more build updates.

removing openssl dependency (except on Linux where it's still necessary)
upgrade cpp-httplib
new cmake-presets
This commit is contained in:
Grant Limberg
2026-06-15 18:51:24 -07:00
parent ace5352388
commit c02c649cd3
6 changed files with 135 additions and 22 deletions
+104 -10
View File
@@ -74,9 +74,17 @@ set(ZT_SSO_SUPPORTED FALSE)
if(CPU_ARCHITECTURE STREQUAL "x86_64" OR CPU_ARCHITECTURE STREQUAL "amd64")
set(ZT_ARCHITECTURE 2)
set(ZT_USE_X64_ASM_SALSA TRUE)
set(ZT_USE_X64_ASM_ED25519 TRUE)
# x64 ed25519 asm (qhasm): Linux/BSD only here, matching make-mac.mk which omits it on
# macOS (macOS uses the portable Ed25519). NB: it *does* assemble on macOS and the .s
# export macOS-underscored symbols, so this is a parity choice with make-mac.mk, not a
# technical limitation.
if(NOT APPLE)
set(ZT_USE_X64_ASM_ED25519 TRUE)
endif()
set(ZT_SSO_SUPPORTED TRUE)
if(NOT MSVC)
# macOS x86_64 has SSE2 by default; skip the explicit flag (it would also leak into
# the arm64 slice of a universal build). See the aarch64 branch note below.
if(NOT MSVC AND NOT APPLE)
add_compile_options(-msse -msse2)
endif()
elseif(CPU_ARCHITECTURE STREQUAL "e2k" OR CPU_ARCHITECTURE STREQUAL "e2k64")
@@ -90,9 +98,15 @@ elseif(CPU_ARCHITECTURE STREQUAL "i386" OR CPU_ARCHITECTURE STREQUAL "i486"
elseif(CPU_ARCHITECTURE STREQUAL "aarch64" OR CPU_ARCHITECTURE STREQUAL "arm64")
set(ZT_ARCHITECTURE 4)
set(ZT_SSO_SUPPORTED TRUE)
add_definitions(-DZT_NO_TYPE_PUNNING -DZT_ARCH_ARM_HAS_NEON)
if(NOT MSVC)
add_compile_options(-march=armv8-a+crypto -mtune=generic -mstrict-align)
# On Apple, omit the explicit arch defines/flags and let Constants.hpp / AES.hpp
# self-detect from compiler builtins (per -arch slice) -- this is what make-mac.mk
# does, and it's required for universal (arm64 + x86_64) builds, where a global
# -march=armv8-a+crypto or -DZT_ARCH_ARM_HAS_NEON would wrongly hit the x86_64 slice.
if(NOT APPLE)
add_definitions(-DZT_NO_TYPE_PUNNING -DZT_ARCH_ARM_HAS_NEON)
if(NOT MSVC)
add_compile_options(-march=armv8-a+crypto -mtune=generic -mstrict-align)
endif()
endif()
elseif(CPU_ARCHITECTURE MATCHES "^(arm|armel|armhf|armv6|armv6l|armv6k|armv6kz|armv6zk|armv7|armv7l|armv7hl|armv7ve)$")
set(ZT_ARCHITECTURE 3)
@@ -205,6 +219,20 @@ if(ZT_SSO_SUPPORTED)
add_definitions(-DZT_SSO_SUPPORTED=1)
endif()
# A universal macOS build can't put the per-arch crypto .s asm in the (fat) core target --
# it would be assembled for the wrong slice. Mirror make-mac.mk: keep the x64 Salsa20/12
# asm but build it as a separate x86_64-only object (node/CMakeLists.txt) and define
# ZT_USE_X64_ASM_SALSA2012 so Packet.cpp uses it -- its `&& ZT_ARCH_X64` guard keeps it off
# the arm64 slice. The ed25519/arm32 asm aren't used on macOS, so drop those.
list(LENGTH CMAKE_OSX_ARCHITECTURES _zt_osx_arch_count)
if(APPLE AND _zt_osx_arch_count GREATER 1)
set(ZT_USE_X64_ASM_SALSA FALSE) # not added to the fat core target...
set(ZT_MACOS_UNIVERSAL_X64_SALSA_ASM TRUE) # ...built x86_64-only and linked in instead
add_definitions(-DZT_USE_X64_ASM_SALSA2012)
set(ZT_USE_X64_ASM_ED25519 FALSE)
set(ZT_USE_ARM32_NEON_ASM_CRYPTO FALSE)
endif()
# Faster crypto assembly. These -D gates pair with the source selection in
# node/CMakeLists.txt, which reads the ZT_USE_*_ASM_* variables set above.
if(ZT_USE_X64_ASM_SALSA)
@@ -375,7 +403,17 @@ endif()
include(FetchContent)
include(ExternalProject)
find_package(OpenSSL REQUIRED)
# OpenSSL is not used by the C++ daemon: the control plane is plain-HTTP cpp-httplib
# (HTTPLIB_USE_OPENSSL_IF_AVAILABLE=OFF) and SSO/OIDC TLS lives in rustybits (native-tls).
# It IS needed for the controller (libpq/redis TLS) and on Linux/BSD (rustybits' native-tls
# links system OpenSSL there). macOS/Windows daemons need none -- which is what lets a
# universal macOS build avoid a fat OpenSSL.
if(ZT1_CENTRAL_CONTROLLER OR (UNIX AND NOT APPLE))
set(ZT_NEED_OPENSSL TRUE)
endif()
if(ZT_NEED_OPENSSL)
find_package(OpenSSL REQUIRED)
endif()
find_package(nlohmann_json REQUIRED)
# inja: found if installed (Homebrew), otherwise fetched (Debian has no package).
include(cmake/inja.cmake)
@@ -441,9 +479,62 @@ endif()
# rustybits (built via cargo, linked as a static library)
# ---------------------------------------------------------------------------
if(WIN32)
set(RUSTYBITS_LIB ${PROJ_DIR}/rustybits/target/release/rustybits.lib)
# cargo builds for the host triple by default; cross-target the selected arch
# explicitly so an x64 host can build x86/ARM64. The lib then lands under
# target/<triple>/release. (The cbindgen header always goes to target/rustybits.h
# per rustybits/build.rs, regardless of --target.) Requires the Rust target to be
# installed: rustup target add {i686,aarch64}-pc-windows-msvc.
if(ZT_ARCHITECTURE EQUAL 1)
set(RUSTYBITS_TRIPLE i686-pc-windows-msvc)
elseif(ZT_ARCHITECTURE EQUAL 4)
set(RUSTYBITS_TRIPLE aarch64-pc-windows-msvc)
else()
set(RUSTYBITS_TRIPLE x86_64-pc-windows-msvc)
endif()
set(RUSTYBITS_LIB ${PROJ_DIR}/rustybits/target/${RUSTYBITS_TRIPLE}/release/rustybits.lib)
set(RUSTYBITS_BUILD_COMMAND cd ${PROJ_DIR}/rustybits && cargo build --release --target ${RUSTYBITS_TRIPLE})
elseif(APPLE)
# Honor CMAKE_OSX_ARCHITECTURES so rustybits matches the C/C++ slices. cargo builds
# one target triple at a time, so a universal (multi-arch) build builds each arch and
# lipo's them into one fat archive. Unset = native host build. Cross / universal builds
# need the Rust target(s): rustup target add {x86_64,aarch64}-apple-darwin.
set(_rb_triples "")
foreach(_a IN LISTS CMAKE_OSX_ARCHITECTURES)
if(_a STREQUAL "x86_64")
list(APPEND _rb_triples x86_64-apple-darwin)
elseif(_a STREQUAL "arm64")
list(APPEND _rb_triples aarch64-apple-darwin)
endif()
endforeach()
list(LENGTH _rb_triples _rb_n)
if(_rb_n GREATER 1)
# Universal: build each arch, then lipo into a single fat static lib.
set(RUSTYBITS_LIB ${PROJ_DIR}/rustybits/target/zt-universal/librustybits.a)
set(RUSTYBITS_BUILD_COMMAND "")
set(_rb_lipo_inputs "")
foreach(_t IN LISTS _rb_triples)
if(RUSTYBITS_BUILD_COMMAND)
list(APPEND RUSTYBITS_BUILD_COMMAND COMMAND)
endif()
list(APPEND RUSTYBITS_BUILD_COMMAND cd ${PROJ_DIR}/rustybits && cargo build --release --target ${_t})
list(APPEND _rb_lipo_inputs ${PROJ_DIR}/rustybits/target/${_t}/release/librustybits.a)
endforeach()
list(APPEND RUSTYBITS_BUILD_COMMAND
COMMAND ${CMAKE_COMMAND} -E make_directory ${PROJ_DIR}/rustybits/target/zt-universal
COMMAND lipo -create -output ${RUSTYBITS_LIB} ${_rb_lipo_inputs})
elseif(_rb_n EQUAL 1)
# Single explicit arch (e.g. cross-compiling x86_64 on an arm64 host).
set(RUSTYBITS_LIB ${PROJ_DIR}/rustybits/target/${_rb_triples}/release/librustybits.a)
set(RUSTYBITS_BUILD_COMMAND cd ${PROJ_DIR}/rustybits && cargo build --release --target ${_rb_triples})
else()
# No explicit arch: native host build.
set(RUSTYBITS_LIB ${PROJ_DIR}/rustybits/target/release/librustybits.a)
set(RUSTYBITS_BUILD_COMMAND cd ${PROJ_DIR}/rustybits && cargo build --release)
endif()
else()
# Linux / BSD: native host build.
set(RUSTYBITS_LIB ${PROJ_DIR}/rustybits/target/release/librustybits.a)
set(RUSTYBITS_BUILD_COMMAND cd ${PROJ_DIR}/rustybits && cargo build --release)
endif()
set(RUSTYBITS_INCLUDE_DIR ${PROJ_DIR}/rustybits/target)
@@ -451,7 +542,7 @@ ExternalProject_Add(
rustybits_build
DOWNLOAD_COMMAND ""
CONFIGURE_COMMAND ""
BUILD_COMMAND cd ${PROJ_DIR}/rustybits && cargo build --release
BUILD_COMMAND ${RUSTYBITS_BUILD_COMMAND}
INSTALL_COMMAND ""
BUILD_BYPRODUCTS ${RUSTYBITS_LIB} ${RUSTYBITS_INCLUDE_DIR}/rustybits.h
)
@@ -489,9 +580,12 @@ set(LINKED_LIBRARIES
nlohmann_json::nlohmann_json
opentelemetry-cpp::api
rustybits
OpenSSL::Crypto
OpenSSL::SSL
)
# OpenSSL only where it's actually needed (controller / Linux rustybits); the macOS/
# Windows daemon links none. See the find_package(OpenSSL) note above.
if(ZT_NEED_OPENSSL)
list(APPEND LINKED_LIBRARIES OpenSSL::Crypto OpenSSL::SSL)
endif()
# The bundled FileDB network controller (only built when ZT_NONFREE; central
# backends are layered in under ZT1_CENTRAL_CONTROLLER inside the target).
+4
View File
@@ -41,6 +41,8 @@
{ "name": "macos-controller-debug", "inherits": "macos-base", "displayName": "macOS Central Controller (Debug)", "cacheVariables": { "ZT1_CENTRAL_CONTROLLER": "ON", "CMAKE_BUILD_TYPE": "Debug" } },
{ "name": "macos-free-release", "inherits": "macos-base", "displayName": "macOS daemon, free / no controller (Release)", "cacheVariables": { "ZT_NONFREE": "OFF" } },
{ "name": "macos-free-debug", "inherits": "macos-base", "displayName": "macOS daemon, free / no controller (Debug)", "cacheVariables": { "ZT_NONFREE": "OFF", "CMAKE_BUILD_TYPE": "Debug" } },
{ "name": "macos-universal-release", "inherits": "macos-base", "displayName": "macOS universal daemon (arm64 + x86_64, Release)", "cacheVariables": { "CMAKE_OSX_ARCHITECTURES": "arm64;x86_64" } },
{ "name": "macos-universal-debug", "inherits": "macos-base", "displayName": "macOS universal daemon (arm64 + x86_64, Debug)", "cacheVariables": { "CMAKE_OSX_ARCHITECTURES": "arm64;x86_64", "CMAKE_BUILD_TYPE": "Debug" } },
{
"name": "windows-x64",
@@ -101,6 +103,8 @@
{ "name": "macos-controller-debug", "configurePreset": "macos-controller-debug" },
{ "name": "macos-free-release", "configurePreset": "macos-free-release" },
{ "name": "macos-free-debug", "configurePreset": "macos-free-debug" },
{ "name": "macos-universal-release", "configurePreset": "macos-universal-release" },
{ "name": "macos-universal-debug", "configurePreset": "macos-universal-debug" },
{ "name": "windows-x64-release", "configurePreset": "windows-x64", "configuration": "Release" },
{ "name": "windows-x64-debug", "configurePreset": "windows-x64", "configuration": "Debug" },
{ "name": "windows-arm64-release", "configurePreset": "windows-arm64", "configuration": "Release" },
+5 -1
View File
@@ -14,7 +14,11 @@ set(BUILD_SHARED_LIBS OFF CACHE INTERNAL "")
set(HTTPLIB_COMPILE OFF CACHE INTERNAL "")
set(HTTPLIB_USE_ZLIB_IF_AVAILABLE ON CACHE INTERNAL "Use zlib if available")
set(HTTPLIB_USE_BROTLI_IF_AVAILABLE ON CACHE INTERNAL "Use brotli if available")
set(HTTPLIB_USE_OPENSSL_IF_AVAILABLE ON CACHE INTERNAL "Use OpenSSL if available")
# The ZeroTier control plane is plain HTTP on localhost (no httplib SSLServer/SSLClient
# anywhere), and outbound SSO/OIDC TLS lives in rustybits (native-tls), so httplib never
# needs OpenSSL. Keeping this ON would link OpenSSL purely as dead weight -- which also
# blocks universal macOS builds (Homebrew OpenSSL is single-arch).
set(HTTPLIB_USE_OPENSSL_IF_AVAILABLE OFF CACHE INTERNAL "ZeroTier uses httplib for plain HTTP only")
set(HTTPLIB_USE_ZSTD_IF_AVAILABLE ON CACHE INTERNAL "Use zstd if available")
FetchContent_MakeAvailable(cpp-httplib)
+17 -4
View File
@@ -113,9 +113,22 @@ target_include_directories(zerotier-core
PRIVATE
${prometheus-cpp-lite_INCLUDE}
)
target_link_libraries(zerotier-core
PRIVATE
nlohmann_json::nlohmann_json
Threads::Threads
target_link_libraries(zerotier-core
PRIVATE
nlohmann_json::nlohmann_json
Threads::Threads
prometheus-cpp-lite
Threads::Threads)
# macOS universal: the x64 Salsa20/12 asm must be a single-arch (x86_64) object so it
# lands only in the x86_64 slice of the fat binary (mirrors make-mac.mk's `as -arch
# x86_64`). A separate target with OSX_ARCHITECTURES x86_64 does that under a universal
# configure; Packet.cpp's `ZT_USE_X64_ASM_SALSA2012 && ZT_ARCH_X64` guard keeps the arm64
# slice from referencing it.
if(ZT_MACOS_UNIVERSAL_X64_SALSA_ASM)
add_library(zt-salsa-x64-asm STATIC ${CMAKE_SOURCE_DIR}/ext/x64-salsa2012-asm/salsa2012.s)
set_target_properties(zt-salsa-x64-asm PROPERTIES OSX_ARCHITECTURES "x86_64")
set_source_files_properties(${CMAKE_SOURCE_DIR}/ext/x64-salsa2012-asm/salsa2012.s
PROPERTIES COMPILE_FLAGS "-x assembler-with-cpp")
target_link_libraries(zerotier-core PUBLIC zt-salsa-x64-asm)
endif()
+4 -5
View File
@@ -11,18 +11,17 @@ set(INCLUDE_DIRS
${RUSTYBITS_INCLUDE_DIR}
)
find_package(OpenSSL REQUIRED)
# No OpenSSL here: the control plane is plain-HTTP cpp-httplib and SSO TLS is in rustybits.
# The executable links OpenSSL only where actually needed (controller / Linux rustybits)
# -- see the top-level CMakeLists.
set(LINK_LIBS
zerotier-osdep
zerotier-core
prometheus-cpp-lite
nlohmann_json::nlohmann_json
nlohmann_json::nlohmann_json
Threads::Threads
opentelemetry-cpp::api
Threads::Threads
OpenSSL::Crypto
OpenSSL::SSL
rustybits
)
+1 -2
View File
@@ -1,8 +1,7 @@
{
"name": "zerotierone",
"description": "External dependencies for the ZeroTier One Windows daemon build. opentelemetry-cpp (API only) is provided by scripts/bootstrap-deps.ps1, and inja/cpp-httplib/miniupnpc are fetched by CMake, so they are intentionally not listed here. Only used when configuring with the vcpkg toolchain (the windows-* CMake presets); inert on Linux/macOS.",
"description": "External dependencies for the ZeroTier One Windows daemon build. opentelemetry-cpp (API only) is provided by scripts/bootstrap-deps.ps1, and inja/cpp-httplib/miniupnpc are fetched by CMake, so they are intentionally not listed here. OpenSSL is not needed on Windows either: the control plane is plain-HTTP cpp-httplib and rustybits' SSO TLS uses SChannel (native-tls). Only used when configuring with the vcpkg toolchain (the windows-* CMake presets); inert on Linux/macOS.",
"dependencies": [
"openssl",
"nlohmann-json"
]
}