Compare commits
No commits in common. "rawhide" and "f40" have entirely different histories.
19 changed files with 5805 additions and 1744 deletions
8
.gitignore
vendored
8
.gitignore
vendored
|
|
@ -51,11 +51,3 @@
|
|||
/openjdk-24+34-ea.tar.xz
|
||||
/openjdk-24+36.tar.xz
|
||||
/openjdk-24.0.1+9.tar.xz
|
||||
/openjdk-24.0.2+12.tar.xz
|
||||
/openjdk-25+13-ea.tar.xz
|
||||
/openjdk-25+26-ea.tar.xz
|
||||
/openjdk-25+32-ea.tar.xz
|
||||
/openjdk-jdk-25+36.tar.xz
|
||||
/openjdk-25+36.tar.xz
|
||||
/openjdk-25.0.1+8.tar.xz
|
||||
/openjdk-26+29-ea.tar.xz
|
||||
|
|
|
|||
65
0001-8352692-Add-support-for-extra-jlink-options.patch
Normal file
65
0001-8352692-Add-support-for-extra-jlink-options.patch
Normal file
|
|
@ -0,0 +1,65 @@
|
|||
From bc0ebeddc31949a5d84a9494e8adccc2bade357e Mon Sep 17 00:00:00 2001
|
||||
From: Severin Gehwolf <sgehwolf@openjdk.org>
|
||||
Date: Wed, 26 Mar 2025 10:53:07 +0000
|
||||
Subject: [PATCH 1/2] 8352692: Add support for extra jlink options
|
||||
|
||||
Reviewed-by: ihse, erikj
|
||||
---
|
||||
make/Images.gmk | 4 ++++
|
||||
make/autoconf/jdk-options.m4 | 12 ++++++++++++
|
||||
make/autoconf/spec.gmk.template | 1 +
|
||||
3 files changed, 17 insertions(+)
|
||||
|
||||
diff --git a/make/Images.gmk b/make/Images.gmk
|
||||
index c5d0ef11b5d..cbaf85f7942 100644
|
||||
--- a/make/Images.gmk
|
||||
+++ b/make/Images.gmk
|
||||
@@ -101,6 +101,10 @@ ifeq ($(JLINK_PRODUCE_LINKABLE_RUNTIME), true)
|
||||
JLINK_JDK_EXTRA_OPTS += --generate-linkable-runtime
|
||||
endif
|
||||
|
||||
+ifneq ($(JLINK_USER_EXTRA_FLAGS), )
|
||||
+ JLINK_JDK_EXTRA_OPTS += $(JLINK_USER_EXTRA_FLAGS)
|
||||
+endif
|
||||
+
|
||||
$(eval $(call SetupExecute, jlink_jdk, \
|
||||
WARN := Creating jdk image, \
|
||||
DEPS := $(JDK_JMODS) $(BASE_RELEASE_FILE) \
|
||||
diff --git a/make/autoconf/jdk-options.m4 b/make/autoconf/jdk-options.m4
|
||||
index 61638ce5a2c..b6fce9cc323 100644
|
||||
--- a/make/autoconf/jdk-options.m4
|
||||
+++ b/make/autoconf/jdk-options.m4
|
||||
@@ -628,6 +628,18 @@ AC_DEFUN_ONCE([JDKOPT_SETUP_JLINK_OPTIONS],
|
||||
DEFAULT_DESC: [enabled by default unless --enable-linkable-runtime is set],
|
||||
CHECKING_MSG: [if packaged modules are kept])
|
||||
AC_SUBST(JLINK_KEEP_PACKAGED_MODULES)
|
||||
+
|
||||
+ ################################################################################
|
||||
+ #
|
||||
+ # Extra jlink options to be (optionally) passed to the JDK build
|
||||
+ #
|
||||
+ UTIL_ARG_WITH(NAME: extra-jlink-flags, TYPE: string,
|
||||
+ DEFAULT: [],
|
||||
+ DESC: [extra flags to be passed to jlink during the build],
|
||||
+ OPTIONAL: true)
|
||||
+
|
||||
+ JLINK_USER_EXTRA_FLAGS="$EXTRA_JLINK_FLAGS"
|
||||
+ AC_SUBST(JLINK_USER_EXTRA_FLAGS)
|
||||
])
|
||||
|
||||
################################################################################
|
||||
diff --git a/make/autoconf/spec.gmk.template b/make/autoconf/spec.gmk.template
|
||||
index 18770c6d360..63d5ce05147 100644
|
||||
--- a/make/autoconf/spec.gmk.template
|
||||
+++ b/make/autoconf/spec.gmk.template
|
||||
@@ -710,6 +710,7 @@ NEW_JAVADOC = $(INTERIM_LANGTOOLS_ARGS) $(JAVADOC_MAIN_CLASS)
|
||||
JMOD_COMPRESS := @JMOD_COMPRESS@
|
||||
JLINK_KEEP_PACKAGED_MODULES := @JLINK_KEEP_PACKAGED_MODULES@
|
||||
JLINK_PRODUCE_LINKABLE_RUNTIME := @JLINK_PRODUCE_LINKABLE_RUNTIME@
|
||||
+JLINK_USER_EXTRA_FLAGS := @JLINK_USER_EXTRA_FLAGS@
|
||||
|
||||
RCFLAGS := @RCFLAGS@
|
||||
|
||||
--
|
||||
2.49.0
|
||||
|
||||
830
0002-8352689-Allow-for-hash-sum-overrides-when-linking-fr.patch
Normal file
830
0002-8352689-Allow-for-hash-sum-overrides-when-linking-fr.patch
Normal file
|
|
@ -0,0 +1,830 @@
|
|||
From 2a5c9b874aa86b244dec041bed05ca3d1f66ccaa Mon Sep 17 00:00:00 2001
|
||||
From: Severin Gehwolf <sgehwolf@redhat.com>
|
||||
Date: Thu, 27 Mar 2025 14:50:54 +0100
|
||||
Subject: [PATCH 2/2] 8352689: Allow for hash sum overrides when linking from
|
||||
the run-time image
|
||||
|
||||
---
|
||||
.../jdk/tools/jlink/internal/JRTArchive.java | 34 +++++-
|
||||
.../jdk/tools/jlink/internal/Jlink.java | 12 +-
|
||||
.../jdk/tools/jlink/internal/JlinkTask.java | 72 +++++++++++-
|
||||
.../jlink/internal/LinkableRuntimeImage.java | 17 ++-
|
||||
.../tools/jlink/resources/jlink.properties | 6 +
|
||||
test/jdk/tools/jlink/IntegrationTest.java | 4 +-
|
||||
.../jlink/runtimeImage/AddOptionsTest.java | 1 -
|
||||
.../BasicJlinkMissingJavaBase.java | 1 -
|
||||
.../jlink/runtimeImage/BasicJlinkTest.java | 1 -
|
||||
.../runtimeImage/CustomModuleJlinkTest.java | 1 -
|
||||
.../runtimeImage/GenerateJLIClassesTest.java | 1 -
|
||||
.../runtimeImage/JavaSEReproducibleTest.java | 1 -
|
||||
.../KeepPackagedModulesFailTest.java | 1 -
|
||||
.../runtimeImage/ModifiedFilesExitTest.java | 1 -
|
||||
.../ModifiedFilesWarningTest.java | 1 -
|
||||
.../ModifiedFilesWithShaOverrideBase.java | 111 ++++++++++++++++++
|
||||
.../ModifiedFilesWithShaOverrideFileTest.java | 77 ++++++++++++
|
||||
.../ModifiedFilesWithShaOverrideTest.java | 65 ++++++++++
|
||||
.../jlink/runtimeImage/MultiHopTest.java | 1 -
|
||||
...PackagedModulesVsRuntimeImageLinkTest.java | 1 -
|
||||
.../PatchedJDKModuleJlinkTest.java | 1 -
|
||||
.../jlink/runtimeImage/SystemModulesTest.java | 1 -
|
||||
.../runtimeImage/SystemModulesTest2.java | 1 -
|
||||
23 files changed, 376 insertions(+), 36 deletions(-)
|
||||
create mode 100644 test/jdk/tools/jlink/runtimeImage/ModifiedFilesWithShaOverrideBase.java
|
||||
create mode 100644 test/jdk/tools/jlink/runtimeImage/ModifiedFilesWithShaOverrideFileTest.java
|
||||
create mode 100644 test/jdk/tools/jlink/runtimeImage/ModifiedFilesWithShaOverrideTest.java
|
||||
|
||||
diff --git a/src/jdk.jlink/share/classes/jdk/tools/jlink/internal/JRTArchive.java b/src/jdk.jlink/share/classes/jdk/tools/jlink/internal/JRTArchive.java
|
||||
index df7d35ac777..823d03c50fe 100644
|
||||
--- a/src/jdk.jlink/share/classes/jdk/tools/jlink/internal/JRTArchive.java
|
||||
+++ b/src/jdk.jlink/share/classes/jdk/tools/jlink/internal/JRTArchive.java
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
- * Copyright (c) 2024, Red Hat, Inc.
|
||||
+ * Copyright (c) 2024, 2025, Red Hat, Inc.
|
||||
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
|
||||
*
|
||||
* This code is free software; you can redistribute it and/or modify it
|
||||
@@ -41,10 +41,12 @@
|
||||
import java.util.ArrayList;
|
||||
import java.util.Arrays;
|
||||
import java.util.Collections;
|
||||
+import java.util.HashSet;
|
||||
import java.util.HexFormat;
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
import java.util.Objects;
|
||||
+import java.util.Set;
|
||||
import java.util.function.Function;
|
||||
import java.util.function.Predicate;
|
||||
import java.util.stream.Collectors;
|
||||
@@ -74,6 +76,7 @@ public class JRTArchive implements Archive {
|
||||
// Maps a module resource path to the corresponding diff to packaged
|
||||
// modules for that resource (if any)
|
||||
private final Map<String, ResourceDiff> resDiff;
|
||||
+ private final Map<String, Set<String>> altHashSums;
|
||||
private final boolean errorOnModifiedFile;
|
||||
private final TaskHelper taskHelper;
|
||||
|
||||
@@ -86,11 +89,15 @@ public class JRTArchive implements Archive {
|
||||
* install aborts the link.
|
||||
* @param perModDiff The lib/modules (a.k.a jimage) diff for this module,
|
||||
* possibly an empty list if there are no differences.
|
||||
+ * @param altHashSums A map of alternative hash sums for files in
|
||||
+ * a module, possibly empty.
|
||||
+ * @param taskHelper The task helper reference.
|
||||
*/
|
||||
JRTArchive(String module,
|
||||
Path path,
|
||||
boolean errorOnModifiedFile,
|
||||
List<ResourceDiff> perModDiff,
|
||||
+ Map<String, Set<String>> altHashSums,
|
||||
TaskHelper taskHelper) {
|
||||
this.module = module;
|
||||
this.path = path;
|
||||
@@ -105,6 +112,7 @@ public class JRTArchive implements Archive {
|
||||
this.resDiff = Objects.requireNonNull(perModDiff).stream()
|
||||
.collect(Collectors.toMap(ResourceDiff::getName, Function.identity()));
|
||||
this.taskHelper = taskHelper;
|
||||
+ this.altHashSums = altHashSums;
|
||||
}
|
||||
|
||||
@Override
|
||||
@@ -217,7 +225,21 @@ private void addNonClassResources() {
|
||||
|
||||
// Read from the base JDK image.
|
||||
Path path = BASE.resolve(m.resPath);
|
||||
- if (shaSumMismatch(path, m.hashOrTarget, m.symlink)) {
|
||||
+ // Allow for additional hash sums so as to support
|
||||
+ // file modifications done after jlink has run at build
|
||||
+ // time. For example for Windows builds done with
|
||||
+ // --with-external-symbols-in-bundles=public or
|
||||
+ // distribution builds, where some post-processing happens
|
||||
+ // on produced binaries and libraries invalidating the
|
||||
+ // hash sum included in the jdk.jlink module for those
|
||||
+ // files at jlink-time
|
||||
+ Set<String> shaSums = new HashSet<>();
|
||||
+ shaSums.add(m.hashOrTarget);
|
||||
+ Set<String> extra = altHashSums.get(m.resPath);
|
||||
+ if (extra != null) {
|
||||
+ shaSums.addAll(extra);
|
||||
+ }
|
||||
+ if (shaSumMismatch(path, shaSums, m.symlink)) {
|
||||
if (errorOnModifiedFile) {
|
||||
String msg = taskHelper.getMessage("err.runtime.link.modified.file", path.toString());
|
||||
IOException cause = new IOException(msg);
|
||||
@@ -239,14 +261,12 @@ private void addNonClassResources() {
|
||||
}
|
||||
}
|
||||
|
||||
- static boolean shaSumMismatch(Path res, String expectedSha, boolean isSymlink) {
|
||||
+ static boolean shaSumMismatch(Path res, Set<String> expectedShas, boolean isSymlink) {
|
||||
if (isSymlink) {
|
||||
return false;
|
||||
}
|
||||
// handle non-symlink resources
|
||||
try {
|
||||
- HexFormat format = HexFormat.of();
|
||||
- byte[] expected = format.parseHex(expectedSha);
|
||||
MessageDigest digest = MessageDigest.getInstance("SHA-512");
|
||||
try (InputStream is = Files.newInputStream(res)) {
|
||||
byte[] buf = new byte[1024];
|
||||
@@ -256,7 +276,9 @@ static boolean shaSumMismatch(Path res, String expectedSha, boolean isSymlink) {
|
||||
}
|
||||
}
|
||||
byte[] actual = digest.digest();
|
||||
- return !MessageDigest.isEqual(expected, actual);
|
||||
+ // Convert actual to string
|
||||
+ String strActual = HexFormat.of().formatHex(actual);
|
||||
+ return !expectedShas.contains(strActual);
|
||||
} catch (Exception e) {
|
||||
throw new AssertionError("SHA-512 sum check failed!", e);
|
||||
}
|
||||
diff --git a/src/jdk.jlink/share/classes/jdk/tools/jlink/internal/Jlink.java b/src/jdk.jlink/share/classes/jdk/tools/jlink/internal/Jlink.java
|
||||
index 99029651bfb..12e26bd4aef 100644
|
||||
--- a/src/jdk.jlink/share/classes/jdk/tools/jlink/internal/Jlink.java
|
||||
+++ b/src/jdk.jlink/share/classes/jdk/tools/jlink/internal/Jlink.java
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
- * Copyright (c) 2015, 2024, Oracle and/or its affiliates. All rights reserved.
|
||||
+ * Copyright (c) 2015, 2025, Oracle and/or its affiliates. All rights reserved.
|
||||
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
|
||||
*
|
||||
* This code is free software; you can redistribute it and/or modify it
|
||||
@@ -148,7 +148,7 @@ public static final class JlinkConfiguration {
|
||||
private final Set<String> modules;
|
||||
private final ModuleFinder finder;
|
||||
private final boolean linkFromRuntimeImage;
|
||||
- private final boolean ignoreModifiedRuntime;
|
||||
+ private final LinkableRuntimeImage.Config runtimeImageConfig;
|
||||
private final boolean generateRuntimeImage;
|
||||
|
||||
/**
|
||||
@@ -162,13 +162,13 @@ public JlinkConfiguration(Path output,
|
||||
Set<String> modules,
|
||||
ModuleFinder finder,
|
||||
boolean linkFromRuntimeImage,
|
||||
- boolean ignoreModifiedRuntime,
|
||||
+ LinkableRuntimeImage.Config runtimeImageConfig,
|
||||
boolean generateRuntimeImage) {
|
||||
this.output = output;
|
||||
this.modules = Objects.requireNonNull(modules);
|
||||
this.finder = finder;
|
||||
this.linkFromRuntimeImage = linkFromRuntimeImage;
|
||||
- this.ignoreModifiedRuntime = ignoreModifiedRuntime;
|
||||
+ this.runtimeImageConfig = runtimeImageConfig;
|
||||
this.generateRuntimeImage = generateRuntimeImage;
|
||||
}
|
||||
|
||||
@@ -198,8 +198,8 @@ public boolean linkFromRuntimeImage() {
|
||||
return linkFromRuntimeImage;
|
||||
}
|
||||
|
||||
- public boolean ignoreModifiedRuntime() {
|
||||
- return ignoreModifiedRuntime;
|
||||
+ public LinkableRuntimeImage.Config runtimeImageConfig() {
|
||||
+ return runtimeImageConfig;
|
||||
}
|
||||
|
||||
public boolean isGenerateRuntimeImage() {
|
||||
diff --git a/src/jdk.jlink/share/classes/jdk/tools/jlink/internal/JlinkTask.java b/src/jdk.jlink/share/classes/jdk/tools/jlink/internal/JlinkTask.java
|
||||
index 928b9a47934..bf63f7e6795 100644
|
||||
--- a/src/jdk.jlink/share/classes/jdk/tools/jlink/internal/JlinkTask.java
|
||||
+++ b/src/jdk.jlink/share/classes/jdk/tools/jlink/internal/JlinkTask.java
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
- * Copyright (c) 2015, 2024, Oracle and/or its affiliates. All rights reserved.
|
||||
+ * Copyright (c) 2015, 2025, Oracle and/or its affiliates. All rights reserved.
|
||||
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
|
||||
*
|
||||
* This code is free software; you can redistribute it and/or modify it
|
||||
@@ -191,7 +191,43 @@ public class JlinkTask {
|
||||
// be used for linking from the run-time image.
|
||||
new Option<JlinkTask>(false, (task, opt, arg) -> {
|
||||
task.options.generateLinkableRuntime = true;
|
||||
- }, true, "--generate-linkable-runtime")
|
||||
+ }, true, "--generate-linkable-runtime"),
|
||||
+ new Option<JlinkTask>(true, (task, opt, arg) -> {
|
||||
+ if (arg.startsWith("@")) {
|
||||
+ // Read overrides from file
|
||||
+ if (!task.options.shaOverrides.isEmpty()) {
|
||||
+ // Only allow a single @file value
|
||||
+ throw taskHelper.newBadArgs("err.sha.overrides.multiple");
|
||||
+ }
|
||||
+ // Ignore non-existing sha overrides file.
|
||||
+ //
|
||||
+ // This is to allow for custom builds needing to optionally
|
||||
+ // support run-time image links on (possibly) modified
|
||||
+ // binaries/debuginfo files done after the JDK build
|
||||
+ //
|
||||
+ // Allow for JAVA_HOME relative paths for the file, by replacing
|
||||
+ // the ${java.home} token in the file name
|
||||
+ String fileName = arg.substring(1);
|
||||
+ if (fileName.startsWith("${java.home}")) {
|
||||
+ String javaHome = System.getProperty("java.home");
|
||||
+ fileName = javaHome + fileName.substring(12 /* ${java.home}.length() */);
|
||||
+ }
|
||||
+ Path file = Paths.get(fileName);
|
||||
+ if (Files.exists(file)) {
|
||||
+ try {
|
||||
+ Files.readAllLines(file).stream()
|
||||
+ .forEach(task.options.shaOverrides::add);
|
||||
+ } catch (IOException e) {
|
||||
+ throw taskHelper.newBadArgs("err.sha.overrides.freaderr", file.toString());
|
||||
+ }
|
||||
+ }
|
||||
+ } else {
|
||||
+ // Allow multiple values, separated by comma in addition to
|
||||
+ // multiple times the same option.
|
||||
+ Arrays.asList(arg.split(",")).stream()
|
||||
+ .forEach(task.options.shaOverrides::add);
|
||||
+ }
|
||||
+ }, true, "--sha-overrides"),
|
||||
};
|
||||
|
||||
|
||||
@@ -235,6 +271,7 @@ static class OptionsValues {
|
||||
boolean suggestProviders = false;
|
||||
boolean ignoreModifiedRuntime = false;
|
||||
boolean generateLinkableRuntime = false;
|
||||
+ final Set<String> shaOverrides = new HashSet<>();
|
||||
}
|
||||
|
||||
public static final String OPTIONS_RESOURCE = "jdk/tools/jlink/internal/options";
|
||||
@@ -459,14 +496,41 @@ private JlinkConfiguration initJlinkConfig() throws BadArgs {
|
||||
throw taskHelper.newBadArgs("err.runtime.link.packaged.mods");
|
||||
}
|
||||
|
||||
+ LinkableRuntimeImage.Config linkableRuntimeConfig = new LinkableRuntimeImage.Config(
|
||||
+ options.ignoreModifiedRuntime,
|
||||
+ isLinkFromRuntime ? buildShaSumMap(taskHelper, options.shaOverrides) : null);
|
||||
return new JlinkConfiguration(options.output,
|
||||
roots,
|
||||
finder,
|
||||
isLinkFromRuntime,
|
||||
- options.ignoreModifiedRuntime,
|
||||
+ linkableRuntimeConfig,
|
||||
options.generateLinkableRuntime);
|
||||
}
|
||||
|
||||
+ private Map<String, Map<String, Set<String>>> buildShaSumMap(TaskHelper taskHelper,
|
||||
+ Set<String> shaOverrides) throws BadArgs {
|
||||
+ Map<String, Map<String, Set<String>>> moduleToFiles = new HashMap<>();
|
||||
+ for (String t: shaOverrides) {
|
||||
+ String trimmed = t.trim();
|
||||
+ if (trimmed.startsWith("#")) {
|
||||
+ // skip comment lines
|
||||
+ continue;
|
||||
+ }
|
||||
+ String[] tokens = trimmed.split("\\|");
|
||||
+ if (tokens.length != 3) {
|
||||
+ throw taskHelper.newBadArgs("err.sha.overrides.bad.format", t);
|
||||
+ }
|
||||
+ // t is a '|'-separated item of (in that order):
|
||||
+ // <module-name>
|
||||
+ // <file-path>
|
||||
+ // <SHA-512-sum>
|
||||
+ Map<String, Set<String>> perModuleMap = moduleToFiles.computeIfAbsent(tokens[0], k -> new HashMap<>());
|
||||
+ Set<String> shaSumsPerFile = perModuleMap.computeIfAbsent(tokens[1], k -> new HashSet<>());
|
||||
+ shaSumsPerFile.add(tokens[2]);
|
||||
+ }
|
||||
+ return moduleToFiles;
|
||||
+ }
|
||||
+
|
||||
/*
|
||||
* Creates a ModuleFinder for the given module paths.
|
||||
*/
|
||||
@@ -788,7 +852,7 @@ private static Archive newArchive(String module,
|
||||
taskHelper.getMessage("err.not.a.module.directory", path));
|
||||
}
|
||||
} else if (config.linkFromRuntimeImage()) {
|
||||
- return LinkableRuntimeImage.newArchive(module, path, config.ignoreModifiedRuntime(), taskHelper);
|
||||
+ return LinkableRuntimeImage.newArchive(module, path, config.runtimeImageConfig(), taskHelper);
|
||||
} else {
|
||||
throw new IllegalArgumentException(
|
||||
taskHelper.getMessage("err.not.modular.format", module, path));
|
||||
diff --git a/src/jdk.jlink/share/classes/jdk/tools/jlink/internal/LinkableRuntimeImage.java b/src/jdk.jlink/share/classes/jdk/tools/jlink/internal/LinkableRuntimeImage.java
|
||||
index 935af4585ad..a9b146d55a2 100644
|
||||
--- a/src/jdk.jlink/share/classes/jdk/tools/jlink/internal/LinkableRuntimeImage.java
|
||||
+++ b/src/jdk.jlink/share/classes/jdk/tools/jlink/internal/LinkableRuntimeImage.java
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
- * Copyright (c) 2024, Red Hat, Inc.
|
||||
+ * Copyright (c) 2024, 2025, Red Hat, Inc.
|
||||
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
|
||||
*
|
||||
* This code is free software; you can redistribute it and/or modify it
|
||||
@@ -29,6 +29,8 @@
|
||||
import java.io.InputStream;
|
||||
import java.nio.file.Path;
|
||||
import java.util.List;
|
||||
+import java.util.Map;
|
||||
+import java.util.Set;
|
||||
|
||||
import jdk.tools.jlink.internal.runtimelink.ResourceDiff;
|
||||
|
||||
@@ -67,7 +69,7 @@ private static InputStream getDiffInputStream(String module) throws IOException
|
||||
|
||||
public static Archive newArchive(String module,
|
||||
Path path,
|
||||
- boolean ignoreModifiedRuntime,
|
||||
+ Config config,
|
||||
TaskHelper taskHelper) {
|
||||
assert isLinkableRuntime();
|
||||
// Here we retrieve the per module difference file, which is
|
||||
@@ -81,8 +83,15 @@ public static Archive newArchive(String module,
|
||||
throw new AssertionError("Failure to retrieve resource diff for " +
|
||||
"module " + module, e);
|
||||
}
|
||||
- return new JRTArchive(module, path, !ignoreModifiedRuntime, perModuleDiff, taskHelper);
|
||||
+ return new JRTArchive(module,
|
||||
+ path,
|
||||
+ !config.ignoreModifiedRuntime,
|
||||
+ perModuleDiff,
|
||||
+ // Empty map if no alternative sha sums
|
||||
+ config.altHashSums.computeIfAbsent(module, k -> Map.of()),
|
||||
+ taskHelper);
|
||||
}
|
||||
|
||||
-
|
||||
+ static record Config(boolean ignoreModifiedRuntime,
|
||||
+ Map<String, Map<String, Set<String>>> altHashSums) {}
|
||||
}
|
||||
diff --git a/src/jdk.jlink/share/classes/jdk/tools/jlink/resources/jlink.properties b/src/jdk.jlink/share/classes/jdk/tools/jlink/resources/jlink.properties
|
||||
index a491b758ea0..59f5860d131 100644
|
||||
--- a/src/jdk.jlink/share/classes/jdk/tools/jlink/resources/jlink.properties
|
||||
+++ b/src/jdk.jlink/share/classes/jdk/tools/jlink/resources/jlink.properties
|
||||
@@ -127,6 +127,12 @@ err.runtime.link.packaged.mods=This JDK has no packaged modules.\
|
||||
err.runtime.link.modified.file={0} has been modified
|
||||
err.runtime.link.patched.module=jlink does not support linking from the run-time image\
|
||||
\ when running on a patched runtime with --patch-module
|
||||
+
|
||||
+# Linking from the run-time image, SHA sum handling
|
||||
+err.sha.overrides.multiple=option --sha-overrides does not allow @file and non-file combinations
|
||||
+err.sha.overrides.freaderr=Error reading file ''{0}'' passed with option --sha-overrides
|
||||
+err.sha.overrides.bad.format=Bad format in --sha-overrides. Token was {0}. Expected <module-name>|<file-path>|<sha-sum>
|
||||
+
|
||||
err.no.module.path=--module-path option must be specified with --add-modules ALL-MODULE-PATH
|
||||
err.empty.module.path=No module found in module path ''{0}'' with --add-modules ALL-MODULE-PATH
|
||||
err.limit.modules=--limit-modules not allowed with --add-modules ALL-MODULE-PATH
|
||||
diff --git a/test/jdk/tools/jlink/IntegrationTest.java b/test/jdk/tools/jlink/IntegrationTest.java
|
||||
index 5a8d0bce15a..818c31b9eef 100644
|
||||
--- a/test/jdk/tools/jlink/IntegrationTest.java
|
||||
+++ b/test/jdk/tools/jlink/IntegrationTest.java
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
- * Copyright (c) 2015, 2024, Oracle and/or its affiliates. All rights reserved.
|
||||
+ * Copyright (c) 2015, 2025, Oracle and/or its affiliates. All rights reserved.
|
||||
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
|
||||
*
|
||||
* This code is free software; you can redistribute it and/or modify it
|
||||
@@ -159,7 +159,7 @@ private static void test() throws Exception {
|
||||
mods,
|
||||
JlinkTask.limitFinder(JlinkTask.newModuleFinder(modulePaths), limits, mods),
|
||||
linkFromRuntime,
|
||||
- false /* ignore modified runtime */,
|
||||
+ null /* run-time image link config */,
|
||||
false /* generate run-time image */);
|
||||
|
||||
List<Plugin> lst = new ArrayList<>();
|
||||
diff --git a/test/jdk/tools/jlink/runtimeImage/AddOptionsTest.java b/test/jdk/tools/jlink/runtimeImage/AddOptionsTest.java
|
||||
index 827f7da624d..4f25bc3ee66 100644
|
||||
--- a/test/jdk/tools/jlink/runtimeImage/AddOptionsTest.java
|
||||
+++ b/test/jdk/tools/jlink/runtimeImage/AddOptionsTest.java
|
||||
@@ -33,7 +33,6 @@
|
||||
* @summary Test --add-options jlink plugin when linking from the run-time image
|
||||
* @requires (vm.compMode != "Xcomp" & os.maxMemory >= 2g)
|
||||
* @library ../../lib /test/lib
|
||||
- * @enablePreview
|
||||
* @modules java.base/jdk.internal.jimage
|
||||
* jdk.jlink/jdk.tools.jlink.internal
|
||||
* jdk.jlink/jdk.tools.jlink.plugin
|
||||
diff --git a/test/jdk/tools/jlink/runtimeImage/BasicJlinkMissingJavaBase.java b/test/jdk/tools/jlink/runtimeImage/BasicJlinkMissingJavaBase.java
|
||||
index ebf5b060665..cb28f6f2b86 100644
|
||||
--- a/test/jdk/tools/jlink/runtimeImage/BasicJlinkMissingJavaBase.java
|
||||
+++ b/test/jdk/tools/jlink/runtimeImage/BasicJlinkMissingJavaBase.java
|
||||
@@ -34,7 +34,6 @@
|
||||
* but java.xml.jmod present. It should link from the run-time image without errors.
|
||||
* @requires (jlink.packagedModules & vm.compMode != "Xcomp" & os.maxMemory >= 2g)
|
||||
* @library ../../lib /test/lib
|
||||
- * @enablePreview
|
||||
* @modules java.base/jdk.internal.jimage
|
||||
* jdk.jlink/jdk.tools.jlink.internal
|
||||
* jdk.jlink/jdk.tools.jlink.plugin
|
||||
diff --git a/test/jdk/tools/jlink/runtimeImage/BasicJlinkTest.java b/test/jdk/tools/jlink/runtimeImage/BasicJlinkTest.java
|
||||
index 8cbd74e5ed1..f82c16c036d 100644
|
||||
--- a/test/jdk/tools/jlink/runtimeImage/BasicJlinkTest.java
|
||||
+++ b/test/jdk/tools/jlink/runtimeImage/BasicJlinkTest.java
|
||||
@@ -32,7 +32,6 @@
|
||||
* @summary Test basic linking from the run-time image
|
||||
* @requires (vm.compMode != "Xcomp" & os.maxMemory >= 2g)
|
||||
* @library ../../lib /test/lib
|
||||
- * @enablePreview
|
||||
* @modules java.base/jdk.internal.jimage
|
||||
* jdk.jlink/jdk.tools.jlink.internal
|
||||
* jdk.jlink/jdk.tools.jlink.plugin
|
||||
diff --git a/test/jdk/tools/jlink/runtimeImage/CustomModuleJlinkTest.java b/test/jdk/tools/jlink/runtimeImage/CustomModuleJlinkTest.java
|
||||
index d6c237a173b..15cd88ae9fc 100644
|
||||
--- a/test/jdk/tools/jlink/runtimeImage/CustomModuleJlinkTest.java
|
||||
+++ b/test/jdk/tools/jlink/runtimeImage/CustomModuleJlinkTest.java
|
||||
@@ -32,7 +32,6 @@
|
||||
* @summary Test jmod-less jlink with a custom module
|
||||
* @requires (vm.compMode != "Xcomp" & os.maxMemory >= 2g)
|
||||
* @library ../../lib /test/lib
|
||||
- * @enablePreview
|
||||
* @modules java.base/jdk.internal.jimage
|
||||
* jdk.jlink/jdk.tools.jlink.internal
|
||||
* jdk.jlink/jdk.tools.jlink.plugin
|
||||
diff --git a/test/jdk/tools/jlink/runtimeImage/GenerateJLIClassesTest.java b/test/jdk/tools/jlink/runtimeImage/GenerateJLIClassesTest.java
|
||||
index e59d18bd6f0..2a45d920f2d 100644
|
||||
--- a/test/jdk/tools/jlink/runtimeImage/GenerateJLIClassesTest.java
|
||||
+++ b/test/jdk/tools/jlink/runtimeImage/GenerateJLIClassesTest.java
|
||||
@@ -32,7 +32,6 @@
|
||||
* @summary Verify JLI class generation in run-time image link mode
|
||||
* @requires (vm.compMode != "Xcomp" & os.maxMemory >= 2g)
|
||||
* @library ../../lib /test/lib
|
||||
- * @enablePreview
|
||||
* @modules java.base/jdk.internal.jimage
|
||||
* jdk.jlink/jdk.tools.jlink.internal
|
||||
* jdk.jlink/jdk.tools.jlink.plugin
|
||||
diff --git a/test/jdk/tools/jlink/runtimeImage/JavaSEReproducibleTest.java b/test/jdk/tools/jlink/runtimeImage/JavaSEReproducibleTest.java
|
||||
index a376d075ecd..b2137b7b94d 100644
|
||||
--- a/test/jdk/tools/jlink/runtimeImage/JavaSEReproducibleTest.java
|
||||
+++ b/test/jdk/tools/jlink/runtimeImage/JavaSEReproducibleTest.java
|
||||
@@ -33,7 +33,6 @@
|
||||
* image.
|
||||
* @requires (vm.compMode != "Xcomp" & os.maxMemory >= 2g)
|
||||
* @library ../../lib /test/lib
|
||||
- * @enablePreview
|
||||
* @modules java.base/jdk.internal.jimage
|
||||
* jdk.jlink/jdk.tools.jlink.internal
|
||||
* jdk.jlink/jdk.tools.jlink.plugin
|
||||
diff --git a/test/jdk/tools/jlink/runtimeImage/KeepPackagedModulesFailTest.java b/test/jdk/tools/jlink/runtimeImage/KeepPackagedModulesFailTest.java
|
||||
index 6fdaf5a9824..2b13043b1db 100644
|
||||
--- a/test/jdk/tools/jlink/runtimeImage/KeepPackagedModulesFailTest.java
|
||||
+++ b/test/jdk/tools/jlink/runtimeImage/KeepPackagedModulesFailTest.java
|
||||
@@ -34,7 +34,6 @@
|
||||
* --keep-packaged-modules fails as expected.
|
||||
* @requires (vm.compMode != "Xcomp" & os.maxMemory >= 2g)
|
||||
* @library ../../lib /test/lib
|
||||
- * @enablePreview
|
||||
* @modules java.base/jdk.internal.jimage
|
||||
* jdk.jlink/jdk.tools.jlink.internal
|
||||
* jdk.jlink/jdk.tools.jlink.plugin
|
||||
diff --git a/test/jdk/tools/jlink/runtimeImage/ModifiedFilesExitTest.java b/test/jdk/tools/jlink/runtimeImage/ModifiedFilesExitTest.java
|
||||
index 777ce302ce7..b318418de16 100644
|
||||
--- a/test/jdk/tools/jlink/runtimeImage/ModifiedFilesExitTest.java
|
||||
+++ b/test/jdk/tools/jlink/runtimeImage/ModifiedFilesExitTest.java
|
||||
@@ -33,7 +33,6 @@
|
||||
* and files have been modified
|
||||
* @requires (vm.compMode != "Xcomp" & os.maxMemory >= 2g)
|
||||
* @library ../../lib /test/lib
|
||||
- * @enablePreview
|
||||
* @modules java.base/jdk.internal.jimage
|
||||
* jdk.jlink/jdk.tools.jlink.internal
|
||||
* jdk.jlink/jdk.tools.jlink.plugin
|
||||
diff --git a/test/jdk/tools/jlink/runtimeImage/ModifiedFilesWarningTest.java b/test/jdk/tools/jlink/runtimeImage/ModifiedFilesWarningTest.java
|
||||
index c871024f37c..a309f5cbbc5 100644
|
||||
--- a/test/jdk/tools/jlink/runtimeImage/ModifiedFilesWarningTest.java
|
||||
+++ b/test/jdk/tools/jlink/runtimeImage/ModifiedFilesWarningTest.java
|
||||
@@ -32,7 +32,6 @@
|
||||
* image and files have been modified
|
||||
* @requires (vm.compMode != "Xcomp" & os.maxMemory >= 2g)
|
||||
* @library ../../lib /test/lib
|
||||
- * @enablePreview
|
||||
* @modules java.base/jdk.internal.jimage
|
||||
* jdk.jlink/jdk.tools.jlink.internal
|
||||
* jdk.jlink/jdk.tools.jlink.plugin
|
||||
diff --git a/test/jdk/tools/jlink/runtimeImage/ModifiedFilesWithShaOverrideBase.java b/test/jdk/tools/jlink/runtimeImage/ModifiedFilesWithShaOverrideBase.java
|
||||
new file mode 100644
|
||||
index 00000000000..529fbda2ef9
|
||||
--- /dev/null
|
||||
+++ b/test/jdk/tools/jlink/runtimeImage/ModifiedFilesWithShaOverrideBase.java
|
||||
@@ -0,0 +1,111 @@
|
||||
+/*
|
||||
+ * Copyright (c) 2025, Red Hat, Inc.
|
||||
+ * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
|
||||
+ *
|
||||
+ * This code is free software; you can redistribute it and/or modify it
|
||||
+ * under the terms of the GNU General Public License version 2 only, as
|
||||
+ * published by the Free Software Foundation.
|
||||
+ *
|
||||
+ * This code is distributed in the hope that it will be useful, but WITHOUT
|
||||
+ * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
||||
+ * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
+ * version 2 for more details (a copy is included in the LICENSE file that
|
||||
+ * accompanied this code).
|
||||
+ *
|
||||
+ * You should have received a copy of the GNU General Public License version
|
||||
+ * 2 along with this work; if not, write to the Free Software Foundation,
|
||||
+ * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||
+ *
|
||||
+ * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
|
||||
+ * or visit www.oracle.com if you need additional information or have any
|
||||
+ * questions.
|
||||
+ */
|
||||
+
|
||||
+import java.io.IOException;
|
||||
+import java.io.InputStream;
|
||||
+import java.nio.file.Files;
|
||||
+import java.nio.file.Path;
|
||||
+import java.security.MessageDigest;
|
||||
+import java.util.ArrayList;
|
||||
+import java.util.HexFormat;
|
||||
+import java.util.List;
|
||||
+
|
||||
+import jdk.test.lib.process.OutputAnalyzer;
|
||||
+import jtreg.SkippedException;
|
||||
+import tests.Helper;
|
||||
+
|
||||
+/*
|
||||
+ * Base class for sha overrides tests
|
||||
+ */
|
||||
+public abstract class ModifiedFilesWithShaOverrideBase extends ModifiedFilesTest {
|
||||
+
|
||||
+ protected static final String SHA_OVERRIDE_FLAG = "--sha-overrides";
|
||||
+
|
||||
+ @Override
|
||||
+ protected Path modifyFileInImage(Path jmodLessImg) {
|
||||
+ try {
|
||||
+ Path libJVM = jmodLessImg.resolve("lib").resolve("server").resolve(System.mapLibraryName("jvm"));
|
||||
+ String shaBefore = buildSHA512(libJVM);
|
||||
+ List<String> objcopy = new ArrayList<>();
|
||||
+ objcopy.add("objcopy");
|
||||
+ // The OpenJDK build doesn't strip all symbols by default. In order
|
||||
+ // to get a different libjvm.so file, we strip everything. The
|
||||
+ // expectation is for the sha to be different before and after the
|
||||
+ // stripping of the file.
|
||||
+ objcopy.add("--strip-all");
|
||||
+ objcopy.add(libJVM.toString());
|
||||
+ ProcessBuilder builder = new ProcessBuilder(objcopy);
|
||||
+ Process p = builder.start();
|
||||
+ int returnVal = p.waitFor();
|
||||
+ if (returnVal != 0) {
|
||||
+ throw new SkippedException("Stripping of libjvm failed. Is objcopy installed?");
|
||||
+ }
|
||||
+ String shaAfter = buildSHA512(libJVM);
|
||||
+ if (shaBefore.equals(shaAfter)) {
|
||||
+ throw new SkippedException("Binary file would be the same before after - test skipped");
|
||||
+ }
|
||||
+ return libJVM;
|
||||
+ } catch (IOException | InterruptedException e) {
|
||||
+ throw new SkippedException("Stripping of libjvm failed: " + e.getMessage());
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ @Override
|
||||
+ void testAndAssert(Path modifiedFile, Helper helper, Path initialImage) throws Exception {
|
||||
+ String extraJlinkOption = getShaOverrideOption(modifiedFile, initialImage);
|
||||
+ CapturingHandler handler = new CapturingHandler();
|
||||
+ jlinkUsingImage(new JlinkSpecBuilder()
|
||||
+ .helper(helper)
|
||||
+ .imagePath(initialImage)
|
||||
+ .name(getTargetName())
|
||||
+ .addModule("java.base")
|
||||
+ .validatingModule("java.base")
|
||||
+ .extraJlinkOpt(extraJlinkOption) // allow for the modified sha
|
||||
+ .build(), handler);
|
||||
+ OutputAnalyzer out = handler.analyzer();
|
||||
+ // verify we don't get a warning message for the modified file
|
||||
+ out.stdoutShouldNotMatch(".* has been modified");
|
||||
+ out.stdoutShouldNotContain("java.lang.IllegalArgumentException");
|
||||
+ out.stdoutShouldNotContain("IOException");
|
||||
+ }
|
||||
+
|
||||
+ public abstract String getTargetName();
|
||||
+ public abstract String getShaOverrideOption(Path modifiedFile, Path initialImage);
|
||||
+
|
||||
+ protected String buildSHA512(Path modifiedFile) {
|
||||
+ try {
|
||||
+ MessageDigest digest = MessageDigest.getInstance("SHA-512");
|
||||
+ try (InputStream is = Files.newInputStream(modifiedFile)) {
|
||||
+ byte[] buf = new byte[1024];
|
||||
+ int readBytes = -1;
|
||||
+ while ((readBytes = is.read(buf)) != -1) {
|
||||
+ digest.update(buf, 0, readBytes);
|
||||
+ }
|
||||
+ }
|
||||
+ byte[] actual = digest.digest();
|
||||
+ return HexFormat.of().formatHex(actual);
|
||||
+ } catch (Exception e) {
|
||||
+ throw new AssertionError("SHA-512 sum generation failed");
|
||||
+ }
|
||||
+ }
|
||||
+}
|
||||
diff --git a/test/jdk/tools/jlink/runtimeImage/ModifiedFilesWithShaOverrideFileTest.java b/test/jdk/tools/jlink/runtimeImage/ModifiedFilesWithShaOverrideFileTest.java
|
||||
new file mode 100644
|
||||
index 00000000000..d20eecd40e7
|
||||
--- /dev/null
|
||||
+++ b/test/jdk/tools/jlink/runtimeImage/ModifiedFilesWithShaOverrideFileTest.java
|
||||
@@ -0,0 +1,77 @@
|
||||
+/*
|
||||
+ * Copyright (c) 2025, Red Hat, Inc.
|
||||
+ * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
|
||||
+ *
|
||||
+ * This code is free software; you can redistribute it and/or modify it
|
||||
+ * under the terms of the GNU General Public License version 2 only, as
|
||||
+ * published by the Free Software Foundation.
|
||||
+ *
|
||||
+ * This code is distributed in the hope that it will be useful, but WITHOUT
|
||||
+ * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
||||
+ * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
+ * version 2 for more details (a copy is included in the LICENSE file that
|
||||
+ * accompanied this code).
|
||||
+ *
|
||||
+ * You should have received a copy of the GNU General Public License version
|
||||
+ * 2 along with this work; if not, write to the Free Software Foundation,
|
||||
+ * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||
+ *
|
||||
+ * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
|
||||
+ * or visit www.oracle.com if you need additional information or have any
|
||||
+ * questions.
|
||||
+ */
|
||||
+
|
||||
+import java.io.File;
|
||||
+import java.io.FileWriter;
|
||||
+import java.io.IOException;
|
||||
+import java.io.PrintWriter;
|
||||
+import java.nio.file.Path;
|
||||
+
|
||||
+/*
|
||||
+ * @test
|
||||
+ * @summary Verify no warnings are being produced on a modified file which
|
||||
+ * gets the SHA override from a file
|
||||
+ * @requires (vm.compMode != "Xcomp" & os.maxMemory >= 2g & os.family == "linux")
|
||||
+ * @library ../../lib /test/lib
|
||||
+ * @modules java.base/jdk.internal.jimage
|
||||
+ * jdk.jlink/jdk.tools.jlink.internal
|
||||
+ * jdk.jlink/jdk.tools.jlink.plugin
|
||||
+ * jdk.jlink/jdk.tools.jimage
|
||||
+ * @build tests.* jdk.test.lib.process.OutputAnalyzer
|
||||
+ * jdk.test.lib.process.ProcessTools
|
||||
+ * @run main/othervm -Xmx1g ModifiedFilesWithShaOverrideFileTest
|
||||
+ */
|
||||
+public class ModifiedFilesWithShaOverrideFileTest extends ModifiedFilesWithShaOverrideBase {
|
||||
+
|
||||
+ public static void main(String[] args) throws Exception {
|
||||
+ ModifiedFilesWithShaOverrideFileTest test = new ModifiedFilesWithShaOverrideFileTest();
|
||||
+ test.run();
|
||||
+ }
|
||||
+
|
||||
+ @Override
|
||||
+ String initialImageName() {
|
||||
+ return "java-base-jlink-with-sha-override-file";
|
||||
+ }
|
||||
+
|
||||
+ @Override
|
||||
+ public String getTargetName() {
|
||||
+ return "java-base-jlink-with-sha-override-file-target";
|
||||
+ }
|
||||
+
|
||||
+ @Override
|
||||
+ public String getShaOverrideOption(Path modifiedFile, Path initialImage) {
|
||||
+ String strippedSha = buildSHA512(modifiedFile);
|
||||
+ Path relativePath = initialImage.relativize(modifiedFile);
|
||||
+ // Modified file is libjvm.so, which is in java.base
|
||||
+ String overrideVal = String.format("%s|%s|%s", "java.base", relativePath.toString(), strippedSha);
|
||||
+ // Write a file in JAVA_HOME of the linkable runtime with the sha
|
||||
+ // override.
|
||||
+ File overrideFile = initialImage.resolve("test_sha_override.txt").toFile();
|
||||
+ try (PrintWriter pw = new PrintWriter(new FileWriter(overrideFile))) {
|
||||
+ pw.println(overrideVal);
|
||||
+ } catch (IOException e) {
|
||||
+ throw new AssertionError("Test failed unexpectedly: ", e);
|
||||
+ }
|
||||
+ return SHA_OVERRIDE_FLAG + "=@${java.home}/test_sha_override.txt";
|
||||
+ }
|
||||
+}
|
||||
diff --git a/test/jdk/tools/jlink/runtimeImage/ModifiedFilesWithShaOverrideTest.java b/test/jdk/tools/jlink/runtimeImage/ModifiedFilesWithShaOverrideTest.java
|
||||
new file mode 100644
|
||||
index 00000000000..ef0e541655d
|
||||
--- /dev/null
|
||||
+++ b/test/jdk/tools/jlink/runtimeImage/ModifiedFilesWithShaOverrideTest.java
|
||||
@@ -0,0 +1,65 @@
|
||||
+/*
|
||||
+ * Copyright (c) 2025, Red Hat, Inc.
|
||||
+ * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
|
||||
+ *
|
||||
+ * This code is free software; you can redistribute it and/or modify it
|
||||
+ * under the terms of the GNU General Public License version 2 only, as
|
||||
+ * published by the Free Software Foundation.
|
||||
+ *
|
||||
+ * This code is distributed in the hope that it will be useful, but WITHOUT
|
||||
+ * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
||||
+ * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
+ * version 2 for more details (a copy is included in the LICENSE file that
|
||||
+ * accompanied this code).
|
||||
+ *
|
||||
+ * You should have received a copy of the GNU General Public License version
|
||||
+ * 2 along with this work; if not, write to the Free Software Foundation,
|
||||
+ * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||
+ *
|
||||
+ * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
|
||||
+ * or visit www.oracle.com if you need additional information or have any
|
||||
+ * questions.
|
||||
+ */
|
||||
+
|
||||
+import java.nio.file.Path;
|
||||
+
|
||||
+/*
|
||||
+ * @test
|
||||
+ * @summary Verify no warnings are being produced on a modified file which
|
||||
+ * gets the SHA override from command line
|
||||
+ * @requires (vm.compMode != "Xcomp" & os.maxMemory >= 2g & os.family == "linux")
|
||||
+ * @library ../../lib /test/lib
|
||||
+ * @modules java.base/jdk.internal.jimage
|
||||
+ * jdk.jlink/jdk.tools.jlink.internal
|
||||
+ * jdk.jlink/jdk.tools.jlink.plugin
|
||||
+ * jdk.jlink/jdk.tools.jimage
|
||||
+ * @build tests.* jdk.test.lib.process.OutputAnalyzer
|
||||
+ * jdk.test.lib.process.ProcessTools
|
||||
+ * @run main/othervm -Xmx1g ModifiedFilesWithShaOverrideTest
|
||||
+ */
|
||||
+public class ModifiedFilesWithShaOverrideTest extends ModifiedFilesWithShaOverrideBase {
|
||||
+
|
||||
+ public static void main(String[] args) throws Exception {
|
||||
+ ModifiedFilesWithShaOverrideTest test = new ModifiedFilesWithShaOverrideTest();
|
||||
+ test.run();
|
||||
+ }
|
||||
+
|
||||
+ @Override
|
||||
+ String initialImageName() {
|
||||
+ return "java-base-jlink-with-sha-override";
|
||||
+ }
|
||||
+
|
||||
+ @Override
|
||||
+ public String getTargetName() {
|
||||
+ return "java-base-jlink-with-sha-override-target";
|
||||
+ }
|
||||
+
|
||||
+ @Override
|
||||
+ public String getShaOverrideOption(Path modifiedFile, Path initialImage) {
|
||||
+ String strippedSha = buildSHA512(modifiedFile);
|
||||
+ Path relativePath = initialImage.relativize(modifiedFile);
|
||||
+ // Modified file is libjvm.so, which is in java.base
|
||||
+ String overrideVal = String.format("%s|%s|%s", "java.base", relativePath.toString(), strippedSha);
|
||||
+ return SHA_OVERRIDE_FLAG + "=" + overrideVal;
|
||||
+ }
|
||||
+}
|
||||
diff --git a/test/jdk/tools/jlink/runtimeImage/MultiHopTest.java b/test/jdk/tools/jlink/runtimeImage/MultiHopTest.java
|
||||
index 0e2cabe7425..dfb7c9eb180 100644
|
||||
--- a/test/jdk/tools/jlink/runtimeImage/MultiHopTest.java
|
||||
+++ b/test/jdk/tools/jlink/runtimeImage/MultiHopTest.java
|
||||
@@ -33,7 +33,6 @@
|
||||
* @summary Verify that a jlink using the run-time image cannot include jdk.jlink
|
||||
* @requires (vm.compMode != "Xcomp" & os.maxMemory >= 2g)
|
||||
* @library ../../lib /test/lib
|
||||
- * @enablePreview
|
||||
* @modules java.base/jdk.internal.jimage
|
||||
* jdk.jlink/jdk.tools.jlink.internal
|
||||
* jdk.jlink/jdk.tools.jlink.plugin
|
||||
diff --git a/test/jdk/tools/jlink/runtimeImage/PackagedModulesVsRuntimeImageLinkTest.java b/test/jdk/tools/jlink/runtimeImage/PackagedModulesVsRuntimeImageLinkTest.java
|
||||
index d276e80702b..a49bac80dc0 100644
|
||||
--- a/test/jdk/tools/jlink/runtimeImage/PackagedModulesVsRuntimeImageLinkTest.java
|
||||
+++ b/test/jdk/tools/jlink/runtimeImage/PackagedModulesVsRuntimeImageLinkTest.java
|
||||
@@ -42,7 +42,6 @@
|
||||
* produce the same result
|
||||
* @requires (jlink.packagedModules & vm.compMode != "Xcomp" & os.maxMemory >= 2g)
|
||||
* @library ../../lib /test/lib
|
||||
- * @enablePreview
|
||||
* @modules java.base/jdk.internal.jimage
|
||||
* jdk.jlink/jdk.tools.jlink.internal
|
||||
* jdk.jlink/jdk.tools.jlink.plugin
|
||||
diff --git a/test/jdk/tools/jlink/runtimeImage/PatchedJDKModuleJlinkTest.java b/test/jdk/tools/jlink/runtimeImage/PatchedJDKModuleJlinkTest.java
|
||||
index d4654ec98bd..494b830a145 100644
|
||||
--- a/test/jdk/tools/jlink/runtimeImage/PatchedJDKModuleJlinkTest.java
|
||||
+++ b/test/jdk/tools/jlink/runtimeImage/PatchedJDKModuleJlinkTest.java
|
||||
@@ -35,7 +35,6 @@
|
||||
* @summary Test run-time link with --patch-module. Expect failure.
|
||||
* @requires (vm.compMode != "Xcomp" & os.maxMemory >= 2g)
|
||||
* @library ../../lib /test/lib
|
||||
- * @enablePreview
|
||||
* @modules java.base/jdk.internal.jimage
|
||||
* jdk.jlink/jdk.tools.jlink.internal
|
||||
* jdk.jlink/jdk.tools.jlink.plugin
|
||||
diff --git a/test/jdk/tools/jlink/runtimeImage/SystemModulesTest.java b/test/jdk/tools/jlink/runtimeImage/SystemModulesTest.java
|
||||
index d0a6234eec0..f9256068a40 100644
|
||||
--- a/test/jdk/tools/jlink/runtimeImage/SystemModulesTest.java
|
||||
+++ b/test/jdk/tools/jlink/runtimeImage/SystemModulesTest.java
|
||||
@@ -34,7 +34,6 @@
|
||||
* @summary Test appropriate handling of generated SystemModules* classes in run-time image link mode
|
||||
* @requires (vm.compMode != "Xcomp" & os.maxMemory >= 2g)
|
||||
* @library ../../lib /test/lib
|
||||
- * @enablePreview
|
||||
* @modules java.base/jdk.internal.jimage
|
||||
* jdk.jlink/jdk.tools.jlink.internal
|
||||
* jdk.jlink/jdk.tools.jlink.plugin
|
||||
diff --git a/test/jdk/tools/jlink/runtimeImage/SystemModulesTest2.java b/test/jdk/tools/jlink/runtimeImage/SystemModulesTest2.java
|
||||
index ee22a55f3a7..b77c5a760f9 100644
|
||||
--- a/test/jdk/tools/jlink/runtimeImage/SystemModulesTest2.java
|
||||
+++ b/test/jdk/tools/jlink/runtimeImage/SystemModulesTest2.java
|
||||
@@ -35,7 +35,6 @@
|
||||
* generated classes to not be there.
|
||||
* @requires (vm.compMode != "Xcomp" & os.maxMemory >= 2g)
|
||||
* @library ../../lib /test/lib
|
||||
- * @enablePreview
|
||||
* @modules java.base/jdk.internal.jimage
|
||||
* jdk.jlink/jdk.tools.jlink.internal
|
||||
* jdk.jlink/jdk.tools.jlink.plugin
|
||||
--
|
||||
2.49.0
|
||||
|
||||
144
BuildShaSumFile.java
Normal file
144
BuildShaSumFile.java
Normal file
|
|
@ -0,0 +1,144 @@
|
|||
import java.io.FileWriter;
|
||||
import java.io.IOException;
|
||||
import java.io.InputStream;
|
||||
import java.io.PrintWriter;
|
||||
import java.io.UncheckedIOException;
|
||||
import java.lang.module.ModuleDescriptor;
|
||||
import java.lang.module.ModuleFinder;
|
||||
import java.lang.module.ModuleReference;
|
||||
import java.nio.file.Files;
|
||||
import java.nio.file.Path;
|
||||
import java.security.MessageDigest;
|
||||
import java.util.ArrayList;
|
||||
import java.util.Arrays;
|
||||
import java.util.HexFormat;
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
import java.util.Scanner;
|
||||
import java.util.Set;
|
||||
import java.util.function.Function;
|
||||
import java.util.spi.ToolProvider;
|
||||
import java.util.stream.Collectors;
|
||||
|
||||
public class BuildShaSumFile {
|
||||
|
||||
// Mirrored from ResourcePoolEntry.Type:
|
||||
private enum Type {
|
||||
CLASS_OR_RESOURCE(0),
|
||||
CONFIG(1),
|
||||
HEADER_FILE(2),
|
||||
LEGAL_NOTICE(3),
|
||||
MAN_PAGE(4),
|
||||
NATIVE_CMD(5),
|
||||
NATIVE_LIB(6),
|
||||
TOP(7);
|
||||
|
||||
int intVal;
|
||||
|
||||
Type(int val) {
|
||||
this.intVal = val;
|
||||
}
|
||||
|
||||
Integer getOrdinal() {
|
||||
return intVal;
|
||||
}
|
||||
}
|
||||
|
||||
private static final String RESOURCE_FILE_FORMAT = "jdk/tools/jlink/internal/runtimelink/fs_%s_files";
|
||||
private static final Map<Integer, Type> TYPE_MAP = Arrays.stream(Type.values())
|
||||
.collect(Collectors.toMap(Type::getOrdinal, Function.identity()));
|
||||
private static final Module JLINK_MODULE = ToolProvider.findFirst("jlink").orElseThrow().getClass().getModule();
|
||||
private static final Set<Type> BINARIES_LIBS = Set.of(Type.NATIVE_CMD, Type.NATIVE_LIB);
|
||||
|
||||
private final String outPutFile;
|
||||
|
||||
public BuildShaSumFile(String output) {
|
||||
this.outPutFile = output;
|
||||
}
|
||||
|
||||
/*
|
||||
* Use the fs_<module-name>_files resource part of jdk.jlink to
|
||||
* figure out the files part of a module from the JDK image.
|
||||
*
|
||||
* Note that the file is of the following format:
|
||||
* <type-id>|<symlink>|<sha512sum>|<file-path>
|
||||
*
|
||||
* Example:
|
||||
* 5|0|428e61a697dc05f585333888f0d9baaef7dad088c279f052e189e401471d0c94e99711f567c5d1e5d2e08259c3b320b9d239cbb610f7c347b2eff4eec8ce712c|bin/jmod
|
||||
*/
|
||||
private List<String> getModuleFiles(String module, Set<Type> includeTypes) {
|
||||
List<String> moduleFiles = new ArrayList<>();
|
||||
String resourceFile = String.format(RESOURCE_FILE_FORMAT, module);
|
||||
try (InputStream in = JLINK_MODULE.getResourceAsStream(resourceFile);
|
||||
Scanner scanner = new Scanner(in)) {
|
||||
while (scanner.hasNextLine()) {
|
||||
String[] tokens = scanner.nextLine().split("\\|", 4);
|
||||
Integer typeInt = Integer.valueOf(tokens[0]);
|
||||
Type type = TYPE_MAP.get(typeInt);
|
||||
boolean isSymlink = Integer.valueOf(tokens[1]) == 1;
|
||||
if (includeTypes.contains(type) && !isSymlink) {
|
||||
moduleFiles.add(tokens[3]);
|
||||
}
|
||||
}
|
||||
} catch (IOException e) {
|
||||
throw new UncheckedIOException(e);
|
||||
}
|
||||
return moduleFiles;
|
||||
}
|
||||
|
||||
private String sha512Sum(String file) {
|
||||
try {
|
||||
MessageDigest digest = MessageDigest.getInstance("SHA-512");
|
||||
try (InputStream is = Files.newInputStream(Path.of(System.getProperty("java.home")).resolve(Path.of(file)))) {
|
||||
byte[] buf = new byte[1024];
|
||||
int readBytes = -1;
|
||||
while ((readBytes = is.read(buf)) != -1) {
|
||||
digest.update(buf, 0, readBytes);
|
||||
}
|
||||
}
|
||||
byte[] hashSum = digest.digest();
|
||||
return HexFormat.of().formatHex(hashSum);
|
||||
} catch (Exception e) {
|
||||
throw new RuntimeException("Failed to generate hash sum");
|
||||
}
|
||||
}
|
||||
|
||||
public void produceHashSumFile() {
|
||||
// Sanity check JEP 493 enabled builds:
|
||||
String resourceFile = String.format(RESOURCE_FILE_FORMAT, "java.base");
|
||||
try (InputStream in = JLINK_MODULE.getResourceAsStream(resourceFile)) {
|
||||
if (in == null) {
|
||||
System.out.println("Not a JEP 493 enabled build. Aborting!");
|
||||
return;
|
||||
}
|
||||
} catch (IOException e) {
|
||||
throw new UncheckedIOException(e);
|
||||
}
|
||||
try (PrintWriter pw = new PrintWriter(new FileWriter(Path.of(outPutFile).toFile()))) {
|
||||
ModuleFinder.ofSystem().findAll().stream()
|
||||
.map(ModuleReference::descriptor)
|
||||
.map(ModuleDescriptor::name).forEach(m -> {
|
||||
List<String> moduleFiles = getModuleFiles(m, BINARIES_LIBS);
|
||||
for (String file: moduleFiles) {
|
||||
String shaSum = sha512Sum(file);
|
||||
pw.println(String.format("%s|%s|%s", m, file, shaSum));
|
||||
}
|
||||
});
|
||||
|
||||
} catch (IOException e) {
|
||||
throw new UncheckedIOException(e);
|
||||
}
|
||||
System.out.println("File " + outPutFile + " written. " +
|
||||
"You can feed that now to 'jlink's --sha-overrides option.");
|
||||
}
|
||||
|
||||
public static void main(String[] args) {
|
||||
if (args.length != 1) {
|
||||
System.err.println("Usage: " + BuildShaSumFile.class.getSimpleName() + " <sha-sum-file>");
|
||||
System.exit(1);
|
||||
}
|
||||
BuildShaSumFile b = new BuildShaSumFile(args[0]);
|
||||
b.produceHashSumFile();
|
||||
}
|
||||
|
||||
}
|
||||
|
|
@ -1,154 +0,0 @@
|
|||
diff --git a/make/Bundles.gmk b/make/Bundles.gmk
|
||||
index 8161b3b036254..0b324e7e3f3fc 100644
|
||||
--- a/make/Bundles.gmk
|
||||
+++ b/make/Bundles.gmk
|
||||
@@ -185,77 +185,30 @@ endif
|
||||
|
||||
ifneq ($(filter product-bundles% legacy-bundles, $(MAKECMDGOALS)), )
|
||||
|
||||
- SYMBOLS_EXCLUDE_PATTERN := %.debuginfo %.diz %.map
|
||||
-
|
||||
- # There may be files with spaces in the names, so use ShellFindFiles
|
||||
- # explicitly.
|
||||
+ # There may be files with spaces in the names, so use ShellFindFiles explicitly.
|
||||
ALL_JDK_FILES := $(call ShellFindFiles, $(JDK_IMAGE_DIR))
|
||||
- ifneq ($(JDK_IMAGE_DIR), $(JDK_SYMBOLS_IMAGE_DIR))
|
||||
- ALL_JDK_SYMBOLS_FILES := $(call ShellFindFiles, $(JDK_SYMBOLS_IMAGE_DIR))
|
||||
- else
|
||||
- ALL_JDK_SYMBOLS_FILES := $(ALL_JDK_FILES)
|
||||
- endif
|
||||
ifneq ($(JDK_IMAGE_DIR), $(JDK_DEMOS_IMAGE_DIR))
|
||||
ALL_JDK_DEMOS_FILES := $(call ShellFindFiles, $(JDK_DEMOS_IMAGE_DIR))
|
||||
else
|
||||
ALL_JDK_DEMOS_FILES := $(ALL_JDK_FILES)
|
||||
endif
|
||||
|
||||
- # Create special filter rules when dealing with unzipped .dSYM directories on
|
||||
- # macosx
|
||||
- ifeq ($(call isTargetOs, macosx), true)
|
||||
- ifeq ($(ZIP_EXTERNAL_DEBUG_SYMBOLS), false)
|
||||
- JDK_SYMBOLS_EXCLUDE_PATTERN := $(addprefix %, \
|
||||
- $(call containing, .dSYM/, $(patsubst $(JDK_IMAGE_DIR)/%, %, \
|
||||
- $(ALL_JDK_SYMBOLS_FILES))))
|
||||
- endif
|
||||
- endif
|
||||
-
|
||||
- # Create special filter rules when dealing with debug symbols on windows
|
||||
- ifeq ($(call isTargetOs, windows), true)
|
||||
- ifeq ($(SHIP_DEBUG_SYMBOLS), )
|
||||
- JDK_SYMBOLS_EXCLUDE_PATTERN := %.pdb
|
||||
- endif
|
||||
- endif
|
||||
-
|
||||
JDK_BUNDLE_FILES := \
|
||||
$(filter-out \
|
||||
- $(JDK_SYMBOLS_EXCLUDE_PATTERN) \
|
||||
$(JDK_EXTRA_EXCLUDES) \
|
||||
- $(SYMBOLS_EXCLUDE_PATTERN) \
|
||||
$(JDK_IMAGE_HOMEDIR)/demo/% \
|
||||
, \
|
||||
$(ALL_JDK_FILES) \
|
||||
)
|
||||
|
||||
- JDK_SYMBOLS_BUNDLE_FILES := \
|
||||
- $(call FindFiles, $(SYMBOLS_IMAGE_DIR))
|
||||
+ JDK_SYMBOLS_BUNDLE_FILES := $(call FindFiles, $(SYMBOLS_IMAGE_DIR))
|
||||
|
||||
TEST_DEMOS_BUNDLE_FILES := $(filter $(JDK_DEMOS_IMAGE_HOMEDIR)/demo/%, \
|
||||
$(ALL_JDK_DEMOS_FILES))
|
||||
|
||||
ALL_JRE_FILES := $(call ShellFindFiles, $(JRE_IMAGE_DIR))
|
||||
|
||||
- # Create special filter rules when dealing with unzipped .dSYM directories on
|
||||
- # macosx
|
||||
- ifeq ($(OPENJDK_TARGET_OS), macosx)
|
||||
- ifeq ($(ZIP_EXTERNAL_DEBUG_SYMBOLS), false)
|
||||
- JRE_SYMBOLS_EXCLUDE_PATTERN := $(addprefix %, \
|
||||
- $(call containing, .dSYM/, $(patsubst $(JRE_IMAGE_DIR)/%, %, $(ALL_JRE_FILES))))
|
||||
- endif
|
||||
- endif
|
||||
-
|
||||
- # Create special filter rules when dealing with debug symbols on windows
|
||||
- ifeq ($(call isTargetOs, windows), true)
|
||||
- ifeq ($(SHIP_DEBUG_SYMBOLS), )
|
||||
- JRE_SYMBOLS_EXCLUDE_PATTERN := %.pdb
|
||||
- endif
|
||||
- endif
|
||||
-
|
||||
- JRE_BUNDLE_FILES := $(filter-out \
|
||||
- $(JRE_SYMBOLS_EXCLUDE_PATTERN) \
|
||||
- $(SYMBOLS_EXCLUDE_PATTERN), \
|
||||
- $(ALL_JRE_FILES))
|
||||
+ JRE_BUNDLE_FILES := $(ALL_JRE_FILES)
|
||||
|
||||
ifeq ($(MACOSX_CODESIGN_MODE), hardened)
|
||||
# Macosx release build and code signing available.
|
||||
diff --git a/make/CreateJmods.gmk b/make/CreateJmods.gmk
|
||||
index 3280b24924a34..32f107b6bb6a0 100644
|
||||
--- a/make/CreateJmods.gmk
|
||||
+++ b/make/CreateJmods.gmk
|
||||
@@ -218,10 +218,14 @@ ifeq ($(call isTargetOs, windows), true)
|
||||
ifeq ($(SHIP_DEBUG_SYMBOLS), )
|
||||
JMOD_FLAGS += --exclude '**{_the.*,_*.marker*,*.diz,*.pdb,*.map}'
|
||||
else
|
||||
- JMOD_FLAGS += --exclude '**{_the.*,_*.marker*,*.diz,*.map}'
|
||||
+ JMOD_FLAGS += --exclude '**{_the.*,_*.marker*,*.map}'
|
||||
endif
|
||||
else
|
||||
- JMOD_FLAGS += --exclude '**{_the.*,_*.marker*,*.diz,*.debuginfo,*.dSYM/**,*.dSYM}'
|
||||
+ ifeq ($(SHIP_DEBUG_SYMBOLS), )
|
||||
+ JMOD_FLAGS += --exclude '**{_the.*,_*.marker*,*.diz,*.debuginfo,*.dSYM/**,*.dSYM}'
|
||||
+ else
|
||||
+ JMOD_FLAGS += --exclude '**{_the.*,_*.marker*}'
|
||||
+ endif
|
||||
endif
|
||||
|
||||
# Unless we are creating a very large module, use the small tool JVM options
|
||||
diff --git a/make/autoconf/jdk-options.m4 b/make/autoconf/jdk-options.m4
|
||||
index bb18877800192..87d147d4f074b 100644
|
||||
--- a/make/autoconf/jdk-options.m4
|
||||
+++ b/make/autoconf/jdk-options.m4
|
||||
@@ -316,23 +316,36 @@ AC_DEFUN_ONCE([JDKOPT_SETUP_DEBUG_SYMBOLS],
|
||||
AC_MSG_CHECKING([if we should add external native debug symbols to the shipped bundles])
|
||||
AC_ARG_WITH([external-symbols-in-bundles],
|
||||
[AS_HELP_STRING([--with-external-symbols-in-bundles],
|
||||
- [which type of external native debug symbol information shall be shipped in product bundles (none, public, full)
|
||||
- (e.g. ship full/stripped pdbs on Windows) @<:@none@:>@])])
|
||||
+ [which type of external native debug symbol information shall be shipped with bundles/images (none, public, full).
|
||||
+ @<:@none in release builds, full otherwise. --with-native-debug-symbols=external/zipped is a prerequisite. public is only supported on Windows@:>@])],
|
||||
+ [],
|
||||
+ [with_external_symbols_in_bundles=default])
|
||||
|
||||
if test "x$with_external_symbols_in_bundles" = x || test "x$with_external_symbols_in_bundles" = xnone ; then
|
||||
AC_MSG_RESULT([no])
|
||||
elif test "x$with_external_symbols_in_bundles" = xfull || test "x$with_external_symbols_in_bundles" = xpublic ; then
|
||||
- if test "x$OPENJDK_TARGET_OS" != xwindows ; then
|
||||
- AC_MSG_ERROR([--with-external-symbols-in-bundles currently only works on windows!])
|
||||
- elif test "x$COPY_DEBUG_SYMBOLS" != xtrue ; then
|
||||
- AC_MSG_ERROR([--with-external-symbols-in-bundles only works when --with-native-debug-symbols=external is used!])
|
||||
- elif test "x$with_external_symbols_in_bundles" = xfull ; then
|
||||
+ if test "x$COPY_DEBUG_SYMBOLS" != xtrue ; then
|
||||
+ AC_MSG_ERROR([--with-external-symbols-in-bundles only works when --with-native-debug-symbols=external/zipped is used!])
|
||||
+ elif test "x$with_external_symbols_in_bundles" = xpublic && test "x$OPENJDK_TARGET_OS" != xwindows ; then
|
||||
+ AC_MSG_ERROR([--with-external-symbols-in-bundles=public is only supported on Windows!])
|
||||
+ fi
|
||||
+
|
||||
+ if test "x$with_external_symbols_in_bundles" = xfull ; then
|
||||
AC_MSG_RESULT([full])
|
||||
SHIP_DEBUG_SYMBOLS=full
|
||||
else
|
||||
AC_MSG_RESULT([public])
|
||||
SHIP_DEBUG_SYMBOLS=public
|
||||
fi
|
||||
+ elif test "x$with_external_symbols_in_bundles" = xdefault ; then
|
||||
+ if test "x$DEBUG_LEVEL" = xrelease ; then
|
||||
+ AC_MSG_RESULT([no (default)])
|
||||
+ elif test "x$COPY_DEBUG_SYMBOLS" = xtrue ; then
|
||||
+ AC_MSG_RESULT([full (default)])
|
||||
+ SHIP_DEBUG_SYMBOLS=full
|
||||
+ else
|
||||
+ AC_MSG_RESULT([no (default, native debug symbols are not external/zipped)])
|
||||
+ fi
|
||||
else
|
||||
AC_MSG_ERROR([$with_external_symbols_in_bundles is an unknown value for --with-external-symbols-in-bundles])
|
||||
fi
|
||||
732
NEWS
732
NEWS
|
|
@ -2,669 +2,77 @@ Key:
|
|||
|
||||
JDK-X - https://bugs.openjdk.java.net/browse/JDK-X
|
||||
CVE-XXXX-YYYY: https://cve.mitre.org/cgi-bin/cvename.cgi?name=XXXX-YYYY
|
||||
JEP-XYZ: https://openjdk.org/jeps/XYZ
|
||||
|
||||
New in release OpenJDK 25.0.1 (2025-10-21):
|
||||
New in release OpenJDK 24.0.1+9 (2025-4-16):
|
||||
===========================================
|
||||
- JDK-8211851: (ch) java/nio/channels/AsynchronousSocketChannel/StressLoopback.java times out (aix)
|
||||
- JDK-8290043: serviceability/attach/ConcAttachTest.java failed "guarantee(!CheckJNICalls) failed: Attached JNI thread exited without being detached"
|
||||
- JDK-8337494: Clarify JarInputStream behavior
|
||||
- JDK-8337692: Better TLS connection support
|
||||
- JDK-8338430: Improve compiler transformations
|
||||
- JDK-8339356: Test javax/net/ssl/SSLSocket/Tls13PacketSize.java failed with java.net.SocketException: An established connection was aborted by the software in your host machine
|
||||
- JDK-8342562: Enhance Deflater operations
|
||||
- JDK-8343007: Enhance Buffered Image handling
|
||||
- JDK-8344361: Restore null return for invalid services from legacy providers
|
||||
- JDK-8345276: Remove EA from the JDK 24 version string with first RC promotion
|
||||
- JDK-8345614: Improve AnnotationFormatError message for duplicate annotation interfaces
|
||||
- JDK-8345684: OperatingSystemMXBean.getSystemCpuLoad() throws NPE
|
||||
- JDK-8345959: Make JVM_IsStaticallyLinked JVM_LEAF
|
||||
- JDK-8346014: Bump version numbers for 24.0.1
|
||||
- JDK-8346082: Output JVMTI agent information in hserr files
|
||||
- JDK-8346239: Improve memory efficiency of JimageDiffGenerator
|
||||
- JDK-8346324: javax/swing/JScrollBar/4865918/bug4865918.java fails in CI
|
||||
- JDK-8346587: Distrust TLS server certificates anchored by Camerfirma Root CAs
|
||||
- JDK-8346688: GenShen: Missing metadata trigger log message
|
||||
- JDK-8346690: Shenandoah: Fix log message for end of GC usage report
|
||||
- JDK-8346712: Remove com/sun/net/httpserver/TcpNoDelayNotRequired.java test
|
||||
- JDK-8346713: [testsuite] NeverActAsServerClassMachine breaks TestPLABAdaptToMinTLABSize.java TestPinnedHumongousFragmentation.java TestPinnedObjectContents.java
|
||||
- JDK-8346868: RISC-V: compiler/sharedstubs tests fail after JDK-8332689
|
||||
- JDK-8346887: DrawFocusRect() may cause an assertion failure
|
||||
- JDK-8347124: Clean tests with --enable-linkable-runtime
|
||||
- JDK-8347129: cpuset cgroups controller is required for no good reason
|
||||
- JDK-8347256: Epsilon: Demote heap size and AlwaysPreTouch warnings to info level
|
||||
- JDK-8347299: Add annotations to test cases in LicenseTest
|
||||
- JDK-8347334: JimageDiffGenerator code clean-ups
|
||||
- JDK-8347424: Fix and rewrite sun/security/x509/DNSName/LeadingPeriod.java test
|
||||
- JDK-8347496: Test jdk/jfr/jvm/TestModularImage.java fails after JDK-8347124: No javac
|
||||
- JDK-8347506: Compatible OCSP readtimeout property with OCSP timeout
|
||||
- JDK-8347564: ZGC: Crash in DependencyContext::clean_unloading_dependents
|
||||
- JDK-8347847: Enhance jar file support
|
||||
- JDK-8347911: Limit the length of inflated text chunks
|
||||
- JDK-8347965: (tz) Update Timezone Data to 2025a
|
||||
- JDK-8348562: ZGC: segmentation fault due to missing node type check in barrier elision analysis
|
||||
- JDK-8349058: 'internal proprietary API' warnings make javac warnings unusable
|
||||
- JDK-8349084: Update vectors used in several PQC benchmarks
|
||||
- JDK-8349183: [BACKOUT] Optimization for StringBuilder append boolean & null
|
||||
- JDK-8349239: [BACKOUT] Reuse StringLatin1::putCharsAt and StringUTF16::putCharsAt
|
||||
- JDK-8349828: Redo - Change milestone to fcs for newly created jdk24.0.1 branch
|
||||
- JDK-8350820: OperatingSystemMXBean CpuLoad() methods return -1.0 on Windows
|
||||
|
||||
* CVEs
|
||||
- CVE-2025-53057
|
||||
- CVE-2025-53066
|
||||
- CVE-2025-61748
|
||||
* Changes
|
||||
- JDK-8315131: Clarify VarHandle set/get access on 32-bit platforms
|
||||
- JDK-8352637: Enhance bytecode verification
|
||||
- JDK-8356294: Enhance Path Factories
|
||||
- JDK-8356587: Missing object ID X in pool jdk.types.Method
|
||||
- JDK-8357826: Avoid running some jtreg tests when asan is configured
|
||||
- JDK-8358452: JNI exception pending in Java_sun_awt_screencast_ScreencastHelper_remoteDesktopKeyImpl of screencast_pipewire.c:1214 (ID: 51119)
|
||||
- JDK-8358577: Test serviceability/jvmti/thread/GetCurrentContendedMonitor/contmon01/contmon01.java failed: unexpexcted monitor object
|
||||
- JDK-8358819: The first year is not displayed correctly in Japanese Calendar
|
||||
- JDK-8359059: Bump version numbers for 25.0.1
|
||||
- JDK-8359218: RISC-V: Only enable CRC32 intrinsic when AvoidUnalignedAccess == false
|
||||
- JDK-8359270: C2: alignment check should consider base offset when emitting arraycopy runtime call
|
||||
- JDK-8359454: Enhance String handling
|
||||
- JDK-8359596: Behavior change when both -Xlint:options and -Xlint:-options flags are given
|
||||
- JDK-8360179: RISC-V: Only enable BigInteger intrinsics when AvoidUnalignedAccess == false
|
||||
- JDK-8360533: ContainerRuntimeVersionTestUtils fromVersionString fails with some docker versions
|
||||
- JDK-8360647: [XWayland] [OL10] NumPad keys are not triggered
|
||||
- JDK-8360679: Shenandoah: AOT saved adapter calls into broken GC barrier stub
|
||||
- JDK-8360937: Enhance certificate handling
|
||||
- JDK-8361212: Remove AffirmTrust root CAs
|
||||
- JDK-8361532: RISC-V: Several vector tests fail after JDK-8354383
|
||||
- JDK-8361829: [TESTBUG] RISC-V: compiler/vectorization/runner/BasicIntOpTest.java fails with RVV but not Zvbb
|
||||
- JDK-8362109: Change milestone to fcs for all releases
|
||||
- JDK-8362882: Update SubmissionPublisher() specification to reflect use of ForkJoinPool.asyncCommonPool()
|
||||
- JDK-8366223: ZGC: ZPageAllocator::cleanup_failed_commit_multi_partition is broken
|
||||
- JDK-8367031: [backout] Change java.time month/day field types to 'byte'
|
||||
- JDK-8368308: ISO 4217 Amendment 180 Update
|
||||
|
||||
Notes on individual issues:
|
||||
===========================
|
||||
|
||||
core-libs/java.io:serialization:
|
||||
|
||||
JDK-8367031: [backout] Change java.time month/day field types to 'byte'
|
||||
=======================================================================
|
||||
In the initial release of OpenJDK 25, attempting to read serialised
|
||||
Class objects created by earlier versions of OpenJDK for several of
|
||||
the `java.time` classes would fail with a
|
||||
`InvalidClassException`. Similarly, `java.time` Class objects
|
||||
serialised with OpenJDK 25 could not be read by older OpenJDK
|
||||
versions. This was due to the type of the day and month fields in
|
||||
these classes being changed to `byte`. This change has now been
|
||||
reverted and compatibility between OpenJDK 25 and older versions
|
||||
restored.
