openssl_1_1: fix build after 3.0.19 patch update

The security update for OpenSSL 3.0.19 (d1cc6bdd) updated
use-etc-ssl-certs.patch to match the new formatting in 3.0.19,
which removed whitespace from preprocessor directives.

OpenSSL 1.1.1w still uses the old formatting, causing the shared
patch to fail.

This patch restores the old patch files into subfolder `1.1`, they
are byte-for-byte identical (same git blob hash).
This commit is contained in:
Marc Brinkmann
2026-01-29 15:01:10 +01:00
parent 738b45b42c
commit 61e7d035d3
3 changed files with 30 additions and 1 deletions
@@ -0,0 +1,13 @@
diff --git a/include/internal/cryptlib.h b/include/internal/cryptlib.h
index 329ef62..9a8df64 100644
--- a/include/internal/cryptlib.h
+++ b/include/internal/cryptlib.h
@@ -56,7 +56,7 @@ DEFINE_LHASH_OF(MEM);
# ifndef OPENSSL_SYS_VMS
# define X509_CERT_AREA OPENSSLDIR
# define X509_CERT_DIR OPENSSLDIR "/certs"
-# define X509_CERT_FILE OPENSSLDIR "/cert.pem"
+# define X509_CERT_FILE "/nix/var/nix/profiles/default/etc/ssl/certs/ca-bundle.crt"
# define X509_PRIVATE_DIR OPENSSLDIR "/private"
# define CTLOG_FILE OPENSSLDIR "/ct_log_list.cnf"
# else
@@ -0,0 +1,13 @@
diff --git a/include/internal/cryptlib.h b/include/internal/cryptlib.h
index 329ef62..9a8df64 100644
--- a/include/internal/cryptlib.h
+++ b/include/internal/cryptlib.h
@@ -56,7 +56,7 @@ DEFINE_LHASH_OF(MEM);
# ifndef OPENSSL_SYS_VMS
# define X509_CERT_AREA OPENSSLDIR
# define X509_CERT_DIR OPENSSLDIR "/certs"
-# define X509_CERT_FILE OPENSSLDIR "/cert.pem"
+# define X509_CERT_FILE "/etc/ssl/certs/ca-certificates.crt"
# define X509_PRIVATE_DIR OPENSSLDIR "/private"
# define CTLOG_FILE OPENSSLDIR "/ct_log_list.cnf"
# else
@@ -417,7 +417,10 @@ in
./1.1/nix-ssl-cert-file.patch
(
if stdenv.hostPlatform.isDarwin then ./use-etc-ssl-certs-darwin.patch else ./use-etc-ssl-certs.patch
if stdenv.hostPlatform.isDarwin then
./1.1/use-etc-ssl-certs-darwin.patch
else
./1.1/use-etc-ssl-certs.patch
)
];
withDocs = true;