Openembedded Core Discussions
 help / color / mirror / Atom feed
From: Alexander Kanavin <alex.kanavin@gmail.com>
To: openembedded-core@lists.openembedded.org
Subject: [PATCH 05/24] nss: update to 3.49.1
Date: Mon, 20 Jan 2020 18:24:51 +0100	[thread overview]
Message-ID: <20200120172510.22648-5-alex.kanavin@gmail.com> (raw)
In-Reply-To: <20200120172510.22648-1-alex.kanavin@gmail.com>

Drop a backport, and a patch that causes build errors with
the new version.

Add a patch to make ARM HW crypto optional; upstream for some
reason does not allow disabling it.

Signed-off-by: Alexander Kanavin <alex.kanavin@gmail.com>
---
 ...ppc64-inline-assembler-for-clang-r-j.patch | 35 -------------------
 ...figure-option-to-disable-ARM-HW-cryp.patch | 35 +++++++++++++++++++
 .../nss/nss/nss-fix-nsinstall-build.patch     |  2 +-
 .../nss/{nss_3.45.bb => nss_3.49.1.bb}        | 13 ++++---
 4 files changed, 44 insertions(+), 41 deletions(-)
 delete mode 100644 meta/recipes-support/nss/nss/0001-Bug-1493916-Fix-ppc64-inline-assembler-for-clang-r-j.patch
 create mode 100644 meta/recipes-support/nss/nss/0001-freebl-add-a-configure-option-to-disable-ARM-HW-cryp.patch
 rename meta/recipes-support/nss/{nss_3.45.bb => nss_3.49.1.bb} (95%)

