77 lines
3.2 KiB
Diff
77 lines
3.2 KiB
Diff
diff --git a/pkgs/development/libraries/openssl/default.nix b/pkgs/development/libraries/openssl/default.nix
|
|
index d4be8cc2428..3979698711f 100644
|
|
--- a/pkgs/development/libraries/openssl/default.nix
|
|
+++ b/pkgs/development/libraries/openssl/default.nix
|
|
@@ -50,9 +50,21 @@ let
|
|
substituteInPlace crypto/async/arch/async_posix.h \
|
|
--replace '!defined(__ANDROID__) && !defined(__OpenBSD__)' \
|
|
'!defined(__ANDROID__) && !defined(__OpenBSD__) && 0'
|
|
+ '' + optionalString static
|
|
+ # On static builds, the ENGINESDIR will be empty, but its path will be
|
|
+ # compiled into the library. In order to minimize the runtime dependencies
|
|
+ # of packages that statically link openssl, we move it into the OPENSSLDIR,
|
|
+ # which will be separated into the 'etc' output.
|
|
+ ''
|
|
+ substituteInPlace Configurations/unix-Makefile.tmpl \
|
|
+ --replace 'ENGINESDIR=$(libdir)/engines-{- $sover_dirname -}' \
|
|
+ 'ENGINESDIR=$(OPENSSLDIR)/engines-{- $sover_dirname -}'
|
|
'';
|
|
|
|
- outputs = [ "bin" "dev" "out" "man" ] ++ optional withDocs "doc";
|
|
+ outputs = [ "bin" "dev" "out" "man" ]
|
|
+ ++ optional withDocs "doc"
|
|
+ # Separate output for the runtime dependencies of the static build.
|
|
+ ++ optional static "etc";
|
|
setOutputFlags = false;
|
|
separateDebugInfo =
|
|
!stdenv.hostPlatform.isDarwin &&
|
|
@@ -101,7 +113,17 @@ let
|
|
configureFlags = [
|
|
"shared" # "shared" builds both shared and static libraries
|
|
"--libdir=lib"
|
|
- "--openssldir=etc/ssl"
|
|
+ (if !static then
|
|
+ "--openssldir=etc/ssl"
|
|
+ else
|
|
+ # Separate the OPENSSLDIR into its own output, as its path will be
|
|
+ # compiled into 'libcrypto.a'. This makes it a runtime dependency of
|
|
+ # any package that statically links openssl, so we want to keep that
|
|
+ # output minimal. We need to prepend '/.' to the path in order to make
|
|
+ # it appear absolute before variable expansion, the 'prefix' would be
|
|
+ # prepended to it otherwise.
|
|
+ "--openssldir=/.$(etc)/etc/ssl"
|
|
+ )
|
|
] ++ lib.optionals withCryptodev [
|
|
"-DHAVE_CRYPTODEV"
|
|
"-DUSE_CRYPTODEV_DIGESTS"
|
|
@@ -131,6 +153,9 @@ let
|
|
if [ -n "$(echo $out/lib/*.so $out/lib/*.dylib $out/lib/*.dll)" ]; then
|
|
rm "$out/lib/"*.a
|
|
fi
|
|
+
|
|
+ # 'etc' is a separate output on static builds only.
|
|
+ etc=$out
|
|
'' + lib.optionalString (!stdenv.hostPlatform.isWindows)
|
|
# Fix bin/c_rehash's perl interpreter line
|
|
#
|
|
@@ -152,14 +177,15 @@ let
|
|
mv $out/include $dev/
|
|
|
|
# remove dependency on Perl at runtime
|
|
- rm -r $out/etc/ssl/misc
|
|
+ rm -r $etc/etc/ssl/misc
|
|
|
|
- rmdir $out/etc/ssl/{certs,private}
|
|
+ rmdir $etc/etc/ssl/{certs,private}
|
|
'';
|
|
|
|
postFixup = lib.optionalString (!stdenv.hostPlatform.isWindows) ''
|
|
- # Check to make sure the main output doesn't depend on perl
|
|
- if grep -r '${buildPackages.perl}' $out; then
|
|
+ # Check to make sure the main output and the static runtime dependencies
|
|
+ # don't depend on perl
|
|
+ if grep -r '${buildPackages.perl}' $out $etc; then
|
|
echo "Found an erroneous dependency on perl ^^^" >&2
|
|
exit 1
|
|
fi
|