meson: make the CSPRNG backend configurable
The CSPRNG backend is not configurable in Meson and isn't quite discoverable, either. Make it configurable and add the actual backend used to the summary. Signed-off-by: Patrick Steinhardt <ps@pks.im> Signed-off-by: Junio C Hamano <gitster@pobox.com>
Patrick Steinhardt committed
Jan 22, 2025 at 13:05 UTC
ef8c3a1b8aa04e09a00dffcfda24daec6908615c
2 files changed
+23
-7
meson.build
+21
-7
@@ -1332,6 +1332,7 @@ if not meson.is_cross_build() and fs.exists('/dev/tty')
1332
libgit_c_args += '-DHAVE_DEV_TTY'
1333
endif
1334
1335
+csprng_backend = get_option('csprng_backend')
1336
https_backend = get_option('https_backend')
1337
sha1_backend = get_option('sha1_backend')
1338
sha1_unsafe_backend = get_option('sha1_unsafe_backend')
@@ -1343,7 +1344,7 @@ if https_backend == 'auto' and security_framework.found()
1344
https_backend = 'CommonCrypto'
1345
endif
1346
1346
-openssl_required = 'openssl' in [https_backend, sha1_backend, sha1_unsafe_backend, sha256_backend]
1347
+openssl_required = 'openssl' in [csprng_backend, https_backend, sha1_backend, sha1_unsafe_backend, sha256_backend]
1348
openssl = dependency('openssl', required: openssl_required, default_options: ['default_library=static'])
1349
if https_backend == 'auto' and openssl.found()
1350
https_backend = 'openssl'
@@ -1428,18 +1429,30 @@ else
1429
error('Unhandled SHA256 backend ' + sha256_backend)
1430
endif
1431
1431
-if compiler.has_header_symbol('stdlib.h', 'arc4random_buf')
1432
+# Backends are ordered to reflect our preference for more secure and faster
1433
+# ones over the ones that are less so.
1434
+if csprng_backend in ['auto', 'arc4random'] and compiler.has_header_symbol('stdlib.h', 'arc4random_buf', required: csprng_backend == 'arc4random')
1435
libgit_c_args += '-DHAVE_ARC4RANDOM'
1433
-elif compiler.has_header_symbol('bsd/stdlib.h', 'arc4random_buf')
1436
+ csprng_backend = 'arc4random'
1437
+elif csprng_backend in ['auto', 'arc4random_bsd'] and compiler.has_header_symbol('bsd/stdlib.h', 'arc4random_buf', required: csprng_backend == 'arc4random_bsd')
1438
libgit_c_args += '-DHAVE_ARC4RANDOM_BSD'
1435
-elif compiler.has_function('getrandom', prefix: '#include <sys/random.h>')
1439
+ csprng_backend = 'arc4random_bsd'
1440
+elif csprng_backend in ['auto', 'getrandom'] and compiler.has_header_symbol('sys/random.h', 'getrandom', required: csprng_backend == 'getrandom')
1441
libgit_c_args += '-DHAVE_GETRANDOM'
1437
-elif compiler.has_function('getentropy', prefix: '#include <unistd.h>')
1442
+ csprng_backend = 'getrandom'
1443
+elif csprng_backend in ['auto', 'getentropy'] and compiler.has_header_symbol('unistd.h', 'getentropy', required: csprng_backend == 'getentropy')
1444
libgit_c_args += '-DHAVE_GETENTROPY'
1439
-elif compiler.has_function('RtlGenRandom', prefix: '#include <windows.h>\n#include <ntsecapi.h>')
1445
+ csprng_backend = 'getentropy'
1446
+elif csprng_backend in ['auto', 'rtlgenrandom'] and compiler.has_header_symbol('ntsecapi.h', 'RtlGenRandom', prefix: '#include <windows.h>', required: csprng_backend == 'rtlgenrandom')
1447
libgit_c_args += '-DHAVE_RTLGENRANDOM'
1441
-elif openssl.found()
1448
+ csprng_backend = 'rtlgenrandom'
1449
+elif csprng_backend in ['auto', 'openssl'] and openssl.found()
1450
libgit_c_args += '-DHAVE_OPENSSL_CSPRNG'
1451
+ csprng_backend = 'openssl'
1452
+elif csprng_backend in ['auto', 'urandom']
1453
+ csprng_backend = 'urandom'
1454
+else
1455
+ error('Unsupported CSPRNG backend: ' + csprng_backend)
1456
endif
1457
1458
if get_option('runtime_prefix')
@@ -1977,6 +1990,7 @@ summary({
1990
}, section: 'Auto-detected features')
1991
1992
summary({
1993
+ 'csprng': csprng_backend,
1994
'https': https_backend,
1995
'sha1': sha1_backend,
1996
'sha1_unsafe': sha1_unsafe_backend,
meson_options.txt
+2
@@ -47,6 +47,8 @@ option('regex', type: 'feature', value: 'auto',
47
description: 'Use the system-provided regex library instead of the bundled one.')
48
49
# Backends.
50
+option('csprng_backend', type: 'combo', value: 'auto', choices: ['auto', 'arc4random', 'arc4random_bsd', 'getrandom', 'getentropy', 'rtlgenrandom', 'openssl', 'urandom'],
51
+ description: 'The backend to use for generating cryptographically-secure pseudo-random numbers.')
52
option('https_backend', type: 'combo', value: 'auto', choices: ['auto', 'openssl', 'CommonCrypto', 'none'],
53
description: 'The HTTPS backend to use when connecting to remotes.')
54
option('sha1_backend', type: 'combo', choices: ['openssl', 'block', 'sha1dc', 'CommonCrypto'], value: 'sha1dc',