| git.druid.rocks | index | druid520 | ports | ports/ | ssl/ | libressl/ | add.sh |
ports/ssl/libressl/add.sh
set -e
git clone https://github.com/libressl/portable.git libressl
cd libressl
# libtoolize deposits ltmain.sh one directory up due to mp's <port>/<port>
# staging nesting; retry once after copying it back down if the first
# autoreconf (run inside autogen.sh) fails because of it.
./autogen.sh || { cp ../ltmain.sh . 2>/dev/null && ./autogen.sh; }
# strip any static/PIE-forcing flags from a global build-flags policy
# (-static-pie, -static, -fno-pie, -no-pie) from BOTH CFLAGS and
# LDFLAGS before building: libressl's own libtool-driven build links a
# REAL shared library (libcrypto.so/libssl.so/libtls.so, not just the
# static .a) alongside the static one, and -static-pie is a link MODE
# flag fundamentally incompatible with -shared -- gcc/ld pick the
# static-pie crt startup object (rcrt1.o, meant for a static-PIE
# EXECUTABLE) even when -shared is also present, and rcrt1.o expects a
# `main` symbol no shared library has: "undefined reference to `main'"
# building libcrypto.so. -fPIC is kept (needed either way: it's what
# makes the resulting .a's own object files usable by something ELSE
# that IS static-pie, like networking/curl's own libcurl.a). explicit
# CFLAGS/LDFLAGS on the configure/make command line, not just
# re-exporting the shell vars: autoconf's own ./configure only reads
# CFLAGS/LDFLAGS from the environment at cache-generation time, and an
# inherited exported value (set by whatever invoked this add.sh) wins
# over a later plain shell assignment unless overridden explicitly here.
ls_cflags="$(printf '%s' "$CFLAGS" | sed -E 's/-static-pie|-static\b|-fno-pie|-no-pie//g')"
ls_ldflags="$(printf '%s' "$LDFLAGS" | sed -E 's/-static-pie|-static\b|-fno-pie|-no-pie//g')"
# explicit --enable-shared: overrides this build session's own
# CONFIG_SITE default of enable_shared=no (see /etc/mp-static.site),
# which exists precisely so ports that DON'T need a .so don't build
# one under a global -static-pie policy -- libressl is a deliberate
# exception since git-remote-https itself needs libssl.so/libcrypto.so
# at runtime.
CFLAGS="$ls_cflags" LDFLAGS="$ls_ldflags" ./configure --prefix=$MP_PREFIX --enable-shared --enable-static $CONFIGURE_FLAGS
make CFLAGS="$ls_cflags" LDFLAGS="$ls_ldflags"
make install
# libressl installs its default trust bundle at etc/ssl/cert.pem (its
# own, BSD-style convention); most other software (curl among them)
# defaults to looking for the Alpine/Debian-style etc/ssl/certs/
# ca-certificates.crt instead and won't autodetect the bundle without
# it, failing every TLS connection with "error adding trust anchors"
# despite a perfectly good bundle sitting right there under a different
# name.
mkdir -p $MP_PREFIX/etc/ssl/certs
ln -sf ../cert.pem $MP_PREFIX/etc/ssl/certs/ca-certificates.crt
make clean || true