From 02835b151960e0291de3d17f99c7fe9c0a79330c Mon Sep 17 00:00:00 2001 From: mueller_minki Date: Sun, 4 Oct 2026 20:41:27 +0200 Subject: [PATCH] Improve build workflow --- Makefile | 13 +++---------- tools/build-libssh2.sh | 43 ++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 46 insertions(+), 10 deletions(-) create mode 100755 tools/build-libssh2.sh diff --git a/Makefile b/Makefile index 2049fde..19bde08 100644 --- a/Makefile +++ b/Makefile @@ -16,7 +16,8 @@ BUILD := build # headers and curl). BUNDLE_LIBSSH2=yes|no overrides the check. LIBSSH2_VER := 1.11.1 LIBSSH2_SHA256 := d9ec76cbe34db98eec3539fe2c899d26b0c837cb3eb466a56b0f109cabf658f7 -LIBSSH2_DIR := deps/libssh2-$(LIBSSH2_VER) +# Named after the OpenSSL it was built against, so it is rebuilt when that changes. +LIBSSH2_DIR := deps/libssh2-$(LIBSSH2_VER)-openssl$(shell pkg-config --modversion libssl 2>/dev/null) BUNDLE_LIBSSH2 ?= $(shell pkg-config --atleast-version=1.11 libssh2 2>/dev/null && echo no || echo yes) ifeq ($(BUNDLE_LIBSSH2),yes) @@ -63,15 +64,7 @@ $(BUILD)/schema.h: schema.sql | $(BUILD) # Kept outside $(BUILD) so "make clean" (run by install.sh) does not download it again. $(LIBSSH2_DIR)/lib/libssh2.a: | check-deps @echo "system libssh2 is older than 1.11; building libssh2 $(LIBSSH2_VER) (static)" - rm -rf deps/src && mkdir -p deps/src - curl -fsSL --max-filesize 20000000 -o deps/src/libssh2.tar.gz \ - https://libssh2.org/download/libssh2-$(LIBSSH2_VER).tar.gz - echo "$(LIBSSH2_SHA256) deps/src/libssh2.tar.gz" | sha256sum -c - - tar -xzf deps/src/libssh2.tar.gz -C deps/src - cd deps/src/libssh2-$(LIBSSH2_VER) && ./configure --quiet --prefix="$(abspath $(LIBSSH2_DIR))" \ - --disable-shared --enable-static --with-pic --with-crypto=openssl --without-libz \ - --disable-examples-build --disable-docker-tests --disable-sshd-tests && $(MAKE) && $(MAKE) install - rm -rf deps/src + tools/build-libssh2.sh $(LIBSSH2_VER) $(LIBSSH2_SHA256) "$(abspath $(LIBSSH2_DIR))" $(BUILD)/%.o: $(SRC)/%.c $(wildcard $(SRC)/*.h) $(BUILD)/schema.h $(LIBSSH2_A) | $(BUILD) check-deps $(CC) $(CFLAGS) $(PKG_CFLAGS) -I$(BUILD) -c -o $@ $< diff --git a/tools/build-libssh2.sh b/tools/build-libssh2.sh new file mode 100755 index 0000000..5bb8210 --- /dev/null +++ b/tools/build-libssh2.sh @@ -0,0 +1,43 @@ +#!/bin/sh +# Builds a static libssh2 for the Makefile when the system one is too old. +# Usage: tools/build-libssh2.sh +# +# libssh2 is compiled against the OpenSSL that pkg-config reports, which is +# also the one patchbayd links. Another OpenSSL in /usr/local would otherwise +# shadow its headers (the compiler searches /usr/local/include first, and -I +# cannot move system directories ahead), leaving OpenSSL 3 calls in libssh2 +# that the system OpenSSL 1.1 libraries do not have. +set -eu + +ver=$1 +sha=$2 +prefix=$3 +work=deps/src + +rm -rf "$work" +mkdir -p "$work" +curl -fsSL --max-filesize 20000000 -o "$work/libssh2.tar.gz" "https://libssh2.org/download/libssh2-$ver.tar.gz" +echo "$sha $work/libssh2.tar.gz" | sha256sum -c - +tar -xzf "$work/libssh2.tar.gz" -C "$work" + +# must resolve to the reported OpenSSL only: stage symlinks to +# its header directories (Debian keeps opensslconf.h in a multiarch one). +inc=$(pkg-config --variable=includedir libssl) +arch=$(${CC:-cc} -print-multiarch 2>/dev/null || true) +flags="" +for d in "$inc" ${arch:+"$inc/$arch"}; do + [ -d "$d/openssl" ] || continue + stage="$PWD/$work/inc$(echo "$d" | tr / _)" + mkdir -p "$stage" + ln -s "$d/openssl" "$stage/openssl" + flags="$flags -I$stage" +done + +cd "$work/libssh2-$ver" +./configure --quiet --prefix="$prefix" --disable-shared --enable-static --with-pic \ + --with-crypto=openssl --without-libz --disable-examples-build --disable-docker-tests --disable-sshd-tests \ + CPPFLAGS="$flags $(pkg-config --cflags libssl)" LDFLAGS="$(pkg-config --libs-only-L libssl)" +make +make install +cd - >/dev/null +rm -rf "$work"