python / python/cpython

OpenSSL configure API checks use the wrong library order for dependencies in LIBS

Aperta
#157,755 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

build topic-SSL type-bug
Lingua principale
Python
Stelle
77.2k
Fork
35.9k
Metriche di merge delle PR
Metriche PR in attesa

Descrizione

Bug description:

The OpenSSL API checks in configure.ac put LIBS before OPENSSL_LIBS and LIBCRYPTO_LIBS. When static OpenSSL depends on a library supplied through LIBS, the linker can encounter the dependency before the archive that references it. The API checks then fail and _ssl / _hashlib are marked as missing.

This is inconsistent with the initial AX_CHECK_OPENSSL link check, which already puts OPENSSL_LIBS before LIBS and succeeds with the same inputs.

Reproduction

Use a static OpenSSL build with zlib enabled (Configure linux-x86_64 no-shared no-tests zlib, with the zlib include/library paths supplied), and a static zlib archive. From an empty CPython build directory:

# Set these to the installed libraries and CPython source tree.
openssl_prefix=/path/to/openssl-zlib
openssl_libdir="$openssl_prefix/lib64"
zlib_archive=/path/to/libz.a
cpython_source=/path/to/cpython

PKG_CONFIG=/bin/false \
LDFLAGS="-L$openssl_libdir" \
LIBS="$zlib_archive" \
"$cpython_source/configure" \
    --with-openssl="$openssl_prefix" \
    --without-ensurepip

Use lib instead of lib64 if appropriate for the OpenSSL installation. Disabling pkg-config here exercises manually supplied dependency flags rather than having pkg-config supply the transitive libraries.

Actual result:

checking whether compiling and linking against OpenSSL works... yes
checking whether OpenSSL provides required ssl module APIs... no
checking whether OpenSSL provides required hashlib module APIs... no
checking for stdlib extension module _ssl... missing
checking for stdlib extension module _hashlib... missing

The failing SSL probe links in this order (paths abbreviated):

gcc ... conftest.c -ldl /path/to/libz.a -lssl -lcrypto
libcrypto.a(libcrypto-lib-c_zlib.o): undefined reference to `inflate'
libcrypto.a(libcrypto-lib-c_zlib.o): undefined reference to `deflate'

Expected: both API checks succeed. Moving the OpenSSL libraries before LIBS fixes both checks with otherwise identical inputs:

-  LIBS="$LIBS $OPENSSL_LIBS"
+  LIBS="$OPENSSL_LIBS $LIBS"

-  LIBS="$LIBS $LIBCRYPTO_LIBS"
+  LIBS="$LIBCRYPTO_LIBS $LIBS"

After regenerating configure with Autoconf 2.72, both API checks and both module configuration results become yes. The unmodified source also passes with ordinary static OpenSSL built without zlib, so this is specific to dependency ordering, not all static OpenSSL configurations.

CPython versions tested on:

CPython main branch, 3.13.15

Operating systems tested on:

main branch on Linux (WSL Ubuntu), 3.13.15 on all vcpkg ci https://github.com/microsoft/vcpkg/pull/53840

Linked PRs
  • gh-157756

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Direzione di ricerca

Inizia in configure.ac, nei controlli dell’API OpenSSL, e confronta l’ordinamento delle relative librerie con quello del controllo di collegamento iniziale di AX_CHECK_OPENSSL. Riproduci il comando configure per OpenSSL statico con zlib, rigenera configure con Autoconf 2.72 e verifica che sia i controlli dell’API sia i controlli dei moduli _ssl e _hashlib riportino esito positivo.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
c, python
Ambito
build-system
Tipo di issue
Bug
Difficoltà
2/5
Tempo stimato
Mezza giornata
Stato di attività
Ferma
Chiarezza
Specificata chiaramente
Idoneità per principianti
35/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.