<feed xmlns='http://www.w3.org/2005/Atom'>
<title>packages/utils/cryptsetup/patches/010-configure-detect-openssl-without-argon2.patch, branch master</title>
<subtitle>Mirror of packages feed</subtitle>
<id>https://git.openwrt.org/feed/packages/atom?h=master</id>
<link rel='self' href='https://git.openwrt.org/feed/packages/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/'/>
<updated>2026-09-11T00:46:29Z</updated>
<entry>
<title>cryptsetup: fix Argon2 with OpenSSL built without it</title>
<updated>2026-09-11T00:46:29Z</updated>
<author>
<name>Daniel Golle</name>
</author>
<published>2026-09-10T14:33:44Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=5b684a6713c98507edadb70869cb1653044497fa'/>
<id>urn:sha1:5b684a6713c98507edadb70869cb1653044497fa</id>
<content type='text'>
OpenWrt builds OpenSSL with no-blake2, which OpenSSL's Configure turns
into no-argon2 because Argon2 is built on BLAKE2b. The cryptsetup
configure script only looks for the OSSL_KDF_PARAM_ARGON2_VERSION macro,
which such a build still installs, so it drops the bundled Argon2 and
EVP_KDF_fetch() fails at runtime. Every LUKS2 keyslot using Argon2 then
fails instantly with "Keyslot open failed", and cryptsetup benchmark
reports argon2id as N/A. Add a patch that also checks OPENSSL_NO_ARGON2
so the bundled implementation is used again.

Fixes: fbac2e7861fb ("cryptsetup: update to 2.8.7")
Signed-off-by: Daniel Golle &lt;daniel@makrotopia.org&gt;
</content>
</entry>
</feed>
