Compare commits

...
Sign in to create a new pull request.

33 commits

Author SHA1 Message Date
Yaakov Selkowitz
cbe66ee3a7 Restore gmp tarball to sources 2025-11-25 09:54:16 -05:00
Yaakov Selkowitz
33160d08cb Drop RHEL10-specific patch
The test was fixed to be FIPS-compliant:

https://gitlab.com/gnutls/gnutls/-/merge_requests/1932
2025-11-25 14:42:39 +00:00
Alexander Sosedkin
98206a06fe Disable native assembly to work around bz2416812 2025-11-25 10:30:27 +01:00
Daniel P. Berrangé
c5fcada2f3 Add missing Provides: bundled(..) for gmp & leancrypto
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2025-11-21 16:14:40 +09:00
Daiki Ueno
9f95ff6e69 Remove unnecessary PKG_CONFIG_PATH setting
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2025-11-21 16:12:20 +09:00
Daiki Ueno
3078b09e41 Enable crypto-auditing probes
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2025-11-21 11:48:31 +09:00
Daiki Ueno
7441432f8c Minor fixes to spec file and packit configuration
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2025-11-21 11:48:21 +09:00
Daiki Ueno
000d285047 Update to 3.8.11 upstream release
- Resolves: rhbz#2416041

Upstream tag: 3.8.11
Upstream commit: b841c70e

Commit authored by Packit automation (https://packit.dev/)
2025-11-20 19:40:16 +09:00
Krenzelok Frantisek
92cc61b531 Revert "Enable kTLS by default"
This reverts commit 330d52f8da.
2025-08-26 17:33:12 +02:00
Krenzelok Frantisek
330d52f8da Enable kTLS by default
Resolves: rhbz#2130000

- https://fedoraproject.org/wiki/Changes/KTLSSupportForGnuTLS.
- kTLS is now enabled by default if all requirements are met.
- Modify the docs to reflect the change of defaults.
- Picked-up a patch that fixes state transition in the KTLS code path.
2025-08-25 17:39:12 +02:00
Zoltan Fridrich
7be798d940 Rebuild
Signed-off-by: Zoltan Fridrich <zfridric@redhat.com>
2025-07-29 15:04:46 +02:00
Fedora Release Engineering
b690a96329 Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild 2025-07-23 22:53:49 +00:00
Daiki Ueno
e45aaed8ab Update to 3.8.10 upstream release
Also update the bundled leancrypto to 1.5.0.

Signed-off-by: Daiki Ueno <dueno@redhat.com>
2025-07-10 05:48:08 +09:00
Yaakov Selkowitz
25f7cc5fad Fix build on kernel 6.14+
kTLS KeyUpdate is supported as of this version, leading to the
ktls_keyupdate.sh being able to pass thereon, and therefore
the builder's kernel must now be checked here too.

https://gitlab.com/gnutls/gnutls/-/merge_requests/1934
2025-07-06 18:20:47 -04:00
Daiki Ueno
5bef1c86aa Update leancrypto to 1.3.0
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2025-04-02 17:34:52 +09:00
Peter Robinson
c3aaff5c62 Bump for gmp build 2025-03-30 11:46:20 +01:00
Zoltan Fridrich
63494651c6 Rebuild GnuTLS
Signed-off-by: Zoltan Fridrich <zfridric@redhat.com>
2025-03-03 11:17:54 +01:00
Daiki Ueno
6ea0d5328d Bump nettle dependency to 3.10.1
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2025-02-17 10:32:20 +09:00
Daiki Ueno
b5e51ef2d2 Rebuild against nettle 3.10.1
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2025-02-14 14:58:10 +09:00
Daiki Ueno
9c5597be5c Switch from liboqs to leancrypto
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2025-02-10 18:17:05 +09:00
Daiki Ueno
6c3a0c118e Update to gnutls 3.8.9 release
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2025-02-10 11:04:35 +09:00
Yaakov Selkowitz
e026bdad11 Fix ELN build
The bundled gmp (for RHEL builds) needs a C23 fix for a configure test:

https://src.fedoraproject.org/rpms/gmp/pull-request/8

Also, one test needs to be modified as the DEFAULT crypto policy rejects
TLS ciphers with RSA key exchange in RHEL 10:

https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10-beta/html/considerations_in_adopting_rhel_10/security#security
2025-02-05 11:30:38 -05:00
Daiki Ueno
c25fdb6fa9 Disable GOST in RHEL-9 or later
Resolves: RHEL-56919
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2025-01-22 23:17:41 -05:00
Fedora Release Engineering
8d60243b00 Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild 2025-01-16 23:06:20 +00:00
Daiki Ueno
abb8fe2e0b Update to 3.8.8 upstream release
- Resolves: rhbz#2323786

Upstream tag: 3.8.8
Upstream commit: 40267b5e

Commit authored by Packit automation (https://packit.dev/)
2024-11-05 16:44:35 +09:00
Daiki Ueno
db84cc7c55 Fix build with latest mingw-gcc
mingw{32,64}-cpp are not installed by default, and
--enable-local-libopts should be unnecessary, as we have switched away
from autogen.

Signed-off-by: Daiki Ueno <dueno@redhat.com>
2024-11-05 16:40:46 +09:00
Daiki Ueno
a9b00cffcc Update downstream patches for 3.8.8
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2024-11-05 14:51:06 +09:00
Daiki Ueno
f89c924634 Remove distribution suffix before updating to 3.8.8
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2024-11-05 14:20:20 +09:00
Richard W.M. Jones
760d4e32b2 Remove mingw p11tool.exe
Without mingw-p11-kit we don't build this.
2024-09-13 08:34:18 +01:00
Richard W.M. Jones
9ca47ed49e Remove mingw-p11-kit dependency (RHBZ#2312031) 2024-09-12 22:12:02 +01:00
Daiki Ueno
7d85f31654 Stop pulling in compression libraries through gnutls.pc
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2024-08-16 10:59:05 +09:00
Daiki Ueno
e9fcd31237 Update to 3.8.7 upstream release
- Resolves: rhbz#2305086

Upstream tag: 3.8.7
Upstream commit: 994d9392

Commit authored by Packit automation (https://packit.dev/)
2024-08-15 21:03:31 +09:00
Daiki Ueno
39c1bd20e2 Remove upstreamed patches before updating to 3.8.7
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2024-08-15 16:56:19 +09:00
11 changed files with 1635 additions and 69 deletions

16
.gitignore vendored
View file

@ -157,3 +157,19 @@ gnutls-2.10.1-nosrp.tar.bz2
/gnutls-3.8.6.tar.xz
/gnutls-3.8.6.tar.xz.sig
/gmp-6.2.1.tar.xz
/gnutls-3.8.7.tar.xz
/gnutls-3.8.7.tar.xz.sig
/gnutls-3.8.7.1.tar.xz
/gnutls-3.8.7.1.tar.xz.sig
/gnutls-3.8.8.tar.xz
/gnutls-3.8.8.tar.xz.sig
/gnutls-3.8.9.tar.xz
/gnutls-3.8.9.tar.xz.sig
/leancrypto-1.2.0.tar.gz
/leancrypto-1.3.0.tar.gz
/gnutls-3.8.10.tar.xz
/gnutls-3.8.10.tar.xz.sig
/leancrypto-1.5.0.tar.gz
/gnutls-3.8.11.tar.xz
/gnutls-3.8.11.tar.xz.sig
/leancrypto-1.6.0.tar.gz

View file

@ -28,5 +28,4 @@ actions:
jobs:
- job: propose_downstream
trigger: release
metadata:
dist_git_branches: fedora-all
dist_git_branches: fedora-all

View file

@ -1,3 +1,3 @@
This repository is maintained by packit.
https://packit.dev/
The file was generated using packit 0.97.3.
The file was generated using packit 1.12.0.

13
gmp-6.2.1-c23.patch Normal file
View file

@ -0,0 +1,13 @@
diff --git a/acinclude.m4 b/acinclude.m4
index 906071c..a466b7c 100644
--- a/acinclude.m4
+++ b/acinclude.m4
@@ -609,7 +609,7 @@ GMP_PROG_CC_WORKS_PART([$1], [long long reliability test 1],
#if defined (__GNUC__) && ! defined (__cplusplus)
typedef unsigned long long t1;typedef t1*t2;
-void g(){}
+void g(int, t2, t1, t2, t2, int){}
void h(){}
static __inline__ t1 e(t2 rp,t2 up,int n,t1 v0)
{t1 c,x,r;int i;if(v0){c=1;for(i=1;i<n;i++){x=up[i];r=x+1;rp[i]=r;}}return c;}

View file

@ -1,25 +0,0 @@
From 18c555b4d2461ad202996398609552b9c4ecd43b Mon Sep 17 00:00:00 2001
From: rpm-build <rpm-build>
Date: Wed, 22 Nov 2023 15:21:49 +0900
Subject: [PATCH] gnutls-3.7.8-ktls_skip_tls12_chachapoly_test.patch
Signed-off-by: rpm-build <rpm-build>
---
tests/gnutls_ktls.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/tests/gnutls_ktls.c b/tests/gnutls_ktls.c
index ccbe566..049c888 100644
--- a/tests/gnutls_ktls.c
+++ b/tests/gnutls_ktls.c
@@ -347,7 +347,6 @@ void doit(void)
{
run("NORMAL:-VERS-ALL:+VERS-TLS1.2:-CIPHER-ALL:+AES-128-GCM");
run("NORMAL:-VERS-ALL:+VERS-TLS1.2:-CIPHER-ALL:+AES-256-GCM");
- run("NORMAL:-VERS-ALL:+VERS-TLS1.2:-CIPHER-ALL:+CHACHA20-POLY1305");
run("NORMAL:-VERS-ALL:+VERS-TLS1.3:-CIPHER-ALL:+AES-128-GCM");
run("NORMAL:-VERS-ALL:+VERS-TLS1.3:-CIPHER-ALL:+AES-256-GCM");
run("NORMAL:-VERS-ALL:+VERS-TLS1.3:-CIPHER-ALL:+CHACHA20-POLY1305");
--
2.41.0

View file

@ -0,0 +1,114 @@
From e0eb2bbb212a5c9d72311c59e7235832a0075dcc Mon Sep 17 00:00:00 2001
From: rpm-build <rpm-build>
Date: Wed, 9 Jul 2025 18:54:48 +0900
Subject: [PATCH] add tests/ktls_utils.h
Signed-off-by: rpm-build <rpm-build>
---
tests/ktls_utils.h | 94 ++++++++++++++++++++++++++++++++++++++++++++++
1 file changed, 94 insertions(+)
create mode 100644 tests/ktls_utils.h
diff --git a/tests/ktls_utils.h b/tests/ktls_utils.h
new file mode 100644
index 0000000..231618d
--- /dev/null
+++ b/tests/ktls_utils.h
@@ -0,0 +1,94 @@
+#ifndef GNUTLS_TESTS_KTLS_UTILS_H
+#define GNUTLS_TESTS_KTLS_UTILS_H
+
+#include <fcntl.h>
+#include <signal.h>
+
+#include <netinet/in.h>
+
+#include <sys/socket.h>
+#include <sys/wait.h>
+
+/* Sets the NONBLOCK flag on the socket(fd) */
+inline static int set_nonblocking(int fd)
+{
+ int flags = fcntl(fd, F_GETFL, 0);
+ if (flags == -1) {
+ return 1;
+ }
+
+ if (fcntl(fd, F_SETFL, flags | O_NONBLOCK) == -1) {
+ return 2;
+ }
+
+ return 0;
+}
+
+/* Creates a pair of TCP connected sockets */
+static int create_socket_pair(int *client_fd, int *server_fd)
+{
+ int ret;
+ struct sockaddr_in saddr;
+ socklen_t addrlen;
+ int listener;
+
+ listener = socket(AF_INET, SOCK_STREAM, 0);
+ if (listener == -1) {
+ fail("error in listener(): %s\n", strerror(errno));
+ return 1;
+ }
+
+ int opt = 0;
+ setsockopt(listener, SOL_SOCKET, SO_REUSEADDR, &opt, sizeof(opt));
+
+ memset(&saddr, 0, sizeof(saddr));
+ saddr.sin_family = AF_INET;
+ saddr.sin_addr.s_addr = htonl(INADDR_LOOPBACK);
+ saddr.sin_port = 0;
+
+ ret = bind(listener, (struct sockaddr *)&saddr, sizeof(saddr));
+ if (ret == -1) {
+ fail("error in bind(): %s\n", strerror(errno));
+ return 1;
+ }
+
+ addrlen = sizeof(saddr);
+ ret = getsockname(listener, (struct sockaddr *)&saddr, &addrlen);
+ if (ret == -1) {
+ fail("error in getsockname(): %s\n", strerror(errno));
+ return 1;
+ }
+
+ ret = listen(listener, 1);
+ if (ret == -1) {
+ fail("error in listen(): %s\n", strerror(errno));
+ close(listener);
+ return 1;
+ }
+
+ *client_fd = socket(AF_INET, SOCK_STREAM, 0);
+ if (*client_fd < 0) {
+ fail("error in socket(): %s\n", strerror(errno));
+ return 1;
+ }
+
+ ret = connect(*client_fd, (struct sockaddr *)&saddr, addrlen);
+ if (ret < 0) {
+ fail("error in connect(): %s\n", strerror(errno));
+ close(listener);
+ close(*client_fd);
+ return 1;
+ }
+
+ *server_fd = accept(listener, NULL, NULL);
+ if (*server_fd < 0) {
+ fail("error in accept(): %s\n", strerror(errno));
+ close(listener);
+ close(*client_fd);
+ return 1;
+ }
+
+ return 0;
+}
+
+#endif //GNUTLS_TESTS_KTLS_UTILS_H
--
2.49.0

View file

@ -0,0 +1,58 @@
From 15fb5ad536c375a74cc0d87859c9fc919d924c9d Mon Sep 17 00:00:00 2001
From: rpm-build <rpm-build>
Date: Thu, 10 Jul 2025 05:45:06 +0900
Subject: [PATCH] support VPATH build for mldsa tests
Signed-off-by: rpm-build <rpm-build>
---
tests/cert-tests/mldsa.sh | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/tests/cert-tests/mldsa.sh b/tests/cert-tests/mldsa.sh
index 7e31e11..55e31ce 100644
--- a/tests/cert-tests/mldsa.sh
+++ b/tests/cert-tests/mldsa.sh
@@ -130,7 +130,7 @@ for variant in 44 65 87; do
# Check default
TMPKEYDEFAULT=$testdir/key-$algo-$format-default
TMPKEY=$testdir/key-$algo-$format
- ${VALGRIND} "${CERTTOOL}" -k --no-text --infile "data/key-$algo-$format.pem" >"$TMPKEYDEFAULT"
+ ${VALGRIND} "${CERTTOOL}" -k --no-text --infile "$srcdir/data/key-$algo-$format.pem" >"$TMPKEYDEFAULT"
if [ $? != 0 ]; then
cat "$TMPKEYDEFAULT"
exit 1
@@ -138,19 +138,19 @@ for variant in 44 65 87; do
# The "expandedKey" format doesn't have public key part
if [ "$format" = seed ] || [ "$format" = both ]; then
- if ! "${DIFF}" "$TMPKEYDEFAULT" "data/key-$algo-both.pem"; then
+ if ! "${DIFF}" "$TMPKEYDEFAULT" "$srcdir/data/key-$algo-both.pem"; then
exit 1
fi
fi
# Check roundtrip with --key-format
- ${VALGRIND} "${CERTTOOL}" -k --no-text --key-format "$format" --infile "data/key-$algo-$format.pem" >"$TMPKEY"
+ ${VALGRIND} "${CERTTOOL}" -k --no-text --key-format "$format" --infile "$srcdir/data/key-$algo-$format.pem" >"$TMPKEY"
if [ $? != 0 ]; then
cat "$TMPKEY"
exit 1
fi
- if ! "${DIFF}" "$TMPKEY" "data/key-$algo-$format.pem"; then
+ if ! "${DIFF}" "$TMPKEY" "$srcdir/data/key-$algo-$format.pem"; then
exit 1
fi
done
@@ -164,7 +164,7 @@ for n in 1; do
fi
echo "Testing inconsistent ML-DSA key ($n)"
- if "${CERTTOOL}" -k --infile "data/key-mldsa-inconsistent$n.pem"; then
+ if "${CERTTOOL}" -k --infile "$srcdir/data/key-mldsa-inconsistent$n.pem"; then
exit 1
fi
done
--
2.49.0

View file

@ -0,0 +1,29 @@
From a36b73a21e4b5b6e051b23192a645dea34c9d6af Mon Sep 17 00:00:00 2001
From: Daiki Ueno <ueno@gnu.org>
Date: Tue, 5 Nov 2024 14:45:46 +0900
Subject: [PATCH] tests: skip CHACHA20-POLY1305 in TLS 1.2 when KTLS is enabled
Signed-off-by: Daiki Ueno <ueno@gnu.org>
---
tests/gnutls_ktls.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/tests/gnutls_ktls.c b/tests/gnutls_ktls.c
index 90d3e9af91..d5ac4efecc 100644
--- a/tests/gnutls_ktls.c
+++ b/tests/gnutls_ktls.c
@@ -347,9 +347,11 @@ void doit(void)
{
run("NORMAL:-VERS-ALL:+VERS-TLS1.2:-CIPHER-ALL:+AES-128-GCM");
run("NORMAL:-VERS-ALL:+VERS-TLS1.2:-CIPHER-ALL:+AES-256-GCM");
+#if 0
if (!gnutls_fips140_mode_enabled()) {
run("NORMAL:-VERS-ALL:+VERS-TLS1.2:-CIPHER-ALL:+CHACHA20-POLY1305");
}
+#endif
run("NORMAL:-VERS-ALL:+VERS-TLS1.3:-CIPHER-ALL:+AES-128-GCM");
run("NORMAL:-VERS-ALL:+VERS-TLS1.3:-CIPHER-ALL:+AES-256-GCM");
if (!gnutls_fips140_mode_enabled()) {
--
2.47.0

