This repository is the source of truth for third-party binary dependencies used by Passepartout and Partout. It owns the upstream source pins, patches, cross-platform build recipes, packaging, and release metadata.
The repository invokes each vendor's native build directly: OpenSSL Configure, Mbed TLS's CMake build, and nmake for wxWidgets. There is no repository-level meta-build system.
Build scripts select one vendor and target at a time, matching the CI matrix:
scripts/build-apple-xcframeworks.sh all openssl
scripts/build-vendors.sh android-arm64-v8a mbedtls
scripts/build-vendors.sh linux-x64 opensslInitialize the OpenSSL and Mbed TLS sources before building:
scripts/checkout-vendors.shConsumers download the published vendor/platform archives independently. Partout uses system libraries where available and otherwise resolves the relevant vendor archive URL; this repository never checks out or builds Partout.
Vendor Prebuilts(partout-vendors.yml) builds the vendor distribution matrix.Windows wxWidgetsbuilds static wxWidgets libraries with MSVC.Release Prebuiltsdownloads successful workflow artifacts and uploads them to a GitHub Release.
All workflows are manual (workflow_dispatch) while the packaging format is settling. Build workflows upload GitHub Actions artifacts; the release workflow publishes those artifacts as release assets.
The vendor workflow can build all, openssl, or mbedtls. Selecting one vendor rebuilds it for every platform it supports. Every matrix entry emits a release-ready vendor/platform artifact; all only selects the complete matrix.
The release workflow selects the latest successful all run by creation time
from the 100 most recent vendor runs. Windows wxWidgets is selected independently
in the same way. Pass a specific vendor workflow run ID to publish or replace
only that run's vendor artifacts.
Release downloads select only OpenSSL and Mbed TLS vendor artifacts and Windows wxWidgets artifacts, including when reusing older build runs. Uploading to an existing release replaces matching assets but does not remove older assets.
The Apple matrix builds OpenSSL and Mbed TLS in separate parallel jobs. Each job produces one static XCFramework containing slices for:
- iOS device (
arm64) and simulator (arm64,x86_64) - macOS (
arm64,x86_64) - tvOS device (
arm64) and simulator (arm64,x86_64)
OpenSSL's libssl.a and libcrypto.a are consolidated into one archive per slice. Mbed TLS's libmbedtls.a, libmbedx509.a, and libmbedcrypto.a are consolidated similarly. No dynamic library is included in an Apple XCFramework.
Each job emits a zipped SwiftPM-compatible XCFramework, a .checksum sidecar, and vendor metadata for release aggregation. Build all Apple vendors locally with:
scripts/build-apple-xcframeworks.sh allPass a vendor as the second argument to reproduce one CI job, for example:
scripts/build-apple-xcframeworks.sh all opensslAndroid arm64-v8a builds OpenSSL and Mbed TLS in two parallel jobs. Windows x64 and arm64 each build OpenSSL and Mbed TLS in two parallel jobs. Every build job configures and packages only its selected vendor, producing names such as openssl-android-arm64-v8a.tar.gz and mbedtls-windows-arm64.zip.
Linux builds OpenSSL and Mbed TLS natively for x64 and arm64 in four separate jobs. Each package contains that vendor's libraries, public headers, and manifest for its architecture; OpenSSL is shared, while Mbed TLS is static.
Windows Mbed TLS is built as native MSVC COFF static libraries for the selected
x64 or arm64 target. Its runtime library is selected with
MSVC_RUNTIME_LIBRARY (the CI default is MultiThreadedDLL, corresponding to
/MD) so consumers do not mix CRT models.
The Android, Linux, and Windows Mbed TLS packages retain the upstream CMake
package metadata and expose MbedTLS::mbedtls, MbedTLS::mbedx509, and
MbedTLS::tfpsacrypto. Consumers can discover the package by adding
the extracted prebuilt root to CMAKE_PREFIX_PATH.
The local scripts take the same vendor selection as CI, for example:
scripts/build-vendors.sh android-arm64-v8a openssl
scripts/build-vendors.sh linux-x64 openssl
scripts/build-vendors-windows.ps1 -Target windows-x64 -Vendor mbedtlsThe vendors/openssl and vendors/mbedtls submodules pin their upstream revisions. Toolchain versions are pinned by the build scripts and workflow files.
Every Android, Linux, and Windows package includes a manifest containing its exact source revisions, target, linkage, and toolchain metadata. Apple builds emit equivalent vendor-specific metadata. The release workflow attaches one manifest.json that aggregates the metadata for every published OpenSSL, Mbed TLS, and wxWidgets artifact; intermediate manifests are not published separately.