meson: make the CSPRNG backend configurable

The CSPRNG backend is not configurable in Meson and isn't quite discoverable, either. Make it configurable and add the actual backend used to the summary. Signed-off-by: Patrick Steinhardt <ps@pks.im> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Patrick Steinhardt committed Jan 22, 2025 at 13:05 UTC ef8c3a1b8aa04e09a00dffcfda24daec6908615c
2 files changed +23 -7
meson.build
+21 -7
@@ -1332,6 +1332,7 @@ if not meson.is_cross_build() and fs.exists('/dev/tty')
1332 libgit_c_args += '-DHAVE_DEV_TTY'
1333 endif
1334
1335 +csprng_backend = get_option('csprng_backend')
1336 https_backend = get_option('https_backend')
1337 sha1_backend = get_option('sha1_backend')
1338 sha1_unsafe_backend = get_option('sha1_unsafe_backend')
@@ -1343,7 +1344,7 @@ if https_backend == 'auto' and security_framework.found()
1344 https_backend = 'CommonCrypto'
1345 endif
1346
1346 -openssl_required = 'openssl' in [https_backend, sha1_backend, sha1_unsafe_backend, sha256_backend]
1347 +openssl_required = 'openssl' in [csprng_backend, https_backend, sha1_backend, sha1_unsafe_backend, sha256_backend]
1348 openssl = dependency('openssl', required: openssl_required, default_options: ['default_library=static'])
1349 if https_backend == 'auto' and openssl.found()
1350 https_backend = 'openssl'
@@ -1428,18 +1429,30 @@ else
1429 error('Unhandled SHA256 backend ' + sha256_backend)
1430 endif
1431
1431 -if compiler.has_header_symbol('stdlib.h', 'arc4random_buf')
1432 +# Backends are ordered to reflect our preference for more secure and faster
1433 +# ones over the ones that are less so.
1434 +if csprng_backend in ['auto', 'arc4random'] and compiler.has_header_symbol('stdlib.h', 'arc4random_buf', required: csprng_backend == 'arc4random')
1435 libgit_c_args += '-DHAVE_ARC4RANDOM'
1433 -elif compiler.has_header_symbol('bsd/stdlib.h', 'arc4random_buf')
1436 + csprng_backend = 'arc4random'
1437 +elif csprng_backend in ['auto', 'arc4random_bsd'] and compiler.has_header_symbol('bsd/stdlib.h', 'arc4random_buf', required: csprng_backend == 'arc4random_bsd')
1438 libgit_c_args += '-DHAVE_ARC4RANDOM_BSD'
1435 -elif compiler.has_function('getrandom', prefix: '#include <sys/random.h>')
1439 + csprng_backend = 'arc4random_bsd'
1440 +elif csprng_backend in ['auto', 'getrandom'] and compiler.has_header_symbol('sys/random.h', 'getrandom', required: csprng_backend == 'getrandom')
1441 libgit_c_args += '-DHAVE_GETRANDOM'
1437 -elif compiler.has_function('getentropy', prefix: '#include <unistd.h>')
1442 + csprng_backend = 'getrandom'
1443 +elif csprng_backend in ['auto', 'getentropy'] and compiler.has_header_symbol('unistd.h', 'getentropy', required: csprng_backend == 'getentropy')
1444 libgit_c_args += '-DHAVE_GETENTROPY'
1439 -elif compiler.has_function('RtlGenRandom', prefix: '#include <windows.h>\n#include <ntsecapi.h>')
1445 + csprng_backend = 'getentropy'
1446 +elif csprng_backend in ['auto', 'rtlgenrandom'] and compiler.has_header_symbol('ntsecapi.h', 'RtlGenRandom', prefix: '#include <windows.h>', required: csprng_backend == 'rtlgenrandom')
1447 libgit_c_args += '-DHAVE_RTLGENRANDOM'
1441 -elif openssl.found()
1448 + csprng_backend = 'rtlgenrandom'
1449 +elif csprng_backend in ['auto', 'openssl'] and openssl.found()
1450 libgit_c_args += '-DHAVE_OPENSSL_CSPRNG'
1451 + csprng_backend = 'openssl'
1452 +elif csprng_backend in ['auto', 'urandom']
1453 + csprng_backend = 'urandom'
1454 +else
1455 + error('Unsupported CSPRNG backend: ' + csprng_backend)
1456 endif
1457
1458 if get_option('runtime_prefix')
@@ -1977,6 +1990,7 @@ summary({
1990 }, section: 'Auto-detected features')
1991
1992 summary({
1993 + 'csprng': csprng_backend,
1994 'https': https_backend,
1995 'sha1': sha1_backend,
1996 'sha1_unsafe': sha1_unsafe_backend,
meson_options.txt
+2
@@ -47,6 +47,8 @@ option('regex', type: 'feature', value: 'auto',
47 description: 'Use the system-provided regex library instead of the bundled one.')
48
49 # Backends.
50 +option('csprng_backend', type: 'combo', value: 'auto', choices: ['auto', 'arc4random', 'arc4random_bsd', 'getrandom', 'getentropy', 'rtlgenrandom', 'openssl', 'urandom'],
51 + description: 'The backend to use for generating cryptographically-secure pseudo-random numbers.')
52 option('https_backend', type: 'combo', value: 'auto', choices: ['auto', 'openssl', 'CommonCrypto', 'none'],
53 description: 'The HTTPS backend to use when connecting to remotes.')
54 option('sha1_backend', type: 'combo', choices: ['openssl', 'block', 'sha1dc', 'CommonCrypto'], value: 'sha1dc',