View Ticket
2026-09-27
14:41 • New ticket [c0cd214ad4] Building And Testing Against A Static OpenSSL Fails. artifact: f37f308176 user: anonymous

Ticket Hash: c0cd214ad4722efae9bf669c7db4abcfa93d4473
Title: Building And Testing Against A Static OpenSSL Fails
Status: Open Type: Build Problem
Severity: Important Priority:
Subsystem: Resolution:
Last Modified: 2026-09-27 14:41:17
18.9 hours ago
Created: 2026-09-27 14:41:17
18.9 hours ago
Version Found In: tcltls-20260905210751-225266f767
User Comments:
anonymous added on 2026-09-27 14:41:17:
Hi,
I've run into a few problems building and testing TclTLS from source against a statically linked version of OpenSSL and a statically linked Tcl installation, these are the problems I encountered with some copy-pasted CLI output below:
1. Just running 'make' fails due to an issue building documentation, the workaround is running 'make binaries && make libraries && make install-binaries && make install-libraries'
2. The build process creates the 'pkgIndex.tcl' in the source directory but does not install it. I had to manually 'install pkgIndex.tcl /path/to/custom/tcl/lib/tcltls2.0.1'
3. Loading the example snippet from the man page fails.
4. I also noticed static library libtcl9tls2.0.1.a is surprisingly small, only 136KB.

> uname -r
6.12.108-1-MANJARO

% info tclversion
9.1

> ./openssl --version
OpenSSL 4.0.2 25 Aug 2026 (Library: OpenSSL 4.0.2 25 Aug 2026)

> cd tcltls-20260905210751-225266f767


> ./configure --disable-shared --enable-static-ssl --with-tcl=/path/to/custom/tcl/lib --with-tclsh=/path/to/custom/tcl/bin/tclsh --with-openssl-pkgconfig=/path/to/custom/openssl/lib64/pkgconfig/ --with-tclinclude=/path/to/custom/tcl/include/ --with-openssl-libdir=/path/to/custom/openssl/lib64/ --enable-64bit

> make
sed -e '/^\\s*\#/d' -e '/^\\s*$/d' -e 's/\\/\\\\/g' -e 's/\"/\\"/g' -e 's/^/"/' \
    -e 's/$/\\n\"/' 'library/tls.tcl' > 'tls.tcl.h' || { rm -f tls.tcl.h; exit 1; }
gcc -DPACKAGE_NAME=\"tls\" -DPACKAGE_TARNAME=\"tls\" -DPACKAGE_VERSION=\"2.0.1\" -DPACKAGE_STRING=\"tls\ 2.0.1\" -DPACKAGE_BUGREPORT=\"\" -DPACKAGE_URL=\"\" -DBUILD_tls=/\*\*/ -DHAVE_STDIO_H=1 -DHAVE_STDLIB_H=1 -DHAVE_STRING_H=1 -DHAVE_INTTYPES_H=1 -DHAVE_STDINT_H=1 -DHAVE_STRINGS_H=1 -DHAVE_SYS_STAT_H=1 -DHAVE_SYS_TYPES_H=1 -DHAVE_UNISTD_H=1 -DSTDC_HEADERS=1 -DUSE_THREAD_ALLOC=1 -D_REENTRANT=1 -D_THREAD_SAFE=1 -DTCL_THREADS=1 -DSTATIC_BUILD=1 -DUSE_TCL_STUBS=1 -DUSE_TCLOO_STUBS=1 -DMODULE_SCOPE=extern\ __attribute__\(\(__visibility__\(\"hidden\"\)\)\) -DHAVE_HIDDEN=1 -DHAVE_CAST_TO_UNION=1 -DHAVE_STDBOOL_H=1 -DTCL_WIDE_INT_IS_LONG=1 -DTCL_CFG_OPTIMIZED=1 -DUSE_TCL_STUBS=1 -DNO_SSL3=1 -D_FORTIFY_SOURCE=2 -fstack-protector-all -fno-strict-overflow  -Wno-deprecated-declarations -I/usr/include -I"/path/to/custom/tcl/include/"  -I.    -O2 -fomit-frame-pointer -DNDEBUG -Wall -fPIC -pipe -m64 -O2 -fomit-frame-pointer -DNDEBUG -Wall  -c `echo ./generic/tls.c` -o tls.o
gcc -DPACKAGE_NAME=\"tls\" -DPACKAGE_TARNAME=\"tls\" -DPACKAGE_VERSION=\"2.0.1\" -DPACKAGE_STRING=\"tls\ 2.0.1\" -DPACKAGE_BUGREPORT=\"\" -DPACKAGE_URL=\"\" -DBUILD_tls=/\*\*/ -DHAVE_STDIO_H=1 -DHAVE_STDLIB_H=1 -DHAVE_STRING_H=1 -DHAVE_INTTYPES_H=1 -DHAVE_STDINT_H=1 -DHAVE_STRINGS_H=1 -DHAVE_SYS_STAT_H=1 -DHAVE_SYS_TYPES_H=1 -DHAVE_UNISTD_H=1 -DSTDC_HEADERS=1 -DUSE_THREAD_ALLOC=1 -D_REENTRANT=1 -D_THREAD_SAFE=1 -DTCL_THREADS=1 -DSTATIC_BUILD=1 -DUSE_TCL_STUBS=1 -DUSE_TCLOO_STUBS=1 -DMODULE_SCOPE=extern\ __attribute__\(\(__visibility__\(\"hidden\"\)\)\) -DHAVE_HIDDEN=1 -DHAVE_CAST_TO_UNION=1 -DHAVE_STDBOOL_H=1 -DTCL_WIDE_INT_IS_LONG=1 -DTCL_CFG_OPTIMIZED=1 -DUSE_TCL_STUBS=1 -DNO_SSL3=1 -D_FORTIFY_SOURCE=2 -fstack-protector-all -fno-strict-overflow  -Wno-deprecated-declarations -I/usr/include -I"/path/to/custom/tcl/include/"  -I.    -O2 -fomit-frame-pointer -DNDEBUG -Wall -fPIC -pipe -m64 -O2 -fomit-frame-pointer -DNDEBUG -Wall  -c `echo ./generic/tlsBIO.c` -o tlsBIO.o
gcc -DPACKAGE_NAME=\"tls\" -DPACKAGE_TARNAME=\"tls\" -DPACKAGE_VERSION=\"2.0.1\" -DPACKAGE_STRING=\"tls\ 2.0.1\" -DPACKAGE_BUGREPORT=\"\" -DPACKAGE_URL=\"\" -DBUILD_tls=/\*\*/ -DHAVE_STDIO_H=1 -DHAVE_STDLIB_H=1 -DHAVE_STRING_H=1 -DHAVE_INTTYPES_H=1 -DHAVE_STDINT_H=1 -DHAVE_STRINGS_H=1 -DHAVE_SYS_STAT_H=1 -DHAVE_SYS_TYPES_H=1 -DHAVE_UNISTD_H=1 -DSTDC_HEADERS=1 -DUSE_THREAD_ALLOC=1 -D_REENTRANT=1 -D_THREAD_SAFE=1 -DTCL_THREADS=1 -DSTATIC_BUILD=1 -DUSE_TCL_STUBS=1 -DUSE_TCLOO_STUBS=1 -DMODULE_SCOPE=extern\ __attribute__\(\(__visibility__\(\"hidden\"\)\)\) -DHAVE_HIDDEN=1 -DHAVE_CAST_TO_UNION=1 -DHAVE_STDBOOL_H=1 -DTCL_WIDE_INT_IS_LONG=1 -DTCL_CFG_OPTIMIZED=1 -DUSE_TCL_STUBS=1 -DNO_SSL3=1 -D_FORTIFY_SOURCE=2 -fstack-protector-all -fno-strict-overflow  -Wno-deprecated-declarations -I/usr/include -I"/path/to/custom/tcl/include/"  -I.    -O2 -fomit-frame-pointer -DNDEBUG -Wall -fPIC -pipe -m64 -O2 -fomit-frame-pointer -DNDEBUG -Wall  -c `echo ./generic/tlsIO.c` -o tlsIO.o
gcc -DPACKAGE_NAME=\"tls\" -DPACKAGE_TARNAME=\"tls\" -DPACKAGE_VERSION=\"2.0.1\" -DPACKAGE_STRING=\"tls\ 2.0.1\" -DPACKAGE_BUGREPORT=\"\" -DPACKAGE_URL=\"\" -DBUILD_tls=/\*\*/ -DHAVE_STDIO_H=1 -DHAVE_STDLIB_H=1 -DHAVE_STRING_H=1 -DHAVE_INTTYPES_H=1 -DHAVE_STDINT_H=1 -DHAVE_STRINGS_H=1 -DHAVE_SYS_STAT_H=1 -DHAVE_SYS_TYPES_H=1 -DHAVE_UNISTD_H=1 -DSTDC_HEADERS=1 -DUSE_THREAD_ALLOC=1 -D_REENTRANT=1 -D_THREAD_SAFE=1 -DTCL_THREADS=1 -DSTATIC_BUILD=1 -DUSE_TCL_STUBS=1 -DUSE_TCLOO_STUBS=1 -DMODULE_SCOPE=extern\ __attribute__\(\(__visibility__\(\"hidden\"\)\)\) -DHAVE_HIDDEN=1 -DHAVE_CAST_TO_UNION=1 -DHAVE_STDBOOL_H=1 -DTCL_WIDE_INT_IS_LONG=1 -DTCL_CFG_OPTIMIZED=1 -DUSE_TCL_STUBS=1 -DNO_SSL3=1 -D_FORTIFY_SOURCE=2 -fstack-protector-all -fno-strict-overflow  -Wno-deprecated-declarations -I/usr/include -I"/path/to/custom/tcl/include/"  -I.    -O2 -fomit-frame-pointer -DNDEBUG -Wall -fPIC -pipe -m64 -O2 -fomit-frame-pointer -DNDEBUG -Wall  -c `echo ./generic/tlsX509.c` -o tlsX509.o
rm -f libtcl9tls2.0.1.a
ar cr libtcl9tls2.0.1.a tls.o tlsBIO.o tlsIO.o tlsX509.o 
ranlib libtcl9tls2.0.1.a
make nroff documentation
Called UpdateStringOfFsPath with invalid object
make: *** [Makefile:219: make-docs-n] Error 132

> make binaries && make libraries && make install-binaries && make install-libraries

> install pkgIndex.tcl /path/to/custom/tcl/lib/tcltls2.0.1

> cat /tmp/test.tcl
package require http
package require tls

set url "https://www.tcl.tk/"
http::register https 443 [list ::tls::socket -autoservername 1 -require 1]

# Get URL
set token [http::geturl $url]

> /path/to/custom/tcl/bin/tclsh
% source "/tmp/test.tcl"
couldn't load file "/path/to/custom/tcl/lib/tcltls2.0.1/libtcl9tls2.0.1.a": /path/to/custom/tcl/lib/tcltls2.0.1/libtcl9tls2.0.1.a: invalid ELF header

> cat /path/to/custom/tcl/lib/tcltls2.0.1/pkgIndex.tcl
# -*- tcl -*-
# Tcl package index file, version 1.1
#
if {[package vsatisfies [package provide Tcl] 9.0-]} {
    package ifneeded tls 2.0.1 [list apply {{dir} {
        # Load library
        load [file join $dir libtcl9tls2.0.1.a] [string totitle tls]

        # Source init file
        set initScript [file join $dir tls.tcl]
        if {[file exists $initScript]} {
            source -encoding utf-8 $initScript
        }
    }} $dir]
} else {
    if {![package vsatisfies [package provide Tcl] 8.5]} {return}
    package ifneeded tls 2.0.1 [list apply {{dir} {
        # Load library
        if {[string tolower [file extension libtls2.0.1.a]] in [list .dll .dylib .so]} {
            # Load dynamic library
            load [file join $dir libtls2.0.1.a] [string totitle tls]
        } else {
            # Static library
            load {} [string totitle tls]
        }

        # Source init file
        set initScript [file join $dir tls.tcl]
        if {[file exists $initScript]} {
            source -encoding utf-8 $initScript
        }
    }} $dir]
}