Skip to content

Release: master-next → master (aws-lc coexistence + SDK 1.0.0 GA) - #17315

Merged
rpcme merged 42 commits into
masterfrom
master-next
Sep 30, 2026
Merged

rpcme merged 42 commits into
masterfrom
master-next

Conversation

@rpcme

@rpcme rpcme commented Sep 29, 2026

Copy link
Copy Markdown
Member

Release Summary

This is a major release containing the AWS-LC / OpenSSL coexistence migration and the AWS C SDK 1.0.0 GA upgrade — 42 commits across the entire SDK chain.

Highlights

AWS-LC Coexistence (OpenSSL 4.0 compatibility)

  • aws-lc built with ENABLE_DIST_PKG=ON: libraries renamed to libcrypto-awslc.so/libssl-awslc.so, headers to ${includedir}/aws-lc/. No file conflicts with OpenSSL.
  • s2n-tls switched from OpenSSL to aws-lc unconditionally. Unblocks builds against OpenSSL 4.0 (blacksail series).
  • All 18 SDK recipes: CMAKE_FIND_PACKAGE_PREFER_CONFIG=ON + CMAKE_PREFIX_PATH for config-mode crypto discovery.
  • aws-crt-cpp and aws-iot-device-sdk-cpp-v2 switched to build-deps=OFF for proper SBOM tracking.
  • aws-crt-python switched to no-buildin-sdk with system shared libraries.
  • arm32 excluded (COMPATIBLE_HOST:arm = "null") — aws-lc cmake compiler test fails on arm32 in OE.

SDK 1.0.0 GA Upgrades (14 recipes)

Recipe From To
aws-checksums 0.2.11 1.0.0
aws-c-sdkutils 0.2.10 1.0.0
aws-c-compression 0.3.3 1.0.0
aws-c-cal 0.9.15 1.0.0
aws-c-io 0.27.7 1.0.0
aws-c-http 0.11.1 1.0.0
aws-c-auth 0.10.5 1.0.0
aws-c-mqtt 0.16.2 1.0.0
aws-c-event-stream 0.7.2 1.0.0
aws-c-s3 0.13.7 1.2.0
aws-c-iot 0.2.2 1.0.0
aws-crt-cpp 0.43.5 0.43.7
aws-crt-python 0.36.2 0.37.0
aws-sdk-cpp 1.11.884 1.11.898

Other upgrades

  • aws-lc 5.9.0 → 5.10.0
  • s2n 1.7.8 → 1.7.10
  • aws-c-common 1.0.0 → 1.0.1
  • aws-cli-v2 2.36.32 → 2.36.39
  • amazon-ssm-agent 3.3.5226.0 → 3.3.5390.0
  • aws-greengrass-component-sdk 1.0.4 → 1.1.0
  • aws-iot-securetunneling-localproxy: full recipe rework (all patches dropped, upstream restructured cmake)
  • python3-boto3/botocore: multiple incremental upgrades to 1.43.101
  • layer.conf: LAYERSERIES_COMPAT updated to blacksail

Infrastructure & fixes

  • SPDX license compliance fixes (corepkcs11, others)
  • fix: force json output in create-ec2-ami.sh (cherry-pick from master)
  • urllib3 dependency added to botocore

Known limitations

CI

All recipes verified on qemuarm, qemuarm64, qemux86-64, and qemuriscv64 via per-PR CI. Full integration ptests passed.

Detailed closure report

See AWS_LC_CLOSURE_REPORT.md in the repo for per-recipe cmake flag analysis.

rpcme and others added 30 commits September 16, 2026 18:58
OE-core now requires LICENSE fields to use SPDX identifiers [1].
- Replace '&' with 'AND' (SPDX compound expression syntax)
- Replace 'OASIS' with 'LicenseRef-OASIS' (non-SPDX custom license)
- Update NO_GENERIC_LICENSE key to match

[1] https://lore.kernel.org/openembedded-core/20260720204946.2597206-1-JPEWhacker@gmail.com/
corepkcs11: NO_GENERIC_LICENSE key should NOT have LicenseRef- prefix.
The OE-core convention is LICENSE = "LicenseRef-OASIS" but
NO_GENERIC_LICENSE[OASIS] (without prefix). Matches the pattern used
by docbook-xml-dtd4 in OE-core.

amazon-cloudwatch-agent: LICENSE was declared as just "MIT" but the Go
agent bundles dependencies under multiple licenses. Updated to match
the actual licenses detected by BitBake's license scanner.
s2n-tls has dropped OpenSSL 4.0 support, requiring aws-lc as its crypto
backend. Enable ENABLE_DIST_PKG in aws-lc so it can coexist with OpenSSL
on the same image:

aws-lc changes:
- Enable ENABLE_DIST_PKG=ON: libraries renamed to libcrypto-awslc.so and
  libssl-awslc.so (no file conflict with OpenSSL's libcrypto.so/libssl.so)
- Headers install to ${includedir}/aws-lc/ (COHABITANT_HEADERS)
- Remove RCONFLICTS with openssl (no longer needed)
- Suppress the openssl -> aws-lc/openssl header symlink that would conflict
  with OpenSSL's include directory
- Update FILES patterns for new library names

s2n changes:
- DEPENDS unconditionally on aws-lc (remove openssl conditional)
- Set CMAKE_FIND_PACKAGE_PREFER_CONFIG=ON so find_package(crypto) uses
  aws-lc's cmake config (config mode) instead of s2n's Findcrypto.cmake
  fallback that searches for openssl-style paths

This is Phase 1+2 of the aws-lc coexistence project. Once verified, the
remaining SDK chain recipes will be updated in a follow-up.
Phase 4 of the aws-lc coexistence project. All AWS C SDK recipes that
previously depended on openssl (directly or via PACKAGECONFIG[static]
conditional) now depend on aws-lc unconditionally.

Changed recipes:
- aws-c-cal: conditional -> aws-lc
- aws-c-io: conditional -> aws-lc
- aws-c-auth: conditional -> aws-lc
- aws-c-event-stream: conditional -> aws-lc
- aws-c-s3: conditional -> aws-lc
- aws-c-http: direct openssl -> aws-lc
- aws-c-iot: direct openssl -> aws-lc
- aws-crt-python: direct openssl -> aws-lc
- aws-crt-cpp: build-deps openssl -> aws-lc
- aws-iot-device-sdk-cpp-v2: build-deps openssl -> aws-lc

NOT changed (use OpenSSL directly, not through s2n):
- amazon-kvs-producer-sdk-c/cpp
- amazon-kvs-webrtc-sdk
- aws-iot-device-sdk-embedded-c
…penSSL

The cmake toolchain file had hardcoded paths to the native sysroot's
OpenSSL (libcrypto.so, openssl/crypto.h). This caused the vendored CRT
build to link against native x86 OpenSSL when cross-compiling.

Replace with CMAKE_FIND_PACKAGE_PREFER_CONFIG and CMAKE_PREFIX_PATH
pointing to the target sysroot, so the vendored build finds aws-lc's
crypto-config.cmake instead.
aws-c-cal links against libcrypto-awslc.so at runtime (through s2n
and directly). Without aws-lc in RDEPENDS, the library may not be
pulled into the target image, causing runtime failures in binaries
that depend on the SDK chain (e.g. fleet provisioning --help returns
non-zero because libcrypto-awslc.so is missing).
Root cause: the vendored build compiled _awscrt.abi3.so against the
submodule's aws-lc, but at runtime it loads the system aws-lc
(ENABLE_DIST_PKG), which doesn't export EVP_aead_aes_128_gcm_tls13.

Fix: set PACKAGECONFIG default to 'no-buildin-sdk' so aws-crt-python
uses system-installed SDK libraries (including aws-lc with ENABLE_DIST_PKG)
instead of vendoring its own copies from git submodules.

Confirmed from QEMU ptest logs:
  ImportError: _awscrt.abi3.so: undefined symbol: EVP_aead_aes_128_gcm_tls13
aws-lc cannot build on arm32, and s2n unconditionally depends on it.
Adding the arm32 exclusion to s2n causes BitBake to skip the entire
SDK chain on arm32, avoiding a guaranteed build failure and saving
CI time.
With build-deps=ON, all SDK libraries were compiled together with
ASan flags. With build-deps=OFF, aws-crt-cpp links against system
libraries that aren't compiled with ASan, causing:
  ASan runtime does not come first in initial library list

Disable sanitizer until all SDK chain recipes add sanitize support.
Only affects x86-64 ptests.
rpcme and others added 12 commits September 28, 2026 23:41
It's not only the ptest package that depends on the urllib3 package
v1.1.0 fixes the Cargo.lock sync issue (aws-greengrass/aws-greengrass-component-sdk#160).
Regenerated crates.inc from new Cargo.lock.
Drop all 4 patches (upstream restructured cmake in 7f82dbc):
- 0001: boost version pin (upstream now version-agnostic)
- 0002: cxx standard removal (now handled via sed)
- 0004: cmake version (upstream now 3.10...3.30)
- 0005: boost system headers (upstream now uses SYSTEM)

Update do_configure:prepend for the new cmake module structure:
- Remove CMAKE_CXX_STANDARD 14 (recipe needs c++20)
- Use shared protobuf (disable static-lib rewrite in LocalproxyProtobuf.cmake)
@rpcme
rpcme requested a review from a team as a code owner September 29, 2026 21:11
@rpcme
rpcme merged commit 945fa75 into master Sep 30, 2026
11 of 12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants