From: Thomas Bonnefille <thomas.bonnefille@bootlin.com>
To: Sascha Hauer <s.hauer@pengutronix.de>,
Ahmad Fatoum <a.fatoum@pengutronix.de>,
"open list:BAREBOX" <barebox@lists.infradead.org>
Cc: "Thomas Petazzoni" <thomas.petazzoni@bootlin.com>,
"Miquèl Raynal" <miquel.raynal@bootlin.com>,
"Alexis Lothoré" <alexis.lothore@bootlin.com>,
"Thomas Bonnefille" <thomas.bonnefille@bootlin.com>
Subject: [PATCH] ci: container: build openssl against musl
Date: Tue, 11 Aug 2026 19:22:14 +0200 [thread overview]
Message-ID: <20260811-add-openssl-musl-to-ci-v1-1-0ca5525f1775@bootlin.com> (raw)
Since 3c739b95ee ("sandbox: enable keytoc in hosttools_defconfig") the
hosttools_defconfig also builds keytoc a tool required to inject
cryptographic keys in a device tree.
This software needs openssl to be compiled. However, as barebox-ci is
using Debian as the base of its container, the openssl package given by
apt is compiled with the glibc.
In order to compile keytoc with musl, build a version of openssl against
musl in the barebox-ci container.
Signed-off-by: Thomas Bonnefille <thomas.bonnefille@bootlin.com>
---
Hello, I added the support to build openssl against Musl, this fixes the
commit 3c739b9 in CI.
Another patch has been sent previously to fix this issue
(https://lore.kernel.org/barebox/20260805142055.3844660-1-a.fatoum@pengutronix.de/)
I didn't find it in the 'next' branch of the Github repository
(git.pengutronix.de seems down on my side) and I assumed it wasn't
applied so I didn't include a revert commit for it.
---
test/Containerfile | 13 +++++++++++++
1 file changed, 13 insertions(+)
diff --git a/test/Containerfile b/test/Containerfile
index 296835d080..00f24a210f 100644
--- a/test/Containerfile
+++ b/test/Containerfile
@@ -118,4 +118,17 @@ ENV LLVM_SUFFIX=-${LLVM_VERSION}
RUN ln -Ts /usr/lib/llvm-${LLVM_VERSION}/lib/clang/${LLVM_VERSION}/lib/linux/ \
/usr/lib/llvm-${LLVM_VERSION}/lib/clang/${LLVM_VERSION}/lib/x86_64-pc-linux-gnu
+ENV OPENSSL_VERSION=3.5.6
+ENV PKG_CONFIG_PATH=/opt/openssl-musl/lib64/pkgconfig
+RUN cd /tmp && \
+ wget https://github.com/openssl/openssl/releases/download/openssl-$OPENSSL_VERSION/openssl-$OPENSSL_VERSION.tar.gz && \
+ echo "deae7c80cba99c4b4f940ecadb3c3338b13cb77418409238e57d7f31f2a3b736 openssl-$OPENSSL_VERSION.tar.gz" | sha256sum --check --status && \
+ tar -xzf openssl-$OPENSSL_VERSION.tar.gz && \
+ cd openssl-$OPENSSL_VERSION && \
+ ./Configure linux-x86_64 no-shared no-tests no-secure-memory no-afalgeng \
+ --prefix=/opt/openssl-musl --openssldir=/opt/openssl-musl/ssl CC=musl-gcc && \
+ make -j$(nproc) && make install_sw && \
+ ln -s /opt/openssl-musl/include/openssl /usr/include/x86_64-linux-musl && \
+ rm -rf /tmp/openssl-$OPENSSL_VERSION.tar.gz /tmp/openssl-$OPENSSL_VERSION
+
USER barebox:barebox
---
base-commit: 4705656eeeaba0dd3617b69172328daf4dbf9060
change-id: 20260806-add-openssl-musl-to-ci-f086904d4648
Best regards,
--
Thomas Bonnefille <thomas.bonnefille@bootlin.com>
reply other threads:[~2026-08-11 17:24 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260811-add-openssl-musl-to-ci-v1-1-0ca5525f1775@bootlin.com \
--to=thomas.bonnefille@bootlin.com \
--cc=a.fatoum@pengutronix.de \
--cc=alexis.lothore@bootlin.com \
--cc=barebox@lists.infradead.org \
--cc=miquel.raynal@bootlin.com \
--cc=s.hauer@pengutronix.de \
--cc=thomas.petazzoni@bootlin.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox