From f0d5a78ef9a42fba421cf63be9a4da3a3ce1ec4d Mon Sep 17 00:00:00 2001 From: Dmitry Misharov Date: Thu, 10 Sep 2026 13:49:38 +0200 Subject: [PATCH 1/5] test.yml: use snapshot.debian.org in the Debian 11 container Debian 11 (bullseye) LTS ended on 2026-08-31 and the bullseye-security Release file on deb.debian.org expired on 2026-09-07, so "apt-get update" now fails with "Release file ... is expired" and every debian-11 job breaks at the "Install prerequisites" step. Switch to the snapshot.debian.org entries that the debian:11 image already ships commented out in /etc/apt/sources.list, disable the Valid-Until check since snapshots are frozen, and retry transient failures because snapshot.debian.org throttles clients. Assisted-by: Claude:claude-fable-5-1 --- .github/workflows/test.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 544bd35..93b3bd5 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -52,7 +52,9 @@ jobs: steps: - name: "Install prerequisites" run: | - apt-get update + sed -i -e 's|^deb |#deb |' \ + -e 's|^# deb http://snapshot|deb http://snapshot|' /etc/apt/sources.list && \ + apt-get -o Acquire::Check-Valid-Until=false -o Acquire::Retries=3 update && \ apt-get install -y cmake gcc g++ make perl - name: "Checkout openssl" uses: "actions/checkout@v5" From 1f49d12c72dd90ad1c7cc9b94d81b36a1e65e753 Mon Sep 17 00:00:00 2001 From: Dmitry Misharov Date: Thu, 10 Sep 2026 13:49:38 +0200 Subject: [PATCH 2/5] test.yml: drop EOL OpenSSL branches from the matrix, add 4.0 and 4.1 OpenSSL 3.0, 3.2 and 3.3 have reached end of life, so stop testing against them. Add the openssl-4.0 and openssl-4.1 release branches, and bump OPENSSL_VERSION passed for master on Ubuntu 20.04 to 4.2 to match VERSION.dat. Assisted-by: Claude:claude-fable-5-1 --- .github/workflows/test.yml | 119 +++++++++++++++---------------------- 1 file changed, 47 insertions(+), 72 deletions(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 93b3bd5..a68e7a6 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -11,32 +11,27 @@ jobs: matrix: release: [ { - openssl-branch: "openssl-3.0", - cmakeopts: '-D "run_newrawkey_algos=newrawkey;-a;x25519" -D "run_evp_fetch_pqs=evp_fetch;;"', - configopts: 'no-tests', - has-ssl_poll_perf: false, - }, { - openssl-branch: "openssl-3.2", + openssl-branch: "openssl-3.4", cmakeopts: '-D "run_newrawkey_algos=newrawkey;-a;x25519" -D "run_evp_fetch_pqs=evp_fetch;;"', configopts: 'no-apps no-tests', has-ssl_poll_perf: false, }, { - openssl-branch: "openssl-3.3", - cmakeopts: '-D "run_newrawkey_algos=newrawkey;-a;x25519" -D "run_evp_fetch_pqs=evp_fetch;;"', + openssl-branch: "openssl-3.5", + cmakeopts: '', configopts: 'no-apps no-tests', has-ssl_poll_perf: false, }, { - openssl-branch: "openssl-3.4", - cmakeopts: '-D "run_newrawkey_algos=newrawkey;-a;x25519" -D "run_evp_fetch_pqs=evp_fetch;;"', + openssl-branch: "openssl-3.6", + cmakeopts: '', configopts: 'no-apps no-tests', - has-ssl_poll_perf: false, + has-ssl_poll_perf: true, }, { - openssl-branch: "openssl-3.5", + openssl-branch: "openssl-4.0", cmakeopts: '', configopts: 'no-apps no-tests', - has-ssl_poll_perf: false, + has-ssl_poll_perf: true, }, { - openssl-branch: "openssl-3.6", + openssl-branch: "openssl-4.1", cmakeopts: '', configopts: 'no-apps no-tests', has-ssl_poll_perf: true, @@ -112,21 +107,6 @@ jobs: matrix: release: [ { - openssl-branch: "openssl-3.0", - cmakeopts: '-D "run_newrawkey_algos=newrawkey;-a;x25519" -D "run_evp_fetch_pqs=evp_fetch;;" -D OPENSSL_VERSION=3.0', - configopts: 'no-tests', - has-ssl_poll_perf: false, - }, { - openssl-branch: "openssl-3.2", - cmakeopts: '-D "run_newrawkey_algos=newrawkey;-a;x25519" -D "run_evp_fetch_pqs=evp_fetch;;" -D OPENSSL_VERSION=3.2', - configopts: 'no-apps no-tests', - has-ssl_poll_perf: false, - }, { - openssl-branch: "openssl-3.3", - cmakeopts: '-D "run_newrawkey_algos=newrawkey;-a;x25519" -D "run_evp_fetch_pqs=evp_fetch;;" -D OPENSSL_VERSION=3.3', - configopts: 'no-apps no-tests', - has-ssl_poll_perf: false, - }, { openssl-branch: "openssl-3.4", cmakeopts: '-D "run_newrawkey_algos=newrawkey;-a;x25519" -D "run_evp_fetch_pqs=evp_fetch;;" -D OPENSSL_VERSION=3.4', configopts: 'no-apps no-tests', @@ -142,10 +122,20 @@ jobs: configopts: 'no-apps no-tests', has-ssl_poll_perf: true, }, { - openssl-branch: "master", + openssl-branch: "openssl-4.0", cmakeopts: '-D OPENSSL_VERSION=4.0', configopts: 'no-apps no-tests', has-ssl_poll_perf: true, + }, { + openssl-branch: "openssl-4.1", + cmakeopts: '-D OPENSSL_VERSION=4.1', + configopts: 'no-apps no-tests', + has-ssl_poll_perf: true, + }, { + openssl-branch: "master", + cmakeopts: '-D OPENSSL_VERSION=4.2', + configopts: 'no-apps no-tests', + has-ssl_poll_perf: true, } ] runs-on: "ubuntu-latest" @@ -213,32 +203,27 @@ jobs: matrix: release: [ { - openssl-branch: "openssl-3.0", - cmakeopts: '-D "run_newrawkey_algos=newrawkey;-a;x25519" -D "run_evp_fetch_pqs=evp_fetch;;" -D "run_handshake_pool_size=handshake;;;-o 4"', - configopts: 'no-tests', - has-ssl_poll_perf: false, - }, { - openssl-branch: "openssl-3.2", + openssl-branch: "openssl-3.4", cmakeopts: '-D "run_newrawkey_algos=newrawkey;-a;x25519" -D "run_evp_fetch_pqs=evp_fetch;;" -D "run_handshake_pool_size=handshake;;;-o 4"', configopts: 'no-apps no-tests', has-ssl_poll_perf: false, }, { - openssl-branch: "openssl-3.3", - cmakeopts: '-D "run_newrawkey_algos=newrawkey;-a;x25519" -D "run_evp_fetch_pqs=evp_fetch;;" -D "run_handshake_pool_size=handshake;;;-o 4"', + openssl-branch: "openssl-3.5", + cmakeopts: '-D "run_handshake_pool_size=handshake;;;-o 4"', configopts: 'no-apps no-tests', has-ssl_poll_perf: false, }, { - openssl-branch: "openssl-3.4", - cmakeopts: '-D "run_newrawkey_algos=newrawkey;-a;x25519" -D "run_evp_fetch_pqs=evp_fetch;;" -D "run_handshake_pool_size=handshake;;;-o 4"', + openssl-branch: "openssl-3.6", + cmakeopts: '-D "run_handshake_pool_size=handshake;;;-o 4"', configopts: 'no-apps no-tests', - has-ssl_poll_perf: false, + has-ssl_poll_perf: true, }, { - openssl-branch: "openssl-3.5", + openssl-branch: "openssl-4.0", cmakeopts: '-D "run_handshake_pool_size=handshake;;;-o 4"', configopts: 'no-apps no-tests', - has-ssl_poll_perf: false, + has-ssl_poll_perf: true, }, { - openssl-branch: "openssl-3.6", + openssl-branch: "openssl-4.1", cmakeopts: '-D "run_handshake_pool_size=handshake;;;-o 4"', configopts: 'no-apps no-tests', has-ssl_poll_perf: true, @@ -360,32 +345,27 @@ jobs: matrix: release: [ { - openssl-branch: "openssl-3.0", - cmakeopts: '-D "run_newrawkey_algos=newrawkey;-a;x25519" -D "run_evp_fetch_pqs=evp_fetch;;"', - configopts: 'no-tests', - has-ssl_poll_perf: false, - }, { - openssl-branch: "openssl-3.2", + openssl-branch: "openssl-3.4", cmakeopts: '-D "run_newrawkey_algos=newrawkey;-a;x25519" -D "run_evp_fetch_pqs=evp_fetch;;"', configopts: 'no-apps no-tests', has-ssl_poll_perf: false, }, { - openssl-branch: "openssl-3.3", - cmakeopts: '-D "run_newrawkey_algos=newrawkey;-a;x25519" -D "run_evp_fetch_pqs=evp_fetch;;"', + openssl-branch: "openssl-3.5", + cmakeopts: '', configopts: 'no-apps no-tests', has-ssl_poll_perf: false, }, { - openssl-branch: "openssl-3.4", - cmakeopts: '-D "run_newrawkey_algos=newrawkey;-a;x25519" -D "run_evp_fetch_pqs=evp_fetch;;"', + openssl-branch: "openssl-3.6", + cmakeopts: '', configopts: 'no-apps no-tests', - has-ssl_poll_perf: false, + has-ssl_poll_perf: true, }, { - openssl-branch: "openssl-3.5", + openssl-branch: "openssl-4.0", cmakeopts: '', configopts: 'no-apps no-tests', - has-ssl_poll_perf: false, + has-ssl_poll_perf: true, }, { - openssl-branch: "openssl-3.6", + openssl-branch: "openssl-4.1", cmakeopts: '', configopts: 'no-apps no-tests', has-ssl_poll_perf: true, @@ -458,32 +438,27 @@ jobs: matrix: release: [ { - openssl-branch: "openssl-3.0", - cmakeopts: '-D "run_newrawkey_algos=newrawkey;-a;x25519" -D "run_evp_fetch_pqs=evp_fetch;;" -D "run_handshake_pool_size=handshake;;;-o 4"', - configopts: 'no-tests', - has-ssl_poll_perf: false, - }, { - openssl-branch: "openssl-3.2", + openssl-branch: "openssl-3.4", cmakeopts: '-D "run_newrawkey_algos=newrawkey;-a;x25519" -D "run_evp_fetch_pqs=evp_fetch;;" -D "run_handshake_pool_size=handshake;;;-o 4"', configopts: 'no-apps no-tests', has-ssl_poll_perf: false, }, { - openssl-branch: "openssl-3.3", - cmakeopts: '-D "run_newrawkey_algos=newrawkey;-a;x25519" -D "run_evp_fetch_pqs=evp_fetch;;" -D "run_handshake_pool_size=handshake;;;-o 4"', + openssl-branch: "openssl-3.5", + cmakeopts: '-D "run_handshake_pool_size=handshake;;;-o 4"', configopts: 'no-apps no-tests', has-ssl_poll_perf: false, }, { - openssl-branch: "openssl-3.4", - cmakeopts: '-D "run_newrawkey_algos=newrawkey;-a;x25519" -D "run_evp_fetch_pqs=evp_fetch;;" -D "run_handshake_pool_size=handshake;;;-o 4"', + openssl-branch: "openssl-3.6", + cmakeopts: '-D "run_handshake_pool_size=handshake;;;-o 4"', configopts: 'no-apps no-tests', - has-ssl_poll_perf: false, + has-ssl_poll_perf: true, }, { - openssl-branch: "openssl-3.5", + openssl-branch: "openssl-4.0", cmakeopts: '-D "run_handshake_pool_size=handshake;;;-o 4"', configopts: 'no-apps no-tests', - has-ssl_poll_perf: false, + has-ssl_poll_perf: true, }, { - openssl-branch: "openssl-3.6", + openssl-branch: "openssl-4.1", cmakeopts: '-D "run_handshake_pool_size=handshake;;;-o 4"', configopts: 'no-apps no-tests', has-ssl_poll_perf: true, From 96d0c195295bea9f335608b4f477884653f18364 Mon Sep 17 00:00:00 2001 From: Dmitry Misharov Date: Thu, 10 Sep 2026 13:51:46 +0200 Subject: [PATCH 3/5] test.yml: update actions/checkout to v7 v7.0.1 is the current release; v5 is two majors behind. Nothing in the v6 (credentials persisted to a separate file, Node.js 24) or v7 (fork PRs blocked for pull_request_target/workflow_run) changes affects this workflow, which only triggers on pull_request and workflow_dispatch. Assisted-by: Claude:claude-fable-5-1 --- .github/workflows/test.yml | 20 ++++++++++---------- 1 file changed, 10 insertions(+), 10 deletions(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index a68e7a6..b1c54ca 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -52,7 +52,7 @@ jobs: apt-get -o Acquire::Check-Valid-Until=false -o Acquire::Retries=3 update && \ apt-get install -y cmake gcc g++ make perl - name: "Checkout openssl" - uses: "actions/checkout@v5" + uses: "actions/checkout@v7" with: repository: "openssl/openssl" ref: ${{ matrix.release.openssl-branch }} @@ -71,7 +71,7 @@ jobs: run: | make install_sw - name: "Checkout perftools" - uses: "actions/checkout@v5" + uses: "actions/checkout@v7" with: path: "perftools" - name: "Config perftools build with -DDEBUG" @@ -148,7 +148,7 @@ jobs: apt-get update apt-get install -y cmake gcc g++ make perl - name: "Checkout openssl" - uses: "actions/checkout@v5" + uses: "actions/checkout@v7" with: repository: "openssl/openssl" ref: ${{ matrix.release.openssl-branch }} @@ -167,7 +167,7 @@ jobs: run: | make install_sw - name: "Checkout perftools" - uses: "actions/checkout@v5" + uses: "actions/checkout@v7" with: path: "perftools" - name: "Config perftools build with -DDEBUG" @@ -245,7 +245,7 @@ jobs: run: | sudo pkg install -y cmake gcc perl5 - name: "Checkout openssl" - uses: "actions/checkout@v5" + uses: "actions/checkout@v7" with: repository: "openssl/openssl" ref: ${{ matrix.release.openssl-branch }} @@ -279,7 +279,7 @@ jobs: cd openssl make install_sw - name: "Checkout perftools" - uses: "actions/checkout@v5" + uses: "actions/checkout@v7" with: path: "perftools" - name: "Config perftools build with -DDEBUG" @@ -383,7 +383,7 @@ jobs: choco install nasm "C:\Program Files\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append - name: "Checkout openssl" - uses: "actions/checkout@v5" + uses: "actions/checkout@v7" with: repository: "openssl/openssl" ref: ${{ matrix.release.openssl-branch }} @@ -402,7 +402,7 @@ jobs: call "C:\Program Files\Microsoft Visual Studio\18\Enterprise\VC\Auxiliary\Build\vcvars64.bat" nmake - name: "Checkout perftools" - uses: "actions/checkout@v5" + uses: "actions/checkout@v7" with: path: "perftools" - name: "Config perftools build with -DDEBUG" @@ -472,7 +472,7 @@ jobs: runs-on: "macos-latest" steps: - name: "Checkout openssl" - uses: "actions/checkout@v5" + uses: "actions/checkout@v7" with: repository: "openssl/openssl" ref: ${{ matrix.release.openssl-branch }} @@ -491,7 +491,7 @@ jobs: run: | make install_sw - name: "Checkout perftools" - uses: "actions/checkout@v5" + uses: "actions/checkout@v7" with: path: "perftools" - name: "Config perftools build with -DDEBUG" From a707b601de5c3dbce5bf5d2e689076c181f6ce6d Mon Sep 17 00:00:00 2001 From: Dmitry Misharov Date: Thu, 10 Sep 2026 13:53:48 +0200 Subject: [PATCH 4/5] test.yml: install NASM on Windows the same way openssl/openssl does Replace "choco install nasm" with the installer-download snippet used in the openssl/openssl Windows workflows: fetch nasm-3.01-installer-x64.exe from the openssl-library.org ci-deps mirror, verify its SHA256 against the value in openssl's .github/ci-deps.json (inlined here, as perftools has no such file), and run the installer silently. Forks fall back to downloading the same installer from nasm.us without the hash check, as in openssl/openssl. Assisted-by: Claude:claude-fable-5-1 --- .github/workflows/test.yml | 17 +++++++++++++++-- 1 file changed, 15 insertions(+), 2 deletions(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index b1c54ca..371aa69 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -378,9 +378,22 @@ jobs: ] runs-on: "windows-latest" steps: - - name: "Install prerequisites" + - name: "Install nasm" + if: github.repository == 'openssl/perftools' + run: | + $installer = "nasm-3.01-installer-x64.exe" + Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/$installer" -OutFile $installer + $expected = "7881e9febc8b6558581041019b7890f109bef0694d93ed82c9589794c7b5a600" + $actual = (Get-FileHash $installer -Algorithm SHA256).Hash + if ($actual -ne $expected) { throw "SHA256 mismatch for $installer (expected $expected, got $actual)" } + Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait + "C:\Program Files\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append + - name: "Install nasm (forks)" + if: github.repository != 'openssl/perftools' run: | - choco install nasm + $installer = "nasm-3.01-installer-x64.exe" + Invoke-WebRequest -Uri "https://www.nasm.us/pub/nasm/releasebuilds/3.01/win64/$installer" -OutFile $installer + Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait "C:\Program Files\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append - name: "Checkout openssl" uses: "actions/checkout@v7" From 8105890779c381a55168857021afcf0470901da0 Mon Sep 17 00:00:00 2001 From: Dmitry Misharov Date: Thu, 10 Sep 2026 14:00:32 +0200 Subject: [PATCH 5/5] test.yml: build OpenSSL on Windows with jom instead of nmake Install jom the same way openssl/openssl does: download jom-1.1.7.exe from the openssl-library.org ci-deps mirror and verify its SHA256, with forks falling back to the jom_1_1_7.zip from download.qt.io. Copy .github/ci-deps.json verbatim from openssl/openssl so the NASM step can read its expected hash from there too, instead of the inlined value. The perftools checkout is moved to the front of the job so that the file (and the patch below) is available before the install steps. Build with "jom /j4 /S" for every branch. MSVC cannot be parallelised while /Zi routes debug info through shared .pdb files, which is what openssl/openssl#30703 fixed by switching to /Z7. That change is in master and openssl-4.1 only, so for openssl-3.4 through openssl-4.0 the backport used by the perf-test-automation playbooks in the ansible repo is applied to the OpenSSL tree with "git apply -C1" before configuring. The patch is copied verbatim into patches/ and selected per matrix entry via the new z7-patch key; it was checked to apply against the current heads of all four branches. Assisted-by: Claude:claude-fable-5-1 --- .github/ci-deps.json | 5 + .github/workflows/test.yml | 39 ++++++-- ...ompiler-flag-to-enable-parallel-buil.patch | 91 +++++++++++++++++++ 3 files changed, 129 insertions(+), 6 deletions(-) create mode 100644 .github/ci-deps.json create mode 100644 patches/0001-Windows-Use-Z7-compiler-flag-to-enable-parallel-buil.patch diff --git a/.github/ci-deps.json b/.github/ci-deps.json new file mode 100644 index 0000000..f075460 --- /dev/null +++ b/.github/ci-deps.json @@ -0,0 +1,5 @@ +{ + "jom-1.1.7.exe": "8435dbf96eb9ee65395d46d04dc3af2ff6b2618aefbc7964eeede9be669e8bd6", + "nasm-3.01-installer-x64.exe": "7881e9febc8b6558581041019b7890f109bef0694d93ed82c9589794c7b5a600", + "nasm-3.01-installer-x86.exe": "2e3041dd2abe36cb7e9938057c3cf090dd2eac42d3280957359f87c4d83b9ed0" +} diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 371aa69..62443a1 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -349,41 +349,51 @@ jobs: cmakeopts: '-D "run_newrawkey_algos=newrawkey;-a;x25519" -D "run_evp_fetch_pqs=evp_fetch;;"', configopts: 'no-apps no-tests', has-ssl_poll_perf: false, + z7-patch: "0001-Windows-Use-Z7-compiler-flag-to-enable-parallel-buil.patch", }, { openssl-branch: "openssl-3.5", cmakeopts: '', configopts: 'no-apps no-tests', has-ssl_poll_perf: false, + z7-patch: "0001-Windows-Use-Z7-compiler-flag-to-enable-parallel-buil.patch", }, { openssl-branch: "openssl-3.6", cmakeopts: '', configopts: 'no-apps no-tests', has-ssl_poll_perf: true, + z7-patch: "0001-Windows-Use-Z7-compiler-flag-to-enable-parallel-buil.patch", }, { openssl-branch: "openssl-4.0", cmakeopts: '', configopts: 'no-apps no-tests', has-ssl_poll_perf: true, + z7-patch: "0001-Windows-Use-Z7-compiler-flag-to-enable-parallel-buil.patch", }, { openssl-branch: "openssl-4.1", cmakeopts: '', configopts: 'no-apps no-tests', has-ssl_poll_perf: true, + z7-patch: '', }, { openssl-branch: "master", cmakeopts: '', configopts: 'no-apps no-tests', has-ssl_poll_perf: true, + z7-patch: '', } ] runs-on: "windows-latest" steps: + - name: "Checkout perftools" + uses: "actions/checkout@v7" + with: + path: "perftools" - name: "Install nasm" if: github.repository == 'openssl/perftools' run: | $installer = "nasm-3.01-installer-x64.exe" Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/$installer" -OutFile $installer - $expected = "7881e9febc8b6558581041019b7890f109bef0694d93ed82c9589794c7b5a600" + $expected = (Get-Content "$env:GITHUB_WORKSPACE\perftools\.github\ci-deps.json" -Raw | ConvertFrom-Json).$installer $actual = (Get-FileHash $installer -Algorithm SHA256).Hash if ($actual -ne $expected) { throw "SHA256 mismatch for $installer (expected $expected, got $actual)" } Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait @@ -395,6 +405,22 @@ jobs: Invoke-WebRequest -Uri "https://www.nasm.us/pub/nasm/releasebuilds/3.01/win64/$installer" -OutFile $installer Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait "C:\Program Files\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append + - name: "Install jom" + if: github.repository == 'openssl/perftools' + run: | + mkdir C:\jom + Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/jom-1.1.7.exe" -OutFile C:\jom\jom.exe + $expected = (Get-Content "$env:GITHUB_WORKSPACE\perftools\.github\ci-deps.json" -Raw | ConvertFrom-Json).'jom-1.1.7.exe' + $actual = (Get-FileHash C:\jom\jom.exe -Algorithm SHA256).Hash + if ($actual -ne $expected) { throw "SHA256 mismatch for jom.exe (expected $expected, got $actual)" } + "C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append + - name: "Install jom (forks)" + if: github.repository != 'openssl/perftools' + run: | + mkdir C:\jom + Invoke-WebRequest -Uri "https://download.qt.io/official_releases/jom/jom_1_1_7.zip" -OutFile C:\jom\jom.zip + Expand-Archive -Path C:\jom\jom.zip -DestinationPath C:\jom + "C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append - name: "Checkout openssl" uses: "actions/checkout@v7" with: @@ -402,6 +428,11 @@ jobs: ref: ${{ matrix.release.openssl-branch }} fetch-depth: 1 path: "openssl" + - name: "Apply the /Z7 parallel-build patch to openssl" + if: ${{ matrix.release.z7-patch != '' }} + working-directory: ".\\openssl" + run: | + git apply -C1 --verbose "$env:GITHUB_WORKSPACE\perftools\patches\${{ matrix.release.z7-patch }}" - name: "Config openssl build" working-directory: ".\\openssl" shell: cmd @@ -413,11 +444,7 @@ jobs: shell: cmd run: | call "C:\Program Files\Microsoft Visual Studio\18\Enterprise\VC\Auxiliary\Build\vcvars64.bat" - nmake - - name: "Checkout perftools" - uses: "actions/checkout@v7" - with: - path: "perftools" + jom /j4 /S - name: "Config perftools build with -DDEBUG" if: ${{ matrix.release.has-ssl_poll_perf }} working-directory: ".\\perftools\\source" diff --git a/patches/0001-Windows-Use-Z7-compiler-flag-to-enable-parallel-buil.patch b/patches/0001-Windows-Use-Z7-compiler-flag-to-enable-parallel-buil.patch new file mode 100644 index 0000000..e1c0c5c --- /dev/null +++ b/patches/0001-Windows-Use-Z7-compiler-flag-to-enable-parallel-buil.patch @@ -0,0 +1,91 @@ +From be67880c1e6e37102a8488f81a8263554fa97d53 Mon Sep 17 00:00:00 2001 +From: Milan Broz +Date: Thu, 2 Apr 2026 12:51:46 +0200 +Subject: [PATCH] Windows: Use /Z7 compiler flag to enable parallel builds +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +MSVC compilation on Windows cannot be reliably parallelized +with tools like jom (an nmake replacement) due to contention +on shared .pdb files used for debug info. Writes to a shared +.pdb must be serialized. + +The /FS compiler flag serializes concurrent compiler writes, +but does not resolve contention when the compiler and linker +access the same .pdb file. With shared .pdb files (e.g. app.pdb), +the makefile does not prevent races between the linker and +compilation of multiple targets. + +This can be resolved either by restructuring the makefile +to introduce sentinel dependencies that serialize the conflicting +steps, or by eliminating the shared .pdb entirely. + +This patch takes the latter approach: it replaces /Zi with /Z7, +which embeds debug info directly into each .obj file and avoids +any shared-file contention. /Z7 is supported by all MSVC versions. + +The linker-generated .pdb is unaffected. + +Side effects: object files are slightly larger, and all .pdb files +are now named after their target — the shared app.pdb, ossl_static.pdb, +and dso.pdb no longer exist. + +With this change, jom can be used to parallelize the build. + +Fixes: #9931 + +Signed-off-by: Milan Broz + +Reviewed-by: Neil Horman +Reviewed-by: Norbert Pocs +MergeDate: Mon Apr 13 08:46:20 2026 +(Merged from https://github.com/openssl/openssl/pull/30703) +--- + Configurations/10-main.conf | 6 +++--- + Configurations/windows-makefile.tmpl | 4 +--- + 2 files changed, 4 insertions(+), 6 deletions(-) + +diff --git a/Configurations/10-main.conf b/Configurations/10-main.conf +index 76cbf0ffa0..c7002eff39 100644 +--- a/Configurations/10-main.conf ++++ b/Configurations/10-main.conf +@@ -1541,10 +1541,10 @@ my %targets = ( + "UNICODE", "_UNICODE", + "_CRT_SECURE_NO_DEPRECATE", + "_WINSOCK_DEPRECATED_NO_WARNINGS"), +- lib_cflags => add("/Zi /Fdossl_static.pdb"), ++ lib_cflags => add("/Z7"), + lib_defines => add("L_ENDIAN"), +- dso_cflags => "/Zi /Fddso.pdb", +- bin_cflags => "/Zi /Fdapp.pdb", ++ dso_cflags => "/Z7", ++ bin_cflags => "/Z7", + # def_flag made to empty string so a .def file gets generated + shared_defflag => '', + shared_ldflag => "/dll", +diff --git a/Configurations/windows-makefile.tmpl b/Configurations/windows-makefile.tmpl +index a3c52ac19d..16fed4670d 100644 +--- a/Configurations/windows-makefile.tmpl ++++ b/Configurations/windows-makefile.tmpl +@@ -450,7 +450,7 @@ uninstall: {- "uninstall_docs" if !$disabled{docs}; -} uninstall_sw {- $disabled + + libclean: + "$(PERL)" -e "map { m/(.*)\.dll$$/; unlink glob """{.,apps,test,fuzz}/$$1.*"""; } @ARGV" $(SHLIBS) +- -del /Q /F $(LIBS) libcrypto.* libssl.* ossl_static.pdb ++ -del /Q /F $(LIBS) libcrypto.* libssl.* + + clean: libclean + {- join("\n\t", map { "-if exist $_ del /Q /F $_" } @HTMLDOCS1) || "\@rem" -} +@@ -545,8 +545,6 @@ install_dev: install_runtime_libs + "$(INSTALLTOP)\include\openssl" + @"$(PERL)" "$(SRCDIR)\util\mkdir-p.pl" "$(libdir)" + @"$(PERL)" "$(SRCDIR)\util\copy.pl" $(INSTALL_LIBS) "$(libdir)" +- @if "$(SHLIBS)"=="" \ +- "$(PERL)" "$(SRCDIR)\util\copy.pl" ossl_static.pdb "$(libdir)" + @"$(PERL)" "$(SRCDIR)\util\mkdir-p.pl" "$(CMAKECONFIGDIR)" + @"$(PERL)" "$(SRCDIR)\util\copy.pl" $(INSTALL_EXPORTERS_CMAKE) "$(CMAKECONFIGDIR)" + +-- +2.54.0 +