blob: 4923f686850d052c1e57d41a75051232b10b8692 [file] [log] [blame]
Andrew Geissler82c905d2020-04-13 13:39:40 -05001SUMMARY = "Mozilla's SSL and TLS implementation"
2DESCRIPTION = "Network Security Services (NSS) is a set of libraries \
3designed to support cross-platform development of \
4security-enabled client and server applications. \
5Applications built with NSS can support SSL v2 and v3, \
6TLS, PKCS 5, PKCS 7, PKCS 11, PKCS 12, S/MIME, X.509 \
7v3 certificates, and other security standards."
8HOMEPAGE = "http://www.mozilla.org/projects/security/pki/nss/"
9SECTION = "libs"
10
11DEPENDS = "sqlite3 nspr zlib nss-native"
12DEPENDS_class-native = "sqlite3-native nspr-native zlib-native"
13
14LICENSE = "MPL-2.0 | (MPL-2.0 & GPL-2.0+) | (MPL-2.0 & LGPL-2.1+)"
15
16LIC_FILES_CHKSUM = "file://nss/COPYING;md5=3b1e88e1b9c0b5a4b2881d46cce06a18 \
17 file://nss/lib/freebl/mpi/doc/LICENSE;md5=491f158d09d948466afce85d6f1fe18f \
18 file://nss/lib/freebl/mpi/doc/LICENSE-MPL;md5=5d425c8f3157dbf212db2ec53d9e5132"
19
20VERSION_DIR = "${@d.getVar('BP').upper().replace('-', '_').replace('.', '_') + '_RTM'}"
21
22SRC_URI = "http://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/${VERSION_DIR}/src/${BP}.tar.gz \
23 file://nss.pc.in \
24 file://signlibs.sh \
25 file://0001-nss-fix-support-cross-compiling.patch \
26 file://nss-no-rpath-for-cross-compiling.patch \
27 file://nss-fix-incorrect-shebang-of-perl.patch \
28 file://disable-Wvarargs-with-clang.patch \
29 file://pqg.c-ULL_addend.patch \
30 file://blank-cert9.db \
31 file://blank-key4.db \
32 file://system-pkcs11.txt \
33 file://nss-fix-nsinstall-build.patch \
34 file://0001-freebl-add-a-configure-option-to-disable-ARM-HW-cryp.patch \
Andrew Geissler82c905d2020-04-13 13:39:40 -050035 "
36
Andrew Geissler748a4832020-07-24 16:24:21 -050037SRC_URI[sha256sum] = "dab18bbfcf5e347934cda664df75ce9fd912a5772686c40d3c805e53c08d6e43"
Andrew Geissler82c905d2020-04-13 13:39:40 -050038
39UPSTREAM_CHECK_URI = "https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_Releases"
40UPSTREAM_CHECK_REGEX = "NSS_(?P<pver>.+)_release_notes"
41
42inherit siteinfo
43
44TD = "${S}/tentative-dist"
45TDS = "${S}/tentative-dist-staging"
46
Andrew Geissler7f40b712020-05-15 14:09:53 -050047# cortex-a55 is ARMv8.2-a based but libatomic explicitly asks for -march=armv8.1-a
48# which caused -march conflicts in gcc
49TUNE_CCARGS_remove = "-mcpu=cortex-a55+crc -mcpu=cortex-a55 -mcpu=cortex-a55+crc+crypto"
50
Andrew Geissler82c905d2020-04-13 13:39:40 -050051TARGET_CC_ARCH += "${LDFLAGS}"
52
53do_configure_prepend_libc-musl () {
54 sed -i -e '/-DHAVE_SYS_CDEFS_H/d' ${S}/nss/lib/dbm/config/config.mk
55}
56
57do_compile_prepend_class-native() {
58 export NSPR_INCLUDE_DIR=${STAGING_INCDIR_NATIVE}/nspr
59 export NSPR_LIB_DIR=${STAGING_LIBDIR_NATIVE}
60 export NSS_ENABLE_WERROR=0
61}
62
63do_compile_prepend_class-nativesdk() {
64 export LDFLAGS=""
65}
66
67do_compile_prepend_class-native() {
68 # Need to set RPATH so that chrpath will do its job correctly
69 RPATH="-Wl,-rpath-link,${STAGING_LIBDIR_NATIVE} -Wl,-rpath-link,${STAGING_BASE_LIBDIR_NATIVE} -Wl,-rpath,${STAGING_LIBDIR_NATIVE} -Wl,-rpath,${STAGING_BASE_LIBDIR_NATIVE}"
70}
71
72do_compile() {
73 export NSPR_INCLUDE_DIR=${STAGING_INCDIR}/nspr
74
75 export CROSS_COMPILE=1
76 export NATIVE_CC="${BUILD_CC}"
77 # Additional defines needed on Centos 7
78 export NATIVE_FLAGS="${BUILD_CFLAGS} -DLINUX -Dlinux"
79 export BUILD_OPT=1
80
81 export FREEBL_NO_DEPEND=1
82 export FREEBL_LOWHASH=1
83
84 export LIBDIR=${libdir}
85 export MOZILLA_CLIENT=1
86 export NS_USE_GCC=1
87 export NSS_USE_SYSTEM_SQLITE=1
88 export NSS_ENABLE_ECC=1
89
90 ${@bb.utils.contains("TUNE_FEATURES", "crypto", "export NSS_USE_ARM_HW_CRYPTO=1", "", d)}
91
92 export OS_RELEASE=3.4
93 export OS_TARGET=Linux
94 export OS_ARCH=Linux
95
96 if [ "${TARGET_ARCH}" = "powerpc" ]; then
97 OS_TEST=ppc
98 elif [ "${TARGET_ARCH}" = "powerpc64" ]; then
99 OS_TEST=ppc64
100 elif [ "${TARGET_ARCH}" = "mips" -o "${TARGET_ARCH}" = "mipsel" -o "${TARGET_ARCH}" = "mips64" -o "${TARGET_ARCH}" = "mips64el" ]; then
101 OS_TEST=mips
102 elif [ "${TARGET_ARCH}" = "aarch64_be" ]; then
103 OS_TEST="aarch64"
104 else
105 OS_TEST="${TARGET_ARCH}"
106 fi
107
108 if [ "${SITEINFO_BITS}" = "64" ]; then
109 export USE_64=1
110 elif [ "${TARGET_ARCH}" = "x86_64" -a "${SITEINFO_BITS}" = "32" ]; then
111 export USE_X32=1
112 fi
113
114 export NSS_DISABLE_GTESTS=1
115
116 # We can modify CC in the environment, but if we set it via an
117 # argument to make, nsinstall, a host program, will also build with it!
118 #
119 # nss pretty much does its own thing with CFLAGS, so we put them into CC.
120 # Optimization will get clobbered, but most of the stuff will survive.
121 # The motivation for this is to point to the correct place for debug
122 # source files and CFLAGS does that. Nothing uses CCC.
123 #
124 export CC="${CC} ${CFLAGS}"
125 make -C ./nss CCC="${CXX} -g" \
126 OS_TEST=${OS_TEST} \
Andrew Geissler748a4832020-07-24 16:24:21 -0500127 RPATH="${RPATH}" \
128 autobuild
Andrew Geissler82c905d2020-04-13 13:39:40 -0500129}
130
131do_compile[vardepsexclude] += "SITEINFO_BITS"
132
133do_install_prepend_class-nativesdk() {
134 export LDFLAGS=""
135}
136
137do_install() {
138 export CROSS_COMPILE=1
139 export NATIVE_CC="${BUILD_CC}"
140 export BUILD_OPT=1
141
142 export FREEBL_NO_DEPEND=1
143
144 export LIBDIR=${libdir}
145 export MOZILLA_CLIENT=1
146 export NS_USE_GCC=1
147 export NSS_USE_SYSTEM_SQLITE=1
148 export NSS_ENABLE_ECC=1
149
150 export OS_RELEASE=3.4
151 export OS_TARGET=Linux
152 export OS_ARCH=Linux
153
154 if [ "${TARGET_ARCH}" = "powerpc" ]; then
155 OS_TEST=ppc
156 elif [ "${TARGET_ARCH}" = "powerpc64" ]; then
157 OS_TEST=ppc64
158 elif [ "${TARGET_ARCH}" = "mips" -o "${TARGET_ARCH}" = "mipsel" -o "${TARGET_ARCH}" = "mips64" -o "${TARGET_ARCH}" = "mips64el" ]; then
159 OS_TEST=mips
160 elif [ "${TARGET_ARCH}" = "aarch64_be" ]; then
161 CPU_ARCH=aarch64
162 OS_TEST="aarch64"
163 else
164 OS_TEST="${TARGET_ARCH}"
165 fi
166 if [ "${SITEINFO_BITS}" = "64" ]; then
167 export USE_64=1
168 elif [ "${TARGET_ARCH}" = "x86_64" -a "${SITEINFO_BITS}" = "32" ]; then
169 export USE_X32=1
170 fi
171
172 export NSS_DISABLE_GTESTS=1
173
174 make -C ./nss \
175 CCC="${CXX}" \
176 OS_TEST=${OS_TEST} \
177 SOURCE_LIB_DIR="${TD}/${libdir}" \
178 SOURCE_BIN_DIR="${TD}/${bindir}" \
179 install
180
181 install -d ${D}/${libdir}/
182 for file in ${S}/dist/*.OBJ/lib/*.so; do
183 echo "Installing `basename $file`..."
184 cp $file ${D}/${libdir}/
185 done
186
187 for shared_lib in ${TD}/${libdir}/*.so.*; do
188 if [ -f $shared_lib ]; then
189 cp $shared_lib ${D}/${libdir}
190 ln -sf $(basename $shared_lib) ${D}/${libdir}/$(basename $shared_lib .1oe)
191 fi
192 done
193 for shared_lib in ${TD}/${libdir}/*.so; do
194 if [ -f $shared_lib -a ! -e ${D}/${libdir}/$shared_lib ]; then
195 cp $shared_lib ${D}/${libdir}
196 fi
197 done
198
199 install -d ${D}/${includedir}/nss3
200 install -m 644 -t ${D}/${includedir}/nss3 dist/public/nss/*
201
202 install -d ${D}/${bindir}
203 for binary in ${TD}/${bindir}/*; do
204 install -m 755 -t ${D}/${bindir} $binary
205 done
206}
207
208do_install[vardepsexclude] += "SITEINFO_BITS"
209
210do_install_append() {
211 # Create empty .chk files for the NSS libraries at build time. They could
212 # be regenerated at target's boot time.
213 for file in libsoftokn3.chk libfreebl3.chk libnssdbm3.chk; do
214 touch ${D}/${libdir}/$file
215 chmod 755 ${D}/${libdir}/$file
216 done
217 install -D -m 755 ${WORKDIR}/signlibs.sh ${D}/${bindir}/signlibs.sh
218
219 install -d ${D}${libdir}/pkgconfig/
220 sed 's/%NSS_VERSION%/${PV}/' ${WORKDIR}/nss.pc.in | sed 's/%NSPR_VERSION%/4.9.2/' > ${D}${libdir}/pkgconfig/nss.pc
221 sed -i s:OEPREFIX:${prefix}:g ${D}${libdir}/pkgconfig/nss.pc
222 sed -i s:OEEXECPREFIX:${exec_prefix}:g ${D}${libdir}/pkgconfig/nss.pc
223 sed -i s:OELIBDIR:${libdir}:g ${D}${libdir}/pkgconfig/nss.pc
224 sed -i s:OEINCDIR:${includedir}/nss3:g ${D}${libdir}/pkgconfig/nss.pc
225}
226
227do_install_append_class-target() {
228 # It used to call certutil to create a blank certificate with empty password at
229 # build time, but the checksum of key4.db changes every time when certutil is called.
230 # It causes non-determinism issue, so provide databases with a blank certificate
231 # which are originally from output of nss in qemux86-64 build. You can get these
232 # databases by:
233 # certutil -N -d sql:/database/path/ --empty-password
234 install -d ${D}${sysconfdir}/pki/nssdb/
235 install -m 0644 ${WORKDIR}/blank-cert9.db ${D}${sysconfdir}/pki/nssdb/cert9.db
236 install -m 0644 ${WORKDIR}/blank-key4.db ${D}${sysconfdir}/pki/nssdb/key4.db
237 install -m 0644 ${WORKDIR}/system-pkcs11.txt ${D}${sysconfdir}/pki/nssdb/pkcs11.txt
238}
239
240PACKAGE_WRITE_DEPS += "nss-native"
241pkg_postinst_${PN} () {
242 if [ -n "$D" ]; then
243 for I in $D${libdir}/lib*.chk; do
244 DN=`dirname $I`
245 BN=`basename $I .chk`
246 FN=$DN/$BN.so
247 shlibsign -i $FN
248 if [ $? -ne 0 ]; then
249 exit 1
250 fi
251 done
252 else
253 signlibs.sh
254 fi
255}
256
257PACKAGES =+ "${PN}-smime"
258FILES_${PN}-smime = "\
259 ${bindir}/smime \
260"
261
262FILES_${PN} = "\
263 ${sysconfdir} \
264 ${bindir} \
265 ${libdir}/lib*.chk \
266 ${libdir}/lib*.so \
267 "
268
269FILES_${PN}-dev = "\
270 ${libdir}/nss \
271 ${libdir}/pkgconfig/* \
272 ${includedir}/* \
273 "
274
275RDEPENDS_${PN}-smime = "perl"
276
277BBCLASSEXTEND = "native nativesdk"