File diff suppressed because it is too large Load diff

View file

@ -12,24 +12,26 @@ sha256sum:close()
print(string.sub(hash, 0, 16))
}
Version: 3.8.6
Version: 3.8.11
Release: %{?autorelease}%{!?autorelease:1%{?dist}}
Patch: gnutls-3.2.7-rpath.patch
# follow https://gitlab.com/gnutls/gnutls/-/issues/1443
Patch: gnutls-3.7.8-ktls_skip_tls12_chachapoly_test.patch
Patch: gnutls-3.8.6-compression-dlwrap.patch
Patch: gnutls-3.8.6-liboqs-x25519-kyber768d00.patch
Patch: gnutls-3.8.6-nettle-rsa-oaep.patch
Patch: gnutls-3.8.8-tests-ktls-skip-tls12-chachapoly.patch
%bcond_without bootstrap
%bcond_without dane
%bcond_without fips
%bcond_with tpm12
%bcond_without tpm2
%if 0%{?rhel} >= 9
%bcond_with gost
%else
%bcond_without gost
%endif
%bcond_without certificate_compression
%bcond_without liboqs
%bcond_without leancrypto
%bcond_without crypto_auditing
%bcond_without tests
%if 0%{?fedora} && 0%{?fedora} < 38
@ -67,13 +69,13 @@ BuildRequires: readline-devel, libtasn1-devel >= 4.3
%if %{with certificate_compression}
BuildRequires: zlib-devel, brotli-devel, libzstd-devel
%endif
%if %{with liboqs}
BuildRequires: liboqs-devel
%endif
%if %{with bootstrap}
BuildRequires: automake, autoconf, gperf, libtool, texinfo
%endif
BuildRequires: nettle-devel >= 3.10
BuildRequires: nettle-devel >= 3.10.1
%if %{with leancrypto}
BuildRequires: meson
%endif
%if %{with tpm12}
BuildRequires: trousers-devel >= 0.3.11.2
%endif
@ -85,6 +87,9 @@ BuildRequires: libunistring-devel
BuildRequires: net-tools, softhsm, gcc, gcc-c++
BuildRequires: gnupg2
BuildRequires: git-core
%if %{with crypto_auditing}
BuildRequires: systemtap-sdt-devel
%endif
# for a sanity check on cert loading
BuildRequires: p11-kit-trust, ca-certificates
@ -92,7 +97,7 @@ Requires: crypto-policies
Requires: p11-kit-trust
Requires: libtasn1 >= 4.3
# always bump when a nettle release is packaged
Requires: nettle >= 3.10
Requires: nettle >= 3.10.1
%if %{with tpm12}
Recommends: trousers >= 0.3.11.2
%endif
@ -103,21 +108,21 @@ BuildRequires: unbound-devel unbound-libs
BuildRequires: make gtk-doc
%if %{with mingw}
BuildRequires: mingw32-cpp
BuildRequires: mingw32-filesystem >= 95
BuildRequires: mingw32-gcc
BuildRequires: mingw32-gcc-c++
BuildRequires: mingw32-libtasn1 >= 4.3
BuildRequires: mingw32-readline
BuildRequires: mingw32-zlib
BuildRequires: mingw32-p11-kit >= 0.23.1
BuildRequires: mingw32-nettle >= 3.6
BuildRequires: mingw64-cpp
BuildRequires: mingw64-filesystem >= 95
BuildRequires: mingw64-gcc
BuildRequires: mingw64-gcc-c++
BuildRequires: mingw64-libtasn1 >= 4.3
BuildRequires: mingw64-readline
BuildRequires: mingw64-zlib
BuildRequires: mingw64-p11-kit >= 0.23.1
BuildRequires: mingw64-nettle >= 3.6
%endif
@ -128,9 +133,16 @@ Source1: https://www.gnupg.org/ftp/gcrypt/gnutls/v%{short_version}/%{name}-%{ver
Source2: https://gnutls.org/gnutls-release-keyring.gpg
%if %{with bundled_gmp}
Provides: bundled(gmp) = 6.2.1
Source100: gmp-6.2.1.tar.xz
# Taken from the main gmp package
Source101: gmp-6.2.1-intel-cet.patch
Source102: gmp-6.2.1-c23.patch
%endif
%if %{with leancrypto}
Provides: bundled(leancrypto) = 1.6.0
Source300: leancrypto-1.6.0.tar.gz
%endif
# Wildcard bundling exception https://fedorahosted.org/fpc/ticket/174
@ -261,12 +273,20 @@ mkdir -p bundled_gmp
pushd bundled_gmp
tar --strip-components=1 -xf %{SOURCE100}
patch -p1 < %{SOURCE101}
patch -p1 < %{SOURCE102}
popd
%endif
%build
%define _lto_cflags %{nil}
%if %{with leancrypto}
mkdir -p bundled_leancrypto
pushd bundled_leancrypto
tar --strip-components=1 -xf %{SOURCE300}
popd
%endif
%if %{with bundled_gmp}
pushd bundled_gmp
autoreconf -ifv
@ -278,6 +298,43 @@ export GMP_CFLAGS="-I$PWD/bundled_gmp"
export GMP_LIBS="$PWD/bundled_gmp/.libs/libgmp.a"
%endif
%if %{with leancrypto}
pushd bundled_leancrypto
%set_build_flags
meson setup -Dprefix="$PWD/install" -Dlibdir="$PWD/install/lib" \
-Ddefault_library=static \
-Dascon=disabled -Dascon_keccak=disabled \
-Dbike_5=disabled -Dbike_3=disabled -Dbike_1=disabled \
-Dkyber_x25519=disabled -Ddilithium_ed25519=disabled \
-Dx509_parser=disabled -Dx509_generator=disabled \
