Hi Ryan,
On 20:54-20260909, Ryan Eatmon via lists.yoctoproject.org wrote:
> Backport a set of kernel patches to 6.6 to fix the OpenSSL build
> failures.
>
> Signed-off-by: Ryan Eatmon <[email protected]>
> ---
> v2; Added missing Upstream-Status.
>
> ...mon-SSL-helper-functions-to-a-header.patch | 205 ++++++++++++++++++
> ...-using-deprecated-ERR_get_error_line.patch | 121 +++++++++++
> ...-pkcs11-provider-for-OPENSSL-MAJOR-3.patch | 163 ++++++++++++++
> .../linux/linux-ti-staging_6.6.bb | 6 +
> 4 files changed, 495 insertions(+)
> create mode 100644
> meta-ti-bsp/recipes-kernel/linux/files/0001-move-common-SSL-helper-functions-to-a-header.patch
> create mode 100644
> meta-ti-bsp/recipes-kernel/linux/files/0002-avoid-using-deprecated-ERR_get_error_line.patch
> create mode 100644
> meta-ti-bsp/recipes-kernel/linux/files/0003-use-pkcs11-provider-for-OPENSSL-MAJOR-3.patch
>
> diff --git
> a/meta-ti-bsp/recipes-kernel/linux/files/0001-move-common-SSL-helper-functions-to-a-header.patch
>
> b/meta-ti-bsp/recipes-kernel/linux/files/0001-move-common-SSL-helper-functions-to-a-header.patch
> new file mode 100644
> index 00000000..6a58b5eb
> --- /dev/null
> +++
> b/meta-ti-bsp/recipes-kernel/linux/files/0001-move-common-SSL-helper-functions-to-a-header.patch
> @@ -0,0 +1,205 @@
> +From 300e6d4116f956b035281ec94297dc4dc8d4e1d3 Mon Sep 17 00:00:00 2001
> +From: Jan Stancek <[email protected]>
> +Date: Fri, 12 Jul 2024 09:11:14 +0200
> +Subject: sign-file,extract-cert: move common SSL helper functions to a header
> +
> +Couple error handling helpers are repeated in both tools, so
> +move them to a common header.
> +
> +Signed-off-by: Jan Stancek <[email protected]>
> +Reviewed-by: Jarkko Sakkinen <[email protected]>
> +Tested-by: R Nageswara Sastry <[email protected]>
> +Reviewed-by: Neal Gompa <[email protected]>
> +Signed-off-by: Jarkko Sakkinen <[email protected]>
> +
> +Upstream-Status: Inappropriate [OE specific]
> +---
> + MAINTAINERS | 1 +
> + certs/Makefile | 2 +-
> + certs/extract-cert.c | 37 ++-----------------------------------
> + scripts/sign-file.c | 37 ++-----------------------------------
> + scripts/ssl-common.h | 39 +++++++++++++++++++++++++++++++++++++++
> + 5 files changed, 45 insertions(+), 71 deletions(-)
> + create mode 100644 scripts/ssl-common.h
> +
> +diff --git a/MAINTAINERS b/MAINTAINERS
> +index 9278c30ef1d5a..23f9028848552 100644
> +--- a/MAINTAINERS
> ++++ b/MAINTAINERS
> +@@ -5204,6 +5204,7 @@ S: Maintained
> + F: Documentation/admin-guide/module-signing.rst
> + F: certs/
> + F: scripts/sign-file.c
> ++F: scripts/ssl-common.h
> + F: tools/certs/
> +
> + CFAG12864B LCD DRIVER
> +diff --git a/certs/Makefile b/certs/Makefile
> +index 1094e3860c2a7..f6fa4d8d75e05 100644
> +--- a/certs/Makefile
> ++++ b/certs/Makefile
> +@@ -84,5 +84,5 @@ targets += x509_revocation_list
> +
> + hostprogs := extract-cert
> +
> +-HOSTCFLAGS_extract-cert.o = $(shell $(HOSTPKG_CONFIG) --cflags libcrypto 2>
> /dev/null)
> ++HOSTCFLAGS_extract-cert.o = $(shell $(HOSTPKG_CONFIG) --cflags libcrypto 2>
> /dev/null) -I$(srctree)/scripts
> + HOSTLDLIBS_extract-cert = $(shell $(HOSTPKG_CONFIG) --libs libcrypto 2>
> /dev/null || echo -lcrypto)
> +diff --git a/certs/extract-cert.c b/certs/extract-cert.c
> +index 70e9ec89d87d3..8e7ba9974a1fa 100644
> +--- a/certs/extract-cert.c
> ++++ b/certs/extract-cert.c
> +@@ -23,6 +23,8 @@
> + #include <openssl/err.h>
> + #include <openssl/engine.h>
> +
> ++#include "ssl-common.h"
> ++
> + /*
> + * OpenSSL 3.0 deprecates the OpenSSL's ENGINE API.
> + *
> +@@ -40,41 +42,6 @@ void format(void)
> + exit(2);
> + }
> +
> +-static void display_openssl_errors(int l)
> +-{
> +- const char *file;
> +- char buf[120];
> +- int e, line;
> +-
> +- if (ERR_peek_error() == 0)
> +- return;
> +- fprintf(stderr, "At main.c:%d:\n", l);
> +-
> +- while ((e = ERR_get_error_line(&file, &line))) {
> +- ERR_error_string(e, buf);
> +- fprintf(stderr, "- SSL %s: %s:%d\n", buf, file, line);
> +- }
> +-}
> +-
> +-static void drain_openssl_errors(void)
> +-{
> +- const char *file;
> +- int line;
> +-
> +- if (ERR_peek_error() == 0)
> +- return;
> +- while (ERR_get_error_line(&file, &line)) {}
> +-}
> +-
> +-#define ERR(cond, fmt, ...) \
> +- do { \
> +- bool __cond = (cond); \
> +- display_openssl_errors(__LINE__); \
> +- if (__cond) { \
> +- err(1, fmt, ## __VA_ARGS__); \
> +- } \
> +- } while(0)
> +-
> + static const char *key_pass;
> + static BIO *wb;
> + static char *cert_dst;
> +diff --git a/scripts/sign-file.c b/scripts/sign-file.c
> +index 3edb156ae52c3..39ba58db5d4ea 100644
> +--- a/scripts/sign-file.c
> ++++ b/scripts/sign-file.c
> +@@ -29,6 +29,8 @@
> + #include <openssl/err.h>
> + #include <openssl/engine.h>
> +
> ++#include "ssl-common.h"
> ++
> + /*
> + * OpenSSL 3.0 deprecates the OpenSSL's ENGINE API.
> + *
> +@@ -83,41 +85,6 @@ void format(void)
> + exit(2);
> + }
> +
> +-static void display_openssl_errors(int l)
> +-{
> +- const char *file;
> +- char buf[120];
> +- int e, line;
> +-
> +- if (ERR_peek_error() == 0)
> +- return;
> +- fprintf(stderr, "At main.c:%d:\n", l);
> +-
> +- while ((e = ERR_get_error_line(&file, &line))) {
> +- ERR_error_string(e, buf);
> +- fprintf(stderr, "- SSL %s: %s:%d\n", buf, file, line);
> +- }
> +-}
> +-
> +-static void drain_openssl_errors(void)
> +-{
> +- const char *file;
> +- int line;
> +-
> +- if (ERR_peek_error() == 0)
> +- return;
> +- while (ERR_get_error_line(&file, &line)) {}
> +-}
> +-
> +-#define ERR(cond, fmt, ...) \
> +- do { \
> +- bool __cond = (cond); \
> +- display_openssl_errors(__LINE__); \
> +- if (__cond) { \
> +- errx(1, fmt, ## __VA_ARGS__); \
> +- } \
> +- } while(0)
> +-
> + static const char *key_pass;
> +
> + static int pem_pw_cb(char *buf, int len, int w, void *v)
> +diff --git a/scripts/ssl-common.h b/scripts/ssl-common.h
> +new file mode 100644
> +index 0000000000000..e6711c75ed913
> +--- /dev/null
> ++++ b/scripts/ssl-common.h
> +@@ -0,0 +1,39 @@
> ++/* SPDX-License-Identifier: LGPL-2.1+ */
> ++/*
> ++ * SSL helper functions shared by sign-file and extract-cert.
> ++ */
> ++
> ++static void display_openssl_errors(int l)
> ++{
> ++ const char *file;
> ++ char buf[120];
> ++ int e, line;
> ++
> ++ if (ERR_peek_error() == 0)
> ++ return;
> ++ fprintf(stderr, "At main.c:%d:\n", l);
> ++
> ++ while ((e = ERR_get_error_line(&file, &line))) {
> ++ ERR_error_string(e, buf);
> ++ fprintf(stderr, "- SSL %s: %s:%d\n", buf, file, line);
> ++ }
> ++}
> ++
> ++static void drain_openssl_errors(void)
> ++{
> ++ const char *file;
> ++ int line;
> ++
> ++ if (ERR_peek_error() == 0)
> ++ return;
> ++ while (ERR_get_error_line(&file, &line)) {}
> ++}
> ++
> ++#define ERR(cond, fmt, ...) \
> ++ do { \
> ++ bool __cond = (cond); \
> ++ display_openssl_errors(__LINE__); \
> ++ if (__cond) { \
> ++ errx(1, fmt, ## __VA_ARGS__); \
> ++ } \
> ++ } while (0)
> +--
> +cgit 1.3.1-korg
> +
> diff --git
> a/meta-ti-bsp/recipes-kernel/linux/files/0002-avoid-using-deprecated-ERR_get_error_line.patch
>
> b/meta-ti-bsp/recipes-kernel/linux/files/0002-avoid-using-deprecated-ERR_get_error_line.patch
> new file mode 100644
> index 00000000..993f6739
> --- /dev/null
> +++
> b/meta-ti-bsp/recipes-kernel/linux/files/0002-avoid-using-deprecated-ERR_get_error_line.patch
> @@ -0,0 +1,121 @@
> +From 467d60eddf55588add232feda325da7215ddaf30 Mon Sep 17 00:00:00 2001
> +From: Jan Stancek <[email protected]>
> +Date: Fri, 12 Jul 2024 09:11:15 +0200
> +Subject: sign-file,extract-cert: avoid using deprecated ERR_get_error_line()
> +
> +ERR_get_error_line() is deprecated since OpenSSL 3.0.
> +
> +Use ERR_peek_error_line() instead, and combine display_openssl_errors()
> +and drain_openssl_errors() to a single function where parameter decides
> +if it should consume errors silently.
> +
> +Signed-off-by: Jan Stancek <[email protected]>
> +Reviewed-by: Jarkko Sakkinen <[email protected]>
> +Tested-by: R Nageswara Sastry <[email protected]>
> +Reviewed-by: Neal Gompa <[email protected]>
> +Signed-off-by: Jarkko Sakkinen <[email protected]>
> +
> +Upstream-Status: Inappropriate [OE-specifc]
Typo in "specific".
