Repository navigation
imx-test, secure-obj, libpkcs11: fix the build with current OE-core - #2789
Merged
otavio merged 4 commits intoOct 2, 2026
Merged
Conversation
patgen's Makefile adds -I$(PKG_CONFIG_SYSROOT_DIR)/usr/include/freetype2, but OE-core 68d2d38483 moved that export into the pkgconfig class, so the path fell back to the host and poison-system-directories failed do_compile. Tested with bitbake imx-test on imx93-11x11-lpddr4x-evk. Signed-off-by: Luciano Dittgen <luciano.dittgen@ossystems.com.br>
OpenSSL 4.0 removed the ENGINE API, so sobj_eng_app no longer links and secure-obj failed do_compile. Porting the engine means a new provider; it was installed under openssl-1.0.0/engines, which OpenSSL 3 and later never search, and nothing uses it. Tested with bitbake secure-obj libpkcs11 secure-obj-module on ls1012ardb. Signed-off-by: Luciano Dittgen <luciano.dittgen@ossystems.com.br>
The apps compile with plain $(CC) and never see CFLAGS, so mp_verify, unstripped here, kept TMPDIR in its debug info and failed the buildpaths QA check. Pass DEBUG_PREFIX_MAP on CC. Tested with bitbake secure-obj on ls1012ardb. Signed-off-by: Luciano Dittgen <luciano.dittgen@ossystems.com.br>
The app target compiles with plain $(CC) and never sees CFLAGS. Under GCC 15's C23 default thread_test.c fails (false as an identifier, a () prototype called with an argument), and without DEBUG_PREFIX_MAP its debug info fails the buildpaths QA check. Tested with bitbake libpkcs11 on ls1012ardb. Signed-off-by: Luciano Dittgen <luciano.dittgen@ossystems.com.br>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
imx-test, secure-obj and libpkcs11 don't build on current master with current OE-core. These 4 commits make them build again. Nothing else changes.
The breakage turned up while fixing
yocto-check-layer test_machine_signatures, because those fixes need these recipes to build. The signatures PR (#2790) is stacked on this one, so please merge this one first.Commits
adec33001imx-test: Inherit pkgconfigdo_compile: patgen's-I$(PKG_CONFIG_SYSROOT_DIR)/usr/include/freetype2fell back to the host and tripped poison-system-directories. OE-core 68d2d38483 moved thePKG_CONFIG_SYSROOT_DIRexport into the pkgconfig class.inherit pkgconfig461fd62basecure-obj: Drop the OpenSSL enginedo_compile:sobj_eng_appno longer links, because OpenSSL 4.0 removed the ENGINE API40d4d6b93secure-obj: Keep build paths out of the securekey_lib appsdo_package_qa[buildpaths]:mp_verifykept TMPDIR in its debug info. The apps compile with plain$(CC)and never seeCFLAGS.CC:append = " ${DEBUG_PREFIX_MAP}"e040a2beflibpkcs11: Build the test apps with gnu17 and the debug prefix mapdo_compile: GCC 15's C23 default rejectsthread_test.c(falseas an identifier, a()prototype called with an argument). After that,do_package_qa[buildpaths] for the same reason as secure-obj.-std=gnu17andDEBUG_PREFIX_MAPon the app buildBehaviour change: the secure-obj OpenSSL engine is gone
461fd62baremoves from thesecure-objpackage:libeng_secure_obj.so, installed under${libdir}/${ARCH}-linux-gnu/openssl-1.0.0/engines;sobj_eng_app, its test app.Porting it to OpenSSL 4.0 would mean rewriting it as a provider:
eng_secure_obj.cis about 900 lines onRSA_METHOD/EC_KEY_METHOD. It was also installed in anopenssl-1.0.0/enginesdirectory that OpenSSL 3 and later never search, and no recipe in the layer uses it. The TA and the key-management library (libsecure_obj.soand its apps) are unchanged.Validation
There's no before/after buildhistory diff for these commits, because each recipe fails to build on master. The evidence is that each one now builds through
do_package_qaon the machine listed. The signatures PR then built and compared all three recipes on top of these repairs.oelint-adv: no findings in the 4 changed files, before or after.