diff --git a/0001-Update-OpenSSL-API-usage-in-pkcs11-util.patch b/0001-Update-OpenSSL-API-usage-in-pkcs11-util.patch new file mode 100644 index 0000000..8ef4095 --- /dev/null +++ b/0001-Update-OpenSSL-API-usage-in-pkcs11-util.patch @@ -0,0 +1,56 @@ +From 8778e08f3d9e9a924c814f54c47d7f766d370859 Mon Sep 17 00:00:00 2001 +From: Simo Sorce +Date: Fri, 17 Apr 2026 12:22:22 -0400 +Subject: [PATCH] Update OpenSSL API usage in pkcs11-util + +Replace direct accesses to ASN1_STRING internal fields (data and length) with +the official OpenSSL accessor functions, and update an X509_NAME pointer to be +const. This ensures compatibility with newer OpenSSL versions that make these +structures opaque and strictly enforce const correctness. + +Co-authored-by: Gemini +Signed-off-by: Simo Sorce +--- + src/sbsign/sbsign.c | 3 +-- + src/shared/pkcs11-util.c | 4 ++-- + 2 files changed, 3 insertions(+), 4 deletions(-) + +diff --git a/src/sbsign/sbsign.c b/src/sbsign/sbsign.c +index d13dc5e..ebbda17 100644 +--- a/src/sbsign/sbsign.c ++++ b/src/sbsign/sbsign.c +@@ -262,8 +262,7 @@ static int spc_indirect_data_content_new(const void *digest, size_t digestsz, ui + return log_error_errno(SYNTHETIC_ERRNO(EIO), "Failed to get SpcPeImageData object: %s", + ERR_error_string(ERR_get_error(), NULL)); + +- idc->data->value->value.sequence->data = TAKE_PTR(peidraw); +- idc->data->value->value.sequence->length = peidrawsz; ++ ASN1_STRING_set0(idc->data->value->value.sequence, TAKE_PTR(peidraw), peidrawsz); + idc->messageDigest->digestAlgorithm->algorithm = OBJ_nid2obj(NID_sha256); + if (!idc->messageDigest->digestAlgorithm->algorithm) + return log_error_errno(SYNTHETIC_ERRNO(EIO), "Failed to get SHA256 object: %s", +diff --git a/src/shared/pkcs11-util.c b/src/shared/pkcs11-util.c +index 3062bcc..c2f5ba2 100644 +--- a/src/shared/pkcs11-util.c ++++ b/src/shared/pkcs11-util.c +@@ -554,7 +554,7 @@ int pkcs11_token_read_public_key( + return log_debug_errno(SYNTHETIC_ERRNO(EIO), "Failed to init an EVP_PKEY_CTX for EC."); + + OSSL_PARAM ec_params[8] = { +- OSSL_PARAM_octet_string(OSSL_PKEY_PARAM_PUB_KEY, os->data, os->length) ++ OSSL_PARAM_octet_string(OSSL_PKEY_PARAM_PUB_KEY, (void*) ASN1_STRING_get0_data(os), ASN1_STRING_length(os)) + }; + + _cleanup_free_ void *order = NULL, *p = NULL, *a = NULL, *b = NULL, *generator = NULL; +@@ -663,7 +663,7 @@ int pkcs11_token_read_x509_certificate( + }; + CK_RV rv; + _cleanup_(X509_freep) X509 *x509 = NULL; +- X509_NAME *name = NULL; ++ const X509_NAME *name = NULL; + int r; + + r = dlopen_p11kit(); +-- +2.53.0 + diff --git a/systemd.spec b/systemd.spec index 5ef1613..4452925 100644 --- a/systemd.spec +++ b/systemd.spec @@ -152,6 +152,9 @@ Patch: 38769.patch # Workaround for https://bugzilla.redhat.com/show_bug.cgi?id=2415701 Patch: 0002-machined-continue-without-resolve.hook-socket.patch +# Openssl 4 build fixes +Patch: 0001-Update-OpenSSL-API-usage-in-pkcs11-util.patch + %endif %ifarch %{ix86} x86_64 aarch64 riscv64