Skip to content

Commit e73cc82

Browse files
authored
fix: preserve musl compatibility in FIPS build (#1008)
## Why [#997](#997) added the musl compatibility check to the FIPS `native-jar` execution, but did not port the corresponding link and post-link handling from the Linux release profiles. As a result, FIPS artifacts retain glibc loader and runtime dependencies that make them fail the new check. ## Changes - link the C++ runtime and unwinder archives statically in `fips-boringssl-static` - remove the architecture-specific `ld-linux` `DT_NEEDED` entry from the final FIPS native library before the musl check - document that FIPS, x86_64, and aarch64 profiles each duplicate these compatibility settings ## Verification - `xmllint --noout boringssl-static/pom.xml` - `git diff --check` - downstream Linux FIPS builds completed successfully on x86_64 and aarch64, including the native musl compatibility check Local Maven model validation was not run because this machine has no Java runtime.
1 parent f76ebd0 commit e73cc82

2 files changed

Lines changed: 23 additions & 7 deletions

File tree

‎boringssl-static/pom.xml‎

Lines changed: 16 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -313,6 +313,21 @@
313313
</then>
314314
</if>
315315

316+
<!-- Same ld-linux DT_NEEDED removal as the release profiles.
317+
See docs/musl-compatibility.md -->
318+
<if>
319+
<equals arg1="${os.detected.name}" arg2="linux" />
320+
<then>
321+
<exec executable="patchelf" failonerror="true" dir="${nativeLibOnlyDir}/META-INF/native/linux${archBits}/" resolveexecutable="true">
322+
<arg value="--remove-needed" />
323+
<arg value="ld-linux-x86-64.so.2" />
324+
<arg value="--remove-needed" />
325+
<arg value="ld-linux-aarch64.so.1" />
326+
<arg value="libnetty_tcnative.so" />
327+
</exec>
328+
</then>
329+
</if>
330+
316331
<!-- Assert the invariants the steps above establish, on the final bytes and
317332
before the jar is assembled. Bound here rather than to verify because every
318333
build, deploy and staging command is "clean package <plugin>:goal" and so
@@ -398,7 +413,7 @@
398413
<configureArg>--libdir=${project.build.directory}/native-build/target/lib</configureArg>
399414
<configureArg>CFLAGS=-O3 -Werror -fno-omit-frame-pointer -fvisibility=hidden -Wunused -Wno-unused-value</configureArg>
400415
<configureArg>CPPFLAGS=-DHAVE_OPENSSL -I${boringsslCheckoutDir}/include</configureArg>
401-
<configureArg>LDFLAGS=-L${boringsslBuildDir} -lssl -lcrypto -ldecrepit -lstdc++</configureArg>
416+
<configureArg>LDFLAGS=-L${boringsslBuildDir} -lssl -lcrypto -ldecrepit -l:libstdc++.a -l:libgcc.a -l:libgcc_eh.a</configureArg>
402417
</configureArgs>
403418
</configuration>
404419
</execution>

‎docs/musl-compatibility.md‎

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -238,13 +238,13 @@ protocol/cipher against a released version. It must be identical.
238238
| file | role |
239239
|---|---|
240240
| `openssl-dynamic/src/main/c/musl_compat.c` | weak fallbacks for the Class B symbols. Applies to **every** profile, since it is a source file. |
241-
| `boringssl-static/pom.xml`, antrun `native-jar` target | post-link `patchelf --remove-needed ld-linux-*` (Class A). Present in **both** release profiles: `boringssl-static-default` (x86_64) and `linux-aarch64`. |
241+
| `boringssl-static/pom.xml`, antrun `native-jar` target | post-link `patchelf --remove-needed ld-linux-*` (Class A). Present in the FIPS profile and both release profiles: `fips-boringssl-static`, `boringssl-static-default` (x86_64), and `linux-aarch64`. |
242242
| `docker/Dockerfile.centos6` | installs `patchelf` from the upstream prebuilt **static** binary — CentOS 6 is EOL with no EPEL, and `objcopy` cannot remove a `DT_NEEDED`. Needs `--no-check-certificate`, same as the OpenSSL download: the CA bundle cannot verify modern GitHub TLS. |
243243
| `docker/Dockerfile.cross_compile_aarch64` | installs `patchelf` from EPEL 7 (available there, unlike CentOS 6) |
244244

245-
Note the two release profiles duplicate the whole native build, so **a change to one does not
246-
apply to the other**. `linux-aarch64` cross-compiles from an x86_64 host; patchelf is
247-
arch-agnostic and edits the aarch64 object correctly from there (verified), whereas the
245+
Note the FIPS profile and two release profiles duplicate the whole native build, so **a change to
246+
one does not apply to the others**. `linux-aarch64` cross-compiles from an x86_64 host; patchelf
247+
is arch-agnostic and edits the aarch64 object correctly from there (verified), whereas the
248248
`strip` in that profile has to use the cross-prefixed `aarch64-none-linux-gnu-strip`.
249249

250250
### Rules for `musl_compat.c`
@@ -438,8 +438,9 @@ Other notes:
438438
- Ant's `<exec>` does not echo silent commands, so absence of `strip`/`patchelf` output in the
439439
log does **not** mean they did not run. Verify on the artifact instead.
440440
- Link flags are set per profile and are duplicated: the x86_64 default profile sets
441-
`hawtjniLdflags` in the `ldflags-setup` antrun execution, while the `linux-aarch64` profile
442-
hardcodes `LDFLAGS` in its hawtjni `configureArgs`. Changing one does not change the other.
441+
`hawtjniLdflags` in the `ldflags-setup` antrun execution, while the FIPS and `linux-aarch64`
442+
profiles hardcode `LDFLAGS` in their hawtjni `configureArgs`. Changing one does not change the
443+
others.
443444

444445
---
445446

0 commit comments

Comments
 (0)