diff --git a/.gitignore b/.gitignore index 7b3c1e0..61e38c2 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,2 @@ -SOURCES/shenandoah8u492-b09.tar.xz +SOURCES/shenandoah8u502-b07.tar.xz SOURCES/tapsets-icedtea-3.15.0.tar.xz diff --git a/.java-1.8.0-openjdk.metadata b/.java-1.8.0-openjdk.metadata index 76d6419..cd2d818 100644 --- a/.java-1.8.0-openjdk.metadata +++ b/.java-1.8.0-openjdk.metadata @@ -1,2 +1,2 @@ -9664167c92746481d7484061434ed1ddea110e7f SOURCES/shenandoah8u492-b09.tar.xz +d874ba8e6e76629915b4464267cc07156355b84b SOURCES/shenandoah8u502-b07.tar.xz 7ae2cba67467825b2c2a5fec7aea041865023002 SOURCES/tapsets-icedtea-3.15.0.tar.xz diff --git a/SOURCES/NEWS b/SOURCES/NEWS index b03f669..aea4751 100644 --- a/SOURCES/NEWS +++ b/SOURCES/NEWS @@ -3,6 +3,91 @@ Key: JDK-X - https://bugs.openjdk.java.net/browse/JDK-X CVE-XXXX-YYYY: https://cve.mitre.org/cgi-bin/cvename.cgi?name=XXXX-YYYY +New in release OpenJDK 8u502 (2026-07-21): +=========================================== +Live versions of these release notes can be found at: + * https://bit.ly/openjdk8u502 + +* Changes + - JDK-6815126: intermittent SimulResumerTest.java failure + - JDK-8162545: Mac build failure + - JDK-8199138: Add RISC-V support to Zero + - JDK-8209362: sun/security/ssl/SSLSocketImpl/ReuseAddr.java failed due to "BindException: Address already in use (Bind failed)" + - JDK-8246330: Add TLS Tests for Legacy ECDSA curves + - JDK-8249159: Downport test rework for SSLSocketTemplate from 8224650 + - JDK-8261235: C1 compilation fails with assert(res->vreg_number() == index) failed: conversion check + - JDK-8273135: java/awt/color/ICC_ColorSpace/MTTransformReplacedProfile.java crashes in liblcms.dylib with NULLSeek+0x7 + - JDK-8274736: Concurrent read/close of SSLSockets causes SSLSessions to be invalidated unnecessarily + - JDK-8280158: New test from JDK-8274736 failed with/without patch in JDK11u + - JDK-8298873: Update IllegalRecordVersion.java for changes to TLS implementation + - JDK-8301189: validate-source fails after JDK-8298873 + - JDK-8314730: GHA: Drop libfreetype6-dev transitional package in favor of libfreetype-dev + - JDK-8321489: Update LCMS to 2.16 + - JDK-8336451: [11u] GHA macos-13 and macos-15 builders are unable to resolve local hostname + - JDK-8348110: Update LCMS to 2.17 + - JDK-8351359: OperatingSystemMXBean: values from getCpuLoad and getProcessCpuLoad are stale after 24.8 days (Windows) + - JDK-8363966: GHA: Switch cross-compiling sysroots to Debian trixie + - JDK-8368041: Enhance TLS certificate handling + - JDK-8369996: Testcase java/net/Socket/B8312065.java fails on Mac, AIX and Solaris + - JDK-8372351: Add 2 WISeKey roots + - JDK-8374058: Enhance JPEG handling + - JDK-8374888: Implement internal test cache to help UserIterCount test performance + - JDK-8375065: Update LCMS to 2.18 + - JDK-8377158: Enhance XBM image support + - JDK-8377498: Improve HttpServer handling + - JDK-8377833: Enhance Jar file processing + - JDK-8378631: Update Zlib Data Compression Library to Version 1.3.2 + - JDK-8378687: Improve delegation of HttpURLConnection + - JDK-8379684: Bump update version of OpenJDK: 8u502 + - JDK-8380377: [8u] Problem list CAInterop.java#teliarootcav2 + - JDK-8380672: Improve certification checking + - JDK-8380689: distrust/Chunghwa.java test fails with a compilation error + - JDK-8380947: Add pull request template + - JDK-8381039: Enhance AWT ImagingLib + - JDK-8381049: Enhance Jar handling + - JDK-8381185: Improve Nashorn index handling + - JDK-8381195: Enhance Dataview Implementation + - JDK-8381519: Enhance Der Value Handling + - JDK-8381796: Enhance Certificate parsing + - JDK-8383175: (tz) Update Timezone Data to 2026b + - JDK-8383354: Update LCMS to 2.19.1 + - JDK-8383473: Follow on from tzdata2026b time change to include temporary hack BC time change + - JDK-8384158: GHA: Downgrade Windows GHA runners to windows-2022 temporarily + +security-libs/java.security: + +JDK-8372351: Add 2 WISeKey roots +================================ +The following root certificates have been added to the cacerts +truststore: + +Alias Name: wisekeyglobalrootgbca +Distinguished Name: CN=OISTE WISeKey Global Root GB CA, OU=OISTE Foundation Endorsed, O=WISeKey, C=CH +Serial Number: 76b1205274f0858746b3f8231af6c2c0 +Valid From: Mon Dec 01 15:00:32 GMT 2014 +Valid Until: Thu Dec 01 15:10:31 GMT 2039 + +Alias Name: wisekeyglobalrootgcca +Distinguished Name: CN=OISTE WISeKey Global Root GC CA, OU=OISTE Foundation Endorsed, O=WISeKey, C=CH +Serial Number: 212a560caeda0cab4045bf2ba22d3aea +Valid From: Tue May 09 09:48:34 GMT 2017 +Valid Until: Fri May 09 09:58:33 GMT 2042 + +JDK-8381796: Enhance Certificate parsing +======================================== +With this release of OpenJDK, a security and system property +`com.sun.security.crl.maxSize` is introduced which acts as a maximum +size limit on a Certificate Revocation List (CRL) downloaded over the +network. For URICertStore requests, the value is the maximum size in +bytes of the DER-encoded CRL. For LDAPCertStore queries, the +threshold is the sum of all CRLs downloaded from a single search. By +default, the maximum size is 20MiB (20971520 bytes) and CRLs larger +than this will be discarded. A value less than zero may be used to +turn off the size limit and non-numeric values will be ignored. A +non-empty value for the system property takes precedence over the +security property. Enabling 'certpath' debug logging will output the +current size limit and note any discarded CRLs. + New in release OpenJDK 8u492 (2026-04-21): =========================================== Live versions of these release notes can be found at: diff --git a/SOURCES/TestTranslations.java b/SOURCES/TestTranslations.java index 199d765..88e689c 100644 --- a/SOURCES/TestTranslations.java +++ b/SOURCES/TestTranslations.java @@ -1,5 +1,5 @@ /* TestTranslations -- Ensure translations are available for new timezones - Copyright (C) 2022 Red Hat, Inc. + Copyright (C) 2026 Red Hat, Inc. This program is free software: you can redistribute it and/or modify it under the terms of the GNU Affero General Public License as @@ -60,15 +60,34 @@ public class TestTranslations { public static void main(String[] args) { + boolean debug = false; + if (args.length < 1) { System.err.println("Test must be started with the name of the locale provider."); System.exit(1); } + if (args.length > 1) { + debug = Boolean.parseBoolean(args[1]); + } + + System.err.printf("Debugging: %s\n", debug); + + testZoneStrings(debug); + + String localeProvider = args[0]; + testZone(localeProvider, KYIV, + new String[] { "Europe/Kiev", "Europe/Kyiv", "Europe/Uzhgorod", "Europe/Zaporozhye" }); + testZone(localeProvider, CIUDAD_JUAREZ, + new String[] { "America/Cambridge_Bay", "America/Ciudad_Juarez" }); + } + + private static void testZoneStrings(final boolean debug) { System.out.println("Checking sanity of full zone string set..."); boolean invalid = Arrays.stream(Locale.getAvailableLocales()) - .peek(l -> System.out.println("Locale: " + l)) + .peek(l -> System.out.printf(debug ? "Locale: %s\n" : "", l)) .map(l -> DateFormatSymbols.getInstance(l).getZoneStrings()) + .peek(df -> System.out.printf(debug ? "Zone string size: %s\n" : "", df.length)) .flatMap(zs -> Arrays.stream(zs)) .flatMap(names -> Arrays.stream(names)) .filter(name -> Objects.isNull(name) || name.isEmpty()) @@ -78,12 +97,6 @@ public class TestTranslations { System.err.println("Zone string for a locale returned null or empty string"); System.exit(2); } - - String localeProvider = args[0]; - testZone(localeProvider, KYIV, - new String[] { "Europe/Kiev", "Europe/Kyiv", "Europe/Uzhgorod", "Europe/Zaporozhye" }); - testZone(localeProvider, CIUDAD_JUAREZ, - new String[] { "America/Cambridge_Bay", "America/Ciudad_Juarez" }); } private static void testZone(String localeProvider, Map exp, String[] ids) { diff --git a/SOURCES/java-1.8.0-openjdk-portable.specfile b/SOURCES/java-1.8.0-openjdk-portable.specfile index aa8fa60..47741bc 100644 --- a/SOURCES/java-1.8.0-openjdk-portable.specfile +++ b/SOURCES/java-1.8.0-openjdk-portable.specfile @@ -1,3 +1,86 @@ +# New Version-String scheme-style defines +%global majorver 8 +# Define version of OpenJDK 8 used +%global project openjdk +%global repo shenandoah-jdk8u +%global openjdk_revision 8u502-b07 +%global shenandoah_revision shenandoah%{openjdk_revision} +# e.g. aarch64-shenandoah-jdk8u212-b04-shenandoah-merge-2019-04-30 -> aarch64-shenandoah-jdk8u212-b04 +%global version_tag %(VERSION=%{shenandoah_revision}; echo ${VERSION%%-shenandoah-merge*}) +# eg # jdk8u60-b27 -> jdk8u60 or # aarch64-jdk8u60-b27 -> aarch64-jdk8u60 (dont forget spec escape % by %%) +%global whole_update %(VERSION=%{version_tag}; echo ${VERSION%%-*}) +# eg jdk8u60 -> 60 or aarch64-jdk8u60 -> 60 +%global updatever %(VERSION=%{whole_update}; echo ${VERSION##*u}) +# eg jdk8u60-b27 -> b27 +%global buildver %(VERSION=%{version_tag}; echo ${VERSION##*-}) +%global portablerelease 1 +%global rpmrelease 0 + +# Define IcedTea version used for SystemTap tapsets and desktop file +%global icedteaver 3.15.0 +# Define current Git revision for the FIPS support patches +%global fipsver 6d1aade0648 +# Define current Git revision for the cacerts patch +%global cacertsver 8139f2361c2 +%global javaver 1.%{majorver}.0 + +# Standard JPackage naming and versioning defines +%global origin openjdk +%global origin_nice OpenJDK +%global top_level_dir_name %{shenandoah_revision} + +# Define milestone (EA for pre-releases, GA ("fcs") for releases) +# Release will be (where N is usually a number starting at 1): +# - 0.N.ea for EA releases, +# - N for GA releases +%global is_ga 1 +%if %{is_ga} +%global milestone fcs +%global milestone_version %{nil} +%global extraver %{nil} +%global eaprefix %{nil} +%else +%global milestone ea +%global milestone_version "-ea" +%global extraver .%{milestone} +%global eaprefix 0. +%endif + +%global compatiblename java-%{javaver}-%{origin} + +Name: %{compatiblename}-portable%{?pkgos:-%{pkgos}} +Version: %{javaver}.%{updatever}.%{buildver} +Release: %{?eaprefix}%{portablerelease}.%{rpmrelease}%{?extraver}%{?dist} + +%global fullversion %{compatiblename}-%{version}-%{release} + +# java-1.5.0-ibm from jpackage.org set Epoch to 1 for unknown reasons +# and this change was brought into RHEL-4. java-1.5.0-ibm packages +# also included the epoch in their virtual provides. This created a +# situation where in-the-wild java-1.5.0-ibm packages provided "java = +# 1:1.5.0". In RPM terms, "1.6.0 < 1:1.5.0" since 1.6.0 is +# interpreted as 0:1.6.0. So the "java >= 1.6.0" requirement would be +# satisfied by the 1:1.5.0 packages. Thus we need to set the epoch in +# JDK package >= 1.6.0 to 1, and packages referring to JDK virtual +# provides >= 1.6.0 must specify the epoch, "java >= 1:1.6.0". + +Epoch: 1 +Summary: %{origin_nice} %{majorver} Runtime Environment portable edition +Group: Development/Languages + +# HotSpot code is licensed under GPLv2 +# JDK library code is licensed under GPLv2 with the Classpath exception +# The Apache license is used in code taken from Apache projects (primarily JAXP & JAXWS) +# DOM levels 2 & 3 and the XML digital signature schemas are licensed under the W3C Software License +# The JSR166 concurrency code is in the public domain +# The BSD and MIT licenses are used for a number of third-party libraries (see THIRD_PARTY_README) +# The OpenJDK source tree includes the JPEG library (IJG), zlib & libpng (zlib), giflib and LCMS (MIT) +# The test code includes copies of NSS under the Mozilla Public License v2.0 +# The PCSClite headers are under a BSD with advertising license +# The elliptic curve cryptography (ECC) source code is licensed under the LGPLv2.1 or any later version +License: ASL 1.1 and ASL 2.0 and BSD and BSD with advertising and GPL+ and GPLv2 and GPLv2 with exceptions and IJG and LGPLv2+ and MIT and MPLv2.0 and Public Domain and W3C and zlib +URL: http://openjdk.java.net/ + # RPM conditionals so as to be able to dynamically produce # slowdebug/release builds. See: # http://rpm.org/user_doc/conditional_builds.html @@ -83,6 +166,9 @@ # we need to distinguish between big and little endian PPC64 %global ppc64le ppc64le %global ppc64be ppc64 ppc64p7 + +# Define the architectures on which we build +ExclusiveArch: %{aarch64} %{ix86} %{ppc64le} s390x x86_64 # Set of architectures which support multiple ABIs %global multilib_arches %{power64} sparc64 x86_64 # Set of architectures for which we build slowdebug builds @@ -177,6 +263,10 @@ %endif %global bootjdk /usr/lib/jvm/java-%{buildjdkver}-openjdk +# Disable LTO as this causes build failures at the moment. +# See RHBZ#1861401 and https://bugs.gentoo.org/833097 +%define _lto_cflags %{nil} + # Filter out flags from the optflags macro that cause problems with the OpenJDK build # We filter out -O flags so that the optimization of HotSpot is not lowered from O3 to O2 # We filter out -Wall which will otherwise cause HotSpot to produce hundreds of thousands of warnings (100+mb logs) @@ -266,25 +356,6 @@ %global with_systemtap 0 %endif -# New Version-String scheme-style defines -%global majorver 8 -# Define version of OpenJDK 8 used -%global project openjdk -%global repo shenandoah-jdk8u -%global openjdk_revision 8u492-b09 -%global shenandoah_revision shenandoah%{openjdk_revision} -# Define IcedTea version used for SystemTap tapsets and desktop file -%global icedteaver 3.15.0 -# Define current Git revision for the FIPS support patches -%global fipsver 6d1aade0648 -# Define current Git revision for the cacerts patch -%global cacertsver 8139f2361c2 - -# Standard JPackage naming and versioning defines -%global origin openjdk -%global origin_nice OpenJDK -%global top_level_dir_name %{shenandoah_revision} - # Settings for local security configuration %global security_file %{top_level_dir_name}/jdk/src/share/lib/security/java.security-%{_target_os} %global cacerts_file /etc/pki/java/cacerts @@ -295,11 +366,11 @@ # Define what url should JVM offer in case of a crash report # order may be important, epel may have rhel declared %if 0%{?epel} -%global oj_vendor_bug_url https://bugzilla.redhat.com/enter_bug.cgi?product=Fedora%20EPEL&component=%{component}&version=epel%{epel} +%global oj_vendor_bug_url https://bugzilla.redhat.com/enter_bug.cgi?product=Fedora%20EPEL&component=%{compatiblename}&version=epel%{epel} %else %if 0%{?fedora} # Does not work for rawhide, keeps the version field empty -%global oj_vendor_bug_url https://bugzilla.redhat.com/enter_bug.cgi?product=Fedora&component=%{component}&version=%{fedora} +%global oj_vendor_bug_url https://bugzilla.redhat.com/enter_bug.cgi?product=Fedora&component=%{compatiblename}&version=%{fedora} %else %if 0%{?rhel} %global oj_vendor_bug_url https://access.redhat.com/support/cases/ @@ -309,39 +380,6 @@ %endif %endif -# e.g. aarch64-shenandoah-jdk8u212-b04-shenandoah-merge-2019-04-30 -> aarch64-shenandoah-jdk8u212-b04 -%global version_tag %(VERSION=%{shenandoah_revision}; echo ${VERSION%%-shenandoah-merge*}) -# eg # jdk8u60-b27 -> jdk8u60 or # aarch64-jdk8u60-b27 -> aarch64-jdk8u60 (dont forget spec escape % by %%) -%global whole_update %(VERSION=%{version_tag}; echo ${VERSION%%-*}) -# eg jdk8u60 -> 60 or aarch64-jdk8u60 -> 60 -%global updatever %(VERSION=%{whole_update}; echo ${VERSION##*u}) -# eg jdk8u60-b27 -> b27 -%global buildver %(VERSION=%{version_tag}; echo ${VERSION##*-}) -%global rpmrelease 1 -# Define milestone (EA for pre-releases, GA ("fcs") for releases) -# Release will be (where N is usually a number starting at 1): -# - 0.N%%{?extraver}%%{?dist} for EA releases, -# - N%%{?extraver}{?dist} for GA releases -%global is_ga 1 -%if %{is_ga} -%global milestone fcs -%global milestone_version %{nil} -%global extraver %{nil} -%global eaprefix %{nil} -%else -%global milestone ea -%global milestone_version "-ea" -%global extraver .%{milestone} -%global eaprefix 0. -%endif -# priority must be 7 digits in total. The expression is workarounding tip -%global priority %(TIP=1800%{updatever}; echo ${TIP/tip/999}) - -%global javaver 1.%{majorver}.0 - -# parametrized macros are order-sensitive -%global compatiblename %{name} -%global fullversion %{compatiblename}-%{version}-%{release} # images stub %global jdkimage j2sdk-image %global jreimage j2re-image @@ -353,91 +391,34 @@ %define uniquejavadocdir() %{expand:%{fullversion}%{?1}} # main id and dir of this jdk %define uniquesuffix() %{expand:%{fullversion}.%{_arch}%{?1}} -%define jreportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable%{1}.jre;g") -%define jdkportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable%{1}.jdk;g") +%define jreportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable%{1}.jre;g") +%define jdkportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable%{1}.jdk;g") +# RPM 4.19 no longer accept our double percentaged %%{nil} passed to %%{1} +# so we have to pass in "" but evaluate it, otherwise files will include it %define jreportablearchive() %{expand:%{jreportablenameimpl -- %%{1}}.tar.xz} +%define jreportablearchive_for_files() %(echo %{jreportablearchive -- ""}) %define jdkportablearchive() %{expand:%{jdkportablenameimpl -- %%{1}}.tar.xz} +%define jdkportablearchive_for_files() %(echo %{jdkportablearchive -- ""}) %define jreportablename() %{expand:%{jreportablenameimpl -- %%{1}}} %define jdkportablename() %{expand:%{jdkportablenameimpl -- %%{1}}} -%define docportablename() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable.docs;g") +%define docportablename() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable.docs;g") %define docportablearchive() %{docportablename}.tar.xz -%define miscportablename() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable.misc;g") +%define miscportablename() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable.misc;g") %define miscportablearchive() %{miscportablename}.tar.xz -# Fix for https://bugzilla.redhat.com/show_bug.cgi?id=1111349. -# See also https://bugzilla.redhat.com/show_bug.cgi?id=1590796 -# as to why some libraries *cannot* be excluded. In particular, -# these are: -# libjsig.so, libjava.so, libjawt.so, libjvm.so and libverify.so -%global _privatelibs libatk-wrapper[.]so.*|libattach[.]so.*|libawt_headless[.]so.*|libawt[.]so.*|libawt_xawt[.]so.*|libdt_socket[.]so.*|libfontmanager[.]so.*%{freetype_lib}|libhprof[.]so.*|libinstrument[.]so.*|libj2gss[.]so.*|libj2pcsc[.]so.*|libj2pkcs11[.]so.*|libjaas_unix[.]so.*|libjava_crw_demo[.]so.*%{jpeg_lib}|libjdwp[.]so.*|libjli[.]so.*|libjsdt[.]so.*|libjsoundalsa[.]so.*|libjsound[.]so.*|liblcms[.]so.*|libmanagement[.]so.*|libmlib_image[.]so.*|libnet[.]so.*|libnio[.]so.*|libnpt[.]so.*|libsaproc[.]so.*|libsctp[.]so.*|libsplashscreen[.]so.*|libsunec[.]so.*|libsystemconf[.]so.*|libunpack[.]so.*|libzip[.]so.*|lib[.]so\\(SUNWprivate_.* -%global __provides_exclude ^(%{_privatelibs})$ -%global __requires_exclude ^(%{_privatelibs})$ - -# Standard JPackage directories and symbolic links. -%global sdkdir() %{expand:%{uniquesuffix %%1}} -%global jrelnk() %{expand:jre-%{javaver}-%{origin}-%{version}-%{release}.%{_arch}%1} - -%global jredir() %{expand:%{sdkdir %%1}/jre} -%global sdkbindir() %{expand:%{_jvmdir}/%{sdkdir %%1}/bin} -%global jrebindir() %{expand:%{_jvmdir}/%{jredir %%1}/bin} %global alt_java_name alt-java -%global jvmjardir() %{expand:%{_jvmjardir}/%{uniquesuffix %%1}} - -%global rpm_state_dir %{_localstatedir}/lib/rpm-state/ - -# For flatpack builds hard-code /usr/sbin/alternatives, -# otherwise use %%{_sbindir} relative path. -%if 0%{?flatpak} -%global alternatives_requires /usr/sbin/alternatives -%else -%global alternatives_requires %{_sbindir}/alternatives -%endif # Prevent brp-java-repack-jars from being run. %global __jar_repack 0 -# portables have grown out of its component, moving back to java-x-vendor -# this expression, when declared as global, filled component with java-x-vendor portable -%define component %(echo %{name} | sed "s;-portable;;g") - -Name: java-%{javaver}-%{origin}-portable -Version: %{javaver}.%{updatever}.%{buildver} -Release: %{?eaprefix}%{rpmrelease}%{?extraver}%{?dist} -# java-1.5.0-ibm from jpackage.org set Epoch to 1 for unknown reasons -# and this change was brought into RHEL-4. java-1.5.0-ibm packages -# also included the epoch in their virtual provides. This created a -# situation where in-the-wild java-1.5.0-ibm packages provided "java = -# 1:1.5.0". In RPM terms, "1.6.0 < 1:1.5.0" since 1.6.0 is -# interpreted as 0:1.6.0. So the "java >= 1.6.0" requirement would be -# satisfied by the 1:1.5.0 packages. Thus we need to set the epoch in -# JDK package >= 1.6.0 to 1, and packages referring to JDK virtual -# provides >= 1.6.0 must specify the epoch, "java >= 1:1.6.0". - -Epoch: 1 -Summary: %{origin_nice} %{majorver} Runtime Environment portable edition -Group: Development/Languages - -# HotSpot code is licensed under GPLv2 -# JDK library code is licensed under GPLv2 with the Classpath exception -# The Apache license is used in code taken from Apache projects (primarily JAXP & JAXWS) -# DOM levels 2 & 3 and the XML digital signature schemas are licensed under the W3C Software License -# The JSR166 concurrency code is in the public domain -# The BSD and MIT licenses are used for a number of third-party libraries (see THIRD_PARTY_README) -# The OpenJDK source tree includes the JPEG library (IJG), zlib & libpng (zlib), giflib and LCMS (MIT) -# The test code includes copies of NSS under the Mozilla Public License v2.0 -# The PCSClite headers are under a BSD with advertising license -# The elliptic curve cryptography (ECC) source code is licensed under the LGPLv2.1 or any later version -License: ASL 1.1 and ASL 2.0 and BSD and BSD with advertising and GPL+ and GPLv2 and GPLv2 with exceptions and IJG and LGPLv2+ and MIT and MPLv2.0 and Public Domain and W3C and zlib -URL: http://openjdk.java.net/ - # Shenandoah HotSpot # openjdk/shenandoah-jdk8u contains an integration forest of # OpenJDK 8u and the Shenandoah garbage collector # To regenerate, use: -# VERSION=%%{shenandoah_revision} +# VERSION= # FILE_NAME_ROOT=${VERSION} # REPO_ROOT= generate_source_tarball.sh -# where the source is obtained from http://github.com/%%{project}/%%{repo} +# where the source is obtained from http://github.com// Source0: %{shenandoah_revision}.tar.xz # Custom README for -src subpackage @@ -501,11 +482,14 @@ Patch534: rh1648246-always_instruct_vm_to_assume_multiple_processors_are_availab Patch1000: rh1648249-add_commented_out_nss_cfg_provider_to_java_security.patch # RH1582504: Use RSA as default for keytool, as DSA is disabled in all crypto policies except LEGACY Patch1003: rh1582504-rsa_default_for_keytool.patch +# RH1750419: Enable build of speculative store bypass hardened alt-java (CVE-2018-3639) +Patch600: rh1750419-redhat_alt_java.patch # Crypto policy and FIPS support patches # Patch is generated from the fips tree at https://github.com/rh-openjdk/jdk8u/tree/fips -# as follows: git diff %%{openjdk_revision} common jdk > fips-8u-$(git show -s --format=%h HEAD).patch +# as follows: git diff common jdk > fips-8u-$(git show -s --format=%h HEAD).patch # Diff is limited to src and make subdirectories to exclude .github changes + # Fixes currently included: # PR3183, RH1340845: Support Fedora/RHEL8 system crypto policy # PR3655: Allow use of system crypto policy to be disabled by the user @@ -547,8 +531,8 @@ Patch528: pr3083-rh1346460-for_ssl_debug_return_null_instead_of_exception_when_t # as follows: git diff fips > pr2888-rh2055274-support_system_cacerts-$(git show -s --format=%h HEAD).patch Patch539: pr2888-rh2055274-support_system_cacerts-%{cacertsver}.patch Patch541: rh1684077-openjdk_should_depend_on_pcsc-lite-libs_instead_of_pcsc-lite-devel.patch -# RH1750419: Enable build of speculative store bypass hardened alt-java (CVE-2018-3639) -Patch600: rh1750419-redhat_alt_java.patch +# JDK-8385876: [8u] hotspot/src/share/vm/code/compiledIC.cpp:406:30: error: 'this' pointer is null +Patch542: jdk8385876-zero_this_pointer_is_null.patch ############################################# # @@ -699,13 +683,13 @@ Provides: bundled(freetype) = 2.14.2 # Version in jdk/src/share/native/sun/awt/giflib/gif_lib.h Provides: bundled(giflib) = 6.1.2 # Version in jdk/src/share/native/sun/java2d/cmm/lcms/lcms2.h -Provides: bundled(lcms2) = 2.15.0 +Provides: bundled(lcms2) = 2.19.1 # Version in jdk/src/share/native/sun/awt/image/jpeg/jpeglib.h Provides: bundled(libjpeg) = 6b # Version in jdk/src/share/native/sun/awt/libpng/png.h Provides: bundled(libpng) = 1.6.57 # Version in jdk/src/share/native/java/util/zip/zlib/zlib.h -Provides: bundled(zlib) = 1.3.1 +Provides: bundled(zlib) = 1.3.2 # We link statically against libstdc++ to increase portability BuildRequires: libstdc++-static %endif @@ -805,11 +789,7 @@ export XZ_OPT="-T0" %endif %setup -q -c -n %{uniquesuffix ""} -T -a 0 # https://bugzilla.redhat.com/show_bug.cgi?id=1189084 -prioritylength=`expr length %{priority}` -if [ $prioritylength -ne 7 ] ; then - echo "priority must be 7 digits in total, violated" - exit 14 -fi + # For old patches ln -s %{top_level_dir_name} jdk8 ln -s %{top_level_dir_name} openjdk @@ -825,20 +805,6 @@ cp %{SOURCE101} %{top_level_dir_name}/common/autoconf/build-aux/ # OpenJDK patches -# This syntax is deprecated: -# %patchN [...] -# and should be replaced with: -# %patch -PN [...] -# For example: -# %patch1001 -p1 -# becomes: -# %patch -P1001 -p1 -# The replacement format suggested by recent (circa Fedora 38) RPM -# deprecation messages: -# %patch N [...] -# is not backward-compatible with prior (circa RHEL-8) versions of -# rpmbuild. - %if %{system_libs} # Remove libraries that are linked sh %{SOURCE12} @@ -881,6 +847,7 @@ pushd %{top_level_dir_name} %patch -P502 -p1 %patch -P14 -p1 %patch -P15 -p1 +%patch -P542 -p1 popd # Early fixes @@ -949,7 +916,6 @@ sed -e "s:@NSS_LIBDIR@:%{NSS_LIBDIR}:g" %{SOURCE17} > nss.fips.cfg export NUM_PROC=%(/usr/bin/getconf _NPROCESSORS_ONLN 2> /dev/null || :) export NUM_PROC=${NUM_PROC:-1} %if 0%{?_smp_ncpus_max} -# Honor %%_smp_ncpus_max [ ${NUM_PROC} -gt %{?_smp_ncpus_max} ] && export NUM_PROC=%{?_smp_ncpus_max} %endif %ifnarch %{ix86} @@ -959,21 +925,33 @@ export XZ_OPT="-T0" %ifarch s390x sparc64 alpha %{power64} %{aarch64} export ARCH_DATA_MODEL=64 %endif -%ifarch alpha -export CFLAGS="$CFLAGS -mieee" -%endif -# We use ourcppflags because the OpenJDK build seems to -# pass EXTRA_CFLAGS to the HotSpot C++ compiler... +# HotSpot uses EXTRA_CPP_FLAGS since JDK-8374917 in 8u492-b01 EXTRA_CFLAGS="%ourcppflags -Wno-error" EXTRA_CPP_FLAGS="%ourcppflags" + +%ifarch alpha +export EXTRA_CPP_FLAGS="$CFLAGS -mieee" +%endif + %ifarch %{power64} ppc EXTRA_CFLAGS="$EXTRA_CFLAGS -fno-tree-vectorize" # fix rpmlint warnings EXTRA_CFLAGS="$EXTRA_CFLAGS -fno-strict-aliasing" +# Workaround -Wnonnull warnings (OPENJDK-4894) +EXTRA_CPP_FLAGS="$EXTRA_CPP_FLAGS -Wno-nonnull" %endif + +%ifnarch %{zero_arches} +# -Wstringop-overflow is not supported on RHEL 7's gcc +%if 0%{?rhel} != 7 +EXTRA_CPP_FLAGS="$EXTRA_CPP_FLAGS -Wno-error=stringop-overflow" +%endif +%endif + EXTRA_ASFLAGS="${EXTRA_CFLAGS} -Wa,--generate-missing-build-notes=yes" -export EXTRA_CFLAGS EXTRA_ASFLAGS + +export EXTRA_CFLAGS EXTRA_CPP_FLAGS EXTRA_ASFLAGS function buildjdk() { local outputdir=${1} @@ -1501,9 +1479,9 @@ done %files # main package builds always -%{_jvmdir}/%{jreportablearchive -- %%{nil}} +%{_jvmdir}/%{jreportablearchive_for_files} %{_jvmdir}/%{jreportablearchive -- .debuginfo} -%{_jvmdir}/%{jreportablearchive -- %%{nil}}.sha256sum +%{_jvmdir}/%{jreportablearchive_for_files}.sha256sum %{_jvmdir}/%{jreportablearchive -- .debuginfo}.sha256sum %else @@ -1516,9 +1494,9 @@ done %if %{include_normal_build} %files devel -%{_jvmdir}/%{jdkportablearchive -- %%{nil}} +%{_jvmdir}/%{jdkportablearchive_for_files} %{_jvmdir}/%{jdkportablearchive -- .debuginfo} -%{_jvmdir}/%{jdkportablearchive -- %%{nil}}.sha256sum +%{_jvmdir}/%{jdkportablearchive_for_files}.sha256sum %{_jvmdir}/%{jdkportablearchive -- .debuginfo}.sha256sum %files unstripped @@ -1560,6 +1538,49 @@ done %endif %changelog +* Fri Jul 17 2026 Andrea Bolognani - 1:1.8.0.502.b07-1.0 +- Strip %%{dist} more thoroughly +- Resolves: OPENJDK-4907 + +* Thu Jul 16 2026 Andrew Hughes - 1:1.8.0.502.b07-1.0 +- Update to 8u502-b07 (GA). +- Update release notes for 8u502-b07. +- Bump lcms2 version to 2.19.1 following JDK-8321489, JDK-8348110, JDK-8375065 & JDK-8383354 +- Bump zlib version to 1.3.2 following JDK-8378631 +- Port ForFiles patch to RHEL and update to use standard function naming format +- Remove macro references in comments where possible (%dnl not compatible enough yet) +- Cleanup RPM only macros unused in the portable spec file +- Move version information and core NVR definitions back towards the top of the file +- Explictly define supported architectures +- Specify portablerelease and rpmrelease (always 0 for portables) in the Release field +- Make zone string debug output optional in TestTranslations +- Add RHEL 7 opt-out on -Werror=stringop-overflow which is unsupported on its gcc +- ** This tarball is embargoed until 2026-07-21 @ 1pm PT. ** +- Resolves: OPENJDK-4869 +- Related: OPENJDK-4896 +- Resolves: OPENJDK-4903 +- Resolves: OPENJDK-4904 +- Resolves: OPENJDK-4906 +- Resolves: OPENJDK-4908 +- Related: OPENJDK-4895 + +* Wed Jul 15 2026 Jiri Vanek - 1:1.8.0.502.b07-1.0 +- Redeclared ForFiles release sections as %%nil no longer works with %%1 +- RPM 4.19 no longer accept our double percentaged %%{nil} passed to %%{1} +- so we have to pass in "" but evaluate it, otherwise files record will include it +- Resolves: OPENJDK-4896 + +* Sat Apr 18 2026 Andrew Hughes - 1:1.8.0.492.b09-2 +- Add CVEs for 8u482 & 8u492 to NEWS +- Add attempted patch for JDK-8385876 to fix -Wnonnull build failure with s390x Zero on CentOS 9 +- Workaround -Wnonull failure with ppc64le on CentOS 9 using -Wno-nonnull +- Workaround -Werror=stringop-overflow failure with JIT debug builds on CentOS 9 using -Wno-error=stringop-overflow +- Workaround undefined symbol: _ZN16G1TriggerClosure9do_oop_nvIjEEvPT_ by disabling LTO +- Resolves: OPENJDK-4893 +- Resolves: OPENJDK-4894 +- Resolves: OPENJDK-4895 +- Resolves: OPENJDK-4909 + * Fri Apr 17 2026 Andrew Hughes - 1:1.8.0.492.b09-1 - Update to 8u492-b09 (GA) - Update release notes for 8u492-b09. diff --git a/SOURCES/jdk8385876-zero_this_pointer_is_null.patch b/SOURCES/jdk8385876-zero_this_pointer_is_null.patch new file mode 100644 index 0000000..84bf5ef --- /dev/null +++ b/SOURCES/jdk8385876-zero_this_pointer_is_null.patch @@ -0,0 +1,28 @@ +diff --git a/hotspot/src/share/vm/code/compiledIC.cpp b/hotspot/src/share/vm/code/compiledIC.cpp +index 63821c0613..b0e3d057ca 100644 +--- a/hotspot/src/share/vm/code/compiledIC.cpp ++++ b/hotspot/src/share/vm/code/compiledIC.cpp +@@ -403,7 +403,8 @@ void CompiledIC::set_to_monomorphic(CompiledICInfo& info) { + assert(info.cached_metadata() != NULL && info.cached_metadata()->is_method(), "sanity check"); + CompiledStaticCall* csc = compiledStaticCall_at(instruction_address()); + methodHandle method (thread, (Method*)info.cached_metadata()); +- csc->set_to_interpreted(method, info.entry()); ++ // Compiler sees 'this' as null on Zero but it should never actually get called ++ NOT_ZERO(csc->set_to_interpreted(method, info.entry())); + if (TraceICs) { + ResourceMark rm(thread); + tty->print_cr ("IC@" INTPTR_FORMAT ": monomorphic to interpreter: %s", +diff --git a/hotspot/src/share/vm/runtime/sharedRuntime.cpp b/hotspot/src/share/vm/runtime/sharedRuntime.cpp +index a136da9054..39fb84628b 100644 +--- a/hotspot/src/share/vm/runtime/sharedRuntime.cpp ++++ b/hotspot/src/share/vm/runtime/sharedRuntime.cpp +@@ -1319,7 +1319,8 @@ methodHandle SharedRuntime::resolve_sub_helper(JavaThread *thread, + } + } else { + CompiledStaticCall* ssc = compiledStaticCall_before(caller_frame.pc()); +- if (ssc->is_clean()) ssc->set(static_call_info); ++ // Compiler sees 'this' as null on Zero but it should never actually get called ++ NOT_ZERO(if (ssc->is_clean()) ssc->set(static_call_info)); + } + } + diff --git a/SPECS/java-1.8.0-openjdk.spec b/SPECS/java-1.8.0-openjdk.spec index a58ef4c..2778d0b 100644 --- a/SPECS/java-1.8.0-openjdk.spec +++ b/SPECS/java-1.8.0-openjdk.spec @@ -3,6 +3,98 @@ # it and then adjust portablerelease and portablesuffix # to match the new portable. +# New Version-String scheme-style defines +%global majorver 8 +# Define version of OpenJDK 8 used +%global project openjdk +%global repo shenandoah-jdk8u +%global openjdk_revision 8u502-b07 +%global shenandoah_revision shenandoah%{openjdk_revision} +# e.g. aarch64-shenandoah-jdk8u212-b04-shenandoah-merge-2019-04-30 -> aarch64-shenandoah-jdk8u212-b04 +%global version_tag %(VERSION=%{shenandoah_revision}; echo ${VERSION%%-shenandoah-merge*}) +# eg # jdk8u60-b27 -> jdk8u60 or # aarch64-jdk8u60-b27 -> aarch64-jdk8u60 (dont forget spec escape % by %%) +%global whole_update %(VERSION=%{version_tag}; echo ${VERSION%%-*}) +# eg jdk8u60 -> 60 or aarch64-jdk8u60 -> 60 +%global updatever %(VERSION=%{whole_update}; echo ${VERSION##*u}) +# eg jdk8u60-b27 -> b27 +%global buildver %(VERSION=%{version_tag}; echo ${VERSION##*-}) +%global portablerelease 1 +%global rpmrelease 1 + +# Define IcedTea version used for SystemTap tapsets and desktop files +%global icedteaver 3.15.0 +# Define current Git revision for the FIPS support patches +%global fipsver 6d1aade0648 +# Define current Git revision for the cacerts patch +%global cacertsver 8139f2361c2 +%global javaver 1.%{majorver}.0 + +# Standard JPackage naming and versioning defines +%global origin openjdk +%global origin_nice OpenJDK +%global top_level_dir_name %{shenandoah_revision} + +# Define milestone (EA for pre-releases, GA ("fcs") for releases) +# Release will be (where N is usually a number starting at 1): +# - 0.N.ea for EA releases, +# - N for GA releases +%global is_ga 1 +%if %{is_ga} +%global milestone fcs +%global milestone_version %{nil} +%global extraver %{nil} +%global eaprefix %{nil} +%else +%global milestone ea +%global milestone_version "-ea" +%global extraver .%{milestone} +%global eaprefix 0. +%endif + +%global compatiblename java-%{javaver}-%{origin} + +Name: %{compatiblename} +Version: %{javaver}.%{updatever}.%{buildver} +Release: %{?eaprefix}%{portablerelease}.%{rpmrelease}%{?extraver}%{?dist} + +%global fullversion %{compatiblename}-%{version}-%{release} + +# java-1.5.0-ibm from jpackage.org set Epoch to 1 for unknown reasons +# and this change was brought into RHEL-4. java-1.5.0-ibm packages +# also included the epoch in their virtual provides. This created a +# situation where in-the-wild java-1.5.0-ibm packages provided "java = +# 1:1.5.0". In RPM terms, "1.6.0 < 1:1.5.0" since 1.6.0 is +# interpreted as 0:1.6.0. So the "java >= 1.6.0" requirement would be +# satisfied by the 1:1.5.0 packages. Thus we need to set the epoch in +# JDK package >= 1.6.0 to 1, and packages referring to JDK virtual +# provides >= 1.6.0 must specify the epoch, "java >= 1:1.6.0". + +Epoch: 1 +Summary: %{origin_nice} %{majorver} Runtime Environment +Group: Development/Languages + +# HotSpot code is licensed under GPLv2 +# JDK library code is licensed under GPLv2 with the Classpath exception +# The Apache license is used in code taken from Apache projects (primarily JAXP & JAXWS) +# DOM levels 2 & 3 and the XML digital signature schemas are licensed under the W3C Software License +# The JSR166 concurrency code is in the public domain +# The BSD and MIT licenses are used for a number of third-party libraries (see THIRD_PARTY_README) +# The OpenJDK source tree includes the JPEG library (IJG), zlib & libpng (zlib), giflib and LCMS (MIT) +# The test code includes copies of NSS under the Mozilla Public License v2.0 +# The PCSClite headers are under a BSD with advertising license +# The elliptic curve cryptography (ECC) source code is licensed under the LGPLv2.1 or any later version +License: ASL 1.1 and ASL 2.0 and BSD and BSD with advertising and GPL+ and GPLv2 and GPLv2 with exceptions and IJG and LGPLv2+ and MIT and MPLv2.0 and Public Domain and W3C and zlib +URL: http://openjdk.java.net/ + +# Settings used by the portable build +# Release field for the portable build +# The rpmrelease field is always zero for portables +%global prelease %{?eaprefix}%{portablerelease}.0%{?extraver} +# Portable suffix differs between RHEL and CentOS +%global portablerhel 8 +%global portablebuilddir /builddir/build/BUILD +%global portablesuffix el%{portablerhel} + # RPM conditionals so as to be able to dynamically produce # slowdebug/release builds. See: # http://rpm.org/user_doc/conditional_builds.html @@ -98,7 +190,7 @@ # rpm -ql --noghost java-11-openjdk-headless-11.0.1.13-8.fc29.x86_64.rpm | grep bin # == rpm -ql java-11-openjdk-headless-slowdebug-11.0.1.13-8.fc29.x86_64.rpm | grep bin # != rpm -ql java-11-openjdk-headless-11.0.1.13-8.fc29.x86_64.rpm | grep bin -# similarly for other %%{_jvmdir}/{jre,java} and %%{_javadocdir}/{java,java-zip} +# similarly for other <_jvmdir>/{jre,java} and <_javadocdir>/{java,java-zip} # Indicates whether this is the default JDK on this version of RHEL %global is_system_jdk 1 @@ -107,6 +199,9 @@ # we need to distinguish between big and little endian PPC64 %global ppc64le ppc64le %global ppc64be ppc64 ppc64p7 + +# Define the architectures on which we build +ExclusiveArch: %{aarch64} %{ix86} %{ppc64le} s390x x86_64 # Set of architectures which support multiple ABIs %global multilib_arches %{power64} sparc64 x86_64 # Set of architectures for which we build slowdebug builds @@ -295,26 +390,6 @@ %global with_systemtap 0 %endif -# New Version-String scheme-style defines -%global majorver 8 - -# Define version of OpenJDK 8 used -%global project openjdk -%global repo shenandoah-jdk8u -%global openjdk_revision 8u492-b09 -%global shenandoah_revision shenandoah%{openjdk_revision} -# Define IcedTea version used for SystemTap tapsets and desktop files -%global icedteaver 3.15.0 -# Define current Git revision for the FIPS support patches -%global fipsver 6d1aade0648 -# Define current Git revision for the cacerts patch -%global cacertsver 8139f2361c2 - -# Standard JPackage naming and versioning defines -%global origin openjdk -%global origin_nice OpenJDK -%global top_level_dir_name %{shenandoah_revision} - # Settings for local security configuration %global security_file %{top_level_dir_name}/jdk/src/share/lib/security/java.security-%{_target_os} %global cacerts_file /etc/pki/java/cacerts @@ -339,38 +414,7 @@ %endif %endif -# e.g. aarch64-shenandoah-jdk8u212-b04-shenandoah-merge-2019-04-30 -> aarch64-shenandoah-jdk8u212-b04 -%global version_tag %(VERSION=%{shenandoah_revision}; echo ${VERSION%%-shenandoah-merge*}) -# eg # jdk8u60-b27 -> jdk8u60 or # aarch64-jdk8u60-b27 -> aarch64-jdk8u60 (dont forget spec escape % by %%) -%global whole_update %(VERSION=%{version_tag}; echo ${VERSION%%-*}) -# eg jdk8u60 -> 60 or aarch64-jdk8u60 -> 60 -%global updatever %(VERSION=%{whole_update}; echo ${VERSION##*u}) -# eg jdk8u60-b27 -> b27 -%global buildver %(VERSION=%{version_tag}; echo ${VERSION##*-}) -%global rpmrelease 1 -# Settings used by the portable build -%global portablerelease 1 -%global portablerhel 8 -%global portablesuffix el%{portablerhel} -%global portablebuilddir /builddir/build/BUILD - -# Define milestone (EA for pre-releases, GA ("fcs") for releases) -# Release will be (where N is usually a number starting at 1): -# - 0.N%%{?extraver}%%{?dist} for EA releases, -# - N%%{?extraver}{?dist} for GA releases -%global is_ga 1 -%if %{is_ga} -%global milestone fcs -%global milestone_version %{nil} -%global extraver %{nil} -%global eaprefix %{nil} -%else -%global milestone ea -%global milestone_version "-ea" -%global extraver .%{milestone} -%global eaprefix 0. -%endif -# priority must be 7 digits in total. The expression is workarounding tip +# priority must be 7 digits in total; up to openjdk 1.8 %if %is_system_jdk %global priority %(TIP=1800%{updatever}; echo ${TIP/tip/999}) %else @@ -378,11 +422,6 @@ %global priority 00000%{interimver}1 %endif -%global javaver 1.%{majorver}.0 - -# parametrized macros are order-sensitive -%global compatiblename %{name} -%global fullversion %{compatiblename}-%{version}-%{release} # output dir stub %define installoutputdir() %{expand:install/jdk8.install%{?1}} # we can copy the javadoc to not arched dir, or make it not noarch @@ -413,7 +452,7 @@ %global rpm_state_dir %{_localstatedir}/lib/rpm-state/ # For flatpack builds hard-code /usr/sbin/alternatives, -# otherwise use %%{_sbindir} relative path. +# otherwise use <_sbindir> relative path. %if 0%{?flatpak} %global alternatives_requires /usr/sbin/alternatives %else @@ -437,7 +476,7 @@ %global tapsetdir %{tapsetdirttapset}/%{stapinstall} %endif -# not-duplicated scriptlets for normal/debug packages +# non-duplicated scriptlets for normal/debug packages %global update_desktop_icons /usr/bin/gtk-update-icon-cache %{_datadir}/icons/hicolor &>/dev/null || : %define save_alternatives() %{expand: @@ -814,6 +853,7 @@ exit 0 %license %{_jvmdir}/%{jredir -- %{?1}}/ASSEMBLY_EXCEPTION %license %{_jvmdir}/%{jredir -- %{?1}}/LICENSE %license %{_jvmdir}/%{jredir -- %{?1}}/THIRD_PARTY_README +%dir %{_defaultdocdir}/%{uniquejavadocdir -- %{?1}} %doc %{_defaultdocdir}/%{uniquejavadocdir -- %{?1}}/NEWS %doc %{_defaultdocdir}/%{uniquejavadocdir -- %{?1}}/README.md %doc %{_defaultdocdir}/%{uniquejavadocdir -- %{?1}}/java-1.%{majorver}.0-openjdk-portable.specfile @@ -1121,6 +1161,7 @@ exit 0 %define files_javadoc_zip() %{expand: %defattr(-,root,root,-) +%dir %{_javadocdir}/%{uniquejavadocdir -- %{?1}} %doc %{_javadocdir}/%{uniquejavadocdir -- %{?1}}.zip %license %{installoutputdir -- %{?1}}/jre/LICENSE } @@ -1165,8 +1206,8 @@ Provides: jre%{?1} = %{epoch}:%{javaver} Requires: ca-certificates # Require javapackages-filesystem for ownership of /usr/lib/jvm/ Requires: javapackages-filesystem -# 2026a required as of JDK-8379035 -Requires: tzdata-java >= 2026a +# 2026b required as of JDK-8383175 +Requires: tzdata-java >= 2026b # for support of kernel stream control # libsctp.so.1 is being `dlopen`ed on demand Requires: lksctp-tools%{?_isa} @@ -1293,47 +1334,14 @@ Provides: java-%{javaver}-%{origin}-accessibility = %{epoch}:%{version}-%{releas # Prevent brp-java-repack-jars from being run %global __jar_repack 0 -Name: java-%{javaver}-%{origin} -Version: %{javaver}.%{updatever}.%{buildver} -Release: %{?eaprefix}%{rpmrelease}%{?extraver}%{?dist} -# Equivalent for the portable build -%global pversion %{version} -%global prelease %{?eaprefix}%{portablerelease}%{?extraver} -# java-1.5.0-ibm from jpackage.org set Epoch to 1 for unknown reasons -# and this change was brought into RHEL-4. java-1.5.0-ibm packages -# also included the epoch in their virtual provides. This created a -# situation where in-the-wild java-1.5.0-ibm packages provided "java = -# 1:1.5.0". In RPM terms, "1.6.0 < 1:1.5.0" since 1.6.0 is -# interpreted as 0:1.6.0. So the "java >= 1.6.0" requirement would be -# satisfied by the 1:1.5.0 packages. Thus we need to set the epoch in -# JDK package >= 1.6.0 to 1, and packages referring to JDK virtual -# provides >= 1.6.0 must specify the epoch, "java >= 1:1.6.0". - -Epoch: 1 -Summary: %{origin_nice} %{majorver} Runtime Environment -Group: Development/Languages - -# HotSpot code is licensed under GPLv2 -# JDK library code is licensed under GPLv2 with the Classpath exception -# The Apache license is used in code taken from Apache projects (primarily JAXP & JAXWS) -# DOM levels 2 & 3 and the XML digital signature schemas are licensed under the W3C Software License -# The JSR166 concurrency code is in the public domain -# The BSD and MIT licenses are used for a number of third-party libraries (see THIRD_PARTY_README) -# The OpenJDK source tree includes the JPEG library (IJG), zlib & libpng (zlib), giflib and LCMS (MIT) -# The test code includes copies of NSS under the Mozilla Public License v2.0 -# The PCSClite headers are under a BSD with advertising license -# The elliptic curve cryptography (ECC) source code is licensed under the LGPLv2.1 or any later version -License: ASL 1.1 and ASL 2.0 and BSD and BSD with advertising and GPL+ and GPLv2 and GPLv2 with exceptions and IJG and LGPLv2+ and MIT and MPLv2.0 and Public Domain and W3C and zlib -URL: http://openjdk.java.net/ - # Shenandoah HotSpot # openjdk/shenandoah-jdk8u contains an integration forest of # OpenJDK 8u and the Shenandoah garbage collector # To regenerate, use: -# VERSION=%%{shenandoah_revision} +# VERSION= # FILE_NAME_ROOT=${VERSION} # REPO_ROOT= generate_source_tarball.sh -# where the source is obtained from http://github.com/%%{project}/%%{repo} +# where the source is obtained from http://github.com// Source0: %{shenandoah_revision}.tar.xz # Use 'icedtea_sync.sh' to update the following @@ -1382,11 +1390,11 @@ Source21: NEWS Source22: repack_reproducible_policies.sh # Setup variables to reference correct sources -%global releasezip %{_jvmdir}/%{name}-portable-%{pversion}-%{prelease}.portable.unstripped.jdk.%{_arch}.tar.xz -%global docszip %{_jvmdir}/%{name}-portable-%{pversion}-%{prelease}.portable.docs.%{_arch}.tar.xz -%global misczip %{_jvmdir}/%{name}-portable-%{pversion}-%{prelease}.portable.misc.%{_arch}.tar.xz -%global slowdebugzip %{_jvmdir}/%{name}-portable-%{pversion}-%{prelease}.portable.slowdebug.jdk.%{_arch}.tar.xz -%global fastdebugzip %{_jvmdir}/%{name}-portable-%{pversion}-%{prelease}.portable.fastdebug.jdk.%{_arch}.tar.xz +%global releasezip %{_jvmdir}/%{name}-%{version}-%{prelease}.portable.unstripped.jdk.%{_arch}.tar.xz +%global docszip %{_jvmdir}/%{name}-%{version}-%{prelease}.portable.docs.%{_arch}.tar.xz +%global misczip %{_jvmdir}/%{name}-%{version}-%{prelease}.portable.misc.%{_arch}.tar.xz +%global slowdebugzip %{_jvmdir}/%{name}-%{version}-%{prelease}.portable.slowdebug.jdk.%{_arch}.tar.xz +%global fastdebugzip %{_jvmdir}/%{name}-%{version}-%{prelease}.portable.fastdebug.jdk.%{_arch}.tar.xz ############################################ # @@ -1406,10 +1414,12 @@ Patch534: rh1648246-always_instruct_vm_to_assume_multiple_processors_are_availab Patch1000: rh1648249-add_commented_out_nss_cfg_provider_to_java_security.patch # RH1582504: Use RSA as default for keytool, as DSA is disabled in all crypto policies except LEGACY Patch1003: rh1582504-rsa_default_for_keytool.patch +# RH1750419: Enable build of speculative store bypass hardened alt-java (CVE-2018-3639) +Patch600: rh1750419-redhat_alt_java.patch # Crypto policy and FIPS support patches # Patch is generated from the fips tree at https://github.com/rh-openjdk/jdk8u/tree/fips -# as follows: git diff %%{openjdk_revision} common jdk > fips-8u-$(git show -s --format=%h HEAD).patch +# as follows: git diff common jdk > fips-8u-$(git show -s --format=%h HEAD).patch # Diff is limited to src and make subdirectories to exclude .github changes # Fixes currently included: # PR3183, RH1340845: Support Fedora/RHEL8 system crypto policy @@ -1453,8 +1463,8 @@ Patch528: pr3083-rh1346460-for_ssl_debug_return_null_instead_of_exception_when_t Patch539: pr2888-rh2055274-support_system_cacerts-%{cacertsver}.patch # RH1684077, JDK-8009550: Depend on pcsc-lite-libs instead of pcsc-lite-devel as this is only in optional repo Patch541: rh1684077-openjdk_should_depend_on_pcsc-lite-libs_instead_of_pcsc-lite-devel.patch -# RH1750419: Enable build of speculative store bypass hardened alt-java (CVE-2018-3639) -Patch600: rh1750419-redhat_alt_java.patch +# JDK-8385876: [8u] hotspot/src/share/vm/code/compiledIC.cpp:406:30: error: 'this' pointer is null +Patch542: jdk8385876-zero_this_pointer_is_null.patch ############################################# # @@ -1582,22 +1592,22 @@ BuildRequires: zip # For definitions and macros like jvmdir BuildRequires: javapackages-filesystem %if %{include_normal_build} -BuildRequires: java-1.%{majorver}.0-openjdk-portable-unstripped = %{epoch}:%{pversion}-%{prelease}.%{portablesuffix} +BuildRequires: java-1.%{majorver}.0-openjdk-portable-unstripped = %{epoch}:%{version}-%{prelease}.%{portablesuffix} %endif %if %{include_fastdebug_build} -BuildRequires: java-1.%{majorver}.0-openjdk-portable-devel-fastdebug = %{epoch}:%{pversion}-%{prelease}.%{portablesuffix} +BuildRequires: java-1.%{majorver}.0-openjdk-portable-devel-fastdebug = %{epoch}:%{version}-%{prelease}.%{portablesuffix} %endif %if %{include_debug_build} -BuildRequires: java-1.%{majorver}.0-openjdk-portable-devel-slowdebug = %{epoch}:%{pversion}-%{prelease}.%{portablesuffix} +BuildRequires: java-1.%{majorver}.0-openjdk-portable-devel-slowdebug = %{epoch}:%{version}-%{prelease}.%{portablesuffix} %endif -BuildRequires: java-1.%{majorver}.0-openjdk-portable-docs = %{epoch}:%{pversion}-%{prelease}.%{portablesuffix} -BuildRequires: java-1.%{majorver}.0-openjdk-portable-misc = %{epoch}:%{pversion}-%{prelease}.%{portablesuffix} +BuildRequires: java-1.%{majorver}.0-openjdk-portable-docs = %{epoch}:%{version}-%{prelease}.%{portablesuffix} +BuildRequires: java-1.%{majorver}.0-openjdk-portable-misc = %{epoch}:%{version}-%{prelease}.%{portablesuffix} # Zero-assembler build requirement %ifarch %{zero_arches} BuildRequires: libffi-devel %endif -# 2026a required as of JDK-8379035 -BuildRequires: tzdata-java >= 2026a +# 2026b required as of JDK-8383175 +BuildRequires: tzdata-java >= 2026b # Earlier versions have a bug in tree vectorization on PPC BuildRequires: gcc >= 4.8.3-8 @@ -1618,13 +1628,13 @@ Provides: bundled(freetype) = 2.14.2 # Version in jdk/src/share/native/sun/awt/giflib/gif_lib.h Provides: bundled(giflib) = 6.1.2 # Version in jdk/src/share/native/sun/java2d/cmm/lcms/lcms2.h -Provides: bundled(lcms2) = 2.15.0 +Provides: bundled(lcms2) = 2.19.1 # Version in jdk/src/share/native/sun/awt/image/jpeg/jpeglib.h Provides: bundled(libjpeg) = 6b # Version in jdk/src/share/native/sun/awt/libpng/png.h Provides: bundled(libpng) = 1.6.57 # Version in jdk/src/share/native/java/util/zip/zlib/zlib.h -Provides: bundled(zlib) = 1.3.1 +Provides: bundled(zlib) = 1.3.2 %endif # this is always built, also during debug-only build @@ -1898,12 +1908,14 @@ echo "Milestone: %{milestone}" export XZ_OPT="-T0" %endif %setup -q -c -n %{uniquesuffix ""} -T -a 0 + # https://bugzilla.redhat.com/show_bug.cgi?id=1189084 prioritylength=`expr length %{priority}` if [ $prioritylength -ne 7 ] ; then echo "priority must be 7 digits in total, violated" exit 14 fi + # For old patches ln -s %{top_level_dir_name} jdk8 ln -s %{top_level_dir_name} openjdk @@ -1917,20 +1929,6 @@ cp %{SOURCE101} %{top_level_dir_name}/common/autoconf/build-aux/ # OpenJDK patches -# This syntax is deprecated: -# %patchN [...] -# and should be replaced with: -# %patch -PN [...] -# For example: -# %patch1001 -p1 -# becomes: -# %patch -P1001 -p1 -# The replacement format suggested by recent (circa Fedora 38) RPM -# deprecation messages: -# %patch N [...] -# is not backward-compatible with prior (circa RHEL-8) versions of -# rpmbuild. - %if %{system_libs} # Remove libraries that are linked sh %{SOURCE12} @@ -1972,6 +1970,7 @@ pushd %{top_level_dir_name} %patch -P502 -p1 %patch -P14 -p1 %patch -P15 -p1 +%patch -P542 -p1 popd # Early fixes @@ -2083,7 +2082,7 @@ for suffix in %{build_loop} ; do %endif %endif # Fix build paths in ELF files so it looks like we built them - portablenvr="%{name}-portable-%{pversion}-%{prelease}.%{portablesuffix}.%{_arch}" + portablenvr="%{name}-%{VERSION}-%{prelease}.%{portablesuffix}.%{_arch}" for file in $(find ${installdir} -type f) ; do if ! echo ${file} | grep -q 'libffi' ; then if file ${file} | grep -q 'ELF'; then @@ -2426,9 +2425,9 @@ done -- see https://bugzilla.redhat.com/show_bug.cgi?id=1290388 for pretrans over pre -- if copy-jdk-configs is in transaction, it installs in pretrans to temp -- if copy_jdk_configs is in temp, then it means that copy-jdk-configs is in transaction and so is --- preferred over one in %%{_libexecdir}. If it is not in transaction, then depends +-- preferred over one in <_libexecdir>. If it is not in transaction, then depends -- whether copy-jdk-configs is installed or not. If so, then configs are copied --- (copy_jdk_configs from %%{_libexecdir} used) or not copied at all +-- (copy_jdk_configs from <_libexecdir> used) or not copied at all local posix = require "posix" if (os.getenv("debug") == "true") then @@ -2716,6 +2715,51 @@ cjc.mainProgram(args) %endif %changelog +* Fri Jul 17 2026 Andrew Hughes - 1:1.8.0.502.b07-1.1 +- Update to 8u502-b07 (GA). +- Update release notes for 8u502-b07. +- Bump lcms2 version to 2.19.1 following JDK-8321489, JDK-8348110, JDK-8375065 & JDK-8383354 +- Bump zlib version to 1.3.2 following JDK-8378631 +- Require tzdata 2026b due to upstream inclusion of JDK-8383175 +- Add attempted patch for JDK-8385876 to fix -Wnonnull build failure with s390x Zero on CentOS 9 +- Remove macro references in comments where possible (%dnl not compatible enough yet) +- Move version information and core NVR definitions back towards the top of the file +- Explictly define supported architectures +- Specify portablerelease and rpmrelease (always 0 for portables) in the Release field +- Make zone string debug output optional in TestTranslations +- Change javadoc-zip to just own the top-level directory, not include the entire subtree +- Update tagged versions to include 9.8.0-z & 9.9.0. +- Cleanup tagging and gating scripts to appease shellcheck: +- * scripts/builds/build_vanilla.sh: Use an array to handle the varying arguments to rhpkg. +- * scripts/builds/check_signatures.sh: Quote variable usage. +- * scripts/builds/waive_issue.sh: Remove redundant 'test "x"' usage. +- * scripts/builds/waive_leapp_issue.sh: Likewise. +- * scripts/builds/waive_rpminspect.sh: Likewise. +- * scripts/builds/waive_usual_rpminspect.sh: Likewise and add missing WORKING_DIR variable. +- * scripts/builds/waive_usual_tier0.sh: Remove redundant 'test "x"' usage. +- Obsolete old RHEL releases (8.2.0-z, 9.0.0-z, 9.7.0-z) +- Sync the copy of the portable specfile with the latest update +- Sync portable naming with later JDKs, due to adoption of by portable +- Drop which is a redundant alias for version now +- Update tagging scripts to include signature checks and correctly handle gating +- Add gating scripts to simplify obtaining results and waiving issues +- ** This tarball is embargoed until 2026-07-21 @ 1pm PT. ** +- Resolves: RHEL-212354 +- Resolves: RHEL-188874 +- Resolves: RHEL-212132 +- Resolves: RHEL-212311 +- Resolves: RHEL-212317 +- Related: RHEL-212322 +- Resolves: RHEL-212355 +- Resolves: RHEL-212356 +- Resolves: RHEL-212357 +- Resolves: RHEL-212358 + +* Fri Jul 17 2026 Thomas Fitzsimmons - 1:1.8.0.502.b07-1.1 +- Make headless own /usr/share/doc/java-1.8.0-openjdk +- Make javadoc-zip own /usr/share/javadoc/java-1.8.0-openjdk +- Resolves: RHEL-212322 + * Fri Apr 17 2026 Andrew Hughes - 1:1.8.0.492.b09-1 - Update to 8u492-b09 (GA) - Update release notes for 8u492-b09.