nonarch_libdir}/ssl-3/misc ${bindir}/c_rehash"
FILES:${PN}-ossl-module-legacy = "${libdir}/ossl-modules/legacy.so"
FILES:${PN}-ossl-module-fips = "${libdir}/ossl-modules/fips.so"
-FILES:${PN} =+ "${libdir}/ssl-3/* ${libdir}/ossl-modules/"
+FILES:${PN} =+ "${nonarch_libdir}/ssl-3/* ${libdir}/ossl-modules/"
FILES:${PN}:append:class-nativesdk = " ${SDKPATHNATIVE}/environment-setup.d/openssl.sh"
CONFFILES:openssl-conf = "${sysconfdir}/ssl/openssl.cnf"
next reply other threads:[~2026-09-02 10:00 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-02 10:00 jaeyoon.jung [this message]
2026-09-03 7:13 ` [OE-core] [PATCH v2] openssl: use nonarch_libdir for openssldir Mathieu Dubois-Briand
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260902100013.2136263-1-jaeyoon.jung@lge.com \
--to=jaeyoon.jung@lge.com \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.