* [Buildroot] [PATCH v2 1/2] package/libopenssl: disable atomic operations for m68k Coldfire
@ 2026-09-03 6:39 Bernd Kuhls
2026-09-03 6:39 ` [Buildroot] [PATCH v2 2/2] package/libcurl: security bump to version 8.22.0 Bernd Kuhls
2026-09-04 11:51 ` [Buildroot] [PATCH v2 1/2] package/libopenssl: disable atomic operations for m68k Coldfire Peter Korsgaard
0 siblings, 2 replies; 4+ messages in thread
From: Bernd Kuhls @ 2026-09-03 6:39 UTC (permalink / raw)
To: buildroot
This patch fixes a build error with OpenSSL-enabled libcurl which was
detected by the Gitlab pipelines:
checking for openssl options with pkg-config... found
configure: pkg-config: SSL_LIBS: "-lssl -lcrypto -pthread"
configure: pkg-config: SSL_LDFLAGS: "-L/builds/bkuhls/buildroot/br-test-pkg/bootlin-m68k-5208-uclibc/host/bin/../m68k-buildroot-uclinux-uclibc/sysroot/usr/lib"
configure: pkg-config: SSL_CPPFLAGS: ""
checking for HMAC_Update in -lcrypto... no
checking for HMAC_Init_ex in -lcrypto... no
checking OpenSSL linking with -ldl... no
checking OpenSSL linking with -ldl and -lpthread... no
checking for SSL_set_quic_use_legacy_codepoint... no
checking for SSL_set_quic_tls_cbs... no
configure: OpenSSL version does not speak any known QUIC API
configure: OPT_OPENSSL: /builds/bkuhls/buildroot/br-test-pkg/bootlin-m68k-5208-uclibc/host/m68k-buildroot-uclinux-uclibc/sysroot/usr
configure: OPENSSL_ENABLED:
configure: error: --with-openssl was given but OpenSSL could not be detected
make[1]: *** [package/pkg-generic.mk:263: /builds/bkuhls/buildroot/br-test-pkg/bootlin-m68k-5208-uclibc/build/libcurl-8.21.0/.stamp_configured] Error 1
Although OpenSSL was found using pkg-config the build tests fail.
A local build shows the concrete error in config.log, for example:
configure:27577: checking for HMAC_Update in -lcrypto
configure:27599: /home/bernd/buildroot/output/host/bin/m68k-linux-gcc
-o conftest -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE
-D_FILE_OFFSET_BITS=64 -O2 -g0 -fno-dwarf2-cfi-asm -Wl,-elf2flt=-r
-static -Werror-implicit-function-declaration -Wno-system-headers
-D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64
-D_GNU_SOURCE -Wl,-elf2flt=-r -static
-L/home/bernd/buildroot/output/host/bin/../m68k-buildroot-uclinux-uclibc/sysroot/usr/lib
-L/home/bernd/buildroot/output/host/bin/../m68k-buildroot-uclinux-uclibc/sysroot/usr/lib
conftest.c -lcrypto -lssl -lcrypto -lz -pthread -lz >&5
/home/bernd/buildroot/output/host/opt/ext-toolchain/m68k-buildroot-uclinux-uclibc/bin/ld.real:
/home/bernd/buildroot/output/host/bin/../m68k-buildroot-uclinux-uclibc/sysroot/usr/lib/libcrypto.a(libcrypto-lib-threads_pthread.o):
in function `ossl_rcu_read_lock':
threads_pthread.c:(.text+0xa4): undefined reference to `__atomic_fetch_add_8'
This error occurs many times for various atomic operations:
$ grep "undefined reference to \`__atomic" output/build/libcurl-8.20.0/config.log | sort -u | grep -v real
threads_pthread.c:(.text+0x28a): undefined reference to `__atomic_fetch_sub_8'
threads_pthread.c:(.text+0x3b4): undefined reference to `__atomic_fetch_add_8'
threads_pthread.c:(.text+0x9c8): undefined reference to `__atomic_is_lock_free'
threads_pthread.c:(.text+0xa4): undefined reference to `__atomic_fetch_add_8'
threads_pthread.c:(.text+0xa9c): undefined reference to `__atomic_is_lock_free'
threads_pthread.c:(.text+0xb66): undefined reference to `__atomic_is_lock_free'
threads_pthread.c:(.text+0xc30): undefined reference to `__atomic_is_lock_free'
threads_pthread.c:(.text+0xcdc): undefined reference to `__atomic_is_lock_free'
The build error can be reproduced with the current buildroot tree using
this defconfig:
BR2_m68k=y
BR2_m68k_cf5208=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_M68K_COLDFIRE_UCLIBC_STABLE=y
BR2_PACKAGE_OPENSSL=y
BR2_PACKAGE_LIBCURL=y
Although the toolchain lacks atomics support
$ grep ATOMIC .config
$
it emits atomic-related defines, for example:
$ echo | output/host/bin/m68k-linux-gcc -dM -E - | grep __ATOMIC_ACQ_REL
#define __ATOMIC_ACQ_REL 4
$
This specific define __ATOMIC_ACQ_REL is used in OpenSSL to enable
atomic support at various places:
https://github.com/openssl/openssl/blob/openssl-3.6.3/crypto/threads_pthread.c
causing the build errors we see with the mentioned defconfig.
To fix the problem we use an OpenSSL-provided define to forcefully
disable the usage of atomic intrinsics.
The misdetection of atomic intrinsics for m68k coldfire is not a new
problem:
https://lists.buildroot.org/pipermail/buildroot/2017-May/180841.html
https://lists.buildroot.org/pipermail/buildroot/2026-May/803110.html
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
v2: fixed patch description (Baruch)
package/libopenssl/libopenssl.mk | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/package/libopenssl/libopenssl.mk b/package/libopenssl/libopenssl.mk
index 9ddc85c197..9b3eec4baa 100644
--- a/package/libopenssl/libopenssl.mk
+++ b/package/libopenssl/libopenssl.mk
@@ -23,6 +23,10 @@ ifeq ($(BR2_m68k_cf),y)
LIBOPENSSL_CFLAGS += -mxgot
# resolves an assembler "out of range error" with blake2 and sha512 algorithms
LIBOPENSSL_CFLAGS += -DOPENSSL_SMALL_FOOTPRINT
+# disable atomic operations
+ifeq ($(BR2_TOOLCHAIN_HAS_ATOMIC),)
+LIBOPENSSL_CFLAGS += -DBROKEN_CLANG_ATOMICS
+endif
endif
ifeq ($(BR2_USE_MMU),)
--
2.47.3
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot
^ permalink raw reply related [flat|nested] 4+ messages in thread
* [Buildroot] [PATCH v2 2/2] package/libcurl: security bump to version 8.22.0
2026-09-03 6:39 [Buildroot] [PATCH v2 1/2] package/libopenssl: disable atomic operations for m68k Coldfire Bernd Kuhls
@ 2026-09-03 6:39 ` Bernd Kuhls
2026-09-04 11:51 ` Peter Korsgaard
2026-09-04 11:51 ` [Buildroot] [PATCH v2 1/2] package/libopenssl: disable atomic operations for m68k Coldfire Peter Korsgaard
1 sibling, 1 reply; 4+ messages in thread
From: Bernd Kuhls @ 2026-09-03 6:39 UTC (permalink / raw)
To: buildroot
https://curl.se/ch/8.22.0.html
https://daniel.haxx.se/blog/2026/09/02/curl-8-22-0/
Fixes the following CVEs:
CVE-2026-13608: OpenLDAP SASL authentication bypass
CVE-2026-18924: HTTP/2 server push UAF
CVE-2026-19931: Negotiate ambient user conn reuse
CVE-2026-80229: OpenSSL provider use-after-free
CVE-2026-80230: OpenSSL pinning bypass
CVE-2026-80231: native CA store conn reuse
CVE-2026-80255: secure cookie attribute bypass with tab
CVE-2026-82208: wolfSSL CA-cache hit overrides callback
CVE-2026-82209: domain-scoped PSL domain cookie
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
v2: no changes
Series passed Gitlab pipelines:
https://gitlab.com/bkuhls/buildroot/-/commits/1ee4fc21f8ea0a236ba8681a49400e915f10ff4e
package/libcurl/libcurl.hash | 6 +++---
package/libcurl/libcurl.mk | 2 +-
2 files changed, 4 insertions(+), 4 deletions(-)
diff --git a/package/libcurl/libcurl.hash b/package/libcurl/libcurl.hash
index e2393bf2f4..0a7b9e0169 100644
--- a/package/libcurl/libcurl.hash
+++ b/package/libcurl/libcurl.hash
@@ -1,7 +1,7 @@
-# From https://github.com/curl/curl/releases/tag/curl-8_21_0
+# From https://github.com/curl/curl/releases/tag/curl-8_22_0
# after checking pgp signature:
-# https://curl.se/download/curl-8.21.0.tar.xz.asc
+# https://curl.se/download/curl-8.22.0.tar.xz.asc
# signed with key 27EDEAF22F3ABCEB50DB9A125CC908FDB71E12C2
-sha256 aa1b66a70eace83dc624508745646c08ae561de512ab403adffb93ac87fc72e6 curl-8.21.0.tar.xz
+sha256 f7ef3ae8a22e521f289803fe93543eb64c329b58aa73a9e224dfd915a2a5f4f7 curl-8.22.0.tar.xz
# Locally computed
sha256 82f2f4427d6545ee5aaac4f0b80428da6cc8ba41c2cf5da3a03680ec327b9681 COPYING
diff --git a/package/libcurl/libcurl.mk b/package/libcurl/libcurl.mk
index 219ce9f712..c3590a8a9e 100644
--- a/package/libcurl/libcurl.mk
+++ b/package/libcurl/libcurl.mk
@@ -4,7 +4,7 @@
#
################################################################################
-LIBCURL_VERSION = 8.21.0
+LIBCURL_VERSION = 8.22.0
LIBCURL_SOURCE = curl-$(LIBCURL_VERSION).tar.xz
LIBCURL_SITE = https://curl.se/download
LIBCURL_DEPENDENCIES = host-pkgconf \
--
2.47.3
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [Buildroot] [PATCH v2 1/2] package/libopenssl: disable atomic operations for m68k Coldfire
2026-09-03 6:39 [Buildroot] [PATCH v2 1/2] package/libopenssl: disable atomic operations for m68k Coldfire Bernd Kuhls
2026-09-03 6:39 ` [Buildroot] [PATCH v2 2/2] package/libcurl: security bump to version 8.22.0 Bernd Kuhls
@ 2026-09-04 11:51 ` Peter Korsgaard
1 sibling, 0 replies; 4+ messages in thread
From: Peter Korsgaard @ 2026-09-04 11:51 UTC (permalink / raw)
To: Bernd Kuhls; +Cc: buildroot
>>>>> "Bernd" == Bernd Kuhls <bernd@kuhls.net> writes:
> This patch fixes a build error with OpenSSL-enabled libcurl which was
> detected by the Gitlab pipelines:
> checking for openssl options with pkg-config... found
> configure: pkg-config: SSL_LIBS: "-lssl -lcrypto -pthread"
> configure: pkg-config: SSL_LDFLAGS: "-L/builds/bkuhls/buildroot/br-test-pkg/bootlin-m68k-5208-uclibc/host/bin/../m68k-buildroot-uclinux-uclibc/sysroot/usr/lib"
> configure: pkg-config: SSL_CPPFLAGS: ""
> checking for HMAC_Update in -lcrypto... no
> checking for HMAC_Init_ex in -lcrypto... no
> checking OpenSSL linking with -ldl... no
> checking OpenSSL linking with -ldl and -lpthread... no
> checking for SSL_set_quic_use_legacy_codepoint... no
> checking for SSL_set_quic_tls_cbs... no
> configure: OpenSSL version does not speak any known QUIC API
> configure: OPT_OPENSSL: /builds/bkuhls/buildroot/br-test-pkg/bootlin-m68k-5208-uclibc/host/m68k-buildroot-uclinux-uclibc/sysroot/usr
> configure: OPENSSL_ENABLED:
> configure: error: --with-openssl was given but OpenSSL could not be detected
> make[1]: *** [package/pkg-generic.mk:263: /builds/bkuhls/buildroot/br-test-pkg/bootlin-m68k-5208-uclibc/build/libcurl-8.21.0/.stamp_configured] Error 1
> Although OpenSSL was found using pkg-config the build tests fail.
> A local build shows the concrete error in config.log, for example:
> configure:27577: checking for HMAC_Update in -lcrypto
> configure:27599: /home/bernd/buildroot/output/host/bin/m68k-linux-gcc
> -o conftest -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE
> -D_FILE_OFFSET_BITS=64 -O2 -g0 -fno-dwarf2-cfi-asm -Wl,-elf2flt=-r
> -static -Werror-implicit-function-declaration -Wno-system-headers
> -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64
> -D_GNU_SOURCE -Wl,-elf2flt=-r -static
> -L/home/bernd/buildroot/output/host/bin/../m68k-buildroot-uclinux-uclibc/sysroot/usr/lib
> -L/home/bernd/buildroot/output/host/bin/../m68k-buildroot-uclinux-uclibc/sysroot/usr/lib
> conftest.c -lcrypto -lssl -lcrypto -lz -pthread -lz >&5
> /home/bernd/buildroot/output/host/opt/ext-toolchain/m68k-buildroot-uclinux-uclibc/bin/ld.real:
> /home/bernd/buildroot/output/host/bin/../m68k-buildroot-uclinux-uclibc/sysroot/usr/lib/libcrypto.a(libcrypto-lib-threads_pthread.o):
> in function `ossl_rcu_read_lock':
> threads_pthread.c:(.text+0xa4): undefined reference to `__atomic_fetch_add_8'
> This error occurs many times for various atomic operations:
> $ grep "undefined reference to \`__atomic" output/build/libcurl-8.20.0/config.log | sort -u | grep -v real
> threads_pthread.c:(.text+0x28a): undefined reference to `__atomic_fetch_sub_8'
> threads_pthread.c:(.text+0x3b4): undefined reference to `__atomic_fetch_add_8'
> threads_pthread.c:(.text+0x9c8): undefined reference to `__atomic_is_lock_free'
> threads_pthread.c:(.text+0xa4): undefined reference to `__atomic_fetch_add_8'
> threads_pthread.c:(.text+0xa9c): undefined reference to `__atomic_is_lock_free'
> threads_pthread.c:(.text+0xb66): undefined reference to `__atomic_is_lock_free'
> threads_pthread.c:(.text+0xc30): undefined reference to `__atomic_is_lock_free'
> threads_pthread.c:(.text+0xcdc): undefined reference to `__atomic_is_lock_free'
> The build error can be reproduced with the current buildroot tree using
> this defconfig:
> BR2_m68k=y
> BR2_m68k_cf5208=y
> BR2_TOOLCHAIN_EXTERNAL=y
> BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_M68K_COLDFIRE_UCLIBC_STABLE=y
> BR2_PACKAGE_OPENSSL=y
> BR2_PACKAGE_LIBCURL=y
> Although the toolchain lacks atomics support
> $ grep ATOMIC .config
> $
> it emits atomic-related defines, for example:
> $ echo | output/host/bin/m68k-linux-gcc -dM -E - | grep __ATOMIC_ACQ_REL
> #define __ATOMIC_ACQ_REL 4
> $
> This specific define __ATOMIC_ACQ_REL is used in OpenSSL to enable
> atomic support at various places:
> https://github.com/openssl/openssl/blob/openssl-3.6.3/crypto/threads_pthread.c
> causing the build errors we see with the mentioned defconfig.
> To fix the problem we use an OpenSSL-provided define to forcefully
> disable the usage of atomic intrinsics.
> The misdetection of atomic intrinsics for m68k coldfire is not a new
> problem:
> https://lists.buildroot.org/pipermail/buildroot/2017-May/180841.html
> https://lists.buildroot.org/pipermail/buildroot/2026-May/803110.html
> Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
> ---
> v2: fixed patch description (Baruch)
Committed, thanks.
--
Bye, Peter Korsgaard
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [Buildroot] [PATCH v2 2/2] package/libcurl: security bump to version 8.22.0
2026-09-03 6:39 ` [Buildroot] [PATCH v2 2/2] package/libcurl: security bump to version 8.22.0 Bernd Kuhls
@ 2026-09-04 11:51 ` Peter Korsgaard
0 siblings, 0 replies; 4+ messages in thread
From: Peter Korsgaard @ 2026-09-04 11:51 UTC (permalink / raw)
To: Bernd Kuhls; +Cc: buildroot
>>>>> "Bernd" == Bernd Kuhls <bernd@kuhls.net> writes:
> https://curl.se/ch/8.22.0.html
> https://daniel.haxx.se/blog/2026/09/02/curl-8-22-0/
> Fixes the following CVEs:
> CVE-2026-13608: OpenLDAP SASL authentication bypass
> CVE-2026-18924: HTTP/2 server push UAF
> CVE-2026-19931: Negotiate ambient user conn reuse
> CVE-2026-80229: OpenSSL provider use-after-free
> CVE-2026-80230: OpenSSL pinning bypass
> CVE-2026-80231: native CA store conn reuse
> CVE-2026-80255: secure cookie attribute bypass with tab
> CVE-2026-82208: wolfSSL CA-cache hit overrides callback
> CVE-2026-82209: domain-scoped PSL domain cookie
> Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
> ---
> v2: no changes
> Series passed Gitlab pipelines:
> https://gitlab.com/bkuhls/buildroot/-/commits/1ee4fc21f8ea0a236ba8681a49400e915f10ff4e
Committed, thanks.
--
Bye, Peter Korsgaard
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-09-04 11:51 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-03 6:39 [Buildroot] [PATCH v2 1/2] package/libopenssl: disable atomic operations for m68k Coldfire Bernd Kuhls
2026-09-03 6:39 ` [Buildroot] [PATCH v2 2/2] package/libcurl: security bump to version 8.22.0 Bernd Kuhls
2026-09-04 11:51 ` Peter Korsgaard
2026-09-04 11:51 ` [Buildroot] [PATCH v2 1/2] package/libopenssl: disable atomic operations for m68k Coldfire Peter Korsgaard
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.