openssh.mk 4.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145
  1. ################################################################################
  2. #
  3. # openssh
  4. #
  5. ################################################################################
  6. OPENSSH_VERSION_MAJOR = 9.7
  7. OPENSSH_VERSION_MINOR = p1
  8. OPENSSH_VERSION = $(OPENSSH_VERSION_MAJOR)$(OPENSSH_VERSION_MINOR)
  9. OPENSSH_CPE_ID_VERSION = $(OPENSSH_VERSION_MAJOR)
  10. OPENSSH_CPE_ID_UPDATE = $(OPENSSH_VERSION_MINOR)
  11. OPENSSH_SITE = http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable
  12. OPENSSH_LICENSE = BSD-3-Clause, BSD-2-Clause, Public Domain
  13. OPENSSH_LICENSE_FILES = LICENCE
  14. # 0001-Improve-detection-of-fzero-call-used-regs-used.patch
  15. OPENSSH_AUTORECONF = YES
  16. # 0002-sshsigdie-async-signal-unsafe.patch
  17. OPENSSH_IGNORE_CVES += CVE-2024-6387
  18. OPENSSH_CONF_ENV = \
  19. LD="$(TARGET_CC)" \
  20. LDFLAGS="$(TARGET_CFLAGS)" \
  21. LIBS=`$(PKG_CONFIG_HOST_BINARY) --libs openssl`
  22. OPENSSH_CPE_ID_VENDOR = openbsd
  23. OPENSSH_CONF_OPTS = \
  24. --sysconfdir=/etc/ssh \
  25. --with-default-path=$(BR2_SYSTEM_DEFAULT_PATH) \
  26. $(if $(BR2_PACKAGE_OPENSSH_SANDBOX),--with-sandbox,--without-sandbox) \
  27. --disable-lastlog \
  28. --disable-utmp \
  29. --disable-utmpx \
  30. --disable-wtmp \
  31. --disable-wtmpx \
  32. --disable-strip
  33. OPENSSH_SELINUX_MODULES = ssh
  34. define OPENSSH_PERMISSIONS
  35. /var/empty d 755 root root - - - - -
  36. endef
  37. ifeq ($(BR2_TOOLCHAIN_HAS_GCC_BUG_110934),y)
  38. OPENSSH_CONF_OPTS += --without-hardening
  39. endif
  40. ifeq ($(BR2_TOOLCHAIN_SUPPORTS_PIE),)
  41. OPENSSH_CONF_OPTS += --without-pie
  42. endif
  43. OPENSSH_DEPENDENCIES = host-pkgconf zlib openssl
  44. ifeq ($(BR2_PACKAGE_CRYPTODEV_LINUX),y)
  45. OPENSSH_DEPENDENCIES += cryptodev-linux
  46. OPENSSH_CONF_OPTS += --with-ssl-engine
  47. else
  48. OPENSSH_CONF_OPTS += --without-ssl-engine
  49. endif
  50. ifeq ($(BR2_PACKAGE_AUDIT),y)
  51. OPENSSH_DEPENDENCIES += audit
  52. OPENSSH_CONF_OPTS += --with-audit=linux
  53. else
  54. OPENSSH_CONF_OPTS += --without-audit
  55. endif
  56. ifeq ($(BR2_PACKAGE_LINUX_PAM),y)
  57. define OPENSSH_INSTALL_PAM_CONF
  58. $(INSTALL) -D -m 644 $(@D)/contrib/sshd.pam.generic $(TARGET_DIR)/etc/pam.d/sshd
  59. $(SED) '\%password required /lib/security/pam_cracklib.so%d' $(TARGET_DIR)/etc/pam.d/sshd
  60. $(SED) 's/\#UsePAM no/UsePAM yes/' $(TARGET_DIR)/etc/ssh/sshd_config
  61. endef
  62. OPENSSH_DEPENDENCIES += linux-pam
  63. OPENSSH_CONF_OPTS += --with-pam
  64. OPENSSH_POST_INSTALL_TARGET_HOOKS += OPENSSH_INSTALL_PAM_CONF
  65. else
  66. OPENSSH_CONF_OPTS += --without-pam
  67. endif
  68. ifeq ($(BR2_PACKAGE_LIBSELINUX),y)
  69. OPENSSH_DEPENDENCIES += libselinux
  70. OPENSSH_CONF_OPTS += --with-selinux
  71. else
  72. OPENSSH_CONF_OPTS += --without-selinux
  73. endif
  74. ifeq ($(BR2_PACKAGE_SYSTEMD_SYSUSERS),y)
  75. define OPENSSH_INSTALL_SYSTEMD_SYSUSERS
  76. $(INSTALL) -m 0644 -D package/openssh/sshd-sysusers.conf \
  77. $(TARGET_DIR)/usr/lib/sysusers.d/sshd.conf
  78. endef
  79. else
  80. define OPENSSH_USERS
  81. sshd -1 sshd -1 * /var/empty - - SSH drop priv user
  82. endef
  83. endif
  84. # Let the default install rule only install the configuration file.
  85. # The programs will be installed based on the config options selected.
  86. OPENSSH_INSTALL_TARGET_OPTS = DESTDIR=$(TARGET_DIR) install-sysconf
  87. ifeq ($(BR2_PACKAGE_OPENSSH_CLIENT),y)
  88. define OPENSSH_INSTALL_CLIENT_PROGRAMS
  89. $(INSTALL) -D -m 0755 $(@D)/ssh $(TARGET_DIR)/usr/bin/ssh
  90. $(INSTALL) -D -m 0755 $(@D)/scp $(TARGET_DIR)/usr/bin/scp
  91. $(INSTALL) -D -m 0755 $(@D)/sftp $(TARGET_DIR)/usr/bin/sftp
  92. $(INSTALL) -D -m 0755 $(@D)/ssh-agent $(TARGET_DIR)/usr/bin/ssh-agent
  93. $(INSTALL) -D -m 0755 $(@D)/ssh-add $(TARGET_DIR)/usr/bin/ssh-add
  94. $(INSTALL) -D -m 4711 $(@D)/ssh-keysign $(TARGET_DIR)/usr/libexec/ssh-keysign
  95. $(INSTALL) -D -m 0755 $(@D)/ssh-pkcs11-helper $(TARGET_DIR)/usr/libexec/ssh-pkcs11-helper
  96. $(INSTALL) -D -m 0755 $(@D)/contrib/ssh-copy-id $(TARGET_DIR)/usr/bin/ssh-copy-id
  97. endef
  98. OPENSSH_POST_INSTALL_TARGET_HOOKS += OPENSSH_INSTALL_CLIENT_PROGRAMS
  99. endif
  100. ifeq ($(BR2_PACKAGE_OPENSSH_SERVER),y)
  101. define OPENSSH_INSTALL_SERVER_PROGRAMS
  102. $(INSTALL) -D -m 0755 $(@D)/sshd $(TARGET_DIR)/usr/sbin/sshd
  103. $(INSTALL) -D -m 0755 $(@D)/sftp-server $(TARGET_DIR)/usr/libexec/sftp-server
  104. endef
  105. OPENSSH_POST_INSTALL_TARGET_HOOKS += OPENSSH_INSTALL_SERVER_PROGRAMS
  106. define OPENSSH_INSTALL_INIT_SYSTEMD
  107. $(INSTALL) -D -m 644 package/openssh/sshd.service \
  108. $(TARGET_DIR)/usr/lib/systemd/system/sshd.service
  109. $(OPENSSH_INSTALL_SYSTEMD_SYSUSERS)
  110. endef
  111. define OPENSSH_INSTALL_INIT_SYSV
  112. $(INSTALL) -D -m 755 package/openssh/S50sshd \
  113. $(TARGET_DIR)/etc/init.d/S50sshd
  114. endef
  115. endif
  116. ifeq ($(BR2_PACKAGE_OPENSSH_KEY_UTILS),y)
  117. define OPENSSH_INSTALL_KEY_UTILS
  118. $(INSTALL) -D -m 0755 $(@D)/ssh-keygen $(TARGET_DIR)/usr/bin/ssh-keygen
  119. $(INSTALL) -D -m 0755 $(@D)/ssh-keyscan $(TARGET_DIR)/usr/bin/ssh-keyscan
  120. endef
  121. OPENSSH_POST_INSTALL_TARGET_HOOKS += OPENSSH_INSTALL_KEY_UTILS
  122. endif
  123. $(eval $(autotools-package))