import UBI java-21-openjdk-21.0.12.0.8-1.2.el10_2

This commit is contained in:
AlmaLinux RelEng Bot 2026-07-22 19:07:53 -04:00
parent 9ce599680d
commit bc31185b2b
6 changed files with 714 additions and 350 deletions

2
.gitignore vendored
View File

@ -1,2 +1,2 @@
openjdk-21.0.11+10.tar.xz
openjdk-21.0.12+8.tar.xz
tapsets-icedtea-6.0.0pre00-c848b93a8598.tar.xz

339
NEWS
View File

@ -3,6 +3,345 @@ Key:
JDK-X - https://bugs.openjdk.java.net/browse/JDK-X
CVE-XXXX-YYYY: https://cve.mitre.org/cgi-bin/cvename.cgi?name=XXXX-YYYY
New in release OpenJDK 21.0.12 (2026-07-21):
===========================================
Live versions of these release notes can be found at:
* https://bit.ly/openjdk2112
* CVEs
* Changes
- JDK-7184899: Test sun/java2d/X11SurfaceData/SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fail
- JDK-8015444: java/awt/Focus/KeyStrokeTest.java sometimes fails
- JDK-8064922: [macos] Test javax/swing/JTabbedPane/4624207/bug4624207.java fails
- JDK-8068293: [TEST_BUG] Test closed/com/sun/java/swing/plaf/motif/InternalFrame/4150591/bug4150591.java fails with GTKLookAndFeel
- JDK-8068310: [TEST_BUG] Test javax/swing/JColorChooser/Test4234761.java fails with GTKL&F
- JDK-8068378: [TEST_BUG]The java/awt/Modal/PrintDialogsTest/PrintDialogsTest.java instruction need to update
- JDK-8129418: JShell: better highlighting of errors in imports on demand
- JDK-8144124: [macosx] The tabs can't be aligned when we pressing the key of 'R','B','L','C' or 'T'.
- JDK-8183336: Better cleanup for jdk/test/java/lang/module/customfs/ModulesInCustomFileSystem.java
- JDK-8203004: UnixMultiResolutionSplashTest.java fails on Ubuntu16.04
- JDK-8212084: G1: Implement UseGCOverheadLimit
- JDK-8213530: Test java/awt/Modal/ToFront/DialogToFrontModeless1Test.java fails on Linux
- JDK-8221451: PIT: sun/java2d/X11SurfaceData/SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fails
- JDK-8225787: java/awt/Window/GetScreenLocation/GetScreenLocationTest.java fails on Ubuntu
- JDK-8255463: java/nio/channels/spi/SelectorProvider/inheritedChannel/InheritedChannelTest.java failed with ThreadTimeoutException
- JDK-8274082: Wrong test name in jtreg run tag for java/awt/print/PrinterJob/SwingUIText.java
- JDK-8277444: Data race between JvmtiClassFileReconstituter::copy_bytecodes and class linking
- JDK-8278102: containers/docker/TestJcmd.java failed with "RuntimeException: Could not find specified process"
- JDK-8286258: [Accessibility,macOS,VoiceOver] VoiceOver reads the spinner value wrong and sometime partially
- JDK-8286865: vmTestbase/vm/mlvm/meth/stress/jni/nativeAndMH/Test.java fails with Out of space in CodeCache
- JDK-8293484: AArch64: TestUseSHA512IntrinsicsOptionOnSupportedCPU.java fails on CPU with SHA512 feature support
- JDK-8297191: [macos] Printing a page range with starting page > 1 results in missing pages
- JDK-8298783: java/lang/ref/FinalizerHistogramTest.java failed with "RuntimeException: MyObject is not found in test output"
- JDK-8298823: [macos] java/awt/Mouse/EnterExitEvents/DragWindowTest.java continues to fail with "No MouseReleased event on label!"
- JDK-8299304: Test "java/awt/print/PrinterJob/PageDialogTest.java" fails on macOS 13 x64 because the Page Dialog blocks the Toolkit
- JDK-8310645: CancelledResponse.java does not use HTTP/2 when testing the HttpClient
- JDK-8311538: CDS InternSharedString test fails on huge pages host - cannot find shared string
- JDK-8315588: JShell does not accept underscore from JEP 443 even with --enable-preview
- JDK-8318365: Test runtime/cds/appcds/sharedStrings/InternSharedString.java fails after JDK-8311538
- JDK-8318662: Refactor some jdk/java/net/httpclient/http2 tests to JUnit
- JDK-8319326: GC: Make TestParallelRefProc use createTestJavaProcessBuilder
- JDK-8319540: GC: Make TestSelectDefaultGC use createTestJavaProcessBuilder
- JDK-8320677: Printer tests use invalid '@run main/manual=yesno
- JDK-8321303: Intermittent open/test/jdk/java/awt/KeyboardFocusmanager/ConsumeNextMnemonicKeyTypedTest/ConsumeNextMnemonicKeyTypedTest.java failure on Linux
- JDK-8321687: Test vmTestbase/nsk/jvmti/scenarios/contention/TC03/tc03t002/TestDescription.java failed: JVMTI_ERROR_THREAD_NOT_ALIVE
- JDK-8322532: JShell : Unnamed variable issue
- JDK-8323089: networkaddress.cache.ttl is not a system property
- JDK-8323545: java/awt/GraphicsDevice/CheckDisplayModes.java fails with "exit code: 133"
- JDK-8323672: Suppress unwanted autoconf added flags in CC and CXX
- JDK-8323792: ThreadSnapshot::initialize can cause assert in Thread::check_for_dangling_thread_pointer (possibility of dangling Thread pointer)
- JDK-8326458: Menu mnemonics don't toggle in Windows LAF when F10 is pressed
- JDK-8328300: Convert PrintDialogsTest.java from Applet to main program
- JDK-8329273: C2 SuperWord: Some basic MemorySegment IR tests
- JDK-8330704: Clean up non-standard use of /** comments in some langtools tests
- JDK-8330806: test/hotspot/jtreg/compiler/c1/TestLargeMonitorOffset.java fails on ARM32
- JDK-8332495: java/util/logging/LoggingDeadlock2.java fails with AssertionError: Some tests failed
- JDK-8333729: C2 SuperWord: remove some @requires usages in test/hotspot/jtreg/compiler/loopopts/superword
- JDK-8334928: Test sun/security/ssl/SSLSocketImpl/ReuseAddr.java failed: java.net.BindException: Address already in use
- JDK-8338103: Stabilize and open source a Swing OGL ButtonResizeTest
- JDK-8338554: Fix inconsistencies in javadoc/doclet/testLinkOption/TestRedirectLinks.java
- JDK-8338883: Show warning when CreateCoredumpOnCrash set, but core dump will not happen
- JDK-8339233: Test javax/swing/JButton/SwingButtonResizeTestWithOpenGL.java#id failed: Button renderings are different after window resize
- JDK-8339638: Update vmTestbase/nsk/jvmti/*Field*Watch tests to use virtual thread factory
- JDK-8339879: Open some dialog awt tests
- JDK-8339975: Open some dialog awt tests 2
- JDK-8340140: Open some dialog awt tests 3
- JDK-8340336: Open some checkbox awt tests
- JDK-8340494: Open some dialog awt tests 4
- JDK-8340818: Add a new jtreg test root to test the generated documentation
- JDK-8340851: Open some TextArea awt tests
- JDK-8340987: Open some TextArea awt tests 1
- JDK-8341055: Open some TextArea awt tests 2
- JDK-8341292: Open some TextArea awt tests 3
- JDK-8341376: Open some TextArea awt tests 4
- JDK-8341427: JFR: Adjust object sampler span handling
- JDK-8341436: containers/docker/TestJcmdWithSideCar.java takes needlessly long to run
- JDK-8341833: incomplete snippet from loaded files from command line is ignored
- JDK-8342401: [TESTBUG] javax/swing/JSpinner/8223788/JSpinnerButtonFocusTest.java test fails in ubuntu 22.04 on SBR Hosts
- JDK-8342836: Automatically determine that a test in the docs test root is requested
- JDK-8344128: Regression: make help broken after JDK-8340818
- JDK-8345618: javax/swing/text/Caret/8163124/CaretFloatingPointAPITest.java leaves Caret is not complete
- JDK-8346154: [XWayland] Some tests fail intermittently in the CI, but not locally
- JDK-8346683: Problem list automated tests that fail on macOS15
- JDK-8347836: Disabled PopupMenu shows shortcuts on Mac
- JDK-8349084: Update vectors used in several PQC benchmarks
- JDK-8349192: jvmti/scenarios/contention/TC05/tc05t001 fails: ERROR: tc05t001.cpp, 281: (waitedThreadCpuTime - waitThreadCpuTime) < (EXPECTED_ACCURACY * 1000000)
- JDK-8349533: Refactor validator tests shell files to java
- JDK-8349699: XSL transform fails with certain UTF-8 characters on 1024 byte boundaries
- JDK-8349959: Test CR6740048.java passes unexpectedly missing CR6740048.xsd
- JDK-8350749: Upgrade JLine to 3.29.0
- JDK-8350808: Small typos in JShell method SnippetEvent.toString()
- JDK-8352020: [CompileFramework] enable compilation for VectorAPI
- JDK-8352147: G1: TestEagerReclaimHumongousRegionsClearMarkBits test takes very long
- JDK-8352149: Test java/awt/Frame/MultiScreenTest.java fails: Window list is empty
- JDK-8352431: java/net/httpclient/EmptyAuthenticate.java uses "localhost"
- JDK-8352685: Opensource JInternalFrame tests - series2
- JDK-8352733: Improve RotFontBoundsTest test
- JDK-8352877: Opensource Several Font related tests - Batch 1
- JDK-8353124: java/lang/Thread/virtual/stress/Skynet.java#Z times out on macosx-x64-debug
- JDK-8353488: Open some JComboBox bugs 3
- JDK-8353552: Opensource Several Font related tests - Batch 3
- JDK-8354163: Open source Swing tests Batch 1
- JDK-8354695: Open source several swing tests batch7
- JDK-8354900: javax/swing/AbstractButton/bug4133768.java failing on macosx-aarch64
- JDK-8354910: Output by java.io.IO or System.console() corrupted for some non-ASCII characters
- JDK-8355048: ProblemList TestGlyphVectorLayout.java on all platforms
- JDK-8355179: Reinstate javax/swing/JScrollBar/4865918/bug4865918.java headful and macos run
- JDK-8355332: Fix failing semi-manual test EDT issue
- JDK-8355371: NegativeArraySizeException in print methods in IO or System.console() in JShell
- JDK-8355443: [java.io] Use @requires tag instead of exiting based on File.separatorChar value
- JDK-8356695: java/lang/StringBuilder/HugeCapacity.java failing with OOME
- JDK-8356868: Not all cgroup parameters are made available
- JDK-8357062: Update Public Suffix List to 823beb1
- JDK-8357082: Stabilize and add debug logs to CopyAreaOOB.java
- JDK-8357086: os::xxx functions returning memory size should return size_t
- JDK-8357280: (bf) Remove @requires tags from java/nio/Buffer/LimitDirectMemory[NegativeTest].java
- JDK-8357390: java/awt/Toolkit/ScreenInsetsTest/ScreenInsetsTest.java Test failing on Ubuntu 24.04 Vm Hosts used by Oracle's internal CI system
- JDK-8358058: sun/java2d/OpenGL/DrawImageBg.java Test fails intermittently
- JDK-8359364: java/net/URL/EarlyOrDelayedParsing test fails intermittently
- JDK-8359472: JVM crashes when attaching a dynamic agent before JVMTI_PHASE_LIVE
- JDK-8359978: Test javax/net/ssl/SSLSocket/Tls13PacketSize.java failed again with java.net.SocketException: An established connection was aborted by the software in your host machine
- JDK-8360160: ubuntu-22-04 machine is failing client tests
- JDK-8360395: sun/security/tools/keytool/i18n.java user country is current user location instead of the language
- JDK-8360562: sun/security/tools/keytool/i18n.java add an ability to add comment for failures
- JDK-8360702: runtime/Thread/AsyncExceptionTest.java timed out
- JDK-8360882: Tests throw SkippedException when they should fail
- JDK-8361106: [TEST] com/sun/net/httpserver/Test9.java fails with java.nio.file.FileSystemException
- JDK-8361606: ConsumeNextMnemonicKeyTypedTest.java fails on Windows: character typed with VK_A: a
- JDK-8361894: sun/security/krb5/config/native/TestDynamicStore.java ensure that the test is run with sudo
- JDK-8362428: Update IANA Language Subtag Registry to Version 2025-08-25
- JDK-8363943: ARM32: Represent Registers as values
- JDK-8363949: Incorrect jtreg header in MonitorWithDeadObjectTest.java
- JDK-8364190: JFR: RemoteRecordingStream withers don't work
- JDK-8364315: Remove unused xml files from test/jaxp/javax/xml/jaxp/functional/javax/xml/transform/xmlfiles
- JDK-8364756: JFR: Improve slow tests
- JDK-8364927: Add @requires annotation to TestReclaimStringsLeaksMemory.java
- JDK-8365379: SU3.applyInsets may produce wrong results
- JDK-8365398: TEST_BUG: java/rmi/transport/checkLeaseInfoLeak/CheckLeaseLeak.java failing intermittently
- JDK-8365423: [macos26] java/awt/MenuBar/8007006/bug8007006.java fails on macOS 26
- JDK-8365424: [macos26] java/awt/Frame/DisposeTest.java fails on macOS 26
- JDK-8365623: test/jdk/sun/security/pkcs11/tls/ tests skipped without skip exception
- JDK-8365625: Can't change accelerator colors in Windows L&F
- JDK-8365776: Convert JShell tests to use JUnit instead of TestNG
- JDK-8365861: test/jdk/sun/security/pkcs11/Provider/ tests skipped without SkippedException
- JDK-8365863: /test/jdk/sun/security/pkcs11/Cipher tests skip without SkippedException
- JDK-8365893: test/jdk/java/lang/Thread/virtual/JfrEvents.java failing intermittently
- JDK-8366031: Mark com/sun/nio/sctp/SctpChannel/CloseDescriptors.java as intermittent
- JDK-8366182: Some PKCS11Tests are being skipped when they shouldn't
- JDK-8366369: Add @requires linux for GTK L&F tests
- JDK-8366852: java/awt/Choice/ChoiceMouseWheelTest/ChoiceMouseWheelTest.java test is failing
- JDK-8367096: jdk/open/test/jdk/sun/security/pkcs11/ rsa, ec, config, secmod and sslecc tests are skipping but showing as pass
- JDK-8367485: os::physical_memory is broken in 32-bit JVMs when running on 64-bit OSes
- JDK-8367784: java/awt/Focus/InitialFocusTest/InitialFocusTest1.java failed with Wrong focus owner
- JDK-8368029: Several tests in httpserver/simpleserver should throw SkipException
- JDK-8368041: Enhance TLS certificate handling
- JDK-8368181: ProblemList java/awt/Dialog/ModalExcludedTest/ModalExcludedTest.java
- JDK-8368335: Refactor the rest of Locale TestNG based tests to JUnit
- JDK-8368498: Use JUnit instead of TestNG for jdk_text tests
- JDK-8368524: Tests are skipped and shown as passed in test/jdk/sun/security/pkcs11/Cipher/KeyWrap
- JDK-8368551: Core dump warning may be confusing
- JDK-8368625: com/sun/net/httpserver/ServerStopTerminationTest.java fails intermittently
- JDK-8368670: Deadlock in JFR on event register + class load
- JDK-8368754: runtime/cds/appcds/SignedJar.java log regex is too strict
- JDK-8368866: compiler/codecache/stress/UnexpectedDeoptimizationTest.java intermittent timed out
- JDK-8368885: NMT CommandLine tests can check for error better
- JDK-8368892: Make JEditorPane/TestBrowserBGColor.java headless
- JDK-8369251: Opensource few tests
- JDK-8369335: Two sun/java2d/OpenGL tests fail on Windows after JDK-8358058
- JDK-8369516: Delete duplicate imaging test
- JDK-8369561: sun/java2d/OpenGL/DrawBitmaskImage.java#id0: Incorrect color for first pixel (actual=ff000000)
- JDK-8369683: Exclude runtime/Monitor/MonitorWithDeadObjectTest.java#DumpThreadsBeforeDetach on Alpine Linux debug
- JDK-8369851: Remove darcy author tags from langtools tests
- JDK-8369950: TLS connection to IPv6 address fails with BCJSSE due to IllegalArgumentException
- JDK-8370378: Some compiler tests inadvertently exclude particular platforms
- JDK-8370489: Some compiler tests miss the @key randomness
- JDK-8370492: [Linux] Update cpu shares to cpu.weight mapping function
- JDK-8370511: test/jdk/javax/swing/JSlider/bug4382876.java does not release previously pressed keys
- JDK-8370732: Use WhiteBox.getWhiteBox().fullGC() to provoking gc for nsk/jvmti tests
- JDK-8370905: Update vm.defmeth tests to use virtual threads
- JDK-8370942: test/jdk/java/security/Provider/NewInstance.java and /test/jdk/java/security/cert/CertStore/NoLDAP.java may skip without notifying
- JDK-8371262: sun/security/pkcs11/Cipher/KeyWrap tests may silently skip
- JDK-8371349: Update NSS library to 3.117
- JDK-8371364: Refactor javax/swing/JFileChooser/FileSizeCheck.java to use Util.findComponent()
- JDK-8371365: Update javax/swing/JFileChooser/bug4759934.java to use Util.findComponent()
- JDK-8371366: java/net/httpclient/whitebox/RawChannelTestDriver.java fails intermittently in jtreg timeout
- JDK-8371383: Test sun/security/tools/jarsigner/DefaultOptions.java failed due to CertificateNotYetValidException
- JDK-8371503: RETAIN_IMAGE_AFTER_TEST do not work for some tests
- JDK-8371895: Lower GCTimeLimit in TestUseGCOverheadLimit.java
- JDK-8371967: Add Visual Studio 2026 to build toolchain for Windows
- JDK-8372120: Add missing sound keyword to MIDI tests
- JDK-8372272: Hotspot shared lib loading - add load attempts to Events::log
- JDK-8372351: Add 2 WISeKey roots
- JDK-8372609: Bug4944439 does not enforce locale correctly
- JDK-8372661: Add a null-safe static factory method to "jdk.test.lib.net.SimpleSSLContext"
- JDK-8373101: JdkClient and JdkServer test classes ignore namedGroups field
- JDK-8373239: Test java/awt/print/PrinterJob/PageRanges.java fails with incorrect selection of printed pages
- JDK-8373275: Improve DTLS handshaking
- JDK-8373537: Migrate "test/jdk/com/sun/net/httpserver/" to null-safe "SimpleSSLContext" methods
- JDK-8373593: Support latest VS2026 MSC_VER in abstract_vm_version.cpp
- JDK-8373623: Refactor Serialization tests for Records to JUnit
- JDK-8373632: Some sound tests failing in CI due to lack of sound key
- JDK-8373650: Test "javax/swing/JMenuItem/6458123/ManualBug6458123.java" fails because the check icons are not aligned properly as expected
- JDK-8373690: Unexpected Keystore message using jdk.crypto.disabledAlgorithms
- JDK-8373704: Improve "SocketException: Protocol family unavailable" message
- JDK-8373716: Refactor further java/util tests from TestNG to JUnit
- JDK-8373793: TestDynamicStore.java '/manual' disables use of '/timeout'
- JDK-8373796: Refactor java/net/httpclient/ThrowingPublishers*.java tests to use JUnit5
- JDK-8373807: test/jdk/java/net/httpclient/websocket/DummyWebSocketServer.java getURI() uses "localhost"
- JDK-8373832: Test java/lang/invoke/TestVHInvokerCaching.java tests nothing
- JDK-8373847: Test javax/swing/JMenuItem/MenuItemTest/bug6197830.java failed because The test case automatically fails when clicking any items in the “Nothing” menu in all four windows (Left-to-right)-Menu Item Test and (Right-to-left)-Menu Item Test
- JDK-8373866: Refactor java/net/httpclient/ThrowingSubscribers*.java tests to use JUnit5
- JDK-8373869: Refactor java/net/httpclient/ThrowingPushPromises*.java tests to use JUnit5
- JDK-8373928: 4 Dangling pointer defect groups in java.c
- JDK-8373931: Test javax/sound/sampled/Clip/AutoCloseTimeCheck.java timed out
- JDK-8374058: Enhance JPEG handling
- JDK-8374304: MultiResolutionSplashTest.java fails in CI: "Image with wrong resolution is used for splash screen!"
- JDK-8374322: TestMemoryWithSubgroups.java fails Permission denied
- JDK-8374434: Several JShell tests report JUnit discovery warnings
- JDK-8374506: Incorrect positioning of arrow icon in parent JMenu in Windows L&F
- JDK-8374711: Hotspot runtime/CommandLine/OptionsValidation/TestOptionsWithRanges fails without printing the option name
- JDK-8374769: PPC: MASM::pop_cont_fastpath() should reset _cont_fastpath if SP == _cont_fastpath
- JDK-8374888: Implement internal test cache to help UserIterCount test performance
- JDK-8374998: Failing os::write - remove bad file
- JDK-8375065: Update LCMS to 2.18
- JDK-8375080: The tools/jpackage/windows/Win8365790Test.java may fail with ClassNotFoundException: jtreg.SkippedException
- JDK-8375231: Refactor util/ServiceLoader tests to use JUnit
- JDK-8375232: Refactor util/StringJoiner tests to use JUnit
- JDK-8375233: Refactor util/Vector tests to use JUnit
- JDK-8375742: Test java/lang/invoke/MethodHandleProxies/Driver.java does not run Unnamed.java
- JDK-8376031: HttpsURLConnection.getServerCertificates() throws "java.lang.IllegalStateException: connection not yet open" for the HEAD method
- JDK-8376151: Test javax/swing/JFileChooser/4966171/bug4966171.java is failing with OOME
- JDK-8376152: Test javax/sound/sampled/Clip/bug5070081.java timed out then completed
- JDK-8376233: Clean up code in Desktop native peer
- JDK-8376889: Enhance JfrRecorder::on_create_vm_3() assert output
- JDK-8377158: Enhance XBM image support
- JDK-8377167: javax/imageio/ReadAbortTest.java throw NPE when x11 unavailable
- JDK-8377347: jdk/jfr/event/gc/detailed/TestZAllocationStallEvent.java intermittent OOME
- JDK-8377498: Improve HttpServer handling
- JDK-8377602: Create automated test for PageRange
- JDK-8377727: Ghost caret and focus appear in noneditable text fields
- JDK-8377833: Enhance Jar file processing
- JDK-8377910: Minor cleanup of java/io/FileDescriptor/Sharing.java
- JDK-8377944: LowMemoryTest2.java#id1 intermittent fails OOME: Metaspace
- JDK-8378113: Add sun/java2d/OpenGL/ScaleParamsOOB.java to the ProblemList.txt file
- JDK-8378201: [OGL] glXMakeContextCurrent() drops the buffers of the unbound drawable
- JDK-8378353: [PPC64] StringCoding.countPositives causes errors when the length is not a proper 32 bit int
- JDK-8378417: Printing All pages results in NPE for 1.1 PrintJob
- JDK-8378561: Mark gc/shenandoah/compiler/TestLinkToNativeRBP.java as /native
- JDK-8378687: Improve delegation of HttpURLConnection
- JDK-8378775: Bump update version for OpenJDK: jdk-21.0.12
- JDK-8378802: [21u] backport changes to TKit.java by JDK-8352419
- JDK-8378810: Enable missing FFM test via jtreg requires for RISC-V
- JDK-8378878: Refactor java/nio/channels/AsynchronousSocketChannel test to use JUnit
- JDK-8379464: Enable missing stack walking test via jtreg requires for RISC-V
- JDK-8380011: Path-to-gcroots search should not trigger stack overflows
- JDK-8380222: Refactor test/jdk/java/lang/Character TestNG tests to JUnit
- JDK-8380316: Test runtime/os/AvailableProcessors.java fails Invalid argument
- JDK-8380428: ProblemList containers/docker/TestJcmdWithSideCar.java on linux-all
- JDK-8380474: Crash SEGV in ThreadIdTable::lazy_initialize after JDK-8323792
- JDK-8380565: PPC64: deoptimization stub should save vector registers
- JDK-8380672: Improve certification checking
- JDK-8380947: Add pull request template
- JDK-8381039: Enhance AWT ImagingLib
- JDK-8381049: Enhance Jar handling
- JDK-8381205: GHA: Upgrade Node.js 20 to 24
- JDK-8381315: compiler/vectorapi/TestVectorReallocation.java fails with -XX:UseAVX=1 after JDK-8380565
- JDK-8381519: Enhance Der Value Handling
- JDK-8381796: Enhance Certificate parsing
- JDK-8382018: test/jdk/java/nio/file/spi/SetDefaultProvider.java leaves a directory in /tmp
- JDK-8382242: JFR: Metadata reconstruction invalidates ConstantMap for java.lang.String
- JDK-8382419: Add missed @key randomness after JDK-8370489
- JDK-8383175: (tz) Update Timezone Data to 2026b
- JDK-8383185: [21u] Backport of JDK-8382925 causes test failure in SetDefaultProvider
- JDK-8383354: Update LCMS to 2.19.1
- JDK-8383473: Follow on from tzdata2026b time change to include temporary hack BC time change
- JDK-8383601: RISC-V: ShenandoahBarrierSetAssembler::load_reference_barrier calls "weak" on "phantom" path
- JDK-8383630: Fix iteration in tests doing class redefinition
- JDK-8384158: GHA: Downgrade Windows GHA runners to windows-2022 temporarily
- JDK-8384486: NTLM tests fail on Windows 11 and Windows Server 2025
- JDK-8384495: Update Libpng to 1.6.58
- JDK-8384540: [25u, 21u, 17u] Update GHA JDKs after Apr/26 updates
- JDK-8384815: SelectOneKeyOutOfMany and PreferredKey fail after expired test certificate
- JDK-8384902: Update GIFlib to 6.1.3
- JDK-8385390: Update FreeType to 2.14.3
- JDK-8385490: Update HarfBuzz to 14.2.0
- JDK-8386551: Windows build broken because of MSys2/Make update
Notes on individual issues:
===========================
hotspot/gc:
JDK-8212084: G1: Implement UseGCOverheadLimit
=============================================
In this release, the G1 garbage collector now respects the values of
`GCTimeLimit` and `GCHeapFreeLimit`. The garbage collector will throw
an `OutOfMemoryException` (OOME) when the garbage collection overhead
is more than `GCTimeLimit` percent (default: 98%) and the free Java
heap is less than `GCHeapFreeLimit` (default: 2%) for five consecutive
garbage collections.
This feature is enabled by default. It may be disabled by specifying
the `-XX:-UseGCOverheadLimit` option. The implementation mirrors the
functionality already provided by the parallel garbage collector,
though there may be differences in the exact conditions when an OOME
is triggered, due to differences in the way the collectors calculate
the collection overhead and free Java heap.
security-libs/java.security:
JDK-8372351: Add 2 WISeKey roots
================================
The following root certificates have been added to the cacerts
truststore:
Alias Name: wisekeyglobalrootgbca
Distinguished Name: CN=OISTE WISeKey Global Root GB CA, OU=OISTE Foundation Endorsed, O=WISeKey, C=CH
Serial Number: 76b1205274f0858746b3f8231af6c2c0
Valid From: Mon Dec 01 15:00:32 GMT 2014
Valid Until: Thu Dec 01 15:10:31 GMT 2039
Alias Name: wisekeyglobalrootgcca
Distinguished Name: CN=OISTE WISeKey Global Root GC CA, OU=OISTE Foundation Endorsed, O=WISeKey, C=CH
Serial Number: 212a560caeda0cab4045bf2ba22d3aea
Valid From: Tue May 09 09:48:34 GMT 2017
Valid Until: Fri May 09 09:58:33 GMT 2042
JDK-8381796: Enhance Certificate parsing
========================================
With this release of OpenJDK, a security and system property
`com.sun.security.crl.maxSize` is introduced which acts as a maximum
size limit on a Certificate Revocation List (CRL) downloaded over the
network. For URICertStore requests, the value is the maximum size in
bytes of the DER-encoded CRL. For LDAPCertStore queries, the
threshold is the sum of all CRLs downloaded from a single search. By
default, the maximum size is 20MiB (20971520 bytes) and CRLs larger
than this will be discarded. A value less than zero may be used to
turn off the size limit and non-numeric values will be ignored. A
non-empty value for the system property takes precedence over the
security property. Enabling 'certpath' debug logging will output the
current size limit and note any discarded CRLs.
New in release OpenJDK 21.0.11 (2026-04-21):
===========================================
Live versions of these release notes can be found at:

View File

@ -1,5 +1,5 @@
/* TestTranslations -- Ensure translations are available for new timezones
Copyright (C) 2022 Red Hat, Inc.
Copyright (C) 2026 Red Hat, Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as
@ -60,15 +60,34 @@ public class TestTranslations {
public static void main(String[] args) {
boolean debug = false;
if (args.length < 1) {
System.err.println("Test must be started with the name of the locale provider.");
System.exit(1);
}
if (args.length > 1) {
debug = Boolean.parseBoolean(args[1]);
}
System.err.printf("Debugging: %s\n", debug);
testZoneStrings(debug);
String localeProvider = args[0];
testZone(localeProvider, KYIV,
new String[] { "Europe/Kiev", "Europe/Kyiv", "Europe/Uzhgorod", "Europe/Zaporozhye" });
testZone(localeProvider, CIUDAD_JUAREZ,
new String[] { "America/Cambridge_Bay", "America/Ciudad_Juarez" });
}
private static void testZoneStrings(final boolean debug) {
System.out.println("Checking sanity of full zone string set...");
boolean invalid = Arrays.stream(Locale.getAvailableLocales())
.peek(l -> System.out.println("Locale: " + l))
.peek(l -> System.out.printf(debug ? "Locale: %s\n" : "", l))
.map(l -> DateFormatSymbols.getInstance(l).getZoneStrings())
.peek(df -> System.out.printf(debug ? "Zone string size: %s\n" : "", df.length))
.flatMap(zs -> Arrays.stream(zs))
.flatMap(names -> Arrays.stream(names))
.filter(name -> Objects.isNull(name) || name.isEmpty())
@ -78,12 +97,6 @@ public class TestTranslations {
System.err.println("Zone string for a locale returned null or empty string");
System.exit(2);
}
String localeProvider = args[0];
testZone(localeProvider, KYIV,
new String[] { "Europe/Kiev", "Europe/Kyiv", "Europe/Uzhgorod", "Europe/Zaporozhye" });
testZone(localeProvider, CIUDAD_JUAREZ,
new String[] { "America/Cambridge_Bay", "America/Ciudad_Juarez" });
}
private static void testZone(String localeProvider, Map<Locale,String[]> exp, String[] ids) {

View File

@ -1,5 +1,98 @@
# debug_package %%{nil} is portable-jdks specific
%define debug_package %{nil}
# New Version-String scheme-style defines
%global featurever 21
%global interimver 0
%global updatever 12
%global patchver 0
%global buildver 8
%global portablerelease 1
%global rpmrelease 0
# Define IcedTea version used for SystemTap tapsets and desktop file
%global icedteaver 6.0.0pre00-c848b93a8598
# Define current Git revision for the FIPS support patches
%global fipsver feef2dc3ca7
# Define JDK versions
%global newjavaver %{featurever}.%{interimver}.%{updatever}.%{patchver}
%global javaver %{featurever}
# Strip up to 6 trailing zeros in newjavaver, as the JDK does, to get the correct version used in filenames
%global filever %(svn=%{newjavaver}; for i in 1 2 3 4 5 6 ; do svn=${svn%%.0} ; done; echo ${svn})
# The tag used to create the OpenJDK tarball
%global vcstag jdk-%{filever}+%{buildver}%{?tagsuffix:-%{tagsuffix}}
# Standard JPackage naming and versioning defines
%global origin openjdk
%global origin_nice OpenJDK
%global top_level_dir_name %{vcstag}
%global top_level_dir_name_backup %{top_level_dir_name}-backup
# Define an optional suffix for the OS this package is built on
%if 0%{?rhel} == 7
%global pkgos rhel7
%endif
# Define milestone (EA for pre-releases, GA for releases)
# Release will be (where N is usually a number starting at 1):
# - 0.N.ea<dist> for EA releases,
# - N<dist> for GA releases
%global is_ga 1
%if %{is_ga}
%global build_type GA
%global ea_designator ""
%global ea_designator_zip %{nil}
%global extraver %{nil}
%global eaprefix %{nil}
%else
%global build_type EA
%global ea_designator ea
%global ea_designator_zip -%{ea_designator}
%global extraver .%{ea_designator}
%global eaprefix 0.
%endif
%global compatiblename java-%{javaver}-%{origin}
Name: %{compatiblename}-portable%{?pkgos:-%{pkgos}}
Version: %{newjavaver}.%{buildver}
Release: %{?eaprefix}%{portablerelease}.%{rpmrelease}%{?extraver}%{?dist}
%global fullversion %{compatiblename}-%{version}-%{release}
# java-1.5.0-ibm from jpackage.org set Epoch to 1 for unknown reasons
# and this change was brought into RHEL-4. java-1.5.0-ibm packages
# also included the epoch in their virtual provides. This created a
# situation where in-the-wild java-1.5.0-ibm packages provided "java =
# 1:1.5.0". In RPM terms, "1.6.0 < 1:1.5.0" since 1.6.0 is
# interpreted as 0:1.6.0. So the "java >= 1.6.0" requirement would be
# satisfied by the 1:1.5.0 packages. Thus we need to set the epoch in
# JDK package >= 1.6.0 to 1, and packages referring to JDK virtual
# provides >= 1.6.0 must specify the epoch, "java >= 1:1.6.0".
Epoch: 1
Summary: %{origin_nice} %{featurever} Runtime Environment portable edition
# Groups are only used up to RHEL 8 and on Fedora versions prior to F30
%if (0%{?rhel} > 0 && 0%{?rhel} <= 8) || (0%{?fedora} >= 0 && 0%{?fedora} < 30)
Group: Development/Languages
%endif
# HotSpot code is licensed under GPLv2
# JDK library code is licensed under GPLv2 with the Classpath exception
# The Apache license is used in code taken from Apache projects (primarily xalan & xerces)
# DOM levels 2 & 3 and the XML digital signature schemas are licensed under the W3C Software License
# The JSR166 concurrency code is in the public domain
# The BSD and MIT licenses are used for a number of third-party libraries (see ADDITIONAL_LICENSE_INFO)
# The OpenJDK source tree includes:
# - JPEG library (IJG), zlib & libpng (zlib), giflib (MIT), harfbuzz (ISC),
# - freetype (FTL), jline (BSD) and LCMS (MIT)
# - jquery (MIT), jdk.crypto.cryptoki PKCS 11 wrapper (RSA)
# - public_suffix_list.dat from publicsuffix.org (MPLv2.0)
# The test code includes copies of NSS under the Mozilla Public License v2.0
# The PCSClite headers are under a BSD with advertising license
# The elliptic curve cryptography (ECC) source code is licensed under the LGPLv2.1 or any later version
License: ASL 1.1 and ASL 2.0 and BSD and BSD with advertising and GPL+ and GPLv2 and GPLv2 with exceptions and IJG and LGPLv2+ and MIT and MPLv2.0 and Public Domain and W3C and zlib and ISC and FTL and RSA
URL: http://openjdk.java.net/
# We are producing RPMs containing only tarballs
# and checksums so there are no binaries outside
# the tarballs to be processed for debuginfo
%define debug_package %{nil}
# RPM conditionals so as to be able to dynamically produce
# slowdebug/release builds. See:
@ -96,25 +189,6 @@
%global normal_build %{nil}
%endif
# We have hardcoded list of files, which is appearing in alternatives, and in files
# in alternatives those are slaves and master, very often triplicated by man pages
# in files all masters and slaves are ghosted
# the ghosts are here to allow installation via query like `dnf install /usr/bin/java`
# you can list those files, with appropriate sections: cat *.spec | grep -e --install -e --slave -e post_
# TODO - fix those hardcoded lists via single list
# Those files must *NOT* be ghosted for *slowdebug* packages
# FIXME - if you are moving jshell or jlink or similar, always modify all three sections
# you can check via headless and devels:
# rpm -ql --noghost java-11-openjdk-headless-11.0.1.13-8.fc29.x86_64.rpm | grep bin
# == rpm -ql java-11-openjdk-headless-slowdebug-11.0.1.13-8.fc29.x86_64.rpm | grep bin
# != rpm -ql java-11-openjdk-headless-11.0.1.13-8.fc29.x86_64.rpm | grep bin
# similarly for other %%{_jvmdir}/{jre,java} and %%{_javadocdir}/{java,java-zip}
%define is_release_build() %( if [ "%{?1}" == "%{debug_suffix_unquoted}" -o "%{?1}" == "%{fastdebug_suffix_unquoted}" ]; then echo "0" ; else echo "1"; fi )
# while JDK is a techpreview(is_system_jdk=0), some provides are turned off. Once jdk stops to be an techpreview, move it to 1
# as sytem JDK, we mean any JDK which can run whole system java stack without issues (like bytecode issues, module issues, dependencies...)
%global is_system_jdk 0
%global aarch64 aarch64 arm64 armv8
# we need to distinguish between big and little endian PPC64
%global ppc64le ppc64le
@ -326,17 +400,14 @@
%global with_systemtap 0
%endif
# New Version-String scheme-style defines
%global featurever 21
%global interimver 0
%global updatever 11
%global patchver 0
# buildjdkver is usually same as %%{featurever},
# but in time of bootstrap of next jdk, it is featurever-1,
# buildjdkver is usually same as featurever,
# but at the time of bootstrap of the next jdk, it is featurever-1,
# and this it is better to change it here, on single place
%global buildjdkver %{featurever}
# We don't add any LTS designator for STS packages (Fedora and EPEL).
# We need to explicitly exclude EPEL as it would have the %%{rhel} macro defined.
# We need to explicitly exclude EPEL as it has the rhel macro defined.
%if 0%{?rhel} && !0%{?epel}
%global lts_designator "LTS"
%global lts_designator_zip -%{lts_designator}
@ -358,7 +429,8 @@
# Define vendor information used by OpenJDK
%global oj_vendor Red Hat, Inc.
%global oj_vendor_url https://www.redhat.com/
# Define what url should JVM offer in case of a crash report
# Define what url the JVM should offer in case of a crash report
# order may be important, epel may have rhel declared
%if 0%{?epel}
%global oj_vendor_bug_url https://bugzilla.redhat.com/enter_bug.cgi?product=Fedora%20EPEL&component=%{name}&version=epel%{epel}
@ -374,67 +446,13 @@
%endif
%endif
%endif
%global oj_vendor_version (Red_Hat-%{version}-%{rpmrelease})
%global oj_vendor_version (Red_Hat-%{version}-%{portablerelease})
# Define IcedTea version used for SystemTap tapsets and desktop file
%global icedteaver 6.0.0pre00-c848b93a8598
# Define current Git revision for the FIPS support patches
%global fipsver feef2dc3ca7
# Define JDK versions
%global newjavaver %{featurever}.%{interimver}.%{updatever}.%{patchver}
%global javaver %{featurever}
# Strip up to 6 trailing zeros in newjavaver, as the JDK does, to get the correct version used in filenames
%global filever %(svn=%{newjavaver}; for i in 1 2 3 4 5 6 ; do svn=${svn%%.0} ; done; echo ${svn})
# The tag used to create the OpenJDK tarball
%global vcstag jdk-%{filever}+%{buildver}%{?tagsuffix:-%{tagsuffix}}
# Standard JPackage naming and versioning defines
%global origin openjdk
%global origin_nice OpenJDK
%global top_level_dir_name %{vcstag}
%global top_level_dir_name_backup %{top_level_dir_name}-backup
%global buildver 10
%global rpmrelease 1
#%%global tagsuffix %%{nil}
# Priority must be 8 digits in total; up to openjdk 1.8, we were using 18..... so when we moved to 11, we had to add another digit
%if %is_system_jdk
# Using 10 digits may overflow the int used for priority, so we combine the patch and build versions
# It is very unlikely we will ever have a patch version > 4 or a build version > 20, so we combine as (patch * 20) + build.
# This means 11.0.9.0+11 would have had a priority of 11000911 as before
# A 11.0.9.1+1 would have had a priority of 11000921 (20 * 1 + 1), thus ensuring it is bigger than 11.0.9.0+11
%global combiver $( expr 20 '*' %{patchver} + %{buildver} )
%global priority %( printf '%02d%02d%02d%02d' %{featurever} %{interimver} %{updatever} %{combiver} )
%else
# for techpreview, using 1, so slowdebugs can have 0
%global priority %( printf '%08d' 1 )
%endif
# Define milestone (EA for pre-releases, GA for releases)
# Release will be (where N is usually a number starting at 1):
# - 0.N%%{?extraver}%%{?dist} for EA releases,
# - N%%{?extraver}{?dist} for GA releases
%global is_ga 1
%if %{is_ga}
%global build_type GA
%global ea_designator ""
%global ea_designator_zip %{nil}
%global extraver %{nil}
%global eaprefix %{nil}
%else
%global build_type EA
%global ea_designator ea
%global ea_designator_zip -%{ea_designator}
%global extraver .%{ea_designator}
%global eaprefix 0.
%endif
# parametrized macros are order-sensitive
%global compatiblename java-%{featurever}-%{origin}
%global fullversion %{compatiblename}-%{version}-%{release}
# images directories from upstream build
%global jdkimage jdk
%global static_libs_image static-libs
# output dir stub
# Parameterised macros are order-sensitive
%define buildoutputdir() %{expand:build/jdk%{featurever}.build%{?1}}
%define installoutputdir() %{expand:install/jdk%{featurever}.install%{?1}}
%global altjavaoutputdir install/altjava.install
@ -445,41 +463,30 @@
%define uniquesuffix() %{expand:%{fullversion}.%{_arch}%{?1}}
# portable only declarations
%global jreimage jre
%define jreportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable%{1}.jre;g")
%define jdkportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable%{1}.jdk;g")
%define staticlibsportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable%{1}.static-libs;g")
%define jreportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable%{1}.jre;g")
%define jdkportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable%{1}.jdk;g")
%define staticlibsportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable%{1}.static-libs;g")
# RPM 4.19 no longer accept our double percentaged %%{nil} passed to %%{1}
# so we have to pass in "" but evaluate it, otherwise files will include it
%define jreportablearchive() %{expand:%{jreportablenameimpl -- %%{1}}.tar.xz}
%define jreportablearchive_for_files() %(echo %{jreportablearchive -- ""})
%define jdkportablearchive() %{expand:%{jdkportablenameimpl -- %%{1}}.tar.xz}
%define jdkportablearchive_for_files() %(echo %{jdkportablearchive -- ""})
%define staticlibsportablearchive() %{expand:%{staticlibsportablenameimpl -- %%{1}}.tar.xz}
%define staticlibsportablearchive_for_files() %(echo %{staticlibsportablearchive -- ""})
%define jreportablename() %{expand:%{jreportablenameimpl -- %%{1}}}
%define jdkportablename() %{expand:%{jdkportablenameimpl -- %%{1}}}
# Intentionally use jdkportablenameimpl here since we want to have static-libs files overlayed on
# top of the JDK archive
# We intentionally use jdkportablenameimpl here since we want to have
# static-libs files overlayed on top of the JDK archive
%define staticlibsportablename() %{expand:%{jdkportablenameimpl -- %%{1}}}
%define docportablename() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable.docs;g")
%define docportablearchive() %{docportablename}.tar.xz
%define miscportablename() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable.misc;g")
%define miscportablearchive() %{miscportablename}.tar.xz
#################################################################
# fix for https://bugzilla.redhat.com/show_bug.cgi?id=1111349
# https://bugzilla.redhat.com/show_bug.cgi?id=1590796#c14
# https://bugzilla.redhat.com/show_bug.cgi?id=1655938
%global _privatelibs libsplashscreen[.]so.*|libawt_xawt[.]so.*|libjli[.]so.*|libattach[.]so.*|libawt[.]so.*|libextnet[.]so.*|libawt_headless[.]so.*|libdt_socket[.]so.*|libfontmanager[.]so.*|libinstrument[.]so.*|libj2gss[.]so.*|libj2pcsc[.]so.*|libj2pkcs11[.]so.*|libjaas[.]so.*|libjavajpeg[.]so.*|libjdwp[.]so.*|libjimage[.]so.*|libjsound[.]so.*|liblcms[.]so.*|libmanagement[.]so.*|libmanagement_agent[.]so.*|libmanagement_ext[.]so.*|libmlib_image[.]so.*|libnet[.]so.*|libnio[.]so.*|libprefs[.]so.*|librmi[.]so.*|libsaproc[.]so.*|libsctp[.]so.*|libsystemconf[.]so.*|libzip[.]so.*%{freetype_lib}
%global _publiclibs libjawt[.]so.*|libjava[.]so.*|libjvm[.]so.*|libverify[.]so.*|libjsig[.]so.*
%if %is_system_jdk
%global __provides_exclude ^(%{_privatelibs})$
%global __requires_exclude ^(%{_privatelibs})$
# Never generate lib-style provides/requires for slowdebug packages
%global __provides_exclude_from ^.*/%{uniquesuffix -- %{debug_suffix_unquoted}}/.*$
%global __requires_exclude_from ^.*/%{uniquesuffix -- %{debug_suffix_unquoted}}/.*$
%global __provides_exclude_from ^.*/%{uniquesuffix -- %{fastdebug_suffix_unquoted}}/.*$
%global __requires_exclude_from ^.*/%{uniquesuffix -- %{fastdebug_suffix_unquoted}}/.*$
%else
# Don't generate provides/requires for JDK provided shared libraries at all.
%global __provides_exclude ^(%{_privatelibs}|%{_publiclibs})$
%global __requires_exclude ^(%{_privatelibs}|%{_publiclibs})$
%endif
# These macros are not parameterised as the same is shared by all builds
%define docportablename() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable.docs;g")
%define docportablearchive() %{docportablename}.tar.xz
%define miscportablename() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable.misc;g")
%define miscportablearchive() %{miscportablename}.tar.xz
# VM variant being built
%ifarch %{zero_arches}
@ -488,28 +495,11 @@
%global vm_variant server
%endif
%global etcjavasubdir %{_sysconfdir}/java/java-%{javaver}-%{origin}
%define etcjavadir() %{expand:%{etcjavasubdir}/%{uniquesuffix -- %{?1}}}
# Standard JPackage directories and symbolic links.
%define sdkdir() %{expand:%{uniquesuffix -- %{?1}}}
%define jrelnk() %{expand:jre-%{javaver}-%{origin}-%{version}-%{release}.%{_arch}%{?1}}
%define sdkbindir() %{expand:%{_jvmdir}/%{sdkdir -- %{?1}}/bin}
%define jrebindir() %{expand:%{_jvmdir}/%{sdkdir -- %{?1}}/bin}
%global alt_java_name alt-java
%global devkit_name %{origin}-devkit
%global rpm_state_dir %{_localstatedir}/lib/rpm-state/
# For flatpack builds hard-code /usr/sbin/alternatives,
# otherwise use %%{_sbindir} relative path.
%if 0%{?flatpak}
%global alternatives_requires /usr/sbin/alternatives
%else
%global alternatives_requires %{_sbindir}/alternatives
%endif
# Portables have no repo (requires/provides), but these are awesome for orientation in spec
# Also scriptlets are happily missing and files are handled old fashion
# not-duplicated requires/provides/obsoletes for normal/debug packages
@ -534,11 +524,6 @@
# Prevent brp-java-repack-jars from being run
%global __jar_repack 0
# Define an optional suffix for the OS this package is built on
%if 0%{?rhel} == 7
%global pkgos rhel7
%endif
# Define the architectures on which we build
# On RHEL, this should be the architectures with a devkit
%if 0%{?centos} == 0
@ -547,43 +532,6 @@ ExclusiveArch: %{devkit_arches}
ExclusiveArch: %{aarch64} %{ppc64le} riscv64 s390x x86_64
%endif
Name: java-%{javaver}-%{origin}-portable%{?pkgos:-%{pkgos}}
Version: %{newjavaver}.%{buildver}
Release: %{?eaprefix}%{rpmrelease}%{?extraver}%{?dist}
# java-1.5.0-ibm from jpackage.org set Epoch to 1 for unknown reasons
# and this change was brought into RHEL-4. java-1.5.0-ibm packages
# also included the epoch in their virtual provides. This created a
# situation where in-the-wild java-1.5.0-ibm packages provided "java =
# 1:1.5.0". In RPM terms, "1.6.0 < 1:1.5.0" since 1.6.0 is
# interpreted as 0:1.6.0. So the "java >= 1.6.0" requirement would be
# satisfied by the 1:1.5.0 packages. Thus we need to set the epoch in
# JDK package >= 1.6.0 to 1, and packages referring to JDK virtual
# provides >= 1.6.0 must specify the epoch, "java >= 1:1.6.0".
Epoch: 1
Summary: %{origin_nice} %{featurever} Runtime Environment portable edition
# Groups are only used up to RHEL 8 and on Fedora versions prior to F30
%if (0%{?rhel} > 0 && 0%{?rhel} <= 8) || (0%{?fedora} >= 0 && 0%{?fedora} < 30)
Group: Development/Languages
%endif
# HotSpot code is licensed under GPLv2
# JDK library code is licensed under GPLv2 with the Classpath exception
# The Apache license is used in code taken from Apache projects (primarily xalan & xerces)
# DOM levels 2 & 3 and the XML digital signature schemas are licensed under the W3C Software License
# The JSR166 concurrency code is in the public domain
# The BSD and MIT licenses are used for a number of third-party libraries (see ADDITIONAL_LICENSE_INFO)
# The OpenJDK source tree includes:
# - JPEG library (IJG), zlib & libpng (zlib), giflib (MIT), harfbuzz (ISC),
# - freetype (FTL), jline (BSD) and LCMS (MIT)
# - jquery (MIT), jdk.crypto.cryptoki PKCS 11 wrapper (RSA)
# - public_suffix_list.dat from publicsuffix.org (MPLv2.0)
# The test code includes copies of NSS under the Mozilla Public License v2.0
# The PCSClite headers are under a BSD with advertising license
# The elliptic curve cryptography (ECC) source code is licensed under the LGPLv2.1 or any later version
License: ASL 1.1 and ASL 2.0 and BSD and BSD with advertising and GPL+ and GPLv2 and GPLv2 with exceptions and IJG and LGPLv2+ and MIT and MPLv2.0 and Public Domain and W3C and zlib and ISC and FTL and RSA
URL: http://openjdk.java.net/
# The source tarball, generated using generate_source_tarball.sh
Source0: https://openjdk-sources.osci.io/openjdk%{featurever}/open%{vcstag}%{ea_designator_zip}.tar.xz
@ -626,9 +574,11 @@ Source18: TestTranslations.java
#
############################################
# Crypto policy and FIPS support patches
# Patch is generated from the fips-21u tree at https://github.com/rh-openjdk/jdk/tree/fips-21u
# as follows: git diff %%{vcstag} src make test > fips-21u-$(git show -s --format=%h HEAD).patch
# as follows: git diff <vcstag> src make test > fips-21u-$(git show -s --format=%h HEAD).patch
# Diff is limited to src and make subdirectories to exclude .github changes
# Fixes currently included:
# PR3183, RH1340845: Follow system wide crypto policy
# PR3695: Allow use of system crypto policy to be disabled by the user
@ -762,17 +712,17 @@ BuildRequires: libpng-devel
BuildRequires: zlib-devel
%else
# Version in src/java.desktop/share/native/libfreetype/include/freetype/freetype.h
Provides: bundled(freetype) = 2.14.2
Provides: bundled(freetype) = 2.14.3
# Version in src/java.desktop/share/native/libsplashscreen/giflib/gif_lib.h
Provides: bundled(giflib) = 6.1.2
Provides: bundled(giflib) = 6.1.3
# Version in src/java.desktop/share/native/libharfbuzz/hb-version.h
Provides: bundled(harfbuzz) = 12.3.2
Provides: bundled(harfbuzz) = 14.2.0
# Version in src/java.desktop/share/native/liblcms/lcms2.h
Provides: bundled(lcms2) = 2.17.0
Provides: bundled(lcms2) = 2.19.1
# Version in src/java.desktop/share/native/libjavajpeg/jpeglib.h
Provides: bundled(libjpeg) = 6b
# Version in src/java.desktop/share/native/libsplashscreen/libpng/png.h
Provides: bundled(libpng) = 1.6.57
Provides: bundled(libpng) = 1.6.58
# Version in src/java.base/share/native/libzip/zlib/zlib.h
Provides: bundled(zlib) = 1.3.2
# We link statically against libstdc++ to increase portability
@ -962,11 +912,6 @@ echo "Build JDK version is %{buildjdkver}, feature JDK version is %{featurever}"
export XZ_OPT="-T0"
%setup -q -c -n %{uniquesuffix ""} -T -a 0
# https://bugzilla.redhat.com/show_bug.cgi?id=1189084
prioritylength=`expr length %{priority}`
if [ $prioritylength -ne 8 ] ; then
echo "priority must be 8 digits in total, violated"
exit 14
fi
# OpenJDK patches
@ -976,19 +921,7 @@ sh %{SOURCE12} %{top_level_dir_name}
%endif
# Patch the JDK
# This syntax is deprecated:
# %patchN [...]
# and should be replaced with:
# %patch -PN [...]
# For example:
# %patch1001 -p1
# becomes:
# %patch -P1001 -p1
# The replacement format suggested by recent (circa Fedora 38) RPM
# deprecation messages:
# %patch N [...]
# is not backward-compatible with prior (circa RHEL-8) versions of
# rpmbuild.
pushd %{top_level_dir_name}
# Add crypto policy and FIPS support
%patch -P1001 -p1
@ -1069,7 +1002,6 @@ done
export NUM_PROC=%(/usr/bin/getconf _NPROCESSORS_ONLN 2> /dev/null || :)
export NUM_PROC=${NUM_PROC:-1}
%if 0%{?_smp_ncpus_max}
# Honor %%_smp_ncpus_max
[ ${NUM_PROC} -gt %{?_smp_ncpus_max} ] && export NUM_PROC=%{?_smp_ncpus_max}
%endif
export XZ_OPT="-T0"
@ -1186,8 +1118,8 @@ function buildjdk() {
mkdir -p ${outputdir}
pushd ${outputdir}
# Note: zlib and freetype use %{link_type}
# rather than ${link_opt} as the system versions
# Note: zlib and freetype use link_type (macro)
# rather than link_opt (shell var) as the system versions
# are always used in a system_libs build, even
# for the static library build
LD_LIBRARY_PATH=${LIBPATH} \
@ -1881,8 +1813,8 @@ done
%files
# main package builds always
%{_jvmdir}/%{jreportablearchive -- %%{nil}}
%{_jvmdir}/%{jreportablearchive -- %%{nil}}.sha256sum
%{_jvmdir}/%{jreportablearchive_for_files}
%{_jvmdir}/%{jreportablearchive_for_files}.sha256sum
%else
%files
# placeholder
@ -1891,15 +1823,15 @@ done
%if %{include_normal_build}
%files devel
%{_jvmdir}/%{jdkportablearchive -- %%{nil}}
%{_jvmdir}/%{jdkportablearchive_for_files}
%{_jvmdir}/%{jdkportablearchive -- .debuginfo}
%{_jvmdir}/%{jdkportablearchive -- %%{nil}}.sha256sum
%{_jvmdir}/%{jdkportablearchive_for_files}.sha256sum
%{_jvmdir}/%{jdkportablearchive -- .debuginfo}.sha256sum
%if %{include_staticlibs}
%files static-libs
%{_jvmdir}/%{staticlibsportablearchive -- %%{nil}}
%{_jvmdir}/%{staticlibsportablearchive -- %%{nil}}.sha256sum
%{_jvmdir}/%{staticlibsportablearchive_for_files}
%{_jvmdir}/%{staticlibsportablearchive_for_files}.sha256sum
%endif
%files unstripped
@ -1953,6 +1885,39 @@ done
%endif
%changelog
* Wed Jul 15 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:21.0.12.0.8-1.0
- Update to jdk-21.0.12+8 (GA)
- Update release notes to 21.0.12+8
- Bump freetype version to 2.14.3 following JDK-8385390
- Bump giflib version to 6.1.3 following JDK-8384902
- Bump HarfBuzz version to 14.2.0 following JDK-8385490
- Bump lcms2 version to 2.19.1 following JDK-8375065 & JDK-8383354
- Bump libpng version to 1.6.58 following JDK-8384495
- ** This tarball is embargoed until 2026-07-21 @ 1pm PT. **
- Resolves: OPENJDK-4865
* Wed Jul 15 2026 Andrea Bolognani <abologna@redhat.com> - 1:21.0.11.0.10-2.0
- Strip %%{dist} more thoroughly
- Resolves: OPENJDK-4891
* Fri Jun 26 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:21.0.11.0.10-2.0
- Port ForFiles patch to RHEL and update to use standard function naming format
- Remove macro references in comments where possible (%dnl not compatible enough yet)
- Drop unused tagsuffix line which causes issues on older RPM versions without %dnl
- Cleanup RPM only macros unused in the portable spec file
- Move version information and core NVR definitions back towards the top of the file
- Specify portablerelease and rpmrelease (always 0 for portables) in the Release field
- Related: OPENJDK-4887
- Resolves: OPENJDK-4888
- Resolves: OPENJDK-4889
- Resolves: OPENJDK-4890
* Fri Jun 26 2026 Jiri Vanek <jvanek@redhat.com> - 1:25.0.3.0.9-2.0
- Redeclared ForFiles release sections as %%nil no longer works with %%1
- RPM 4.19 no longer accept our double percentaged %%{nil} passed to %%{1}
- so we have to pass in "" but evaluate it, otherwise files record will include it
- Resolves: OPENJDK-4887
* Sat Apr 18 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:21.0.11.0.10-1
- Update to jdk-21.0.11+10 (GA)
- Update release notes to 21.0.11+10

View File

@ -3,6 +3,113 @@
# it and then adjust portablerelease and portablesuffix
# to match the new portable.
# New Version-String scheme-style defines
%global featurever 21
%global interimver 0
%global updatever 12
%global patchver 0
%global buildver 8
%global portablerelease 1
%global rpmrelease 2
# Define IcedTea version used for SystemTap tapsets and desktop file
%global icedteaver 6.0.0pre00-c848b93a8598
# Define current Git revision for the FIPS support patches
%global fipsver feef2dc3ca7
# Define JDK versions
%global newjavaver %{featurever}.%{interimver}.%{updatever}.%{patchver}
%global javaver %{featurever}
# Strip up to 6 trailing zeros in newjavaver, as the JDK does, to get the correct version used in filenames
%global filever %(svn=%{newjavaver}; for i in 1 2 3 4 5 6 ; do svn=${svn%%.0} ; done; echo ${svn})
# The tag used to create the OpenJDK tarball
%global vcstag jdk-%{filever}+%{buildver}%{?tagsuffix:-%{tagsuffix}}
# Standard JPackage naming and versioning defines
%global origin openjdk
%global origin_nice OpenJDK
%global top_level_dir_name %{vcstag}
%global top_level_dir_name_backup %{top_level_dir_name}-backup
# Define milestone (EA for pre-releases, GA for releases)
# Release will be (where N is usually a number starting at 1):
# - 0.N.ea<dist> for EA releases,
# - N<dist> for GA releases
%global is_ga 1
%if %{is_ga}
%global build_type GA
%global ea_designator ""
%global ea_designator_zip %{nil}
%global extraver %{nil}
%global eaprefix %{nil}
%else
%global build_type EA
%global ea_designator ea
%global ea_designator_zip -%{ea_designator}
%global extraver .%{ea_designator}
%global eaprefix 0.
%endif
%global compatiblename java-%{javaver}-%{origin}
Name: %{compatiblename}
Version: %{newjavaver}.%{buildver}
Release: %{?eaprefix}%{portablerelease}.%{rpmrelease}%{?extraver}%{?dist}
%global fullversion %{compatiblename}-%{version}-%{release}
# java-1.5.0-ibm from jpackage.org set Epoch to 1 for unknown reasons
# and this change was brought into RHEL-4. java-1.5.0-ibm packages
# also included the epoch in their virtual provides. This created a
# situation where in-the-wild java-1.5.0-ibm packages provided "java =
# 1:1.5.0". In RPM terms, "1.6.0 < 1:1.5.0" since 1.6.0 is
# interpreted as 0:1.6.0. So the "java >= 1.6.0" requirement would be
# satisfied by the 1:1.5.0 packages. Thus we need to set the epoch in
# JDK package >= 1.6.0 to 1, and packages referring to JDK virtual
# provides >= 1.6.0 must specify the epoch, "java >= 1:1.6.0".
Epoch: 1
Summary: %{origin_nice} %{featurever} Runtime Environment
# Groups are only used up to RHEL 8 and on Fedora versions prior to F30
%if (0%{?rhel} > 0 && 0%{?rhel} <= 8) || (0%{?fedora} >= 0 && 0%{?fedora} < 30)
Group: Development/Languages
%endif
# HotSpot code is licensed under GPLv2
# JDK library code is licensed under GPLv2 with the Classpath exception
# The Apache license is used in code taken from Apache projects (primarily xalan & xerces)
# DOM levels 2 & 3 and the XML digital signature schemas are licensed under the W3C Software License
# The JSR166 concurrency code is in the public domain
# The BSD and MIT licenses are used for a number of third-party libraries (see ADDITIONAL_LICENSE_INFO)
# The OpenJDK source tree includes:
# - JPEG library (IJG), zlib & libpng (zlib), giflib (MIT), harfbuzz (ISC),
# - freetype (FTL), jline (BSD) and LCMS (MIT)
# - jquery (MIT), jdk.crypto.cryptoki PKCS 11 wrapper (RSA)
# - public_suffix_list.dat from publicsuffix.org (MPLv2.0)
# The test code includes copies of NSS under the Mozilla Public License v2.0
# The PCSClite headers are under a BSD with advertising license
# The elliptic curve cryptography (ECC) source code is licensed under the LGPLv2.1 or any later version
License: ASL 1.1 and ASL 2.0 and BSD and BSD with advertising and GPL+ and GPLv2 and GPLv2 with exceptions and IJG and LGPLv2+ and MIT and MPLv2.0 and Public Domain and W3C and zlib and ISC and FTL and RSA
URL: http://openjdk.java.net/
# Define the OS the portable JDK is built on
# This is undefined for CentOS & openjdk-portable-rhel-8 builds and
# equals 'rhel7' for openjdk-portable-rhel-7 builds
%if 0
%global pkgos rhel7
%endif
# Define the root name of the portable packages
%global pkgnameroot java-%{featurever}-%{origin}-portable%{?pkgos:-%{pkgos}}
# Release field for the portable build
# The rpmrelease field is always zero for portables
%global prelease %{?eaprefix}%{portablerelease}.0%{?extraver}
# Portable suffix differs between RHEL and CentOS
%if 0%{?centos} == 0
%global portablerhel %{?pkgos:7_9}%{!?pkgos:8}
%else
%global portablerhel 9
%endif
%global portablebuilddir /builddir/build/BUILD
%global portablesuffix el%{portablerhel}
# RPM conditionals so as to be able to dynamically produce
# slowdebug/release builds. See:
# http://rpm.org/user_doc/conditional_builds.html
@ -87,19 +194,20 @@
%global normal_build %{nil}
%endif
# We have hardcoded list of files, which is appearing in alternatives, and in files
# in alternatives those are slaves and master, very often triplicated by man pages
# in files all masters and slaves are ghosted
# the ghosts are here to allow installation via query like `dnf install /usr/bin/java`
# you can list those files, with appropriate sections: cat *.spec | grep -e --install -e --slave -e post_ -e alternatives
# We have a hardcoded list of files, which appears in alternatives and in files
# In alternatives, those are slaves and master, very often triplicated by man pages
# In files, all masters and slaves are ghosted
# The ghosts are here to allow installation via query like `dnf install /usr/bin/java`
# You can list those files, with appropriate sections: cat *.spec | grep -e --install -e --slave -e post_ -e alternatives
# TODO - fix those hardcoded lists via single list
# Those files must *NOT* be ghosted for *slowdebug* packages
# Those files must *NOT* be ghosted for *debug* packages
# FIXME - if you are moving jshell or jlink or similar, always modify all three sections
# you can check via headless and devels:
# You can check via headless and devels:
# rpm -ql --noghost java-11-openjdk-headless-11.0.1.13-8.fc29.x86_64.rpm | grep bin
# == rpm -ql java-11-openjdk-headless-slowdebug-11.0.1.13-8.fc29.x86_64.rpm | grep bin
# != rpm -ql java-11-openjdk-headless-11.0.1.13-8.fc29.x86_64.rpm | grep bin
# similarly for other %%{_jvmdir}/{jre,java} and %%{_javadocdir}/{java,java-zip}
# and similarly for other packages.
%define is_release_build() %( if [ "%{?1}" == "%{debug_suffix_unquoted}" -o "%{?1}" == "%{fastdebug_suffix_unquoted}" ]; then echo "0" ; else echo "1"; fi )
# Indicates whether this is the default JDK on this version of RHEL
@ -309,13 +417,8 @@
%global with_systemtap 0
%endif
# New Version-String scheme-style defines
%global featurever 21
%global interimver 0
%global updatever 11
%global patchver 0
# We don't add any LTS designator for STS packages (Fedora and EPEL).
# We need to explicitly exclude EPEL as it would have the %%{rhel} macro defined.
# We need to explicitly exclude EPEL as it has the rhel macro defined.
%if 0%{?rhel} && !0%{?epel}
%global lts_designator "LTS"
%global lts_designator_zip -%{lts_designator}
@ -327,7 +430,8 @@
# Define vendor information used by OpenJDK
%global oj_vendor Red Hat, Inc.
%global oj_vendor_url https://www.redhat.com/
# Define what url should JVM offer in case of a crash report
# Define what url the JVM should offer in case of a crash report
# order may be important, epel may have rhel declared
%if 0%{?epel}
%global oj_vendor_bug_url https://bugzilla.redhat.com/enter_bug.cgi?product=Fedora%20EPEL&component=%{name}&version=epel%{epel}
@ -345,42 +449,6 @@
%endif
%global oj_vendor_version (Red_Hat-%{version}-%{portablerelease})
# Define IcedTea version used for SystemTap tapsets and desktop file
%global icedteaver 6.0.0pre00-c848b93a8598
# Define current Git revision for the FIPS support patches
%global fipsver feef2dc3ca7
# Define JDK versions
%global newjavaver %{featurever}.%{interimver}.%{updatever}.%{patchver}
%global javaver %{featurever}
# Strip up to 6 trailing zeros in newjavaver, as the JDK does, to get the correct version used in filenames
%global filever %(svn=%{newjavaver}; for i in 1 2 3 4 5 6 ; do svn=${svn%%.0} ; done; echo ${svn})
# The tag used to create the OpenJDK tarball
%global vcstag jdk-%{filever}+%{buildver}%{?tagsuffix:-%{tagsuffix}}
# Define the OS the portable JDK is built on
# This is undefined for CentOS & openjdk-portable-rhel-8 builds and
# equals 'rhel7' for openjdk-portable-rhel-7 builds
%if 0
%global pkgos rhel7
%endif
# Standard JPackage naming and versioning defines
%global origin openjdk
%global origin_nice OpenJDK
%global top_level_dir_name %{vcstag}
%global top_level_dir_name_backup %{top_level_dir_name}-backup
%global buildver 10
%global rpmrelease 2
# Settings used by the portable build
%global portablerelease 1
# Portable suffix differs between RHEL and CentOS
%if 0%{?centos} == 0
%global portablesuffix %{?pkgos:el7_9}%{!?pkgos:el8}
%else
%global portablesuffix el9
%endif
%global portablebuilddir /builddir/build/BUILD
# Priority must be 8 digits in total; up to openjdk 1.8, we were using 18..... so when we moved to 11, we had to add another digit
%if %is_system_jdk
# Using 10 digits may overflow the int used for priority, so we combine the patch and build versions
@ -394,28 +462,6 @@
%global priority %( printf '%08d' 1 )
%endif
# Define milestone (EA for pre-releases, GA for releases)
# Release will be (where N is usually a number starting at 1):
# - 0.N%%{?extraver}%%{?dist} for EA releases,
# - N%%{?extraver}{?dist} for GA releases
%global is_ga 1
%if %{is_ga}
%global build_type GA
%global ea_designator ""
%global ea_designator_zip %{nil}
%global extraver %{nil}
%global eaprefix %{nil}
%else
%global build_type EA
%global ea_designator ea
%global ea_designator_zip -%{ea_designator}
%global extraver .%{ea_designator}
%global eaprefix 0.
%endif
# parametrized macros are order-sensitive
%global compatiblename java-%{featurever}-%{origin}
%global fullversion %{compatiblename}-%{version}-%{release}
# images directories from upstream build
%global jdkimage jdk
%global static_libs_image static-libs
@ -465,7 +511,7 @@
%global rpm_state_dir %{_localstatedir}/lib/rpm-state/
# For flatpack builds hard-code /usr/sbin/alternatives,
# otherwise use %%{_sbindir} relative path.
# otherwise use _sbindir relative path.
%if 0%{?flatpak}
%global alternatives_requires /usr/sbin/alternatives
%else
@ -1176,51 +1222,10 @@ Provides: java-%{origin}-src%{?1} = %{epoch}:%{version}-%{release}
# Prevent brp-java-repack-jars from being run
%global __jar_repack 0
# Define the root name of the portable packages
%global pkgnameroot java-%{featurever}-%{origin}-portable%{?pkgos:-%{pkgos}}
# Define the architectures on which we build
ExclusiveArch: %{aarch64} %{ppc64le} s390x x86_64 riscv64
Name: java-%{javaver}-%{origin}
Version: %{newjavaver}.%{buildver}
Release: %{?eaprefix}%{rpmrelease}%{?extraver}%{?dist}
# Equivalent for the portable build
%global prelease %{?eaprefix}%{portablerelease}%{?extraver}
# java-1.5.0-ibm from jpackage.org set Epoch to 1 for unknown reasons
# and this change was brought into RHEL-4. java-1.5.0-ibm packages
# also included the epoch in their virtual provides. This created a
# situation where in-the-wild java-1.5.0-ibm packages provided "java =
# 1:1.5.0". In RPM terms, "1.6.0 < 1:1.5.0" since 1.6.0 is
# interpreted as 0:1.6.0. So the "java >= 1.6.0" requirement would be
# satisfied by the 1:1.5.0 packages. Thus we need to set the epoch in
# JDK package >= 1.6.0 to 1, and packages referring to JDK virtual
# provides >= 1.6.0 must specify the epoch, "java >= 1:1.6.0".
Epoch: 1
Summary: %{origin_nice} %{featurever} Runtime Environment
# Groups are only used up to RHEL 8 and on Fedora versions prior to F30
%if (0%{?rhel} > 0 && 0%{?rhel} <= 8) || (0%{?fedora} >= 0 && 0%{?fedora} < 30)
Group: Development/Languages
%endif
# HotSpot code is licensed under GPLv2
# JDK library code is licensed under GPLv2 with the Classpath exception
# The Apache license is used in code taken from Apache projects (primarily xalan & xerces)
# DOM levels 2 & 3 and the XML digital signature schemas are licensed under the W3C Software License
# The JSR166 concurrency code is in the public domain
# The BSD and MIT licenses are used for a number of third-party libraries (see ADDITIONAL_LICENSE_INFO)
# The OpenJDK source tree includes:
# - JPEG library (IJG), zlib & libpng (zlib), giflib (MIT), harfbuzz (ISC),
# - freetype (FTL), jline (BSD) and LCMS (MIT)
# - jquery (MIT), jdk.crypto.cryptoki PKCS 11 wrapper (RSA)
# - public_suffix_list.dat from publicsuffix.org (MPLv2.0)
# The test code includes copies of NSS under the Mozilla Public License v2.0
# The PCSClite headers are under a BSD with advertising license
# The elliptic curve cryptography (ECC) source code is licensed under the LGPLv2.1 or any later version
License: ASL 1.1 and ASL 2.0 and BSD and BSD with advertising and GPL+ and GPLv2 and GPLv2 with exceptions and IJG and LGPLv2+ and MIT and MPLv2.0 and Public Domain and W3C and zlib and ISC and FTL and RSA
URL: http://openjdk.java.net/
# The source tarball, generated using generate_source_tarball.sh
Source0: https://openjdk-sources.osci.io/openjdk%{featurever}/open%{vcstag}%{ea_designator_zip}.tar.xz
@ -1294,9 +1299,11 @@ Source30: 0008-Tools.gmk-Use-update-repository-on-RHEL-rather-than-.patch
############################################
# Crypto policy and FIPS support patches
# Patch is generated from the fips-21u tree at https://github.com/rh-openjdk/jdk/tree/fips-21u
# as follows: git diff %%{vcstag} src make test > fips-21u-$(git show -s --format=%h HEAD).patch
# as follows: git diff <vcstag> src make test > fips-21u-$(git show -s --format=%h HEAD).patch
# Diff is limited to src and make subdirectories to exclude .github changes
# Fixes currently included:
# PR3183, RH1340845: Follow system wide crypto policy
# PR3695: Allow use of system crypto policy to be disabled by the user
@ -1426,17 +1433,17 @@ BuildRequires: libpng-devel
BuildRequires: zlib-devel
%else
# Version in src/java.desktop/share/native/libfreetype/include/freetype/freetype.h
Provides: bundled(freetype) = 2.14.2
Provides: bundled(freetype) = 2.14.3
# Version in src/java.desktop/share/native/libsplashscreen/giflib/gif_lib.h
Provides: bundled(giflib) = 6.1.2
Provides: bundled(giflib) = 6.1.3
# Version in src/java.desktop/share/native/libharfbuzz/hb-version.h
Provides: bundled(harfbuzz) = 12.3.2
Provides: bundled(harfbuzz) = 14.2.0
# Version in src/java.desktop/share/native/liblcms/lcms2.h
Provides: bundled(lcms2) = 2.17.0
Provides: bundled(lcms2) = 2.19.1
# Version in src/java.desktop/share/native/libjavajpeg/jpeglib.h
Provides: bundled(libjpeg) = 6b
# Version in src/java.desktop/share/native/libsplashscreen/libpng/png.h
Provides: bundled(libpng) = 1.6.57
Provides: bundled(libpng) = 1.6.58
# Version in src/java.base/share/native/libzip/zlib/zlib.h
Provides: bundled(zlib) = 1.3.2
%endif
@ -1809,19 +1816,7 @@ sh %{SOURCE12} %{top_level_dir_name}
%endif
# Patch the JDK
# This syntax is deprecated:
# %patchN [...]
# and should be replaced with:
# %patch -PN [...]
# For example:
# %patch1001 -p1
# becomes:
# %patch -P1001 -p1
# The replacement format suggested by recent (circa Fedora 38) RPM
# deprecation messages:
# %patch N [...]
# is not backward-compatible with prior (circa RHEL-8) versions of
# rpmbuild.
pushd %{top_level_dir_name}
# Add crypto policy and FIPS support
%patch -P1001 -p1
@ -2475,6 +2470,58 @@ exit 0
%endif
%changelog
* Sat Jul 18 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:21.0.12.0.8-1.2
- Bump release for PQC build
- Related: RHEL-212302
- Related: RHEL-212303
- Related: RHEL-212304
- Related: RHEL-151191
- Related: RHEL-212305
- Related: RHEL-188872
- Related: RHEL-212306
- Related: RHEL-212307
- Related: RHEL-151162
* Sat Jul 18 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:21.0.12.0.8-1.1
- Update to jdk-21.0.12+8 (GA)
- Update release notes to 21.0.12+8
- Bump freetype version to 2.14.3 following JDK-8385390
- Bump giflib version to 6.1.3 following JDK-8384902
- Bump HarfBuzz version to 14.2.0 following JDK-8385490
- Bump lcms2 version to 2.19.1 following JDK-8375065 & JDK-8383354
- Bump libpng version to 1.6.58 following JDK-8384495
- Update tagging scripts to include signature checks and correctly handle gating
- Update tagged versions to include 9.8.0-z, 9.9.0, 10.2-z & 10.3.
- Add gating scripts to simplify obtaining results and waiving issues
- Cleanup tagging and gating scripts to appease shellcheck:
- * scripts/builds/build_vanilla.sh: Use an array to handle the varying arguments to rhpkg.
- * scripts/builds/check_signatures.sh: Quote variable usage.
- * scripts/builds/waive_issue.sh: Remove redundant 'test "x"' usage.
- * scripts/builds/waive_leapp_issue.sh: Likewise.
- * scripts/builds/waive_rpminspect.sh: Likewise.
- * scripts/builds/waive_usual_rpminspect.sh: Likewise and add missing WORKING_DIR variable.
- * scripts/builds/waive_usual_tier0.sh: Remove redundant 'test "x"' usage.
- Remove macro references in comments where possible (%dnl not compatible enough yet)
- Move version information and core NVR definitions back towards the top of the file
- Specify portablerelease and rpmrelease (always 0 for portables) in the Release field
- Obsolete old RHEL releases (9.7.0-z, 10.1-z)
- Make zone string debug output optional in TestTranslations
- Sync the copy of the portable specfile with the latest update
- ** This tarball is embargoed until 2026-07-21 @ 1pm PT. **
- Resolves: RHEL-212302
- Resolves: RHEL-212303
- Resolves: RHEL-212304
- Resolves: RHEL-151191
- Resolves: RHEL-212305
- Resolves: RHEL-188872
- Resolves: RHEL-212306
- Resolves: RHEL-212307
* Sat Jul 18 2026 Thomas Fitzsimmons <fitzsim@redhat.com> - 1:21.0.11.0.10-1.3
- Disable abidiff inspection in rpminspect.yaml to avoid an out-of-memory error on the CentOS test farm
- See: https://docs.testing-farm.io/Testing%20Farm/0.1/errors.html#TFE-1
- Resolves: RHEL-151162
* Mon Apr 20 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:21.0.11.0.10-2
- Bump release for PQC build
- Related: RHEL-169611

View File

@ -1,2 +1,2 @@
SHA512 (openjdk-21.0.11+10.tar.xz) = 65f20c20040a146d5c7477536d7f479d79459fc676b0ed2df2aa42704e9c12e455e748704ee1dac60ef97014cb91136265f8fd4ee10d4673368db99b18dec61f
SHA512 (openjdk-21.0.12+8.tar.xz) = 514c28f1819b12fb6f5a04c3ebc4358d8694135dc9566314dfe7368485e947f0f03e1835f069d0e989768537e953e4b3cd16f294289f6d4e2fbf74fffe9886d8
SHA512 (tapsets-icedtea-6.0.0pre00-c848b93a8598.tar.xz) = 97d026212363b3c83f6a04100ad7f6fdde833d16579717f8756e2b8c2eb70e144a41a330cb9ccde9c3badd37a2d54fdf4650a950ec21d8b686d545ecb2a64d30