Skip to content

Pass macOS OpenSSL compiler flags to Configure instead of CFLAGS - #796

Merged
alex merged 1 commit into
pyca:mainfrom
moathfarajat-commits:macos-openssl-optimisation
Sep 25, 2026
Merged

alex merged 1 commit into
pyca:mainfrom
moathfarajat-commits:macos-openssl-optimisation

Conversation

@moathfarajat-commits

Copy link
Copy Markdown
Contributor

Setting CFLAGS in the environment makes OpenSSL's Configure replace the target's default -O3 -Wall, so the macOS OpenSSL builds, and the wheels that link them, have been compiled at -O0 (pyca/cryptography#15702). Flags given to Configure as arguments are appended to the defaults instead. The matrix value stays in an environment variable, so it isn't expanded into the script.

           perl ./Configure \
               --prefix="${BASEDIR}/artifact" \
               --openssldir=${{ matrix.ARCH.OPENSSLDIR }} \
               darwin64-${{ matrix.ARCH.NAME }}-cc \
-              $OPENSSL_BUILD_FLAGS
+              $OPENSSL_BUILD_FLAGS \
+              $MACOS_CFLAGS
           make -j$(sysctl -n hw.logicalcpu)
           make install_sw
         env:
-          CFLAGS: ${{ matrix.ARCH.CFLAGS }}
+          MACOS_CFLAGS: ${{ matrix.ARCH.CFLAGS }}

After this change the embedded compiler line should begin cc -fPIC -arch arm64 -O3 -Wall -mmacosx-version-min=11.0.

@alex alex left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

great find, thanks

@alex
alex merged commit 4e97397 into pyca:main Sep 25, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants