Compare commits

...

11 Commits

Author SHA1 Message Date
acb923167d Portable build 2026-07-16 07:34:03 +00:00
5e3fe9ae73 Portable build
Fix portable archive macros for RPM 4.19
2026-06-16 04:19:14 +00:00
5dc2112246 Portable build
Fix portable archive macros for RPM 4.19
2026-03-15 03:56:47 +00:00
52ada43c6e Portable build
Fix portable archive macros for RPM 4.19
2026-03-12 04:10:11 +00:00
db8784caf4 Portable build
Fix portable archive macros for RPM 4.19
2026-03-05 10:32:29 +00:00
eabdullin
5fbc6a622b Portable build 2025-12-10 12:54:46 +00:00
eabdullin
a08e258b0a Portable build 2025-12-09 09:08:02 +00:00
eabdullin
dd9cc1d5a0 Portable build 2025-12-07 04:13:02 +00:00
eabdullin
0c1b531c29 Portable build 2025-12-06 04:19:20 +00:00
eabdullin
708f8165e7 Portable build 2025-11-29 04:24:03 +00:00
eabdullin
ef1aceed36 Portable build 2025-11-27 07:22:06 +00:00
26 changed files with 3522 additions and 2948 deletions

3
.gitignore vendored
View File

@ -44,3 +44,6 @@
/openjdk-25+36.tar.xz
/openjdk-25.0.1+8.tar.xz
/nssadapter-0.1.0.tar.xz
/openjdk-25.0.2+10.tar.xz
/nssadapter-0.1.1.tar.xz
/openjdk-25.0.3+9.tar.xz

843
NEWS
View File

@ -3,6 +3,849 @@ Key:
JDK-X - https://bugs.openjdk.java.net/browse/JDK-X
CVE-XXXX-YYYY: https://cve.mitre.org/cgi-bin/cvename.cgi?name=XXXX-YYYY
New in release OpenJDK 25.0.3 (2026-04-21):
===========================================
Live versions of these release notes can be found at:
* https://bit.ly/openjdk2503
* CVEs
- CVE-2026-22007
- CVE-2026-22008
- CVE-2026-22013
- CVE-2026-22016
- CVE-2026-22018
- CVE-2026-22021
- CVE-2026-23865
- CVE-2026-34268
- CVE-2026-34282
* Changes
- JDK-7191877: TEST_BUG: java/rmi/transport/checkLeaseInfoLeak/CheckLeaseLeak.java failing intermittently
- JDK-8030957: AIX: Implement OperatingSystemMXBean.getSystemCpuLoad() and .getProcessCpuLoad() on AIX
- JDK-8068378: [TEST_BUG]The java/awt/Modal/PrintDialogsTest/PrintDialogsTest.java instruction need to update
- JDK-8183336: Better cleanup for jdk/test/java/lang/module/customfs/ModulesInCustomFileSystem.java
- JDK-8212084: G1: Implement UseGCOverheadLimit
- JDK-8244336: Restrict algorithms at JCE layer
- JDK-8246037: Shenandoah: update man pages to mention -XX:+UseShenandoahGC
- JDK-8255463: java/nio/channels/spi/SelectorProvider/inheritedChannel/InheritedChannelTest.java failed with ThreadTimeoutException
- JDK-8256289: java/awt/Focus/AppletInitialFocusTest/AppletInitialFocusTest1.java failed with "RuntimeException: Wrong focus owner: java.awt.Button[button1,41,36,56x23,label=Button1]"
- JDK-8274082: Wrong test name in jtreg run tag for java/awt/print/PrinterJob/SwingUIText.java
- JDK-8286258: [Accessibility,macOS,VoiceOver] VoiceOver reads the spinner value wrong and sometime partially
- JDK-8286865: vmTestbase/vm/mlvm/meth/stress/jni/nativeAndMH/Test.java fails with Out of space in CodeCache
- JDK-8287062: com/sun/jndi/ldap/LdapPoolTimeoutTest.java failed due to different timeout message
- JDK-8293484: AArch64: TestUseSHA512IntrinsicsOptionOnSupportedCPU.java fails on CPU with SHA512 feature support
- JDK-8299304: Test "java/awt/print/PrinterJob/PageDialogTest.java" fails on macOS 13 x64 because the Page Dialog blocks the Toolkit
- JDK-8307495: Specialize atomic bitset functions for aix-ppc
- JDK-8313770: jdk/internal/platform/docker/TestSystemMetrics.java fails on Ubuntu
- JDK-8316274: javax/swing/ButtonGroup/TestButtonGroupFocusTraversal.java fails in Ubuntu 23.10 with Motif LAF
- JDK-8317838: java/nio/channels/Channels/SocketChannelStreams.java running into timeout (aix)
- JDK-8318662: Refactor some jdk/java/net/httpclient/http2 tests to JUnit
- JDK-8320677: Printer tests use invalid '@run main/manual=yesno
- JDK-8333857: Test sun/security/ssl/SSLSessionImpl/ResumeChecksServer.java failed: Existing session was used
- JDK-8333871: Check return values of sysinfo
- JDK-8334928: Test sun/security/ssl/SSLSocketImpl/ReuseAddr.java failed: java.net.BindException: Address already in use
- JDK-8335646: Nimbus : JLabel not painted with LAF defined foreground color on Ubuntu 24.04
- JDK-8336695: Update Commons BCEL to Version 6.10.0
- JDK-8339791: Refactor MiscUndecorated/ActiveAWTWindowTest.java
- JDK-8341039: compiler/cha/TypeProfileFinalMethod.java fails with assertEquals expected: 0 but was: 2
- JDK-8342175: MemoryEaterMT fails intermittently with ExceptionInInitializerError
- JDK-8342401: [TESTBUG] javax/swing/JSpinner/8223788/JSpinnerButtonFocusTest.java test fails in ubuntu 22.04 on SBR Hosts
- JDK-8342640: GenShen: Silently ignoring ShenandoahGCHeuristics considered poor user-experience
- JDK-8342659: Test vmTestbase/nsk/jdi/ObjectReference/referringObjects/referringObjects002/referringObjects002.java failed: Class nsk.share.jdi.TestClass1 was not unloaded
- JDK-8343316: Review and update tests using explicit provider names
- JDK-8343340: Swapping checking do not work for MetricsMemoryTester failcount
- JDK-8343474: [updates] Customize README.md to specifics of update project
- JDK-8344073: Test runtime/cds/appcds/TestParallelGCWithCDS.java#id0 failed
- JDK-8346154: [XWayland] Some tests fail intermittently in the CI, but not locally
- JDK-8346962: Test CRLReadTimeout.java fails with -Xcomp on a fastdebug build
- JDK-8348014: Enhance certificate processing
- JDK-8349192: jvmti/scenarios/contention/TC05/tc05t001 fails: ERROR: tc05t001.cpp, 281: (waitedThreadCpuTime - waitThreadCpuTime) < (EXPECTED_ACCURACY * 1000000)
- JDK-8352149: Test java/awt/Frame/MultiScreenTest.java fails: Window list is empty
- JDK-8353755: Add a helper method to Util - findComponent()
- JDK-8354244: Use random data in MinMaxRed_Long data arrays
- JDK-8354469: Keytool exposes the password in plain text when command is piped using | grep
- JDK-8354894: java/lang/Thread/virtual/Starvation.java timeout on server with high CPUs
- JDK-8354937: Cleanup some sparc related coding in os_linux
- JDK-8356548: Use ClassFile API instead of ASM to transform classes in tests
- JDK-8356868: Not all cgroup parameters are made available
- JDK-8357277: Update OpenSSL library for interop tests
- JDK-8357380: java/lang/StringBuilder/RacingSBThreads.java times out with C1
- JDK-8357390: java/awt/Toolkit/ScreenInsetsTest/ScreenInsetsTest.java Test failing on Ubuntu 24.04 Vm Hosts used by Oracle's internal CI system
- JDK-8357470: src/java.base/share/classes/sun/security/util/Debug.java implement the test for args.toLowerCase
- JDK-8357570: [macOS] os::Bsd::available_memory() might return too low values
- JDK-8357591: Re-enable CDS test cases for jvmci after JDK-8345826
- JDK-8358058: sun/java2d/OpenGL/DrawImageBg.java Test fails intermittently
- JDK-8358159: Empty mode/padding in cipher transformations
- JDK-8358529: GenShen: Heuristics do not respond to changes in SoftMaxHeapSize
- JDK-8358679: [asan] vmTestbase/nsk/jvmti tests show memory issues
- JDK-8358686: CDS and AOT can cause buffer truncation warning even when logging is disabled
- JDK-8358735: GenShen: block_start() may be incorrect after class unloading
- JDK-8358756: [s390x] Test StartupOutput.java crash due to CodeCache size
- JDK-8358801: javac produces class that does not pass verifier.
- JDK-8359064: Expose reason for marking nmethod non-entrant to JVMCI client
- JDK-8359182: Use @requires instead of SkippedException for MaxPath.java
- JDK-8359388: Stricter checking for cipher transformations
- JDK-8359418: Test "javax/swing/text/GlyphView/bug4188841.java" failed because the phrase of text pane does not match the instructions
- JDK-8359472: JVM crashes when attaching a dynamic agent before JVMTI_PHASE_LIVE
- JDK-8359707: Add classfile modification code to RedefineClassHelper
- JDK-8359868: Shenandoah: Free threshold heuristic does not use SoftMaxHeapSize
- JDK-8359978: Test javax/net/ssl/SSLSocket/Tls13PacketSize.java failed again with java.net.SocketException: An established connection was aborted by the software in your host machine
- JDK-8360049: CodeInvalidationReasonTest.java fails with ZGC on AArch64
- JDK-8360160: ubuntu-22-04 machine is failing client tests
- JDK-8360169: Problem list CodeInvalidationReasonTest.java on linux-riscv64 until JDK-8360168 is fixed
- JDK-8360271: String.indexOf intrinsics fail with +EnableX86ECoreOpts and -CompactStrings
- JDK-8360395: sun/security/tools/keytool/i18n.java user country is current user location instead of the language
- JDK-8360539: DTLS handshakes fails due to improper cookie validation logic
- JDK-8360562: sun/security/tools/keytool/i18n.java add an ability to add comment for failures
- JDK-8360702: runtime/Thread/AsyncExceptionTest.java timed out
- JDK-8360882: Tests throw SkippedException when they should fail
- JDK-8361067: Test ExtraButtonDrag.java requires frame.dispose in finally block
- JDK-8361106: [TEST] com/sun/net/httpserver/Test9.java fails with java.nio.file.FileSystemException
- JDK-8361363: ShenandoahAsserts::print_obj() does not work for forwarded objects and UseCompactObjectHeaders
- JDK-8361381: GlyphLayout behavior differs on JDK 11+ compared to JDK 8
- JDK-8361492: [IR Framework] Has too restrictive regex for load and store
- JDK-8361521: BogusFocusableWindowState.java fails with StackOverflowError on Linux
- JDK-8361530: Test javax/swing/GraphicsConfigNotifier/StalePreferredSize.java timed out
- JDK-8361613: System.console() should only be available for interactive terminal
- JDK-8361894: sun/security/krb5/config/native/TestDynamicStore.java ensure that the test is run with sudo
- JDK-8362284: RISC-V: cleanup NativeMovRegMem
- JDK-8362979: C2 fails with unexpected node in SuperWord truncation: CmpLTMask, RoundF
- JDK-8363950: Incorrect jtreg header in TestLayoutVsICU.java
- JDK-8364373: Transform Affine transformations
- JDK-8364465: Enhance behavior of some intrinsics
- JDK-8364580: Test compiler/vectorization/TestSubwordTruncation.java fails on platforms without RoundF/RoundD
- JDK-8364741: [asan] runtime/ErrorHandling/PrintVMInfoAtExitTest.java fails because output differs slightly
- JDK-8364756: JFR: Improve slow tests
- JDK-8364936: Shenandoah: Switch nmethod entry barriers to conc_instruction_and_data_patch
- JDK-8365065: cancelled ForkJoinPool tasks no longer throw CancellationException
- JDK-8365184: sun/tools/jhsdb/HeapDumpTestWithActiveProcess.java Re-enable SerialGC flag on debuggee process
- JDK-8365305: The ARIA role contentinfo is not valid for the element <footer>
- JDK-8365398: TEST_BUG: java/rmi/transport/checkLeaseInfoLeak/CheckLeaseLeak.java failing intermittently
- JDK-8365526: Crash with null Symbol passed to SystemDictionary::resolve_or_null
- JDK-8365570: C2 fails assert(false) failed: Unexpected node in SuperWord truncation: CastII
- JDK-8365776: Convert JShell tests to use JUnit instead of TestNG
- JDK-8365861: test/jdk/sun/security/pkcs11/Provider/ tests skipped without SkippedException
- JDK-8365972: JFR: ThreadDump and ClassLoaderStatistics events may cause back to back rotations
- JDK-8366082: Improve queue size computation in CPU-time sampler
- JDK-8366128: jdk/jdk/nio/zipfs/TestPosix.java::testJarFile uses wrong file
- JDK-8366182: Some PKCS11Tests are being skipped when they shouldn't
- JDK-8366261: Provide utility methods for sun.security.util.Password
- JDK-8366278: Form control element <select> has no associated label
- JDK-8366369: Add @requires linux for GTK L&F tests
- JDK-8366486: Test jdk/jfr/event/profiling/TestCPUTimeSampleMultipleRecordings.java is timing out
- JDK-8366733: Re-examine older java.text NF, DF, and DFS serialization tests
- JDK-8366747: RISC-V: Improve VerifyMethodHandles for method handle linkers
- JDK-8366817: test/jdk/javax/net/ssl/TLSCommon/interop/JdkProcServer.java and JdkProcClient.java should not delete logs
- JDK-8366874: Test gc/arguments/TestParallelGCErgo.java fails with UseTransparentHugePages
- JDK-8366878: Improve flags of compiler/loopopts/superword/TestAlignVectorFuzzer.java
- JDK-8366908: Use a different class for testing JDK-8351654
- JDK-8366938: Test runtime/handshake/HandshakeTimeoutTest.java crashed
- JDK-8366951: Test runtime/logging/StressAsyncUL.java is timing out
- JDK-8367135: Test compiler/loopstripmining/CheckLoopStripMining.java needs internal timeouts adjusted
- JDK-8367271: Add parsing tests to DateFormat JMH benchmark
- JDK-8367278: Test compiler/startup/StartupOutput.java timed out after completion on Windows
- JDK-8367302: New test jdk/jfr/event/profiling/TestCPUTimeSampleQueueAutoSizes.java from JDK-8366082 is failing
- JDK-8367371: Remove @requires vm.opt.UseLargePages from InternSharedString.java test
- JDK-8367372: Test `test/hotspot/jtreg/gc/TestObjectAlignmentCardSize.java` fails on 32 bit systems
- JDK-8367463: Improved Arena allocations
- JDK-8367583: sun/security/util/AlgorithmConstraints/InvalidCryptoDisabledAlgos.java fails after JDK-8244336
- JDK-8367772: Refactor createUI in PassFailJFrame
- JDK-8367784: java/awt/Focus/InitialFocusTest/InitialFocusTest1.java failed with Wrong focus owner
- JDK-8367862: debug.cpp: Do not print help message for methods ifdef'd out
- JDK-8367901: Calendar.roll(hour, 24) returns wrong result
- JDK-8367994: test/jdk/sun/security/pkcs11/Signature/ tests pass when they should skip
- JDK-8368029: Several tests in httpserver/simpleserver should throw SkipException
- JDK-8368182: AOT cache creation fails with class defined by JNI
- JDK-8368328: CompactNumberFormat.clone does not produce independent instances
- JDK-8368335: Refactor the rest of Locale TestNG based tests to JUnit
- JDK-8368498: Use JUnit instead of TestNG for jdk_text tests
- JDK-8368500: ContextClassLoader cannot be reset on threads in ForkJoinPool.commonPool()
- JDK-8368551: Core dump warning may be confusing
- JDK-8368625: com/sun/net/httpserver/ServerStopTerminationTest.java fails intermittently
- JDK-8368677: acvp test should throw SkippedException when no ACVP-Server available
- JDK-8368683: [process] Increase jtreg debug output maxOutputSize for TreeTest
- JDK-8368754: runtime/cds/appcds/SignedJar.java log regex is too strict
- JDK-8368787: Error reporting: hs_err files should show instructions when referencing code in nmethods
- JDK-8368866: compiler/codecache/stress/UnexpectedDeoptimizationTest.java intermittent timed out
- JDK-8368882: NPE during text drawing on machine with JP locale
- JDK-8368885: NMT CommandLine tests can check for error better
- JDK-8368892: Make JEditorPane/TestBrowserBGColor.java headless
- JDK-8369032: Add test to ensure serialized ICC_Profile stores only necessary optional data
- JDK-8369050: DecimalFormat Rounding Errors for Fractional Ties Near Zero
- JDK-8369227: Virtual thread stuck in PARKED state
- JDK-8369255: Assess and remedy any unsafe usage of the Semaphores used by JFR
- JDK-8369282: Distrust TLS server certificates anchored by Chunghwa ePKI Root CA
- JDK-8369335: Two sun/java2d/OpenGL tests fail on Windows after JDK-8358058
- JDK-8369505: jhsdb jstack cannot handle continuation stub
- JDK-8369516: Delete duplicate imaging test
- JDK-8369575: Enhance crypto algorithm support
- JDK-8369804: TestGenerators.java fails with IllegalArgumentException: bound must be greater than origin
- JDK-8369851: Remove darcy author tags from langtools tests
- JDK-8369858: Remove darcy author tags from jdk tests
- JDK-8369881: C2: Unexpected node in SuperWord truncation: ReverseBytesS, ReverseBytesUS
- JDK-8369911: Test sun/java2d/marlin/ClipShapeTest.java#CubicDoDash, #Cubic and #Poly fail intermittent
- JDK-8369991: Thread blocking during JFR emergency dump must be in safepoint safe state
- JDK-8370036: TestJhsdbJstackWithVirtualThread.java fails when run with -showversion
- JDK-8370064: Test runtime/NMT/CheckForProperDetailStackTrace.java fails on Windows when using stripped pdb files
- JDK-8370197: Add missing @Override annotations in com.sun.beans package
- JDK-8370201: Test serviceability/sa/TestJhsdbJstackWithVirtualThread.java fails due to VM warnings
- JDK-8370203: Add jcmd AOT.end_recording diagnostic command
- JDK-8370240: [PPC64] jhsdb jstack cannot handle continuation stub
- JDK-8370242: JFR: Clear event reference eagerly when using EventStream
- JDK-8370244: [PPC64] Several vector tests fail on Power8
- JDK-8370325: G1: Disallow GC for TLAB allocation
- JDK-8370378: Some compiler tests inadvertently exclude particular platforms
- JDK-8370393: Cleanup handling of ancient Windows versions from GetJavaProperties java_props_md
- JDK-8370405: C2: mismatched store from MergeStores wrongly scalarized in allocation elimination
- JDK-8370492: [Linux] Update cpu shares to cpu.weight mapping function
- JDK-8370511: test/jdk/javax/swing/JSlider/bug4382876.java does not release previously pressed keys
- JDK-8370529: Enhance Path Factories Redux
- JDK-8370572: Cgroups hierarchical memory limit is not honored after JDK-8322420
- JDK-8370579: PPC: fix inswri immediate argument order
- JDK-8370615: Improve Kerberos credentialing
- JDK-8370636: com/sun/jdi/TwoThreadsTest.java should wait for completion of all threads
- JDK-8370646: TestLargeUTF8Length.java needs lots of memory
- JDK-8370649: Add intermittent tag for gc/shenandoah/generational/TestOldGrowthTriggers.java
- JDK-8370708: RISC-V: Add VerifyStackAtCalls
- JDK-8370730: Test serviceability/attach/EarlyDynamicLoad/EarlyDynamicLoad.java needs to be resilient about warnings
- JDK-8370732: Use WhiteBox.getWhiteBox().fullGC() to provoking gc for nsk/jvmti tests
- JDK-8370887: DelayScheduler.replace method may break the 4-ary heap in certain scenarios
- JDK-8370905: Update vm.defmeth tests to use virtual threads
- JDK-8370942: test/jdk/java/security/Provider/NewInstance.java and /test/jdk/java/security/cert/CertStore/NoLDAP.java may skip without notifying
- JDK-8370966: Create regression test for the hierarchical memory limit fix in JDK-8370572
- JDK-8370986: Enhance Zip file reading
- JDK-8370995: Enhance ZipFile usage
- JDK-8371014: Dump JFR recording on CrashOnOutOfMemoryError is incorrectly implemented
- JDK-8371103: vmTestbase/nsk/jvmti/scenarios/events/EM02/em02t006/TestDescription.java failing
- JDK-8371262: sun/security/pkcs11/Cipher/KeyWrap tests may silently skip
- JDK-8371316: Adjust assertion (GC pause time cannot be smaller than the sum of each phase) in G1GCPhaseTimes::print
- JDK-8371349: Update NSS library to 3.117
- JDK-8371364: Refactor javax/swing/JFileChooser/FileSizeCheck.java to use Util.findComponent()
- JDK-8371365: Update javax/swing/JFileChooser/bug4759934.java to use Util.findComponent()
- JDK-8371366: java/net/httpclient/whitebox/RawChannelTestDriver.java fails intermittently in jtreg timeout
- JDK-8371368: SIGSEGV in JfrVframeStream::next_vframe() on arm64
- JDK-8371383: Test sun/security/tools/jarsigner/DefaultOptions.java failed due to CertificateNotYetValidException
- JDK-8371385: compiler/escapeAnalysis/TestRematerializeObjects.java fails in case of -XX:-UseUnalignedAccesses
- JDK-8371420: Still sporadic failures of gc/TestAlwaysPreTouchBehavior.java#<gcname> on Linux after JDK-8359104
- JDK-8371485: ProblemList awt/Mixing/AWT_Mixing/JTableInGlassPaneOverlapping.java for linux
- JDK-8371559: Intermittent timeouts in test javax/net/ssl/Stapling/HttpsUrlConnClient.java
- JDK-8371608: Jtreg test jdk/internal/vm/Continuation/Fuzz.java sometimes fails with (fast)debug binaries
- JDK-8371759: Add missing @Override annotations in com.sun.imageio package
- JDK-8371769: TestMemoryInvisibleParent.java fails with java.nio.file.AccessDeniedException
- JDK-8371830: Enhance certificate chain validation
- JDK-8371854: Shenandoah: Simplify WALK_FORWARD_IN_BLOCK_START use
- JDK-8371864: GaloisCounterMode.implGCMCrypt0 AVX512/AVX2 intrinsics stubs cause AES-GCM encryption failure for certain payload sizes
- JDK-8371895: Lower GCTimeLimit in TestUseGCOverheadLimit.java
- JDK-8371935: Enhance key generation
- JDK-8371944: AOT configuration is corrupted when app closes System.out
- JDK-8371948: TestStackOverflowDuringInit.java fails xss too small on linux-aarch64
- JDK-8371966: RISC-V: Incorrect pointer dereference in TemplateInterpreterGenerator::generate_native_entry
- JDK-8371967: Add Visual Studio 2026 to build toolchain for Windows
- JDK-8371978: tools/jar/ReproducibleJar.java fails on XFS
- JDK-8372012: java/nio/file/attribute/BasicFileAttributeView/SetTimesNanos.java should check ability to create links
- JDK-8372046: compiler/floatingpoint/TestSubNodeFloatDoubleNegation.java fails IR verification
- JDK-8372048: Performance improvement on Linux remote desktop
- JDK-8372110: GenShen: Fix erroneous assert
- JDK-8372120: Add missing sound keyword to MIDI tests
- JDK-8372147: ConnectionFlowControlTest should use HttpResponse.connectionLabel()
- JDK-8372321: TestBackToBackSensitive fails intermittently after JDK-8365972
- JDK-8372348: Adjust some UL / JFR string deduplication output messages
- JDK-8372412: Increase buffer size for ring-buffer events in CollectedHeap
- JDK-8372441: JFR: Improve logging of TestBackToBackSensitive
- JDK-8372534: Update Libpng to 1.6.51
- JDK-8372586: Crashes on ppc64(le) after JDK-8371368
- JDK-8372589: VM crashes on init when NonNMethodCodeHeapSize is set too small and UseTransparentHugePages is enabled
- JDK-8372591: assert(!current->cont_fastpath() || freeze.check_valid_fast_path()) failed
- JDK-8372609: Bug4944439 does not enforce locale correctly
- JDK-8372661: Add a null-safe static factory method to "jdk.test.lib.net.SimpleSSLContext"
- JDK-8372704: ThreadMXBean.getThreadUserTime may return total time
- JDK-8372710: Update ProcessBuilder/Basic regex
- JDK-8372733: GHA: Bump to Ubuntu 24.04
- JDK-8372756: Mouse additional buttons and horizontal scrolling are broken on XWayland GNOME >= 47 after JDK-8351907
- JDK-8372835: WorkQueue::push is missing an acquire-fence
- JDK-8372857: Improve debuggability of java/rmi/server/RemoteServer/AddrInUse.java test
- JDK-8372860: TestCodeCacheUnloadDuringConcCycle fails on ARM32
- JDK-8372977: Unnecessary gthread-2.0 loading
- JDK-8372988: Test runtime/Nestmates/membership/TestNestHostErrorWithMultiThread.java failed: Unexpected interrupt
- JDK-8373021: aarch64: MacroAssembler::arrays_equals reads out of bounds
- JDK-8373101: JdkClient and JdkServer test classes ignore namedGroups field
- JDK-8373106: JFR suspend/resume deadlock on macOS in pthreads library
- JDK-8373290: Update FreeType to 2.14.1
- JDK-8373429: gc/g1/TestCodeCacheUnloadDuringConcCycle fails on various platforms
- JDK-8373476: (tz) Update Timezone Data to 2025c
- JDK-8373485: JFR Crash during sampling: assert(jt->has_last_Java_frame()) failed: invariant
- JDK-8373525: C2: assert(_base == Long) failed: Not a Long
- JDK-8373537: Migrate "test/jdk/com/sun/net/httpserver/" to null-safe "SimpleSSLContext" methods
- JDK-8373593: Support latest VS2026 MSC_VER in abstract_vm_version.cpp
- JDK-8373623: Refactor Serialization tests for Records to JUnit
- JDK-8373630: r18_tls should not be modified on Windows AArch64
- JDK-8373632: Some sound tests failing in CI due to lack of sound key
- JDK-8373704: Improve "SocketException: Protocol family unavailable" message
- JDK-8373716: Refactor further java/util tests from TestNG to JUnit
- JDK-8373727: New XBM images parser regression: only the first line of the bitmap array is parsed
- JDK-8373793: TestDynamicStore.java '/manual' disables use of '/timeout'
- JDK-8373807: test/jdk/java/net/httpclient/websocket/DummyWebSocketServer.java getURI() uses "localhost"
- JDK-8373832: Test java/lang/invoke/TestVHInvokerCaching.java tests nothing
- JDK-8373869: Refactor java/net/httpclient/ThrowingPushPromises*.java tests to use JUnit5
- JDK-8373931: Test javax/sound/sampled/Clip/AutoCloseTimeCheck.java timed out
- JDK-8373946: Synth ProgressBarUI implementation confuses background painting with border painting
- JDK-8373984: Check for macos 11 in CGraphicsDevice.m can be removed
- JDK-8373998: RISC-V: simple optimization of ConvHF2F
- JDK-8374056: RISC-V: Fix argument passing for the RiscvFlushIcache::flush
- JDK-8374178: Missing include in systemDictionary.cpp after JDK-8365526
- JDK-8374433: java/util/Locale/PreserveTagCase.java does not run any tests
- JDK-8374434: Several JShell tests report JUnit discovery warnings
- JDK-8374525: RISC-V: Several masked float16 vector operations are not supported
- JDK-8374555: No need for visible input warning in s.s.u.Password when not reading from System.in
- JDK-8374557: Enhance TLS connection handling
- JDK-8374642: EscapeHash macro fails with GNU make 4.3 and 4.4
- JDK-8374644: Regression in GZIPInputStream performance after JDK-7036144
- JDK-8374711: Hotspot runtime/CommandLine/OptionsValidation/TestOptionsWithRanges fails without printing the option name
- JDK-8374872: Cleanup outdated SAP AG copyright header info
- JDK-8374875: Improve perfMemory warning about 'Insufficient space for shared memory file'
- JDK-8375057: Update HarfBuzz to 12.3.2
- JDK-8375063: Update Libpng to 1.6.54
- JDK-8375094: RISC-V: Fix client builds after JDK-8368732
- JDK-8375231: Refactor util/ServiceLoader tests to use JUnit
- JDK-8375232: Refactor util/StringJoiner tests to use JUnit
- JDK-8375233: Refactor util/Vector tests to use JUnit
- JDK-8375311: Some builds are missing debug helpers
- JDK-8375530: PPC64: incorrect quick verify_method_data_pointer check causes poor performance in debug build
- JDK-8375549: ConcurrentModificationException if jdk.crypto.disabledAlgorithms has multiple entries with known oid
- JDK-8375598: VM crashes with "assert((labs(val) & 0xFFFFFFFF00000000) == 0 || dest == (address)-1) failed: must be 32bit offset or -1" when using too high value for NonNMethodCodeHeapSize
- JDK-8375657: RISC-V: Need to check size in SharedRuntime::is_wide_vector
- JDK-8375742: Test java/lang/invoke/MethodHandleProxies/Driver.java does not run Unnamed.java
- JDK-8375963: [25u] Set designator DEFAULT_PROMOTED_VERSION_PRE=ea in jdk25u-dev
- JDK-8375999: com/sun/jndi/ldap/LdapPoolTimeoutTest.java fails sporadically on Windows
- JDK-8376572: RISC-V: Interpreter: Load array index as signed int
- JDK-8376688: Gtest os.attempt_reserve_memory_between_small_range_fill_hole_vm fails on AIX 7.3
- JDK-8376889: Enhance JfrRecorder::on_create_vm_3() assert output
- JDK-8377347: jdk/jfr/event/gc/detailed/TestZAllocationStallEvent.java intermittent OOME
- JDK-8377509: Add licenses for gcc 14.2.0
- JDK-8377526: Update Libpng to 1.6.55
- JDK-8377811: [25u] G1: Optional Evacuations may evacuate pinned objects
- JDK-8377898: Hotspot build on AIX with unused-functions warning reports some unused functions
- JDK-8377905: gcc.md included with every build
- JDK-8378113: Add sun/java2d/OpenGL/ScaleParamsOOB.java to the ProblemList.txt file
- JDK-8378218: MSYS2 reports cygwin triplet causing bash configure failure
- JDK-8378353: [PPC64] StringCoding.countPositives causes errors when the length is not a proper 32 bit int
- JDK-8378623: Use unique font names in FormatCharAdvanceTest
- JDK-8378631: Update Zlib Data Compression Library to Version 1.3.2
- JDK-8378823: AIX build fails after zlib updated by JDK-8378631
- JDK-8378853: [25u] Make backport of JDK-8244336 comply with differences in CSR
- JDK-8379035: (tz) Update Timezone Data to 2026a
- JDK-8379158: Update FreeType to 2.14.2
- JDK-8379256: Update GIFlib to 6.1.1
- JDK-8380078: Update GIFlib to 6.1.2
- JDK-8380959: Update Libpng to 1.6.56
- JDK-8382047: Update Libpng to 1.6.57
- JDK-8382438: [25u] Remove designator DEFAULT_PROMOTED_VERSION_PRE=ea for release 25.0.3
Notes on individual issues:
===========================
security-libs/javax.net.ssl:
JDK-8369282: Distrust TLS server certificates anchored by Chunghwa ePKI Root CA
===============================================================================
In accordance with similar plans recently announced by Google and
Mozilla, the JDK will not trust Transport Layer Security (TLS)
certificates issued after the 17th of March 2026 which are anchored by
Chungwa root certificates.
Certificates issued on or before the 17th of March, 2026 will continue
to be trusted until they expire.
If a server's certificate chain is anchored by an affected
certificate, attempts to negotiate a TLS session will fail with an
Exception that indicates the trust anchor is not trusted. For example,
"TLS server certificate issued after 2026-03-17 and anchored by a
distrusted legacy Chungwa root CA: OU=ePKI Root Certification
Authority, O="Chunghwa Telecom Co.", Ltd. C=TW"
To check whether a certificate in a JDK keystore is affected by this
change, you can the `keytool` utility:
keytool -v -list -alias <your_server_alias> -keystore <your_keystore_filename>
If any of the certificates in the chain are affected by this change,
then you will need to update the certificate or contact the
organisation responsible for managing the certificate.
These restrictions apply to the following Chungwa root certificates
included in the JDK:
Alias name: chunghwaepkirootca
OU=ePKI Root Certification Authority
O="Chunghwa Telecom Co., Ltd."
C=TW
SHA256:A6:F4:DC:63:A2:4B:FD:CF:54:EF:2A:6A:08:2A:0A:72:DE:35:80:3E:2F:F5:FF:52:7A:E5:D8:72:06:DF:D5
Users can, *at their own risk*, remove this restriction by modifying
the `java.security` configuration file (or override it by using the
`java.security.properties` system property) so "CHUNGWA_TLS" is no
longer listed in the `jdk.security.caDistrustPolicies` security
property.
hotspot/jfr:
JDK-8365972: JFR: ThreadDump and ClassLoaderStatistics events may cause back to back rotations
==============================================================================================
In previous OpenJDK releases, the `jdk.ThreadDump` and
`jdk.ClassLoaderStatistics` events were written at the beginning of a
new file created by a file rotation. However, in applications with
many threads (typically more than a thousand), deep Java stacks
(typically more than three hundred frames) or many class loaders
(typically hundreds of thousands), the size of these events alone
could trigger a further file rotation within one second. This causes
other relevant data to be flushed out very quickly (e.g. about fifteen
seconds if using the default 250MB max file size). In this release,
these events are only written when a recording starts and at the end
of a file rotation.
security-libs/java.security:
JDK-8244336: Restrict algorithms at JCE layer
=============================================
A security property named `jdk.crypto.disabledAlgorithms` has been
added that can be used to disable JCE/JCA cryptographic services. The
property accepts a comma-separated list of services, specified as
Service.AlgorithName. The current list of supported services is
`Cipher`, `KeyStore`, `MessageDigest` and `Signature`. Algorithms
should be drawn from those specified by the Java Security Standard
Algorithm Names Specification [0]. For example:
jdk.crypto.disabledAlgorithms=Cipher.RSA/ECB/PKCS1Padding, MessageDigest.MD2
would disable the RSA cipher when used with the ECB cipher algorithm
mode and PKCS #1 algorithm padding, and the MD2 message digest
algorithm.
The default value for this security property is empty, which means
that no algorithms are disabled out-of-the-box. The value of the
security property specified in `java.security` can be overridden by
specifying a system property of the same name,
`jdk.crypto.disabledAlgorithms`. With the above example in place in
`java.security`, running `java` as:
$ java -Djdk.crypto.disabledAlgorithms=
would cause these algorithms to be enabled for that run of the Java
virtual machine.
[0] https://docs.oracle.com/en/java/javase/25/docs/specs/security/standard-names.html
JDK-8354469: Keytool exposes the password in plain text when command is piped using | grep
==========================================================================================
The `keytool` and `jarsigner` commands read passwords using the system
console with echoing disabled to avoid them being displayed on screen.
However, the system console is usually only available when both the
standard input and standard output have *not* been redirected. In
previous OpenJDK releases, running these tools with input or output
redirected would cause the password to be echoed to the screen in
plain text. With this release, echoing no longer takes place in such
scenarios when using these tools or the JAAS `TextCallbackHandler`
API.
hotspot/gc:
JDK-8212084: G1: Implement UseGCOverheadLimit
=============================================
In this release, the G1 garbage collector now respects the values of
`GCTimeLimit` and `GCHeapFreeLimit`. The garbage collector will throw
an `OutOfMemoryException` (OOME) when the garbage collection overhead
is more than `GCTimeLimit` percent (default: 98%) and the free Java
heap is less than `GCHeapFreeLimit` (default: 2%) for five consecutive
garbage collections.
This feature is enabled by default. It may be disabled by specifying
the `-XX:-UseGCOverheadLimit` option. The implementation mirrors the
functionality already provided by the parallel garbage collector,
though there may be differences in the exact conditions when an OOME
is triggered, due to differences in the way the collectors calculate
the collection overhead and free Java heap.
New in release OpenJDK 25.0.2 (2026-01-20):
===========================================
* CVEs
- CVE-2026-21925
- CVE-2026-21932
- CVE-2026-21933
- CVE-2026-21945
* Changes
- JDK-8023263: [TESTBUG] Test closed/java/awt/Focus/InactiveWindowTest/InactiveFocusRace fails due to not enough time to initialize graphic components
- JDK-8162380: [TEST_BUG] MouseEvent/.../AltGraphModifierTest.java has only "Fail" button
- JDK-8201778: Speed up test javax/net/ssl/DTLS/PacketLossRetransmission.java
- JDK-8265429: Improve GCM encryption
- JDK-8277444: Data race between JvmtiClassFileReconstituter::copy_bytecodes and class linking
- JDK-8279005: sun/tools/jstat tests do not check for test case exit codes after JDK-8245129
- JDK-8304811: vmTestbase/vm/mlvm/indy/func/jvmti/stepBreakPopReturn/INDIFY_Test.java fails with JVMTI_ERROR_TYPE_MISMATCH
- JDK-8305567: serviceability/tmtools/jstat/GcTest01.java failed utils.JstatGcResults.assertConsistency
- JDK-8317801: java/net/Socket/asyncClose/Race.java fails intermittently (aix)
- JDK-8320836: jtreg gtest runs should limit heap size
- JDK-8325766: Extend CertificateBuilder to create trust and end entity certificates programmatically
- JDK-8333526: Restructure java/nio/channels/DatagramChannel/StressNativeSignal.java to a fail fast exception handling policy
- JDK-8333783: java/nio/channels/FileChannel/directio/DirectIOTest.java is unstable with AV software
- JDK-8334238: Enhance AddLShortcutTest jpackage test
- JDK-8335986: Test javax/swing/JCheckBox/4449413/bug4449413.java fails on Windows 11 x64 because RBMenuItem's and CBMenuItem's checkmark on the left side are not visible
- JDK-8341496: Improve JMX connections
- JDK-8343218: Add option to disable allocating interface and abstract classes in non-class metaspace
- JDK-8343546: GHA: Cache required dependencies in master-branch workflow
- JDK-8345810: Custom launchers must be linked with pthread to avoid dynamic linker issues
- JDK-8346753: Test javax/swing/JMenuItem/RightLeftOrientation/RightLeftOrientation.java fails on Windows Server 2025 x64 because the icons of RBMenuItem and CBMenuItem are not visible in Nimbus LookAndFeel
- JDK-8346839: [TESTBUG] "java/awt/textfield/setechochartest4/setechochartest4.java" failed because the test frame disappears on clicking "Click Several Times" button
- JDK-8346884: Add since checker test to jdk.editpad
- JDK-8346952: GetGraphicsStressTest.java fails: Native resources unavailable
- JDK-8347277: java/awt/Focus/ComponentLostFocusTest.java fails intermittently
- JDK-8349188: LineBorder does not scale correctly
- JDK-8350621: Code cache stops scheduling GC
- JDK-8351487: [ubsan] jvmti.h runtime error: load of value which is not a valid value
- JDK-8352016: Improve java/lang/RuntimeTests/RuntimeExitLogTest.java
- JDK-8354348: Enable Extended EVEX to REX2/REX demotion for commutative operations with same dst and src2
- JDK-8354415: [Ubuntu25.04] api/java_awt/GraphicsDevice/indexTGF.html#SetDisplayMode - setDisplayMode_REFRESH_RATE_UNKNOWN fails: Height is different on vnc
- JDK-8354447: Missing test for retroactive @SuppressWarnings("dangling-doc-comments") behavior
- JDK-8354646: java.awt.TextField allows to identify the spaces in a password when double clicked at the starting and end of the text
- JDK-8355478: DoubleActionESC.java fails intermittently
- JDK-8356324: JVM crash (SIGSEGV at ClassListParser::resolve_indy_impl) during -Xshare:dump starting from 21.0.5
- JDK-8356897: Update NSS library to 3.111
- JDK-8357064: cds/appcds/ArchiveRelocationTest.java failed with missing expected output
- JDK-8357141: Update to use jtreg 7.5.2
- JDK-8357382: runtime/cds/appcds/aotClassLinking/BulkLoaderTest.java#aot fails with Xcomp and C1
- JDK-8357396: Refactor nmethod::make_not_entrant to use Enum instead of "const char*"
- JDK-8357691: File blocked.certs contains bad content when boot jdk 25 is used, sun/security/lib/CheckBlockedCerts.java failing
- JDK-8357694: RISC-V: Several IR verification tests fail when vlen=128
- JDK-8357799: Improve instructions for JFileChooser/HTMLFileName.java
- JDK-8357816: Add test from JDK-8350576
- JDK-8357822: C2: Multiple string optimization tests are no longer testing string concatenation optimizations
- JDK-8357959: (bf) ByteBuffer.allocateDirect initialization can result in large TTSP spikes
- JDK-8358048: java/net/httpclient/HttpsTunnelAuthTest.java incorrectly calls Thread::stop
- JDK-8358340: Support CDS heap archive with Generational Shenandoah
- JDK-8358532: JFileChooser in GTK L&F still displays HTML filename
- JDK-8358535: Changes in ClassValue (JDK-8351996) caused a 1-9% regression in Renaissance-PageRank
- JDK-8358556: Assert when running with -XX:-UseLibmIntrinsic
- JDK-8358685: [TEST] AOTLoggingTag.java failed with missing log message
- JDK-8358697: TextLayout/MyanmarTextTest.java passes if no Myanmar font is found
- JDK-8358723: jpackage signing issues: the main launcher doesn't have entitlements
- JDK-8358748: Large page size initialization fails with assert "page_size must be a power of 2"
- JDK-8358751: C2: Recursive inlining check for compiled lambda forms is broken
- JDK-8358813: JPasswordField identifies spaces in password via delete shortcuts
- JDK-8359061: Update and ProblemList manual test java/awt/Cursor/CursorDragTest/ListDragCursor.java
- JDK-8359104: gc/TestAlwaysPreTouchBehavior.java#<gcname> fails on Linux
- JDK-8359105: RISC-V: No need for acquire fence in safepoint poll during JNI calls
- JDK-8359127: Amend java/nio/channels/DatagramChannel/PromiscuousIPv6.java to use @requires for OS platform selection
- JDK-8359167: Remove unused test/hotspot/jtreg/vmTestbase/nsk/share/jpda/BindServer.java
- JDK-8359207: Remove runtime/signal/TestSigusr2.java since it is always skipped
- JDK-8359423: Improve error message in case of missing jsa shared archive
- JDK-8359428: Test 'javax/swing/JTabbedPane/bug4499556.java' failed because after selecting one of L&F items, the test case automatically failed when clicking on L&F Menu button again
- JDK-8359449: [TEST] open/test/jdk/java/io/File/SymLinks.java Refactor extract method for Windows specific test
- JDK-8359477: com/sun/net/httpserver/Test12.java appears to have a temp file race
- JDK-8359501: Enhance Handling of URIs
- JDK-8359687: Use PassFailJFrame for java/awt/print/Dialog/DialogType.java
- JDK-8359690: New test TestCPUTimeSampleThrottling still fails intermittently
- JDK-8359735: [Ubuntu 25.10] java/lang/ProcessBuilder/Basic.java, java/lang/ProcessHandle/InfoTest.java fail due to rust-coreutils
- JDK-8359827: Test runtime/Thread/ThreadCountLimit.java need loop increasing the limit
- JDK-8360022: ClassRefDupInConstantPoolTest.java fails when running in repeat
- JDK-8360090: [TEST] RISC-V: disable some cds tests on qemu
- JDK-8360178: TestArguments.atojulong gtest has incorrect format string
- JDK-8360219: [AIX] assert(locals_base >= l2) failed: bad placement
- JDK-8360255: runtime/jni/checked/TestLargeUTF8Length.java fails with -XX:-CompactStrings
- JDK-8360408: [TEST] Use @requires tag instead of exiting based on "os.name" property value for sun/net/www/protocol/file/FileURLTest.java
- JDK-8360411: [TEST] open/test/jdk/java/io/File/MaxPathLength.java Refactor extract method to encapsulate Windows specific test logic
- JDK-8360518: Docker tests do not work when asan is configured
- JDK-8360520: RISC-V: C1: Fix primitive array clone intrinsic regression after JDK-8333154
- JDK-8360664: Null pointer dereference in src/hotspot/share/prims/jvmtiTagMap.cpp in IterateOverHeapObjectClosure::do_object()
- JDK-8360783: CTW: Skip deoptimization between tiers
- JDK-8360791: [ubsan] Adjust signal handling
- JDK-8360867: CTW: Disable inline cache verification
- JDK-8360981: Remove use of Thread.stop in test/jdk/java/net/Socket/DeadlockTest.java
- JDK-8361112: Use exact float -> Float16 conversion method in Float16 tests
- JDK-8361180: Disable CompiledDirectCall verification with -VerifyInlineCaches
- JDK-8361198: [AIX] fix misleading error output in thread_cpu_time_unchecked
- JDK-8361211: C2: Final graph reshaping generates unencodeable klass constants
- JDK-8361215: Add AOT test case: verification constraint classes are excluded
- JDK-8361253: CommandLineOptionTest library should report observed values on failure
- JDK-8361255: CTW: Tolerate more NCDFE problems
- JDK-8361298: SwingUtilities/bug4967768.java fails where character P is not underline
- JDK-8361314: Test serviceability/jvmti/VMEvent/MyPackage/VMEventRecursionTest.java FATAL ERROR in native method: Failed during the GetClassSignature call
- JDK-8361367: AOT ExcludedClasses.java test failed with missing constant pool logs
- JDK-8361423: Add IPSupport::printPlatformSupport to java/net/NetworkInterface/IPv4Only.java
- JDK-8361449: RISC-V: Code cleanup for native call
- JDK-8361478: GHA: Use MSYS2 from GHA runners
- JDK-8361494: [IR Framework] Escape too much in replacement of placeholder
- JDK-8361497: Scoped Values: orElse and orElseThrow do not access the cache
- JDK-8361504: RISC-V: Make C1 clone intrinsic platform guard more specific
- JDK-8361520: Stabilize SystemGC benchmarks
- JDK-8361599: [PPC64] enable missing tests via jtreg requires
- JDK-8361711: Add library name configurability to PKCS11Test.java
- JDK-8361748: Enforce limits on the size of an XBM image
- JDK-8361839: Problemlist BogusFocusableWindowState due to failures in the CI pipeline
- JDK-8361868: [GCC static analyzer] complains about missing calloc - NULL checks in p11_util.c
- JDK-8361871: [GCC static analyzer] complains about use of uninitialized value ckpObject in p11_util.c
- JDK-8361888: [GCC static analyzer] ProcessImpl_md.c Java_java_lang_ProcessImpl_forkAndExec error: use of uninitialized value '*(ChildStuff *)p.mode
- JDK-8361892: AArch64: Incorrect matching rule leading to improper oop instruction encoding
- JDK-8361897: gc/z/TestUncommit.java fails with Uncommitted too slow
- JDK-8361948: Shenandoah: region free capacity unit mismatch
- JDK-8361950: Update to use jtreg 8
- JDK-8361959: [GCC static analyzer] java_props_md.c leak of 'temp' variable is reported
- JDK-8362107: Update the Jan CPU26_01 release date in master branch after forking Oct CPU25_10
- JDK-8362123: ClassLoader Leak via Executors.newSingleThreadExecutor(...)
- JDK-8362169: Pointer passed to upcall may get wrong scope
- JDK-8362204: test/jdk/sun/awt/font/TestDevTransform.java fails on Ubuntu 24.04
- JDK-8362207: Add more test cases for possible double-rounding in fma
- JDK-8362282: runtime/logging/StressAsyncUL.java failed with exitValue = 134
- JDK-8362308: Enhance Bitmap operations
- JDK-8362379: Test serviceability/HeapDump/UnmountedVThreadNativeMethodAtTop.java should mark as /native
- JDK-8362390: AIX make fails in awt_GraphicsEnv.c
- JDK-8362482: [TESTBUG] serviceability/HeapDump/UnmountedVThreadNativeMethodAtTop.java: System.gc() does not provide full GC
- JDK-8362501: Update test/hotspot/jtreg/applications/jcstress/README
- JDK-8362515: RISC-V: cleanup NativeFarCall
- JDK-8362516: Support of GCC static analyzer (-fanalyzer)
- JDK-8362530: VM crash with -XX:+PrintTieredEvents when collecting AOT profiling
- JDK-8362532: Test gc/g1/plab/* duplicate command-line options
- JDK-8362533: Tests sun/management/jmxremote/bootstrap/* duplicate VM flags
- JDK-8362581: Timeouts in java/nio/channels/SocketChannel/OpenLeak.java on UNIX
- JDK-8362582: GHA: Increase bundle retention time to deal with infra overload better
- JDK-8362596: RISC-V: Improve _vectorizedHashCode intrinsic
- JDK-8362602: Add test.timeout.factor to CompileFactory to avoid test timeouts
- JDK-8362632: Improve HttpServer Request handling
- JDK-8362834: Several runtime/Thread tests should mark as /native
- JDK-8362836: JFR: Broken pipe in jdk/jfr/event/io/TestIOTopFrame.java
- JDK-8362838: RISC-V: Incorrect matching rule leading to improper oop instruction encoding
- JDK-8362855: Test java/net/ipv6tests/TcpTest.java should report SkippedException when there no ia4addr or ia6addr
- JDK-8362889: [GCC static analyzer] leak in libstringPlatformChars.c
- JDK-8362972: C2 fails with unexpected node in SuperWord truncation: IsFiniteF, IsFiniteD
- JDK-8363676: [GCC static analyzer] missing return value check of malloc in OGLContext_SetTransform
- JDK-8363696: Update the release version and date for OpenJDK 25u
- JDK-8363720: Follow up to JDK-8360411 with post review comments
- JDK-8363895: Minimal build fails with slowdebug builds after JDK-8354887
- JDK-8363898: RISC-V: TestRangeCheckHoistingScaledIV.java fails after JDK-8355293 when running without RVV
- JDK-8363910: Avoid tuning for Power10 CPUs on Linux ppc64le when gcc < 10 is used
- JDK-8363928: Specifying AOTCacheOutput with a blank path causes the JVM to crash
- JDK-8363965: GHA: Switch cross-compiling sysroots to Debian bookworm
- JDK-8363966: GHA: Switch cross-compiling sysroots to Debian trixie
- JDK-8364090: Dump JFR recording on CrashOnOutOfMemoryError
- JDK-8364111: InstanceMirrorKlass iterators should handle CDS and hidden classes consistently
- JDK-8364114: Test TestHugePageDecisionsAtVMStartup.java#LP_enabled fails when no free hugepage
- JDK-8364120: RISC-V: unify the usage of MacroAssembler::instruction_size
- JDK-8364150: RISC-V: Leftover for JDK-8343430 removing old trampoline call
- JDK-8364177: JDK fails to build due to undefined symbol in libpng on LoongArch64
- JDK-8364184: [REDO] AArch64: [VectorAPI] sve vector math operations are not supported after JDK-8353217
- JDK-8364190: JFR: RemoteRecordingStream withers don't work
- JDK-8364198: NMT should have a better corruption message
- JDK-8364199: Enhance list of environment variables printed in hserr/hsinfo file
- JDK-8364212: Shenandoah: Rework archived objects loading
- JDK-8364214: Enhance polygon data support
- JDK-8364235: Fix for JDK-8361447 breaks the alignment requirements for GuardedMemory
- JDK-8364257: JFR: User-defined events and settings with a one-letter name cannot be configured
- JDK-8364263: HttpClient: Improve encapsulation of ProxyServer
- JDK-8364296: Set IntelJccErratumMitigation flag ergonomically
- JDK-8364352: Some tests fail when using a limited number of pregenerated .jsa CDS archives
- JDK-8364454: ProblemList runtime/cds/DeterministicDump.java on macos for JDK-8363986
- JDK-8364503: gc/g1/TestCodeCacheUnloadDuringConcCycle.java fails because of race printing to stdout
- JDK-8364514: [asan] runtime/jni/checked/TestCharArrayReleasing.java heap-buffer-overflow
- JDK-8364556: JFR: Disable SymbolTableStatistics and StringTableStatistics in default.jfc
- JDK-8364597: Replace THL A29 Limited with Tencent
- JDK-8364611: (process) Child process SIGPIPE signal disposition should be default
- JDK-8364660: ClassVerifier::ends_in_athrow() should be removed
- JDK-8364764: java/nio/channels/vthread/BlockingChannelOps.java subtests timed out
- JDK-8364786: Test java/net/vthread/HttpALot.java intermittently fails - 24999 handled, expected 25000
- JDK-8364984: Many jpackage tests are failing on Linux after JDK-8334238
- JDK-8364993: JFR: Disable jdk.ModuleExport in default.jfc
- JDK-8364996: java/awt/font/FontNames/LocaleFamilyNames.java times out on Windows
- JDK-8365058: Enhance CopyOnWriteArraySet
- JDK-8365071: ARM32: JFR intrinsic jvm_commit triggers C2 regalloc assert
- JDK-8365086: CookieStore.getURIs() and get(URI) should return an immutable List
- JDK-8365165: Zap C-heap memory at delete/free
- JDK-8365166: ARM32: missing os::fetch_bcp_from_context implementation
- JDK-8365168: Use 64-bit aligned addresses for CK_ULONG access in PKCS11 native key code
- JDK-8365200: RISC-V: compiler/loopopts/superword/TestGeneralizedReductions.java fails with Zvbb and vlen=128
- JDK-8365206: RISC-V: compiler/c2/irTests/TestFloat16ScalarOperations.java is failing on riscv64
- JDK-8365240: [asan] exclude some tests when using asan enabled binaries
- JDK-8365260: Problemlist 1 test due to failures in the CI pipeline
- JDK-8365265: x86 short forward jump exceeds 8-bit offset in methodHandles_x86.cpp when using Intel APX
- JDK-8365271: Improve Swing supports
- JDK-8365280: Enhance JOptionPane
- JDK-8365302: RISC-V: compiler/loopopts/superword/TestAlignVector.java fails when vlen=128
- JDK-8365307: AIX make fails after JDK-8364611
- JDK-8365312: GCC 12 cannot compile SVE on aarch64 with auto-var-init pattern
- JDK-8365389: Remove static color fields from SwingUtilities3 and WindowsMenuItemUI
- JDK-8365425: [macos26] javax/swing/JInternalFrame/8160248/JInternalFrameDraggingTest.java fails on macOS 26
- JDK-8365442: [asan] runtime/ErrorHandling/CreateCoredumpOnCrash.java fails
- JDK-8365468: EagerJVMCI should only apply to the CompilerBroker JVMCI runtime
- JDK-8365487: [asan] some oops (mode) related tests fail
- JDK-8365543: UnixNativeDispatcher.init should lookup open64at and stat64at on AIX
- JDK-8365571: GenShen: PLAB promotions may remain disabled for evacuation threads
- JDK-8365615: Improve JMenuBar/RightLeftOrientation.java
- JDK-8365638: JFR: Add --exact for debugging out-of-order events
- JDK-8365660: test/jdk/sun/security/pkcs11/KeyAgreement/ tests skipped without SkipExceprion
- JDK-8365700: Jar --validate without any --file option leaves around a temporary file /tmp/tmpJar<number>.jar
- JDK-8365726: Test crashed with assert in C1 thread: Possible safepoint reached by thread that does not allow it
- JDK-8365772: RISC-V: correctly prereserve NaN payload when converting from float to float16 in vector way
- JDK-8365790: Shutdown hook for application image does not work on Windows
- JDK-8365811: test/jdk/java/net/CookieHandler/B6644726.java failure - "Should have 5 cookies. Got only 4, expires probably didn't parse correctly"
- JDK-8365823: Revert storing abstract and interface Klasses to non-class metaspace
- JDK-8365834: Mark java/net/httpclient/ManyRequests.java as intermittent
- JDK-8365841: RISC-V: Several IR verification tests fail after JDK-8350960 without Zvfh
- JDK-8365844: RISC-V: TestBadFormat.java fails when running without RVV
- JDK-8365863: /test/jdk/sun/security/pkcs11/Cipher tests skip without SkippedException
- JDK-8365913: Support latest MSC_VER in abstract_vm_version.cpp
- JDK-8365919: Replace currentTimeMillis with nanoTime in Stresser.java
- JDK-8365926: RISC-V: Performance regression in renaissance (chi-square)
- JDK-8365956: GenShen: Adaptive tenuring threshold algorithm may raise threshold prematurely
- JDK-8365983: Tests should throw SkippedException when SCTP not supported
- JDK-8366028: MethodType::fromMethodDescriptorString should not throw UnsupportedOperationException for invalid descriptors
- JDK-8366029: Do not add -XX:VerifyArchivedFields by default to CDS tests
- JDK-8366031: Mark com/sun/nio/sctp/SctpChannel/CloseDescriptors.java as intermittent
- JDK-8366075: Problemlist 2 tests due to failures in the CI pipeline
- JDK-8366092: [GCC static analyzer] UnixOperatingSystem.c warning: use of uninitialized value 'systemTicks'
- JDK-8366147: ZGC: ZPageAllocator::cleanup_failed_commit_single_partition may leak memory
- JDK-8366159: SkippedException is treated as a pass for pkcs11/KeyStore, pkcs11/SecretKeyFactory and pkcs11/SecureRandom
- JDK-8366208: Unexpected exception in sun.java2d.cmm.lcms.LCMSImageLayout
- JDK-8366229: runtime/Thread/TooSmallStackSize.java runs with all collectors
- JDK-8366250: Problemlist 3 tests due to failures in the CI pipeline
- JDK-8366340: Problemlist 1 test due to failures in the CI pipeline
- JDK-8366342: Key generator and key pair generator tests skipping, but showing as passed
- JDK-8366359: Test should throw SkippedException when there is no lpstat
- JDK-8366365: [test] test/lib-test/jdk/test/whitebox/CPUInfoTest.java should be updated
- JDK-8366434: THP not working properly with G1 after JDK-8345655
- JDK-8366446: Test java/awt/geom/ConcurrentDrawPolygonTest.java fails intermittently
- JDK-8366537: Test "java/util/TimeZone/DefaultTimeZoneTest.java" is not updating the zone ID as expected
- JDK-8366558: Gtests leave /tmp/cgroups-test* files
- JDK-8366694: Test JdbStopInNotificationThreadTest.java timed out after 60 second
- JDK-8366750: Remove test 'java/awt/Choice/ChoiceMouseWheelTest/ChoiceMouseWheelTest.java' from problemlist
- JDK-8366764: Deproblemlist java/awt/ScrollPane/ScrollPositionTest.java
- JDK-8366800: Problemlist 1 test due to failures in the CI pipeline
- JDK-8366844: Update and automate MouseDraggedOriginatedByScrollBarTest.java
- JDK-8366850: Test com/sun/jdi/JdbStopInNotificationThreadTest.java failed
- JDK-8366893: java/lang/Thread/virtual/stress/GetStackTraceALotWhenPinned.java timed out on macos-aarch64
- JDK-8366948: AOT cache creation crashes when iterating training data
- JDK-8366980: TestTransparentHugePagesHeap.java fails when run with -UseCompressedOops
- JDK-8367017: Remove legacy checks from WrappedToolkitTest and convert from bash
- JDK-8367021: Regression in LocaleDataTest refactoring
- JDK-8367048: RISC-V: Correct pipeline descriptions of the architecture
- JDK-8367066: RISC-V: refine register selection in MacroAssembler:: decode_klass_not_null
- JDK-8367098: RISC-V: sync CPU features with related JVM flags for dependant ones
- JDK-8367131: Test com/sun/jdi/ThreadMemoryLeakTest.java fails on 32 bits
- JDK-8367133: DTLS: fragmentation of Finished message results in handshake failure
- JDK-8367137: RISC-V: Detect Zicboz block size via hwprobe
- JDK-8367237: Thread-Safety Usage Warning for java.text.Collator Classes
- JDK-8367277: Fix copyright header in JMXInterfaceBindingTest.java
- JDK-8367313: CTW: Execute in AWT headless mode
- JDK-8367333: C2: Vector math operation intrinsification failure
- JDK-8367348: Enhance PassFailJFrame to support links in HTML
- JDK-8367378: GenShen: Missing timing stats when old mark buffers are flushed during final update refs
- JDK-8367384: The ICC_Profile class may throw exceptions during serialization
- JDK-8367598: Switch to CRC32C for SEED calculation in jdk.test.lib.Utils
- JDK-8367616: RISC-V: Auto-enable Zicboz extension for debug builds
- JDK-8367689: Revert removal of several compilation-related vmStructs fields
- JDK-8367692: RISC-V: Align post call nop
- JDK-8367694: Fix jtreg test failure when Intel APX is enabled for KNL platforms
- JDK-8367780: Enable UseAPX on Intel CPUs only when both APX_F and APX_NCI_NDD_NF cpuid features are present
- JDK-8367782: VerifyJarEntryName.java: Fix modifyJarEntryName to operate on bytes and re-introduce verifySignatureEntryName
- JDK-8367869: Test java/io/FileDescriptor/Sync.java timed out
- JDK-8367904: Test java/net/InetAddress/ptr/Lookup.java should throw SkippedException
- JDK-8367948: JFR: MethodTrace threshold setting has no effect
- JDK-8367953: JFR sampler threads does not appear in thread dump
- JDK-8367969: C2: compiler/vectorapi/TestVectorMathLib.java fails without UnlockDiagnosticVMOptions
- JDK-8367988: NewFileSystemTests.readOnlyZipFileFailure fails when run by root user
- JDK-8368032: Enhance Certificate Checking
- JDK-8368071: Compilation throughput regressed 2X-8X after JDK-8355003
- JDK-8368152: Shenandoah: Incorrect behavior at end of degenerated cycle
- JDK-8368192: Test java/lang/ProcessBuilder/Basic.java#id0 fails with Exception: Stack trace
- JDK-8368366: RISC-V: AlignVector is mistakenly set to AvoidUnalignedAccesses
- JDK-8368367: Test jdk/jfr/event/gc/detailed/TestGCHeapMemoryUsageEvent.java fails jdk.GCHeapMemoryUsage "expected 0 > 0"
- JDK-8368565: Adjust comment regarding dependency of libjvm.so to librt
- JDK-8368606: Printer lookup returns empty on AIX platform due to uninitialized results list
- JDK-8368668: Several vmTestbase/vm/gc/compact tests timed out on large memory machine
- JDK-8368670: Deadlock in JFR on event register + class load
- JDK-8368698: runtime/cds/appcds/aotCache/OldClassSupport.java assert(can_add()) failed: Cannot add TrainingData objects
- JDK-8368732: RISC-V: Detect support for misaligned vector access via hwprobe
- JDK-8368890: open/test/jdk/tools/jpackage/macosx/NameWithSpaceTest.java fails randomly
- JDK-8368893: RISC-V: crash after JDK-8352673 on fastdebug version
- JDK-8368960: Adjust java UL logging in the build
- JDK-8368982: Test sun/security/tools/jarsigner/EC.java completed and timed out
- JDK-8369078: Fix faulty test conversion in IllegalCharsetName.java
- JDK-8369184: SimpleTimeZone equals() Returns True for Unequal Instances with Different hashCode Values
- JDK-8369190: JavaFrameAnchor on AArch64 has unnecessary barriers and wrong store order in MacroAssembler
- JDK-8369226: GHA: Switch to MacOS 15
- JDK-8369319: java/net/httpclient/CancelRequestTest.java fails intermittently
- JDK-8369450: [Ubuntu 25.10] openjdk fails to build due to rust-coreutils date
- JDK-8369487: Revert EA option for build promotion
- JDK-8369506: Bytecode rewriting causes Java heap corruption on AArch64
- JDK-8369560: Slowdebug build without CDS fails
- JDK-8369563: Gtest dll_address_to_function_and_library_name has issues with stripped pdb files
- JDK-8369616: JavaFrameAnchor on RISC-V has unnecessary barriers and wrong store order in MacroAssembler
- JDK-8369656: Calling CompletableFuture.join() could execute task in common pool
- JDK-8369657: [AIX] TOC overflow in static-launcher build when building slowdebug after JDK-8352064
- JDK-8369853: jpackage signing tests fail after JDK-8358723
- JDK-8369868: Compilation error in Win8365790Test.java with JDK-8358723 fix resulting in CI tier3 failure
- JDK-8369946: Bytecode rewriting causes Java heap corruption on PPC
- JDK-8369947: Bytecode rewriting causes Java heap corruption on RISC-V
- JDK-8369979: Flag UsePopCountInstruction was accidentally disabled on PPC64
- JDK-8370048: Shenandoah: Deprecated ShenandoahPacing option
- JDK-8370049: [s390x] G1 barrier compareAndExchange does not return old value when compareExchange fails
- JDK-8370318: AES-GCM vector intrinsic may read out of bounds (x86_64, AVX-512)
- JDK-8370331: Problemlist 2 tests due to failures in the CI pipeline
- JDK-8370428: Change milestone to fcs for all releases
- JDK-8370465: Right to Left Orientation Issues with MenuItem Component
- JDK-8371094: --mac-signing-key-user-name no longer works
- JDK-8371425: Include folder names in vscode workspace virtual folders
- JDK-8371697: test/jdk/java/nio/file/FileStore/Basic.java fails after 8360887 on linux
- JDK-8372753: jpackage ignores --file-associations option with predefined app image
Notes on individual issues:
===========================
core-libs/java.lang.invoke:
JDK-8358535: Changes in ClassValue (JDK-8351996) caused a 1-9% regression in Renaissance-PageRank
=================================================================================================
Behavioural changes in ClassValue in the original release of OpenJDK
25 (JDK-8351996) caused a noticeable performance regression after use
of ClassValue::remove. The cause of this regression was found to be
the accidental removal of a cache update in ClassValue::readAccess,
leading to ClassValue::get calls taking the slow path rather than
using the cache. In this update, the cache update is restored.
core-svc/javax.management:
JDK-8341496: Improve JMX connections
====================================
With this release of OpenJDK, SSL connections created by
javax.rmi.ssl.SslRMIClientSocketFactory now enable HTTPS-based
endpoint identification by default. This can be disabled by setting
the new system property
jdk.rmi.ssl.client.enableEndpointIdentification to false.
hotspot/gc:
JDK-8366434: THP not working properly with G1 after JDK-8345655
===============================================================
Refactoring of the memory reservation code in the original release of
OpenJDK 25 (JDK-8345655) caused a set page size provided by
`os::vm_page_size()` to always be used rather than a value passed in
by the calling method. As the page size is used by the G1 garbage
collector to determine the alignment of the reservation, this lead to
reservations being ineligible for Transparent Huge Pages (THP). In
this update, the caller specified page size is restored.
security-libs/java.security:
JDK-8368032: Enhance Certificate Checking
=========================================
OpenJDK supports the authorityInfoAccess extension in X.509
certificates when the `com.sun.security.enableAIAcaIssuers` system
property is set to `true`. With this release of OpenJDK, a security
and system property `com.sun.security.allowedAIALocations` is
introduced which acts as a filter on the URIs specified in the
extension. By default, the property is empty, which will cause all
URIs to be denied when the extension is enabled. A value of `any` may
be used to allow all URIs or a whitespace-separated list of filters
may be used for more fine-grained control. The syntax of the filters
is specified in the `java.security` file. A non-empty value for the
system property takes precedence over the security property.
New in release OpenJDK 25.0.1 (2025-10-21):
===========================================

View File

@ -23,28 +23,30 @@
#
# Usage:
#
# bash create-redhat-properties-files.bash <target directory>
# bash create-redhat-properties-files.bash <target directory> <nssadapter path>
#
# Example usage in spec file:
#
# bash -x create-redhat-properties-files.bash ${imagepath}/conf/security
# bash -x create-redhat-properties-files.bash ${installdir}/conf/security \
# %{_libdir}/%{sdkdir -- ${suffix}}/libnssadapter.so
#
# When you make changes to the file set here, also update the %files
# section in the spec file, and the JDK_PROPS_FILES_JDK_25 variables
# in TestSecurityProperties.java.
[[ $# == 1 ]] || exit 1
[[ $# == 2 ]] || exit 1
SECURITY="${1}"
NSSADAPTER="${2}"
VENDOR="${SECURITY}"/redhat
install --directory --mode=755 "${VENDOR}"
install --directory --mode=755 "${VENDOR}"/true
install --directory --mode=755 "${VENDOR}"/false
# /usr/lib/jvm/java-25-openjdk/conf/security/redhat/SunPKCS11-FIPS.cfg
install --mode 644 /dev/stdin "${VENDOR}"/SunPKCS11-FIPS.cfg <<'EOF'
install --mode 644 /dev/stdin "${VENDOR}"/SunPKCS11-FIPS.cfg <<EOF
name = FIPS
library = ${java.home}/lib/libnssadapter.so
library = ${NSSADAPTER}
slot = 3
nssUseSecmod = false
attributes(*,CKO_SECRET_KEY,*)={ CKA_SIGN=true CKA_ENCRYPT=true }
@ -107,16 +109,8 @@ security.provider.8=
keystore.type=pkcs12
EOF
# /usr/lib/jvm/java-25-openjdk/conf/security/redhat/fips.properties
# For now, this prevents an include cycle on JDKs that do not support
# ${__redhat_fips__}. In the future the goal is for it be overwritten
# (based on /proc/sys/crypto/fips_enabled) at FIPS configuration time
# (by fips-mode-setup or by grubby), at RPM install time by a
# post-install hook, and/or during boot by a systemd oneshot service.
install --mode 644 /dev/stdin "${VENDOR}"/fips.properties <<'EOF'
include false/fips.properties
EOF
# Make sure java.security exists before appending
test -e "${SECURITY}"/java.security || ( echo "${SECURITY}/java.security not found" && false )
cat >> "${SECURITY}"/java.security <<'EOF'
#

View File

@ -0,0 +1,87 @@
diff --git a/src/java.base/share/classes/java/security/Provider.java b/src/java.base/share/classes/java/security/Provider.java
index de2845fb550..60eeab678ca 100644
--- a/src/java.base/share/classes/java/security/Provider.java
+++ b/src/java.base/share/classes/java/security/Provider.java
@@ -1203,6 +1203,34 @@ public Set<Service> getServices() {
return serviceSet;
}
+ /* vvvvvvvvvvvvvvvvvvvvvvvvvvvvv FIPS PATCH vvvvvvvvvvvvvvvvvvvvvvvvvvvvv */
+ private static final class RedHatFIPSFilter {
+ static final boolean IS_ON = Boolean.parseBoolean(
+ Security.getProperty("__redhat_fips_filter__"));
+ private static final Map<String, Set<String>> ALLOW_LIST = Map.of(
+ "SUN", Set.of(
+ "AlgorithmParameterGenerator",
+ "AlgorithmParameters", "CertificateFactory",
+ "CertPathBuilder", "CertPathValidator", "CertStore",
+ "Configuration", "KeyStore"),
+ "SunEC", Set.of(
+ "AlgorithmParameters", "KeyFactory"),
+ "SunJCE", Set.of(
+ "AlgorithmParameters",
+ "AlgorithmParameterGenerator", "KeyFactory",
+ "SecretKeyFactory"),
+ "SunRsaSign", Set.of(
+ "KeyFactory", "AlgorithmParameters")
+ );
+
+ static boolean isAllowed(String provName, String serviceType) {
+ Set<String> allowedServiceTypes = ALLOW_LIST.get(provName);
+ return allowedServiceTypes == null ||
+ allowedServiceTypes.contains(serviceType);
+ }
+ }
+ /* ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ FIPS PATCH ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ */
+
/**
* Add a service. If a service of the same type with the same algorithm
* name exists, and it was added using {@link #putService putService()},
@@ -1231,6 +1259,15 @@ protected void putService(Service s) {
("service.getProvider() must match this Provider object");
}
String type = s.getType();
+ /* vvvvvvvvvvvvvvvvvvvvvvvvvvv FIPS PATCH vvvvvvvvvvvvvvvvvvvvvvvvvvv */
+ if (RedHatFIPSFilter.IS_ON && !RedHatFIPSFilter.isAllowed(name, type)) {
+ if (debug != null) {
+ debug.println("The previous " + name + ".putService() call " +
+ "was skipped by " + RedHatFIPSFilter.class.getName());
+ }
+ return;
+ }
+ /* ^^^^^^^^^^^^^^^^^^^^^^^^^^^ FIPS PATCH ^^^^^^^^^^^^^^^^^^^^^^^^^^^ */
String algorithm = s.getAlgorithm();
ServiceKey key = new ServiceKey(type, algorithm, true);
implRemoveService(serviceMap.get(key));
diff --git a/src/java.base/share/classes/java/security/Security.java b/src/java.base/share/classes/java/security/Security.java
index 6969fe8a8e1..4501d5971c4 100644
--- a/src/java.base/share/classes/java/security/Security.java
+++ b/src/java.base/share/classes/java/security/Security.java
@@ -323,7 +323,27 @@ public Properties getInitialProperties() {
}
private static void initialize() {
+ /* vvvvvvvvvvvvvvvvvvvvvvvvvvv FIPS PATCH vvvvvvvvvvvvvvvvvvvvvvvvvvv */
+ /* This 'include'-directives-only magic property is an internal */
+ /* implementation detail that could (and probably will!) change. */
+ /* Red Hat customers should NOT rely on this for their own use. */
+ String fipsKernelFlag = "/proc/sys/crypto/fips_enabled";
+ boolean fipsModeOn;
+ try (InputStream is = new java.io.FileInputStream(fipsKernelFlag)) {
+ fipsModeOn = is.read() == '1';
+ } catch (IOException ioe) {
+ fipsModeOn = false;
+ if (sdebug != null) {
+ sdebug.println("Failed to read FIPS kernel file: " + ioe);
+ }
+ }
+ String fipsMagicPropName = "__redhat_fips__";
+ System.setProperty(fipsMagicPropName, "" + fipsModeOn);
+ /* ^^^^^^^^^^^^^^^^^^^^^^^^^^^ FIPS PATCH ^^^^^^^^^^^^^^^^^^^^^^^^^^^ */
SecPropLoader.loadAll();
+ /* vvvvvvvvvvvvvvvvvvvvvvvvvvv FIPS PATCH vvvvvvvvvvvvvvvvvvvvvvvvvvv */
+ System.clearProperty(fipsMagicPropName);
+ /* ^^^^^^^^^^^^^^^^^^^^^^^^^^^ FIPS PATCH ^^^^^^^^^^^^^^^^^^^^^^^^^^^ */
initialSecurityProperties = (Properties) props.clone();
if (sdebug != null) {
for (String key : props.stringPropertyNames()) {

View File

@ -1,4 +1,97 @@
# debug_package %%{nil} is portable-jdks specific
# New Version-String scheme-style defines
%global featurever 25
%global interimver 0
%global updatever 3
%global patchver 0
%global buildver 9
%global portablerelease 3
%global rpmrelease 0
# Define IcedTea version used for SystemTap tapsets and desktop file
%global icedteaver 6.0.0pre00-c848b93a8598
# Define current Git revision for the FIPS support patches
%global fipsver 57722aab802
# Define JDK versions
%global newjavaver %{featurever}.%{interimver}.%{updatever}.%{patchver}
%global javaver %{featurever}
# Strip up to 6 trailing zeros in newjavaver, as the JDK does, to get the correct version used in filenames
%global filever %(svn=%{newjavaver}; for i in 1 2 3 4 5 6 ; do svn=${svn%%.0} ; done; echo ${svn})
# The tag used to create the OpenJDK tarball
%global vcstag jdk-%{filever}+%{buildver}%{?tagsuffix:-%{tagsuffix}}
# Standard JPackage naming and versioning defines
%global origin openjdk
%global origin_nice OpenJDK
%global top_level_dir_name %{vcstag}
%global top_level_dir_name_backup %{top_level_dir_name}-backup
# Define an optional suffix for the OS this package is built on
%if 0%{?rhel} == 7
%global pkgos rhel7
%endif
# Define milestone (EA for pre-releases, GA for releases)
# Release will be (where N is usually a number starting at 1):
# - 0.N.ea<dist> for EA releases,
# - N<dist> for GA releases
%global is_ga 1
%if %{is_ga}
%global build_type GA
%global ea_designator ""
%global ea_designator_zip %{nil}
%global extraver %{nil}
%global eaprefix %{nil}
%else
%global build_type EA
%global ea_designator ea
%global ea_designator_zip -%{ea_designator}
%global extraver .%{ea_designator}
%global eaprefix 0.
%endif
%global compatiblename java-%{javaver}-%{origin}
Name: %{compatiblename}-portable%{?pkgos:-%{pkgos}}
Version: %{newjavaver}.%{buildver}
Release: %{?eaprefix}%{portablerelease}.%{rpmrelease}%{?extraver}%{?dist}
%global fullversion %{compatiblename}-%{version}-%{release}
# java-1.5.0-ibm from jpackage.org set Epoch to 1 for unknown reasons
# and this change was brought into RHEL-4. java-1.5.0-ibm packages
# also included the epoch in their virtual provides. This created a
# situation where in-the-wild java-1.5.0-ibm packages provided "java =
# 1:1.5.0". In RPM terms, "1.6.0 < 1:1.5.0" since 1.6.0 is
# interpreted as 0:1.6.0. So the "java >= 1.6.0" requirement would be
# satisfied by the 1:1.5.0 packages. Thus we need to set the epoch in
# JDK package >= 1.6.0 to 1, and packages referring to JDK virtual
# provides >= 1.6.0 must specify the epoch, "java >= 1:1.6.0".
Epoch: 1
Summary: %{origin_nice} %{featurever} Runtime Environment portable edition
# Groups are only used up to RHEL 8 and on Fedora versions prior to F30
%if (0%{?rhel} > 0 && 0%{?rhel} <= 8) || (0%{?fedora} >= 0 && 0%{?fedora} < 30)
Group: Development/Languages
%endif
# HotSpot code is licensed under GPLv2
# JDK library code is licensed under GPLv2 with the Classpath exception
# The Apache license is used in code taken from Apache projects (primarily xalan & xerces)
# DOM levels 2 & 3 and the XML digital signature schemas are licensed under the W3C Software License
# The JSR166 concurrency code is in the public domain
# The BSD and MIT licenses are used for a number of third-party libraries (see ADDITIONAL_LICENSE_INFO)
# The OpenJDK source tree includes:
# - JPEG library (IJG), zlib & libpng (zlib), giflib (MIT), harfbuzz (ISC),
# - freetype (FTL), jline (BSD) and LCMS (MIT)
# - jquery (MIT), jdk.crypto.cryptoki PKCS 11 wrapper (RSA)
# - public_suffix_list.dat from publicsuffix.org (MPLv2.0)
# The test code includes copies of NSS under the Mozilla Public License v2.0
# The PCSClite headers are under a BSD with advertising license
# The elliptic curve cryptography (ECC) source code is licensed under the LGPLv2.1 or any later version
License: ASL 1.1 and ASL 2.0 and BSD and BSD with advertising and GPL+ and GPLv2 and GPLv2 with exceptions and IJG and LGPLv2+ and MIT and MPLv2.0 and Public Domain and W3C and zlib and ISC and FTL and RSA
URL: http://openjdk.java.net/
# We are producing RPMs containing only tarballs
# and checksums so there are no binaries outside
# the tarballs to be processed for debuginfo
%define debug_package %{nil}
# RPM conditionals so as to be able to dynamically produce
@ -96,25 +189,6 @@
%global normal_build %{nil}
%endif
# We have hardcoded list of files, which is appearing in alternatives, and in files
# in alternatives those are slaves and master, very often triplicated by man pages
# in files all masters and slaves are ghosted
# the ghosts are here to allow installation via query like `dnf install /usr/bin/java`
# you can list those files, with appropriate sections: cat *.spec | grep -e --install -e --slave -e post_
# TODO - fix those hardcoded lists via single list
# Those files must *NOT* be ghosted for *slowdebug* packages
# FIXME - if you are moving jshell or jlink or similar, always modify all three sections
# you can check via headless and devels:
# rpm -ql --noghost java-11-openjdk-headless-11.0.1.13-8.fc29.x86_64.rpm | grep bin
# == rpm -ql java-11-openjdk-headless-slowdebug-11.0.1.13-8.fc29.x86_64.rpm | grep bin
# != rpm -ql java-11-openjdk-headless-11.0.1.13-8.fc29.x86_64.rpm | grep bin
# similarly for other %%{_jvmdir}/{jre,java} and %%{_javadocdir}/{java,java-zip}
%define is_release_build() %( if [ "%{?1}" == "%{debug_suffix_unquoted}" -o "%{?1}" == "%{fastdebug_suffix_unquoted}" ]; then echo "0" ; else echo "1"; fi )
# while JDK is a techpreview(is_system_jdk=0), some provides are turned off. Once jdk stops to be an techpreview, move it to 1
# as sytem JDK, we mean any JDK which can run whole system java stack without issues (like bytecode issues, module issues, dependencies...)
%global is_system_jdk 0
%global aarch64 aarch64 arm64 armv8
# we need to distinguish between big and little endian PPC64
%global ppc64le ppc64le
@ -226,7 +300,7 @@
# other targets since this target is configured to use in-tree
# AWT dependencies: lcms, libjpeg, libpng, libharfbuzz, giflib
# and possibly others
%global static_libs_target static-libs-image
%global static_libs_target static-libs-graal-image
%else
%global static_libs_target %{nil}
%endif
@ -333,17 +407,14 @@
%global with_systemtap 0
%endif
# New Version-String scheme-style defines
%global featurever 25
%global interimver 0
%global updatever 1
%global patchver 0
# buildjdkver is usually same as %%{featurever},
# but in time of bootstrap of next jdk, it is featurever-1,
# buildjdkver is usually same as featurever,
# but at the time of bootstrap of the next jdk, it is featurever-1,
# and this it is better to change it here, on single place
%global buildjdkver %{featurever}
# We don't add any LTS designator for STS packages (Fedora and EPEL).
# We need to explicitly exclude EPEL as it would have the %%{rhel} macro defined.
# We need to explicitly exclude EPEL as it has the rhel macro defined.
%if 0%{?rhel} && !0%{?epel}
%global lts_designator "LTS"
%global lts_designator_zip -%{lts_designator}
@ -355,7 +426,8 @@
# Define vendor information used by OpenJDK
%global oj_vendor Red Hat, Inc.
%global oj_vendor_url https://www.redhat.com/
# Define what url should JVM offer in case of a crash report
# Define what url the JVM should offer in case of a crash report
# order may be important, epel may have rhel declared
%if 0%{?epel}
%global oj_vendor_bug_url https://bugzilla.redhat.com/enter_bug.cgi?product=Fedora%20EPEL&component=%{name}&version=epel%{epel}
@ -371,67 +443,13 @@
%endif
%endif
%endif
%global oj_vendor_version (Red_Hat-%{version}-%{rpmrelease})
%global oj_vendor_version (Red_Hat-%{version}-%{portablerelease})
# Define IcedTea version used for SystemTap tapsets and desktop file
%global icedteaver 6.0.0pre00-c848b93a8598
# Define current Git revision for the FIPS support patches
%global fipsver 9203d50836c
# Define JDK versions
%global newjavaver %{featurever}.%{interimver}.%{updatever}.%{patchver}
%global javaver %{featurever}
# Strip up to 6 trailing zeros in newjavaver, as the JDK does, to get the correct version used in filenames
%global filever %(svn=%{newjavaver}; for i in 1 2 3 4 5 6 ; do svn=${svn%%.0} ; done; echo ${svn})
# The tag used to create the OpenJDK tarball
%global vcstag jdk-%{filever}+%{buildver}%{?tagsuffix:-%{tagsuffix}}
# Standard JPackage naming and versioning defines
%global origin openjdk
%global origin_nice OpenJDK
%global top_level_dir_name %{vcstag}
%global top_level_dir_name_backup %{top_level_dir_name}-backup
%global buildver 8
%global rpmrelease 1
#%%global tagsuffix %%{nil}
# Priority must be 8 digits in total; up to openjdk 1.8, we were using 18..... so when we moved to 11, we had to add another digit
%if %is_system_jdk
# Using 10 digits may overflow the int used for priority, so we combine the patch and build versions
# It is very unlikely we will ever have a patch version > 4 or a build version > 20, so we combine as (patch * 20) + build.
# This means 11.0.9.0+11 would have had a priority of 11000911 as before
# A 11.0.9.1+1 would have had a priority of 11000921 (20 * 1 + 1), thus ensuring it is bigger than 11.0.9.0+11
%global combiver $( expr 20 '*' %{patchver} + %{buildver} )
%global priority %( printf '%02d%02d%02d%02d' %{featurever} %{interimver} %{updatever} %{combiver} )
%else
# for techpreview, using 1, so slowdebugs can have 0
%global priority %( printf '%08d' 1 )
%endif
# Define milestone (EA for pre-releases, GA for releases)
# Release will be (where N is usually a number starting at 1):
# - 0.N%%{?extraver}%%{?dist} for EA releases,
# - N%%{?extraver}{?dist} for GA releases
%global is_ga 1
%if %{is_ga}
%global build_type GA
%global ea_designator ""
%global ea_designator_zip %{nil}
%global extraver %{nil}
%global eaprefix %{nil}
%else
%global build_type EA
%global ea_designator ea
%global ea_designator_zip -%{ea_designator}
%global extraver .%{ea_designator}
%global eaprefix 0.
%endif
# parametrized macros are order-sensitive
%global compatiblename java-%{featurever}-%{origin}
%global fullversion %{compatiblename}-%{version}-%{release}
# images directories from upstream build
%global jdkimage jdk
%global static_libs_image static-libs
%global static_libs_image static-libs-graal
# output dir stub
# Parameterised macros are order-sensitive
%define buildoutputdir() %{expand:build/jdk%{featurever}.build%{?1}}
%define installoutputdir() %{expand:install/jdk%{featurever}.install%{?1}}
%global altjavaoutputdir install/altjava.install
@ -442,20 +460,29 @@
%define uniquesuffix() %{expand:%{fullversion}.%{_arch}%{?1}}
# portable only declarations
%global jreimage jre
%define jreportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable%{1}.jre;g")
%define jdkportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable%{1}.jdk;g")
%define staticlibsportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable%{1}.static-libs;g")
%define jreportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable%{1}.jre;g")
%define jdkportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable%{1}.jdk;g")
%define staticlibsportablenameimpl() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable%{1}.static-libs;g")
# RPM 4.19 no longer accept our double percentaged %%{nil} passed to %%{1}
# so we have to pass in "" but evaluate it, otherwise files will include it
%define jreportablearchive() %{expand:%{jreportablenameimpl -- %%{1}}.tar.xz}
%define jreportablearchive_for_files() %(echo %{jreportablearchive -- ""})
%define jdkportablearchive() %{expand:%{jdkportablenameimpl -- %%{1}}.tar.xz}
%define jdkportablearchive_for_files() %(echo %{jdkportablearchive -- ""})
%define staticlibsportablearchive() %{expand:%{staticlibsportablenameimpl -- %%{1}}.tar.xz}
%define staticlibsportablearchive_for_files() %(echo %{staticlibsportablearchive -- ""})
%define jreportablename() %{expand:%{jreportablenameimpl -- %%{1}}}
%define jdkportablename() %{expand:%{jdkportablenameimpl -- %%{1}}}
# Intentionally use jdkportablenameimpl here since we want to have static-libs files overlayed on
# top of the JDK archive
# We intentionally use jdkportablenameimpl here since we want to have
# static-libs files overlayed on top of the JDK archive
%define staticlibsportablename() %{expand:%{jdkportablenameimpl -- %%{1}}}
%define docportablename() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable.docs;g")
# These macros are not parameterised as the same is shared by all builds
%define docportablename() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable.docs;g")
%define docportablearchive() %{docportablename}.tar.xz
%define miscportablename() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}\\(_[0-9]\\)*;portable.misc;g")
%define miscportablename() %(echo %{uniquesuffix ""} | sed "s;el%{rhel}[^.]*;portable.misc;g")
%define miscportablearchive() %{miscportablename}.tar.xz
# JDK to use for bootstrapping
@ -474,26 +501,6 @@
%global build_hotspot_first 0
%endif
#################################################################
# fix for https://bugzilla.redhat.com/show_bug.cgi?id=1111349
# https://bugzilla.redhat.com/show_bug.cgi?id=1590796#c14
# https://bugzilla.redhat.com/show_bug.cgi?id=1655938
%global _privatelibs libsplashscreen[.]so.*|libawt_xawt[.]so.*|libjli[.]so.*|libattach[.]so.*|libawt[.]so.*|libextnet[.]so.*|libawt_headless[.]so.*|libdt_socket[.]so.*|libfontmanager[.]so.*|libinstrument[.]so.*|libj2gss[.]so.*|libj2pcsc[.]so.*|libj2pkcs11[.]so.*|libjaas[.]so.*|libjavajpeg[.]so.*|libjdwp[.]so.*|libjimage[.]so.*|libjsound[.]so.*|liblcms[.]so.*|libmanagement[.]so.*|libmanagement_agent[.]so.*|libmanagement_ext[.]so.*|libmlib_image[.]so.*|libnet[.]so.*|libnio[.]so.*|libprefs[.]so.*|librmi[.]so.*|libsaproc[.]so.*|libsctp[.]so.*|libsystemconf[.]so.*|libzip[.]so.*%{freetype_lib}
%global _publiclibs libjawt[.]so.*|libjava[.]so.*|libjvm[.]so.*|libverify[.]so.*|libjsig[.]so.*
%if %is_system_jdk
%global __provides_exclude ^(%{_privatelibs})$
%global __requires_exclude ^(%{_privatelibs})$
# Never generate lib-style provides/requires for slowdebug packages
%global __provides_exclude_from ^.*/%{uniquesuffix -- %{debug_suffix_unquoted}}/.*$
%global __requires_exclude_from ^.*/%{uniquesuffix -- %{debug_suffix_unquoted}}/.*$
%global __provides_exclude_from ^.*/%{uniquesuffix -- %{fastdebug_suffix_unquoted}}/.*$
%global __requires_exclude_from ^.*/%{uniquesuffix -- %{fastdebug_suffix_unquoted}}/.*$
%else
# Don't generate provides/requires for JDK provided shared libraries at all.
%global __provides_exclude ^(%{_privatelibs}|%{_publiclibs})$
%global __requires_exclude ^(%{_privatelibs}|%{_publiclibs})$
%endif
# VM variant being built
%ifarch %{zero_arches}
%global vm_variant zero
@ -501,28 +508,11 @@
%global vm_variant server
%endif
%global etcjavasubdir %{_sysconfdir}/java/java-%{javaver}-%{origin}
%define etcjavadir() %{expand:%{etcjavasubdir}/%{uniquesuffix -- %{?1}}}
# Standard JPackage directories and symbolic links.
%define sdkdir() %{expand:%{uniquesuffix -- %{?1}}}
%define jrelnk() %{expand:jre-%{javaver}-%{origin}-%{version}-%{release}.%{_arch}%{?1}}
%define sdkbindir() %{expand:%{_jvmdir}/%{sdkdir -- %{?1}}/bin}
%define jrebindir() %{expand:%{_jvmdir}/%{sdkdir -- %{?1}}/bin}
%global alt_java_name alt-java
%global devkit_name %{origin}-devkit
%global rpm_state_dir %{_localstatedir}/lib/rpm-state/
# For flatpack builds hard-code /usr/sbin/alternatives,
# otherwise use %%{_sbindir} relative path.
%if 0%{?flatpak}
%global alternatives_requires /usr/sbin/alternatives
%else
%global alternatives_requires %{_sbindir}/alternatives
%endif
# Portables have no repo (requires/provides), but these are awesome for orientation in spec
# Also scriptlets are happily missing and files are handled old fashion
# not-duplicated requires/provides/obsoletes for normal/debug packages
@ -547,11 +537,6 @@
# Prevent brp-java-repack-jars from being run
%global __jar_repack 0
# Define an optional suffix for the OS this package is built on
%if 0%{?rhel} == 7
%global pkgos rhel7
%endif
# Define the architectures on which we build
# On RHEL, this should be the architectures with a devkit
%if 0%{?centos} == 0
@ -560,43 +545,6 @@ ExclusiveArch: %{devkit_arches}
ExclusiveArch: %{aarch64} %{ppc64le} s390x x86_64 riscv64
%endif
Name: java-%{javaver}-%{origin}-portable%{?pkgos:-%{pkgos}}
Version: %{newjavaver}.%{buildver}
Release: %{?eaprefix}%{rpmrelease}%{?extraver}%{?dist}
# java-1.5.0-ibm from jpackage.org set Epoch to 1 for unknown reasons
# and this change was brought into RHEL-4. java-1.5.0-ibm packages
# also included the epoch in their virtual provides. This created a
# situation where in-the-wild java-1.5.0-ibm packages provided "java =
# 1:1.5.0". In RPM terms, "1.6.0 < 1:1.5.0" since 1.6.0 is
# interpreted as 0:1.6.0. So the "java >= 1.6.0" requirement would be
# satisfied by the 1:1.5.0 packages. Thus we need to set the epoch in
# JDK package >= 1.6.0 to 1, and packages referring to JDK virtual
# provides >= 1.6.0 must specify the epoch, "java >= 1:1.6.0".
Epoch: 1
Summary: %{origin_nice} %{featurever} Runtime Environment portable edition
# Groups are only used up to RHEL 8 and on Fedora versions prior to F30
%if (0%{?rhel} > 0 && 0%{?rhel} <= 8) || (0%{?fedora} >= 0 && 0%{?fedora} < 30)
Group: Development/Languages
%endif
# HotSpot code is licensed under GPLv2
# JDK library code is licensed under GPLv2 with the Classpath exception
# The Apache license is used in code taken from Apache projects (primarily xalan & xerces)
# DOM levels 2 & 3 and the XML digital signature schemas are licensed under the W3C Software License
# The JSR166 concurrency code is in the public domain
# The BSD and MIT licenses are used for a number of third-party libraries (see ADDITIONAL_LICENSE_INFO)
# The OpenJDK source tree includes:
# - JPEG library (IJG), zlib & libpng (zlib), giflib (MIT), harfbuzz (ISC),
# - freetype (FTL), jline (BSD) and LCMS (MIT)
# - jquery (MIT), jdk.crypto.cryptoki PKCS 11 wrapper (RSA)
# - public_suffix_list.dat from publicsuffix.org (MPLv2.0)
# The test code includes copies of NSS under the Mozilla Public License v2.0
# The PCSClite headers are under a BSD with advertising license
# The elliptic curve cryptography (ECC) source code is licensed under the LGPLv2.1 or any later version
License: ASL 1.1 and ASL 2.0 and BSD and BSD with advertising and GPL+ and GPLv2 and GPLv2 with exceptions and IJG and LGPLv2+ and MIT and MPLv2.0 and Public Domain and W3C and zlib and ISC and FTL and RSA
URL: http://openjdk.java.net/
# The source tarball, generated using generate_source_tarball.sh
Source0: https://openjdk-sources.osci.io/openjdk%{featurever}/open%{vcstag}%{ea_designator_zip}.tar.xz
@ -638,43 +586,18 @@ Source18: TestTranslations.java
# RPM/distribution specific patches
#
############################################
# Crypto policy and FIPS support patches
# Patch is generated from the fips-25u tree at https://github.com/rh-openjdk/jdk/tree/fips-25u
# as follows: git diff %%{vcstag} src make test > fips-21u-$(git show -s --format=%h HEAD).patch
# as follows: git diff <vcstag> src make test > fips-25u-$(git show -s --format=%h HEAD).patch
# Diff is limited to src and make subdirectories to exclude .github changes
# Fixes currently included:
# PR3183, RH1340845: Follow system wide crypto policy
# PR3695: Allow use of system crypto policy to be disabled by the user
# RH1655466: Support RHEL FIPS mode using SunPKCS11 provider
# RH1818909: No ciphersuites availale for SSLSocket in FIPS mode
# RH1860986: Disable TLSv1.3 with the NSS-FIPS provider until PKCS#11 v3.0 support is available
# RH1915071: Always initialise JavaSecuritySystemConfiguratorAccess
# RH1929465: Improve system FIPS detection
# RH1995150: Disable non-FIPS crypto in SUN and SunEC security providers
# RH1996182: Login to the NSS software token in FIPS mode
# RH1991003: Allow plain key import unless com.redhat.fips.plainKeySupport is set to false
# RH2021263: Resolve outstanding FIPS issues
# RH2052819: Fix FIPS reliance on crypto policies
# RH2052829: Detect NSS at Runtime for FIPS detection
# RH2052070: Enable AlgorithmParameters and AlgorithmParameterGenerator services in FIPS mode
# RH2023467: Enable FIPS keys export
# RH2094027: SunEC runtime permission for FIPS
# RH2036462: sun.security.pkcs11.wrapper.PKCS11.getInstance breakage
# RH2090378: Revert to disabling system security properties and FIPS mode support together
# RH2104724: Avoid import/export of DH private keys
# RH2092507: P11Key.getEncoded does not work for DH keys in FIPS mode
# Build the systemconf library on all platforms
# RH2048582: Support PKCS#12 keystores [now part of JDK-8301553 upstream]
# RH2020290: Support TLS 1.3 in FIPS mode
# Add nss.fips.cfg support to OpenJDK tree
# RH2117972: Extend the support for NSS DBs (PKCS11) in FIPS mode
# Remove forgotten dead code from RH2020290 and RH2104724
# OJ1357: Fix issue on FIPS with a SecurityManager in place
# RH2134669: Add missing attributes when registering services in FIPS mode.
# test/jdk/sun/security/pkcs11/fips/VerifyMissingAttributes.java: fixed jtreg main class
# RH1940064: Enable XML Signature provider in FIPS mode
# RH2173781: Avoid calling C_GetInfo() too early, before cryptoki is initialized [now part of JDK-8301553 upstream]
# Disabled until 25: Patch1001: fips-%{featurever}u-%{fipsver}.patch
# OPENJDK-2108: Internal __redhat_fips__ property
# OPENJDK-2123: Algorithms lockdown
# OPENJDK-4559: Red Hat Build of OpenJDK 25 should not restrict all the providers in FIPS
Patch1001: fips-%{featurever}u-%{fipsver}.patch
#############################################
#
@ -690,7 +613,12 @@ Source18: TestTranslations.java
#
#############################################
# Currently empty
# JDK-8375294: (fs) Files.copy can fail with EOPNOTSUPP when copy_file_range not supported
Patch2001: jdk8375294-handle-EOPNOTSUPP-in-copying.patch
# JDK-8347901: C2 should remove unused leaf / pure runtime calls
Patch2002: jdk8347901-c2_unused_leaf_removal.patch
# JDK-83787313: C2: performance regression due to missing constant folding for Math.pow()
Patch2003: jdk8378713-c2_missing_pow_constant_folding.patch
#############################################
#
@ -773,19 +701,19 @@ BuildRequires: libpng-devel
BuildRequires: zlib-devel
%else
# Version in src/java.desktop/share/legal/freetype.md
Provides: bundled(freetype) = 2.13.3
Provides: bundled(freetype) = 2.14.2
# Version in src/java.desktop/share/native/libsplashscreen/giflib/gif_lib.h
Provides: bundled(giflib) = 5.2.2
Provides: bundled(giflib) = 6.1.2
# Version in src/java.desktop/share/native/libharfbuzz/hb-version.h
Provides: bundled(harfbuzz) = 10.4.0
Provides: bundled(harfbuzz) = 12.3.2
# Version in src/java.desktop/share/native/liblcms/lcms2.h
Provides: bundled(lcms2) = 2.17.0
# Version in src/java.desktop/share/native/libjavajpeg/jpeglib.h
Provides: bundled(libjpeg) = 6b
# Version in src/java.desktop/share/native/libsplashscreen/libpng/png.h
Provides: bundled(libpng) = 1.6.47
Provides: bundled(libpng) = 1.6.57
# Version in src/java.base/share/native/libzip/zlib/zlib.h
Provides: bundled(zlib) = 1.3.1
Provides: bundled(zlib) = 1.3.2
# We link statically against libstdc++ to increase portability
%ifnarch %{devkit_arches}
BuildRequires: libstdc++-static
@ -974,11 +902,6 @@ fi
export XZ_OPT="-T0"
%setup -q -c -n %{uniquesuffix ""} -T -a 0
# https://bugzilla.redhat.com/show_bug.cgi?id=1189084
prioritylength=`expr length %{priority}`
if [ $prioritylength -ne 8 ] ; then
echo "priority must be 8 digits in total, violated"
exit 14
fi
# OpenJDK patches
@ -988,23 +911,15 @@ sh %{SOURCE12} %{top_level_dir_name}
%endif
# Patch the JDK
# This syntax is deprecated:
# %patchN [...]
# and should be replaced with:
# %patch -PN [...]
# For example:
# %patch1001 -p1
# becomes:
# %patch -P1001 -p1
# The replacement format suggested by recent (circa Fedora 38) RPM
# deprecation messages:
# %patch N [...]
# is not backward-compatible with prior (circa RHEL-8) versions of
# rpmbuild.
pushd %{top_level_dir_name}
# Add crypto policy and FIPS support
# Disabled until 25
#%patch -P1001 -p1
%patch -P1001 -p1
# Add EOPNOTSUPP patch
%patch -P2001 -p1
# Add C2 patches
%patch -P2002 -p1
%patch -P2003 -p1
popd # openjdk
echo "Generating %{alt_java_name} man page"
@ -1088,7 +1003,6 @@ cat %{bootjdk}/release
export NUM_PROC=%(/usr/bin/getconf _NPROCESSORS_ONLN 2> /dev/null || :)
export NUM_PROC=${NUM_PROC:-1}
%if 0%{?_smp_ncpus_max}
# Honor %%_smp_ncpus_max
[ ${NUM_PROC} -gt %{?_smp_ncpus_max} ] && export NUM_PROC=%{?_smp_ncpus_max}
%endif
export XZ_OPT="-T0"
@ -1208,8 +1122,8 @@ function buildjdk() {
mkdir -p ${outputdir}
pushd ${outputdir}
# Note: zlib and freetype use %{link_type}
# rather than ${link_opt} as the system versions
# Note: zlib and freetype use link_type (macro)
# rather than link_opt (shell var) as the system versions
# are always used in a system_libs build, even
# for the static library build
LD_LIBRARY_PATH=${LIBPATH} \
@ -1724,6 +1638,11 @@ $JAVA_HOME/bin/java -XX:+UnlockExperimentalVMOptions -XX:+UseShenandoahGC -versi
$JAVA_HOME/bin/java -Djava.locale.providers=CLDR $(echo $(basename %{SOURCE18})|sed "s|\.java||") CLDR
%endif
# Check blocked.certs is valid (OPENJDK-4362)
jtreg_test=$(pwd)/%{top_level_dir_name}/test/jdk/sun/security/lib/CheckBlockedCerts.java
jtreg_dir=$(dirname ${jtreg_test})
$JAVA_HOME/bin/java --add-exports java.base/sun.security.util=ALL-UNNAMED -Dtest.src=${jtreg_dir} ${jtreg_test}
# Check src.zip has all sources. See RHBZ#1130490
unzip -l $JAVA_HOME/lib/src.zip | grep 'sun.misc.Unsafe'
@ -1895,8 +1814,8 @@ done
%files
# main package builds always
%{_jvmdir}/%{jreportablearchive -- %%{nil}}
%{_jvmdir}/%{jreportablearchive -- %%{nil}}.sha256sum
%{_jvmdir}/%{jreportablearchive_for_files}
%{_jvmdir}/%{jreportablearchive_for_files}.sha256sum
%else
%files
# placeholder
@ -1905,15 +1824,15 @@ done
%if %{include_normal_build}
%files devel
%{_jvmdir}/%{jdkportablearchive -- %%{nil}}
%{_jvmdir}/%{jdkportablearchive_for_files}
%{_jvmdir}/%{jdkportablearchive -- .debuginfo}
%{_jvmdir}/%{jdkportablearchive -- %%{nil}}.sha256sum
%{_jvmdir}/%{jdkportablearchive_for_files}.sha256sum
%{_jvmdir}/%{jdkportablearchive -- .debuginfo}.sha256sum
%if %{include_staticlibs}
%files static-libs
%{_jvmdir}/%{staticlibsportablearchive -- %%{nil}}
%{_jvmdir}/%{staticlibsportablearchive -- %%{nil}}.sha256sum
%{_jvmdir}/%{staticlibsportablearchive_for_files}
%{_jvmdir}/%{staticlibsportablearchive_for_files}.sha256sum
%endif
%files unstripped
@ -1967,6 +1886,89 @@ done
%endif
%changelog
* Thu Jul 16 2026 Andrew Lukoshko <alukoshko@almalinux.org> - 1:25.0.3.0.9-3.0
- Portable build
* Mon Jul 13 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.3.0.9-3.0
- Add 25u backports of JDK-8347901 & JDK-8378713 C2 performance fixes
- Resolves: OPENJDK-4885
* Thu Jul 02 2026 Andrea Bolognani <abologna@redhat.com> - 1:25.0.3.0.9-3.0
- Strip %%{dist} more thoroughly
- Resolves: OPENJDK-4881
* Fri Jun 26 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.3.0.9-2.0
- Port ForFiles patch to RHEL and update to use standard function naming format
- Remove macro references in comments where possible (%dnl not compatible enough yet)
- Drop unused tagsuffix line which causes issues on older RPM versions without %dnl
- Cleanup RPM only macros unused in the portable spec file
- Move version information and core NVR definitions back towards the top of the file
- Specify portablerelease and rpmrelease (always 0 for portables) in the Release field
- Related: OPENJDK-4872
- Resolves: OPENJDK-4873
- Resolves: OPENJDK-4875
- Resolves: OPENJDK-4876
* Fri Jun 26 2026 Jiri Vanek <jvanek@redhat.com> - 1:25.0.3.0.9-2
- Redeclared ForFiles release sections as %%nil no longer works with %%1
- RPM 4.19 no longer accept our double percentaged %%{nil} passed to %%{1}
- so we have to pass in "" but evaluate it, otherwise files record will include it
- Resolves: OPENJDK-4872
* Sat Apr 18 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.3.0.9-1
- Update to jdk-25.0.3+9 (GA)
- Update release notes to 25.0.3+9
- Update FIPS patch to 57722aab802 version synced with 25.0.3+8
- Drop local libpng patches now JDK-8372534, JDK-8375063 & JDK-8377526 are included upstream
- Drop local HarfBuzz patch now JDK-8375057 is included upstream
- Bump freetype version to 2.14.2 following JDK-8373290 & JDK-8379158
- Bump giflib version to 6.1.2 following JDK-8379256 & JDK-8380078
- Bump libpng version to 1.6.57 following JDK-8380959 & JDK-8382047
- Bump zlib version to 1.3.2 following JDK-8378631
- Add JDK-8375294 EOPNOTSUPP patch ahead of 25.0.4
- ** This tarball is embargoed until 2026-04-21 @ 1pm PT. **
- Resolves: OPENJDK-4634
- Resolves: OPENJDK-4656
- Resolves: OPENJDK-4607
- Resolves: OPENJDK-4675
* Tue Mar 03 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.2.0.10-3
- Update FIPS patch to e55ada9353e to include the fix for the too restrictive provider lockdown
- Fix FIPS issue list to represent the new 25u version
- Add JDK-8375063 libpng 1.6.54 ahead of 25.0.3
- Add JDK-8375057 harfbuzz 12.3.2 ahead of 25.0.3
- Add JDK-8377526 libpng 1.6.55 ahead of 25.0.3
- Bump libpng version to 1.6.55 following JDK-8375063 & JDK-8377526
- Bump harfbuzz version to 12.3.2 following JDK-8375057
- Resolves: OPENJDK-4570
- Resolves: OPENJDK-4304
- Resolves: OPENJDK-4524
- Resolves: OPENJDK-4544
- Resolves: OPENJDK-4553
* Mon Jan 12 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.2.0.10-2
- Add JDK-8372534 libpng 1.6.51 ahead of 25.0.3
- Bump libpng version to 1.6.51 following JDK-8372534
- Add CVEs for 25.0.2 to NEWS
- Correct version and date for this upcoming release in NEWS
- Related: OPENJDK-4359
* Mon Jan 12 2026 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.2.0.10-1
- Update to jdk-25.0.2+10 (GA)
- Update release notes to 25.0.2+10
- Add test to ensure blocked.certs is valid (OPENJDK-4362)
- ** This tarball is embargoed until 2026-01-20 @ 1pm PT. **
- Resolves: OPENJDK-4359
- Resolves: OPENJDK-4362
* Tue Dec 02 2025 Severin Gehwolf <sgehwolf@redhat.com> - 1:25.0.1.0.8-2
- Switch from static-libs-image to static-libs-graal-image to avoid large unneeded libjvm.a
- Resolves: OPENJDK-4197
* Tue Dec 02 2025 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.1.0.8-2
- Incorporate new FIPS patch for 25u
- Resolves: OPENJDK-4184
* Mon Nov 10 2025 Andrew Hughes <gnu.andrew@redhat.com> - 1:25.0.1.0.8-1
- Update to jdk-25.0.1+8 (GA)
- Update release notes to 25.0.1+8

File diff suppressed because it is too large Load Diff

1
java-25-openjdk.spec Symbolic link
View File

@ -0,0 +1 @@
java-25-openjdk-portable.specfile

View File

@ -0,0 +1,772 @@
From 09853461a6896ab1f15469c753c21ca212e7e650 Mon Sep 17 00:00:00 2001
From: duke <duke@openjdk.org>
Date: Tue, 7 Apr 2026 15:14:53 +0000
Subject: [PATCH 1/2] Backport ed70910b0f3e1b19d915ec13ac3434407d01bc5d
---
src/hotspot/share/opto/callnode.cpp | 53 +++++++-
src/hotspot/share/opto/callnode.hpp | 29 ++++-
src/hotspot/share/opto/classes.hpp | 2 +
src/hotspot/share/opto/compile.cpp | 19 +++
src/hotspot/share/opto/divnode.cpp | 158 ++++++++++--------------
src/hotspot/share/opto/divnode.hpp | 35 +++---
src/hotspot/share/opto/graphKit.cpp | 29 +++--
src/hotspot/share/opto/graphKit.hpp | 1 +
src/hotspot/share/opto/library_call.cpp | 2 +-
src/hotspot/share/opto/macro.cpp | 15 +--
src/hotspot/share/opto/multnode.cpp | 13 ++
src/hotspot/share/opto/multnode.hpp | 46 +++++++
src/hotspot/share/opto/node.cpp | 12 +-
src/hotspot/share/opto/node.hpp | 5 +-
src/hotspot/share/opto/parse2.cpp | 8 +-
15 files changed, 282 insertions(+), 145 deletions(-)
diff --git a/src/hotspot/share/opto/callnode.cpp b/src/hotspot/share/opto/callnode.cpp
index 6f13ce0f809..fc4b0c35dff 100644
--- a/src/hotspot/share/opto/callnode.cpp
+++ b/src/hotspot/share/opto/callnode.cpp
@@ -935,7 +935,7 @@ Node *CallNode::result_cast() {
}
-void CallNode::extract_projections(CallProjections* projs, bool separate_io_proj, bool do_asserts) {
+void CallNode::extract_projections(CallProjections* projs, bool separate_io_proj, bool do_asserts) const {
projs->fallthrough_proj = nullptr;
projs->fallthrough_catchproj = nullptr;
projs->fallthrough_ioproj = nullptr;
@@ -1319,6 +1319,57 @@ void CallLeafVectorNode::calling_convention( BasicType* sig_bt, VMRegPair *parm_
//=============================================================================
+bool CallLeafPureNode::is_unused() const {
+ return proj_out_or_null(TypeFunc::Parms) == nullptr;
+}
+
+bool CallLeafPureNode::is_dead() const {
+ return proj_out_or_null(TypeFunc::Control) == nullptr;
+}
+
+/* We make a tuple of the global input state + TOP for the output values.
+ * We use this to delete a pure function that is not used: by replacing the call with
+ * such a tuple, we let output Proj's idealization pick the corresponding input of the
+ * pure call, so jumping over it, and effectively, removing the call from the graph.
+ * This avoids doing the graph surgery manually, but leaves that to IGVN
+ * that is specialized for doing that right. We need also tuple components for output
+ * values of the function to respect the return arity, and in case there is a projection
+ * that would pick an output (which shouldn't happen at the moment).
+ */
+TupleNode* CallLeafPureNode::make_tuple_of_input_state_and_top_return_values(const Compile* C) const {
+ // Transparently propagate input state but parameters
+ TupleNode* tuple = TupleNode::make(
+ tf()->range(),
+ in(TypeFunc::Control),
+ in(TypeFunc::I_O),
+ in(TypeFunc::Memory),
+ in(TypeFunc::FramePtr),
+ in(TypeFunc::ReturnAdr));
+
+ // And add TOPs for the return values
+ for (uint i = TypeFunc::Parms; i < tf()->range()->cnt(); i++) {
+ tuple->set_req(i, C->top());
+ }
+
+ return tuple;
+}
+
+Node* CallLeafPureNode::Ideal(PhaseGVN* phase, bool can_reshape) {
+ if (is_dead()) {
+ return nullptr;
+ }
+
+ // We need to wait until IGVN because during parsing, usages might still be missing
+ // and we would remove the call immediately.
+ if (can_reshape && is_unused()) {
+ // The result is not used. We remove the call by replacing it with a tuple, that
+ // is later disintegrated by the projections.
+ return make_tuple_of_input_state_and_top_return_values(phase->C);
+ }
+
+ return CallRuntimeNode::Ideal(phase, can_reshape);
+}
+
#ifndef PRODUCT
void CallLeafNode::dump_spec(outputStream *st) const {
st->print("# ");
diff --git a/src/hotspot/share/opto/callnode.hpp b/src/hotspot/share/opto/callnode.hpp
index 213fbda4e89..2462a88143f 100644
--- a/src/hotspot/share/opto/callnode.hpp
+++ b/src/hotspot/share/opto/callnode.hpp
@@ -752,7 +752,7 @@ class CallNode : public SafePointNode {
// Collect all the interesting edges from a call for use in
// replacing the call by something else. Used by macro expansion
// and the late inlining support.
- void extract_projections(CallProjections* projs, bool separate_io_proj, bool do_asserts = true);
+ void extract_projections(CallProjections* projs, bool separate_io_proj, bool do_asserts = true) const;
virtual uint match_edge(uint idx) const;
@@ -928,6 +928,33 @@ class CallLeafNode : public CallRuntimeNode {
#endif
};
+/* A pure function call, they are assumed not to be safepoints, not to read or write memory,
+ * have no exception... They just take parameters, return a value without side effect. It is
+ * always correct to create some, or remove them, if the result is not used.
+ *
+ * They still have control input to allow easy lowering into other kind of calls that require
+ * a control, but this is more a technical than a moral constraint.
+ *
+ * Pure calls must have only control and data input and output: I/O, Memory and so on must be top.
+ * Nevertheless, pure calls can typically be expensive math operations so care must be taken
+ * when letting the node float.
+ */
+class CallLeafPureNode : public CallLeafNode {
+protected:
+ bool is_unused() const;
+ bool is_dead() const;
+ TupleNode* make_tuple_of_input_state_and_top_return_values(const Compile* C) const;
+
+public:
+ CallLeafPureNode(const TypeFunc* tf, address addr, const char* name,
+ const TypePtr* adr_type)
+ : CallLeafNode(tf, addr, name, adr_type) {
+ init_class_id(Class_CallLeafPure);
+ }
+ int Opcode() const override;
+ Node* Ideal(PhaseGVN* phase, bool can_reshape) override;
+};
+
//------------------------------CallLeafNoFPNode-------------------------------
// CallLeafNode, not using floating point or using it in the same manner as
// the generated code
diff --git a/src/hotspot/share/opto/classes.hpp b/src/hotspot/share/opto/classes.hpp
index bc259eed2d1..587d5fad8f2 100644
--- a/src/hotspot/share/opto/classes.hpp
+++ b/src/hotspot/share/opto/classes.hpp
@@ -61,6 +61,7 @@ macro(CallDynamicJava)
macro(CallJava)
macro(CallLeaf)
macro(CallLeafNoFP)
+macro(CallLeafPure)
macro(CallLeafVector)
macro(CallRuntime)
macro(CallStaticJava)
@@ -372,6 +373,7 @@ macro(SubI)
macro(SubL)
macro(TailCall)
macro(TailJump)
+macro(Tuple)
macro(MacroLogicV)
macro(ThreadLocal)
macro(Unlock)
diff --git a/src/hotspot/share/opto/compile.cpp b/src/hotspot/share/opto/compile.cpp
index 2b956dcb5d8..9f7f48b9a34 100644
--- a/src/hotspot/share/opto/compile.cpp
+++ b/src/hotspot/share/opto/compile.cpp
@@ -3298,6 +3298,25 @@ void Compile::final_graph_reshaping_main_switch(Node* n, Final_Reshape_Counts& f
case Op_Opaque1: // Remove Opaque Nodes before matching
n->subsume_by(n->in(1), this);
break;
+ case Op_CallLeafPure: {
+ // If the pure call is not supported, then lower to a CallLeaf.
+ if (!Matcher::match_rule_supported(Op_CallLeafPure)) {
+ CallNode* call = n->as_Call();
+ CallNode* new_call = new CallLeafNode(call->tf(), call->entry_point(),
+ call->_name, TypeRawPtr::BOTTOM);
+ new_call->init_req(TypeFunc::Control, call->in(TypeFunc::Control));
+ new_call->init_req(TypeFunc::I_O, C->top());
+ new_call->init_req(TypeFunc::Memory, C->top());
+ new_call->init_req(TypeFunc::ReturnAdr, C->top());
+ new_call->init_req(TypeFunc::FramePtr, C->top());
+ for (unsigned int i = TypeFunc::Parms; i < call->tf()->domain()->cnt(); i++) {
+ new_call->init_req(i, call->in(i));
+ }
+ n->subsume_by(new_call, this);
+ }
+ frc.inc_call_count();
+ break;
+ }
case Op_CallStaticJava:
case Op_CallJava:
case Op_CallDynamicJava:
diff --git a/src/hotspot/share/opto/divnode.cpp b/src/hotspot/share/opto/divnode.cpp
index a70194274a7..5dd8be877ff 100644
--- a/src/hotspot/share/opto/divnode.cpp
+++ b/src/hotspot/share/opto/divnode.cpp
@@ -42,19 +42,19 @@
#include <math.h>
-ModFloatingNode::ModFloatingNode(Compile* C, const TypeFunc* tf, const char* name) : CallLeafNode(tf, nullptr, name, TypeRawPtr::BOTTOM) {
+ModFloatingNode::ModFloatingNode(Compile* C, const TypeFunc* tf, address addr, const char* name) : CallLeafPureNode(tf, addr, name, TypeRawPtr::BOTTOM) {
add_flag(Flag_is_macro);
C->add_macro_node(this);
}
-ModDNode::ModDNode(Compile* C, Node* a, Node* b) : ModFloatingNode(C, OptoRuntime::Math_DD_D_Type(), "drem") {
+ModDNode::ModDNode(Compile* C, Node* a, Node* b) : ModFloatingNode(C, OptoRuntime::Math_DD_D_Type(), CAST_FROM_FN_PTR(address, SharedRuntime::drem), "drem") {
init_req(TypeFunc::Parms + 0, a);
init_req(TypeFunc::Parms + 1, C->top());
init_req(TypeFunc::Parms + 2, b);
init_req(TypeFunc::Parms + 3, C->top());
}
-ModFNode::ModFNode(Compile* C, Node* a, Node* b) : ModFloatingNode(C, OptoRuntime::modf_Type(), "frem") {
+ModFNode::ModFNode(Compile* C, Node* a, Node* b) : ModFloatingNode(C, OptoRuntime::modf_Type(), CAST_FROM_FN_PTR(address, SharedRuntime::frem), "frem") {
init_req(TypeFunc::Parms + 0, a);
init_req(TypeFunc::Parms + 1, b);
}
@@ -1516,137 +1516,109 @@ const Type* UModLNode::Value(PhaseGVN* phase) const {
return unsigned_mod_value<TypeLong, julong, jlong>(phase, this);
}
-Node* ModFNode::Ideal(PhaseGVN* phase, bool can_reshape) {
- if (!can_reshape) {
- return nullptr;
- }
- PhaseIterGVN* igvn = phase->is_IterGVN();
-
- bool result_is_unused = proj_out_or_null(TypeFunc::Parms) == nullptr;
- bool not_dead = proj_out_or_null(TypeFunc::Control) != nullptr;
- if (result_is_unused && not_dead) {
- return replace_with_con(igvn, TypeF::make(0.));
- }
-
- // Either input is TOP ==> the result is TOP
- const Type* t1 = phase->type(dividend());
- const Type* t2 = phase->type(divisor());
- if (t1 == Type::TOP || t2 == Type::TOP) {
- return phase->C->top();
- }
-
+const Type* ModFNode::get_result_if_constant(const Type* dividend, const Type* divisor) const {
// If either number is not a constant, we know nothing.
- if ((t1->base() != Type::FloatCon) || (t2->base() != Type::FloatCon)) {
+ if ((dividend->base() != Type::FloatCon) || (divisor->base() != Type::FloatCon)) {
return nullptr; // note: x%x can be either NaN or 0
}
- float f1 = t1->getf();
- float f2 = t2->getf();
- jint x1 = jint_cast(f1); // note: *(int*)&f1, not just (int)f1
- jint x2 = jint_cast(f2);
+ float dividend_f = dividend->getf();
+ float divisor_f = divisor->getf();
+ jint dividend_i = jint_cast(dividend_f); // note: *(int*)&f1, not just (int)f1
+ jint divisor_i = jint_cast(divisor_f);
// If either is a NaN, return an input NaN
- if (g_isnan(f1)) {
- return replace_with_con(igvn, t1);
+ if (g_isnan(dividend_f)) {
+ return dividend;
}
- if (g_isnan(f2)) {
- return replace_with_con(igvn, t2);
+ if (g_isnan(divisor_f)) {
+ return divisor;
}
// If an operand is infinity or the divisor is +/- zero, punt.
- if (!g_isfinite(f1) || !g_isfinite(f2) || x2 == 0 || x2 == min_jint) {
+ if (!g_isfinite(dividend_f) || !g_isfinite(divisor_f) || divisor_i == 0 || divisor_i == min_jint) {
return nullptr;
}
// We must be modulo'ing 2 float constants.
// Make sure that the sign of the fmod is equal to the sign of the dividend
- jint xr = jint_cast(fmod(f1, f2));
- if ((x1 ^ xr) < 0) {
+ jint xr = jint_cast(fmod(dividend_f, divisor_f));
+ if ((dividend_i ^ xr) < 0) {
xr ^= min_jint;
}
- return replace_with_con(igvn, TypeF::make(jfloat_cast(xr)));
+ return TypeF::make(jfloat_cast(xr));
}
-Node* ModDNode::Ideal(PhaseGVN* phase, bool can_reshape) {
- if (!can_reshape) {
- return nullptr;
- }
- PhaseIterGVN* igvn = phase->is_IterGVN();
-
- bool result_is_unused = proj_out_or_null(TypeFunc::Parms) == nullptr;
- bool not_dead = proj_out_or_null(TypeFunc::Control) != nullptr;
- if (result_is_unused && not_dead) {
- return replace_with_con(igvn, TypeD::make(0.));
- }
-
- // Either input is TOP ==> the result is TOP
- const Type* t1 = phase->type(dividend());
- const Type* t2 = phase->type(divisor());
- if (t1 == Type::TOP || t2 == Type::TOP) {
- return nullptr;
- }
-
+const Type* ModDNode::get_result_if_constant(const Type* dividend, const Type* divisor) const {
// If either number is not a constant, we know nothing.
- if ((t1->base() != Type::DoubleCon) || (t2->base() != Type::DoubleCon)) {
+ if ((dividend->base() != Type::DoubleCon) || (divisor->base() != Type::DoubleCon)) {
return nullptr; // note: x%x can be either NaN or 0
}
- double f1 = t1->getd();
- double f2 = t2->getd();
- jlong x1 = jlong_cast(f1); // note: *(long*)&f1, not just (long)f1
- jlong x2 = jlong_cast(f2);
+ double dividend_d = dividend->getd();
+ double divisor_d = divisor->getd();
+ jlong dividend_l = jlong_cast(dividend_d); // note: *(long*)&f1, not just (long)f1
+ jlong divisor_l = jlong_cast(divisor_d);
// If either is a NaN, return an input NaN
- if (g_isnan(f1)) {
- return replace_with_con(igvn, t1);
+ if (g_isnan(dividend_d)) {
+ return dividend;
}
- if (g_isnan(f2)) {
- return replace_with_con(igvn, t2);
+ if (g_isnan(divisor_d)) {
+ return divisor;
}
// If an operand is infinity or the divisor is +/- zero, punt.
- if (!g_isfinite(f1) || !g_isfinite(f2) || x2 == 0 || x2 == min_jlong) {
+ if (!g_isfinite(dividend_d) || !g_isfinite(divisor_d) || divisor_l == 0 || divisor_l == min_jlong) {
return nullptr;
}
// We must be modulo'ing 2 double constants.
// Make sure that the sign of the fmod is equal to the sign of the dividend
- jlong xr = jlong_cast(fmod(f1, f2));
- if ((x1 ^ xr) < 0) {
+ jlong xr = jlong_cast(fmod(dividend_d, divisor_d));
+ if ((dividend_l ^ xr) < 0) {
xr ^= min_jlong;
}
- return replace_with_con(igvn, TypeD::make(jdouble_cast(xr)));
+ return TypeD::make(jdouble_cast(xr));
}
-Node* ModFloatingNode::replace_with_con(PhaseIterGVN* phase, const Type* con) {
- Compile* C = phase->C;
- Node* con_node = phase->makecon(con);
- CallProjections projs;
- extract_projections(&projs, false, false);
- phase->replace_node(projs.fallthrough_proj, in(TypeFunc::Control));
- if (projs.fallthrough_catchproj != nullptr) {
- phase->replace_node(projs.fallthrough_catchproj, in(TypeFunc::Control));
- }
- if (projs.fallthrough_memproj != nullptr) {
- phase->replace_node(projs.fallthrough_memproj, in(TypeFunc::Memory));
- }
- if (projs.catchall_memproj != nullptr) {
- phase->replace_node(projs.catchall_memproj, C->top());
- }
- if (projs.fallthrough_ioproj != nullptr) {
- phase->replace_node(projs.fallthrough_ioproj, in(TypeFunc::I_O));
- }
- assert(projs.catchall_ioproj == nullptr, "no exceptions from floating mod");
- assert(projs.catchall_catchproj == nullptr, "no exceptions from floating mod");
- if (projs.resproj != nullptr) {
- phase->replace_node(projs.resproj, con_node);
+Node* ModFloatingNode::Ideal(PhaseGVN* phase, bool can_reshape) {
+ if (can_reshape) {
+ PhaseIterGVN* igvn = phase->is_IterGVN();
+
+ // Either input is TOP ==> the result is TOP
+ const Type* dividend_type = phase->type(dividend());
+ const Type* divisor_type = phase->type(divisor());
+ if (dividend_type == Type::TOP || divisor_type == Type::TOP) {
+ return phase->C->top();
+ }
+ const Type* constant_result = get_result_if_constant(dividend_type, divisor_type);
+ if (constant_result != nullptr) {
+ return make_tuple_of_input_state_and_constant_result(igvn, constant_result);
+ }
}
- phase->replace_node(this, C->top());
- C->remove_macro_node(this);
- disconnect_inputs(C);
- return nullptr;
+
+ return CallLeafPureNode::Ideal(phase, can_reshape);
+}
+
+/* Give a tuple node for ::Ideal to return, made of the input state (control to return addr)
+ * and the given constant result. Idealization of projections will make sure to transparently
+ * propagate the input state and replace the result by the said constant.
+ */
+TupleNode* ModFloatingNode::make_tuple_of_input_state_and_constant_result(PhaseIterGVN* phase, const Type* con) const {
+ Node* con_node = phase->makecon(con);
+ TupleNode* tuple = TupleNode::make(
+ tf()->range(),
+ in(TypeFunc::Control),
+ in(TypeFunc::I_O),
+ in(TypeFunc::Memory),
+ in(TypeFunc::FramePtr),
+ in(TypeFunc::ReturnAdr),
+ con_node);
+
+ return tuple;
}
//=============================================================================
diff --git a/src/hotspot/share/opto/divnode.hpp b/src/hotspot/share/opto/divnode.hpp
index 127e2431b0b..b13460c89f5 100644
--- a/src/hotspot/share/opto/divnode.hpp
+++ b/src/hotspot/share/opto/divnode.hpp
@@ -156,40 +156,45 @@ class ModLNode : public Node {
};
// Base class for float and double modulus
-class ModFloatingNode : public CallLeafNode {
+class ModFloatingNode : public CallLeafPureNode {
+ TupleNode* make_tuple_of_input_state_and_constant_result(PhaseIterGVN* phase, const Type* con) const;
+
protected:
- Node* replace_with_con(PhaseIterGVN* phase, const Type* con);
+ virtual Node* dividend() const = 0;
+ virtual Node* divisor() const = 0;
+ virtual const Type* get_result_if_constant(const Type* dividend, const Type* divisor) const = 0;
public:
- ModFloatingNode(Compile* C, const TypeFunc* tf, const char *name);
+ ModFloatingNode(Compile* C, const TypeFunc* tf, address addr, const char* name);
+ Node* Ideal(PhaseGVN* phase, bool can_reshape) override;
};
// Float Modulus
class ModFNode : public ModFloatingNode {
private:
- Node* dividend() const { return in(TypeFunc::Parms + 0); }
- Node* divisor() const { return in(TypeFunc::Parms + 1); }
+ Node* dividend() const override { return in(TypeFunc::Parms + 0); }
+ Node* divisor() const override { return in(TypeFunc::Parms + 1); }
+ const Type* get_result_if_constant(const Type* dividend, const Type* divisor) const override;
public:
ModFNode(Compile* C, Node* a, Node* b);
- virtual int Opcode() const;
- virtual uint ideal_reg() const { return Op_RegF; }
- virtual uint size_of() const { return sizeof(*this); }
- virtual Node* Ideal(PhaseGVN* phase, bool can_reshape);
+ int Opcode() const override;
+ uint ideal_reg() const override { return Op_RegF; }
+ uint size_of() const override { return sizeof(*this); }
};
// Double Modulus
class ModDNode : public ModFloatingNode {
private:
- Node* dividend() const { return in(TypeFunc::Parms + 0); }
- Node* divisor() const { return in(TypeFunc::Parms + 2); }
+ Node* dividend() const override { return in(TypeFunc::Parms + 0); }
+ Node* divisor() const override { return in(TypeFunc::Parms + 2); }
+ const Type* get_result_if_constant(const Type* dividend, const Type* divisor) const override;
public:
ModDNode(Compile* C, Node* a, Node* b);
- virtual int Opcode() const;
- virtual uint ideal_reg() const { return Op_RegD; }
- virtual uint size_of() const { return sizeof(*this); }
- virtual Node* Ideal(PhaseGVN* phase, bool can_reshape);
+ int Opcode() const override;
+ uint ideal_reg() const override { return Op_RegD; }
+ uint size_of() const override { return sizeof(*this); }
};
//------------------------------UModINode---------------------------------------
diff --git a/src/hotspot/share/opto/graphKit.cpp b/src/hotspot/share/opto/graphKit.cpp
index 20feca26ede..1b8b7008578 100644
--- a/src/hotspot/share/opto/graphKit.cpp
+++ b/src/hotspot/share/opto/graphKit.cpp
@@ -1880,14 +1880,20 @@ Node* GraphKit::set_results_for_java_call(CallJavaNode* call, bool separate_io_p
// after the call, if this call has restricted memory effects.
Node* GraphKit::set_predefined_input_for_runtime_call(SafePointNode* call, Node* narrow_mem) {
// Set fixed predefined input arguments
- Node* memory = reset_memory();
- Node* m = narrow_mem == nullptr ? memory : narrow_mem;
- call->init_req( TypeFunc::Control, control() );
- call->init_req( TypeFunc::I_O, top() ); // does no i/o
- call->init_req( TypeFunc::Memory, m ); // may gc ptrs
- call->init_req( TypeFunc::FramePtr, frameptr() );
- call->init_req( TypeFunc::ReturnAdr, top() );
- return memory;
+ call->init_req(TypeFunc::Control, control());
+ call->init_req(TypeFunc::I_O, top()); // does no i/o
+ call->init_req(TypeFunc::ReturnAdr, top());
+ if (call->is_CallLeafPure()) {
+ call->init_req(TypeFunc::Memory, top());
+ call->init_req(TypeFunc::FramePtr, top());
+ return nullptr;
+ } else {
+ Node* memory = reset_memory();
+ Node* m = narrow_mem == nullptr ? memory : narrow_mem;
+ call->init_req(TypeFunc::Memory, m); // may gc ptrs
+ call->init_req(TypeFunc::FramePtr, frameptr());
+ return memory;
+ }
}
//-------------------set_predefined_output_for_runtime_call--------------------
@@ -1905,6 +1911,11 @@ void GraphKit::set_predefined_output_for_runtime_call(Node* call,
const TypePtr* hook_mem) {
// no i/o
set_control(_gvn.transform( new ProjNode(call,TypeFunc::Control) ));
+ if (call->is_CallLeafPure()) {
+ // Pure function have only control (for now) and data output, in particular
+ // they don't touch the memory, so we don't want a memory proj that is set after.
+ return;
+ }
if (keep_mem) {
// First clone the existing memory state
set_all_memory(keep_mem);
@@ -2491,6 +2502,8 @@ Node* GraphKit::make_runtime_call(int flags,
} else if (flags & RC_VECTOR){
uint num_bits = call_type->range()->field_at(TypeFunc::Parms)->is_vect()->length_in_bytes() * BitsPerByte;
call = new CallLeafVectorNode(call_type, call_addr, call_name, adr_type, num_bits);
+ } else if (flags & RC_PURE) {
+ call = new CallLeafPureNode(call_type, call_addr, call_name, adr_type);
} else {
call = new CallLeafNode(call_type, call_addr, call_name, adr_type);
}
diff --git a/src/hotspot/share/opto/graphKit.hpp b/src/hotspot/share/opto/graphKit.hpp
index 28773d75333..806a211d7e2 100644
--- a/src/hotspot/share/opto/graphKit.hpp
+++ b/src/hotspot/share/opto/graphKit.hpp
@@ -784,6 +784,7 @@ class GraphKit : public Phase {
RC_NARROW_MEM = 16, // input memory is same as output
RC_UNCOMMON = 32, // freq. expected to be like uncommon trap
RC_VECTOR = 64, // CallLeafVectorNode
+ RC_PURE = 128, // CallLeaf is pure
RC_LEAF = 0 // null value: no flags set
};
diff --git a/src/hotspot/share/opto/library_call.cpp b/src/hotspot/share/opto/library_call.cpp
index f74af38387c..12960d101a8 100644
--- a/src/hotspot/share/opto/library_call.cpp
+++ b/src/hotspot/share/opto/library_call.cpp
@@ -1802,7 +1802,7 @@ bool LibraryCallKit::runtime_math(const TypeFunc* call_type, address funcAddr, c
Node* b = (call_type == OptoRuntime::Math_DD_D_Type()) ? argument(2) : nullptr;
const TypePtr* no_memory_effects = nullptr;
- Node* trig = make_runtime_call(RC_LEAF, call_type, funcAddr, funcName,
+ Node* trig = make_runtime_call(RC_LEAF | RC_PURE, call_type, funcAddr, funcName,
no_memory_effects,
a, top(), b, b ? top() : nullptr);
Node* value = _gvn.transform(new ProjNode(trig, TypeFunc::Parms+0));
diff --git a/src/hotspot/share/opto/macro.cpp b/src/hotspot/share/opto/macro.cpp
index acf1dbabf19..aafc5d3c170 100644
--- a/src/hotspot/share/opto/macro.cpp
+++ b/src/hotspot/share/opto/macro.cpp
@@ -2638,17 +2638,14 @@ bool PhaseMacroExpand::expand_macro_nodes() {
switch (n->Opcode()) {
case Op_ModD:
case Op_ModF: {
- bool is_drem = n->Opcode() == Op_ModD;
CallNode* mod_macro = n->as_Call();
- CallNode* call = new CallLeafNode(mod_macro->tf(),
- is_drem ? CAST_FROM_FN_PTR(address, SharedRuntime::drem)
- : CAST_FROM_FN_PTR(address, SharedRuntime::frem),
- is_drem ? "drem" : "frem", TypeRawPtr::BOTTOM);
+ CallNode* call = new CallLeafPureNode(mod_macro->tf(), mod_macro->entry_point(),
+ mod_macro->_name, TypeRawPtr::BOTTOM);
call->init_req(TypeFunc::Control, mod_macro->in(TypeFunc::Control));
- call->init_req(TypeFunc::I_O, mod_macro->in(TypeFunc::I_O));
- call->init_req(TypeFunc::Memory, mod_macro->in(TypeFunc::Memory));
- call->init_req(TypeFunc::ReturnAdr, mod_macro->in(TypeFunc::ReturnAdr));
- call->init_req(TypeFunc::FramePtr, mod_macro->in(TypeFunc::FramePtr));
+ call->init_req(TypeFunc::I_O, C->top());
+ call->init_req(TypeFunc::Memory, C->top());
+ call->init_req(TypeFunc::ReturnAdr, C->top());
+ call->init_req(TypeFunc::FramePtr, C->top());
for (unsigned int i = 0; i < mod_macro->tf()->domain()->cnt() - TypeFunc::Parms; i++) {
call->init_req(TypeFunc::Parms + i, mod_macro->in(TypeFunc::Parms + i));
}
diff --git a/src/hotspot/share/opto/multnode.cpp b/src/hotspot/share/opto/multnode.cpp
index 736e84315ee..f429d5daac0 100644
--- a/src/hotspot/share/opto/multnode.cpp
+++ b/src/hotspot/share/opto/multnode.cpp
@@ -120,6 +120,10 @@ const TypePtr *ProjNode::adr_type() const {
if (bottom_type() == Type::MEMORY) {
// in(0) might be a narrow MemBar; otherwise we will report TypePtr::BOTTOM
Node* ctrl = in(0);
+ if (ctrl->Opcode() == Op_Tuple) {
+ // Jumping over Tuples: the i-th projection of a Tuple is the i-th input of the Tuple.
+ ctrl = ctrl->in(_con);
+ }
if (ctrl == nullptr) return nullptr; // node is dead
const TypePtr* adr_type = ctrl->adr_type();
#ifdef ASSERT
@@ -163,6 +167,15 @@ void ProjNode::check_con() const {
assert(_con < t->is_tuple()->cnt(), "ProjNode::_con must be in range");
}
+//------------------------------Identity---------------------------------------
+Node* ProjNode::Identity(PhaseGVN* phase) {
+ if (in(0) != nullptr && in(0)->Opcode() == Op_Tuple) {
+ // Jumping over Tuples: the i-th projection of a Tuple is the i-th input of the Tuple.
+ return in(0)->in(_con);
+ }
+ return this;
+}
+
//------------------------------Value------------------------------------------
const Type* ProjNode::Value(PhaseGVN* phase) const {
if (in(0) == nullptr) return Type::TOP;
diff --git a/src/hotspot/share/opto/multnode.hpp b/src/hotspot/share/opto/multnode.hpp
index dff2caed38d..834dcfdca6d 100644
--- a/src/hotspot/share/opto/multnode.hpp
+++ b/src/hotspot/share/opto/multnode.hpp
@@ -82,6 +82,7 @@ class ProjNode : public Node {
virtual const Type *bottom_type() const;
virtual const TypePtr *adr_type() const;
virtual bool pinned() const;
+ virtual Node* Identity(PhaseGVN* phase);
virtual const Type* Value(PhaseGVN* phase) const;
virtual uint ideal_reg() const;
virtual const RegMask &out_RegMask() const;
@@ -105,4 +106,49 @@ class ProjNode : public Node {
ProjNode* other_if_proj() const;
};
+/* Tuples are used to avoid manual graph surgery. When a node with Proj outputs (such as a call)
+ * must be removed and its ouputs replaced by its input, or some other value, we can make its
+ * ::Ideal return a tuple of what we want for each output: the ::Identity of output Proj will
+ * take care to jump over the Tuple and directly pick up the right input of the Tuple.
+ *
+ * For instance, if a function call is proven to have no side effect and return the constant 0,
+ * we can replace it with the 6-tuple:
+ * (control input, IO input, memory input, frame ptr input, return addr input, Con:0)
+ * all the output projections will pick up the input of the now gone call, except for the result
+ * projection that is replaced by 0.
+ *
+ * Using TupleNode avoid manual graph surgery and leave that to our expert surgeon: IGVN.
+ * Since the user of a Tuple are expected to be Proj, when creating a tuple during idealization,
+ * the output Proj should be enqueued for IGVN immediately after, and the tuple should not survive
+ * after the current IGVN.
+ */
+class TupleNode : public MultiNode {
+ const TypeTuple* _tf;
+
+ template <typename... NN>
+ static void make_helper(TupleNode* tn, uint i, Node* node, NN... nn) {
+ tn->set_req(i, node);
+ make_helper(tn, i + 1, nn...);
+ }
+
+ static void make_helper(TupleNode*, uint) {}
+
+public:
+ TupleNode(const TypeTuple* tf) : MultiNode(tf->cnt()), _tf(tf) {}
+
+ int Opcode() const override;
+ const Type* bottom_type() const override { return _tf; }
+
+ /* Give as many `Node*` as you want in the `nn` pack:
+ * TupleNode::make(tf, input1)
+ * TupleNode::make(tf, input1, input2, input3, input4)
+ */
+ template <typename... NN>
+ static TupleNode* make(const TypeTuple* tf, NN... nn) {
+ TupleNode* tn = new TupleNode(tf);
+ make_helper(tn, 0, nn...);
+ return tn;
+ }
+};
+
#endif // SHARE_OPTO_MULTNODE_HPP
diff --git a/src/hotspot/share/opto/node.cpp b/src/hotspot/share/opto/node.cpp
index 8f6c67c16f5..5ecc038954d 100644
--- a/src/hotspot/share/opto/node.cpp
+++ b/src/hotspot/share/opto/node.cpp
@@ -2946,23 +2946,13 @@ bool Node::is_dead_loop_safe() const {
bool Node::is_div_or_mod(BasicType bt) const { return Opcode() == Op_Div(bt) || Opcode() == Op_Mod(bt) ||
Opcode() == Op_UDiv(bt) || Opcode() == Op_UMod(bt); }
-bool Node::is_pure_function() const {
- switch (Opcode()) {
- case Op_ModD:
- case Op_ModF:
- return true;
- default:
- return false;
- }
-}
-
// `maybe_pure_function` is assumed to be the input of `this`. This is a bit redundant,
// but we already have and need maybe_pure_function in all the call sites, so
// it makes it obvious that the `maybe_pure_function` is the same node as in the caller,
// while it takes more thinking to realize that a locally computed in(0) must be equal to
// the local in the caller.
bool Node::is_data_proj_of_pure_function(const Node* maybe_pure_function) const {
- return Opcode() == Op_Proj && as_Proj()->_con == TypeFunc::Parms && maybe_pure_function->is_pure_function();
+ return Opcode() == Op_Proj && as_Proj()->_con == TypeFunc::Parms && maybe_pure_function->is_CallLeafPure();
}
//=============================================================================
diff --git a/src/hotspot/share/opto/node.hpp b/src/hotspot/share/opto/node.hpp
index 2bbb10879f5..dc0ac474c4b 100644
--- a/src/hotspot/share/opto/node.hpp
+++ b/src/hotspot/share/opto/node.hpp
@@ -54,6 +54,7 @@ class CallDynamicJavaNode;
class CallJavaNode;
class CallLeafNode;
class CallLeafNoFPNode;
+class CallLeafPureNode;
class CallNode;
class CallRuntimeNode;
class CallStaticJavaNode;
@@ -673,6 +674,7 @@ class Node {
DEFINE_CLASS_ID(CallRuntime, Call, 1)
DEFINE_CLASS_ID(CallLeaf, CallRuntime, 0)
DEFINE_CLASS_ID(CallLeafNoFP, CallLeaf, 0)
+ DEFINE_CLASS_ID(CallLeafPure, CallLeaf, 1)
DEFINE_CLASS_ID(Allocate, Call, 2)
DEFINE_CLASS_ID(AllocateArray, Allocate, 0)
DEFINE_CLASS_ID(AbstractLock, Call, 3)
@@ -907,6 +909,7 @@ class Node {
DEFINE_CLASS_QUERY(CallJava)
DEFINE_CLASS_QUERY(CallLeaf)
DEFINE_CLASS_QUERY(CallLeafNoFP)
+ DEFINE_CLASS_QUERY(CallLeafPure)
DEFINE_CLASS_QUERY(CallRuntime)
DEFINE_CLASS_QUERY(CallStaticJava)
DEFINE_CLASS_QUERY(Catch)
@@ -1289,8 +1292,6 @@ class Node {
bool is_div_or_mod(BasicType bt) const;
- bool is_pure_function() const;
-
bool is_data_proj_of_pure_function(const Node* maybe_pure_function) const;
//----------------- Printing, etc
diff --git a/src/hotspot/share/opto/parse2.cpp b/src/hotspot/share/opto/parse2.cpp
index 1a4c3c91c4f..04b6e49b620 100644
--- a/src/hotspot/share/opto/parse2.cpp
+++ b/src/hotspot/share/opto/parse2.cpp
@@ -1097,11 +1097,11 @@ void Parse::jump_switch_ranges(Node* key_val, SwitchRange *lo, SwitchRange *hi,
Node* Parse::floating_point_mod(Node* a, Node* b, BasicType type) {
assert(type == BasicType::T_FLOAT || type == BasicType::T_DOUBLE, "only float and double are floating points");
- CallNode* mod = type == BasicType::T_DOUBLE ? static_cast<CallNode*>(new ModDNode(C, a, b)) : new ModFNode(C, a, b);
+ CallLeafPureNode* mod = type == BasicType::T_DOUBLE ? static_cast<CallLeafPureNode*>(new ModDNode(C, a, b)) : new ModFNode(C, a, b);
- Node* prev_mem = set_predefined_input_for_runtime_call(mod);
- mod = _gvn.transform(mod)->as_Call();
- set_predefined_output_for_runtime_call(mod, prev_mem, TypeRawPtr::BOTTOM);
+ set_predefined_input_for_runtime_call(mod);
+ mod = _gvn.transform(mod)->as_CallLeafPure();
+ set_predefined_output_for_runtime_call(mod);
Node* result = _gvn.transform(new ProjNode(mod, TypeFunc::Parms + 0));
record_for_igvn(mod);
return result;
--
2.53.0

View File

@ -0,0 +1,63 @@
From dbbdc1dffd10608195487fa139e77c4a90c80658 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Ji=C5=99=C3=AD=20Van=C4=9Bk?= <jvanek@openjdk.org>
Date: Wed, 15 Apr 2026 12:54:49 +0000
Subject: [PATCH] 8375294: (fs) Files.copy can fail with EOPNOTSUPP when
copy_file_range not supported
Reviewed-by: andrew
Backport-of: 30cda00010888b6e9a2bf8cdeaedbb3eb4b6a222
---
src/java.base/linux/native/libnio/ch/FileDispatcherImpl.c | 5 +++--
src/java.base/linux/native/libnio/fs/LinuxNativeDispatcher.c | 3 ++-
2 files changed, 5 insertions(+), 3 deletions(-)
diff --git a/src/java.base/linux/native/libnio/ch/FileDispatcherImpl.c b/src/java.base/linux/native/libnio/ch/FileDispatcherImpl.c
index efbd0ca5684..54d640b03a4 100644
--- a/src/java.base/linux/native/libnio/ch/FileDispatcherImpl.c
+++ b/src/java.base/linux/native/libnio/ch/FileDispatcherImpl.c
@@ -1,5 +1,5 @@
/*
- * Copyright (c) 2000, 2024, Oracle and/or its affiliates. All rights reserved.
+ * Copyright (c) 2000, 2026, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
@@ -63,7 +63,7 @@ Java_sun_nio_ch_FileDispatcherImpl_transferFrom0(JNIEnv *env, jobject this,
if (n < 0) {
if (errno == EAGAIN)
return IOS_UNAVAILABLE;
- if (errno == ENOSYS)
+ if (errno == ENOSYS || errno == EOPNOTSUPP)
return IOS_UNSUPPORTED_CASE;
if ((errno == EBADF || errno == EINVAL || errno == EXDEV) &&
((ssize_t)count >= 0))
@@ -103,6 +103,7 @@ Java_sun_nio_ch_FileDispatcherImpl_transferTo0(JNIEnv *env, jobject this,
case EINVAL:
case ENOSYS:
case EXDEV:
+ case EOPNOTSUPP:
// ignore and try sendfile()
break;
default:
diff --git a/src/java.base/linux/native/libnio/fs/LinuxNativeDispatcher.c b/src/java.base/linux/native/libnio/fs/LinuxNativeDispatcher.c
index c90e99dda07..4677411b0ba 100644
--- a/src/java.base/linux/native/libnio/fs/LinuxNativeDispatcher.c
+++ b/src/java.base/linux/native/libnio/fs/LinuxNativeDispatcher.c
@@ -1,5 +1,5 @@
/*
- * Copyright (c) 2008, 2024, Oracle and/or its affiliates. All rights reserved.
+ * Copyright (c) 2008, 2026, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
@@ -193,6 +193,7 @@ Java_sun_nio_fs_LinuxNativeDispatcher_directCopy0
case EINVAL:
case ENOSYS:
case EXDEV:
+ case EOPNOTSUPP:
// ignore and try sendfile()
break;
default:
--
2.52.0

View File

@ -0,0 +1,626 @@
From 1f61b6754b5abce07db45fd385a19c2cf9296a08 Mon Sep 17 00:00:00 2001
From: Kangcheng Xu <kxu@redhat.com>
Date: Mon, 27 Apr 2026 10:14:39 -0400
Subject: [PATCH 2/2] Backport 7f631ea958e30246b927f3524f0fbf37334422b9
---
src/hotspot/share/opto/callnode.cpp | 175 ++++++++++++++
src/hotspot/share/opto/callnode.hpp | 17 ++
src/hotspot/share/opto/classes.hpp | 1 +
src/hotspot/share/opto/library_call.cpp | 62 +----
src/hotspot/share/opto/macro.cpp | 19 +-
.../intrinsics/math/PowDNodeTests.java | 218 ++++++++++++++++++
.../compiler/lib/ir_framework/IRNode.java | 11 +
7 files changed, 437 insertions(+), 66 deletions(-)
create mode 100644 test/hotspot/jtreg/compiler/intrinsics/math/PowDNodeTests.java
diff --git a/src/hotspot/share/opto/callnode.cpp b/src/hotspot/share/opto/callnode.cpp
index fc4b0c35dff..cb6cc2082b3 100644
--- a/src/hotspot/share/opto/callnode.cpp
+++ b/src/hotspot/share/opto/callnode.cpp
@@ -42,6 +42,7 @@
#include "opto/rootnode.hpp"
#include "opto/runtime.hpp"
#include "runtime/sharedRuntime.hpp"
+#include "runtime/stubRoutines.hpp"
#include "utilities/powerOfTwo.hpp"
#include "code/vmreg.hpp"
@@ -1354,6 +1355,25 @@ TupleNode* CallLeafPureNode::make_tuple_of_input_state_and_top_return_values(con
return tuple;
}
+CallLeafPureNode* CallLeafPureNode::inline_call_leaf_pure_node(Node* control) const {
+ Node* top = Compile::current()->top();
+ if (control == nullptr) {
+ control = in(TypeFunc::Control);
+ }
+
+ CallLeafPureNode* call = new CallLeafPureNode(tf(), entry_point(), _name, nullptr);
+ call->init_req(TypeFunc::Control, control);
+ call->init_req(TypeFunc::I_O, top);
+ call->init_req(TypeFunc::Memory, top);
+ call->init_req(TypeFunc::ReturnAdr, top);
+ call->init_req(TypeFunc::FramePtr, top);
+ for (unsigned int i = 0; i < tf()->domain()->cnt() - TypeFunc::Parms; i++) {
+ call->init_req(TypeFunc::Parms + i, in(TypeFunc::Parms + i));
+ }
+
+ return call;
+}
+
Node* CallLeafPureNode::Ideal(PhaseGVN* phase, bool can_reshape) {
if (is_dead()) {
return nullptr;
@@ -2424,3 +2444,158 @@ bool CallNode::may_modify_arraycopy_helper(const TypeOopPtr* dest_t, const TypeO
return true;
}
+
+PowDNode::PowDNode(Compile* C, Node* base, Node* exp)
+ : CallLeafPureNode(
+ OptoRuntime::Math_DD_D_Type(),
+ StubRoutines::dpow() != nullptr ? StubRoutines::dpow() : CAST_FROM_FN_PTR(address, SharedRuntime::dpow),
+ "pow",
+ nullptr) {
+ add_flag(Flag_is_macro);
+ C->add_macro_node(this);
+
+ init_req(TypeFunc::Parms + 0, base);
+ init_req(TypeFunc::Parms + 1, C->top()); // double slot padding
+ init_req(TypeFunc::Parms + 2, exp);
+ init_req(TypeFunc::Parms + 3, C->top()); // double slot padding
+}
+
+const Type* PowDNode::Value(PhaseGVN* phase) const {
+ const Type* t_base = phase->type(base());
+ const Type* t_exp = phase->type(exp());
+
+ if (t_base == Type::TOP || t_exp == Type::TOP) {
+ return Type::TOP;
+ }
+
+ const TypeD* base_con = t_base->isa_double_constant();
+ const TypeD* exp_con = t_exp->isa_double_constant();
+ const TypeD* result_t = nullptr;
+
+ // constant folding: both inputs are constants
+ if (base_con != nullptr && exp_con != nullptr) {
+ result_t = TypeD::make(SharedRuntime::dpow(base_con->getd(), exp_con->getd()));
+ }
+
+ // Special cases when only the exponent is known:
+ if (exp_con != nullptr) {
+ double e = exp_con->getd();
+
+ // If the second argument is positive or negative zero, then the result is 1.0.
+ // i.e., pow(x, +/-0.0D) => 1.0
+ if (e == 0.0) { // true for both -0.0 and +0.0
+ result_t = TypeD::ONE;
+ }
+
+ // If the second argument is NaN, then the result is NaN.
+ // i.e., pow(x, NaN) => NaN
+ if (g_isnan(e)) {
+ result_t = TypeD::make(NAN);
+ }
+ }
+
+ if (result_t != nullptr) {
+ // We can't simply return a TypeD here, it must be a tuple type to be compatible with call nodes.
+ const Type** fields = TypeTuple::fields(2);
+ fields[TypeFunc::Parms + 0] = result_t;
+ fields[TypeFunc::Parms + 1] = Type::HALF;
+ return TypeTuple::make(TypeFunc::Parms + 2, fields);
+ }
+
+ return tf()->range();
+}
+
+Node* PowDNode::Ideal(PhaseGVN* phase, bool can_reshape) {
+ if (!can_reshape) {
+ return nullptr; // wait for igvn
+ }
+
+ PhaseIterGVN* igvn = phase->is_IterGVN();
+ Node* base = this->base();
+ Node* exp = this->exp();
+
+ const Type* t_exp = phase->type(exp);
+ const TypeD* exp_con = t_exp->isa_double_constant();
+
+ // Special cases when only the exponent is known:
+ if (exp_con != nullptr) {
+ double e = exp_con->getd();
+
+ // If the second argument is 1.0, then the result is the same as the first argument.
+ // i.e., pow(x, 1.0) => x
+ if (e == 1.0) {
+ return make_tuple_of_input_state_and_result(igvn, base);
+ }
+
+ // If the second argument is 2.0, then strength reduce to multiplications.
+ // i.e., pow(x, 2.0) => x * x
+ if (e == 2.0) {
+ Node* mul = igvn->transform(new MulDNode(base, base));
+ return make_tuple_of_input_state_and_result(igvn, mul);
+ }
+
+ // If the second argument is 0.5, the strength reduce to square roots.
+ // i.e., pow(x, 0.5) => sqrt(x) iff x > 0
+ if (e == 0.5 && Matcher::match_rule_supported(Op_SqrtD)) {
+ Node* ctrl = in(TypeFunc::Control);
+ Node* zero = igvn->zerocon(T_DOUBLE);
+
+ // According to the API specs, pow(-0.0, 0.5) = 0.0 and sqrt(-0.0) = -0.0.
+ // So pow(-0.0, 0.5) shouldn't be replaced with sqrt(-0.0).
+ // -0.0/+0.0 are both excluded since floating-point comparison doesn't distinguish -0.0 from +0.0.
+ Node* cmp = igvn->register_new_node_with_optimizer(new CmpDNode(base, zero));
+ Node* test = igvn->register_new_node_with_optimizer(new BoolNode(cmp, BoolTest::le));
+
+ IfNode* iff = new IfNode(ctrl, test, PROB_UNLIKELY_MAG(3), COUNT_UNKNOWN);
+ igvn->register_new_node_with_optimizer(iff);
+ Node* if_slow = igvn->register_new_node_with_optimizer(new IfTrueNode(iff)); // x <= 0
+ Node* if_fast = igvn->register_new_node_with_optimizer(new IfFalseNode(iff)); // x > 0
+
+ // slow path: call pow(x, 0.5)
+ Node* call = igvn->register_new_node_with_optimizer(inline_call_leaf_pure_node(if_slow));
+ Node* call_ctrl = igvn->register_new_node_with_optimizer(new ProjNode(call, TypeFunc::Control));
+ Node* call_result = igvn->register_new_node_with_optimizer(new ProjNode(call, TypeFunc::Parms + 0));
+
+ // fast path: sqrt(x)
+ Node* sqrt = igvn->register_new_node_with_optimizer(new SqrtDNode(igvn->C, if_fast, base));
+
+ // merge paths
+ RegionNode* region = new RegionNode(3);
+ igvn->register_new_node_with_optimizer(region);
+ region->init_req(1, call_ctrl); // slow path
+ region->init_req(2, if_fast); // fast path
+
+ PhiNode* phi = new PhiNode(region, Type::DOUBLE);
+ igvn->register_new_node_with_optimizer(phi);
+ phi->init_req(1, call_result); // slow: pow() result
+ phi->init_req(2, sqrt); // fast: sqrt() result
+
+ igvn->C->set_has_split_ifs(true); // Has chance for split-if optimization
+
+ return make_tuple_of_input_state_and_result(igvn, phi, region);
+ }
+ }
+
+ return CallLeafPureNode::Ideal(phase, can_reshape);
+}
+
+// We can't simply have Ideal() returning a Con or MulNode since the users are still expecting a Call node, but we could
+// produce a tuple that follows the same pattern so users can still get control, io, memory, etc..
+TupleNode* PowDNode::make_tuple_of_input_state_and_result(PhaseIterGVN* phase, Node* result, Node* control) {
+ if (control == nullptr) {
+ control = in(TypeFunc::Control);
+ }
+
+ Compile* C = phase->C;
+ C->remove_macro_node(this);
+ TupleNode* tuple = TupleNode::make(
+ tf()->range(),
+ control,
+ in(TypeFunc::I_O),
+ in(TypeFunc::Memory),
+ in(TypeFunc::FramePtr),
+ in(TypeFunc::ReturnAdr),
+ result,
+ C->top());
+ return tuple;
+}
diff --git a/src/hotspot/share/opto/callnode.hpp b/src/hotspot/share/opto/callnode.hpp
index 2462a88143f..bb87746a3f6 100644
--- a/src/hotspot/share/opto/callnode.hpp
+++ b/src/hotspot/share/opto/callnode.hpp
@@ -953,6 +953,8 @@ class CallLeafPureNode : public CallLeafNode {
}
int Opcode() const override;
Node* Ideal(PhaseGVN* phase, bool can_reshape) override;
+
+ CallLeafPureNode* inline_call_leaf_pure_node(Node* control = nullptr) const;
};
//------------------------------CallLeafNoFPNode-------------------------------
@@ -1304,4 +1306,19 @@ class UnlockNode : public AbstractLockNode {
JVMState* dbg_jvms() const { return nullptr; }
#endif
};
+
+//------------------------------PowDNode--------------------------------------
+class PowDNode : public CallLeafPureNode {
+ TupleNode* make_tuple_of_input_state_and_result(PhaseIterGVN* phase, Node* result, Node* control = nullptr);
+
+public:
+ PowDNode(Compile* C, Node* base, Node* exp);
+ int Opcode() const override;
+ const Type* Value(PhaseGVN* phase) const override;
+ Node* Ideal(PhaseGVN* phase, bool can_reshape) override;
+
+ Node* base() const { return in(TypeFunc::Parms + 0); }
+ Node* exp() const { return in(TypeFunc::Parms + 2); }
+};
+
#endif // SHARE_OPTO_CALLNODE_HPP
diff --git a/src/hotspot/share/opto/classes.hpp b/src/hotspot/share/opto/classes.hpp
index 587d5fad8f2..b7ba16e99a0 100644
--- a/src/hotspot/share/opto/classes.hpp
+++ b/src/hotspot/share/opto/classes.hpp
@@ -283,6 +283,7 @@ macro(OpaqueZeroTripGuard)
macro(OpaqueNotNull)
macro(OpaqueInitializedAssertionPredicate)
macro(OpaqueTemplateAssertionPredicate)
+macro(PowD)
macro(ProfileBoolean)
macro(OrI)
macro(OrL)
diff --git a/src/hotspot/share/opto/library_call.cpp b/src/hotspot/share/opto/library_call.cpp
index 12960d101a8..6c71a61ba75 100644
--- a/src/hotspot/share/opto/library_call.cpp
+++ b/src/hotspot/share/opto/library_call.cpp
@@ -1817,61 +1817,17 @@ bool LibraryCallKit::runtime_math(const TypeFunc* call_type, address funcAddr, c
//------------------------------inline_math_pow-----------------------------
bool LibraryCallKit::inline_math_pow() {
+ Node* base = argument(0);
Node* exp = argument(2);
- const TypeD* d = _gvn.type(exp)->isa_double_constant();
- if (d != nullptr) {
- if (d->getd() == 2.0) {
- // Special case: pow(x, 2.0) => x * x
- Node* base = argument(0);
- set_result(_gvn.transform(new MulDNode(base, base)));
- return true;
- } else if (d->getd() == 0.5 && Matcher::match_rule_supported(Op_SqrtD)) {
- // Special case: pow(x, 0.5) => sqrt(x)
- Node* base = argument(0);
- Node* zero = _gvn.zerocon(T_DOUBLE);
-
- RegionNode* region = new RegionNode(3);
- Node* phi = new PhiNode(region, Type::DOUBLE);
-
- Node* cmp = _gvn.transform(new CmpDNode(base, zero));
- // According to the API specs, pow(-0.0, 0.5) = 0.0 and sqrt(-0.0) = -0.0.
- // So pow(-0.0, 0.5) shouldn't be replaced with sqrt(-0.0).
- // -0.0/+0.0 are both excluded since floating-point comparison doesn't distinguish -0.0 from +0.0.
- Node* test = _gvn.transform(new BoolNode(cmp, BoolTest::le));
-
- Node* if_pow = generate_slow_guard(test, nullptr);
- Node* value_sqrt = _gvn.transform(new SqrtDNode(C, control(), base));
- phi->init_req(1, value_sqrt);
- region->init_req(1, control());
-
- if (if_pow != nullptr) {
- set_control(if_pow);
- address target = StubRoutines::dpow() != nullptr ? StubRoutines::dpow() :
- CAST_FROM_FN_PTR(address, SharedRuntime::dpow);
- const TypePtr* no_memory_effects = nullptr;
- Node* trig = make_runtime_call(RC_LEAF, OptoRuntime::Math_DD_D_Type(), target, "POW",
- no_memory_effects, base, top(), exp, top());
- Node* value_pow = _gvn.transform(new ProjNode(trig, TypeFunc::Parms+0));
-#ifdef ASSERT
- Node* value_top = _gvn.transform(new ProjNode(trig, TypeFunc::Parms+1));
- assert(value_top == top(), "second value must be top");
-#endif
- phi->init_req(2, value_pow);
- region->init_req(2, _gvn.transform(new ProjNode(trig, TypeFunc::Control)));
- }
-
- C->set_has_split_ifs(true); // Has chance for split-if optimization
- set_control(_gvn.transform(region));
- record_for_igvn(region);
- set_result(_gvn.transform(phi));
- return true;
- }
- }
-
- return StubRoutines::dpow() != nullptr ?
- runtime_math(OptoRuntime::Math_DD_D_Type(), StubRoutines::dpow(), "dpow") :
- runtime_math(OptoRuntime::Math_DD_D_Type(), CAST_FROM_FN_PTR(address, SharedRuntime::dpow), "POW");
+ CallNode* pow = new PowDNode(C, base, exp);
+ set_predefined_input_for_runtime_call(pow);
+ pow = _gvn.transform(pow)->as_CallLeafPure();
+ set_predefined_output_for_runtime_call(pow);
+ Node* result = _gvn.transform(new ProjNode(pow, TypeFunc::Parms + 0));
+ record_for_igvn(pow);
+ set_result(result);
+ return true;
}
//------------------------------inline_math_native-----------------------------
diff --git a/src/hotspot/share/opto/macro.cpp b/src/hotspot/share/opto/macro.cpp
index aafc5d3c170..a28043c8d8f 100644
--- a/src/hotspot/share/opto/macro.cpp
+++ b/src/hotspot/share/opto/macro.cpp
@@ -2484,6 +2484,7 @@ void PhaseMacroExpand::eliminate_macro_nodes() {
assert(n->Opcode() == Op_LoopLimit ||
n->Opcode() == Op_ModD ||
n->Opcode() == Op_ModF ||
+ n->Opcode() == Op_PowD ||
n->is_OpaqueNotNull() ||
n->is_OpaqueInitializedAssertionPredicate() ||
n->Opcode() == Op_MaxL ||
@@ -2637,19 +2638,11 @@ bool PhaseMacroExpand::expand_macro_nodes() {
default:
switch (n->Opcode()) {
case Op_ModD:
- case Op_ModF: {
- CallNode* mod_macro = n->as_Call();
- CallNode* call = new CallLeafPureNode(mod_macro->tf(), mod_macro->entry_point(),
- mod_macro->_name, TypeRawPtr::BOTTOM);
- call->init_req(TypeFunc::Control, mod_macro->in(TypeFunc::Control));
- call->init_req(TypeFunc::I_O, C->top());
- call->init_req(TypeFunc::Memory, C->top());
- call->init_req(TypeFunc::ReturnAdr, C->top());
- call->init_req(TypeFunc::FramePtr, C->top());
- for (unsigned int i = 0; i < mod_macro->tf()->domain()->cnt() - TypeFunc::Parms; i++) {
- call->init_req(TypeFunc::Parms + i, mod_macro->in(TypeFunc::Parms + i));
- }
- _igvn.replace_node(mod_macro, call);
+ case Op_ModF:
+ case Op_PowD: {
+ CallLeafPureNode* call_macro = n->as_CallLeafPure();
+ CallLeafPureNode* call = call_macro->inline_call_leaf_pure_node();
+ _igvn.replace_node(call_macro, call);
transform_later(call);
break;
}
diff --git a/test/hotspot/jtreg/compiler/intrinsics/math/PowDNodeTests.java b/test/hotspot/jtreg/compiler/intrinsics/math/PowDNodeTests.java
new file mode 100644
index 00000000000..e28cc5ab346
--- /dev/null
+++ b/test/hotspot/jtreg/compiler/intrinsics/math/PowDNodeTests.java
@@ -0,0 +1,218 @@
+/*
+ * Copyright (c) 2026, IBM and/or its affiliates. All rights reserved.
+ * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
+ *
+ * This code is free software; you can redistribute it and/or modify it
+ * under the terms of the GNU General Public License version 2 only, as
+ * published by the Free Software Foundation.
+ *
+ * This code is distributed in the hope that it will be useful, but WITHOUT
+ * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
+ * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
+ * version 2 for more details (a copy is included in the LICENSE file that
+ * accompanied this code).
+ *
+ * You should have received a copy of the GNU General Public License version
+ * 2 along with this work; if not, write to the Free Software Foundation,
+ * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+ *
+ * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
+ * or visit www.oracle.com if you need additional information or have any
+ * questions.
+ *
+ */
+package compiler.intrinsics.math;
+
+import jdk.test.lib.Asserts;
+
+import compiler.lib.ir_framework.*;
+import compiler.lib.generators.*;
+import static compiler.lib.generators.Generators.*;
+
+import java.util.Random;
+
+/*
+ * @test
+ * @bug 8378713
+ * @key randomness
+ * @summary Math.pow(base, exp) should constant propagate
+ * @library /test/lib /
+ * @run driver ${test.main.class}
+ */
+public class PowDNodeTests {
+ public static final Generator<Double> UNIFORMS = G.uniformDoubles(); // [0, 1)
+
+ public static final double B = UNIFORMS.next() * 1000.0d;
+ public static final double E = UNIFORMS.next() * 1000.0d + 3.0d; // e >= 3 to avoid strength reduction code
+
+ public static void main(String[] args) {
+ TestFramework.run();
+
+ testCorrectness();
+ }
+
+ // Test 1: pow(2.0, 10.0) -> 1024.0
+ @Test
+ @IR(failOn = {IRNode.POW_D})
+ public static double constantLiteralFolding() {
+ return Math.pow(2.0, 10.0); // should fold to 1024.0
+ }
+
+ // Test 2: pow(final B, final E) -> B^E
+ @Test
+ @IR(failOn = {IRNode.POW_D})
+ public static double constantStaticFolding() {
+ return Math.pow(B, E); // should fold to B^E
+ }
+
+ // Test 3: pow(b, 0.0) -> 1.0
+ @Test
+ @IR(failOn = {IRNode.POW_D})
+ @Arguments(values = {Argument.RANDOM_EACH})
+ public static double expZero(double b) {
+ return Math.pow(b, 0.0);
+ }
+
+ // Test 4: pow(b, 1.0) -> b (identity)
+ @Test
+ @IR(failOn = {IRNode.POW_D})
+ @Arguments(values = {Argument.RANDOM_EACH})
+ public static double expOne(double b) {
+ return Math.pow(b, 1.0);
+ }
+
+ // Test 5: pow(b, NaN) -> NaN
+ @Test
+ @IR(failOn = {IRNode.POW_D})
+ @Arguments(values = {Argument.RANDOM_EACH})
+ public static double expNaN(double b) {
+ return Math.pow(b, Double.NaN);
+ }
+
+ // Test 6: pow(b, 2.0) -> b * b
+ // More tests in TestPow2Opt.java
+ @Test
+ @IR(failOn = {IRNode.POW_D})
+ @IR(counts = {IRNode.MUL_D, "1"})
+ @Arguments(values = {Argument.RANDOM_EACH})
+ public static double expTwo(double b) {
+ return Math.pow(b, 2.0);
+ }
+
+ // Test 7: pow(b, 0.5) -> b <= 0.0 ? pow(b, 0.5) : sqrt(b)
+ // More tests in TestPow0Dot5Opt.java
+ @Test
+ @IR(counts = {IRNode.IF, "1"})
+ @IR(counts = {IRNode.SQRT_D, "1"})
+ @IR(counts = {".*CallLeaf.*pow.*", "1"}, phase = CompilePhase.BEFORE_MATCHING)
+ @Arguments(values = {Argument.RANDOM_EACH})
+ public static double expDot5(double b) {
+ return Math.pow(b, 0.5); // expand to: if (b > 0) { sqrt(b) } else { call(b) }
+ }
+
+ // Test 8: non-constant exponent stays as call
+ @Test
+ @IR(counts = {IRNode.POW_D, "1"})
+ @Arguments(values = {Argument.RANDOM_EACH, Argument.RANDOM_EACH})
+ public static double nonConstant(double b, double e) {
+ return Math.pow(b, e);
+ }
+
+ // Test 9: late constant discovery on base (after loop opts)
+ @Test
+ @IR(counts = {IRNode.POW_D, "1"}, phase = CompilePhase.AFTER_PARSING)
+ @IR(failOn = {IRNode.POW_D})
+ public static double lateBaseConstant() {
+ double base = 0;
+ for (int i = 0; i < 4; i++) {
+ if ((i % 2) == 0) {
+ base = B;
+ }
+ }
+ // After loop opts, base == B (constant), so pow(B, E) folds
+ return Math.pow(base, E);
+ }
+
+ // Test 10: late constant discovery on exp (after loop opts)
+ @Test
+ @IR(counts = {IRNode.POW_D, "1"}, phase = CompilePhase.AFTER_PARSING)
+ @IR(failOn = {IRNode.POW_D})
+ public static double lateExpConstant() {
+ double exp = 0;
+ for (int i = 0; i < 4; i++) {
+ if ((i % 2) == 0) {
+ exp = E;
+ }
+ }
+ // After loop opts, exp == E (constant), so pow(B, E) folds
+ return Math.pow(B, exp);
+ }
+
+ // Test 11: late constant discoveries on both base and exp (after loop opts)
+ @Test
+ @IR(counts = {IRNode.POW_D, "1"}, phase = CompilePhase.AFTER_PARSING)
+ @IR(failOn = {IRNode.POW_D})
+ public static double lateBothConstant() {
+ double base = 0, exp = 0;
+ for (int i = 0; i < 4; i++) {
+ if ((i % 2) == 0) {
+ base = B;
+ exp = E;
+ }
+ }
+ // After loop opts, base = B, exp == E, so pow(B, E) folds
+ return Math.pow(base, exp);
+ }
+
+ private static void assertEQWithinOneUlp(double expected, double observed) {
+ if (Double.isNaN(expected) && Double.isNaN(observed)) return;
+
+ // Math.pow() requires result must be within 1 ulp of the respective magnitude
+ double ulp = Math.max(Math.ulp(expected), Math.ulp(observed));
+ if (Math.abs(expected - observed) > ulp) {
+ throw new AssertionError(String.format(
+ "expect = %x, observed = %x, ulp = %x",
+ Double.doubleToRawLongBits(expected), Double.doubleToRawLongBits(observed), Double.doubleToRawLongBits(ulp)
+ ));
+ }
+ }
+
+ private static void testCorrectness() {
+ // No need to warm up for intrinsics
+ Asserts.assertEQ(1024.0d, constantLiteralFolding());
+
+ double BE = StrictMath.pow(B, E);
+ assertEQWithinOneUlp(BE, constantStaticFolding());
+ assertEQWithinOneUlp(BE, lateBaseConstant());
+ assertEQWithinOneUlp(BE, lateExpConstant());
+ assertEQWithinOneUlp(BE, lateBothConstant());
+
+ Generator<Double> anyBits = G.anyBitsDouble();
+ Generator<Double> largeDoubles = G.uniformDoubles(Long.MAX_VALUE, Double.MAX_VALUE);
+ Generator<Double> doubles = G.doubles();
+ double[] values = {
+ Double.MIN_VALUE, Double.MIN_NORMAL, -42.0d, -1.0d, -0.0d, +0.0d, 0.5d, 1.0d, 2.0d, 123d, Double.MAX_VALUE,
+ Double.NEGATIVE_INFINITY, Double.POSITIVE_INFINITY, Double.NaN,
+ UNIFORMS.next(), UNIFORMS.next(),
+ largeDoubles.next(), -largeDoubles.next(), // some sufficiently large magnitudes
+ anyBits.next(), anyBits.next(), // any bits with potentially more NaN representation
+ doubles.next(), doubles.next() // a healthy sprinkle of whatever else is possible
+ };
+
+ for (double b : values) {
+ // Strength reduced, so we know the bits matches exactly
+ Asserts.assertEQ(1.0d, expZero(b));
+ Asserts.assertEQ(b, expOne(b));
+ Asserts.assertEQ(b * b, expTwo(b));
+
+ assertEQWithinOneUlp(Double.NaN, expNaN(b));
+
+ // Runtime calls, so make sure the result is within 1 ulp
+ assertEQWithinOneUlp(StrictMath.pow(b, 0.5d), expDot5(b));
+
+ for (double e : values) {
+ assertEQWithinOneUlp(StrictMath.pow(b, e), nonConstant(b, e));
+ }
+ }
+ }
+}
diff --git a/test/hotspot/jtreg/compiler/lib/ir_framework/IRNode.java b/test/hotspot/jtreg/compiler/lib/ir_framework/IRNode.java
index 7b751f1a72c..6a95a2b5da7 100644
--- a/test/hotspot/jtreg/compiler/lib/ir_framework/IRNode.java
+++ b/test/hotspot/jtreg/compiler/lib/ir_framework/IRNode.java
@@ -1858,6 +1858,11 @@ public class IRNode {
beforeMatchingNameRegex(SQRT_HF, "SqrtHF");
}
+ public static final String SQRT_D = PREFIX + "SQRT_D" + POSTFIX;
+ static {
+ beforeMatchingNameRegex(SQRT_D, "SqrtD");
+ }
+
public static final String SQRT_F = PREFIX + "SQRT_F" + POSTFIX;
static {
beforeMatchingNameRegex(SQRT_F, "SqrtF");
@@ -2825,6 +2830,12 @@ public class IRNode {
macroNodes(MOD_D, regex);
}
+ public static final String POW_D = PREFIX + "POW_D" + POSTFIX;
+ static {
+ String regex = START + "PowD" + MID + END;
+ macroNodes(POW_D, regex);
+ }
+
public static final String BLACKHOLE = PREFIX + "BLACKHOLE" + POSTFIX;
static {
fromBeforeRemoveUselessToFinalCode(BLACKHOLE, "Blackhole");
--
2.53.0

View File

@ -1,3 +1,4 @@
---
inspections:
javabytecode: off
abidiff: off

View File

@ -1,6 +1,6 @@
#!/bin/sh
#!/bin/bash
# Copyright (C) 2024 Red Hat, Inc.
# Copyright (C) 2026 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
@ -20,20 +20,24 @@
# Builds a scratch build of vanilla OpenJDK with no local patches
SEPARATE_ARCHES=${1}
CMD="--target java-openjdk-rhel-8-build --skip-nvr-check --nowait";
CMD=(rhpkg -v build --target java-openjdk-rhel-8-build --skip-nvr-check --nowait);
SUPPORTED_ARCHES="aarch64 ppc64le s390x x86_64";
if [ "x${SEPARATE_ARCHES}" = "x" ] ; then
if [ "${SEPARATE_ARCHES}" = "" ] ; then
SEPARATE_ARCHES=0;
fi
if [ ${SEPARATE_ARCHES} -eq 1 ] ; then
for arch in ${SUPPORTED_ARCHES}; do \
rhpkg -v build --arches ${arch} --scratch ${CMD} ; \
done && brew watch-task --mine
if [ "${SEPARATE_ARCHES}" -eq 1 ] ; then
for arch in ${SUPPORTED_ARCHES}; do \
ARCH_CMD=("${CMD[@]}" --arches "${arch}" --scratch) ;
echo "Executing ${ARCH_CMD[*]}";
command "${ARCH_CMD[@]}";
done
else
rhpkg -v build ${CMD} && brew watch-task --mine
echo "Executing ${CMD[*]}";
command "${CMD[@]}";
fi
brew watch-task --mine
# Local Variables:
# compile-command: "shellcheck build_vanilla.sh"

