Bug 15114

Summary: curl build fails when ssh is enable
Product: [Build System, Metadata & Runtime] Meta-yocto Reporter: frederic.chanal
Component: meta-yoctoAssignee: Steve Sakoman <steve>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Medium+ CC: poky.bs.watcher, poky.watcher, randy.macleod
Version: 3.1.26   
Target Milestone: 3.1.26   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)

Description frederic.chanal 2023-05-05 14:28:59 UTC
Hi, 

Following the introduction of a CVE-2023-27534 patch in curl for dunsfell (https://git.yoctoproject.org/poky/commit/meta/recipes-support/curl?h=dunfell&id=00af542d30e27be23c927ad214ffbef368ab3215) the build now fails when curl is configured with `libssh2` (PACKAGECONFIG_append = " libssh2")

Extract of the error:

| ../x86_64-linux-libtool  --tag=CC   --mode=compile gcc  -DHAVE_CONFIG_H   -I../../curl-7.69.1/include -I../lib -I../../curl-7.69.1/lib  -DBUILDING_LIBCURL  -DCURL_HIDDEN_SYMBOLS -isystem/cwd/build/tmp/work/x86_64-linux/curl-native/7.69.1-r0/recipe-sysroot-native/usr/include -I/cwd/build/tmp/work/x86_64-linux/curl-native/7.69.1-r0/recipe-sysroot-native/usr/lib/..//include -I/cwd/build/tmp/work/x86_64-linux/curl-native/7.69.1-r0/recipe-sysroot-native/usr/lib/pkgconfig/../../../usr/include -I/cwd/build/tmp/work/x86_64-linux/curl-native/7.69.1-r0/recipe-sysroot-native/usr/lib/pkgconfig/../../../usr/include  -fvisibility=hidden -isystem/cwd/build/tmp/work/x86_64-linux/curl-native/7.69.1-r0/recipe-sysroot-native/usr/include -O2 -pipe -Werror-implicit-function-declaration -Wno-system-headers  -c -o vauth/libcurl_la-krb5_sspi.lo `test -f 'vauth/krb5_sspi.c' || echo '../../curl-7.69.1/lib/'`vauth/krb5_sspi.c
| ../../curl-7.69.1/lib/curl_path.c: In function ‘Curl_getworkingpath’:
| ../../curl-7.69.1/lib/curl_path.c:44:17: error: storage size of ‘npath’ isn’t known
|    44 |   struct dynbuf npath;
|       |                 ^~~~~
| ../../curl-7.69.1/lib/curl_path.c:52:3: error: implicit declaration of function ‘Curl_dyn_init’; did you mean ‘Curl_ssh_init’? [-Werror=implicit-function-declaration]
|    52 |   Curl_dyn_init(&npath, MAX_SSHPATH_LEN);
|       |   ^~~~~~~~~~~~~
|       |   Curl_ssh_init
| ../../curl-7.69.1/lib/curl_path.c:58:8: error: implicit declaration of function ‘Curl_dyn_addn’ [-Werror=implicit-function-declaration]
|    58 |     if(Curl_dyn_addn(&npath, &working_path[3], working_path_len - 3)) {
|       |        ^~~~~~~~~~~~~


The patch depends on code that is not available on Curl 7.69.1 (namely `dynbufs.[ch]`)

When Curl is compiled without the `libssh2` PACKAGECONFIG option there's no error cause the patch act on code that is not compiled in this case.

Maybe a solution is to upgrade to curl >= 7.71 where this https://github.com/curl/curl/pull/5300 has been added.
Comment 1 Randy MacLeod 2023-05-11 14:34:08 UTC
3.1.25 is released but we don't have 3.1.26 in the menus yet so parked.