diff --git a/meta/recipes-support/nss/nss/0001-Bug-1493916-Fix-ppc64-inline-assembler-for-clang-r-j.patch b/meta/recipes-support/nss/nss/0001-Bug-1493916-Fix-ppc64-inline-assembler-for-clang-r-j.patch
deleted file mode 100644
index 59e44e68418..00000000000
--- a/meta/recipes-support/nss/nss/0001-Bug-1493916-Fix-ppc64-inline-assembler-for-clang-r-j.patch
+++ /dev/null
@@ -1,35 +0,0 @@
-From 6b351dbb049b3b3ab6c0d51aa3c1c7fb3c9df80c Mon Sep 17 00:00:00 2001
-From: =?UTF-8?q?Dan=20Hor=C3=A1k?= <dan@danny.cz>
-Date: Mon, 22 Jul 2019 11:07:41 -0700
-Subject: [PATCH] Bug 1493916 - Fix ppc64 inline assembler for clang r=jcj
- Seems clang's inline assembler doesn't want registers to be prefixed with
- "r", while gcc accepts both - r0 and 0 for GPR0.
-
-tested with clang 6.0 and gcc 8.1
-
---HG--
-extra : amend_source : 87e09bb59c78bdb25b9573b9f29511e10b9db6fa
-extra : histedit_source : 9b3fad70ac2851bf7de14d42c34db4a5fba41710
-
-Upstream-Status: Backport [https://github.com/nss-dev/nss/commit/671d89b6c4a6f41707bb044534751098e2e3f211]
-Signed-off-by: Khem Raj <raj.khem@gmail.com>
----
- nss/lib/freebl/mpi/mpcpucache.c | 2 +-
- 1 file changed, 1 insertion(+), 1 deletion(-)
-
-diff --git a/nss/lib/freebl/mpi/mpcpucache.c b/nss/lib/freebl/mpi/mpcpucache.c
-index 336b4cc..2ad291f 100644
---- a/nss/lib/freebl/mpi/mpcpucache.c
-+++ b/nss/lib/freebl/mpi/mpcpucache.c
-@@ -727,7 +727,7 @@ static inline void
- dcbzl(char *array)
- {
-     register char *a asm("r2") = array;
--    __asm__ __volatile__("dcbzl %0,r0"
-+    __asm__ __volatile__("dcbzl %0,0"
-                          : "=r"(a)
-                          : "0"(a));
- }
--- 
-2.24.0
-
diff --git a/meta/recipes-support/nss/nss/0001-freebl-add-a-configure-option-to-disable-ARM-HW-cryp.patch b/meta/recipes-support/nss/nss/0001-freebl-add-a-configure-option-to-disable-ARM-HW-cryp.patch
new file mode 100644
index 00000000000..fe29d198820
--- /dev/null
+++ b/meta/recipes-support/nss/nss/0001-freebl-add-a-configure-option-to-disable-ARM-HW-cryp.patch
@@ -0,0 +1,35 @@
+From 5595e9651aca39af945931c73eb524a0f8bd130d Mon Sep 17 00:00:00 2001
+From: Alexander Kanavin <alex.kanavin@gmail.com>
+Date: Wed, 18 Dec 2019 12:29:50 +0100
+Subject: [PATCH] freebl: add a configure option to disable ARM HW crypto
+
+Not all current hardware supports it, particularly anything
+prior to armv8 does not.
+
+Upstream-Status: Pending
+Signed-off-by: Alexander Kanavin <alex.kanavin@gmail.com>
+---
+ nss/lib/freebl/Makefile | 3 +++
+ 1 file changed, 3 insertions(+)
+
+diff --git a/nss/lib/freebl/Makefile b/nss/lib/freebl/Makefile
+index 06506f0..a8b015d 100644
+--- a/nss/lib/freebl/Makefile
++++ b/nss/lib/freebl/Makefile
+@@ -125,6 +125,8 @@ else
+         DEFINES += -DNSS_X86
+ endif
+ endif
++
++ifdef NSS_USE_ARM_HW_CRYPTO
+ ifeq ($(CPU_ARCH),aarch64)
+     DEFINES += -DUSE_HW_AES
+     EXTRA_SRCS += aes-armv8.c gcm-aarch64.c
+@@ -145,6 +147,7 @@ ifeq ($(CPU_ARCH),arm)
+         endif
+     endif
+ endif
++endif
+ 
+ ifeq ($(OS_TARGET),OSF1)
+     DEFINES += -DMP_ASSEMBLY_MULTIPLY -DMP_NO_MP_WORD
diff --git a/meta/recipes-support/nss/nss/nss-fix-nsinstall-build.patch b/meta/recipes-support/nss/nss/nss-fix-nsinstall-build.patch
index 181c69adb04..43c09d13eaf 100644
--- a/meta/recipes-support/nss/nss/nss-fix-nsinstall-build.patch
+++ b/meta/recipes-support/nss/nss/nss-fix-nsinstall-build.patch
@@ -29,7 +29,7 @@ Index: nss-3.24/nss/coreconf/nsinstall/Makefile
 +# to clean the '-m64' from ARCHFLAG and LDFLAGS.
 +ARCHFLAG =
 +LDFLAGS =
-+CFLAGS =
++# CFLAGS =
 +
  ifeq (,$(filter-out OS2 WIN%,$(OS_TARGET)))
  PROGRAM		=
diff --git a/meta/recipes-support/nss/nss_3.45.bb b/meta/recipes-support/nss/nss_3.49.1.bb
similarity index 95%
rename from meta/recipes-support/nss/nss_3.45.bb
rename to meta/recipes-support/nss/nss_3.49.1.bb
index c8005a5b3a5..94f4b88fa53 100644
--- a/meta/recipes-support/nss/nss_3.45.bb
+++ b/meta/recipes-support/nss/nss_3.49.1.bb
@@ -25,17 +25,17 @@ SRC_URI = "http://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/${VERSIO
            file://0001-nss-fix-support-cross-compiling.patch \
            file://nss-no-rpath-for-cross-compiling.patch \
            file://nss-fix-incorrect-shebang-of-perl.patch \
-           file://nss-fix-nsinstall-build.patch \
            file://disable-Wvarargs-with-clang.patch \
            file://pqg.c-ULL_addend.patch \
-           file://0001-Bug-1493916-Fix-ppc64-inline-assembler-for-clang-r-j.patch \
            file://blank-cert9.db \
            file://blank-key4.db \
            file://system-pkcs11.txt \
+           file://nss-fix-nsinstall-build.patch \
+           file://0001-freebl-add-a-configure-option-to-disable-ARM-HW-cryp.patch \
            "
 
-SRC_URI[md5sum] = "f1752d7223ee9d910d551e57264bafa8"
-SRC_URI[sha256sum] = "112f05223d1fde902c170966bfc6f011b24a838be16969b110ecf2bb7bc24e8b"
+SRC_URI[md5sum] = "6b92ac02dcf9e9e44df5390f6814c157"
+SRC_URI[sha256sum] = "d9aa42e49e02bb0dc0a2f164604cfc718e11a2a06ddb266cd676376ac21b026e"
 
 UPSTREAM_CHECK_URI = "https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_Releases"
 UPSTREAM_CHECK_REGEX = "NSS_(?P<pver>.+)_release_notes"
@@ -69,7 +69,8 @@ do_compile_prepend_class-native() {
 do_compile() {
     export CROSS_COMPILE=1
     export NATIVE_CC="${BUILD_CC}"
-    export NATIVE_FLAGS="${BUILD_CFLAGS}"
+    # Additional defines needed on Centos 7
+    export NATIVE_FLAGS="${BUILD_CFLAGS} -DLINUX -Dlinux"
     export BUILD_OPT=1
 
     export FREEBL_NO_DEPEND=1
@@ -81,6 +82,8 @@ do_compile() {
     export NSS_USE_SYSTEM_SQLITE=1
     export NSS_ENABLE_ECC=1
 
