From bc31185b2b91150589e62dfdf6bf5f9b9f0e68a1 Mon Sep 17 00:00:00 2001 From: AlmaLinux RelEng Bot Date: Wed, 22 Jul 2026 19:07:53 -0400 Subject: [PATCH] import UBI java-21-openjdk-21.0.12.0.8-1.2.el10_2 --- .gitignore | 2 +- NEWS | 339 +++++++++++++++++++++++++++ TestTranslations.java | 29 ++- java-21-openjdk-portable.specfile | 377 ++++++++++++++---------------- java-21-openjdk.spec | 315 ++++++++++++++----------- sources | 2 +- 6 files changed, 714 insertions(+), 350 deletions(-) diff --git a/.gitignore b/.gitignore index e054c39..3eda6a3 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,2 @@ -openjdk-21.0.11+10.tar.xz +openjdk-21.0.12+8.tar.xz tapsets-icedtea-6.0.0pre00-c848b93a8598.tar.xz diff --git a/NEWS b/NEWS index 61a67cd..d8616f5 100644 --- a/NEWS +++ b/NEWS @@ -3,6 +3,345 @@ Key: JDK-X - https://bugs.openjdk.java.net/browse/JDK-X CVE-XXXX-YYYY: https://cve.mitre.org/cgi-bin/cvename.cgi?name=XXXX-YYYY +New in release OpenJDK 21.0.12 (2026-07-21): +=========================================== +Live versions of these release notes can be found at: + * https://bit.ly/openjdk2112 + +* CVEs +* Changes + - JDK-7184899: Test sun/java2d/X11SurfaceData/SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fail + - JDK-8015444: java/awt/Focus/KeyStrokeTest.java sometimes fails + - JDK-8064922: [macos] Test javax/swing/JTabbedPane/4624207/bug4624207.java fails + - JDK-8068293: [TEST_BUG] Test closed/com/sun/java/swing/plaf/motif/InternalFrame/4150591/bug4150591.java fails with GTKLookAndFeel + - JDK-8068310: [TEST_BUG] Test javax/swing/JColorChooser/Test4234761.java fails with GTKL&F + - JDK-8068378: [TEST_BUG]The java/awt/Modal/PrintDialogsTest/PrintDialogsTest.java instruction need to update + - JDK-8129418: JShell: better highlighting of errors in imports on demand + - JDK-8144124: [macosx] The tabs can't be aligned when we pressing the key of 'R','B','L','C' or 'T'. + - JDK-8183336: Better cleanup for jdk/test/java/lang/module/customfs/ModulesInCustomFileSystem.java + - JDK-8203004: UnixMultiResolutionSplashTest.java fails on Ubuntu16.04 + - JDK-8212084: G1: Implement UseGCOverheadLimit + - JDK-8213530: Test java/awt/Modal/ToFront/DialogToFrontModeless1Test.java fails on Linux + - JDK-8221451: PIT: sun/java2d/X11SurfaceData/SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fails + - JDK-8225787: java/awt/Window/GetScreenLocation/GetScreenLocationTest.java fails on Ubuntu + - JDK-8255463: java/nio/channels/spi/SelectorProvider/inheritedChannel/InheritedChannelTest.java failed with ThreadTimeoutException + - JDK-8274082: Wrong test name in jtreg run tag for java/awt/print/PrinterJob/SwingUIText.java + - JDK-8277444: Data race between JvmtiClassFileReconstituter::copy_bytecodes and class linking + - JDK-8278102: containers/docker/TestJcmd.java failed with "RuntimeException: Could not find specified process" + - JDK-8286258: [Accessibility,macOS,VoiceOver] VoiceOver reads the spinner value wrong and sometime partially + - JDK-8286865: vmTestbase/vm/mlvm/meth/stress/jni/nativeAndMH/Test.java fails with Out of space in CodeCache + - JDK-8293484: AArch64: TestUseSHA512IntrinsicsOptionOnSupportedCPU.java fails on CPU with SHA512 feature support + - JDK-8297191: [macos] Printing a page range with starting page > 1 results in missing pages + - JDK-8298783: java/lang/ref/FinalizerHistogramTest.java failed with "RuntimeException: MyObject is not found in test output" + - JDK-8298823: [macos] java/awt/Mouse/EnterExitEvents/DragWindowTest.java continues to fail with "No MouseReleased event on label!" + - JDK-8299304: Test "java/awt/print/PrinterJob/PageDialogTest.java" fails on macOS 13 x64 because the Page Dialog blocks the Toolkit + - JDK-8310645: CancelledResponse.java does not use HTTP/2 when testing the HttpClient + - JDK-8311538: CDS InternSharedString test fails on huge pages host - cannot find shared string + - JDK-8315588: JShell does not accept underscore from JEP 443 even with --enable-preview + - JDK-8318365: Test runtime/cds/appcds/sharedStrings/InternSharedString.java fails after JDK-8311538 + - JDK-8318662: Refactor some jdk/java/net/httpclient/http2 tests to JUnit + - JDK-8319326: GC: Make TestParallelRefProc use createTestJavaProcessBuilder + - JDK-8319540: GC: Make TestSelectDefaultGC use createTestJavaProcessBuilder + - JDK-8320677: Printer tests use invalid '@run main/manual=yesno + - JDK-8321303: Intermittent open/test/jdk/java/awt/KeyboardFocusmanager/ConsumeNextMnemonicKeyTypedTest/ConsumeNextMnemonicKeyTypedTest.java failure on Linux + - JDK-8321687: Test vmTestbase/nsk/jvmti/scenarios/contention/TC03/tc03t002/TestDescription.java failed: JVMTI_ERROR_THREAD_NOT_ALIVE + - JDK-8322532: JShell : Unnamed variable issue + - JDK-8323089: networkaddress.cache.ttl is not a system property + - JDK-8323545: java/awt/GraphicsDevice/CheckDisplayModes.java fails with "exit code: 133" + - JDK-8323672: Suppress unwanted autoconf added flags in CC and CXX + - JDK-8323792: ThreadSnapshot::initialize can cause assert in Thread::check_for_dangling_thread_pointer (possibility of dangling Thread pointer) + - JDK-8326458: Menu mnemonics don't toggle in Windows LAF when F10 is pressed + - JDK-8328300: Convert PrintDialogsTest.java from Applet to main program + - JDK-8329273: C2 SuperWord: Some basic MemorySegment IR tests + - JDK-8330704: Clean up non-standard use of /** comments in some langtools tests + - JDK-8330806: test/hotspot/jtreg/compiler/c1/TestLargeMonitorOffset.java fails on ARM32 + - JDK-8332495: java/util/logging/LoggingDeadlock2.java fails with AssertionError: Some tests failed + - JDK-8333729: C2 SuperWord: remove some @requires usages in test/hotspot/jtreg/compiler/loopopts/superword + - JDK-8334928: Test sun/security/ssl/SSLSocketImpl/ReuseAddr.java failed: java.net.BindException: Address already in use + - JDK-8338103: Stabilize and open source a Swing OGL ButtonResizeTest + - JDK-8338554: Fix inconsistencies in javadoc/doclet/testLinkOption/TestRedirectLinks.java + - JDK-8338883: Show warning when CreateCoredumpOnCrash set, but core dump will not happen + - JDK-8339233: Test javax/swing/JButton/SwingButtonResizeTestWithOpenGL.java#id failed: Button renderings are different after window resize + - JDK-8339638: Update vmTestbase/nsk/jvmti/*Field*Watch tests to use virtual thread factory + - JDK-8339879: Open some dialog awt tests + - JDK-8339975: Open some dialog awt tests 2 + - JDK-8340140: Open some dialog awt tests 3 + - JDK-8340336: Open some checkbox awt tests + - JDK-8340494: Open some dialog awt tests 4 + - JDK-8340818: Add a new jtreg test root to test the generated documentation + - JDK-8340851: Open some TextArea awt tests + - JDK-8340987: Open some TextArea awt tests 1 + - JDK-8341055: Open some TextArea awt tests 2 + - JDK-8341292: Open some TextArea awt tests 3 + - JDK-8341376: Open some TextArea awt tests 4 + - JDK-8341427: JFR: Adjust object sampler span handling + - JDK-8341436: containers/docker/TestJcmdWithSideCar.java takes needlessly long to run + - JDK-8341833: incomplete snippet from loaded files from command line is ignored + - JDK-8342401: [TESTBUG] javax/swing/JSpinner/8223788/JSpinnerButtonFocusTest.java test fails in ubuntu 22.04 on SBR Hosts + - JDK-8342836: Automatically determine that a test in the docs test root is requested + - JDK-8344128: Regression: make help broken after JDK-8340818 + - JDK-8345618: javax/swing/text/Caret/8163124/CaretFloatingPointAPITest.java leaves Caret is not complete + - JDK-8346154: [XWayland] Some tests fail intermittently in the CI, but not locally + - JDK-8346683: Problem list automated tests that fail on macOS15 + - JDK-8347836: Disabled PopupMenu shows shortcuts on Mac + - JDK-8349084: Update vectors used in several PQC benchmarks + - JDK-8349192: jvmti/scenarios/contention/TC05/tc05t001 fails: ERROR: tc05t001.cpp, 281: (waitedThreadCpuTime - waitThreadCpuTime) < (EXPECTED_ACCURACY * 1000000) + - JDK-8349533: Refactor validator tests shell files to java + - JDK-8349699: XSL transform fails with certain UTF-8 characters on 1024 byte boundaries + - JDK-8349959: Test CR6740048.java passes unexpectedly missing CR6740048.xsd + - JDK-8350749: Upgrade JLine to 3.29.0 + - JDK-8350808: Small typos in JShell method SnippetEvent.toString() + - JDK-8352020: [CompileFramework] enable compilation for VectorAPI + - JDK-8352147: G1: TestEagerReclaimHumongousRegionsClearMarkBits test takes very long + - JDK-8352149: Test java/awt/Frame/MultiScreenTest.java fails: Window list is empty + - JDK-8352431: java/net/httpclient/EmptyAuthenticate.java uses "localhost" + - JDK-8352685: Opensource JInternalFrame tests - series2 + - JDK-8352733: Improve RotFontBoundsTest test + - JDK-8352877: Opensource Several Font related tests - Batch 1 + - JDK-8353124: java/lang/Thread/virtual/stress/Skynet.java#Z times out on macosx-x64-debug + - JDK-8353488: Open some JComboBox bugs 3 + - JDK-8353552: Opensource Several Font related tests - Batch 3 + - JDK-8354163: Open source Swing tests Batch 1 + - JDK-8354695: Open source several swing tests batch7 + - JDK-8354900: javax/swing/AbstractButton/bug4133768.java failing on macosx-aarch64 + - JDK-8354910: Output by java.io.IO or System.console() corrupted for some non-ASCII characters + - JDK-8355048: ProblemList TestGlyphVectorLayout.java on all platforms + - JDK-8355179: Reinstate javax/swing/JScrollBar/4865918/bug4865918.java headful and macos run + - JDK-8355332: Fix failing semi-manual test EDT issue + - JDK-8355371: NegativeArraySizeException in print methods in IO or System.console() in JShell + - JDK-8355443: [java.io] Use @requires tag instead of exiting based on File.separatorChar value + - JDK-8356695: java/lang/StringBuilder/HugeCapacity.java failing with OOME + - JDK-8356868: Not all cgroup parameters are made available + - JDK-8357062: Update Public Suffix List to 823beb1 + - JDK-8357082: Stabilize and add debug logs to CopyAreaOOB.java + - JDK-8357086: os::xxx functions returning memory size should return size_t + - JDK-8357280: (bf) Remove @requires tags from java/nio/Buffer/LimitDirectMemory[NegativeTest].java + - JDK-8357390: java/awt/Toolkit/ScreenInsetsTest/ScreenInsetsTest.java Test failing on Ubuntu 24.04 Vm Hosts used by Oracle's internal CI system + - JDK-8358058: sun/java2d/OpenGL/DrawImageBg.java Test fails intermittently + - JDK-8359364: java/net/URL/EarlyOrDelayedParsing test fails intermittently + - JDK-8359472: JVM crashes when attaching a dynamic agent before JVMTI_PHASE_LIVE + - JDK-8359978: Test javax/net/ssl/SSLSocket/Tls13PacketSize.java failed again with java.net.SocketException: An established connection was aborted by the software in your host machine + - JDK-8360160: ubuntu-22-04 machine is failing client tests + - JDK-8360395: sun/security/tools/keytool/i18n.java user country is current user location instead of the language + - JDK-8360562: sun/security/tools/keytool/i18n.java add an ability to add comment for failures + - JDK-8360702: runtime/Thread/AsyncExceptionTest.java timed out + - JDK-8360882: Tests throw SkippedException when they should fail + - JDK-8361106: [TEST] com/sun/net/httpserver/Test9.java fails with java.nio.file.FileSystemException + - JDK-8361606: ConsumeNextMnemonicKeyTypedTest.java fails on Windows: character typed with VK_A: a + - JDK-8361894: sun/security/krb5/config/native/TestDynamicStore.java ensure that the test is run with sudo + - JDK-8362428: Update IANA Language Subtag Registry to Version 2025-08-25 + - JDK-8363943: ARM32: Represent Registers as values + - JDK-8363949: Incorrect jtreg header in MonitorWithDeadObjectTest.java + - JDK-8364190: JFR: RemoteRecordingStream withers don't work + - JDK-8364315: Remove unused xml files from test/jaxp/javax/xml/jaxp/functional/javax/xml/transform/xmlfiles + - JDK-8364756: JFR: Improve slow tests + - JDK-8364927: Add @requires annotation to TestReclaimStringsLeaksMemory.java + - JDK-8365379: SU3.applyInsets may produce wrong results + - JDK-8365398: TEST_BUG: java/rmi/transport/checkLeaseInfoLeak/CheckLeaseLeak.java failing intermittently + - JDK-8365423: [macos26] java/awt/MenuBar/8007006/bug8007006.java fails on macOS 26 + - JDK-8365424: [macos26] java/awt/Frame/DisposeTest.java fails on macOS 26 + - JDK-8365623: test/jdk/sun/security/pkcs11/tls/ tests skipped without skip exception + - JDK-8365625: Can't change accelerator colors in Windows L&F + - JDK-8365776: Convert JShell tests to use JUnit instead of TestNG + - JDK-8365861: test/jdk/sun/security/pkcs11/Provider/ tests skipped without SkippedException + - JDK-8365863: /test/jdk/sun/security/pkcs11/Cipher tests skip without SkippedException + - JDK-8365893: test/jdk/java/lang/Thread/virtual/JfrEvents.java failing intermittently + - JDK-8366031: Mark com/sun/nio/sctp/SctpChannel/CloseDescriptors.java as intermittent + - JDK-8366182: Some PKCS11Tests are being skipped when they shouldn't + - JDK-8366369: Add @requires linux for GTK L&F tests + - JDK-8366852: java/awt/Choice/ChoiceMouseWheelTest/ChoiceMouseWheelTest.java test is failing + - JDK-8367096: jdk/open/test/jdk/sun/security/pkcs11/ rsa, ec, config, secmod and sslecc tests are skipping but showing as pass + - JDK-8367485: os::physical_memory is broken in 32-bit JVMs when running on 64-bit OSes + - JDK-8367784: java/awt/Focus/InitialFocusTest/InitialFocusTest1.java failed with Wrong focus owner + - JDK-8368029: Several tests in httpserver/simpleserver should throw SkipException + - JDK-8368041: Enhance TLS certificate handling + - JDK-8368181: ProblemList java/awt/Dialog/ModalExcludedTest/ModalExcludedTest.java + - JDK-8368335: Refactor the rest of Locale TestNG based tests to JUnit + - JDK-8368498: Use JUnit instead of TestNG for jdk_text tests + - JDK-8368524: Tests are skipped and shown as passed in test/jdk/sun/security/pkcs11/Cipher/KeyWrap + - JDK-8368551: Core dump warning may be confusing + - JDK-8368625: com/sun/net/httpserver/ServerStopTerminationTest.java fails intermittently + - JDK-8368670: Deadlock in JFR on event register + class load + - JDK-8368754: runtime/cds/appcds/SignedJar.java log regex is too strict + - JDK-8368866: compiler/codecache/stress/UnexpectedDeoptimizationTest.java intermittent timed out + - JDK-8368885: NMT CommandLine tests can check for error better + - JDK-8368892: Make JEditorPane/TestBrowserBGColor.java headless + - JDK-8369251: Opensource few tests + - JDK-8369335: Two sun/java2d/OpenGL tests fail on Windows after JDK-8358058 + - JDK-8369516: Delete duplicate imaging test + - JDK-8369561: sun/java2d/OpenGL/DrawBitmaskImage.java#id0: Incorrect color for first pixel (actual=ff000000) + - JDK-8369683: Exclude runtime/Monitor/MonitorWithDeadObjectTest.java#DumpThreadsBeforeDetach on Alpine Linux debug + - JDK-8369851: Remove darcy author tags from langtools tests + - JDK-8369950: TLS connection to IPv6 address fails with BCJSSE due to IllegalArgumentException + - JDK-8370378: Some compiler tests inadvertently exclude particular platforms + - JDK-8370489: Some compiler tests miss the @key randomness + - JDK-8370492: [Linux] Update cpu shares to cpu.weight mapping function + - JDK-8370511: test/jdk/javax/swing/JSlider/bug4382876.java does not release previously pressed keys + - JDK-8370732: Use WhiteBox.getWhiteBox().fullGC() to provoking gc for nsk/jvmti tests + - JDK-8370905: Update vm.defmeth tests to use virtual threads + - JDK-8370942: test/jdk/java/security/Provider/NewInstance.java and /test/jdk/java/security/cert/CertStore/NoLDAP.java may skip without notifying + - JDK-8371262: sun/security/pkcs11/Cipher/KeyWrap tests may silently skip + - JDK-8371349: Update NSS library to 3.117 + - JDK-8371364: Refactor javax/swing/JFileChooser/FileSizeCheck.java to use Util.findComponent() + - JDK-8371365: Update javax/swing/JFileChooser/bug4759934.java to use Util.findComponent() + - JDK-8371366: java/net/httpclient/whitebox/RawChannelTestDriver.java fails intermittently in jtreg timeout + - JDK-8371383: Test sun/security/tools/jarsigner/DefaultOptions.java failed due to CertificateNotYetValidException + - JDK-8371503: RETAIN_IMAGE_AFTER_TEST do not work for some tests + - JDK-8371895: Lower GCTimeLimit in TestUseGCOverheadLimit.java + - JDK-8371967: Add Visual Studio 2026 to build toolchain for Windows + - JDK-8372120: Add missing sound keyword to MIDI tests + - JDK-8372272: Hotspot shared lib loading - add load attempts to Events::log + - JDK-8372351: Add 2 WISeKey roots + - JDK-8372609: Bug4944439 does not enforce locale correctly + - JDK-8372661: Add a null-safe static factory method to "jdk.test.lib.net.SimpleSSLContext" + - JDK-8373101: JdkClient and JdkServer test classes ignore namedGroups field + - JDK-8373239: Test java/awt/print/PrinterJob/PageRanges.java fails with incorrect selection of printed pages + - JDK-8373275: Improve DTLS handshaking + - JDK-8373537: Migrate "test/jdk/com/sun/net/httpserver/" to null-safe "SimpleSSLContext" methods + - JDK-8373593: Support latest VS2026 MSC_VER in abstract_vm_version.cpp + - JDK-8373623: Refactor Serialization tests for Records to JUnit + - JDK-8373632: Some sound tests failing in CI due to lack of sound key + - JDK-8373650: Test "javax/swing/JMenuItem/6458123/ManualBug6458123.java" fails because the check icons are not aligned properly as expected + - JDK-8373690: Unexpected Keystore message using jdk.crypto.disabledAlgorithms + - JDK-8373704: Improve "SocketException: Protocol family unavailable" message + - JDK-8373716: Refactor further java/util tests from TestNG to JUnit + - JDK-8373793: TestDynamicStore.java '/manual' disables use of '/timeout' + - JDK-8373796: Refactor java/net/httpclient/ThrowingPublishers*.java tests to use JUnit5 + - JDK-8373807: test/jdk/java/net/httpclient/websocket/DummyWebSocketServer.java getURI() uses "localhost" + - JDK-8373832: Test java/lang/invoke/TestVHInvokerCaching.java tests nothing + - JDK-8373847: Test javax/swing/JMenuItem/MenuItemTest/bug6197830.java failed because The test case automatically fails when clicking any items in the “Nothing” menu in all four windows (Left-to-right)-Menu Item Test and (Right-to-left)-Menu Item Test + - JDK-8373866: Refactor java/net/httpclient/ThrowingSubscribers*.java tests to use JUnit5 + - JDK-8373869: Refactor java/net/httpclient/ThrowingPushPromises*.java tests to use JUnit5 + - JDK-8373928: 4 Dangling pointer defect groups in java.c + - JDK-8373931: Test javax/sound/sampled/Clip/AutoCloseTimeCheck.java timed out + - JDK-8374058: Enhance JPEG handling + - JDK-8374304: MultiResolutionSplashTest.java fails in CI: "Image with wrong resolution is used for splash screen!" + - JDK-8374322: TestMemoryWithSubgroups.java fails Permission denied + - JDK-8374434: Several JShell tests report JUnit discovery warnings + - JDK-8374506: Incorrect positioning of arrow icon in parent JMenu in Windows L&F + - JDK-8374711: Hotspot runtime/CommandLine/OptionsValidation/TestOptionsWithRanges fails without printing the option name + - JDK-8374769: PPC: MASM::pop_cont_fastpath() should reset _cont_fastpath if SP == _cont_fastpath + - JDK-8374888: Implement internal test cache to help UserIterCount test performance + - JDK-8374998: Failing os::write - remove bad file + - JDK-8375065: Update LCMS to 2.18 + - JDK-8375080: The tools/jpackage/windows/Win8365790Test.java may fail with ClassNotFoundException: jtreg.SkippedException + - JDK-8375231: Refactor util/ServiceLoader tests to use JUnit + - JDK-8375232: Refactor util/StringJoiner tests to use JUnit + - JDK-8375233: Refactor util/Vector tests to use JUnit + - JDK-8375742: Test java/lang/invoke/MethodHandleProxies/Driver.java does not run Unnamed.java + - JDK-8376031: HttpsURLConnection.getServerCertificates() throws "java.lang.IllegalStateException: connection not yet open" for the HEAD method + - JDK-8376151: Test javax/swing/JFileChooser/4966171/bug4966171.java is failing with OOME + - JDK-8376152: Test javax/sound/sampled/Clip/bug5070081.java timed out then completed + - JDK-8376233: Clean up code in Desktop native peer + - JDK-8376889: Enhance JfrRecorder::on_create_vm_3() assert output + - JDK-8377158: Enhance XBM image support + - JDK-8377167: javax/imageio/ReadAbortTest.java throw NPE when x11 unavailable + - JDK-8377347: jdk/jfr/event/gc/detailed/TestZAllocationStallEvent.java intermittent OOME + - JDK-8377498: Improve HttpServer handling + - JDK-8377602: Create automated test for PageRange + - JDK-8377727: Ghost caret and focus appear in non‑editable text fields + - JDK-8377833: Enhance Jar file processing + - JDK-8377910: Minor cleanup of java/io/FileDescriptor/Sharing.java + - JDK-8377944: LowMemoryTest2.java#id1 intermittent fails OOME: Metaspace + - JDK-8378113: Add sun/java2d/OpenGL/ScaleParamsOOB.java to the ProblemList.txt file + - JDK-8378201: [OGL] glXMakeContextCurrent() drops the buffers of the unbound drawable + - JDK-8378353: [PPC64] StringCoding.countPositives causes errors when the length is not a proper 32 bit int + - JDK-8378417: Printing All pages results in NPE for 1.1 PrintJob + - JDK-8378561: Mark gc/shenandoah/compiler/TestLinkToNativeRBP.java as /native + - JDK-8378687: Improve delegation of HttpURLConnection + - JDK-8378775: Bump update version for OpenJDK: jdk-21.0.12 + - JDK-8378802: [21u] backport changes to TKit.java by JDK-8352419 + - JDK-8378810: Enable missing FFM test via jtreg requires for RISC-V + - JDK-8378878: Refactor java/nio/channels/AsynchronousSocketChannel test to use JUnit + - JDK-8379464: Enable missing stack walking test via jtreg requires for RISC-V + - JDK-8380011: Path-to-gcroots search should not trigger stack overflows + - JDK-8380222: Refactor test/jdk/java/lang/Character TestNG tests to JUnit + - JDK-8380316: Test runtime/os/AvailableProcessors.java fails Invalid argument + - JDK-8380428: ProblemList containers/docker/TestJcmdWithSideCar.java on linux-all + - JDK-8380474: Crash SEGV in ThreadIdTable::lazy_initialize after JDK-8323792 + - JDK-8380565: PPC64: deoptimization stub should save vector registers + - JDK-8380672: Improve certification checking + - JDK-8380947: Add pull request template + - JDK-8381039: Enhance AWT ImagingLib + - JDK-8381049: Enhance Jar handling + - JDK-8381205: GHA: Upgrade Node.js 20 to 24 + - JDK-8381315: compiler/vectorapi/TestVectorReallocation.java fails with -XX:UseAVX=1 after JDK-8380565 + - JDK-8381519: Enhance Der Value Handling + - JDK-8381796: Enhance Certificate parsing + - JDK-8382018: test/jdk/java/nio/file/spi/SetDefaultProvider.java leaves a directory in /tmp + - JDK-8382242: JFR: Metadata reconstruction invalidates ConstantMap for java.lang.String + - JDK-8382419: Add missed @key randomness after JDK-8370489 + - JDK-8383175: (tz) Update Timezone Data to 2026b + - JDK-8383185: [21u] Backport of JDK-8382925 causes test failure in SetDefaultProvider + - JDK-8383354: Update LCMS to 2.19.1 + - JDK-8383473: Follow on from tzdata2026b time change to include temporary hack BC time change + - JDK-8383601: RISC-V: ShenandoahBarrierSetAssembler::load_reference_barrier calls "weak" on "phantom" path + - JDK-8383630: Fix iteration in tests doing class redefinition + - JDK-8384158: GHA: Downgrade Windows GHA runners to windows-2022 temporarily + - JDK-8384486: NTLM tests fail on Windows 11 and Windows Server 2025 + - JDK-8384495: Update Libpng to 1.6.58 + - JDK-8384540: [25u, 21u, 17u] Update GHA JDKs after Apr/26 updates + - JDK-8384815: SelectOneKeyOutOfMany and PreferredKey fail after expired test certificate + - JDK-8384902: Update GIFlib to 6.1.3 + - JDK-8385390: Update FreeType to 2.14.3 + - JDK-8385490: Update HarfBuzz to 14.2.0 + - JDK-8386551: Windows build broken because of MSys2/Make update + +Notes on individual issues: +=========================== + +hotspot/gc: + +JDK-8212084: G1: Implement UseGCOverheadLimit +============================================= +In this release, the G1 garbage collector now respects the values of +`GCTimeLimit` and `GCHeapFreeLimit`. The garbage collector will throw +an `OutOfMemoryException` (OOME) when the garbage collection overhead +is more than `GCTimeLimit` percent (default: 98%) and the free Java +heap is less than `GCHeapFreeLimit` (default: 2%) for five consecutive +garbage collections. + +This feature is enabled by default. It may be disabled by specifying +the `-XX:-UseGCOverheadLimit` option. The implementation mirrors the +functionality already provided by the parallel garbage collector, +though there may be differences in the exact conditions when an OOME +is triggered, due to differences in the way the collectors calculate +the collection overhead and free Java heap. + +security-libs/java.security: + +JDK-8372351: Add 2 WISeKey roots +================================ +The following root certificates have been added to the cacerts +truststore: + +Alias Name: wisekeyglobalrootgbca +Distinguished Name: CN=OISTE WISeKey Global Root GB CA, OU=OISTE Foundation Endorsed, O=WISeKey, C=CH +Serial Number: 76b1205274f0858746b3f8231af6c2c0 +Valid From: Mon Dec 01 15:00:32 GMT 2014 +Valid Until: Thu Dec 01 15:10:31 GMT 2039 + +Alias Name: wisekeyglobalrootgcca +Distinguished Name: CN=OISTE WISeKey Global Root GC CA, OU=OISTE Foundation Endorsed, O=WISeKey, C=CH +Serial Number: 212a560caeda0cab4045bf2ba22d3aea +Valid From: Tue May 09 09:48:34 GMT 2017 +Valid Until: Fri May 09 09:58:33 GMT 2042 + +JDK-8381796: Enhance Certificate parsing +======================================== +With this release of OpenJDK, a security and system property +`com.sun.security.crl.maxSize` is introduced which acts as a maximum +size limit on a Certificate Revocation List (CRL) downloaded over the +network. For URICertStore requests, the value is the maximum size in +bytes of the DER-encoded CRL. For LDAPCertStore queries, the +threshold is the sum of all CRLs downloaded from a single search. By +default, the maximum size is 20MiB (20971520 bytes) and CRLs larger +than this will be discarded. A value less than zero may be used to +turn off the size limit and non-numeric values will be ignored. A +non-empty value for the system property takes precedence over the +security property. Enabling 'certpath' debug logging will output the +current size limit and note any discarded CRLs. + New in release OpenJDK 21.0.11 (2026-04-21): =========================================== Live versions of these release notes can be found at: diff --git a/TestTranslations.java b/TestTranslations.java index f6a4fe2..66d0d6f 100644 --- a/TestTranslations.java +++ b/TestTranslations.java @@ -1,5 +1,5 @@ /* TestTranslations -- Ensure translations are available for new timezones - Copyright (C) 2022 Red Hat, Inc. + Copyright (C) 2026 Red Hat, Inc. This program is free software: you can redistribute it and/or modify it under the terms of the GNU Affero General Public License as @@ -60,15 +60,34 @@ public class TestTranslations { public static void main(String[] args) { + boolean debug = false; + if (args.length < 1) { System.err.println("Test must be started with the name of the locale provider."); System.exit(1); } + if (args.length > 1) { + debug = Boolean.parseBoolean(args[1]); + } + + System.err.printf("Debugging: %s\n", debug); + + testZoneStrings(debug); + + String localeProvider = args[0]; + testZone(localeProvider, KYIV, + new String[] { "Europe/Kiev", "Europe/Kyiv", "Europe/Uzhgorod", "Europe/Zaporozhye" }); + testZone(localeProvider, CIUDAD_JUAREZ, + new String[] { "America/Cambridge_Bay", "America/Ciudad_Juarez" }); + } + + private static void testZoneStrings(final boolean debug) { System.out.println("Checking sanity of full zone string set..."); boolean invalid = Arrays.stream(Locale.getAvailableLocales()) - .peek(l -> System.out.println("Locale: " + l)) + .peek(l -> System.out.printf(debug ? "Locale: %s\n" : "", l)) .map(l -> DateFormatSymbols.getInstance(l).getZoneStrings()) + .peek(df -> System.out.printf(debug ? "Zone string size: %s\n" : "", df.length)) .flatMap(zs -> Arrays.stream(zs)) .flatMap(names -> Arrays.stream(names)) .filter(name -> Objects.isNull(name) || name.isEmpty()) @@ -78,12 +97,6 @@ public class TestTranslations { System.err.println("Zone string for a locale returned null or empty string"); System.exit(2); } - - String localeProvider = args[0]; - testZone(localeProvider, KYIV, - new String[] { "Europe/Kiev", "Europe/Kyiv", "Europe/Uzhgorod", "Europe/Zaporozhye" }); - testZone(localeProvider, CIUDAD_JUAREZ, - new String[] { "America/Cambridge_Bay", "America/Ciudad_Juarez" }); } private static void testZone(String localeProvider, Map exp, String[] ids) { diff --git a/java-21-openjdk-portable.specfile b/java-21-openjdk-portable.specfile index 66945e8..ae2e631 100644 --- a/java-21-openjdk-portable.specfile +++ b/java-21-openjdk-portable.specfile @@ -1,5 +1,98 @@ -# debug_package %%{nil} is portable-jdks specific -%define debug_package %{nil} +# New Version-String scheme-style defines +%global featurever 21 +%global interimver 0 +%global updatever 12 +%global patchver 0 +%global buildver 8 +%global portablerelease 1 +%global rpmrelease 0 + +# Define IcedTea version used for SystemTap tapsets and desktop file +%global icedteaver 6.0.0pre00-c848b93a8598 +# Define current Git revision for the FIPS support patches +%global fipsver feef2dc3ca7 +# Define JDK versions +%global newjavaver %{featurever}.%{interimver}.%{updatever}.%{patchver} +%global javaver %{featurever} +# Strip up to 6 trailing zeros in newjavaver, as the JDK does, to get the correct version used in filenames +%global filever %(svn=%{newjavaver}; for i in 1 2 3 4 5 6 ; do svn=${svn%%.0} ; done; echo ${svn}) +# The tag used to create the OpenJDK tarball +%global vcstag jdk-%{filever}+%{buildver}%{?tagsuffix:-%{tagsuffix}} + +# Standard JPackage naming and versioning defines +%global origin openjdk +%global origin_nice OpenJDK +%global top_level_dir_name %{vcstag} +%global top_level_dir_name_backup %{top_level_dir_name}-backup +# Define an optional suffix for the OS this package is built on +%if 0%{?rhel} == 7 +%global pkgos rhel7 +%endif + +# Define milestone (EA for pre-releases, GA for releases) +# Release will be (where N is usually a number starting at 1): +# - 0.N.ea for EA releases, +# - N for GA releases +%global is_ga 1 +%if %{is_ga} +%global build_type GA +%global ea_designator "" +%global ea_designator_zip %{nil} +%global extraver %{nil} +%global eaprefix %{nil} +%else +%global build_type EA +%global ea_designator ea +%global ea_designator_zip -%{ea_designator} +%global extraver .%{ea_designator} +%global eaprefix 0. +%endif + +%global compatiblename java-%{javaver}-%{origin} + +Name: %{compatiblename}-portable%{?pkgos:-%{pkgos}} +Version: %{newjavaver}.%{buildver} +Release: %{?eaprefix}%{portablerelease}.%{rpmrelease}%{?extraver}%{?dist} + +%global fullversion %{compatiblename}-%{version}-%{release} + +# java-1.5.0-ibm from jpackage.org set Epoch to 1 for unknown reasons +# and this change was brought into RHEL-4. java-1.5.0-ibm packages +# also included the epoch in their virtual provides. This created a +# situation where in-the-wild java-1.5.0-ibm packages provided "java = +# 1:1.5.0". In RPM terms, "1.6.0 < 1:1.5.0" since 1.6.0 is +# interpreted as 0:1.6.0. So the "java >= 1.6.0" requirement would be +# satisfied by the 1:1.5.0 packages. Thus we need to set the epoch in +# JDK package >= 1.6.0 to 1, and packages referring to JDK virtual +# provides >= 1.6.0 must specify the epoch, "java >= 1:1.6.0". +Epoch: 1 +Summary: %{origin_nice} %{featurever} Runtime Environment portable edition +# Groups are only used up to RHEL 8 and on Fedora versions prior to F30 +%if (0%{?rhel} > 0 && 0%{?rhel} <= 8) || (0%{?fedora} >= 0 && 0%{?fedora} < 30) +Group: Development/Languages +%endif + +# HotSpot code is licensed under GPLv2 +# JDK library code is licensed under GPLv2 with the Classpath exception +# The Apache license is used in code taken from Apache projects (primarily xalan & xerces) +# DOM levels 2 & 3 and the XML digital signature schemas are licensed under the W3C Software License +# The JSR166 concurrency code is in the public domain +# The BSD and MIT licenses are used for a number of third-party libraries (see ADDITIONAL_LICENSE_INFO) +# The OpenJDK source tree includes: +# - JPEG library (IJG), zlib & libpng (zlib), giflib (MIT), harfbuzz (ISC), +# - freetype (FTL), jline (BSD) and LCMS (MIT) +# - jquery (MIT), jdk.crypto.cryptoki PKCS 11 wrapper (RSA) +# - public_suffix_list.dat from publicsuffix.org (MPLv2.0) +# The test code includes copies of NSS under the Mozilla Public License v2.0 +# The PCSClite headers are under a BSD with advertising license +# The elliptic curve cryptography (ECC) source code is licensed under the LGPLv2.1 or any later version +License: ASL 1.1 and ASL 2.0 and BSD and BSD with advertising and GPL+ and GPLv2 and GPLv2 with exceptions and IJG and LGPLv2+ and MIT and MPLv2.0 and Public Domain and W3C and zlib and ISC and FTL and RSA +URL: http://openjdk.java.net/ + +# We are producing RPMs containing only tarballs +# and checksums so there are no binaries outside +# the tarballs to be processed for debuginfo +%define debug_package %{nil} # RPM conditionals so as to be able to dynamically produce # slowdebug/release builds. See: @@ -96,25 +189,6 @@ %global normal_build %{nil} %endif -# We have hardcoded list of files, which is appearing in alternatives, and in files -# in alternatives those are slaves and master, very often triplicated by man pages -# in files all masters and slaves are ghosted -# the ghosts are here to allow installation via query like `dnf install /usr/bin/java` -# you can list those files, with appropriate sections: cat *.spec | grep -e --install -e --slave -e post_ -# TODO - fix those hardcoded lists via single list -# Those files must *NOT* be ghosted for *slowdebug* packages -# FIXME - if you are moving jshell or jlink or similar, always modify all three sections -# you can check via headless and devels: -# rpm -ql --noghost java-11-openjdk-headless-11.0.1.13-8.fc29.x86_64.rpm | grep bin -# == rpm -ql java-11-openjdk-headless-slowdebug-11.0.1.13-8.fc29.x86_64.rpm | grep bin -# != rpm -ql java-11-openjdk-headless-11.0.1.13-8.fc29.x86_64.rpm | grep bin -# similarly for other %%{_jvmdir}/{jre,java} and %%{_javadocdir}/{java,java-zip} -%define is_release_build() %( if [ "%{?1}" == "%{debug_suffix_unquoted}" -o "%{?1}" == "%{fastdebug_suffix_unquoted}" ]; then echo "0" ; else echo "1"; fi ) - -# while JDK is a techpreview(is_system_jdk=0), some provides are turned off. Once jdk stops to be an techpreview, move it to 1 -# as sytem JDK, we mean any JDK which can run whole system java stack without issues (like bytecode issues, module issues, dependencies...) -%global is_system_jdk 0 - %global aarch64 aarch64 arm64 armv8 # we need to distinguish between big and little endian PPC64 %global ppc64le ppc64le @@ -326,17 +400,14 @@ %global with_systemtap 0 %endif -# New Version-String scheme-style defines -%global featurever 21 -%global interimver 0 -%global updatever 11 -%global patchver 0 -# buildjdkver is usually same as %%{featurever}, -# but in time of bootstrap of next jdk, it is featurever-1, + +# buildjdkver is usually same as featurever, +# but at the time of bootstrap of the next jdk, it is featurever-1, # and this it is better to change it here, on single place %global buildjdkver %{featurever} + # We don't add any LTS designator for STS packages (Fedora and EPEL). -# We need to explicitly exclude EPEL as it would have the %%{rhel} macro defined. +# We need to explicitly exclude EPEL as it has the rhel macro defined. %if 0%{?rhel} && !0%{?epel} %global lts_designator "LTS" %global lts_designator_zip -%{lts_designator} @@ -358,7 +429,8 @@ # Define vendor information used by OpenJDK %global oj_vendor Red Hat, Inc. %global oj_vendor_url https://www.redhat.com/ -# Define what url should JVM offer in case of a crash report + +# Define what url the JVM should offer in case of a crash report # order may be important, epel may have rhel declared %if 0%{?epel} %global oj_vendor_bug_url https://bugzilla.redhat.com/enter_bug.cgi?product=Fedora%20EPEL&component=%{name}&version=epel%{epel} @@ -374,67 +446,13 @@ %endif %endif %endif -%global oj_vendor_version (Red_Hat-%{version}-%{rpmrelease}) +%global oj_vendor_version (Red_Hat-%{version}-%{portablerelease}) -# Define IcedTea version used for SystemTap tapsets and desktop file -%global icedteaver 6.0.0pre00-c848b93a8598 -# Define current Git revision for the FIPS support patches -%global fipsver feef2dc3ca7 -# Define JDK versions -%global newjavaver %{featurever}.%{interimver}.%{updatever}.%{patchver} -%global javaver %{featurever} -# Strip up to 6 trailing zeros in newjavaver, as the JDK does, to get the correct version used in filenames -%global filever %(svn=%{newjavaver}; for i in 1 2 3 4 5 6 ; do svn=${svn%%.0} ; done; echo ${svn}) -# The tag used to create the OpenJDK tarball -%global vcstag jdk-%{filever}+%{buildver}%{?tagsuffix:-%{tagsuffix}} - -# Standard JPackage naming and versioning defines -%global origin openjdk -%global origin_nice OpenJDK -%global top_level_dir_name %{vcstag} -%global top_level_dir_name_backup %{top_level_dir_name}-backup -%global buildver 10 -%global rpmrelease 1 -#%%global tagsuffix %%{nil} -# Priority must be 8 digits in total; up to openjdk 1.8, we were using 18..... so when we moved to 11, we had to add another digit -%if %is_system_jdk -# Using 10 digits may overflow the int used for priority, so we combine the patch and build versions -# It is very unlikely we will ever have a patch version > 4 or a build version > 20, so we combine as (patch * 20) + build. -# This means 11.0.9.0+11 would have had a priority of 11000911 as before -# A 11.0.9.1+1 would have had a priority of 11000921 (20 * 1 + 1), thus ensuring it is bigger than 11.0.9.0+11 -%global combiver $( expr 20 '*' %{patchver} + %{buildver} ) -%global priority %( printf '%02d%02d%02d%02d' %{featurever} %{interimver} %{updatever} %{combiver} ) -%else -# for techpreview, using 1, so slowdebugs can have 0 -%global priority %( printf '%08d' 1 ) -%endif - -# Define milestone (EA for pre-releases, GA for releases) -# Release will be (where N is usually a number starting at 1): -# - 0.N%%{?extraver}%%{?dist} for EA releases, -# - N%%{?extraver}{?dist} for GA releases -%global is_ga 1 -%if %{is_ga} -%global build_type GA -%global ea_designator "" -%global ea_designator_zip %{nil} -%global extraver %{nil} -%global eaprefix %{nil} -%else -%global build_type EA -%global ea_designator ea -%global ea_designator_zip -%{ea_designator} -%global extraver .%{ea_designator} -%global eaprefix 0. -%endif - -# parametrized macros are order-sensitive -%global compatiblename java-%{featurever}-%{origin} -%global fullversion %{compatiblename}-%{version}-%{release} # images directories from upstream build %global jdkimage jdk %global static_libs_image static-libs # output dir stub +# Parameterised macros are order-sensitive %define buildoutputdir() %{expand:build/jdk%{featurever}.build%{?1}} %define installoutputdir() %{expand:install/jdk%{featurever}.install%{?1}} %global altjavaoutputdir install/altjava.install @@ -445,41 +463,30 @@ %define uniquesuffix() %{expand:%{fullversion}.%{_arch}%{?1}} # portable only declarations %global jreimage jre -%define jreportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable%{1}.jre;g") -%define jdkportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable%{1}.jdk;g") -%define staticlibsportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable%{1}.static-libs;g") +%define jreportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable%{1}.jre;g") +%define jdkportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable%{1}.jdk;g") +%define staticlibsportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable%{1}.static-libs;g") + +# RPM 4.19 no longer accept our double percentaged %%{nil} passed to %%{1} +# so we have to pass in "" but evaluate it, otherwise files will include it %define jreportablearchive() %{expand:%{jreportablenameimpl -- %%{1}}.tar.xz} +%define jreportablearchive_for_files() %(echo %{jreportablearchive -- ""}) %define jdkportablearchive() %{expand:%{jdkportablenameimpl -- %%{1}}.tar.xz} +%define jdkportablearchive_for_files() %(echo %{jdkportablearchive -- ""}) %define staticlibsportablearchive() %{expand:%{staticlibsportablenameimpl -- %%{1}}.tar.xz} +%define staticlibsportablearchive_for_files() %(echo %{staticlibsportablearchive -- ""}) + %define jreportablename() %{expand:%{jreportablenameimpl -- %%{1}}} %define jdkportablename() %{expand:%{jdkportablenameimpl -- %%{1}}} -# Intentionally use jdkportablenameimpl here since we want to have static-libs files overlayed on -# top of the JDK archive +# We intentionally use jdkportablenameimpl here since we want to have +# static-libs files overlayed on top of the JDK archive %define staticlibsportablename() %{expand:%{jdkportablenameimpl -- %%{1}}} -%define docportablename() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable.docs;g") -%define docportablearchive() %{docportablename}.tar.xz -%define miscportablename() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable.misc;g") -%define miscportablearchive() %{miscportablename}.tar.xz -################################################################# -# fix for https://bugzilla.redhat.com/show_bug.cgi?id=1111349 -# https://bugzilla.redhat.com/show_bug.cgi?id=1590796#c14 -# https://bugzilla.redhat.com/show_bug.cgi?id=1655938 -%global _privatelibs libsplashscreen[.]so.*|libawt_xawt[.]so.*|libjli[.]so.*|libattach[.]so.*|libawt[.]so.*|libextnet[.]so.*|libawt_headless[.]so.*|libdt_socket[.]so.*|libfontmanager[.]so.*|libinstrument[.]so.*|libj2gss[.]so.*|libj2pcsc[.]so.*|libj2pkcs11[.]so.*|libjaas[.]so.*|libjavajpeg[.]so.*|libjdwp[.]so.*|libjimage[.]so.*|libjsound[.]so.*|liblcms[.]so.*|libmanagement[.]so.*|libmanagement_agent[.]so.*|libmanagement_ext[.]so.*|libmlib_image[.]so.*|libnet[.]so.*|libnio[.]so.*|libprefs[.]so.*|librmi[.]so.*|libsaproc[.]so.*|libsctp[.]so.*|libsystemconf[.]so.*|libzip[.]so.*%{freetype_lib} -%global _publiclibs libjawt[.]so.*|libjava[.]so.*|libjvm[.]so.*|libverify[.]so.*|libjsig[.]so.* -%if %is_system_jdk -%global __provides_exclude ^(%{_privatelibs})$ -%global __requires_exclude ^(%{_privatelibs})$ -# Never generate lib-style provides/requires for slowdebug packages -%global __provides_exclude_from ^.*/%{uniquesuffix -- %{debug_suffix_unquoted}}/.*$ -%global __requires_exclude_from ^.*/%{uniquesuffix -- %{debug_suffix_unquoted}}/.*$ -%global __provides_exclude_from ^.*/%{uniquesuffix -- %{fastdebug_suffix_unquoted}}/.*$ -%global __requires_exclude_from ^.*/%{uniquesuffix -- %{fastdebug_suffix_unquoted}}/.*$ -%else -# Don't generate provides/requires for JDK provided shared libraries at all. -%global __provides_exclude ^(%{_privatelibs}|%{_publiclibs})$ -%global __requires_exclude ^(%{_privatelibs}|%{_publiclibs})$ -%endif +# These macros are not parameterised as the same is shared by all builds +%define docportablename() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable.docs;g") +%define docportablearchive() %{docportablename}.tar.xz +%define miscportablename() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable.misc;g") +%define miscportablearchive() %{miscportablename}.tar.xz # VM variant being built %ifarch %{zero_arches} @@ -488,28 +495,11 @@ %global vm_variant server %endif -%global etcjavasubdir %{_sysconfdir}/java/java-%{javaver}-%{origin} -%define etcjavadir() %{expand:%{etcjavasubdir}/%{uniquesuffix -- %{?1}}} -# Standard JPackage directories and symbolic links. -%define sdkdir() %{expand:%{uniquesuffix -- %{?1}}} -%define jrelnk() %{expand:jre-%{javaver}-%{origin}-%{version}-%{release}.%{_arch}%{?1}} - -%define sdkbindir() %{expand:%{_jvmdir}/%{sdkdir -- %{?1}}/bin} -%define jrebindir() %{expand:%{_jvmdir}/%{sdkdir -- %{?1}}/bin} - %global alt_java_name alt-java %global devkit_name %{origin}-devkit %global rpm_state_dir %{_localstatedir}/lib/rpm-state/ -# For flatpack builds hard-code /usr/sbin/alternatives, -# otherwise use %%{_sbindir} relative path. -%if 0%{?flatpak} -%global alternatives_requires /usr/sbin/alternatives -%else -%global alternatives_requires %{_sbindir}/alternatives -%endif - # Portables have no repo (requires/provides), but these are awesome for orientation in spec # Also scriptlets are happily missing and files are handled old fashion # not-duplicated requires/provides/obsoletes for normal/debug packages @@ -534,11 +524,6 @@ # Prevent brp-java-repack-jars from being run %global __jar_repack 0 -# Define an optional suffix for the OS this package is built on -%if 0%{?rhel} == 7 -%global pkgos rhel7 -%endif - # Define the architectures on which we build # On RHEL, this should be the architectures with a devkit %if 0%{?centos} == 0 @@ -547,43 +532,6 @@ ExclusiveArch: %{devkit_arches} ExclusiveArch: %{aarch64} %{ppc64le} riscv64 s390x x86_64 %endif -Name: java-%{javaver}-%{origin}-portable%{?pkgos:-%{pkgos}} -Version: %{newjavaver}.%{buildver} -Release: %{?eaprefix}%{rpmrelease}%{?extraver}%{?dist} -# java-1.5.0-ibm from jpackage.org set Epoch to 1 for unknown reasons -# and this change was brought into RHEL-4. java-1.5.0-ibm packages -# also included the epoch in their virtual provides. This created a -# situation where in-the-wild java-1.5.0-ibm packages provided "java = -# 1:1.5.0". In RPM terms, "1.6.0 < 1:1.5.0" since 1.6.0 is -# interpreted as 0:1.6.0. So the "java >= 1.6.0" requirement would be -# satisfied by the 1:1.5.0 packages. Thus we need to set the epoch in -# JDK package >= 1.6.0 to 1, and packages referring to JDK virtual -# provides >= 1.6.0 must specify the epoch, "java >= 1:1.6.0". - -Epoch: 1 -Summary: %{origin_nice} %{featurever} Runtime Environment portable edition -# Groups are only used up to RHEL 8 and on Fedora versions prior to F30 -%if (0%{?rhel} > 0 && 0%{?rhel} <= 8) || (0%{?fedora} >= 0 && 0%{?fedora} < 30) -Group: Development/Languages -%endif - -# HotSpot code is licensed under GPLv2 -# JDK library code is licensed under GPLv2 with the Classpath exception -# The Apache license is used in code taken from Apache projects (primarily xalan & xerces) -# DOM levels 2 & 3 and the XML digital signature schemas are licensed under the W3C Software License -# The JSR166 concurrency code is in the public domain -# The BSD and MIT licenses are used for a number of third-party libraries (see ADDITIONAL_LICENSE_INFO) -# The OpenJDK source tree includes: -# - JPEG library (IJG), zlib & libpng (zlib), giflib (MIT), harfbuzz (ISC), -# - freetype (FTL), jline (BSD) and LCMS (MIT) -# - jquery (MIT), jdk.crypto.cryptoki PKCS 11 wrapper (RSA) -# - public_suffix_list.dat from publicsuffix.org (MPLv2.0) -# The test code includes copies of NSS under the Mozilla Public License v2.0 -# The PCSClite headers are under a BSD with advertising license -# The elliptic curve cryptography (ECC) source code is licensed under the LGPLv2.1 or any later version -License: ASL 1.1 and ASL 2.0 and BSD and BSD with advertising and GPL+ and GPLv2 and GPLv2 with exceptions and IJG and LGPLv2+ and MIT and MPLv2.0 and Public Domain and W3C and zlib and ISC and FTL and RSA -URL: http://openjdk.java.net/ - # The source tarball, generated using generate_source_tarball.sh Source0: https://openjdk-sources.osci.io/openjdk%{featurever}/open%{vcstag}%{ea_designator_zip}.tar.xz @@ -626,9 +574,11 @@ Source18: TestTranslations.java # ############################################ # Crypto policy and FIPS support patches + # Patch is generated from the fips-21u tree at https://github.com/rh-openjdk/jdk/tree/fips-21u -# as follows: git diff %%{vcstag} src make test > fips-21u-$(git show -s --format=%h HEAD).patch +# as follows: git diff src make test > fips-21u-$(git show -s --format=%h HEAD).patch # Diff is limited to src and make subdirectories to exclude .github changes + # Fixes currently included: # PR3183, RH1340845: Follow system wide crypto policy # PR3695: Allow use of system crypto policy to be disabled by the user @@ -762,17 +712,17 @@ BuildRequires: libpng-devel BuildRequires: zlib-devel %else # Version in src/java.desktop/share/native/libfreetype/include/freetype/freetype.h -Provides: bundled(freetype) = 2.14.2 +Provides: bundled(freetype) = 2.14.3 # Version in src/java.desktop/share/native/libsplashscreen/giflib/gif_lib.h -Provides: bundled(giflib) = 6.1.2 +Provides: bundled(giflib) = 6.1.3 # Version in src/java.desktop/share/native/libharfbuzz/hb-version.h -Provides: bundled(harfbuzz) = 12.3.2 +Provides: bundled(harfbuzz) = 14.2.0 # Version in src/java.desktop/share/native/liblcms/lcms2.h -Provides: bundled(lcms2) = 2.17.0 +Provides: bundled(lcms2) = 2.19.1 # Version in src/java.desktop/share/native/libjavajpeg/jpeglib.h Provides: bundled(libjpeg) = 6b # Version in src/java.desktop/share/native/libsplashscreen/libpng/png.h -Provides: bundled(libpng) = 1.6.57 +Provides: bundled(libpng) = 1.6.58 # Version in src/java.base/share/native/libzip/zlib/zlib.h Provides: bundled(zlib) = 1.3.2 # We link statically against libstdc++ to increase portability @@ -962,11 +912,6 @@ echo "Build JDK version is %{buildjdkver}, feature JDK version is %{featurever}" export XZ_OPT="-T0" %setup -q -c -n %{uniquesuffix ""} -T -a 0 # https://bugzilla.redhat.com/show_bug.cgi?id=1189084 -prioritylength=`expr length %{priority}` -if [ $prioritylength -ne 8 ] ; then - echo "priority must be 8 digits in total, violated" - exit 14 -fi # OpenJDK patches @@ -976,19 +921,7 @@ sh %{SOURCE12} %{top_level_dir_name} %endif # Patch the JDK -# This syntax is deprecated: -# %patchN [...] -# and should be replaced with: -# %patch -PN [...] -# For example: -# %patch1001 -p1 -# becomes: -# %patch -P1001 -p1 -# The replacement format suggested by recent (circa Fedora 38) RPM -# deprecation messages: -# %patch N [...] -# is not backward-compatible with prior (circa RHEL-8) versions of -# rpmbuild. + pushd %{top_level_dir_name} # Add crypto policy and FIPS support %patch -P1001 -p1 @@ -1069,7 +1002,6 @@ done export NUM_PROC=%(/usr/bin/getconf _NPROCESSORS_ONLN 2> /dev/null || :) export NUM_PROC=${NUM_PROC:-1} %if 0%{?_smp_ncpus_max} -# Honor %%_smp_ncpus_max [ ${NUM_PROC} -gt %{?_smp_ncpus_max} ] && export NUM_PROC=%{?_smp_ncpus_max} %endif export XZ_OPT="-T0" @@ -1186,8 +1118,8 @@ function buildjdk() { mkdir -p ${outputdir} pushd ${outputdir} - # Note: zlib and freetype use %{link_type} - # rather than ${link_opt} as the system versions + # Note: zlib and freetype use link_type (macro) + # rather than link_opt (shell var) as the system versions # are always used in a system_libs build, even # for the static library build LD_LIBRARY_PATH=${LIBPATH} \ @@ -1881,8 +1813,8 @@ done %files # main package builds always -%{_jvmdir}/%{jreportablearchive -- %%{nil}} -%{_jvmdir}/%{jreportablearchive -- %%{nil}}.sha256sum +%{_jvmdir}/%{jreportablearchive_for_files} +%{_jvmdir}/%{jreportablearchive_for_files}.sha256sum %else %files # placeholder @@ -1891,15 +1823,15 @@ done %if %{include_normal_build} %files devel -%{_jvmdir}/%{jdkportablearchive -- %%{nil}} +%{_jvmdir}/%{jdkportablearchive_for_files} %{_jvmdir}/%{jdkportablearchive -- .debuginfo} -%{_jvmdir}/%{jdkportablearchive -- %%{nil}}.sha256sum +%{_jvmdir}/%{jdkportablearchive_for_files}.sha256sum %{_jvmdir}/%{jdkportablearchive -- .debuginfo}.sha256sum %if %{include_staticlibs} %files static-libs -%{_jvmdir}/%{staticlibsportablearchive -- %%{nil}} -%{_jvmdir}/%{staticlibsportablearchive -- %%{nil}}.sha256sum +%{_jvmdir}/%{staticlibsportablearchive_for_files} +%{_jvmdir}/%{staticlibsportablearchive_for_files}.sha256sum %endif %files unstripped @@ -1953,6 +1885,39 @@ done %endif %changelog +* Wed Jul 15 2026 Andrew Hughes - 1:21.0.12.0.8-1.0 +- Update to jdk-21.0.12+8 (GA) +- Update release notes to 21.0.12+8 +- Bump freetype version to 2.14.3 following JDK-8385390 +- Bump giflib version to 6.1.3 following JDK-8384902 +- Bump HarfBuzz version to 14.2.0 following JDK-8385490 +- Bump lcms2 version to 2.19.1 following JDK-8375065 & JDK-8383354 +- Bump libpng version to 1.6.58 following JDK-8384495 +- ** This tarball is embargoed until 2026-07-21 @ 1pm PT. ** +- Resolves: OPENJDK-4865 + +* Wed Jul 15 2026 Andrea Bolognani - 1:21.0.11.0.10-2.0 +- Strip %%{dist} more thoroughly +- Resolves: OPENJDK-4891 + +* Fri Jun 26 2026 Andrew Hughes - 1:21.0.11.0.10-2.0 +- Port ForFiles patch to RHEL and update to use standard function naming format +- Remove macro references in comments where possible (%dnl not compatible enough yet) +- Drop unused tagsuffix line which causes issues on older RPM versions without %dnl +- Cleanup RPM only macros unused in the portable spec file +- Move version information and core NVR definitions back towards the top of the file +- Specify portablerelease and rpmrelease (always 0 for portables) in the Release field +- Related: OPENJDK-4887 +- Resolves: OPENJDK-4888 +- Resolves: OPENJDK-4889 +- Resolves: OPENJDK-4890 + +* Fri Jun 26 2026 Jiri Vanek - 1:25.0.3.0.9-2.0 +- Redeclared ForFiles release sections as %%nil no longer works with %%1 +- RPM 4.19 no longer accept our double percentaged %%{nil} passed to %%{1} +- so we have to pass in "" but evaluate it, otherwise files record will include it +- Resolves: OPENJDK-4887 + * Sat Apr 18 2026 Andrew Hughes - 1:21.0.11.0.10-1 - Update to jdk-21.0.11+10 (GA) - Update release notes to 21.0.11+10 diff --git a/java-21-openjdk.spec b/java-21-openjdk.spec index e4f21a4..9c4abc6 100644 --- a/java-21-openjdk.spec +++ b/java-21-openjdk.spec @@ -3,6 +3,113 @@ # it and then adjust portablerelease and portablesuffix # to match the new portable. +# New Version-String scheme-style defines +%global featurever 21 +%global interimver 0 +%global updatever 12 +%global patchver 0 +%global buildver 8 +%global portablerelease 1 +%global rpmrelease 2 + +# Define IcedTea version used for SystemTap tapsets and desktop file +%global icedteaver 6.0.0pre00-c848b93a8598 +# Define current Git revision for the FIPS support patches +%global fipsver feef2dc3ca7 +# Define JDK versions +%global newjavaver %{featurever}.%{interimver}.%{updatever}.%{patchver} +%global javaver %{featurever} +# Strip up to 6 trailing zeros in newjavaver, as the JDK does, to get the correct version used in filenames +%global filever %(svn=%{newjavaver}; for i in 1 2 3 4 5 6 ; do svn=${svn%%.0} ; done; echo ${svn}) +# The tag used to create the OpenJDK tarball +%global vcstag jdk-%{filever}+%{buildver}%{?tagsuffix:-%{tagsuffix}} + +# Standard JPackage naming and versioning defines +%global origin openjdk +%global origin_nice OpenJDK +%global top_level_dir_name %{vcstag} +%global top_level_dir_name_backup %{top_level_dir_name}-backup + +# Define milestone (EA for pre-releases, GA for releases) +# Release will be (where N is usually a number starting at 1): +# - 0.N.ea for EA releases, +# - N for GA releases +%global is_ga 1 +%if %{is_ga} +%global build_type GA +%global ea_designator "" +%global ea_designator_zip %{nil} +%global extraver %{nil} +%global eaprefix %{nil} +%else +%global build_type EA +%global ea_designator ea +%global ea_designator_zip -%{ea_designator} +%global extraver .%{ea_designator} +%global eaprefix 0. +%endif + +%global compatiblename java-%{javaver}-%{origin} + +Name: %{compatiblename} +Version: %{newjavaver}.%{buildver} +Release: %{?eaprefix}%{portablerelease}.%{rpmrelease}%{?extraver}%{?dist} + +%global fullversion %{compatiblename}-%{version}-%{release} + +# java-1.5.0-ibm from jpackage.org set Epoch to 1 for unknown reasons +# and this change was brought into RHEL-4. java-1.5.0-ibm packages +# also included the epoch in their virtual provides. This created a +# situation where in-the-wild java-1.5.0-ibm packages provided "java = +# 1:1.5.0". In RPM terms, "1.6.0 < 1:1.5.0" since 1.6.0 is +# interpreted as 0:1.6.0. So the "java >= 1.6.0" requirement would be +# satisfied by the 1:1.5.0 packages. Thus we need to set the epoch in +# JDK package >= 1.6.0 to 1, and packages referring to JDK virtual +# provides >= 1.6.0 must specify the epoch, "java >= 1:1.6.0". +Epoch: 1 +Summary: %{origin_nice} %{featurever} Runtime Environment +# Groups are only used up to RHEL 8 and on Fedora versions prior to F30 +%if (0%{?rhel} > 0 && 0%{?rhel} <= 8) || (0%{?fedora} >= 0 && 0%{?fedora} < 30) +Group: Development/Languages +%endif + +# HotSpot code is licensed under GPLv2 +# JDK library code is licensed under GPLv2 with the Classpath exception +# The Apache license is used in code taken from Apache projects (primarily xalan & xerces) +# DOM levels 2 & 3 and the XML digital signature schemas are licensed under the W3C Software License +# The JSR166 concurrency code is in the public domain +# The BSD and MIT licenses are used for a number of third-party libraries (see ADDITIONAL_LICENSE_INFO) +# The OpenJDK source tree includes: +# - JPEG library (IJG), zlib & libpng (zlib), giflib (MIT), harfbuzz (ISC), +# - freetype (FTL), jline (BSD) and LCMS (MIT) +# - jquery (MIT), jdk.crypto.cryptoki PKCS 11 wrapper (RSA) +# - public_suffix_list.dat from publicsuffix.org (MPLv2.0) +# The test code includes copies of NSS under the Mozilla Public License v2.0 +# The PCSClite headers are under a BSD with advertising license +# The elliptic curve cryptography (ECC) source code is licensed under the LGPLv2.1 or any later version +License: ASL 1.1 and ASL 2.0 and BSD and BSD with advertising and GPL+ and GPLv2 and GPLv2 with exceptions and IJG and LGPLv2+ and MIT and MPLv2.0 and Public Domain and W3C and zlib and ISC and FTL and RSA +URL: http://openjdk.java.net/ + +# Define the OS the portable JDK is built on +# This is undefined for CentOS & openjdk-portable-rhel-8 builds and +# equals 'rhel7' for openjdk-portable-rhel-7 builds +%if 0 +%global pkgos rhel7 +%endif +# Define the root name of the portable packages +%global pkgnameroot java-%{featurever}-%{origin}-portable%{?pkgos:-%{pkgos}} +# Release field for the portable build +# The rpmrelease field is always zero for portables +%global prelease %{?eaprefix}%{portablerelease}.0%{?extraver} +# Portable suffix differs between RHEL and CentOS +%if 0%{?centos} == 0 +%global portablerhel %{?pkgos:7_9}%{!?pkgos:8} +%else +%global portablerhel 9 +%endif +%global portablebuilddir /builddir/build/BUILD +%global portablesuffix el%{portablerhel} + # RPM conditionals so as to be able to dynamically produce # slowdebug/release builds. See: # http://rpm.org/user_doc/conditional_builds.html @@ -87,19 +194,20 @@ %global normal_build %{nil} %endif -# We have hardcoded list of files, which is appearing in alternatives, and in files -# in alternatives those are slaves and master, very often triplicated by man pages -# in files all masters and slaves are ghosted -# the ghosts are here to allow installation via query like `dnf install /usr/bin/java` -# you can list those files, with appropriate sections: cat *.spec | grep -e --install -e --slave -e post_ -e alternatives +# We have a hardcoded list of files, which appears in alternatives and in files +# In alternatives, those are slaves and master, very often triplicated by man pages +# In files, all masters and slaves are ghosted +# The ghosts are here to allow installation via query like `dnf install /usr/bin/java` +# You can list those files, with appropriate sections: cat *.spec | grep -e --install -e --slave -e post_ -e alternatives # TODO - fix those hardcoded lists via single list -# Those files must *NOT* be ghosted for *slowdebug* packages +# Those files must *NOT* be ghosted for *debug* packages # FIXME - if you are moving jshell or jlink or similar, always modify all three sections -# you can check via headless and devels: +# You can check via headless and devels: # rpm -ql --noghost java-11-openjdk-headless-11.0.1.13-8.fc29.x86_64.rpm | grep bin # == rpm -ql java-11-openjdk-headless-slowdebug-11.0.1.13-8.fc29.x86_64.rpm | grep bin # != rpm -ql java-11-openjdk-headless-11.0.1.13-8.fc29.x86_64.rpm | grep bin -# similarly for other %%{_jvmdir}/{jre,java} and %%{_javadocdir}/{java,java-zip} +# and similarly for other packages. + %define is_release_build() %( if [ "%{?1}" == "%{debug_suffix_unquoted}" -o "%{?1}" == "%{fastdebug_suffix_unquoted}" ]; then echo "0" ; else echo "1"; fi ) # Indicates whether this is the default JDK on this version of RHEL @@ -309,13 +417,8 @@ %global with_systemtap 0 %endif -# New Version-String scheme-style defines -%global featurever 21 -%global interimver 0 -%global updatever 11 -%global patchver 0 # We don't add any LTS designator for STS packages (Fedora and EPEL). -# We need to explicitly exclude EPEL as it would have the %%{rhel} macro defined. +# We need to explicitly exclude EPEL as it has the rhel macro defined. %if 0%{?rhel} && !0%{?epel} %global lts_designator "LTS" %global lts_designator_zip -%{lts_designator} @@ -327,7 +430,8 @@ # Define vendor information used by OpenJDK %global oj_vendor Red Hat, Inc. %global oj_vendor_url https://www.redhat.com/ -# Define what url should JVM offer in case of a crash report + +# Define what url the JVM should offer in case of a crash report # order may be important, epel may have rhel declared %if 0%{?epel} %global oj_vendor_bug_url https://bugzilla.redhat.com/enter_bug.cgi?product=Fedora%20EPEL&component=%{name}&version=epel%{epel} @@ -345,42 +449,6 @@ %endif %global oj_vendor_version (Red_Hat-%{version}-%{portablerelease}) -# Define IcedTea version used for SystemTap tapsets and desktop file -%global icedteaver 6.0.0pre00-c848b93a8598 -# Define current Git revision for the FIPS support patches -%global fipsver feef2dc3ca7 -# Define JDK versions -%global newjavaver %{featurever}.%{interimver}.%{updatever}.%{patchver} -%global javaver %{featurever} -# Strip up to 6 trailing zeros in newjavaver, as the JDK does, to get the correct version used in filenames -%global filever %(svn=%{newjavaver}; for i in 1 2 3 4 5 6 ; do svn=${svn%%.0} ; done; echo ${svn}) -# The tag used to create the OpenJDK tarball -%global vcstag jdk-%{filever}+%{buildver}%{?tagsuffix:-%{tagsuffix}} - -# Define the OS the portable JDK is built on -# This is undefined for CentOS & openjdk-portable-rhel-8 builds and -# equals 'rhel7' for openjdk-portable-rhel-7 builds -%if 0 -%global pkgos rhel7 -%endif - -# Standard JPackage naming and versioning defines -%global origin openjdk -%global origin_nice OpenJDK -%global top_level_dir_name %{vcstag} -%global top_level_dir_name_backup %{top_level_dir_name}-backup -%global buildver 10 -%global rpmrelease 2 -# Settings used by the portable build -%global portablerelease 1 -# Portable suffix differs between RHEL and CentOS -%if 0%{?centos} == 0 -%global portablesuffix %{?pkgos:el7_9}%{!?pkgos:el8} -%else -%global portablesuffix el9 -%endif -%global portablebuilddir /builddir/build/BUILD - # Priority must be 8 digits in total; up to openjdk 1.8, we were using 18..... so when we moved to 11, we had to add another digit %if %is_system_jdk # Using 10 digits may overflow the int used for priority, so we combine the patch and build versions @@ -394,28 +462,6 @@ %global priority %( printf '%08d' 1 ) %endif -# Define milestone (EA for pre-releases, GA for releases) -# Release will be (where N is usually a number starting at 1): -# - 0.N%%{?extraver}%%{?dist} for EA releases, -# - N%%{?extraver}{?dist} for GA releases -%global is_ga 1 -%if %{is_ga} -%global build_type GA -%global ea_designator "" -%global ea_designator_zip %{nil} -%global extraver %{nil} -%global eaprefix %{nil} -%else -%global build_type EA -%global ea_designator ea -%global ea_designator_zip -%{ea_designator} -%global extraver .%{ea_designator} -%global eaprefix 0. -%endif - -# parametrized macros are order-sensitive -%global compatiblename java-%{featurever}-%{origin} -%global fullversion %{compatiblename}-%{version}-%{release} # images directories from upstream build %global jdkimage jdk %global static_libs_image static-libs @@ -465,7 +511,7 @@ %global rpm_state_dir %{_localstatedir}/lib/rpm-state/ # For flatpack builds hard-code /usr/sbin/alternatives, -# otherwise use %%{_sbindir} relative path. +# otherwise use _sbindir relative path. %if 0%{?flatpak} %global alternatives_requires /usr/sbin/alternatives %else @@ -1176,51 +1222,10 @@ Provides: java-%{origin}-src%{?1} = %{epoch}:%{version}-%{release} # Prevent brp-java-repack-jars from being run %global __jar_repack 0 -# Define the root name of the portable packages -%global pkgnameroot java-%{featurever}-%{origin}-portable%{?pkgos:-%{pkgos}} # Define the architectures on which we build ExclusiveArch: %{aarch64} %{ppc64le} s390x x86_64 riscv64 -Name: java-%{javaver}-%{origin} -Version: %{newjavaver}.%{buildver} -Release: %{?eaprefix}%{rpmrelease}%{?extraver}%{?dist} -# Equivalent for the portable build -%global prelease %{?eaprefix}%{portablerelease}%{?extraver} -# java-1.5.0-ibm from jpackage.org set Epoch to 1 for unknown reasons -# and this change was brought into RHEL-4. java-1.5.0-ibm packages -# also included the epoch in their virtual provides. This created a -# situation where in-the-wild java-1.5.0-ibm packages provided "java = -# 1:1.5.0". In RPM terms, "1.6.0 < 1:1.5.0" since 1.6.0 is -# interpreted as 0:1.6.0. So the "java >= 1.6.0" requirement would be -# satisfied by the 1:1.5.0 packages. Thus we need to set the epoch in -# JDK package >= 1.6.0 to 1, and packages referring to JDK virtual -# provides >= 1.6.0 must specify the epoch, "java >= 1:1.6.0". - -Epoch: 1 -Summary: %{origin_nice} %{featurever} Runtime Environment -# Groups are only used up to RHEL 8 and on Fedora versions prior to F30 -%if (0%{?rhel} > 0 && 0%{?rhel} <= 8) || (0%{?fedora} >= 0 && 0%{?fedora} < 30) -Group: Development/Languages -%endif - -# HotSpot code is licensed under GPLv2 -# JDK library code is licensed under GPLv2 with the Classpath exception -# The Apache license is used in code taken from Apache projects (primarily xalan & xerces) -# DOM levels 2 & 3 and the XML digital signature schemas are licensed under the W3C Software License -# The JSR166 concurrency code is in the public domain -# The BSD and MIT licenses are used for a number of third-party libraries (see ADDITIONAL_LICENSE_INFO) -# The OpenJDK source tree includes: -# - JPEG library (IJG), zlib & libpng (zlib), giflib (MIT), harfbuzz (ISC), -# - freetype (FTL), jline (BSD) and LCMS (MIT) -# - jquery (MIT), jdk.crypto.cryptoki PKCS 11 wrapper (RSA) -# - public_suffix_list.dat from publicsuffix.org (MPLv2.0) -# The test code includes copies of NSS under the Mozilla Public License v2.0 -# The PCSClite headers are under a BSD with advertising license -# The elliptic curve cryptography (ECC) source code is licensed under the LGPLv2.1 or any later version -License: ASL 1.1 and ASL 2.0 and BSD and BSD with advertising and GPL+ and GPLv2 and GPLv2 with exceptions and IJG and LGPLv2+ and MIT and MPLv2.0 and Public Domain and W3C and zlib and ISC and FTL and RSA -URL: http://openjdk.java.net/ - # The source tarball, generated using generate_source_tarball.sh Source0: https://openjdk-sources.osci.io/openjdk%{featurever}/open%{vcstag}%{ea_designator_zip}.tar.xz @@ -1294,9 +1299,11 @@ Source30: 0008-Tools.gmk-Use-update-repository-on-RHEL-rather-than-.patch ############################################ # Crypto policy and FIPS support patches + # Patch is generated from the fips-21u tree at https://github.com/rh-openjdk/jdk/tree/fips-21u -# as follows: git diff %%{vcstag} src make test > fips-21u-$(git show -s --format=%h HEAD).patch +# as follows: git diff src make test > fips-21u-$(git show -s --format=%h HEAD).patch # Diff is limited to src and make subdirectories to exclude .github changes + # Fixes currently included: # PR3183, RH1340845: Follow system wide crypto policy # PR3695: Allow use of system crypto policy to be disabled by the user @@ -1426,17 +1433,17 @@ BuildRequires: libpng-devel BuildRequires: zlib-devel %else # Version in src/java.desktop/share/native/libfreetype/include/freetype/freetype.h -Provides: bundled(freetype) = 2.14.2 +Provides: bundled(freetype) = 2.14.3 # Version in src/java.desktop/share/native/libsplashscreen/giflib/gif_lib.h -Provides: bundled(giflib) = 6.1.2 +Provides: bundled(giflib) = 6.1.3 # Version in src/java.desktop/share/native/libharfbuzz/hb-version.h -Provides: bundled(harfbuzz) = 12.3.2 +Provides: bundled(harfbuzz) = 14.2.0 # Version in src/java.desktop/share/native/liblcms/lcms2.h -Provides: bundled(lcms2) = 2.17.0 +Provides: bundled(lcms2) = 2.19.1 # Version in src/java.desktop/share/native/libjavajpeg/jpeglib.h Provides: bundled(libjpeg) = 6b # Version in src/java.desktop/share/native/libsplashscreen/libpng/png.h -Provides: bundled(libpng) = 1.6.57 +Provides: bundled(libpng) = 1.6.58 # Version in src/java.base/share/native/libzip/zlib/zlib.h Provides: bundled(zlib) = 1.3.2 %endif @@ -1809,19 +1816,7 @@ sh %{SOURCE12} %{top_level_dir_name} %endif # Patch the JDK -# This syntax is deprecated: -# %patchN [...] -# and should be replaced with: -# %patch -PN [...] -# For example: -# %patch1001 -p1 -# becomes: -# %patch -P1001 -p1 -# The replacement format suggested by recent (circa Fedora 38) RPM -# deprecation messages: -# %patch N [...] -# is not backward-compatible with prior (circa RHEL-8) versions of -# rpmbuild. + pushd %{top_level_dir_name} # Add crypto policy and FIPS support %patch -P1001 -p1 @@ -2475,6 +2470,58 @@ exit 0 %endif %changelog +* Sat Jul 18 2026 Andrew Hughes - 1:21.0.12.0.8-1.2 +- Bump release for PQC build +- Related: RHEL-212302 +- Related: RHEL-212303 +- Related: RHEL-212304 +- Related: RHEL-151191 +- Related: RHEL-212305 +- Related: RHEL-188872 +- Related: RHEL-212306 +- Related: RHEL-212307 +- Related: RHEL-151162 + +* Sat Jul 18 2026 Andrew Hughes - 1:21.0.12.0.8-1.1 +- Update to jdk-21.0.12+8 (GA) +- Update release notes to 21.0.12+8 +- Bump freetype version to 2.14.3 following JDK-8385390 +- Bump giflib version to 6.1.3 following JDK-8384902 +- Bump HarfBuzz version to 14.2.0 following JDK-8385490 +- Bump lcms2 version to 2.19.1 following JDK-8375065 & JDK-8383354 +- Bump libpng version to 1.6.58 following JDK-8384495 +- Update tagging scripts to include signature checks and correctly handle gating +- Update tagged versions to include 9.8.0-z, 9.9.0, 10.2-z & 10.3. +- Add gating scripts to simplify obtaining results and waiving issues +- Cleanup tagging and gating scripts to appease shellcheck: +- * scripts/builds/build_vanilla.sh: Use an array to handle the varying arguments to rhpkg. +- * scripts/builds/check_signatures.sh: Quote variable usage. +- * scripts/builds/waive_issue.sh: Remove redundant 'test "x"' usage. +- * scripts/builds/waive_leapp_issue.sh: Likewise. +- * scripts/builds/waive_rpminspect.sh: Likewise. +- * scripts/builds/waive_usual_rpminspect.sh: Likewise and add missing WORKING_DIR variable. +- * scripts/builds/waive_usual_tier0.sh: Remove redundant 'test "x"' usage. +- Remove macro references in comments where possible (%dnl not compatible enough yet) +- Move version information and core NVR definitions back towards the top of the file +- Specify portablerelease and rpmrelease (always 0 for portables) in the Release field +- Obsolete old RHEL releases (9.7.0-z, 10.1-z) +- Make zone string debug output optional in TestTranslations +- Sync the copy of the portable specfile with the latest update +- ** This tarball is embargoed until 2026-07-21 @ 1pm PT. ** +- Resolves: RHEL-212302 +- Resolves: RHEL-212303 +- Resolves: RHEL-212304 +- Resolves: RHEL-151191 +- Resolves: RHEL-212305 +- Resolves: RHEL-188872 +- Resolves: RHEL-212306 +- Resolves: RHEL-212307 + +* Sat Jul 18 2026 Thomas Fitzsimmons - 1:21.0.11.0.10-1.3 +- Disable abidiff inspection in rpminspect.yaml to avoid an out-of-memory error on the CentOS test farm +- See: https://docs.testing-farm.io/Testing%20Farm/0.1/errors.html#TFE-1 +- Resolves: RHEL-151162 + * Mon Apr 20 2026 Andrew Hughes - 1:21.0.11.0.10-2 - Bump release for PQC build - Related: RHEL-169611 diff --git a/sources b/sources index 2ed9e11..bea9cce 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (openjdk-21.0.11+10.tar.xz) = 65f20c20040a146d5c7477536d7f479d79459fc676b0ed2df2aa42704e9c12e455e748704ee1dac60ef97014cb91136265f8fd4ee10d4673368db99b18dec61f +SHA512 (openjdk-21.0.12+8.tar.xz) = 514c28f1819b12fb6f5a04c3ebc4358d8694135dc9566314dfe7368485e947f0f03e1835f069d0e989768537e953e4b3cd16f294289f6d4e2fbf74fffe9886d8 SHA512 (tapsets-icedtea-6.0.0pre00-c848b93a8598.tar.xz) = 97d026212363b3c83f6a04100ad7f6fdde833d16579717f8756e2b8c2eb70e144a41a330cb9ccde9c3badd37a2d54fdf4650a950ec21d8b686d545ecb2a64d30