|
||||
|
||||
Note that this incompatibility occurred with the `Class` object and
|
||||
not an instance of the object i.e. `writeObject(LocalDate.class)`
|
||||
would produce incompatible serialised data, but
|
||||
`writeObject(LocalDate.now())` would not.
|
||||
|
||||
security-libs/java.security:
|
||||
|
||||
JDK-8361212: Remove AffirmTrust root CAs
|
||||
========================================
|
||||
The following root certificates from AffirmTrust, which were
|
||||
deactivated in the 21.0.5 release of October 2024, have been removed
|
||||
from the `cacerts` keystore:
|
||||
|
||||
Alias name: affirmtrustcommercialca [jdk]
|
||||
CN=AffirmTrust Commercial
|
||||
O=AffirmTrust
|
||||
C=US
|
||||
SHA256: 03:76:AB:1D:54:C5:F9:80:3C:E4:B2:E2:01:A0:EE:7E:EF:7B:57:B6:36:E8:A9:3C:9B:8D:48:60:C9:6F:5F:A7
|
||||
|
||||
Alias name: affirmtrustnetworkingca [jdk]
|
||||
CN=AffirmTrust Networking
|
||||
O=AffirmTrust
|
||||
C=US
|
||||
SHA256: 0A:81:EC:5A:92:97:77:F1:45:90:4A:F3:8D:5D:50:9F:66:B5:E2:C5:8F:CD:B5:31:05:8B:0E:17:F3:F0B4:1B
|
||||
|
||||
Alias name: affirmtrustpremiumca [jdk]
|
||||
CN=AffirmTrust Premium
|
||||
O=AffirmTrust
|
||||
C=US
|
||||
SHA256: 70:A7:3F:7F:37:6B:60:07:42:48:90:45:34:B1:14:82:D5:BF:0E:69:8E:CC:49:8D:F5:25:77:EB:F2:E9:3B:9A
|
||||
|
||||
Alias name: affirmtrustpremiumeccca [jdk]
|
||||
CN=AffirmTrust Premium ECC
|
||||
O=AffirmTrust
|
||||
C=US
|
||||
SHA256: BD:71:FD:F6:DA:97:E4:CF:62:D1:64:7A:DD:25:81:B0:7D:79:AD:F8:39:7E:B4:EC:BA:9C:5E:84:88:82:14:23
|
||||
|
||||
New in release OpenJDK 25.0.0 (2025-09-16):
|
||||
New in release OpenJDK 24.0.0+34 (2025-03-18):
|
||||
===========================================
|
||||
Major changes are listed below. Some changes may have been backported
|
||||
to earlier releases following their first appearance in OpenJDK 22
|
||||
through to 25.
|
||||
|
||||
NEW FEATURES
|
||||
============
|
||||
|
||||
Language Features
|
||||
=================
|
||||
|
||||
Flexible Constructor Bodies
|
||||
============================
|
||||
https://openjdk.org/jeps/447
|
||||
https://openjdk.org/jeps/482
|
||||
https://openjdk.org/jeps/492
|
||||
https://openjdk.org/jeps/513
|
||||
|
||||
In constructors in the Java programming language, allow statements to
|
||||
appear before an explicit constructor invocation, i.e., super(..) or
|
||||
this(..). The statements cannot reference the instance under
|
||||
construction, but they can initialize its fields. Initializing fields
|
||||
before invoking another constructor makes a class more reliable when
|
||||
methods are overridden.
|
||||
|
||||
This language feature is now finalised (JEP 513). It was first
|
||||
introduced as a preview language feature
|
||||
(http://openjdk.java.net/jeps/12) in OpenJDK 22 (JEP 447) under the
|
||||
name "Statements before super(...)". It reached a second preview in
|
||||
OpenJDK 23 (JEP 482) with the addition of allowing fields to be
|
||||
initialized before invoking another constructor. It reached a third
|
||||
preview in OpenJDK 24 (JEP 492).
|
||||
|
||||
Unnamed Patterns and Variables
|
||||
==============================
|
||||
https://openjdk.org/jeps/443
|
||||
https://openjdk.org/jeps/456
|
||||
|
||||
Enhance the Java language with unnamed patterns, which match a record
|
||||
component without stating the component's name or type, and unnamed
|
||||
variables, which can be initialized but not used. Both are denoted by
|
||||
an underscore character, _.
|
||||
|
||||
This feature is now finalised (JEP 456). It was a preview feature
|
||||
(http://openjdk.java.net/jeps/12) in OpenJDK 21 (JEP 443).
|
||||
|
||||
Primitive Types in Patterns, instanceof, and switch
|
||||
===================================================
|
||||
https://openjdk.org/jeps/455
|
||||
https://openjdk.org/jeps/488
|
||||
https://openjdk.org/jeps/507
|
||||
|
||||
Enhance pattern matching by allowing primitive type patterns in all
|
||||
pattern contexts, and extend instanceof and switch to work with all
|
||||
primitive types.
|
||||
|
||||
This is a preview language feature (http://openjdk.java.net/jeps/12)
|
||||
introduced in OpenJDK 23 (JEP 455) with a second preview in OpenJDK 24
|
||||
(JEP 488) and reaching a third in OpenJDK 25 (JEP 507).
|
||||
|
||||
Module Import Declarations
|
||||
==========================
|
||||
https://openjdk.org/jeps/476
|
||||
https://openjdk.org/jeps/494
|
||||
https://openjdk.org/jeps/511
|
||||
|
||||
Enhance the Java programming language with the ability to succinctly
|
||||
import all of the packages exported by a module. This simplifies the
|
||||
reuse of modular libraries, but does not require the importing code to
|
||||
be in a module itself.
|
||||
|
||||
This language feature is now finalised (JEP 511). It was introduced as
|
||||
a preview language feature (http://openjdk.java.net/jeps/12) in
|
||||
OpenJDK 23 (JEP 476) and had a second preview in OpenJDK 24 (JEP 494).
|
||||
|
||||
Library Features
|
||||
================
|
||||
|
||||
Foreign Function & Memory API
|
||||
=============================
|
||||
https://openjdk.org/jeps/412
|
||||
https://openjdk.org/jeps/419
|
||||
https://openjdk.org/jeps/424
|
||||
https://openjdk.org/jeps/434
|
||||
https://openjdk.org/jeps/442
|
||||
https://openjdk.org/jeps/454
|
||||
|
||||
Introduce an API by which Java programs can interoperate with code and
|
||||
data outside of the Java runtime. By efficiently invoking foreign
|
||||
functions (i.e., code outside the JVM), and by safely accessing
|
||||
foreign memory (i.e., memory not managed by the JVM), the API enables
|
||||
Java programs to call native libraries and process native data without
|
||||
the brittleness and danger of JNI.
|
||||
|
||||
This API is now finalised (JEP 454). It was first introduced in
|
||||
incubation (https://openjdk.java.net/jeps/11) in OpenJDK 17 (JEP 412),
|
||||
and is an evolution of the Foreign Memory Access API (OpenJDK 14
|
||||
through 16) and Foreign Linker API (OpenJDK 16) (see release notes for
|
||||
java-17-openjdk). OpenJDK 18 saw a second round of incubation (JEP
|
||||
419) before its inclusion as a preview feature
|
||||
(http://openjdk.java.net/jeps/12) in OpenJDK 19 (JEP 424). A second
|
||||
preview took place in OpenJDK 20 (JEP 434) and a third and final
|
||||
preview in OpenJDK 21 (JEP 442).
|
||||
|
||||
Prepare to Restrict the Use of JNI
|
||||
==================================
|
||||
https://openjdk.org/jeps/472
|
||||
|
||||
Issue warnings about uses of the Java Native Interface (JNI) and
|
||||
adjust the Foreign Function & Memory (FFM) API to issue warnings in a
|
||||
consistent manner. All such warnings aim to prepare developers for a
|
||||
future release that ensures integrity by default by uniformly
|
||||
restricting JNI and the FFM API. Application developers can avoid both
|
||||
current warnings and future restrictions by selectively enabling these
|
||||
interfaces where essential using the --enable-native-access
|
||||
command-line option.
|
||||
|
||||
Class-File API
|
||||
==============
|
||||
https://openjdk.org/jeps/457
|
||||
https://openjdk.org/jeps/466
|
||||
https://openjdk.org/jeps/484
|
||||
|
||||
Provide a standard API for parsing, generating, and transforming Java
|
||||
class files.
|
||||
|
||||
This API is now finalised (JEP 484). It was introduced as a preview
|
||||
library feature (http://openjdk.java.net/jeps/12) in OpenJDK 22 (JEP
|
||||
457) with a second preview in OpenJDK 23 (JEP 466).
|
||||
|
||||
Vector API
|
||||
==========
|
||||
https://openjdk.org/jeps/338
|
||||
https://openjdk.org/jeps/414
|
||||
https://openjdk.org/jeps/417
|
||||
https://openjdk.org/jeps/426
|
||||
https://openjdk.org/jeps/438
|
||||
https://openjdk.org/jeps/448
|
||||
https://openjdk.org/jeps/460
|
||||
https://openjdk.org/jeps/469
|
||||
https://openjdk.org/jeps/489
|
||||
https://openjdk.org/jeps/508
|
||||
|
||||
Introduce an API to express vector computations that reliably compile
|
||||
at runtime to optimal vector hardware instructions on supported CPU
|
||||
architectures and thus achieve superior performance to equivalent
|
||||
scalar computations.
|
||||
|
||||
This is an incubation feature (https://openjdk.java.net/jeps/11)
|
||||
introduced in OpenJDK 16 (JEP 338). A second round of incubation took
|
||||
place in OpenJDK 17 (JEP 414), OpenJDK 18 (JEP 417) saw a third,
|
||||
OpenJDK 19 a fourth (JEP 426), OpenJDK 20 (JEP 438) a fifth, OpenJDK
|
||||
21 a sixth (JEP 448), OpenJDK 22 a seventh (JEP 460), OpenJDK 23 an
|
||||
eighth (JEP 469), OpenJDK 24 a ninth (JEP 489) and it reaches its
|
||||
tenth in OpenJDK 25 (JEP 508).
|
||||
|
||||
Stream Gatherers
|
||||
================
|
||||
https://openjdk.org/jeps/461
|
||||
https://openjdk.org/jeps/473
|
||||
https://openjdk.org/jeps/485
|
||||
|
||||
Enhance the Stream API to support custom intermediate operations. This
|
||||
will allow stream pipelines to transform data in ways that are not
|
||||
easily achievable with the existing built-in intermediate operations.
|
||||
|
||||
This API is now finalised (JEP 485). It was introduced as a preview
|
||||
library feature (http://openjdk.java.net/jeps/12) in OpenJDK 22 (JEP
|
||||
461) with a second preview in OpenJDK 23 (JEP 473).
|
||||
|
||||
Structured Concurrency
|
||||
======================
|
||||
https://openjdk.org/jeps/428
|
||||
https://openjdk.org/jeps/437
|
||||
https://openjdk.org/jeps/453
|
||||
https://openjdk.org/jeps/462
|
||||
https://openjdk.org/jeps/480
|
||||
https://openjdk.org/jeps/499
|
||||
https://openjdk.org/jeps/505
|
||||
|
||||
Simplify multithreaded programming by introducing an API for
|
||||
structured concurrency. Structured concurrency treats multiple tasks
|
||||
running in different threads as a single unit of work, thereby
|
||||
streamlining error handling and cancellation, improving reliability,
|
||||
and enhancing observability.
|
||||
|
||||
This API was first introduced in incubation
|
||||
(https://openjdk.java.net/jeps/11) in OpenJDK 19 (JEP 428) and had a
|
||||
second round of incubation in OpenJDK 20 (JEP 437). It became a
|
||||
preview feature (http://openjdk.java.net/jeps/12) in OpenJDK 21 (JEP
|
||||
453), reached its second preview in OpenJDK 22 (JEP 462), had a third
|
||||
preview in OpenJDK 23 (JEP 480), a fourth in OpenJDK 24 (JEP 499) and
|
||||
reaches its fifth in OpenJDK 25 (JEP 505).
|
||||
|
||||
Compact Source Files and Instance Main Methods
|
||||
==============================================
|
||||
https://openjdk.org/jeps/445
|
||||
https://openjdk.org/jeps/463
|
||||
https://openjdk.org/jeps/477
|
||||
https://openjdk.org/jeps/495
|
||||
https://openjdk.org/jeps/512
|
||||
|
||||
Evolve the Java programming language so that beginners can write their
|
||||
first programs without needing to understand language features
|
||||
designed for large programs. Far from using a separate dialect of the
|
||||
language, beginners can write streamlined declarations for
|
||||
single-class programs and then seamlessly expand their programs to use
|
||||
more advanced features as their skills grow. Experienced developers
|
||||
can likewise enjoy writing small programs succinctly, without the need
|
||||
for constructs intended for programming in the large.
|
||||
|
||||
This library feature is now finalised (JEP 512) with some minor
|
||||
changes from the last release. It was first introduced as a preview
|
||||
(http://openjdk.java.net/jeps/12) in OpenJDK 21 (JEP 445) under the
|
||||
name "Unnamed Classes and Instance Main Methods". It reached a second
|
||||
preview in OpenJDK 22 (JEP 463) and a third in OpenJDK 23 (JEP 477)
|
||||
under the new name, "Implicitly Declared Classes and Instance Main
|
||||
Methods", due to the move away from unnamed classes to an implicitly
|
||||
declared name chosen by the host system. It had a fourth preview in
|
||||
OpenJDK 24 (JEP 495) with new terminology and a revised title ("Simple
|
||||
Source Files and Instance Main Methods"), but otherwise unchanged.
|
||||
|
||||
Scoped Values
|
||||
=============
|
||||
https://openjdk.org/jeps/429
|
||||
https://openjdk.org/jeps/446
|
||||
https://openjdk.org/jeps/464
|
||||
https://openjdk.org/jeps/481
|
||||
https://openjdk.org/jeps/487
|
||||
https://openjdk.org/jeps/506
|
||||
|
||||
Introduce scoped values, which enable the sharing of immutable data
|
||||
within and across threads. They are preferred to thread-local
|
||||
variables, especially when using large numbers of virtual threads.
|
||||
|
||||
This API is now finalised (JEP 506). This API was first introduced in
|
||||
incubation (https://openjdk.java.net/jeps/11) in OpenJDK 20 (JEP
|
||||
429). It became a preview feature (http://openjdk.java.net/jeps/12) in
|
||||
OpenJDK 21 (JEP 446), had a second preview in OpenJDK 22 (JEP 464), a
|
||||
third in OpenJDK 23 (JEP 481) and a fourth in OpenJDK 24 (JEP 487).
|
||||
|
||||
Key Derivation Function API
|
||||
===========================
|
||||
https://openjdk.org/jeps/478
|
||||
https://openjdk.org/jeps/510
|
||||
|
||||
Introduce an API for Key Derivation Functions (KDFs), which are
|
||||
cryptographic algorithms for deriving additional keys from a secret
|
||||
key and other data.
|
||||
|
||||
This API is now finalised (JEP 510). It was first introduced as a
|
||||
preview library feature (http://openjdk.java.net/jeps/12) in OpenJDK
|
||||
24 (JEP 478).
|
||||
|
||||
Quantum-Resistant Module-Lattice-Based Key Encapsulation Mechanism
|
||||
==================================================================
|
||||
https://openjdk.org/jeps/496
|
||||
|
||||
Enhance the security of Java applications by providing an
|
||||
implementation of the quantum-resistant Module-Lattice-Based
|
||||
Key-Encapsulation Mechanism (ML-KEM). Key encapsulation mechanisms
|
||||
(KEMs) are used to secure symmetric keys over insecure communication
|
||||
channels using public key cryptography. ML-KEM is designed to be
|
||||
secure against future quantum computing attacks. It has been
|
||||
standardized by the United States National Institute of Standards and
|
||||
Technology (NIST) in FIPS 203 [0].
|
||||
|
||||
[0] https://csrc.nist.gov/pubs/fips/203/final
|
||||
|
||||
Quantum-Resistant Module-Lattice-Based Digital Signature Algorithm
|
||||
==================================================================
|
||||
https://openjdk.org/jeps/497
|
||||
|
||||
Enhance the security of Java applications by providing an
|
||||
implementation of the quantum-resistant Module-Lattice-Based Digital
|
||||
Signature Algorithm (ML-DSA). Digital signatures are used to detect
|
||||
unauthorized modifications to data and to authenticate the identity of
|
||||
signatories. ML-DSA is designed to be secure against future quantum
|
||||
computing attacks. It has been standardized by the United States
|
||||
National Institute of Standards and Technology (NIST) in FIPS 204 [0].
|
||||
|
||||
[0] https://csrc.nist.gov/pubs/fips/204/final
|
||||
|
||||
PEM Encodings of Cryptographic Objects
|
||||
======================================
|
||||
https://openjdk.org/jeps/470
|
||||
|
||||
Introduce an API for encoding objects that represent cryptographic
|
||||
keys, certificates, and certificate revocation lists into the
|
||||
widely-used Privacy-Enhanced Mail (PEM) transport format, and for
|
||||
decoding from that format back into objects.
|
||||
|
||||
This is a preview library feature (http://openjdk.java.net/jeps/12)
|
||||
introduced in OpenJDK 25 (JEP 470).
|
||||
|
||||
Stable Values
|
||||
=============
|
||||
https://openjdk.org/jeps/502
|
||||
|
||||
Introduce an API for stable values, which are objects that hold
|
||||
immutable data. Stable values are treated as constants by the JVM,
|
||||
enabling the same performance optimizations that are enabled by
|
||||
declaring a field final. Compared to final fields, however, stable
|
||||
values offer greater flexibility as to the timing of their
|
||||
initialization.
|
||||
|
||||
This is a preview library feature (http://openjdk.java.net/jeps/12)
|
||||
introduced in OpenJDK 25 (JEP 502).
|
||||
|
||||
Virtual Machine Enhancements
|
||||
============================
|
||||
|
||||
Region Pinning for G1
|
||||
=====================
|
||||
https://openjdk.org/jeps/423
|
||||
|
||||
Reduce latency by implementing region pinning in G1, so that garbage
|
||||
collection need not be disabled during Java Native Interface (JNI)
|
||||
critical regions.
|
||||
|
||||
ZGC: Generational Mode by Default
|
||||
=================================
|
||||
https://openjdk.org/jeps/439
|
||||
https://openjdk.org/jeps/474
|
||||
|
||||
Switch the default mode of the Z Garbage Collector (ZGC) to the
|
||||
generational mode. Deprecate the non-generational mode, with the
|
||||
intent to remove it in a future release.
|
||||
|
||||
Late Barrier Expansion for G1
|
||||
=============================
|
||||
https://openjdk.org/jeps/475
|
||||
|
||||
Simplify the implementation of the G1 garbage collector's barriers,
|
||||
which record information about application memory accesses, by
|
||||
shifting their expansion from early in the C2 JIT's compilation
|
||||
pipeline to later.
|
||||
|
||||
Ahead-of-Time Class Loading & Linking
|
||||
=====================================
|
||||
https://openjdk.org/jeps/483
|
||||
https://openjdk.org/jeps/514
|
||||
|
||||
Improve startup time by making the classes of an application instantly
|
||||
available, in a loaded and linked state, when the HotSpot Java Virtual
|
||||
Machine starts. Achieve this by monitoring the application during one
|
||||
run and storing the loaded and linked forms of all classes in a cache
|
||||
for use in subsequent runs. Lay a foundation for future improvements
|
||||
to both startup and warmup time.
|
||||
|
||||
Using this feature requires a two stage process:
|
||||
|
||||
1. Create the Ahead-of-Time cache from a training run of the
|
||||
application using the option `--XX:AOTCacheOutput=<cache name>` where
|
||||
`<cache name>` is the cache reference to use in later runs.
|
||||
|
||||
2. When running the application in testing or production, use the
|
||||
option `-XX:AOTCache=<cache name>` to run the application with the
|
||||
cache generated in #2.
|
||||
|
||||
Previously, in OpenJDK 24 (JEP 483), the training run and cache
|
||||
creation were handled by two separate steps:
|
||||
|
||||
1. Populate the Ahead-of-Time configuration data with a training run
|
||||
of the application using the options `-XX:AOTMode=record
|
||||
-XX:AOTConfiguration=<config name>` where `<config name>` is the
|
||||
configuration reference to use in #2.
|
||||
|
||||
2. Create the Ahead-of-Time cache using the options
|
||||
`-XX:AOTMode=create -XX:AOTConfiguration=<config name>
|
||||
-XX:AOTCache=<cache name>` where `<config name>` is the configuration
|
||||
reference from #1 and `<cache name>` is the cache reference to use in
|
||||
later runs.
|
||||
|
||||
JEP 514 ("Ahead-of-Time Command-Line Ergonomics") in OpenJDK 25 adds
|
||||
the option `--XX:AOTCacheOutput` which performs both the above steps
|
||||
from a single command-line invocation using a temporary configuration
|
||||
file. A new environment variable, `JDK_AOT_VM_OPTIONS`, can be used
|
||||
to pass options to the cache creation step without affecting the
|
||||
training run step.
|
||||
|
||||
Ahead-of-Time Method Profiling
|
||||
==============================
|
||||
https://openjdk.org/jeps/515
|
||||
|
||||
Improve warmup time by making method-execution profiles from a
|
||||
previous run of an application instantly available, when the HotSpot
|
||||
Java Virtual Machine starts. This will enable the JIT compiler to
|
||||
generate native code immediately upon application startup, rather than
|
||||
having to wait for profiles to be collected.
|
||||
|
||||
Synchronize Virtual Threads without Pinning
|
||||
===========================================
|
||||
https://openjdk.org/jeps/491
|
||||
|
||||
Improve the scalability of Java code that uses synchronized methods
|
||||
and statements by arranging for virtual threads that block in such
|
||||
constructs to release their underlying platform threads for use by
|
||||
other virtual threads. This will eliminate nearly all cases of virtual
|
||||
threads being pinned to platform threads, which severely restricts the
|
||||
number of virtual threads available to handle an application's
|
||||
workload.
|
||||
|
||||
Compact Object Headers
|
||||
======================
|
||||
https://openjdk.org/jeps/450
|
||||
https://openjdk.org/jeps/519
|
||||
|
||||
Reduce the size of object headers in the HotSpot JVM from between 96
|
||||
and 128 bits down to 64 bits on 64-bit architectures. This will reduce
|
||||
heap size, improve deployment density, and increase data locality.
|
||||
|
||||
This is now a production feature in OpenJDK 25 (JEP 519) enabled using
|
||||
`-XX:+UseCompactObjectHeaders`. It was first introduced as an
|
||||
experimental feature (JEP 450) that also required the use of
|
||||
`-XX:+UnlockExperimentalVMOptions`.
|
||||
|
||||
Generational Shenandoah
|
||||
=======================
|
||||
https://openjdk.org/jeps/404
|
||||
https://openjdk.org/jeps/521
|
||||
|
||||
Enhance the Shenandoah garbage collector with experimental
|
||||
generational collection capabilities to improve sustainable
|
||||
throughput, load-spike resilience, and memory utilization.
|
||||
|
||||
This is now a production feature in OpenJDK 25 (JEP 521) enabled using
|
||||
`-XX:ShenandoahGCMode=generational`. It was first introduced as an
|
||||
experimental feature (JEP 404) that also required the use of
|
||||
`-XX:+UnlockExperimentalVMOptions`.
|
||||
|
||||
JFR Cooperative Sampling
|
||||
========================
|
||||
https://openjdk.org/jeps/518
|
||||
|
||||
Improve the stability of the JDK Flight Recorder (JFR) when it
|
||||
asynchronously samples Java thread stacks. Achieve this by walking
|
||||
call stacks only at safepoints, while minimizing safepoint bias.
|
||||
|
||||
JFR Method Timing & Tracing
|
||||
===========================
|
||||
https://openjdk.org/jeps/520
|
||||
|
||||
Extend the JDK Flight Recorder (JFR) with facilities for method timing
|
||||
and tracing via bytecode instrumentation.
|
||||
|
||||
JFR CPU-Time Profiling
|
||||
======================
|
||||
https://openjdk.org/jeps/509
|
||||
|
||||
Enhance the JDK Flight Recorder (JFR) to capture more accurate
|
||||
CPU-time profiling information on Linux.
|
||||
|
||||
This is an experimental feature so its JFR events are tagged with the
|
||||
`@Experimental` annotation. Unlike other experimental virtual machine
|
||||
features, it does not need to be explicitly enabled with
|
||||
`-XX:+UnlockExperimentalVMOptions`.
|
||||
|
||||
Tools
|
||||
=====
|
||||
|
||||
Launch Multi-File Source-Code Programs
|
||||
======================================
|
||||
https://openjdk.org/jeps/458
|
||||
|
||||
Enhance the java application launcher to be able to run a program
|
||||
supplied as multiple files of Java source code. This will make the
|
||||
transition from small programs to larger ones more gradual, enabling
|
||||
developers to choose whether and when to go to the trouble of
|
||||
configuring a build tool.
|
||||
|
||||
Markdown Documentation Comments
|
||||
===============================
|
||||
https://openjdk.org/jeps/467
|
||||
|
||||
Enable JavaDoc documentation comments to be written in Markdown rather
|
||||
than solely in a mixture of HTML and JavaDoc @-tags.
|
||||
|
||||
Linking Run-Time Images without JMODs
|
||||
=====================================
|
||||
https://openjdk.org/jeps/493
|
||||
|
||||
Reduce the size of the JDK by approximately 25% by enabling the jlink
|
||||
tool to create custom run-time images without using the JDK's JMOD
|
||||
files.
|
||||
|
||||
This feature must be enabled when the JDK is built using the
|
||||
--enable-linkable-runtime option. It will not be enabled by default,
|
||||
and some JDK vendors may choose not to enable it.
|
||||
|
||||
DEPRECATIONS
|
||||
============
|
||||
|
||||
Deprecate the Memory-Access Methods in sun.misc.Unsafe for Removal
|
||||
==================================================================
|
||||
https://openjdk.org/jeps/471
|
||||
|
||||
Deprecate the memory-access methods in sun.misc.Unsafe for removal in
|
||||
a future release. These unsupported methods have been superseded by
|
||||
standard APIs, namely the VarHandle API (JEP 193, OpenJDK 9) and the
|
||||
Foreign Function & Memory API (JEP 454, OpenJDK 22). We strongly
|
||||
encourage library developers to migrate from sun.misc.Unsafe to
|
||||
supported replacements, so that applications can migrate smoothly to
|
||||
modern JDK releases.
|
||||
|
||||
Warn upon Use of Memory-Access Methods in sun.misc.Unsafe
|
||||
=========================================================
|
||||
https://openjdk.org/jeps/498
|
||||
|
||||
Issue a warning at run time on the first occasion that any
|
||||
memory-access method in sun.misc.Unsafe is invoked. All of these
|
||||
unsupported methods were terminally deprecated in JDK 23 (see JEP 471
|
||||
above). They have been superseded by standard APIs, namely the
|
||||
VarHandle API (JEP 193, OpenJDK 9) and the Foreign Function & Memory
|
||||
API (JEP 454, OpenJDK 22). We strongly encourage library developers to
|
||||
migrate from sun.misc.Unsafe to supported replacements, so that
|
||||
applications can migrate smoothly to modern JDK releases.
|
||||
|
||||
Permanently Disable the Security Manager
|
||||
========================================
|
||||
https://openjdk.org/jeps/486
|
||||
|
||||
The Security Manager has not been the primary means of securing
|
||||
client-side Java code for many years, it has rarely been used to
|
||||
secure server-side code, and it is costly to maintain. We therefore
|
||||
deprecated it for removal in OpenJDK 17 via JEP 411 (2021). As the
|
||||
next step toward removing the Security Manager, we will revise the
|
||||
Java Platform specification so that developers cannot enable it and
|
||||
other Platform classes do not refer to it. This change will have no
|
||||
impact on the vast majority of applications, libraries, and tools. We
|
||||
will remove the Security Manager API in a future release.
|
||||
|
||||
REMOVALS
|
||||
========
|
||||
|
||||
String Templates
|
||||
================
|
||||
https://openjdk.org/jeps/430
|
||||
https://openjdk.org/jeps/459
|
||||
https://openjdk.org/jeps/465
|
||||
|
||||
This was a preview feature (http://openjdk.java.net/jeps/12)
|
||||
introduced in OpenJDK 21 (JEP 430) with a second preview in OpenJDK 22
|
||||
(JEP 459). A third preview was proposed but ultimately withdrawn for
|
||||
OpenJDK 23 (JEP 465) and the feature is no longer present. See [0]
|
||||
for further explanation.
|
||||
|
||||
[0] https://mail.openjdk.org/pipermail/amber-spec-experts/2024-April/004106.html
|
||||
|
||||
Remove the Windows & Linux 32-bit x86 Ports
|
||||
===========================================
|
||||
https://openjdk.org/jeps/449
|
||||
https://openjdk.org/jeps/479
|
||||
https://openjdk.org/jeps/501
|
||||
https://openjdk.org/jeps/503
|
||||
|
||||
Remove the source code and build support for the Windows (JEP 479) &
|
||||
Linux (JEP 503) 32-bit x86 ports. The Windows port was deprecated for
|
||||
removal in JDK 21 by JEP 449 and the Linux port was deprecated for
|
||||
removal in JDK 24 by JEP 501. Both deprecations took place with the
|
||||
express intent to remove the ports in a future release.
|
||||
|
||||
Following this removal of these 32-bit x86 ports, the
|
||||
architecture-agnostic Zero port is the only way to run Java programs
|
||||
on 32-bit x86 processors.
|
||||
|
||||
ZGC: Remove the Non-Generational Mode
|
||||
=====================================
|
||||
https://openjdk.org/jeps/439
|
||||
https://openjdk.org/jeps/474
|
||||
https://openjdk.org/jeps/490
|
||||
|
||||
Remove the non-generational mode of the Z Garbage Collector (ZGC),
|
||||
keeping the generational mode as the default for ZGC (see JEP 439 &
|
||||
474).
|
||||
- 404: Generational Shenandoah (Experimental)
|
||||
- 450: Compact Object Headers (Experimental)
|
||||
- 472: Prepare to Restrict the Use of JNI
|
||||
- 475: Late Barrier Expansion for G1
|
||||
- 478: Key Derivation Function API (Preview)
|
||||
- 479: Remove the Windows 32-bit x86 Port
|
||||
- 483: Ahead-of-Time Class Loading & Linking
|
||||
- 484: Class-File API
|
||||
- 485: Stream Gatherers
|
||||
- 486: Permanently Disable the Security Manager
|
||||
- 487: Scoped Values (Fourth Preview)
|
||||
- 488: Primitive Types in Patterns, instanceof, and switch (Second Preview)
|
||||
- 489: Vector API (Ninth Incubator)
|
||||
- 490: ZGC: Remove the Non-Generational Mode
|
||||
- 491: Synchronize Virtual Threads without Pinning
|
||||
- 492: Flexible Constructor Bodies (Third Preview)
|
||||
- 493: Linking Run-Time Images without JMODs
|
||||
- 494: Module Import Declarations (Second Preview)
|
||||
- 495: Simple Source Files and Instance Main Methods (Fourth Preview)
|
||||
- 496: Quantum-Resistant Module-Lattice-Based Key Encapsulation Mechanism
|
||||
- 497: Quantum-Resistant Module-Lattice-Based Digital Signature Algorithm
|
||||
- 498: Warn upon Use of Memory-Access Methods in sun.misc.Unsafe
|
||||
- 499: Structured Concurrency (Fourth Preview)
|
||||
- 501: Deprecate the 32-bit x86 Port for Removal
|
||||
|
|
|
|||
|
|
@ -4,11 +4,11 @@ This package contains the latest rolling release of OpenJDK. OpenJDK
|
|||
has a release cadence of six months, with a new release in March and
|
||||
September each year.
|
||||
|
||||
The current release is OpenJDK 25. For a list of major changes from
|
||||
The current release is OpenJDK 23. For a list of major changes from
|
||||
OpenJDK 21, see the NEWS file included in this package and the
|
||||
upstream release page:
|
||||
|
||||
https://openjdk.org/projects/jdk/25/
|
||||
https://openjdk.org/projects/jdk/23/
|
||||
|
||||
This package is intended for those who want to follow the latest
|
||||
OpenJDK releases. Long term support versions of OpenJDK are available
|
||||
|
|
|
|||
|
|
@ -50,11 +50,11 @@ public class TestTranslations {
|
|||
"Mountain Daylight Time", "MDT", "MDT",
|
||||
"Mountain Time", "MT", "MT"});
|
||||
map.put(Locale.FRANCE, new String[] { "heure normale des Rocheuses", "UTC\u221207:00", "MST",
|
||||
"heure d\u2019\u00e9t\u00e9 des Rocheuses", "UTC\u221206:00", "MST",
|
||||
"heure des Rocheuses", "UTC\u221207:00", "MST"});
|
||||
map.put(Locale.GERMANY, new String[] { "Rocky-Mountains-Normalzeit", "GMT-07:00", "MST",
|
||||
"Rocky-Mountains-Sommerzeit", "GMT-06:00", "MST",
|
||||
"Rocky-Mountains-Zeit", "GMT-07:00", "MST"});
|
||||
"heure d\u2019\u00e9t\u00e9 des Rocheuses", "UTC\u221206:00", "MDT",
|
||||
"heure des Rocheuses", "UTC\u221207:00", "MT"});
|
||||
map.put(Locale.GERMANY, new String[] { "Rocky-Mountain-Normalzeit", "GMT-07:00", "MST",
|
||||
"Rocky-Mountain-Sommerzeit", "GMT-06:00", "MDT",
|
||||
"Rocky-Mountain-Zeit", "GMT-07:00", "MT"});
|
||||
CIUDAD_JUAREZ = Collections.unmodifiableMap(map);
|
||||
}
|
||||
|
||||
|
|
@ -97,10 +97,14 @@ public class TestTranslations {
|
|||
|
||||
System.out.printf("Checking locale %s for %s...\n", l, id);
|
||||
|
||||
if ("JRE".equals(localeProvider) || "CLDR".equals(localeProvider)) {
|
||||
if ("JRE".equals(localeProvider)) {
|
||||
expectedShortStd = expected[2];
|
||||
expectedShortDST = expected[5];
|
||||
expectedShortGen = expected[8];
|
||||
} else if ("CLDR".equals(localeProvider)) {
|
||||
expectedShortStd = expected[1];
|
||||
expectedShortDST = expected[4];
|
||||
expectedShortGen = expected[7];
|
||||
} else {
|
||||
System.err.printf("Invalid locale provider %s\n", localeProvider);
|
||||
System.exit(3);
