meson: wire up unsafe SHA1 backend
In 06c92dafb8 (Makefile: allow specifying a SHA-1 for non-cryptographic uses, 2024-09-26), we have introduced a cryptographically-insecure backend for SHA1 that can optionally be used in some contexts where the processed data is not security relevant. This effort was in-flight with the effort to introduce Meson, so we don't have an equivalent here. Wire up a new build option that lets users pick an unsafe SHA1 backend. Note that for simplicity's sake we have to drop the error condition around an unhandled SHA1 backend. This should be fine though given that Meson verifies the value for combo-options for us. Signed-off-by: Patrick Steinhardt <ps@pks.im> Signed-off-by: Junio C Hamano <gitster@pobox.com>
Patrick Steinhardt committed
Dec 30, 2024 at 15:24 UTC
d2c0b6a86cb0f1a73d9ad5fcffda45497cd7ad42
2 files changed
+32
-10
meson.build
+30
-10
@@ -1327,15 +1327,16 @@ endif
1327
1328
https_backend = get_option('https_backend')
1329
sha1_backend = get_option('sha1_backend')
1330
+sha1_unsafe_backend = get_option('sha1_unsafe_backend')
1331
sha256_backend = get_option('sha256_backend')
1332
1332
-security_framework = dependency('Security', required: 'CommonCrypto' in [https_backend, sha1_backend])
1333
+security_framework = dependency('Security', required: 'CommonCrypto' in [https_backend, sha1_backend, sha1_unsafe_backend])
1334
core_foundation_framework = dependency('CoreFoundation', required: security_framework.found())
1335
if https_backend == 'auto' and security_framework.found()
1336
https_backend = 'CommonCrypto'
1337
endif
1338
1338
-openssl_required = 'openssl' in [https_backend, sha1_backend, sha256_backend]
1339
+openssl_required = 'openssl' in [https_backend, sha1_backend, sha1_unsafe_backend, sha256_backend]
1340
openssl = dependency('openssl', required: openssl_required, default_options: ['default_library=static'])
1341
if https_backend == 'auto' and openssl.found()
1342
https_backend = 'openssl'
@@ -1368,19 +1369,38 @@ if sha1_backend == 'sha1dc'
1369
'sha1dc/sha1.c',
1370
'sha1dc/ubc_check.c',
1371
]
1371
-elif sha1_backend == 'CommonCrypto'
1372
+endif
1373
+if sha1_backend == 'CommonCrypto' or sha1_unsafe_backend == 'CommonCrypto'
1374
+ if sha1_backend == 'CommonCrypto'
1375
+ libgit_c_args += '-DSHA1_APPLE'
1376
+ endif
1377
+ if sha1_unsafe_backend == 'CommonCrypto'
1378
+ libgit_c_args += '-DSHA1_APPLE_UNSAFE'
1379
+ endif
1380
+
1381
libgit_c_args += '-DCOMMON_DIGEST_FOR_OPENSSL'
1373
- libgit_c_args += '-DSHA1_APPLE'
1382
# Apple CommonCrypto requires chunking
1383
libgit_c_args += '-DSHA1_MAX_BLOCK_SIZE=1024L*1024L*1024L'
1376
-elif sha1_backend == 'openssl'
1377
- libgit_c_args += '-DSHA1_OPENSSL'
1384
+endif
1385
+if sha1_backend == 'openssl' or sha1_unsafe_backend == 'openssl'
1386
+ if sha1_backend == 'openssl'
1387
+ libgit_c_args += '-DSHA1_OPENSSL'
1388
+ endif
1389
+ if sha1_unsafe_backend == 'openssl'
1390
+ libgit_c_args += '-DSHA1_OPENSSL_UNSAFE'
1391
+ endif
1392
+
1393
libgit_dependencies += openssl
1379
-elif sha1_backend == 'block'
1380
- libgit_c_args += '-DSHA1_BLK'
1394
+endif
1395
+if sha1_backend == 'block' or sha1_unsafe_backend == 'block'
1396
+ if sha1_backend == 'block'
1397
+ libgit_c_args += '-DSHA1_BLK'
1398
+ endif
1399
+ if sha1_unsafe_backend == 'block'
1400
+ libgit_c_args += '-DSHA1_BLK_UNSAFE'
1401
+ endif
1402
+
1403
libgit_sources += 'block-sha1/sha1.c'
1382
-else
1383
- error('Unhandled SHA1 backend ' + sha1_backend)
1404
endif
1405
1406
if sha256_backend == 'openssl'
meson_options.txt
+2
@@ -51,6 +51,8 @@ option('https_backend', type: 'combo', value: 'auto', choices: ['auto', 'openssl
51
description: 'The HTTPS backend to use when connecting to remotes.')
52
option('sha1_backend', type: 'combo', choices: ['openssl', 'block', 'sha1dc', 'CommonCrypto'], value: 'sha1dc',
53
description: 'The backend used for hashing objects with the SHA1 object format.')
54
+option('sha1_unsafe_backend', type: 'combo', choices: ['openssl', 'block', 'CommonCrypto', 'none'], value: 'none',
55
+ description: 'The backend used for hashing data with the SHA1 object format in case no cryptographic security is needed.')
56
option('sha256_backend', type: 'combo', choices: ['openssl', 'nettle', 'gcrypt', 'block'], value: 'block',
57
description: 'The backend used for hashing objects with the SHA256 object format.')
58