View File

@ -0,0 +1,77 @@
#!/bin/sh
# Copyright (C) 2026 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Check the signatures (if any) in RHEL RPM buildinfo
# This is intended to be run from the tagging scripts
# Return codes:
# - 1 - Buildinfo file not specified
# - 2 = Missing buildinfo file
# - 3 = No signatures
# - 4 = Multiple signature types found
# - 5 = PQC signature found
# - 6 = Old signature (fd431d51) found
# - 7 = Unknown signature found
BUILDINFO=${1}
NEW_SIGNATURE="release4";
OLD_SIGNATURE="fd431d51";
if test "${BUILDINFO}" = ""; then
echo "${0} <BUILDINFO>";
exit 1;
fi
if ! test -e "${BUILDINFO}" ; then
echo "${BUILDINFO} not found.";
exit 2;
fi
if grep -q "Signatures" < "${BUILDINFO}" ; then
signature=$(grep "Signatures" < "${BUILDINFO}" | cut -d ' ' -f 2- | uniq -c | sed 's#^\W*##');
uniq_count=$(echo "${signature}" | wc -l);
if test "${uniq_count}" -gt 1; then
echo "Multiple signature types found:";
echo "${signature}";
exit 4;
fi
sig_count=$(echo "${signature}" | cut -d ' ' -f 1);
sig_type=$(echo "${signature}" | cut -d ' ' -f 2);
echo "${sig_count} signatures of type ${sig_type} found";
if echo "${sig_type}" | grep -q "${NEW_SIGNATURE}" ; then
echo "PQC signature found.";
exit 5;
elif echo "${sig_type}" | grep -q "${OLD_SIGNATURE}"; then
echo "Old pre-PQC signature found.";
exit 6;
else
echo "Unknown signature found.";
exit 7;
fi
else
echo "Build has no signatures.";
exit 3;
fi
# Local Variables:
# compile-command: "shellcheck check_signatures.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -0,0 +1,63 @@
#!/bin/bash
# Copyright (C) 2026 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Retrieve the results of a gating test using the ID from the JSON
# retrieved by query_build_gating.sh
RESULT_ID=${1}
if test "${RESULT_ID}" = ""; then
echo "No ID specified.";
echo "${0} <RESULT_ID>";
exit 1;
fi
CURL=$(command -v curl)
JSON_TOOL=$(command -v jq)
if test "${CURL}" = ""; then
echo "curl not found";
exit 2;
fi
if test "${JSON_TOOL}" = ""; then
echo "jq not found";
exit 3;
fi
URL="https://resultsdb-api.engineering.redhat.com/api/v2.0/results/${RESULT_ID}"
JSON_OUT=$(mktemp --tmpdir out.XXXXXX.json)
CMD=("${CURL}" --silent --show-error "${URL}")
echo "${CMD[@]}"
if command "${CMD[@]}" > "${JSON_OUT}" ; then
"${JSON_TOOL}" < "${JSON_OUT}"
else
echo "Failed to obtain JSON";
exit 4;
fi
# Local Variables:
# compile-command: "shellcheck get_gating_results.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -0,0 +1,94 @@
#!/bin/bash
# Copyright (C) 2026 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Retrieve the status of a build's progress through gating
RHEL_VER=${1}
NVR=${2}
if test "${RHEL_VER}" = ""; then
echo "No RHEL version specified.";
echo "${0} <RHEL_VER> <NVR>";
exit 1;
fi
if test "${NVR}" = ""; then
echo "No NVR specified.";
echo "${0} <RHEL_VER> <NVR>";
exit 2;
fi
CURL=$(command -v curl)
JSON_TOOL=$(command -v jq)
JSON_FILE=$(mktemp --tmpdir query.XXXXXX.json)
JSON_OUT=$(mktemp --tmpdir out.XXXXXX.json)
URL="https://greenwave.engineering.redhat.com/api/v1.0/decision"
if test "${CURL}" = ""; then
echo "curl not found";
exit 3;
fi
if test "${JSON_TOOL}" = ""; then
echo "jq not found";
exit 4;
fi
{
echo "{";
printf "\t\"decision_context\":\"osci_compose_gate\",\n";
printf "\t\"product_version\":\"rhel-%d\",\n" "${RHEL_VER}";
printf "\t\"subject_type\":\"koji_build\",\n";
printf "\t\"subject_identifier\":\"%s\",\n" "${NVR}";
printf "\t\"verbose\":false\n";
echo "}";
} > "${JSON_FILE}"
echo "Sending the following JSON...";
cat "${JSON_FILE}"
CMD=("${CURL}" --silent --show-error -X POST)
JSON_COMMAND="--json";
# Check --json is available
${CURL} ${JSON_COMMAND} 2> /dev/null
if [ $? -eq 2 ] ; then
echo "--json unsupported; falling back on --data-ascii";
CMD=("${CMD[@]}" --header Content-Type:application/json --data-ascii);
else
CMD=("${CMD[@]}" "${JSON_COMMAND}");
fi
CMD=("${CMD[@]}" "@${JSON_FILE}" "${URL}")
echo "${CMD[@]}"
if command "${CMD[@]}" > "${JSON_OUT}" ; then
"${JSON_TOOL}" < "${JSON_OUT}"
else
echo "Failed to obtain JSON";
exit 5;
fi
# Local Variables:
# compile-command: "shellcheck query_build_gating.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

87
scripts/builds/tag_rhel.sh Executable file
View File

@ -0,0 +1,87 @@
#!/bin/sh
# Copyright (C) 2026 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Tag public RHEL RPMs into gating for all supported streams
# This is intended to be run from tag_rhel_<ver>_(public|embargoed).sh
BUILD="${1}"
BUILDLOG="${2}"
SUFFIX="${3}"
shift 3;
SUPPORTED_VERS="$*"
CMD_SYNTAX="${0} <BUILD> <BUILDLOG> <SUFFIX> <SUPPORTED_VERS>";
GATE_SUFFIX="gate"
if test "${BUILD}" = ""; then
echo "${CMD_SYNTAX}";
exit 1;
fi
if test "${BUILDLOG}" = ""; then
echo "${CMD_SYNTAX}";
exit 2;
fi
if test "${SUPPORTED_VERS}" = ""; then
echo "${CMD_SYNTAX}";
exit 3;
fi
buildtags=$(grep "^Tag" "${BUILDLOG}" | cut -d : -f 2-)
echo "Build has tags ${buildtags}";
if [ "${SUFFIX}" = "${GATE_SUFFIX}" ] ; then
echo "Gating system can only handle one tag at a time."
echo "Script will need to be re-run for subsequent tags once previous tag has moved to -candidate."
if echo "${buildtags}" | grep -q "${GATE_SUFFIX}"; then
echo "Tag with \"-${GATE_SUFFIX}\" found. Please complete gating before re-running.";
exit 1;
fi
fi
done=0;
for ver in ${SUPPORTED_VERS}; do
vertag="rhel-${ver}";
proposedtag="${vertag}-${SUFFIX}";
echo "Checking if ${BUILD} has been added to ${vertag}...";
if echo "${buildtags}" | grep -q "${vertag}" ; then
echo "${BUILD} has been tagged into ${proposedtag}";
else
if [ "${SUFFIX}" = "${GATE_SUFFIX}" ] && [ "${done}" -eq 1 ]; then
echo "Already added a tag. Need to tag ${proposedtag} in a future run.";
else
echo "Tagging ${BUILD} into ${proposedtag}";
brew tag-build --nowait "${proposedtag}" "${BUILD}";
done=1;
fi
fi
done
if [ "${done}" -eq 1 ]; then
brew watch-task --mine;
else
echo "Nothing to do.";
fi
# Local Variables:
# compile-command: "shellcheck tag_rhel.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -0,0 +1,67 @@
#!/bin/sh
# Copyright (C) 2026 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Tag newer PQC embargoed RHEL 10 RPMs into supported z-streams
BUILD=${1}
if test "${BUILD}" = ""; then
echo "${0} <BUILD>";
exit 1;
fi
BUILDLOG=$(mktemp --tmpdir "temp-${BUILD}-buildinfo-XXX")
SUPPORTED_VERS="10.2-z 10.1-z"
WORKING_DIR=$(dirname "${0}")
EMBARGOED_SUFFIX="nocompose-candidate"
echo "Obtaining buildinfo for ${BUILD}...";
brew buildinfo "${BUILD}" 2>&1 | tee "${BUILDLOG}" > /dev/null
echo "Checking signatures for ${BUILD}...";
"${WORKING_DIR}"/check_signatures.sh "${BUILDLOG}"
# Return codes:
# - 1 - Buildinfo file not specified
# - 2 = Missing buildinfo file
# - 3 = No signatures
# - 4 = Multiple signature types found
# - 5 = PQC signature found
# - 6 = Old signature (fd431d51) found
# - 7 = Unknown signature found
ret=$?;
if [ "${ret}" -eq 6 ] ; then
echo "Build has old signatures which should not be the case for OpenJDK 25";
exit 2;
elif ! { [ "${ret}" -eq 6 ] || [ "${ret}" -eq 3 ] ; } ; then
echo "Signature check failed.";
exit 3;
fi
echo "Tagging embargoed build for ${SUPPORTED_VERS}...";
"${WORKING_DIR}"/tag_rhel.sh "${BUILD}" "${BUILDLOG}" "${EMBARGOED_SUFFIX}" "${SUPPORTED_VERS}"
rm -f "${BUILDLOG}"
# Local Variables:
# compile-command: "shellcheck tag_rhel_10_embargoed_pqc.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -0,0 +1,67 @@
#!/bin/sh
# Copyright (C) 2026 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Tag newer PQC public RHEL 10 RPMs into gating for all supported streams
BUILD=${1}
if test "${BUILD}" = ""; then
echo "${0} <BUILD>";
exit 1;
fi
BUILDLOG=$(mktemp --tmpdir "temp-${BUILD}-buildinfo-XXX")
SUPPORTED_VERS="10.3 10.2-z 10.1-z"
WORKING_DIR=$(dirname "${0}")
GATE_SUFFIX="gate"
echo "Obtaining buildinfo for ${BUILD}...";
brew buildinfo "${BUILD}" 2>&1 | tee "${BUILDLOG}" > /dev/null
echo "Checking signatures for ${BUILD}...";
"${WORKING_DIR}"/check_signatures.sh "${BUILDLOG}"
# Return codes:
# - 1 - Buildinfo file not specified
# - 2 = Missing buildinfo file
# - 3 = No signatures
# - 4 = Multiple signature types found
# - 5 = PQC signature found
# - 6 = Old signature (fd431d51) found
# - 7 = Unknown signature found
ret=$?;
if [ "${ret}" -eq 6 ] ; then
echo "Build has old signatures which should not be the case for OpenJDK 25";
exit 2;
elif ! { [ "${ret}" -eq 5 ] || [ "${ret}" -eq 3 ] ; } ; then
echo "Signature check failed.";
exit 3;
fi
echo "Tagging build into gating for ${SUPPORTED_VERS}...";
"${WORKING_DIR}"/tag_rhel.sh "${BUILD}" "${BUILDLOG}" "${GATE_SUFFIX}" "${SUPPORTED_VERS}"
rm -f "${BUILDLOG}"
# Local Variables:
# compile-command: "shellcheck tag_rhel_10_public_pqc.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -0,0 +1,67 @@
#!/bin/sh
# Copyright (C) 2026 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Tag newer PQC embargoed RHEL 9 RPMs into supported z-streams
BUILD=${1}
if test "${BUILD}" = ""; then
echo "${0} <BUILD>";
exit 1;
fi
BUILDLOG=$(mktemp --tmpdir "temp-${BUILD}-buildinfo-XXX")
SUPPORTED_VERS="9.8.0-z 9.7.0-z"
WORKING_DIR=$(dirname "${0}")
EMBARGOED_SUFFIX="nocompose-candidate"
echo "Obtaining buildinfo for ${BUILD}...";
brew buildinfo "${BUILD}" 2>&1 | tee "${BUILDLOG}" > /dev/null
echo "Checking signatures for ${BUILD}...";
"${WORKING_DIR}"/check_signatures.sh "${BUILDLOG}"
# Return codes:
# - 1 - Buildinfo file not specified
# - 2 = Missing buildinfo file
# - 3 = No signatures
# - 4 = Multiple signature types found
# - 5 = PQC signature found
# - 6 = Old signature (fd431d51) found
# - 7 = Unknown signature found
ret=$?;
if [ "${ret}" -eq 6 ] ; then
echo "Build has old signatures which should not be the case for OpenJDK 25";
exit 2;
elif ! { [ "${ret}" -eq 6 ] || [ "${ret}" -eq 3 ] ; } ; then
echo "Signature check failed.";
exit 3;
fi
echo "Tagging embargoed build for ${SUPPORTED_VERS}...";
"${WORKING_DIR}"/tag_rhel.sh "${BUILD}" "${BUILDLOG}" "${EMBARGOED_SUFFIX}" "${SUPPORTED_VERS}"
rm -f "${BUILDLOG}"
# Local Variables:
# compile-command: "shellcheck tag_rhel_9_embargoed_pqc.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -0,0 +1,67 @@
#!/bin/sh
# Copyright (C) 2026 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Tag newer PQC public RHEL 9 RPMs into gating for all supported streams
BUILD=${1}
if test "${BUILD}" = ""; then
echo "${0} <BUILD>";
exit 1;
fi
BUILDLOG=$(mktemp --tmpdir "temp-${BUILD}-buildinfo-XXX")
SUPPORTED_VERS="9.9.0 9.8.0-z 9.7.0-z"
WORKING_DIR=$(dirname "${0}")
GATE_SUFFIX="gate"
echo "Obtaining buildinfo for ${BUILD}...";
brew buildinfo "${BUILD}" 2>&1 | tee "${BUILDLOG}" > /dev/null
echo "Checking signatures for ${BUILD}...";
"${WORKING_DIR}"/check_signatures.sh "${BUILDLOG}"
# Return codes:
# - 1 - Buildinfo file not specified
# - 2 = Missing buildinfo file
# - 3 = No signatures
# - 4 = Multiple signature types found
# - 5 = PQC signature found
# - 6 = Old signature (fd431d51) found
# - 7 = Unknown signature found
ret=$?;
if [ "${ret}" -eq 6 ] ; then
echo "Build has old signatures which should not be the case for OpenJDK 25";
exit 2;
elif ! { [ "${ret}" -eq 5 ] || [ "${ret}" -eq 3 ] ; } ; then
echo "Signature check failed.";
exit 3;
fi
echo "Tagging build into gating for ${SUPPORTED_VERS}...";
"${WORKING_DIR}"/tag_rhel.sh "${BUILD}" "${BUILDLOG}" "${GATE_SUFFIX}" "${SUPPORTED_VERS}"
rm -f "${BUILDLOG}"
# Local Variables:
# compile-command: "shellcheck tag_rhel_9_public_pqc.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

132
scripts/builds/waive_issue.sh Executable file
View File

@ -0,0 +1,132 @@
#!/bin/bash
# Copyright (C) 2026 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Waive a gating issue
RHEL_VER=${1}
NVR=${2}
TESTCASE=${3}
COMMENT=${4}
CURL=$(command -v curl)
JSON_TOOL=$(command -v json_verify)
JSON_FORMAT=$(command -v jq)
JSON_FILE=$(mktemp --tmpdir waive.XXXXXX.json)
HEADER_FILE=$(mktemp --tmpdir waive.XXXXXX.headers)
JSON_OUT=$(mktemp --tmpdir out.XXXXXX.json)
CACERT=/etc/ssl/certs/2022-IT-Root-CA.pem
CACERT_DIR=$(dirname ${CACERT})
URL="https://waiverdb.engineering.redhat.com/api/v1.0/waivers/"
if test -z "${JSON_TOOL}" -o ! -x "${JSON_TOOL}" ; then
echo "JSON verifier not found. Skipping verification.";
SKIP_JSON=1;
else
SKIP_JSON=0;
fi
if test "${RHEL_VER}" = ""; then
echo "No RHEL version specified.";
echo "${0} <RHEL_VER> <NVR> <TESTCASE> <COMMENT>";
exit 1;
fi
if test "${NVR}" = ""; then
echo "No NVR specified.";
echo "${0} <RHEL_VER> <NVR> <TESTCASE> <COMMENT>";
exit 2;
fi
if test "${TESTCASE}" = ""; then
echo "No testcase specified.";
echo "${0} <RHEL_VER> <NVR> <TESTCASE> <COMMENT>";
exit 3;
fi
if test "${COMMENT}" = ""; then
COMMENT="Gating broken";
echo "Setting COMMENT to default of '${COMMENT}'"
fi
if test "${CURL}" = ""; then
echo "curl not found";
exit 4;
fi
if test "${JSON_FORMAT}" = ""; then
echo "jq not found";
exit 5;
fi
{
echo "{";
printf "\t\"subject_type\":\"brew-build\",\n";
printf "\t\"subject_identifier\":\"%s\",\n" "${NVR}";
printf "\t\"testcase\":\"%s\",\n" "${TESTCASE}";
printf "\t\"waived\":true,\n";
printf "\t\"product_version\":\"rhel-%d\",\n" "${RHEL_VER}"
printf "\t\"comment\":\"%s\"\n" "${COMMENT}";
echo "}"
} > "${JSON_FILE}"
if [ "${SKIP_JSON}" -eq 0 ] ; then
"${JSON_TOOL}" < "${JSON_FILE}" || exit 6;
fi
CMD=("${CURL}" --silent --show-error --capath "${CACERT_DIR}" --negotiate -u :)
JSON_COMMAND="--json";
# Check --json is available
${CURL} ${JSON_COMMAND} 2> /dev/null
if [ $? -eq 2 ] ; then
echo "--json unsupported; falling back on --data-binary";
{
echo "Content-Type: application/json";
echo "Accept: application/json";
} > "${HEADER_FILE}"
echo "Header file:";
cat "${HEADER_FILE}"
CMD=("${CMD[@]}" --header "@${HEADER_FILE}" --data-binary);
else
CMD=("${CMD[@]}" "${JSON_COMMAND}");
fi
CMD=("${CMD[@]}" "@${JSON_FILE}" "${URL}")
echo "Sending the following JSON...";
cat "${JSON_FILE}"
echo "${CMD[@]}"
if command "${CMD[@]}" > "${JSON_OUT}" ; then
"${JSON_FORMAT}" < "${JSON_OUT}"
else
echo "Failed to file waiver";
exit 7;
fi
rm -v "${JSON_FILE}"
rm -v "${HEADER_FILE}"
# Local Variables:
# compile-command: "shellcheck waive_issue.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -1,6 +1,6 @@
#!/bin/sh
# Copyright (C) 2024 Red Hat, Inc.
# Copyright (C) 2026 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
@ -17,26 +17,29 @@
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Builds the RPM on RHEL 8
# Waive the leapp gating test which never seems to work
NVR=${1}
USER=${2}
RHEL_VER=${1}
NVR=${2}
if test "${NVR}" = ""; then
echo "${0} <NVR> <USER>";
WORKING_DIR=$(dirname "${0}")
if test "${RHEL_VER}" = ""; then
echo "No RHEL version specified.";
echo "${0} <RHEL_VER> <NVR>";
exit 1;
fi
if test "${USER}" = ""; then
echo "${0} <NVR> <USER>";
if test "${NVR}" = ""; then
echo "No NVR specified.";
echo "${0} <RHEL_VER> <NVR>";
exit 2;
fi
METADATA="{\"osci\": {\"upstream_nvr\": \"${NVR}\", \"upstream_owner_name\": \"${USER}\"}, \"rhel-target\": \"latest\"}"
rhpkg -v build --target=java-openjdk-rhel-8-build --custom-user-metadata "${METADATA}"
"${WORKING_DIR}"/waive_issue.sh "${RHEL_VER}" "${NVR}" leapp.brew-build.upgrade.distro "AWOL"
# Local Variables:
# compile-command: "shellcheck build_rhel_8.sh"
# compile-command: "shellcheck waive_leapp_issue.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4

View File

@ -0,0 +1,53 @@
#!/bin/sh
# Copyright (C) 2026 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Waive a rpminspect gating issue
RHEL_VER=${1}
NVR=${2}
COMMENT=${3}
WORKING_DIR=$(dirname "${0}")
if test "${RHEL_VER}" = ""; then
echo "No RHEL version specified.";
echo "${0} <RHEL_VER> <NVR> <COMMENT>";
exit 1;
fi
if test "${NVR}" = ""; then
echo "No NVR specified.";
echo "${0} <RHEL_VER> <NVR> <COMMENT>";
exit 2;
fi
if test "${COMMENT}" = ""; then
echo "No comment specified.";
echo "${0} <RHEL_VER> <NVR> <COMMENT>";
exit 3;
fi
"${WORKING_DIR}"/waive_issue.sh "${RHEL_VER}" "${NVR}" osci.brew-build.rpminspect.static-analysis "${COMMENT}"
# Local Variables:
# compile-command: "shellcheck waive_rpminspect.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -0,0 +1,48 @@
#!/bin/sh
# Copyright (C) 2026 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Waive the recurring rpminspect gating issues
# Should be resolved by RHELPLAN-102267
WORKING_DIR=$(dirname "${0}")
RHEL_VER=${1}
NVR=${2}
if test "${RHEL_VER}" = ""; then
echo "No RHEL version specified.";
echo "${0} <RHEL_VER> <NVR>";
exit 1;
fi
if test "${NVR}" = ""; then
echo "No NVR specified.";
echo "${0} <RHEL_VER> <NVR>";
exit 2;
fi
"${WORKING_DIR}"/waive_rpminspect.sh "${RHEL_VER}" "${NVR}" \
"Usual failures we waived through rpmdiff; slowdebug unoptimised, RPATH and IPv4 functions"
# Local Variables:
# compile-command: "shellcheck waive_usual_rpminspect.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4
# End:

View File

@ -1,6 +1,6 @@
#!/bin/sh
# Copyright (C) 2024 Red Hat, Inc.
# Copyright (C) 2026 Red Hat, Inc.
# Written by:
# Andrew John Hughes <gnu.andrew@redhat.com>
#
@ -17,12 +17,30 @@
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
# Builds the portable on RHEL 7
# Waive the usual tier0 gating issue
# Should be resolved by OPENJDK-4517
rhpkg -v build --target=java-openjdk-rhel-7-build --skip-nvr-check
RHEL_VER=${1}
NVR=${2}
WORKING_DIR=$(dirname "${0}")
if test "${RHEL_VER}" = ""; then
echo "No RHEL version specified.";
echo "${0} <RHEL_VER> <NVR>";
exit 1;
fi
if test "${NVR}" = ""; then
echo "No NVR specified.";
echo "${0} <RHEL_VER> <NVR>";
exit 2;
fi
"${WORKING_DIR}"/waive_issue.sh "${RHEL_VER}" "${NVR}" osci.brew-build.tier0.functional "Test unable to parse spec file"
# Local Variables:
# compile-command: "shellcheck build_rhel_7_portable_build.sh"
# compile-command: "shellcheck waive_usual_tier0.sh"
# fill-column: 80
# indent-tabs-mode: nil
# sh-basic-offset: 4

View File

@ -98,7 +98,7 @@ else
echo "No apparent backouts.";
fi
printf "\nChecking for bundled library updates...";
if grep -iE ':( \(tz\))? update.*(freetype|gif|harfbuzz|lcms|jpeg|png|timezone|zlib)' "${TMPDIR}/fixes" > "${TMPDIR}/bundles"; then
if grep -iE ':( \(tz\))? (update|upgrade).*(freetype|gif|harfbuzz|lcms|jpeg|png|timezone|zlib)' "${TMPDIR}/fixes" > "${TMPDIR}/bundles"; then
printf "found.\nWARNING: Review the following with respect to bundled provides:\n";
cat "${TMPDIR}/bundles";
echo "Compare the output of $(dirname "${0}")/get_bundle_versions.sh with the RPM using the JDK source tree"

View File

@ -1,3 +1,3 @@
SHA512 (tapsets-icedtea-6.0.0pre00-c848b93a8598.tar.xz) = 97d026212363b3c83f6a04100ad7f6fdde833d16579717f8756e2b8c2eb70e144a41a330cb9ccde9c3badd37a2d54fdf4650a950ec21d8b686d545ecb2a64d30
SHA512 (openjdk-25.0.1+8.tar.xz) = eb84d876f81ca02803283e8294c89b6acbed3753426811c3bcc228615c9618deefc85da4aa702800cac2feb103e628ee8b92292b316e9d7e12a58b6de69c5085
SHA512 (nssadapter-0.1.0.tar.xz) = 581f49d1a27550e3a2fa0a9d407f43c507627a8439827904d14daaf24e071d9f73884a2abe4cb3d36d26f1af09ef7d20724b2d40c9bac202e0316fac6c1a636b
SHA512 (nssadapter-0.1.1.tar.xz) = 2b4675cfbfa2ccb6c9a4870a4b58ae555267f5b8c9bdb0cf37b075483e6e9ea929561c05070453cf0d67b0b029de5408274555bf2ff50e9533219e898b2717f9
SHA512 (openjdk-25.0.3+9.tar.xz) = 382dcf42ede35c7e48e0f9403d30172e6bc6367517e0c49211ab9d2e43373c3d7e586969c27795f0bfd17ae5c9f00702e955495a31d7ea757f54f06e8a4cf113