All of lore.kernel.org
 help / color / mirror / Atom feed
* [Buildroot] [PATCH] package/expat: fix no high quality entropy warning on Linux <3.17 or glibc <2.25
@ 2026-08-25  9:34 Thomas Devoogdt
  2026-08-25 20:10 ` Julien Olivain via buildroot
  2026-09-04 12:18 ` Thomas Perale via buildroot
  0 siblings, 2 replies; 3+ messages in thread
From: Thomas Devoogdt @ 2026-08-25  9:34 UTC (permalink / raw)
  To: buildroot; +Cc: Fabrice Fontaine, Thomas Devoogdt

xmlparse.c:150:4: error: #error You do not have support for any sources of high quality entropy enabled.
For end user security, that is probably not what you want. Your options include:
  * Linux >=3.17 + glibc >=2.25 (getrandom): HAVE_GETRANDOM,
  * Linux >=3.17 + glibc (including <2.25) (syscall SYS_getrandom): HAVE_SYSCALL_GETRANDOM,
  * BSD / macOS >=10.7 / glibc >=2.36 (arc4random_buf): HAVE_ARC4RANDOM_BUF,
  * BSD / macOS (including <10.7) / glibc >=2.36 (arc4random): HAVE_ARC4RANDOM,
  * BSD / macOS >=10.12 / glibc >=2.25 (getentropy): HAVE_GETENTROPY,
  * Linux (including <3.17) / BSD / macOS (including <10.7) / Solaris >=8 (/dev/urandom): XML_DEV_URANDOM,
  * Windows >=Vista (rand_s): _WIN32.
If you insist on not using any of these, bypass this error by defining XML_POOR_ENTROPY and be vulnerable to hash flooding;
you have been warned. If you have reasons to patch this detection code away or need changes to the build system, please open a bug. Thank you!

This is caused by the upstream commit "Autotools: Stop using /dev/urandom by default"
https://github.com/libexpat/libexpat/commit/d30eca113a44562137d59835cf2255ea32d11ba6

But since all Linux systems have /dev/urandom, we can just enable it by default.

Moved config options to multiline layout to fit within the 80 characters.

Signed-off-by: Thomas Devoogdt <thomas.devoogdt@barco.com>
---
 package/expat/expat.mk | 12 ++++++++++--
 1 file changed, 10 insertions(+), 2 deletions(-)

diff --git a/package/expat/expat.mk b/package/expat/expat.mk
index 7645edfd52..a82be75a4d 100644
--- a/package/expat/expat.mk
+++ b/package/expat/expat.mk
@@ -14,8 +14,16 @@ EXPAT_CPE_ID_VENDOR = libexpat_project
 EXPAT_CPE_ID_PRODUCT = libexpat
 
 EXPAT_CONF_OPTS = \
-	--without-docbook --without-examples --without-tests --without-xmlwf
-HOST_EXPAT_CONF_OPTS = --without-docbook --without-examples --without-tests
+	--with-dev-urandom \
+	--without-docbook \
+	--without-examples \
+	--without-tests \
+	--without-xmlwf
+
+HOST_EXPAT_CONF_OPTS = \
+	--without-docbook \
+	--without-examples \
+	--without-tests
 
 $(eval $(autotools-package))
 $(eval $(host-autotools-package))
-- 
2.43.0

_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [Buildroot] [PATCH] package/expat: fix no high quality entropy warning on Linux <3.17 or glibc <2.25
  2026-08-25  9:34 [Buildroot] [PATCH] package/expat: fix no high quality entropy warning on Linux <3.17 or glibc <2.25 Thomas Devoogdt
@ 2026-08-25 20:10 ` Julien Olivain via buildroot
  2026-09-04 12:18 ` Thomas Perale via buildroot
  1 sibling, 0 replies; 3+ messages in thread
From: Julien Olivain via buildroot @ 2026-08-25 20:10 UTC (permalink / raw)
  To: Thomas Devoogdt; +Cc: buildroot, Fabrice Fontaine, Thomas Devoogdt

On 25/08/2026 11:34, Thomas Devoogdt wrote:
> xmlparse.c:150:4: error: #error You do not have support for any sources 
> of high quality entropy enabled.
> For end user security, that is probably not what you want. Your options 
> include:
>   * Linux >=3.17 + glibc >=2.25 (getrandom): HAVE_GETRANDOM,
>   * Linux >=3.17 + glibc (including <2.25) (syscall SYS_getrandom): 
> HAVE_SYSCALL_GETRANDOM,
>   * BSD / macOS >=10.7 / glibc >=2.36 (arc4random_buf): 
> HAVE_ARC4RANDOM_BUF,
>   * BSD / macOS (including <10.7) / glibc >=2.36 (arc4random): 
> HAVE_ARC4RANDOM,
>   * BSD / macOS >=10.12 / glibc >=2.25 (getentropy): HAVE_GETENTROPY,
>   * Linux (including <3.17) / BSD / macOS (including <10.7) / Solaris 
> >=8 (/dev/urandom): XML_DEV_URANDOM,
>   * Windows >=Vista (rand_s): _WIN32.
> If you insist on not using any of these, bypass this error by defining 
> XML_POOR_ENTROPY and be vulnerable to hash flooding;
> you have been warned. If you have reasons to patch this detection code 
> away or need changes to the build system, please open a bug. Thank you!
> 
> This is caused by the upstream commit "Autotools: Stop using 
> /dev/urandom by default"
> https://github.com/libexpat/libexpat/commit/d30eca113a44562137d59835cf2255ea32d11ba6
> 
> But since all Linux systems have /dev/urandom, we can just enable it by 
> default.
> 
> Moved config options to multiline layout to fit within the 80 
> characters.
> 
> Signed-off-by: Thomas Devoogdt <thomas.devoogdt@barco.com>

