-
Notifications
You must be signed in to change notification settings - Fork 19
/
Makefile
executable file
·228 lines (196 loc) · 6.51 KB
/
Makefile
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
BUILD_DIR = $(PWD)/build
OPENVPN_WINDOWS_BUILDROOT = openvpn-build/generic/tmp
OPENVPN_WINDOWS_SOURCEROOT = openvpn-build/generic/sources
STRIP = strip
OPENSSL_CONFIGURE_SCRIPT = ./config
OPENSSL_VERSION = 3.0.8
OPENSSL_CONFIG = no-weak-ssl-ciphers no-ssl3 no-ssl3-method no-bf no-rc2 no-rc4 no-rc5 \
no-md4 no-seed no-cast no-camellia no-idea enable-ec_nistp_64_gcc_128 enable-rfc3779
# To stop OpenSSL from loading C:\etc\ssl\openvpn.cnf (and equivalent) on start.
# Prevents escalation attack to SYSTEM user.
OPENSSL_CONFIG += no-autoload-config
OPENSSL_LIB_DIR = $(BUILD_DIR)/lib64
OPENVPN_VERSION = 2.6.8
OPENVPN_CONFIG = --enable-static --disable-shared --disable-debug --disable-plugin-down-root \
--disable-management --disable-port-share --disable-systemd --disable-dependency-tracking \
--disable-pkcs11 --disable-plugin-auth-pam --enable-plugins \
--disable-lzo --disable-lz4 --enable-comp-stub
LIBMNL_CONFIG = --enable-static --disable-shared
LIBNFTNL_CONFIG = --enable-static --disable-shared
LIBNL_CONFIG = --enable-static --disable-shared --enable-cli=no --disable-debug
LIBNFTNL_CFLAGS = -g -O2
# You likely need GNU Make for this to work.
UNAME_S := $(shell uname -s)
UNAME_M := $(shell uname -m)
# Compute host platform
ifeq ($(UNAME_S),Linux)
HOST = "$(UNAME_M)-unknown-linux-gnu"
endif
ifeq ($(UNAME_S),Darwin)
ifeq ($(UNAME_M), arm64)
HOST = "aarch64-apple-darwin"
else
HOST = "$(UNAME_M)-apple-darwin"
endif
endif
ifneq (,$(findstring MINGW,$(UNAME_S)))
HOST = "x86_64-pc-windows-msvc"
endif
# Compute target platform
ifndef $(TARGET)
TARGET = $(HOST)
endif
# Compute build flags for host+target combination
ifeq ($(UNAME_S),Darwin)
OPENSSL_LIB_DIR = $(BUILD_DIR)/lib
OPENSSL_CONFIGURE_SCRIPT = ./Configure
PLATFORM_OPENVPN_CONFIG = --host=$(TARGET)
ifeq ($(TARGET),x86_64-apple-darwin)
TARGET_ARCH = "x86_64"
MACOSX_DEPLOYMENT_TARGET = "10.13"
endif
ifeq ($(TARGET),aarch64-apple-darwin)
TARGET_ARCH = "arm64"
MACOSX_DEPLOYMENT_TARGET = "11.0"
endif
PLATFORM_OPENSSL_CONFIG += "darwin64-$(TARGET_ARCH)-cc"
CFLAGS = -arch $(TARGET_ARCH) -mmacosx-version-min=$(MACOSX_DEPLOYMENT_TARGET)
LDFLAGS = -arch $(TARGET_ARCH) -mmacosx-version-min=$(MACOSX_DEPLOYMENT_TARGET)
endif
ifeq ($(UNAME_S),Linux)
PLATFORM_OPENSSL_CONFIG = -static
PLATFORM_OPENVPN_CONFIG = --enable-dco --disable-iproute2
ifeq ($(TARGET),aarch64-unknown-linux-gnu)
OPENSSL_LIB_DIR = $(BUILD_DIR)/lib
ifneq ($(HOST),aarch64-unknown-linux-gnu)
export CC := aarch64-linux-gnu-gcc
STRIP = aarch64-linux-gnu-strip
OPENSSL_CONFIGURE_SCRIPT = ./Configure
PLATFORM_OPENSSL_CONFIG += linux-aarch64
PLATFORM_OPENVPN_CONFIG += --host=aarch64-linux
LIBMNL_CONFIG += --host=aarch64-linux
LIBNFTNL_CONFIG += --host=aarch64-linux
LIBNL_CONFIG += --host=aarch64-linux
endif
else
# ARM doesn't support 'mcmodel=large'
LIBNFTNL_CFLAGS += -mcmodel=large
endif
endif
ifneq (,$(findstring darwin,$(TARGET)))
GOOS = darwin
endif
ifneq (,$(findstring linux,$(TARGET)))
GOOS = linux
endif
ifneq (,$(findstring windows,$(TARGET)))
GOOS = windows
endif
ifneq (,$(findstring aarch64,$(TARGET)))
GOARCH = arm64
else
GOARCH = amd64
endif
.PHONY: help clean clean-build clean-submodules openssl openvpn openvpn_windows libmnl libnftnl libnl apisocks5
help:
@echo "Please run a more specific target"
@echo "'make openvpn' will build a statically linked OpenVPN binary"
@echo "'make libnftnl' will build static libraries of libmnl and libnftnl and copy to linux/"
@echo "'make apisocks5' will build the apisocks5 program and copy to ./$TARGET/"
clean: clean-build clean-submodules
clean-build:
rm -rf $(BUILD_DIR)
clean-submodules:
cd openssl; [ -e "Makefile" ] && $(MAKE) clean || true
cd openvpn; [ -e "Makefile" ] && $(MAKE) clean || true
openssl:
@echo "Building OpenSSL"
mkdir -p $(BUILD_DIR)
cd openssl; \
export MACOSX_DEPLOYMENT_TARGET="$(MACOSX_DEPLOYMENT_TARGET)" ; \
KERNEL_BITS=64 $(OPENSSL_CONFIGURE_SCRIPT) no-shared \
--prefix=$(BUILD_DIR) \
--openssldir=$(BUILD_DIR) \
$(PLATFORM_OPENSSL_CONFIG) \
$(OPENSSL_CONFIG) ; \
$(MAKE) clean ; \
$(MAKE) build_libs build_apps ; \
$(MAKE) install_sw
openvpn: openssl libnl
@echo "Building OpenVPN"
mkdir -p $(BUILD_DIR) $(TARGET)
cd openvpn ; \
export MACOSX_DEPLOYMENT_TARGET="$(MACOSX_DEPLOYMENT_TARGET)" ; \
export CFLAGS="$(CFLAGS)"; \
autoreconf -f -i -v ; \
./configure \
--prefix=$(BUILD_DIR) \
$(OPENVPN_CONFIG) $(PLATFORM_OPENVPN_CONFIG) \
LIBNL_GENL_CFLAGS="-I$(PWD)/libnl/include" \
LIBNL_GENL_LIBS="-L$(PWD)/libnl/lib/.libs -lnl-genl-3" \
OPENSSL_CFLAGS="-I$(BUILD_DIR)/include" \
OPENSSL_LIBS="-L$(OPENSSL_LIB_DIR) -lssl -lcrypto -lpthread -ldl" ; \
$(MAKE) clean ; \
$(MAKE) ; \
$(MAKE) install
$(STRIP) $(BUILD_DIR)/sbin/openvpn
cp $(BUILD_DIR)/sbin/openvpn $(TARGET)/
openvpn_windows: clean-submodules
rm -rf "$(OPENVPN_WINDOWS_BUILDROOT)"
mkdir -p $(OPENVPN_WINDOWS_BUILDROOT)
mkdir -p $(OPENVPN_WINDOWS_SOURCEROOT)
ln -sf $(PWD)/openssl $(OPENVPN_WINDOWS_BUILDROOT)/openssl-$(OPENSSL_VERSION)
ln -sf $(PWD)/openvpn $(OPENVPN_WINDOWS_BUILDROOT)/openvpn-$(OPENVPN_VERSION)
cd openvpn; autoreconf -fiv
EXTRA_OPENVPN_CONFIG="$(OPENVPN_CONFIG)" \
OPENVPN_VERSION="$(OPENVPN_VERSION)" \
OPENSSL_VERSION="$(OPENSSL_VERSION)" \
TAP_CFLAGS="-I$(PWD)/x86_64-pc-windows-msvc/tap-windows" \
EXTRA_OPENSSL_CONFIG="-static-libgcc no-shared $(OPENSSL_CONFIG)" \
EXTRA_TARGET_LDFLAGS="-Wl,-Bstatic" \
OPT_OPENVPN_CFLAGS="-O2 -flto" \
CHOST=x86_64-w64-mingw32 \
CBUILD=x86_64-pc-linux-gnu \
DO_STATIC=1 \
IMAGEROOT="$(BUILD_DIR)" \
./openvpn-build/generic/build
cp openvpn/src/openvpn/openvpn.exe ./x86_64-pc-windows-msvc/
apisocks5:
# GOOS and GOARCH enable cross-compiling
# ldflags -s and -w produce a stipped binary (https://pkg.go.dev/cmd/link)
cd apisocks5;\
GOOS=$(GOOS) GOARCH=$(GOARCH) go build -ldflags="-s -w" -o ../$(TARGET)/
ifneq (,$(findstring unknown-linux-gnu,$(TARGET)))
libnl:
@echo "Building libnl"
cd libnl; \
./autogen.sh; \
./configure $(LIBNL_CONFIG); \
$(MAKE) clean; \
$(MAKE)
libmnl:
@echo "Building libmnl"
mkdir -p $(TARGET)
cd libmnl; \
./autogen.sh; \
./configure $(LIBMNL_CONFIG); \
$(MAKE) clean; \
$(MAKE)
cp libmnl/src/.libs/libmnl.a $(TARGET)/
libnftnl: libmnl
@echo "Building libnftnl"
mkdir -p $(TARGET)
cd libnftnl; \
./autogen.sh; \
LIBMNL_LIBS="-L$(PWD)/libmnl/src/.libs -lmnl" \
LIBMNL_CFLAGS="-I$(PWD)/libmnl/include" \
CFLAGS="$(LIBNFTNL_CFLAGS)" \
./configure $(LIBNFTNL_CONFIG); \
$(MAKE) clean; \
$(MAKE)
cp libnftnl/src/.libs/libnftnl.a $(TARGET)/
else
libnl:
libmnl:
libnftnl:
endif