GH-51634: [C++][CI] Apply a google-cloud-cpp patch for OpenSSL 4.x compatibility - #51635
Merged
Merged
Conversation
|
|
Collaborator
Author
|
wget 1.25.0 depends on |
Member
|
Can we apply a patch like the following? diff --git a/google/cloud/internal/openssl/parse_service_account_p12_file.cc b/google/cloud/internal/openssl/parse_service_account_p12_file.cc
index bb0462dcf0..9dfb59750b 100644
--- a/google/cloud/internal/openssl/parse_service_account_p12_file.cc
+++ b/google/cloud/internal/openssl/parse_service_account_p12_file.cc
@@ -85,7 +85,7 @@ StatusOr<ServiceAccountCredentialsInfo> ParseServiceAccountP12File(
}
// This is automatically deleted by `cert`.
- X509_NAME* name = X509_get_subject_name(cert.get());
+ auto* name = X509_get_subject_name(cert.get());
std::string service_account_id = [&name]() -> std::string {
auto openssl_free = [](void* addr) { OPENSSL_free(addr); }; |
Collaborator
Author
|
Notes for myself (For future development) My idea was below diff --git a/.github/workflows/ruby.yml b/.github/workflows/ruby.yml
index 7feb8296a3..81de0e0aba 100644
--- a/.github/workflows/ruby.yml
+++ b/.github/workflows/ruby.yml
@@ -184,6 +184,17 @@ jobs:
for ruby_package_gemfile in ruby/*/Gemfile; do \
bundle install --gemfile ${ruby_package_gemfile}
done
+ # Homebrew on macOS now provides OpenSSL 4.x.
+ # However, google-cloud-cpp, which depends on OpenSSL,
+ # does not yet support OpenSSL 4.x.
+ # Therefore, explicitly prefer OpenSSL 3.x here.
+ #
+ # TODO: Once google-cloud-cpp supports OpenSSL 4.x, remove this part
+ # https://github.com/googleapis/google-cloud-cpp/issues/16510
+ - name: Link OpenSSL 3.x
+ run: |
+ brew unlink openssl@4
+ brew link openssl@3
- name: Setup ccache
run: |
ci/scripts/ccache_setup.sh
diff --git a/cpp/cmake_modules/FindOpenSSLAlt.cmake b/cpp/cmake_modules/FindOpenSSLAlt.cmake
index 03c61e6ea2..e6f21f2d92 100644
--- a/cpp/cmake_modules/FindOpenSSLAlt.cmake
+++ b/cpp/cmake_modules/FindOpenSSLAlt.cmake
@@ -22,7 +22,14 @@ endif()
if(APPLE AND NOT OPENSSL_ROOT_DIR)
find_program(BREW brew)
if(BREW)
- foreach(BREW_OPENSSL_VERSION "" "3" "3.0" "1.1")
+ # Homebrew on macOS now provides OpenSSL 4.x.
+ # However, google-cloud-cpp, which depends on OpenSSL,
+ # does not yet support OpenSSL 4.x.
+ # Therefore, explicitly prefer OpenSSL 3.x here.
+ #
+ # TODO: Once google-cloud-cpp supports OpenSSL 4.x, add `""` before `"3"`.
+ # https://github.com/googleapis/google-cloud-cpp/issues/16510
+ foreach(BREW_OPENSSL_VERSION "3" "3.0" "1.1")
set(BREW_OPENSSL_PACKAGE "openssl")
if(BREW_OPENSSL_VERSION)
string(APPEND BREW_OPENSSL_PACKAGE "@${BREW_OPENSSL_VERSION}") |
hiroyuki-sato
marked this pull request as ready for review
September 30, 2026 04:03
Collaborator
Author
|
@kou Thanks for the review. I've created a patch and updated it to apply the patch. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rationale for this change
The current version of google-cloud-cpp used by Arrow does not build with OpenSSL 4.x
What changes are included in this PR?
This change applies a patch to google-cloud-cpp as a workaround for OpenSSL 4.x compatibility.
Are these changes tested?
Yes.
Are there any user-facing changes?
No.
Was AI used for this PR?
In accordance to the AI generation guidelines, please disclose below whether and how AI was used in this PR.
PR code and description written by:
Reviewed before submission by: