Skip to content

GH-51634: [C++][CI] Apply a google-cloud-cpp patch for OpenSSL 4.x compatibility - #51635

Merged
kou merged 22 commits into
apache:mainfrom
hiroyuki-sato:topic/build-with-openssl-3
Sep 30, 2026
Merged

kou merged 22 commits into
apache:mainfrom
hiroyuki-sato:topic/build-with-openssl-3

Conversation

@hiroyuki-sato

@hiroyuki-sato hiroyuki-sato commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Rationale for this change

The current version of google-cloud-cpp used by Arrow does not build with OpenSSL 4.x

What changes are included in this PR?

This change applies a patch to google-cloud-cpp as a workaround for OpenSSL 4.x compatibility.

Are these changes tested?

Yes.

Are there any user-facing changes?

No.

Was AI used for this PR?

In accordance to the AI generation guidelines, please disclose below whether and how AI was used in this PR.

PR code and description written by:

  • Human
  • AI

Reviewed before submission by:

  • Human
  • AI
  • Not reviewed

@github-actions

Copy link
Copy Markdown

⚠️ GitHub issue #51634 has been automatically assigned in GitHub to PR creator.

@hiroyuki-sato hiroyuki-sato changed the title GH-51634: [C++][CI] Pin OpenSSL 3.x on macOS GH-51634: [C++][CI] Prefer OpenSSL 3.x on macOS Sep 30, 2026
@hiroyuki-sato

Copy link
Copy Markdown
Collaborator Author

wget 1.25.0 depends on openssl@4

brew info wget
==> wget ✔: stable 1.25.0 (bottled), HEAD
brew uses --installed openssl@4
wget

@kou

kou commented Sep 30, 2026

Copy link
Copy Markdown
Member

Can we apply a patch like the following?

diff --git a/google/cloud/internal/openssl/parse_service_account_p12_file.cc b/google/cloud/internal/openssl/parse_service_account_p12_file.cc
index bb0462dcf0..9dfb59750b 100644
--- a/google/cloud/internal/openssl/parse_service_account_p12_file.cc
+++ b/google/cloud/internal/openssl/parse_service_account_p12_file.cc
@@ -85,7 +85,7 @@ StatusOr<ServiceAccountCredentialsInfo> ParseServiceAccountP12File(
   }
 
   // This is automatically deleted by `cert`.
-  X509_NAME* name = X509_get_subject_name(cert.get());
+  auto* name = X509_get_subject_name(cert.get());
 
   std::string service_account_id = [&name]() -> std::string {
     auto openssl_free = [](void* addr) { OPENSSL_free(addr); };

@hiroyuki-sato hiroyuki-sato changed the title GH-51634: [C++][CI] Prefer OpenSSL 3.x on macOS GH-51634: [C++][CI] Apply a google-cloud-cpp patch for OpenSSL 4.x compatibility Sep 30, 2026
@hiroyuki-sato

Copy link
Copy Markdown
Collaborator Author

Notes for myself (For future development)

My idea was below

diff --git a/.github/workflows/ruby.yml b/.github/workflows/ruby.yml
index 7feb8296a3..81de0e0aba 100644
--- a/.github/workflows/ruby.yml
+++ b/.github/workflows/ruby.yml
@@ -184,6 +184,17 @@ jobs:
           for ruby_package_gemfile in ruby/*/Gemfile; do \
             bundle install --gemfile ${ruby_package_gemfile}
           done
+      # Homebrew on macOS now provides OpenSSL 4.x.
+      # However, google-cloud-cpp, which depends on OpenSSL,
+      # does not yet support OpenSSL 4.x.
+      # Therefore, explicitly prefer OpenSSL 3.x here.
+      #
+      # TODO: Once google-cloud-cpp supports OpenSSL 4.x, remove this part
+      # https://github.com/googleapis/google-cloud-cpp/issues/16510
+      - name: Link OpenSSL 3.x
+        run: |
+          brew unlink openssl@4
+          brew link openssl@3
       - name: Setup ccache
         run: |
           ci/scripts/ccache_setup.sh
diff --git a/cpp/cmake_modules/FindOpenSSLAlt.cmake b/cpp/cmake_modules/FindOpenSSLAlt.cmake
index 03c61e6ea2..e6f21f2d92 100644
--- a/cpp/cmake_modules/FindOpenSSLAlt.cmake
+++ b/cpp/cmake_modules/FindOpenSSLAlt.cmake
@@ -22,7 +22,14 @@ endif()
 if(APPLE AND NOT OPENSSL_ROOT_DIR)
   find_program(BREW brew)
   if(BREW)
-    foreach(BREW_OPENSSL_VERSION "" "3" "3.0" "1.1")
+    # Homebrew on macOS now provides OpenSSL 4.x.
+    # However, google-cloud-cpp, which depends on OpenSSL,
+    # does not yet support OpenSSL 4.x.
+    # Therefore, explicitly prefer OpenSSL 3.x here.
+    #
+    # TODO: Once google-cloud-cpp supports OpenSSL 4.x, add `""` before `"3"`.
+    # https://github.com/googleapis/google-cloud-cpp/issues/16510
+    foreach(BREW_OPENSSL_VERSION "3" "3.0" "1.1")
       set(BREW_OPENSSL_PACKAGE "openssl")
       if(BREW_OPENSSL_VERSION)
         string(APPEND BREW_OPENSSL_PACKAGE "@${BREW_OPENSSL_VERSION}")

@hiroyuki-sato
hiroyuki-sato marked this pull request as ready for review September 30, 2026 04:03
@hiroyuki-sato

Copy link
Copy Markdown
Collaborator Author

@kou Thanks for the review. I've created a patch and updated it to apply the patch.

@kou kou left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1

@kou
kou merged commit b8a45d2 into apache:main Sep 30, 2026
58 of 60 checks passed
@kou kou removed the awaiting review Awaiting review label Sep 30, 2026
@github-actions github-actions Bot added the awaiting merge Awaiting merge label Sep 30, 2026
@hiroyuki-sato
hiroyuki-sato deleted the topic/build-with-openssl-3 branch September 30, 2026 06:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants