diff --git a/.gitignore b/.gitignore index fb3730c..46375c9 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,2 @@ -SOURCES/openjdk-21.0.12+8.tar.xz +SOURCES/openjdk-21.0.12.1+1.tar.xz SOURCES/tapsets-icedtea-6.0.0pre00-c848b93a8598.tar.xz diff --git a/.java-21-openjdk.metadata b/.java-21-openjdk.metadata index e037844..6670cc3 100644 --- a/.java-21-openjdk.metadata +++ b/.java-21-openjdk.metadata @@ -1,2 +1,2 @@ -ea834fa6f0a59b71501f1a59a5ae8a6c2dfa3974 SOURCES/openjdk-21.0.12+8.tar.xz +489c384a1dec22fc3d2265c17002a7c0c26ff66b SOURCES/openjdk-21.0.12.1+1.tar.xz c8281ee37b77d535c9c1af86609a531958ff7b34 SOURCES/tapsets-icedtea-6.0.0pre00-c848b93a8598.tar.xz diff --git a/SOURCES/NEWS b/SOURCES/NEWS index d8616f5..3213d01 100644 --- a/SOURCES/NEWS +++ b/SOURCES/NEWS @@ -3,12 +3,38 @@ Key: JDK-X - https://bugs.openjdk.java.net/browse/JDK-X CVE-XXXX-YYYY: https://cve.mitre.org/cgi-bin/cvename.cgi?name=XXXX-YYYY +New in release OpenJDK 21.0.12.1 (2026-08-18): +============================================== +Live versions of these release notes can be found at: + * https://bit.ly/openjdk210121 + +* CVEs + - CVE-2026-60589 + - CVE-2026-61308 + - CVE-2026-70907 +* Changes + - JDK-8333743: Change .jcheck/conf branches property to match valid branches + - JDK-8382471: Improve Resource Resolving + - JDK-8384708: Enhance HTTP Connections + - JDK-8386205: Enhance TLS server + - JDK-8388789: Bump update version for OpenJDK: jdk-21.0.12.1 + - JDK-8389946: [21u] Remove designator DEFAULT_PROMOTED_VERSION_PRE=ea for release 21.0.12.1 + New in release OpenJDK 21.0.12 (2026-07-21): =========================================== Live versions of these release notes can be found at: * https://bit.ly/openjdk2112 * CVEs + - CVE-2026-46968 + - CVE-2026-46917 + - CVE-2026-47010 + - CVE-2026-47021 + - CVE-2026-47027 + - CVE-2026-60147 + - CVE-2026-47059 + - CVE-2026-47063 + - CVE-2026-41254 * Changes - JDK-7184899: Test sun/java2d/X11SurfaceData/SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fail - JDK-8015444: java/awt/Focus/KeyStrokeTest.java sometimes fails diff --git a/SOURCES/java-21-openjdk-portable.specfile b/SOURCES/java-21-openjdk-portable.specfile index ae2e631..f177b48 100644 --- a/SOURCES/java-21-openjdk-portable.specfile +++ b/SOURCES/java-21-openjdk-portable.specfile @@ -2,8 +2,8 @@ %global featurever 21 %global interimver 0 %global updatever 12 -%global patchver 0 -%global buildver 8 +%global patchver 1 +%global buildver 1 %global portablerelease 1 %global rpmrelease 0 @@ -25,8 +25,16 @@ %global top_level_dir_name %{vcstag} %global top_level_dir_name_backup %{top_level_dir_name}-backup # Define an optional suffix for the OS this package is built on -%if 0%{?rhel} == 7 -%global pkgos rhel7 +# The portable package is intended to be built on either RHEL 8 +# or CentOS Stream 9; any other OS will automatically get an +# appropriate suffix +%global rhel_buildos 8 +%global centos_buildos 9 +%if 0%{?centos} == 0 && 0%{?rhel} != 0%{rhel_buildos} +%global pkgos rhel%{?rhel} +%endif +%if 0%{?centos} != 0 && 0%{?centos} != 0%{centos_buildos} +%global pkgos rhel%{?centos} %endif # Define milestone (EA for pre-releases, GA for releases) @@ -235,7 +243,7 @@ URL: http://openjdk.java.net/ # Set of architectures for which we have a devkit # Only used on RHEL %if 0%{?centos} == 0 -%global devkit_arches %{aarch64} %{ppc64le} riscv64 s390x x86_64 +%global devkit_arches %{aarch64} %{ppc64le} s390x x86_64 %endif # By default, we build a slowdebug build during main build on JIT architectures @@ -526,8 +534,14 @@ URL: http://openjdk.java.net/ # Define the architectures on which we build # On RHEL, this should be the architectures with a devkit +# The exception is riscv64, which was introduced too recently +# for a devkit to exist. In that case, we build without devkit %if 0%{?centos} == 0 +%if 0%{?rhel} >= 10 +ExclusiveArch: %{devkit_arches} riscv64 +%else ExclusiveArch: %{devkit_arches} +%endif %else ExclusiveArch: %{aarch64} %{ppc64le} riscv64 s390x x86_64 %endif @@ -538,7 +552,7 @@ Source0: https://openjdk-sources.osci.io/openjdk%{featurever}/open%{vcstag}%{ea_ # Use 'icedtea_sync.sh' to update the following # They are based on code contained in the IcedTea project (6.x). # Systemtap tapsets. Zipped up to keep it small. -Source8: tapsets-icedtea-%%{icedteaver}.tar.xz +Source8: tapsets-icedtea-%{icedteaver}.tar.xz # Desktop files. Adapted from IcedTea # Disabled in portables @@ -683,7 +697,7 @@ BuildRequires: zip BuildRequires: tar BuildRequires: unzip BuildRequires: javapackages-filesystem -BuildRequires: java-%{buildjdkver}-%{origin}%{?pkgos:-%{pkgos}}-devel +BuildRequires: java-%{buildjdkver}-%{origin}-devel # Zero-assembler build requirement %ifarch %{zero_arches} BuildRequires: libffi-devel @@ -873,6 +887,7 @@ The %{origin_nice} %{featurever} miscellany. echo "Preparing %{oj_vendor_version}" echo "System is RHEL=%{?rhel}%{!?rhel:0}, CentOS=%{?centos}%{!?centos:0}, EPEL=%{?epel}%{!?epel:0}, Fedora=%{?fedora}%{!?fedora:0}" +echo "Portable suffix is %{?pkgos}%{!?pkgos:unset}" # Using the echo macro breaks rpmdev-bumpspec, as it parses the first line of stdout :-( %if 0%{?stapinstall:1} @@ -1885,6 +1900,30 @@ done %endif %changelog +* Mon Aug 10 2026 Andrew Hughes - 1:21.0.12.1.1-1.0 +- Update to jdk-21.0.12.1+1 (GA) +- Update release notes to 21.0.12.1+1 +- Fix double '%' in specification of IcedTea sources +- ** This tarball is embargoed until 2026-08-18 @ 1pm PT. ** +- Resolves: OPENJDK-5042 + +* Mon Aug 10 2026 Andrew Hughes - 1:21.0.12.0.8-3.0 +- Make rhel usage in pkgos optional as it may be undefined +- Simplify pkgos conditional to work on RHEL 8 +- Related: OPENJDK-5045 + +* Fri Aug 07 2026 Andrea Bolognani - 1:21.0.12.0.8-3.0 +- Automatically set pkgos when necessary +- Remove now redundant pkgos usage in JDK build dependency +- Don't attempt to use devkit on riscv64 +- Resolves: OPENJDK-5045 +- Resolves: OPENJDK-5046 + +* Wed Jul 29 2026 Andrew Hughes - 1:21.0.12.0.8-2.0 +- Add CVEs to NEWS file +- Update to tarball with final changeset ID +- Related: OPENJDK-4865 + * Wed Jul 15 2026 Andrew Hughes - 1:21.0.12.0.8-1.0 - Update to jdk-21.0.12+8 (GA) - Update release notes to 21.0.12+8 diff --git a/SPECS/java-21-openjdk.spec b/SPECS/java-21-openjdk.spec index cc7ba17..26e0c74 100644 --- a/SPECS/java-21-openjdk.spec +++ b/SPECS/java-21-openjdk.spec @@ -7,8 +7,8 @@ %global featurever 21 %global interimver 0 %global updatever 12 -%global patchver 0 -%global buildver 8 +%global patchver 1 +%global buildver 1 %global portablerelease 1 %global rpmrelease 1 @@ -2562,6 +2562,19 @@ require "copy_jdk_configs.lua" %endif %changelog +* Mon Aug 10 2026 Andrew Hughes - 1:21.0.12.1.1-1.1 +- Update to jdk-21.0.12.1+1 (GA) +- Update release notes to 21.0.12.1+1 +- Sync the copy of the portable specfile with the latest update +- ** This tarball is embargoed until 2026-08-18 @ 1pm PT. ** +- Resolves: RHEL-235610 + +* Wed Jul 29 2026 Andrew Hughes - 1:21.0.12.0.8-2.1 +- Add CVEs to NEWS file +- Update to tarball with final changeset ID +- Sync the copy of the portable specfile with the latest update +- Related: RHEL-188853 + * Sat Jul 18 2026 Andrew Hughes - 1:21.0.12.0.8-1.1 - Update to jdk-21.0.12+8 (GA) - Update release notes to 21.0.12+8