All of lore.kernel.org
 help / color / mirror / Atom feed
* [Buildroot] [PATCH] package/expat: fix no high quality entropy warning on Linux <3.17 or glibc <2.25
@ 2026-08-25  9:34 Thomas Devoogdt
  2026-08-25 20:10 ` Julien Olivain via buildroot
  2026-09-04 12:18 ` Thomas Perale via buildroot
  0 siblings, 2 replies; 3+ messages in thread
From: Thomas Devoogdt @ 2026-08-25  9:34 UTC (permalink / raw)
  To: buildroot; +Cc: Fabrice Fontaine, Thomas Devoogdt

xmlparse.c:150:4: error: #error You do not have support for any sources of high quality entropy enabled.
For end user security, that is probably not what you want. Your options include:
  * Linux >=3.17 + glibc >=2.25 (getrandom): HAVE_GETRANDOM,
  * Linux >=3.17 + glibc (including <2.25) (syscall SYS_getrandom): HAVE_SYSCALL_GETRANDOM,
  * BSD / macOS >=10.7 / glibc >=2.36 (arc4random_buf): HAVE_ARC4RANDOM_BUF,
  * BSD / macOS (including <10.7) / glibc >=2.36 (arc4random): HAVE_ARC4RANDOM,
  * BSD / macOS >=10.12 / glibc >=2.25 (getentropy): HAVE_GETENTROPY,
  * Linux (including <3.17) / BSD / macOS (including <10.7) / Solaris >=8 (/dev/urandom): XML_DEV_URANDOM,
  * Windows >=Vista (rand_s): _WIN32.
If you insist on not using any of these, bypass this error by defining XML_POOR_ENTROPY and be vulnerable to hash flooding;
you have been warned. If you have reasons to patch this detection code away or need changes to the build system, please open a bug. Thank you!

This is caused by the upstream commit "Autotools: Stop using /dev/urandom by default"
https://github.com/libexpat/libexpat/commit/d30eca113a44562137d59835cf2255ea32d11ba6

But since all Linux systems have /dev/urandom, we can just enable it by default.

Moved config options to multiline layout to fit within the 80 characters.

Signed-off-by: Thomas Devoogdt <thomas.devoogdt@barco.com>
---
 package/expat/expat.mk | 12 ++++++++++--
 1 file changed, 10 insertions(+), 2 deletions(-)

diff --git a/package/expat/expat.mk b/package/expat/expat.mk
index 7645edfd52..a82be75a4d 100644
--- a/package/expat/expat.mk
+++ b/package/expat/expat.mk
@@ -14,8 +14,16 @@ EXPAT_CPE_ID_VENDOR = libexpat_project
 EXPAT_CPE_ID_PRODUCT = libexpat
 
 EXPAT_CONF_OPTS = \
-	--without-docbook --without-examples --without-tests --without-xmlwf
-HOST_EXPAT_CONF_OPTS = --without-docbook --without-examples --without-tests
+	--with-dev-urandom \
+	--without-docbook \
+	--without-examples \
+	--without-tests \
+	--without-xmlwf
+
+HOST_EXPAT_CONF_OPTS = \
+	--without-docbook \
+	--without-examples \
+	--without-tests
 
 $(eval $(autotools-package))
 $(eval $(host-autotools-package))
-- 
2.43.0

_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply related	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-04 12:19 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-25  9:34 [Buildroot] [PATCH] package/expat: fix no high quality entropy warning on Linux <3.17 or glibc <2.25 Thomas Devoogdt
2026-08-25 20:10 ` Julien Olivain via buildroot
2026-09-04 12:18 ` Thomas Perale via buildroot

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.