meta-wolfssl/recipes-connectivity
Zackery 9eb5563329
Refactor finalization (#149)
* Refactor meta-wolfssl: modularize feature enablement and centralize helpers in bbclass

Refactored layer.conf to unconditionally include all recipes, moved feature-specific configuration into modular .inc files, created wolfssl-helper.bbclass with reusable do_wolfssl_autogen and do_wolfssl_check_package tasks, updated all recipes to use the new pattern, and standardized commercial license variables to be recipe-specific.

Use a virtual wolfssl to make library switching easier for fips vs non fips or other wolfSSL packages

Set wolfssl libraries as the deafualt weak Preferred_Provider option for packages

* Merged refactor and new test changes

* Combine refactor changes and add replace default and fips modes

* Add working and tested fips, replace default, non-fips, non-replace-default work

* Add FIPS replace default to layers and test all options

* Refactor bbappends to be more yocto like

* Add overide to openssl configure

* Address comment concerns

* Only do neccesary simlinks

* Only do neccesary simlinks

* Convert wolfprovider test bbappend to inc file

* Add Image minimals for all wolfprovider modes

* Fully tested images

* Get conf files from source

* Fix FIPS package issues

* Fixes 7z extraction issues, mostly around using password when the
  password has already been stripped out
* Fixes autoreconf and configure issues with the FIPS package
* Fixes wolfcrypttest and wolfcryptbenchmark not being isntalled with
  FIPS when they are selected

* Fix unstable meta data for fips package

* Fix the execution command for QEMU

The execution of QEMU to get the hash would fail when cross-compiling to
a different CPU target. This fixes it.

* gnutls-wolfssl layers

Added 3 layers
- gnutls: gnutls fork patched to use wolfssl as cryptographic
  provider
- wolfssl: wolfssl configured to work against gnutls
- wolfssl-gnutls-wrapper: shim layer that gets called by gnutls
  applications when linked against gnutls-wolfssl
- gnutls-wolfssl-tests: tests from the wolfssl-gnutls-wrapper folder
  installed under /usr/lib/wolfssl-gnutls-wrapper/

Everything gets installed under /usr ovverriding the system installed
recipes, the wrapper is symlinked in /opt.
Fips currently not supported.

* fips support

* Removed hmac generation and installation since this step is already
happening on the base recipe

* gnutls layers (from https://github.com/wolfSSL/meta-wolfssl/pull/111/)
rebased against the new staging branch (refactor-meta-wolfssl)

* - added gnutls-image-minimal;
- update layer.conf to conditionally include gnutls-image-minimal if
  included in the WOLFSSL_DEMOS;
- minor update to inc/gnutls/gnutls-enable-wolfssl.inc to by pass the
  fuzzing binaries from the base recipes;

* added do_configure[network] = "1" to the inc file (fixes networking issues on
some builds)

* Add support for GCP and tarballs

The commercial package can now be retrieved from GCP and can be a
tarball without password protection.

* fix stamp.h in append rather than main .bb

* Update wolfprovider include files with local changes

* Add messages for debug files

* Follow Debian convention for provider config in openssl.cnf

- Install provider*.conf files to /etc/ssl/openssl.cnf.d/ instead of /opt
- Remove OPENSSL_CONF environment variable approach
- Add .include directive to openssl.cnf automatically in explicit load mode
- This allows OpenSSL to automatically load the provider configuration
- Update script output to reflect the new approach

* Append conf fil

* Don't use fixed version for FIPS

User can use any FIPS wolfSSL package

* Fix naming for new fips rename

* Add final wolfprovider refactor changes

* Benchmark and GPG Error Patch to resolve build issues and disable benchmarking due to length of time it takes to run AES GCM in current port

* Fixes for when GNUPG is needed

* Update wolfProvider images to match other demo images,
add to bbclass to ensure configurations are not added
to reciepes automatically.

* Fips Image for reference

* Fix openssl target detection

This was not working properly on an ARM64 build.

* Add symlink in ossl-modules, install provider.conf from main module

* Remove debug for wolfprovider

* Add fix for loading conf in wolfproviderenv

* linuxkm: add non-FIPS kernel module recipe and initramfs integration class

This introduces support for building the wolfSSL Linux kernel module (linuxkm)
in non-FIPS configurations and adds a generic bbclass for including the module
in any initramfs image.

Key additions:
 - New recipe: wolfssl-linuxkm.bb (non-FIPS)
   * Builds linuxkm against the target kernel
   * Installs libwolfssl.ko into /lib/modules/.../extra
   * Adds auto-load entry under /etc/modules-load.d/
   * Tracks upstream wolfSSL master at commit 3062d1524

 - New class: wolfssl-initramfs.bbclass
   * Allows any initramfs image to include the linuxkm module
   * Intended to be inherited from BSP/distro override layers

This prepares the layer for future FIPS/non-FIPS split support and provides
a clean mechanism for systems that need early-boot availability of the
wolfSSL kernel module.

Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com>

* Add openssl ptest patch

* Fix openssl patch

* linuxkm: update to latest commit to include randomness changes for Tegra kernel

Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com>

* Add wolfssl-kernel-random.bbclass for kernel randomness patches

Bbclass to apply wolfSSL DRBG callback hooks to Linux kernel.
Fetches patches from wolfSSL GitHub, works with any kernel flavor.

Usage in kernel bbappend:
  inherit wolfssl-kernel-random
  WOLFSSL_KERNEL_RANDOM_PATCH = "5.17-ubuntu-jammy-tegra"

Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com>

* Add curl ptest patch

* Make RD and FIPS detection more robust

* Refactor to handle all cases

* Wrong file location for curl .inc

* - Updated gnutls to point to the 3.8.11 branch to get the 3.8.11 version
  of gnutls-wolfssl (https://github.com/wolfSSL/gnutls/tree/gnutls-wolfssl-3.8.11);
- added nettle 3.10 recipe, gnutls depends on nettle to be >= 3.10;
- removed conditional bbappends in favor of the demo image and
  recipes-core + inc configuration setup;

* Add fix for wolfProvider curl FIPS

* Add openssh ptest patch for wolfprovider

* Fix location of openSSH patch to point to upstream osp

* linuxkm-fips: add Yocto recipe

Add commercial FIPS LinuxKM recipe.

Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com>
Signed-off-by: Zackery Backman <zackery@wolfssl.com>

* Wolfprovider patch fix and other cleanup

* Add librelp ptest patch for FIPS

* Add support for wolfProvider RD unit test

* Add replace default method for fips image

* Update rev for wolfProvider

* Update wolfProvider ref

* Update ref version for pr 347

* fixing compatability and file layout for .incs porting

* fix pathing for gcrypt patch file

* FIPS-off gnutls recipes + minimal fips-off image.

* Update ref version for cmd test specific commit to pr 347

* fix buggy paths in meta-wolfssl

* Fix issue with missing config script and also add gcs to linuxkm recipe

* Move commercial bundle evaluation outside of recipes and into bbclass

* Cleanup to readmes

* remove the need for the librelp patch

* Update emails to point at support email

* add Gnutls images to the main readme

* Fix typo in example for wolfprovider meta-data and update licensing to point to 2024/correct md5sum

---------

Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com>
Signed-off-by: Zackery Backman <zackery@wolfssl.com>
Co-authored-by: Aidan Garske <aidan@wolfssl.com>
Co-authored-by: Andrew Hutchings <andrew@linuxjedi.co.uk>
Co-authored-by: Reda Chouk <reda@wolfssl.com>
Co-authored-by: Paul Adelsbach <paul.adelsbach@wolfssl.com>
Co-authored-by: Sameeh Jubran <sameeh@wolfssl.com>
Co-authored-by: Andrew Hutchings <andrew@wolfssl.com>
2026-02-02 15:43:35 -07:00
..
bind Refactor finalization (#149) 2026-02-02 15:43:35 -07:00
openssh Refactor finalization (#149) 2026-02-02 15:43:35 -07:00
socat Refactor finalization (#149) 2026-02-02 15:43:35 -07:00
README.md revert removing older socat version 2024-07-24 14:04:50 -06:00

README.md

Supported Ports

In this section these projects have been ported to work with specific versions of packages shipped with yocto to be used with wolfSSL

BIND

This supports using BIND version: 9.11.22, which was shipped with Yocto Dunfell.

  • Usage: Change the line in the meta-wolfssl/conf/layer.conf from:

    # Uncomment if building bind with wolfSSL.
    #BBFILES += "${LAYERDIR}/recipes-connectivity/bind/*.bbappend"
    

    to:

    # Uncomment if building bind with wolfSSL.
    BBFILES += "${LAYERDIR}/recipes-connectivity/bind/*.bbappend"
    

    Then just compile the image that use's BIND and include the wolfSSL package or preform bitbake bind

OpenSSH

This supports using OpenSSH version: 8.5p1, which was shipped with Yocto Hardknott

  • Usage: Change the line in the meta-wolfssl/conf/layer.conf from:

    # Uncomment if building OpenSSH with wolfSSL.
    #BBFILES += "${LAYERDIR}/recipes-connectivity/openssh/*.bbappend"
    

    to:

    # Uncomment if building OpenSSH with wolfSSL.
    #BBFILES += "${LAYERDIR}/recipes-connectivity/openssh/*.bbappend"
    

    Then just compile the image that use's OpenSSH and include the wolfSSL package or preform bitbake openssh

Socat

This supports using Socat version: 1.7.3.4, which was shipped with Yocto Dunfell And supports version 1.8.0.0 if updating the version of Socat in Yocto Dunfell

  • Usage: Change the line in the meta-wolfssl/conf/layer.conf from:

    # Uncomment if building socat with wolfSSL.
    #BBFILES += "${LAYERDIR}/recipes-connectivity/socat/*.bbappend"
    

    to:

    # Uncomment if building socat with wolfSSL.
    BBFILES += "${LAYERDIR}/recipes-connectivity/socat/*.bbappend"
    

    Then just compile the image that use's Socat and include the wolfSSL package or preform bitbake socat