| Message ID | 20260831160943.3999351-1-jimmy.wesolowski@mobileye.com |
|---|---|
| State | New |
| Headers | show |
| Series | openssh: ensure libxcrypt is enabled to provide a crypt() implementation | expand |
>>>>> "Jimmy" == Jimmy Durand Wesolowski via buildroot <buildroot@buildroot.org> writes: > When OpenSSL is enabled, if DES support is enabled, OpenSSH uses > DES_crypt. However, without OpenSSL or its DES support, there is no > available crypt() implementation for OpenSSH libopenbsd-compat xcrypt() > function, resulting in the following error: > .../host/bin/i686-buildroot-linux-gnu-gcc -o sshd-auth sshd-auth.o > auth2-methods.o auth-rhosts.o auth-passwd.o sshpty.o sshlogin.o > servconf.o serverloop.o auth.o auth2.o auth-options.o session.o > auth2-chall.o groupaccess.o auth-bsdauth.o auth2-hostbased.o > auth2-kbdint.o auth2-none.o auth2-passwd.o auth2-pubkey.o > auth2-pubkeyfile.o auth2-gss.o gss-serv.o gss-serv-krb5.o > monitor_wrap.o auth-krb5.o audit.o audit-bsm.o audit-linux.o > platform.o loginrec.o auth-pam.o auth-shadow.o auth-sia.o > sandbox-null.o sandbox-rlimit.o sandbox-darwin.o > sandbox-seccomp-filter.o sandbox-capsicum.o sandbox-solaris.o > sftp-server.o sftp-common.o uidswap.o ssh-pkcs11-client.o > ssh-sk-client.o -L. -Lopenbsd-compat/ -D_LARGEFILE_SOURCE > -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -O2 -g0 > -D_FORTIFY_SOURCE=1 -Wl,-z,relro -Wl,-z,now -Wl,-z,noexecstack > -fstack-protector-strong -pie -lssh -lopenbsd-compat > -L.../host/bin/../i686-buildroot-linux-gnu/sysroot/usr/lib > -lssl -lcrypto -lcrypto -lz > .../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../ > i686-buildroot-linux-gnu/bin/ld: > openbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt': > xcrypt.c:(.text+0x51): undefined reference to `crypt' > .../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../ > i686-buildroot-linux-gnu/bin/ld: > openbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt': > xcrypt.c:(.text+0x51): undefined reference to `crypt' collect2: error: > ld returned 1 exit status make[2]: *** [Makefile:233: sshd-auth] Error > 1 make[2]: *** Waiting for unfinished jobs.... collect2: error: ld > returned 1 exit status make[2]: *** [Makefile:230: sshd-session] Error > 1 make[1]: *** [package/pkg-generic.mk:273: > .../build/openssh-10.4p1/.stamp_built] > Error 2 make: *** [Makefile:83: _all] Error 2 > This commit enables BR2_PACKAGE_LIBXCRYPT with OpenSSH as long as the > glibc is used. Since "sshd-auth" is compiled regardless of > BR2_PACKAGE_OPENSSH_SERVER, we need to enable it with BR2_PACKAGE_OPENSSH. > Signed-off-by: Jimmy Durand Wesolowski <jimmy.wesolowski@mobileye.com> Committed, thanks.
diff --git a/package/openssh/Config.in b/package/openssh/Config.in index 25843447a7..3b0adad63d 100644 --- a/package/openssh/Config.in +++ b/package/openssh/Config.in @@ -3,6 +3,7 @@ config BR2_PACKAGE_OPENSSH depends on BR2_USE_MMU # fork() select BR2_PACKAGE_OPENSSL select BR2_PACKAGE_ZLIB + select BR2_PACKAGE_LIBXCRYPT if BR2_TOOLCHAIN_USES_GLIBC help A free version of the SSH protocol suite of network connectivity tools. The standard 'ssh', 'sshd', 'scp', and @@ -22,7 +23,6 @@ config BR2_PACKAGE_OPENSSH_CLIENT config BR2_PACKAGE_OPENSSH_SERVER bool "server" default y - select BR2_PACKAGE_LIBXCRYPT if BR2_TOOLCHAIN_USES_GLIBC help Server programs: sshd, sftp-server diff --git a/package/openssh/openssh.mk b/package/openssh/openssh.mk index dd0a6e023e..f2e1f235c0 100644 --- a/package/openssh/openssh.mk +++ b/package/openssh/openssh.mk @@ -51,7 +51,7 @@ endif OPENSSH_DEPENDENCIES = host-pkgconf zlib openssl # crypt() in libcrypt only required for sshd. -ifeq ($(BR2_PACKAGE_OPENSSH_SERVER)$(BR2_PACKAGE_LIBXCRYPT),yy) +ifeq ($(BR2_PACKAGE_LIBXCRYPT),y) OPENSSH_DEPENDENCIES += libxcrypt endif
When OpenSSL is enabled, if DES support is enabled, OpenSSH uses DES_crypt. However, without OpenSSL or its DES support, there is no available crypt() implementation for OpenSSH libopenbsd-compat xcrypt() function, resulting in the following error: .../host/bin/i686-buildroot-linux-gnu-gcc -o sshd-auth sshd-auth.o auth2-methods.o auth-rhosts.o auth-passwd.o sshpty.o sshlogin.o servconf.o serverloop.o auth.o auth2.o auth-options.o session.o auth2-chall.o groupaccess.o auth-bsdauth.o auth2-hostbased.o auth2-kbdint.o auth2-none.o auth2-passwd.o auth2-pubkey.o auth2-pubkeyfile.o auth2-gss.o gss-serv.o gss-serv-krb5.o monitor_wrap.o auth-krb5.o audit.o audit-bsm.o audit-linux.o platform.o loginrec.o auth-pam.o auth-shadow.o auth-sia.o sandbox-null.o sandbox-rlimit.o sandbox-darwin.o sandbox-seccomp-filter.o sandbox-capsicum.o sandbox-solaris.o sftp-server.o sftp-common.o uidswap.o ssh-pkcs11-client.o ssh-sk-client.o -L. -Lopenbsd-compat/ -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -O2 -g0 -D_FORTIFY_SOURCE=1 -Wl,-z,relro -Wl,-z,now -Wl,-z,noexecstack -fstack-protector-strong -pie -lssh -lopenbsd-compat -L.../host/bin/../i686-buildroot-linux-gnu/sysroot/usr/lib -lssl -lcrypto -lcrypto -lz .../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../ i686-buildroot-linux-gnu/bin/ld: openbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt': xcrypt.c:(.text+0x51): undefined reference to `crypt' .../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../ i686-buildroot-linux-gnu/bin/ld: openbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt': xcrypt.c:(.text+0x51): undefined reference to `crypt' collect2: error: ld returned 1 exit status make[2]: *** [Makefile:233: sshd-auth] Error 1 make[2]: *** Waiting for unfinished jobs.... collect2: error: ld returned 1 exit status make[2]: *** [Makefile:230: sshd-session] Error 1 make[1]: *** [package/pkg-generic.mk:273: .../build/openssh-10.4p1/.stamp_built] Error 2 make: *** [Makefile:83: _all] Error 2 This commit enables BR2_PACKAGE_LIBXCRYPT with OpenSSH as long as the glibc is used. Since "sshd-auth" is compiled regardless of BR2_PACKAGE_OPENSSH_SERVER, we need to enable it with BR2_PACKAGE_OPENSSH. Signed-off-by: Jimmy Durand Wesolowski <jimmy.wesolowski@mobileye.com> --- package/openssh/Config.in | 2 +- package/openssh/openssh.mk | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-)