Release: master-next → master (aws-lc coexistence + SDK 1.0.0 GA) - #17315
Merged
Merged
Conversation
OE-core now requires LICENSE fields to use SPDX identifiers [1]. - Replace '&' with 'AND' (SPDX compound expression syntax) - Replace 'OASIS' with 'LicenseRef-OASIS' (non-SPDX custom license) - Update NO_GENERIC_LICENSE key to match [1] https://lore.kernel.org/openembedded-core/20260720204946.2597206-1-JPEWhacker@gmail.com/
corepkcs11: NO_GENERIC_LICENSE key should NOT have LicenseRef- prefix. The OE-core convention is LICENSE = "LicenseRef-OASIS" but NO_GENERIC_LICENSE[OASIS] (without prefix). Matches the pattern used by docbook-xml-dtd4 in OE-core. amazon-cloudwatch-agent: LICENSE was declared as just "MIT" but the Go agent bundles dependencies under multiple licenses. Updated to match the actual licenses detected by BitBake's license scanner.
s2n-tls has dropped OpenSSL 4.0 support, requiring aws-lc as its crypto
backend. Enable ENABLE_DIST_PKG in aws-lc so it can coexist with OpenSSL
on the same image:
aws-lc changes:
- Enable ENABLE_DIST_PKG=ON: libraries renamed to libcrypto-awslc.so and
libssl-awslc.so (no file conflict with OpenSSL's libcrypto.so/libssl.so)
- Headers install to ${includedir}/aws-lc/ (COHABITANT_HEADERS)
- Remove RCONFLICTS with openssl (no longer needed)
- Suppress the openssl -> aws-lc/openssl header symlink that would conflict
with OpenSSL's include directory
- Update FILES patterns for new library names
s2n changes:
- DEPENDS unconditionally on aws-lc (remove openssl conditional)
- Set CMAKE_FIND_PACKAGE_PREFER_CONFIG=ON so find_package(crypto) uses
aws-lc's cmake config (config mode) instead of s2n's Findcrypto.cmake
fallback that searches for openssl-style paths
This is Phase 1+2 of the aws-lc coexistence project. Once verified, the
remaining SDK chain recipes will be updated in a follow-up.
Phase 4 of the aws-lc coexistence project. All AWS C SDK recipes that previously depended on openssl (directly or via PACKAGECONFIG[static] conditional) now depend on aws-lc unconditionally. Changed recipes: - aws-c-cal: conditional -> aws-lc - aws-c-io: conditional -> aws-lc - aws-c-auth: conditional -> aws-lc - aws-c-event-stream: conditional -> aws-lc - aws-c-s3: conditional -> aws-lc - aws-c-http: direct openssl -> aws-lc - aws-c-iot: direct openssl -> aws-lc - aws-crt-python: direct openssl -> aws-lc - aws-crt-cpp: build-deps openssl -> aws-lc - aws-iot-device-sdk-cpp-v2: build-deps openssl -> aws-lc NOT changed (use OpenSSL directly, not through s2n): - amazon-kvs-producer-sdk-c/cpp - amazon-kvs-webrtc-sdk - aws-iot-device-sdk-embedded-c
…penSSL The cmake toolchain file had hardcoded paths to the native sysroot's OpenSSL (libcrypto.so, openssl/crypto.h). This caused the vendored CRT build to link against native x86 OpenSSL when cross-compiling. Replace with CMAKE_FIND_PACKAGE_PREFER_CONFIG and CMAKE_PREFIX_PATH pointing to the target sysroot, so the vendored build finds aws-lc's crypto-config.cmake instead.
aws-c-cal links against libcrypto-awslc.so at runtime (through s2n and directly). Without aws-lc in RDEPENDS, the library may not be pulled into the target image, causing runtime failures in binaries that depend on the SDK chain (e.g. fleet provisioning --help returns non-zero because libcrypto-awslc.so is missing).
Root cause: the vendored build compiled _awscrt.abi3.so against the submodule's aws-lc, but at runtime it loads the system aws-lc (ENABLE_DIST_PKG), which doesn't export EVP_aead_aes_128_gcm_tls13. Fix: set PACKAGECONFIG default to 'no-buildin-sdk' so aws-crt-python uses system-installed SDK libraries (including aws-lc with ENABLE_DIST_PKG) instead of vendoring its own copies from git submodules. Confirmed from QEMU ptest logs: ImportError: _awscrt.abi3.so: undefined symbol: EVP_aead_aes_128_gcm_tls13
aws-lc cannot build on arm32, and s2n unconditionally depends on it. Adding the arm32 exclusion to s2n causes BitBake to skip the entire SDK chain on arm32, avoiding a guaranteed build failure and saving CI time.
With build-deps=ON, all SDK libraries were compiled together with ASan flags. With build-deps=OFF, aws-crt-cpp links against system libraries that aren't compiled with ASan, causing: ASan runtime does not come first in initial library list Disable sanitizer until all SDK chain recipes add sanitize support. Only affects x86-64 ptests.
It's not only the ptest package that depends on the urllib3 package
v1.1.0 fixes the Cargo.lock sync issue (aws-greengrass/aws-greengrass-component-sdk#160). Regenerated crates.inc from new Cargo.lock.
Drop all 4 patches (upstream restructured cmake in 7f82dbc): - 0001: boost version pin (upstream now version-agnostic) - 0002: cxx standard removal (now handled via sed) - 0004: cmake version (upstream now 3.10...3.30) - 0005: boost system headers (upstream now uses SYSTEM) Update do_configure:prepend for the new cmake module structure: - Remove CMAKE_CXX_STANDARD 14 (recipe needs c++20) - Use shared protobuf (disable static-lib rewrite in LocalproxyProtobuf.cmake)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Release Summary
This is a major release containing the AWS-LC / OpenSSL coexistence migration and the AWS C SDK 1.0.0 GA upgrade — 42 commits across the entire SDK chain.
Highlights
AWS-LC Coexistence (OpenSSL 4.0 compatibility)
ENABLE_DIST_PKG=ON: libraries renamed tolibcrypto-awslc.so/libssl-awslc.so, headers to${includedir}/aws-lc/. No file conflicts with OpenSSL.CMAKE_FIND_PACKAGE_PREFER_CONFIG=ON+CMAKE_PREFIX_PATHfor config-mode crypto discovery.build-deps=OFFfor proper SBOM tracking.no-buildin-sdkwith system shared libraries.COMPATIBLE_HOST:arm = "null") — aws-lc cmake compiler test fails on arm32 in OE.SDK 1.0.0 GA Upgrades (14 recipes)
Other upgrades
Infrastructure & fixes
Known limitations
build-deps=OFF(issue aws-crt-cpp: re-enable ASan sanitizer support with build-deps=OFF #17281)CI
All recipes verified on qemuarm, qemuarm64, qemux86-64, and qemuriscv64 via per-PR CI. Full integration ptests passed.
Detailed closure report
See
AWS_LC_CLOSURE_REPORT.mdin the repo for per-recipe cmake flag analysis.