mirror of
https://github.com/PowerShell/PowerShell
synced 2026-06-08 12:12:50 +00:00
Patch System.Net.Http.Native.dylib
Again, .NET Core expects users to forcibly link the third party OpenSSL libraries into system directories, which the Homebrew team advises strongly against (and attempts to prevent). This also affects the System.Net.Http library, and results in runtime errors during SSL certificate validation. So instead, we patch what we can, when we can.
This commit is contained in:
+5
-1
@@ -222,6 +222,7 @@ function Start-PSBuild {
|
||||
# This is allowed to fail since the user may have already restored
|
||||
Write-Warning ".NET Core links the incorrect OpenSSL, correcting NuGet package libraries..."
|
||||
find $env:HOME/.nuget -name System.Security.Cryptography.Native.dylib | xargs sudo install_name_tool -add_rpath /usr/local/opt/openssl/lib
|
||||
find $env:HOME/.nuget -name System.Net.Http.Native.dylib | xargs sudo install_name_tool -change /usr/lib/libcurl.4.dylib /usr/local/opt/curl/lib/libcurl.4.dylib
|
||||
}
|
||||
}
|
||||
|
||||
@@ -820,13 +821,16 @@ function Start-PSBootstrap {
|
||||
precheck 'brew' "Bootstrap dependency 'brew' not found, must install Homebrew! See http://brew.sh/"
|
||||
|
||||
# Build tools
|
||||
$Deps += "curl", "cmake"
|
||||
$Deps += "cmake"
|
||||
|
||||
# .NET Core required runtime libraries
|
||||
$Deps += "openssl"
|
||||
|
||||
# Install dependencies
|
||||
Start-NativeExecution { brew install $Deps }
|
||||
|
||||
# Install patched version of curl
|
||||
Start-NativeExecution { brew install curl --with-openssl }
|
||||
}
|
||||
|
||||
# Install [fpm](https://github.com/jordansissel/fpm) and [ronn](https://github.com/rtomayko/ronn)
|
||||
|
||||
@@ -142,6 +142,7 @@ Also install [Homebrew's OpenSSL][openssl]:
|
||||
|
||||
```
|
||||
brew install openssl
|
||||
brew install curl --with-openssl
|
||||
```
|
||||
|
||||
[Homebrew][brew] is the missing package manager for macOS.
|
||||
@@ -167,6 +168,7 @@ To patch .NET Core's cryptography libraries, we use `install_name_tool`:
|
||||
|
||||
```
|
||||
find ~/.nuget -name System.Security.Cryptography.Native.dylib | xargs sudo install_name_tool -add_rpath /usr/local/opt/openssl/lib
|
||||
find ~/.nuget -name System.Net.Http.Native.dylib | xargs sudo install_name_tool -change /usr/lib/libcurl.4.dylib /usr/local/opt/curl/lib/libcurl.4.dylib
|
||||
```
|
||||
|
||||
This updates .NET Core's library to look in Homebrew's OpenSSL installation location instead of the system library location.
|
||||
|
||||
@@ -87,14 +87,22 @@ case "$OSTYPE" in
|
||||
esac
|
||||
;;
|
||||
darwin*)
|
||||
patched=0
|
||||
if hash brew 2>/dev/null; then
|
||||
if [[ ! -d $(brew --prefix openssl) ]]; then
|
||||
echo "Installing OpenSSL with brew..."
|
||||
if ! brew install openssl; then
|
||||
echo "ERROR: OpenSSL failed to install! Crypto functions will not work..." >&2
|
||||
# Don't abort because it is not fatal
|
||||
elif ! brew install curl --with-openssl; then
|
||||
echo "ERROR: curl failed to build against OpenSSL; SSL functions will not work..." >&2
|
||||
# Still not fatal
|
||||
else
|
||||
# OpenSSL installation succeeded; remember to patch System.Net.Http after PowerShell installation
|
||||
patched=1
|
||||
fi
|
||||
fi
|
||||
|
||||
else
|
||||
echo "ERROR: brew not found! OpenSSL may not be available..." >&2
|
||||
# Don't abort because it is not fatal
|
||||
@@ -102,6 +110,10 @@ case "$OSTYPE" in
|
||||
|
||||
echo "Installing $package with sudo ..."
|
||||
sudo installer -pkg "./$package" -target /
|
||||
if [[ $patched -eq 1 ]]; then
|
||||
echo "Patching System.Net.Http for libcurl and OpenSSL..."
|
||||
find /usr/local/microsoft/powershell -name System.Net.Http.Native.dylib | xargs sudo install_name_tool -change /usr/lib/libcurl.4.dylib /usr/local/opt/curl/lib/libcurl.4.dylib
|
||||
fi
|
||||
;;
|
||||
esac
|
||||
|
||||
|
||||
Reference in New Issue
Block a user