Applied to master, thanks. I also added extra info in the commit log. 
See:
https://gitlab.com/buildroot.org/buildroot/-/commit/c22fc74f2b4e5b6082203ecd839d530058e0106d

Best regards,

Julien.
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [Buildroot] [PATCH] package/expat: fix no high quality entropy warning on Linux <3.17 or glibc <2.25
  2026-08-25  9:34 [Buildroot] [PATCH] package/expat: fix no high quality entropy warning on Linux <3.17 or glibc <2.25 Thomas Devoogdt
  2026-08-25 20:10 ` Julien Olivain via buildroot
@ 2026-09-04 12:18 ` Thomas Perale via buildroot
  1 sibling, 0 replies; 3+ messages in thread
From: Thomas Perale via buildroot @ 2026-09-04 12:18 UTC (permalink / raw)
  To: Thomas Devoogdt; +Cc: Thomas Perale, buildroot

In reply of:
> xmlparse.c:150:4: error: #error You do not have support for any sources of high quality entropy enabled.
> For end user security, that is probably not what you want. Your options include:
>   * Linux >=3.17 + glibc >=2.25 (getrandom): HAVE_GETRANDOM,
>   * Linux >=3.17 + glibc (including <2.25) (syscall SYS_getrandom): HAVE_SYSCALL_GETRANDOM,
>   * BSD / macOS >=10.7 / glibc >=2.36 (arc4random_buf): HAVE_ARC4RANDOM_BUF,
>   * BSD / macOS (including <10.7) / glibc >=2.36 (arc4random): HAVE_ARC4RANDOM,
>   * BSD / macOS >=10.12 / glibc >=2.25 (getentropy): HAVE_GETENTROPY,
>   * Linux (including <3.17) / BSD / macOS (including <10.7) / Solaris >=8 (/dev/urandom): XML_DEV_URANDOM,
>   * Windows >=Vista (rand_s): _WIN32.
> If you insist on not using any of these, bypass this error by defining XML_POOR_ENTROPY and be vulnerable to hash flooding;
> you have been warned. If you have reasons to patch this detection code away or need changes to the build system, please open a bug. Thank you!
> 
> This is caused by the upstream commit "Autotools: Stop using /dev/urandom by default"
> https://github.com/libexpat/libexpat/commit/d30eca113a44562137d59835cf2255ea32d11ba6
> 
> But since all Linux systems have /dev/urandom, we can just enable it by default.
> 
> Moved config options to multiline layout to fit within the 80 characters.
> 
> Signed-off-by: Thomas Devoogdt <thomas.devoogdt@barco.com>

Applied to 2025.02.x & 2026.05.x. Thanks

> ---
>  package/expat/expat.mk | 12 ++++++++++--
>  1 file changed, 10 insertions(+), 2 deletions(-)
> 
> diff --git a/package/expat/expat.mk b/package/expat/expat.mk
> index 7645edfd52..a82be75a4d 100644
> --- a/package/expat/expat.mk
> +++ b/package/expat/expat.mk
> @@ -14,8 +14,16 @@ EXPAT_CPE_ID_VENDOR = libexpat_project
>  EXPAT_CPE_ID_PRODUCT = libexpat
>  
>  EXPAT_CONF_OPTS = \
> -	--without-docbook --without-examples --without-tests --without-xmlwf
> -HOST_EXPAT_CONF_OPTS = --without-docbook --without-examples --without-tests
> +	--with-dev-urandom \
> +	--without-docbook \
> +	--without-examples \
> +	--without-tests \
> +	--without-xmlwf
> +
> +HOST_EXPAT_CONF_OPTS = \
> +	--without-docbook \
> +	--without-examples \
> +	--without-tests
>  
>  $(eval $(autotools-package))
>  $(eval $(host-autotools-package))
> -- 
> 2.43.0
> 
> _______________________________________________
> buildroot mailing list
> buildroot@buildroot.org
> https://lists.buildroot.org/mailman/listinfo/buildroot
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-04 12:19 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-25  9:34 [Buildroot] [PATCH] package/expat: fix no high quality entropy warning on Linux <3.17 or glibc <2.25 Thomas Devoogdt
2026-08-25 20:10 ` Julien Olivain via buildroot
2026-09-04 12:18 ` Thomas Perale via buildroot

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.