Replace NSS with Pale Moon's

This commit is contained in:
wuggy 2026-06-29 21:29:25 +01:00
commit 8c2e376f94
2870 changed files with 1762232 additions and 1374220 deletions

View file

@ -17,7 +17,7 @@
'<(DEPTH)/exports.gyp:nss_exports'
],
'conditions': [
[ 'cc_is_clang==1', {
[ 'cc_is_clang==1 and force_integrated_as!=1', {
'cflags': [
'-no-integrated-as',
],
@ -54,28 +54,55 @@
],
},
{
# TODO: make this so that all hardware accelerated code is in here.
'target_name': 'hw-acc-crypto',
'target_name': 'hw-acc-crypto-avx',
'type': 'static_library',
'sources': [
'verified/Hacl_Chacha20_Vec128.c',
],
# 'sources': [
# All AVX hardware accelerated crypto currently requires x64
# ],
'dependencies': [
'<(DEPTH)/exports.gyp:nss_exports'
],
'conditions': [
[ 'target_arch=="ia32" or target_arch=="x64"', {
[ 'target_arch=="x64"', {
'cflags': [
'-mssse3'
'-mssse3',
'-msse4.1',
'-msse4.2'
],
'cflags_mozilla': [
'-mssse3'
'-mssse3',
'-msse4.1',
'-msse4.2',
'-mpclmul',
'-maes',
'-mavx',
],
# GCC doesn't define this.
'defines': [
'__SSSE3__',
],
}],
[ 'OS=="linux" or OS=="android" or OS=="dragonfly" or OS=="freebsd" or \
OS=="netbsd" or OS=="openbsd"', {
'cflags': [
'-mpclmul',
'-maes',
'-mavx',
],
}],
# macOS build doesn't use cflags.
[ 'OS=="mac" or OS=="ios"', {
'xcode_settings': {
'OTHER_CFLAGS': [
'-mssse3',
'-msse4.1',
'-msse4.2',
'-mpclmul',
'-maes',
'-mavx',
],
},
}],
[ 'target_arch=="arm"', {
# Gecko doesn't support non-NEON platform on Android, but tier-3
# platform such as Linux/arm will need it
@ -83,6 +110,82 @@
'-mfpu=neon'
],
}],
[ 'target_arch=="x64"', {
'sources': [
'verified/Hacl_Poly1305_128.c',
'verified/Hacl_Chacha20_Vec128.c',
'verified/Hacl_Chacha20Poly1305_128.c',
],
}],
],
},
{
'target_name': 'hw-acc-crypto-avx2',
'type': 'static_library',
# 'sources': [
# All AVX2 hardware accelerated crypto currently requires x64
# ],
'dependencies': [
'<(DEPTH)/exports.gyp:nss_exports'
],
'conditions': [
[ 'target_arch=="x64"', {
'cflags': [
'-mssse3',
'-msse4.1',
'-msse4.2'
],
'cflags_mozilla': [
'-mssse3',
'-msse4.1',
'-msse4.2',
'-mpclmul',
'-maes',
'-mavx',
'-mavx2',
],
# GCC doesn't define this.
'defines': [
'__SSSE3__',
],
}],
[ 'OS=="linux" or OS=="android" or OS=="dragonfly" or OS=="freebsd" or \
OS=="netbsd" or OS=="openbsd"', {
'cflags': [
'-mpclmul',
'-maes',
'-mavx',
'-mavx2',
],
}],
# macOS build doesn't use cflags.
[ 'OS=="mac" or OS=="ios"', {
'xcode_settings': {
'OTHER_CFLAGS': [
'-mssse3',
'-msse4.1',
'-msse4.2',
'-mpclmul',
'-maes',
'-mavx',
'-mavx2',
],
},
}],
[ 'target_arch=="arm"', {
# Gecko doesn't support non-NEON platform on Android, but tier-3
# platform such as Linux/arm will need it
'cflags_mozilla': [
'-mfpu=neon'
],
}],
[ 'target_arch=="x64"', {
'sources': [
'verified/Hacl_Poly1305_256.c',
'verified/Hacl_Chacha20_Vec256.c',
'verified/Hacl_Chacha20Poly1305_256.c',
],
}],
],
},
{
@ -116,6 +219,57 @@
}]
]
},
{
'target_name': 'sha-x86_c_lib',
'type': 'static_library',
'sources': [
'sha256-x86.c'
],
'dependencies': [
'<(DEPTH)/exports.gyp:nss_exports'
],
'cflags': [
'-msha',
'-mssse3',
'-msse4.1'
],
'cflags_mozilla': [
'-msha',
'-mssse3',
'-msse4.1'
],
'conditions': [
# macOS build doesn't use cflags.
[ 'OS=="mac" or OS=="ios"', {
'xcode_settings': {
'OTHER_CFLAGS': [
'-msha',
'-mssse3',
'-msse4.1'
],
},
}]
]
},
{
'target_name': 'gcm-aes-arm32-neon_c_lib',
'type': 'static_library',
'sources': [
'gcm-arm32-neon.c'
],
'dependencies': [
'<(DEPTH)/exports.gyp:nss_exports'
],
'cflags': [
'-march=armv7',
'-mfpu=neon',
'<@(softfp_cflags)',
],
'cflags_mozilla': [
'-mfpu=neon',
'<@(softfp_cflags)',
]
},
{
'target_name': 'gcm-aes-aarch64_c_lib',
'type': 'static_library',
@ -136,18 +290,167 @@
'target_name': 'gcm-aes-ppc_c_lib',
'type': 'static_library',
'sources': [
'gcm-ppc.c'
'gcm-ppc.c',
'sha512-p8.s',
],
'dependencies': [
'<(DEPTH)/exports.gyp:nss_exports'
],
'cflags': [
'-mcrypto',
'-maltivec'
'conditions': [
[ 'disable_crypto_vsx==0', {
'cflags': [
'-mcrypto',
'-maltivec'
],
'cflags_mozilla': [
'-mcrypto',
'-maltivec'
],
}, 'disable_crypto_vsx==1', {
'cflags': [
'-maltivec'
],
'cflags_mozilla': [
'-maltivec'
],
}]
]
},
{
'target_name': 'gcm-aes-ppc_lib',
'type': 'static_library',
'sources': [
'ppc-gcm.s',
],
'cflags_mozilla': [
'-mcrypto',
'-maltivec'
'dependencies': [
'<(DEPTH)/exports.gyp:nss_exports'
],
'conditions': [
[ 'cc_is_clang==1 and force_integrated_as!=1', {
'cflags': [
'-no-integrated-as',
],
'cflags_mozilla': [
'-no-integrated-as',
],
'asflags_mozilla': [
'-no-integrated-as',
],
}],
],
},
{
'target_name': 'ppc-gcm-wrap-nodepend_c_lib',
'type': 'static_library',
'sources': [
'ppc-gcm-wrap.c',
],
'dependencies': [
'<(DEPTH)/exports.gyp:nss_exports',
'gcm-aes-ppc_lib',
],
},
{
'target_name': 'ppc-gcm-wrap_c_lib',
'type': 'static_library',
'sources': [
'ppc-gcm-wrap.c',
],
'dependencies': [
'<(DEPTH)/exports.gyp:nss_exports',
'gcm-aes-ppc_lib',
],
'defines!': [
'FREEBL_NO_DEPEND',
],
},
{
'target_name': 'gcm-sha512-nodepend-ppc_c_lib',
'type': 'static_library',
'sources': [
'sha512.c',
],
'dependencies': [
'<(DEPTH)/exports.gyp:nss_exports'
],
'conditions': [
[ 'disable_crypto_vsx==0', {
'cflags': [
'-mcrypto',
'-maltivec',
'-mvsx',
'-funroll-loops',
'-fpeel-loops'
],
'cflags_mozilla': [
'-mcrypto',
'-maltivec',
'-mvsx',
'-funroll-loops',
'-fpeel-loops'
],
}, 'disable_crypto_vsx==1', {
'cflags': [
'-maltivec',
'-funroll-loops',
'-fpeel-loops'
],
'cflags_mozilla': [
'-maltivec',
'-funroll-loops',
'-fpeel-loops'
],
}]
]
},
{
'target_name': 'gcm-sha512-ppc_c_lib',
'type': 'static_library',
'sources': [
'sha512.c',
],
'dependencies': [
'<(DEPTH)/exports.gyp:nss_exports'
],
'conditions': [
[ 'disable_crypto_vsx==0', {
'cflags': [
'-mcrypto',
'-maltivec',
'-mvsx',
'-funroll-loops',
'-fpeel-loops'
],
'cflags_mozilla': [
'-mcrypto',
'-maltivec',
'-mvsx',
'-funroll-loops',
'-fpeel-loops'
],
}, 'disable_crypto_vsx==1', {
'cflags': [
'-maltivec',
'-funroll-loops',
'-fpeel-loops'
],
'cflags_mozilla': [
'-maltivec',
'-funroll-loops',
'-fpeel-loops'
],
}]
],
'defines!': [
'FREEBL_NO_DEPEND',
],
},
{
'target_name': 'chacha20-ppc_lib',
'type': 'static_library',
'sources': [
'chacha20poly1305-ppc.c',
'chacha20-ppc64le.S',
]
},
{
@ -155,6 +458,8 @@
'type': 'static_library',
'sources': [
'aes-armv8.c',
'sha1-armv8.c',
'sha256-armv8.c',
],
'dependencies': [
'<(DEPTH)/exports.gyp:nss_exports'
@ -163,11 +468,13 @@
[ 'target_arch=="arm"', {
'cflags': [
'-march=armv8-a',
'-mfpu=crypto-neon-fp-armv8'
'-mfpu=crypto-neon-fp-armv8',
'<@(softfp_cflags)',
],
'cflags_mozilla': [
'-march=armv8-a',
'-mfpu=crypto-neon-fp-armv8'
'-mfpu=crypto-neon-fp-armv8',
'<@(softfp_cflags)',
],
}, 'target_arch=="arm64" or target_arch=="aarch64"', {
'cflags': [
@ -200,26 +507,61 @@
],
'dependencies': [
'<(DEPTH)/exports.gyp:nss_exports',
'hw-acc-crypto',
'hw-acc-crypto-avx',
'hw-acc-crypto-avx2',
],
'conditions': [
[ 'target_arch=="ia32" or target_arch=="x64"', {
'dependencies': [
'gcm-aes-x86_c_lib',
],
}, 'disable_arm_hw_aes==0 and (target_arch=="arm" or target_arch=="arm64" or target_arch=="aarch64")', {
}, '(disable_arm_hw_aes==0 or disable_arm_hw_sha1==0 or disable_arm_hw_sha2==0) and (target_arch=="arm" or target_arch=="arm64" or target_arch=="aarch64")', {
'dependencies': [
'armv8_c_lib'
],
}],
[ '(target_arch=="ia32" or target_arch=="x64") and disable_intel_hw_sha==0', {
'dependencies': [
'sha-x86_c_lib',
],
}],
[ 'disable_arm32_neon==0 and target_arch=="arm"', {
'dependencies': [
'gcm-aes-arm32-neon_c_lib',
],
}],
[ 'disable_arm32_neon==1 and target_arch=="arm"', {
'defines!': [
'NSS_DISABLE_ARM32_NEON',
],
}],
[ 'target_arch=="arm64" or target_arch=="aarch64"', {
'dependencies': [
'gcm-aes-aarch64_c_lib',
],
}],
[ 'target_arch=="ppc64le"', {
[ 'disable_altivec==0 and target_arch=="ppc64"', {
'dependencies': [
'gcm-aes-ppc_c_lib',
'gcm-sha512-ppc_c_lib',
],
}],
[ 'disable_altivec==0 and target_arch=="ppc64le"', {
'dependencies': [
'gcm-aes-ppc_c_lib',
'gcm-sha512-ppc_c_lib',
'chacha20-ppc_lib',
'ppc-gcm-wrap_c_lib',
],
}],
[ 'disable_altivec==1 and (target_arch=="ppc64" or target_arch=="ppc64le")', {
'defines!': [
'NSS_DISABLE_ALTIVEC',
],
}],
[ 'disable_crypto_vsx==1 and (target_arch=="ppc" or target_arch=="ppc64" or target_arch=="ppc64le")', {
'defines!': [
'NSS_DISABLE_CRYPTO_VSX',
],
}],
[ 'OS=="linux"', {
@ -228,6 +570,7 @@
'FREEBL_LOWHASH',
'USE_HW_AES',
'INTEL_GCM',
'PPC_GCM',
],
'conditions': [
[ 'target_arch=="x64"', {
@ -251,7 +594,8 @@
],
'dependencies': [
'<(DEPTH)/exports.gyp:nss_exports',
'hw-acc-crypto',
'hw-acc-crypto-avx',
'hw-acc-crypto-avx2',
],
'conditions': [
[ 'target_arch=="ia32" or target_arch=="x64"', {
@ -263,14 +607,50 @@
'armv8_c_lib',
],
}],
[ '(target_arch=="ia32" or target_arch=="x64") and disable_intel_hw_sha==0', {
'dependencies': [
'sha-x86_c_lib',
],
}],
[ 'disable_arm32_neon==0 and target_arch=="arm"', {
'dependencies': [
'gcm-aes-arm32-neon_c_lib',
],
}],
[ 'disable_arm32_neon==1 and target_arch=="arm"', {
'defines!': [
'NSS_DISABLE_ARM32_NEON',
],
}],
[ 'target_arch=="arm64" or target_arch=="aarch64"', {
'dependencies': [
'gcm-aes-aarch64_c_lib',
],
}],
[ 'target_arch=="ppc64" or target_arch=="ppc64le"', {
'dependencies': [
'gcm-aes-ppc_c_lib',
[ 'disable_altivec==0', {
'conditions': [
[ 'target_arch=="ppc64"', {
'dependencies': [
'gcm-aes-ppc_c_lib',
'gcm-sha512-nodepend-ppc_c_lib',
],
}, 'target_arch=="ppc64le"', {
'dependencies': [
'gcm-aes-ppc_c_lib',
'gcm-sha512-nodepend-ppc_c_lib',
'ppc-gcm-wrap-nodepend_c_lib',
],
}],
],
}],
[ 'disable_altivec==1 and (target_arch=="ppc64" or target_arch=="ppc64le")', {
'defines!': [
'NSS_DISABLE_ALTIVEC',
],
}],
[ 'disable_crypto_vsx==1 and (target_arch=="ppc" or target_arch=="ppc64" or target_arch=="ppc64le")', {
'defines!': [
'NSS_DISABLE_CRYPTO_VSX',
],
}],
[ 'OS!="linux"', {
@ -291,7 +671,7 @@
'intel-gcm-wrap_c_lib',
],
}],
[ 'OS=="win" and cc_is_clang==1', {
[ 'OS=="win" and (target_arch=="ia32" or target_arch=="x64") and cc_is_clang==1', {
'dependencies': [
'intel-gcm-wrap_c_lib',
],
@ -321,7 +701,8 @@
'type': 'shared_library',
'dependencies': [
'<(DEPTH)/exports.gyp:nss_exports',
'hw-acc-crypto',
'hw-acc-crypto-avx',
'hw-acc-crypto-avx2',
],
},
{
@ -337,7 +718,8 @@
],
'dependencies': [
'<(DEPTH)/exports.gyp:nss_exports',
'hw-acc-crypto',
'hw-acc-crypto-avx',
'hw-acc-crypto-avx2',
],
'asflags_mozilla': [
'-mcpu=v9', '-Wa,-xarch=v9a'
@ -379,6 +761,10 @@
'mpi',
'ecl',
'verified',
'verified/internal',
'verified/karamel/include',
'verified/karamel/krmllib/dist/minimal',
'deprecated',
],
'defines': [
'SHLIB_SUFFIX=\"<(dll_suffix)\"',
@ -422,20 +808,49 @@
},
},
}],
[ '(OS=="win" or OS=="mac" or OS=="ios") and (target_arch=="ia32" or target_arch=="x64") and disable_intel_hw_sha==0', {
'defines': [
'USE_HW_SHA2',
],
}],
[ '(OS=="win" or OS=="mac" or OS=="ios") and (target_arch=="arm64" or target_arch=="aarch64") and disable_arm_hw_aes==0', {
'defines': [
'USE_HW_AES',
],
}],
[ '(OS=="win" or OS=="mac" or OS=="ios") and (target_arch=="arm64" or target_arch=="aarch64") and disable_arm_hw_sha1==0', {
'defines': [
'USE_HW_SHA1',
],
}],
[ '(OS=="win" or OS=="mac" or OS=="ios") and (target_arch=="arm64" or target_arch=="aarch64") and disable_arm_hw_sha2==0', {
'defines': [
'USE_HW_SHA2',
],
}],
[ 'cc_use_gnu_ld==1 and OS=="win" and target_arch=="x64"', {
# mingw x64
'defines': [
'MP_IS_LITTLE_ENDIAN',
],
}],
[ 'have_int128_support==1', {
# Poly1305_256 requires the flag to run
['target_arch=="x64"', {
'defines':[
'HACL_CAN_COMPILE_VEC128',
'HACL_CAN_COMPILE_VEC256',
],
}],
# MSVC has no __int128 type. Use emulated int128 and leave
# have_int128_support as-is for Curve25519 impl. selection.
[ 'have_int128_support==1 and (OS!="win" or cc_is_clang==1 or cc_is_gcc==1)', {
'defines': [
# The Makefile does version-tests on GCC, but we're not doing that here.
'HAVE_INT128_SUPPORT',
],
}, {
'defines': [
'KRML_NOUINT128',
'KRML_VERIFIED_UINT128',
],
}],
[ 'OS=="linux"', {
@ -443,6 +858,13 @@
'FREEBL_LOWHASH',
'FREEBL_NO_DEPEND',
],
'conditions': [
[ 'disable_altivec==0 and target_arch=="ppc64le"', {
'defines': [
'PPC_GCM',
],
}],
],
}],
[ 'OS=="linux" or OS=="android"', {
'conditions': [
@ -479,11 +901,26 @@
'ARMHF',
],
}],
[ 'disable_intel_hw_sha==0 and (target_arch=="ia32" or target_arch=="x64")', {
'defines': [
'USE_HW_SHA2',
],
}],
[ 'disable_arm_hw_aes==0 and (target_arch=="arm" or target_arch=="arm64" or target_arch=="aarch64")', {
'defines': [
'USE_HW_AES',
],
}],
[ 'disable_arm_hw_sha1==0 and (target_arch=="arm" or target_arch=="arm64" or target_arch=="aarch64")', {
'defines': [
'USE_HW_SHA1',
],
}],
[ 'disable_arm_hw_sha2==0 and (target_arch=="arm" or target_arch=="arm64" or target_arch=="aarch64")', {
'defines': [
'USE_HW_SHA2',
],
}],
],
}],
],
@ -491,17 +928,16 @@
'variables': {
'module': 'nss',
'conditions': [
[ 'OS!="win"', {
'conditions': [
[ 'target_arch=="x64" or target_arch=="arm64" or target_arch=="aarch64"', {
'have_int128_support%': 1,
}, {
'have_int128_support%': 0,
}],
],
[ 'target_arch=="x64" or target_arch=="arm64" or target_arch=="aarch64"', {
'have_int128_support%': 1,
}, {
'have_int128_support%': 0,
}],
[ 'target_arch=="arm"', {
# When the compiler uses the softfloat ABI, we want to use the compatible softfp ABI when enabling NEON for these objects.
# Confusingly, __SOFTFP__ is the name of the define for the softfloat ABI, not for the softfp ABI.
'softfp_cflags': '<!(${CC:-cc} -o - -E -dM - ${CFLAGS} < /dev/null | grep __SOFTFP__ > /dev/null && echo -mfloat-abi=softfp || true)',
}],
],
}
}