Compare commits

...

8 Commits
c10s ... a10

Author SHA1 Message Date
Eduard Abdullin
9d9f159540 Use el9 portable packages 2026-07-23 11:00:07 +00:00
Eduard Abdullin
85d70d1866 Use el9 portable packages 2026-07-23 07:32:47 +00:00
AlmaLinux RelEng Bot
d7bf41b302 import UBI java-25-openjdk-25.0.4.0.7-1.1.el10_2 2026-07-22 20:08:48 -04:00
AlmaLinux RelEng Bot
c4cdb2e1bb import UBI java-25-openjdk-25.0.3.0.9-1.el10_2 2026-04-22 19:03:30 -04:00
AlmaLinux RelEng Bot
716dbac5d3 import UBI java-25-openjdk-25.0.2.0.10-4.el10_2 2026-03-30 13:09:01 -04:00
34aa7b5a28 import UBI java-25-openjdk-25.0.2.0.10-1.el10 2026-01-26 17:02:39 +00:00
94d175ddcc import UBI java-25-openjdk-25.0.1.0.8-6.el10 2026-01-05 12:05:30 +00:00
f4b2e144e5 import UBI java-25-openjdk-25.0.1.0.8-2.el10 2025-11-17 23:36:11 +00:00
27 changed files with 3625 additions and 1717 deletions

48
.gitignore vendored
View File

@ -1,45 +1,3 @@
/openjdk-jdk17u-jdk-17.0.7+7.tar.xz nssadapter-0.1.1.tar.xz
/tapsets-icedtea-6.0.0pre00-c848b93a8598.tar.xz openjdk-25.0.4+7.tar.xz
/openjdk-jdk18u-jdk-18.0.1+0.tar.xz tapsets-icedtea-6.0.0pre00-c848b93a8598.tar.xz
/openjdk-jdk18u-jdk-18.0.1+10.tar.xz
/openjdk-jdk18u-jdk-18.0.1.1+2.tar.xz
/openjdk-jdk18u-jdk-18.0.2+9.tar.xz
/openjdk-jdk19u-jdk-19+36.tar.xz
/openjdk-jdk19u-jdk-19.0.1+10.tar.xz
/openjdk-jdk19u-jdk-19.0.2+7.tar.xz
/openjdk-jdk20u-jdk-20+36.tar.xz
/openjdk-jdk20u-jdk-20.0.1+9.tar.xz
/openjdk-jdk20u-jdk-20.0.2+9.tar.xz
/openjdk-jdk21u-jdk-21+35.tar.xz
/openjdk-21.0.1+12.tar.xz
/openjdk-21.0.2+11.tar.xz
/openjdk-21.0.2+12.tar.xz
/openjdk-21.0.2+13.tar.xz
/openjdk-21.0.3+1-ea.tar.xz
/openjdk-21.0.3+7-ea.tar.xz
/openjdk-21.0.3+9.tar.xz
/openjdk-21.0.4+1-ea.tar.xz
/openjdk-21.0.4+5-ea.tar.xz
/openjdk-21.0.4+7.tar.xz
/openjdk-21.0.5+1-ea.tar.xz
/openjdk-21.0.5+5-ea.tar.xz
/openjdk-21.0.5+9-ea.tar.xz
/openjdk-21.0.5+10.tar.xz
/openjdk-21.0.5+11.tar.xz
/openjdk-21.0.6+6-ea.tar.xz
/openjdk-21.0.6+7.tar.xz
/openjdk-21.0.7+1-ea.tar.xz
/openjdk-21.0.7+2-ea.tar.xz
/openjdk-21.0.7+3-ea.tar.xz
/openjdk-21.0.7+4-ea.tar.xz
/openjdk-21.0.7+5-ea.tar.xz
/openjdk-21.0.7+6.tar.xz
/openjdk-21.0.8+1-ea.tar.xz
/openjdk-21.0.8+2-ea.tar.xz
/openjdk-21.0.8+8-ea.tar.xz
/openjdk-21.0.8+9.tar.xz
/openjdk-22.0.2+9.tar.xz
/openjdk-23.0.2+7.tar.xz
/openjdk-24.0.2+12.tar.xz
/openjdk-25+36.tar.xz
/openjdk-25.0.1+8.tar.xz

1190
NEWS

File diff suppressed because it is too large Load Diff

View File

@ -21,15 +21,32 @@ import java.security.Security;
import java.util.Properties; import java.util.Properties;
public class TestSecurityProperties { public class TestSecurityProperties {
private static final String JAVA_HOME = System.getProperty("java.home");
// JDK 11 // JDK 11
private static final String JDK_PROPS_FILE_JDK_11 = System.getProperty("java.home") + "/conf/security/java.security"; private static final String JDK_PROPS_FILE_JDK_11 = JAVA_HOME + "/conf/security/java.security";
// JDK 8 // JDK 8
private static final String JDK_PROPS_FILE_JDK_8 = System.getProperty("java.home") + "/lib/security/java.security"; private static final String JDK_PROPS_FILE_JDK_8 = JAVA_HOME + "/lib/security/java.security";
// JDK 25
// Omit fips.properties files since they are not relevant to this test.
// Omit JAVA_HOME + "/conf/security/redhat/crypto-policies.properties" which simply includes
// true/crypto-policies.properties in case redhat.crypto-policies is left undefined.
private static final String[] JDK_PROPS_FILES_JDK_25_ENABLED = {
JAVA_HOME + "/conf/security/redhat/true/crypto-policies.properties",
"/etc/crypto-policies/back-ends/java.config"
};
private static final String[] JDK_PROPS_FILES_JDK_25_DISABLED = {
JAVA_HOME + "/conf/security/redhat/false/crypto-policies.properties"
};
private static final String POLICY_FILE = "/etc/crypto-policies/back-ends/java.config"; private static final String POLICY_FILE = "/etc/crypto-policies/back-ends/java.config";
private static final String MSG_PREFIX = "DEBUG: "; private static final String MSG_PREFIX = "DEBUG: ";
private static final String javaVersion = System.getProperty("java.version");
// float for java 1.8
private static final float JAVA_FEATURE = Float.parseFloat(System.getProperty("java.specification.version"));
public static void main(String[] args) { public static void main(String[] args) {
if (args.length == 0) { if (args.length == 0) {
System.err.println("TestSecurityProperties <true|false>"); System.err.println("TestSecurityProperties <true|false>");
@ -40,18 +57,24 @@ public class TestSecurityProperties {
boolean enabled = Boolean.valueOf(args[0]); boolean enabled = Boolean.valueOf(args[0]);
System.out.println(MSG_PREFIX + "System security properties enabled: " + enabled); System.out.println(MSG_PREFIX + "System security properties enabled: " + enabled);
Properties jdkProps = new Properties(); Properties jdkProps = new Properties();
loadProperties(jdkProps); loadProperties(jdkProps, enabled);
if (enabled) { if (enabled) {
loadPolicy(jdkProps); loadPolicy(jdkProps);
} }
for (Object key: jdkProps.keySet()) { for (Object key : jdkProps.keySet()) {
String sKey = (String)key; String sKey = (String) key;
if (JAVA_FEATURE >= 25 && sKey.equals("include")) {
// Avoid the following exception on 25: IllegalArgumentException: Key 'include' is
// reserved and cannot be used as a Security property name. Hard-code the includes
// in JDK_PROPS_FILES_JDK_25_ENABLED and JDK_PROPS_FILES_JDK_25_DISABLED instead.
continue;
}
System.out.println(MSG_PREFIX + "Checking " + sKey); System.out.println(MSG_PREFIX + "Checking " + sKey);
String securityVal = Security.getProperty(sKey); String securityVal = Security.getProperty(sKey);
String jdkSecVal = jdkProps.getProperty(sKey); String jdkSecVal = jdkProps.getProperty(sKey);
if (!jdkSecVal.equals(securityVal)) { if (!jdkSecVal.equals(securityVal)) {
String msg = "Expected value '" + jdkSecVal + "' for key '" + String msg = "Expected value '" + jdkSecVal + "' for key '" +
sKey + "'" + " but got value '" + securityVal + "'"; sKey + "'" + " but got value '" + securityVal + "'";
throw new RuntimeException("Test failed! " + msg); throw new RuntimeException("Test failed! " + msg);
} else { } else {
System.out.println(MSG_PREFIX + sKey + " = " + jdkSecVal + " as expected."); System.out.println(MSG_PREFIX + sKey + " = " + jdkSecVal + " as expected.");
@ -60,17 +83,26 @@ public class TestSecurityProperties {
System.out.println("TestSecurityProperties PASSED!"); System.out.println("TestSecurityProperties PASSED!");
} }
private static void loadProperties(Properties props) { private static void loadPropertiesFile(Properties props, String propsFile) {
String javaVersion = System.getProperty("java.version"); try (FileInputStream fin = new FileInputStream(propsFile)) {
props.load(fin);
} catch (Exception e) {
throw new RuntimeException("Test failed!", e);
}
}
private static void loadProperties(Properties props, boolean enabled) {
System.out.println(MSG_PREFIX + "Java version is " + javaVersion); System.out.println(MSG_PREFIX + "Java version is " + javaVersion);
String propsFile = JDK_PROPS_FILE_JDK_11; String propsFile = JDK_PROPS_FILE_JDK_11;
if (javaVersion.startsWith("1.8.0")) { if (javaVersion.startsWith("1.8.0")) {
propsFile = JDK_PROPS_FILE_JDK_8; propsFile = JDK_PROPS_FILE_JDK_8;
} }
try (FileInputStream fin = new FileInputStream(propsFile)) { loadPropertiesFile(props, propsFile);
props.load(fin); if (JAVA_FEATURE >= 25) {
} catch (Exception e) { for (String file : enabled ? JDK_PROPS_FILES_JDK_25_ENABLED : JDK_PROPS_FILES_JDK_25_DISABLED) {
throw new RuntimeException("Test failed!", e); System.out.println(MSG_PREFIX + "Loading " + file);
loadPropertiesFile(props, file);
}
} }
} }
@ -83,3 +115,17 @@ public class TestSecurityProperties {
} }
} }
/*
* Local Variables:
* compile-command: "\
* /usr/lib/jvm/java-25-openjdk/bin/javac TestSecurityProperties.java \
* && (/usr/lib/jvm/java-25-openjdk/bin/java TestSecurityProperties false ; [[ $? == 1 ]]) \
* && (/usr/lib/jvm/java-25-openjdk/bin/java -Dredhat.crypto-policies=true TestSecurityProperties false ; [[ $? == 1 ]]) \
* && (/usr/lib/jvm/java-25-openjdk/bin/java -Dredhat.crypto-policies=false TestSecurityProperties true ; [[ $? == 1 ]]) \
* && /usr/lib/jvm/java-25-openjdk/bin/java TestSecurityProperties true \
* && /usr/lib/jvm/java-25-openjdk/bin/java -Dredhat.crypto-policies=true TestSecurityProperties true \
* && /usr/lib/jvm/java-25-openjdk/bin/java -Dredhat.crypto-policies=false TestSecurityProperties false" \
* fill-column: 124
* End:
*/

View File

@ -1,5 +1,5 @@
/* TestTranslations -- Ensure translations are available for new timezones /* TestTranslations -- Ensure translations are available for new timezones
Copyright (C) 2022 Red Hat, Inc. Copyright (C) 2026 Red Hat, Inc.
This program is free software: you can redistribute it and/or modify This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as it under the terms of the GNU Affero General Public License as
@ -50,25 +50,38 @@ public class TestTranslations {
"Mountain Daylight Time", "MDT", "MDT", "Mountain Daylight Time", "MDT", "MDT",
"Mountain Time", "MT", "MT"}); "Mountain Time", "MT", "MT"});
map.put(Locale.FRANCE, new String[] { "heure normale des Rocheuses", "UTC\u221207:00", "MST", map.put(Locale.FRANCE, new String[] { "heure normale des Rocheuses", "UTC\u221207:00", "MST",
"heure d\u2019\u00e9t\u00e9 des Rocheuses", "UTC\u221206:00", "MST", "heure d\u2019\u00e9t\u00e9 des Rocheuses", "UTC\u221206:00", "MDT",
"heure des Rocheuses", "UTC\u221207:00", "MST"}); "heure des Rocheuses", "UTC\u221207:00", "MT"});
map.put(Locale.GERMANY, new String[] { "Rocky-Mountains-Normalzeit", "GMT-07:00", "MST", map.put(Locale.GERMANY, new String[] { "Rocky-Mountains-Normalzeit", "GMT-07:00", "MST",
"Rocky-Mountains-Sommerzeit", "GMT-06:00", "MST", "Rocky-Mountains-Sommerzeit", "GMT-06:00", "MDT",
"Rocky-Mountains-Zeit", "GMT-07:00", "MST"}); "Rocky-Mountains-Zeit", "GMT-07:00", "MT"});
CIUDAD_JUAREZ = Collections.unmodifiableMap(map); CIUDAD_JUAREZ = Collections.unmodifiableMap(map);
} }
public static void main(String[] args) { public static void main(String[] args) {
if (args.length < 1) { boolean debug = false;
System.err.println("Test must be started with the name of the locale provider.");
System.exit(1); if (args.length > 0) {
debug = Boolean.parseBoolean(args[0]);
} }
System.err.printf("Debugging: %s\n", debug);
testZoneStrings(debug);
testZone(KYIV,
new String[] { "Europe/Kiev", "Europe/Kyiv", "Europe/Uzhgorod", "Europe/Zaporozhye" });
testZone(CIUDAD_JUAREZ,
new String[] { "America/Cambridge_Bay", "America/Ciudad_Juarez" });
}
private static void testZoneStrings(final boolean debug) {
System.out.println("Checking sanity of full zone string set..."); System.out.println("Checking sanity of full zone string set...");
boolean invalid = Arrays.stream(Locale.getAvailableLocales()) boolean invalid = Arrays.stream(Locale.getAvailableLocales())
.peek(l -> System.out.println("Locale: " + l)) .peek(l -> System.out.printf(debug ? "Locale: %s\n" : "", l))
.map(l -> DateFormatSymbols.getInstance(l).getZoneStrings()) .map(l -> DateFormatSymbols.getInstance(l).getZoneStrings())
.peek(df -> System.out.printf(debug ? "Zone string size: %s\n" : "", df.length))
.flatMap(zs -> Arrays.stream(zs)) .flatMap(zs -> Arrays.stream(zs))
.flatMap(names -> Arrays.stream(names)) .flatMap(names -> Arrays.stream(names))
.filter(name -> Objects.isNull(name) || name.isEmpty()) .filter(name -> Objects.isNull(name) || name.isEmpty())
@ -78,15 +91,9 @@ public class TestTranslations {
System.err.println("Zone string for a locale returned null or empty string"); System.err.println("Zone string for a locale returned null or empty string");
System.exit(2); System.exit(2);
} }
String localeProvider = args[0];
testZone(localeProvider, KYIV,
new String[] { "Europe/Kiev", "Europe/Kyiv", "Europe/Uzhgorod", "Europe/Zaporozhye" });
testZone(localeProvider, CIUDAD_JUAREZ,
new String[] { "America/Cambridge_Bay", "America/Ciudad_Juarez" });
} }
private static void testZone(String localeProvider, Map<Locale,String[]> exp, String[] ids) { private static void testZone(Map<Locale,String[]> exp, String[] ids) {
for (Locale l : exp.keySet()) { for (Locale l : exp.keySet()) {
String[] expected = exp.get(l); String[] expected = exp.get(l);
System.out.printf("Expected values for %s are %s\n", l, Arrays.toString(expected)); System.out.printf("Expected values for %s are %s\n", l, Arrays.toString(expected));
@ -97,16 +104,11 @@ public class TestTranslations {
System.out.printf("Checking locale %s for %s...\n", l, id); System.out.printf("Checking locale %s for %s...\n", l, id);
if ("JRE".equals(localeProvider) || "CLDR".equals(localeProvider)) { expectedShortStd = expected[2];
expectedShortStd = expected[2]; expectedShortDST = expected[5];
expectedShortDST = expected[5]; expectedShortGen = expected[8];
expectedShortGen = expected[8]; System.out.printf("Using short values %s, %s and %s\n",
} else { expectedShortStd, expectedShortDST, expectedShortGen);
System.err.printf("Invalid locale provider %s\n", localeProvider);
System.exit(3);
}
System.out.printf("Locale Provider is %s, using short values %s, %s and %s\n",
localeProvider, expectedShortStd, expectedShortDST, expectedShortGen);
String longStd = TimeZone.getTimeZone(id).getDisplayName(false, TimeZone.LONG, l); String longStd = TimeZone.getTimeZone(id).getDisplayName(false, TimeZone.LONG, l);
String shortStd = TimeZone.getTimeZone(id).getDisplayName(false, TimeZone.SHORT, l); String shortStd = TimeZone.getTimeZone(id).getDisplayName(false, TimeZone.SHORT, l);

View File

@ -0,0 +1,168 @@
#!/bin/bash
#
# Create Red Hat OpenJDK security properties directory hierarchy.
#
# Copyright (C) 2025 IBM Corporation. All rights reserved.
#
# Written by:
# Francisco Ferrari Bihurriet <fferrari@redhat.com>
# Thomas Fitzsimmons <fitzsim@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
#
# Usage:
#
# bash create-redhat-properties-files.bash <target directory> <nssadapter path>
#
# Example usage in spec file:
#
# bash -x create-redhat-properties-files.bash ${installdir}/conf/security \
# %{_libdir}/%{sdkdir -- ${suffix}}/libnssadapter.so
#
# When you make changes to the file set here, also update the %files
# section in the spec file, and the JDK_PROPS_FILES_JDK_25 variables
# in TestSecurityProperties.java.
[[ $# == 2 ]] || exit 1
SECURITY="${1}"
NSSADAPTER="${2}"
VENDOR="${SECURITY}"/redhat
install --directory --mode=755 "${VENDOR}"
install --directory --mode=755 "${VENDOR}"/true
install --directory --mode=755 "${VENDOR}"/false
# /usr/lib/jvm/java-25-openjdk/conf/security/redhat/SunPKCS11-FIPS.cfg
install --mode 644 /dev/stdin "${VENDOR}"/SunPKCS11-FIPS.cfg <<EOF
name = FIPS
library = ${NSSADAPTER}
slot = 3
nssUseSecmod = false
attributes(*,CKO_SECRET_KEY,*)={ CKA_SIGN=true CKA_ENCRYPT=true }
EOF
# /usr/lib/jvm/java-25-openjdk/conf/security/redhat/false/crypto-policies.properties
install --mode 644 /dev/stdin "${VENDOR}"/false/crypto-policies.properties <<'EOF'
# Empty on purpose, for ${redhat.crypto-policies}=false
EOF
# /usr/lib/jvm/java-25-openjdk/conf/security/redhat/true/crypto-policies.properties
install --mode 644 /dev/stdin "${VENDOR}"/true/crypto-policies.properties <<'EOF'
#
# Apply the system-wide crypto policy
#
include /etc/crypto-policies/back-ends/java.config
#
# Apply the FIPS-specific security properties, if needed
#
include ../${__redhat_fips__}/fips.properties
EOF
# /usr/lib/jvm/java-25-openjdk/conf/security/redhat/crypto-policies.properties
install --mode 644 /dev/stdin "${VENDOR}"/crypto-policies.properties <<'EOF'
#
# Default choice for the crypto-policies setup
#
include true/crypto-policies.properties
EOF
# /usr/lib/jvm/java-25-openjdk/conf/security/redhat/false/fips.properties
install --mode 644 /dev/stdin "${VENDOR}"/false/fips.properties <<'EOF'
# Empty on purpose, for when FIPS is disabled.
EOF
# /usr/lib/jvm/java-25-openjdk/conf/security/redhat/true/fips.properties
install --mode 644 /dev/stdin "${VENDOR}"/true/fips.properties <<'EOF'
#
# Enable the downstream-patch RedHatFIPSFilter code
#
__redhat_fips_filter__=true
#
# FIPS mode Security Providers List
#
security.provider.1=SunPKCS11 ${java.home}/conf/security/redhat/SunPKCS11-FIPS.cfg
security.provider.2=SUN
security.provider.3=SunEC
security.provider.4=SunJSSE
security.provider.5=SunJCE
security.provider.6=SunRsaSign
security.provider.7=XMLDSig
security.provider.8=
# ^ empty on purpose, to finish the Providers List
#
# FIPS mode default keystore type
#
keystore.type=pkcs12
EOF
# Make sure java.security exists before appending
test -e "${SECURITY}"/java.security || ( echo "${SECURITY}/java.security not found" && false )
cat >> "${SECURITY}"/java.security <<'EOF'
#
# System-wide crypto-policies and FIPS setup
#
# The following crypto-policies setup automatically detects when the system
# is in FIPS mode and configures OpenJDK accordingly. If OpenJDK needs to
# ignore the system and disable its FIPS setup, just disable the usage of
# the system crypto-policies, by any of the methods described below.
#
# The redhat.crypto-policies system property is a boolean switch that
# controls the usage on a per-run basis. For example, pass
# -Dredhat.crypto-policies=false to disable the system crypto-policies.
#
# This setup consists of the following files in $JAVA_HOME/conf/security:
#
# 'redhat/false/crypto-policies.properties' (policies usage disabled file)
# Empty file, applied when the boolean switch is passed as false.
#
# 'redhat/true/crypto-policies.properties' (policies usage enabled file)
# Performs the crypto-policies and FIPS setup, applied when the boolean
# switch is passed as true.
#
# 'redhat/crypto-policies.properties' (policies usage default file)
# Determines the default choice by including one of the previous files,
# applied when the boolean switch is not passed.
# The system crypto-policies usage is enabled by default:
# include true/crypto-policies.properties
#
# To enable or disable the usage of the crypto-policies on a per-deployment
# basis, edit the policies usage default file, changing the included file.
# For example, execute the following command to persistently disable the
# crypto-policies:
# sed -i s/true/false/ $JAVA_HOME/conf/security/redhat/crypto-policies.properties
# Applications can still override this on a per-run basis, for example by
# passing -Dredhat.crypto-policies=true.
#
# To disable the redhat.crypto-policies boolean switch, modify the following
# include directive as follows. Replace ${redhat.crypto-policies} by true to
# force-apply the system crypto-policies:
# include redhat/true/crypto-policies.properties
# Remove or comment out the include directive to force-disable the setup:
# #include redhat/${redhat.crypto-policies}/crypto-policies.properties
#
include redhat/${redhat.crypto-policies}/crypto-policies.properties
# ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
# WARNING: anything placed after this include directive will apply on top
# of the described setup. Adding properties below this section is strongly
# discouraged, as it poses a risk of overriding the system crypto-policies
# or invalidating the FIPS deployment.
EOF
# Local Variables:
# compile-command: "shellcheck create-redhat-properties-files.bash"
# End:

View File

@ -0,0 +1,87 @@
diff --git a/src/java.base/share/classes/java/security/Provider.java b/src/java.base/share/classes/java/security/Provider.java
index de2845fb550..60eeab678ca 100644
--- a/src/java.base/share/classes/java/security/Provider.java
+++ b/src/java.base/share/classes/java/security/Provider.java
@@ -1203,6 +1203,34 @@ public Set<Service> getServices() {
return serviceSet;
}
+ /* vvvvvvvvvvvvvvvvvvvvvvvvvvvvv FIPS PATCH vvvvvvvvvvvvvvvvvvvvvvvvvvvvv */
+ private static final class RedHatFIPSFilter {
+ static final boolean IS_ON = Boolean.parseBoolean(
+ Security.getProperty("__redhat_fips_filter__"));
+ private static final Map<String, Set<String>> ALLOW_LIST = Map.of(
+ "SUN", Set.of(
+ "AlgorithmParameterGenerator",
+ "AlgorithmParameters", "CertificateFactory",
+ "CertPathBuilder", "CertPathValidator", "CertStore",
+ "Configuration", "KeyStore"),
+ "SunEC", Set.of(
+ "AlgorithmParameters", "KeyFactory"),
+ "SunJCE", Set.of(
+ "AlgorithmParameters",
+ "AlgorithmParameterGenerator", "KeyFactory",
+ "SecretKeyFactory"),
+ "SunRsaSign", Set.of(
+ "KeyFactory", "AlgorithmParameters")
+ );
+
+ static boolean isAllowed(String provName, String serviceType) {
+ Set<String> allowedServiceTypes = ALLOW_LIST.get(provName);
+ return allowedServiceTypes == null ||
+ allowedServiceTypes.contains(serviceType);
+ }
+ }
+ /* ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ FIPS PATCH ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ */
+
/**
* Add a service. If a service of the same type with the same algorithm
* name exists, and it was added using {@link #putService putService()},
@@ -1231,6 +1259,15 @@ protected void putService(Service s) {
("service.getProvider() must match this Provider object");
}
String type = s.getType();
+ /* vvvvvvvvvvvvvvvvvvvvvvvvvvv FIPS PATCH vvvvvvvvvvvvvvvvvvvvvvvvvvv */
+ if (RedHatFIPSFilter.IS_ON && !RedHatFIPSFilter.isAllowed(name, type)) {
+ if (debug != null) {
+ debug.println("The previous " + name + ".putService() call " +
+ "was skipped by " + RedHatFIPSFilter.class.getName());
+ }
+ return;
+ }
+ /* ^^^^^^^^^^^^^^^^^^^^^^^^^^^ FIPS PATCH ^^^^^^^^^^^^^^^^^^^^^^^^^^^ */
String algorithm = s.getAlgorithm();
ServiceKey key = new ServiceKey(type, algorithm, true);
implRemoveService(serviceMap.get(key));
diff --git a/src/java.base/share/classes/java/security/Security.java b/src/java.base/share/classes/java/security/Security.java
index 6969fe8a8e1..4501d5971c4 100644
--- a/src/java.base/share/classes/java/security/Security.java
+++ b/src/java.base/share/classes/java/security/Security.java
@@ -323,7 +323,27 @@ public Properties getInitialProperties() {
}
private static void initialize() {
+ /* vvvvvvvvvvvvvvvvvvvvvvvvvvv FIPS PATCH vvvvvvvvvvvvvvvvvvvvvvvvvvv */
+ /* This 'include'-directives-only magic property is an internal */
+ /* implementation detail that could (and probably will!) change. */
+ /* Red Hat customers should NOT rely on this for their own use. */
+ String fipsKernelFlag = "/proc/sys/crypto/fips_enabled";
+ boolean fipsModeOn;
+ try (InputStream is = new java.io.FileInputStream(fipsKernelFlag)) {
+ fipsModeOn = is.read() == '1';
+ } catch (IOException ioe) {
+ fipsModeOn = false;
+ if (sdebug != null) {
+ sdebug.println("Failed to read FIPS kernel file: " + ioe);
+ }
+ }
+ String fipsMagicPropName = "__redhat_fips__";
+ System.setProperty(fipsMagicPropName, "" + fipsModeOn);
+ /* ^^^^^^^^^^^^^^^^^^^^^^^^^^^ FIPS PATCH ^^^^^^^^^^^^^^^^^^^^^^^^^^^ */
SecPropLoader.loadAll();
+ /* vvvvvvvvvvvvvvvvvvvvvvvvvvv FIPS PATCH vvvvvvvvvvvvvvvvvvvvvvvvvvv */
+ System.clearProperty(fipsMagicPropName);
+ /* ^^^^^^^^^^^^^^^^^^^^^^^^^^^ FIPS PATCH ^^^^^^^^^^^^^^^^^^^^^^^^^^^ */
initialSecurityProperties = (Properties) props.clone();
if (sdebug != null) {
for (String key : props.stringPropertyNames()) {

View File

@ -1,7 +0,0 @@
# recipients: java-qa
--- !Policy
product_versions:
- rhel-10
decision_context: osci_compose_gate
rules:
- !PassingTestCaseRule {test_case_name: osci.brew-build.tier0.functional}

View File

@ -1,4 +1,97 @@
# debug_package %%{nil} is portable-jdks specific # New Version-String scheme-style defines
%global featurever 25
%global interimver 0
%global updatever 4
%global patchver 0
%global buildver 7
%global portablerelease 1
%global rpmrelease 0
# Define IcedTea version used for SystemTap tapsets and desktop file
%global icedteaver 6.0.0pre00-c848b93a8598
# Define current Git revision for the FIPS support patches
%global fipsver 57722aab802
# Define JDK versions
%global newjavaver %{featurever}.%{interimver}.%{updatever}.%{patchver}
%global javaver %{featurever}
# Strip up to 6 trailing zeros in newjavaver, as the JDK does, to get the correct version used in filenames
%global filever %(svn=%{newjavaver}; for i in 1 2 3 4 5 6 ; do svn=${svn%%.0} ; done; echo ${svn})
# The tag used to create the OpenJDK tarball
%global vcstag jdk-%{filever}+%{buildver}%{?tagsuffix:-%{tagsuffix}}
# Standard JPackage naming and versioning defines
%global origin openjdk
%global origin_nice OpenJDK
%global top_level_dir_name %{vcstag}
%global top_level_dir_name_backup %{top_level_dir_name}-backup
# Define an optional suffix for the OS this package is built on
%if 0%{?rhel} == 7
%global pkgos rhel7
%endif
# Define milestone (EA for pre-releases, GA for releases)
# Release will be (where N is usually a number starting at 1):
# - 0.N.ea<dist> for EA releases,
# - N<dist> for GA releases
%global is_ga 1
%if %{is_ga}
%global build_type GA
%global ea_designator ""
%global ea_designator_zip %{nil}
%global extraver %{nil}
%global eaprefix %{nil}
%else
%global build_type EA
%global ea_designator ea
%global ea_designator_zip -%{ea_designator}
%global extraver .%{ea_designator}
%global eaprefix 0.
%endif
%global compatiblename java-%{javaver}-%{origin}
Name: %{compatiblename}-portable%{?pkgos:-%{pkgos}}
Version: %{newjavaver}.%{buildver}
Release: %{?eaprefix}%{portablerelease}.%{rpmrelease}%{?extraver}%{?dist}
%global fullversion %{compatiblename}-%{version}-%{release}
# java-1.5.0-ibm from jpackage.org set Epoch to 1 for unknown reasons
# and this change was brought into RHEL-4. java-1.5.0-ibm packages
# also included the epoch in their virtual provides. This created a
# situation where in-the-wild java-1.5.0-ibm packages provided "java =
# 1:1.5.0". In RPM terms, "1.6.0 < 1:1.5.0" since 1.6.0 is
# interpreted as 0:1.6.0. So the "java >= 1.6.0" requirement would be
# satisfied by the 1:1.5.0 packages. Thus we need to set the epoch in
# JDK package >= 1.6.0 to 1, and packages referring to JDK virtual
# provides >= 1.6.0 must specify the epoch, "java >= 1:1.6.0".
Epoch: 1
Summary: %{origin_nice} %{featurever} Runtime Environment portable edition
# Groups are only used up to RHEL 8 and on Fedora versions prior to F30
%if (0%{?rhel} > 0 && 0%{?rhel} <= 8) || (0%{?fedora} >= 0 && 0%{?fedora} < 30)
Group: Development/Languages
%endif
# HotSpot code is licensed under GPLv2
# JDK library code is licensed under GPLv2 with the Classpath exception
# The Apache license is used in code taken from Apache projects (primarily xalan & xerces)
# DOM levels 2 & 3 and the XML digital signature schemas are licensed under the W3C Software License
# The JSR166 concurrency code is in the public domain
# The BSD and MIT licenses are used for a number of third-party libraries (see ADDITIONAL_LICENSE_INFO)
# The OpenJDK source tree includes:
# - JPEG library (IJG), zlib & libpng (zlib), giflib (MIT), harfbuzz (ISC),
# - freetype (FTL), jline (BSD) and LCMS (MIT)
# - jquery (MIT), jdk.crypto.cryptoki PKCS 11 wrapper (RSA)
# - public_suffix_list.dat from publicsuffix.org (MPLv2.0)
# The test code includes copies of NSS under the Mozilla Public License v2.0
# The PCSClite headers are under a BSD with advertising license
# The elliptic curve cryptography (ECC) source code is licensed under the LGPLv2.1 or any later version
License: ASL 1.1 and ASL 2.0 and BSD and BSD with advertising and GPL+ and GPLv2 and GPLv2 with exceptions and IJG and LGPLv2+ and MIT and MPLv2.0 and Public Domain and W3C and zlib and ISC and FTL and RSA
URL: http://openjdk.java.net/
# We are producing RPMs containing only tarballs
# and checksums so there are no binaries outside
# the tarballs to be processed for debuginfo
%define debug_package %{nil} %define debug_package %{nil}
# RPM conditionals so as to be able to dynamically produce # RPM conditionals so as to be able to dynamically produce
@ -96,25 +189,6 @@
%global normal_build %{nil} %global normal_build %{nil}
%endif %endif
# We have hardcoded list of files, which is appearing in alternatives, and in files
# in alternatives those are slaves and master, very often triplicated by man pages
# in files all masters and slaves are ghosted
# the ghosts are here to allow installation via query like `dnf install /usr/bin/java`
# you can list those files, with appropriate sections: cat *.spec | grep -e --install -e --slave -e post_
# TODO - fix those hardcoded lists via single list
# Those files must *NOT* be ghosted for *slowdebug* packages
# FIXME - if you are moving jshell or jlink or similar, always modify all three sections
# you can check via headless and devels:
# rpm -ql --noghost java-11-openjdk-headless-11.0.1.13-8.fc29.x86_64.rpm | grep bin
# == rpm -ql java-11-openjdk-headless-slowdebug-11.0.1.13-8.fc29.x86_64.rpm | grep bin
# != rpm -ql java-11-openjdk-headless-11.0.1.13-8.fc29.x86_64.rpm | grep bin
# similarly for other %%{_jvmdir}/{jre,java} and %%{_javadocdir}/{java,java-zip}
%define is_release_build() %( if [ "%{?1}" == "%{debug_suffix_unquoted}" -o "%{?1}" == "%{fastdebug_suffix_unquoted}" ]; then echo "0" ; else echo "1"; fi )
# while JDK is a techpreview(is_system_jdk=0), some provides are turned off. Once jdk stops to be an techpreview, move it to 1
# as sytem JDK, we mean any JDK which can run whole system java stack without issues (like bytecode issues, module issues, dependencies...)
%global is_system_jdk 0
%global aarch64 aarch64 arm64 armv8 %global aarch64 aarch64 arm64 armv8
# we need to distinguish between big and little endian PPC64 # we need to distinguish between big and little endian PPC64
%global ppc64le ppc64le %global ppc64le ppc64le
@ -226,7 +300,7 @@
# other targets since this target is configured to use in-tree # other targets since this target is configured to use in-tree
# AWT dependencies: lcms, libjpeg, libpng, libharfbuzz, giflib # AWT dependencies: lcms, libjpeg, libpng, libharfbuzz, giflib
# and possibly others # and possibly others
%global static_libs_target static-libs-image %global static_libs_target static-libs-graal-image
%else %else
%global static_libs_target %{nil} %global static_libs_target %{nil}
%endif %endif
@ -333,17 +407,14 @@
%global with_systemtap 0 %global with_systemtap 0
%endif %endif
# New Version-String scheme-style defines
%global featurever 25 # buildjdkver is usually same as featurever,
%global interimver 0 # but at the time of bootstrap of the next jdk, it is featurever-1,
%global updatever 1
%global patchver 0
# buildjdkver is usually same as %%{featurever},
# but in time of bootstrap of next jdk, it is featurever-1,
# and this it is better to change it here, on single place # and this it is better to change it here, on single place
%global buildjdkver %{featurever} %global buildjdkver %{featurever}
# We don't add any LTS designator for STS packages (Fedora and EPEL). # We don't add any LTS designator for STS packages (Fedora and EPEL).
# We need to explicitly exclude EPEL as it would have the %%{rhel} macro defined. # We need to explicitly exclude EPEL as it has the rhel macro defined.
%if 0%{?rhel} && !0%{?epel} %if 0%{?rhel} && !0%{?epel}
%global lts_designator "LTS" %global lts_designator "LTS"
%global lts_designator_zip -%{lts_designator} %global lts_designator_zip -%{lts_designator}
@ -355,7 +426,8 @@
# Define vendor information used by OpenJDK # Define vendor information used by OpenJDK
%global oj_vendor Red Hat, Inc. %global oj_vendor Red Hat, Inc.
%global oj_vendor_url https://www.redhat.com/ %global oj_vendor_url https://www.redhat.com/
# Define what url should JVM offer in case of a crash report
# Define what url the JVM should offer in case of a crash report
# order may be important, epel may have rhel declared # order may be important, epel may have rhel declared
%if 0%{?epel} %if 0%{?epel}
%global oj_vendor_bug_url https://bugzilla.redhat.com/enter_bug.cgi?product=Fedora%20EPEL&component=%{name}&version=epel%{epel} %global oj_vendor_bug_url https://bugzilla.redhat.com/enter_bug.cgi?product=Fedora%20EPEL&component=%{name}&version=epel%{epel}
@ -371,67 +443,13 @@
%endif %endif
%endif %endif
%endif %endif
%global oj_vendor_version (Red_Hat-%{version}-%{rpmrelease}) %global oj_vendor_version (Red_Hat-%{version}-%{portablerelease})
# Define IcedTea version used for SystemTap tapsets and desktop file
%global icedteaver 6.0.0pre00-c848b93a8598
# Define current Git revision for the FIPS support patches
%global fipsver 9203d50836c
# Define JDK versions
%global newjavaver %{featurever}.%{interimver}.%{updatever}.%{patchver}
%global javaver %{featurever}
# Strip up to 6 trailing zeros in newjavaver, as the JDK does, to get the correct version used in filenames
%global filever %(svn=%{newjavaver}; for i in 1 2 3 4 5 6 ; do svn=${svn%%.0} ; done; echo ${svn})
# The tag used to create the OpenJDK tarball
%global vcstag jdk-%{filever}+%{buildver}%{?tagsuffix:-%{tagsuffix}}
# Standard JPackage naming and versioning defines
%global origin openjdk
%global origin_nice OpenJDK
%global top_level_dir_name %{vcstag}
%global top_level_dir_name_backup %{top_level_dir_name}-backup
%global buildver 8
%global rpmrelease 1
#%%global tagsuffix %%{nil}
# Priority must be 8 digits in total; up to openjdk 1.8, we were using 18..... so when we moved to 11, we had to add another digit
%if %is_system_jdk
# Using 10 digits may overflow the int used for priority, so we combine the patch and build versions
# It is very unlikely we will ever have a patch version > 4 or a build version > 20, so we combine as (patch * 20) + build.
# This means 11.0.9.0+11 would have had a priority of 11000911 as before
# A 11.0.9.1+1 would have had a priority of 11000921 (20 * 1 + 1), thus ensuring it is bigger than 11.0.9.0+11
%global combiver $( expr 20 '*' %{patchver} + %{buildver} )
%global priority %( printf '%02d%02d%02d%02d' %{featurever} %{interimver} %{updatever} %{combiver} )
%else
# for techpreview, using 1, so slowdebugs can have 0
%global priority %( printf '%08d' 1 )
%endif
# Define milestone (EA for pre-releases, GA for releases)
# Release will be (where N is usually a number starting at 1):
# - 0.N%%{?extraver}%%{?dist} for EA releases,
# - N%%{?extraver}{?dist} for GA releases
%global is_ga 1
%if %{is_ga}
%global build_type GA
%global ea_designator ""
%global ea_designator_zip %{nil}
%global extraver %{nil}
%global eaprefix %{nil}
%else
%global build_type EA
%global ea_designator ea
%global ea_designator_zip -%{ea_designator}
%global extraver .%{ea_designator}
%global eaprefix 0.
%endif
# parametrized macros are order-sensitive
%global compatiblename java-%{featurever}-%{origin}
%global fullversion %{compatiblename}-%{version}-%{release}
# images directories from upstream build # images directories from upstream build
%global jdkimage jdk %global jdkimage jdk
%global static_libs_image static-libs %global static_libs_image static-libs-graal
# output dir stub # output dir stub
# Parameterised macros are order-sensitive
%define buildoutputdir() %{expand:build/jdk%{featurever}.build%{?1}} %define buildoutputdir() %{expand:build/jdk%{featurever}.build%{?1}}
%define installoutputdir() %{expand:install/jdk%{featurever}.install%{?1}} %define installoutputdir() %{expand:install/jdk%{featurever}.install%{?1}}
%global altjavaoutputdir install/altjava.install %global altjavaoutputdir install/altjava.install
@ -442,20 +460,29 @@
%define uniquesuffix() %{expand:%{fullversion}.%{_arch}%{?1}} %define uniquesuffix() %{expand:%{fullversion}.%{_arch}%{?1}}
# portable only declarations # portable only declarations
%global jreimage jre %global jreimage jre
%define jreportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable%{1}.jre;g") %define jreportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable%{1}.jre;g")
%define jdkportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable%{1}.jdk;g") %define jdkportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable%{1}.jdk;g")
%define staticlibsportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable%{1}.static-libs;g") %define staticlibsportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable%{1}.static-libs;g")
# RPM 4.19 no longer accept our double percentaged %%{nil} passed to %%{1}
# so we have to pass in "" but evaluate it, otherwise files will include it
%define jreportablearchive() %{expand:%{jreportablenameimpl -- %%{1}}.tar.xz} %define jreportablearchive() %{expand:%{jreportablenameimpl -- %%{1}}.tar.xz}
%define jreportablearchive_for_files() %(echo %{jreportablearchive -- ""})
%define jdkportablearchive() %{expand:%{jdkportablenameimpl -- %%{1}}.tar.xz} %define jdkportablearchive() %{expand:%{jdkportablenameimpl -- %%{1}}.tar.xz}
%define jdkportablearchive_for_files() %(echo %{jdkportablearchive -- ""})
%define staticlibsportablearchive() %{expand:%{staticlibsportablenameimpl -- %%{1}}.tar.xz} %define staticlibsportablearchive() %{expand:%{staticlibsportablenameimpl -- %%{1}}.tar.xz}
%define staticlibsportablearchive_for_files() %(echo %{staticlibsportablearchive -- ""})
%define jreportablename() %{expand:%{jreportablenameimpl -- %%{1}}} %define jreportablename() %{expand:%{jreportablenameimpl -- %%{1}}}
%define jdkportablename() %{expand:%{jdkportablenameimpl -- %%{1}}} %define jdkportablename() %{expand:%{jdkportablenameimpl -- %%{1}}}
# Intentionally use jdkportablenameimpl here since we want to have static-libs files overlayed on # We intentionally use jdkportablenameimpl here since we want to have
# top of the JDK archive # static-libs files overlayed on top of the JDK archive
%define staticlibsportablename() %{expand:%{jdkportablenameimpl -- %%{1}}} %define staticlibsportablename() %{expand:%{jdkportablenameimpl -- %%{1}}}
%define docportablename() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable.docs;g")
# These macros are not parameterised as the same is shared by all builds
%define docportablename() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable.docs;g")
%define docportablearchive() %{docportablename}.tar.xz %define docportablearchive() %{docportablename}.tar.xz
%define miscportablename() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable.misc;g") %define miscportablename() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable.misc;g")
%define miscportablearchive() %{miscportablename}.tar.xz %define miscportablearchive() %{miscportablename}.tar.xz
# JDK to use for bootstrapping # JDK to use for bootstrapping
@ -474,26 +501,6 @@
%global build_hotspot_first 0 %global build_hotspot_first 0
%endif %endif
#################################################################
# fix for https://bugzilla.redhat.com/show_bug.cgi?id=1111349
# https://bugzilla.redhat.com/show_bug.cgi?id=1590796#c14
# https://bugzilla.redhat.com/show_bug.cgi?id=1655938
%global _privatelibs libsplashscreen[.]so.*|libawt_xawt[.]so.*|libjli[.]so.*|libattach[.]so.*|libawt[.]so.*|libextnet[.]so.*|libawt_headless[.]so.*|libdt_socket[.]so.*|libfontmanager[.]so.*|libinstrument[.]so.*|libj2gss[.]so.*|libj2pcsc[.]so.*|libj2pkcs11[.]so.*|libjaas[.]so.*|libjavajpeg[.]so.*|libjdwp[.]so.*|libjimage[.]so.*|libjsound[.]so.*|liblcms[.]so.*|libmanagement[.]so.*|libmanagement_agent[.]so.*|libmanagement_ext[.]so.*|libmlib_image[.]so.*|libnet[.]so.*|libnio[.]so.*|libprefs[.]so.*|librmi[.]so.*|libsaproc[.]so.*|libsctp[.]so.*|libsystemconf[.]so.*|libzip[.]so.*%{freetype_lib}
%global _publiclibs libjawt[.]so.*|libjava[.]so.*|libjvm[.]so.*|libverify[.]so.*|libjsig[.]so.*
%if %is_system_jdk
%global __provides_exclude ^(%{_privatelibs})$
%global __requires_exclude ^(%{_privatelibs})$
# Never generate lib-style provides/requires for slowdebug packages
%global __provides_exclude_from ^.*/%{uniquesuffix -- %{debug_suffix_unquoted}}/.*$
%global __requires_exclude_from ^.*/%{uniquesuffix -- %{debug_suffix_unquoted}}/.*$
%global __provides_exclude_from ^.*/%{uniquesuffix -- %{fastdebug_suffix_unquoted}}/.*$
%global __requires_exclude_from ^.*/%{uniquesuffix -- %{fastdebug_suffix_unquoted}}/.*$
%else
# Don't generate provides/requires for JDK provided shared libraries at all.
%global __provides_exclude ^(%{_privatelibs}|%{_publiclibs})$
%global __requires_exclude ^(%{_privatelibs}|%{_publiclibs})$
%endif
# VM variant being built # VM variant being built
%ifarch %{zero_arches} %ifarch %{zero_arches}
%global vm_variant zero %global vm_variant zero
@ -501,28 +508,11 @@
%global vm_variant server %global vm_variant server
%endif %endif
%global etcjavasubdir %{_sysconfdir}/java/java-%{javaver}-%{origin}
%define etcjavadir() %{expand:%{etcjavasubdir}/%{uniquesuffix -- %{?1}}}
# Standard JPackage directories and symbolic links.
%define sdkdir() %{expand:%{uniquesuffix -- %{?1}}}
%define jrelnk() %{expand:jre-%{javaver}-%{origin}-%{version}-%{release}.%{_arch}%{?1}}
%define sdkbindir() %{expand:%{_jvmdir}/%{sdkdir -- %{?1}}/bin}
%define jrebindir() %{expand:%{_jvmdir}/%{sdkdir -- %{?1}}/bin}
%global alt_java_name alt-java %global alt_java_name alt-java
%global devkit_name %{origin}-devkit %global devkit_name %{origin}-devkit
%global rpm_state_dir %{_localstatedir}/lib/rpm-state/ %global rpm_state_dir %{_localstatedir}/lib/rpm-state/
# For flatpack builds hard-code /usr/sbin/alternatives,
# otherwise use %%{_sbindir} relative path.
%if 0%{?flatpak}
%global alternatives_requires /usr/sbin/alternatives
%else
%global alternatives_requires %{_sbindir}/alternatives
%endif
# Portables have no repo (requires/provides), but these are awesome for orientation in spec # Portables have no repo (requires/provides), but these are awesome for orientation in spec
# Also scriptlets are happily missing and files are handled old fashion # Also scriptlets are happily missing and files are handled old fashion
# not-duplicated requires/provides/obsoletes for normal/debug packages # not-duplicated requires/provides/obsoletes for normal/debug packages
@ -547,11 +537,6 @@
# Prevent brp-java-repack-jars from being run # Prevent brp-java-repack-jars from being run
%global __jar_repack 0 %global __jar_repack 0
# Define an optional suffix for the OS this package is built on
%if 0%{?rhel} == 7
%global pkgos rhel7
%endif
# Define the architectures on which we build # Define the architectures on which we build
# On RHEL, this should be the architectures with a devkit # On RHEL, this should be the architectures with a devkit
%if 0%{?centos} == 0 %if 0%{?centos} == 0
@ -560,43 +545,6 @@ ExclusiveArch: %{devkit_arches}
ExclusiveArch: %{aarch64} %{ppc64le} s390x x86_64 riscv64 ExclusiveArch: %{aarch64} %{ppc64le} s390x x86_64 riscv64
%endif %endif
Name: java-%{javaver}-%{origin}-portable%{?pkgos:-%{pkgos}}
Version: %{newjavaver}.%{buildver}
Release: %{?eaprefix}%{rpmrelease}%{?extraver}%{?dist}
# java-1.5.0-ibm from jpackage.org set Epoch to 1 for unknown reasons
# and this change was brought into RHEL-4. java-1.5.0-ibm packages
# also included the epoch in their virtual provides. This created a
# situation where in-the-wild java-1.5.0-ibm packages provided "java =
# 1:1.5.0". In RPM terms, "1.6.0 < 1:1.5.0" since 1.6.0 is
# interpreted as 0:1.6.0. So the "java >= 1.6.0" requirement would be
# satisfied by the 1:1.5.0 packages. Thus we need to set the epoch in
# JDK package >= 1.6.0 to 1, and packages referring to JDK virtual
# provides >= 1.6.0 must specify the epoch, "java >= 1:1.6.0".
Epoch: 1
Summary: %{origin_nice} %{featurever} Runtime Environment portable edition
# Groups are only used up to RHEL 8 and on Fedora versions prior to F30
%if (0%{?rhel} > 0 && 0%{?rhel} <= 8) || (0%{?fedora} >= 0 && 0%{?fedora} < 30)
Group: Development/Languages
%endif
# HotSpot code is licensed under GPLv2
# JDK library code is licensed under GPLv2 with the Classpath exception
# The Apache license is used in code taken from Apache projects (primarily xalan & xerces)
# DOM levels 2 & 3 and the XML digital signature schemas are licensed under the W3C Software License
# The JSR166 concurrency code is in the public domain
# The BSD and MIT licenses are used for a number of third-party libraries (see ADDITIONAL_LICENSE_INFO)
# The OpenJDK source tree includes:
# - JPEG library (IJG), zlib & libpng (zlib), giflib (MIT), harfbuzz (ISC),
# - freetype (FTL), jline (BSD) and LCMS (MIT)
# - jquery (MIT), jdk.crypto.cryptoki PKCS 11 wrapper (RSA)
# - public_suffix_list.dat from publicsuffix.org (MPLv2.0)
# The test code includes copies of NSS under the Mozilla Public License v2.0
# The PCSClite headers are under a BSD with advertising license
# The elliptic curve cryptography (ECC) source code is licensed under the LGPLv2.1 or any later version
License: ASL 1.1 and ASL 2.0 and BSD and BSD with advertising and GPL+ and GPLv2 and GPLv2 with exceptions and IJG and LGPLv2+ and MIT and MPLv2.0 and Public Domain and W3C and zlib and ISC and FTL and RSA
URL: http://openjdk.java.net/
# The source tarball, generated using generate_source_tarball.sh # The source tarball, generated using generate_source_tarball.sh
Source0: https://openjdk-sources.osci.io/openjdk%{featurever}/open%{vcstag}%{ea_designator_zip}.tar.xz Source0: https://openjdk-sources.osci.io/openjdk%{featurever}/open%{vcstag}%{ea_designator_zip}.tar.xz
@ -638,43 +586,18 @@ Source18: TestTranslations.java
# RPM/distribution specific patches # RPM/distribution specific patches
# #
############################################ ############################################
# Crypto policy and FIPS support patches # Crypto policy and FIPS support patches
# Patch is generated from the fips-25u tree at https://github.com/rh-openjdk/jdk/tree/fips-25u # Patch is generated from the fips-25u tree at https://github.com/rh-openjdk/jdk/tree/fips-25u
# as follows: git diff %%{vcstag} src make test > fips-21u-$(git show -s --format=%h HEAD).patch # as follows: git diff <vcstag> src make test > fips-25u-$(git show -s --format=%h HEAD).patch
# Diff is limited to src and make subdirectories to exclude .github changes # Diff is limited to src and make subdirectories to exclude .github changes
# Fixes currently included: # Fixes currently included:
# PR3183, RH1340845: Follow system wide crypto policy # OPENJDK-2108: Internal __redhat_fips__ property
# PR3695: Allow use of system crypto policy to be disabled by the user # OPENJDK-2123: Algorithms lockdown
# RH1655466: Support RHEL FIPS mode using SunPKCS11 provider # OPENJDK-4559: Red Hat Build of OpenJDK 25 should not restrict all the providers in FIPS
# RH1818909: No ciphersuites availale for SSLSocket in FIPS mode Patch1001: fips-%{featurever}u-%{fipsver}.patch
# RH1860986: Disable TLSv1.3 with the NSS-FIPS provider until PKCS#11 v3.0 support is available
# RH1915071: Always initialise JavaSecuritySystemConfiguratorAccess
# RH1929465: Improve system FIPS detection
# RH1995150: Disable non-FIPS crypto in SUN and SunEC security providers
# RH1996182: Login to the NSS software token in FIPS mode
# RH1991003: Allow plain key import unless com.redhat.fips.plainKeySupport is set to false
# RH2021263: Resolve outstanding FIPS issues
# RH2052819: Fix FIPS reliance on crypto policies
# RH2052829: Detect NSS at Runtime for FIPS detection
# RH2052070: Enable AlgorithmParameters and AlgorithmParameterGenerator services in FIPS mode
# RH2023467: Enable FIPS keys export
# RH2094027: SunEC runtime permission for FIPS
# RH2036462: sun.security.pkcs11.wrapper.PKCS11.getInstance breakage
# RH2090378: Revert to disabling system security properties and FIPS mode support together
# RH2104724: Avoid import/export of DH private keys
# RH2092507: P11Key.getEncoded does not work for DH keys in FIPS mode
# Build the systemconf library on all platforms
# RH2048582: Support PKCS#12 keystores [now part of JDK-8301553 upstream]
# RH2020290: Support TLS 1.3 in FIPS mode
# Add nss.fips.cfg support to OpenJDK tree
# RH2117972: Extend the support for NSS DBs (PKCS11) in FIPS mode
# Remove forgotten dead code from RH2020290 and RH2104724
# OJ1357: Fix issue on FIPS with a SecurityManager in place
# RH2134669: Add missing attributes when registering services in FIPS mode.
# test/jdk/sun/security/pkcs11/fips/VerifyMissingAttributes.java: fixed jtreg main class
# RH1940064: Enable XML Signature provider in FIPS mode
# RH2173781: Avoid calling C_GetInfo() too early, before cryptoki is initialized [now part of JDK-8301553 upstream]
# Disabled until 25: Patch1001: fips-%{featurever}u-%{fipsver}.patch
############################################# #############################################
# #
@ -690,7 +613,10 @@ Source18: TestTranslations.java
# #
############################################# #############################################
# Currently empty # JDK-8347901: C2 should remove unused leaf / pure runtime calls
Patch2002: jdk8347901-c2_unused_leaf_removal.patch
# JDK-83787313: C2: performance regression due to missing constant folding for Math.pow()
Patch2003: jdk8378713-c2_missing_pow_constant_folding.patch
############################################# #############################################
# #
@ -773,19 +699,19 @@ BuildRequires: libpng-devel
BuildRequires: zlib-devel BuildRequires: zlib-devel
%else %else
# Version in src/java.desktop/share/legal/freetype.md # Version in src/java.desktop/share/legal/freetype.md
Provides: bundled(freetype) = 2.13.3 Provides: bundled(freetype) = 2.14.3
# Version in src/java.desktop/share/native/libsplashscreen/giflib/gif_lib.h # Version in src/java.desktop/share/native/libsplashscreen/giflib/gif_lib.h
Provides: bundled(giflib) = 5.2.2 Provides: bundled(giflib) = 6.1.3
# Version in src/java.desktop/share/native/libharfbuzz/hb-version.h # Version in src/java.desktop/share/native/libharfbuzz/hb-version.h
Provides: bundled(harfbuzz) = 10.4.0 Provides: bundled(harfbuzz) = 14.2.0
# Version in src/java.desktop/share/native/liblcms/lcms2.h # Version in src/java.desktop/share/native/liblcms/lcms2.h
Provides: bundled(lcms2) = 2.17.0 Provides: bundled(lcms2) = 2.19.1
# Version in src/java.desktop/share/native/libjavajpeg/jpeglib.h # Version in src/java.desktop/share/native/libjavajpeg/jpeglib.h
Provides: bundled(libjpeg) = 6b Provides: bundled(libjpeg) = 6b
# Version in src/java.desktop/share/native/libsplashscreen/libpng/png.h # Version in src/java.desktop/share/native/libsplashscreen/libpng/png.h
Provides: bundled(libpng) = 1.6.47 Provides: bundled(libpng) = 1.6.58
# Version in src/java.base/share/native/libzip/zlib/zlib.h # Version in src/java.base/share/native/libzip/zlib/zlib.h
Provides: bundled(zlib) = 1.3.1 Provides: bundled(zlib) = 1.3.2
# We link statically against libstdc++ to increase portability # We link statically against libstdc++ to increase portability
%ifnarch %{devkit_arches} %ifnarch %{devkit_arches}
BuildRequires: libstdc++-static BuildRequires: libstdc++-static
@ -974,11 +900,6 @@ fi
export XZ_OPT="-T0" export XZ_OPT="-T0"
%setup -q -c -n %{uniquesuffix ""} -T -a 0 %setup -q -c -n %{uniquesuffix ""} -T -a 0
# https://bugzilla.redhat.com/show_bug.cgi?id=1189084 # https://bugzilla.redhat.com/show_bug.cgi?id=1189084
prioritylength=`expr length %{priority}`
if [ $prioritylength -ne 8 ] ; then
echo "priority must be 8 digits in total, violated"
exit 14
fi
# OpenJDK patches # OpenJDK patches
@ -988,23 +909,13 @@ sh %{SOURCE12} %{top_level_dir_name}
%endif %endif
# Patch the JDK # Patch the JDK
# This syntax is deprecated:
# %patchN [...]
# and should be replaced with:
# %patch -PN [...]
# For example:
# %patch1001 -p1
# becomes:
# %patch -P1001 -p1
# The replacement format suggested by recent (circa Fedora 38) RPM
# deprecation messages:
# %patch N [...]
# is not backward-compatible with prior (circa RHEL-8) versions of
# rpmbuild.
pushd %{top_level_dir_name} pushd %{top_level_dir_name}
# Add crypto policy and FIPS support # Add crypto policy and FIPS support
# Disabled until 25 %patch -P1001 -p1
#%patch -P1001 -p1 # Add C2 patches
%patch -P2002 -p1
%patch -P2003 -p1
popd # openjdk popd # openjdk
echo "Generating %{alt_java_name} man page" echo "Generating %{alt_java_name} man page"
@ -1088,7 +999,6 @@ cat %{bootjdk}/release
export NUM_PROC=%(/usr/bin/getconf _NPROCESSORS_ONLN 2> /dev/null || :) export NUM_PROC=%(/usr/bin/getconf _NPROCESSORS_ONLN 2> /dev/null || :)
export NUM_PROC=${NUM_PROC:-1} export NUM_PROC=${NUM_PROC:-1}
%if 0%{?_smp_ncpus_max} %if 0%{?_smp_ncpus_max}
# Honor %%_smp_ncpus_max
[ ${NUM_PROC} -gt %{?_smp_ncpus_max} ] && export NUM_PROC=%{?_smp_ncpus_max} [ ${NUM_PROC} -gt %{?_smp_ncpus_max} ] && export NUM_PROC=%{?_smp_ncpus_max}
%endif %endif
export XZ_OPT="-T0" export XZ_OPT="-T0"
@ -1208,8 +1118,8 @@ function buildjdk() {
mkdir -p ${outputdir} mkdir -p ${outputdir}
pushd ${outputdir} pushd ${outputdir}
# Note: zlib and freetype use %{link_type} # Note: zlib and freetype use link_type (macro)
# rather than ${link_opt} as the system versions # rather than link_opt (shell var) as the system versions
# are always used in a system_libs build, even # are always used in a system_libs build, even
# for the static library build # for the static library build
LD_LIBRARY_PATH=${LIBPATH} \ LD_LIBRARY_PATH=${LIBPATH} \
@ -1718,12 +1628,14 @@ $JAVA_HOME/bin/java -XX:+UnlockExperimentalVMOptions -XX:+UseShenandoahGC -versi
# Check translations are available for new timezones (during flatpak builds, the # Check translations are available for new timezones (during flatpak builds, the
# tzdb.dat used by this test is not where the test expects it, so this is # tzdb.dat used by this test is not where the test expects it, so this is
# disabled for flatpak builds) # disabled for flatpak builds)
# Disable test until we are on the latest JDK $JAVA_HOME/bin/java %{SOURCE18}
$JAVA_HOME/bin/javac -d . %{SOURCE18}
$JAVA_HOME/bin/java $(echo $(basename %{SOURCE18})|sed "s|\.java||") JRE
$JAVA_HOME/bin/java -Djava.locale.providers=CLDR $(echo $(basename %{SOURCE18})|sed "s|\.java||") CLDR
%endif %endif
# Check blocked.certs is valid (OPENJDK-4362)
jtreg_test=$(pwd)/%{top_level_dir_name}/test/jdk/sun/security/lib/CheckBlockedCerts.java
jtreg_dir=$(dirname ${jtreg_test})
$JAVA_HOME/bin/java --add-exports java.base/sun.security.util=ALL-UNNAMED -Dtest.src=${jtreg_dir} ${jtreg_test}
# Check src.zip has all sources. See RHBZ#1130490 # Check src.zip has all sources. See RHBZ#1130490
unzip -l $JAVA_HOME/lib/src.zip | grep 'sun.misc.Unsafe' unzip -l $JAVA_HOME/lib/src.zip | grep 'sun.misc.Unsafe'
@ -1895,8 +1807,8 @@ done
%files %files
# main package builds always # main package builds always
%{_jvmdir}/%{jreportablearchive -- %%{nil}} %{_jvmdir}/%{jreportablearchive_for_files}
%{_jvmdir}/%{jreportablearchive -- %%{nil}}.sha256sum %{_jvmdir}/%{jreportablearchive_for_files}.sha256sum
%else %else
%files %files
# placeholder # placeholder
@ -1905,15 +1817,15 @@ done
%if %{include_normal_build} %if %{include_normal_build}
%files devel %files devel
%{_jvmdir}/%{jdkportablearchive -- %%{nil}} %{_jvmdir}/%{jdkportablearchive_for_files}
%{_jvmdir}/%{jdkportablearchive -- .debuginfo} %{_jvmdir}/%{jdkportablearchive -- .debuginfo}
%{_jvmdir}/%{jdkportablearchive -- %%{nil}}.sha256sum %{_jvmdir}/%{jdkportablearchive_for_files}.sha256sum
%{_jvmdir}/%{jdkportablearchive -- .debuginfo}.sha256sum %{_jvmdir}/%{jdkportablearchive -- .debuginfo}.sha256sum
%if %{include_staticlibs} %if %{include_staticlibs}
%files static-libs %files static-libs
%{_jvmdir}/%{staticlibsportablearchive -- %%{nil}} %{_jvmdir}/%{staticlibsportablearchive_for_files}
%{_jvmdir}/%{staticlibsportablearchive -- %%{nil}}.sha256sum %{_jvmdir}/%{staticlibsportablearchive_for_files}.sha256sum
%endif %endif
%files unstripped %files unstripped
@ -1967,6 +1879,102 @@ done
%endif %endif
%changelog %changelog
* Thu Jul 16 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.4.0.7-1.0
- Update to jdk-25.0.4+7 (GA)
- Update release notes to 25.0.4+7
- Bump freetype version to 2.14.3 following JDK-8385390
- Bump giflib version to 6.1.3 following JDK-8384902
- Bump HarfBuzz version to 14.2.0 following JDK-8385490
- Bump lcms2 version to 2.19.1 following JDK-8375065 & JDK-8383354
- Bump libpng version to 1.6.58 following JDK-8384495
- Drop local copy of JDK-8375294 EOPNOTSUPP patch
- Revert fr_FR and de_DE changes made in d43f0e6186370fdeb0ca2f3594f39783e20eef1c now JDK-8382020 is fixed
- Simplify TestTranslations run now there is only the CLDR provider and one set of data (JDK-8174269)
- Make zone string debug output optional in TestTranslations
- ** This tarball is embargoed until 2026-07-21 @ 1pm PT. **
- Resolves: OPENJDK-4865
- Resolves: OPENJDK-4902
* Mon Jul 13 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.3.0.9-3.0
- Add 25u backports of JDK-8347901 & JDK-8378713 C2 performance fixes
- Resolves: OPENJDK-4885
* Thu Jul 02 2026 Andrea Bolognani <abologna@redhat.com> - 1:25.0.3.0.9-3.0
- Strip %%{dist} more thoroughly
- Resolves: OPENJDK-4881
* Fri Jun 26 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.3.0.9-2.0
- Port ForFiles patch to RHEL and update to use standard function naming format
- Remove macro references in comments where possible (%dnl not compatible enough yet)
- Drop unused tagsuffix line which causes issues on older RPM versions without %dnl
- Cleanup RPM only macros unused in the portable spec file
- Move version information and core NVR definitions back towards the top of the file
- Specify portablerelease and rpmrelease (always 0 for portables) in the Release field
- Related: OPENJDK-4872
- Resolves: OPENJDK-4873
- Resolves: OPENJDK-4875
- Resolves: OPENJDK-4876
* Fri Jun 26 2026 Jiri Vanek <jvanek@redhat.com> - 1:25.0.3.0.9-2
- Redeclared ForFiles release sections as %%nil no longer works with %%1
- RPM 4.19 no longer accept our double percentaged %%{nil} passed to %%{1}
- so we have to pass in "" but evaluate it, otherwise files record will include it
- Resolves: OPENJDK-4872
* Sat Apr 18 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.3.0.9-1
- Update to jdk-25.0.3+9 (GA)
- Update release notes to 25.0.3+9
- Update FIPS patch to 57722aab802 version synced with 25.0.3+8
- Drop local libpng patches now JDK-8372534, JDK-8375063 & JDK-8377526 are included upstream
- Drop local HarfBuzz patch now JDK-8375057 is included upstream
- Bump freetype version to 2.14.2 following JDK-8373290 & JDK-8379158
- Bump giflib version to 6.1.2 following JDK-8379256 & JDK-8380078
- Bump libpng version to 1.6.57 following JDK-8380959 & JDK-8382047
- Bump zlib version to 1.3.2 following JDK-8378631
- Add JDK-8375294 EOPNOTSUPP patch ahead of 25.0.4
- ** This tarball is embargoed until 2026-04-21 @ 1pm PT. **
- Resolves: OPENJDK-4634
- Resolves: OPENJDK-4656
- Resolves: OPENJDK-4607
- Resolves: OPENJDK-4675
* Tue Mar 03 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.2.0.10-3
- Update FIPS patch to e55ada9353e to include the fix for the too restrictive provider lockdown
- Fix FIPS issue list to represent the new 25u version
- Add JDK-8375063 libpng 1.6.54 ahead of 25.0.3
- Add JDK-8375057 harfbuzz 12.3.2 ahead of 25.0.3
- Add JDK-8377526 libpng 1.6.55 ahead of 25.0.3
- Bump libpng version to 1.6.55 following JDK-8375063 & JDK-8377526
- Bump harfbuzz version to 12.3.2 following JDK-8375057
- Resolves: OPENJDK-4570
- Resolves: OPENJDK-4304
- Resolves: OPENJDK-4524
- Resolves: OPENJDK-4544
- Resolves: OPENJDK-4553
* Mon Jan 12 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.2.0.10-2
- Add JDK-8372534 libpng 1.6.51 ahead of 25.0.3
- Bump libpng version to 1.6.51 following JDK-8372534
- Add CVEs for 25.0.2 to NEWS
- Correct version and date for this upcoming release in NEWS
- Related: OPENJDK-4359
* Mon Jan 12 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.2.0.10-1
- Update to jdk-25.0.2+10 (GA)
- Update release notes to 25.0.2+10
- Add test to ensure blocked.certs is valid (OPENJDK-4362)
- ** This tarball is embargoed until 2026-01-20 @ 1pm PT. **
- Resolves: OPENJDK-4359
- Resolves: OPENJDK-4362
* Tue Dec 02 2025 Severin Gehwolf <sgehwolf@redhat.com> - 1:25.0.1.0.8-2
- Switch from static-libs-image to static-libs-graal-image to avoid large unneeded libjvm.a
- Resolves: OPENJDK-4197
* Tue Dec 02 2025 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.1.0.8-2
- Incorporate new FIPS patch for 25u
- Resolves: OPENJDK-4184
* Mon Nov 10 2025 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.1.0.8-1 * Mon Nov 10 2025 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.1.0.8-1
- Update to jdk-25.0.1+8 (GA) - Update to jdk-25.0.1+8 (GA)
- Update release notes to 25.0.1+8 - Update release notes to 25.0.1+8

View File

@ -3,6 +3,132 @@
# it and then adjust portablerelease and portablesuffix # it and then adjust portablerelease and portablesuffix
# to match the new portable. # to match the new portable.
# New Version-String scheme-style defines
%global featurever 25
%global interimver 0
%global updatever 4
%global patchver 0
%global buildver 7
%global portablerelease 1
%global rpmrelease 1
# Define IcedTea version used for SystemTap tapsets and desktop file
%global icedteaver 6.0.0pre00-c848b93a8598
# Define current Git revision for the FIPS support patches
%global fipsver 57722aab802
# Define nssadapter variables
%global nssadapter_version 0.1.1
%global nssadapter_name nssadapter-%{nssadapter_version}
# Define whether the crypto policy is expected to be active when testing
%global crypto_policy_active true
# Define JDK versions
%global newjavaver %{featurever}.%{interimver}.%{updatever}.%{patchver}
%global javaver %{featurever}
# Strip up to 6 trailing zeros in newjavaver, as the JDK does, to get the correct version used in filenames
%global filever %(svn=%{newjavaver}; for i in 1 2 3 4 5 6 ; do svn=${svn%%.0} ; done; echo ${svn})
# The tag used to create the OpenJDK tarball
%global vcstag jdk-%{filever}+%{buildver}%{?tagsuffix:-%{tagsuffix}}
# Standard JPackage naming and versioning defines
%global origin openjdk
%global origin_nice OpenJDK
%global top_level_dir_name %{vcstag}
%global top_level_dir_name_backup %{top_level_dir_name}-backup
# Define milestone (EA for pre-releases, GA for releases)
# Release will be (where N is usually a number starting at 1):
# - 0.N.ea<dist> for EA releases,
# - N<dist> for GA releases
%global is_ga 1
%if %{is_ga}
%global build_type GA
%global ea_designator ""
%global ea_designator_zip %{nil}
%global extraver %{nil}
%global eaprefix %{nil}
%else
%global build_type EA
%global ea_designator ea
%global ea_designator_zip -%{ea_designator}
%global extraver .%{ea_designator}
%global eaprefix 0.
%endif
%global compatiblename java-%{javaver}-%{origin}
Name: %{compatiblename}
Version: %{newjavaver}.%{buildver}
Release: %{?eaprefix}%{portablerelease}.%{rpmrelease}%{?extraver}%{?dist}.alma.1
%global fullversion %{compatiblename}-%{version}-%{release}
# java-1.5.0-ibm from jpackage.org set Epoch to 1 for unknown reasons
# and this change was brought into RHEL-4. java-1.5.0-ibm packages
# also included the epoch in their virtual provides. This created a
# situation where in-the-wild java-1.5.0-ibm packages provided "java =
# 1:1.5.0". In RPM terms, "1.6.0 < 1:1.5.0" since 1.6.0 is
# interpreted as 0:1.6.0. So the "java >= 1.6.0" requirement would be
# satisfied by the 1:1.5.0 packages. Thus we need to set the epoch in
# JDK package >= 1.6.0 to 1, and packages referring to JDK virtual
# provides >= 1.6.0 must specify the epoch, "java >= 1:1.6.0".
Epoch: 1
Summary: %{origin_nice} %{featurever} Runtime Environment
# Groups are only used up to RHEL 8 and on Fedora versions prior to F30
%if (0%{?rhel} > 0 && 0%{?rhel} <= 8) || (0%{?fedora} >= 0 && 0%{?fedora} < 30)
Group: Development/Languages
%endif
# HotSpot code is licensed under GPLv2
# JDK library code is licensed under GPLv2 with the Classpath exception
# The Apache license is used in code taken from Apache projects (primarily xalan & xerces)
# DOM levels 2 & 3 and the XML digital signature schemas are licensed under the W3C Software License
# The JSR166 concurrency code is in the public domain
# The BSD and MIT licenses are used for a number of third-party libraries (see ADDITIONAL_LICENSE_INFO)
# The OpenJDK source tree includes:
# - JPEG library (IJG), zlib & libpng (zlib), giflib (MIT), harfbuzz (ISC),
# - freetype (FTL), jline (BSD) and LCMS (MIT)
# - jquery (MIT), jdk.crypto.cryptoki PKCS 11 wrapper (RSA)
# - public_suffix_list.dat from publicsuffix.org (MPLv2.0)
# The test code includes copies of NSS under the Mozilla Public License v2.0
# The PCSClite headers are under a BSD with advertising license
# The elliptic curve cryptography (ECC) source code is licensed under the LGPLv2.1 or any later version
License: ASL 1.1 and ASL 2.0 and BSD and BSD with advertising and GPL+ and GPLv2 and GPLv2 with exceptions and IJG and LGPLv2+ and MIT and MPLv2.0 and Public Domain and W3C and zlib and ISC and FTL and RSA
URL: http://openjdk.java.net/
# Define the OS the portable JDK is built on
# This is undefined for CentOS & openjdk-portable-rhel-8 builds and
# equals 'rhel7' for openjdk-portable-rhel-7 builds
%if 0
%global pkgos rhel7
%endif
# Define the root name of the portable packages
%global pkgnameroot java-%{featurever}-%{origin}-portable%{?pkgos:-%{pkgos}}
# Release field for the portable build
# The rpmrelease field is always zero for portables
%global prelease %{?eaprefix}%{portablerelease}.0%{?extraver}
# Portable suffix differs between RHEL and CentOS
%if 0%{?centos} == 0
%global portablerhel %{?pkgos:7_9}%{!?pkgos:8}
%else
%global portablerhel 9
%endif
%global portablebuilddir /builddir/build/BUILD
%global portablesuffix el%{portablerhel}
%if 0%{?almalinux}
%ifarch riscv64
%global portablerhel 10
%else
%global portablerhel 9
%endif
%endif
# Check if pandoc was available to generate docs (including man pages)
%if 0%{?portablerhel} == 8
%global pandoc_available 1
%else
%global pandoc_available 0
%endif
# RPM conditionals so as to be able to dynamically produce # RPM conditionals so as to be able to dynamically produce
# slowdebug/release builds. See: # slowdebug/release builds. See:
# http://rpm.org/user_doc/conditional_builds.html # http://rpm.org/user_doc/conditional_builds.html
@ -87,19 +213,20 @@
%global normal_build %{nil} %global normal_build %{nil}
%endif %endif
# We have hardcoded list of files, which is appearing in alternatives, and in files # We have a hardcoded list of files, which appears in alternatives and in files
# in alternatives those are slaves and master, very often triplicated by man pages # In alternatives, those are slaves and master, very often triplicated by man pages
# in files all masters and slaves are ghosted # In files, all masters and slaves are ghosted
# the ghosts are here to allow installation via query like `dnf install /usr/bin/java` # The ghosts are here to allow installation via query like `dnf install /usr/bin/java`
# you can list those files, with appropriate sections: cat *.spec | grep -e --install -e --slave -e post_ -e alternatives # You can list those files, with appropriate sections: cat *.spec | grep -e --install -e --slave -e post_ -e alternatives
# TODO - fix those hardcoded lists via single list # TODO - fix those hardcoded lists via single list
# Those files must *NOT* be ghosted for *slowdebug* packages # Those files must *NOT* be ghosted for *debug* packages
# FIXME - if you are moving jshell or jlink or similar, always modify all three sections # FIXME - if you are moving jshell or jlink or similar, always modify all three sections
# you can check via headless and devels: # You can check via headless and devels:
# rpm -ql --noghost java-11-openjdk-headless-11.0.1.13-8.fc29.x86_64.rpm | grep bin # rpm -ql --noghost java-11-openjdk-headless-11.0.1.13-8.fc29.x86_64.rpm | grep bin
# == rpm -ql java-11-openjdk-headless-slowdebug-11.0.1.13-8.fc29.x86_64.rpm | grep bin # == rpm -ql java-11-openjdk-headless-slowdebug-11.0.1.13-8.fc29.x86_64.rpm | grep bin
# != rpm -ql java-11-openjdk-headless-11.0.1.13-8.fc29.x86_64.rpm | grep bin # != rpm -ql java-11-openjdk-headless-11.0.1.13-8.fc29.x86_64.rpm | grep bin
# similarly for other %%{_jvmdir}/{jre,java} and %%{_javadocdir}/{java,java-zip} # and similarly for other packages.
%define is_release_build() %( if [ "%{?1}" == "%{debug_suffix_unquoted}" -o "%{?1}" == "%{fastdebug_suffix_unquoted}" ]; then echo "0" ; else echo "1"; fi ) %define is_release_build() %( if [ "%{?1}" == "%{debug_suffix_unquoted}" -o "%{?1}" == "%{fastdebug_suffix_unquoted}" ]; then echo "0" ; else echo "1"; fi )
# Indicates whether this is the default JDK on this version of RHEL # Indicates whether this is the default JDK on this version of RHEL
@ -204,27 +331,6 @@
%endif %endif
%endif %endif
%if %{include_staticlibs}
# Extra target for producing the static-libraries. Separate from
# other targets since this target is configured to use in-tree
# AWT dependencies: lcms, libjpeg, libpng, libharfbuzz, giflib
# and possibly others
%global static_libs_target static-libs-image
%else
%global static_libs_target %{nil}
%endif
# RPM JDK builds keep the debug symbols internal, to be later stripped by RPM
%global debug_symbols internal
# unlike portables,the rpms have to use static_libs_target very dynamically
%global bootstrap_targets images
%global release_targets images docs-zip
# No docs nor bootcycle for debug builds
%global debug_targets images
# Target to use to just build HotSpot
%global hotspot_target hotspot
# debugedit tool for rewriting ELF file paths # debugedit tool for rewriting ELF file paths
%if 0%{?rhel} >= 10 %if 0%{?rhel} >= 10
# From RHEL 10, the tool is in its own package installed in the usual location # From RHEL 10, the tool is in its own package installed in the usual location
@ -234,15 +340,6 @@
%global debugedit %{_rpmconfigdir}/debugedit %global debugedit %{_rpmconfigdir}/debugedit
%endif %endif
# Filter out flags from the optflags macro that cause problems with the OpenJDK build
# We filter out -O flags so that the optimization of HotSpot is not lowered from O3 to O2
# We filter out -Wall which will otherwise cause HotSpot to produce hundreds of thousands of warnings (100+mb logs)
# We replace it with -Wformat (required by -Werror=format-security) and -Wno-cpp to avoid FORTIFY_SOURCE warnings
# We filter out -fexceptions as the HotSpot build explicitly does -fno-exceptions and it's otherwise the default for C++
%global ourflags %(echo %optflags | sed -e 's|-Wall|-Wformat -Wno-cpp|' | sed -r -e 's|-O[0-9]*||')
%global ourcppflags %(echo %ourflags | sed -e 's|-fexceptions||')
%global ourldflags %{__global_ldflags}
# In some cases, the arch used by the JDK does # In some cases, the arch used by the JDK does
# not match _arch. # not match _arch.
# Also, in some cases, the machine name used by SystemTap # Also, in some cases, the machine name used by SystemTap
@ -313,13 +410,8 @@
%global with_systemtap 0 %global with_systemtap 0
%endif %endif
# New Version-String scheme-style defines
%global featurever 25
%global interimver 0
%global updatever 1
%global patchver 0
# We don't add any LTS designator for STS packages (Fedora and EPEL). # We don't add any LTS designator for STS packages (Fedora and EPEL).
# We need to explicitly exclude EPEL as it would have the %%{rhel} macro defined. # We need to explicitly exclude EPEL as it has the rhel macro defined.
%if 0%{?rhel} && !0%{?epel} %if 0%{?rhel} && !0%{?epel}
%global lts_designator "LTS" %global lts_designator "LTS"
%global lts_designator_zip -%{lts_designator} %global lts_designator_zip -%{lts_designator}
@ -331,7 +423,8 @@
# Define vendor information used by OpenJDK # Define vendor information used by OpenJDK
%global oj_vendor Red Hat, Inc. %global oj_vendor Red Hat, Inc.
%global oj_vendor_url https://www.redhat.com/ %global oj_vendor_url https://www.redhat.com/
# Define what url should JVM offer in case of a crash report
# Define what url the JVM should offer in case of a crash report
# order may be important, epel may have rhel declared # order may be important, epel may have rhel declared
%if 0%{?epel} %if 0%{?epel}
%global oj_vendor_bug_url https://bugzilla.redhat.com/enter_bug.cgi?product=Fedora%20EPEL&component=%{name}&version=epel%{epel} %global oj_vendor_bug_url https://bugzilla.redhat.com/enter_bug.cgi?product=Fedora%20EPEL&component=%{name}&version=epel%{epel}
@ -349,51 +442,6 @@
%endif %endif
%global oj_vendor_version (Red_Hat-%{version}-%{portablerelease}) %global oj_vendor_version (Red_Hat-%{version}-%{portablerelease})
# Define IcedTea version used for SystemTap tapsets and desktop file
%global icedteaver 6.0.0pre00-c848b93a8598
# Define current Git revision for the crypto policy & FIPS support patches
%global fipsver 9203d50836c
# Define whether the crypto policy is expected to be active when testing
%global crypto_policy_active false
# Define JDK versions
%global newjavaver %{featurever}.%{interimver}.%{updatever}.%{patchver}
%global javaver %{featurever}
# Strip up to 6 trailing zeros in newjavaver, as the JDK does, to get the correct version used in filenames
%global filever %(svn=%{newjavaver}; for i in 1 2 3 4 5 6 ; do svn=${svn%%.0} ; done; echo ${svn})
# The tag used to create the OpenJDK tarball
%global vcstag jdk-%{filever}+%{buildver}%{?tagsuffix:-%{tagsuffix}}
# Define the OS the portable JDK is built on
# This is undefined for CentOS & openjdk-portable-rhel-8 builds and
# equals 'rhel7' for openjdk-portable-rhel-7 builds
%if 0
%global pkgos rhel7
%endif
# Standard JPackage naming and versioning defines
%global origin openjdk
%global origin_nice OpenJDK
%global top_level_dir_name %{vcstag}
%global top_level_dir_name_backup %{top_level_dir_name}-backup
%global buildver 8
%global rpmrelease 2
# Settings used by the portable build
%global portablerelease 1
# Portable suffix differs between RHEL and CentOS
%if 0%{?centos} == 0
%global portablerhel %{?pkgos:7_9}%{!?pkgos:8}
%else
%global portablerhel 9
%endif
%global portablebuilddir /builddir/build/BUILD
%global portablesuffix el%{portablerhel}
# Check if pandoc was available to generate docs (including man pages)
%if 0%{?portablerhel} == 8
%global pandoc_available 1
%else
%global pandoc_available 0
%endif
# Priority must be 8 digits in total; up to openjdk 1.8, we were using 18..... so when we moved to 11, we had to add another digit # Priority must be 8 digits in total; up to openjdk 1.8, we were using 18..... so when we moved to 11, we had to add another digit
%if %is_system_jdk %if %is_system_jdk
# Using 10 digits may overflow the int used for priority, so we combine the patch and build versions # Using 10 digits may overflow the int used for priority, so we combine the patch and build versions
@ -407,32 +455,6 @@
%global priority %( printf '%08d' 1 ) %global priority %( printf '%08d' 1 )
%endif %endif
# Define milestone (EA for pre-releases, GA for releases)
# Release will be (where N is usually a number starting at 1):
# - 0.N%%{?extraver}%%{?dist} for EA releases,
# - N%%{?extraver}{?dist} for GA releases
%global is_ga 1
%if %{is_ga}
%global build_type GA
%global ea_designator ""
%global ea_designator_zip %{nil}
%global extraver %{nil}
%global eaprefix %{nil}
%else
%global build_type EA
%global ea_designator ea
%global ea_designator_zip -%{ea_designator}
%global extraver .%{ea_designator}
%global eaprefix 0.
%endif
# parametrized macros are order-sensitive
%global compatiblename java-%{featurever}-%{origin}
%global fullversion %{compatiblename}-%{version}-%{release}
# images directories from upstream build
%global jdkimage jdk
%global static_libs_image static-libs
# output dir stub
%define installoutputdir() %{expand:install/jdk%{featurever}.install%{?1}} %define installoutputdir() %{expand:install/jdk%{featurever}.install%{?1}}
# we can copy the javadoc to not arched dir, or make it not noarch # we can copy the javadoc to not arched dir, or make it not noarch
%define uniquejavadocdir() %{expand:%{compatiblename}%{?1}} %define uniquejavadocdir() %{expand:%{compatiblename}%{?1}}
@ -478,7 +500,7 @@
%global rpm_state_dir %{_localstatedir}/lib/rpm-state/ %global rpm_state_dir %{_localstatedir}/lib/rpm-state/
# For flatpack builds hard-code /usr/sbin/alternatives, # For flatpack builds hard-code /usr/sbin/alternatives,
# otherwise use %%{_sbindir} relative path. # otherwise use _sbindir relative path.
%if 0%{?flatpak} %if 0%{?flatpak}
%global alternatives_requires /usr/sbin/alternatives %global alternatives_requires /usr/sbin/alternatives
%else %else
@ -904,6 +926,21 @@ fi
%config(noreplace) %{etcjavadir -- %{?1}}/conf/security/policy/unlimited/default_US_export.policy %config(noreplace) %{etcjavadir -- %{?1}}/conf/security/policy/unlimited/default_US_export.policy
%{etcjavadir -- %{?1}}/conf/security/policy/README.txt %{etcjavadir -- %{?1}}/conf/security/policy/README.txt
%config(noreplace) %{etcjavadir -- %{?1}}/conf/security/java.security %config(noreplace) %{etcjavadir -- %{?1}}/conf/security/java.security
%dir %{etcjavadir -- %{?1}}/conf/security/redhat
%dir %{etcjavadir -- %{?1}}/conf/security/redhat/false
%dir %{etcjavadir -- %{?1}}/conf/security/redhat/true
# config-noreplace in case the system administrator wants to adjust
# the FIPS configuration
%config(noreplace) %{etcjavadir -- %{?1}}/conf/security/redhat/SunPKCS11-FIPS.cfg
# config-noreplace in case the system administrator wants to change
# the default for crypto-policies usage
%config(noreplace) %{etcjavadir -- %{?1}}/conf/security/redhat/crypto-policies.properties
# The system administrator is never expected to change these files -- they
# are implementation details -- so leave them as not config-noreplace
%config %{etcjavadir -- %{?1}}/conf/security/redhat/false/crypto-policies.properties
%config %{etcjavadir -- %{?1}}/conf/security/redhat/true/crypto-policies.properties
%config %{etcjavadir -- %{?1}}/conf/security/redhat/false/fips.properties
%config %{etcjavadir -- %{?1}}/conf/security/redhat/true/fips.properties
%config(noreplace) %{etcjavadir -- %{?1}}/conf/management/jmxremote.access %config(noreplace) %{etcjavadir -- %{?1}}/conf/management/jmxremote.access
# This is a config template, thus not config-noreplace # This is a config template, thus not config-noreplace
%config %{etcjavadir -- %{?1}}/conf/management/jmxremote.password.template %config %{etcjavadir -- %{?1}}/conf/management/jmxremote.password.template
@ -1066,7 +1103,6 @@ fi
%dir %{_jvmdir}/%{sdkdir -- %{?1}}/lib/static/linux-%{archinstall} %dir %{_jvmdir}/%{sdkdir -- %{?1}}/lib/static/linux-%{archinstall}
%dir %{_jvmdir}/%{sdkdir -- %{?1}}/lib/static/linux-%{archinstall}/glibc %dir %{_jvmdir}/%{sdkdir -- %{?1}}/lib/static/linux-%{archinstall}/glibc
%{_jvmdir}/%{sdkdir -- %{?1}}/lib/static/linux-%{archinstall}/glibc/lib*.a %{_jvmdir}/%{sdkdir -- %{?1}}/lib/static/linux-%{archinstall}/glibc/lib*.a
%{_jvmdir}/%{sdkdir -- %{?1}}/lib/static/linux-%{archinstall}/glibc/%{vm_variant}/lib*.a
} }
%define files_javadoc() %{expand: %define files_javadoc() %{expand:
@ -1092,6 +1128,11 @@ fi
%endif %endif
} }
%define files_crypto_adapter() %{expand:
%dir %{_libdir}/%{sdkdir -- %{?1}}
%{_libdir}/%{sdkdir -- %{?1}}/libnssadapter.so
}
# not-duplicated requires/provides/obsoletes for normal/debug packages # not-duplicated requires/provides/obsoletes for normal/debug packages
%define java_rpo() %{expand: %define java_rpo() %{expand:
Requires: fontconfig%{?_isa} Requires: fontconfig%{?_isa}
@ -1132,8 +1173,8 @@ Requires: ca-certificates
# Require javapackages-filesystem for ownership of /usr/lib/jvm/ and macros # Require javapackages-filesystem for ownership of /usr/lib/jvm/ and macros
Requires: javapackages-filesystem Requires: javapackages-filesystem
# Require zone-info data provided by tzdata-java sub-package # Require zone-info data provided by tzdata-java sub-package
# 2025a required as of JDK-8347965 # 2026b required as of JDK-8383175
Requires: tzdata-java >= 2025a Requires: tzdata-java >= 2026b
# for support of kernel stream control # for support of kernel stream control
# libsctp.so.1 is being `dlopen`ed on demand # libsctp.so.1 is being `dlopen`ed on demand
Requires: lksctp-tools%{?_isa} Requires: lksctp-tools%{?_isa}
@ -1141,8 +1182,6 @@ Requires: lksctp-tools%{?_isa}
Requires: cups-libs Requires: cups-libs
# for system security properties # for system security properties
Requires: crypto-policies Requires: crypto-policies
# for FIPS PKCS11 provider
Requires: nss
# Post requires alternatives to install tool alternatives # Post requires alternatives to install tool alternatives
Requires(post): %{alternatives_requires} Requires(post): %{alternatives_requires}
# Postun requires alternatives to uninstall tool alternatives # Postun requires alternatives to uninstall tool alternatives
@ -1152,6 +1191,8 @@ Requires(postun): %{alternatives_requires}
%if 0%{?rhel} >= 8 || 0%{?fedora} > 0 %if 0%{?rhel} >= 8 || 0%{?fedora} > 0
Suggests: lksctp-tools%{?_isa}, pcsc-lite-libs%{?_isa} Suggests: lksctp-tools%{?_isa}, pcsc-lite-libs%{?_isa}
%endif %endif
# for libnssadapter.so
Requires: %{name}-crypto-adapter%{?1}%{?_isa} = %{epoch}:%{version}-%{release}
# Standard JPackage base provides # Standard JPackage base provides
Provides: jre-%{javaver}-%{origin}-headless%{?1} = %{epoch}:%{version}-%{release} Provides: jre-%{javaver}-%{origin}-headless%{?1} = %{epoch}:%{version}-%{release}
@ -1254,51 +1295,10 @@ Provides: java-%{origin}-src%{?1} = %{epoch}:%{version}-%{release}
# Prevent brp-java-repack-jars from being run # Prevent brp-java-repack-jars from being run
%global __jar_repack 0 %global __jar_repack 0
# Define the root name of the portable packages
%global pkgnameroot java-%{featurever}-%{origin}-portable%{?pkgos:-%{pkgos}}
# Define the architectures on which we build # Define the architectures on which we build
ExclusiveArch: %{aarch64} %{ppc64le} s390x x86_64 riscv64 ExclusiveArch: %{aarch64} %{ppc64le} s390x x86_64 riscv64
Name: java-%{javaver}-%{origin}
Version: %{newjavaver}.%{buildver}
Release: %{?eaprefix}%{rpmrelease}%{?extraver}%{?dist}
# Equivalent for the portable build
%global prelease %{?eaprefix}%{portablerelease}%{?extraver}
# java-1.5.0-ibm from jpackage.org set Epoch to 1 for unknown reasons
# and this change was brought into RHEL-4. java-1.5.0-ibm packages
# also included the epoch in their virtual provides. This created a
# situation where in-the-wild java-1.5.0-ibm packages provided "java =
# 1:1.5.0". In RPM terms, "1.6.0 < 1:1.5.0" since 1.6.0 is
# interpreted as 0:1.6.0. So the "java >= 1.6.0" requirement would be
# satisfied by the 1:1.5.0 packages. Thus we need to set the epoch in
# JDK package >= 1.6.0 to 1, and packages referring to JDK virtual
# provides >= 1.6.0 must specify the epoch, "java >= 1:1.6.0".
Epoch: 1
Summary: %{origin_nice} %{featurever} Runtime Environment
# Groups are only used up to RHEL 8 and on Fedora versions prior to F30
%if (0%{?rhel} > 0 && 0%{?rhel} <= 8) || (0%{?fedora} >= 0 && 0%{?fedora} < 30)
Group: Development/Languages
%endif
# HotSpot code is licensed under GPLv2
# JDK library code is licensed under GPLv2 with the Classpath exception
# The Apache license is used in code taken from Apache projects (primarily xalan & xerces)
# DOM levels 2 & 3 and the XML digital signature schemas are licensed under the W3C Software License
# The JSR166 concurrency code is in the public domain
# The BSD and MIT licenses are used for a number of third-party libraries (see ADDITIONAL_LICENSE_INFO)
# The OpenJDK source tree includes:
# - JPEG library (IJG), zlib & libpng (zlib), giflib (MIT), harfbuzz (ISC),
# - freetype (FTL), jline (BSD) and LCMS (MIT)
# - jquery (MIT), jdk.crypto.cryptoki PKCS 11 wrapper (RSA)
# - public_suffix_list.dat from publicsuffix.org (MPLv2.0)
# The test code includes copies of NSS under the Mozilla Public License v2.0
# The PCSClite headers are under a BSD with advertising license
# The elliptic curve cryptography (ECC) source code is licensed under the LGPLv2.1 or any later version
License: ASL 1.1 and ASL 2.0 and BSD and BSD with advertising and GPL+ and GPLv2 and GPLv2 with exceptions and IJG and LGPLv2+ and MIT and MPLv2.0 and Public Domain and W3C and zlib and ISC and FTL and RSA
URL: http://openjdk.java.net/
# The source tarball, generated using generate_source_tarball.sh # The source tarball, generated using generate_source_tarball.sh
Source0: https://openjdk-sources.osci.io/openjdk%{featurever}/open%{vcstag}%{ea_designator_zip}.tar.xz Source0: https://openjdk-sources.osci.io/openjdk%{featurever}/open%{vcstag}%{ea_designator_zip}.tar.xz
@ -1355,6 +1355,12 @@ Source29: 0007-Tools.gmk-Exclude-systemtap-sdt-devel-on-s390x-ppc64.patch
# Use update repository on RHEL rather than GA (OPENJDK-3589) # Use update repository on RHEL rather than GA (OPENJDK-3589)
Source30: 0008-Tools.gmk-Use-update-repository-on-RHEL-rather-than-.patch Source30: 0008-Tools.gmk-Use-update-repository-on-RHEL-rather-than-.patch
# FIPS support sources.
# For libnssadapter.so (RHEL-128413)
Source31: https://github.com/rh-openjdk/nss-native-fips-key-import-export-adapter/releases/download/%{nssadapter_version}/%{nssadapter_name}.tar.xz
# Create OpenJDK's crypto-policies hierarchy (RHEL-128409)
Source32: create-redhat-properties-files.bash
# Setup variables to reference correct sources # Setup variables to reference correct sources
%global releasezip %{_jvmdir}/%{name}-%{version}-%{prelease}.portable.unstripped.jdk.%{_arch}.tar.xz %global releasezip %{_jvmdir}/%{name}-%{version}-%{prelease}.portable.unstripped.jdk.%{_arch}.tar.xz
%global staticlibzip %{_jvmdir}/%{name}-%{version}-%{prelease}.portable.static-libs.%{_arch}.tar.xz %global staticlibzip %{_jvmdir}/%{name}-%{version}-%{prelease}.portable.static-libs.%{_arch}.tar.xz
@ -1372,42 +1378,16 @@ Source30: 0008-Tools.gmk-Use-update-repository-on-RHEL-rather-than-.patch
############################################ ############################################
# Crypto policy and FIPS support patches # Crypto policy and FIPS support patches
# Patch is generated from the fips-25u tree at https://github.com/rh-openjdk/jdk/tree/fips-25u # Patch is generated from the fips-25u tree at https://github.com/rh-openjdk/jdk/tree/fips-25u
# as follows: git diff %%{vcstag} src make test > fips-21u-$(git show -s --format=%h HEAD).patch # as follows: git diff <vcstag> src make test > fips-25u-$(git show -s --format=%h HEAD).patch
# Diff is limited to src and make subdirectories to exclude .github changes # Diff is limited to src and make subdirectories to exclude .github changes
# Fixes currently included: # Fixes currently included:
# PR3183, RH1340845: Follow system wide crypto policy # OPENJDK-2108: Internal __redhat_fips__ property
# PR3695: Allow use of system crypto policy to be disabled by the user # OPENJDK-2123: Algorithms lockdown
# RH1655466: Support RHEL FIPS mode using SunPKCS11 provider # OPENJDK-4559: Red Hat Build of OpenJDK 25 should not restrict all the providers in FIPS
# RH1818909: No ciphersuites availale for SSLSocket in FIPS mode Patch1001: fips-%{featurever}u-%{fipsver}.patch
# RH1860986: Disable TLSv1.3 with the NSS-FIPS provider until PKCS#11 v3.0 support is available
# RH1915071: Always initialise JavaSecuritySystemConfiguratorAccess
# RH1929465: Improve system FIPS detection
# RH1995150: Disable non-FIPS crypto in SUN and SunEC security providers
# RH1996182: Login to the NSS software token in FIPS mode
# RH1991003: Allow plain key import unless com.redhat.fips.plainKeySupport is set to false
# RH2021263: Resolve outstanding FIPS issues
# RH2052819: Fix FIPS reliance on crypto policies
# RH2052829: Detect NSS at Runtime for FIPS detection
# RH2052070: Enable AlgorithmParameters and AlgorithmParameterGenerator services in FIPS mode
# RH2023467: Enable FIPS keys export
# RH2094027: SunEC runtime permission for FIPS
# RH2036462: sun.security.pkcs11.wrapper.PKCS11.getInstance breakage
# RH2090378: Revert to disabling system security properties and FIPS mode support together
# RH2104724: Avoid import/export of DH private keys
# RH2092507: P11Key.getEncoded does not work for DH keys in FIPS mode
# Build the systemconf library on all platforms
# RH2048582: Support PKCS#12 keystores [now part of JDK-8301553 upstream]
# RH2020290: Support TLS 1.3 in FIPS mode
# Add nss.fips.cfg support to OpenJDK tree
# RH2117972: Extend the support for NSS DBs (PKCS11) in FIPS mode
# Remove forgotten dead code from RH2020290 and RH2104724
# OJ1357: Fix issue on FIPS with a SecurityManager in place
# RH2134669: Add missing attributes when registering services in FIPS mode.
# test/jdk/sun/security/pkcs11/fips/VerifyMissingAttributes.java: fixed jtreg main class
# RH1940064: Enable XML Signature provider in FIPS mode
# RH2173781: Avoid calling C_GetInfo() too early, before cryptoki is initialized [now part of JDK-8301553 upstream]
# Disabled until 25: Patch1001: fips-%{featurever}u-%{fipsver}.patch
############################################# #############################################
# #
@ -1423,7 +1403,10 @@ Source30: 0008-Tools.gmk-Use-update-repository-on-RHEL-rather-than-.patch
# #
############################################# #############################################
# Currently empty # JDK-8347901: C2 should remove unused leaf / pure runtime calls
Patch2002: jdk8347901-c2_unused_leaf_removal.patch
# JDK-83787313: C2: performance regression due to missing constant folding for Math.pow()
Patch2003: jdk8378713-c2_missing_pow_constant_folding.patch
############################################# #############################################
# #
@ -1433,6 +1416,14 @@ Source30: 0008-Tools.gmk-Use-update-repository-on-RHEL-rather-than-.patch
# Currently empty # Currently empty
#############################################
#
# NSS adapter patches
#
#############################################
# Currently empty
BuildRequires: autoconf BuildRequires: autoconf
BuildRequires: automake BuildRequires: automake
BuildRequires: alsa-lib-devel BuildRequires: alsa-lib-devel
@ -1480,8 +1471,8 @@ BuildRequires: %{pkgnameroot}-misc = %{epoch}:%{version}-%{prelease}.%{portables
%ifarch %{zero_arches} %ifarch %{zero_arches}
BuildRequires: libffi-devel BuildRequires: libffi-devel
%endif %endif
# 2025a required as of JDK-8347965 # 2026b required as of JDK-8383175
BuildRequires: tzdata-java >= 2025a BuildRequires: tzdata-java >= 2026b
# Earlier versions have a bug in tree vectorization on PPC # Earlier versions have a bug in tree vectorization on PPC
BuildRequires: gcc >= 4.8.3-8 BuildRequires: gcc >= 4.8.3-8
@ -1490,6 +1481,10 @@ BuildRequires: systemtap-sdt-devel
%endif %endif
BuildRequires: make BuildRequires: make
# libnssadapter.so build requirements
BuildRequires: nss-devel
BuildRequires: nss-softokn-devel
%if %{system_libs} %if %{system_libs}
BuildRequires: freetype-devel BuildRequires: freetype-devel
BuildRequires: giflib-devel BuildRequires: giflib-devel
@ -1500,19 +1495,19 @@ BuildRequires: libpng-devel
BuildRequires: zlib-devel BuildRequires: zlib-devel
%else %else
# Version in src/java.desktop/share/legal/freetype.md # Version in src/java.desktop/share/legal/freetype.md
Provides: bundled(freetype) = 2.13.3 Provides: bundled(freetype) = 2.14.3
# Version in src/java.desktop/share/native/libsplashscreen/giflib/gif_lib.h # Version in src/java.desktop/share/native/libsplashscreen/giflib/gif_lib.h
Provides: bundled(giflib) = 5.2.2 Provides: bundled(giflib) = 6.1.3
# Version in src/java.desktop/share/native/libharfbuzz/hb-version.h # Version in src/java.desktop/share/native/libharfbuzz/hb-version.h
Provides: bundled(harfbuzz) = 10.4.0 Provides: bundled(harfbuzz) = 14.2.0
# Version in src/java.desktop/share/native/liblcms/lcms2.h # Version in src/java.desktop/share/native/liblcms/lcms2.h
Provides: bundled(lcms2) = 2.17.0 Provides: bundled(lcms2) = 2.19.1
# Version in src/java.desktop/share/native/libjavajpeg/jpeglib.h # Version in src/java.desktop/share/native/libjavajpeg/jpeglib.h
Provides: bundled(libjpeg) = 6b Provides: bundled(libjpeg) = 6b
# Version in src/java.desktop/share/native/libsplashscreen/libpng/png.h # Version in src/java.desktop/share/native/libsplashscreen/libpng/png.h
Provides: bundled(libpng) = 1.6.47 Provides: bundled(libpng) = 1.6.58
# Version in src/java.base/share/native/libzip/zlib/zlib.h # Version in src/java.base/share/native/libzip/zlib/zlib.h
Provides: bundled(zlib) = 1.3.1 Provides: bundled(zlib) = 1.3.2
%endif %endif
%ifarch %{sleef_arches} %ifarch %{sleef_arches}
# SLEEF is always bundled # SLEEF is always bundled
@ -1836,6 +1831,46 @@ Requires(postun): %{alternatives_requires}
The %{origin_nice} %{featurever} API documentation compressed in a single archive. The %{origin_nice} %{featurever} API documentation compressed in a single archive.
%endif %endif
# java-25-openjdk-crypto-adapter
%if %{include_normal_build}
%package crypto-adapter
Summary: %{origin_nice} %{featurever} Cryptography Adapter Library
%if (0%{?rhel} > 0 && 0%{?rhel} <= 8) || (0%{?fedora} >= 0 && 0%{?fedora} < 30)
Group: Development/Languages
%endif
# java-25-openjdk-crypto-adapter does not need an "rpo" function since
# its specific nss and nss-softokn library requirements are
# automatically generated by RPM.
%description crypto-adapter
The %{origin_nice} %{featurever} cryptography adapter library.
%endif
%if %{include_debug_build}
%package crypto-adapter-slowdebug
Summary: %{origin_nice} %{featurever} Cryptography Adapter Library %{debug_on}
%if (0%{?rhel} > 0 && 0%{?rhel} <= 8) || (0%{?fedora} >= 0 && 0%{?fedora} < 30)
Group: Development/Languages
%endif
%description crypto-adapter-slowdebug
The %{origin_nice} %{featurever} cryptography adapter library.
%{debug_warning}
%endif
%if %{include_fastdebug_build}
%package crypto-adapter-fastdebug
Summary: %{origin_nice} %{featurever} Cryptography Adapter Library %{fastdebug_on}
%if (0%{?rhel} > 0 && 0%{?rhel} <= 8) || (0%{?fedora} >= 0 && 0%{?fedora} < 30)
Group: Development/Languages
%endif
%description crypto-adapter-fastdebug
The %{origin_nice} %{featurever} cryptography adapter library.
%{fastdebug_warning}
%endif
%prep %prep
echo "Preparing %{oj_vendor_version}" echo "Preparing %{oj_vendor_version}"
@ -1873,6 +1908,8 @@ fi
export XZ_OPT="-T0" export XZ_OPT="-T0"
%setup -q -c -n %{uniquesuffix ""} -T -a 0 %setup -q -c -n %{uniquesuffix ""} -T -a 0
# Prepare libnssadapter.so source code
tar -xJf %{SOURCE31}
# https://bugzilla.redhat.com/show_bug.cgi?id=1189084 # https://bugzilla.redhat.com/show_bug.cgi?id=1189084
prioritylength=`expr length %{priority}` prioritylength=`expr length %{priority}`
if [ $prioritylength -ne 8 ] ; then if [ $prioritylength -ne 8 ] ; then
@ -1888,25 +1925,20 @@ sh %{SOURCE12} %{top_level_dir_name}
%endif %endif
# Patch the JDK # Patch the JDK
# This syntax is deprecated:
# %patchN [...]
# and should be replaced with:
# %patch -PN [...]
# For example:
# %patch1001 -p1
# becomes:
# %patch -P1001 -p1
# The replacement format suggested by recent (circa Fedora 38) RPM
# deprecation messages:
# %patch N [...]
# is not backward-compatible with prior (circa RHEL-8) versions of
# rpmbuild.
pushd %{top_level_dir_name} pushd %{top_level_dir_name}
# Add crypto policy and FIPS support # Add crypto policy and FIPS support
# Disabled until 25 %patch -P1001 -p1
#%patch -P1001 -p1 # Add C2 patches
%patch -P2002 -p1
%patch -P2003 -p1
popd # openjdk popd # openjdk
# Patch NSS adapter
pushd %{nssadapter_name}
# Nothing to do
popd # nssadapter
# The OpenJDK version file includes the current # The OpenJDK version file includes the current
# upstream version information. For some reason, # upstream version information. For some reason,
# configure does not automatically use the # configure does not automatically use the
@ -1948,11 +1980,12 @@ done
function customisejdk() { function customisejdk() {
local imagepath=${1} local imagepath=${1}
local suffix=${2}
if [ -d ${imagepath} ] ; then if [ -d ${imagepath} ] ; then
# Turn on system security properties # Install crypto-policies FIPS configuration files and append
sed -i -e "s:^security.useSystemPropertiesFile=.*:security.useSystemPropertiesFile=true:" \ # include line to java.security
${imagepath}/conf/security/java.security bash -ex %{SOURCE32} ${imagepath}/conf/security %{_libdir}/%{sdkdir -- ${suffix}}/libnssadapter.so
# Use system-wide tzdata # Use system-wide tzdata
rm ${imagepath}/lib/tzdb.dat rm ${imagepath}/lib/tzdb.dat
@ -1977,12 +2010,16 @@ for suffix in %{build_loop} ; do
if [ "x$suffix" = "x" ] ; then if [ "x$suffix" = "x" ] ; then
jdkzip=%{releasezip} jdkzip=%{releasezip}
staticlibzip=%{staticlibzip} staticlibzip=%{staticlibzip}
make -C %{nssadapter_name} CFLAGS="%{build_cflags}" LDFLAGS="%{build_ldflags}"
elif [ "x$suffix" = "x%{fastdebug_suffix_unquoted}" ] ; then elif [ "x$suffix" = "x%{fastdebug_suffix_unquoted}" ] ; then
jdkzip=%{fastdebugzip} jdkzip=%{fastdebugzip}
staticlibzip=%{fastdebugstaticlibzip} staticlibzip=%{fastdebugstaticlibzip}
make -C %{nssadapter_name} CFLAGS="%{build_cflags}" LDFLAGS="%{build_ldflags}"
else # slowdebug else # slowdebug
jdkzip=%{slowdebugzip} jdkzip=%{slowdebugzip}
staticlibzip=%{slowdebugstaticlibzip} staticlibzip=%{slowdebugstaticlibzip}
# Disable _FORTIFY_SOURCE to allow for no optimization
make -C %{nssadapter_name} CFLAGS="%{build_cflags} -O0 -Wp,-U_FORTIFY_SOURCE" LDFLAGS="%{build_ldflags}"
fi fi
installdir=%{installoutputdir -- ${suffix}} installdir=%{installoutputdir -- ${suffix}}
@ -1992,6 +2029,10 @@ for suffix in %{build_loop} ; do
tar -xJf ${staticlibzip} tar -xJf ${staticlibzip}
mv java-%{featurever}-openjdk* ${installdir} mv java-%{featurever}-openjdk* ${installdir}
# Install and clean libnssadapter.so
install -m 755 %{nssadapter_name}/bin/libnssadapter.so ${installdir}/lib
make -C %{nssadapter_name} clean
# Fix build paths in ELF files so it looks like we built them # Fix build paths in ELF files so it looks like we built them
portablenvr="%{name}-%{VERSION}-%{prelease}.%{portablesuffix}.%{_arch}" portablenvr="%{name}-%{VERSION}-%{prelease}.%{portablesuffix}.%{_arch}"
for file in $(find ${installdir} -type f) ; do for file in $(find ${installdir} -type f) ; do
@ -2017,7 +2058,7 @@ for suffix in %{build_loop} ; do
%endif %endif
# Final setup on the main image # Final setup on the main image
customisejdk ${installdir} customisejdk ${installdir} ${suffix}
# Print release information # Print release information
cat ${installdir}/release cat ${installdir}/release
@ -2057,7 +2098,7 @@ $JAVA_HOME/bin/java -XX:+UnlockExperimentalVMOptions -XX:+UseShenandoahGC -versi
export PROG=$(echo $(basename %{SOURCE15})|sed "s|\.java||") export PROG=$(echo $(basename %{SOURCE15})|sed "s|\.java||")
export SEC_DEBUG="-Djava.security.debug=properties" export SEC_DEBUG="-Djava.security.debug=properties"
$JAVA_HOME/bin/java ${SEC_DEBUG} ${PROG} %{crypto_policy_active} $JAVA_HOME/bin/java ${SEC_DEBUG} ${PROG} %{crypto_policy_active}
$JAVA_HOME/bin/java ${SEC_DEBUG} -Djava.security.disableSystemPropertiesFile=true ${PROG} false $JAVA_HOME/bin/java ${SEC_DEBUG} -Dredhat.crypto-policies=false ${PROG} false
# Check correct vendor values have been set # Check correct vendor values have been set
$JAVA_HOME/bin/javac -d . %{SOURCE16} $JAVA_HOME/bin/javac -d . %{SOURCE16}
@ -2067,10 +2108,7 @@ $JAVA_HOME/bin/java -XX:+UnlockExperimentalVMOptions -XX:+UseShenandoahGC -versi
# Check translations are available for new timezones (during flatpak builds, the # Check translations are available for new timezones (during flatpak builds, the
# tzdb.dat used by this test is not where the test expects it, so this is # tzdb.dat used by this test is not where the test expects it, so this is
# disabled for flatpak builds) # disabled for flatpak builds)
# Disable test until we are on the latest JDK $JAVA_HOME/bin/java %{SOURCE18}
$JAVA_HOME/bin/javac -d . %{SOURCE18}
$JAVA_HOME/bin/java $(echo $(basename %{SOURCE18})|sed "s|\.java||") JRE
$JAVA_HOME/bin/java -Djava.locale.providers=CLDR $(echo $(basename %{SOURCE18})|sed "s|\.java||") CLDR
%endif %endif
# Check src.zip has all sources. See RHBZ#1130490 # Check src.zip has all sources. See RHBZ#1130490
@ -2225,6 +2263,9 @@ install -D -p -m 755 ${miscdir}/%{alt_java_name} $RPM_BUILD_ROOT%{jrebindir -- $
done done
%endif %endif
install -d -m 755 $RPM_BUILD_ROOT%{_libdir}/%{sdkdir -- ${suffix}}
mv $RPM_BUILD_ROOT%{_jvmdir}/%{sdkdir -- $suffix}/lib/libnssadapter.so $RPM_BUILD_ROOT%{_libdir}/%{sdkdir -- ${suffix}}
# Remove empty cacerts database # Remove empty cacerts database
rm -f $RPM_BUILD_ROOT%{_jvmdir}/%{sdkdir -- $suffix}/lib/security/cacerts rm -f $RPM_BUILD_ROOT%{_jvmdir}/%{sdkdir -- $suffix}/lib/security/cacerts
# Install cacerts symlink needed by some apps which hard-code the path # Install cacerts symlink needed by some apps which hard-code the path
@ -2471,6 +2512,9 @@ exit 0
%endif %endif
%if %{include_normal_build} %if %{include_normal_build}
%files crypto-adapter
%{files_crypto_adapter %{nil}}
%files headless %files headless
%{files_jre_headless %{nil}} %{files_jre_headless %{nil}}
@ -2502,6 +2546,9 @@ exit 0
%endif %endif
%if %{include_debug_build} %if %{include_debug_build}
%files crypto-adapter-slowdebug
%{files_crypto_adapter -- %{debug_suffix_unquoted}}
%files slowdebug %files slowdebug
%{files_jre -- %{debug_suffix_unquoted}} %{files_jre -- %{debug_suffix_unquoted}}
@ -2527,6 +2574,9 @@ exit 0
%endif %endif
%if %{include_fastdebug_build} %if %{include_fastdebug_build}
%files crypto-adapter-fastdebug
%{files_crypto_adapter -- %{fastdebug_suffix_unquoted}}
%files fastdebug %files fastdebug
%{files_jre -- %{fastdebug_suffix_unquoted}} %{files_jre -- %{fastdebug_suffix_unquoted}}
@ -2553,6 +2603,164 @@ exit 0
%endif %endif
%changelog %changelog
* Thu Jul 23 2026 Eduard Abdullin <eabdullin@almalinux.org> - 1:25.0.4.0.7-1.1.alma.1
- Use el9 portable packages
* Thu Jul 16 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.4.0.7-1.0
- Update to jdk-25.0.4+7 (GA)
- Update release notes to 25.0.4+7
- Bump freetype version to 2.14.3 following JDK-8385390
- Bump giflib version to 6.1.3 following JDK-8384902
- Bump HarfBuzz version to 14.2.0 following JDK-8385490
- Bump lcms2 version to 2.19.1 following JDK-8375065 & JDK-8383354
- Bump libpng version to 1.6.58 following JDK-8384495
- Require tzdata 2026b due to upstream inclusion of JDK-8383175
- Drop local copy of JDK-8375294 EOPNOTSUPP patch
- Obsolete old RHEL releases (9.7.0-z, 10.1-z)
- Revert fr_FR and de_DE changes made in d43f0e6186370fdeb0ca2f3594f39783e20eef1c now JDK-8382020 is fixed
- Simplify TestTranslations run now there is only the CLDR provider and one set of data (JDK-8174269)
- Make zone string debug output optional in TestTranslations
- Sync the copy of the portable specfile with the latest update
- ** This tarball is embargoed until 2026-07-21 @ 1pm PT. **
- Resolves: RHEL-188883
- Resolves: RHEL-212294
- Resolves: RHEL-212296
* Tue Jul 14 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.3.0.9-3.1
- Cleanup tagging and gating scripts to appease shellcheck:
- * scripts/builds/build_vanilla.sh: Use an array to handle the varying arguments to rhpkg.
- * scripts/builds/check_signatures.sh: Quote variable usage.
- * scripts/builds/waive_issue.sh: Remove redundant 'test "x"' usage.
- * scripts/builds/waive_leapp_issue.sh: Likewise.
- * scripts/builds/waive_rpminspect.sh: Likewise.
- * scripts/builds/waive_usual_rpminspect.sh: Likewise and add missing WORKING_DIR variable.
- * scripts/builds/waive_usual_tier0.sh: Remove redundant 'test "x"' usage.
- Remove macro references in comments where possible (%dnl not compatible enough yet)
- Move version information and core NVR definitions back towards the top of the file
- Specify portablerelease and rpmrelease (always 0 for portables) in the Release field
- Add 25u backports of JDK-8347901 & JDK-8378713 C2 performance fixes
- Sync the copy of the portable specfile with the latest update
- Related: RHEL-155327
- Related: RHEL-155339
- Resolves: RHEL-150977
- Resolves: RHEL-210972
- Resolves: RHEL-210993
* Sat Apr 18 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.3.0.9-1
- Update to jdk-25.0.3+9 (GA)
- Update release notes to 25.0.3+9
- Update FIPS patch to 57722aab802 version synced with 25.0.3+8
- Drop local libpng patches now JDK-8372534, JDK-8375063 & JDK-8377526 are included upstream
- Drop local HarfBuzz patch now JDK-8375057 is included upstream
- Bump freetype version to 2.14.2 following JDK-8373290 & JDK-8379158
- Bump giflib version to 6.1.2 following JDK-8379256 & JDK-8380078
- Bump libpng version to 1.6.57 following JDK-8380959 & JDK-8382047
- Bump zlib version to 1.3.2 following JDK-8378631
- Bump tzdata version to 2026a following JDK-8379035
- Add JDK-8375294 EOPNOTSUPP patch ahead of 25.0.4
- Sync the copy of the portable specfile with the latest update
- ** This tarball is embargoed until 2026-04-21 @ 1pm PT. **
- Resolves: RHEL-169620
- Resolves: RHEL-157091
- Resolves: RHEL-161217
- Resolves: RHEL-161333
- Resolves: RHEL-169613
* Thu Mar 12 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.2.0.10-4
- Add tagging scripts with signature checks and gating handling
- Update tagged versions to include 9.8.0-z, 9.9.0, 10.2-z & 10.3.
- Add gating scripts to simplify obtaining results and waiving issues
- Sync the copy of the portable specfile with the latest update
- Resolves: RHEL-155327
- Resolves: RHEL-155337
- Resolves: RHEL-155339
- Related: RHEL-155000
- Related: RHEL-146649
- Related: RHEL-148327
- Related: RHEL-148830
* Wed Mar 11 2026 Thomas Fitzsimmons <fitzsim@redhat.com> - 1:25.0.2.0.10-3
- Disable abidiff inspection in rpminspect.yaml to avoid an out-of-memory error on the CentOS test farm
- See: https://docs.testing-farm.io/Testing%20Farm/0.1/errors.html#TFE-1
- Resolves: RHEL-150976
* Tue Mar 03 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.2.0.10-3
- Update FIPS patch to e55ada9353e to include the fix for the too restrictive provider lockdown
- Fix FIPS issue list to represent the new 25u version
- Add JDK-8375063 libpng 1.6.54 ahead of 25.0.3
- Add JDK-8375057 harfbuzz 12.3.2 ahead of 25.0.3
- Add JDK-8377526 libpng 1.6.55 ahead of 25.0.3
- Bump libpng version to 1.6.55 following JDK-8375063 & JDK-8377526
- Bump harfbuzz version to 12.3.2 following JDK-8375057
- Bump nssadapter version to bring in shared PKCS11 session fix
- Drop LDFLAGS nssadapter patch which is now upstream in 0.1.1
- Resolves: RHEL-155000
- Resolves: RHEL-146649
- Resolves: RHEL-148327
- Resolves: RHEL-148830
- Resolves: RHEL-155044
* Wed Feb 18 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.2.0.10-2
- Bump rpmrelease for CentOS build
- Related: RHEL-139579
- Related: RHEL-131430
- Related: RHEL-131443
- Related: RHEL-142855
- Related: RHEL-142799
* Wed Jan 21 2026 Jiri Vanek <jvanek@redhat.com> - 1:25.0.2.0.10-1
- Execute create-redhat-properties-files.bash with '-e' to exit on failure
- Related: RHEL-142855
* Mon Jan 12 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.2.0.10-1
- Update to jdk-25.0.2+10 (GA)
- Update release notes to 25.0.2+10
- Add JDK-8372534 libpng 1.6.51 ahead of 25.0.3
- Bump libpng version to 1.6.51 following JDK-8372534
- Bump ID of NSS adapter patch so we can stay in sync with portable on the libpng patch
- Test for java.security's existence in create-redhat-properties-files.bash
- Handle 'upgrade' as an alternative to 'update' in openjdk_news.sh
- Sync the copy of the portable specfile with the latest update
- ** This tarball is embargoed until 2026-01-20 @ 1pm PT. **
- Resolves: RHEL-139579
- Resolves: RHEL-131430
- Resolves: RHEL-131443
- Resolves: RHEL-142855
- Resolves: RHEL-142799
* Sat Dec 06 2025 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.1.0.8-6
- Sync the copy of the portable specfile with the latest update
- Related: RHEL-133733
- Related: RHEL-133735
* Thu Dec 04 2025 Thomas Fitzsimmons <fitzsim@redhat.com> - 1:25.0.1.0.8-6
- Remove /usr/lib/jvm/java-25-openjdk/conf/security/redhat/fips.properties
- Resolves: RHEL-131897
* Thu Dec 04 2025 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.1.0.8-5
- Incorporate new FIPS patch for 25u
- Drop static libjvm.a following adjusted build target for portable build
- Remove redundant (and now outdated) build targets, jdkimage and static_libs_image
- Pass ourflags and ourldflags into the nssadapter build using CFLAGS & LDFLAGS
- Patch the nssadapter build to recognise LDFLAGS
- Remove OpenJDK compiler flag filters and use build_{c,ld}flags directly
- Resolves: RHEL-133733
- Resolves: RHEL-133735
- Resolves: RHEL-133763
* Wed Nov 26 2025 Thomas Fitzsimmons <fitzsim@redhat.com> - 1:25.0.1.0.8-4
- Add java-25-openjdk-crypto-adapter subpackage
- Update library setting in create-redhat-properties-files.bash
- Resolves: RHEL-131896
* Mon Nov 24 2025 Thomas Fitzsimmons <fitzsim@redhat.com> - 1:25.0.1.0.8-3
- Add libnssadapter.so
- Add FIPS crypto-policies configuration
- Remove obsolete security.useSystemPropertiesFile setup
- Update TestSecurityProperties.java test and calling convention
- Resolves: RHEL-128413
- Resolves: RHEL-128409
* Wed Nov 12 2025 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.1.0.8-2 * Wed Nov 12 2025 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.1.0.8-2
- Remove superfluous backslashes that cause two alternative commands to be combined - Remove superfluous backslashes that cause two alternative commands to be combined
- Related: RHEL-120553 - Related: RHEL-120553

View File

@ -0,0 +1,772 @@
From 09853461a6896ab1f15469c753c21ca212e7e650 Mon Sep 17 00:00:00 2001
From: duke <duke@openjdk.org>
Date: Tue, 7 Apr 2026 15:14:53 +0000
Subject: [PATCH 1/2] Backport ed70910b0f3e1b19d915ec13ac3434407d01bc5d
---
src/hotspot/share/opto/callnode.cpp | 53 +++++++-
src/hotspot/share/opto/callnode.hpp | 29 ++++-
src/hotspot/share/opto/classes.hpp | 2 +
src/hotspot/share/opto/compile.cpp | 19 +++
src/hotspot/share/opto/divnode.cpp | 158 ++++++++++--------------
src/hotspot/share/opto/divnode.hpp | 35 +++---
src/hotspot/share/opto/graphKit.cpp | 29 +++--
src/hotspot/share/opto/graphKit.hpp | 1 +
src/hotspot/share/opto/library_call.cpp | 2 +-
src/hotspot/share/opto/macro.cpp | 15 +--
src/hotspot/share/opto/multnode.cpp | 13 ++
src/hotspot/share/opto/multnode.hpp | 46 +++++++
src/hotspot/share/opto/node.cpp | 12 +-
src/hotspot/share/opto/node.hpp | 5 +-
src/hotspot/share/opto/parse2.cpp | 8 +-
15 files changed, 282 insertions(+), 145 deletions(-)
diff --git a/src/hotspot/share/opto/callnode.cpp b/src/hotspot/share/opto/callnode.cpp
index 6f13ce0f809..fc4b0c35dff 100644
--- a/src/hotspot/share/opto/callnode.cpp
+++ b/src/hotspot/share/opto/callnode.cpp
@@ -935,7 +935,7 @@ Node *CallNode::result_cast() {
}
-void CallNode::extract_projections(CallProjections* projs, bool separate_io_proj, bool do_asserts) {
+void CallNode::extract_projections(CallProjections* projs, bool separate_io_proj, bool do_asserts) const {
projs->fallthrough_proj = nullptr;
projs->fallthrough_catchproj = nullptr;
projs->fallthrough_ioproj = nullptr;
@@ -1319,6 +1319,57 @@ void CallLeafVectorNode::calling_convention( BasicType* sig_bt, VMRegPair *parm_
//=============================================================================
+bool CallLeafPureNode::is_unused() const {
+ return proj_out_or_null(TypeFunc::Parms) == nullptr;
+}
+
+bool CallLeafPureNode::is_dead() const {
+ return proj_out_or_null(TypeFunc::Control) == nullptr;
+}
+
+/* We make a tuple of the global input state + TOP for the output values.
+ * We use this to delete a pure function that is not used: by replacing the call with
+ * such a tuple, we let output Proj's idealization pick the corresponding input of the
+ * pure call, so jumping over it, and effectively, removing the call from the graph.
+ * This avoids doing the graph surgery manually, but leaves that to IGVN
+ * that is specialized for doing that right. We need also tuple components for output
+ * values of the function to respect the return arity, and in case there is a projection
+ * that would pick an output (which shouldn't happen at the moment).
+ */
+TupleNode* CallLeafPureNode::make_tuple_of_input_state_and_top_return_values(const Compile* C) const {
+ // Transparently propagate input state but parameters
+ TupleNode* tuple = TupleNode::make(
+ tf()->range(),
+ in(TypeFunc::Control),
+ in(TypeFunc::I_O),
+ in(TypeFunc::Memory),
+ in(TypeFunc::FramePtr),
+ in(TypeFunc::ReturnAdr));
+
+ // And add TOPs for the return values
+ for (uint i = TypeFunc::Parms; i < tf()->range()->cnt(); i++) {
+ tuple->set_req(i, C->top());
+ }
+
+ return tuple;
+}
+
+Node* CallLeafPureNode::Ideal(PhaseGVN* phase, bool can_reshape) {
+ if (is_dead()) {
+ return nullptr;
+ }
+
+ // We need to wait until IGVN because during parsing, usages might still be missing
+ // and we would remove the call immediately.
+ if (can_reshape && is_unused()) {
+ // The result is not used. We remove the call by replacing it with a tuple, that
+ // is later disintegrated by the projections.
+ return make_tuple_of_input_state_and_top_return_values(phase->C);
+ }
+
+ return CallRuntimeNode::Ideal(phase, can_reshape);
+}
+
#ifndef PRODUCT
void CallLeafNode::dump_spec(outputStream *st) const {
st->print("# ");
diff --git a/src/hotspot/share/opto/callnode.hpp b/src/hotspot/share/opto/callnode.hpp
index 213fbda4e89..2462a88143f 100644
--- a/src/hotspot/share/opto/callnode.hpp
+++ b/src/hotspot/share/opto/callnode.hpp
@@ -752,7 +752,7 @@ class CallNode : public SafePointNode {
// Collect all the interesting edges from a call for use in
// replacing the call by something else. Used by macro expansion
// and the late inlining support.
- void extract_projections(CallProjections* projs, bool separate_io_proj, bool do_asserts = true);
+ void extract_projections(CallProjections* projs, bool separate_io_proj, bool do_asserts = true) const;
virtual uint match_edge(uint idx) const;
@@ -928,6 +928,33 @@ class CallLeafNode : public CallRuntimeNode {
#endif
};
+/* A pure function call, they are assumed not to be safepoints, not to read or write memory,
+ * have no exception... They just take parameters, return a value without side effect. It is
+ * always correct to create some, or remove them, if the result is not used.
+ *
+ * They still have control input to allow easy lowering into other kind of calls that require
+ * a control, but this is more a technical than a moral constraint.
+ *
+ * Pure calls must have only control and data input and output: I/O, Memory and so on must be top.
+ * Nevertheless, pure calls can typically be expensive math operations so care must be taken
+ * when letting the node float.
+ */
+class CallLeafPureNode : public CallLeafNode {
+protected:
+ bool is_unused() const;
+ bool is_dead() const;
+ TupleNode* make_tuple_of_input_state_and_top_return_values(const Compile* C) const;
+
+public:
+ CallLeafPureNode(const TypeFunc* tf, address addr, const char* name,
+ const TypePtr* adr_type)
+ : CallLeafNode(tf, addr, name, adr_type) {
+ init_class_id(Class_CallLeafPure);
+ }
+ int Opcode() const override;
+ Node* Ideal(PhaseGVN* phase, bool can_reshape) override;
+};
+
//------------------------------CallLeafNoFPNode-------------------------------
// CallLeafNode, not using floating point or using it in the same manner as
// the generated code
diff --git a/src/hotspot/share/opto/classes.hpp b/src/hotspot/share/opto/classes.hpp
index bc259eed2d1..587d5fad8f2 100644
--- a/src/hotspot/share/opto/classes.hpp
+++ b/src/hotspot/share/opto/classes.hpp
@@ -61,6 +61,7 @@ macro(CallDynamicJava)
macro(CallJava)
macro(CallLeaf)
macro(CallLeafNoFP)
+macro(CallLeafPure)
macro(CallLeafVector)
macro(CallRuntime)
macro(CallStaticJava)
@@ -372,6 +373,7 @@ macro(SubI)
macro(SubL)
macro(TailCall)
macro(TailJump)
+macro(Tuple)
macro(MacroLogicV)
macro(ThreadLocal)
macro(Unlock)
diff --git a/src/hotspot/share/opto/compile.cpp b/src/hotspot/share/opto/compile.cpp
index 2b956dcb5d8..9f7f48b9a34 100644
--- a/src/hotspot/share/opto/compile.cpp
+++ b/src/hotspot/share/opto/compile.cpp
@@ -3298,6 +3298,25 @@ void Compile::final_graph_reshaping_main_switch(Node* n, Final_Reshape_Counts& f
case Op_Opaque1: // Remove Opaque Nodes before matching
n->subsume_by(n->in(1), this);
break;
+ case Op_CallLeafPure: {
+ // If the pure call is not supported, then lower to a CallLeaf.
+ if (!Matcher::match_rule_supported(Op_CallLeafPure)) {
+ CallNode* call = n->as_Call();
+ CallNode* new_call = new CallLeafNode(call->tf(), call->entry_point(),
+ call->_name, TypeRawPtr::BOTTOM);
+ new_call->init_req(TypeFunc::Control, call->in(TypeFunc::Control));
+ new_call->init_req(TypeFunc::I_O, C->top());
+ new_call->init_req(TypeFunc::Memory, C->top());
+ new_call->init_req(TypeFunc::ReturnAdr, C->top());
+ new_call->init_req(TypeFunc::FramePtr, C->top());
+ for (unsigned int i = TypeFunc::Parms; i < call->tf()->domain()->cnt(); i++) {
+ new_call->init_req(i, call->in(i));
+ }
+ n->subsume_by(new_call, this);
+ }
+ frc.inc_call_count();
+ break;
+ }
case Op_CallStaticJava:
case Op_CallJava:
case Op_CallDynamicJava:
diff --git a/src/hotspot/share/opto/divnode.cpp b/src/hotspot/share/opto/divnode.cpp
index a70194274a7..5dd8be877ff 100644
--- a/src/hotspot/share/opto/divnode.cpp
+++ b/src/hotspot/share/opto/divnode.cpp
@@ -42,19 +42,19 @@
#include <math.h>
-ModFloatingNode::ModFloatingNode(Compile* C, const TypeFunc* tf, const char* name) : CallLeafNode(tf, nullptr, name, TypeRawPtr::BOTTOM) {
+ModFloatingNode::ModFloatingNode(Compile* C, const TypeFunc* tf, address addr, const char* name) : CallLeafPureNode(tf, addr, name, TypeRawPtr::BOTTOM) {
add_flag(Flag_is_macro);
C->add_macro_node(this);
}
-ModDNode::ModDNode(Compile* C, Node* a, Node* b) : ModFloatingNode(C, OptoRuntime::Math_DD_D_Type(), "drem") {
+ModDNode::ModDNode(Compile* C, Node* a, Node* b) : ModFloatingNode(C, OptoRuntime::Math_DD_D_Type(), CAST_FROM_FN_PTR(address, SharedRuntime::drem), "drem") {
init_req(TypeFunc::Parms + 0, a);
init_req(TypeFunc::Parms + 1, C->top());
init_req(TypeFunc::Parms + 2, b);
init_req(TypeFunc::Parms + 3, C->top());
}
-ModFNode::ModFNode(Compile* C, Node* a, Node* b) : ModFloatingNode(C, OptoRuntime::modf_Type(), "frem") {
+ModFNode::ModFNode(Compile* C, Node* a, Node* b) : ModFloatingNode(C, OptoRuntime::modf_Type(), CAST_FROM_FN_PTR(address, SharedRuntime::frem), "frem") {
init_req(TypeFunc::Parms + 0, a);
init_req(TypeFunc::Parms + 1, b);
}
@@ -1516,137 +1516,109 @@ const Type* UModLNode::Value(PhaseGVN* phase) const {
return unsigned_mod_value<TypeLong, julong, jlong>(phase, this);
}
-Node* ModFNode::Ideal(PhaseGVN* phase, bool can_reshape) {
- if (!can_reshape) {
- return nullptr;
- }
- PhaseIterGVN* igvn = phase->is_IterGVN();
-
- bool result_is_unused = proj_out_or_null(TypeFunc::Parms) == nullptr;
- bool not_dead = proj_out_or_null(TypeFunc::Control) != nullptr;
- if (result_is_unused && not_dead) {
- return replace_with_con(igvn, TypeF::make(0.));
- }
-
- // Either input is TOP ==> the result is TOP
- const Type* t1 = phase->type(dividend());
- const Type* t2 = phase->type(divisor());
- if (t1 == Type::TOP || t2 == Type::TOP) {
- return phase->C->top();
- }
-
+const Type* ModFNode::get_result_if_constant(const Type* dividend, const Type* divisor) const {
// If either number is not a constant, we know nothing.
- if ((t1->base() != Type::FloatCon) || (t2->base() != Type::FloatCon)) {
+ if ((dividend->base() != Type::FloatCon) || (divisor->base() != Type::FloatCon)) {
return nullptr; // note: x%x can be either NaN or 0
}
- float f1 = t1->getf();
- float f2 = t2->getf();
- jint x1 = jint_cast(f1); // note: *(int*)&f1, not just (int)f1
- jint x2 = jint_cast(f2);
+ float dividend_f = dividend->getf();
+ float divisor_f = divisor->getf();
+ jint dividend_i = jint_cast(dividend_f); // note: *(int*)&f1, not just (int)f1
+ jint divisor_i = jint_cast(divisor_f);
// If either is a NaN, return an input NaN
- if (g_isnan(f1)) {
- return replace_with_con(igvn, t1);
+ if (g_isnan(dividend_f)) {
+ return dividend;
}
- if (g_isnan(f2)) {
- return replace_with_con(igvn, t2);
+ if (g_isnan(divisor_f)) {
+ return divisor;
}
// If an operand is infinity or the divisor is +/- zero, punt.
- if (!g_isfinite(f1) || !g_isfinite(f2) || x2 == 0 || x2 == min_jint) {
+ if (!g_isfinite(dividend_f) || !g_isfinite(divisor_f) || divisor_i == 0 || divisor_i == min_jint) {
return nullptr;
}
// We must be modulo'ing 2 float constants.
// Make sure that the sign of the fmod is equal to the sign of the dividend
- jint xr = jint_cast(fmod(f1, f2));
- if ((x1 ^ xr) < 0) {
+ jint xr = jint_cast(fmod(dividend_f, divisor_f));
+ if ((dividend_i ^ xr) < 0) {
xr ^= min_jint;
}
- return replace_with_con(igvn, TypeF::make(jfloat_cast(xr)));
+ return TypeF::make(jfloat_cast(xr));
}
-Node* ModDNode::Ideal(PhaseGVN* phase, bool can_reshape) {
- if (!can_reshape) {
- return nullptr;
- }
- PhaseIterGVN* igvn = phase->is_IterGVN();
-
- bool result_is_unused = proj_out_or_null(TypeFunc::Parms) == nullptr;
- bool not_dead = proj_out_or_null(TypeFunc::Control) != nullptr;
- if (result_is_unused && not_dead) {
- return replace_with_con(igvn, TypeD::make(0.));
- }
-
- // Either input is TOP ==> the result is TOP
- const Type* t1 = phase->type(dividend());
- const Type* t2 = phase->type(divisor());
- if (t1 == Type::TOP || t2 == Type::TOP) {
- return nullptr;
- }
-
+const Type* ModDNode::get_result_if_constant(const Type* dividend, const Type* divisor) const {
// If either number is not a constant, we know nothing.
- if ((t1->base() != Type::DoubleCon) || (t2->base() != Type::DoubleCon)) {
+ if ((dividend->base() != Type::DoubleCon) || (divisor->base() != Type::DoubleCon)) {
return nullptr; // note: x%x can be either NaN or 0
}
- double f1 = t1->getd();
- double f2 = t2->getd();
- jlong x1 = jlong_cast(f1); // note: *(long*)&f1, not just (long)f1
- jlong x2 = jlong_cast(f2);
+ double dividend_d = dividend->getd();
+ double divisor_d = divisor->getd();
+ jlong dividend_l = jlong_cast(dividend_d); // note: *(long*)&f1, not just (long)f1
+ jlong divisor_l = jlong_cast(divisor_d);
// If either is a NaN, return an input NaN
- if (g_isnan(f1)) {
- return replace_with_con(igvn, t1);
+ if (g_isnan(dividend_d)) {
+ return dividend;
}
- if (g_isnan(f2)) {
- return replace_with_con(igvn, t2);
+ if (g_isnan(divisor_d)) {
+ return divisor;
}
// If an operand is infinity or the divisor is +/- zero, punt.
- if (!g_isfinite(f1) || !g_isfinite(f2) || x2 == 0 || x2 == min_jlong) {
+ if (!g_isfinite(dividend_d) || !g_isfinite(divisor_d) || divisor_l == 0 || divisor_l == min_jlong) {
return nullptr;
}
// We must be modulo'ing 2 double constants.
// Make sure that the sign of the fmod is equal to the sign of the dividend
- jlong xr = jlong_cast(fmod(f1, f2));
- if ((x1 ^ xr) < 0) {
+ jlong xr = jlong_cast(fmod(dividend_d, divisor_d));
+ if ((dividend_l ^ xr) < 0) {
xr ^= min_jlong;
}
- return replace_with_con(igvn, TypeD::make(jdouble_cast(xr)));
+ return TypeD::make(jdouble_cast(xr));
}
-Node* ModFloatingNode::replace_with_con(PhaseIterGVN* phase, const Type* con) {
- Compile* C = phase->C;
- Node* con_node = phase->makecon(con);
- CallProjections projs;
- extract_projections(&projs, false, false);
- phase->replace_node(projs.fallthrough_proj, in(TypeFunc::Control));
- if (projs.fallthrough_catchproj != nullptr) {
- phase->replace_node(projs.fallthrough_catchproj, in(TypeFunc::Control));
- }
- if (projs.fallthrough_memproj != nullptr) {
- phase->replace_node(projs.fallthrough_memproj, in(TypeFunc::Memory));
- }
- if (projs.catchall_memproj != nullptr) {
- phase->replace_node(projs.catchall_memproj, C->top());
- }
- if (projs.fallthrough_ioproj != nullptr) {
- phase->replace_node(projs.fallthrough_ioproj, in(TypeFunc::I_O));
- }
- assert(projs.catchall_ioproj == nullptr, "no exceptions from floating mod");
- assert(projs.catchall_catchproj == nullptr, "no exceptions from floating mod");
- if (projs.resproj != nullptr) {
- phase->replace_node(projs.resproj, con_node);
+Node* ModFloatingNode::Ideal(PhaseGVN* phase, bool can_reshape) {
+ if (can_reshape) {
+ PhaseIterGVN* igvn = phase->is_IterGVN();
+
+ // Either input is TOP ==> the result is TOP
+ const Type* dividend_type = phase->type(dividend());
+ const Type* divisor_type = phase->type(divisor());
+ if (dividend_type == Type::TOP || divisor_type == Type::TOP) {
+ return phase->C->top();
+ }
+ const Type* constant_result = get_result_if_constant(dividend_type, divisor_type);
+ if (constant_result != nullptr) {
+ return make_tuple_of_input_state_and_constant_result(igvn, constant_result);
+ }
}
- phase->replace_node(this, C->top());
- C->remove_macro_node(this);
- disconnect_inputs(C);
- return nullptr;
+
+ return CallLeafPureNode::Ideal(phase, can_reshape);
+}
+
+/* Give a tuple node for ::Ideal to return, made of the input state (control to return addr)
+ * and the given constant result. Idealization of projections will make sure to transparently
+ * propagate the input state and replace the result by the said constant.
+ */
+TupleNode* ModFloatingNode::make_tuple_of_input_state_and_constant_result(PhaseIterGVN* phase, const Type* con) const {
+ Node* con_node = phase->makecon(con);
+ TupleNode* tuple = TupleNode::make(
+ tf()->range(),
+ in(TypeFunc::Control),
+ in(TypeFunc::I_O),
+ in(TypeFunc::Memory),
+ in(TypeFunc::FramePtr),
+ in(TypeFunc::ReturnAdr),
+ con_node);
+
+ return tuple;
}
//=============================================================================
diff --git a/src/hotspot/share/opto/divnode.hpp b/src/hotspot/share/opto/divnode.hpp
index 127e2431b0b..b13460c89f5 100644
--- a/src/hotspot/share/opto/divnode.hpp
+++ b/src/hotspot/share/opto/divnode.hpp
@@ -156,40 +156,45 @@ class ModLNode : public Node {
};
// Base class for float and double modulus
-class ModFloatingNode : public CallLeafNode {
+class ModFloatingNode : public CallLeafPureNode {
+ TupleNode* make_tuple_of_input_state_and_constant_result(PhaseIterGVN* phase, const Type* con) const;
+
protected:
- Node* replace_with_con(PhaseIterGVN* phase, const Type* con);
+ virtual Node* dividend() const = 0;
+ virtual Node* divisor() const = 0;
+ virtual const Type* get_result_if_constant(const Type* dividend, const Type* divisor) const = 0;
public:
- ModFloatingNode(Compile* C, const TypeFunc* tf, const char *name);
+ ModFloatingNode(Compile* C, const TypeFunc* tf, address addr, const char* name);
+ Node* Ideal(PhaseGVN* phase, bool can_reshape) override;
};
// Float Modulus
class ModFNode : public ModFloatingNode {
private:
- Node* dividend() const { return in(TypeFunc::Parms + 0); }
- Node* divisor() const { return in(TypeFunc::Parms + 1); }
+ Node* dividend() const override { return in(TypeFunc::Parms + 0); }
+ Node* divisor() const override { return in(TypeFunc::Parms + 1); }
+ const Type* get_result_if_constant(const Type* dividend, const Type* divisor) const override;
public:
ModFNode(Compile* C, Node* a, Node* b);
- virtual int Opcode() const;
- virtual uint ideal_reg() const { return Op_RegF; }
- virtual uint size_of() const { return sizeof(*this); }
- virtual Node* Ideal(PhaseGVN* phase, bool can_reshape);
+ int Opcode() const override;
+ uint ideal_reg() const override { return Op_RegF; }
+ uint size_of() const override { return sizeof(*this); }
};
// Double Modulus
class ModDNode : public ModFloatingNode {
private:
- Node* dividend() const { return in(TypeFunc::Parms + 0); }
- Node* divisor() const { return in(TypeFunc::Parms + 2); }
+ Node* dividend() const override { return in(TypeFunc::Parms + 0); }
+ Node* divisor() const override { return in(TypeFunc::Parms + 2); }
+ const Type* get_result_if_constant(const Type* dividend, const Type* divisor) const override;
public:
ModDNode(Compile* C, Node* a, Node* b);
- virtual int Opcode() const;
- virtual uint ideal_reg() const { return Op_RegD; }
- virtual uint size_of() const { return sizeof(*this); }
- virtual Node* Ideal(PhaseGVN* phase, bool can_reshape);
+ int Opcode() const override;
+ uint ideal_reg() const override { return Op_RegD; }
+ uint size_of() const override { return sizeof(*this); }
};
//------------------------------UModINode---------------------------------------
diff --git a/src/hotspot/share/opto/graphKit.cpp b/src/hotspot/share/opto/graphKit.cpp
index 20feca26ede..1b8b7008578 100644
--- a/src/hotspot/share/opto/graphKit.cpp
+++ b/src/hotspot/share/opto/graphKit.cpp
@@ -1880,14 +1880,20 @@ Node* GraphKit::set_results_for_java_call(CallJavaNode* call, bool separate_io_p
// after the call, if this call has restricted memory effects.
Node* GraphKit::set_predefined_input_for_runtime_call(SafePointNode* call, Node* narrow_mem) {
// Set fixed predefined input arguments
- Node* memory = reset_memory();
- Node* m = narrow_mem == nullptr ? memory : narrow_mem;
- call->init_req( TypeFunc::Control, control() );
- call->init_req( TypeFunc::I_O, top() ); // does no i/o
- call->init_req( TypeFunc::Memory, m ); // may gc ptrs
- call->init_req( TypeFunc::FramePtr, frameptr() );
- call->init_req( TypeFunc::ReturnAdr, top() );
- return memory;
+ call->init_req(TypeFunc::Control, control());
+ call->init_req(TypeFunc::I_O, top()); // does no i/o
+ call->init_req(TypeFunc::ReturnAdr, top());
+ if (call->is_CallLeafPure()) {
+ call->init_req(TypeFunc::Memory, top());
+ call->init_req(TypeFunc::FramePtr, top());
+ return nullptr;
+ } else {
+ Node* memory = reset_memory();
+ Node* m = narrow_mem == nullptr ? memory : narrow_mem;
+ call->init_req(TypeFunc::Memory, m); // may gc ptrs
+ call->init_req(TypeFunc::FramePtr, frameptr());
+ return memory;
+ }
}
//-------------------set_predefined_output_for_runtime_call--------------------
@@ -1905,6 +1911,11 @@ void GraphKit::set_predefined_output_for_runtime_call(Node* call,
const TypePtr* hook_mem) {
// no i/o
set_control(_gvn.transform( new ProjNode(call,TypeFunc::Control) ));
+ if (call->is_CallLeafPure()) {
+ // Pure function have only control (for now) and data output, in particular
+ // they don't touch the memory, so we don't want a memory proj that is set after.
+ return;
+ }
if (keep_mem) {
// First clone the existing memory state
set_all_memory(keep_mem);
@@ -2491,6 +2502,8 @@ Node* GraphKit::make_runtime_call(int flags,
} else if (flags & RC_VECTOR){
uint num_bits = call_type->range()->field_at(TypeFunc::Parms)->is_vect()->length_in_bytes() * BitsPerByte;
call = new CallLeafVectorNode(call_type, call_addr, call_name, adr_type, num_bits);
+ } else if (flags & RC_PURE) {
+ call = new CallLeafPureNode(call_type, call_addr, call_name, adr_type);
} else {
call = new CallLeafNode(call_type, call_addr, call_name, adr_type);
}
diff --git a/src/hotspot/share/opto/graphKit.hpp b/src/hotspot/share/opto/graphKit.hpp
index 28773d75333..806a211d7e2 100644
--- a/src/hotspot/share/opto/graphKit.hpp
+++ b/src/hotspot/share/opto/graphKit.hpp
@@ -784,6 +784,7 @@ class GraphKit : public Phase {
RC_NARROW_MEM = 16, // input memory is same as output
RC_UNCOMMON = 32, // freq. expected to be like uncommon trap
RC_VECTOR = 64, // CallLeafVectorNode
+ RC_PURE = 128, // CallLeaf is pure
RC_LEAF = 0 // null value: no flags set
};
diff --git a/src/hotspot/share/opto/library_call.cpp b/src/hotspot/share/opto/library_call.cpp
index f74af38387c..12960d101a8 100644
--- a/src/hotspot/share/opto/library_call.cpp
+++ b/src/hotspot/share/opto/library_call.cpp
@@ -1802,7 +1802,7 @@ bool LibraryCallKit::runtime_math(const TypeFunc* call_type, address funcAddr, c
Node* b = (call_type == OptoRuntime::Math_DD_D_Type()) ? argument(2) : nullptr;
const TypePtr* no_memory_effects = nullptr;
- Node* trig = make_runtime_call(RC_LEAF, call_type, funcAddr, funcName,
+ Node* trig = make_runtime_call(RC_LEAF | RC_PURE, call_type, funcAddr, funcName,
no_memory_effects,
a, top(), b, b ? top() : nullptr);
Node* value = _gvn.transform(new ProjNode(trig, TypeFunc::Parms+0));
diff --git a/src/hotspot/share/opto/macro.cpp b/src/hotspot/share/opto/macro.cpp
index acf1dbabf19..aafc5d3c170 100644
--- a/src/hotspot/share/opto/macro.cpp
+++ b/src/hotspot/share/opto/macro.cpp
@@ -2638,17 +2638,14 @@ bool PhaseMacroExpand::expand_macro_nodes() {
switch (n->Opcode()) {
case Op_ModD:
case Op_ModF: {
- bool is_drem = n->Opcode() == Op_ModD;
CallNode* mod_macro = n->as_Call();
- CallNode* call = new CallLeafNode(mod_macro->tf(),
- is_drem ? CAST_FROM_FN_PTR(address, SharedRuntime::drem)
- : CAST_FROM_FN_PTR(address, SharedRuntime::frem),
- is_drem ? "drem" : "frem", TypeRawPtr::BOTTOM);
+ CallNode* call = new CallLeafPureNode(mod_macro->tf(), mod_macro->entry_point(),
+ mod_macro->_name, TypeRawPtr::BOTTOM);
call->init_req(TypeFunc::Control, mod_macro->in(TypeFunc::Control));
- call->init_req(TypeFunc::I_O, mod_macro->in(TypeFunc::I_O));
- call->init_req(TypeFunc::Memory, mod_macro->in(TypeFunc::Memory));
- call->init_req(TypeFunc::ReturnAdr, mod_macro->in(TypeFunc::ReturnAdr));
- call->init_req(TypeFunc::FramePtr, mod_macro->in(TypeFunc::FramePtr));
+ call->init_req(TypeFunc::I_O, C->top());
+ call->init_req(TypeFunc::Memory, C->top());
+ call->init_req(TypeFunc::ReturnAdr, C->top());
+ call->init_req(TypeFunc::FramePtr, C->top());
for (unsigned int i = 0; i < mod_macro->tf()->domain()->cnt() - TypeFunc::Parms; i++) {
call->init_req(TypeFunc::Parms + i, mod_macro->in(TypeFunc::Parms + i));
}
diff --git a/src/hotspot/share/opto/multnode.cpp b/src/hotspot/share/opto/multnode.cpp
index 736e84315ee..f429d5daac0 100644
--- a/src/hotspot/share/opto/multnode.cpp
+++ b/src/hotspot/share/opto/multnode.cpp
@@ -120,6 +120,10 @@ const TypePtr *ProjNode::adr_type() const {
if (bottom_type() == Type::MEMORY) {
// in(0) might be a narrow MemBar; otherwise we will report TypePtr::BOTTOM
Node* ctrl = in(0);
+ if (ctrl->Opcode() == Op_Tuple) {
+ // Jumping over Tuples: the i-th projection of a Tuple is the i-th input of the Tuple.
+ ctrl = ctrl->in(_con);
+ }
if (ctrl == nullptr) return nullptr; // node is dead
const TypePtr* adr_type = ctrl->adr_type();
#ifdef ASSERT
@@ -163,6 +167,15 @@ void ProjNode::check_con() const {
assert(_con < t->is_tuple()->cnt(), "ProjNode::_con must be in range");
}
+//------------------------------Identity---------------------------------------
+Node* ProjNode::Identity(PhaseGVN* phase) {
+ if (in(0) != nullptr && in(0)->Opcode() == Op_Tuple) {
+ // Jumping over Tuples: the i-th projection of a Tuple is the i-th input of the Tuple.
+ return in(0)->in(_con);
+ }
+ return this;
+}
+
//------------------------------Value------------------------------------------
const Type* ProjNode::Value(PhaseGVN* phase) const {
if (in(0) == nullptr) return Type::TOP;
diff --git a/src/hotspot/share/opto/multnode.hpp b/src/hotspot/share/opto/multnode.hpp
index dff2caed38d..834dcfdca6d 100644
--- a/src/hotspot/share/opto/multnode.hpp
+++ b/src/hotspot/share/opto/multnode.hpp
@@ -82,6 +82,7 @@ class ProjNode : public Node {
virtual const Type *bottom_type() const;
virtual const TypePtr *adr_type() const;
virtual bool pinned() const;
+ virtual Node* Identity(PhaseGVN* phase);
virtual const Type* Value(PhaseGVN* phase) const;
virtual uint ideal_reg() const;
virtual const RegMask &out_RegMask() const;
@@ -105,4 +106,49 @@ class ProjNode : public Node {
ProjNode* other_if_proj() const;
};
+/* Tuples are used to avoid manual graph surgery. When a node with Proj outputs (such as a call)
+ * must be removed and its ouputs replaced by its input, or some other value, we can make its
+ * ::Ideal return a tuple of what we want for each output: the ::Identity of output Proj will
+ * take care to jump over the Tuple and directly pick up the right input of the Tuple.
+ *
+ * For instance, if a function call is proven to have no side effect and return the constant 0,
+ * we can replace it with the 6-tuple:
+ * (control input, IO input, memory input, frame ptr input, return addr input, Con:0)
+ * all the output projections will pick up the input of the now gone call, except for the result
+ * projection that is replaced by 0.
+ *
+ * Using TupleNode avoid manual graph surgery and leave that to our expert surgeon: IGVN.
+ * Since the user of a Tuple are expected to be Proj, when creating a tuple during idealization,
+ * the output Proj should be enqueued for IGVN immediately after, and the tuple should not survive
+ * after the current IGVN.
+ */
+class TupleNode : public MultiNode {
+ const TypeTuple* _tf;
+
+ template <typename... NN>
+ static void make_helper(TupleNode* tn, uint i, Node* node, NN... nn) {
+ tn->set_req(i, node);
+ make_helper(tn, i + 1, nn...);
+ }
+
+ static void make_helper(TupleNode*, uint) {}
+
+public:
+ TupleNode(const TypeTuple* tf) : MultiNode(tf->cnt()), _tf(tf) {}
+
+ int Opcode() const override;
+ const Type* bottom_type() const override { return _tf; }
+
+ /* Give as many `Node*` as you want in the `nn` pack:
+ * TupleNode::make(tf, input1)
+ * TupleNode::make(tf, input1, input2, input3, input4)
+ */
+ template <typename... NN>
+ static TupleNode* make(const TypeTuple* tf, NN... nn) {
+ TupleNode* tn = new TupleNode(tf);
+ make_helper(tn, 0, nn...);
+ return tn;
+ }
+};
+
#endif // SHARE_OPTO_MULTNODE_HPP
diff --git a/src/hotspot/share/opto/node.cpp b/src/hotspot/share/opto/node.cpp
index 8f6c67c16f5..5ecc038954d 100644
--- a/src/hotspot/share/opto/node.cpp
+++ b/src/hotspot/share/opto/node.cpp
@@ -2946,23 +2946,13 @@ bool Node::is_dead_loop_safe() const {
bool Node::is_div_or_mod(BasicType bt) const { return Opcode() == Op_Div(bt) || Opcode() == Op_Mod(bt) ||
Opcode() == Op_UDiv(bt) || Opcode() == Op_UMod(bt); }
-bool Node::is_pure_function() const {
- switch (Opcode()) {
- case Op_ModD:
- case Op_ModF:
- return true;
- default:
- return false;
- }
-}
-
// `maybe_pure_function` is assumed to be the input of `this`. This is a bit redundant,
// but we already have and need maybe_pure_function in all the call sites, so
// it makes it obvious that the `maybe_pure_function` is the same node as in the caller,
// while it takes more thinking to realize that a locally computed in(0) must be equal to
// the local in the caller.
bool Node::is_data_proj_of_pure_function(const Node* maybe_pure_function) const {
- return Opcode() == Op_Proj && as_Proj()->_con == TypeFunc::Parms && maybe_pure_function->is_pure_function();
+ return Opcode() == Op_Proj && as_Proj()->_con == TypeFunc::Parms && maybe_pure_function->is_CallLeafPure();
}
//=============================================================================
diff --git a/src/hotspot/share/opto/node.hpp b/src/hotspot/share/opto/node.hpp
index 2bbb10879f5..dc0ac474c4b 100644
--- a/src/hotspot/share/opto/node.hpp
+++ b/src/hotspot/share/opto/node.hpp
@@ -54,6 +54,7 @@ class CallDynamicJavaNode;
class CallJavaNode;
class CallLeafNode;
class CallLeafNoFPNode;
+class CallLeafPureNode;
class CallNode;
class CallRuntimeNode;
class CallStaticJavaNode;
@@ -673,6 +674,7 @@ class Node {
DEFINE_CLASS_ID(CallRuntime, Call, 1)
DEFINE_CLASS_ID(CallLeaf, CallRuntime, 0)
DEFINE_CLASS_ID(CallLeafNoFP, CallLeaf, 0)
+ DEFINE_CLASS_ID(CallLeafPure, CallLeaf, 1)
DEFINE_CLASS_ID(Allocate, Call, 2)
DEFINE_CLASS_ID(AllocateArray, Allocate, 0)
DEFINE_CLASS_ID(AbstractLock, Call, 3)
@@ -907,6 +909,7 @@ class Node {
DEFINE_CLASS_QUERY(CallJava)
DEFINE_CLASS_QUERY(CallLeaf)
DEFINE_CLASS_QUERY(CallLeafNoFP)
+ DEFINE_CLASS_QUERY(CallLeafPure)
DEFINE_CLASS_QUERY(CallRuntime)
DEFINE_CLASS_QUERY(CallStaticJava)
DEFINE_CLASS_QUERY(Catch)
@@ -1289,8 +1292,6 @@ class Node {
bool is_div_or_mod(BasicType bt) const;
- bool is_pure_function() const;
-
bool is_data_proj_of_pure_function(const Node* maybe_pure_function) const;
//----------------- Printing, etc
diff --git a/src/hotspot/share/opto/parse2.cpp b/src/hotspot/share/opto/parse2.cpp
index 1a4c3c91c4f..04b6e49b620 100644
--- a/src/hotspot/share/opto/parse2.cpp
+++ b/src/hotspot/share/opto/parse2.cpp
@@ -1097,11 +1097,11 @@ void Parse::jump_switch_ranges(Node* key_val, SwitchRange *lo, SwitchRange *hi,
Node* Parse::floating_point_mod(Node* a, Node* b, BasicType type) {
assert(type == BasicType::T_FLOAT || type == BasicType::T_DOUBLE, "only float and double are floating points");
- CallNode* mod = type == BasicType::T_DOUBLE ? static_cast<CallNode*>(new ModDNode(C, a, b)) : new ModFNode(C, a, b);
+ CallLeafPureNode* mod = type == BasicType::T_DOUBLE ? static_cast<CallLeafPureNode*>(new ModDNode(C, a, b)) : new ModFNode(C, a, b);
- Node* prev_mem = set_predefined_input_for_runtime_call(mod);
- mod = _gvn.transform(mod)->as_Call();
- set_predefined_output_for_runtime_call(mod, prev_mem, TypeRawPtr::BOTTOM);
+ set_predefined_input_for_runtime_call(mod);
+ mod = _gvn.transform(mod)->as_CallLeafPure();
+ set_predefined_output_for_runtime_call(mod);
Node* result = _gvn.transform(new ProjNode(mod, TypeFunc::Parms + 0));
record_for_igvn(mod);
return result;
--
2.53.0

View File

@ -0,0 +1,626 @@
From 1f61b6754b5abce07db45fd385a19c2cf9296a08 Mon Sep 17 00:00:00 2001
From: Kangcheng Xu <kxu@redhat.com>
Date: Mon, 27 Apr 2026 10:14:39 -0400
Subject: [PATCH 2/2] Backport 7f631ea958e30246b927f3524f0fbf37334422b9
---
src/hotspot/share/opto/callnode.cpp | 175 ++++++++++++++
src/hotspot/share/opto/callnode.hpp | 17 ++
src/hotspot/share/opto/classes.hpp | 1 +
src/hotspot/share/opto/library_call.cpp | 62 +----
src/hotspot/share/opto/macro.cpp | 19 +-
.../intrinsics/math/PowDNodeTests.java | 218 ++++++++++++++++++
.../compiler/lib/ir_framework/IRNode.java | 11 +
7 files changed, 437 insertions(+), 66 deletions(-)
create mode 100644 test/hotspot/jtreg/compiler/intrinsics/math/PowDNodeTests.java
diff --git a/src/hotspot/share/opto/callnode.cpp b/src/hotspot/share/opto/callnode.cpp
index fc4b0c35dff..cb6cc2082b3 100644
--- a/src/hotspot/share/opto/callnode.cpp
+++ b/src/hotspot/share/opto/callnode.cpp
@@ -42,6 +42,7 @@
#include "opto/rootnode.hpp"
#include "opto/runtime.hpp"
#include "runtime/sharedRuntime.hpp"
+#include "runtime/stubRoutines.hpp"
#include "utilities/powerOfTwo.hpp"
#include "code/vmreg.hpp"
@@ -1354,6 +1355,25 @@ TupleNode* CallLeafPureNode::make_tuple_of_input_state_and_top_return_values(con
return tuple;
}
+CallLeafPureNode* CallLeafPureNode::inline_call_leaf_pure_node(Node* control) const {
+ Node* top = Compile::current()->top();
+ if (control == nullptr) {
+ control = in(TypeFunc::Control);
+ }
+
+ CallLeafPureNode* call = new CallLeafPureNode(tf(), entry_point(), _name, nullptr);
+ call->init_req(TypeFunc::Control, control);
+ call->init_req(TypeFunc::I_O, top);
+ call->init_req(TypeFunc::Memory, top);
+ call->init_req(TypeFunc::ReturnAdr, top);
+ call->init_req(TypeFunc::FramePtr, top);
+ for (unsigned int i = 0; i < tf()->domain()->cnt() - TypeFunc::Parms; i++) {
+ call->init_req(TypeFunc::Parms + i, in(TypeFunc::Parms + i));
+ }
+
+ return call;
+}
+
Node* CallLeafPureNode::Ideal(PhaseGVN* phase, bool can_reshape) {
if (is_dead()) {
return nullptr;
@@ -2424,3 +2444,158 @@ bool CallNode::may_modify_arraycopy_helper(const TypeOopPtr* dest_t, const TypeO
return true;
}
+
+PowDNode::PowDNode(Compile* C, Node* base, Node* exp)
+ : CallLeafPureNode(
+ OptoRuntime::Math_DD_D_Type(),
+ StubRoutines::dpow() != nullptr ? StubRoutines::dpow() : CAST_FROM_FN_PTR(address, SharedRuntime::dpow),
+ "pow",
+ nullptr) {
+ add_flag(Flag_is_macro);
+ C->add_macro_node(this);
+
+ init_req(TypeFunc::Parms + 0, base);
+ init_req(TypeFunc::Parms + 1, C->top()); // double slot padding
+ init_req(TypeFunc::Parms + 2, exp);
+ init_req(TypeFunc::Parms + 3, C->top()); // double slot padding
+}
+
+const Type* PowDNode::Value(PhaseGVN* phase) const {
+ const Type* t_base = phase->type(base());
+ const Type* t_exp = phase->type(exp());
+
+ if (t_base == Type::TOP || t_exp == Type::TOP) {
+ return Type::TOP;
+ }
+
+ const TypeD* base_con = t_base->isa_double_constant();
+ const TypeD* exp_con = t_exp->isa_double_constant();
+ const TypeD* result_t = nullptr;
+
+ // constant folding: both inputs are constants
+ if (base_con != nullptr && exp_con != nullptr) {
+ result_t = TypeD::make(SharedRuntime::dpow(base_con->getd(), exp_con->getd()));
+ }
+
+ // Special cases when only the exponent is known:
+ if (exp_con != nullptr) {
+ double e = exp_con->getd();
+
+ // If the second argument is positive or negative zero, then the result is 1.0.
+ // i.e., pow(x, +/-0.0D) => 1.0
+ if (e == 0.0) { // true for both -0.0 and +0.0
+ result_t = TypeD::ONE;
+ }
+
+ // If the second argument is NaN, then the result is NaN.
+ // i.e., pow(x, NaN) => NaN
+ if (g_isnan(e)) {
+ result_t = TypeD::make(NAN);
+ }
+ }
+
+ if (result_t != nullptr) {
+ // We can't simply return a TypeD here, it must be a tuple type to be compatible with call nodes.
+ const Type** fields = TypeTuple::fields(2);
+ fields[TypeFunc::Parms + 0] = result_t;
+ fields[TypeFunc::Parms + 1] = Type::HALF;
+ return TypeTuple::make(TypeFunc::Parms + 2, fields);
+ }
+
+ return tf()->range();
+}
+
+Node* PowDNode::Ideal(PhaseGVN* phase, bool can_reshape) {
+ if (!can_reshape) {
+ return nullptr; // wait for igvn
+ }
+
+ PhaseIterGVN* igvn = phase->is_IterGVN();
+ Node* base = this->base();
+ Node* exp = this->exp();
+
+ const Type* t_exp = phase->type(exp);
+ const TypeD* exp_con = t_exp->isa_double_constant();
+
+ // Special cases when only the exponent is known:
+ if (exp_con != nullptr) {
+ double e = exp_con->getd();
+
+ // If the second argument is 1.0, then the result is the same as the first argument.
+ // i.e., pow(x, 1.0) => x
+ if (e == 1.0) {
+ return make_tuple_of_input_state_and_result(igvn, base);
+ }
+
+ // If the second argument is 2.0, then strength reduce to multiplications.
+ // i.e., pow(x, 2.0) => x * x
+ if (e == 2.0) {
+ Node* mul = igvn->transform(new MulDNode(base, base));
+ return make_tuple_of_input_state_and_result(igvn, mul);
+ }
+
+ // If the second argument is 0.5, the strength reduce to square roots.
+ // i.e., pow(x, 0.5) => sqrt(x) iff x > 0
+ if (e == 0.5 && Matcher::match_rule_supported(Op_SqrtD)) {
+ Node* ctrl = in(TypeFunc::Control);
+ Node* zero = igvn->zerocon(T_DOUBLE);
+
+ // According to the API specs, pow(-0.0, 0.5) = 0.0 and sqrt(-0.0) = -0.0.
+ // So pow(-0.0, 0.5) shouldn't be replaced with sqrt(-0.0).
+ // -0.0/+0.0 are both excluded since floating-point comparison doesn't distinguish -0.0 from +0.0.
+ Node* cmp = igvn->register_new_node_with_optimizer(new CmpDNode(base, zero));
+ Node* test = igvn->register_new_node_with_optimizer(new BoolNode(cmp, BoolTest::le));
+
+ IfNode* iff = new IfNode(ctrl, test, PROB_UNLIKELY_MAG(3), COUNT_UNKNOWN);
+ igvn->register_new_node_with_optimizer(iff);
+ Node* if_slow = igvn->register_new_node_with_optimizer(new IfTrueNode(iff)); // x <= 0
+ Node* if_fast = igvn->register_new_node_with_optimizer(new IfFalseNode(iff)); // x > 0
+
+ // slow path: call pow(x, 0.5)
+ Node* call = igvn->register_new_node_with_optimizer(inline_call_leaf_pure_node(if_slow));
+ Node* call_ctrl = igvn->register_new_node_with_optimizer(new ProjNode(call, TypeFunc::Control));
+ Node* call_result = igvn->register_new_node_with_optimizer(new ProjNode(call, TypeFunc::Parms + 0));
+
+ // fast path: sqrt(x)
+ Node* sqrt = igvn->register_new_node_with_optimizer(new SqrtDNode(igvn->C, if_fast, base));
+
+ // merge paths
+ RegionNode* region = new RegionNode(3);
+ igvn->register_new_node_with_optimizer(region);
+ region->init_req(1, call_ctrl); // slow path
+ region->init_req(2, if_fast); // fast path
+
+ PhiNode* phi = new PhiNode(region, Type::DOUBLE);
+ igvn->register_new_node_with_optimizer(phi);
+ phi->init_req(1, call_result); // slow: pow() result
+ phi->init_req(2, sqrt); // fast: sqrt() result
+
+ igvn->C->set_has_split_ifs(true); // Has chance for split-if optimization
+
+ return make_tuple_of_input_state_and_result(igvn, phi, region);
+ }
+ }
+
+ return CallLeafPureNode::Ideal(phase, can_reshape);
+}
+
+// We can't simply have Ideal() returning a Con or MulNode since the users are still expecting a Call node, but we could
+// produce a tuple that follows the same pattern so users can still get control, io, memory, etc..
+TupleNode* PowDNode::make_tuple_of_input_state_and_result(PhaseIterGVN* phase, Node* result, Node* control) {
+ if (control == nullptr) {
+ control = in(TypeFunc::Control);
+ }
+
+ Compile* C = phase->C;
+ C->remove_macro_node(this);
+ TupleNode* tuple = TupleNode::make(
+ tf()->range(),
+ control,
+ in(TypeFunc::I_O),
+ in(TypeFunc::Memory),
+ in(TypeFunc::FramePtr),
+ in(TypeFunc::ReturnAdr),
+ result,
+ C->top());
+ return tuple;
+}
diff --git a/src/hotspot/share/opto/callnode.hpp b/src/hotspot/share/opto/callnode.hpp
index 2462a88143f..bb87746a3f6 100644
--- a/src/hotspot/share/opto/callnode.hpp
+++ b/src/hotspot/share/opto/callnode.hpp
@@ -953,6 +953,8 @@ class CallLeafPureNode : public CallLeafNode {
}
int Opcode() const override;
Node* Ideal(PhaseGVN* phase, bool can_reshape) override;
+
+ CallLeafPureNode* inline_call_leaf_pure_node(Node* control = nullptr) const;
};
//------------------------------CallLeafNoFPNode-------------------------------
@@ -1304,4 +1306,19 @@ class UnlockNode : public AbstractLockNode {
JVMState* dbg_jvms() const { return nullptr; }
#endif
};
+
+//------------------------------PowDNode--------------------------------------
+class PowDNode : public CallLeafPureNode {
+ TupleNode* make_tuple_of_input_state_and_result(PhaseIterGVN* phase, Node* result, Node* control = nullptr);
+
+public:
+ PowDNode(Compile* C, Node* base, Node* exp);
+ int Opcode() const override;
+ const Type* Value(PhaseGVN* phase) const override;
+ Node* Ideal(PhaseGVN* phase, bool can_reshape) override;
+
+ Node* base() const { return in(TypeFunc::Parms + 0); }
+ Node* exp() const { return in(TypeFunc::Parms + 2); }
+};
+
#endif // SHARE_OPTO_CALLNODE_HPP
diff --git a/src/hotspot/share/opto/classes.hpp b/src/hotspot/share/opto/classes.hpp
index 587d5fad8f2..b7ba16e99a0 100644
--- a/src/hotspot/share/opto/classes.hpp
+++ b/src/hotspot/share/opto/classes.hpp
@@ -283,6 +283,7 @@ macro(OpaqueZeroTripGuard)
macro(OpaqueNotNull)
macro(OpaqueInitializedAssertionPredicate)
macro(OpaqueTemplateAssertionPredicate)
+macro(PowD)
macro(ProfileBoolean)
macro(OrI)
macro(OrL)
diff --git a/src/hotspot/share/opto/library_call.cpp b/src/hotspot/share/opto/library_call.cpp
index 12960d101a8..6c71a61ba75 100644
--- a/src/hotspot/share/opto/library_call.cpp
+++ b/src/hotspot/share/opto/library_call.cpp
@@ -1817,61 +1817,17 @@ bool LibraryCallKit::runtime_math(const TypeFunc* call_type, address funcAddr, c
//------------------------------inline_math_pow-----------------------------
bool LibraryCallKit::inline_math_pow() {
+ Node* base = argument(0);
Node* exp = argument(2);
- const TypeD* d = _gvn.type(exp)->isa_double_constant();
- if (d != nullptr) {
- if (d->getd() == 2.0) {
- // Special case: pow(x, 2.0) => x * x
- Node* base = argument(0);
- set_result(_gvn.transform(new MulDNode(base, base)));
- return true;
- } else if (d->getd() == 0.5 && Matcher::match_rule_supported(Op_SqrtD)) {
- // Special case: pow(x, 0.5) => sqrt(x)
- Node* base = argument(0);
- Node* zero = _gvn.zerocon(T_DOUBLE);
-
- RegionNode* region = new RegionNode(3);
- Node* phi = new PhiNode(region, Type::DOUBLE);
-
- Node* cmp = _gvn.transform(new CmpDNode(base, zero));
- // According to the API specs, pow(-0.0, 0.5) = 0.0 and sqrt(-0.0) = -0.0.
- // So pow(-0.0, 0.5) shouldn't be replaced with sqrt(-0.0).
- // -0.0/+0.0 are both excluded since floating-point comparison doesn't distinguish -0.0 from +0.0.
- Node* test = _gvn.transform(new BoolNode(cmp, BoolTest::le));
-
- Node* if_pow = generate_slow_guard(test, nullptr);
- Node* value_sqrt = _gvn.transform(new SqrtDNode(C, control(), base));
- phi->init_req(1, value_sqrt);
- region->init_req(1, control());
-
- if (if_pow != nullptr) {
- set_control(if_pow);
- address target = StubRoutines::dpow() != nullptr ? StubRoutines::dpow() :
- CAST_FROM_FN_PTR(address, SharedRuntime::dpow);
- const TypePtr* no_memory_effects = nullptr;
- Node* trig = make_runtime_call(RC_LEAF, OptoRuntime::Math_DD_D_Type(), target, "POW",
- no_memory_effects, base, top(), exp, top());
- Node* value_pow = _gvn.transform(new ProjNode(trig, TypeFunc::Parms+0));
-#ifdef ASSERT
- Node* value_top = _gvn.transform(new ProjNode(trig, TypeFunc::Parms+1));
- assert(value_top == top(), "second value must be top");
-#endif
- phi->init_req(2, value_pow);
- region->init_req(2, _gvn.transform(new ProjNode(trig, TypeFunc::Control)));
- }
-
- C->set_has_split_ifs(true); // Has chance for split-if optimization
- set_control(_gvn.transform(region));
- record_for_igvn(region);
- set_result(_gvn.transform(phi));
- return true;
- }
- }
-
- return StubRoutines::dpow() != nullptr ?
- runtime_math(OptoRuntime::Math_DD_D_Type(), StubRoutines::dpow(), "dpow") :
- runtime_math(OptoRuntime::Math_DD_D_Type(), CAST_FROM_FN_PTR(address, SharedRuntime::dpow), "POW");
+ CallNode* pow = new PowDNode(C, base, exp);
+ set_predefined_input_for_runtime_call(pow);
+ pow = _gvn.transform(pow)->as_CallLeafPure();
+ set_predefined_output_for_runtime_call(pow);
+ Node* result = _gvn.transform(new ProjNode(pow, TypeFunc::Parms + 0));
+ record_for_igvn(pow);
+ set_result(result);
+ return true;
}
//------------------------------inline_math_native-----------------------------
diff --git a/src/hotspot/share/opto/macro.cpp b/src/hotspot/share/opto/macro.cpp
index aafc5d3c170..a28043c8d8f 100644
--- a/src/hotspot/share/opto/macro.cpp
+++ b/src/hotspot/share/opto/macro.cpp
@@ -2484,6 +2484,7 @@ void PhaseMacroExpand::eliminate_macro_nodes() {
assert(n->Opcode() == Op_LoopLimit ||
n->Opcode() == Op_ModD ||
n->Opcode() == Op_ModF ||
+ n->Opcode() == Op_PowD ||
n->is_OpaqueNotNull() ||
n->is_OpaqueInitializedAssertionPredicate() ||
n->Opcode() == Op_MaxL ||
@@ -2637,19 +2638,11 @@ bool PhaseMacroExpand::expand_macro_nodes() {
default:
switch (n->Opcode()) {
case Op_ModD:
- case Op_ModF: {
- CallNode* mod_macro = n->as_Call();
- CallNode* call = new CallLeafPureNode(mod_macro->tf(), mod_macro->entry_point(),
- mod_macro->_name, TypeRawPtr::BOTTOM);
- call->init_req(TypeFunc::Control, mod_macro->in(TypeFunc::Control));
- call->init_req(TypeFunc::I_O, C->top());
- call->init_req(TypeFunc::Memory, C->top());
- call->init_req(TypeFunc::ReturnAdr, C->top());
- call->init_req(TypeFunc::FramePtr, C->top());
- for (unsigned int i = 0; i < mod_macro->tf()->domain()->cnt() - TypeFunc::Parms; i++) {
- call->init_req(TypeFunc::Parms + i, mod_macro->in(TypeFunc::Parms + i));
- }
- _igvn.replace_node(mod_macro, call);
+ case Op_ModF:
+ case Op_PowD: {
+ CallLeafPureNode* call_macro = n->as_CallLeafPure();
+ CallLeafPureNode* call = call_macro->inline_call_leaf_pure_node();
+ _igvn.replace_node(call_macro, call);
transform_later(call);
break;
}
diff --git a/test/hotspot/jtreg/compiler/intrinsics/math/PowDNodeTests.java b/test/hotspot/jtreg/compiler/intrinsics/math/PowDNodeTests.java
new file mode 100644
index 00000000000..e28cc5ab346
--- /dev/null
+++ b/test/hotspot/jtreg/compiler/intrinsics/math/PowDNodeTests.java
@@ -0,0 +1,218 @@
+/*
+ * Copyright (c) 2026, IBM and/or its affiliates. All rights reserved.
+ * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
+ *
+ * This code is free software; you can redistribute it and/or modify it
+ * under the terms of the GNU General Public License version 2 only, as
+ * published by the Free Software Foundation.
+ *
+ * This code is distributed in the hope that it will be useful, but WITHOUT
+ * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
+ * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
+ * version 2 for more details (a copy is included in the LICENSE file that
+ * accompanied this code).
+ *
+ * You should have received a copy of the GNU General Public License version
+ * 2 along with this work; if not, write to the Free Software Foundation,
+ * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+ *
+ * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
+ * or visit www.oracle.com if you need additional information or have any
+ * questions.
+ *
+ */
+package compiler.intrinsics.math;
+
+import jdk.test.lib.Asserts;
+
+import compiler.lib.ir_framework.*;
+import compiler.lib.generators.*;
+import static compiler.lib.generators.Generators.*;
+
+import java.util.Random;
+
+/*
+ * @test
+ * @bug 8378713
+ * @key randomness
+ * @summary Math.pow(base, exp) should constant propagate
+ * @library /test/lib /
+ * @run driver ${test.main.class}
+ */
+public class PowDNodeTests {
+ public static final Generator<Double> UNIFORMS = G.uniformDoubles(); // [0, 1)
+
+ public static final double B = UNIFORMS.next() * 1000.0d;
+ public static final double E = UNIFORMS.next() * 1000.0d + 3.0d; // e >= 3 to avoid strength reduction code
+
+ public static void main(String[] args) {
+ TestFramework.run();
+
+ testCorrectness();
+ }
+
+ // Test 1: pow(2.0, 10.0) -> 1024.0
+ @Test
+ @IR(failOn = {IRNode.POW_D})
+ public static double constantLiteralFolding() {
+ return Math.pow(2.0, 10.0); // should fold to 1024.0
+ }
+
+ // Test 2: pow(final B, final E) -> B^E
+ @Test
+ @IR(failOn = {IRNode.POW_D})
+ public static double constantStaticFolding() {
+ return Math.pow(B, E); // should fold to B^E
+ }
+
+ // Test 3: pow(b, 0.0) -> 1.0
+ @Test
+ @IR(failOn = {IRNode.POW_D})
+ @Arguments(values = {Argument.RANDOM_EACH})
+ public static double expZero(double b) {
+ return Math.pow(b, 0.0);
+ }
+
+ // Test 4: pow(b, 1.0) -> b (identity)
+ @Test
+ @IR(failOn = {IRNode.POW_D})
+ @Arguments(values = {Argument.RANDOM_EACH})
+ public static double expOne(double b) {
+ return Math.pow(b, 1.0);
+ }
+
+ // Test 5: pow(b, NaN) -> NaN
+ @Test
+ @IR(failOn = {IRNode.POW_D})
+ @Arguments(values = {Argument.RANDOM_EACH})
+ public static double expNaN(double b) {
+ return Math.pow(b, Double.NaN);
+ }
+
+ // Test 6: pow(b, 2.0) -> b * b
+ // More tests in TestPow2Opt.java
+ @Test
+ @IR(failOn = {IRNode.POW_D})
+ @IR(counts = {IRNode.MUL_D, "1"})
+ @Arguments(values = {Argument.RANDOM_EACH})
+ public static double expTwo(double b) {
+ return Math.pow(b, 2.0);
+ }
+
+ // Test 7: pow(b, 0.5) -> b <= 0.0 ? pow(b, 0.5) : sqrt(b)
+ // More tests in TestPow0Dot5Opt.java
+ @Test
+ @IR(counts = {IRNode.IF, "1"})
+ @IR(counts = {IRNode.SQRT_D, "1"})
+ @IR(counts = {".*CallLeaf.*pow.*", "1"}, phase = CompilePhase.BEFORE_MATCHING)
+ @Arguments(values = {Argument.RANDOM_EACH})
+ public static double expDot5(double b) {
+ return Math.pow(b, 0.5); // expand to: if (b > 0) { sqrt(b) } else { call(b) }
+ }
+
+ // Test 8: non-constant exponent stays as call
+ @Test
+ @IR(counts = {IRNode.POW_D, "1"})
+ @Arguments(values = {Argument.RANDOM_EACH, Argument.RANDOM_EACH})
+ public static double nonConstant(double b, double e) {
+ return Math.pow(b, e);
+ }
+
+ // Test 9: late constant discovery on base (after loop opts)
+ @Test
+ @IR(counts = {IRNode.POW_D, "1"}, phase = CompilePhase.AFTER_PARSING)
+ @IR(failOn = {IRNode.POW_D})
+ public static double lateBaseConstant() {
+ double base = 0;
+ for (int i = 0; i < 4; i++) {
+ if ((i % 2) == 0) {
+ base = B;
+ }
+ }
+ // After loop opts, base == B (constant), so pow(B, E) folds
+ return Math.pow(base, E);
+ }
+
+ // Test 10: late constant discovery on exp (after loop opts)
+ @Test
+ @IR(counts = {IRNode.POW_D, "1"}, phase = CompilePhase.AFTER_PARSING)
+ @IR(failOn = {IRNode.POW_D})
+ public static double lateExpConstant() {
+ double exp = 0;
+ for (int i = 0; i < 4; i++) {
+ if ((i % 2) == 0) {
+ exp = E;
+ }
+ }
+ // After loop opts, exp == E (constant), so pow(B, E) folds
+ return Math.pow(B, exp);
+ }
+
+ // Test 11: late constant discoveries on both base and exp (after loop opts)
+ @Test
+ @IR(counts = {IRNode.POW_D, "1"}, phase = CompilePhase.AFTER_PARSING)
+ @IR(failOn = {IRNode.POW_D})
+ public static double lateBothConstant() {
+ double base = 0, exp = 0;
+ for (int i = 0; i < 4; i++) {
+ if ((i % 2) == 0) {
+ base = B;
+ exp = E;
+ }
+ }
+ // After loop opts, base = B, exp == E, so pow(B, E) folds
+ return Math.pow(base, exp);
+ }
+
+ private static void assertEQWithinOneUlp(double expected, double observed) {
+ if (Double.isNaN(expected) && Double.isNaN(observed)) return;
+
+ // Math.pow() requires result must be within 1 ulp of the respective magnitude
+ double ulp = Math.max(Math.ulp(expected), Math.ulp(observed));
+ if (Math.abs(expected - observed) > ulp) {
+ throw new AssertionError(String.format(
+ "expect = %x, observed = %x, ulp = %x",
+ Double.doubleToRawLongBits(expected), Double.doubleToRawLongBits(observed), Double.doubleToRawLongBits(ulp)
+ ));
+ }
+ }
+
+ private static void testCorrectness() {
+ // No need to warm up for intrinsics
+ Asserts.assertEQ(1024.0d, constantLiteralFolding());
+
+ double BE = StrictMath.pow(B, E);
+ assertEQWithinOneUlp(BE, constantStaticFolding());
+ assertEQWithinOneUlp(BE, lateBaseConstant());
+ assertEQWithinOneUlp(BE, lateExpConstant());
+ assertEQWithinOneUlp(BE, lateBothConstant());
+
+ Generator<Double> anyBits = G.anyBitsDouble();
+ Generator<Double> largeDoubles = G.uniformDoubles(Long.MAX_VALUE, Double.MAX_VALUE);
+ Generator<Double> doubles = G.doubles();
+ double[] values = {
+ Double.MIN_VALUE, Double.MIN_NORMAL, -42.0d, -1.0d, -0.0d, +0.0d, 0.5d, 1.0d, 2.0d, 123d, Double.MAX_VALUE,
+ Double.NEGATIVE_INFINITY, Double.POSITIVE_INFINITY, Double.NaN,
+ UNIFORMS.next(), UNIFORMS.next(),
+ largeDoubles.next(), -largeDoubles.next(), // some sufficiently large magnitudes
+ anyBits.next(), anyBits.next(), // any bits with potentially more NaN representation
+ doubles.next(), doubles.next() // a healthy sprinkle of whatever else is possible
+ };
+
+ for (double b : values) {
+ // Strength reduced, so we know the bits matches exactly
+ Asserts.assertEQ(1.0d, expZero(b));
+ Asserts.assertEQ(b, expOne(b));
+ Asserts.assertEQ(b * b, expTwo(b));
+
+ assertEQWithinOneUlp(Double.NaN, expNaN(b));
+
+ // Runtime calls, so make sure the result is within 1 ulp
+ assertEQWithinOneUlp(StrictMath.pow(b, 0.5d), expDot5(b));
+
+ for (double e : values) {
+ assertEQWithinOneUlp(StrictMath.pow(b, e), nonConstant(b, e));
+ }
+ }
+ }
+}
diff --git a/test/hotspot/jtreg/compiler/lib/ir_framework/IRNode.java b/test/hotspot/jtreg/compiler/lib/ir_framework/IRNode.java
index 7b751f1a72c..6a95a2b5da7 100644
--- a/test/hotspot/jtreg/compiler/lib/ir_framework/IRNode.java
+++ b/test/hotspot/jtreg/compiler/lib/ir_framework/IRNode.java
@@ -1858,6 +1858,11 @@ public class IRNode {
beforeMatchingNameRegex(SQRT_HF, "SqrtHF");
}
+ public static final String SQRT_D = PREFIX + "SQRT_D" + POSTFIX;
+ static {
+ beforeMatchingNameRegex(SQRT_D, "SqrtD");
+ }
+
public static final String SQRT_F = PREFIX + "SQRT_F" + POSTFIX;
static {
beforeMatchingNameRegex(SQRT_F, "SqrtF");
@@ -2825,6 +2830,12 @@ public class IRNode {
macroNodes(MOD_D, regex);
}
+ public static final String POW_D = PREFIX + "POW_D" + POSTFIX;
+ static {
+ String regex = START + "PowD" + MID + END;
+ macroNodes(POW_D, regex);
+ }
+
public static final String BLACKHOLE = PREFIX + "BLACKHOLE" + POSTFIX;
static {
fromBeforeRemoveUselessToFinalCode(BLACKHOLE, "Blackhole");
--
2.53.0

View File

@ -1,3 +0,0 @@
---
inspections:
javabytecode: off

View File

@ -1,29 +0,0 @@
#!/bin/sh
# Copyright (C) 2024 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Builds the RPM on CentOS 9 or 10
centpkg -v build
# Local Variables:
# compile-command: "shellcheck build_centos.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -1,29 +0,0 @@
#!/bin/sh
# Copyright (C) 2024 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Builds the portable on CentOS
centpkg -v build --target java-openjdk-portable-build --rhel-target none
# Local Variables:
# compile-command: "shellcheck build_centos_portable_build.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -1,43 +0,0 @@
#!/bin/sh
# Copyright (C) 2024 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Builds the RPM on RHEL 10
NVR=${1}
USER=${2}
if test "${NVR}" = ""; then
echo "${0} <NVR> <USER>";
exit 1;
fi
if test "${USER}" = ""; then
echo "${0} <NVR> <USER>";
exit 2;
fi
METADATA="{\"osci\": {\"upstream_nvr\": \"${NVR}\", \"upstream_owner_name\": \"${USER}\"}, \"rhel-target\": \"latest\"}"
rhpkg -v build --target=java-openjdk-rhel-10-build --custom-user-metadata "${METADATA}"
# Local Variables:
# compile-command: "shellcheck build_rhel_10.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -1,29 +0,0 @@
#!/bin/sh
# Copyright (C) 2024 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Builds the portable on RHEL 7
rhpkg -v build --target=java-openjdk-rhel-7-build --skip-nvr-check
# Local Variables:
# compile-command: "shellcheck build_rhel_7_portable_build.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -1,43 +0,0 @@
#!/bin/sh
# Copyright (C) 2024 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Builds the RPM on RHEL 8
NVR=${1}
USER=${2}
if test "${NVR}" = ""; then
echo "${0} <NVR> <USER>";
exit 1;
fi
if test "${USER}" = ""; then
echo "${0} <NVR> <USER>";
exit 2;
fi
METADATA="{\"osci\": {\"upstream_nvr\": \"${NVR}\", \"upstream_owner_name\": \"${USER}\"}, \"rhel-target\": \"latest\"}"
rhpkg -v build --target=java-openjdk-rhel-8-build --custom-user-metadata "${METADATA}"
# Local Variables:
# compile-command: "shellcheck build_rhel_8.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -1,43 +0,0 @@
#!/bin/sh
# Copyright (C) 2024 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Builds the RPM on RHEL 9
NVR=${1}
USER=${2}
if test "${NVR}" = ""; then
echo "${0} <NVR> <USER>";
exit 1;
fi
if test "${USER}" = ""; then
echo "${0} <NVR> <USER>";
exit 2;
fi
METADATA="{\"osci\": {\"upstream_nvr\": \"${NVR}\", \"upstream_owner_name\": \"${USER}\"}, \"rhel-target\": \"latest\"}"
rhpkg -v build --target=java-openjdk-rhel-9-build --custom-user-metadata "${METADATA}"
# Local Variables:
# compile-command: "shellcheck build_rhel_9.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -1,29 +0,0 @@
#!/bin/sh
# Copyright (C) 2024 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Builds the portable on RHEL 8
rhpkg -v build --target=java-openjdk-rhel-8-build --skip-nvr-check
# Local Variables:
# compile-command: "shellcheck build_rhel_portable_build.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -1,43 +0,0 @@
#!/bin/sh
# Copyright (C) 2024 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Builds a scratch build of vanilla OpenJDK with no local patches
SEPARATE_ARCHES=${1}
CMD="--target java-openjdk-rhel-8-build --skip-nvr-check --nowait";
SUPPORTED_ARCHES="aarch64 ppc64le s390x x86_64";
if [ "x${SEPARATE_ARCHES}" = "x" ] ; then
SEPARATE_ARCHES=0;
fi
if [ ${SEPARATE_ARCHES} -eq 1 ] ; then
for arch in ${SUPPORTED_ARCHES}; do \
rhpkg -v build --arches ${arch} --scratch ${CMD} ; \
done && brew watch-task --mine
else
rhpkg -v build ${CMD} && brew watch-task --mine
fi
# Local Variables:
# compile-command: "shellcheck build_vanilla.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -1,61 +0,0 @@
#!/bin/sh
# Copyright (C) 2024 Red Hat, Inc.
# Written by Andrew John Hughes <gnu.andrew@redhat.com>.
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <https://www.gnu.org/licenses/>.
TREE=${1}
if test "${TREE}" = ""; then
TREE=${PWD}
fi
if [ -e "${TREE}"/nashorn/.hg ] || [ -e "${TREE}"/nashorn/merge.changeset ] ; then
NASHORN="nashorn" ;
fi
if [ -e "${TREE}"/corba/.hg ] || [ -e "${TREE}"/corba/merge.changeset ] ; then
CORBA="corba";
fi
if [ -e "${TREE}"/jaxp/.hg ] || [ -e "${TREE}"/jaxp/merge.changeset ] ; then
JAXP="jaxp";
fi
if [ -e "${TREE}"/jaxws/.hg ] || [ -e "${TREE}"/jaxws/merge.changeset ] ; then
JAXWS="jaxws";
fi
if [ -e "${TREE}"/langtools/.hg ] || [ -e "${TREE}"/langtools/merge.changeset ] ; then
LANGTOOLS="langtools";
fi
if [ -e "${TREE}"/jdk/.hg ] || [ -e "${TREE}"/jdk/merge.changeset ] ; then
JDK="jdk";
fi
if [ -e "${TREE}"/hotspot/.hg ] || [ -e "${TREE}"/hotspot/merge.changeset ] ; then
HOTSPOT="hotspot";
fi
SUBTREES="${CORBA} ${JAXP} ${JAXWS} ${LANGTOOLS} ${NASHORN} ${JDK} ${HOTSPOT}";
echo "${SUBTREES}"
# Local Variables:
# compile-command: "shellcheck discover_trees.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -1,294 +0,0 @@
#!/bin/bash
# Copyright (C) 2024 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
# Thomas Fitzsimmons <fitzsim@redhat.com>
# Jiri Vanek <jvanek@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Generates the source tarball for OpenJDK projects.
#
# There are multiple ways to specify the source code location and version:
#
# 1. Specify the version (VERSION), the location of the Git repository
# (REPO_ROOT) and the root of the output tarball name (FILE_NAME_ROOT)
# 2. Specify the version (VERSION) along with an upstream project name
# (PROJECT_NAME) and repository name (REPO_NAME) that can be used
# to construct the URL of the upstream OpenJDK repository.
# 3. Specify OPENJDK_LATEST=1 and allow the script to obtain the JDK
# feature version from the spec file, which is then used to
# obtain the latest build promotion from the upstream repository.
#
# An appropriate bootstrap JDK is also required for when ./configure
# is run within the checked out repository to generate the .src-rev.
# file. This can be specified by setting BOOT_JDK.
#
# Example 1:
# This will check out the specified version from the specified
# repository and construct a tarball called openjdk-17.0.3+5.tar.xz:
#
# $ VERSION=jdk-17.0.3+5 FILE_NAME_ROOT=open${VERSION} \
# REPO_ROOT=$HOME/projects/openjdk/upstream/17u \
# BOOT_JDK=/usr/lib/jvm/java-17-openjdk ./generate_source_tarball.sh
#
# Example 2:
# This will check out the same version as example 1, but from the
# upstream repository:
#
# $ VERSION=jdk-17.0.3+5 PROJECT_NAME=openjdk REPO_NAME=jdk17u \
# BOOT_JDK=/usr/lib/jvm/java-17-openjdk ./generate_source_tarball.sh
#
# Example 3:
# This will read the OpenJDK feature version from the spec file, then create a
# tarball from the most recent tag for that version in the upstream Git
# repository.
#
# $ OPENJDK_LATEST=1 \
# BOOT_JDK=/usr/lib/jvm/java-17-openjdk ./generate_source_tarball.sh
#
set -e
OPENJDK_URL_DEFAULT=https://github.com
COMPRESSION_DEFAULT=xz
if [ "$1" = "help" ] ; then
echo "Behaviour may be specified by setting the following variables:"
echo
echo "VERSION - the version of the specified OpenJDK project"
echo " (required unless OPENJDK_LATEST is set)"
echo "PROJECT_NAME - the name of the OpenJDK project being archived"
echo " (needed to compute REPO_ROOT and/or"
echo " FILE_NAME_ROOT automatically;"
echo " optional if they are set explicitly)"
echo "REPO_NAME - the name of the OpenJDK repository"
echo " (needed to compute REPO_ROOT automatically;"
echo " optional if REPO_ROOT is set explicitly)"
echo "OPENJDK_URL - the URL to retrieve code from"
echo " (defaults to ${OPENJDK_URL_DEFAULT})"
echo "COMPRESSION - the compression type to use"
echo " (defaults to ${COMPRESSION_DEFAULT})"
echo "FILE_NAME_ROOT - name of the archive, minus extensions"
echo " (defaults to PROJECT_NAME-VERSION)"
echo "REPO_ROOT - the location of the Git repository to archive"
echo " (defaults to OPENJDK_URL/PROJECT_NAME/REPO_NAME.git)"
echo "TO_COMPRESS - what part of clone to pack"
echo " (defaults to ${VERSION})"
echo "BOOT_JDK - the bootstrap JDK to satisfy the configure run"
echo " (defaults to packaged JDK version)"
echo "WITH_TEMP - run in a temporary directory"
echo " (defaults to disabled)"
echo "OPENJDK_LATEST - deduce VERSION from most recent upstream tag"
echo " (implies WITH_TEMP, computes everything else"
echo " automatically; Note: accesses network to read"
echo " tag list from remote Git repository)"
exit 1;
fi
if [ "$OPENJDK_LATEST" != "" ] ; then
FEATURE_VERSION=$(echo '%featurever' \
| rpmspec --shell ./*.spec 2>/dev/null \
| grep --after-context 1 featurever \
| tail --lines 1)
PROJECT_NAME=openjdk
REPO_NAME=jdk"${FEATURE_VERSION}"u
# Skip -ga tags since those are the same as the most recent non-ga tag, and
# the non-ga tag is the one that is used to generated the official source
# tarball. For example:
# ca760c86642aa2e0d9b571aaabac054c0239fbdc refs/tags/jdk-17.0.10-ga^{}
# 25a2e6c20c9a96853714284cabc6b456eb095070 refs/tags/jdk-17.0.10-ga
# ca760c86642aa2e0d9b571aaabac054c0239fbdc refs/tags/jdk-17.0.10+7^{}
# e49c5749b10f3e90274b72e9279f794fdd191d27 refs/tags/jdk-17.0.10+7
VERSION=$(git ls-remote --tags --refs --sort=-version:refname \
"${OPENJDK_URL_DEFAULT}/${PROJECT_NAME}/${REPO_NAME}.git" \
"jdk-${FEATURE_VERSION}*" \
| grep --invert-match '\-ga$' \
| head --lines 1 | cut --characters 52-)
FILE_NAME_ROOT=open${VERSION}
WITH_TEMP=1
fi
if [ "$WITH_TEMP" != "" ] ; then
pushd "$(mktemp --directory --tmpdir temp-generated-source-tarball-XXX)"
fi
if [ "$VERSION" = "" ] ; then
echo "No VERSION specified"
exit 2
fi
echo "Version: ${VERSION}"
NUM_VER=${VERSION##jdk-}
RELEASE_VER=${NUM_VER%%+*}
BUILD_VER=${NUM_VER##*+}
MAJOR_VER=${RELEASE_VER%%.*}
echo "Major version is ${MAJOR_VER}, release ${RELEASE_VER}, build ${BUILD_VER}"
if [ "$BOOT_JDK" = "" ] ; then
echo "No boot JDK specified".
BOOT_JDK=/usr/lib/jvm/java-${MAJOR_VER}-openjdk;
echo -n "Checking for ${BOOT_JDK}...";
if [ -d "${BOOT_JDK}" ] && [ -x "${BOOT_JDK}"/bin/java ] ; then
echo "Boot JDK found at ${BOOT_JDK}";
else
echo "Not found";
PREV_VER=$((MAJOR_VER - 1));
BOOT_JDK=/usr/lib/jvm/java-${PREV_VER}-openjdk;
echo -n "Checking for ${BOOT_JDK}...";
if [ -d ${BOOT_JDK} ] && [ -x ${BOOT_JDK}/bin/java ] ; then
echo "Boot JDK found at ${BOOT_JDK}";
else
echo "Not found";
exit 4;
fi
fi
else
echo "Boot JDK: ${BOOT_JDK}";
fi
if [ "$OPENJDK_URL" = "" ] ; then
OPENJDK_URL=${OPENJDK_URL_DEFAULT}
echo "No OpenJDK URL specified; defaulting to ${OPENJDK_URL}"
else
echo "OpenJDK URL: ${OPENJDK_URL}"
fi
if [ "$COMPRESSION" = "" ] ; then
# rhel 5 needs tar.gz
COMPRESSION=${COMPRESSION_DEFAULT}
fi
echo "Creating a tar.${COMPRESSION} archive"
if [ "$FILE_NAME_ROOT" = "" ] ; then
if [ "$PROJECT_NAME" = "" ] ; then
echo "No PROJECT_NAME specified, needed by FILE_NAME_ROOT"
exit 1
fi
FILE_NAME_ROOT=${PROJECT_NAME}-${VERSION}
echo "No file name root specified; default to ${FILE_NAME_ROOT}"
fi
if [ "$REPO_ROOT" = "" ] ; then
if [ "$PROJECT_NAME" = "" ] ; then
echo "No PROJECT_NAME specified, needed by REPO_ROOT"
exit 1
fi
if [ "$REPO_NAME" = "" ] ; then
echo "No REPO_NAME specified, needed by REPO_ROOT"
exit 3
fi
REPO_ROOT="${OPENJDK_URL}/${PROJECT_NAME}/${REPO_NAME}.git"
echo "No repository root specified; default to ${REPO_ROOT}"
fi;
if [ "$TO_COMPRESS" = "" ] ; then
TO_COMPRESS="${VERSION}"
echo "No targets to be compressed specified ; default to ${TO_COMPRESS}"
fi;
echo -e "Settings:"
echo -e "\tVERSION: ${VERSION}"
echo -e "\tPROJECT_NAME: ${PROJECT_NAME}"
echo -e "\tREPO_NAME: ${REPO_NAME}"
echo -e "\tOPENJDK_URL: ${OPENJDK_URL}"
echo -e "\tCOMPRESSION: ${COMPRESSION}"
echo -e "\tFILE_NAME_ROOT: ${FILE_NAME_ROOT}"
echo -e "\tREPO_ROOT: ${REPO_ROOT}"
echo -e "\tTO_COMPRESS: ${TO_COMPRESS}"
echo -e "\tBOOT_JDK: ${BOOT_JDK}"
echo -e "\tWITH_TEMP: ${WITH_TEMP}"
echo -e "\tOPENJDK_LATEST: ${OPENJDK_LATEST}"
if [ -d "${FILE_NAME_ROOT}" ] ; then
echo "Reusing existing ${FILE_NAME_ROOT}"
STAT_TIME="$(stat --format=%Y "${FILE_NAME_ROOT}")"
TAR_TIME="$(date --date=@"${STAT_TIME}" --iso-8601=seconds)"
else
mkdir "${FILE_NAME_ROOT}"
pushd "${FILE_NAME_ROOT}"
echo "Cloning ${VERSION} root repository from ${REPO_ROOT}"
if realpath -q "${REPO_ROOT}"; then
echo "Local path detected; not adding depth argument";
DEPTH="--";
else
DEPTH="--depth=1";
echo "Remote repository detected; adding ${DEPTH}";
fi
git clone -b "${VERSION}" "${DEPTH}" "${REPO_ROOT}" "${VERSION}"
pushd "${VERSION}"
TAR_TIME="$(git log --max-count 1 --format=%cI)"
popd
popd
fi
pushd "${FILE_NAME_ROOT}"
# Generate .src-rev so build has knowledge of the revision the tarball was
# created from
mkdir build
pushd build
sh "${PWD}"/../"${VERSION}"/configure --with-boot-jdk="${BOOT_JDK}"
make store-source-revision
popd
rm -rf build
# Remove commit checks
echo "Removing $(find "${VERSION}" -name '.jcheck' -print)"
find "${VERSION}" -name '.jcheck' -print0 | xargs -0 rm -r
# Remove history and GHA
echo "find ${VERSION} -name '.hgtags'"
find "${VERSION}" -name '.hgtags' -exec rm -v '{}' '+'
echo "find ${VERSION} -name '.hgignore'"
find "${VERSION}" -name '.hgignore' -exec rm -v '{}' '+'
echo "find ${VERSION} -name '.gitattributes'"
find "${VERSION}" -name '.gitattributes' -exec rm -v '{}' '+'
echo "find ${VERSION} -name '.gitignore'"
find "${VERSION}" -name '.gitignore' -exec rm -v '{}' '+'
# Work around some Git objects not having write permissions.
echo "chmod --recursive u+w ${VERSION}/.git"
chmod --recursive u+w "${VERSION}"/.git
echo "find ${VERSION} -name '.git'"
find "${VERSION}" -name '.git' -exec rm -rv '{}' '+'
echo "find ${VERSION} -name '.github'"
find "${VERSION}" -name '.github' -exec rm -rv '{}' '+'
echo "Compressing remaining forest"
if [ "$COMPRESSION" = "xz" ] ; then
SWITCH=cJf
else
SWITCH=czf
fi
EA_PART="$(awk -F= \
'/^DEFAULT_PROMOTED_VERSION_PRE/ { if ($2) print "-"$2 }' \
"${VERSION}"/make/conf/version-numbers.conf)"
TARBALL_NAME=${FILE_NAME_ROOT}${EA_PART}.tar.${COMPRESSION}
XZ_OPT=${XZ_OPT-"-T0"} \
tar --mtime="${TAR_TIME}" --owner=root --group=root --sort=name \
--exclude-vcs -$SWITCH "${TARBALL_NAME}" "${TO_COMPRESS}"
mv "${TARBALL_NAME}" ..
popd
if [ "$WITH_TEMP" != "" ] ; then
echo "Tarball is: $(realpath .)/${TARBALL_NAME}"
popd
else
echo -n "Done. You may want to remove the uncompressed version"
echo " - $FILE_NAME_ROOT"
fi
# Local Variables:
# compile-command: "shellcheck generate_source_tarball.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -1,172 +0,0 @@
#!/usr/bin/env sh
# Copyright (C) 2025 Red Hat, Inc.
# Original written by Antonio Vieiro <avieirov@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
if [ $# -ne 1 ]; then
echo "Usage: $0 openjdk-root-directory"
exit 1
fi
JDKROOT=$1
if [ ! -d "${JDKROOT}" ] ; then
echo "${JDKROOT} is not a directory.";
exit 2
fi
# Work out the OpenJDK version
# OpenJDK >= 10 has its version in the build machinery
# OpenJDK >= 17 stores it in a new location (JDK-8258246)
VERSION_FILE="${JDKROOT}"/make/conf/version-numbers.conf
printf "Checking for %s..." "${VERSION_FILE}";
if [ ! -f "${VERSION_FILE}" ] ; then
VERSION_FILE="${JDKROOT}"/make/autoconf/version-numbers
echo "Not found; using old version file ${VERSION_FILE}";
else
echo "found.";
fi
if [ -e "${VERSION_FILE}" ] ; then
openjdk_version=$(grep '^DEFAULT_VERSION_FEATURE' "${VERSION_FILE}" | cut -d '=' -f 2)
elif [ -e "${JDKROOT}"/jdk/src/java.base/share/classes/java/lang/Object.java ] ; then
openjdk_version=9;
elif [ -e "${JDKROOT}"/common/autoconf ] ; then
openjdk_version=8;
else
openjdk_version=7;
fi
echo "OpenJDK version: ${openjdk_version}";
#
# Freetype
#
if [ "${openjdk_version}" -gt 8 ] ; then
FREETYPE=src/java.desktop/share/native/libfreetype/include/freetype/freetype.h
ABS_FREETYPE="${JDKROOT}"/"${FREETYPE}"
if [ ! -f "${ABS_FREETYPE}" ]; then
echo "Freetype header not found!"
exit 2
fi
FREETYPE_VERSION=$(awk '/#define FREETYPE_MAJOR/ {MAJOR=$3} /#define FREETYPE_MINOR/ {MINOR=$3} /#define FREETYPE_PATCH/ {PATCH=$3} END {printf "%s.%s.%s", MAJOR, MINOR, PATCH}' "${ABS_FREETYPE}")
else
echo "No bundled FreeType on ${openjdk_version}";
fi
# giflib
if [ "${openjdk_version}" -gt 8 ] ; then
GIFLIB=src/java.desktop/share/native/libsplashscreen/giflib/gif_lib.h
else
GIFLIB=jdk/src/share/native/sun/awt/giflib/gif_lib.h
fi
ABS_GIFLIB="${JDKROOT}"/"${GIFLIB}"
if [ ! -f "${ABS_GIFLIB}" ]; then
echo "giflib header not found!"
exit 3
fi
GIFLIB_VERSION=$(awk '/#define GIFLIB_MAJOR/ {MAJOR=$3} /#define GIFLIB_MINOR/ {MINOR=$3} /#define GIFLIB_RELEASE/ {PATCH=$3} END {printf "%s.%s.%s", MAJOR, MINOR, PATCH}' "${ABS_GIFLIB}")
# harfbuzz
if [ "${openjdk_version}" -gt 8 ] ; then
HARFBUZZ=src/java.desktop/share/native/libharfbuzz/hb-version.h
ABS_HARFBUZZ="${JDKROOT}/${HARFBUZZ}"
if [ ! -f "${ABS_HARFBUZZ}" ]; then
echo "HarfBuzz header not found!"
exit 4
fi
HARFBUZZ_VERSION=$(awk '/#define HB_VERSION_MAJOR/ {MAJOR=$3} /#define HB_VERSION_MINOR/ {MINOR=$3} /#define HB_VERSION_MICRO/ {PATCH=$3} END {printf "%s.%s.%s", MAJOR, MINOR, PATCH}' "${ABS_HARFBUZZ}")
else
echo "No HarfBuzz on ${openjdk_version}";
fi
# lcms
if [ "${openjdk_version}" -gt 8 ] ; then
LCMS=src/java.desktop/share/native/liblcms/lcms2.h
else
LCMS=jdk/src/share/native/sun/java2d/cmm/lcms/lcms2.h
fi
ABS_LCMS="${JDKROOT}"/"${LCMS}"
if [ ! -f "${ABS_LCMS}" ]; then
echo "lcms header not found!"
exit 5
fi
LCMS_VERSION=$(awk '/#define LCMS_VERSION/ { MAJOR=int($3 / 1000); REST=$3 % 1000; MINOR=int(REST / 10); PATCH=REST % 10; } END {printf "%s.%s.%s", MAJOR, MINOR, PATCH}' "${ABS_LCMS}")
# jpeg
if [ "${openjdk_version}" -gt 8 ] ; then
JPEG=src/java.desktop/share/native/libjavajpeg/jpeglib.h
else
JPEG=jdk/src/share/native/sun/awt/image/jpeg/jpeglib.h
fi
ABS_JPEG="${JDKROOT}"/"${JPEG}"
if [ ! -f "${ABS_JPEG}" ]; then
echo "jpeg header not found!"
exit 6
fi
JPEG_VERSION=$(awk '/#define JPEG_LIB_VERSION/ { VERSION=$3; MAJOR=int(VERSION / 10); MINOR=VERSION%10; } END {printf "%s%c", MAJOR, (MINOR+96)}' "${ABS_JPEG}")
# png
if [ "${openjdk_version}" -gt 8 ] ; then
PNG=src/java.desktop/share/native/libsplashscreen/libpng/png.h
else
PNG=jdk/src/share/native/sun/awt/libpng/png.h
fi
ABS_PNG="${JDKROOT}"/"${PNG}"
if [ ! -f "${ABS_PNG}" ]; then
echo "png header not found!"
exit 7
fi
PNG_VERSION=$(awk '/#define PNG_LIBPNG_VER_STRING/ { VERSION=$3; gsub("\"", "", VERSION) } END {print VERSION}' "${ABS_PNG}")
# zlib
if [ "${openjdk_version}" -gt 8 ] ; then
ZLIB=src/java.base/share/native/libzip/zlib/zlib.h
else
ZLIB=jdk/src/share/native/java/util/zip/zlib/zlib.h
fi
ABS_ZLIB="${JDKROOT}"/"${ZLIB}"
if [ ! -f "${ABS_ZLIB}" ]; then
echo "zlib header not found!"
exit 8
fi
ZLIB_VERSION=$(awk '/#define ZLIB_VERSION/ { VERSION=$3; gsub("\"", "", VERSION) } END {print VERSION}' "${ABS_ZLIB}")
# Print output
printf "\nRPM definitions:\n"
if [ "${openjdk_version}" -gt 8 ] ; then
echo "# Version in ${FREETYPE}"
echo "Provides: bundled(freetype) = ${FREETYPE_VERSION}"
fi
echo "# Version in ${GIFLIB}"
echo "Provides: bundled(giflib) = ${GIFLIB_VERSION}"
if [ "${openjdk_version}" -gt 8 ] ; then
echo "# Version in ${HARFBUZZ}"
echo "Provides: bundled(harfbuzz) = ${HARFBUZZ_VERSION}"
fi
echo "# Version in ${LCMS}"
echo "Provides: bundled(lcms2) = ${LCMS_VERSION}"
echo "# Version in ${JPEG}"
echo "Provides: bundled(libjpeg) = ${JPEG_VERSION}"
echo "# Version in ${PNG}"
echo "Provides: bundled(libpng) = ${PNG_VERSION}"
echo "# Version in ${ZLIB}"
echo "Provides: bundled(zlib) = ${ZLIB_VERSION}"
# Local Variables:
# compile-command: "shellcheck get_bundle_versions.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -1,198 +0,0 @@
#!/bin/bash
# Copyright (C) 2024 Red Hat, Inc.
# Written by Andrew John Hughes <gnu.andrew@redhat.com>.
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
ICEDTEA_USE_VCS=true
ICEDTEA_VERSION=3.15.0
ICEDTEA_URL=https://icedtea.classpath.org/download/source
ICEDTEA_SIGNING_KEY=CFDA0F9B35964222
ICEDTEA_HG_URL=https://icedtea.classpath.org/hg/icedtea11
set -e
RPM_DIR=${PWD}
if [ ! -f "${RPM_DIR}/jconsole.desktop.in" ] ; then
echo "Not in RPM source tree.";
exit 1;
fi
if test "${TMPDIR}" = ""; then
TMPDIR=/tmp;
fi
WORKDIR=${TMPDIR}/it.sync
echo "Using working directory ${WORKDIR}"
mkdir "${WORKDIR}"
pushd "${WORKDIR}"
if test "${WGET}" = ""; then
WGET=$(which wget);
if test "${WGET}" = ""; then
echo "wget not found";
exit 1;
fi
fi
if test "${TAR}" = ""; then
TAR=$(which tar)
if test "${TAR}" = ""; then
echo "tar not found";
exit 2;
fi
fi
echo "Dependencies:";
echo -e "\tWGET: ${WGET}";
echo -e "\tTAR: ${TAR}\n";
if test "${ICEDTEA_USE_VCS}" = "true"; then
echo "Mode: Using VCS";
if test "${GREP}" = ""; then
GREP=$(which grep);
if test "${GREP}" = ""; then
echo "grep not found";
exit 3;
fi
fi
if test "${CUT}" = ""; then
CUT=$(which cut);
if test "${CUT}" = ""; then
echo "cut not found";
exit 4;
fi
fi
if test "${TR}" = ""; then
TR=$(which tr);
if test "${TR}" = ""; then
echo "tr not found";
exit 5;
fi
fi
if test "${HG}" = ""; then
HG=$(which hg);
if test "${HG}" = ""; then
echo "hg not found";
exit 6;
fi
fi
echo "Dependencies:";
echo -e "\tGREP: ${GREP}";
echo -e "\tCUT: ${CUT}";
echo -e "\tTR: ${TR}";
echo -e "\tHG: ${HG}";
echo "Checking out repository from VCS...";
${HG} clone ${ICEDTEA_HG_URL} icedtea
echo "Obtaining version from configure.ac...";
ROOT_VER=$(${GREP} '^AC_INIT' icedtea/configure.ac|${CUT} -d ',' -f 2|${TR} -d '[][:space:]')
echo "Root version from configure: ${ROOT_VER}";
VCS_REV=$(${HG} log -R icedtea --template '{node|short}' -r tip)
echo "VCS revision: ${VCS_REV}";
ICEDTEA_VERSION="${ROOT_VER}-${VCS_REV}"
echo "Creating icedtea-${ICEDTEA_VERSION}";
mkdir "icedtea-${ICEDTEA_VERSION}"
echo "Copying required files from checkout to icedtea-${ICEDTEA_VERSION}";
# Commented out for now as IcedTea 6's jconsole.desktop.in is outdated
#cp -a icedtea/jconsole.desktop.in ../icedtea-${ICEDTEA_VERSION}
cp -a "${RPM_DIR}/jconsole.desktop.in" "icedtea-${ICEDTEA_VERSION}"
cp -a icedtea/tapset "icedtea-${ICEDTEA_VERSION}"
rm -rf icedtea
else
echo "Mode: Using tarball";
if test "${ICEDTEA_VERSION}" = ""; then
echo "No IcedTea version specified for tarball download.";
exit 3;
fi
if test "${CHECKSUM}" = ""; then
CHECKSUM=$(which sha256sum)
if test "${CHECKSUM}" = ""; then
echo "sha256sum not found";
exit 4;
fi
fi
if test "${PGP}" = ""; then
PGP=$(which gpg)
if test "${PGP}" = ""; then
echo "gpg not found";
exit 5;
fi
fi
echo "Dependencies:";
echo -e "\tCHECKSUM: ${CHECKSUM}";
echo -e "\tPGP: ${PGP}\n";
echo "Checking for IcedTea signing key ${ICEDTEA_SIGNING_KEY}...";
if ! gpg --list-keys ${ICEDTEA_SIGNING_KEY}; then
echo "IcedTea signing key ${ICEDTEA_SIGNING_KEY} not installed.";
exit 6;
fi
echo "Downloading IcedTea release tarball...";
${WGET} -v ${ICEDTEA_URL}/icedtea-${ICEDTEA_VERSION}.tar.xz
echo "Downloading IcedTea tarball signature...";
${WGET} -v ${ICEDTEA_URL}/icedtea-${ICEDTEA_VERSION}.tar.xz.sig
echo "Downloading IcedTea tarball checksums...";
${WGET} -v ${ICEDTEA_URL}/icedtea-${ICEDTEA_VERSION}.sha256
echo "Verifying checksums...";
${CHECKSUM} --check --ignore-missing icedtea-${ICEDTEA_VERSION}.sha256
echo "Checking signature...";
${PGP} --verify icedtea-${ICEDTEA_VERSION}.tar.xz.sig
echo "Extracting files...";
${TAR} xJf icedtea-${ICEDTEA_VERSION}.tar.xz \
icedtea-${ICEDTEA_VERSION}/tapset \
icedtea-${ICEDTEA_VERSION}/jconsole.desktop.in
rm -vf icedtea-${ICEDTEA_VERSION}.tar.xz
rm -vf icedtea-${ICEDTEA_VERSION}.tar.xz.sig
rm -vf icedtea-${ICEDTEA_VERSION}.sha256
fi
echo "Replacing desktop files...";
mv -v "icedtea-${ICEDTEA_VERSION}/jconsole.desktop.in" "${RPM_DIR}"
echo "Creating new tapset tarball...";
mv -v "icedtea-${ICEDTEA_VERSION}" openjdk
${TAR} cJf "${RPM_DIR}/tapsets-icedtea-${ICEDTEA_VERSION}.tar.xz" openjdk
rm -rvf openjdk
popd
rm -rf "${WORKDIR}"
# Local Variables:
# compile-command: "shellcheck icedtea_sync.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -1,114 +0,0 @@
#!/bin/bash
# Copyright (C) 2024 Red Hat, Inc.
# Written by Andrew John Hughes <gnu.andrew@redhat.com>, 2012-2022
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
OLD_RELEASE=$1
NEW_RELEASE=$2
REPO=$3
SUBDIR=$4
SCRIPT_DIR=$(dirname "${0}")
if test "${SUBDIR}" = ""; then
echo "No subdirectory specified; using .";
SUBDIR=".";
fi
if test "$REPO" = ""; then
echo "No repository specified; using ${PWD}"
REPO=${PWD}
fi
if test "${TMPDIR}" = ""; then
TMPDIR=/tmp;
fi
echo "Repository: ${REPO}"
if [ -e "${REPO}/.git" ] ; then
TYPE=git;
elif [ -e "${REPO}/.hg" ] ; then
TYPE=hg;
else
echo "No Mercurial or Git repository detected.";
exit 1;
fi
if test "$OLD_RELEASE" = "" || test "$NEW_RELEASE" = ""; then
echo "ERROR: Need to specify old and new release";
exit 2;
fi
echo "Listing fixes between $OLD_RELEASE and $NEW_RELEASE in $REPO"
rm -f "${TMPDIR}/fixes2" "${TMPDIR}/fixes3" "${TMPDIR}/fixes"
for repos in . $("${SCRIPT_DIR}/discover_trees.sh" "${REPO}");
do
if test "$TYPE" = "hg"; then
hg log -r "tag('$NEW_RELEASE'):tag('$OLD_RELEASE') - tag('$OLD_RELEASE')" -R "$REPO/$repos" -G -M "${REPO}/${SUBDIR}" | \
grep -E '^[o:| ]*summary'|grep -v 'Added tag'|sed -r 's#^[o:| ]*summary:\W*([0-9])# - JDK-\1#'| \
sed 's#^[o:| ]*summary:\W*# - #' >> "${TMPDIR}/fixes2";
hg log -v -r "tag('$NEW_RELEASE'):tag('$OLD_RELEASE') - tag('$OLD_RELEASE')" -R "$REPO/$repos" -G -M "${REPO}/${SUBDIR}" | \
grep -E '^[o:| ]*[0-9]{7}'|sed -r 's#^[o:| ]*([0-9]{7})# - JDK-\1#' >> "${TMPDIR}/fixes3";
else
git -C "${REPO}" log --no-merges --pretty=format:%B "${NEW_RELEASE}...${OLD_RELEASE}" -- "${SUBDIR}" |grep -E '^[0-9]{7}' | \
sed -r 's#^([0-9])# - JDK-\1#' >> "${TMPDIR}/fixes2";
touch "${TMPDIR}/fixes3" ; # unused
fi
done
sort "${TMPDIR}/fixes2" "${TMPDIR}/fixes3" > "${TMPDIR}/fixes4"
uniq "${TMPDIR}/fixes4" > "${TMPDIR}/fixes"
rm -f "${TMPDIR}/fixes2" "${TMPDIR}/fixes3"
if ! [ -s "${TMPDIR}/fixes" ] ; then
echo "Failed to obtain fixes.";
exit 3;
fi
echo "In ${TMPDIR}/fixes:"
cat "${TMPDIR}/fixes"
printf "\nChecking for duplicates...";
if uniq -d "${TMPDIR}/fixes4" | grep 'JDK' > "${TMPDIR}/dupes"; then
printf "found.\nWARNING: Review the following duplicates:\n";
cat "${TMPDIR}/dupes";
else
echo "No apparent duplicates.";
fi
rm -f "${TMPDIR}/fixes4";
printf "\nChecking for backouts...";
if grep -i 'backout' "${TMPDIR}/fixes" > "${TMPDIR}/backouts"; then
printf "found.\nWARNING: Review the following backouts:\n"
cat "${TMPDIR}/backouts";
else
echo "No apparent backouts.";
fi
printf "\nChecking for bundled library updates...";
if grep -iE ':( \(tz\))? update.*(freetype|gif|harfbuzz|lcms|jpeg|png|timezone|zlib)' "${TMPDIR}/fixes" > "${TMPDIR}/bundles"; then
printf "found.\nWARNING: Review the following with respect to bundled provides:\n";
cat "${TMPDIR}/bundles";
echo "Compare the output of $(dirname "${0}")/get_bundle_versions.sh with the RPM using the JDK source tree"
else
echo "No apparent library updates.";
fi
# Local Variables:
# compile-command: "shellcheck openjdk_news.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -1,2 +1,3 @@
SHA512 (nssadapter-0.1.1.tar.xz) = 2b4675cfbfa2ccb6c9a4870a4b58ae555267f5b8c9bdb0cf37b075483e6e9ea929561c05070453cf0d67b0b029de5408274555bf2ff50e9533219e898b2717f9
SHA512 (openjdk-25.0.4+7.tar.xz) = bd2c336ba2f0196e361bc8fd81a39cd9907682c0fac3a2b24a703a2abcede0fc75247fc54767329fc45d2f562f2728e3691db864363e9ab326c8218280831494
SHA512 (tapsets-icedtea-6.0.0pre00-c848b93a8598.tar.xz) = 97d026212363b3c83f6a04100ad7f6fdde833d16579717f8756e2b8c2eb70e144a41a330cb9ccde9c3badd37a2d54fdf4650a950ec21d8b686d545ecb2a64d30 SHA512 (tapsets-icedtea-6.0.0pre00-c848b93a8598.tar.xz) = 97d026212363b3c83f6a04100ad7f6fdde833d16579717f8756e2b8c2eb70e144a41a330cb9ccde9c3badd37a2d54fdf4650a950ec21d8b686d545ecb2a64d30
SHA512 (openjdk-25.0.1+8.tar.xz) = eb84d876f81ca02803283e8294c89b6acbed3753426811c3bcc228615c9618deefc85da4aa702800cac2feb103e628ee8b92292b316e9d7e12a58b6de69c5085

View File

@ -1,21 +0,0 @@
---
- hosts: localhost
roles:
- role: standard-test-source
tags:
- always
- role: standard-test-basic
tags:
- classic
- atomic
required_packages:
- java-21-openjdk-devel
tests:
- javaVersion1:
dir: ~
run: set -ex; useradd franta1; su franta1 -c 'java -version';
run: set -ex; useradd franta4; su franta4 -c 'javac -version';
run: ls -l /usr/lib/jvm;
- javaVersion2:
dir: ~
run: set -ex; useradd franta2; su franta2 -c 'java --version'