-Dpkcs7_parser=disabled -Dpkcs7_generator=disabled \
-Dsha2-256=disabled \
-Daes_gcm=disabled -Daes_cbc=disabled -Daes_ctr=disabled -Daes_xts=disabled \
-Dchacha20=disabled -Dchacha20poly1305=disabled -Dchacha20_drng=disabled \
-Ddrbg_hash=disabled -Ddrbg_hmac=disabled \
-Dhash_crypt=disabled \
-Dhmac=disabled -Dhkdf=disabled \
-Dkdf_ctr=disabled -Dkdf_fb=disabled -Dkdf_dpi=disabled \
-Dpbkdf2=disabled \
-Dkmac_drng=disabled -Dcshake_drng=disabled \
-Dhotp=disabled -Dtotp=disabled \
-Daes_block=disabled -Daes_cbc=disabled -Daes_ctr=disabled \
-Daes_kw=disabled -Dapps=disabled \
-Ddisable-asm=true \
_build
# the reason for -Ddisable-asm=true being bz2416812
# revert once the root cause is fixed
meson compile -C _build
meson install -C _build
popd
export LEANCRYPTO_DIR="$PWD/bundled_leancrypto/install"
export LEANCRYPTO_CFLAGS="-I$LEANCRYPTO_DIR/include"
export LEANCRYPTO_LIBS="$LEANCRYPTO_DIR/lib/libleancrypto.a"
%endif
%if %{with bootstrap}
autoreconf -fi
%endif
@ -297,6 +354,7 @@ export FIPS_MODULE_NAME="$OS_NAME ${OS_VERSION_ID%%.*} %name"
mkdir native_build
pushd native_build
%global _configure ../configure
%configure \
%if %{with fips}
@ -344,15 +402,23 @@ pushd native_build
%else
--without-zlib --without-brotli --without-zstd \
%endif
%if %{with liboqs}
--with-liboqs \
%if %{with leancrypto}
--with-leancrypto \
%else
--without-liboqs \
--without-leancrypto \
%endif
%if %{with crypto_auditing}
--enable-crypto-auditing \
%else
--disable-crypto-auditing \
%endif
--disable-rpath \
--with-default-priority-string="@SYSTEM"
%make_build
%if %{with leancrypto}
sed -i '/^Requires.private:/s/leancrypto[ ,]*//g' lib/gnutls.pc
%endif
popd
%if %{with mingw}
@ -370,12 +436,12 @@ export CCASFLAGS=""
--disable-rpath \
--disable-nls \
--disable-cxx \
--enable-local-libopts \
--enable-shared \
--without-tpm \
--with-included-unistring \
--disable-doc \
--with-default-priority-string="@SYSTEM"
--with-default-priority-string="@SYSTEM" \
--without-p11-kit
%mingw_make %{?_smp_mflags}
%endif
@ -443,22 +509,7 @@ rm -f $RPM_BUILD_ROOT%{mingw64_libdir}/ncrypt.dll*
%check
%if %{with tests}
pushd native_build
# KeyUpdate is not yet supported in the kernel.
xfail_tests=ktls_keyupdate.sh
# The ktls.sh test currently only supports kernel 5.11+. This needs to
# be checked at run time, as the koji builder might be using a different
# version of kernel on the host than the one indicated by the
# kernel-devel package.
case "$(uname -r)" in
4.* | 5.[0-9].* | 5.10.* )
xfail_tests="$xfail_tests ktls.sh"
;;
esac
make check %{?_smp_mflags} GNUTLS_SYSTEM_PRIORITY_FILE=/dev/null XFAIL_TESTS="$xfail_tests"
make check %{?_smp_mflags} GNUTLS_SYSTEM_PRIORITY_FILE=/dev/null || { cat tests/test-suite.log tests/cert-tests/test-suite.log tests/slow/test-suite.log src/gl/tests/test-suite.log; exit 1; }
popd
%endif
@ -468,7 +519,7 @@ popd
%{_libdir}/.libgnutls.so.30*.hmac
%endif
%doc README.md AUTHORS NEWS THANKS
%license LICENSE doc/COPYING doc/COPYING.LESSER
%license COPYING COPYING.LESSERv2
%files c++
%{_libdir}/libgnutlsxx.so.*
@ -512,14 +563,14 @@ popd
%if %{with mingw}
%files -n mingw32-%{name}
%license LICENSE doc/COPYING doc/COPYING.LESSER
%license COPYING COPYING.LESSERv2
%{mingw32_bindir}/certtool.exe
%{mingw32_bindir}/gnutls-cli-debug.exe
%{mingw32_bindir}/gnutls-cli.exe
%{mingw32_bindir}/gnutls-serv.exe
%{mingw32_bindir}/libgnutls-30.dll
%{mingw32_bindir}/ocsptool.exe
%{mingw32_bindir}/p11tool.exe
#%%{mingw32_bindir}/p11tool.exe
%{mingw32_bindir}/psktool.exe
%if %{with srp}
%{mingw32_bindir}/srptool.exe
@ -530,14 +581,14 @@ popd
%{mingw32_includedir}/gnutls/
%files -n mingw64-%{name}
%license LICENSE doc/COPYING doc/COPYING.LESSER
%license COPYING COPYING.LESSERv2
%{mingw64_bindir}/certtool.exe
%{mingw64_bindir}/gnutls-cli-debug.exe
%{mingw64_bindir}/gnutls-cli.exe
%{mingw64_bindir}/gnutls-serv.exe
%{mingw64_bindir}/libgnutls-30.dll
%{mingw64_bindir}/ocsptool.exe
%{mingw64_bindir}/p11tool.exe
#%%{mingw64_bindir}/p11tool.exe
%{mingw64_bindir}/psktool.exe
%if %{with srp}
%{mingw64_bindir}/srptool.exe

View file

@ -1,4 +1,5 @@
SHA512 (gnutls-3.8.6.tar.xz) = 58631c456dfb43f8cb6a1703ffa91c593a33357f37dc146e808d88692e19c7ac10aeabea40bee9952205be97e00648879e9f0fa80e670e8e695f8633ba726513
SHA512 (gnutls-3.8.6.tar.xz.sig) = 3f9552cdf5fa96184fbe394dd484fb55e6a3577d1e048aea373b82cda335ea0f174f2fb11926dc58532c1f950cd10a6a35bc36e9fe813a1259eae5c5364920b2
SHA512 (gnutls-3.8.11.tar.xz) = 68f9e5bec3aa6686fd3319cc9c88a5cc44e2a75144049fc9de5fb55fef2241b4e16996af4be5dd48308abbee8cfaed6c862903f6bb89aff5dfa5410075bd7386
SHA512 (gnutls-3.8.11.tar.xz.sig) = 90883e5736299b103844ca42b85d371969ef66b50b60cb185e814ad9978598796e9ed07a590245ff28ac6ac084b1dee93fae0845576464583a5941835990957d
SHA512 (gnutls-release-keyring.gpg) = 8c2b39239d1d8c5319757fcf669f28a11de7f8ec4a726f9904c57ba8105bea80240083c0de71b747115907bab46569f10cf58004137cc7884ac5c20f8319ae0a
SHA512 (gmp-6.2.1.tar.xz) = c99be0950a1d05a0297d65641dd35b75b74466f7bf03c9e8a99895a3b2f9a0856cd17887738fa51cf7499781b65c049769271cbcb77d057d2e9f1ec52e07dd84
SHA512 (leancrypto-1.6.0.tar.gz) = cb6ace4a1642208dd7656b62a48e99d6261f471aa7967b738057745a4534abfa11d380dd5de98a737c0c13b1e1cb37ce780e02297eefc1cf839581629d34e100