[d4c9331] | 1 | AC_INIT(mod_gnutls, 0.9.1) |
---|
[9706fc2] | 2 | OOO_CONFIG_NICE(config.nice) |
---|
[42307a9] | 3 | MOD_GNUTLS_VERSION=AC_PACKAGE_VERSION |
---|
[6e0bfd6] | 4 | AC_PREREQ(2.53) |
---|
[9706fc2] | 5 | AC_CONFIG_SRCDIR([src/mod_gnutls.c]) |
---|
[6e0bfd6] | 6 | AC_CONFIG_AUX_DIR(config) |
---|
[7bebb42] | 7 | |
---|
[5a6446d] | 8 | OOO_MAINTAIN_MODE |
---|
[9706fc2] | 9 | AM_MAINTAINER_MODE |
---|
| 10 | AC_CANONICAL_TARGET |
---|
[9a4d250] | 11 | # mod_gnutls test suite requires GNU make |
---|
| 12 | AM_INIT_AUTOMAKE([-Wno-portability]) |
---|
[6e0bfd6] | 13 | AM_CONFIG_HEADER(include/mod_gnutls_config.h:config.in) |
---|
[9706fc2] | 14 | |
---|
[eda8686] | 15 | LT_INIT([disable-static]) |
---|
| 16 | |
---|
[42307a9] | 17 | AC_SUBST(MOD_GNUTLS_VERSION) |
---|
[9706fc2] | 18 | |
---|
| 19 | AC_PROG_CC |
---|
[dff03fa] | 20 | AC_PROG_CC_C99 |
---|
[9706fc2] | 21 | AC_PROG_LD |
---|
| 22 | AC_PROG_INSTALL |
---|
[7bebb42] | 23 | AC_PROG_LIBTOOL |
---|
[9706fc2] | 24 | |
---|
[4aec9a1] | 25 | AC_CONFIG_MACRO_DIR([m4]) |
---|
| 26 | |
---|
[d60ff7b] | 27 | AP_VERSION=2.4.17 |
---|
[9706fc2] | 28 | CHECK_APACHE(,$AP_VERSION, |
---|
| 29 | :,:, |
---|
| 30 | AC_MSG_ERROR([*** Apache version $AP_VERSION not found!]) |
---|
| 31 | ) |
---|
| 32 | |
---|
[b4eef18] | 33 | dnl Maybe use the binaries for tests, too? |
---|
| 34 | AC_ARG_WITH([gnutls-dev], |
---|
| 35 | AS_HELP_STRING([--with-gnutls-dev=DIR], |
---|
| 36 | [Use GnuTLS libraries from a development (git) tree. Use \ |
---|
| 37 | this if you want to test mod_gnutls with the latest \ |
---|
| 38 | GnuTLS code.]), |
---|
| 39 | [ |
---|
| 40 | AS_IF([test -d "${with_gnutls_dev}" ], |
---|
| 41 | [ |
---|
| 42 | LIBGNUTLS_CFLAGS="-I${with_gnutls_dev}/lib/includes" |
---|
| 43 | LIBGNUTLS_LIBS="-lgnutls -L${with_gnutls_dev}/lib/.libs -R${with_gnutls_dev}/lib/.libs" |
---|
| 44 | ], |
---|
| 45 | [AC_MSG_ERROR([--with-gnutls-dev=DIR requires a directory!])]) |
---|
| 46 | ], []) |
---|
| 47 | |
---|
[65c84e5] | 48 | PKG_CHECK_MODULES([LIBGNUTLS], [gnutls >= 3.6.3]) |
---|
[cac3a7f] | 49 | |
---|
| 50 | LIBGNUTLS_VERSION=`pkg-config --modversion gnutls` |
---|
[16068f4] | 51 | |
---|
[0bda20f] | 52 | AC_ARG_ENABLE(vpath-install, |
---|
| 53 | AS_HELP_STRING([--enable-vpath-install], |
---|
| 54 | [Modify the Apache module directory provided by apxs to \ |
---|
| 55 | follow --prefix, if necessary. Most users will not want this, \ |
---|
| 56 | but it is required for VPATH builds including "make \ |
---|
| 57 | distcheck".]), |
---|
| 58 | vpath_install=$enableval, vpath_install=no) |
---|
| 59 | AM_CONDITIONAL([ENABLE_VPATH_INSTALL], [test "$vpath_install" = "yes"]) |
---|
| 60 | |
---|
[787dab7] | 61 | AC_ARG_ENABLE(srp, |
---|
| 62 | AS_HELP_STRING([--disable-srp], |
---|
| 63 | [unconditionally disable the SRP functionality]), |
---|
| 64 | use_srp=$enableval, use_srp=yes) |
---|
[b072204] | 65 | |
---|
[f71e6ce] | 66 | # check if the available GnuTLS library supports SRP |
---|
| 67 | AC_SEARCH_LIBS([gnutls_srp_server_get_username], [gnutls], [], [use_srp="no"]) |
---|
| 68 | |
---|
[7ff6c6c] | 69 | GNUTLS_FEAT_CFLAGS="" |
---|
[787dab7] | 70 | if test "$use_srp" != "no"; then |
---|
[7ff6c6c] | 71 | GNUTLS_FEAT_CFLAGS="-DENABLE_SRP=1" |
---|
| 72 | fi |
---|
| 73 | |
---|
| 74 | # check if the available GnuTLS library supports raw extension parsing |
---|
| 75 | AC_SEARCH_LIBS([gnutls_ext_raw_parse], [gnutls], [early_sni="yes"], |
---|
| 76 | [early_sni="no"]) |
---|
| 77 | if test "$early_sni" != "no"; then |
---|
[a939015] | 78 | ENABLE_EARLY_SNI=1 |
---|
| 79 | # This is for the test server configuration |
---|
| 80 | EXPECT_EARLY_SNI="Define EXPECT_EARLY_SNI" |
---|
| 81 | else |
---|
| 82 | ENABLE_EARLY_SNI=0 |
---|
| 83 | EXPECT_EARLY_SNI="" |
---|
[787dab7] | 84 | fi |
---|
[a939015] | 85 | AC_SUBST(ENABLE_EARLY_SNI) |
---|
| 86 | AC_SUBST(EXPECT_EARLY_SNI) |
---|
| 87 | AM_SUBST_NOTMAKE(EXPECT_EARLY_SNI) |
---|
[c70c6d7] | 88 | |
---|
[fd82e59] | 89 | AC_ARG_ENABLE(strict, |
---|
| 90 | AS_HELP_STRING([--disable-strict], |
---|
| 91 | [Avoid strict compiler warnings and errors]), |
---|
| 92 | use_strict=$enableval, use_strict=yes) |
---|
| 93 | |
---|
| 94 | STRICT_CFLAGS="" |
---|
| 95 | if test "$use_strict" != "no"; then |
---|
[6135393] | 96 | STRICT_CFLAGS="-Wall -Werror -Wextra -Wno-error=deprecated-declarations" |
---|
[fd82e59] | 97 | fi |
---|
| 98 | |
---|
[787dab7] | 99 | AC_MSG_CHECKING([whether to enable SRP functionality]) |
---|
| 100 | AC_MSG_RESULT($use_srp) |
---|
| 101 | |
---|
[f3a3f6f] | 102 | AM_PATH_PYTHON([3]) |
---|
| 103 | AX_PYTHON_MODULE([yaml], [fatal]) |
---|
| 104 | |
---|
[412ee84] | 105 | dnl Optionally disable flock |
---|
| 106 | AC_ARG_ENABLE(flock, |
---|
[dff57b4] | 107 | AS_HELP_STRING([--disable-flock], [Disable use of flock during tests \ |
---|
| 108 | (some exotic architectures don't support it)]), |
---|
[412ee84] | 109 | [use_flock=$enableval], [use_flock=yes]) |
---|
[5d9f34e] | 110 | # Check if flock is available and supports --timeout |
---|
| 111 | AC_PATH_PROG([FLOCK], [flock], [no]) |
---|
| 112 | AS_IF([test "${FLOCK}" != "no"], |
---|
| 113 | [ |
---|
| 114 | AC_MSG_CHECKING([whether ${FLOCK} supports --timeout]) |
---|
| 115 | lockfile="$(mktemp)" |
---|
| 116 | AS_IF([${FLOCK} --timeout 1 ${lockfile} true >&AS_MESSAGE_LOG_FD 2>&1], |
---|
| 117 | [flock_works="yes"], [flock_works="no"]) |
---|
| 118 | AC_MSG_RESULT([$flock_works]) |
---|
[4ae5b82] | 119 | # Old versions of flock do not support --verbose. They fail |
---|
| 120 | # without executing the command but still return 0. Check for |
---|
| 121 | # this behavior by testing if the rm command was executed. |
---|
| 122 | AC_MSG_CHECKING([whether ${FLOCK} supports --verbose]) |
---|
| 123 | testfile="$(mktemp)" |
---|
| 124 | AS_IF([${FLOCK} --verbose --timeout 1 ${lockfile} rm "${testfile}" \ |
---|
| 125 | >&AS_MESSAGE_LOG_FD 2>&1; test ! -e "${testfile}"], |
---|
| 126 | [flock_verbose="yes"; FLOCK="${FLOCK} --verbose"], |
---|
| 127 | [flock_verbose="no"; rm "${testfile}"]) |
---|
| 128 | AC_MSG_RESULT([$flock_verbose]) |
---|
| 129 | rm "${lockfile}" |
---|
[5d9f34e] | 130 | ], |
---|
| 131 | [flock_works="no"]) |
---|
| 132 | # disable flock if requested by user or it doesn't support timeout |
---|
| 133 | AM_CONDITIONAL([DISABLE_FLOCK], |
---|
| 134 | [test "$enable_flock" = "no" || test "$flock_works" = "no"]) |
---|
[412ee84] | 135 | |
---|
[21181b2] | 136 | # openssl is needed as the responder for OCSP tests |
---|
| 137 | AC_PATH_PROG([OPENSSL], [openssl], [no]) |
---|
[81018a4] | 138 | AM_CONDITIONAL([ENABLE_OCSP_TEST], [test "${OPENSSL}" != "no"]) |
---|
[42bee37] | 139 | |
---|
[cf4e708] | 140 | dnl Enable test namespaces? Default is "yes". |
---|
| 141 | AC_ARG_ENABLE(test-namespaces, |
---|
[267a27a] | 142 | AS_HELP_STRING([--disable-test-namespaces], [Disable use of \ |
---|
| 143 | namespaces for tests (limits parallelization)]), |
---|
[cf4e708] | 144 | [use_netns=$enableval], [use_netns=yes]) |
---|
[b21bf4f] | 145 | |
---|
[267a27a] | 146 | # Check if "unshare" is available and has permission to create |
---|
| 147 | # network, IPC, and user namespaces |
---|
[b21bf4f] | 148 | AC_PATH_PROG([UNSHARE], [unshare], [no]) |
---|
| 149 | AS_IF([test "${UNSHARE}" != "no"], |
---|
| 150 | [ |
---|
[267a27a] | 151 | AC_MSG_CHECKING([for permission to use namespaces]) |
---|
| 152 | AS_IF([${UNSHARE} --net --ipc -r /bin/sh -c \ |
---|
[d7c2508] | 153 | "ip link set up lo && ip addr show" >&AS_MESSAGE_LOG_FD 2>&1], |
---|
[b21bf4f] | 154 | [unshare_works="yes"], [unshare_works="no"]) |
---|
| 155 | AC_MSG_RESULT([$unshare_works]) |
---|
| 156 | ], |
---|
[1bb6b1c] | 157 | [unshare_works="no"]) |
---|
[b21bf4f] | 158 | # decide whether to enable network namespaces |
---|
| 159 | AS_IF([test "$enable_test_namespaces" != "no" \ |
---|
| 160 | && test "$unshare_works" = "yes"], |
---|
| 161 | [use_netns="yes"], [use_netns="no"]) |
---|
[cf4e708] | 162 | AM_CONDITIONAL([ENABLE_NETNS], [test "$use_netns" != "no"]) |
---|
[b21bf4f] | 163 | # Adjust Apache configuration for tests accordingly: Use pthread mutex |
---|
| 164 | # and test specific PID files if using namespaces, defaults otherwise. |
---|
| 165 | AS_IF([test "$use_netns" = "yes"], |
---|
[37beb92] | 166 | [MUTEX_CONF="Mutex pthread default"; PID_AFFIX="-\${TEST_NAME}"], |
---|
| 167 | [MUTEX_CONF=""; PID_AFFIX=""]) |
---|
| 168 | AC_SUBST(MUTEX_CONF) |
---|
[cf4e708] | 169 | AC_SUBST(PID_AFFIX) |
---|
[37beb92] | 170 | AM_SUBST_NOTMAKE(MUTEX_CONF) |
---|
[cf4e708] | 171 | AM_SUBST_NOTMAKE(PID_AFFIX) |
---|
| 172 | |
---|
[fa45dcb] | 173 | AC_ARG_ENABLE(msva, |
---|
| 174 | AS_HELP_STRING([--enable-msva], |
---|
| 175 | [enable Monkeysphere client certificate verification]), |
---|
| 176 | use_msva=$enableval, use_msva=no) |
---|
[b27cce7] | 177 | AM_CONDITIONAL([USE_MSVA], [test "$use_msva" != "no"]) |
---|
[fa45dcb] | 178 | |
---|
| 179 | MSVA_CFLAGS="" |
---|
| 180 | if test "$use_msva" != "no"; then |
---|
[b27cce7] | 181 | AC_CHECK_HEADERS([msv/msv.h], [], |
---|
[fa45dcb] | 182 | [AC_MSG_ERROR([*** No libmsv headers found!])]) |
---|
| 183 | AC_SEARCH_LIBS([msv_query_agent], [msv], [], |
---|
| 184 | [AC_MSG_ERROR([*** No libmsv found with msv_query_agent!])]) |
---|
[b27cce7] | 185 | MSVA_CFLAGS="-DENABLE_MSVA=1" |
---|
[fa45dcb] | 186 | fi |
---|
| 187 | |
---|
| 188 | AC_MSG_CHECKING([whether to enable MSVA functionality]) |
---|
| 189 | AC_MSG_RESULT($use_msva) |
---|
| 190 | |
---|
[6e1d45d] | 191 | # Building documentation requires pandoc, which in turn needs pdflatex |
---|
| 192 | # to build PDF output. |
---|
[28f3f4f] | 193 | build_doc=no |
---|
[6e1d45d] | 194 | AC_PATH_PROG([PANDOC], [pandoc], [no]) |
---|
| 195 | if test "$PANDOC" != "no"; then |
---|
| 196 | AC_PATH_PROG([PDFLATEX], [pdflatex], [no]) |
---|
[28f3f4f] | 197 | if test "$PDFLATEX" != "no"; then |
---|
[7f2fd55] | 198 | build_doc="html, manual page, pdf" |
---|
[28f3f4f] | 199 | else |
---|
[7f2fd55] | 200 | build_doc="html, manual page" |
---|
[28f3f4f] | 201 | fi |
---|
[7225749] | 202 | else |
---|
| 203 | AC_PATH_PROG([MARKDOWN], [markdown], [no]) |
---|
| 204 | if test "$MARKDOWN" != "no"; then |
---|
| 205 | build_doc="html stub" |
---|
| 206 | fi |
---|
[6e1d45d] | 207 | fi |
---|
| 208 | AM_CONDITIONAL([USE_PANDOC], [test "$PANDOC" != "no"]) |
---|
| 209 | AM_CONDITIONAL([USE_PDFLATEX], [test "$PANDOC" != "no" && \ |
---|
| 210 | test "$PDFLATEX" != "no"]) |
---|
[7225749] | 211 | AM_CONDITIONAL([USE_MARKDOWN], [test -n "$MARKDOWN" && \ |
---|
| 212 | test "$MARKDOWN" != "no"]) |
---|
[6e1d45d] | 213 | |
---|
[af7da2d] | 214 | # Check for Apache binary |
---|
[83b3901] | 215 | AC_PATH_PROGS([APACHE2], [apache2 httpd], [no], [$PATH:/usr/sbin]) |
---|
[af7da2d] | 216 | if test "${APACHE2}" = "no"; then |
---|
| 217 | AC_MSG_WARN([Neither apache2 nor httpd found in \ |
---|
[52c3f68] | 218 | PATH. Test suite will fail.]) |
---|
| 219 | fi |
---|
| 220 | |
---|
[0e069b6] | 221 | AC_PATH_PROGS([HTTP_CLI], [curl], [no]) |
---|
[67f2f58] | 222 | |
---|
[7ff6c6c] | 223 | MODULE_CFLAGS="${LIBGNUTLS_CFLAGS} ${GNUTLS_FEAT_CFLAGS} ${MSVA_CFLAGS} ${APXS_CFLAGS} ${AP_INCLUDES} ${APR_INCLUDES} ${APU_INCLUDES} ${STRICT_CFLAGS}" |
---|
[6bbd378] | 224 | MODULE_LIBS="${LIBGNUTLS_LIBS}" |
---|
[9706fc2] | 225 | |
---|
[278381d] | 226 | AC_PATH_PROGS([SOFTHSM], [softhsm2-util], [no]) |
---|
[5eb4544] | 227 | AM_CONDITIONAL([HAVE_SOFTHSM], [test "${SOFTHSM}" != "no"]) |
---|
| 228 | |
---|
[9706fc2] | 229 | AC_SUBST(MODULE_CFLAGS) |
---|
[16068f4] | 230 | AC_SUBST(MODULE_LIBS) |
---|
[9706fc2] | 231 | |
---|
[26081ce] | 232 | # assign default values to TEST_HOST and TEST_IP if necessary |
---|
| 233 | : ${TEST_HOST:="localhost"} |
---|
[a08b25e] | 234 | : ${TEST_IP:="[[::1]] 127.0.0.1"} |
---|
[26081ce] | 235 | AC_ARG_VAR([TEST_HOST], [Host name to use for server instances started by \ |
---|
[a08b25e] | 236 | "make check", must resolve to addresses in TEST_IP. \ |
---|
| 237 | The default is "localhost".]) |
---|
| 238 | AC_ARG_VAR([TEST_IP], [List of IP addresses to use for server instances \ |
---|
| 239 | started by "make check". The default is \ |
---|
| 240 | "[::1] 127.0.0.1". Note that IPv6 addresses must be \ |
---|
| 241 | enclosed in square brackets.]) |
---|
| 242 | |
---|
[6c030c1] | 243 | : ${TEST_LOCK_WAIT:="30"} |
---|
| 244 | : ${TEST_QUERY_TIMEOUT:="30"} |
---|
| 245 | AC_ARG_VAR([TEST_LOCK_WAIT], [Timeout in seconds to acquire locks for \ |
---|
| 246 | Apache instances in the test suite, or the \ |
---|
| 247 | previous instance to remove its PID file if \ |
---|
| 248 | flock is not used. Default is 30.]) |
---|
| 249 | AC_ARG_VAR([TEST_QUERY_TIMEOUT], [Timeout in seconds for HTTPS requests \ |
---|
| 250 | sent using gnutls-cli in the test suite. \ |
---|
| 251 | Default is 30.]) |
---|
| 252 | |
---|
[aeaf28b] | 253 | dnl Allow user to set SoftHSM PKCS #11 module |
---|
| 254 | AC_ARG_VAR([SOFTHSM_LIB], [Absolute path of the SoftHSM PKCS @%:@11 module to \ |
---|
| 255 | use. By default the test suite will search common \ |
---|
| 256 | library paths.]) |
---|
| 257 | |
---|
[a08b25e] | 258 | dnl Build list of "Listen" statements for Apache |
