Backport a set of kernel patches to 6.6 to fix the OpenSSL build
failures.

Signed-off-by: Ryan Eatmon <[email protected]>
---
v2; Added missing Upstream-Status.

 ...mon-SSL-helper-functions-to-a-header.patch | 205 ++++++++++++++++++
 ...-using-deprecated-ERR_get_error_line.patch | 121 +++++++++++
 ...-pkcs11-provider-for-OPENSSL-MAJOR-3.patch | 163 ++++++++++++++
 .../linux/linux-ti-staging_6.6.bb             |   6 +
 4 files changed, 495 insertions(+)
 create mode 100644 
meta-ti-bsp/recipes-kernel/linux/files/0001-move-common-SSL-helper-functions-to-a-header.patch
 create mode 100644 
meta-ti-bsp/recipes-kernel/linux/files/0002-avoid-using-deprecated-ERR_get_error_line.patch
 create mode 100644 
meta-ti-bsp/recipes-kernel/linux/files/0003-use-pkcs11-provider-for-OPENSSL-MAJOR-3.patch

diff --git 
a/meta-ti-bsp/recipes-kernel/linux/files/0001-move-common-SSL-helper-functions-to-a-header.patch
 
b/meta-ti-bsp/recipes-kernel/linux/files/0001-move-common-SSL-helper-functions-to-a-header.patch
new file mode 100644
index 00000000..6a58b5eb
--- /dev/null
+++ 
b/meta-ti-bsp/recipes-kernel/linux/files/0001-move-common-SSL-helper-functions-to-a-header.patch
@@ -0,0 +1,205 @@
+From 300e6d4116f956b035281ec94297dc4dc8d4e1d3 Mon Sep 17 00:00:00 2001
+From: Jan Stancek <[email protected]>
+Date: Fri, 12 Jul 2024 09:11:14 +0200
+Subject: sign-file,extract-cert: move common SSL helper functions to a header
+
+Couple error handling helpers are repeated in both tools, so
+move them to a common header.
+
+Signed-off-by: Jan Stancek <[email protected]>
+Reviewed-by: Jarkko Sakkinen <[email protected]>
+Tested-by: R Nageswara Sastry <[email protected]>
+Reviewed-by: Neal Gompa <[email protected]>
+Signed-off-by: Jarkko Sakkinen <[email protected]>
+
+Upstream-Status: Inappropriate [OE specific]
+---
+ MAINTAINERS          |  1 +
+ certs/Makefile       |  2 +-
+ certs/extract-cert.c | 37 ++-----------------------------------
+ scripts/sign-file.c  | 37 ++-----------------------------------
+ scripts/ssl-common.h | 39 +++++++++++++++++++++++++++++++++++++++
+ 5 files changed, 45 insertions(+), 71 deletions(-)
+ create mode 100644 scripts/ssl-common.h
+
+diff --git a/MAINTAINERS b/MAINTAINERS
+index 9278c30ef1d5a..23f9028848552 100644
+--- a/MAINTAINERS
++++ b/MAINTAINERS
+@@ -5204,6 +5204,7 @@ S:       Maintained
+ F:    Documentation/admin-guide/module-signing.rst
+ F:    certs/
+ F:    scripts/sign-file.c
++F:    scripts/ssl-common.h
+ F:    tools/certs/
+ 
+ CFAG12864B LCD DRIVER
+diff --git a/certs/Makefile b/certs/Makefile
+index 1094e3860c2a7..f6fa4d8d75e05 100644
+--- a/certs/Makefile
++++ b/certs/Makefile
+@@ -84,5 +84,5 @@ targets += x509_revocation_list
+ 
+ hostprogs := extract-cert
+ 
+-HOSTCFLAGS_extract-cert.o = $(shell $(HOSTPKG_CONFIG) --cflags libcrypto 2> 
/dev/null)
++HOSTCFLAGS_extract-cert.o = $(shell $(HOSTPKG_CONFIG) --cflags libcrypto 2> 
/dev/null) -I$(srctree)/scripts
+ HOSTLDLIBS_extract-cert = $(shell $(HOSTPKG_CONFIG) --libs libcrypto 2> 
/dev/null || echo -lcrypto)
+diff --git a/certs/extract-cert.c b/certs/extract-cert.c
+index 70e9ec89d87d3..8e7ba9974a1fa 100644
+--- a/certs/extract-cert.c
++++ b/certs/extract-cert.c
+@@ -23,6 +23,8 @@
+ #include <openssl/err.h>
+ #include <openssl/engine.h>
+ 
++#include "ssl-common.h"
++
+ /*
+  * OpenSSL 3.0 deprecates the OpenSSL's ENGINE API.
+  *
+@@ -40,41 +42,6 @@ void format(void)
+       exit(2);
+ }
+ 
+-static void display_openssl_errors(int l)
+-{
+-      const char *file;
+-      char buf[120];
+-      int e, line;
+-
+-      if (ERR_peek_error() == 0)
+-              return;
+-      fprintf(stderr, "At main.c:%d:\n", l);
+-
+-      while ((e = ERR_get_error_line(&file, &line))) {
+-              ERR_error_string(e, buf);
+-              fprintf(stderr, "- SSL %s: %s:%d\n", buf, file, line);
+-      }
+-}
+-
+-static void drain_openssl_errors(void)
+-{
+-      const char *file;
+-      int line;
+-
+-      if (ERR_peek_error() == 0)
+-              return;
+-      while (ERR_get_error_line(&file, &line)) {}
+-}
+-
+-#define ERR(cond, fmt, ...)                           \
+-      do {                                            \
+-              bool __cond = (cond);                   \
+-              display_openssl_errors(__LINE__);       \
+-              if (__cond) {                           \
+-                      err(1, fmt, ## __VA_ARGS__);    \
+-              }                                       \
+-      } while(0)
+-
+ static const char *key_pass;
+ static BIO *wb;
+ static char *cert_dst;
+diff --git a/scripts/sign-file.c b/scripts/sign-file.c
+index 3edb156ae52c3..39ba58db5d4ea 100644
+--- a/scripts/sign-file.c
++++ b/scripts/sign-file.c
+@@ -29,6 +29,8 @@
+ #include <openssl/err.h>
+ #include <openssl/engine.h>
+ 
++#include "ssl-common.h"
++
+ /*
+  * OpenSSL 3.0 deprecates the OpenSSL's ENGINE API.
+  *
+@@ -83,41 +85,6 @@ void format(void)
+       exit(2);
+ }
+ 
+-static void display_openssl_errors(int l)
+-{
+-      const char *file;
+-      char buf[120];
+-      int e, line;
+-
+-      if (ERR_peek_error() == 0)
+-              return;
+-      fprintf(stderr, "At main.c:%d:\n", l);
+-
+-      while ((e = ERR_get_error_line(&file, &line))) {
+-              ERR_error_string(e, buf);
+-              fprintf(stderr, "- SSL %s: %s:%d\n", buf, file, line);
+-      }
+-}
+-
+-static void drain_openssl_errors(void)
+-{
+-      const char *file;
+-      int line;
+-
+-      if (ERR_peek_error() == 0)
+-              return;
+-      while (ERR_get_error_line(&file, &line)) {}
+-}
+-
+-#define ERR(cond, fmt, ...)                           \
+-      do {                                            \
+-              bool __cond = (cond);                   \
+-              display_openssl_errors(__LINE__);       \
+-              if (__cond) {                           \
+-                      errx(1, fmt, ## __VA_ARGS__);   \
+-              }                                       \
+-      } while(0)
+-
+ static const char *key_pass;
+ 
+ static int pem_pw_cb(char *buf, int len, int w, void *v)
+diff --git a/scripts/ssl-common.h b/scripts/ssl-common.h
+new file mode 100644
+index 0000000000000..e6711c75ed913
+--- /dev/null
++++ b/scripts/ssl-common.h
+@@ -0,0 +1,39 @@
++/* SPDX-License-Identifier: LGPL-2.1+ */
++/*
++ * SSL helper functions shared by sign-file and extract-cert.
++ */
++
++static void display_openssl_errors(int l)
++{
++      const char *file;
++      char buf[120];
++      int e, line;
++
++      if (ERR_peek_error() == 0)
++              return;
++      fprintf(stderr, "At main.c:%d:\n", l);
++
++      while ((e = ERR_get_error_line(&file, &line))) {
++              ERR_error_string(e, buf);
++              fprintf(stderr, "- SSL %s: %s:%d\n", buf, file, line);
++      }
++}
++
++static void drain_openssl_errors(void)
++{
++      const char *file;
++      int line;
++
++      if (ERR_peek_error() == 0)
++              return;
++      while (ERR_get_error_line(&file, &line)) {}
++}
++
++#define ERR(cond, fmt, ...)                           \
++      do {                                            \
++              bool __cond = (cond);                   \
++              display_openssl_errors(__LINE__);       \
++              if (__cond) {                           \
++                      errx(1, fmt, ## __VA_ARGS__);   \
++              }                                       \
++      } while (0)
+-- 
+cgit 1.3.1-korg
+
diff --git 
a/meta-ti-bsp/recipes-kernel/linux/files/0002-avoid-using-deprecated-ERR_get_error_line.patch
 
b/meta-ti-bsp/recipes-kernel/linux/files/0002-avoid-using-deprecated-ERR_get_error_line.patch
new file mode 100644
index 00000000..993f6739
--- /dev/null
+++ 
b/meta-ti-bsp/recipes-kernel/linux/files/0002-avoid-using-deprecated-ERR_get_error_line.patch
@@ -0,0 +1,121 @@
+From 467d60eddf55588add232feda325da7215ddaf30 Mon Sep 17 00:00:00 2001
+From: Jan Stancek <[email protected]>
+Date: Fri, 12 Jul 2024 09:11:15 +0200
+Subject: sign-file,extract-cert: avoid using deprecated ERR_get_error_line()
+
+ERR_get_error_line() is deprecated since OpenSSL 3.0.
+
+Use ERR_peek_error_line() instead, and combine display_openssl_errors()
+and drain_openssl_errors() to a single function where parameter decides
+if it should consume errors silently.
+
+Signed-off-by: Jan Stancek <[email protected]>
+Reviewed-by: Jarkko Sakkinen <[email protected]>
+Tested-by: R Nageswara Sastry <[email protected]>
+Reviewed-by: Neal Gompa <[email protected]>
+Signed-off-by: Jarkko Sakkinen <[email protected]>
+
+Upstream-Status: Inappropriate [OE-specifc]
+---
+ certs/extract-cert.c |  4 ++--
+ scripts/sign-file.c  |  6 +++---
+ scripts/ssl-common.h | 23 ++++++++---------------
+ 3 files changed, 13 insertions(+), 20 deletions(-)
+
+diff --git a/certs/extract-cert.c b/certs/extract-cert.c
+index 8e7ba9974a1fa..61bbe00856717 100644
+--- a/certs/extract-cert.c
++++ b/certs/extract-cert.c
+@@ -99,11 +99,11 @@ int main(int argc, char **argv)
+               parms.cert = NULL;
+ 
+               ENGINE_load_builtin_engines();
+-              drain_openssl_errors();
++              drain_openssl_errors(__LINE__, 1);
+               e = ENGINE_by_id("pkcs11");
+               ERR(!e, "Load PKCS#11 ENGINE");
+               if (ENGINE_init(e))
+-                      drain_openssl_errors();
++                      drain_openssl_errors(__LINE__, 1);
+               else
+                       ERR(1, "ENGINE_init");
+               if (key_pass)
+diff --git a/scripts/sign-file.c b/scripts/sign-file.c
+index 39ba58db5d4ea..bb3fdf1a617c2 100644
+--- a/scripts/sign-file.c
++++ b/scripts/sign-file.c
+@@ -114,11 +114,11 @@ static EVP_PKEY *read_private_key(const char 
*private_key_name)
+               ENGINE *e;
+ 
+               ENGINE_load_builtin_engines();
+-              drain_openssl_errors();
++              drain_openssl_errors(__LINE__, 1);
+               e = ENGINE_by_id("pkcs11");
+               ERR(!e, "Load PKCS#11 ENGINE");
+               if (ENGINE_init(e))
+-                      drain_openssl_errors();
++                      drain_openssl_errors(__LINE__, 1);
+               else
+                       ERR(1, "ENGINE_init");
+               if (key_pass)
+@@ -273,7 +273,7 @@ int main(int argc, char **argv)
+ 
+               /* Digest the module data. */
+               OpenSSL_add_all_digests();
+-              display_openssl_errors(__LINE__);
++              drain_openssl_errors(__LINE__, 0);
+               digest_algo = EVP_get_digestbyname(hash_algo);
+               ERR(!digest_algo, "EVP_get_digestbyname");
+ 
+diff --git a/scripts/ssl-common.h b/scripts/ssl-common.h
+index e6711c75ed913..2db0e181143cf 100644
+--- a/scripts/ssl-common.h
++++ b/scripts/ssl-common.h
+@@ -3,7 +3,7 @@
+  * SSL helper functions shared by sign-file and extract-cert.
+  */
+ 
+-static void display_openssl_errors(int l)
++static void drain_openssl_errors(int l, int silent)
+ {
+       const char *file;
+       char buf[120];
+@@ -11,28 +11,21 @@ static void display_openssl_errors(int l)
+ 
+       if (ERR_peek_error() == 0)
+               return;
+-      fprintf(stderr, "At main.c:%d:\n", l);
++      if (!silent)
++              fprintf(stderr, "At main.c:%d:\n", l);
+ 
+-      while ((e = ERR_get_error_line(&file, &line))) {
++      while ((e = ERR_peek_error_line(&file, &line))) {
+               ERR_error_string(e, buf);
+-              fprintf(stderr, "- SSL %s: %s:%d\n", buf, file, line);
++              if (!silent)
++                      fprintf(stderr, "- SSL %s: %s:%d\n", buf, file, line);
++              ERR_get_error();
+       }
+ }
+ 
+-static void drain_openssl_errors(void)
+-{
+-      const char *file;
+-      int line;
+-
+-      if (ERR_peek_error() == 0)
+-              return;
+-      while (ERR_get_error_line(&file, &line)) {}
+-}
+-
+ #define ERR(cond, fmt, ...)                           \
+       do {                                            \
+               bool __cond = (cond);                   \
+-              display_openssl_errors(__LINE__);       \
++              drain_openssl_errors(__LINE__, 0);      \
+               if (__cond) {                           \
+                       errx(1, fmt, ## __VA_ARGS__);   \
+               }                                       \
+-- 
+cgit 1.3.1-korg
+
diff --git 
a/meta-ti-bsp/recipes-kernel/linux/files/0003-use-pkcs11-provider-for-OPENSSL-MAJOR-3.patch
 
b/meta-ti-bsp/recipes-kernel/linux/files/0003-use-pkcs11-provider-for-OPENSSL-MAJOR-3.patch
new file mode 100644
index 00000000..8f509895
--- /dev/null
+++ 
b/meta-ti-bsp/recipes-kernel/linux/files/0003-use-pkcs11-provider-for-OPENSSL-MAJOR-3.patch
@@ -0,0 +1,163 @@
+From 558bdc45dfb2669e1741384a0c80be9c82fa052c Mon Sep 17 00:00:00 2001
+From: Jan Stancek <[email protected]>
+Date: Fri, 20 Sep 2024 19:52:48 +0300
+Subject: sign-file,extract-cert: use pkcs11 provider for OPENSSL MAJOR >= 3
+
+ENGINE API has been deprecated since OpenSSL version 3.0 [1].
+Distros have started dropping support from headers and in future
+it will likely disappear also from library.
+
+It has been superseded by the PROVIDER API, so use it instead
+for OPENSSL MAJOR >= 3.
+
+[1] https://github.com/openssl/openssl/blob/master/README-ENGINES.md
+
+[jarkko: fixed up alignment issues reported by checkpatch.pl --strict]
+
+Signed-off-by: Jan Stancek <[email protected]>
+Reviewed-by: Jarkko Sakkinen <[email protected]>
+Tested-by: R Nageswara Sastry <[email protected]>
+Reviewed-by: Neal Gompa <[email protected]>
+Signed-off-by: Jarkko Sakkinen <[email protected]>
+
+Upstream-Status: Inappropriate [OE-specifc]
+---
+ certs/extract-cert.c | 103 ++++++++++++++++++++++++++++++++++++---------------
+ 1 file changed, 73 insertions(+), 30 deletions(-)
+
+(limited to 'certs/extract-cert.c')
+
+diff --git a/certs/extract-cert.c b/certs/extract-cert.c
+index 61bbe00856717..7d6d468ed6129 100644
+--- a/certs/extract-cert.c
++++ b/certs/extract-cert.c
+@@ -21,17 +21,18 @@
+ #include <openssl/bio.h>
+ #include <openssl/pem.h>
+ #include <openssl/err.h>
+-#include <openssl/engine.h>
+-
++#if OPENSSL_VERSION_MAJOR >= 3
++# define USE_PKCS11_PROVIDER
++# include <openssl/provider.h>
++# include <openssl/store.h>
++#else
++# if !defined(OPENSSL_NO_ENGINE) && !defined(OPENSSL_NO_DEPRECATED_3_0)
++#  define USE_PKCS11_ENGINE
++#  include <openssl/engine.h>
++# endif
++#endif
+ #include "ssl-common.h"
+ 
+-/*
+- * OpenSSL 3.0 deprecates the OpenSSL's ENGINE API.
+- *
+- * Remove this if/when that API is no longer used
+- */
+-#pragma GCC diagnostic ignored "-Wdeprecated-declarations"
+-
+ #define PKEY_ID_PKCS7 2
+ 
+ static __attribute__((noreturn))
+@@ -61,6 +62,66 @@ static void write_cert(X509 *x509)
+               fprintf(stderr, "Extracted cert: %s\n", buf);
+ }
+ 
++static X509 *load_cert_pkcs11(const char *cert_src)
++{
++      X509 *cert = NULL;
++#ifdef USE_PKCS11_PROVIDER
++      OSSL_STORE_CTX *store;
++
++      if (!OSSL_PROVIDER_try_load(NULL, "pkcs11", true))
++              ERR(1, "OSSL_PROVIDER_try_load(pkcs11)");
++      if (!OSSL_PROVIDER_try_load(NULL, "default", true))
++              ERR(1, "OSSL_PROVIDER_try_load(default)");
++
++      store = OSSL_STORE_open(cert_src, NULL, NULL, NULL, NULL);
++      ERR(!store, "OSSL_STORE_open");
++
++      while (!OSSL_STORE_eof(store)) {
++              OSSL_STORE_INFO *info = OSSL_STORE_load(store);
++
++              if (!info) {
++                      drain_openssl_errors(__LINE__, 0);
++                      continue;
++              }
++              if (OSSL_STORE_INFO_get_type(info) == OSSL_STORE_INFO_CERT) {
++                      cert = OSSL_STORE_INFO_get1_CERT(info);
++                      ERR(!cert, "OSSL_STORE_INFO_get1_CERT");
++              }
++              OSSL_STORE_INFO_free(info);
++              if (cert)
++                      break;
++      }
++      OSSL_STORE_close(store);
++#elif defined(USE_PKCS11_ENGINE)
++              ENGINE *e;
++              struct {
++                      const char *cert_id;
++                      X509 *cert;
++              } parms;
++
++              parms.cert_id = cert_src;
++              parms.cert = NULL;
++
++              ENGINE_load_builtin_engines();
++              drain_openssl_errors(__LINE__, 1);
++              e = ENGINE_by_id("pkcs11");
++              ERR(!e, "Load PKCS#11 ENGINE");
++              if (ENGINE_init(e))
++                      drain_openssl_errors(__LINE__, 1);
++              else
++                      ERR(1, "ENGINE_init");
++              if (key_pass)
++                      ERR(!ENGINE_ctrl_cmd_string(e, "PIN", key_pass, 0), 
"Set PKCS#11 PIN");
++              ENGINE_ctrl_cmd(e, "LOAD_CERT_CTRL", 0, &parms, NULL, 1);
++              ERR(!parms.cert, "Get X.509 from PKCS#11");
++              cert = parms.cert;
++#else
++              fprintf(stderr, "no pkcs11 engine/provider available\n");
++              exit(1);
++#endif
++      return cert;
++}
++
+ int main(int argc, char **argv)
+ {
+       char *cert_src;
+@@ -89,28 +150,10 @@ int main(int argc, char **argv)
+               fclose(f);
+               exit(0);
+       } else if (!strncmp(cert_src, "pkcs11:", 7)) {
+-              ENGINE *e;
+-              struct {
+-                      const char *cert_id;
+-                      X509 *cert;
+-              } parms;
++              X509 *cert = load_cert_pkcs11(cert_src);
+ 
+-              parms.cert_id = cert_src;
+-              parms.cert = NULL;
+-
+-              ENGINE_load_builtin_engines();
+-              drain_openssl_errors(__LINE__, 1);
+-              e = ENGINE_by_id("pkcs11");
+-              ERR(!e, "Load PKCS#11 ENGINE");
+-              if (ENGINE_init(e))
+-                      drain_openssl_errors(__LINE__, 1);
+-              else
+-                      ERR(1, "ENGINE_init");
+-              if (key_pass)
+-                      ERR(!ENGINE_ctrl_cmd_string(e, "PIN", key_pass, 0), 
"Set PKCS#11 PIN");
+-              ENGINE_ctrl_cmd(e, "LOAD_CERT_CTRL", 0, &parms, NULL, 1);
+-              ERR(!parms.cert, "Get X.509 from PKCS#11");
+-              write_cert(parms.cert);
++              ERR(!cert, "load_cert_pkcs11 failed");
++              write_cert(cert);
+       } else {
+               BIO *b;
+               X509 *x509;
+-- 
+cgit 1.3.1-korg
+
diff --git a/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging_6.6.bb 
b/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging_6.6.bb
index 9acc95c8..3d6b7007 100644
--- a/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging_6.6.bb
+++ b/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging_6.6.bb
@@ -28,6 +28,12 @@ KERNEL_REPRODUCIBILITY_PATCHES = " \
     file://0001-vt-conmakehash-improve-reproducibility.patch \
 "
 
+SRC_URI += "\
+    file://0001-move-common-SSL-helper-functions-to-a-header.patch \
+    file://0002-avoid-using-deprecated-ERR_get_error_line.patch \
+    file://0003-use-pkcs11-provider-for-OPENSSL-MAJOR-3.patch \
+"
+
 # Special configuration for remoteproc/rpmsg IPC modules
 module_conf_rpmsg_client_sample = "blacklist rpmsg_client_sample"
 module_conf_ti_k3_r5_remoteproc = "softdep ti_k3_r5_remoteproc pre: 
virtio_rpmsg_bus"
-- 
2.43.0

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#20360): 
https://lists.yoctoproject.org/g/meta-ti/message/20360
Mute This Topic: https://lists.yoctoproject.org/mt/121174439/21656
Group Owner: [email protected]
Unsubscribe: https://lists.yoctoproject.org/g/meta-ti/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to