> +---
> + certs/extract-cert.c | 4 ++--
> + scripts/sign-file.c | 6 +++---
> + scripts/ssl-common.h | 23 ++++++++---------------
> + 3 files changed, 13 insertions(+), 20 deletions(-)
> +
> +diff --git a/certs/extract-cert.c b/certs/extract-cert.c
> +index 8e7ba9974a1fa..61bbe00856717 100644
> +--- a/certs/extract-cert.c
> ++++ b/certs/extract-cert.c
> +@@ -99,11 +99,11 @@ int main(int argc, char **argv)
> + parms.cert = NULL;
> +
> + ENGINE_load_builtin_engines();
> +- drain_openssl_errors();
> ++ drain_openssl_errors(__LINE__, 1);
> + e = ENGINE_by_id("pkcs11");
> + ERR(!e, "Load PKCS#11 ENGINE");
> + if (ENGINE_init(e))
> +- drain_openssl_errors();
> ++ drain_openssl_errors(__LINE__, 1);
> + else
> + ERR(1, "ENGINE_init");
> + if (key_pass)
> +diff --git a/scripts/sign-file.c b/scripts/sign-file.c
> +index 39ba58db5d4ea..bb3fdf1a617c2 100644
> +--- a/scripts/sign-file.c
> ++++ b/scripts/sign-file.c
> +@@ -114,11 +114,11 @@ static EVP_PKEY *read_private_key(const char
> *private_key_name)
> + ENGINE *e;
> +
> + ENGINE_load_builtin_engines();
> +- drain_openssl_errors();
> ++ drain_openssl_errors(__LINE__, 1);
> + e = ENGINE_by_id("pkcs11");
> + ERR(!e, "Load PKCS#11 ENGINE");
> + if (ENGINE_init(e))
> +- drain_openssl_errors();
> ++ drain_openssl_errors(__LINE__, 1);
> + else
> + ERR(1, "ENGINE_init");
> + if (key_pass)
> +@@ -273,7 +273,7 @@ int main(int argc, char **argv)
> +
> + /* Digest the module data. */
> + OpenSSL_add_all_digests();
> +- display_openssl_errors(__LINE__);
> ++ drain_openssl_errors(__LINE__, 0);
> + digest_algo = EVP_get_digestbyname(hash_algo);
> + ERR(!digest_algo, "EVP_get_digestbyname");
> +
> +diff --git a/scripts/ssl-common.h b/scripts/ssl-common.h
> +index e6711c75ed913..2db0e181143cf 100644
> +--- a/scripts/ssl-common.h
> ++++ b/scripts/ssl-common.h
> +@@ -3,7 +3,7 @@
> + * SSL helper functions shared by sign-file and extract-cert.
> + */
> +
> +-static void display_openssl_errors(int l)
> ++static void drain_openssl_errors(int l, int silent)
> + {
> + const char *file;
> + char buf[120];
> +@@ -11,28 +11,21 @@ static void display_openssl_errors(int l)
> +
> + if (ERR_peek_error() == 0)
> + return;
> +- fprintf(stderr, "At main.c:%d:\n", l);
> ++ if (!silent)
> ++ fprintf(stderr, "At main.c:%d:\n", l);
> +
> +- while ((e = ERR_get_error_line(&file, &line))) {
> ++ while ((e = ERR_peek_error_line(&file, &line))) {
> + ERR_error_string(e, buf);
> +- fprintf(stderr, "- SSL %s: %s:%d\n", buf, file, line);
> ++ if (!silent)
> ++ fprintf(stderr, "- SSL %s: %s:%d\n", buf, file, line);
> ++ ERR_get_error();
> + }
> + }
> +
> +-static void drain_openssl_errors(void)
> +-{
> +- const char *file;
> +- int line;
> +-
> +- if (ERR_peek_error() == 0)
> +- return;
> +- while (ERR_get_error_line(&file, &line)) {}
> +-}
> +-
> + #define ERR(cond, fmt, ...) \
> + do { \
> + bool __cond = (cond); \
> +- display_openssl_errors(__LINE__); \
> ++ drain_openssl_errors(__LINE__, 0); \
> + if (__cond) { \
> + errx(1, fmt, ## __VA_ARGS__); \
> + } \
> +--
> +cgit 1.3.1-korg
> +
> diff --git
> a/meta-ti-bsp/recipes-kernel/linux/files/0003-use-pkcs11-provider-for-OPENSSL-MAJOR-3.patch
>
> b/meta-ti-bsp/recipes-kernel/linux/files/0003-use-pkcs11-provider-for-OPENSSL-MAJOR-3.patch
> new file mode 100644
> index 00000000..8f509895
> --- /dev/null
> +++
> b/meta-ti-bsp/recipes-kernel/linux/files/0003-use-pkcs11-provider-for-OPENSSL-MAJOR-3.patch
> @@ -0,0 +1,163 @@
> +From 558bdc45dfb2669e1741384a0c80be9c82fa052c Mon Sep 17 00:00:00 2001
> +From: Jan Stancek <[email protected]>
> +Date: Fri, 20 Sep 2024 19:52:48 +0300
> +Subject: sign-file,extract-cert: use pkcs11 provider for OPENSSL MAJOR >= 3
> +
> +ENGINE API has been deprecated since OpenSSL version 3.0 [1].
> +Distros have started dropping support from headers and in future
> +it will likely disappear also from library.