---|
[21181b2] | 259 | LISTEN_LIST="@%:@ Listen addresses for the test servers" |
---|
[a08b25e] | 260 | for i in ${TEST_IP}; do |
---|
| 261 | LISTEN_LIST="${LISTEN_LIST} |
---|
| 262 | Listen ${i}:\${TEST_PORT}" |
---|
| 263 | done |
---|
[21181b2] | 264 | # Available extra ports, tests can "Define" variables of the listed |
---|
| 265 | # names in their apache.conf to enable them. |
---|
[967bf9b] | 266 | for j in TEST_HTTP_PORT; do |
---|
[8ac7c0d] | 267 | LISTEN_LIST="${LISTEN_LIST} |
---|
[21181b2] | 268 | <IfDefine ${j}>" |
---|
[8ac7c0d] | 269 | for i in ${TEST_IP}; do |
---|
| 270 | LISTEN_LIST="${LISTEN_LIST} |
---|
[21181b2] | 271 | Listen ${i}:\${${j}}" |
---|
[8ac7c0d] | 272 | done |
---|
| 273 | LISTEN_LIST="${LISTEN_LIST} |
---|
| 274 | </IfDefine>" |
---|
[21181b2] | 275 | done |
---|
[a08b25e] | 276 | AC_SUBST(LISTEN_LIST) |
---|
| 277 | AM_SUBST_NOTMAKE(LISTEN_LIST) |
---|
[26081ce] | 278 | |
---|
[9a18e30] | 279 | DX_DOXYGEN_FEATURE(ON) |
---|
| 280 | DX_DOT_FEATURE(ON) |
---|
| 281 | DX_HTML_FEATURE(ON) |
---|
| 282 | DX_MAN_FEATURE(OFF) |
---|
| 283 | DX_RTF_FEATURE(OFF) |
---|
| 284 | DX_XML_FEATURE(OFF) |
---|
[0020874] | 285 | DX_PDF_FEATURE(OFF) |
---|
[9a18e30] | 286 | DX_PS_FEATURE(OFF) |
---|
| 287 | DX_INIT_DOXYGEN([mod_gnutls], [doc/doxygen.conf], [doc/api]) |
---|
| 288 | |
---|
[6e1d45d] | 289 | AC_CONFIG_FILES([Makefile src/Makefile test/Makefile test/tests/Makefile \ |
---|
[9a18e30] | 290 | doc/Makefile doc/doxygen.conf include/mod_gnutls.h \ |
---|
[94430e6] | 291 | test/proxy_backend.conf test/ocsp_server.conf \ |
---|
[a939015] | 292 | test/apache-conf/early_sni.conf \ |
---|
[ddf6027] | 293 | test/apache-conf/listen.conf \ |
---|
| 294 | test/apache-conf/netns.conf]) |
---|
[9706fc2] | 295 | AC_OUTPUT |
---|
| 296 | |
---|
| 297 | echo "---" |
---|
[42307a9] | 298 | echo "Configuration summary for mod_gnutls:" |
---|
[9706fc2] | 299 | echo "" |
---|
[ea14e97] | 300 | echo " * mod_gnutls version: ${MOD_GNUTLS_VERSION}" |
---|
[16068f4] | 301 | echo " * Apache Modules directory: ${AP_LIBEXECDIR}" |
---|
[42307a9] | 302 | echo " * GnuTLS Library version: ${LIBGNUTLS_VERSION}" |
---|
[b0e4ce6] | 303 | echo " * CFLAGS for GnuTLS: ${LIBGNUTLS_CFLAGS}" |
---|
| 304 | echo " * LDFLAGS for GnuTLS: ${LIBGNUTLS_LIBS}" |
---|
[28f3f4f] | 305 | echo " * SRP Authentication: ${use_srp}" |
---|
| 306 | echo " * MSVA Client Verification: ${use_msva}" |
---|
[8adfa57] | 307 | echo " * Early SNI: ${early_sni}" |
---|
[28f3f4f] | 308 | echo " * Build documentation: ${build_doc}" |
---|
[9706fc2] | 309 | echo "" |
---|
| 310 | echo "---" |
---|