SIGN IN SIGN UP

compat/openssl: support bzlmod builds (#47216)

Make the `--config=openssl` build and tests work under bzlmod
(MODULE.bazel) in addition to the existing WORKSPACE mode. Both modes
keep working.

- Pin the custom bazel registry to the merged quiche HTTP/3 gating
commit.
- Route QUICHE's SSL to the OpenSSL compat layer via the
`--@quiche//:ssl_lib` injection point, mirrored as a label_flag in
`bazel/external/quiche.BUILD` so the flag is valid in both WORKSPACE and
bzlmod builds.
- Exclude QUIC/HTTP3 sources under `--define=quiche_disable_http3=true`,
matching WORKSPACE's `envoy_select_enable_http3` stripping and keeping
BoringSSL-only primitives (e.g. `SIPHASH_24`) out of the OpenSSL build.
- Provide raw BoringSSL source via a dedicated `@boringssl-source` repo
so the compat layer builds without the removed bssl-compat patch.
- Handle bzlmod canonical repo names in the compat
prefixer/dlutil/tests.

---------

Signed-off-by: Jonh Wendell <jwendell@redhat.com>
J
Jonh Wendell committed
1455ee8e01074febbb5dcad6874f7ad0904a238a
Parent: 7df3a6f
Committed by GitHub <noreply@github.com> on 9/4/2026, 9:37:45 PM