|
||||
|
|
|
|||
|
|
@ -1,6 +1,6 @@
|
|||
#!/bin/sh
|
||||
|
||||
# Copyright (C) 2024 Red Hat, Inc.
|
||||
# Copyright (C) 2020 Red Hat, Inc.
|
||||
# Written by Andrew John Hughes <gnu.andrew@redhat.com>.
|
||||
#
|
||||
# This program is free software: you can redistribute it and/or modify
|
||||
|
|
@ -18,44 +18,37 @@
|
|||
|
||||
TREE=${1}
|
||||
|
||||
if test "${TREE}" = ""; then
|
||||
if test "x${TREE}" = "x"; then
|
||||
TREE=${PWD}
|
||||
fi
|
||||
|
||||
if [ -e "${TREE}"/nashorn/.hg ] || [ -e "${TREE}"/nashorn/merge.changeset ] ; then
|
||||
if [ -e ${TREE}/nashorn/.hg -o -e ${TREE}/nashorn/merge.changeset ] ; then
|
||||
NASHORN="nashorn" ;
|
||||
fi
|
||||
|
||||
if [ -e "${TREE}"/corba/.hg ] || [ -e "${TREE}"/corba/merge.changeset ] ; then
|
||||
if [ -e ${TREE}/corba/.hg -o -e ${TREE}/corba/merge.changeset ] ; then
|
||||
CORBA="corba";
|
||||
fi
|
||||
|
||||
if [ -e "${TREE}"/jaxp/.hg ] || [ -e "${TREE}"/jaxp/merge.changeset ] ; then
|
||||
if [ -e ${TREE}/jaxp/.hg -o -e ${TREE}/jaxp/merge.changeset ] ; then
|
||||
JAXP="jaxp";
|
||||
fi
|
||||
|
||||
if [ -e "${TREE}"/jaxws/.hg ] || [ -e "${TREE}"/jaxws/merge.changeset ] ; then
|
||||
if [ -e ${TREE}/jaxws/.hg -o -e ${TREE}/jaxws/merge.changeset ] ; then
|
||||
JAXWS="jaxws";
|
||||
fi
|
||||
|
||||
if [ -e "${TREE}"/langtools/.hg ] || [ -e "${TREE}"/langtools/merge.changeset ] ; then
|
||||
if [ -e ${TREE}/langtools/.hg -o -e ${TREE}/langtools/merge.changeset ] ; then
|
||||
LANGTOOLS="langtools";
|
||||
fi
|
||||
|
||||
if [ -e "${TREE}"/jdk/.hg ] || [ -e "${TREE}"/jdk/merge.changeset ] ; then
|
||||
if [ -e ${TREE}/jdk/.hg -o -e ${TREE}/jdk/merge.changeset ] ; then
|
||||
JDK="jdk";
|
||||
fi
|
||||
|
||||
if [ -e "${TREE}"/hotspot/.hg ] || [ -e "${TREE}"/hotspot/merge.changeset ] ; then
|
||||
if [ -e ${TREE}/hotspot/.hg -o -e ${TREE}/hotspot/merge.changeset ] ; then
|
||||
HOTSPOT="hotspot";
|
||||
fi
|
||||
|
||||
SUBTREES="${CORBA} ${JAXP} ${JAXWS} ${LANGTOOLS} ${NASHORN} ${JDK} ${HOTSPOT}";
|
||||
echo "${SUBTREES}"
|
||||
|
||||
# Local Variables:
|
||||
# compile-command: "shellcheck discover_trees.sh"
|
||||
# fill-column: 80
|
||||
# indent-tabs-mode: nil
|
||||
# sh-basic-offset: 4
|
||||
# End:
|
||||
echo ${SUBTREES}
|
||||
4233
fips-21u-75ffdc48eda.patch
Normal file
4233
fips-21u-75ffdc48eda.patch
Normal file
File diff suppressed because it is too large
Load diff
|
|
@ -1,92 +0,0 @@
|
|||
diff --git a/src/java.base/share/classes/java/security/Provider.java b/src/java.base/share/classes/java/security/Provider.java
|
||||
index de2845fb550..b1e416b90f4 100644
|
||||
--- a/src/java.base/share/classes/java/security/Provider.java
|
||||
+++ b/src/java.base/share/classes/java/security/Provider.java
|
||||
@@ -1203,6 +1203,39 @@ public Set<Service> getServices() {
|
||||
return serviceSet;
|
||||
}
|
||||
|
||||
+ /* vvvvvvvvvvvvvvvvvvvvvvvvvvvvv FIPS PATCH vvvvvvvvvvvvvvvvvvvvvvvvvvvvv */
|
||||
+ private static final class RedHatFIPSFilter {
|
||||
+ static final boolean IS_ON = Boolean.parseBoolean(
|
||||
+ Security.getProperty("__redhat_fips_filter__"));
|
||||
+ private static final Set<String> ANY_SERVICE_TYPE = Set.of();
|
||||
+ private static final Map<String, Set<String>> ALLOW_LIST = Map.of(
|
||||
+ "SunPKCS11-FIPS", ANY_SERVICE_TYPE,
|
||||
+ "SUN", Set.of(
|
||||
+ "AlgorithmParameterGenerator",
|
||||
+ "AlgorithmParameters", "CertificateFactory",
|
||||
+ "CertPathBuilder", "CertPathValidator", "CertStore",
|
||||
+ "Configuration", "KeyStore"),
|
||||
+ "SunEC", Set.of(
|
||||
+ "AlgorithmParameters", "KeyFactory"),
|
||||
+ "SunJSSE", ANY_SERVICE_TYPE,
|
||||
+ "SunJCE", Set.of(
|
||||
+ "AlgorithmParameters",
|
||||
+ "AlgorithmParameterGenerator", "KeyFactory",
|
||||
+ "SecretKeyFactory"),
|
||||
+ "SunRsaSign", Set.of(
|
||||
+ "KeyFactory", "AlgorithmParameters"),
|
||||
+ "XMLDSig", ANY_SERVICE_TYPE
|
||||
+ );
|
||||
+
|
||||
+ static boolean isAllowed(String provName, String serviceType) {
|
||||
+ Set<String> allowedServiceTypes = ALLOW_LIST.get(provName);
|
||||
+ return allowedServiceTypes != null &&
|
||||
+ (allowedServiceTypes == ANY_SERVICE_TYPE ||
|
||||
+ allowedServiceTypes.contains(serviceType));
|
||||
+ }
|
||||
+ }
|
||||
+ /* ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ FIPS PATCH ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ */
|
||||
+
|
||||
/**
|
||||
* Add a service. If a service of the same type with the same algorithm
|
||||
* name exists, and it was added using {@link #putService putService()},
|
||||
@@ -1231,6 +1264,15 @@ protected void putService(Service s) {
|
||||
("service.getProvider() must match this Provider object");
|
||||
}
|
||||
String type = s.getType();
|
||||
+ /* vvvvvvvvvvvvvvvvvvvvvvvvvvv FIPS PATCH vvvvvvvvvvvvvvvvvvvvvvvvvvv */
|
||||
+ if (RedHatFIPSFilter.IS_ON && !RedHatFIPSFilter.isAllowed(name, type)) {
|
||||
+ if (debug != null) {
|
||||
+ debug.println("The previous " + name + ".putService() call " +
|
||||
+ "was skipped by " + RedHatFIPSFilter.class.getName());
|
||||
+ }
|
||||
+ return;
|
||||
+ }
|
||||
+ /* ^^^^^^^^^^^^^^^^^^^^^^^^^^^ FIPS PATCH ^^^^^^^^^^^^^^^^^^^^^^^^^^^ */
|
||||
String algorithm = s.getAlgorithm();
|
||||
ServiceKey key = new ServiceKey(type, algorithm, true);
|
||||
implRemoveService(serviceMap.get(key));
|
||||
diff --git a/src/java.base/share/classes/java/security/Security.java b/src/java.base/share/classes/java/security/Security.java
|
||||
index 6969fe8a8e1..4501d5971c4 100644
|
||||
--- a/src/java.base/share/classes/java/security/Security.java
|
||||
+++ b/src/java.base/share/classes/java/security/Security.java
|
||||
@@ -323,7 +323,27 @@ public Properties getInitialProperties() {
|
||||
}
|
||||
|
||||
private static void initialize() {
|
||||
+ /* vvvvvvvvvvvvvvvvvvvvvvvvvvv FIPS PATCH vvvvvvvvvvvvvvvvvvvvvvvvvvv */
|
||||
+ /* This 'include'-directives-only magic property is an internal */
|
||||
+ /* implementation detail that could (and probably will!) change. */
|
||||
+ /* Red Hat customers should NOT rely on this for their own use. */
|
||||
+ String fipsKernelFlag = "/proc/sys/crypto/fips_enabled";
|
||||
+ boolean fipsModeOn;
|
||||
+ try (InputStream is = new java.io.FileInputStream(fipsKernelFlag)) {
|
||||
+ fipsModeOn = is.read() == '1';
|
||||
+ } catch (IOException ioe) {
|
||||
+ fipsModeOn = false;
|
||||
+ if (sdebug != null) {
|
||||
+ sdebug.println("Failed to read FIPS kernel file: " + ioe);
|
||||
+ }
|
||||
+ }
|
||||
+ String fipsMagicPropName = "__redhat_fips__";
|
||||
+ System.setProperty(fipsMagicPropName, "" + fipsModeOn);
|
||||
+ /* ^^^^^^^^^^^^^^^^^^^^^^^^^^^ FIPS PATCH ^^^^^^^^^^^^^^^^^^^^^^^^^^^ */
|
||||
SecPropLoader.loadAll();
|
||||
+ /* vvvvvvvvvvvvvvvvvvvvvvvvvvv FIPS PATCH vvvvvvvvvvvvvvvvvvvvvvvvvvv */
|
||||
+ System.clearProperty(fipsMagicPropName);
|
||||
+ /* ^^^^^^^^^^^^^^^^^^^^^^^^^^^ FIPS PATCH ^^^^^^^^^^^^^^^^^^^^^^^^^^^ */
|
||||
initialSecurityProperties = (Properties) props.clone();
|
||||
if (sdebug != null) {
|
||||
for (String key : props.stringPropertyNames()) {
|
||||
|
|
@ -1,10 +1,6 @@
|
|||
#!/bin/bash
|
||||
|
||||
# Copyright (C) 2024 Red Hat, Inc.
|
||||
# Written by:
|
||||
# Andrew John Hughes <gnu.andrew@redhat.com>
|
||||
# Thomas Fitzsimmons <fitzsim@redhat.com>
|
||||
# Jiri Vanek <jvanek@redhat.com>
|
||||
#
|
||||
# This program is free software: you can redistribute it and/or modify
|
||||
# it under the terms of the GNU Affero General Public License as
|
||||
|
|
@ -19,46 +15,42 @@
|
|||
# You should have received a copy of the GNU Affero General Public License
|
||||
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
|
||||
# Generates the source tarball for OpenJDK projects.
|
||||
#
|
||||
# There are multiple ways to specify the source code location and version:
|
||||
#
|
||||
# 1. Specify the version (VERSION), the location of the Git repository
|
||||
# (REPO_ROOT) and the root of the output tarball name (FILE_NAME_ROOT)
|
||||
# 2. Specify the version (VERSION) along with an upstream project name
|
||||
# (PROJECT_NAME) and repository name (REPO_NAME) that can be used
|
||||
# to construct the URL of the upstream OpenJDK repository.
|
||||
# 3. Specify OPENJDK_LATEST=1 and allow the script to obtain the JDK
|
||||
# feature version from the spec file, which is then used to
|
||||
# obtain the latest build promotion from the upstream repository.
|
||||
#
|
||||
# An appropriate bootstrap JDK is also required for when ./configure
|
||||
# is run within the checked out repository to generate the .src-rev.
|
||||
# file. This can be specified by setting BOOT_JDK.
|
||||
# Generates the 'source tarball' for JDK projects.
|
||||
#
|
||||
# Example 1:
|
||||
# This will check out the specified version from the specified
|
||||
# repository and construct a tarball called openjdk-17.0.3+5.tar.xz:
|
||||
#
|
||||
# $ VERSION=jdk-17.0.3+5 FILE_NAME_ROOT=open${VERSION} \
|
||||
# REPO_ROOT=$HOME/projects/openjdk/upstream/17u \
|
||||
# BOOT_JDK=/usr/lib/jvm/java-17-openjdk ./generate_source_tarball.sh
|
||||
# When used from local repo set REPO_ROOT pointing to file:// with your repo.
|
||||
# If your local repo follows upstream forests conventions, it may be enough to
|
||||
# set OPENJDK_URL.
|
||||
#
|
||||
# Example 2:
|
||||
# This will check out the same version as example 1, but from the
|
||||
# upstream repository:
|
||||
#
|
||||
# $ VERSION=jdk-25+36 PROJECT_NAME=openjdk REPO_NAME=jdk25u \
|
||||
# BOOT_JDK=/usr/lib/jvm/java-17-openjdk sh scripts/generate_source_tarball.sh
|
||||
#
|
||||
# Example 3:
|
||||
# This will read the OpenJDK feature version from the spec file, then create a
|
||||
# tarball from the most recent tag for that version in the upstream Git
|
||||
# repository.
|
||||
#
|
||||
# $ OPENJDK_LATEST=1 \
|
||||
# BOOT_JDK=/usr/lib/jvm/java-17-openjdk ./generate_source_tarball.sh
|
||||
# $ OPENJDK_LATEST=1 ./generate_source_tarball.sh
|
||||
# [...]
|
||||
# Tarball is: temp-generated-source-tarball-ujD/openjdk-17.0.10+6-ea.tar.xz
|
||||
#
|
||||
# Unless you use OPENJDK_LATEST, you have to set PROJECT_NAME, REPO_NAME and
|
||||
# VERSION, e.g.:
|
||||
#
|
||||
# PROJECT_NAME=openjdk
|
||||
# REPO_NAME=jdk24u
|
||||
# VERSION=jdk-24.0.1+9
|
||||
#
|
||||
# or to e.g., prepare systemtap, icedtea7's jstack and other tapsets:
|
||||
#
|
||||
# VERSION=6327cf1cea9e
|
||||
# REPO_NAME=icedtea7-2.6
|
||||
# PROJECT_NAME=release
|
||||
# OPENJDK_URL=http://icedtea.classpath.org/hg/
|
||||
# TO_COMPRESS="*/tapset"
|
||||
#
|
||||
# They are used to create correct name and are used in construction of sources
|
||||
# URL (unless REPO_ROOT is set).
|
||||
#
|
||||
# This script creates a single source tarball out of the repository based on the
|
||||
# given tag and removes code not allowed in Fedora/RHEL.
|
||||
|
||||
set -e
|
||||
|
||||
|
|
@ -122,7 +114,7 @@ if [ "$OPENJDK_LATEST" != "" ] ; then
|
|||
fi
|
||||
|
||||
if [ "$WITH_TEMP" != "" ] ; then
|
||||
pushd "$(mktemp --directory --tmpdir temp-generated-source-tarball-XXX)"
|
||||
pushd "$(mktemp --directory temp-generated-source-tarball-XXX)"
|
||||
fi
|
||||
|
||||
if [ "$VERSION" = "" ] ; then
|
||||
|
|
@ -208,25 +200,18 @@ echo -e "\tFILE_NAME_ROOT: ${FILE_NAME_ROOT}"
|
|||
echo -e "\tREPO_ROOT: ${REPO_ROOT}"
|
||||
echo -e "\tTO_COMPRESS: ${TO_COMPRESS}"
|
||||
echo -e "\tBOOT_JDK: ${BOOT_JDK}"
|
||||
echo -e "\tWITH_TEMP: ${WITH_TEMP}"
|
||||
echo -e "\tOPENJDK_LATEST: ${OPENJDK_LATEST}"
|
||||
|
||||
if [ -d "${FILE_NAME_ROOT}" ] ; then
|
||||
echo "Reusing existing ${FILE_NAME_ROOT}"
|
||||
echo "exists exists exists exists exists exists exists "
|
||||
echo "reusing reusing reusing reusing reusing reusing "
|
||||
echo "${FILE_NAME_ROOT}"
|
||||
STAT_TIME="$(stat --format=%Y "${FILE_NAME_ROOT}")"
|
||||
TAR_TIME="$(date --date=@"${STAT_TIME}" --iso-8601=seconds)"
|
||||
else
|
||||
mkdir "${FILE_NAME_ROOT}"
|
||||
pushd "${FILE_NAME_ROOT}"
|
||||
echo "Cloning ${VERSION} root repository from ${REPO_ROOT}"
|
||||
if realpath -q "${REPO_ROOT}"; then
|
||||
echo "Local path detected; not adding depth argument";
|
||||
DEPTH="--";
|
||||
else
|
||||
DEPTH="--depth=1";
|
||||
echo "Remote repository detected; adding ${DEPTH}";
|
||||
fi
|
||||
git clone -b "${VERSION}" "${DEPTH}" "${REPO_ROOT}" "${VERSION}"
|
||||
git clone --depth=1 -b "${VERSION}" "${REPO_ROOT}" "${VERSION}"
|
||||
pushd "${VERSION}"
|
||||
TAR_TIME="$(git log --max-count 1 --format=%cI)"
|
||||
popd
|
||||
|
|
@ -242,44 +227,39 @@ pushd "${FILE_NAME_ROOT}"
|
|||
popd
|
||||
rm -rf build
|
||||
|
||||
# Remove commit checks
|
||||
echo "Removing $(find "${VERSION}" -name '.jcheck' -print)"
|
||||
find "${VERSION}" -name '.jcheck' -print0 | xargs -0 rm -r
|
||||
|
||||
# Remove history and GHA
|
||||
echo "find ${VERSION} -name '.hgtags'"
|
||||
find "${VERSION}" -name '.hgtags' -exec rm -v '{}' '+'
|
||||
echo "find ${VERSION} -name '.hgignore'"
|
||||
find "${VERSION}" -name '.hgignore' -exec rm -v '{}' '+'
|
||||
echo "find ${VERSION} -name '.gitattributes'"
|
||||
find "${VERSION}" -name '.gitattributes' -exec rm -v '{}' '+'
|
||||
echo "find ${VERSION} -name '.gitignore'"
|
||||
find "${VERSION}" -name '.gitignore' -exec rm -v '{}' '+'
|
||||
# Work around some Git objects not having write permissions.
|
||||
echo "chmod --recursive u+w ${VERSION}/.git"
|
||||
chmod --recursive u+w "${VERSION}"/.git
|
||||
echo "find ${VERSION} -name '.git'"
|
||||
find "${VERSION}" -name '.git' -exec rm -rv '{}' '+'
|
||||
echo "find ${VERSION} -name '.github'"
|
||||
find "${VERSION}" -name '.github' -exec rm -rv '{}' '+'
|
||||
|
||||
EA_PART="$(awk -F= \
|
||||
'/^DEFAULT_PROMOTED_VERSION_PRE/ { if ($2) print "-"$2 }' \
|
||||
"${VERSION}"/make/conf/version-numbers.conf)"
|
||||
TARBALL_BASE=${FILE_NAME_ROOT}${EA_PART}.tar
|
||||
pushd "${VERSION}"
|
||||
# Omit commit checks, history, and GHA from archive.
|
||||
for skip in .jcheck .hgtags .hgignore .gitattributes .gitignore .github
|
||||
do
|
||||
echo "${skip}"" export-ignore" >> .git/info/attributes
|
||||
done
|
||||
# Do not bother with --mtime here; specify it to tar below.
|
||||
# Unforunately, git-archive sorts added files like .src-rev at the end;
|
||||
# retar below to use GNU tar --sort=name ordering which sorts .src-rev
|
||||
# at the start.
|
||||
git archive --output "${TARBALL_BASE}" --prefix="${VERSION}"/ \
|
||||
--add-file=.src-rev --format=tar "${VERSION}"
|
||||
popd
|
||||
mv "${VERSION}" "${VERSION}".git
|
||||
tar xf "${VERSION}".git/"${TARBALL_BASE}"
|
||||
echo "Compressing remaining forest"
|
||||
if [ "$COMPRESSION" = "xz" ] ; then
|
||||
SWITCH=cJf
|
||||
else
|
||||
SWITCH=czf
|
||||
fi
|
||||
EA_PART="$(awk -F= \
|
||||
'/^DEFAULT_PROMOTED_VERSION_PRE/ { if ($2) print "-"$2 }' \
|
||||
"${VERSION}"/make/conf/version-numbers.conf)"
|
||||
TARBALL_NAME=${FILE_NAME_ROOT}${EA_PART}.tar.${COMPRESSION}
|
||||
TARBALL_NAME=`echo ${TARBALL_BASE}.${COMPRESSION} | sed "s/-jdk-/-/g"`
|
||||
XZ_OPT=${XZ_OPT-"-T0"} \
|
||||
tar --mtime="${TAR_TIME}" --owner=root --group=root --sort=name \
|
||||
--exclude-vcs -$SWITCH "${TARBALL_NAME}" "${TO_COMPRESS}"
|
||||
-$SWITCH "${TARBALL_NAME}" "${TO_COMPRESS}"
|
||||
mv "${TARBALL_NAME}" ..
|
||||
popd
|
||||
if [ "$WITH_TEMP" != "" ] ; then
|
||||
echo "Tarball is: $(realpath .)/${TARBALL_NAME}"
|
||||
echo "Tarball is: $(realpath --relative-to=.. .)/${TARBALL_NAME}"
|
||||
popd
|
||||
else
|
||||
echo -n "Done. You may want to remove the uncompressed version"
|
||||
File diff suppressed because it is too large
Load diff
1
jconsole.desktop.in
Normal file
1
jconsole.desktop.in
Normal file
|
|
@ -0,0 +1 @@
|
|||
# this file is intentionally not here, as portable builds do not have desktop integration
|
||||
76
openjdk_news.sh
Executable file
76
openjdk_news.sh
Executable file
|
|
@ -0,0 +1,76 @@
|
|||
#!/bin/bash
|
||||
|
||||
# Copyright (C) 2022 Red Hat, Inc.
|
||||
# Written by Andrew John Hughes <gnu.andrew@redhat.com>, 2012-2022
|
||||
#
|
||||
# This program is free software: you can redistribute it and/or modify
|
||||
# it under the terms of the GNU Affero General Public License as
|
||||
# published by the Free Software Foundation, either version 3 of the
|
||||
# License, or (at your option) any later version.
|
||||
#
|
||||
# This program is distributed in the hope that it will be useful,
|
||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
# GNU Affero General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU Affero General Public License
|
||||
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
|
||||
OLD_RELEASE=$1
|
||||
NEW_RELEASE=$2
|
||||
REPO=$3
|
||||
SUBDIR=$4
|
||||
SCRIPT_DIR=$(dirname ${0})
|
||||
|
||||
if test "x${SUBDIR}" = "x"; then
|
||||
echo "No subdirectory specified; using .";
|
||||
SUBDIR=".";
|
||||
fi
|
||||
|
||||
if test "x$REPO" = "x"; then
|
||||
echo "No repository specified; using ${PWD}"
|
||||
REPO=${PWD}
|
||||
fi
|
||||
|
||||
if test x${TMPDIR} = x; then
|
||||
TMPDIR=/tmp;
|
||||
fi
|
||||
|
||||
echo "Repository: ${REPO}"
|
||||
|
||||
if [ -e ${REPO}/.git ] ; then
|
||||
TYPE=git;
|
||||
elif [ -e ${REPO}/.hg ] ; then
|
||||
TYPE=hg;
|
||||
else
|
||||
echo "No Mercurial or Git repository detected.";
|
||||
exit 1;
|
||||
fi
|
||||
|
||||
if test "x$OLD_RELEASE" = "x" || test "x$NEW_RELEASE" = "x"; then
|
||||
echo "ERROR: Need to specify old and new release";
|
||||
exit 2;
|
||||
fi
|
||||
|
||||
echo "Listing fixes between $OLD_RELEASE and $NEW_RELEASE in $REPO"
|
||||
rm -f ${TMPDIR}/fixes2 ${TMPDIR}/fixes3 ${TMPDIR}/fixes
|
||||
for repos in . $(${SCRIPT_DIR}/discover_trees.sh ${REPO});
|
||||
do
|
||||
if test "x$TYPE" = "xhg"; then
|
||||
hg log -r "tag('$NEW_RELEASE'):tag('$OLD_RELEASE') - tag('$OLD_RELEASE')" -R $REPO/$repos -G -M ${REPO}/${SUBDIR} | \
|
||||
grep -E '^[o:| ]*summary'|grep -v 'Added tag'|sed -r 's#^[o:| ]*summary:\W*([0-9])# - JDK-\1#'| \
|
||||
sed 's#^[o:| ]*summary:\W*# - #' >> ${TMPDIR}/fixes2;
|
||||
hg log -v -r "tag('$NEW_RELEASE'):tag('$OLD_RELEASE') - tag('$OLD_RELEASE')" -R $REPO/$repos -G -M ${REPO}/${SUBDIR} | \
|
||||
grep -E '^[o:| ]*[0-9]{7}'|sed -r 's#^[o:| ]*([0-9]{7})# - JDK-\1#' >> ${TMPDIR}/fixes3;
|
||||
else
|
||||
git -C ${REPO} log --no-merges --pretty=format:%B ${NEW_RELEASE}...${OLD_RELEASE} -- ${SUBDIR} |grep -E '^[0-9]{7}' | \
|
||||
sed -r 's#^([0-9])# - JDK-\1#' >> ${TMPDIR}/fixes2;
|
||||
touch ${TMPDIR}/fixes3 ; # unused
|
||||
fi
|
||||
done
|
||||
|
||||
sort ${TMPDIR}/fixes2 ${TMPDIR}/fixes3 | uniq > ${TMPDIR}/fixes
|
||||
rm -f ${TMPDIR}/fixes2 ${TMPDIR}/fixes3
|
||||
|
||||
echo "In ${TMPDIR}/fixes:"
|
||||
cat ${TMPDIR}/fixes
|
||||
|
|
@ -1,172 +0,0 @@
|
|||
#!/usr/bin/env sh
|
||||
|
||||
# Copyright (C) 2025 Red Hat, Inc.
|
||||
# Original written by Antonio Vieiro <avieirov@redhat.com>
|
||||
#
|
||||
# This program is free software: you can redistribute it and/or modify
|
||||
# it under the terms of the GNU Affero General Public License as
|
||||
# published by the Free Software Foundation, either version 3 of the
|
||||
# License, or (at your option) any later version.
|
||||
#
|
||||
# This program is distributed in the hope that it will be useful,
|
||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
# GNU Affero General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU Affero General Public License
|
||||
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
|
||||
if [ $# -ne 1 ]; then
|
||||
echo "Usage: $0 openjdk-root-directory"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
JDKROOT=$1
|
||||
|
||||
if [ ! -d "${JDKROOT}" ] ; then
|
||||
echo "${JDKROOT} is not a directory.";
|
||||
exit 2
|
||||
fi
|
||||
|
||||
# Work out the OpenJDK version
|
||||
# OpenJDK >= 10 has its version in the build machinery
|
||||
# OpenJDK >= 17 stores it in a new location (JDK-8258246)
|
||||
VERSION_FILE="${JDKROOT}"/make/conf/version-numbers.conf
|
||||
printf "Checking for %s..." "${VERSION_FILE}";
|
||||
if [ ! -f "${VERSION_FILE}" ] ; then
|
||||
VERSION_FILE="${JDKROOT}"/make/autoconf/version-numbers
|
||||
echo "Not found; using old version file ${VERSION_FILE}";
|
||||
else
|
||||
echo "found.";
|
||||
fi
|
||||
if [ -e "${VERSION_FILE}" ] ; then
|
||||
openjdk_version=$(grep '^DEFAULT_VERSION_FEATURE' "${VERSION_FILE}" | cut -d '=' -f 2)
|
||||
elif [ -e "${JDKROOT}"/jdk/src/java.base/share/classes/java/lang/Object.java ] ; then
|
||||
openjdk_version=9;
|
||||
elif [ -e "${JDKROOT}"/common/autoconf ] ; then
|
||||
openjdk_version=8;
|
||||
else
|
||||
openjdk_version=7;
|
||||
fi
|
||||
echo "OpenJDK version: ${openjdk_version}";
|
||||
|
||||
#
|
||||
# Freetype
|
||||
#
|
||||
if [ "${openjdk_version}" -gt 8 ] ; then
|
||||
FREETYPE=src/java.desktop/share/native/libfreetype/include/freetype/freetype.h
|
||||
ABS_FREETYPE="${JDKROOT}"/"${FREETYPE}"
|
||||
if [ ! -f "${ABS_FREETYPE}" ]; then
|
||||
echo "Freetype header not found!"
|
||||
exit 2
|
||||
fi
|
||||
FREETYPE_VERSION=$(awk '/#define FREETYPE_MAJOR/ {MAJOR=$3} /#define FREETYPE_MINOR/ {MINOR=$3} /#define FREETYPE_PATCH/ {PATCH=$3} END {printf "%s.%s.%s", MAJOR, MINOR, PATCH}' "${ABS_FREETYPE}")
|
||||
else
|
||||
echo "No bundled FreeType on ${openjdk_version}";
|
||||
fi
|
||||
|
||||
# giflib
|
||||
if [ "${openjdk_version}" -gt 8 ] ; then
|
||||
GIFLIB=src/java.desktop/share/native/libsplashscreen/giflib/gif_lib.h
|
||||
else
|
||||
GIFLIB=jdk/src/share/native/sun/awt/giflib/gif_lib.h
|
||||
fi
|
||||
ABS_GIFLIB="${JDKROOT}"/"${GIFLIB}"
|
||||
if [ ! -f "${ABS_GIFLIB}" ]; then
|
||||
echo "giflib header not found!"
|
||||
exit 3
|
||||
fi
|
||||
GIFLIB_VERSION=$(awk '/#define GIFLIB_MAJOR/ {MAJOR=$3} /#define GIFLIB_MINOR/ {MINOR=$3} /#define GIFLIB_RELEASE/ {PATCH=$3} END {printf "%s.%s.%s", MAJOR, MINOR, PATCH}' "${ABS_GIFLIB}")
|
||||
|
||||
# harfbuzz
|
||||
if [ "${openjdk_version}" -gt 8 ] ; then
|
||||
HARFBUZZ=src/java.desktop/share/native/libharfbuzz/hb-version.h
|
||||
ABS_HARFBUZZ="${JDKROOT}/${HARFBUZZ}"
|
||||
if [ ! -f "${ABS_HARFBUZZ}" ]; then
|
||||
echo "HarfBuzz header not found!"
|
||||
exit 4
|
||||
fi
|
||||
HARFBUZZ_VERSION=$(awk '/#define HB_VERSION_MAJOR/ {MAJOR=$3} /#define HB_VERSION_MINOR/ {MINOR=$3} /#define HB_VERSION_MICRO/ {PATCH=$3} END {printf "%s.%s.%s", MAJOR, MINOR, PATCH}' "${ABS_HARFBUZZ}")
|
||||
else
|
||||
echo "No HarfBuzz on ${openjdk_version}";
|
||||
fi
|
||||
|
||||
# lcms
|
||||
if [ "${openjdk_version}" -gt 8 ] ; then
|
||||
LCMS=src/java.desktop/share/native/liblcms/lcms2.h
|
||||
else
|
||||
LCMS=jdk/src/share/native/sun/java2d/cmm/lcms/lcms2.h
|
||||
fi
|
||||
ABS_LCMS="${JDKROOT}"/"${LCMS}"
|
||||
if [ ! -f "${ABS_LCMS}" ]; then
|
||||
echo "lcms header not found!"
|
||||
exit 5
|
||||
fi
|
||||
LCMS_VERSION=$(awk '/#define LCMS_VERSION/ { MAJOR=int($3 / 1000); REST=$3 % 1000; MINOR=int(REST / 10); PATCH=REST % 10; } END {printf "%s.%s.%s", MAJOR, MINOR, PATCH}' "${ABS_LCMS}")
|
||||
|
||||
# jpeg
|
||||
if [ "${openjdk_version}" -gt 8 ] ; then
|
||||
JPEG=src/java.desktop/share/native/libjavajpeg/jpeglib.h
|
||||
else
|
||||
JPEG=jdk/src/share/native/sun/awt/image/jpeg/jpeglib.h
|
||||
fi
|
||||
ABS_JPEG="${JDKROOT}"/"${JPEG}"
|
||||
if [ ! -f "${ABS_JPEG}" ]; then
|
||||
echo "jpeg header not found!"
|
||||
exit 6
|
||||
fi
|
||||
JPEG_VERSION=$(awk '/#define JPEG_LIB_VERSION/ { VERSION=$3; MAJOR=int(VERSION / 10); MINOR=VERSION%10; } END {printf "%s%c", MAJOR, (MINOR+96)}' "${ABS_JPEG}")
|
||||
|
||||
# png
|
||||
if [ "${openjdk_version}" -gt 8 ] ; then
|
||||
PNG=src/java.desktop/share/native/libsplashscreen/libpng/png.h
|
||||
else
|
||||
PNG=jdk/src/share/native/sun/awt/libpng/png.h
|
||||
fi
|
||||
ABS_PNG="${JDKROOT}"/"${PNG}"
|
||||
if [ ! -f "${ABS_PNG}" ]; then
|
||||
echo "png header not found!"
|
||||
exit 7
|
||||
fi
|
||||
PNG_VERSION=$(awk '/#define PNG_LIBPNG_VER_STRING/ { VERSION=$3; gsub("\"", "", VERSION) } END {print VERSION}' "${ABS_PNG}")
|
||||
|
||||
# zlib
|
||||
if [ "${openjdk_version}" -gt 8 ] ; then
|
||||
ZLIB=src/java.base/share/native/libzip/zlib/zlib.h
|
||||
else
|
||||
ZLIB=jdk/src/share/native/java/util/zip/zlib/zlib.h
|
||||
fi
|
||||
ABS_ZLIB="${JDKROOT}"/"${ZLIB}"
|
||||
if [ ! -f "${ABS_ZLIB}" ]; then
|
||||
echo "zlib header not found!"
|
||||
exit 8
|
||||
fi
|
||||
ZLIB_VERSION=$(awk '/#define ZLIB_VERSION/ { VERSION=$3; gsub("\"", "", VERSION) } END {print VERSION}' "${ABS_ZLIB}")
|
||||
|
||||
# Print output
|
||||
printf "\nRPM definitions:\n"
|
||||
if [ "${openjdk_version}" -gt 8 ] ; then
|
||||
echo "# Version in ${FREETYPE}"
|
||||
echo "Provides: bundled(freetype) = ${FREETYPE_VERSION}"
|
||||
fi
|
||||
echo "# Version in ${GIFLIB}"
|
||||
echo "Provides: bundled(giflib) = ${GIFLIB_VERSION}"
|
||||
if [ "${openjdk_version}" -gt 8 ] ; then
|
||||
echo "# Version in ${HARFBUZZ}"
|
||||
echo "Provides: bundled(harfbuzz) = ${HARFBUZZ_VERSION}"
|
||||
fi
|
||||
echo "# Version in ${LCMS}"
|
||||
echo "Provides: bundled(lcms2) = ${LCMS_VERSION}"
|
||||
echo "# Version in ${JPEG}"
|
||||
echo "Provides: bundled(libjpeg) = ${JPEG_VERSION}"
|
||||
echo "# Version in ${PNG}"
|
||||
echo "Provides: bundled(libpng) = ${PNG_VERSION}"
|
||||
echo "# Version in ${ZLIB}"
|
||||
echo "Provides: bundled(zlib) = ${ZLIB_VERSION}"
|
||||
|
||||
# Local Variables:
|
||||
# compile-command: "shellcheck get_bundle_versions.sh"
|
||||
# fill-column: 80
|
||||
# indent-tabs-mode: nil
|
||||
# sh-basic-offset: 4
|
||||
# End:
|
||||
|
|
@ -1,114 +0,0 @@
|
|||
#!/bin/bash
|
||||
|
||||
# Copyright (C) 2024 Red Hat, Inc.
|
||||
# Written by Andrew John Hughes <gnu.andrew@redhat.com>, 2012-2022
|
||||
#
|
||||
# This program is free software: you can redistribute it and/or modify
|
||||
# it under the terms of the GNU Affero General Public License as
|
||||
# published by the Free Software Foundation, either version 3 of the
|
||||
# License, or (at your option) any later version.
|
||||
#
|
||||
# This program is distributed in the hope that it will be useful,
|
||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
# GNU Affero General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU Affero General Public License
|
||||
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
|
||||
OLD_RELEASE=$1
|
||||
NEW_RELEASE=$2
|
||||
REPO=$3
|
||||
SUBDIR=$4
|
||||
SCRIPT_DIR=$(dirname "${0}")
|
||||
|
||||
if test "${SUBDIR}" = ""; then
|
||||
echo "No subdirectory specified; using .";
|
||||
SUBDIR=".";
|
||||
fi
|
||||
|
||||
if test "$REPO" = ""; then
|
||||
echo "No repository specified; using ${PWD}"
|
||||
REPO=${PWD}
|
||||
fi
|
||||
|
||||
if test "${TMPDIR}" = ""; then
|
||||
TMPDIR=/tmp;
|
||||
fi
|
||||
|
||||
echo "Repository: ${REPO}"
|
||||
|
||||
if [ -e "${REPO}/.git" ] ; then
|
||||
TYPE=git;
|
||||
elif [ -e "${REPO}/.hg" ] ; then
|
||||
TYPE=hg;
|
||||
else
|
||||
echo "No Mercurial or Git repository detected.";
|
||||
exit 1;
|
||||
fi
|
||||
|
||||
if test "$OLD_RELEASE" = "" || test "$NEW_RELEASE" = ""; then
|
||||
echo "ERROR: Need to specify old and new release";
|
||||
exit 2;
|
||||
fi
|
||||
|
||||
echo "Listing fixes between $OLD_RELEASE and $NEW_RELEASE in $REPO"
|
||||
rm -f "${TMPDIR}/fixes2" "${TMPDIR}/fixes3" "${TMPDIR}/fixes"
|
||||
for repos in . $("${SCRIPT_DIR}/discover_trees.sh" "${REPO}");
|
||||
do
|
||||
if test "$TYPE" = "hg"; then
|
||||
hg log -r "tag('$NEW_RELEASE'):tag('$OLD_RELEASE') - tag('$OLD_RELEASE')" -R "$REPO/$repos" -G -M "${REPO}/${SUBDIR}" | \
|
||||
grep -E '^[o:| ]*summary'|grep -v 'Added tag'|sed -r 's#^[o:| ]*summary:\W*([0-9])# - JDK-\1#'| \
|
||||
sed 's#^[o:| ]*summary:\W*# - #' >> "${TMPDIR}/fixes2";
|
||||
hg log -v -r "tag('$NEW_RELEASE'):tag('$OLD_RELEASE') - tag('$OLD_RELEASE')" -R "$REPO/$repos" -G -M "${REPO}/${SUBDIR}" | \
|
||||
grep -E '^[o:| ]*[0-9]{7}'|sed -r 's#^[o:| ]*([0-9]{7})# - JDK-\1#' >> "${TMPDIR}/fixes3";
|
||||
else
|
||||
git -C "${REPO}" log --no-merges --pretty=format:%B "${NEW_RELEASE}...${OLD_RELEASE}" -- "${SUBDIR}" |grep -E '^[0-9]{7}' | \
|
||||
sed -r 's#^([0-9])# - JDK-\1#' >> "${TMPDIR}/fixes2";
|
||||
touch "${TMPDIR}/fixes3" ; # unused
|
||||
fi
|
||||
done
|
||||
|
||||
sort "${TMPDIR}/fixes2" "${TMPDIR}/fixes3" > "${TMPDIR}/fixes4"
|
||||
uniq "${TMPDIR}/fixes4" > "${TMPDIR}/fixes"
|
||||
rm -f "${TMPDIR}/fixes2" "${TMPDIR}/fixes3"
|
||||
|
||||
if ! [ -s "${TMPDIR}/fixes" ] ; then
|
||||
echo "Failed to obtain fixes.";
|
||||
exit 3;
|
||||
fi
|
||||
|
||||
echo "In ${TMPDIR}/fixes:"
|
||||
cat "${TMPDIR}/fixes"
|
||||
|
||||
printf "\nChecking for duplicates...";
|
||||
if uniq -d "${TMPDIR}/fixes4" | grep 'JDK' > "${TMPDIR}/dupes"; then
|
||||
printf "found.\nWARNING: Review the following duplicates:\n";
|
||||
cat "${TMPDIR}/dupes";
|
||||
else
|
||||
echo "No apparent duplicates.";
|
||||
fi
|
||||
rm -f "${TMPDIR}/fixes4";
|
||||
|
||||
printf "\nChecking for backouts...";
|
||||
if grep -i 'backout' "${TMPDIR}/fixes" > "${TMPDIR}/backouts"; then
|
||||
printf "found.\nWARNING: Review the following backouts:\n"
|
||||
cat "${TMPDIR}/backouts";
|
||||
else
|
||||
echo "No apparent backouts.";
|
||||
fi
|
||||
printf "\nChecking for bundled library updates...";
|
||||
if grep -iE ':( \(tz\))? update.*(freetype|gif|harfbuzz|lcms|jpeg|png|timezone|zlib)' "${TMPDIR}/fixes" > "${TMPDIR}/bundles"; then
|
||||
printf "found.\nWARNING: Review the following with respect to bundled provides:\n";
|
||||
cat "${TMPDIR}/bundles";
|
||||
echo "Compare the output of $(dirname "${0}")/get_bundle_versions.sh with the RPM using the JDK source tree"
|
||||
else
|
||||
echo "No apparent library updates.";
|
||||
fi
|
||||
|
||||
# Local Variables:
|
||||
# compile-command: "shellcheck openjdk_news.sh"
|
||||
# fill-column: 80
|
||||
# indent-tabs-mode: nil
|
||||
# sh-basic-offset: 4
|
||||
# End:
|
||||
2
sources
2
sources
|
|
@ -1 +1 @@
|
|||
SHA512 (openjdk-26+29-ea.tar.xz) = 4e80882e0de26eff7d46d762e255911d42544473cc5f12ab0af1997969a14cc697e1164cb3c90d894359b58cc42dbd2b233f00fa807dbfad41583da278e26666
|
||||
SHA512 (openjdk-24.0.1+9.tar.xz) = 44bd46f4478d6c466850c39bfefd575bf05f349f58512ecb4ec441eebc7282e27b8dc521a3e7b9d086ada0b43f7399f2258a4237b635a891727144b67911a185
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue