dotnet/runtime · error

OpenSSL is not available, but required for build…

Error message

OpenSSL is not available, but required for build determinism

What it means

Printed at src/coreclr/ilasm/assem.cpp:255 during Assembler::Init when the deterministic-build flag (-HIGHENTROPYVA/DET option) is set but OpenSSL is unavailable on non-Windows/non-Apple platforms. Deterministic builds need a stable crypto hash (SHA-256) for GUID/MVID generation, and ilasm delegates that to OpenSSL via the pal_evp APIs.

Solutions

  1. Install a compatible OpenSSL and ensure ilasm links the pal crypto shim that exposes CryptoNative_OpenSslAvailable.
  2. Drop the /DET (deterministic) flag if determinism is not required.
  3. Build/run on Windows or macOS where the built-in SHA-256 path is used.
  4. Verify that the runtime's libcrypto dependency resolves at load time (ldd on the ilasm binary).

Example fix

// before (Linux without OpenSSL)
ilasm /DET /OUT=app.dll app.il
// after
coreclr_build -DCLR_ENABLE_OPENSSL=1  # rebuild ilasm with OpenSSL
# or simply drop the flag:
ilasm /OUT=app.dll app.il
Defensive patterns

Strategy: validation

Validate before calling

// Before running ilasm /DET on Linux, verify OpenSSL is loadable
#include <dlfcn.h>
bool openssl_available() {
    void* h = dlopen("libcrypto.so", RTLD_NOW);
    if (!h) h = dlopen("libcrypto.so.3", RTLD_NOW);
    if (h) { dlclose(h); return true; }
    return false;
}
// Only pass /DET when openssl_available() is true, or drop the flag.

Prevention

When it happens

Trigger: Triggered when Assembler::Init runs with m_fDeterministic==TRUE and IsOpenSslAvailable() (CryptoNative_OpenSslAvailable) returns 0. The option is enabled via the /DET flag parsed in main.cpp:309.

Common situations: Building ilasm without linking the OpenSSL-based crypto shim, or running on a Linux box where libcrypto is missing/incompatible. The check only fires outside Windows and macOS (those use built-in SHA-256).

Related errors


AI-assisted analysis of dotnet/runtime@60108ba66e (2026-08-10). Data as JSON: /api/errors/e0f61dfb36cf2e04. Report an issue: GitHub.

Appendix: source

Thrown at src/coreclr/ilasm/assem.cpp:255

    if (m_pCeeFileGen != NULL) {
        if (m_pCeeFile)
            m_pCeeFileGen->DestroyCeeFile(&m_pCeeFile);

        DestroyICeeFileGen(&m_pCeeFileGen);

        m_pCeeFileGen = NULL;
    }

    if (FAILED(CreateICeeFileGen(&m_pCeeFileGen))) return FALSE;
    if (FAILED(m_pCeeFileGen->CreateCeeFileEx(&m_pCeeFile,(ULONG)m_dwCeeFileFlags))) return FALSE;
    if (FAILED(m_pCeeFileGen->GetSectionCreate(m_pCeeFile, ".il", sdReadOnly, &m_pILSection))) return FALSE;
    if (FAILED(m_pCeeFileGen->GetSectionCreate (m_pCeeFile, ".sdata", sdReadWrite, &m_pGlobalDataSection))) return FALSE;
    if (FAILED(m_pCeeFileGen->GetSectionCreate (m_pCeeFile, ".tls", sdReadWrite, &m_pTLSSection))) return FALSE;

#if !defined(_WIN32) && !defined(__APPLE__)
    if (m_fDeterministic && !IsOpenSslAvailable())
    {
        fprintf(stderr, "OpenSSL is not available, but required for build determinism\n");
        return FALSE;
    }
#endif

    m_fGeneratePDB = generatePdb;

    return TRUE;
}

void Assembler::SetDLL(BOOL IsDll)
{
    HRESULT OK;
    OK = m_pCeeFileGen->SetDllSwitch(m_pCeeFile, IsDll);
    _ASSERTE(SUCCEEDED(OK));

    m_fDLL = IsDll;
}

View on GitHub (pinned to 60108ba66e)