#928744 u-boot: add support for the Turris Omnia and other OpenSSL reqiring hardware

#928744#5
Date:
2019-05-10 04:11:04 UTC
From:
To:
Please add support to the u-boot source package for building u-boot
binary packages for the Turris Omnia and other hardware where u-boot requires OpenSSL. As I understand it, these binary packages are not redistributable by Debian but folks could build or cross-build them
themselves for deployment on their own hardware. By using dpkg's build
profiles support, those packages could be added to the u-boot source
package, not be built by default but still be able to be manually buildable using the dpkg-buildpackage --build-profiles option.

https://wiki.debian.org/BuildProfileSpec

#928744#10
Date:
2019-05-10 06:45:39 UTC
From:
To:
That's my understanding, yes.

I've thought about this as well... I've been hesitant to implement it
wondering how it would interact with the NEW queue...

if needed I guess a workaround would be to add them to the "u-boot"
package, though it's not available on all architectures, and might
violate "A binary package must contain the exact same content for all
profiles with which it builds"


And now that we've opened the discussion...

Ideally, of course, would be to fix upstream to not require OpenSSL due
to the incompatibility with GPL and port to another library that was
GPL-compatible... in theory it's not a lot of code. I briefly tried
looking into the GNU TLS OpenSSL compatibility layer, but it did not
support the needed functionality.

I also brought this issue up in Guix recently, but eventually just
submitted a patch to remove OpenSSL from the u-boot packaging much like
Debian already does:

https://issues.guix.info/issue/34717

Some past discussion upstream:

https://lists.denx.de/pipermail/u-boot/2017-November/312483.html
https://lists.denx.de/pipermail/u-boot/2017-December/313616.html
https://lists.denx.de/pipermail/u-boot/2017-December/313742.html

It didn't seem like a licensing exception was plausible upstream, as
u-boot is codebase with a lot of individual contributors over the
years...


live well,
  vagrant

#928744#15
Date:
2019-05-10 07:08:43 UTC
From:
To:
Only one way to find out :)

Indeed, even with OpenSSL moving to Apache 2.0, which is compatible
with GPLv3 (and thus GPLv2+), OpenSSL 3.0 will still be incompatible
with the GPLv2-only code in u-boot.

#928744#20
Date:
2021-05-26 15:45:58 UTC
From:
To:
With #972513, OpenSSL support for the u-boot-tools was added, so it should be possible now to build
the requested binary packages.