> +
> +It has been superseded by the PROVIDER API, so use it instead
> +for OPENSSL MAJOR >= 3.
> +
> +[1] https://github.com/openssl/openssl/blob/master/README-ENGINES.md
> +
> +[jarkko: fixed up alignment issues reported by checkpatch.pl --strict]
> +
> +Signed-off-by: Jan Stancek <[email protected]>
> +Reviewed-by: Jarkko Sakkinen <[email protected]>
> +Tested-by: R Nageswara Sastry <[email protected]>
> +Reviewed-by: Neal Gompa <[email protected]>
> +Signed-off-by: Jarkko Sakkinen <[email protected]>
> +
> +Upstream-Status: Inappropriate [OE-specifc]
Nitpicking here, Typo in "specific", I don't think these typos affect anything
major.
> +---
> + certs/extract-cert.c | 103
> ++++++++++++++++++++++++++++++++++++---------------
> + 1 file changed, 73 insertions(+), 30 deletions(-)
> +
> +(limited to 'certs/extract-cert.c')
> +
> +diff --git a/certs/extract-cert.c b/certs/extract-cert.c
> +index 61bbe00856717..7d6d468ed6129 100644
> +--- a/certs/extract-cert.c
> ++++ b/certs/extract-cert.c
> +@@ -21,17 +21,18 @@
> + #include <openssl/bio.h>
> + #include <openssl/pem.h>
> + #include <openssl/err.h>
> +-#include <openssl/engine.h>
> +-
> ++#if OPENSSL_VERSION_MAJOR >= 3
> ++# define USE_PKCS11_PROVIDER
> ++# include <openssl/provider.h>
> ++# include <openssl/store.h>
> ++#else
> ++# if !defined(OPENSSL_NO_ENGINE) && !defined(OPENSSL_NO_DEPRECATED_3_0)
> ++# define USE_PKCS11_ENGINE
> ++# include <openssl/engine.h>
> ++# endif
> ++#endif
> + #include "ssl-common.h"
> +
> +-/*
> +- * OpenSSL 3.0 deprecates the OpenSSL's ENGINE API.
> +- *
> +- * Remove this if/when that API is no longer used
> +- */
> +-#pragma GCC diagnostic ignored "-Wdeprecated-declarations"
> +-
> + #define PKEY_ID_PKCS7 2
> +
> + static __attribute__((noreturn))
> +@@ -61,6 +62,66 @@ static void write_cert(X509 *x509)
> + fprintf(stderr, "Extracted cert: %s\n", buf);
> + }
> +
> ++static X509 *load_cert_pkcs11(const char *cert_src)
> ++{
> ++ X509 *cert = NULL;
> ++#ifdef USE_PKCS11_PROVIDER
> ++ OSSL_STORE_CTX *store;
> ++
> ++ if (!OSSL_PROVIDER_try_load(NULL, "pkcs11", true))
> ++ ERR(1, "OSSL_PROVIDER_try_load(pkcs11)");
> ++ if (!OSSL_PROVIDER_try_load(NULL, "default", true))
> ++ ERR(1, "OSSL_PROVIDER_try_load(default)");
> ++
> ++ store = OSSL_STORE_open(cert_src, NULL, NULL, NULL, NULL);
> ++ ERR(!store, "OSSL_STORE_open");
> ++
> ++ while (!OSSL_STORE_eof(store)) {
> ++ OSSL_STORE_INFO *info = OSSL_STORE_load(store);
> ++
> ++ if (!info) {
> ++ drain_openssl_errors(__LINE__, 0);
> ++ continue;
> ++ }
> ++ if (OSSL_STORE_INFO_get_type(info) == OSSL_STORE_INFO_CERT) {
> ++ cert = OSSL_STORE_INFO_get1_CERT(info);
> ++ ERR(!cert, "OSSL_STORE_INFO_get1_CERT");
> ++ }
> ++ OSSL_STORE_INFO_free(info);
> ++ if (cert)
> ++ break;
> ++ }
> ++ OSSL_STORE_close(store);
> ++#elif defined(USE_PKCS11_ENGINE)
> ++ ENGINE *e;
> ++ struct {
> ++ const char *cert_id;
> ++ X509 *cert;
> ++ } parms;
> ++
> ++ parms.cert_id = cert_src;
> ++ parms.cert = NULL;
> ++
> ++ ENGINE_load_builtin_engines();
> ++ drain_openssl_errors(__LINE__, 1);
> ++ e = ENGINE_by_id("pkcs11");
> ++ ERR(!e, "Load PKCS#11 ENGINE");
> ++ if (ENGINE_init(e))
> ++ drain_openssl_errors(__LINE__, 1);
> ++ else
> ++ ERR(1, "ENGINE_init");
> ++ if (key_pass)
> ++ ERR(!ENGINE_ctrl_cmd_string(e, "PIN", key_pass, 0),
> "Set PKCS#11 PIN");
> ++ ENGINE_ctrl_cmd(e, "LOAD_CERT_CTRL", 0, &parms, NULL, 1);
> ++ ERR(!parms.cert, "Get X.509 from PKCS#11");
> ++ cert = parms.cert;
> ++#else
> ++ fprintf(stderr, "no pkcs11 engine/provider available\n");
> ++ exit(1);
> ++#endif
> ++ return cert;
> ++}
> ++
> + int main(int argc, char **argv)
> + {
> + char *cert_src;
> +@@ -89,28 +150,10 @@ int main(int argc, char **argv)
> + fclose(f);
> + exit(0);
> + } else if (!strncmp(cert_src, "pkcs11:", 7)) {
> +- ENGINE *e;
> +- struct {
> +- const char *cert_id;
> +- X509 *cert;
> +- } parms;
> ++ X509 *cert = load_cert_pkcs11(cert_src);
> +
> +- parms.cert_id = cert_src;
> +- parms.cert = NULL;
> +-
> +- ENGINE_load_builtin_engines();
> +- drain_openssl_errors(__LINE__, 1);
> +- e = ENGINE_by_id("pkcs11");
> +- ERR(!e, "Load PKCS#11 ENGINE");
> +- if (ENGINE_init(e))
> +- drain_openssl_errors(__LINE__, 1);
> +- else
> +- ERR(1, "ENGINE_init");
> +- if (key_pass)
> +- ERR(!ENGINE_ctrl_cmd_string(e, "PIN", key_pass, 0),
> "Set PKCS#11 PIN");
> +- ENGINE_ctrl_cmd(e, "LOAD_CERT_CTRL", 0, &parms, NULL, 1);
> +- ERR(!parms.cert, "Get X.509 from PKCS#11");
> +- write_cert(parms.cert);
> ++ ERR(!cert, "load_cert_pkcs11 failed");
> ++ write_cert(cert);
> + } else {
> + BIO *b;
> + X509 *x509;
> +--
> +cgit 1.3.1-korg
> +
> diff --git a/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging_6.6.bb
> b/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging_6.6.bb
> index 9acc95c8..3d6b7007 100644
> --- a/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging_6.6.bb
> +++ b/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging_6.6.bb
> @@ -28,6 +28,12 @@ KERNEL_REPRODUCIBILITY_PATCHES = " \
> file://0001-vt-conmakehash-improve-reproducibility.patch \
> "
>
> +SRC_URI += "\
> + file://0001-move-common-SSL-helper-functions-to-a-header.patch \
> + file://0002-avoid-using-deprecated-ERR_get_error_line.patch \
> + file://0003-use-pkcs11-provider-for-OPENSSL-MAJOR-3.patch \
> +"
> +
> # Special configuration for remoteproc/rpmsg IPC modules
> module_conf_rpmsg_client_sample = "blacklist rpmsg_client_sample"
> module_conf_ti_k3_r5_remoteproc = "softdep ti_k3_r5_remoteproc pre:
> virtio_rpmsg_bus"
> --
> 2.43.0
>
-- Yogesh
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#20367):
https://lists.yoctoproject.org/g/meta-ti/message/20367
Mute This Topic: https://lists.yoctoproject.org/mt/121174439/21656
Group Owner: [email protected]
Unsubscribe: https://lists.yoctoproject.org/g/meta-ti/unsub
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-