+    ${@bb.utils.contains("TUNE_FEATURES", "crypto", "export NSS_USE_ARM_HW_CRYPTO=1", "", d)}
+
     export OS_RELEASE=3.4
     export OS_TARGET=Linux
     export OS_ARCH=Linux
-- 
2.17.1



  parent reply	other threads:[~2020-01-20 17:25 UTC|newest]

Thread overview: 40+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-01-20 17:24 [PATCH 01/24] python3: update to 3.8.1 Alexander Kanavin
2020-01-20 17:24 ` [PATCH 02/24] python3: do not compile .pyc in parallel during do_install() Alexander Kanavin
2020-01-20 17:24 ` [PATCH 03/24] python3: correctly process ptest output with sed Alexander Kanavin
2020-01-20 17:24 ` [PATCH 04/24] gstreamer1.0-python: add a patch to fix python 3.8 builds Alexander Kanavin
2020-01-20 17:24 ` Alexander Kanavin [this message]
2020-01-21 12:04   ` [PATCH 05/24] nss: update to 3.49.1 Andreas Müller
2020-01-21 12:47     ` Richard Purdie
2020-01-21 19:35       ` Khem Raj
2020-01-21 20:22         ` Richard Purdie
2020-01-21 22:02           ` Khem Raj
2020-01-22  8:13             ` Khem Raj
2020-01-20 17:24 ` [PATCH 06/24] libcap: update to 2.31 Alexander Kanavin
2020-01-20 17:24 ` [PATCH 07/24] selftest: check maintainers.inc for entries without recipes Alexander Kanavin
2020-01-20 17:24 ` [PATCH 08/24] core-image-sato-sdk-ptest: do not pull in ptest-pkgs Alexander Kanavin
2020-01-20 17:24 ` [PATCH 09/24] ptests: exclude mdadm from ptesting Alexander Kanavin
2020-01-20 17:24 ` [PATCH 10/24] ptests: exclude lttng-tools Alexander Kanavin
2020-01-20 17:37   ` Jonathan Rajotte-Julien
2020-01-20 17:44     ` Alexander Kanavin
2020-01-24 12:47     ` Alexander Kanavin
2020-01-24 15:35       ` Jonathan Rajotte-Julien
2020-01-20 22:46   ` Richard Purdie
2020-01-20 17:24 ` [PATCH 11/24] openssh: applied upstream fix for "cert not yet valid" test Alexander Kanavin
2020-01-20 17:24 ` [PATCH 12/24] openssh: explicitly skip unit tests Alexander Kanavin
2020-01-20 17:24 ` [PATCH 13/24] parted: fix more ptests Alexander Kanavin
2020-01-20 17:25 ` [PATCH 14/24] qemu.inc: add vfat to MACHINE_FEATURES Alexander Kanavin
2020-01-20 17:25 ` [PATCH 15/24] rt-tests: exclude another development version (1.6) Alexander Kanavin
2020-01-20 17:25 ` [PATCH 16/24] btrfs-tools: upgrade 5.4 -> 5.4.1 Alexander Kanavin
2020-01-20 17:25 ` [PATCH 17/24] libpipeline: upgrade 1.5.1 -> 1.5.2 Alexander Kanavin
2020-01-20 17:25 ` [PATCH 18/24] msmtp: upgrade 1.8.6 -> 1.8.7 Alexander Kanavin
2020-01-20 17:25 ` [PATCH 19/24] ffmpeg: upgrade 4.2.1 -> 4.2.2 Alexander Kanavin
2020-01-20 17:25 ` [PATCH 20/24] epiphany: upgrade 3.34.2 -> 3.34.3.1 Alexander Kanavin
2020-01-20 17:25 ` [PATCH 21/24] libwebp: upgrade 1.0.3 -> 1.1.0 Alexander Kanavin
2020-01-20 17:25 ` [PATCH 22/24] createrepo-c: upgrade 0.15.4 -> 0.15.5 Alexander Kanavin
2020-01-20 17:25 ` [PATCH 23/24] libsecret: upgrade 0.19.1 -> 0.20.0 Alexander Kanavin
2020-01-20 17:25 ` [PATCH 24/24] meson: update 0.52.1 -> 0.53.0 Alexander Kanavin
2020-01-21  8:24   ` Richard Purdie
2020-01-21 18:44   ` Khem Raj
2020-01-23 15:48     ` Alexander Kanavin
2020-01-23 15:52       ` Khem Raj
2020-01-20 17:32 ` ✗ patchtest: failure for "python3: update to 3.8.1..." and 23 more Patchwork

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20200120172510.22648-5-alex.kanavin@gmail.com \
    --to=alex.kanavin@gmail.com \
    --cc=openembedded-core@lists.openembedded.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox